| 2026 | DBSEC | A Novel Approach to SBOM Extraction from HTTP Messages in Identity Management Security Testing. | Andrea Bisegna, Laura Cristiano, Pietro De Matteis, Eleonora Marchesini, Luca Piras, Silvio Ranise |
| 2025 | DBSEC | Secure and Reliable Digital Wallets: A Threat Model for Secure Storage in eIDAS 2.0. | Zahra Ebadi Ansaroudi, Amir Sharif, Giada Sciarretta, Francesco Antonio Marino, Silvio Ranise |
| 2025 | RE | A First Appraisal of NIS2 and CRA Compliance Leveraging Open Source Tools. | Giovanni Corti, Gianluca Sassetti, Amir Sharif, Serena Elisa Ponta, Matteo Rizzi, Pietro De Matteis, Luca Piras, Roberto Carbone, Silvio Ranise |
| 2025 | SACMAT | Relying on Trust to Balance Protection and Performance in Cryptographic Access Control. | Simone Brunello, Stefano Berlato, Roberto Carbone, Adam J. Lee, Silvio Ranise |
| 2025 | SECRYPT | Enhancing National Digital Identity Systems: A Framework for Institutional and Technical Harm Prevention Inspired by Microsoft's Harms Modeling. | Giovanni Corti, Gianluca Sassetti, Amir Sharif, Roberto Carbone, Silvio Ranise |
| 2024 | CRiSIS | Modeling and Assessing Coercion Threats in Electronic Voting. | Riccardo Longo, Majid Mollaeefar, Umberto Morelli, Chiara Spadafora, Alessandro Tomasi, Silvio Ranise |
| 2024 | CRiSIS | Protecting Digital Identity Wallet: A Threat Model in the Age of eIDAS 2.0. | Amir Sharif, Zahra Ebadi Ansaroudi, Giada Sciarretta, Daniela Phn, Majid Mollaeefar, Wolfgang Hommel, Silvio Ranise |
| 2024 | ICIN | Multi-Objective Microservice Orchestration: Balancing Security and Performance in CCAM. | Stefano Berlato, Silvio Cretti, Domenico Siracusa, Silvio Ranise |
| 2024 | SECRYPT | Automating Compliance for Improving TLS Security Postures: An Assessment of Public Administration Endpoints. | Riccardo Germenia, Salvatore Manfredi, Matteo Rizzi, Giada Sciarretta, Alessandro Tomasi, Silvio Ranise |
| 2023 | DBSEC | Control is Nothing Without Trust a First Look into Digital Identity Wallet Trends. | Zahra Ebadi Ansaroudi, Roberto Carbone, Giada Sciarretta, Silvio Ranise |
| 2023 | DBSEC | Assurance, Consent and Access Control for Privacy-Aware OIDC Deployments. | Gianluca Sassetti, Amir Sharif, Giada Sciarretta, Roberto Carbone, Silvio Ranise |
| 2023 | SECRYPT | A First Appraisal of Cryptographic Mechanisms for the Selective Disclosure of Verifiable Credentials. | Andrea Flamini, Silvio Ranise, Giada Sciarretta, Mario Scuro, Amir Sharif, Alessandro Tomasi |
| 2022 | DBSEC | End-to-End Protection of IoT Communications Through Cryptographic Enforcement of Access Control Policies. | Stefano Berlato, Umberto Morelli, Roberto Carbone, Silvio Ranise |
| 2022 | SACMAT | Demo: TLSAssistant v2: A Modular and Extensible Framework for Securing TLS. | Matteo Rizzi, Salvatore Manfredi, Giada Sciarretta, Silvio Ranise |
| 2021 | DBSEC | Automated Risk Assessment and What-if Analysis of OpenID Connect and OAuth 2.0 Deployments. | Salimeh Dashti, Amir Sharif, Roberto Carbone, Silvio Ranise |
| 2021 | SECRYPT | Cryptographic Enforcement of Access Control Policies in the Cloud: Implementation and Experimental Assessment. | Stefano Berlato, Roberto Carbone, Silvio Ranise |
| 2021 | SECRYPT | Can Data Subject Perception of Privacy Risks Be Useful in a Data Protection Impact Assessment? | Salimeh Dashti, Anderson Santana de Oliveira, Caelin Kaplan, Manuel Dalcastagn, Silvio Ranise |
| 2021 | SECRYPT | A Framework for Security and Risk Analysis of Enrollment Procedures: Application to Fully-remote Solutions based on eDocuments. | Marco Pernpruner, Giada Sciarretta, Silvio Ranise |
| 2020 | CCS | Exploring Architectures for Cryptographic Access Control Enforcement in the Cloud for Fun and Optimization. | Stefano Berlato, Roberto Carbone, Adam J. Lee, Silvio Ranise |
| 2020 | ESORICS | Micro-Id-Gym: A Flexible Tool for Pentesting Identity Management Protocols in the Wild and in the Laboratory. | Andrea Bisegna, Roberto Carbone, Giulio Pellizzari, Silvio Ranise |
| 2020 | ESORICS | Verifiable Contracting - A Use Case for Onboarding and Contract Offering in Financial Services with eIDAS and Verifiable Credentials. | Srgio Manuel Nbrega Gonalves, Alessandro Tomasi, Andrea Bisegna, Giulio Pellizzari, Silvio Ranise |
| 2020 | ESORICS | Automated and Secure Integration of the OpenID Connect iGov Profile in Mobile Native Applications. | Amir Sharif, Roberto Carbone, Giada Sciarretta, Silvio Ranise |
| 2020 | SACMAT | Deploying Access Control Enforcement for IoT in the Cloud-Edge Continuum with the help of the CAP Theorem. | Tahir Ahmad, Umberto Morelli, Silvio Ranise |
| 2019 | DBSEC | Lost in TLS? No More! Assisted Deployment of Secure TLS Configurations. | Salvatore Manfredi, Silvio Ranise, Giada Sciarretta |
| 2019 | ESORICS | An Open and Flexible CyberSecurity Training Laboratory in IT/OT Infrastructures. | Umberto Morelli, Lorenzo Nicolodi, Silvio Ranise |
| 2019 | ESORICS | MuFASA: A Tool for High-level Specification and Analysis of Multi-factor Authentication Protocols. | Federico Sinigaglia, Roberto Carbone, Gabriele Costa, Silvio Ranise |
| 2019 | SERVICES | MQTTSA: A Tool for Automatically Assisting the Secure Deployments of MQTT Brokers. | Andrea Palmieri, Paolo Prem, Silvio Ranise, Umberto Morelli, Tahir Ahmad |
| 2018 | WiMob | SPLIT: A Secure and Scalable RPL routing protocol for Internet of Things. | Mauro Conti, Pallavi Kaliyar, Md Masoom Rabbani, Silvio Ranise |
| 2018 | SACMAT | A Lazy Approach to Access Control as a Service (ACaaS) for IoT: An AWS Case Study. | Tahir Ahmad, Umberto Morelli, Silvio Ranise, Nicola Zannone |
| 2018 | SACMAT | Solving Multi-Objective Workflow Satisfiability Problems with Optimization Modulo Theories Techniques. | Clara Bertolissi, Daniel Ricardo dos Santos, Silvio Ranise |
| 2017 | SACMAT | Security Analysis and Legal Compliance Checking for the Design of Privacy-friendly Information Systems. | Paolo Guarda, Silvio Ranise, Hari Siswantoro |
| 2017 | SAFECOMP | Automated Legal Compliance Checking by Security Policy Analysis. | Silvio Ranise, Hari Siswantoro |
| 2017 | SEC | Assisted Authoring, Analysis and Enforcement of Access Control Policies in the Cloud. | Umberto Morelli, Silvio Ranise |
| 2017 | SEFM | On Run-Time Enforcement of Authorization Constraints in Security-Sensitive Workflows. | Daniel Ricardo dos Santos, Silvio Ranise |
| 2016 | SACMAT | Modular Synthesis of Enforcement Mechanisms for the Workflow Satisfiability Problem: Scalability and Reusability. | Daniel Ricardo dos Santos, Serena Elisa Ponta, Silvio Ranise |
| 2016 | SECRYPT | Security of Mobile Single Sign-On: A Rational Reconstruction of Facebook Login Solution. | Giada Sciarretta, Alessandro Armando, Roberto Carbone, Silvio Ranise |
| 2016 | TACAS | Cerberus: Automated Synthesis of Enforcement Mechanisms for Security-Sensitive Business Processes. | Luca Compagna, Daniel Ricardo dos Santos, Serena Elisa Ponta, Silvio Ranise |
| 2015 | CCS | Mobile App Security Assessment with the MAVeriC Dynamic Analysis Module. | Alessandro Armando, Gianluca Bocci, Gabriele Costa, Rocco Mammoliti, Alessio Merlo, Silvio Ranise, Riccardo Traverso, Andrea Valenza |
| 2015 | CCS | Automated Synthesis of Run-time Monitors to Enforce Authorization Policies in Business Processes. | Clara Bertolissi, Daniel Ricardo dos Santos, Silvio Ranise |
| 2015 | DBSEC | Assisting the Deployment of Security-Sensitive Workflows by Finding Execution Scenarios. | Daniel Ricardo dos Santos, Silvio Ranise, Luca Compagna, Serena Elisa Ponta |
| 2015 | SAC | Automated analysis of RBAC policies with temporal constraints and static role hierarchies. | Silvio Ranise, Anh Tuan Truong, Luca Vigan |
| 2015 | SACMAT | A SMT-based Tool for the Analysis and Enforcement of NATO Content-based Protection and Release Policies. | Alessandro Armando, Silvio Ranise, Riccardo Traverso, Konrad S. Wrona |
| 2015 | SECRYPT | Modeling Authorization Policies for Web Services in Presence of Transitive Dependencies. | Worachet Uttha, Clara Bertolissi, Silvio Ranise |
| 2014 | DBSEC | Incremental Analysis of Evolving Administrative Role Based Access Control Policies. | Silvio Ranise, Anh Tuan Truong |
| 2014 | SACMAT | Attribute based access control for APIs in spring security. | Alessandro Armando, Roberto Carbone, Eyasu Getahun Chekole, Silvio Ranise |
| 2014 | SACMAT | Scalable and precise automated analysis of administrative temporal role-based access control. | Silvio Ranise, Anh Tuan Truong, Alessandro Armando |
| 2013 | SACMAT | Content-based information protection and release in NATO operations. | Alessandro Armando, Matteo Grasso, Sander Oudkerk, Silvio Ranise, Konrad S. Wrona |
| 2012 | CADE | Reachability Modulo Theory Library. | Francesco Alberti, Roberto Bruttomesso, Silvio Ghilardi, Silvio Ranise, Natasha Sharygina |
| 2012 | CADE | From Strong Amalgamability to Modularity of Quantifier-Free Interpolation. | Roberto Bruttomesso, Silvio Ghilardi, Silvio Ranise |
| 2012 | CAV | SAFARI: SMT-Based Abstraction for Arrays with Interpolants. | Francesco Alberti, Roberto Bruttomesso, Silvio Ghilardi, Silvio Ranise, Natasha Sharygina |
| 2012 | DBSEC | Automated and Efficient Analysis of Role-Based Access Control with Attributes. | Alessandro Armando, Silvio Ranise |
| 2012 | LPAR | Lazy Abstraction with Interpolants for Arrays. | Francesco Alberti, Roberto Bruttomesso, Silvio Ghilardi, Silvio Ranise, Natasha Sharygina |
| 2012 | NSS | On the Automated Analysis of Safety in Usage Control: A New Decidability Result. | Silvio Ranise, Alessandro Armando |
| 2011 | CADE | ASASP: Automated Symbolic Analysis of Security Policies. | Francesco Alberti, Alessandro Armando, Silvio Ranise |
| 2011 | CCS | Efficient symbolic automated analysis of administrative attribute-based RBAC-policies. | Francesco Alberti, Alessandro Armando, Silvio Ranise |
| 2010 | CADE | MCMT in the Land of Parametrized Timed Automata. | Alessandro Carioni, Silvio Ghilardi, Silvio Ranise |
| 2010 | CADE | MCMT: A Model Checker Modulo Theories. | Silvio Ghilardi, Silvio Ranise |
| 2010 | SYNASC | WSSMT: Towards the Automated Analysis of Security-Sensitive Services and Applications. | Michele Barletta, Alberto Calvi, Silvio Ranise, Luca Vigan, Luca Zanetti |
| 2010 | SYNASC | Automated Validation of Security-Sensitive Web Services Specified in BPEL and RBAC. | Alberto Calvi, Silvio Ranise, Luca Vigan |
| 2009 | TABLEAUX | Goal-Directed Invariant Synthesis for Model Checking Modulo Theories. | Silvio Ghilardi, Silvio Ranise |
| 2008 | CADE | Towards SMT Model Checking of Array-Based Systems. | Silvio Ghilardi, Enrica Nicolini, Silvio Ranise, Daniele Zucchelli |
| 2007 | CADE | Combination Methods for Satisfiability and Model-Checking of Infinite-State Systems. | Silvio Ghilardi, Enrica Nicolini, Silvio Ranise, Daniele Zucchelli |
| 2007 | ICTAC | Building Extended Canonizers by Graph-Based Deduction. | Silvio Ranise, Christelle Scharff |
| 2006 | CADE | Decidability and Undecidability Results for Nelson-Oppen and Rewrite-Based Decision Procedures. | Maria Paola Bonacina, Silvio Ghilardi, Enrica Nicolini, Silvio Ranise, Daniele Zucchelli |
| 2006 | ICTAC | Decision Procedures for the Formal Analysis of Software. | David Dharbe, Pascal Fontaine, Silvio Ranise, Christophe Ringeissen |
| 2006 | JELIA | Deciding Extensions of the Theory of Arrays by Integrating Decision Procedures and Instantiation Strategies. | Silvio Ghilardi, Enrica Nicolini, Silvio Ranise, Daniele Zucchelli |
| 2006 | LPAR | Automatic Combinability of Rewriting-Based Satisfiability Procedures. | Hlne Kirchner, Silvio Ranise, Christophe Ringeissen, Duc-Khanh Tran |
| 2006 | SEFM | A Theory of Singly-Linked Lists and its Extensible Decision Procedure. | Silvio Ranise, Calogero G. Zarba |
| 2005 | CAV | Efficient Satisfiability Modulo Theories via Delayed Theory Combination. | Marco Bozzano, Roberto Bruttomesso, Alessandro Cimatti, Tommi A. Junttila, Silvio Ranise, Peter van Rossum, Roberto Sebastiani |
| 2005 | ICTAC | On Superposition-Based Satisfiability Procedures and Their Combination. | Hlne Kirchner, Silvio Ranise, Christophe Ringeissen, Duc-Khanh Tran |
| 2004 | AISC | Abstraction-Driven Verification of Array Programs. | David Dharbe, Abdessamad Imine, Silvio Ranise |
| 2004 | ICTAC | Nelson-Oppen, Shostak and the Extended Canonizer: A Family Picture with a Newborn. | Silvio Ranise, Christophe Ringeissen, Duc-Khanh Tran |
| 2004 | LPAR | Combining Lists with Non-stably Infinite Theories. | Pascal Fontaine, Silvio Ranise, Calogero G. Zarba |
| 2003 | SEFM | Light-Weight Theorem Proving for Debugging and Verifying Units of Code. | David Dharbe, Silvio Ranise |
| 2002 | AISC | Combining Generic and Domain Specific Reasoning by Using Contexts. | Silvio Ranise |
| 2001 | CADE | System Description: RDL : Rewrite and Decision Procedure Laboratory. | Alessandro Armando, Luca Compagna, Silvio Ranise |
| 2001 | CP | The Phase Transition of the Linear Inequalities Problem. | Alessandro Armando, Felice Peccia, Silvio Ranise |
| 2001 | CSL | Uniform Derivation of Decision Procedures by Superposition. | Alessandro Armando, Silvio Ranise, Michal Rusinowitch |
| 1998 | AIMSA | Constraint Solving in Logic Programming and in Automated Deduction: A Comparison. | Alessandro Armando, Erica Melis, Silvio Ranise |
| 1998 | AISC | From Integrated Reasoning Specialists to "Plug-and-Play" Reasoning Components. | Alessandro Armando, Silvio Ranise |