The Experts below are selected from a list of 2742 Experts worldwide ranked by ideXlab platform

Alok Pareek - One of the best experts on this subject based on the ideXlab platform.

  • bronzegate real time transactional data Obfuscation for goldengate
    Extending Database Technology, 2010
    Co-Authors: Shenoda Guirguis, Alok Pareek
    Abstract:

    Data privacy laws have appeared recently, such as the HIPAA laws for protecting medical records, and the PCI guidelines for protecting Credit Card information. Data privacy can be defined as maintaining the privacy of Personal Identifiable Information (PII) from unauthorized accessing. PII includes any piece of data that can be used alone, or in conjunction with additional information, to uniquely identify an individual. Examples of such information include national identification numbers, credit card numbers, as well as financial and medical records. Access control methods and data encryption provide a level of data protection from unauthorized access, however, it is not enough; it does not prohibit identity thefts. It was reported that 70% of the data privacy breaches are internal breaches that involve an employee from the enterprise who has access to some training or testing database replica, which contains all the PII. In addition to access control, we need Techniques to obfuscate (i.e., mask or dim) the datasets used for training, testing and analysis purposes. A good data Obfuscation Technique would, among other features, preserve the data usability while protecting its privacy. This challenge is further complicated when real time requirements are added. In this paper we present BronzeGate: Obfuscated GoldenGate, the GoldenGate's real-time solution for transactional data privacy while maintaining data usability. BronzeGate utilizes different Obfuscation functions for different data types to securely obfuscate the data, on real-time, while maintaining its statistical characteristics.

  • EDBT - BronzeGate: real-time transactional data Obfuscation for GoldenGate
    Proceedings of the 13th International Conference on Extending Database Technology - EDBT '10, 2010
    Co-Authors: Shenoda Guirguis, Alok Pareek
    Abstract:

    Data privacy laws have appeared recently, such as the HIPAA laws for protecting medical records, and the PCI guidelines for protecting Credit Card information. Data privacy can be defined as maintaining the privacy of Personal Identifiable Information (PII) from unauthorized accessing. PII includes any piece of data that can be used alone, or in conjunction with additional information, to uniquely identify an individual. Examples of such information include national identification numbers, credit card numbers, as well as financial and medical records. Access control methods and data encryption provide a level of data protection from unauthorized access, however, it is not enough; it does not prohibit identity thefts. It was reported that 70% of the data privacy breaches are internal breaches that involve an employee from the enterprise who has access to some training or testing database replica, which contains all the PII. In addition to access control, we need Techniques to obfuscate (i.e., mask or dim) the datasets used for training, testing and analysis purposes. A good data Obfuscation Technique would, among other features, preserve the data usability while protecting its privacy. This challenge is further complicated when real time requirements are added. In this paper we present BronzeGate: Obfuscated GoldenGate, the GoldenGate's real-time solution for transactional data privacy while maintaining data usability. BronzeGate utilizes different Obfuscation functions for different data types to securely obfuscate the data, on real-time, while maintaining its statistical characteristics.

Shenoda Guirguis - One of the best experts on this subject based on the ideXlab platform.

  • bronzegate real time transactional data Obfuscation for goldengate
    Extending Database Technology, 2010
    Co-Authors: Shenoda Guirguis, Alok Pareek
    Abstract:

    Data privacy laws have appeared recently, such as the HIPAA laws for protecting medical records, and the PCI guidelines for protecting Credit Card information. Data privacy can be defined as maintaining the privacy of Personal Identifiable Information (PII) from unauthorized accessing. PII includes any piece of data that can be used alone, or in conjunction with additional information, to uniquely identify an individual. Examples of such information include national identification numbers, credit card numbers, as well as financial and medical records. Access control methods and data encryption provide a level of data protection from unauthorized access, however, it is not enough; it does not prohibit identity thefts. It was reported that 70% of the data privacy breaches are internal breaches that involve an employee from the enterprise who has access to some training or testing database replica, which contains all the PII. In addition to access control, we need Techniques to obfuscate (i.e., mask or dim) the datasets used for training, testing and analysis purposes. A good data Obfuscation Technique would, among other features, preserve the data usability while protecting its privacy. This challenge is further complicated when real time requirements are added. In this paper we present BronzeGate: Obfuscated GoldenGate, the GoldenGate's real-time solution for transactional data privacy while maintaining data usability. BronzeGate utilizes different Obfuscation functions for different data types to securely obfuscate the data, on real-time, while maintaining its statistical characteristics.

  • EDBT - BronzeGate: real-time transactional data Obfuscation for GoldenGate
    Proceedings of the 13th International Conference on Extending Database Technology - EDBT '10, 2010
    Co-Authors: Shenoda Guirguis, Alok Pareek
    Abstract:

    Data privacy laws have appeared recently, such as the HIPAA laws for protecting medical records, and the PCI guidelines for protecting Credit Card information. Data privacy can be defined as maintaining the privacy of Personal Identifiable Information (PII) from unauthorized accessing. PII includes any piece of data that can be used alone, or in conjunction with additional information, to uniquely identify an individual. Examples of such information include national identification numbers, credit card numbers, as well as financial and medical records. Access control methods and data encryption provide a level of data protection from unauthorized access, however, it is not enough; it does not prohibit identity thefts. It was reported that 70% of the data privacy breaches are internal breaches that involve an employee from the enterprise who has access to some training or testing database replica, which contains all the PII. In addition to access control, we need Techniques to obfuscate (i.e., mask or dim) the datasets used for training, testing and analysis purposes. A good data Obfuscation Technique would, among other features, preserve the data usability while protecting its privacy. This challenge is further complicated when real time requirements are added. In this paper we present BronzeGate: Obfuscated GoldenGate, the GoldenGate's real-time solution for transactional data privacy while maintaining data usability. BronzeGate utilizes different Obfuscation functions for different data types to securely obfuscate the data, on real-time, while maintaining its statistical characteristics.

Jafar Haadi Jafarian - One of the best experts on this subject based on the ideXlab platform.

  • SocialCom/PASSAT - A Vagueness-based Obfuscation Technique for Protecting Location Privacy
    2010 IEEE Second International Conference on Social Computing, 2010
    Co-Authors: Jafar Haadi Jafarian
    Abstract:

    Technical evolution of location technologies has augmented the development and growth of location-based services. With widespread adoption of these services, threats to location privacy are increasing, entailing more robust and sophisticated solutions. This paper proposes an intuitive Obfuscation-based scheme, which uses vagueness in human perception of nearness to provide a flexible and robust location privacy scheme. Key to this work is the concept of vagueness degree, which aims to enhance its robustness against privacy attacks. Furthermore, our scheme is totally in line with human perception of privacy and provides a solution, which mostly suits proximity-based services, social networking environments, and other similar applications. The solution is also applicable to various environments ranging from geographical locations to IP-based and mobile Networks. We propose three privacy-aware architectures for our scheme. In addition, it is shown that the time and space complexity of the scheme is polynomial. The robustness of the scheme against privacy attacks as well as its implementation issues are discussed.

  • A Vagueness-based Obfuscation Technique for Protecting Location Privacy
    2010 IEEE Second International Conference on Social Computing, 2010
    Co-Authors: Jafar Haadi Jafarian
    Abstract:

    Technical evolution of location technologies has augmented the development and growth of location-based services. With widespread adoption of these services, threats to location privacy are increasing, entailing more robust and sophisticated solutions. This paper proposes an intuitive Obfuscation-based scheme, which uses vagueness in human perception of nearness to provide a flexible and robust location privacy scheme. Key to this work is the concept of vagueness degree, which aims to enhance its robustness against privacy attacks. Furthermore, our scheme is totally in line with human perception of privacy and provides a solution, which mostly suits proximity-based services, social networking environments, and other similar applications. The solution is also applicable to various environments ranging from geographical locations to IP-based and mobile Networks. We propose three privacy-aware architectures for our scheme. In addition, it is shown that the time and space complexity of the scheme is polynomial. The robustness of the scheme against privacy attacks as well as its implementation issues are discussed.

  • ICISC - Protecting Location Privacy through a Graph-Based Location Representation and a Robust Obfuscation Technique
    Information Security and Cryptology – ICISC 2008, 2009
    Co-Authors: Jafar Haadi Jafarian, Ali Noorollahi Ravari, Morteza Amini, Rasool Jalili
    Abstract:

    With technical advancement of location technologies and their widespread adoption, information regarding physical location of individuals is becoming more available, augmenting the development and growth of location-based services. As a result of such availability, threats to location privacy are increasing, entailing more robust and sophisticated solutions capable of providing users with straightforward yet flexible privacy. The ultimate objective of this work is to design a privacy-preserving solution, based on Obfuscation Techniques (imprecision and inaccuracy), capable of handling location privacy, as required by users and according to their preferences. To this aim, we propose an intuitive graph-based location model, based on which users can express their regional privacy preferences. We present an Obfuscation-based solution which allows us to achieve location privacy through degradation of location information, as well as measuring the reliability of such information. The proposed approach is robust and efficient, and covers some of the deficiencies of current Obfuscation-based privacy solutions. We also propose two privacy-aware architectures for our solution.

  • protecting location privacy through a graph based location representation and a robust Obfuscation Technique
    International Conference on Information Security and Cryptology, 2009
    Co-Authors: Jafar Haadi Jafarian, Ali Noorollahi Ravari, Morteza Amini, Rasool Jalili
    Abstract:

    With technical advancement of location technologies and their widespread adoption, information regarding physical location of individuals is becoming more available, augmenting the development and growth of location-based services. As a result of such availability, threats to location privacy are increasing, entailing more robust and sophisticated solutions capable of providing users with straightforward yet flexible privacy. The ultimate objective of this work is to design a privacy-preserving solution, based on Obfuscation Techniques (imprecision and inaccuracy), capable of handling location privacy, as required by users and according to their preferences. To this aim, we propose an intuitive graph-based location model, based on which users can express their regional privacy preferences. We present an Obfuscation-based solution which allows us to achieve location privacy through degradation of location information, as well as measuring the reliability of such information. The proposed approach is robust and efficient, and covers some of the deficiencies of current Obfuscation-based privacy solutions. We also propose two privacy-aware architectures for our solution.

Antonella Santone - One of the best experts on this subject based on the ideXlab platform.

  • code reordering Obfuscation Technique detection by means of weak bisimulation
    Advanced Information Networking and Applications, 2020
    Co-Authors: Giuseppe Crincoli, Tiziano Marinaro, Fabio Martinelli, Francesco Mercaldo, Antonella Santone
    Abstract:

    As evidenced from current literature in software security, the current signature detection mechanisms can be easily evaded by attackers simply applying trivial Obfuscation Techniques, usually with software engines able to automatically inject junk code into malicious applications. In fact, the employment of Obfuscation code Techniques is adopted by attackers to generate several (undetected) variants of one malicious sample, making its signature obsolete. Considering that the signature definition is a laborious process manually performed by security analysts, in this paper we propose a method, exploiting weak bisimulation, to detect whether an Android application is modified by means of the code reordering Obfuscation Technique. We present an experimental analysis performed on a real-world data-set of Android applications (obfuscated and not obfuscated), reaching interesting results in the code reordering Obfuscation Technique detection.

  • AINA - Code Reordering Obfuscation Technique Detection by Means of Weak Bisimulation.
    Advanced Information Networking and Applications, 2020
    Co-Authors: Giuseppe Crincoli, Tiziano Marinaro, Fabio Martinelli, Francesco Mercaldo, Antonella Santone
    Abstract:

    As evidenced from current literature in software security, the current signature detection mechanisms can be easily evaded by attackers simply applying trivial Obfuscation Techniques, usually with software engines able to automatically inject junk code into malicious applications. In fact, the employment of Obfuscation code Techniques is adopted by attackers to generate several (undetected) variants of one malicious sample, making its signature obsolete. Considering that the signature definition is a laborious process manually performed by security analysts, in this paper we propose a method, exploiting weak bisimulation, to detect whether an Android application is modified by means of the code reordering Obfuscation Technique. We present an experimental analysis performed on a real-world data-set of Android applications (obfuscated and not obfuscated), reaching interesting results in the code reordering Obfuscation Technique detection.

  • formal methods meet mobile code Obfuscation identification of code reordering Technique
    Workshops on Enabling Technologies: Infrastracture for Collaborative Enterprises, 2017
    Co-Authors: Aniello Cimitile, Fabio Martinelli, Francesco Mercaldo, Vittoria Nardone, Antonella Santone
    Abstract:

    Android represents the most widespread mobile environment. This increasing diffusion is the reason why attackers are attracted to develop malware targeting this platform. Malware writers usually use code Obfuscation Techniques in order to evade the current antimalware detection and to generate new malware variants. These Techniques make code programs harder to understand and they change the signature of the application making ineffective the signature extraction work. We propose a method based on formal methods able to identify whether a mobile application is obfuscated. In this preliminary work we identify one of the most widespread Obfuscation Technique: the code reordering. We test our method on a real-world dataset composed by Android trusted and ransomware samples, obtaining encouraging results.

  • WETICE - Formal Methods Meet Mobile Code Obfuscation Identification of Code Reordering Technique
    2017 IEEE 26th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE), 2017
    Co-Authors: Aniello Cimitile, Fabio Martinelli, Francesco Mercaldo, Vittoria Nardone, Antonella Santone
    Abstract:

    Android represents the most widespread mobile environment. This increasing diffusion is the reason why attackers are attracted to develop malware targeting this platform. Malware writers usually use code Obfuscation Techniques in order to evade the current antimalware detection and to generate new malware variants. These Techniques make code programs harder to understand and they change the signature of the application making ineffective the signature extraction work. We propose a method based on formal methods able to identify whether a mobile application is obfuscated. In this preliminary work we identify one of the most widespread Obfuscation Technique: the code reordering. We test our method on a real-world dataset composed by Android trusted and ransomware samples, obtaining encouraging results.

Paolo Tonella - One of the best experts on this subject based on the ideXlab platform.

  • Empirical assessment of the effort needed to attack programs protected with client/server code splitting
    Empirical Software Engineering, 2019
    Co-Authors: Alessio Viticchié, Leonardo Regano, Cataldo Basile, Mariano Ceccato, Marco Torchiano, Paolo Tonella
    Abstract:

    ContextCode hardening is meant to fight malicious tampering with sensitive code executed on client hosts. Code splitting is a hardening Technique that moves selected chunks of code from client to server. Although widely adopted, the effective benefits of code splitting are not fully understood and thoroughly assessed.ObjectiveThe objective of this work is to compare non protected code vs. code splitting protected code, considering two levels of the chunk size parameter, in order to assess the effectiveness of the protection - in terms of both attack time and success rate - and to understand the attack strategy and process used to overcome the protection.MethodWe conducted an experiment with master students performing attack tasks on a small application hardened with different levels of protection. Students carried out their task working at the source code level.ResultsWe observed a statistically significant effect of code splitting on the attack success rate that, on the average, was reduced from 89% with unprotected clear code to 52% with the most effective protection. The protection variant that moved some small-sized code chunks turned out to be more effective than the alternative moving fewer but larger chunks. Different strategies were identified yielding different success rates. Moreover we discovered that successful attacks exhibited different process w.r.t. failed ones.ConclusionsWe found empirical evidence of the effect of code splitting, assessed the relative magnitude, and evaluated the influence of the chunk size parameter. Moreover we extracted the process used to overcome such Obfuscation Technique.

  • SCAM - Assessment of Source Code Obfuscation Techniques
    2016 IEEE 16th International Working Conference on Source Code Analysis and Manipulation (SCAM), 2016
    Co-Authors: Alessio Viticchié, Leonardo Regano, Cataldo Basile, Mariano Ceccato, Marco Torchiano, Paolo Tonella, Roberto Tiella
    Abstract:

    Obfuscation Techniques are a general category of software protections widely adopted to prevent malicious tampering of the code by making applications more difficult to understand and thus harder to modify. Obfuscation Techniques are divided in code and data Obfuscation, depending on the protected asset. While preliminary empirical studies have been conducted to determine the impact of code Obfuscation, our work aims at assessing the effectiveness and efficiency in preventing attacks of a specific data Obfuscation Technique - VarMerge. We conducted an experiment with student participants performing two attack tasks on clear and obfuscated versions of two applications written in C. The experiment showed a significant effect of data Obfuscation on both the time required to complete and the successful attack efficiency. An application with VarMerge reduces by six times the number of successful attacks per unit of time. This outcome provides a practical clue that can be used when applying software protections based on data Obfuscation.