The Experts below are selected from a list of 24513 Experts worldwide ranked by ideXlab platform

Christoph Meinel - One of the best experts on this subject based on the ideXlab platform.

  • the service Security lab a model driven platform to compose and explore service Security in the cloud
    World Congress on Services, 2010
    Co-Authors: Michael Menzel, Ivonne Thomas, Robert Warschofsky, Christian Willems, Christoph Meinel
    Abstract:

    Cloud computing enables the provisioning of dynamically scalable resources as a service. Next to cloud computing, the paradigm of Service-oriented Architectures emerged to facilitate the provisioning of functionality as services. While both concepts are complementary, their combination enables the flexible provisioning and consumption of independently scalable services. These approaches come along with new Security risks that require the usage of identity and access management solutions and information protection. The requirements concerning Security mechanisms, protocols and options are stated in Security policies that configure the interaction between services and clients in a system. In this paper, we present our cloud-based Service Security Lab that supports the on-demand creation and orchestration of composed applications and services. Our cloud platform enables the testing, monitoring and analysis of Web Services regarding different Security Configurations, concepts and infrastructure components. Since Security policies are hard to understand and even harder to codify, we foster a model-driven approach to simplify the creation of Security Configurations. Our model-driven approach enables the definition of Security requirements at the modelling layer and facilitates a transformation based on Security Configuration patterns.

  • a pattern driven generation of Security policies for service oriented architectures
    International Conference on Web Services, 2010
    Co-Authors: Michael Menzel, Robert Warschofsky, Christoph Meinel
    Abstract:

    Service-oriented Architectures support the provision, discovery, and usage of services in different application contexts. The Web Service specifications provide a technical foundation to implement this paradigm. Moreover, mechanisms are provided to face the new Security challenges raised by SOA. To enable the seamless usage of services, Security requirements can be expressed as Security policies (e.g. WS-Policy and WS-SecurityPolicy) that enable the negotiation of these requirements between clients and services. However, the codification of Security policies is a difficult and error-prone task due to the complexity of the Web Service specifications. In this paper, we introduce our model-driven approach that facilitates the transformation of architecture models annotated with simple Security intentions to Security policies. This transformation is driven by Security Configuration patterns that provide expert knowledge on Web Service Security. Therefore, we will introduce a formalised pattern structure and a domain-specific language to specify these patterns.

  • Security requirements specification in service-oriented business process management
    Proceedings - International Conference on Availability Reliability and Security ARES 2009, 2009
    Co-Authors: Michael Menzel, Ivonne Thomas, Christoph Meinel
    Abstract:

    Service-oriented Architectures deliver a flexible infrastructure to allow independently developed software components to communicate in a seamless manner. In the scope of organisational workflows, SOA provides a suitable foundation to execute business processes as an orchestration of multiple independent services. Along with the increased connectivity, the corresponding Security risks rise exponentially. However, Security requirements are usually defined on a technical level, rather than on an organisational level that would provide a comprehensive view on the participants, the assets and their relationships regarding Security. In this paper, we propose an approach to describe Security requirements at the business process layer and their translation to concrete Security Configuration for service-based systems. We introduce Security elements for business process modelling which allow to evaluate the trustworthiness of participants based on a rating of enterprise assets and to express Security intentions such as confidentiality or integrity on an abstract level. Our aim is to facilitate the generation of Security Configurations based on the modelled requirements. For this purpose, we foster a model-driven approach: Information at the modelling layer is gathered and translated to a domain-independent Security model. Concrete protocols and Security mechanisms are resolved based on a Security pattern system that is introduced in the course of this paper.

Michael Menzel - One of the best experts on this subject based on the ideXlab platform.

  • the service Security lab a model driven platform to compose and explore service Security in the cloud
    World Congress on Services, 2010
    Co-Authors: Michael Menzel, Ivonne Thomas, Robert Warschofsky, Christian Willems, Christoph Meinel
    Abstract:

    Cloud computing enables the provisioning of dynamically scalable resources as a service. Next to cloud computing, the paradigm of Service-oriented Architectures emerged to facilitate the provisioning of functionality as services. While both concepts are complementary, their combination enables the flexible provisioning and consumption of independently scalable services. These approaches come along with new Security risks that require the usage of identity and access management solutions and information protection. The requirements concerning Security mechanisms, protocols and options are stated in Security policies that configure the interaction between services and clients in a system. In this paper, we present our cloud-based Service Security Lab that supports the on-demand creation and orchestration of composed applications and services. Our cloud platform enables the testing, monitoring and analysis of Web Services regarding different Security Configurations, concepts and infrastructure components. Since Security policies are hard to understand and even harder to codify, we foster a model-driven approach to simplify the creation of Security Configurations. Our model-driven approach enables the definition of Security requirements at the modelling layer and facilitates a transformation based on Security Configuration patterns.

  • a pattern driven generation of Security policies for service oriented architectures
    International Conference on Web Services, 2010
    Co-Authors: Michael Menzel, Robert Warschofsky, Christoph Meinel
    Abstract:

    Service-oriented Architectures support the provision, discovery, and usage of services in different application contexts. The Web Service specifications provide a technical foundation to implement this paradigm. Moreover, mechanisms are provided to face the new Security challenges raised by SOA. To enable the seamless usage of services, Security requirements can be expressed as Security policies (e.g. WS-Policy and WS-SecurityPolicy) that enable the negotiation of these requirements between clients and services. However, the codification of Security policies is a difficult and error-prone task due to the complexity of the Web Service specifications. In this paper, we introduce our model-driven approach that facilitates the transformation of architecture models annotated with simple Security intentions to Security policies. This transformation is driven by Security Configuration patterns that provide expert knowledge on Web Service Security. Therefore, we will introduce a formalised pattern structure and a domain-specific language to specify these patterns.

  • Security requirements specification in service-oriented business process management
    Proceedings - International Conference on Availability Reliability and Security ARES 2009, 2009
    Co-Authors: Michael Menzel, Ivonne Thomas, Christoph Meinel
    Abstract:

    Service-oriented Architectures deliver a flexible infrastructure to allow independently developed software components to communicate in a seamless manner. In the scope of organisational workflows, SOA provides a suitable foundation to execute business processes as an orchestration of multiple independent services. Along with the increased connectivity, the corresponding Security risks rise exponentially. However, Security requirements are usually defined on a technical level, rather than on an organisational level that would provide a comprehensive view on the participants, the assets and their relationships regarding Security. In this paper, we propose an approach to describe Security requirements at the business process layer and their translation to concrete Security Configuration for service-based systems. We introduce Security elements for business process modelling which allow to evaluate the trustworthiness of participants based on a rating of enterprise assets and to express Security intentions such as confidentiality or integrity on an abstract level. Our aim is to facilitate the generation of Security Configurations based on the modelled requirements. For this purpose, we foster a model-driven approach: Information at the modelling layer is gathered and translated to a domain-independent Security model. Concrete protocols and Security mechanisms are resolved based on a Security pattern system that is introduced in the course of this paper.

Raouf Boutaba - One of the best experts on this subject based on the ideXlab platform.

  • Security Configuration management in intrusion detection and prevention systems
    International Journal of Security and Networks, 2012
    Co-Authors: Khalid Alsubhi, Yassir Alhazmi, Nizar Bouabdallah, Raouf Boutaba
    Abstract:

    This paper aims to study the impact of Security enforcement levels on the performance and usability of an enterprise information system. We develop a new analytical model to investigate the relationship between the Intrusion Detection and Prevention System performance and the rules mode selection. In particular, we analyze the IDPS rule-checking process along with its consequent action on the resulting Security of the network and on the average service time per event. Simulation was conducted to validate our performance analysis study. The results demonstrate that it is desirable to strike a balance between system Security and network performance.

  • Performance analysis in Intrusion Detection and Prevention Systems
    12th IFIP IEEE International Symposium on Integrated Network Management (IM 2011) and Workshops, 2011
    Co-Authors: Khalid Alsubhi, Nizar Bouabdallah, Raouf Boutaba
    Abstract:

    Intrusion Detection and/or Prevention Systems (IDPS) represent an important line of defense against a variety of attacks that can compromise the Security and proper functioning of an enterprise information system. Although many IDPS systems have been proposed, their appropriate Configuration and control for effective attacks detection/prevention and efficient resources consumption has always been challenging. The evaluation of the IDPS performance for any given Security Configuration is a crucial step for improving real-time capability. This paper aims to analyze the impact of Security enforcement levels on the performance and usability of an enterprise information system. We develop a new analytical model to investigate the relationship between the IDPS performance and the rules mode selection. In particular, we analyze the IDPS rule-checking process along with its consequent action (i.e., alert or drop) on the resulting Security of the network, and on the average service time per event. Simulation was conducted to validate our performance analysis study. Our results show that applying different sets of rules categories and Configuration parameters impacts average service time and affects system Security. The results demonstrate that it is desirable to strike a balance between system Security and network performance.

  • Policy-based Security Configuration management application to intrusion detection and prevention
    IEEE International Conference on Communications, 2009
    Co-Authors: Khalid Alsubhi, Issam Aib, Jérôme François, Raouf Boutaba
    Abstract:

    Intrusion Detection and/or Prevention Systems (IDPS) represent an important line of defense against the variety of attacks that can compromise the Security and well functioning of an enterprise information system. IDPSes can be network or host-based and can collaborate in order to provide better detections of malicious traffic. Although several IDPS systems have been proposed, their appropriate Configuration and control for effective detection and prevention of attacks has always been far from trivial. Another concern is related to the slowing down of system performance when maximum Security is applied, hence the need to trade off between Security enforcement levels and the performance and usability of an enterprise information system. In this paper we motivate the need for and present a policy-based framework for the Configuration and control of the Security enforcement mechanisms of an enterprise information system. The approach is based on dynamic adaptation of Security measures based on the assessment of system vulnerability and threat prediction and provides several levels of attack containment. As an application, we have implemented a dynamic policy-based adaptation mechanism between the Snort signature-based IDPS and the light weight anomaly-based Fire Collaborator IDS. Experiments conducted over the DARPA 2000 and 1999 intrusion detection evaluation datasets show the viability of our framework.

Michiaki Tatsubori - One of the best experts on this subject based on the ideXlab platform.

  • methodology and tools for end to end soa Security Configurations
    IEEE Congress on Services, 2008
    Co-Authors: Fumiko Satoh, Michiaki Tatsubori, Yuichi Nakamura, Nirmal K Mukhi, K Ono
    Abstract:

    The Configuration of non-functional requirements, such as Security, has become important for SOA applications, but the Configuration process has not been discussed comprehensively. In current development processes, the Security requirements are not considered in upstream phases and a developer at a downstream phase is responsible for writing the Security Configuration. However, configuring Security requirements properly is quite difficult for developers because the SOA Security is cross-domain and all required information is not available in the downstream phase. To resolve this problem, we clarify how to configure Security in the SOA application development process, and define the developer's roles in each phase. Additionally, supporting technologies to generate Security Configurations are proposed: Model-Driven Security and Pattern-based Policy Configuration. Our contribution is proposing a methodology for end-to-end Security Configuration for SOA applications and tools for generating detailed Security Configurations from the requirements specified in upstream phases model transformations, making it possible to configure Security properly without increasing developers' workloads.

  • web services Security Configuration in a service oriented architecture
    The Web Conference, 2005
    Co-Authors: Takeshi Imamura, Michiaki Tatsubori, Yuichi Nakamura, Christopher J Giblin
    Abstract:

    Security is one of the major concerns when developing mission-critical business applications, and this concern motivated the Web Services Security specifications. However, the existing tools to configure the Security properties of Web Services give a technology-oriented view; only assisting in choosing data to encrypt and the encryption algorithms to use. A user must manually bridge the gap between the Security requirements and the Configuration, which could cause extra Configuration costs and lead to potential misConfiguration hazards. To ease this situation, we came up with refining Security requirements from business to technology, leveraging the concepts of Service-Oriented Architecture (SOA) and Model-Driven Architecture (MDA). Security requirements are gradually transformed to more detailed ones or countermeasures by bridging the gap between them by using best practice patterns.

  • best practice patterns and tool support for configuring secure web services messaging
    International Conference on Web Services, 2004
    Co-Authors: Michiaki Tatsubori, Takeshi Imamura, Yuhichi Nakamura
    Abstract:

    This paper presents an emerging tool for Security Configuration of service-oriented architectures with Web Services. Security is a major concern when implementing mission-critical business transactions and such concern motivated the development of Web Services Security (WS-Security). However, the existing tools for configuring the Security properties of Web Services give a technology-oriented view, and only assist in choosing the data to encrypt and selecting an encryption algorithm. The users must construct their own mental models of how the Security Configurations actually relate to business policies. In contrast, the tool described here gives a simplified, business-policy-oriented view. It models the messaging with customers and business partners, lists various threats, and presents best-practice Security patterns against the threats. A user can select among variations on the basic patterns according to the business policies, and then apply them to the messaging model through the GUI. The result of the pattern application is described in the Web Services Security Policy Language (WS-Security Policy).

Robert Warschofsky - One of the best experts on this subject based on the ideXlab platform.

  • a pattern driven generation of Security policies for service oriented architectures
    International Conference on Web Services, 2010
    Co-Authors: Michael Menzel, Robert Warschofsky, Christoph Meinel
    Abstract:

    Service-oriented Architectures support the provision, discovery, and usage of services in different application contexts. The Web Service specifications provide a technical foundation to implement this paradigm. Moreover, mechanisms are provided to face the new Security challenges raised by SOA. To enable the seamless usage of services, Security requirements can be expressed as Security policies (e.g. WS-Policy and WS-SecurityPolicy) that enable the negotiation of these requirements between clients and services. However, the codification of Security policies is a difficult and error-prone task due to the complexity of the Web Service specifications. In this paper, we introduce our model-driven approach that facilitates the transformation of architecture models annotated with simple Security intentions to Security policies. This transformation is driven by Security Configuration patterns that provide expert knowledge on Web Service Security. Therefore, we will introduce a formalised pattern structure and a domain-specific language to specify these patterns.

  • the service Security lab a model driven platform to compose and explore service Security in the cloud
    World Congress on Services, 2010
    Co-Authors: Michael Menzel, Ivonne Thomas, Robert Warschofsky, Christian Willems, Christoph Meinel
    Abstract:

    Cloud computing enables the provisioning of dynamically scalable resources as a service. Next to cloud computing, the paradigm of Service-oriented Architectures emerged to facilitate the provisioning of functionality as services. While both concepts are complementary, their combination enables the flexible provisioning and consumption of independently scalable services. These approaches come along with new Security risks that require the usage of identity and access management solutions and information protection. The requirements concerning Security mechanisms, protocols and options are stated in Security policies that configure the interaction between services and clients in a system. In this paper, we present our cloud-based Service Security Lab that supports the on-demand creation and orchestration of composed applications and services. Our cloud platform enables the testing, monitoring and analysis of Web Services regarding different Security Configurations, concepts and infrastructure components. Since Security policies are hard to understand and even harder to codify, we foster a model-driven approach to simplify the creation of Security Configurations. Our model-driven approach enables the definition of Security requirements at the modelling layer and facilitates a transformation based on Security Configuration patterns.