Research area

Cybersecurity

Breaking and fixing real systems: security of protocols, networks and industrial devices, from formal verification to hands-on vulnerability research.

Autonomous and embedded systems are now part of factories, vehicles and critical infrastructures, where a single vulnerability can have physical consequences. Yet their security assessment is often less mature than that of traditional IT.

Research in the Cybersecurity area studies how to protect resources and information in these settings. On the formal side, we model and verify security protocols, such as multi-factor authentication schemes, to discover subtle flaws. On the practical side, we analyse real devices and networks together with industrial partners. This work has led to vulnerability disclosures such as CVE-2022-3203 and CVE-2023-40718.

The MADS lab hosts the Udine node of the Cybersecurity National Lab of CINI, the Italian National Inter-University Consortium for Informatics. Through the national lab we take part in training programmes for young talents, such as CyberChallenge.IT and CyberHighSchools. These programmes gave birth to MadrHacks, the ethical hacking team of the University of Udine.

Students in this area work with real hardware and real attack scenarios, in a lab environment and always following responsible disclosure practices.

Publications

  1. Automatic Verification of Security Properties in Containerized IoT Applications via Bigraphical Modeling

    Cristian Coppo, Francesco Longo, Giovanni Merlino, Antonio Puliafito, Marino Miculan

    Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026), CEUR Workshop Proceedings 4198 · CEUR-WS.org · 2026

    Conference paperSecurity PDF
    BibTeX
    @inproceedings{clmpm:itasec26,
      groups = {cybersecurity},
    	author       = {Coppo, Cristian and Longo, Francesco and Merlino, Giovanni and Puliafito, Antonio and Marino Miculan},
    	editor       = {Davide Maiorca and Pierangela Samarati},
    	title        = {Automatic Verification of Security Properties in Containerized {IoT} Applications via Bigraphical Modeling},
    	booktitle    = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026)},
    	location     = {Cagliari, Italy, February 09-13, 2026},
    	series       = {{CEUR} Workshop Proceedings},
    	volume       = 4198,
    	publisher    = {CEUR-WS.org},
    	year         = 2026,
    	pdf          = {https://ceur-ws.org/Vol-4198/paper59.pdf},
    	html         = {https://ceur-ws.org/Vol-4198}
    }
  2. Experimental Evaluation of Lightweight Encryption Algorithms on 16-bit Microcontrollers

    Marino Miculan, Matteo Paier, Jacopo Plozner

    Proceedings of the 23rd International Conference on Security and Cryptography - SECRYPT · SciTePress · 2026

    Conference paperSecurityDOI PDF
    BibTeX
    @inproceedings{mpp:secrypt26,
      groups = {cybersecurity},
      author       = {Marino Miculan and Matteo Paier and Jacopo Plozner},
      title        = {Experimental Evaluation of Lightweight Encryption Algorithms on 16-bit Microcontrollers},
      booktitle    = {Proceedings of the 23rd International Conference on Security and Cryptography - SECRYPT},
      year         = {2026},
      publisher    = {SciTePress},
      organization = {INSTICC},
      doi          = {10.5220/0015189200004103},
      html         = {https://doi.org/10.5220/0015189200004103},
      Pdf          = {https://marino.miculan.org/assets/pdf/2026-SECRYPT.pdf},
    }
  3. Formal modelling and verifying eIDAS multi-factor authentication with interface-based threat analysis

    Matteo Paier, Roberto L. G. Van Eeden, Marino Miculan

    Software and Systems Modeling · 2026

    Journal articleSecurityDOI PDF
    BibTeX
    @Article{PVM:sosym26,
      groups = {cybersecurity},
      author    = {Paier, Matteo and Van Eeden, Roberto L. G. and Miculan, Marino},
      title     = {Formal modelling and verifying {eIDAS} multi-factor authentication with interface-based threat analysis},
      journal   = {Software and Systems Modeling},
      year      = {2026},
      doi       = {10.1007/s10270-026-01375-9},
      html      = {https://doi.org/10.1007/s10270-026-01375-9},
      pdf = "https://link.springer.com/content/pdf/10.1007/s10270-026-01375-9.pdf",
      selected = true,
    }
  4. Policy Automata for Stateful Authorization

    Massimiliano Baldo, Matteo Paier, Marino Miculan

    Proceedings of the 27th Italian Conference on Theoretical Computer Science (ICTCS 2026), CEUR Workshop Proceedings 4269 · CEUR-WS.org · 2026

    Conference paperSecurity PDF
    BibTeX
    @inproceedings{bpm:ictcs26,
      groups = {cybersecurity},
    	author       = {Baldo, Massimiliano and Paier, Matteo and Miculan, Marino},
    	title        = {Policy Automata for Stateful Authorization},
    	booktitle    = {Proceedings of the 27th Italian Conference on Theoretical Computer Science (ICTCS 2026)},
    	location     = {Udine, Italy, September 07-09, 2026},
    	series       = {{CEUR} Workshop Proceedings},
    	volume       = 4269,
    	publisher    = {CEUR-WS.org},
    	year         = 2026,
    	pdf          = {https://ceur-ws.org/Vol-4269/paper45.pdf},
    	html         = {https://ceur-ws.org/Vol-4269}
    }
  5. SA-SOINN: A Self-Adaptive Neural Network for Continuous Intrusion Detection in Dynamic Environments

    Dennis Glenn Ejeh, Gian Luca Foresti, Marino Miculan, Axel De Nardin

    Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026), CEUR Workshop Proceedings 4198 · CEUR-WS.org · 2026

    Conference paperSecurity PDF
    BibTeX
    @inproceedings{efmd:itasec26,
      groups = {cybersecurity},
    	author       = {Ejeh, Dennis Glenn and Foresti, Gian Luca and Marino Miculan and De Nardin, Axel},
    	editor       = {Davide Maiorca and Pierangela Samarati},
    	title        = {{SA-SOINN}: A Self-Adaptive Neural Network for Continuous Intrusion Detection in Dynamic Environments},
    	booktitle    = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026)},
    	location     = {Cagliari, Italy, February 09-13, 2026},
    	series       = {{CEUR} Workshop Proceedings},
    	volume       = 4198,
    	publisher    = {CEUR-WS.org},
    	year         = 2026,
    	pdf          = {https://ceur-ws.org/Vol-4198/paper2.pdf},
    	html         = {https://ceur-ws.org/Vol-4198}
    }
  6. Security Assessment of Private Package Repositories: An Experience on Acc-Py at CERN

    Michele Lizzit, Francesco Pinzauti, Marino Miculan, Vincenzo Riccio

    Journal of Software: Evolution and Process 38(8), pp. e70159 · 2026

    Journal articleSecurityDOI PDF
    BibTeX
    @Article{lpmr:smr26,
      groups = {cybersecurity},
      author    = {Lizzit, Michele and Pinzauti, Francesco and Miculan, Marino and Riccio, Vincenzo},
      title     = {Security Assessment of Private Package Repositories: An Experience on {Acc-Py} at {CERN}},
      journal   = {Journal of Software: Evolution and Process},
      year      = {2026},
      volume    = {38},
      number    = {8},
      pages     = {e70159},
      doi       = {10.1002/smr.70159},
      html      = {https://doi.org/10.1002/smr.70159},
      pdf       = {https://onlinelibrary.wiley.com/doi/pdf/10.1002/smr.70159},
      issn      = {2047-7473},
    }
  7. Strobilus: Enriching Cedar with Stateful Policies

    Massimiliano Baldo, Pietro Di Gianantonio, Matteo Paier, Marino Miculan

    Proceedings of the 31st ACM Symposium on Access Control Models and Technologies (SACMAT '26), pp. 205–216 · Association for Computing Machinery · 2026

    Conference paperSecurityDOI PDF Code
    BibTeX
    @inproceedings{bdpm:sacmat26,
      groups = {cybersecurity},
    	author       = {Baldo, Massimiliano and Di Gianantonio, Pietro and Paier, Matteo and Miculan, Marino},
    	title        = {Strobilus: Enriching {Cedar} with Stateful Policies},
    	booktitle    = {Proceedings of the 31st {ACM} Symposium on Access Control Models and Technologies (SACMAT '26)},
    	location     = {Waterloo, ON, Canada, July 08-10, 2026},
    	publisher    = {Association for Computing Machinery},
    	year         = 2026,
    	month        = jul,
    	pages        = {205--216},
    	doi          = {10.1145/3750555.3811892},
    	html         = {https://doi.org/10.1145/3750555.3811892},
    	pdf          = {https://marino.miculan.org/assets/pdf/2026-SACMAT.pdf},
    	code         = {https://github.com/strobilus-lang/strobilus-tinytodo-example},
    	isbn         = {979-8-4007-2107-6},
      selected     = true,
    }
  8. OWSM: Empowering Rego for Stateful Access Control

    Massimiliano Baldo, Fabio Ionut Ion, Marino Miculan, Matteo Paier, Vincenzo Riccio

    Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025), CEUR Workshop Proceedings 3962 · CEUR-WS.org · 2025

    Conference paperSecurity PDF
    BibTeX
    @inproceedings{bimpr:itasec25,
      groups = {cybersecurity},
    	author       = {Massimiliano Baldo and Ion, Fabio Ionut and Marino Miculan and Matteo Paier and Vincenzo Riccio},
    	editor       = {Gabriele Costa and Rebecca Montanari and Michele Carminati and Giada Sciarretta},
    	title        = {OWSM: Empowering Rego for Stateful Access Control},
    	booktitle    = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025)},
    	location     = {Bologna, Italy, February 3-8, 2025},
    	series       = {{CEUR} Workshop Proceedings},
    	volume       = 3962,
      publisher    = {CEUR-WS.org},
    	year         = 2025,
    	pdf          = {https://ceur-ws.org/Vol-3962/paper49.pdf},
    	html    = {https://ceur-ws.org/Vol-3962}
    }
  9. Real-Time Anomaly Detection in Docker Containers: A Continuous Learning Approach Using SF-SOINN

    Dennis Glenn Ejeh, Gian Luca Foresti, Marino Miculan, Axel De Nardin

    Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025), CEUR Workshop Proceedings 3962 · CEUR-WS.org · 2025

    Conference paperSecurity PDF
    BibTeX
    @inproceedings{gfmd:itasec25,
      groups = {cybersecurity},
    	author       = {Ejeh, Dennis Glenn and Foresti, Gian Luca and Marino Miculan and De Nardin, Axel},
    	editor       = {Gabriele Costa and Rebecca Montanari and Michele Carminati and Giada Sciarretta},
    	title        = {Real-Time Anomaly Detection in Docker Containers: A Continuous Learning Approach Using {SF-SOINN}},
    	booktitle    = {Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2025)},
    	location     = {Bologna, Italy, February 3-8, 2025},
    	series       = {{CEUR} Workshop Proceedings},
    	volume       = 3962,
    	publisher    = {CEUR-WS.org},
    	year         = 2025,
    	pdf          = {https://ceur-ws.org/Vol-3962/paper45.pdf},
    	html    = {https://ceur-ws.org/Vol-3962}
    }
  10. A Formal Analysis of CIE Level 2 Multi-Factor Authentication via SMS OTP

    Roberto Van Eeden, Matteo Paier, Marino Miculan

    Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT, pp. 483-491 · SciTePress · 2024

    Conference paperSecurityDOI
    BibTeX
    @inproceedings{vepm:secrypt24,
      groups = {cybersecurity},
    author={Van Eeden, Roberto and Matteo Paier and Marino Miculan},
    title={A Formal Analysis of {CIE} Level 2 Multi-Factor Authentication via {SMS OTP}},
    booktitle={Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT},
    year={2024},
    pages={483-491},
    publisher={SciTePress},
    organization={INSTICC},
    doi={10.5220/0012768300003767},
    html = {https://doi.org/10.5220/0012768300003767},
    isbn={978-989-758-709-2},
    issn={2184-7711},
    }

All publications in this area

People

Marino Miculan

Full Professor · Head & founder

Security of protocols and industrial systems, formal models of concurrency, bigraphs

Ivan Scagnetto

Associate Professor

Formal methods, proof assistants, autonomous vehicles

Matteo Paier

Research fellow · PhD (cycle XXXVIII)

Network discovery, authentication protocols

Roberto Van Eeden

MSc student, AI & Cybersecurity

Xhulia Palaj

MSc student, AI & Cybersecurity