Skip to content

Davide Balzarotti

Publication record assembled from the DBLP archive of ranked conferences.

Papers indexed

93

Venues

20

Active years

2002–2026

Best venue rank

A*

Where they publish

Papers

93 indexed papers, newest first.

YearVenueTitleAuthors
2026AsiaCCSThe Role of Domain-Specific Features in Malware Detection: A macOS Case Study.Biagio Montaruli, Andrea Oliveri, Savino Dambra, Davide Balzarotti
2026AsiaCCSSoK: Systematization, Detection, and Hunting of Windows Malware Persistence Techniques.Jorik van Nielen, Andrea Oliveri, Jerre Starink, Andreas Peter, Marieke Huisman, Simone Aonzo, Davide Balzarotti, Andrea Continella
2026NDSSUnveiling BYOVD Threats: Malware's Use and Abuse of Kernel Drivers.Andrea Monzani, Antonio Parata, Andrea Oliveri, Simone Aonzo, Davide Balzarotti, Andrea Lanzi
2026SACSourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem.Biagio Montaruli, Serena Elisa Ponta, Luca Compagna, Davide Balzarotti
2025ACSACOne Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises.Biagio Montaruli, Luca Compagna, Serena Elisa Ponta, Davide Balzarotti
2025ESORICSThe Polymorphism Maze: Understanding Diversities and Similarities in Malware Families.Antonino Vitale, Simone Aonzo, Savino Dambra, Nanda Rani, Lorenzo Ippolito, Platon Kotzias, Juan Caballero, Davide Balzarotti
2025RAIDA Comprehensive Quantification of Inconsistencies in Memory Dumps.Andrea Oliveri, Davide Balzarotti
2025RAID{{alert('CSTI')}}: Large-Scale Detection of Client-Side Template Injection.Lorenzo Pisu, Davide Balzarotti, Davide Maiorca, Giorgio Giacinto
2024AsiaCCSUnmasking the Veiled: A Comprehensive Analysis of Android Evasive Malware.Antonio Ruggia, Dario Nisi, Savino Dambra, Alessio Merlo, Davide Balzarotti, Simone Aonzo
2024CCSOn Understanding and Forecasting Fuzzers Performance with Static Analysis.Dongjia Zhang, Andrea Fioraldi, Davide Balzarotti
2024DCAIModSec-Learn: Boosting ModSecurity with Machine Learning.Christian Scano, Giuseppe Floris, Biagio Montaruli, Luca Demetrio, Andrea Valenza, Luca Compagna, Davide Ariu, Luca Piras, Davide Balzarotti, Battista Biggio
2024NDSSPredictive Context-sensitive Fuzzing.Pietro Borrello, Andrea Fioraldi, Daniele Cono D'Elia, Davide Balzarotti, Leonardo Querzoni, Cristiano Giuffrida
2023CCSDecoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model Performance.Savino Dambra, Yufei Han, Simone Aonzo, Platon Kotzias, Antonino Vitale, Juan Caballero, Davide Balzarotti, Leyla Bilge
2023CCSRaze to the Ground: Query-Efficient Adversarial HTML Attacks on Machine-Learning Phishing Webpage Detectors.Biagio Montaruli, Luca Demetrio, Maura Pintor, Luca Compagna, Davide Balzarotti, Battista Biggio
2023NDSSAn OS-agnostic Approach to Memory Forensics.Andrea Oliveri, Matteo Dell'Amico, Davide Balzarotti
2022AsiaCCSThe Convergence of Source Code and Binary Vulnerability Discovery - A Case Study.Alessandro Mantovani, Luca Compagna, Yan Shoshitaishvili, Davide Balzarotti
2022CCSLibAFL: A Framework to Build Modular and Reusable Fuzzers.Andrea Fioraldi, Dominik Christian Maier, Dongjia Zhang, Davide Balzarotti
2022NDSSTestability Tarpits: the Impact of Code Patterns on the Security Testing of Web Applications.Feras Al Kassar, Giulia Clerici, Luca Compagna, Davide Balzarotti, Fabian Yamaguchi
2022SPJourney to the Center of the Cookie Ecosystem: Unraveling Actors' Roles and Relationships.Iskander Snchez-Rola, Matteo Dell'Amico, Davide Balzarotti, Pierre-Antoine Vervier, Leyla Bilge
2021AsiaCCSSoK: Enabling Security Analyses of Embedded Systems via Rehosting.Andrew Fasano, Tiemoko Ballo, Marius Muench, Tim Leek, Alexander Bulekov, Brendan Dolan-Gavitt, Manuel Egele, Aurlien Francillon, Long Lu, Nick Gregory, Davide Balzarotti, William Robertson
2021CCSTarnhelm: Isolated, Transparent & Confidential Execution of Arbitrary Code in ARM's TrustZone.Davide Quarta, Michele Ianni, Aravind Machiry, Yanick Fratantonio, Eric Gustafson, Davide Balzarotti, Martina Lindorfer, Giovanni Vigna, Christopher Kruegel
2021NDSSDoes Every Second Count? Time-based Evolution of Malware Behavior in Sandboxes.Alexander Kchler, Alessandro Mantovani, Yufei Han, Leyla Bilge, Davide Balzarotti
2021RAIDLost in the Loader: The Many Faces of the Windows PE File Format.Dario Nisi, Mariano Graziano, Yanick Fratantonio, Davide Balzarotti
2021SPTrust, But Verify: A Longitudinal Analysis Of Android OEM Compliance and Customization.Andrea Possemato, Simone Aonzo, Davide Balzarotti, Yanick Fratantonio
2020ACSACThe Tangled Genealogy of IoT Malware.Emanuele Cozzi, Pierre-Antoine Vervier, Matteo Dell'Amico, Yun Shen, Leyla Bilge, Davide Balzarotti
2020NDSSWhen Malware is Packin' Heat; Limits of Machine Learning Classifiers Based on Static Analysis Features.Hojjat Aghakhani, Fabio Gritti, Francesco Mecca, Martina Lindorfer, Stefano Ortolani, Davide Balzarotti, Giovanni Vigna, Christopher Kruegel
2020NDSSPrevalence and Impact of Low-Entropy Packing Schemes in the Malware Ecosystem.Alessandro Mantovani, Simone Aonzo, Xabier Ugarte-Pedrero, Alessio Merlo, Davide Balzarotti
2020WWWDirty Clicks: A Study of the Usability and Security Implications of Click-related Behaviors on the Web.Iskander Snchez-Rola, Davide Balzarotti, Christopher Kruegel, Giovanni Vigna, Igor Santos
2020SPSoK: Cyber Insurance - Technical Challenges and a System Security Roadmap.Savino Dambra, Leyla Bilge, Davide Balzarotti
2019ACSACBakingTimer: privacy analysis of server-side request processing time.Iskander Snchez-Rola, Davide Balzarotti, Igor Santos
2019CCSCan I Opt Out Yet?: GDPR and the Global Illusion of Cookie Control.Iskander Snchez-Rola, Matteo Dell'Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, Igor Santos
2019RAIDToward the Analysis of Embedded Firmware through Automated Re-hosting.Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aurlien Francillon, Yung Ryn Choe, Christopher Kruegel, Giovanni Vigna
2018CCSClock Around the Clock: Time-Based Device Fingerprinting.Iskander Snchez-Rola, Igor Santos, Davide Balzarotti
2018NDSSWhat You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded Devices.Marius Muench, Jan Stijohann, Frank Kargl, Aurlien Francillon, Davide Balzarotti
2018SPUnderstanding Linux Malware.Emanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide Balzarotti
2017CCSEvaluation of Deception-Based Web Attacks Detection.Xiao Han, Nizar Kheir, Davide Balzarotti
2017WWWThe Onions Have Eyes: A Comprehensive Structure and Privacy Analysis of Tor Hidden Services.Iskander Snchez-Rola, Davide Balzarotti, Igor Santos
2017SACAttacks landscape in the dark side of the web.Onur Catakoglu, Marco Balduzzi, Davide Balzarotti
2017SPA Lustrum of Malware Network Communication: Evolution and Insights.Chaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero, Manos Antonakakis
2016CCSROPMEMU: A Framework for the Analysis of Complex Code-Reuse Attacks.Mariano Graziano, Davide Balzarotti, Alain Zidouemba
2016CCSPhishEye: Live Monitoring of Sandboxed Phishing Kits.Xiao Han, Nizar Kheir, Davide Balzarotti
2016DIMVASubverting Operating System Properties Through Evolutionary DKOM Attacks.Mariano Graziano, Lorenzo Flore, Andrea Lanzi, Davide Balzarotti
2016DIMVAGoogle Dorks: Analysis, Creation, and New Defenses.Flavio Toffalini, Maurizio Abb, Damiano Carra, Davide Balzarotti
2016DIMVARAMBO: Run-Time Packer Analysis with Multiple Branch Observation.Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo Garca Bringas
2016DSNMeasuring the Role of Greylisting and Nolisting in Fighting Spam.Fabio Pagani, Matteo De Astis, Mariano Graziano, Andrea Lanzi, Davide Balzarotti
2016RAIDTaming Transactions: Towards Hardware-Assisted Control Flow Integrity Using Transactional Memory.Marius Muench, Fabio Pagani, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna, Davide Balzarotti
2016RAIDUses and Abuses of Server-Side Requests.Giancarlo Pellegrino, Onur Catakoglu, Davide Balzarotti, Christian Rossow
2016WWWAutomatic Extraction of Indicators of Compromise for Web Applications.Onur Catakoglu, Marco Balduzzi, Davide Balzarotti
2015ACSACPIE: Parser Identification in Embedded Systems.Lucian Cojocar, Jonas Zaddach, Roel Verdult, Herbert Bos, Aurlien Francillon, Davide Balzarotti
2015DIMVAThe Role of Cloud Services in Malicious Software: Trends and Insights.Xiao Han, Nizar Kheir, Davide Balzarotti
2015DIMVACutting the Gordian Knot: A Look Under the Hood of Ransomware Attacks.Amin Kharraz, William K. Robertson, Davide Balzarotti, Leyla Bilge, Engin Kirda
2015SPSoK: Deep Packer Inspection: A Longitudinal Study of the Complexity of Run-Time Packers.Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo Garca Bringas
2014CCSOn the effectiveness of risk prediction based on users browsing behavior.Davide Canali, Leyla Bilge, Davide Balzarotti
2014CCSShades of gray: a closer look at emails in the gray area.Jelena Isacenkova, Davide Balzarotti
2014CCSOn the feasibility of software attacks on commodity virtual machine monitors via direct device assignment.Gbor Pk, Andrea Lanzi, Abhinav Srivastava, Davide Balzarotti, Aurlien Francillon, Christoph Neumann
2014DSNOptical Delusions: A Study of Malicious QR Codes in the Wild.Amin Kharraz, Engin Kirda, William K. Robertson, Davide Balzarotti, Aurlien Francillon
2014NDSSToward Black-Box Detection of Logic Flaws in Web Applications.Giancarlo Pellegrino, Davide Balzarotti
2014NDSSAVATAR: A Framework to Support Dynamic Security Analysis of Embedded Systems' Firmwares.Jonas Zaddach, Luca Bruno, Aurlien Francillon, Davide Balzarotti
2013ACSACImplementation and implications of a stealth hard-drive backdoor.Jonas Zaddach, Anil Kurmus, Davide Balzarotti, Erik-Oliver Blass, Aurlien Francillon, Travis Goodspeed, Moitrayee Gupta, Ioannis Koltsidas
2013NDSSBehind the Scenes of Online Attacks: an Analysis of Exploitation Behaviors on the Web.Davide Canali, Davide Balzarotti
2013PSTThe role of phone numbers in understanding cyber-crime schemes.Andrei Costin, Jelena Isacenkova, Marco Balduzzi, Aurlien Francillon, Davide Balzarotti
2013RAIDHypervisor Memory Forensics.Mariano Graziano, Andrea Lanzi, Davide Balzarotti
2013WWWThe role of web hosting providers in detecting compromised websites.Davide Canali, Davide Balzarotti, Aurlien Francillon
2013SPInside the SCAM Jungle: A Closer Look at 419 Scam Email Operations.Jelena Isacenkova, Olivier Thonnard, Andrei Costin, Davide Balzarotti, Aurlien Francillon
2012ACSACDisclosure: detecting botnet command and control servers through large-scale NetFlow analysis.Leyla Bilge, Davide Balzarotti, William K. Robertson, Engin Kirda, Christopher Kruegel
2012ACSACTowards network containment in malware analysis systems.Mariano Graziano, Corrado Leita, Davide Balzarotti
2012COMPSACPreventing Input Validation Vulnerabilities in Web Applications through Automated Type Analysis.Theodoor Scholte, William K. Robertson, Davide Balzarotti, Engin Kirda
2012ISSTAA quantitative study of accuracy in system call-based malware detection.Davide Canali, Andrea Lanzi, Davide Balzarotti, Christopher Kruegel, Mihai Christodorescu, Engin Kirda
2012NDSSInsights into User Behavior in Dealing with Internet Attacks.Kaan Onarlioglu, Utku Ozan Yilmaz, Engin Kirda, Davide Balzarotti
2012SACA security analysis of amazon's elastic compute cloud service.Marco Balduzzi, Jonas Zaddach, Davide Balzarotti, Engin Kirda, Sergio Loureiro
2012SACAn empirical analysis of input validation mechanisms in web applications and languages.Theodoor Scholte, William K. Robertson, Davide Balzarotti, Engin Kirda
2012TAPFrom Model-Checking to Automated Testing of Security Protocols: Bridging the Gap.Alessandro Armando, Giancarlo Pellegrino, Roberto Carbone, Alessio Merlo, Davide Balzarotti
2011DIMVAReverse Social Engineering Attacks in Online Social Networks.Danesh Irani, Marco Balduzzi, Davide Balzarotti, Engin Kirda, Calton Pu
2011DIMVAOperating System Interface Obfuscation and the Revealing of Hidden Operations.Abhinav Srivastava, Andrea Lanzi, Jonathon T. Giffin, Davide Balzarotti
2011FCQuo Vadis? A Study of the Evolution of Input Validation Vulnerabilities in Web Applications.Theodoor Scholte, Davide Balzarotti, Engin Kirda
2011IMCMeasurement and evaluation of a real world deployment of a challenge-response spam filter.Jelena Isacenkova, Davide Balzarotti
2011NDSSAutomated Discovery of Parameter Pollution Vulnerabilities in Web Applications.Marco Balduzzi, Carmen Torrano Gimenez, Davide Balzarotti, Engin Kirda
2010ACSACG-Free: defeating return-oriented programming through gadget-less binaries.Kaan Onarlioglu, Leyla Bilge, Andrea Lanzi, Davide Balzarotti, Engin Kirda
2010CCSA solution for the automated detection of clickjacking attacks.Marco Balduzzi, Manuel Egele, Engin Kirda, Davide Balzarotti, Christopher Kruegel
2010CCSAccessMiner: using system-centric models for malware protection.Andrea Lanzi, Davide Balzarotti, Christopher Kruegel, Mihai Christodorescu, Engin Kirda
2010NDSSEfficient Detection of Split Personalities in Malware.Davide Balzarotti, Marco Cova, Christoph Karlberger, Engin Kirda, Christopher Kruegel, Giovanni Vigna
2010RAIDAbusing Social Networks for Automated User Profiling.Marco Balduzzi, Christian Platzer, Thorsten Holz, Engin Kirda, Davide Balzarotti, Christopher Kruegel
2009WWWAll your contacts are belong to us: automated identity theft attacks on social networks.Leyla Bilge, Thorsten Strufe, Davide Balzarotti, Engin Kirda
2008ISSTAAre your votesDavide Balzarotti, Greg Banks, Marco Cova, Viktoria Felmetsger, Richard A. Kemmerer, William K. Robertson, Fredrik Valeur, Giovanni Vigna
2008SPSaner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications.Davide Balzarotti, Marco Cova, Viktoria Felmetsger, Nenad Jovanovic, Engin Kirda, Christopher Kruegel, Giovanni Vigna
2008SPClearShot: Eavesdropping on Keyboard Input from Video.Davide Balzarotti, Marco Cova, Giovanni Vigna
2007ACSACImproving Signature Testing through Dynamic Data Flow Analysis.Christopher Kruegel, Davide Balzarotti, William K. Robertson, Giovanni Vigna
2007CCSMulti-module vulnerability analysis of web-based applications.Davide Balzarotti, Marco Cova, Viktoria Felmetsger, Giovanni Vigna
2007RAIDSwaddler: An Approach for the Anomaly-Based Detection of State Violations in Web Applications.Marco Cova, Davide Balzarotti, Viktoria Felmetsger, Giovanni Vigna
2005SACLighTS: a lightweight, customizable tuple space supporting context-aware applications.Gian Pietro Picco, Davide Balzarotti, Paolo Costa
2004CCSTesting network-based intrusion detection signatures using mutant exploits.Giovanni Vigna, William K. Robertson, Davide Balzarotti
2002NetworkingFreeing Cooperation from Servers Tyranny.Davide Balzarotti, Carlo Ghezzi, Mattia Monga
2002SEKESupporting configuration management for virtual workgroups ini a peer-to-peer setting.Davide Balzarotti, Carlo Ghezzi, Mattia Monga