VLDB 2026 Research / reviewers in the wild / expert
Roshan K. Thomas
dblp:09/613
· DBLP profile ↗
21ranked-venue papers
8as first author
0since 2021 · last 2015
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 7 first-authorComputer networks · 2Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Network security · 92% Systems and software security · 8% | |
| Computer networks
1 paper |
Network measurement and analytics · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Performance modeling and evaluation · 100% | |
| Databases, data mining, and information retrieval
1 paper |
Database system architecture and tuning · 77% Data models and query languages · 23% |
Topics — the 7 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › attack strategy
denial-of-service attack |
0.2 | 2 | 2009 | Accurately Measuring Denial of Service in Simulation and Testbed Experiments · IEEE Trans. Dependable Secur. Comput. 2009 When is service really denied?: a user-centric dos metric · SIGMETRICS 2007 |
Network measurement and analytics › network performance measurement
quality of service measurement |
0.1 | 1 | 2007 | When is service really denied?: a user-centric dos metric · SIGMETRICS 2007 |
Performance modeling and evaluation
benchmarking |
0.0 | 1 | 2009 | Accurately Measuring Denial of Service in Simulation and Testbed Experiments · IEEE Trans. Dependable Secur. Comput. 2009 |
Database system architecture and tuning
database security |
0.0 | 1 | 1996 | A Trusted Subject Architecture for Multilevel Secure Object-Oriented Databases · IEEE Trans. Knowl. Data Eng. 1996 |
Network security
covert channel |
0.0 | 1 | 1996 | A Trusted Subject Architecture for Multilevel Secure Object-Oriented Databases · IEEE Trans. Knowl. Data Eng. 1996 |
Systems and software security
multilevel security |
0.0 | 1 | 1996 | A Trusted Subject Architecture for Multilevel Secure Object-Oriented Databases · IEEE Trans. Knowl. Data Eng. 1996 |
Data models and query languages
object-oriented database |
0.0 | 1 | 1996 | A Trusted Subject Architecture for Multilevel Secure Object-Oriented Databases · IEEE Trans. Knowl. Data Eng. 1996 |
Methods — techniques the papers use, named apart from their topics
quality-of-service mapping · 0.2human user study · 0.2packet trace analysis · 0.1formal proof · 0.0concurrent computation model · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2015 | First Workshop on Cyber-Physical Systems Security and PrivaCy (CPS-SPC): Challenges and Research DirectionsabstractThe First International Workshop on Cyber-Physical Systems Security and PrivaCy (CPS-SPC) is being held in conjunction with the 22nd ACM CCS Conference. The workshop was motivated by several observations. First, cyber-physical systems represent the new frontier for cyber risk. The attack surface imposed by the convergence of computing, communications and physical control represents unique challenges for security researchers and practitioners. Second, majority of the published literature addressing the security and privacy of CPS reflect a field still in its infancy. As such, the overall principles, models, and theories for securing CPS have not yet emerged. Third, the organizers of this workshop strongly felt that a premiere forum associated with a premiere conference was needed for rapidly publishing diverse, multidisciplinary in-progress work on the security and privacy of CPS and galvanizing the research community. The set of accepted papers reflect this vision. Papers span cyber and control-theoretic foundations, intrusion detection, forensics management, vulnerability analysis and elimination, and field studies. We have organized an exciting program for this workshop and look forward to active participation in this and future workshops. Roshan K. Thomas, Alvaro A. Cárdenas, Rakesh Bobba |
CCS | 1 |
| 2010 | Timing-based localization of in-band wormhole tunnels in MANETsabstractThe problem of localizing in-band wormhole tunnels inMANETs is considered. In an in-band wormhole attack, colluding attackers use a covert tunnel to create the illusion that two remote network regions are directly connected. This apparent shortcut in the topology attracts traffic which the attackers can then control. Jinsub Kim, Dan Sterne, Rommie L. Hardy, Roshan K. Thomas, Lang Tong 0001 |
WISEC | 4 |
| 2009 | E-Hermes: A robust cooperative trust establishment scheme for mobile ad hoc networks
Charikleia Zouridaki, Brian L. Mark, Marek Hejmo, Roshan K. Thomas |
Ad Hoc Networks | 4 |
| 2009 | Accurately Measuring Denial of Service in Simulation and Testbed ExperimentsabstractResearchers in the denial-of-service (DoS) field lack accurate, quantitative, and versatile metrics to measure service denial in simulation and testbed experiments. Without such metrics, it is impossible to measure severity of various attacks, quantify success of proposed defenses, and compare their performance. Existing DoS metrics equate service denial with slow communication, low throughput, high resource utilization, and high loss rate. These metrics are not versatile because they fail to monitor all traffic parameters that signal service degradation. They are not quantitative because they fail to specify exact ranges of parameter values that correspond to good or poor service quality. Finally, they are not accurate since they were not proven to correspond to human perception of service denial. We propose several DoS impact metrics that measure the quality of service experienced by users during an attack. Our metrics are quantitative: they map QoS requirements for several applications into measurable traffic parameters with acceptable, scientifically determined thresholds. They are versatile: they apply to a wide range of attack scenarios, which we demonstrate via testbed experiments and simulations. We also prove metrics' accuracy through testing with human users. Jelena Mirkovic, Alefiya Hussain, Sonia Fahmy, Peter L. Reiher, Roshan K. Thomas |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2007 | When is service really denied?: a user-centric dos metricabstractDenial-of-service (DoS) research community lacks accurate metrics to evaluate an attack's impact on network services, its severity and the effectiveness of a potential defense. We propose several DoS impact metrics that measure the quality of service experienced by end users during an attack, and compare these measurements to application-specific thresholds. Our metrics are ideal for testbed experimentation, since necessary traffic parameters are extracted from packet traces gathered during an experiment. Jelena Mirkovic, Alefiya Hussain, Brett Wilson, Sonia Fahmy, Wei-Min Yao, Peter L. Reiher, Stephen Schwab, Roshan K. Thomas |
SIGMETRICS | 8 |
| 2007 | Hermes: A quantitative trust establishment framework for reliable data packet delivery in MANETsabstractIn mobile ad hoc networks (MANETs), a source node must rely on other nodes to forward its packets on multi-hop routes to the destination. Secure and reliable handling of packets by the intermediate nodes is difficult to ensure in an ad hoc environment. We propose a trust establishment scheme for MA NETs, which aims to improve the reliability of packet forwarding over multi-hop routes in the presence of potentially malicious nodes. Using a Bayesian framework, each node assigns a “trustworthiness” value to each of its neighbor nodes based on direct observations of packet forwarding behavior. More generally, each node forms an “opinion” about each of the other nodes in the network, based on the set of trustworthiness values computed in the network. The opinion metric can be incorporated into ad hoc routing protocols to achieve reliable packet delivery even when a portion of the network exhibits malicious behavior. We present numerical results, which demonstrate the effectiveness of the proposed trust establishment scheme. Charikleia Zouridaki, Brian L. Mark, Marek Hejmo, Roshan K. Thomas |
J. Comput. Secur. | 4 |
| 2006 | On the fairness of flow aggregation for denial-of-service resistant QoS in MANETsabstractMobile ad hoc networks are especially susceptible to denial-of-service attacks due to the lack of infrastructure, the imperfections of the wireless channel, and the limitations of the mobile devices. In principle, providing quality-of-service and resistance against flooding attacks can be achieved with per-flow management. However, a per-flow management scheme makes a mobile device vulnerable to state table exhaustion attacks. To avoid such attacks some degree of flow aggregation is necessary, but such aggregation tends to have a negative impact on flow fairness. We introduce a quantitative metric for the fairness experienced by a flow in the presence of flooding attacks and develop a model to study the impact of flow aggregation on the fairness experienced by a flow in the presence of flooding attacks. We propose a dynamic 3-level flow aggregation scheme, which is able to maintain a high degree of flow fairness even with a relatively small state table size. Our simulation results quantify the impact of flooding attacks on flow fairness and validate the effectiveness of the proposed flow aggregation scheme. Marek Hejmo, Brian L. Mark, Charikleia Zouridaki, Roshan K. Thomas |
QSHINE | 4 |
| 2005 | A Denial-of-Service Resistant Quality-of-Service Signaling Protocol for Mobile Ad Hoc NetworksabstractQuality-of-service (QoS) signaling protocols for mobile ad hoc networks (MANETs) are highly vulnerable to attacks. In particular, a class of denial-of-service (DoS) attacks can severely cripple network performance with relatively little effort expended by the attacker. We propose a distributed QoS signaling protocol that is resistant to a large class of DoS attacks. The key elements of the scheme are: sensing of available bandwidth, traffic policing, and rate monitoring. The proposed signaling scheme provides QoS for real-time traffic and achieves a compromise between signaling protocols that require the maintenance of per-flow state and those that are completely stateless. The signaling scheme scales gracefully in terms of the number of nodes and/or traffic flows in the MANET. We analyze the key security properties of the protocol and present simulation results to demonstrate its resistance to DoS attacks Marek Hejmo, Brian L. Mark, Charikleia Zouridaki, Roshan K. Thomas |
QSHINE | 4 |
| 2004 | A two-tier representation of node mobility in ad hoc networksabstractWe present a two-tier composite model of node mobility that captures group behavior in a mobile ad hoc network. The first tier represents individual node movement and is based on an autoregressive model of mobility. The second tier captures group mobility behavior by considering correlation among node mobility states. Based on the two-tier model, we propose a scheme to detect the presence of groups among the nodes of a network by performing a correlation index test on the node mobility states. We also propose a group-based mobility estimation scheme, which uses the mobility state of a representative node in a group to estimate the mobility states of the rest of the group members. The group estimation scheme can significantly reduce the amount of data collection required to track nodes exhibiting group mobility in mobile ad hoc networks. The two-tier mobility model and the group detection and estimation schemes are validated through simulations and with GPS data. Zainab R. Zaidi, Brian L. Mark, Roshan K. Thomas |
SECON | 3 |
| 2002 | Models for coalition-based access control (CBAC)abstractTo effectively participate in modern coalitions, member organizations must be able to share specific data and functionality with coalition partners, while ensuring that their resources are safe from inappropriate access. This requires access control models, policies, and enforcement mechanisms for coalition resources. This paper describes a family of coalition-based access control (CBAC) models, developed to provide a range of expressivity with an accompanying range of implementation complexity. We define the protection state of a system, which provides the semantics of CBAC-based access policies. Finally, we briefly examine some of the issues for coalition access policy development and administration, and them complexity of implementing access enforcement mechanisms in a coalition environment. Eve Cohen, Roshan K. Thomas, William H. Winsborough, Deborah Shands |
SACMAT | 2 |
| 2001 | Flexible team-based access control using contextsabstractWe discuss the integration of contextual information with team-based access control. The TMAC model was formulated by Thomas in [1] to provide access control for collaborative activity best accomplished by teams of users. In TMAC, access control revolves around teams, where a "team" is an abstraction that encapsulates a collection of users in specific roles and collaborating with the objective of accomplishing a specific task or goal. Users who belong to a team are given access to resources used by a team. However, the effective permissions of a user are always derived from permission types defined for roles that the user belongs to. TMAC is an example of what we call "active security models". These models are aware of the context associated with an ongoing activity in providing access control and thus distinguish the passive concept of permission assignment from the active concept of context-based permission activation. The ability to integrate contextual information allows models such as TMAC to be flexible and express a variety of access policies that can provide tight and just-in-time permission activation. Christos K. Georgiadis, Ioannis Mavridis, George Pangalos, Roshan K. Thomas |
SACMAT | 4 |
| 1997 | Distributed Object Technologies, Databases and Security
Catherine D. McCollum, Donald B. Faatz, William R. Herndon, E. John Sebes, Roshan K. Thomas |
DBSec | 5 |
| 1997 | Task-Based Authorization Controls (TBAC): A Family of Models for Active and Enterprise-Oriented Autorization Management
Roshan K. Thomas, Ravi S. Sandhu |
DBSec | 1 |
| 1996 | A Trusted Subject Architecture for Multilevel Secure Object-Oriented DatabasesabstractWe address security in object-oriented database systems for multilevel secure environments. Such an environment consists of users cleared to various security levels, accessing information labeled with varying classifications. Our purpose is three-fold. First, we show how security can be naturally incorporated into the object model of computing so as to form a foundation for building multilevel secure object-oriented database management systems. Next, we show how such an abstract security model can be realized under a cost-effective, viable, and popular security architecture. Finally, we give security arguments based on trusted subjects and a formal proof to demonstrate the confidentiality of our architecture and approach. A notable feature of our solution is the support for secure synchronous write-up operations. This is useful when low level users want to send information to higher level users. In the object-oriented context, this is naturally modeled and efficiently accomplished through write-up messages sent by low level subjects. However, such write-up messages can pose confidentiality leaks (through timing and signaling channels) if the timing of the receipt and processing of the messages is observable to lower level senders. Such covert channels are a formidable obstacle in building high-assurance secure systems. Further, solutions to problems such as these have been known to involve various tradeoffs between confidentiality, integrity, and performance. We present a concurrent computation model that closes such channels while preserving the conflicting goals of confidentiality, integrity, and performance. Finally, we give a confidentiality proof for a trusted subject architecture and implementation and demonstrate that the trusted subject (process) cannot leak information in violation of multilevel security. Roshan K. Thomas, Ravi S. Sandhu |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1995 | Panel Discussion: Role-Based Access Control and Next-Generation Security Models
Roshan K. Thomas, Elisa Bertino, Pierangela Samarati, Hans Hermann Brüggemann, Bret Hartman, Ravi S. Sandhu |
DBSec | 1 |
| 1994 | Conceptual Foundations for a Model of Task-based AuthorizationsabstractWe describe conceptual foundations to address integrity issues in computerized information systems from the enterprise perspective. The motivation for this effort stems from the recognition that existing models are formulated at too low a level of abstraction, to be useful for modeling organizational requirements, policy aspects, and internal controls, pertaining to maintenance of integrity in information systems. In particular, these models are primarily concerned with the integrity of internal data components within computer systems, and thus lack the constructs necessary to model enterprise level integrity principles. The starting point in the investigation is the notion of authorization functions and tasks associated with business activities carried out in the enterprise. These functions identify the authorization requirements while the authorization tasks embody the concepts required to carry out such authorizations. We believe a model of task-based authorizations will bridge the existing gap between low-level models and very high level ones looking at integrity from a purely organizational and sociological perspective devoid of any direct links to computerized systems. The work described is preliminary and conceptual in nature, but is a necessary prerequisite for the eventual development of a formal model.> Ravi S. Sandhu, Roshan K. Thomas |
CSFW | 2 |
| 1994 | Supporting Object-Based High-Assurance Write-up in Multilevel Databases for the Replicated Architecture
Roshan K. Thomas, Ravi S. Sandhu |
ESORICS | 1 |
| 1993 | Towards a Unified Framework and Theory for Reasoning about Security and Correctness of Transactions in Multilevel databases
Roshan K. Thomas, Ravi S. Sandhu |
DBSec | 1 |
| 1993 | Towards a task-based paradigm for flexible and adaptable access control in distributed applicationsabstractHistorically, the access control problem has been couched within the framework of subjects, object, and rights.In this paper we argue for a newer paradigm for distributed and multi-system applications, that transcends the subject-object view of access control.This new paradigm views access control and authorization not in terms of individual subjects and object, but rather in terms of long-lived tasks that need to be authorized and managed in information systems. Roshan K. Thomas, Ravi S. Sandhu |
NSPW | 1 |
| 1993 | A Kernelized Architecture for Multilevel Secure Object-Oriented Databases Supporting Write-UpabstractThis paper presents a kernelized architecture (i.e., an architecture in which no subject is exempted from the simple-security and ⋆-properties) for multilevel secure (mls) object-oriented database management systems (DBMS’s) which support write-up. R Roshan K. Thomas, Ravi S. Sandhu |
J. Comput. Secur. | 1 |
| 1991 | A Secure Kernelized Architecture for Multiple Object-Oriented DatabasesabstractThe authors present a secure kernelized architecture for multilevel object-oriented database management systems. The architecture is based on the notion of a message filter. It builds upon the typical architecture of current object-oriented database management systems. Since the operations mediated by the message filter are arbitrarily complex operations (as opposed to primitive reads and writes), a secure message filter requires careful attention to potential timing covert channels. Although the overall computation is logically a sequential one, to be secure one must actually execute pieces of the computation concurrently. This raises a synchronization problem for which they give a secure multiversion protocol. The fundamental problem solved is how to securely and correctly 'write up' in terms of abstract operations.> Ravi S. Sandhu, Roshan K. Thomas, Sushil Jajodia |
CSFW | 2 |