VLDB 2026 Research / reviewers in the wild / expert
Mike Surridge
dblp:08/2722 · also Michael Surridge
· DBLP profile ↗
26ranked-venue papers
4as first author
2since 2021 · last 2025
0000-0003-1485-7024ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 10 · 1 first-authorSecurity and privacy · 6 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 6 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 1 first-authorComputer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Systematisation of Security Risk Knowledge Across Different Domains: A Case Study of Security Implications of Medical Devices
Laura Carmichael, Stephen Taylor 0002, Samuel M. Senior, Mike Surridge, Gencer Erdogan, Simeon Tverdal |
ICISSP (1) | 4 |
| 2025 | Knowledge Modelling for Automated Risk Assessment of Cybersecurity and Indirect Patient Harms in Medical ContextsabstractThe use of connected medical and in vitro diagnostic devices (CMD&IVD) as part of individual care and self-care practices is growing. Significant attention is needed to ensure that CMD&IVD remain safe and secure throughout their lifecycles — as if a cybersecurity incident were to occur involving these devices, it is possible that in some cases harm may be brought to the person using them. For the effective safety management of these devices, risk assessment is needed that covers both the cybersecurity and patient safety domains. To this end, we present knowledge modelling of indirect patient harms (e.g., misdiagnosis, delayed treatment etc.) resulting from cybersecurity compromises, along with a methodology for encoding these into a previously developed automated cybersecurity risk assessment tool, to begin to bridge the gap between automated risk assessment related to cybersecurity and patient safety. Samuel M. Senior, Laura Carmichael, Stephen Taylor 0002, Mike Surridge, Xavier Vilalta |
ICISSP (1) | 4 |
| 2018 | Identifying Privacy Risks in Distributed Data Services: A Model-Driven ApproachabstractOnline services are becoming increasingly data-centric; they collect, process, analyze and anonymously disclose growing amounts of personal data. It is crucial that such systems are engineered in a privacy-aware manner in order to satisfy both the privacy requirements of the user, and the legal privacy regulations that the system operates under. How can system developers be better supported to create privacy-aware systems and help them to understand and identify privacy risks? Model-Driven Engineering (MDE) offers a principled approach to engineer systems software. The capture of shared domain knowledge in models and corresponding tool support can increase the developers' understanding. In this paper, we argue for the application of MDE approaches to engineer privacy-aware systems. We present a general purpose privacy model and methodology that can be used to analyse and identify privacy risks in systems that comprise both access control and data pseudonymization enforcement technologies. We evaluate this method using a case-study based approach and show how the model can be applied to engineer privacy-aware systems and privacy policies that reduce the risk of unintended disclosure. Paul Grace, Daniel Burns, Geoffrey Neumann, John Brian Pickering, Panos Melas, Mike Surridge |
ICDCS | 6 |
| 2017 | Towards a Model of User-centered Privacy PreservationabstractThe growth in cloud-based services tailored for users means more and more personal data is being exploited, and with this comes the need to better handle user privacy. Software technologies concentrating on privacy preservation typically present a one-size fits all solution. However, users have different viewpoints of what privacy means to them and therefore, configurable and dynamic privacy preserving solutions have the potential to create useful and tailored services without breaching any user's privacy. In this paper, we present a model of user-centered privacy that can be used to analyse a service's behaviour against user preferences, such that a user can be informed of the privacy implications of that service and what fine-grained actions they can take to maintain their privacy. We show through study that the user-based privacy model can: i) provide customizable privacy aligned with user needs; and ii) identify potential privacy breaches. Paul Grace, Mike Surridge |
ARES | 2 |
| 2014 | Maintaining Trustworthiness of Socio-Technical Systems at Run-Time
Nazila Gol Mohammadi, Torsten Bandyszak, Micha Moffie, Thorsten Weyer, Costas Kalogiros, Bassem I. Nasser, Mike Surridge |
TrustBus | 8 |
| 2013 | Run-Time Risk Management in Adaptive ICT SystemsabstractWe will present results of the SERSCIS project related to risk management and mitigation strategies in adaptive multi-stakeholder ICT systems. The SERSCIS approach involves using semantic threat models to support automated design-time threat identification and mitigation analysis. The focus of this paper is the use of these models at run-time for automated threat detection and diagnosis. This is based on a combination of semantic reasoning and Bayesian inference applied to run-time system monitoring data. The resulting dynamic risk management approach is compared to a conventional ISO 27000 type approach, and validation test results presented from an Airport Collaborative Decision Making (A-CDM) scenario involving data exchange between multiple airport service providers. Mike Surridge, Bassem I. Nasser, Ajay Chakravarthy, Panos Melas |
ARES | 1 |
| 2013 | Modelling Access Propagation in Dynamic SystemsabstractAccess control is a critical feature of many systems, including networks of services, processes within a computer, and objects within a running process. The security consequences of a particular architecture or access control policy are often difficult to determine, especially where some components are not under our control, where components are created dynamically, or where access policies are updated dynamically. The SERSCIS Access Modeller (SAM) takes a model of a system and explores how access can propagate through it. It can both prove defined safety properties and discover unwanted properties. By defining expected behaviours, recording the results as a baseline, and then introducing untrusted actors, SAM can discover a wide variety of design flaws. SAM is designed to handle dynamic systems (i.e., at runtime, new objects are created and access policies modified) and systems where some objects are not trusted. It extends previous approaches such as Scollar and Authodox to provide a programmer-friendly syntax for specifying behaviour, and allows modelling of services with mutually suspicious clients. Taking the Confused Deputy example from Authodox we show that SAM detects the attack automatically; using a web-based backup service, we show how to model RBAC systems, detecting a missing validation check; and using a proxy certificate system, we show how to extend it to model new access mechanisms. On discovering that a library fails to follow an RFC precisely, we re-evaluate our existing models under the new assumption and discover that the proxy certificate design is not safe with this library. Thomas Leonard, Martin Hall-May, Mike Surridge |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2012 | A business-oriented Cloud federation model for real-time applications
Xiaoyu Yang 0001, Bassem I. Nasser, Mike Surridge, Stuart E. Middleton |
Future Gener. Comput. Syst. | 3 |
| 2010 | On-Demand Dynamic Security for Risk-Based Secure Collaboration in CloudsabstractIndustrial adoption of cloud computing for collaborative business processes is limited by their ability to meet inter-enterprise security requirements. Although some clouds offerings comply with security standards, no solution today allows businesses to assess security compliance of applications at the business level and dynamically link to security countermeasures on-demand. In this paper, we present a Platform-as-a-Service infrastructure that combines semantic security risk management tools with dynamic web service policy frameworks to support the mitigation of security threats throughout the lifecycle of a service-oriented application deployed within the cloud. The platform address the need to model security requirements, dynamically provision and configure security services and link operational security events to vulnerabilities and impact assessments at the business level. The Platform has been evaluated using a collaborative engineering design scenario and a proof-of-concept deployed at a multi-tenant cloud as part of the UK CFMS project. The work is being further enhanced in the European Funded SERSCIS project. Stuart Bertram, Mike J. Boniface, Mike Surridge, Neil Briscombe, Martin Hall-May |
IEEE CLOUD | 3 |
| 2010 | Resilient Critical Infrastructure Management Using Service Oriented ArchitectureabstractThe SERSCIS project aims to support the use of interconnected systems of services in Critical Infrastructure (CI) applications. The problem of system interconnectedness is aptly demonstrated by 'Airport Collaborative Decision Making' (A-CDM). Failure or underperformance of any of the interlinked ICT systems may compromise the ability of airports to plan their use of resources to sustain high levels of air traffic, or to provide accurate aircraft movement forecasts to the wider European air traffic management systems. The proposed solution is to introduce further SERSCIS ICT components to manage dependability and interdependency. These use semantic models of the critical infrastructure, including its ICT services, to identify faults and potential risks and to increase human awareness of them. Semantics allows information and services to be described in such a way that makes them understandable to computers. Thus when a failure (or a threat of failure) is detected, SERSCIS components can take action to manage the consequences, including changing the interdependency relationships between services. In some cases, the components will be able to take action autonomously -- e.g. to manage 'local' issues such as the allocation of CPU time to maintain service performance, or the selection of services where there are redundant sources available. In other cases the components will alert human operators so they can take action instead. The goal of this paper is to describe a Service Oriented Architecture (SOA) that can be used to address the management of ICT components and interdependencies in critical infrastructure systems. Martin Hall-May, Mike Surridge |
CISIS | 2 |
| 2007 | Cross-Middleware Interoperability in Distributed Concurrent EngineeringabstractSecure, distributed collaboration between different organizations is a key challenge in Grid computing today. The GDCD project has produced a grid-based demonstrator virtual collaborative facility (VCF) for the European Space Agency. The purpose of this work is to show the potential of Grid technology to support fully distributed concurrent design, while addressing practical considerations including network security, interoperability, and integration of legacy applications. The VCF allows domain engineers to use the concurrent design methodology in a distributed fashion to perform studies for future space missions. To demonstrate the interoperability and integration capabilities of Grid computing in concurrent design, we developed prototype VCF components based on ESA's current excel-based concurrent design facility (a non-distributed environment), using a STEP-compliant database that stores design parameters. The database was exposed as a secure GRIA 5.1 Grid service, whilst a .NET/WSE3.0-based library was developed to enable secure communication between the Excel client and STEP database. Ellis Rowland Watkins, Mark McArdle, Thomas Leonard, Mike Surridge |
eScience | 4 |
| 2007 | Contextualized B2B Registries
Uwe Radetzki, Mike J. Boniface, Mike Surridge |
ICSOC | 3 |
| 2007 | Quality of Service Negotiation for Commercial Medical Grid Services
Stuart E. Middleton, Mike Surridge, Siegfried Benkner, Gerhard Engelbrecht |
J. Grid Comput. | 2 |
| 2005 | OWL-WS: A Workflow Ontology for Dynamic Grid Service CompositionabstractSemantic grid is becoming a key enabler for next generation grid and the need of supporting process description and enactment, by means of composition of multiple resources, emerged as one of the fundamental requirements. Within NextGRID project, the idea of adopting business processes (expressed as workflow policies) as architectural components in a next generation grid has been developed with the aim of providing architecture with dynamic behaviour and in teroperability. The need of a semantic workflow representation language then emerged and was developed defining an OWLS extension able to support workflow description. The resulting OWL-WS (OWL for workflow and services) ontology allows us modelling concept like abstract and concrete services and workflows according to a semantic workflow model also enabling specification of higher-order workflows and semantic service grouping. This language is being used for specifying adaptive business processes (policy) that are used as evaluation and binding mechanisms by a workflow enactment engine. Stefano Beco, Barbara Cantalupo, Ludovico Giammarino, Nikolaos Matskanis, Mike Surridge |
e-Science | 5 |
| 2005 | Grid-Enabling an Existing Instrument-Based National ServiceabstractRecent work by the `CombeChem' project together with the UK National Crystallography Service (NCS) has integrated the NCS into an e-Science environment. The existing high-throughput crystallography facility is enhanced by on-line feedback with the ability to monitor and steer diffraction experiments remotely. Security mechanisms are used to determine authorisation attributes and hence to allow user interaction at appropriate stages, together with access of a database recording the status of the submitted samples. The user can monitor the position of their samples, be alerted to all stages from submission to experiment and then analysis, visualise raw data as it is generated, be involved in the key decision-making during the parameterisation and initialization of the experiment and then track the data collection to ensure its successful completion. Results data are staged to a secure area and made available for download (either the raw diffraction data or a refined structure generated by NCS staff) Jeremy G. Frey, Sam Peppe, Mike Surridge, Ken Meacham, Simon J. Coles, Michael B. Hursthouse, Mark E. Light, Hugo R. Mills, David De Roure, Graham Smith, Ed Zaluska |
e-Science | 3 |
| 2005 | Experiences with GRIA - Industrial Applications on a Web Services GridabstractThe GRIA project set out to make the grid usable by industry. The GRIA middleware is based on Web services, and designed to meet the needs of industry for security and business-to-business (B2B) service procurement and operation. It provides well-defined B2B models for accounting and QoS agreement, and proxy-free delegation to support account management and service federation. The GRIA v3 software is now being used by industry. By taking a business-oriented approach independent of the evolving Open Grid Services Architecture proposals from the Global Grid Forum, GRIA has demonstrated the need for a wider understanding of virtual organizations (VOs). Traditional academic VOs are persistent, resourceful and have logically centralized, membership-oriented management structures. In contrast, the GRIA experience has been that business VOs are likely to be project-focused and have distributed process-oriented management structures Mike Surridge, Stephen Taylor 0002, David De Roure, Ed Zaluska |
e-Science | 1 |
| 2005 | The role of performance engineering techniques in the context of the GridabstractAbstract Performance engineering can be described as a collection of techniques and methodologies whose aim is to provide reliable prediction, measurement and validation of the performance of applications on a variety of computing platforms. This paper reviews techniques for performance estimation and performance engineering developed at the University of Southampton and presents application case studies in task scheduling for engineering meta‐applications, and capacity engineering for a financial transaction processing system. These show that it is important to describe performance in terms of a resource model, and that the choice of models may have to trade accuracy for utility in addressing the operational issues. We then present work from the on‐going EU funded Grid project GRIA, and show how lessons learned from the earlier work have been applied to support a viable business model for Grid service delivery to a specified quality of service level. The key in this case is to accept the limitations of performance estimation methods, and design business models that take these limitations into account rather than attempting to provide hard guarantees over performance. We conclude by identifying some of the key lessons learned in the course of our work over many years and suggest possible directions for future investigations. Copyright © 2005 John Wiley & Sons, Ltd. Anthony J. G. Hey, Juri Papay, Mike Surridge |
Concurr. Pract. Exp. | 3 |
| 2004 | Grid Resources for Industrial ApplicationsabstractWe introduce Grid Resources for Industrial Applications (GRIA), a project that aims to enable commercial use of the Grid. GRIA enables service providers to rent out spare CPU cycles, and clients to hire those CPU cycles. Web services play a key role in the architecture of GRIA, chiefly through their interoperability and security features - they provide a well-defined means of limiting clients' access to discrete operations, thus allowing clients to do "work" on a remote application server without giving them full shell access to the server. In this paper, we focus on requirements, business processes and security, and interoperability and standardisation issues raised by this work. We also describe some of the lessons learned through experience of designing, implementing and deploying a prototype system, GRIA vI. Stephen Taylor 0002, Mike Surridge, Darren Marvin |
ICWS | 2 |
| 2004 | Semantic Web Service Interaction Protocols: An Ontological Approach
Ronald Ashri, Grit Denker, Darren Marvin, Mike Surridge, Terry R. Payne |
ISWC | 4 |
| 2004 | Configuration of distributed message converter systems
Thomas Risse 0001, Karl Aberer, Andreas Wombacher, Mike Surridge, Stephen Taylor 0002 |
Perform. Evaluation | 4 |
| 2003 | Grid Security: Lessons for Peer-to-Peer SystemsabstractThe vision of the Grid is to provide a computational infrastructure supporting flexible, secure, coordinated resource sharing among dynamic collections of individuals, institutions, and resources. The Grid involves access to computer systems and data outside one's own company or institution. Security is therefore a major element in any Grid infrastructure, as it is necessary to ensure that only authorised access is permitted. The early development of the Grid also largely failed to take account of operational realities such as network administrator responsibilities and network devices such as firewalls. We believe that the peer-to-peer community is also likely to face similar conflicts between its decentralized management approach and the day-to-day concerns of those entrusted to maintain our security. We have found that it is necessary to develop a radical solution to some of these problems, including "proxy-free" delegation models and semantically-aware firewalls. The challenge for computer system developers and operators is to allow legitimate users to go about their business, while preventing unauthorised users from perpetrating these various types of abuse. Mike Surridge, Colin Upstill |
Peer-to-Peer Computing | 1 |
| 2001 | Resource Discovery for Dynamic Clusters in Computational GridsabstractWe describe a de-centralised approach to resource management and discovery, based on a community of interacting software agents. Each agent either represents a user application, a resource, or a MatchMaking service. The proposed approach can support dynamic registration of resources and user tasks, facilitating the establishment of dynamic clusters. Resource capability and task requirements are described using an object based data model, enabling new types of devices or new features in existing devices to be identified. A comparison with the Discovery and LookUp services in Jini and TSpaces is also provided. Omer F. Rana, Daniel Bunford-Jones, Kenneth A. Hawick, David W. Walker, Matthew Addis, Mike Surridge |
IPDPS | 6 |
| 2000 | Agent based Resource Discovery for Dynamic Clusters
Omer F. Rana, Daniel Bunford-Jones, David W. Walker, Matthew Addis, Mike Surridge, Kenneth A. Hawick |
CLUSTER | 5 |
| 1999 | Predictive resource management for meta-applications
Nick Floros, Anthony J. G. Hey, K. E. Meacham, Juri Papay, Mike Surridge |
Future Gener. Comput. Syst. | 5 |
| 1998 | Industrial Stochastic Simulations on a European Meta-Computer
Ken Meacham, Nick Floros, Mike Surridge |
Euro-Par | 3 |
| 1996 | A Parallel Molecular Dynamics Simulation Code for Dialkyl Cationic Surfactants
Mike Surridge, D. J. Tildesley, Y. C. Kong, D. B. Adolf |
Parallel Comput. | 1 |