The Experts below are selected from a list of 177 Experts worldwide ranked by ideXlab platform
Csilla Farkas - One of the best experts on this subject based on the ideXlab platform.
-
Ontology Guided XML Security Engine
Journal of Intelligent Information Systems, 2004Co-Authors: Andrei Stoica, Csilla FarkasAbstract:In this paper we study the Security impact of large-scale, semantically enhanced data processing in distributed databases. We present an ontology-supported Security model to detect undesired inferences via replicated XML data. Our model is able to detect inconsistent Security classifications of replicated data. We propose the Ontology Guided XML Security Engine (Oxsegin) architecture to identify data items exposed to ontology-based inference attacks. The main technical contribution is the development of the Probabilistic Inference Engine used by Oxsegin. The inference Engine operates on DTD files, corresponding to XML documents, and detects tags that are ontologically equivalent, i.e., can be abstracted to the same concept in the ontology, but may be different syntactically. Potential illegal inferences occur when two ontologically equivalient tags have contradictory Security classifications. These tags are marked with a Security violation pointer (SVP). Confidence level coefficients, attached to every Security violation pointer, differentiate among the detected SVPs based on the system's confidence in an indicated inference.
-
Ontology guided XML Security Engine
Journal of Intelligent Information Systems, 2004Co-Authors: Andrei G. Stoica, Csilla FarkasAbstract:In this paper we study the Security impact of large scale, semantically enhanced data processing in distributed databases. We present an ontology-supported Security model to detect undesired inferences via replicated XML data. Our model is able to detect inconsistent Security classifications of replicated data. Wc propose the Ontology Guided XML Security Engine (Oxsegin) architecture to identify data items exposed to ontology-based inference attacks. The main technical contribution is the development of the Probabilistic Inference Engine used by Oxsegin. The inference Engine operates on DTD files, corresponding to XML documents, and detects tags that are ontologically equivalent, i.e., can be abstracted to the same concept in the ontology, but may be different syntactically. Potential illegal inferences occur when two ontologically equivalent tags have contradictory Security classifications. These tags are marked with a Security violation pointer (SVP). Confidence level coefficients, attached to every Security violation pointer, differentiate among the detected SVPs based on the system's confidence in an indicated inference.
-
Integrated Security framework for semantically enhanced semi-structured data
2004Co-Authors: Andrei G. Stoica, Csilla FarkasAbstract:This dissertation studies the inference problem in the context of Semantic Web and proposes the design and implementation of a Security framework to detect and prevent unwanted inferences. The proposed Security solution has two main functionalities: prevent undesired inferences via XML query answers, and detect undesired inferences via correlating public domain information. The undesired inference via XML query answers violates data confidentiality requirement by disclosing unauthorized XML document structure. The undesired inference via public domain information violates data confidentiality requirement by correlating related public data to disclose unauthorized information. There is a separate module for each function of the Security Engine: the data access control module and the global data privacy control module. The data access control module provides access to the XML database using secure and semantically consistent partial views. The views are constructed by changing the structure of the XML document to remove vulnerabilities to undesired inferences. The changes in the XML structure are guided by metadata representing semantic data correlations. The module for global data privacy control places the XML document in the context of public information selected from the same knowledge domain. The Security Engine performs two inference procedures to detect inference channels that lead from the public information to the protected data within an organization. The inference procedures detect conflicting Security classifications from (1) semantically similar replicated information, and (2) semantically similar replicated data correlations. An ontology concept hierarchy defines the metadata that guides the inference process. The data inference from the replicated and correlated data inference procedures is formalized in Prolog. The Prolog knowledge base is a representation of the XML documents and the associated ontology. This research is the first step towards developing Security mechanisms to protect semantically enhanced, distributed information from indirect disclosure. In the Semantic Web, the ontologies provide the conceptualization for the external knowledge modeling to prevent inference channels that violate the privacy of protected data.
-
DBSec - Correlated Data Inference
Data and Applications Security XVII, 2004Co-Authors: Csilla Farkas, Andrei G. StoicaAbstract:In this paper we examine undesired inferences in distributed XML documents. An undesired inference is a chain of reasoning that leads to protected data of an organization or an individual, using only intentionally disclosed information. We propose a framework, called Ontology guided XML Security Engine (Oxsegin), to detect and prevent undesired inference attacks. Oxsegin uses the Correlated Inference Algorithm to detect sensitive associations that may exist at a lower Security levels. The system operates on the DTD’s of XML documents to identify data associations and the corresponding Security classifications. Oxsegin uses an ontological class-hierarchy to identify associations with two or more conflicting classifications. A Security Violation Pointer (SVP) is assigned to a set of tags that contribute to the conflicting classification. The likelihood of a detected Security violation is measured by a confidence level coefficient attached to the SVPs.
Andrei Stoica - One of the best experts on this subject based on the ideXlab platform.
-
Ontology Guided XML Security Engine
Journal of Intelligent Information Systems, 2004Co-Authors: Andrei Stoica, Csilla FarkasAbstract:In this paper we study the Security impact of large-scale, semantically enhanced data processing in distributed databases. We present an ontology-supported Security model to detect undesired inferences via replicated XML data. Our model is able to detect inconsistent Security classifications of replicated data. We propose the Ontology Guided XML Security Engine (Oxsegin) architecture to identify data items exposed to ontology-based inference attacks. The main technical contribution is the development of the Probabilistic Inference Engine used by Oxsegin. The inference Engine operates on DTD files, corresponding to XML documents, and detects tags that are ontologically equivalent, i.e., can be abstracted to the same concept in the ontology, but may be different syntactically. Potential illegal inferences occur when two ontologically equivalient tags have contradictory Security classifications. These tags are marked with a Security violation pointer (SVP). Confidence level coefficients, attached to every Security violation pointer, differentiate among the detected SVPs based on the system's confidence in an indicated inference.
Mohd Fadzil Hassan - One of the best experts on this subject based on the ideXlab platform.
-
Adaptive Security architecture for protecting RESTful web services in enterprise computing environment
Service Oriented Computing and Applications, 2018Co-Authors: Mohamed Ibrahim Beer, Mohd Fadzil HassanAbstract:In this modern era of enterprise computing, the enterprise application integration (EAI) is a well-known industry-recognized architectural principle that is built based on loosely coupled application architecture, where service-oriented architecture (SOA) is the architectural pattern for the implementation of EAI, whose computational elements are called as “services.” Though SOA can be implemented in a wide range of technologies, the web services implementation of SOA becomes the current selective choice due to its simplicity that works on basic Internet protocols. Web service technology defines several supporting protocols and specifications such as SOAP and WSDL for communication with client and server for data interchange. A new architectural paradigm has emerged in SOA in recent years called REpresentational State Transfer (REST) that is also used to integrate loosely coupled service components, named RESTful web services, by system integration consortiums. This SOA implementation does not possess adequate Security solutions within it, and its Security is completely dependent on network/transport layer Security that is obsolete owing to latest web technologies such as Web 2.0 and its upgraded version, Web 3.0. Vendor Security products have major implementation constraints such as they need secured organizational environment and breach to SOA specifications, hence introducing new vulnerabilities. Herein, we examine the Security vulnerabilities of RESTful web services in the view of popular OWASP rating methodologies and analyze the gaps in the existing Security solutions. We hence propose an adaptive Security solution for REST that uses public key infrastructure techniques to enhance the Security architecture. The proposed Security architecture is constructed as an adaptive way-forward Internet-of-Things (IoT) friendly Security solution that is comprised of three cyclic parts: learn, predict and prevent. A novel Security component named “intelligent Security Engine” is introduced which learns the possible occurrences of Security threats on SOA using artificial neural networks learning algorithms, then it predicts the potential attacks on SOA based on obtained results by the developed theoretical Security model, and the written algorithms as part of Security solution prevent the SOA attacks. This paper is written to present one of such algorithms to prevent SOA attacks on RESTful web services along the discussion on the obtained results of the conducted proof-of-concept on the real-time SOA environment. A comparison of the proposed system with other competing solutions demonstrates its superiority.
-
CONSTRUCTION OF CUSTOMIZABLE SOA Security FRAMEWORK USING ARTIFICIAL NEURAL NETWORKS
Jurnal Teknologi, 2016Co-Authors: Mohamed Ibrahim B, Mohd Fadzil HassanAbstract:The Web Services technology for the implementation of Service Oriented Architecture (SOA) is the preferred choice in the current era of Enterprise Application Integration (EAI). As Web Services architecture is dynamic and loosely coupled, Security aspects must be considered thoroughly at the time of designing. It is prone for attacks as it uses XML format for data exchange, which is a plain text. A novel Security component named “Intelligent Security Engine (ISE)” is introduced into the proposed framework which incorporates Artificial Neural Networks (ANN) Learning Techniques for supervised knowledge acquisition on Security threats of SOA. Thus, the proposed Security framework is capable in the identification of future Security vulnerabilities of SOA and can work effectively even for in-secured cross organizational EAI environment.
Andrei G. Stoica - One of the best experts on this subject based on the ideXlab platform.
-
Ontology guided XML Security Engine
Journal of Intelligent Information Systems, 2004Co-Authors: Andrei G. Stoica, Csilla FarkasAbstract:In this paper we study the Security impact of large scale, semantically enhanced data processing in distributed databases. We present an ontology-supported Security model to detect undesired inferences via replicated XML data. Our model is able to detect inconsistent Security classifications of replicated data. Wc propose the Ontology Guided XML Security Engine (Oxsegin) architecture to identify data items exposed to ontology-based inference attacks. The main technical contribution is the development of the Probabilistic Inference Engine used by Oxsegin. The inference Engine operates on DTD files, corresponding to XML documents, and detects tags that are ontologically equivalent, i.e., can be abstracted to the same concept in the ontology, but may be different syntactically. Potential illegal inferences occur when two ontologically equivalent tags have contradictory Security classifications. These tags are marked with a Security violation pointer (SVP). Confidence level coefficients, attached to every Security violation pointer, differentiate among the detected SVPs based on the system's confidence in an indicated inference.
-
Integrated Security framework for semantically enhanced semi-structured data
2004Co-Authors: Andrei G. Stoica, Csilla FarkasAbstract:This dissertation studies the inference problem in the context of Semantic Web and proposes the design and implementation of a Security framework to detect and prevent unwanted inferences. The proposed Security solution has two main functionalities: prevent undesired inferences via XML query answers, and detect undesired inferences via correlating public domain information. The undesired inference via XML query answers violates data confidentiality requirement by disclosing unauthorized XML document structure. The undesired inference via public domain information violates data confidentiality requirement by correlating related public data to disclose unauthorized information. There is a separate module for each function of the Security Engine: the data access control module and the global data privacy control module. The data access control module provides access to the XML database using secure and semantically consistent partial views. The views are constructed by changing the structure of the XML document to remove vulnerabilities to undesired inferences. The changes in the XML structure are guided by metadata representing semantic data correlations. The module for global data privacy control places the XML document in the context of public information selected from the same knowledge domain. The Security Engine performs two inference procedures to detect inference channels that lead from the public information to the protected data within an organization. The inference procedures detect conflicting Security classifications from (1) semantically similar replicated information, and (2) semantically similar replicated data correlations. An ontology concept hierarchy defines the metadata that guides the inference process. The data inference from the replicated and correlated data inference procedures is formalized in Prolog. The Prolog knowledge base is a representation of the XML documents and the associated ontology. This research is the first step towards developing Security mechanisms to protect semantically enhanced, distributed information from indirect disclosure. In the Semantic Web, the ontologies provide the conceptualization for the external knowledge modeling to prevent inference channels that violate the privacy of protected data.
-
DBSec - Correlated Data Inference
Data and Applications Security XVII, 2004Co-Authors: Csilla Farkas, Andrei G. StoicaAbstract:In this paper we examine undesired inferences in distributed XML documents. An undesired inference is a chain of reasoning that leads to protected data of an organization or an individual, using only intentionally disclosed information. We propose a framework, called Ontology guided XML Security Engine (Oxsegin), to detect and prevent undesired inference attacks. Oxsegin uses the Correlated Inference Algorithm to detect sensitive associations that may exist at a lower Security levels. The system operates on the DTD’s of XML documents to identify data associations and the corresponding Security classifications. Oxsegin uses an ontological class-hierarchy to identify associations with two or more conflicting classifications. A Security Violation Pointer (SVP) is assigned to a set of tags that contribute to the conflicting classification. The likelihood of a detected Security violation is measured by a confidence level coefficient attached to the SVPs.
Sai Kiran Cherupally - One of the best experts on this subject based on the ideXlab platform.
-
A Smart Hardware Security Engine Combining Entropy Sources of ECG, HRV, and SRAM PUF for Authentication and Secret Key Generation
IEEE Journal of Solid-state Circuits, 2020Co-Authors: Sai Kiran Cherupally, Shihui Yin, Deepak Kadetotad, Chisung Bae, Sang Joon Kim, Jae-sun SeoAbstract:Securing personal data in wearable devices is becoming a crucial necessity as wearable devices are being deployed ubiquitously, which inadvertently exposes them to more sophisticated adversarial attacks. Although authentication systems using a single-entropy source, such as fingerprint or iris, are being used widely, successful spoofing attacks have been made, which show such systems’ vulnerability. To mitigate these issues, new biometric modalities [e.g., electrocardiogram (ECG) and photoplethysmogram (PPG)], as well as multifactor authentication/Security Engine designs, are being investigated. In this work, we present a new smart hardware Security Engine that combines three different sources of entropy, ECG, heart rate variability (HRV), and SRAM-based physical unclonable function (PUF) to perform real-time authentication and generate unique/random signatures. Such hybrid signatures vary person-to-person, device-to-device, and over time, which significantly reduces the scope of an attack and enables secure personal device authentication as well as secret random key generation. The prototype chip fabricated in 65-nm LP CMOS consumes $4.04~\mu \text{W}$ at 0.6 V for real-time authentication. Compared with ECG-only authentication, the average equal error rate of multi-source authentication is reduced by $7\times $ down to 0.2375% for a 741-subject in-house ECG database. The generalization capability of the hardware was also tested by evaluating equal error rate (EER) values using other ECG databases available online. Also, 256-bit keys generated by optimally combining ECG, HRV, and PUF values fully pass nine NIST randomness tests.
-
A-SSCC - A Smart Hardware Security Engine Combining Entropy Sources of ECG, HRV and SRAM PUF for Authentication and Secret Key Generation
2019 IEEE Asian Solid-State Circuits Conference (A-SSCC), 2019Co-Authors: Sai Kiran Cherupally, Shihui Yin, Deepak Kadetotad, Chisung Bae, Sang Joon Kim, Jae-sun SeoAbstract:We present a smart hardware Security Engine that combines three different sources of entropy, electrocardiogram (ECG), heart rate variability (HRV) and SRAM-based physical unclonable function (PUF), to perform real-time authentication and generate unique and random signatures. Such hybrid signatures vary person-to-person, device-to-device, and over time, and hence can be used for personal device authentication as well as secret random key generation, significantly reducing the scope of an attack. The prototype chip fabricated in 65nm LP CMOS consumes 4.04 µW at 0.6 V for real-time authentication. Compared to ECG-only authentication, the equal error rate of multi-source authentication is reduced by 18.9X down to 0.09% for an in-house ECG database. 256-bit secret keys generated by optimally combining ECG, HRV and PUF values pass NIST randomness tests with 100% pass rate.
-
A Smart Hardware Security Engine Combining Entropy Sources of ECG, HRV and SRAM PUF for Authentication and Secret Key Generation
2019 IEEE Asian Solid-State Circuits Conference (A-SSCC), 2019Co-Authors: Sai Kiran Cherupally, Deepak KadetotadAbstract:We present a smart hardware Security Engine that combines three different sources of entropy, electrocardiogram (ECG), heart rate variability (HRV) and SRAM-based physical unclonable function (PUF), to perform real-time authentication and generate unique and random signatures. Such hybrid signatures vary person-to-person, device-to-device, and over time, and hence can be used for personal device authentication as well as secret random key generation, significantly reducing the scope of an attack. The prototype chip fabricated in 65nm LP CMOS consumes 4.04 μW at 0.6 V for real-time authentication. Compared to ECG-only authentication, the equal error rate of multi-source authentication is reduced by 18.9X down to 0.09% for an in-house ECG database. 256-bit secret keys generated by optimally combining ECG, HRV and PUF values pass NIST randomness tests with 100% pass rate.