The Experts below are selected from a list of 261 Experts worldwide ranked by ideXlab platform
A H Anderson - One of the best experts on this subject based on the ideXlab platform.
-
an introduction to the web services Policy language wspl
IEEE International Workshop on Policies for Distributed Systems and Networks, 2004Co-Authors: A H AndersonAbstract:The Web Services Policy Language (WSPL) is suitable for specifying a wide range of policies, including authorization, quality-of-service, quality-of-protection, reliable messaging, privacy, and application-specific service options. WSPL is of particular interest in several respects. It supports merging two policies, resulting in a single Policy that satisfies the requirements of both, assuming such a Policy exists. Policies can be based on comparisons other than equality, allowing policies to depend on fine-grained attributes such as time of day, cost, or network subnet address. By using standard data types and functions for expressing Policy parameters, a standard Policy Engine can support any Policy. The syntax is a strict subset of the OASIS eXtensible Access Control Markup Language (XACML) Standard. WSPL has been implemented, and is under consideration as a standard Policy language for use with Web services.
-
Policy - An introduction to the Web Services Policy Language (WSPL)
Proceedings. Fifth IEEE International Workshop on Policies for Distributed Systems and Networks 2004. POLICY 2004., 2004Co-Authors: A H AndersonAbstract:The Web Services Policy Language (WSPL) is suitable for specifying a wide range of policies, including authorization, quality-of-service, quality-of-protection, reliable messaging, privacy, and application-specific service options. WSPL is of particular interest in several respects. It supports merging two policies, resulting in a single Policy that satisfies the requirements of both, assuming such a Policy exists. Policies can be based on comparisons other than equality, allowing policies to depend on fine-grained attributes such as time of day, cost, or network subnet address. By using standard data types and functions for expressing Policy parameters, a standard Policy Engine can support any Policy. The syntax is a strict subset of the OASIS eXtensible Access Control Markup Language (XACML) Standard. WSPL has been implemented, and is under consideration as a standard Policy language for use with Web services.
Ramin Yahyapour - One of the best experts on this subject based on the ideXlab platform.
-
a multi layered Policy generation and management Engine for semantic Policy mapping in clouds
Digital Communications and Networks, 2020Co-Authors: Faraz Fatemi Moghaddam, Philipp Wieder, Ramin YahyapourAbstract:Abstract The long awaited cloud computing concept is a reality now due to the transformation of computer generations. However, security challenges have become the biggest obstacles for the advancement of this emerging technology. A well-established Policy framework is defined in this paper to generate security policies which are compliant to requirements and capabilities. Moreover, a federated Policy management schema is introduced based on the Policy definition framework and a multi-level Policy application to create and manage virtual clusters with identical or common security levels. The proposed model consists in the design of a well-established ontology according to security mechanisms, a procedure which classifies nodes with common policies into virtual clusters, a Policy Engine to enhance the process of mapping requests to a specific node as well as an associated cluster and matchmaker Engine to eliminate inessential mapping processes. The suggested model has been evaluated according to performance and security parameters to prove the efficiency and reliability of this multi-layered Engine in cloud computing environments during Policy definition, application and mapping procedures.
-
FiCloud - An Updateable Token-Based Schema for Authentication and Access Management in Clouds
2019 7th International Conference on Future Internet of Things and Cloud (FiCloud), 2019Co-Authors: Tayyebe Emadinia, Faraz Fatemi Moghaddam, Philipp Wieder, Shirin Dabbaghi Varnosfaderani, Ramin YahyapourAbstract:Cloud computing is getting universally in production and hence, comprising more valuable information resources. Therefore, providing a secure infrastructure to exchange information is more vital and inevitable. Attackers are looking for a way to penetrate these systems and exploit various techniques, such as account hijack and denial of service attacks, to obtain the information or develop a disorder in the system. The creation of treat models helps to identify the vulnerabilities, prevent potential attacks, and consider appropriate mechanisms to mitigate them. One of these mechanisms is the access control list and the role-based access control list is one of its variants that defines some user groups and allocates resources to specific groups. Token-based authentication is another mechanism which helps to maintain security. When a user requests to access a resource, initially it must be authenticated by a username and represents a token. In this effort, by using the concept of role-based access control and JSON web token framework, a customized framework is proposed and implemented with a higher level of security in comparison to a standard JSON web token framework. Moreover, this proposal has the ability to update the status of access to resources in case of changing access policies by the Policy Engine.
-
a multi level Policy Engine to manage identities and control accesses in cloud computing environment
European Conference on Service-Oriented and Cloud Computing, 2018Co-Authors: Faraz Fatemi Moghaddam, Philipp Wieder, Suleyman Berk Cemberci, Ramin YahyapourAbstract:Security challenges are the most important obstacles for the advancement of IT-based on-demand services and cloud computing as an emerging technology. Lack of coincidence in identity management models based on defined policies and various security levels in different cloud servers is one of the most challenging issues in clouds. In this paper, a Policy-based user authentication model has been presented to provide a reliable and scalable identity management and to map cloud users’ access requests with defined polices of cloud servers. In the proposed schema several components are provided to define access policies by cloud servers, to apply policies based on a structural and reliable ontology, to manage user identities and to semantically map access requests by cloud users with defined polices.
-
a multi layered access Policy Engine for reliable cloud computing
International Conference on Network of Future, 2017Co-Authors: Faraz Fatemi Moghaddam, Philipp Wieder, Ramin YahyapourAbstract:The long awaited Cloud computing concept is a reality now due to the advancement and transformation of computer generations. However, security challenges are most important obstacles for the advancement of this emerging technology. Managing security policies based on capabilities of service provider and requirements of cloud customers is one of the potential issues due to the scalability and isolation concepts in clouds. In this paper, a multi-layered Policy Engine is presented to manage policies securely with the minimum consumption of processing power for enhancement of QoS in virtualized environments. Thus, a Policy Layer Constructor and Reasoning Engine are introduced to divide polices into several layers for enhancing quality and reliability of mapping access requests to cloud nodes. The suggested model has been evaluated with performance, security and competitive analysis, and the reliability and efficiency of multi-layered Policy Engine have been assured for defining, generating and applying security polices in clouds.
-
Policy Engine as a Service (PEaaS): An approach to a reliable Policy management framework in cloud computing environments
Proceedings - 2016 IEEE 4th International Conference on Future Internet of Things and Cloud FiCloud 2016, 2016Co-Authors: Faraz Fatemi Moghaddam, Philipp Wieder, Ramin YahyapourAbstract:Security challenges are the most important obstacle for advancement of IT-based on-demand services and cloud computing as an emerging technology. In this paper, a structural Policy management Engine has been introduced to enhance the reliability of managing different policies in clouds and to provide standard and also dedicated security levels (rings) based on capabilities of the cloud provider and requirements of cloud customers. Accordingly, Policy database has been designed based on capabilities and Policy Engine establishes appropriate relations between Policy database and SLA Engine to provide security terms as a service. Furthermore, Policy match maker and reasoning Engine have been designed for syntactic and semantic analysis of security requests based on three-levels of protection ontology to enhance the process of Policy management in clouds.
Mary R Thompson - One of the best experts on this subject based on the ideXlab platform.
-
certificate based access control for widely distributed resources
USENIX Security Symposium, 1999Co-Authors: Mary R Thompson, William E Johnston, Srilekha S Mudumbai, Gary Hoo, Keith Jackson, Abdelilah EssiariAbstract:We have implemented and deployed an access control mechanism that uses digitally-signed certificates to define and enforce an access Policy for a set of distributed resources that have multiple, independent and geographically dispersed stakeholders. The stakeholders assert their access requirements in use-condition certificates and designate those trusted to attest to the corresponding user attributes. Users are identified by X.509 identity certificates. During a request to use a resource, a Policy Engine collects all the relevant certificates and decides if the user satisfies all the requirements. This paper describes the model, architecture and implementation of this system. It also includes some preliminary performance measurements and our plans for future development of the system.
-
USENIX Security Symposium - Certificate-based access control for widely distributed resources
1999Co-Authors: Mary R Thompson, William E Johnston, Srilekha S Mudumbai, Gary Hoo, Keith Jackson, Abdelilah EssiariAbstract:We have implemented and deployed an access control mechanism that uses digitally-signed certificates to define and enforce an access Policy for a set of distributed resources that have multiple, independent and geographically dispersed stakeholders. The stakeholders assert their access requirements in use-condition certificates and designate those trusted to attest to the corresponding user attributes. Users are identified by X.509 identity certificates. During a request to use a resource, a Policy Engine collects all the relevant certificates and decides if the user satisfies all the requirements. This paper describes the model, architecture and implementation of this system. It also includes some preliminary performance measurements and our plans for future development of the system.
-
authorization and attribute certificates for widely distributed access control
Lawrence Berkeley National Laboratory, 1998Co-Authors: William E Johnston, Srilekha S Mudumbai, Mary R ThompsonAbstract:We describe a system whose purpose is to explore the use of certificates for the distributed management of access rights for resources that have multiple, independent, and geographically dispersed stakeholders. The stakeholders assert their use-conditions in authorization certificates and designate those t rusted to attest to the corresponding attributes. These use-conditions implicitly define access groups through their requirement for certain attributes. All use-conditions must be satisfied simultaneously, so the actual access group is the intersection of all of the groups. A Policy Engine collects the use-condition certificates and attribute certificates when a user attempts to ac cess a particular resource. If all of the use-conditions are met, a capability is generated for the resource. The Policy Engine can provide several different Policy models depending on whether any relationship is established among the use-conditions. The system architecture and implementation is described, together with some of the identified strengths, weaknesses, and vulnerabilities.
-
WETICE - Authorization and attribute certificates for widely distributed access control
Proceedings Seventh IEEE International Workshop on Enabling Technologies: Infrastucture for Collaborative Enterprises (WET ICE '98) (Cat. No.98TB10025, 1Co-Authors: William E Johnston, Srilekha S Mudumbai, Mary R ThompsonAbstract:The authors describe a system whose purpose is to explore the use of certificates for the distributed management of access rights for resources that have multiple, independent, and geographically dispersed stakeholders. The stakeholders assert their use-conditions in authorization certificates and designate those trusted to attest to the corresponding attributes. These use-conditions implicitly define access groups through their requirement for certain attributes. All use-conditions must be satisfied simultaneously, so the actual access group is the intersection of all of the groups. A Policy Engine collects the use-condition certificates and attribute certificates when a user attempts to access a particular resource. If all of the use-conditions are met, a capability is generated for the resource. The Policy Engine can provide several different Policy models depending on whether any relationship is established among the use-conditions. The system architecture and implementation is described, together with some of the identified strengths, weaknesses, and vulnerabilities.
Galen M. Shipman - One of the best experts on this subject based on the ideXlab platform.
-
programmable caches with a data management language and Policy Engine
IEEE ACM International Symposium Cluster Cloud and Grid Computing, 2018Co-Authors: Michael A. Sevilla, Carlos Maltzahn, Peter Alvaro, Reza Nasirigerdeh, Bradley W. Settlemyer, Danny Perez, David Rich, Galen M. ShipmanAbstract:Our analysis of the key-value activity generated by the ParSplice molecular dynamics simulation demonstrates the need for more complex cache management strategies. Baseline measurements show clear key access patterns and hot spots that offer significant opportunity for optimization. We use the data management language and Policy Engine from the Mantle system to dynamically explore a variety of techniques, ranging from basic algorithms and heuristics to statistical models, calculus, and machine learning. While Mantle was originally designed for distributed file systems, we show how the collection of abstractions effectively decomposes the problem into manageable policies for a different application and storage system. Our exploration of this space results in a dynamically sized cache Policy that does not sacrifice any performance while using 32-66% less memory than the default ParSplice configuration.
-
CCGrid - Programmable caches with a data management language and Policy Engine
2018 18th IEEE ACM International Symposium on Cluster Cloud and Grid Computing (CCGRID), 2018Co-Authors: Michael A. Sevilla, Carlos Maltzahn, Peter Alvaro, Reza Nasirigerdeh, Bradley W. Settlemyer, Danny Perez, David Rich, Galen M. ShipmanAbstract:Our analysis of the key-value activity generated by the ParSplice molecular dynamics simulation demonstrates the need for more complex cache management strategies. Baseline measurements show clear key access patterns and hot spots that offer significant opportunity for optimization. We use the data management language and Policy Engine from the Mantle system to dynamically explore a variety of techniques, ranging from basic algorithms and heuristics to statistical models, calculus, and machine learning. While Mantle was originally designed for distributed file systems, we show how the collection of abstractions effectively decomposes the problem into manageable policies for a different application and storage system. Our exploration of this space results in a dynamically sized cache Policy that does not sacrifice any performance while using 32-66% less memory than the default ParSplice configuration.
Shambhu Upadhyaya - One of the best experts on this subject based on the ideXlab platform.
-
security policies to mitigate insider threat in the document control domain
Annual Computer Security Applications Conference, 2004Co-Authors: Suranjan Pramanik, Vidyaraman Sankaranarayanan, Shambhu UpadhyayaAbstract:With rapid advances in online technologies, organizations are migrating from paper based resources to digital documents to achieve high responsiveness and ease of management. These digital documents are the most important asset of an organization and are hence the chief target of insider abuse. Security policies provide the first step to prevent abuse by defining proper and improper usage of resources. Coarse grained security policies that operate on the "principle of least privilege" [J. H. Saltzer et al., (1974)] alone are not enough to address the insider threat, since the typical insider possesses a wide range of privileges to start with. In this paper, we propose a security Policy that is tailored to prevent insider abuse. We define the concept of subject, object, actions, rights, context and information flow as applicable to the document control domain. Access is allowed based on the principles of "least privilege and minimum requirements", subject to certain constraints. Unlike existing techniques, the proposed Policy Engine considers, among other factors, the context of a document request and the information flow between such requests to identify potential malicious insiders. Enforcing these fine-grained access control policies gives us a better platform to prevent the insider abuse. Finally, for demonstration purposes, we present a framework that can be used to specify and enforce these policies on Microsoft Word documents, one of the popular document formats.
-
ACSAC - Security policies to mitigate insider threat in the document control domain
20th Annual Computer Security Applications Conference, 1Co-Authors: Suranjan Pramanik, Vidyaraman Sankaranarayanan, Shambhu UpadhyayaAbstract:With rapid advances in online technologies, organizations are migrating from paper based resources to digital documents to achieve high responsiveness and ease of management. These digital documents are the most important asset of an organization and are hence the chief target of insider abuse. Security policies provide the first step to prevent abuse by defining proper and improper usage of resources. Coarse grained security policies that operate on the "principle of least privilege" [J. H. Saltzer et al., (1974)] alone are not enough to address the insider threat, since the typical insider possesses a wide range of privileges to start with. In this paper, we propose a security Policy that is tailored to prevent insider abuse. We define the concept of subject, object, actions, rights, context and information flow as applicable to the document control domain. Access is allowed based on the principles of "least privilege and minimum requirements", subject to certain constraints. Unlike existing techniques, the proposed Policy Engine considers, among other factors, the context of a document request and the information flow between such requests to identify potential malicious insiders. Enforcing these fine-grained access control policies gives us a better platform to prevent the insider abuse. Finally, for demonstration purposes, we present a framework that can be used to specify and enforce these policies on Microsoft Word documents, one of the popular document formats.
-
IPCCC - AVARE: aggregated vulnerability assessment and response against zero-day exploits
2006 IEEE International Performance Computing and Communications Conference, 1Co-Authors: M. Chandrasekaran, Mukkarram Baig, Shambhu UpadhyayaAbstract:In this paper we propose an automated approach for determining recently published vulnerabilities pertinent to the current network/system configuration using the information aggregated from different bug tracking communities. Such vulnerability assessment and indication mechanisms significantly alleviate the system administrator's burden of manual content digging for vulnerabilities in his/her own configuration context. Furthermore, we propose an extensible defense oriented representation schema (EDORS) for vulnerability representation, which is consequently used by the Policy Engine to generate appropriate IDS signatures. As a result, the generated signatures can be viewed as a preventive stop-gap security measure against zero-day exploits until its patch is released. In the absence of precise detection signatures, we extend our framework to perform forensic analysis on the alerts generated, by constructing Bayesian causality graphs to assess the impact and extent of the attack. The preliminary experiments carried out suggest that our approach is able to analyze the system/network for even the most recent zero-day vulnerabilities and generate their corresponding signatures with very minimal performance and administrative overhead.