<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Technical Track</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Cybersecurity</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Pierpaolo Degano</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Roberto Zunino</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Dipartimento di Informatica Universita di Pisa Pisa</institution>
          ,
          <country country="IT">Italia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Dipartimento di Matematica Universita degli Studi di Trento Trento</institution>
          ,
          <country country="IT">Italia</country>
        </aff>
      </contrib-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>ITASEC19 is the third edition of the Italian Conference on Cybersecurity, an annual event started
in 2017 under the support of the CINI Cybersecurity National Laboratory with the aim of fostering
networking of cybersecurity researchers and professionals coming from universities, companies, and
government institutions. ITASEC19 was held on February 13-15, 2019 in Pisa and was structured
into a main cybersecurity science and technology track devoted to contributed talks; a demo track
devoted to prototypes developed by companies, research centers and universities; tutorials of interest
for the cybersecurity community at large; workshops providing a forum for interactively exchanging
opinions, presenting ideas, and discussing preliminary results; and special sessions where domestic
cybersecurity startups presented their ongoing activities.</p>
      <p>The conference solicited two types of submissions: unpublished contributions to be included in
the conference proceedings and presentation-only contributions of already published work,
preliminary work and position papers. There were 56 submissions from 10 countries around the world.
Among these there were 34 in the unpublished category and 22 in the presentation-only one. Each
submission was reviewed by at least 3 programme committee members, with the exception of four
with two reviews, only.</p>
      <p>The committee decided to accept 13 papers out of the 34 submitted in the unpublished category,
which are included in this proceedings volume. Other 18 papers from the presentation-only category
have been accepted, and have been presented at the conference without being included in this
volume. The peer reviewing process has been dealt with through EasyChair. We would like to
thank the programme committee members and all the external reviewers, as well as the authors of
all submitted papers.</p>
      <p>Besides the 31 presentations, the programme of the technical science and technology track
included this year two invited talks by Prof. David Basin, ETH Zurich and Prof. Peter Y A Ryan,
Universite du Luxembourg, two leading scientists in the wide area of software security, whom we
warmly thank.</p>
      <p>Prof. Basin's keynote, entitled \SCION: Highly Secure, High Performance Internet Routing,"
presented his recent work on building a more secure and performant interdomain routing
infrastructure that is already in productive use in Europe by nancial institutions and government agencies.
It o ers solutions to problems of today's Internet including: protection against DDoS attacks,
freedom from route hijacking, no globally trusted entities, path control enabling geofencing, and true
multipath communication. A distinctive feature of SCION is that large parts of its infrastructure
have been formally veri ed.</p>
      <p>The keynote by Prof. Ryan addressed the security issues arising in electronic voting, because the
increasing digitalisation of democracy brings with it novel and poorly understood attacks. Thus, an
electronic election should deliver, along with the outcome, su cient evidence to convince all,
especially the losers, that the announced outcome is valid. And of course, this must be achieved without
undermining ballot privacy or coercion resistance. A new scheme, Electryo, has been presented
that provides formal means for intuitive and transparent voter veri cation, coercion mitigation and
supports risk limiting audits.</p>
      <p>We would like to thank all the people involved in the organization of ITASEC19 and its tracks,
in particular Paolo Prinetto, Executive Director of the CINI Cybersecurity National Laboratory,
the General Chairs of the entire conference, Marco Conti and Rocco De Nicola.
Programme of the Scienti c and Technical Track
You can nd below the ITASEC19 scienti c and technical sessions. We point out the 13 papers
contained in these proceeding in bold font. All the remaining 18 presentation-only papers are not
contained therein, and they have been presented at the conference.</p>
    </sec>
    <sec id="sec-2">
      <title>Security Analysis I</title>
      <p>{ Elia Geretto, Cedric Tessier and Fabio Massacci</p>
    </sec>
    <sec id="sec-3">
      <title>A QBDI-based Fuzzer Taming Magic Bytes</title>
      <p>{ Valentina Casola, Alessandra De Benedictis and Roberto Nardone</p>
      <p>Towards Model-based Security Assessment of Cloud Applications
{ Federico Concone, Giuseppe Lo Re, Marco Morana and Claudio Ruocco</p>
    </sec>
    <sec id="sec-4">
      <title>Twitter Spam Account Detection by E ective Labeling</title>
    </sec>
    <sec id="sec-5">
      <title>Security Analysis II</title>
      <p>{ Salvatore Manfredi, Silvio Ranise and Giada Sciarretta</p>
      <p>TLSAssistant: a Comprehensive Tool for Identifying and Mitigating TLS Vulnerabilities
{ Gabriele Costa, Andrea Valenza and Alessandro Armando</p>
      <p>Why Charles Can Pen-test: an Evolutionary Approach to Vulnerability Testing
{ Daniele Cono D'Elia, Emilio Coppa, Federico Palmaro, Lorenzo Cavallaro and Camil
Demetrescu</p>
      <p>Reconciling Automatic and Manual Malware Analysis</p>
    </sec>
    <sec id="sec-6">
      <title>Formal Methods</title>
      <p>{ Matteo Busi and Letterio Galletta</p>
    </sec>
    <sec id="sec-7">
      <title>A Brief Tour of Formally Secure Compilation</title>
      <p>{ Roberto Nardone, Ricardo J. Rodriguez and Stefano Marrone</p>
      <p>Formal Security Assessment of Modbus Protocol
{ Marcello Cinque, Domenico Cotroneo and Antonio Pecchia</p>
      <p>Challenges and Directions in Security Information and Event Management (SIEM)</p>
    </sec>
    <sec id="sec-8">
      <title>Network Security</title>
      <p>{ Manuel Cheminod, Luca Durante, Lucia Seno and Adriano Valenzano</p>
      <p>Performance Evaluation and Modeling of an Industrial Application-layer Firewall
{ Lorenzo Ceragioli, Letterio Galletta and Mauro Tempesta</p>
    </sec>
    <sec id="sec-9">
      <title>From Firewalls to Functions and Back</title>
      <p>{ Luca Deri, Samuele Sabella and Simone Mainardi</p>
    </sec>
    <sec id="sec-10">
      <title>Combining System Visibility and Security Using eBPF Dissemination</title>
      <p>{ Enrico Russo, Gabriele Costa and Alessandro Armando</p>
      <p>Scenario Design and Validation for Next Generation Cyber Ranges
{ Maria Teresa Baldassarre, Vita Santa Barletta, Danilo Caivano, Domenico Raguseo
and Michele Scalera</p>
    </sec>
    <sec id="sec-11">
      <title>Teaching Cyber Security: The HACK-SPACE Integrated Model</title>
      <p>{ Antonello Calabro, Said Daoudagh and Eda Marchetti</p>
    </sec>
    <sec id="sec-12">
      <title>Integrating Access Control and Business Process for GDPR Compliance: A Preliminary Study</title>
    </sec>
    <sec id="sec-13">
      <title>Machine Learning</title>
      <p>{ Marino Miculan, Gian Luca Foresti and Claudio Piciarelli</p>
    </sec>
    <sec id="sec-14">
      <title>Towards User Recognition by Shallow WEB Tra c Inspection</title>
      <p>{ Francesco Mercaldo, Vittoria Nardone and Antonella Santone</p>
      <p>An Assessment of Machine Learning Algorithms to Driver Detection
{ Dario Stabili, Mirco Marchetti and Michele Colajanni</p>
      <p>Signal Extraction from Automotive Dataframes
{ Luca Demetrio, Battista Biggio, Giovanni Lagorio, Fabio Roli and Alessandro
Armando</p>
    </sec>
    <sec id="sec-15">
      <title>Explaining Vulnerabilities of Deep Learning to Adversarial Malware Binaries</title>
    </sec>
    <sec id="sec-16">
      <title>Attacks</title>
      <p>{ Simone Aonzo, Alessio Merlo and Yanick Fratantonio</p>
      <p>Phishing Attacks on Modern Android
{ Enrico Cambiaso, Ivan Vaccari, Luca Patti and Maurizio Aiello</p>
    </sec>
    <sec id="sec-17">
      <title>Darknet Security: A Categorization of Attacks to the Tor Network</title>
      <p>{ Davide Maiorca, Alessandro Medda and Giorgio Giacinto</p>
      <p>Macro-Oblivion: Extensive Analysis of Macro-Based Microsoft O ce Malware</p>
    </sec>
    <sec id="sec-18">
      <title>Critical Systems</title>
      <p>{ Giuseppe Bernieri, Mauro Conti and Federica Pascucci</p>
      <p>A Novel Architecture for Cyber-Physical Security in Industrial Control System Networks
{ Davide Cerotti, Daniele Codetta-Raiteri, Giovanna Dondossola, Lavinia Egidi,
Giuliana Franceschinis, Luigi Portinale and Roberta Terruggia</p>
    </sec>
    <sec id="sec-19">
      <title>A Bayesian Network Approach for the Interpretation of Cyber Attacks to Power</title>
    </sec>
    <sec id="sec-20">
      <title>Systems</title>
      <p>{ Giulia Ferri, Giorgiomaria Cicero, Alessandro Biondi and Giorgio Buttazzo</p>
    </sec>
    <sec id="sec-21">
      <title>Towards the Hypervision of Hardware-based Control Flow Integrity for Arm Platforms</title>
    </sec>
    <sec id="sec-22">
      <title>Data-driven security</title>
      <p>{ Francesco Buccafurri, Gianluca Lax, Antonia Russo and Guillaume Zunino</p>
      <p>Allowing Accountable Transactions over Blockchain
{ Roberto Baldoni, Giuseppe Antonio Di Luna, Luca Massarelli, Fabio Petroni and Leonardo
Querzoni
Unsupervised Features Extraction for Binary Similarity Using Graph Embedding Neural
Networks
{ Darius Sas, Francesca Arcelli Fontana and Marco Bessi</p>
      <p>Automatic Detection of Sources and Sinks in Arbitrary Java Libraries</p>
    </sec>
    <sec id="sec-23">
      <title>Cryptography</title>
      <p>{ Marco Rasori, Pericle Perazzo and Gianluca Dini</p>
      <p>ABE-Cities: An Attribute-Based Encryption System for Smart Cities
{ Costantino Agnesi, Luca Calderaro, Silvia Ceccato, Daniele Dequal, Francesco Vedovato, Matteo
Schiavon, Alberto Santamato, Vincenza Luceri, Giuseppe Bianco, Giuseppe Vallone, Nicola
Laurenti and Paolo Villoresi</p>
      <p>Secure Global Communications Enabled by GNSS Satellite-based Quantum Key Distribution
{ Tiziano Fagni, Leonardo Nizzoli, Marinella Petrocchi and Maurizio Tesconi</p>
    </sec>
    <sec id="sec-24">
      <title>Six Things I Hate About You (in Italian) and Six Classi cation Strategies to More and More E ectively Find Them</title>
      <sec id="sec-24-1">
        <title>PROGRAMME COMMITTEE</title>
      </sec>
      <sec id="sec-24-2">
        <title>ADDITIONAL REFEREES</title>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>