Davide Balzarotti
Publication record assembled from the DBLP archive of ranked conferences.
Papers indexed
93
Venues
20
Active years
2002–2026
Best venue rank
A*
Where they publish
Papers
93 indexed papers, newest first.
| Year | Venue | Title | Authors |
|---|---|---|---|
| 2026 | AsiaCCS | The Role of Domain-Specific Features in Malware Detection: A macOS Case Study. | Biagio Montaruli, Andrea Oliveri, Savino Dambra, Davide Balzarotti |
| 2026 | AsiaCCS | SoK: Systematization, Detection, and Hunting of Windows Malware Persistence Techniques. | Jorik van Nielen, Andrea Oliveri, Jerre Starink, Andreas Peter, Marieke Huisman, Simone Aonzo, Davide Balzarotti, Andrea Continella |
| 2026 | NDSS | Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel Drivers. | Andrea Monzani, Antonio Parata, Andrea Oliveri, Simone Aonzo, Davide Balzarotti, Andrea Lanzi |
| 2026 | SAC | SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem. | Biagio Montaruli, Serena Elisa Ponta, Luca Compagna, Davide Balzarotti |
| 2025 | ACSAC | One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises. | Biagio Montaruli, Luca Compagna, Serena Elisa Ponta, Davide Balzarotti |
| 2025 | ESORICS | The Polymorphism Maze: Understanding Diversities and Similarities in Malware Families. | Antonino Vitale, Simone Aonzo, Savino Dambra, Nanda Rani, Lorenzo Ippolito, Platon Kotzias, Juan Caballero, Davide Balzarotti |
| 2025 | RAID | A Comprehensive Quantification of Inconsistencies in Memory Dumps. | Andrea Oliveri, Davide Balzarotti |
| 2025 | RAID | {{alert('CSTI')}}: Large-Scale Detection of Client-Side Template Injection. | Lorenzo Pisu, Davide Balzarotti, Davide Maiorca, Giorgio Giacinto |
| 2024 | AsiaCCS | Unmasking the Veiled: A Comprehensive Analysis of Android Evasive Malware. | Antonio Ruggia, Dario Nisi, Savino Dambra, Alessio Merlo, Davide Balzarotti, Simone Aonzo |
| 2024 | CCS | On Understanding and Forecasting Fuzzers Performance with Static Analysis. | Dongjia Zhang, Andrea Fioraldi, Davide Balzarotti |
| 2024 | DCAI | ModSec-Learn: Boosting ModSecurity with Machine Learning. | Christian Scano, Giuseppe Floris, Biagio Montaruli, Luca Demetrio, Andrea Valenza, Luca Compagna, Davide Ariu, Luca Piras, Davide Balzarotti, Battista Biggio |
| 2024 | NDSS | Predictive Context-sensitive Fuzzing. | Pietro Borrello, Andrea Fioraldi, Daniele Cono D'Elia, Davide Balzarotti, Leonardo Querzoni, Cristiano Giuffrida |
| 2023 | CCS | Decoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model Performance. | Savino Dambra, Yufei Han, Simone Aonzo, Platon Kotzias, Antonino Vitale, Juan Caballero, Davide Balzarotti, Leyla Bilge |
| 2023 | CCS | Raze to the Ground: Query-Efficient Adversarial HTML Attacks on Machine-Learning Phishing Webpage Detectors. | Biagio Montaruli, Luca Demetrio, Maura Pintor, Luca Compagna, Davide Balzarotti, Battista Biggio |
| 2023 | NDSS | An OS-agnostic Approach to Memory Forensics. | Andrea Oliveri, Matteo Dell'Amico, Davide Balzarotti |
| 2022 | AsiaCCS | The Convergence of Source Code and Binary Vulnerability Discovery - A Case Study. | Alessandro Mantovani, Luca Compagna, Yan Shoshitaishvili, Davide Balzarotti |
| 2022 | CCS | LibAFL: A Framework to Build Modular and Reusable Fuzzers. | Andrea Fioraldi, Dominik Christian Maier, Dongjia Zhang, Davide Balzarotti |
| 2022 | NDSS | Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web Applications. | Feras Al Kassar, Giulia Clerici, Luca Compagna, Davide Balzarotti, Fabian Yamaguchi |
| 2022 | SP | Journey to the Center of the Cookie Ecosystem: Unraveling Actors' Roles and Relationships. | Iskander Snchez-Rola, Matteo Dell'Amico, Davide Balzarotti, Pierre-Antoine Vervier, Leyla Bilge |
| 2021 | AsiaCCS | SoK: Enabling Security Analyses of Embedded Systems via Rehosting. | Andrew Fasano, Tiemoko Ballo, Marius Muench, Tim Leek, Alexander Bulekov, Brendan Dolan-Gavitt, Manuel Egele, Aurlien Francillon, Long Lu, Nick Gregory, Davide Balzarotti, William Robertson |
| 2021 | CCS | Tarnhelm: Isolated, Transparent & Confidential Execution of Arbitrary Code in ARM's TrustZone. | Davide Quarta, Michele Ianni, Aravind Machiry, Yanick Fratantonio, Eric Gustafson, Davide Balzarotti, Martina Lindorfer, Giovanni Vigna, Christopher Kruegel |
| 2021 | NDSS | Does Every Second Count? Time-based Evolution of Malware Behavior in Sandboxes. | Alexander Kchler, Alessandro Mantovani, Yufei Han, Leyla Bilge, Davide Balzarotti |
| 2021 | RAID | Lost in the Loader: The Many Faces of the Windows PE File Format. | Dario Nisi, Mariano Graziano, Yanick Fratantonio, Davide Balzarotti |
| 2021 | SP | Trust, But Verify: A Longitudinal Analysis Of Android OEM Compliance and Customization. | Andrea Possemato, Simone Aonzo, Davide Balzarotti, Yanick Fratantonio |
| 2020 | ACSAC | The Tangled Genealogy of IoT Malware. | Emanuele Cozzi, Pierre-Antoine Vervier, Matteo Dell'Amico, Yun Shen, Leyla Bilge, Davide Balzarotti |
| 2020 | NDSS | When Malware is Packin' Heat; Limits of Machine Learning Classifiers Based on Static Analysis Features. | Hojjat Aghakhani, Fabio Gritti, Francesco Mecca, Martina Lindorfer, Stefano Ortolani, Davide Balzarotti, Giovanni Vigna, Christopher Kruegel |
| 2020 | NDSS | Prevalence and Impact of Low-Entropy Packing Schemes in the Malware Ecosystem. | Alessandro Mantovani, Simone Aonzo, Xabier Ugarte-Pedrero, Alessio Merlo, Davide Balzarotti |
| 2020 | WWW | Dirty Clicks: A Study of the Usability and Security Implications of Click-related Behaviors on the Web. | Iskander Snchez-Rola, Davide Balzarotti, Christopher Kruegel, Giovanni Vigna, Igor Santos |
| 2020 | SP | SoK: Cyber Insurance - Technical Challenges and a System Security Roadmap. | Savino Dambra, Leyla Bilge, Davide Balzarotti |
| 2019 | ACSAC | BakingTimer: privacy analysis of server-side request processing time. | Iskander Snchez-Rola, Davide Balzarotti, Igor Santos |
| 2019 | CCS | Can I Opt Out Yet?: GDPR and the Global Illusion of Cookie Control. | Iskander Snchez-Rola, Matteo Dell'Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, Igor Santos |
| 2019 | RAID | Toward the Analysis of Embedded Firmware through Automated Re-hosting. | Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aurlien Francillon, Yung Ryn Choe, Christopher Kruegel, Giovanni Vigna |
| 2018 | CCS | Clock Around the Clock: Time-Based Device Fingerprinting. | Iskander Snchez-Rola, Igor Santos, Davide Balzarotti |
| 2018 | NDSS | What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded Devices. | Marius Muench, Jan Stijohann, Frank Kargl, Aurlien Francillon, Davide Balzarotti |
| 2018 | SP | Understanding Linux Malware. | Emanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide Balzarotti |
| 2017 | CCS | Evaluation of Deception-Based Web Attacks Detection. | Xiao Han, Nizar Kheir, Davide Balzarotti |
| 2017 | WWW | The Onions Have Eyes: A Comprehensive Structure and Privacy Analysis of Tor Hidden Services. | Iskander Snchez-Rola, Davide Balzarotti, Igor Santos |
| 2017 | SAC | Attacks landscape in the dark side of the web. | Onur Catakoglu, Marco Balduzzi, Davide Balzarotti |
| 2017 | SP | A Lustrum of Malware Network Communication: Evolution and Insights. | Chaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero, Manos Antonakakis |
| 2016 | CCS | ROPMEMU: A Framework for the Analysis of Complex Code-Reuse Attacks. | Mariano Graziano, Davide Balzarotti, Alain Zidouemba |
| 2016 | CCS | PhishEye: Live Monitoring of Sandboxed Phishing Kits. | Xiao Han, Nizar Kheir, Davide Balzarotti |
| 2016 | DIMVA | Subverting Operating System Properties Through Evolutionary DKOM Attacks. | Mariano Graziano, Lorenzo Flore, Andrea Lanzi, Davide Balzarotti |
| 2016 | DIMVA | Google Dorks: Analysis, Creation, and New Defenses. | Flavio Toffalini, Maurizio Abb, Damiano Carra, Davide Balzarotti |
| 2016 | DIMVA | RAMBO: Run-Time Packer Analysis with Multiple Branch Observation. | Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo Garca Bringas |
| 2016 | DSN | Measuring the Role of Greylisting and Nolisting in Fighting Spam. | Fabio Pagani, Matteo De Astis, Mariano Graziano, Andrea Lanzi, Davide Balzarotti |
| 2016 | RAID | Taming Transactions: Towards Hardware-Assisted Control Flow Integrity Using Transactional Memory. | Marius Muench, Fabio Pagani, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna, Davide Balzarotti |
| 2016 | RAID | Uses and Abuses of Server-Side Requests. | Giancarlo Pellegrino, Onur Catakoglu, Davide Balzarotti, Christian Rossow |
| 2016 | WWW | Automatic Extraction of Indicators of Compromise for Web Applications. | Onur Catakoglu, Marco Balduzzi, Davide Balzarotti |
| 2015 | ACSAC | PIE: Parser Identification in Embedded Systems. | Lucian Cojocar, Jonas Zaddach, Roel Verdult, Herbert Bos, Aurlien Francillon, Davide Balzarotti |
| 2015 | DIMVA | The Role of Cloud Services in Malicious Software: Trends and Insights. | Xiao Han, Nizar Kheir, Davide Balzarotti |
| 2015 | DIMVA | Cutting the Gordian Knot: A Look Under the Hood of Ransomware Attacks. | Amin Kharraz, William K. Robertson, Davide Balzarotti, Leyla Bilge, Engin Kirda |
| 2015 | SP | SoK: Deep Packer Inspection: A Longitudinal Study of the Complexity of Run-Time Packers. | Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo Garca Bringas |
| 2014 | CCS | On the effectiveness of risk prediction based on users browsing behavior. | Davide Canali, Leyla Bilge, Davide Balzarotti |
| 2014 | CCS | Shades of gray: a closer look at emails in the gray area. | Jelena Isacenkova, Davide Balzarotti |
| 2014 | CCS | On the feasibility of software attacks on commodity virtual machine monitors via direct device assignment. | Gbor Pk, Andrea Lanzi, Abhinav Srivastava, Davide Balzarotti, Aurlien Francillon, Christoph Neumann |
| 2014 | DSN | Optical Delusions: A Study of Malicious QR Codes in the Wild. | Amin Kharraz, Engin Kirda, William K. Robertson, Davide Balzarotti, Aurlien Francillon |
| 2014 | NDSS | Toward Black-Box Detection of Logic Flaws in Web Applications. | Giancarlo Pellegrino, Davide Balzarotti |
| 2014 | NDSS | AVATAR: A Framework to Support Dynamic Security Analysis of Embedded Systems' Firmwares. | Jonas Zaddach, Luca Bruno, Aurlien Francillon, Davide Balzarotti |
| 2013 | ACSAC | Implementation and implications of a stealth hard-drive backdoor. | Jonas Zaddach, Anil Kurmus, Davide Balzarotti, Erik-Oliver Blass, Aurlien Francillon, Travis Goodspeed, Moitrayee Gupta, Ioannis Koltsidas |
| 2013 | NDSS | Behind the Scenes of Online Attacks: an Analysis of Exploitation Behaviors on the Web. | Davide Canali, Davide Balzarotti |
| 2013 | PST | The role of phone numbers in understanding cyber-crime schemes. | Andrei Costin, Jelena Isacenkova, Marco Balduzzi, Aurlien Francillon, Davide Balzarotti |
| 2013 | RAID | Hypervisor Memory Forensics. | Mariano Graziano, Andrea Lanzi, Davide Balzarotti |
| 2013 | WWW | The role of web hosting providers in detecting compromised websites. | Davide Canali, Davide Balzarotti, Aurlien Francillon |
| 2013 | SP | Inside the SCAM Jungle: A Closer Look at 419 Scam Email Operations. | Jelena Isacenkova, Olivier Thonnard, Andrei Costin, Davide Balzarotti, Aurlien Francillon |
| 2012 | ACSAC | Disclosure: detecting botnet command and control servers through large-scale NetFlow analysis. | Leyla Bilge, Davide Balzarotti, William K. Robertson, Engin Kirda, Christopher Kruegel |
| 2012 | ACSAC | Towards network containment in malware analysis systems. | Mariano Graziano, Corrado Leita, Davide Balzarotti |
| 2012 | COMPSAC | Preventing Input Validation Vulnerabilities in Web Applications through Automated Type Analysis. | Theodoor Scholte, William K. Robertson, Davide Balzarotti, Engin Kirda |
| 2012 | ISSTA | A quantitative study of accuracy in system call-based malware detection. | Davide Canali, Andrea Lanzi, Davide Balzarotti, Christopher Kruegel, Mihai Christodorescu, Engin Kirda |
| 2012 | NDSS | Insights into User Behavior in Dealing with Internet Attacks. | Kaan Onarlioglu, Utku Ozan Yilmaz, Engin Kirda, Davide Balzarotti |
| 2012 | SAC | A security analysis of amazon's elastic compute cloud service. | Marco Balduzzi, Jonas Zaddach, Davide Balzarotti, Engin Kirda, Sergio Loureiro |
| 2012 | SAC | An empirical analysis of input validation mechanisms in web applications and languages. | Theodoor Scholte, William K. Robertson, Davide Balzarotti, Engin Kirda |
| 2012 | TAP | From Model-Checking to Automated Testing of Security Protocols: Bridging the Gap. | Alessandro Armando, Giancarlo Pellegrino, Roberto Carbone, Alessio Merlo, Davide Balzarotti |
| 2011 | DIMVA | Reverse Social Engineering Attacks in Online Social Networks. | Danesh Irani, Marco Balduzzi, Davide Balzarotti, Engin Kirda, Calton Pu |
| 2011 | DIMVA | Operating System Interface Obfuscation and the Revealing of Hidden Operations. | Abhinav Srivastava, Andrea Lanzi, Jonathon T. Giffin, Davide Balzarotti |
| 2011 | FC | Quo Vadis? A Study of the Evolution of Input Validation Vulnerabilities in Web Applications. | Theodoor Scholte, Davide Balzarotti, Engin Kirda |
| 2011 | IMC | Measurement and evaluation of a real world deployment of a challenge-response spam filter. | Jelena Isacenkova, Davide Balzarotti |
| 2011 | NDSS | Automated Discovery of Parameter Pollution Vulnerabilities in Web Applications. | Marco Balduzzi, Carmen Torrano Gimenez, Davide Balzarotti, Engin Kirda |
| 2010 | ACSAC | G-Free: defeating return-oriented programming through gadget-less binaries. | Kaan Onarlioglu, Leyla Bilge, Andrea Lanzi, Davide Balzarotti, Engin Kirda |
| 2010 | CCS | A solution for the automated detection of clickjacking attacks. | Marco Balduzzi, Manuel Egele, Engin Kirda, Davide Balzarotti, Christopher Kruegel |
| 2010 | CCS | AccessMiner: using system-centric models for malware protection. | Andrea Lanzi, Davide Balzarotti, Christopher Kruegel, Mihai Christodorescu, Engin Kirda |
| 2010 | NDSS | Efficient Detection of Split Personalities in Malware. | Davide Balzarotti, Marco Cova, Christoph Karlberger, Engin Kirda, Christopher Kruegel, Giovanni Vigna |
| 2010 | RAID | Abusing Social Networks for Automated User Profiling. | Marco Balduzzi, Christian Platzer, Thorsten Holz, Engin Kirda, Davide Balzarotti, Christopher Kruegel |
| 2009 | WWW | All your contacts are belong to us: automated identity theft attacks on social networks. | Leyla Bilge, Thorsten Strufe, Davide Balzarotti, Engin Kirda |
| 2008 | ISSTA | Are your votes | Davide Balzarotti, Greg Banks, Marco Cova, Viktoria Felmetsger, Richard A. Kemmerer, William K. Robertson, Fredrik Valeur, Giovanni Vigna |
| 2008 | SP | Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications. | Davide Balzarotti, Marco Cova, Viktoria Felmetsger, Nenad Jovanovic, Engin Kirda, Christopher Kruegel, Giovanni Vigna |
| 2008 | SP | ClearShot: Eavesdropping on Keyboard Input from Video. | Davide Balzarotti, Marco Cova, Giovanni Vigna |
| 2007 | ACSAC | Improving Signature Testing through Dynamic Data Flow Analysis. | Christopher Kruegel, Davide Balzarotti, William K. Robertson, Giovanni Vigna |
| 2007 | CCS | Multi-module vulnerability analysis of web-based applications. | Davide Balzarotti, Marco Cova, Viktoria Felmetsger, Giovanni Vigna |
| 2007 | RAID | Swaddler: An Approach for the Anomaly-Based Detection of State Violations in Web Applications. | Marco Cova, Davide Balzarotti, Viktoria Felmetsger, Giovanni Vigna |
| 2005 | SAC | LighTS: a lightweight, customizable tuple space supporting context-aware applications. | Gian Pietro Picco, Davide Balzarotti, Paolo Costa |
| 2004 | CCS | Testing network-based intrusion detection signatures using mutant exploits. | Giovanni Vigna, William K. Robertson, Davide Balzarotti |
| 2002 | Networking | Freeing Cooperation from Servers Tyranny. | Davide Balzarotti, Carlo Ghezzi, Mattia Monga |
| 2002 | SEKE | Supporting configuration management for virtual workgroups ini a peer-to-peer setting. | Davide Balzarotti, Carlo Ghezzi, Mattia Monga |