The Experts below are selected from a list of 7977 Experts worldwide ranked by ideXlab platform

Sanjay Kumar Madria - One of the best experts on this subject based on the ideXlab platform.

  • risk assessment in a sensor cloud framework using attack graphs
    IEEE Transactions on Services Computing, 2017
    Co-Authors: Amartya Sen, Sanjay Kumar Madria
    Abstract:

    A sensor cloud consists of various heterogeneous wireless sensor networks (WSNs). These WSNs may have different owners and run a wide variety of user applications on demand in a wireless communication medium. Hence, they are susceptible to various Security attacks. Thus, a need exists to formulate effective and efficient Security measures that safeguard these applications impacted from attack in the sensor cloud. However, analyzing the impact of different attacks and their cause-consequence relationship is a prerequisite before Security measures can be either developed or deployed. In this paper, we propose a risk assessment framework for WSNs in a sensor cloud that utilizes attack graphs. We use Bayesian networks to not only assess but also to analyze attacks on WSNs. The risk assessment framework will first review the impact of attacks on a WSN and estimate reasonable time frames that predict the degradation of WSN Security parameters like confidentiality, integrity and availability. Using our proposed risk assessment framework allows the Security Administrator to better understand the threats present and take necessary actions against them. The framework is validated by comparing the assessment results with that of the results obtained from different simulated attack scenarios.

  • MDM (2) - A Risk Assessment Framework for Wireless Sensor Networks in a Sensor Cloud
    2015 16th IEEE International Conference on Mobile Data Management, 2015
    Co-Authors: Amartya Sen, Sanjay Kumar Madria
    Abstract:

    A Sensor cloud framework is composed of various heterogeneous wireless sensor networks (WSNs) integrated with the cloud platform. Integration with the cloud platform, in addition to the inherent resource and power constrained nature of the sensor nodes makes these WSNs belonging to a sensor cloud susceptible to Security attacks. As such there is a need to formulate effective and efficient Security measures for such an environment. But in doing so, requires an understanding of the likelihood and impact of different attacks feasible on the WSNs. In this paper, we propose a risk assessment framework for the WSNs belonging to a sensor cloud. The proposed risk assessment framework addresses the feasible set of attacks on a WSN identifying the relationships between them and thus estimating their likelihood and impact. This kind of assessment will give the Security Administrator a better perspective of their network and help formulating the required Security measures.

Amartya Sen - One of the best experts on this subject based on the ideXlab platform.

  • risk assessment in a sensor cloud framework using attack graphs
    IEEE Transactions on Services Computing, 2017
    Co-Authors: Amartya Sen, Sanjay Kumar Madria
    Abstract:

    A sensor cloud consists of various heterogeneous wireless sensor networks (WSNs). These WSNs may have different owners and run a wide variety of user applications on demand in a wireless communication medium. Hence, they are susceptible to various Security attacks. Thus, a need exists to formulate effective and efficient Security measures that safeguard these applications impacted from attack in the sensor cloud. However, analyzing the impact of different attacks and their cause-consequence relationship is a prerequisite before Security measures can be either developed or deployed. In this paper, we propose a risk assessment framework for WSNs in a sensor cloud that utilizes attack graphs. We use Bayesian networks to not only assess but also to analyze attacks on WSNs. The risk assessment framework will first review the impact of attacks on a WSN and estimate reasonable time frames that predict the degradation of WSN Security parameters like confidentiality, integrity and availability. Using our proposed risk assessment framework allows the Security Administrator to better understand the threats present and take necessary actions against them. The framework is validated by comparing the assessment results with that of the results obtained from different simulated attack scenarios.

  • MDM (2) - A Risk Assessment Framework for Wireless Sensor Networks in a Sensor Cloud
    2015 16th IEEE International Conference on Mobile Data Management, 2015
    Co-Authors: Amartya Sen, Sanjay Kumar Madria
    Abstract:

    A Sensor cloud framework is composed of various heterogeneous wireless sensor networks (WSNs) integrated with the cloud platform. Integration with the cloud platform, in addition to the inherent resource and power constrained nature of the sensor nodes makes these WSNs belonging to a sensor cloud susceptible to Security attacks. As such there is a need to formulate effective and efficient Security measures for such an environment. But in doing so, requires an understanding of the likelihood and impact of different attacks feasible on the WSNs. In this paper, we propose a risk assessment framework for the WSNs belonging to a sensor cloud. The proposed risk assessment framework addresses the feasible set of attacks on a WSN identifying the relationships between them and thus estimating their likelihood and impact. This kind of assessment will give the Security Administrator a better perspective of their network and help formulating the required Security measures.

Edgar Danielyan - One of the best experts on this subject based on the ideXlab platform.

  • Sun Certified Security Administrator for Solaris 9 & 10 Study Guide
    2005
    Co-Authors: John Chirillo, Edgar Danielyan
    Abstract:

    Table of contents About the Contributors Acknowledgments Preface Introduction Part I: General Security Concepts Chapter 1: Fundamental Security Concepts Chapter 2: Attacks, Motives, and Methods Chapter 3: Security Management and Standards Part II: Detection and Device Management Chapter 4: Logging and Process Accounting Chapter 5: Solaris Auditing, Planning, and Management Chapter 6: Device, System, and File Security Part III: Security Attacks Chapter 7: Denial of Service Attacks Chapter 8: Remote Access Attacks Part IV: File and System Resources Protection Chapter 9: User and Domain Account Management with RBAC Chapter 10: Fundamentals of Access Control Part V: Solaris Cryptographic Framework Chapter 11: Using Cryptographic Services Part VI: Authentication Services and Secure Communication Chapter 12: Secure RPC Across NFS and PAM Chapter 13: SASL and Secure Shell Chapter 14: Sun Enterprise Authentication Mechanism Part VII: Appendices Appendix A: Final Test Study Guide Appendix B: Final Test Appendix C: Final Test Answers Appendix D: Hands-On Exercises and Solutions Index

  • sun certified Security Administrator for solaris 9 10 study guide
    2005
    Co-Authors: John Chirillo, Edgar Danielyan
    Abstract:

    Table of contents About the Contributors Acknowledgments Preface Introduction Part I: General Security Concepts Chapter 1: Fundamental Security Concepts Chapter 2: Attacks, Motives, and Methods Chapter 3: Security Management and Standards Part II: Detection and Device Management Chapter 4: Logging and Process Accounting Chapter 5: Solaris Auditing, Planning, and Management Chapter 6: Device, System, and File Security Part III: Security Attacks Chapter 7: Denial of Service Attacks Chapter 8: Remote Access Attacks Part IV: File and System Resources Protection Chapter 9: User and Domain Account Management with RBAC Chapter 10: Fundamentals of Access Control Part V: Solaris Cryptographic Framework Chapter 11: Using Cryptographic Services Part VI: Authentication Services and Secure Communication Chapter 12: Secure RPC Across NFS and PAM Chapter 13: SASL and Secure Shell Chapter 14: Sun Enterprise Authentication Mechanism Part VII: Appendices Appendix A: Final Test Study Guide Appendix B: Final Test Appendix C: Final Test Answers Appendix D: Hands-On Exercises and Solutions Index

Arif Ghafoor - One of the best experts on this subject based on the ideXlab platform.

  • a framework for composition and enforcement of privacy aware and context driven authorization mechanism for multimedia big data
    IEEE Transactions on Multimedia, 2015
    Co-Authors: Arjmand Samuel, Muhammad Sarfraz, Hammad Haseeb, Saleh Basalamah, Arif Ghafoor
    Abstract:

    The proliferation of multimedia big data for dissemination and sharing of massive amounts of information raises important Security and privacy concerns. One such concern is the composition and enforcement of privacy policies in order to securely manage access of multimedia big data. Several researchers have pointed out that for proper enforcement of privacy policies, the privacy requirements should be captured in access control systems. In this paper, we propose a hybrid approach where privacy requirements are captured in an access control system and present a framework for composition and enforcement of privacy policies. The focus is to allow a user, not a system or Security Administrator to compose conflict free policies for their online multimedia data. An additional requirement is that such a policy be context-aware. We also present a methodology for verifying the privacy policy in order to ensure correctness and logical consistency. The verification process is also used to ensure that sensitive Security requirements are not violated when privacy rules are enforced. A prototype, named Intelligent Privacy Manager (iPM), has been implemented for sharing of multimedia big data in a secure and private manner.

Elena Ferrari - One of the best experts on this subject based on the ideXlab platform.

  • Management of access control policies for XML document sources
    International Journal of Information Security, 2003
    Co-Authors: Barbara Carminati, Elena Ferrari
    Abstract:

    The development of suitable mechanisms for securing XML documents is becoming an urgent need since XML is evolving into a standard for data representation and exchange over the Web. To answer this need, we have designed Author-X [1, 3], a Java-based system specifically conceived for the protection of XML documents. Distinguishing features of the access control model of Author-X are the support for a wide range of protection granularity levels and for subject credentials. Another key characteristic of Author-X is the enforcement of different access control strategies for document release: besides the traditional, on user demand, mode of access control, Author-X also supports push distribution, for document dissemination. Managing an access control system based on such a flexible and expressive model requires the design and implementation of suitable administration tools to help the Security Administrator in efficiently performing administrative operations related to access control policies management. In this paper, we present the strategies and related algorithms we have devised for policy management in Author-X , with particular emphasis on information push support. In the paper, besides presenting the algorithms and the related data structures, we provide a complexity study of the proposed algorithms. Additionally, we describe the implementation of the proposed algorithms in the framework of Author-X .

  • Specifying and enforcing access control policies for XML document sources
    World Wide Web, 2000
    Co-Authors: Elisa Bertino, Silvana Castano, Elena Ferrari, Marco Mesiti
    Abstract:

    The Web is becoming the main information dissemination means in private and public organizations. As a consequence, several applications at both internet and intranet level need mechanisms to support a selective access to data available over the Web. In this context, developing an access control model, and related mechanisms, in terms of XML (eXtensible Markup Language) is an important step, because XML is increasingly used as the language for representing information exchanged over the Web. In this paper, we propose access control policies and an associated model for XML documents, addressing peculiar protection requirements posed by XML. A first requirement is that varying protection granularity levels should be supported to guarantee a differentiated protection of document contents. A second requirement arises from the fact that XML documents do not always conform to a predefined document type. To cope with these requirements, the proposed model supports varying protection granularity levels, ranging from a set of documents, to a single document or specific document portion(s). Moreover, it allows the Security Administrator to choose different policies for documents not covered or only partially covered by the existing access control policies for document types. An access control mechanism for the enforcement of the proposed model is finally described.