VLDB 2026 Research / reviewers in the wild / expert
Basit Shafiq
dblp:11/2433
· DBLP profile ↗
35ranked-venue papers
6as first author
8since 2021 · last 2024
0000-0002-7862-6682ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 7 · 2 first-authorSoftware engineering, systems software and programming languages · 5 · 4 since 2021Artificial intelligence and machine learning · 4Systems, architecture and hardware · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Demo: Orchflow: Orchestration and Management of IoT-Centric Distributed WorkflowsabstractThe evolution of edge and cloud computing infrastructures has opened avenues for developing Internet-centered distributed applications characterized by adaptability, evolvability, and emergence. These applications, such as knowledge-driven distributed workflows are dynamically orchestrated and managed using resources across enterprise networks, cloud data centers, and Internet of Things (IoT) devices. Unlike traditional business processes and scientific workflows, knowledge-driven workflows dynamically evolve and adapt by responding to the environmental context, current execution status, and specific parameters of the case at hand, which are not predictable beforehand. In this demonstration, we present the Orchflow system, designed for dynamic orchestration and management of adaptive IoT-centric workflows. Orchflow enables flexible and location-aware resource selection, iterative and incremental binding, and dynamic deployment of services by considering factors such as spatio-temporal requirements of workflow tasks, resource availability status, underlying service infrastructure constraints, and real-time processing requirements within the workflow. Sehrish Amjad, Ahmed Akhtar, Basit Shafiq, Shafay Shamail, Ayesha Afzal, Jaideep Vaidya |
ICDCS | 4 |
| 2024 | Orchestration and Management of Adaptive IoT-Centric Distributed ApplicationsabstractCurrent Internet of Things (IoT) devices provide a diverse range of functionalities, ranging from measurement and dissemination of sensory data observation, to computation services for real-time data stream processing. In extreme situations such as emergencies, a significant benefit of IoT devices is that they can help gain a more complete situational understanding of the environment. However, this requires the ability to utilize IoT resources while taking into account location, battery life, and other constraints of the underlying edge and IoT devices. A dynamic approach is proposed for orchestration and management of distributed workflow applications using services available in cloud data centers, deployed on servers, or IoT devices at the network edge. Our proposed approach is specifically designed for knowledge-driven business process workflows that are adaptive, interactive, evolvable and emergent. A comprehensive empirical evaluation shows that the proposed approach is effective and resilient to situational changes. Sehrish Amjad, Ahmed Akhtar, Ayesha Afzal, Basit Shafiq, Jaideep Vaidya, Shafay Shamail, Omer F. Rana |
IEEE Internet Things J. | 5 |
| 2024 | Blockchain Based Auditable Access Control for Business Processes With Event Driven PoliciesabstractThe use of blockchain technology has been proposed to provide auditable access control for individual resources. Unlike the case where all resources are owned by a single organization, this work focuses on distributed applications such as business processes and distributed workflows. These applications are often composed of multiple resources/services that are subject to the security and access control policies of different organizational domains. Here, blockchains provide an attractive decentralized solution to provide auditability. However, the underlying access control policies may have event-driven constraints and can be overlapping in terms of the component conditions/rules as well as events. Existing work cannot handle event-driven constraints and does not sufficiently account for overlaps leading to significant overhead in terms of cost and computation time for evaluating authorizations over the blockchain. In this work, we propose an automata-theoretic approach for generating a cost-efficient composite access control policy. We reduce this composite policy generation problem to the standard weighted set cover problem. We show that the composite policy correctly captures all the local access control policies and reduces the policy evaluation cost over the blockchain. We have implemented the initial prototype of our approach using Ethereum as the underlying blockchain and empirically validated the effectiveness and efficiency of our approach. Ablation studies were conducted to determine the impact of changes in individual service policies on the overall cost. Ahmed Akhtar, Masoud Barati, Basit Shafiq, Omer F. Rana, Ayesha Afzal, Jaideep Vaidya, Shafay Shamail |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Collaborative Business Process Fault Resolution in the Services CloudabstractThe emergence of cloud and edge computing has enabled rapid development and deployment of Internet-centric distributed applications. There are many platforms and tools that can facilitate users to develop distributed business process (BP) applications by composing relevant service components in a plug and play manner. However, there is no guarantee that a BP application developed in this way is fault-free. In this paper, we formalize the problem of collaborative BP fault resolution which aims to utilize information from existing fault-free BPs that use similar services to resolve faults in a user developed BP. We present an approach based on association analysis of pairwise transformations between a faulty BP and existing BPs to identify the smallest possible set of transformations to resolve the fault(s) in the user developed BP. An extensive experimental evaluation over both synthetically generated faulty BPs and real BPs developed by users shows the effectiveness of our approach. Muhammad Adeel Zahid, Basit Shafiq, Jaideep Vaidya, Ayesha Afzal, Shafay Shamail |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | BP-DEBUG: A Fault Debugging and Resolution Tool for Business ProcessesabstractCloud computing and Internet-ware software paradigm have enabled rapid development of distributed business process (BP) applications. Several tools are available to facilitate automated/ semi-automated development and deployment of such distributed BPs by orchestrating relevant service components in a plug-and-play fashion. However, the BPs developed using such tools are not guaranteed to be fault-free. In this demonstration, we present a tool called BP-DEBUG for debugging and automated repair of faulty BPs. BP-DEBUG implements our Collaborative Fault Resolution (CFR) approach that utilizes the knowledge of existing BPs with a similar set of web services fault detection and resolution in a given user BP. Essentially, CFR attempts to determine any semantic and structural differences between a faulty BP and related BPs and computes a minimum set of transformations which can be used to repair the faulty BP. Demo url: https://youtu.be/mf49oSekLOA. Muhammad Adeel Zahid, Basit Shafiq, Shafay Shamail, Ayesha Afzal, Jaideep Vaidya |
ICDCS | 2 |
| 2022 | An Integrated Framework for Fault Resolution in Business ProcessesabstractCloud and edge-computing based platforms have enabled rapid development of distributed business process (BP) applications in a plug and play manner. However, these platforms do not provide the needed capabilities for identifying or repairing faults in BPs. Faults in BP may occur due to errors made by BP designers because of their lack of understanding of the underlying component services, misconfiguration of these services, or incorrect/incomplete BP workflow specifications. Such faults may not be discovered at design or development stage and may occur at runtime. In this paper, we present a unified framework for automated fault resolution in BPs. The proposed framework employs a novel and efficient fault resolution approach that extends the generate-and-validate program repair approach. In addition, we propose a hybrid approach that performs fault resolution by analyzing a faulty BP in isolation as well as by comparing with other BPs using similar services. This hybrid approach results in improved accuracy and broader coverage of fault types. We also perform an extensive experimental evaluation to compare the effectiveness of the proposed approach using a dataset of 208 faulty BPs. Muhammad Adeel Zahid, Ahmed Akhtar, Basit Shafiq, Shafay Shamail, Ayesha Afzal, Jaideep Vaidya |
ICWS | 3 |
| 2022 | A Framework for Dynamic Composition and Management of Emergency Response ProcessesabstractAn emergency response process outlines the workflow of different activities that need to be performed in response to an emergency. Effective emergency response requires communication and coordination with the operational systems belonging to different collaborating organizations. Therefore, it is necessary to establish information sharing and system-level interoperability among the diverse operational systems. Unlike typical e-government processes that are well structured and have a well-defined outcome, emergency response processes are knowledge-centric and their workflow structure and execution may evolve as the incident unfolds. It is impractical to define static plans and response process workflows for every possible situation. Instead, a dynamic response should be adaptable to the changing situation. We present an integrated approach that facilitates the dynamic composition of an executable response process. The proposed approach employs ontology-based reasoning to determine the default actions and resource requirements for the given incident and to identify relevant response organizations based on their jurisdictional and mutual aid agreement rules. The Web service APIs of the identified response organizations are then used to generate an executable response process that evolves dynamically. The proposed approach is implemented and experimentally validated using an example scenario derived from the FEMA Hazardous Materials Tabletop Exercises Manual. Abeer Elahraf, Ayesha Afzal, Ahmed Akhtar, Basit Shafiq, Jaideep Vaidya, Shafay Shamail, Nabil R. Adam |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | ASSEMBLE: Attribute, Structure and Semantics Based Service Mapping Approach for Collaborative Business Process DevelopmentabstractDevelopment of a Business Process (BP) is a challenging task for small and medium enterprises (SMEs) which often do not have adequate resources for design, coding, and management of their BPs. Knowledge of existing BPs of related organizations can be exploited for collaborative BP development. However, syntactic and semantic heterogeneity among the Web service operations of BPs across organizations is a major obstacle to such collaborative BP development. In this paper, we propose an approach for collaborative BP development that exploits the attribute and structural similarity of related BPs as well as the semantic information including preconditions and postconditions of operations, to compute a mapping between the available service operations of the user organization and the BP operations of other organizations. We experimentally evaluate the approach with real world data from e-commerce sales BPs and demonstrate its effectiveness. Ayesha Afzal, Basit Shafiq, Shafay Shamail, Abeer Elahraf, Jaideep Vaidya, Nabil R. Adam |
IEEE Trans. Serv. Comput. | 2 |
| 2020 | BP-Com: A Service Mapping Tool for Rapid Development of Business ProcessesabstractBusiness Process (BP) composition is a challenging task for small and medium organizations that do not have sufficient resources for design, coding, and management of their BPs. Cloud infrastructure and service-oriented middleware can be leveraged for rapid development and deployment of BPs of such organizations. BP development in the cloud-based environment can be done by exploiting the knowledge of existing BPs of related organizations. In this demonstration, we present the BP- Com tool which is a Web-based interactive system that enables efficient development of BPs in the cloud. BP-Com implements our service mapping approach called ASSEMBLE that utilizes the attribute, structural and semantics information of service operations of existing BPs in a given domain to help a user organization to compose its BP. Given a collection of related BPs and available service operations of a user organization, BP-Com computes a mapping between the available service operations of the user organization and the BP operations of other organizations. The results of operation mapping are presented to the user for refinement and customization of the generated BP workflow. Executable BP code is then generated in standard BPEL language, which can be deployed on any process execution engine on the user organization's site or on the cloud. Ayesha Afzal, Muhammad Adeel Zahid, Ahmad Akhtar, Basit Shafiq, Shafay Shamail, Abeer Elahraf, Jaideep Vaidya, Nabil R. Adam |
ICDCS | 4 |
| 2020 | Blockchain Based Auditable Access Control for Distributed Business ProcessesabstractThe use of blockchain technology has been proposed to provide auditable access control for individual resources. However, when all resources are owned by a single organization, such expensive solutions may not be needed. In this work we focus on distributed applications such as business processes and distributed workflows. These applications are often composed of multiple resources/services that are subject to the security and access control policies of different organizational domains. Here, blockchains can provide an attractive decentralized solution to provide auditability. However, the underlying access control policies may be overlapping in terms of the component conditions/rules, and simply using existing solutions would result in repeated evaluation of user's authorization separately for each resource, leading to significant overhead in terms of cost and computation time over the blockchain. To address this challenge, we propose an approach that formulates a constraint optimization problem to generate an optimal composite access control policy. This policy is in compliance with all the local access control policies and minimizes the policy evaluation cost over the blockchain. The developed smart contract(s) can then be deployed to the blockchain, and used for access control enforcement. We also discuss how the access control enforcement can be audited using a game-theoretic approach to minimize cost. We have implemented the initial prototype of our approach using Ethereum as the underlying blockchain and experimentally validated the effectiveness and efficiency of our approach. Ahmad Akhtar, Basit Shafiq, Jaideep Vaidya, Ayesha Afzal, Shafay Shamail, Omer F. Rana |
ICDCS | 2 |
| 2018 | Differentially Private Outlier Detection in a Collaborative EnvironmentabstractOutlier detection is one of the most important data analytics tasks and is used in numerous applications and domains. The goal of outlier detection is to find abnormal entities that are significantly different from the remaining data. Often the underlying data is distributed across different organizations. If outlier detection is done locally, the results obtained are not as accurate as when outlier detection is done collaboratively over the combined data. However, the data cannot be easily integrated into a single database due to privacy and legal concerns. In this paper, we address precisely this problem. We first define privacy in the context of collaborative outlier detection. We then develop a novel method to find outliers from both horizontally partitioned and vertically partitioned categorical data in a privacy-preserving manner. Our method is based on a scalable outlier detection technique that uses attribute value frequencies. We provide an end-to-end privacy guarantee by using the differential privacy model and secure multiparty computation techniques. Experiments on real data show that our proposed technique is both effective and efficient. Hafiz Salman Asif, Tanay Talukdar, Jaideep Vaidya, Basit Shafiq, Nabil R. Adam |
Int. J. Cooperative Inf. Syst. | 4 |
| 2017 | A Scalable Privacy-preserving Data Generation Methodology for Exploratory Analysis
Jaideep Vaidya, Basit Shafiq, Muazzam Asani, Nabil R. Adam, Xiaoqian Jiang, Lucila Ohno-Machado |
AMIA | 2 |
| 2017 | Secure and Efficient k-NN Queries
Hafiz Salman Asif, Jaideep Vaidya, Basit Shafiq, Nabil R. Adam |
SEC | 3 |
| 2017 | Composability Verification of Multi-Service Workflows in a Policy-Driven Cloud Computing EnvironmentabstractThe emergence of cloud computing infrastructure and Semantic Web technologies has created unprecedented opportunities for composing large-scale business processes and workflow-based applications that span multiple organizational domains. A key challenge related to composition of such multi-organizational business processes and workflows is posed by the security and access control policies of the underlying organizational domains. In this paper, we propose a framework for verifying secure composability of distributed workflows in an autonomous multi-domain environment. The objective of workflow composability verification is to ensure that all the users or processes executing the designated workflow tasks conform to the time-dependent security policy specifications of all collaborating domains. A key aspect of such verification is to determine the time-dependent schedulability of distributed workflows, assumed to be invoked on a recurrent basis. We use a two-step approach for verifying secure workflow composability. In the first step, a distributed workflow is decomposed into domain-specific projected workflows and is verified for conformance with the respective domain's security and access control policy. In the second step, the cross-domain dependencies amongst the workflow tasks performed by different collaborating domains are verified. Basit Shafiq, Sameera Ghayyur, Ammar Masood, Zahid Pervaiz, Abdulrahman Almutairi, M. Farrukh Khan, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2015 | A Framework for Policy Similarity Evaluation and Migration Based on Change Detection
Jaideep Vaidya, Basit Shafiq, Vijayalakshmi Atluri, David Lorenzi |
NSS | 2 |
| 2015 | Preserving Privacy in Collaborative Business Process CompositionabstractCollaborative business process composition exploits the knowledge of existing business processes of related organizations to compose an executable business process for a given organization based on its requirements and design specifications. Typically, this requires organizations to share and upload their existing business process execution sequences to a central repository. However, even after masking of confidential data, the execution sequences may still include sensitive business information which organizations may not want to share with their competitors. To address this issue, we develop a privacy-preserving Business Process Recommendation and Composition System (BPRCS), that generates a differentially private dataset of execution sequences which can be published and shared with other organizations for composition and implementation of their business processes. We also employ process mining and classification techniques on this differentially private dataset to regenerate the executable business process workflow. We experimentally validate the effectiveness of our approach. Hassaan Irshad, Basit Shafiq, Jaideep Vaidya, Muhammad Ahmed Bashir, Shafay Shamail, Nabil R. Adam |
SECRYPT | 2 |
| 2014 | A Random Decision Tree Framework for Privacy-Preserving Data MiningabstractDistributed data is ubiquitous in modern information driven applications. With multiple sources of data, the natural challenge is to determine how to collaborate effectively across proprietary organizational boundaries while maximizing the utility of collected information. Since using only local data gives suboptimal utility, techniques for privacy-preserving collaborative knowledge discovery must be developed. Existing cryptography-based work for privacy-preserving data mining is still too slow to be effective for large scale data sets to face today’s big data challenge. Previous work on random decision trees (RDT) shows that it is possible to generate equivalent and accurate models with much smaller cost. We exploit the fact that RDTs can naturally fit into a parallel and fully distributed architecture, and develop protocols to implement privacy-preserving RDTs that enable general and efficient distributed privacy-preserving knowledge discovery. Jaideep Vaidya, Basit Shafiq, Wei Fan 0001, Danish Mehmood, David Lorenzi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | Differentially Private Naive Bayes ClassificationabstractPrivacy and security concerns often prevent the sharing of users' data or even of the knowledge gained from it, thus deterring valuable information from being utilized. Privacy-preserving knowledge discovery, if done correctly, can alleviate this problem. One of the most important and widely used data mining techniques is that of classification. We consider the model where a single provider has centralized access to a dataset and would like to release a classifier while protecting privacy to the best extent possible. Recently, the model of differential privacy has been developed which provides a strong privacy guarantee even if adversaries hold arbitrary prior knowledge. In this paper, we apply this rigorous privacy model to develop a Naive Bayes classifier, which is often used as a baseline and consistently provides reasonable classification performance. We experimentally evaluate the proposed approach, and discuss how it could be potentially deployed in PaaS clouds. Jaideep Vaidya, Basit Shafiq, Anirban Basu 0001, Yuan Hong 0001 |
Web Intelligence | 2 |
| 2012 | Secure composition of cascaded Web servicesabstractA business process can be developed as a composition of Web services provided by different service providers. These service providers may have their own policies and constraints for service provisioning and collaboration. In this paper, we focus on secure composition of services, specifically from t Basit Shafiq, Soon Ae Chun, Jaideep Vaidya, Nazia Badar, Nabil R. Adam |
CollaborateCom | 1 |
| 2012 | Privacy-Preserving Subgraph Discovery
Danish Mehmood, Basit Shafiq, Jaideep Vaidya, Yuan Hong 0001, Nabil R. Adam, Vijayalakshmi Atluri |
DBSec | 2 |
| 2012 | A framework for verification and optimal reconfiguration of event-driven role based access control policiesabstractRole based access control (RBAC) is the de facto model used for advanced access control due to its inherent richness and flexibility. Despite its great success at modeling a variety of organizational needs, maintaining large complex policies is a challenging problem. Conflicts within policies can expose the underlying system to numerous vulnerabilities and security risks. Therefore, more comprehensive verification tools for RBAC need to be developed to enable effective access control. In this paper, we propose a verification framework for detection and resolution of inconsistencies and conflicts in policies modeled through event-driven RBAC, an important subset of generalized temporal RBAC applicable to many domains, such as SCADA systems. We define the conflict resolution problem and propose an integer programming based heuristic. The proposed approach is generic and can be tuned to a variety of optimality measures. Basit Shafiq, Jaideep Vaidya, Arif Ghafoor, Elisa Bertino |
SACMAT | 1 |
| 2012 | Semantics-Based Automated Service DiscoveryabstractA vast majority of web services exist without explicit associated semantic descriptions. As a result many services that are relevant to a specific user service request may not be considered during service discovery. In this paper, we address the issue of web service discovery given nonexplicit service description semantics that match a specific service request. Our approach to semantic-based web service discovery involves semantic-based service categorization and semantic enhancement of the service request. We propose a solution for achieving functional level service categorization based on an ontology framework. Additionally, we utilize clustering for accurately classifying the web services based on service functionality. The semantic-based categorization is performed offline at the universal description discovery and integration (UDDI). The semantic enhancement of the service request achieves a better matching with relevant services. The service request enhancement involves expansion of additional terms (retrieved from ontology) that are deemed relevant for the requested functionality. An efficient matching of the enhanced service request with the retrieved service descriptions is achieved utilizing Latent Semantic Indexing (LSI). Our experimental results validate the effectiveness and feasibility of the proposed approach. Aabhas V. Paliwal, Basit Shafiq, Jaideep Vaidya, Hui Xiong 0001, Nabil R. Adam |
IEEE Trans. Serv. Comput. | 2 |
| 2012 | Structure-aware graph anonymizationabstractGraph structured data can be ubiquitously found in the real world. For example, social networks can easily be represented as graphs where the graph connotes the complex sets of relationships between members of social systems. While their analysis cou Xiaoyun He, Jaideep Vaidya, Basit Shafiq, Nabil R. Adam, Vijayalakshmi Atluri |
Web Intell. Agent Syst. | 3 |
| 2010 | Privacy-preserving trust verificationabstractDistributed and open environments require flexible, scalable and extendible trust verification mechanisms to access resources. To address this, the use of digital credentials as a means for making access decisions has been promoted. The resource owner needs to verify if the requester's credentials satisfy the security policy of the owner. However, such verification becomes a challenging problem when either the requester does not wish to disclose her credentials before the verification is complete, or the owner wishes to keep its security policy confidential from the requester, or both. In addition, the requester may associate a score to each of her credentials based on her perceived level of privacy. Earlier proposals to address this problem limit the owners policy to be a set of credentials. However, real world policies are more complex than a simple set. In this paper, we present three alternative privacy preserving trust verification solutions that protect both the owner's policy and requester's credentials, while at the same time allowing more expressive owner's policies that can be specified as a tree structure. We analyze their computational complexity, communication cost and the amount of disclosure. Jaideep Vaidya, Vijayalakshmi Atluri, Basit Shafiq, Nabil R. Adam |
SACMAT | 3 |
| 2010 | Reachability Analysis in Privacy-Preserving Perturbed GraphsabstractMany real world phenomena can be naturally modeled as graph structures whose nodes representing entities and whose edges representing interactions or relationships between entities. The analysis of the graph data have many practical implications. However, the release of the data often poses considerable privacy risk to the individuals involved. In this paper, we address the edge privacy problem in graphs. In particular, we explore random perturbation for privacy preservation in graph data, and propose an iterative derivation process to analyze node reachability within the graph. We specifically focus on deriving the probability that the shortest path linking two nodes in a directed graph is of a particular length. This allows us to determine the expected length of the shortest path between two nodes, and determine whether they are linked or not. The performance of the proposed method is demonstrated via extensive experiments on both real and synthetic datasets. Xiaoyun He, Jaideep Vaidya, Basit Shafiq, Nabil R. Adam, Xiaodong Lin 0004 |
Web Intelligence | 3 |
| 2009 | Efficient Privacy-Preserving Link Discovery
Xiaoyun He, Jaideep Vaidya, Basit Shafiq, Nabil R. Adam, Evimaria Terzi, Tyrone Grandison |
PAKDD | 3 |
| 2009 | Preserving Privacy in Social Networks: A Structure-Aware ApproachabstractGraph structured data can be ubiquitously found in the real world. For example, social networks can easily be represented as graphs where the graph connotes the complex sets of relationships between members of social systems. While their analysis could be beneficial in many aspects, publishing certain types of social networks raises significant privacy concerns. This brings the problem of graph anonymization into sharp focus. Unlike relational data, the true information in graph structured data is encoded within the structure and graph properties. Motivated by this, we propose a structure aware anonymization approach that maximally preserves the structure of the original network as well as its structural properties while anonymizing it. Instead of anonymizing each node one by one independently, our approach treats each partitioned substructural component of the network as one single unit to be anonymized. This maximizes utility while enabling anonymization. We apply our method to both synthetic and real datasets and demonstrate its effectiveness and practical usefulness. Xiaoyun He, Jaideep Vaidya, Basit Shafiq, Nabil R. Adam, Vijayalakshmi Atluri |
Web Intelligence | 3 |
| 2007 | Privacy Preserving Integration of Health Care Data
Nabil R. Adam, Tom White, Basit Shafiq, Jaideep Vaidya, Xiaoyun He |
AMIA | 3 |
| 2007 | Approach for Discovering and Handling Crisis in a Service-Oriented EnvironmentabstractIn an emergency situation failure to respond in a timely manner poses a significant threat. Data needed for timely response comes from various sources and sensors. These individual data streams when viewed in isolation may appear irrelevant, however, when analyzed collectively may identify potential threats. An effective and timely response also requires collaboration and information sharing among various government agencies at all levels. This collaboration information sharing among agencies can be achieved using service-oriented architecture, where agencies provide access to their information resources and applications using Web services. Each of these agencies has its own rules/policies for providing their services. It is therefore, important to verify the correctness of the emergency response processes with respect to the rules/policies of the collaborating agencies involved in the execution of such processes. In this paper we present an approach which addresses the above challenges. Specifically, the proposed approach: a) employs multi stream data mining for identification of potential threats and disambiguation of alarms; b) provides a methodology for the discovery and selection of relevant Web services; c) employs a timed automata based verification methodology for determining the correctness of emergency response processes with respect to the rules of the collaborating agencies. We provide an overview of the initial implementation of the proposed approach. Nabil R. Adam, Vandana Pursnani Janeja, Aabhas V. Paliwal, Basit Shafiq, Cédric Ulmer, Volker Gersabeck, Anne Hardy, Christof Bornhövd, Joachim Schaper |
ISI | 4 |
| 2006 | Technique for Optimal Adaptation of Time-Dependent Workflows with Security ConstraintsabstractDistributed workflow based systems are widely used in various application domains including e-commerce, digital government, healthcare, manufacturing and many others. Workflows in these application domains are not restricted to the administrative boundaries of a single organization [1]. The tasks in a workflow need to be performed in a certain order and often times are subject to temporal constraints and dependencies [1, 2]. A key requirement for such workflow applications is to provide the right data to the right person at the right time. This requirement motivates for dynamic adaptations of workflows for dealing with changing environmental conditions and exceptions. Basit Shafiq, Arjmand Samuel, Elisa Bertino, Arif Ghafoor |
ICDE | 1 |
| 2005 | A GTRBAC Based System for Dynamic Workflow Composition and ManagementabstractIn this paper, we propose an architecture for adaptive real-time workflow-based collaborative system. Such a system is needed to support real-time communication and sharing of information among predefined or ad hoc team of users collaborating with each other for the execution of their respective tasks in the workflow. A key requirement for real-time workflow system is to provide the right data to the right person at the right time. In addition, the workflow needs to be reconfigured if a subtask of a workflow cannot be executed within the due time. We use the generalized temporal role-based access control (GTRBAC) model to capture the real-time dependencies of such workflow applications. In addition, support for triggers in GTRBAC allows dynamic adaptation of workflow based on the occurrence of certain events. Such adaptations may include rescheduling of workflow tasks, reassignment of users to scheduled tasks based on their availability and skill level, and abortion of incomplete tasks. Basit Shafiq, Arjmand Samuel, Halima Ghafoor |
ISORC | 1 |
| 2005 | X-gtrbac admin: A decentralized administration model for enterprise-wide access controlabstractThe modern enterprise spans several functional units or administrative domains with diverse authorization requirements. Access control policies in an enterprise environment typically express these requirements as authorization constraints. While desirable for access control, constraints can lead to conflicts in the overall policy in a multidomain environment. The administration problem for enterprise-wide access control, therefore, not only includes authorization management for users and resources within a single domain but also conflict resolution among heterogeneous access control policies of multiple domains to allow secure interoperation within the enterprise. This work presents design and implementation of X-GTRBAC Admin, an administration model that aims at enabling administration of role-based access control (RBAC) policies in the presence of constraints with support for conflict resolution in a multidomain environment. A key feature of the model is that it allows decentralization of policy administration tasks through the abstraction of administrative domains, which not only simplifies authorization management, but is also fundamental to the concept of decentralized conflict resolution presented. The paper also illustrates the applicability of the outlined administrative concepts in a realistic enterprise environment using an implementation prototype that facilitates policy administration in large enterprises. Rafae Bhatti, Basit Shafiq, Elisa Bertino, Arif Ghafoor, James B. D. Joshi |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2005 | Secure Interoperation in a Multidomain Environment Employing RBAC PoliciesabstractMultidomain application environments where distributed multiple organizations interoperate with each other are becoming a reality as witnessed by emerging Internet-based enterprise applications. Composition of a global coherent security policy that governs information and resource accesses in such environments is a challenging problem. In this paper, we propose a policy integration framework for merging heterogeneous role-based access control (RBAC) policies of multiple domains into a global access control policy. A key challenge in composition of this policy is the resolution of conflicts that may arise among the RBAC policies of individual domains. We propose an integer programming (IP)-based approach for optimal resolution of such conflicts. The optimality criterion is to maximize interdomain role accesses without exceeding the autonomy losses beyond the acceptable limit. Basit Shafiq, James B. D. Joshi, Elisa Bertino, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2003 | Dependencies and separation of duty constraints in GTRBACabstractA Generalized Temporal Role Based Access Control (GTRBAC) model that captures an exhaustive set of temporal constraint needs for access control has recently been proposed. GTRBAC's language constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. In this paper, we identify various time-constrained cardinality, control flow dependency and separation of duty constraints (SoDs). Such constraints allow specification of dynamically changing access control requirements that are typical in today's large systems. In addition to allowing specification of time, the constraints introduced here also allow expressing access control policies at a finer granularity. The inclusion of control flow dependency constraints allows defining much stricter dependency requirements that are typical in workflow types of applications. James B. D. Joshi, Basit Shafiq, Arif Ghafoor, Elisa Bertino |
SACMAT | 2 |
| 2002 | A model for secure multimedia document database system in a distributed environmentabstractThe Internet provides a universal platform for large-scale distribution of information and supports inter-organizational services, system integration, and collaboration. Use of multimedia documents for dissemination and sharing of massive amounts of information is becoming a common practice for Internet-based applications and enterprises. With the rapid proliferation of multimedia data management technologies over the Internet, there is growing concern about security and privacy of information. Composing multimedia documents in a distributed heterogeneous environment involves integrating media objects from multiple security domains that may employ different access control policies for media objects. In this paper, we present a security model for distributed document management system that allows creation, storage, indexing, and presentation of secure multimedia documents. The model is based on a time augmented Petri-net and provides a flexible, multilevel access control mechanism that allows clearance-based access to different levels of information in a document. In addition, the model provides detailed multimedia synchronization requirements including deterministic and non-deterministic temporal relations and incomplete timing information among media objects. James B. D. Joshi, Zhaohui Kevin Li, Husni Fahmi, Basit Shafiq, Arif Ghafoor |
IEEE Trans. Multim. | 4 |