Phd Activity of DAVIDE CHIARELLA
Last updated 13 Novembre 2008
by Davide Chiarella.
Leave of Absence
PhD Courses and Credits
-
6-17/03/2006. BISS 2006: Bertinoro International Spring School, Bertinoro (BO), Italy
- Access Control Systems for Database Systems (ACS)
responsabile: Prof. Elisa Bertino, CS & ECE Department, Purdue University, USA
- Calculi and Languages for Distributed Mobile Computation (CLD)
responsabile: Prof. Rocco De Nicola, Dipartimento di Sistemi e Informatica,Università di Firenze, Italy
- Implicit Computational Complexity (ICC)
responsabile: Prof. Simone Martini, Dipartimento di Scienze dell'Informazione, Università di Bologna, Italy
esame: SOSTENUTO
- Data Mining (DM)
responsabile: Prof. Rosa Meo, Dipartimento di Informatica
Università di Torino, Italy
esame: SOSTENUTO
-
Laurea Specialistica Courses at DISI (Dipartimento di Informatica e Scienze dell'Informazione), Univ. di Genova.
- Sistemi Distribuiti Peer to peer - II semestre A.A. 2005/2006
responsabile: Prof. Giovanni Chiola, Dipartimento di Informatica,Università di Genova, Italy
esame: SOSTENUTO
-
Scuola di Dottorato in Scienze e tecnologie per la società dell’informazione, Univ. di Genova.
- Tecniche di Trasformazione di Spazi Vettoriali Multidimensionali per Applicazioni Statistiche (2007)
Responsabile: Ing. Gabriele Moser, Dept. of Biophysical and Electronic Eng. (DIBE), Università di Genova, Italy
esame: SOSTENUTO
- Machine Learning (2007)
Responsabile: Ing. Marco Muselli, Istituto di Elettronica e di Ingegneria dell'Informazione e delle Telecomunicazioni (I.E.I.I.T.), Sezione di Genova, Italy.
esame: SOSTENUTO
Teaching Assistant Activity
- 2006 - Sistemi Distribuiti P2P: seminario su BitTorrent
- 2007 - I attended upon a thesys titled "Sistemi di rilevamento intrusioni network based: analisi su Snort"
- 2008
- Teaching Assistant in Sicurezza (a.a. 2007/2008) - 4 hours of lessons about Malwares.
- Sistemi Operativi 2 (a.a. 2007/08): seminar on DNS and samba server.
- Teaching Assistant in Sicurezza, Master Universitario Integrato di II livello SIIT – Tecnologie Avanzate per Sistemi Intelligenti Integrati, June 2008 - 8 hours of lessons.
Research Activity
- Supervisor:
Giovanni Chiola
- Research interests:
Worm Detection, Intrusion Detection System, Network Security, Statistical Data Mining, Security in Wireless Network
Pubblications
- Maurizio Aiello, David Avanzini, Davide Chiarella, Gianluca Papaleo. A Tool for Complete Log Mail Analysis: LMA. TNC 2006,part of session Security on the Backbone: Detecting and Responding to Attacks.
- Maurizio Aiello, David Avanzini, Davide Chiarella, Gianluca Papaleo.Worm Detection Using E-mail Data Mining. PRISE 2006, Primo Workshop Italiano su PRIvacy e SEcurity, pp 18-21.
- Maurizio Aiello, David Avanzini, Davide Chiarella, Gianluca Papaleo.SMTP sniffing for intrusion detection purposes. PRISE 2007, Secondo Workshop Italiano su PRIvacy e SEcurity.
- Maurizio Aiello, Davide Chiarella, Gianluca Papaleo. Statistical anomaly detection on real e-mail traffic. CISIS 2008, International Workshop on Computational Intelligence in Security for Information Systems, ACS53 Springer 2008.
- Maurizio Aiello, Davide Chiarella, Alessio Merlo, Gianluca Papaleo. Improvements in physical intrusion detection on LAN. PRISE 2008, Terzo Workshop Italiano su PRIvacy e Security.
- Maurizio Aiello, Davide Chiarella, Claudio Martini, Alfonso Quarati.Introduzione del mail-gateway ESDA nella rete ARiGe. Rapporto Tecnico IEIIT/GE/01/08/ Giugno 2008.
Conferences, Seminars, Short Visits
- 20-21/06/2006: Roma (Italy). Infosecurity 2006 - La fiera della sicurezza informatica - Workshop Roma
- 21/06/2006: Roma (Italy). PRISE 2006 - Primo Workshop Italiano su PRIvacy e SEcurity.
- 17/10/2006: Pisa (Italy). Net&SystemSecurity 2006 - IIT,CNR Pisa.
- 16/11/2006: Bologna (Italy). IEIIT Day 2006 - Facoltà di Ingegneria, Bologna.
- 5-6/06/2007: Roma (Italy). Infosecurity 2007 - La fiera della sicurezza informatica - Workshop Roma
- 06/06/2007: Roma (Italy). PRISE 2007: secondo workshop italiano su PRIvacy e SEcurity.
- Presentation at PRISE 2007: SMTP sniffing for intrusion detection purposes.
- 9/11/2007: Pisa (Italy). IEIIT Day 2007 - IEIIT, Sede di Pisa.
- 23-24/10/2008: Genoa (Italy). CISIS 2008, International Workshop on Computational Intelligence in Security for Information Systems.
- Presentation at CISIS 2008: Statistical anomaly detection on real e-mail traffic.
Annual Reports
- 2006
During this first year of studies I focused my attention on intrusion detection techniques and in particular on mail server. In the first part of the year I improved and released a new stand alone log analyzer module, focused on the first part of my graduate work, which now is hosted by sourceforge. In the second part of the year I made a deeper analysis on the data and results I had and I published with my work mates two papers about my research studies. The first one focuses its attention on LMA, while the second one is about the whole work done, wormpoacher. For more info see my Thesis proposal
- 2007
During this second year of studies I made a deep and accurate analysis of SMTP (Simple Mail Transport Protocol) traffic of a quite big
network ( eleven class C networks) activity of the last three years (2004-2007). From the data collected I extracted some features to use in the development of the Worm Detection System: apropos of it the Worm Poucher Daemon (WPD) structure and the panworm engine detection system are
at a good development stage. Moreover during this year a new idea originated: to extend the seven layer quantity statistical approach (in fact
we can say that we analyze the e-mails sent number, an ISO-OSI seven layer quantity) to other protocols. Regarding my publication activity, I published a paper about my SMTP researches titled SMTP Sniffing for Intrusion Detection Purposes. Here you can find more details about my thesys progress
- 2008
During this third year of studies I focused my attention on writing down the results of the previous analysis and to accomplish some of the goals stated in the previous thesis progress report. The system coding progress is at a good development stage, however the completion of WPD with panworm engine took longer than stated: moreover new aspects, based on a brand new article, convinced me to redesign in future some part of WPD, developing and coding a new module. On the other hand I concentrated my efforts to study malwares in depth and the always changing state of art of anomaly detection. All my activities produced two articles and an internal report. Anyway the main and most important goal of the thesis is confirmed. Here you can find more details about my thesys extension request.
|
|