<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>C. Comito);</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>AI to face covert attacks in IoT and softwarized scenarios: challenges and opportunities</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Angelica Liguori</string-name>
          <email>angelica.liguori@dimes.unical.it</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Simone Mungari</string-name>
          <email>simone.mungari@unical.it</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Marco Zuppelli</string-name>
          <email>marco.zuppelli@ge.imati.cnr.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Carmela Comito</string-name>
          <email>carmela.comito@icar.cnr.it</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Enrico Cambiaso</string-name>
          <email>enrico.cambiaso@ge.ieiit.cnr.it</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Matteo Repetto</string-name>
          <email>matteo.repetto@ge.imati.cnr.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Massimo Guarascio</string-name>
          <email>massimo.guarascio@icar.cnr.it</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Luca Caviglione</string-name>
          <email>luca.caviglione@ge.imati.cnr.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Giuseppe Manco</string-name>
          <email>giuseppe.manco@icar.cnr.it</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="editor">
          <string-name>Stealthy Malware, Stegomalware, Container Security, Evolving Threats</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute for Applied Mathematics and Information Technologies</institution>
          ,
          <addr-line>Via de Marini 6, Genova, 16149</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Institute for High Performance Computing and Networking</institution>
          ,
          <addr-line>via P. Bucci 8-9/C, Rende, 87036</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Institute of Electronics, Computer and Telecommunication Engineering</institution>
          ,
          <addr-line>Via de Marini 6, Genova, 16149</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>University of Calabria</institution>
          ,
          <addr-line>via P. Bucci, Rende, 87036</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>1975</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>Recently, the number of attacks aiming at breaching networked and softwarized environments has been growing exponentially. In particular, information hiding methods and covert attacks have been proven to be able to elude traditional detection systems and exfiltrate sensitive data without producing visible network flows or data exchanges. In this context, Artificial Intelligence techniques can play a key role in detecting these new emerging attacks, owing to their capability of quickly processing huge amounts of data without the necessity of expert intervention. In this work, we discuss the main challenges to face covert attacks in IoT and softwarized environments and we describe some preliminary results obtained by adopting Ital-IA 2023: 3rd National Conference on Artificial Intelligence, orga-</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The recent surge in the use of Artificial Intelligence (AI)
is also supported by its adoption to face the growing
number of cyber threats [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. In fact, in recent years, attacks
intensified both in terms of volume and complexity, for
instance, by using techniques to elude detection or to
conceal trafic flows exchanged with a remote controller
[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Moreover, advanced persistent threats demonstrated
their ability to bypass many security perimeters, also
due to the use of multi-stage loading architectures or
techniques to conceal attack routines. To this aim, AI
demonstrated to represent an efective tool for the
detection, reverse engineering, and forensics operations
nized by CINI, May 29–31, 2023, Pisa, Italy
∗Corresponding author.
operations [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        However, an emerging aspect concerns the use of
information hiding techniques to implement network covert
channels. In this case, the attacker aims at eluding
detection by not triggering classical defense systems based
on trafic anomalies or exfiltrating sensitive data without
producing visible flows. Owing to the efectiveness of the
approach, threat actors are increasingly exploring new
“carriers”, i.e., containers able to conceal secret and
malicious data. In this vein, a very recent efort is devoted to
understanding the feasibility of using the AI itself as a
carrier for malicious data; see, e.g., [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] for a discussion on
how information can be concealed in neurons or model
parameters. To make things more complex, the
increasing softwarization of networks and services accounts for
an almost boundless attack surface that can be exploited
to make future malware dificult to tame.
      </p>
      <p>From this perspective, our paper showcases the most
recent advances and research questions on the use of AI
to mitigate malware leveraging covert communications
or implementing (hidden) leakage attempts in
containerized architectures. Specifically, it discusses the use of
federated learning to eficiently deploy AI-based
countermeasures in ubiquitous IoT scenarios, as well as the
challenges characterizing micro-service architectures built
around container technologies. In addition, to ofer a
comprehensive discussion, we outline opportunities
offered by graph generation to devise new efective
solutions for detecting evolving threats.</p>
      <sec id="sec-1-1">
        <title>Summing up, the contribution of this work is to shed</title>
        <p>Covert Sender
Legitimate Network Traffic
Covert Channel</p>
        <p>Network Packets
with Hidden Information</p>
        <p>Internet</p>
        <p>Covert Receiver
new light on the use of AI to face the emerging threat encoded by the covert endpoints with two distinguished
endowed with covert attacks, especially when targeting TTL values. To reveal the presence of such covert
chanrealistic scenarios based on IoT or container technolo- nels, we developed a detection mechanism based on AI.
gies. Another contribution concerns the investigation In particular, we leveraged autoencoders because of their
of “perspective” challenges given by the use of AI-based capability to also deal with attacks undocumented and
frameworks. unknown a priori, as it happens when considering the</p>
        <p>
          The rest of the paper is structured as follows. Section carrier used to create the covert channel. To perform
2 deals with AI to mitigate threats using covert channels the detection, we monitored “windows” of network
packin IoT ecosystems, whereas Section 3 discusses oppor- ets to extract statistical metrics related to the TTL, e.g,
tunities for improving the security of containerized en- the maximum, the minimum, or the average TTL values.
vironments. Section 4 showcases opportunities arising Only legitimate trafic information has been given to the
from graph generation, and 5 presents challenges and autoencoder to perform the training. By contrast, the
opportunities of using AI for cybersecurity-related tasks. compromised trafic information has been used to
evalLastly, Section 6 concludes the paper. uate the performance of the detection model. Results
showcased the efectiveness of the AI-based approach,
i.e., we obtained ∼91% and ∼94% for the accuracy and the
2. Covert Malware in IoT Scenarios precision, respectively. Despite the promising results, we
extended the work evaluating an incremental learning
Information hiding techniques are increasingly used by scheme based on an ensemble of autoencoders trained
attackers to conceal malware in diferent carriers [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. For on disjointed data chunks [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. Figure 2 depicts the
proexample, network covert channels, i.e., hidden commu- posed architecture. Compared to the results obtained by
nications attempts nested within network trafic, can be using a single autoencoder, we obtained ∼95% both for
used to secretly exfiltrate information or to elude well- the accuracy and the precision when using an
ensemknown Intrusion Detection Systems (IDSes). Figure 1 ble of neural models. By using the incremental learning
depicts a possible reference scenario. In particular, it scheme, the model can also be deployed on devices with
shows the covert sender, e.g., a compromised node of an limited computational and storage resources, for instance
IoT deployment, exchanging secret information via net- in home gateways or edge nodes.
work features with the covert receiver, e.g., the Command Although the ensemble-based model allows for
im&amp; Control facility of the attacker. To do this, the sender proving the detection capabilities w.r.t. a single model,
could directly conceal data within the header of a proto- it requires to set the ensemble size, i.e., the number of
col or encode the information in the temporal evolution windows to consider in learning the model. In addition,
of network packets belonging to a specific conversation. it will be trained only against the data available on a
        </p>
        <p>
          Unfortunately, network covert channels are often ne- single edge node and the owners of the data could be not
glected by standard security tools, thus revealing their inclined to share them.
presence is mandatory to fully assess the security of a To overcome all these issues, we are interested in
inmodern network. To this aim, we addressed the problem vestigating the usage of a federated learning approach
of revealing hidden network communications targeting to address this task. In [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ], we evaluated the benefits
the IPv4 protocol in an IoT ecosystem [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]. We considered of this paradigm in a related (information-hiding)
scethe exfiltration of data hidden in the Time To Live (TTL) nario in which malicious payloads are hidden within
ifeld of a tampered IoT node, i.e., the bit “1” and “0” are
        </p>
        <p>
          Data Stream various possible attacks, threat actors are increasingly
exploiting techniques to let containers leak data beyond
a well-defined execution perimeter [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]. This mechanism
cDhautnaks Di-T D… Di-k D… Di irnestehmisbcleasset,hae schreaarteido nloocfaal rceosvoeurrtccehiasnanlteelr(esdeet,oSeecntcioodne2a):
secret message within its temporal evolution, which can
be observed outside the single container. For instance, a
sender process can manipulate the amount of memory
used within its container to alter the overall (host-level)
Ensemble Model available memory. Then, in parallel, a receiving process
running into another container can infer the message by
Figure 2: Incremental Deep Ensemble model approach. inspecting such a global statistic, e.g., by reading an entry
in the /proc/ filesystem for the case of Docker [
          <xref ref-type="bibr" rid="ref10 ref9">9, 10</xref>
          ].
        </p>
        <p>
          Server The security implications of such an “imperfect” isolation
UUppddaattee SLeorcvaelrMMooddelel Sedravtear taoreorscehveesrtarla.tFeiarsnt,acttoanctkaiannedrssycnacnheroxnchizaenmgea ninyfporromcaetsisoens
to implement DDoS/slow-DoS attacks [
          <xref ref-type="bibr" rid="ref10 ref11">10, 11</xref>
          ]. Second,
containers can leak information to recognize features
of the underlying hardware/software infrastructure and
support the reconnaissance stage at the basis of many
Node1 Node2 Node… Noden complex attack chains [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
        </p>
        <p>
          Ldoactaal Ldoactaal Ldoactaal Ldoactaal appTroomacihti,geastpeescuiachllystiefajlothinytlayttuascekds, wAiIthistaooplrsoambilseintog
gather precise information on the behavior of the overall
Figure 3: Federated Learning Architecture. software architecture [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]. As an example, containers
exchanging information in a secret manner could exhibit
tight temporal correlations. This is due to the need of
high-resolution icons that are commonly used in most altering a resource and “decode” changes close in time,
popular mobile ecosystems, including, Android and iOS. mainly to avoid that other competing processes will
disFigure 3 depicts the proposed approach. We assume to rupt the encoded secret [13]. Hence, AI can be used to
have a centralized server acting the role of coordinator spot anomalies in the “wake-sleep” pattern of containers
among  nodes. The server contains a “weak” DNN de- or to enlighten possible correlations dificult to capture
tector model trained on an initial dataset with a limited with the common sense, e.g., the distillation of signatures
number of examples. In the early stage, this initial detec- in system calls used to access shared statistics exposed by
tor is shared across n end nodes, which then fine-tune the kernel of the guest OS. Another important application
their model against their own local data. To make the of AI concerns the creation of suitable
whitelists/blackpredictor more robust and to find a global model in a lists. In fact, containers can also exhibit tight-coupled
distributed manner, a subset of end nodes periodically interactions when part of the same service. The AI can be
sends updates to the server containing the weights of then leveraged to whitelist containers expected to have
each layer composing their local DNN. The coordinator overlapped or correlated timing behaviors and prevent
aggregates the information received to build an ensemble too aggressive detection rules. Techniques like process
model and again shared it with the peers. This process is mining can be used to define precise traces of the system
iterated until a certain convergence criterion is reached. calls invoked by the software running within the
various containers. This can allow for the early revealing of
possible exfiltration attempts or feed an additional
AI3. Container Security based framework to perform runtime detection of leaking
attempts.
        </p>
        <p>
          Containers are now the preferred choice for the creation Indeed, AI can also be employed to face other types
of scalable frameworks able to take advantage of the of threats. For instance, the trafic exchanged by various
micro-service paradigm. Specifically, their lightweight containers or softwarized architectures can be used to
nature ofers many benefits compared to classical virtual detect exfiltration attempts, network-based attacks (e.g.,
machines, e.g., a smaller resource footprint or a reduced DoS/DDoS) or the presence of crypto-miners sending
delay when deploying new services. Unfortunately, secu- data to a centralized master entity [14]. Besides, more
rity requirements of containers are still not fully under- classical approaches based on the analysis of logs or the
stood as for the case of virtual machines [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. Among the (automatic) correlation of configurations and network
trafic should be updated to handle the highly-mutable the graph structure require flexible architectures able to
and dynamic nature of containerized services. Despite handle such modifications. We plan to devise a
deepthe considered threat, micro-service architectures imple- learning-based approach aiming at predicting graph
evomented via containers present many research challenges lution by considering stepwise changes (that can afect
and open issues, which are very stimulating. On one both, node and edge set). Moreover, to model long-term
hand, the need of gathering, processing and storing traf- evolutions, we are interested in defining an architecture
ifc at “wire speed” without degrading the overall Quality invariant to the network dimension. Learning the
evoluof Experience for feeding the AI poses many technical tion of dynamic graphs by extracting their temporal and
challenges. On the other hand, the presence of sensitive structural characteristics could be useful to identify
polydata and the need of conforming to constraints like the morphic cyber attacks, such as polymorphic malware [21]
General Data Protection Regulation (GDPR) impose to or those leveraging some form of obfuscation. This can
minimize the disclosure of personal or de-anonymizable also help to assess the emerging wave of steganographic
bits. The GDPR also requires to consider both the phys- malware [22]. In essence, this class of threats leverages
ical and legal boundaries where data is stored and pro- information hiding techniques to conceal malicious
ascessed. In this case, softwarized networks and infras- sets (e.g., configuration files or additional attack stages)
tructures are expected to greatly benefit from federated in various software artifacts, such as images, executables
approaches, especially owing to the edge flavor of many or metadata. Unfortunately, being very threat-specific,
future scenarios such as those based on 5G (see, e.g., [15] generalizing their detection via standard mechanisms or
and the references therein). signature-based approaches is a challenging task. In this
        </p>
        <p>Lastly, container security will also benefit from threat- vein, graph generation could lead to a more abstract and
specific hardening and configuration mechanisms. Also unified framework to early detect malicious software
tryin this case, AI represents a stimulating asset. For in- ing to reduce its footprint to remain unnoticed for long
stance, part of the software development life cycle of time frames.
containerized applications [16] can take advantage of AI,
especially to evaluate configurations, impose hardening
constraints or match security issues against known CVEs 5. Future and Main Challenges
or taxonomies. For the specific case of covert attacks, a
promising use case for AI concerns the identification of
resources that can be (ab)used to encode secret
information and characterized by “loose” isolation properties. As
a paradigmatic example, a suitable resource matrix [17]
can be computed by inspecting containers and software
(e.g., used libraries, code patterns, or execution privileges)
to provide automatic configuration policies preventing
leaking behaviors. This represents a major research
challenge, especially to avoid that the container engine will
terminate or impede the execution of “flagged”
containers in a too aggressive manner, thus impairing the quality
of the overall service.</p>
      </sec>
      <sec id="sec-1-2">
        <title>To efectively deploy AI for taming covert and hidden</title>
        <p>threats, various challenges and refinements have to be
addressed. First, the obtained data should model as
faithfully as possible real scenarios dealing with cybersecurity.</p>
        <p>
          This is in general complex, but it becomes
exceptionally hard when considering information-hiding-capable
threats. In fact, the lack of publicly-available datasets
capturing the presence of malware using covert channels
or other elusive mechanisms is a well-known problem
[
          <xref ref-type="bibr" rid="ref2">2, 22</xref>
          ]. Moreover, in publicly-available datasets samples
that represent cyber attacks are rare. Hence, the class
imbalance can dramatically afect the performances of
the detection models. Therefore, it is crucial to devise
approaches able to handle this skewness, e.g., by exploiting
4. Graph Generation for Detection generative models able to produce realistic anomalies.
Again, real data are dificult to retrieve, and, moreover,
In real-world scenarios, such as social networks, biology, they are usually afected by noise. In this respect,
unand recommender systems, complex relations among the labelled data can lead the systems to make errors if not
entities of graphs can hardly be modeled as flat tabu- properly handled as anomalies could be labeled as
“norlar data. In addition, many current AI-based solutions mal”, and, vice versa. In addition, due to data scarcity
assume that the underlying graph is static, however real- and skewness, the systems could erroneously classify
inworld networks are dynamic as both their topology and frequent legit behaviors (due to data shifts) as anomalous
dimension tend to change over time. Dynamic graphs ones.
[18] are typically adopted in several application domains, Moreover, some of the techniques briefly discussed
including cybersecurity with diferent purposes such as in this work [
          <xref ref-type="bibr" rid="ref5 ref6 ref7">5, 6, 7</xref>
          ] are threat-dependent and dificult
malware [19] and intrusion detection [20]. Dynamic evo- to generalize. For instance, AI-based models are able
lution is dificult to model due to the dynamic nature to detect hidden communication attempts only in fields
of the underlying process, where continuous changes in of the IPv4 protocol sharing similar functionalities [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ].
Therefore, a more general approach should be considered
to devise flexible and robust models. A possible idea is
to use more abstract metrics typical of at least a class
of hiding mechanisms. Then, multiple AI pipelines can
be deployed to eficiently detect a family of attacks, e.g.,
methods targeting IPv4 or IPv6 conversations [23]. In
addition, in unsupervised settings, it is dificult to define
boundaries between normal and anomalous behaviors.
        </p>
        <p>Again, this is especially hard when considering covert
attacks, which are stealthy by-design. Similarly, challenges
have to be faced when considering container security.</p>
        <p>On one hand, the overall security model still needs to be
fully understood. On the other hand, the complexity of
the various software layers requires proper modeling to
eficiently provide data to the AI.</p>
        <p>Lastly, as cyber-attacks can be represented via dynamic
graphs, it is crucial to define strategies able to detect
threats in evolving networks. Modeling and predicting
the evolution of dynamic graphs is a challenging task due
to their evolving nature. State-of-the-art systems lack
lfexibility, and, in this respect, models that guarantee
invariance w.r.t the input size should be devised.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>6. Conclusions</title>
      <sec id="sec-2-1">
        <title>This paper discussed the use of AI to address emerging</title>
        <p>challenges, i.e., threats endowed with mechanisms able
to covertly leak data in networked and softwarized
environments. As discussed, each scenario requires facing
diferent challenges. For instance, when dealing with
IoT ecosystems, federated learning could be considered
a main “technology enabler”, especially for distributing
computation and guaranteeing that sensitive data remain
confined at the border of the network. Instead,
containerized architecture could benefit from AI to find
correlations and patterns in the complex interplay of software
components.</p>
        <p>Unfortunately, the AI could also be exploited to hide
data, thus spawning new threats. To this aim, graph
generation should be carefully considered as it can help in
ifnding a convenient representation of operations (both
at the abstract level or in terms of system calls) to
support the detection of advanced ofensive schemes.
Accordingly, part of our future research will address the
aforementioned topics.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Acknowledgments</title>
      <sec id="sec-3-1">
        <title>This work was partially supported by project SERICS (PE00000014) under the NRRP MUR program funded by the EU - NGEU.</title>
        <p>[13] C. Marforio, H. Ritzdorf, A. Francillon, S. Capkun, representation learning and generative modeling,
Analysis of the communication between colluding 2022. doi:10.48550/ARXIV.2208.12126.
applications on modern smartphones, in: Proceed- [19] B. Anderson, D. Quist, J. Neil, C. Storlie, T. Lane,
ings of the 28th Annual Computer Security Appli- Graph-based malware detection using dynamic
cations Conference, 2012, pp. 51–60. analysis, Journal in computer Virology 7 (2011)
[14] J. A. Perez-Diaz, I. A. Valdovinos, K.-K. R. Choo, 247–258.</p>
        <p>D. Zhu, A flexible sdn-based architecture for [20] G. Duan, H. Lv, H. Wang, G. Feng, Application
identifying and mitigating low-rate ddos attacks of a dynamic line graph neural network for
intruusing machine learning, IEEE Access 8 (2020) sion detection with semisupervised learning, IEEE
155859–155872. Transactions on Information Forensics and Security
[15] V. Rey, P. M. S. Sánchez, A. H. Celdrán, G. Bovet, 18 (2023) 699–714.</p>
        <p>Federated learning for malware detection in iot de- [21] E. Avllazagaj, Z. Zhu, L. Bilge, D. Balzarotti, T.
Duvices, Computer Networks 204 (2022) 108693. mitras, When malware changed its mind: An
em[16] T. Rangnau, R. v. Buijtenen, F. Fransen, F. Turk- pirical study of variable program behaviors in the
men, Continuous security testing: A case study real world., in: USENIX Security Symposium, 2021,
on integrating dynamic security testing tools in pp. 3487–3504.
ci/cd pipelines, in: 2020 IEEE 24th International En- [22] L. Caviglione, W. Mazurczyk, Never mind the
malterprise Distributed Object Computing Conference ware, here’s the stegomalware, IEEE Security &amp;
(EDOC), IEEE, 2020, pp. 145–154. Privacy 20 (2022) 101–106.
[17] R. A. Kemmerer, Shared resource matrix methodol- [23] W. Mazurczyk, K. Powójski, L. Caviglione, IPv6
ogy: An approach to identifying storage and timing covert channels in the wild, in: Proceedings of the
channels, ACM Transactions on Computer Systems third central european cybersecurity conference,
1 (1983) 256–277. 2019, pp. 1–6.
[18] S. Gupta, S. Bedathur, A survey on temporal graph</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M. J. H.</given-names>
            <surname>Faruk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Shahriar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Valero</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Barsha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Sobhan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Khan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Whitman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Cuzzocrea</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Lo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Rahman</surname>
          </string-name>
          , et al.,
          <article-title>Malware detection and prevention using artificial intelligence techniques</article-title>
          ,
          <source>in: 2021 IEEE International Conference on Big Data (Big Data)</source>
          , IEEE,
          <year>2021</year>
          , pp.
          <fpage>5369</fpage>
          -
          <lpage>5377</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>W.</given-names>
            <surname>Mazurczyk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Caviglione</surname>
          </string-name>
          ,
          <article-title>Information Hiding as a Challenge for Malware Detection</article-title>
          ,
          <source>IEEE Security &amp; Privacy</source>
          <volume>2</volume>
          (
          <year>2015</year>
          )
          <fpage>89</fpage>
          -
          <lpage>93</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>D.</given-names>
            <surname>Ucci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Aniello</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Baldoni</surname>
          </string-name>
          ,
          <article-title>Survey of machine learning techniques for malware analysis</article-title>
          ,
          <source>Computers &amp; Security</source>
          <volume>81</volume>
          (
          <year>2019</year>
          )
          <fpage>123</fpage>
          -
          <lpage>147</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>T.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Wen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <article-title>Stegonet: Turn deep neural network into a stegomalware</article-title>
          , in: Annual Computer Security Applications Conference,
          <year>2020</year>
          , pp.
          <fpage>928</fpage>
          -
          <lpage>938</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>M.</given-names>
            <surname>Guarascio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Zuppelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Cassavia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Manco</surname>
          </string-name>
          , L. Caviglione,
          <article-title>Detection of Network Covert Channels in IoT Ecosystems Using Machine Learning</article-title>
          ,
          <source>in: Proc. of The Italian Conference on CyberSecurity</source>
          , volume
          <volume>3260</volume>
          <source>of CEUR Workshop Proceedings</source>
          ,
          <year>2022</year>
          , pp.
          <fpage>102</fpage>
          -
          <lpage>113</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>N.</given-names>
            <surname>Cassavia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Caviglione</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Guarascio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Liguori</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Zuppelli</surname>
          </string-name>
          ,
          <article-title>Ensembling Sparse Autoencoders for Network Covert Channel Detection in IoT Ecosystems</article-title>
          ,
          <source>in: Foundations of Intelligent Systems: 26th International Symposium</source>
          , Springer,
          <year>2022</year>
          , pp.
          <fpage>209</fpage>
          -
          <lpage>218</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>N.</given-names>
            <surname>Cassavia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Caviglione</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Guarascio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Liguori</surname>
          </string-name>
          , G. Surace,
          <string-name>
            <given-names>M.</given-names>
            <surname>Zuppelli</surname>
          </string-name>
          ,
          <article-title>Federated learning for the eficient detection of steganographic threats hidden in image icons</article-title>
          ,
          <source>in: Pervasive Knowledge and Collective Intelligence on Web and Social Media</source>
          , Springer Nature Switzerland, Cham,
          <year>2023</year>
          , pp.
          <fpage>83</fpage>
          -
          <lpage>95</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S.</given-names>
            <surname>Sultan</surname>
          </string-name>
          , I. Ahmad, T. Dimitriou,
          <article-title>Container security: Issues, challenges, and the road ahead</article-title>
          ,
          <source>IEEE Access 7</source>
          (
          <year>2019</year>
          )
          <fpage>52976</fpage>
          -
          <lpage>52996</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Luo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Luo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Sun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Shen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ruan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <article-title>Whispers between the containers: High-capacity covert channel attacks in docker</article-title>
          , in: Trustcom/BigDataSE/ISPA, IEEE,
          <year>2016</year>
          , pp.
          <fpage>630</fpage>
          -
          <lpage>637</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>X.</given-names>
            <surname>Gao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Steenkamer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Gu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Kayaalp</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Pendarakis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <article-title>A study on the security implications of information leakages in container clouds</article-title>
          ,
          <source>IEEE Transactions on Dependable and Secure Computing</source>
          <volume>18</volume>
          (
          <year>2018</year>
          )
          <fpage>174</fpage>
          -
          <lpage>191</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>I.</given-names>
            <surname>Vaccari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Aiello</surname>
          </string-name>
          , E. Cambiaso,
          <article-title>Slowtt: A slow denial of service against iot networks</article-title>
          ,
          <source>Information</source>
          <volume>11</volume>
          (
          <year>2020</year>
          )
          <fpage>452</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>F.</given-names>
            <surname>Al-Doghman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Moustafa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
            <surname>Khalil</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Tari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Zomaya</surname>
          </string-name>
          ,
          <article-title>Ai-enabled secure microservices in edge computing: Opportunities and challenges</article-title>
          ,
          <source>IEEE Transactions on Services Computing</source>
          (
          <year>2022</year>
          ).
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>