I am an Assistant Professor in the Services and CyberSecurity group of the University of Twente.

Previously, I was a Postdoctoral Researcher in the Computer Science Department at UC Santa Barbara, working at the SecLab, and I obtained a Ph.D. cum laude in Computer Science and Engineering at Politecnico di Milano in Italy. During my Ph.D., I also took part in two research exchanges, working as a visiting researcher at UCSB and at the School of Computer Science of the University of Sydney.

My research focuses on aspects of computer security traditionally known as systems security. In particular, my main research interests lie in the security of the software that people use in their daily tasks, and revolve around analyzing such software for multiple security purposes, such as malware detection, identification of privacy disclosures, and vulnerability discovery. For example, I have worked on analysis and defense mechanisms against advanced threats such as the infamous ransomware families, on the detection of obfuscated privacy leaks in Android apps, and on the design of novel program analysis techniques to identify and patch vulnerabilities in embedded firmware. 

I strongly believe in open, collaborative science, where researchers can easily and quickly access to previous research outcomes to reproduce and analyze results obtained by others. 

I also love Capture The Flag (CTF) competitions, which I currently play with Shellphish (usually ending up in Vegas to play DEFCON Finals), and I co-organized several editions of the PoliCTF and iCTF.


Zangrandi, L. M., Ede, T. V., Booij, T., Sciancalepore, S., Allodi, L. , & Continella, A. (2022). Stepping out of the MUD: Contextual threat information for IoT devices with manufacturer-provided behaviour profiles. In Proceedings of the Annual Computer Security Applications Conference (ACSAC)
Meijer, M., Petrucci, G. T., Schotsman, M., Morgese, L., Ede, T. V. , Continella, A., Gankhuyag, G., Allodi, L., & Sciancalepore, S. (2022). Federated Lab (FedLab): An Open-source Distributed Platform for Internet of Things (IoT) Research and Experimentation. In IEEE World Forum on IoT (WF-IoT)
Ede, T. V., Khasuntsev, N. , Steen, B. , & Continella, A. (2022). Detecting Anomalous Misconfigurations in AWS Identity and Access Management Policies. In CCSW 2022 - Proceedings of the 2022 Cloud Computing Security Workshop, co-located with CCS 2022 (pp. 63-74) https://doi.org/10.1145/3560810.3564264
Khairi, A. E., Caselli, M., Knierim, C. , Peter, A. , & Continella, A. (2022). Contextualizing System Calls in Containers for Anomaly-Based Intrusion Detection. In CCSW 2022 - Proceedings of the 2022 Cloud Computing Security Workshop, co-located with CCS 2022 (pp. 9-21) https://doi.org/10.1145/3560810.3564266
Galloro, N., Polino, M., Carminati, M. , Continella, A., & Zanero, S. (2022). A Systematical and longitudinal study of evasive behaviors in windows malware. Computers & Security, 113, [102550]. https://doi.org/10.1016/j.cose.2021.102550
van Ede, T., Aghakhani, H., Spahn, N. , Bortolameotti, R., Cova, M. , Continella, A. , van Steen, M. , Peter, A., Kruegel, C., & Vigna, G. (2022). DEEPCASE: Semi-Supervised Contextual Analysis of Security Events. In 2022 IEEE Symposium on Security and Privacy (SP) (pp. 522-539). (Proceedings - IEEE Symposium on Security and Privacy; Vol. 2022-May). IEEE. https://doi.org/10.1109/SP46214.2022.9833671
Melotti, D., Rossi-Bellom, M. , & Continella, A. (2021). Reversing and Fuzzing the Google Titan M Chip. In ROOTS 2021 - Proceedings of the 5th Reversing and Offensive-Oriented Trends Symposium 2021, co-Located with DEEPSEC (ACM International Conference Proceeding Series). Association for Computing Machinery (ACM). https://doi.org/10.1145/3503921.3503922
Ruaro, N., Zeng, K., Dresel, L., Polino, M., Bao, T. , Continella, A., Zanero, S., Kruegel, C., & Vigna, G. (2021). SyML: Guiding symbolic execution toward vulnerable states through pattern learning. In Proceedings of 2021 24th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2021), October 6-8, 2021, Donostia/San Sebastiàn, Spain (pp. 456-468). (ACM International Conference Proceeding Series). Association for Computing Machinery (ACM). https://doi.org/10.1145/3471621.3471865
Garg, C., Machiry, A. , Continella, A., Kruegel, C., & Vigna, G. (2021). Toward a Secure Crowdsourced Location Tracking System. In 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) (pp. 311-322). [3467821] https://doi.org/10.1145/3448300.3467821
Meng, D., Guerriero, M., Machiry, A., Aghakhani, H., Bose, P. , Continella, A., Kruegel, C., & Vigna, G. (2021). Bran: Reduce Vulnerability Search Space in Large Open Source Repositories by Learning Bug Symptoms. In ACM ASIA Conference on Computer and Communications Security (ASIACCS) (pp. 731-743) https://doi.org/10.1145/3433210.3453115

Vakken Collegejaar  2022/2023

Vakken in het huidig collegejaar worden toegevoegd op het moment dat zij definitief zijn in het Osiris systeem. Daarom kan het zijn dat de lijst nog niet compleet is voor het gehele collegejaar.

Vakken Collegejaar  2021/2022



Universiteit Twente
Faculty of Electrical Engineering, Mathematics and Computer Science
Zilverling (gebouwnr. 11), kamer 2023
Hallenweg 19
7522NH  Enschede

