The Experts below are selected from a list of 45555 Experts worldwide ranked by ideXlab platform

R Chow - One of the best experts on this subject based on the ideXlab platform.

  • an extended Capability Architecture to enforce dynamic access control policies
    Annual Computer Security Applications Conference, 1996
    Co-Authors: Ilung Kao, R Chow
    Abstract:

    Capability has been widely used as a fundamental mechanism for access control in distributed systems. When an object manager receives a Capability from a user process for accessing an object, it verifies the genuineness of the Capability and checks whether the access request is allowed with the access rights placed on the Capability. Capabilities have been recognized to be more suitable than centralized access control lists for object protection in a distributed system because of several obvious reasons. However, most existing Capability based systems can only enforce static access control policies, which means all the access privileges a user possesses for an object are fully represented by a Capability and will not change due to object access. These Capability systems cannot be used to enforce dynamic access control policies, required by many complex applications, in which each authorization may depend upon a user's access history and/or an object's history of being accessed. The paper proposes an extended Capability Architecture to enforce dynamic access control policies both effectively and efficiently. The key issue is how to capture the dynamic access information in both capabilities and object managers while avoiding main disadvantages of centralized access control lists. A number of frequently desired security policies are used to demonstrate the power and flexibility of the proposed Architecture. The problems regarding Capability management including propagation, revocation, and distribution of capabilities are also discussed.

  • ACSAC - An extended Capability Architecture to enforce dynamic access control policies
    Proceedings 12th Annual Computer Security Applications Conference, 1
    Co-Authors: Ilung Kao, R Chow
    Abstract:

    Capability has been widely used as a fundamental mechanism for access control in distributed systems. When an object manager receives a Capability from a user process for accessing an object, it verifies the genuineness of the Capability and checks whether the access request is allowed with the access rights placed on the Capability. Capabilities have been recognized to be more suitable than centralized access control lists for object protection in a distributed system because of several obvious reasons. However, most existing Capability based systems can only enforce static access control policies, which means all the access privileges a user possesses for an object are fully represented by a Capability and will not change due to object access. These Capability systems cannot be used to enforce dynamic access control policies, required by many complex applications, in which each authorization may depend upon a user's access history and/or an object's history of being accessed. The paper proposes an extended Capability Architecture to enforce dynamic access control policies both effectively and efficiently. The key issue is how to capture the dynamic access information in both capabilities and object managers while avoiding main disadvantages of centralized access control lists. A number of frequently desired security policies are used to demonstrate the power and flexibility of the proposed Architecture. The problems regarding Capability management including propagation, revocation, and distribution of capabilities are also discussed.

Ilung Kao - One of the best experts on this subject based on the ideXlab platform.

  • an extended Capability Architecture to enforce dynamic access control policies
    Annual Computer Security Applications Conference, 1996
    Co-Authors: Ilung Kao, R Chow
    Abstract:

    Capability has been widely used as a fundamental mechanism for access control in distributed systems. When an object manager receives a Capability from a user process for accessing an object, it verifies the genuineness of the Capability and checks whether the access request is allowed with the access rights placed on the Capability. Capabilities have been recognized to be more suitable than centralized access control lists for object protection in a distributed system because of several obvious reasons. However, most existing Capability based systems can only enforce static access control policies, which means all the access privileges a user possesses for an object are fully represented by a Capability and will not change due to object access. These Capability systems cannot be used to enforce dynamic access control policies, required by many complex applications, in which each authorization may depend upon a user's access history and/or an object's history of being accessed. The paper proposes an extended Capability Architecture to enforce dynamic access control policies both effectively and efficiently. The key issue is how to capture the dynamic access information in both capabilities and object managers while avoiding main disadvantages of centralized access control lists. A number of frequently desired security policies are used to demonstrate the power and flexibility of the proposed Architecture. The problems regarding Capability management including propagation, revocation, and distribution of capabilities are also discussed.

  • ACSAC - An extended Capability Architecture to enforce dynamic access control policies
    Proceedings 12th Annual Computer Security Applications Conference, 1
    Co-Authors: Ilung Kao, R Chow
    Abstract:

    Capability has been widely used as a fundamental mechanism for access control in distributed systems. When an object manager receives a Capability from a user process for accessing an object, it verifies the genuineness of the Capability and checks whether the access request is allowed with the access rights placed on the Capability. Capabilities have been recognized to be more suitable than centralized access control lists for object protection in a distributed system because of several obvious reasons. However, most existing Capability based systems can only enforce static access control policies, which means all the access privileges a user possesses for an object are fully represented by a Capability and will not change due to object access. These Capability systems cannot be used to enforce dynamic access control policies, required by many complex applications, in which each authorization may depend upon a user's access history and/or an object's history of being accessed. The paper proposes an extended Capability Architecture to enforce dynamic access control policies both effectively and efficiently. The key issue is how to capture the dynamic access information in both capabilities and object managers while avoiding main disadvantages of centralized access control lists. A number of frequently desired security policies are used to demonstrate the power and flexibility of the proposed Architecture. The problems regarding Capability management including propagation, revocation, and distribution of capabilities are also discussed.

P.a. Karger - One of the best experts on this subject based on the ideXlab platform.

  • IEEE Symposium on Security and Privacy - Implementing commercial data integrity with secure capabilities
    Proceedings. 1988 IEEE Symposium on Security and Privacy, 1
    Co-Authors: P.a. Karger
    Abstract:

    The author examines the model of D.D. Clark and D.R. Wilson (1987) for commercial data integrity and proposes an implementation based on his own secure Capability Architecture. He shows how secure capabilities and protected subsystems are ideal for implementing commercial data integrity, but also indicates areas where the Clark-Wilson model may have difficulties in actual use. The level of formal verification required appears higher than would be feasible for most commercial systems and the user interface for specifying separation of duties appears extremely complex. >

Adrian Campos - One of the best experts on this subject based on the ideXlab platform.

  • towards a scada forensics Architecture
    ICS-CSR 2013 Proceedings of the 1st International Symposium on ICS & SCADA Cyber Security Research 2013, 2013
    Co-Authors: Tina Wu, Jules Ferdinand Pagna Disso, Kevin Jones, Adrian Campos
    Abstract:

    With the increasing threat of sophisticated attacks on critical infrastructures, it is vital that forensic investigations take place immediately following a security incident. This paper presents an existing SCADA forensic process model and proposes a structured SCADA forensic process model to carry out a forensic investigations. A discussion on the limitations of using traditional forensic investigative processes and the challenges facing forensic investigators. Furthermore, flaws of existing research into providing forensic Capability for SCADA systems are examined in detail. The study concludes with an experimentation of a proposed SCADA forensic Capability Architecture on the Siemens S7 PLC. Modifications to the memory addresses are monitored and recorded for forensic evidence. The collected forensic evidence will be used to aid the reconstruction of a timeline of events, in addition to other collected forensic evidence such as network packet captures.

  • ICS-CSR - Towards a SCADA Forensics Architecture
    2013
    Co-Authors: Jules Ferdinand Pagna Disso, Kevin Jones, Adrian Campos
    Abstract:

    With the increasing threat of sophisticated attacks on critical infrastructures, it is vital that forensic investigations take place immediately following a security incident. This paper presents an existing SCADA forensic process model and proposes a structured SCADA forensic process model to carry out a forensic investigations. A discussion on the limitations of using traditional forensic investigative processes and the challenges facing forensic investigators. Furthermore, flaws of existing research into providing forensic Capability for SCADA systems are examined in detail. The study concludes with an experimentation of a proposed SCADA forensic Capability Architecture on the Siemens S7 PLC. Modifications to the memory addresses are monitored and recorded for forensic evidence. The collected forensic evidence will be used to aid the reconstruction of a timeline of events, in addition to other collected forensic evidence such as network packet captures.

Jules Ferdinand Pagna Disso - One of the best experts on this subject based on the ideXlab platform.

  • towards a scada forensics Architecture
    ICS-CSR 2013 Proceedings of the 1st International Symposium on ICS & SCADA Cyber Security Research 2013, 2013
    Co-Authors: Tina Wu, Jules Ferdinand Pagna Disso, Kevin Jones, Adrian Campos
    Abstract:

    With the increasing threat of sophisticated attacks on critical infrastructures, it is vital that forensic investigations take place immediately following a security incident. This paper presents an existing SCADA forensic process model and proposes a structured SCADA forensic process model to carry out a forensic investigations. A discussion on the limitations of using traditional forensic investigative processes and the challenges facing forensic investigators. Furthermore, flaws of existing research into providing forensic Capability for SCADA systems are examined in detail. The study concludes with an experimentation of a proposed SCADA forensic Capability Architecture on the Siemens S7 PLC. Modifications to the memory addresses are monitored and recorded for forensic evidence. The collected forensic evidence will be used to aid the reconstruction of a timeline of events, in addition to other collected forensic evidence such as network packet captures.

  • ICS-CSR - Towards a SCADA Forensics Architecture
    2013
    Co-Authors: Jules Ferdinand Pagna Disso, Kevin Jones, Adrian Campos
    Abstract:

    With the increasing threat of sophisticated attacks on critical infrastructures, it is vital that forensic investigations take place immediately following a security incident. This paper presents an existing SCADA forensic process model and proposes a structured SCADA forensic process model to carry out a forensic investigations. A discussion on the limitations of using traditional forensic investigative processes and the challenges facing forensic investigators. Furthermore, flaws of existing research into providing forensic Capability for SCADA systems are examined in detail. The study concludes with an experimentation of a proposed SCADA forensic Capability Architecture on the Siemens S7 PLC. Modifications to the memory addresses are monitored and recorded for forensic evidence. The collected forensic evidence will be used to aid the reconstruction of a timeline of events, in addition to other collected forensic evidence such as network packet captures.