{"id":407,"date":"2022-07-20T10:23:23","date_gmt":"2022-07-20T10:23:23","guid":{"rendered":"https:\/\/www.dais.unive.it\/~calzavara\/?page_id=407"},"modified":"2022-07-20T10:24:08","modified_gmt":"2022-07-20T10:24:08","slug":"research","status":"publish","type":"page","link":"https:\/\/www.dais.unive.it\/~calzavara\/?page_id=407","title":{"rendered":"Research"},"content":{"rendered":"\n<p>My research broadly focuses on formal methods, software security and their intersection.\u00a0I have worked on many different topics after my PhD and I&#8217;m always eager to investigate new research areas. Below, you can find relevant research areas to which I&#8217;ve contributed in the last few years. Although not exhaustive, they are representative of what I&#8217;ve been recently working on.<\/p>\n\n\n\n<p><strong>Client-side web security:<\/strong> web security is a rich and varied research area. I&#8217;ve extensively worked on the analysis of client-side security mechanisms, i.e., web application defenses which are enforced at the browser side. I was one of the first researchers to investigate the security guarantees of Content Security Policy (CSP) and I enjoy measuring the effectiveness of deployed client-side defenses in the wild. More recently, I&#8217;ve developed an interest in client-side web security inconsistencies, i.e., inappropriate configurations of client-side defenses which may void their intended security guarantees.<\/p>\n\n\n\n<p><strong>Web sessions:<\/strong> virtually all the web applications that we use on a daily basis feature a password-protected private area. Upon login, a web session starts and users get authenticated access to the web application. Unfortunately, web sessions are fragile and can be attacked in many ways. I&#8217;ve analyzed the security of web sessions with respect to different threat models over the last few years and I&#8217;ve proposed defenses designed to improve over their shortcomings. Most of the proposed solutions have also been formally verified and proved correct.<\/p>\n\n\n\n<p><strong>Adversarial machine learning: <\/strong>machine learning is now phenomenally popular and found applications in many different settings, including security-critical applications. However, researchers identified several vulnerabilities in machine learning algorithms and models, which may lead to exploitation. Over the last few years, I&#8217;ve extensively studied evasion attacks against machine learning models, i.e., malicious perturbations of inputs leading the model into mispredicting. In my research, I&#8217;ve proposed techniques to improve and verify the security of tree-based models against evasion attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>My research broadly focuses on formal methods, software security and their intersection.\u00a0I have worked on many different topics after my PhD and I&#8217;m always eager to investigate new research areas. Below, you can find relevant research areas to which I&#8217;ve contributed in the last few years. Although not exhaustive, they are representative of what I&#8217;ve been recently working on. Client-side&#8230; <a href=\"https:\/\/www.dais.unive.it\/~calzavara\/?page_id=407\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-407","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=\/wp\/v2\/pages\/407"}],"collection":[{"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=407"}],"version-history":[{"count":2,"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=\/wp\/v2\/pages\/407\/revisions"}],"predecessor-version":[{"id":409,"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=\/wp\/v2\/pages\/407\/revisions\/409"}],"wp:attachment":[{"href":"https:\/\/www.dais.unive.it\/~calzavara\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=407"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}