VLDB 2026 Research / reviewers in the wild / expert
Xinwen Zhang
dblp:14/3612
· DBLP profile ↗
94ranked-venue papers
18as first author
14since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 52 · 10 first-authorComputer networks · 12 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 10 · 4 first-author · 8 since 2021Human-computer interaction and ubiquitous computing · 9 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | WEANet: Bridging wavelet inductive bias with network parameter initialization for time series modeling
Chao Yang 0024, Xinwen Zhang, Zihao Li 0005, Yakun Chen, Zhongwen Guo |
Neural Networks | 2 |
| 2026 | Swapping and Purification Scheme Optimization for Entanglement Distribution in Quantum NetworksabstractSwapping and purification are the two fundamental building blocks for high-fidelity entanglement distribution in multi-hop quantum networks. Unfortunately, it is still a mystery how they intertwine with each other to affect the fidelity and cost of end-to-end entanglements. Current scheduling algorithms consider this problem under relatively limited assumptions and a critical yet unjustified conjecture. In this work, we first consider more general assumptions with operation failures and, accordingly, extend a tree-based modeling for joint swapping and purification. Then, we analytically prove the previous conjecture that the optimal strategy underBinary systemis always to purify the entanglements before any swapping. This sheds light on the protocol and device design for quantum networks. We then further propose a tree-based algorithm, which can efficiently schedule swapping and purification along a path for bothBinaryandWerner systems. Extensive simulations of the proposed method against state-of-the-art solutions show that our method uses fewer entanglements to establish qualified end-to-end entanglements, and thus achieves higher network throughput. Jiyao Liu, Xinwen Zhang, Xinliang Wei, Xuanzhang Liu, Hongchang Gao, Yu Wang 0003 |
IEEE Trans. Netw. | 2 |
| 2025 | PDP-FD: Federated Knowledge Distillation Based on Personalized Differential PrivacyabstractFederated learning (FL) is a privacy-preserving distributed machine learning approach that enables training by exchanging model parameters without uploading local private data. However, the data heterogeneity across clients poses significant challenges in achieving personalized privacy protection. Existing methods often struggle to balance privacy and model utility, especially with inconsistent data distributions. Personalized differential privacy (PDP) is a commonly used technique to provide differential privacy (DP) by introducing varying levels of noise for each client. The noise level directly affects the model's utility, making it crucial to precisely determine the appropriate noise for each client. To address this challenge, we propose a federated knowledge distillation method based on PDP, named PDP-FD. PDP-FD dynamically adjusts the network architecture of both base and personalized layers to align with the data characteristics of different clients, enhancing model personalization. Moreover, it allocates an appropriate privacy budget to each client based on the similarity between local and global models, thereby meeting diverse privacy needs. Experimental results show that PDP-FD significantly outperforms existing FL methods in accuracy, effectively balancing privacy protection and model utility. Yushuang Xiao, Juanjuan Wang, Xuebin Ma, Xinwen Zhang, Xiangyu Bai |
CSCWD | 5 |
| 2025 | DPTB-VFL: An Efficient Vertical Federated Learning Framework Based on Boosting Trees and Adaptive Differential PrivacyabstractVertical Federated Learning (VFL) offers a promising approach to collaborative model training, allowing participants to share identical data samples with distinct attributes. This approach avoids direct raw data sharing, enhancing data privacy, though it may sometimes reduce model accuracy. In this paper, we introduce DPTB-VFL, a differential privacy-based vertical federated learning framework that leverages boosting trees. Boosting trees are chosen for their exceptional ability to handle heterogeneous features, deliver robust performance with minimal preprocessing, and provide interpretability-all crucial in privacy-sensitive scenarios. Additionally, most current methods apply a uniform privacy budget across all training steps, overlooking variations in local gradients that could better balance privacy and utility. DPTB-VFL addresses this gap by introducing an adaptive differential privacy protocol, enabling dynamic privacy budget allocation based on the model's learning progress. Experimental evaluations on three public datasets demonstrate that DPTB-VFL not only achieves higher accuracy than existing approaches but also significantly reduces computational latency, aligning data privacy needs with model performance Xinwen Zhang, Xuebin Ma, Yushuang Xiao, Xiangyu Bai |
CSCWD | 1 |
| 2025 | An Efficient Federated Learning with Correlation-Based Pruning: Improving Accuracy under Layer-Wise Differential PrivacyabstractFederated Learning (FL) enables multiple clients to collaboratively train models without sharing data. However, it commonly faces dual challenges of security and high communication costs. Differential Privacy (DP) offers protection by adding noise to model parameters based on strict privacy standards, but excessive noise can compromise model accuracy. Additionally, the communication cost associated with training large-scale models in FL can be both slow and expensive. In this paper, we propose CPDP-FL, an efficient and privacy-preserving federated learning algorithm that combines model pruning with differential privacy to address these issues. By pruning the model based on neuron correlation before client training, we reduce redundant parameters, which not only improves communication efficiency but also reduces the amount of noise needed for DP, thereby preserving model accuracy. During training, we apply differential privacy to the remaining parameters and introduce a novel layer-wise privacy budget allocation strategy. This approach assigns different privacy budgets to different layers to balance privacy protection with model accuracy. Extensive experiments demonstrate that our method achieves high communication efficiency and robust privacy protection while minimizing unnecessary privacy budget expenditure. Xuebin Ma, Xinwen Zhang, Yushuang Xiao, Xiangyu Bai |
CSCWD | 4 |
| 2025 | Sharpness-Aware Optimization Through Variance Suppression on Deep AUC MaximizationabstractSharpness-aware minimization (SAM) is widely rec-ognized for its ability to improve the generalization of deep neural networks by transforming the optimization problem into a minimax problem, aiming to minimize the maximum loss caused by adversarial parameter perturbations within a neighborhood. However, existing work almost exclusively focuses on the original minimization optimization, with very little attention paid to the minimax optimization. In this paper, we introduce a novel algorithm, VaSSO-SGDAM, by leveraging Variance-Suppressed Sharpness-aware Optimization (VaSSO) for deep AUC maximization. We provide a theoretical convergence analysis of this algorithm, marking it as the first work to achieve such significant theoretical outcomes for this kind of problem. Lastly, we implement our method for optimizing the AUC maximization problem, and the experimental findings validate the efficacy of our approach. Xinwen Zhang, Hongchang Gao |
ICDM | 1 |
| 2025 | Joint Swapping and Purification with Failures for Entanglement Distribution in Quantum NetworksabstractSwapping and purification are the two fundamental building blocks for multi-hop quantum networks. However, their interplay and its impact on end-to-end fidelity and cost are not yet fully explored. Existing scheduling algorithms address this problem under certain simplified assumptions and models that may not fully capture the complexities of real scenarios. In this work, we first consider more general assumptions that account for operation failures and extend a tree-based modeling approach for joint swapping and purification. Then, for the first time, we analytically prove the previous conjecture that the optimal strategy under Binary system is always to purify the entanglements before any swapping. This sheds light on the protocol and device design for entanglement distribution in quantum networks. We then further propose a tree-based algorithm, which can efficiently schedule swapping and purification along a path for both Binary and Werner systems. Extensive simulations have been conducted to evaluate the proposed method against the existing solutions, and the results show that our method uses fewer entanglements to establish qualified end-to-end entanglements and thus achieves higher network throughput. Jiyao Liu, Xinwen Zhang, Xinliang Wei, Xuanzhang Liu, Hongchang Gao, Yu Wang 0003 |
IWQoS | 2 |
| 2025 | On the Convergence of Stochastic Smoothed Multi-Level Compositional Gradient Descent AscentabstractMulti-level compositional optimization is a fundamental framework in machine learning with broad applications. While recent advances have addressed compositional minimization problems, the stochastic multi-level compositional minimax problem introduces significant new challenges—most notably, the biased nature of stochastic gradients for both the primal and dual variables. In this work, we address this gap by proposing a novel stochastic multi-level compositional gradient descent-ascent algorithm, incorporating a smoothing technique under the nonconvex-PL condition. We establish a convergence rate to an $(\epsilon, \epsilon/\sqrt{\kappa})$-stationary point with improved dependence on the condition number at $O(\kappa^{3/2})$, where $\epsilon$ denotes the solution accuracy and $\kappa$ represents the condition number. Moreover, we design a novel stage-wise algorithm with variance reduction to address the biased gradient issue under the two-sided PL condition. This algorithm successfully enables a translation from and $(\epsilon, \epsilon/\sqrt{\kappa})$-stationary point to an $\epsilon$-stationary point. Finally, extensive experiments validate the effectiveness of our algorithms. Xinwen Zhang, Hongchang Gao |
NeurIPS | 1 |
| 2025 | Path Planning for Rovers With Slip Prediction in Complex Terrains
Zhengpeng Zhang, Xinwen Zhang, Jiayan Ye, Lijing Bu |
PRCV (3) | 2 |
| 2024 | A Federated Stochastic Multi-level Compositional Minimax Algorithm for Deep AUC MaximizationabstractAUC maximization is an effective approach to address the imbalanced data classification problem in federated learning. In the past few years, a couple of federated AUC maximization approaches have been developed based on the minimax optimization. However, directly solving a minimax optimization problem to maximize the AUC score cannot achieve satisfactory performance. To address this issue, we propose to maximize AUC via optimizing a federated multi-level compositional minimax problem. Specifically, we develop a novel federated multi-level compositional minimax algorithm with rigorous theoretical guarantees to solve this new learning paradigm in both algorithmic design and theoretical analysis. To the best of our knowledge, this is the first work studying the multi-level minimax optimization problem. Additionally, extensive empirical evaluations confirm the efficacy of our proposed approach. Xinwen Zhang, Ali Payani, Myungjin Lee, Richard Souvenir, Hongchang Gao |
ICML | 1 |
| 2024 | Underwater image object detection based on multi-scale feature fusion
Longyu Jiang, Xinwen Zhang |
Mach. Vis. Appl. | 4 |
| 2023 | Distributed Optimization for Big Data Analytics: Beyond MinimizationabstractThe traditional machine learning model can be formulated as an empirical risk minimization problem, which is typically optimized via stochastic gradient descent (SGD). With the emergence of big data, distributed optimization, e.g., distributed SGD, has been attracting increasing attention to facilitate machine learning models for big data analytics. However, existing distributed optimization mainly focuses on the standard empirical risk minimization problem, failing to deal with the emerging machine learning models that are beyond that category. Thus, of particular interest of this tutorial includes the stochastic minimax optimization, stochastic bilevel optimization, and stochastic compositional optimization, which covers a wide range of emerging machine learning models, e.g., model-agnostic meta-learning models, adversarially robust machine learning models, imbalanced data classification models, etc. Since these models have been widely used in big data analytics, it is necessary to provide a comprehensive introduction about the new distributed optimization algorithms designed for these models. Therefore, the goal of this tutorial is to present the state-of-the-art and recent advances in distributed minimax optimization, distributed bilevel optimization, and distributed compositional optimization. In particular, we will introduce the typical applications in each category and discuss the corresponding distributed optimization algorithms in both centralized and decentralized settings. Through this tutorial, the researchers will be exposed to the fundamental algorithmic design and basic convergence theories, and the practitioners will be able to benefit from this tutorial to apply these algorithms to real-world data mining applications. Hongchang Gao, Xinwen Zhang |
KDD | 2 |
| 2023 | Federated Compositional Deep AUC MaximizationabstractFederated learning has attracted increasing attention due to the promise of balancing privacy and large-scale learning; numerous approaches have been proposed. However, most existing approaches focus on problems with balanced data, and prediction performance is far from satisfactory for many real-world applications where the number of samples in different classes is highly imbalanced. To address this challenging problem, we developed a novel federated learning method for imbalanced data by directly optimizing the area under curve (AUC) score. In particular, we formulate the AUC maximization problem as a federated compositional minimax optimization problem, develop a local stochastic compositional gradient descent ascent with momentum algorithm, and provide bounds on the computational and communication complexities of our algorithm. To the best of our knowledge, this is the first work to achieve such favorable theoretical results. Finally, extensive experimental results confirm the efficacy of our method. Xinwen Zhang, Tianbao Yang, Richard Souvenir, Hongchang Gao |
NeurIPS | 1 |
| 2022 | Unsupervised Domain Adaptive Fundus Image Segmentation with Few Labeled Source Data
Qianbi Yu, Dongnan Liu, Chaoyi Zhang, Xinwen Zhang, Tom Weidong Cai |
BMVC | 4 |
| 2019 | ResumeGAN: An Optimized Deep Representation Learning Framework for Talent-Job Fit via Adversarial LearningabstractNowadays, it is popular to utilize online recruitment services for talent recruitment and job recommendation. Given the vast amounts of online talent profiles and job-posts, it is labor-intensive and exhausted for recruiters to manually select only a few potential candidates for further consideration, and also nontrivial for talents to find the most matched job positions. Recently, some deep learning-based approaches are developed to automatically matching the talent resumes and job requirements, and have achieved encouraging performance. In this paper, we propose a novel framework that targets the same task, but integrate different types of information in a more sophisticated way and introduce adversarial learning to learn more expressive representation. In addition, we build a dataset for model evaluation and the effectiveness of our framework is demonstrated by extensive experiments. Yong Luo 0002, Huaizheng Zhang, Yonggang Wen 0001, Xinwen Zhang |
CIKM | 4 |
| 2018 | ResumeNet: A Learning-Based Framework for Automatic Resume Quality AssessmentabstractRecruitment of appropriate people for certain positions is critical for any companies or organizations. Manually screening to select appropriate candidates from large amounts of resumes can be exhausted and time-consuming. However, there is no public tool that can be directly used for automatic resume quality assessment (RQA). This motivates us to develop a method for automatic RQA. Since there is also no public dataset for model training and evaluation, we build a dataset for RQA by collecting around 10K resumes, which are provided by a private resume management company. By investigating the dataset, we identify some factors or features that could be useful to discriminate good resumes from bad ones, e.g., the consistency between different parts of a resume. Then a neural-network model is designed to predict the quality of each resume, where some text processing techniques are incorporated. To deal with the label deficiency issue in the dataset, we propose several variants of the model by either utilizing the pair/triplet-based loss, or introducing some semi-supervised learning technique to make use of the abundant unlabeled data. Both the presented baseline model and its variants are general and easy to implement. Various popular criteria including the receiver operating characteristic (ROC) curve, F-measure and ranking-based average precision (AP) are adopted for model evaluation. We compare the different variants with our baseline model. Since there is no public algorithm for RQA, we further compare our results with those obtained from a website that can score a resume. Experimental results in terms of different criteria demonstrate effectiveness of the proposed method. We foresee that our approach would transform the way of future human resources management. Yong Luo 0002, Huaizheng Zhang, Yonggang Wen 0001, Xinwen Zhang |
ICDM | 5 |
| 2017 | Mandatory Content Access Control for Privacy Protection in Information Centric NetworksabstractSeveral Information Centric Network (ICN) architectures have been proposed as candidates for the future Internet, aiming to solve several salient problems in the current IP-based Internet architecture such as mobility, content dissemination and multi-path forwarding. In general, security and privacy are considered as essential requirements in ICN. However, existing ICN designs lack built-in privacy protection for content providers (CPs), e.g., any router in an Internet Service Provider in ICN can cache any content, which may result in information leakage. In this paper, we propose Mandatory Content Access Control (MCAC), a distributed information flow control mechanism to enable a content provider to control which network nodes can cache its contents. In MCAC, a CP defines different security labels for different contents, and content routers check these labels to decide if a content object should be cached. To ensure correct enforcement of MCAC, we also propose a design of a trusted architecture by extending existing mainstream router architectures. We evaluate the performance of MCAC in the NS-3 simulator. The simulation results show that enforcing MCAC in routers does not introduce significant overhead in content forwarding. Qi Li 0002, Ravi S. Sandhu, Xinwen Zhang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2016 | A Demonstration of Encrypted Logistics Information System
Huakang Li, Xinwen Zhang, Guozi Sun |
APWeb (2) | 2 |
| 2015 | ABSS: An Attribute-based Sanitizable Signature for Integrity of Outsourced Database with Public CloudabstractDatabase outsourcing is an important application of cloud computing, and security is one of the most critical concerns in adopting this application model, such as data privacy, query privacy, etc. Data integrity is another essential requirement for outsourced database system. When the database is outsourced to public cloud, the situation is more complex as different users may modify the data and these users may hold different privileges for different parts of the database. Furthermore, as the cloud is in charge of the management of the database, users have to rely on the cloud to guarantee data integrity. We propose ABSS to protect the integrity of outsourced database which supports fine-grained modification policy. ABSS utilizes an attribute based sanitizable signature scheme, which combining the ingredients of attribute based encryption and sanitizable signature. ABSS enables the database owner to deploy fine-grained policy of database modification and can detect illegal modifications without trusting the cloud. We also discuss the security properties and performance of ABSS to show its practicability. Lei Xu 0012, Xinwen Zhang, Xiaoxin Wu 0001, Larry Shi |
CODASPY | 2 |
| 2015 | Assessing Attack Surface with Component-Based Package Dependency
Xinwen Zhang, Xinming Ou, Liqun Chen 0002, Nigel Edwards |
NSS | 2 |
| 2015 | EASEAndroid: Automatic Policy Analysis and Refinement for Security Enhanced Android via Large-Scale Semi-Supervised Learning
Ruowen Wang, William Enck, Douglas S. Reeves, Xinwen Zhang, Peng Ning, Dingbang Xu, Wu Zhou 0001, Ahmed M. Azab |
USENIX Security Symposium | 4 |
| 2015 | Invalidating Idealized BGP Security Proposals and CountermeasuresabstractBorder Gateway Protocol (BGP) is vulnerable to routing attacks because of the lack of inherent verification mechanism. Several secure BGP schemes have been proposed to prevent routing attacks by leveraging cryptographic verification of BGP routing updates. In this paper, we present a new type of attacks, called TIGER, which aims to invalidate the “proven” security of these secure BGP schemes and allow ASes to announce forged routes even under full deployment of any existing secure BGP proposal. By launching TIGER attacks, malicious ASes can easily generate and announce forged routes which can be successfully verified by the existing secure BGP schemes. Furthermore, TIGER attacks can evade existing routing anomaly detection schemes by guaranteeing routing data-plane availability and consistency of control- and data-plane. Toward a new securing BGP scheme, we propose Anti-TIGER to detect and defend against TIGER attacks. Anti-TIGER enables robust TIGER detection by collaborations between ASes. In particular, we leverage Spread Spectrum Communication technique to watermark certain special probing packets, which manifest the existence of TIGER attacks. Anti-TIGER does not require any modifications in routing data-plane, therefore it is easy to deploy and incrementally deployable. We evaluate the effectiveness of TIGER and Anti-TIGER by experiments with real AS topologies of the Internet. Our experiment results show that TIGER attacks can successfully hijack a considerable number of prefixes. In the meanwhile, Anti-TIGER can achieve 100 percent detection ratio of TIGER attacks. Qi Li 0002, Xinwen Zhang, Purui Su |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2015 | Timing Attacks on Access Privacy in Information Centric Networks and CountermeasuresabstractIn recently proposed information centric networks (ICN), a user issues “interest” packets to retrieve contents from network by names. Once fetched from origin servers, “data” packets are replicated and cached in all routers along routing and forwarding paths, thus allowing further interests from other users to be fulfilled quickly. However, the way ICN caching and interest fulfillment work poses a great privacy risk: the time difference between responses for an interest of cached and uncached content can be used as an indicator to infer whether or not a near-by user has previously requested the same content as that requested by an adversary. This work introduces the extent to which the problem is applicable in ICN and provides several solutions that try to strike a balance between cost and benefits, and raise the bar for an adversary to apply such attack. David Mohaisen, Hesham Mekky, Xinwen Zhang, Haiyong Xie 0001, Yongdae Kim |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2015 | LIVE: Lightweight Integrity Verification and Content Access Control for Named Data NetworkingabstractNamed data networking (NDN) is a new paradigm for the future Internet wherein interest and data packets carry content names rather than the current IP paradigm of source and destination addresses. Security is built into NDN by embedding a public key signature in each data packet to enable verification of authenticity and integrity of the content. However, existing heavyweight signature generation and verification algorithms prevent universal integrity verification among NDN nodes, which may result in content pollution and denial of service attacks. Furthermore, caching and location-independent content access disables the capability of a content provider to control content access, e.g., who can cache a content and which end user or device can access it. We propose a lightweight integrity verification (LIVE) architecture, an extension to the NDN protocol, to address these two issues seamlessly. LIVE enables universal content signature verification in NDN with lightweight signature generation and verification algorithms. Furthermore, it allows a content provider to control content access in NDN nodes by selectively distributing integrity verification tokens to authorized nodes. We evaluate the effectiveness of LIVE with open source CCNx project. Our paper shows that LIVE only incurs average 10% delay in accessing contents. Compared with traditional public key signature schemes, the verification delay is reduced by over 20 times in LIVE. Qi Li 0002, Xinwen Zhang, Qingji Zheng, Ravi S. Sandhu, Xiaoming Fu 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | After we knew it: empirical study and modeling of cost-effectiveness of exploiting prevalent known vulnerabilities across IaaS cloudabstractInfrastructure as a Service (IaaS) cloud has been attracting more and more customers as it provides the highest level of flexibility by offering configurable virtual machines (VMs) and computing infrastructures. Public VM images are usually available for customers to customize and launch. However, the 1 to N mapping between VM images and running instances in IaaS makes vulnerabilities propagate rapidly across the entire public cloud. Besides, IaaS cloud naturally comes with a larger and more stable attack surface and more concentrated target resources than traditional surroundings. In this paper, we first identify the threat of exploiting prevalent vulnerabilities over public IaaS cloud with an empirical study in Amazon EC2. We find that attackers can compromise a considerable number of VMs with trivial cost. We then do a qualitative cost-effectiveness analysis of this threat. Our main result is a two-fold observation: in IaaS cloud, exploiting prevalent vulnerabilities is much more cost-effective than traditional in-house computing environment, therefore attackers have stronger incentive; Fortunately, on the other hand, cloud defenders (cloud providers and customers) also have much lower cost-loss ratio than in traditional environment, therefore they can be more effective for defending attacks. We then build a game-theoretic model and conduct a risk-gain analysis to compare exploiting and patching strategies under cloud and traditional computing environments. Our modeling indicates that under cloud environment, both attack and defense become less cost-effective as time goes by, and the earlier actioner can be more rewarding. We propose countermeasures against such threat in order to bridge the gap between current security situation and defending mechanisms. To our best knowledge, we are the first to analyze and model the threat with prevalent known-vulnerabilities in public cloud. Xinwen Zhang, Xinming Ou |
AsiaCCS | 2 |
| 2014 | Improved anonymous proxy re-encryption with CCA securityabstractOutsourcing private data and heavy computation tasks to the cloud may lead to privacy breach as attackers (e.g., malicious outsiders or cloud administrators) may correlate any relevant information to penetrate information of their interests. Therefore, how to preserve cloud users' privacy has been a top concern when adopting cloud solutions. In this paper, we investigate the identity privacy problem for the proxy re-encryption, which allows any third party (e.g., cloud) to re-encrypt ciphertexts in order to delegate the decryption right from one to another user. The relevant identity information, e.g., whose ciphertext was re-encrypted to the ciphertext under whose public key, may leak because re-encryption keys and ciphertexts (before and after re-encryption) are known to the third party. We review prior anonymity (identity privacy) notions, and find that these notions are either impractical or too weak. To address this problem thoroughly, we rigorously define the anonymity notion that not only embraces the prior anonymity notions but also captures the necessary anonymity requirement for practical applications. In addition, we propose a new and efficient proxy re-encryption scheme. The scheme satisfies the proposed anonymity notion under the Squared Decisional Bilinear Diffie-Hellman assumption and achieves security against chosen ciphertext attack under the Decisional Bilinear Diffie-Hellman assumption in the random oracle model. To the best of our knowledge, it is the first proxy re-encryption scheme attaining both chosen-ciphertext security and anonymity simultaneously. Qingji Zheng, Jiafeng Zhu, Xinwen Zhang |
AsiaCCS | 4 |
| 2014 | A Host-Based Approach for Unknown Fast-Spreading Worm Detection and ContainmentabstractThe fast-spreading worm, which immediately propagates itself after a successful infection, is becoming one of the most serious threats to today’s networked information systems. In this article, we present WormTerminator, a host-based solution for fast Internet worm detection and containment with the assistance of virtual machine techniques based on the fast-worm defining characteristic. In WormTerminator, a virtual machine cloning the host OS runs in parallel to the host OS. Thus, the virtual machine has the same set of vulnerabilities as the host. Any outgoing traffic from the host is diverted through the virtual machine. If the outgoing traffic from the host is for fast worm propagation, the virtual machine should be infected and will exhibit worm propagation pattern very quickly because a fast-spreading worm will start to propagate as soon as it successfully infects a host. To prove the concept, we have implemented a prototype of WormTerminator and have examined its effectiveness against the real Internet worm Linux/Slapper. Our empirical results confirm that WormTerminator is able to completely contain worm propagation in real-time without blocking any non-worm traffic. The major performance cost of WormTerminator is a one-time delay to the start of each outgoing normal connection for worm detection. To reduce the performance overhead, caching is utilized, through which WormTerminator will delay no more than 6% normal outgoing traffic for such detection on average. Songqing Chen, Lei Liu 0021, Xinyuan Wang 0005, Xinwen Zhang, Zhao Zhang 0010 |
ACM Trans. Auton. Adapt. Syst. | 4 |
| 2014 | Design and Implementation of Efficient Integrity Protection for Open Mobile PlatformsabstractThe security of mobile devices such as cellular phones and smartphones has gained extensive attention due to their increasing usage in people's daily life. The problem is challenging as the computing environments of these devices have become more open and general-purpose while at the same time they have the constraints of performance and user experience. We propose and implement SEIP, a simple and efficient but yet effective solution for the integrity protection of real-world cellular phone platforms, which is motivated by the disadvantages of applying traditional integrity models on these performance and user experience constrained devices. The major security objective of SEIP is to protect trusted services and resources (e.g., those belonging to cellular service providers and device manufacturers) from third-party code. We propose a set of simple integrity protection rules based upon open mobile operating system environments and application behaviors. Our design leverages the unique features of mobile devices, such as service convergence and limited permissions of user installed applications, and easily identifies the borderline between trusted and untrusted domains on mobile platforms. Our approach, thus, significantly simplifies policy specifications while still achieves a high assurance of platform integrity. SEIP is deployed within a commercially available Linux-based smartphone and demonstrates that it can effectively prevent certain malware. The security policy of our implementation is less than 20 kB, and a performance study shows that it is lightweight. Xinwen Zhang, Jean-Pierre Seifert, Onur Aciiçmez |
IEEE Trans. Mob. Comput. | 1 |
| 2013 | Protecting access privacy of cached contents in information centric networksabstractIn recently proposed information centric networks (ICN), a user issues "interest" packets to retrieve contents from network by names. Once fetched from origin servers, "data" packets are replicated and cached in all routers along routing and forwarding paths, thus allowing further interests by other users to be fulfilled quickly. However, the way ICN caching works poses a great privacy risk: the time difference between responses for an interest of cached and uncached content can be used as an indicator to infer whether or not a near-by user has previously requested the same content as that requested by an adversary. This work introduces the extent to which the problem is applicable in ICN and provides several solutions that try to strike a balance between their cost and benefits, and raise the bar for the adversary to apply such attack. David Mohaisen, Xinwen Zhang, Max Schuchard, Haiyong Xie 0001, Yongdae Kim |
AsiaCCS | 2 |
| 2013 | AppInk: watermarking android apps for repackaging deterrenceabstractWith increased popularity and wide adoption of smartphones and mobile devices, recent years have seen a new burgeoning economy model centered around mobile apps. However, app repackaging, among many other threats, brings tremendous risk to the ecosystem, including app developers, app market operators, and end users. To mitigate such threat, we propose and develop a watermarking mechanism for Android apps. First, towards automatic watermark embedding and extraction, we introduce the novel concept of manifest app, which is a companion of a target Android app under protection. We then design and develop a tool named AppInk, which takes the source code of an app as input to automatically generate a new app with a transparently-embedded watermark and the associated manifest app. The manifest app can be later used to reliably recognize embedded watermark with zero user intervention. To demonstrate the effectiveness of AppInk in preventing app repackaging, we analyze its robustness in defending against distortive, subtractive, and additive attacks, and then evaluate its resistance against two open source repackaging tools. Our results show that AppInk is easy to use, effective in defending against current known repackaging threats on Android platform, and introduces small performance overhead. Wu Zhou 0001, Xinwen Zhang, Xuxian Jiang |
AsiaCCS | 2 |
| 2013 | Information-centric networking based homenet
Ravishankar Ravindran, Trisha Biswas, Xinwen Zhang, Asit Chakraborti, Guoqiang Wang 0001 |
IM | 3 |
| 2013 | Contextualized information-centric home networkabstractWe deploy information-centric networks (ICN) to serve several applications including content distribution, vehicle-to-vehicle communication (V2V), home networks (homenet), and sensor networks. These applications require policy and context-based interaction between service producers and consumers. We visualize the ICN service layer as a contextualized information-centric bus (CIBUS), over which diverse sets of service producers and consumers co-exist. We develop a prototype and demonstrate several desirable features of ICN for homenets such as contextual service publishing and subscription, zero-configuration based node and service discovery, policy based routing and forwarding with name-based firewall, and device-to-device communication. Furthermore the prototype is applicable to both ad hoc and infrastructure settings, and can deal with diverse devices and services. Trisha Biswas, Asit Chakraborti, Ravishankar Ravindran, Xinwen Zhang, Guoqiang Wang 0001 |
SIGCOMM | 4 |
| 2013 | Behavioral Attestation for Web Services using access policies
Masoom Alam, Xinwen Zhang, Mohammad Nauman, Tamleek Ali, Sajid Anwar 0001, Quratulain Alam |
Multim. Tools Appl. | 2 |
| 2012 | Protecting access privacy of cached contents in information centric networksabstractIn information centric network (ICN), contents are fetched by their names from caches deployed in the network or from origin servers. Once the contents are fetched from the origin server, it is replicated and cached in all routers along the routing and forwarding paths from the user that issues the interest to the origin server, thus allowing further "interests" by other users to be fulfilled quickly. However, the way ICN caching and interest fulfillment work pose a great privacy risk; the time difference between response for interest of cached and uncached contents can be used as an indicator to infer whether or not a near-by user previously requested the same contents requested by the adversary. This work introduces the extent to which the problem is applicable in ICN and provides several solutions to address it. David Mohaisen, Xinwen Zhang, Max Schuchard, Haiyong Xie 0001, Yongdae Kim |
CCS | 2 |
| 2012 | CL-PRE: a certificateless proxy re-encryption scheme for secure data sharing with public cloudabstractWe propose CL-PRE, a certificateless proxy re-encryption scheme for secure data sharing with public cloud, which leverages maximal cloud resources to reduce the computing and communication cost for data owner. Towards running proxy in public cloud environment, we further propose multi-proxy CL-PRE and randomized CL-PRE, which enhance the security and robustness of CL-PRE. We implement all CL-PRE schemes and evaluate their security and performance. Lei Xu 0012, Xiaoxin Wu 0001, Xinwen Zhang |
AsiaCCS | 3 |
| 2012 | STC 2012: the seventh ACM workshop on scalable trusted computingabstractTrusted computing plays a pivotal role to facilitate a party to evaluate the integrity of others or to ensure desired security assurance, which is a very challenging task in large-scale and heterogeneous computing environments. Built upon the success from 2006 to 2011, the seventh ACM Workshop on Scalable Trusted Computing continues to serve as a forum for researchers as well as practitioners to disseminate and discuss recent advances and emerging issues. This proceedings includes selected papers that focus on system architectures, enabling mechanisms, and novel applications of trusted computing. Xinwen Zhang, Xuhua Ding |
CCS | 1 |
| 2012 | Towards end-to-end secure content storage and delivery with public cloudabstractRecent years have witnessed the trend of leveraging cloud-based services for large scale content storage, processing, and distribution. Security and privacy are among top concerns for the public cloud environments. Towards end-to-end content security, we propose and implement CloudSeal, a scheme for securely sharing and distributing content via the public cloud. CloudSeal ensures the confidentiality of content in the public cloud environments with flexible access control policies for subscribers and efficient content distribution via content delivery network. Huijun Xiong, Xinwen Zhang, Danfeng Yao, Xiaoxin Wu 0001, Yonggang Wen 0001 |
CODASPY | 2 |
| 2012 | Supporting seamless mobility in named data networkingabstractInformation-Centric Networking (ICN) architectures aim to replace current host-centric IP architecture with an information-centric one for efficient, secure, and reliable dissemination of information. ICN is built on several salient principles such as publish and subscribe paradigm, named content, innetwork caching, and security over atomic information objects. These features allow a data chunk to be cached and retrieved from multiple nodes in the network, and can be validated without building a connection with its host. Though these tenets simplify the mobility problem in ICN, seamless mobility for real-time applications still demands a control plane. We propose three cross-layer network-assisted seamless mobility schemes: (1) point of attachment based, (2) rendezvous point based, and (3) multicast based, with the overall design objective of minimizing the loss of interests and data during a handoff scenario. This paper describes these schemes in named data networking (NDN) framework and discusses their trade-offs in terms of control and forwarding plane requirements. Ravishankar Ravindran, Samantha Lo, Xinwen Zhang, Guoqiang Wang 0001 |
ICC | 3 |
| 2012 | ThinkAir: Dynamic resource allocation and parallel execution in the cloud for mobile code offloadingabstractSmartphones have exploded in popularity in recent years, becoming ever more sophisticated and capable. As a result, developers worldwide are building increasingly complex applications that require ever increasing amounts of computational power and energy. In this paper we propose ThinkAir, a framework that makes it simple for developers to migrate their smartphone applications to the cloud. ThinkAir exploits the concept of smartphone virtualization in the cloud and provides method-level computation offloading. Advancing on previous work, it focuses on the elasticity and scalability of the cloud and enhances the power of mobile cloud computing by parallelizing method execution using multiple virtual machine (VM) images. We implement ThinkAir and evaluate it with a range of benchmarks starting from simple micro-benchmarks to more complex applications. First, we show that the execution time and energy consumption decrease two orders of magnitude for a N-queens puzzle application and one order of magnitude for a face detection and a virus scan application. We then show that a parallelizable application can invoke multiple VMs to execute in the cloud in a seamless and on-demand manner such as to achieve greater reduction on execution time and energy consumption. We finally use a memory-hungry image combiner tool to demonstrate that applications can dynamically request VMs with more computational power in order to meet their computational requirements. Sokol Kosta, Andrius Aucinas, Pan Hui 0001, Richard Mortier, Xinwen Zhang |
INFOCOM | 5 |
| 2012 | Chrome Extensions: Threat Analysis and Countermeasures
Lei Liu 0021, Xinwen Zhang, Guanhua Yan, Songqing Chen |
NDSS | 2 |
| 2012 | VehiCloud: Cloud Computing Facilitating Routing in Vehicular NetworksabstractEstablishing reliable routing among highly mobile vehicles is a challenging problem in vehicular networks. Towards this issue, we present VehiCloud, a novel cloud computing architecture that leverages emerging cloud computing technologies to deal with unreliable inter-vehicle communications and extend the restricted computational capabilities of mobile devices. A way-point information framework (WIF) is devised within the VehiCloud architecture, aiming to provide routing service for vehicular network, where each vehicle serves as a mobile service node and predicts its future locations by generating way point messages, which describe the trajectory of the vehicle's movement. A decision module in VehiCloud collects vehicles' way points and makes routing decisions for inter-vehicle communication. Selected paths of the routing are globally optimized in terms of message delivery ratio by respecting the constraints of end-to-end delay and communication cost. Our implementation of VehiCloud and real-road experiments demonstrate that it is practical and efficient to address fundamental routing problems for vehicular networks. Dijiang Huang, Xinwen Zhang |
TrustCom | 3 |
| 2012 | An Android runtime security policy enforcement framework
Hammad Banuri, Masoom Alam, Shahryar Khan, Jawad Manzoor, Bahar Ali, Yasar Khan, Mohsin Yaseen, Mir Nauman Tahir, Tamleek Ali, Quratulain Alam, Xinwen Zhang |
Pers. Ubiquitous Comput. | 11 |
| 2012 | Remote Attestation with Domain-Based Integrity Model and Policy AnalysisabstractWe propose and implement an innovative remote attestation framework called DR@FT for efficiently measuring a target system based on an information flow-based integrity model. With this model, the high integrity processes of a system are first measured and verified, and these processes are then protected from accesses initiated by low integrity processes. Toward dynamic systems with frequently changed system states, our framework verifies the latest state changes of a target system instead of considering the entire system information. Our attestation evaluation adopts a graph-based method to represent integrity violations, and the graph-based policy analysis is further augmented with a ranked violation graph to support high semantic reasoning of attestation results. As a result, DR@FT provides efficient and effective attestation of a system's integrity status, and offers intuitive reasoning of attestation results for security administrators. Our experimental results demonstrate the feasibility and practicality of DR@FT. Wenjuan Xu, Xinwen Zhang, Hongxin Hu, Gail-Joon Ahn, Jean-Pierre Seifert |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2012 | Enhancing the Trust of Internet Routing With Lightweight Route AttestationabstractThe weak trust model in Border Gateway Protocol (BGP) introduces severe vulnerabilities for Internet routing including active malicious attacks and unintended misconfigurations. Although various secure BGP solutions have been proposed, the complexity of security enforcement and data-plane attacks still remain open problems. We propose TBGP, a trusted BGP scheme aiming to achieve high authenticity of Internet routing with a simple and lightweight attestation mechanism. TBGP introduces a set of route update and withdrawal rules that, if correctly enforced by each router, can guarantee the authenticity and integrity of route information that is announced to other routers in the Internet. To verify this enforcement, an attestation service running on each router provides interfaces for a neighboring router to challenge the integrity of its routing stack, enforced rules, and the attestation service itself. If this attestation succeeds, the neighboring router updates its routing table or announces the route to its neighbors, following the same rules. Thus, a router on a routing path only needs to verify one neighbor's routing status to ensure that the route information is valid. Through this, TBGP builds a transitive trust relationship among all routers on a routing path. We implement a prototype of TBGP to investigate its practicality. In our implementation, we use identity-based signature and trusted computing techniques to further reduce the complexity of security operations. Our security analysis and performance study shows that TBGP can achieve the security goals of BGP with significantly better convergence performance and lower computation overhead than existing secure BGP solutions. Qi Li 0002, Mingwei Xu 0001, Xinwen Zhang, Patrick P. C. Lee, Ke Xu 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2011 | Enhancing the trust of internet routing with lightweight route attestationabstractThe weak trust model in Border Gateway Protocol (BGP) introduces severe vulnerabilities for Internet routing including active malicious attacks and unintended misconfigurations. Although various secure BGP solutions have been proposed, they share similar weaknesses such as high complexity of security enforcement and incapability of data-plane attack prevention. We propose TBGP, a trusted BGP scheme aiming to achieve high authenticity of Internet routing with a simple and lightweight attestation mechanism. TBGP introduces a set of route update and withdrawal rules that, if correctly enforced by each router, can guarantee the authenticity and integrity of route information that is announced to other routers in the Internet. Through this, TBGP builds a transitive trust relationship among all routers on a routing path. We implement a prototype of TBGP to investigate its practicality. In our implementation, we use identity-based signature (IBS) and trusted computing (TC) techniques to further reduce the complexity of security operations. The performance study show that TBGP can achieve significantly better convergence performance and lower computation overhead than existing secure BGP solutions. Qi Li 0002, Mingwei Xu 0001, Xinwen Zhang, Patrick P. C. Lee, Ke Xu 0002 |
AsiaCCS | 4 |
| 2011 | Poster: a certificateless proxy re-encryption scheme for cloud-based data sharing
Xiaoxin Wu 0001, Lei Xu 0012, Xinwen Zhang |
CCS | 3 |
| 2011 | Towards name-based trust and security for content-centric networkabstractTrust and security have been considered as built-in properties for future Internet architecture. Leveraging the concept of named content in recently proposed information centric network, we propose a name-based trust and security protection mechanism. Our scheme is built with identity-based cryptography (IBC), where the identity of a user or device can act as a public key string. Uniquely, in named content network such as content-centric network (CCN), a content name or its prefixes can be used as public identities, with which content integrity and authenticity can be achieved with IBC algorithms. The trust of a content is seamlessly integrated with the verification of the content's integrity and authenticity with its name or prefix, instead of the public key certificate of its publisher. In addition, flexible confidentiality protection is enabled between content publishers and consumers. For scalable deployment purpose, we further propose to use a hybrid scheme combined with traditional public-key infrastructure (PKI) and IBC. We have implemented this scheme with CCNx open source project on Android. Xinwen Zhang, Katharine Chang, Huijun Xiong, Yonggang Wen 0001, Guangyu Shi, Guoqiang Wang 0001 |
ICNP | 1 |
| 2011 | xDAuth: a scalable and lightweight framework for cross domain access control and delegationabstractCross domain resource sharing and collaborations have become pervasive in today's service oriented organizations. Existing approaches for the realization of cross domain access control are either focused on the model level only without concrete implementation mechanisms, or not general enough to provide a flexible framework for enterprise web applications. In this paper, we present xDAuth, a framework for the realization of cross domain access control and delegation with RESTful web service architecture. While focusing on real issues under the context of cross domain access scenarios such as no predefined trust relationship between a service provider domain and service requestor domain, xDAuth leverages existing web technologies to realize desired security requirements while supporting flexible and scalable security policies and privacy protection with low performance overhead. We have implemented xDAuth in a medical module in OpenERP, an open source ERP system. Our evaluation demonstrates that xDAuth is a feasible framework towards general cross domain access control for service oriented architectures. Masoom Alam, Xinwen Zhang, Kamran Khan |
SACMAT | 2 |
| 2011 | CloudSeal: End-to-End Content Protection in Cloud-Based Storage and Delivery Services
Huijun Xiong, Xinwen Zhang, Danfeng Yao |
SecureComm | 2 |
| 2011 | Patient-centric authorization framework for electronic healthcare services
Gail-Joon Ahn, Hongxin Hu, Michael J. Covington, Xinwen Zhang |
Comput. Secur. | 5 |
| 2011 | Towards an Elastic Application Model for Augmenting the Computing Capabilities of Mobile Devices with Cloud Computing
Xinwen Zhang, Anugeetha Kunjithapatham, Sangoh Jeong, Simon Gibbs |
Mob. Networks Appl. | 1 |
| 2011 | Runtime Administration of an RBAC Profile for XACMLabstractThe eXtensible Access Control Markup Language (XACML) is the de facto language to specify access control policies for web services. XACML has an RBAC profile (XACML-RBAC) to support role-based access control policies. We extend this profile with an administrative RBAC profile, which we refer to as the XACML-ARBAC profile. One of the advantages of doing so is to use policies based on RBAC model to administrate XACML-RBAC policies. Because using permissions granted by XACML-ARBAC policies alter XACML-RBAC policies, enforcing XACML-ARBAC polices requires some concurrency control within XACML access controller's runtime. In order to solve this concurrency problem, we propose a session-aware administrative model for RBAC, and enhance the XACML policy evaluation runtime using a locking mechanism. Experimental study shows reconcilable performance characteristics of our enhancements to Sun's XACML reference implementation. Duminda Wijesekera, Xinwen Zhang |
IEEE Trans. Serv. Comput. | 3 |
| 2010 | Apex: extending Android permission model and enforcement with user-defined runtime constraintsabstractAndroid is the first mass-produced consumer-market open source mobile platform that allows developers to easily create applications and users to readily install them. However, giving users the ability to install third-party applications poses serious security concerns. While the existing security mechanism in Android allows a mobile phone user to see which resources an application requires, she has no choice but to allow access to all the requested permissions if she wishes to use the applications. There is no way of granting some permissions and denying others. Moreover, there is no way of restricting the usage of resources based on runtime constraints such as the location of the device or the number of times a resource has been previously used. In this paper, we present Apex -- a policy enforcement framework for Android that allows a user to selectively grant permissions to applications as well as impose constraints on the usage of resources. We also describe an extended package installer that allows the user to set these constraints through an easy-to-use interface. Our enforcement framework is implemented through a minimal change to the existing Android code base and is backward compatible with the current security mechanism. Mohammad Nauman, Sohail Khan, Xinwen Zhang |
AsiaCCS | 3 |
| 2010 | DR@FT: Efficient Remote Attestation Framework for Dynamic Systems
Wenjuan Xu, Gail-Joon Ahn, Hongxin Hu, Xinwen Zhang, Jean-Pierre Seifert |
ESORICS | 4 |
| 2010 | SEIP: Simple and Efficient Integrity Protection for Open Mobile Platforms
Xinwen Zhang, Jean-Pierre Seifert, Onur Aciiçmez |
ICICS | 1 |
| 2010 | MAuth: A Fine-Grained and User-centric Permission Delegation Framework for Multi-mashup Web ServicesabstractMashups are a new breed of interactive web applications that aggregate and stitch together data retrieved from one or more sources to create an entirely new and innovative set of services. The paradigm is not limited to social networks and many enterprises are redesigning their business processes to create interactive systems in the form of mashups. However, protecting users' private data from unauthorized access in mashups is a challenging security problem. Existing solutions for addressing the various authorization problems are limited due to all-or-nothing policy, third party dependence and scalability issues. In this paper, we present a general permission delegation model for mashups that is fine-grained, user centric and scalable. This contribution has the following objectives: We formally specify the dependency relationships among multiple web applications. Dependency relationships are categorized on the basis of specific data items. We present an extensible reference architecture for configuring multiple web applications and a session management protocol. Masoom Alam, Xinwen Zhang, Mohammad Nauman, Sohail Khan, Quratulain Alam |
SERVICES | 2 |
| 2010 | VMDriver: A Driver-Based Monitoring Mechanism for VirtualizationabstractMonitoring virtual machine (VM) is an essential function for virtualized platforms. Existing solutions are either coarse-grained - monitoring in granularity of VM level, or not general - only support specific monitoring functions for particular guest operating system (OS). Thus they do not satisfy the monitoring requirement in large-scale server cluster such as data center and public cloud platform, where each physical platform runs hundreds of VMs with different guest OSes. In this paper, we propose VMDriver, a general and fine-grained approach for virtualization monitoring. The novel design of VMDriver is the separation of event interception point in VMM level and rich guest OS semantic reconstructions in management domain. With this design, variant monitoring drivers in management domain can mask the differences of guest OSes. We implement VMDriver on Xen and our experimental study shows that it introduces very small performance overhead. We demonstrate its generality by inspecting four aspects information about the target virtual machines with different guest OSes. The unified interface of VMDriver brings convenience to develop complex monitoring tools for distributed virtualization environment. Guofu Xiang, Hai Jin 0001, Deqing Zou, Xinwen Zhang, Sha Wen, Feng Zhao 0003 |
SRDS | 4 |
| 2010 | pBMDS: a behavior-based malware detection system for cellphone devicesabstractComputing environments on cellphones, especially smartphones, are becoming more open and general-purpose, thus they also become attractive targets of malware. Cellphone malware not only causes privacy leakage, extra charges, and depletion of battery power, but also generates malicious traffic and drains down mobile network and service capacity. In this work we devise a novel behavior-based malware detection system named pBMDS, which adopts a probabilistic approach through correlating user inputs with system calls to detect anomalous activities in cellphones. pBMDS observes unique behaviors of the mobile phone applications and the operating users on input and output constrained devices, and leverages a Hidden Markov Model (HMM) to learn application and user behaviors from two major aspects: process state transitions and user operational patterns. Built on these, pBDMS identifies behavioral differences between malware and human users. Through extensive experiments on major smartphone platforms, we show that pBMDS can be easily deployed to existing smartphone hardware and it achieves high detection accuracy and low false positive rates in protecting major applications in smartphones. Liang Xie 0002, Xinwen Zhang, Jean-Pierre Seifert, Sencun Zhu |
WISEC | 2 |
| 2010 | Building dynamic and transparent integrity measurement and protection for virtualized platform in cloud computingabstractAbstract In the cloud computing infrastructure, there is an increasing demand to maintain and verify the integrity of software stacks running on remote systems and protect users' sensitive data. However, due to the fact that software stacks running on cloud platforms are usually provided and maintained by different authorities (or providers) who are potentially untrusting to each other, the problem of measuring and protecting runtime system integrity becomes very challenging and has not been well addressed yet. In this paper, we present an integrity measurement and protection architecture for software stacks running on a guest operating system (OS) of a virtualized platform in cloud environment. Our solution does not change the guest OS, and thus is transparent to the OS authority. Furthermore, our architecture ensures that sensitive information of users is protected once the integrity of software stacks is broken during runtime. We implement our solution on Xen, and present a simple prototype‐based Nimbus. We demonstrate the capability of dynamically detecting the integrity change of programs in cloud computing, and our evaluation results show that the solution is effective for integrity protection with acceptable performance overhead. Copyright © 2010 John Wiley & Sons, Ltd. Ge Cheng, Hai Jin 0001, Deqing Zou, Xinwen Zhang |
Concurr. Comput. Pract. Exp. | 4 |
| 2009 | Exploitation and threat analysis of open mobile devicesabstractThe increasingly open environment of mobile computing systems such as PDAs and smartphones brings rich applications and services to mobile users. Accompanied with this trend is the growing malicious activities against these mobile systems, such as information leakage, service stealing, and power exhaustion. Besides the threats posed against individual mobile users, these unveiled mobile devices also open the door for more serious damage such as disabling critical public cyber physical systems that are connected to the mobile/wireless infrastructure. The impact of such attacks, however, has not been fully recognized. Lei Liu 0021, Xinwen Zhang, Guanhua Yan, Songqing Chen |
ANCS | 2 |
| 2009 | A Secure DVB Set-Top Box via Trusting Computing TechnologiesabstractrdquoThis paper presents a very natural "killer applcation" of modern Commercially Off The Shelf (COTS) available Trusted Computing technologies. The application which we propose is a secure and cost optimized DVB Set-top Box. Our respective reference architecture is exclusively build upon such COTS Trusted Computing technologies and completely avoids the use of any proprietary and thus expensive hardware. Particularly, we will use an orchestration of the following TC concepts from the PC field and standardized by the Trusted Computing Group: Secure Boot, Remote Attestation, Trusted Channels, Virtualization for Domain Isolation, and the Trusted Platform Module (TPM). The Trusted Domain Isolation concept (as realized through Trusted Virtualization) allows the simple subscription to different Service Providers (SP) without the need of any SP-specific hardware requirements. The vast computing power of modern CPU architectures allows for the pure software virtualization of any SP-proprietary hardware. In addition to that isolation concept, the novel hardware assisted security ingredients of modern CPUs allow in combination with the TPM for a verifiable evidence of a tamper-free execution environment for the different SP's. I.e., at all times during the execution of a SP's "virtual set-top box", the respective SP is able to remotely request an attestation of the whole execution platform and ensure its fundamental system integrity. This attestation proves either that no "malicous platform tampering" or "unintended platform use" is happening, or in case that it fails, it gives the SP the possibility to deny further services by simply cutting the content delivery channel. Thus, at all times we can guarantee the various SP's strong security assurances. Moreover, the nowadays very well understood and very efficient (even real-time capable!) virtualization concept allows a simple and efficient migration of different SP architectures to such a universal DVB Set-top Box. In some cases a simple binary migration with only little modifications might be possible. Also, our architecture inherently supports the easy integration of an open but strongly isolated user partition, thus allowing the user for a kind of his own PC within his home TV and Set-top Box combination. Moreover, this also allows for an elegant realization of very recent initiatives aiming to merge the home TV experience with the full Web experience (e.g. See'N'Search [27]). In addition to being a very natural killer application of such Trusted Computing. Onur Aciiçmez, Jean-Pierre Seifert, Xinwen Zhang |
CCNC | 3 |
| 2009 | Building a stateful reference monitor with coloured petri netsabstractThe need for collaboration and information sharing has been recently growing dramatically with the convergence of outsourcing and off shoring, the increasing need to cut costs through cooperative agreements between partners as well as competitors, and the rise in the demand for a high-quality health Basel Katt, Michael Hafner, Xinwen Zhang |
CollaborateCom | 3 |
| 2009 | A usage control policy specification with Petri netsabstractIn this paper we propose a novel usage control policy specification based on Coloured Petri Nets formalism. Recently, usage control has been proposed in order to overcome the shortcomings of transitional access control that fails to meet new security requirements of today's highly dynamic and distri Basel Katt, Michael Hafner, Xinwen Zhang |
CollaborateCom | 3 |
| 2009 | Towards System Integrity Protection with Graph-Based Policy Analysis
Wenjuan Xu, Xinwen Zhang, Gail-Joon Ahn |
DBSec | 2 |
| 2009 | Behavioral Attestation for Business ProcessesabstractService oriented architecture (SOA) is an architectural paradigm that enables dynamic composition of heterogeneous, independent, multi-vendor business services. A prerequisite for such inter-organizational workflows is the establishment of trustworthiness, which is mostly achieved through non-technical measures such as legislation, and/or social consent that businesses, or organizations simply pledge themselves to adhere. In our viewpoint, a business process can only be trustworthy if the behavior of all services in it is trustworthy. Trusted Computing Group (TCG) has defined an open set of specifications for the establishment of trustworthiness through a hardware root-of-trust. This paper has three objectives: firstly, the behavior of individual services in a business process is formally specified. Secondly, in order to overcome the inherent weaknesses of trust management through software alone, a hardware root of-trust devised by the TCG, is used for the measurement of the behavior of individual services in a business process. Finally, a verification mechanism is detailed through which the trustworthiness of a business process can be verified. Masoom Alam, Mohammad Nauman, Xinwen Zhang, Tamleek Ali, Patrick C. K. Hung |
ICWS | 3 |
| 2009 | VirusMeter: Preventing Your Cellphone from Spies
Lei Liu 0021, Guanhua Yan, Xinwen Zhang, Songqing Chen |
RAID | 3 |
| 2009 | Patient-centric authorization framework for sharing electronic health recordsabstractIn modern healthcare environments, a fundamental requirement for achieving continuity of care is the seamless access to distributed patient health records in an integrated and unified manner, directly at the point of care. However, Electronic Health Records (EHRs) contain a significant amount of sensitive information, and allowing data to be accessible at many different sources increases concerns related to patient privacy and data theft. Access control solutions must guarantee that only authorized users have access to such critical records for legitimate purposes, and access control policies from distributed EHR sources must be accurately reflected and enforced accordingly in the integrated EHRs. Gail-Joon Ahn, Hongxin Hu, Michael J. Covington, Xinwen Zhang |
SACMAT | 5 |
| 2009 | Designing System-Level Defenses against Cellphone MalwareabstractCellphones are increasingly becoming attractive targets of various malware, which not only cause privacy leakage, extra charges, and depletion of battery power, but also introduce malicious traffic into networks. In this work, we seek system-level solutions to handle these security threats. Specifically, we propose a mandatory access control-based defense to blocking malware that launch attacks through creating new processes for execution. To combat more elaborated malware which redirect program flows of normal applications to execute malicious code within a legitimate security domain, we further propose using artificial intelligence (AI) techniques such as Graphic Turing test. Through extensive experiments based on both Symbian and Linux smartphones, we show that both our system-level countermeasures effectively detect and block cellphone malware with low false positives, and can be easily deployed on existing smartphone hardware. Liang Xie 0002, Xinwen Zhang, Ashwin Chaugule, Trent Jaeger, Sencun Zhu |
SRDS | 2 |
| 2009 | Towards secure dynamic collaborations with group-based RBAC model
Qi Li 0002, Xinwen Zhang |
Comput. Secur. | 2 |
| 2008 | A Trusted Mobile Phone PrototypeabstractDue to the increasing security demands in mobile devices, the Trusted Computing Group (TCG) formed a dedicated Mobile Phone Working Group (MPWG) to address these security needs. MPWG recently released a Trusted Mobile Phone Reference Architecture (TCG-MPRA) specification that integrates well-known security concepts (TPM, isolation, Integrity Measurement and Verification (IMV), etc.) from the trusted" PC universe, tailored for mobile phones. The business needs of the mobile phone industry mandate 4 different stakeholders (platform owners): device "manufacturer, cellular service provider, general service provider, and the end-user. The specification requires separate trusted and isolated operational domains (Trusted Engines) for each stakeholder. Although the TCG MPWG does not explicitly prescribe a specific technical realization of these trusted engines, a general consensus is use of established (Trusted) Virtualization concepts from corresponding PC architectures. However, we will demo another isolation technique specifically crafted for mobile platforms that respects their resource limitations. We achieve this goal by realizing the MPWG specification by leveraging SELinux which provides a generic domain isolation concept at the kernel level. In addition to utilizing SELinux to realize mobile phone specific (isolated) operational domains, we are also able to seamlessly integrate the important IMV concept into our SELinux-based Trusted Mobile Phone architecture. In our demo we will present a hardware prototvpe, representing a generic mobile phone, implementing the TCG MPWG specification. First, we will "Securely Boot" our TC-aware SELinux kernel out of a hardware Mobile Trusted Module (MTM). Next, we will show how easy and efficient we can realize the 4 isolated Trusted Engines. The value of the Trusted Engines and the fundamental IMV principle will be demonstrated through successful mitigation of two automatic Linux cell-phone worms. The prototype in this demo is in effect, the world's first novel, efficient and inherently secure implementation of MPWG specification. Onur Aciiçmez, Afshin Latifi, Jean-Pierre Seifert, Xinwen Zhang |
CCNC | 4 |
| 2008 | Usage control platformization via trustworthy SELinuxabstractContinuous access control after an object is released into a distributed environment has been regarded as the usage control problem and has been investigated by different researchers in various papers. However, the enabling technology for usage control is a challenging problem and the space has not been fully explored yet. In this paper we identify the general requirements of a trusted usage control enforcement in heterogeneous computing environments, and also propose a general platform architecture to meet these requirements. Masoom Alam, Jean-Pierre Seifert, Qi Li 0002, Xinwen Zhang |
AsiaCCS | 4 |
| 2008 | Access Control Model for Sharing Composite Electronic Health Records
Gail-Joon Ahn, Michael J. Covington, Xinwen Zhang |
CollaborateCom | 4 |
| 2008 | Access control in Group Communication SystemsabstractWith advances in distributed computing technologies, group communication systems (GCS) have received a lot of attentions. Besides reliable and ordered message delivery services, these applications require plenty of security services, such as data secrecy, data integrity, and user authentication. However, less work has been invested on how to integrate authorization scheme within efficient communication systems, especially for group collaborations. In this paper, we present a flexible and efficient authorization scheme which provides group-level fine-grained access control and can be easily integrated to existing GCS. More specifically, we propose the concept of virtual group (VG) and automatic access control policy generation mechanism to realize secure collaborations between different groups. We implement a prototype with Spread and our experimental results demonstrate the efficiency and scalability of our authorization scheme. Qi Li 0002, Xinwen Zhang |
ISCC | 3 |
| 2008 | Model-based behavioral attestationabstractRemote attestation is an important characteristic of trusted computing technology which provides reliable evidence that a trusted environment actually exists. Existing approaches for the realization of remote attestation measure the trustworthiness of a target platform from its binaries, configurations, properties or security policies. All these approaches are low-level attestation techniques only, and none of them define what a trusted behavior actually is and how to specify it. In this paper, we present a novel approach where the trustworthiness of a platform is associated with the behavior of a policy model. In our approach, the behavior of a policy model is attested rather than a software or hardware platform. Thus, the attestation feature is not tied to a specific software or hardware platform, or to a particular remote attestation technique, or to an individual type of security policy. We select usage control (UCON) as our target policy model as it is a comprehensive and exible model. We propose a framework to identify, specify, and attest different behaviors of UCON. Masoom Alam, Xinwen Zhang, Mohammad Nauman, Tamleek Ali, Jean-Pierre Seifert |
SACMAT | 2 |
| 2008 | A general obligation model and continuity: enhanced policy enforcement engine for usage controlabstractThe usage control model (UCON) has been proposed to augment traditional access control models by integrating authorizations, obligations, and conditions and providing the properties of decision continuity and attribute mutability. Several recent work have applied UCON to support security requirements in different computing environments such as resource sharing in collaborative computing systems and data control in remote platforms. In this paper we identify two individual but interrelated problems of the original UCON model and recent implementations: oversimplifying the concept of usage session of the model, and the lack of comprehensive ongoing enforcement mechanism of implementations. We extend the core UCON model with continuous usage sessions thus extensively augment the expressiveness of obligations in UCON, and then propose a general, continuity-enhanced and configurable usage control enforcement engine. Finally we explain how our approach can satisfy flexible security requirements with an implemented prototype for a healthcare information system. Basel Katt, Xinwen Zhang, Ruth Breu, Michael Hafner, Jean-Pierre Seifert |
SACMAT | 2 |
| 2008 | Toward a Usage-Based Security Framework for Collaborative Computing SystemsabstractCollaborative systems such as Grids provide efficient and scalable access to distributed computing capabilities and enable seamless resource sharing between users and platforms. This heterogeneous distribution of resources and the various modes of collaborations that exist between users, virtual organizations, and resource providers require scalable, flexible, and fine-grained access control to protect both individual and shared computing resources. In this article we propose a usage control (UCON) based security framework for collaborative applications, by following a layered approach with policy, enforcement, and implementation models, called the PEI framework. In the policy model layer, UCON policies are specified with predicates on subject and object attributes, along with system attributes as conditional constraints and user actions as obligations. General attributes include not only persistent attributes such as role and group memberships but also mutable usage attributes of subjects and objects. Conditions in UCON can be used to support context-based authorizations in ad hoc collaborations. In the enforcement model layer, our novel framework uses a hybrid approach for subject attribute acquisition with both push and pull modes. By leveraging attribute propagations between a centralized attribute repository and distributed policy decision points, our architecture supports decision continuity and attribute mutability of the UCON policy model, as well as obligation evaluations during policy enforcement. As a proof-of-concept, we implement a prototype system based on our proposed architecture and conduct experimental studies to demonstrate the feasibility and performance of our approach. Xinwen Zhang, Masayuki Nakae, Michael J. Covington, Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2007 | SecureBus: towards application-transparent trusted computing with mandatory access controlabstractThe increasing number of software-based attacks has attracted substantial efforts to prevent applications from malicious interference. For example, Trusted Computing (TC) technologies have been recently proposed to provide strong isolation on application platforms. On the other hand, today pervasively available computing cycles and data resources have enabled various distributed applications that require collaboration among different application processes. These two conflicting trends grow in parallel. While much existing research focuses on one of these two aspects, a few authors have considered simultaneously providing strong isolation as well as collaboration convenience, particularly in the TC environment. However, none of these schemes is transparent. That is, they require modifications either of legacy applications or the underlying Operating System (OS).In this paper, we propose the SecureBus (SB) architecture, aiming to provide strong isolation and flexible controlled information flow and communication between processes at runtime. Since SB is application and OS transparent, existing applications can run without changes to commodity OS's. Furthermore, SB enables the enforcement of general access control policies, which is required but difficult to achieve for typical legacy applications. To study its feasibility and performance overhead, we have implemented a prototype system based on User-Mode Linux. Our experimental results show that SB can effectively achieve its design goals. Xinwen Zhang, Michael J. Covington, Songqing Chen, Ravi S. Sandhu |
AsiaCCS | 1 |
| 2007 | Towards a Times-Based Usage Control Model
Baoxian Zhao, Ravi S. Sandhu, Xinwen Zhang, Xiaolin Qin |
DBSec | 3 |
| 2007 | A Model-Driven Framework for Trusted Computing Based SystemsabstractExisting approaches for Trust Management through software alone - by their very principle - are uncompromising and have inherent weaknesses. Once the information leaves the service provider platform, there is no way to guarantee the integrity of the information on the client (or service requestor) platform. The Trusted Computing Group proposed a quantum leap in security, a hardware based "root of trust" by which the integrity of a platform - be a client or service provider can be verified. However, there is no approach for the integration of this novel but essentially straight forward concept into the distributed application development. We believe that the complexity of Trusted Computing (TC) is one of the key factors that will hinder its successful integration within the web services based distributed application realm. Model-driven techniques offer a promising approach to alleviate the complexity of platforms. This contribution has three objectives. First, we detail SECTET - a model-driven framework for leveraging TC concepts at a higher level of abstraction. We secondly elaborate the integration of platform-independent XACML policies with the platform-specific SELinux policies. Thirdly, we share our experiences regarding the implementation results of the SECTET on TC based systems. Masoom Alam, Jean-Pierre Seifert, Xinwen Zhang |
EDOC | 3 |
| 2007 | Towards a VMM-based usage control framework for OS kernel integrity protectionabstractProtecting kernel integrity is one of the fundamental security objectives in building a trustworthy operating system (OS). For this end, a variety of approaches and systems have been proposed and developed. However, access control models used in most of these systems are not expressive enough to capture important security requirements such as continuous policy enforcement and mutable process and object attributes. Even worse, most existing protection mechanisms in these systems reside in the same space as the running OS, which unfortunately can be disabled or subverted after an attacker successfully exploits kernel-level vulnerabilities (or features) to compromise the OS kernel. The increasing number of kernel-level root kit attacks clearly demonstrates this threat. Xuxian Jiang, Ravi S. Sandhu, Xinwen Zhang |
SACMAT | 4 |
| 2006 | WormTerminator: an effective containment of unknown and polymorphic fast spreading wormsabstractThe fast spreading worm is becoming one of the most serious threats to today's networked information systems. A fast spreading worm could infect hundreds of thousands of hosts within a few minutes. In order to stop a fast spreading worm, we need the capability to detect and contain worms automatically in real-time. While signature based worm detection and containment are effective in detecting and containing known worms, they are inherently ineffective against previously unknown worms and polymorphic worms. Existing traffic anomaly pattern based approaches have the potential to detect and/or contain previously unknown and polymorphic worms, but they either impose too much constraint on normal traffic or allow too much infectious worm traffic to go out to the Internet before an unknown or polymorphic worm can be detected.In this paper, we present WormTerminator, which can detect and completely contain, at least in theory, almost all fast spreading worms in real-time while blocking virtually no normal traffic. WormTerminator detects and contains the fast spreading worm based on its defining characteristic -- a fast spreading worm will start to infect others as soon as it successfully infects one host. WormTerminator also exploits the observation that a fast spreading worm keeps exploiting the same set of vulnerabilities when infecting new machines. To prove the concept, we have implemented a prototype of WormTerminator and have examined its effectiveness against the real Internet worm Linux/Slapper. Songqing Chen, Xinyuan Wang 0005, Lei Liu 0021, Xinwen Zhang |
ANCS | 4 |
| 2006 | A general design towards secure ad-hoc collaborationabstractWe propose a general design for secure collaboration systems, which is underpinned with an access control policy model, an administrative scheme, and an enforcement scheme, based on the Type Usage Control (TUCON) model. TUCON is a generalized form of the usage control model (UCON) proposed recently. By utilizing mutable object attributes, UCON can reflect the dynamic nature of ad-hoc collaborations such as temporal and/or spatial usages. In TUCON, every object has an object type as a persistent attribute, which works as a name space that indicates an organization to which the object belongs. With object types, TUCON policies can distinctly control intra-organization and inter-organization information flows. This approach achieves the autonomy of collaborative teams as well as the mutual confidentiality of collaborating organizations. Masayuki Nakae, Xinwen Zhang, Ravi S. Sandhu |
AsiaCCS | 2 |
| 2006 | Secure information sharing enabled by Trusted Computing and PEI modelsabstractThe central goal of secure information sharing is to "share but protect" where the motivation to "protect" is to safeguard the sensitive content from unauthorized disclosure (in contrast to protecting the content to avoid loss of revenue as in retail Digital Rights Management). This elusive goal has been a major driver for information security for over three decades. Recently, the need for secure information sharing has dramatically increased with the explosion of the Internet and the convergence of outsourcing, offshoring and B2B collaboration in the commercial arena and the real-world demonstration of the tragic consequences of lack of information sharing in the national security arena. As technology has made the "share" aspect ever easier so has it increased the difficulty of enforcing the "protect" aspect. The central contribution of this paper is to show that the emergence of industrial strength Trusted Computing (TC) technology offers a range of novel solutions to the long-standing problem of secure information sharing. To this end we introduce a new framework of three layered models to analyze requirements and develop solutions, and demonstrate the application of this framework in context of TC and secure information sharing. The three layers are policy models (topmost), enforcement models (middle), and implementation models (bottom). Hence the name PEI models. At the policy model layer the secure information sharing space is divided into three categories called password based, device based, and credential based. For each of these policy categories various enforcement and implementation models can be developed. While we believe the PEI framework is relevant to security problems beyond secure information sharing, our goal in this paper is to demonstrate its application in this particular arena and identify questions for future research in this context. An essential benefit of PEI is that the three layers allow us to focus on the more important issues at a higher level of abstraction at the policy and enforcement layers, while leaving deep detail to the implementation layer. This paper focusses on the policy and enforcement layers with only passing mention of the implementation layer. Ravi S. Sandhu, Kumar Ranganathan, Xinwen Zhang |
AsiaCCS | 3 |
| 2006 | Safety analysis of usage control authorization modelsabstractThe usage control (UCON) model was introduced as a unified approach to capture a number of extensions for traditional access control models. While the policy specification flexibility and expressive power of this model have been studied in previous work, as a related and fundamental problem, the safety analysis of UCON has not been explored. This paper presents two fundamental safety results for UCONA, a sub-model of UCON only considering authorizations. In UCONA, an access control decision is based on the subject and/or the object attributes, which can be changed as the side-effects of using the access right, resulting in possible changes to future access control decisions. Hence the safety question in UCONA is all the more pressing since every access can potentially enable additional permissions due to the mutability of attributes in UCON. In this paper, first we show that the safety problem is in general undecidable. Then, we show that a restricted form of UCONA with finite attribute value domains and acyclic attribute creation relation has a decidable safety property. The decidable model maintains good expressive power as shown by specifying an RBAC system with a specific user-role assignment scheme and a DRM application with consumable rights. Xinwen Zhang, Ravi S. Sandhu, Francesco Parisi-Presicce |
AsiaCCS | 1 |
| 2006 | Supporting Ad-hoc Collaboration with Group-based RBAC ModelabstractWith the increasing accessibility of information and data, role-based access control (RBAC) has become a popular technique for security and privacy purposes. However, trusted collaboration between different groups in large corporate Intranets is still an unresolved problem. The challenge is how to extend existing access control model for efficient security management and administration to allow trusted collaboration between different groups. In this paper, we propose a group-based RBAC model (GB-RBAC) for this purpose. In particular, virtual group is proposed in our model to allow secure information and resource sharing in multi-group collaboration environments. All the members of a virtual group build trust relation between themselves and are authorized to join the collaborative work. The scheme and strategies provided in this paper meet the requirements of security, autonomy, and privacy for collaborations. As a result, our scheme provides an easy way to employ RBAC policies to secure ad-hoc collaboration Qi Li 0002, Xinwen Zhang, Sihan Qing |
CollaborateCom | 2 |
| 2006 | ROBAC: Scalable Role and Organization Based Access Control ModelsabstractIn RBAC, roles are typically created based on job functions inside an organization. Traditional RBAC does not scale up well for modeling security policies spanning multiple organizations. To solve this problem, a family of extended RBAC models called role and organization based access control (ROBAC) models is proposed and formalized in this paper. Two examples are used to motivate and demonstrate the usefulness of ROBAC. Comparison between ROBAC and other related RBAC models is given. We show that ROBAC can significantly reduce administration complexity for Web and Internet-based applications involving a large number of organizations. Some administrative issues for ROBAC are identified and discussed. Although the theoretical-expressive power of ROBAC is the same as that of RBAC, it is more succinct and intuitive to use ROBAC than to use RBAC when applications involve many organizations Xinwen Zhang, Ravi S. Sandhu |
CollaborateCom | 2 |
| 2006 | A usage-based authorization framework for collaborative computing systemsabstractCollaborative systems such as Grids provide efficient and scalable access to distributed computing capabilities and enable seamless resource sharing between users and platforms. This heterogeneous distribution of resources and the various modes of collaborations that exist between users, virtual organizations, and resource providers require scalable, flexible, and fine-grained access control to pro-tect both individual and shared computing resources. In this paper we propose a usage control (UCON) based authorization frame-work for collaborative applications. In our framework, usage con-trol policies are defined using subject and object attributes, along with system attributes as conditions. General attributes include not only persistent attributes such as role and group memberships, but also mutable usage attributes of subjects and objects. Conditions in UCON can be used to support context-based authorizations in ad-hoc collaborations. As a proof-of-concept we implement a pro-totype system based on our proposed architecture and conduct ex-perimental studies to demonstrate the feasibility and performance of our approach. Xinwen Zhang, Masayuki Nakae, Michael J. Covington, Ravi S. Sandhu |
SACMAT | 1 |
| 2006 | An effective role administration model using organization structureabstractRole-based access control (RBAC) is a well-accepted model for access control in an enterprise environment. When we apply RBAC model to large enterprises, effective role administration is a major issue. ARBAC97 is a well-known solution for decentralized RBAC administration. ARBAC97 authorizes administrative roles by means of role ranges and prerequisite conditions, where prerequisite conditions effectively work as a restricted pool for administrative roles to pick users or permissions. Although attractive and elegant in their own right, these mechanisms have significant shortcomings. In this paper, we propose an improved role administration model named ARBAC02 to overcome the weaknesses of ARBAC97. ARBAC02 introduces the concept of organization structure for defining user and permission pools independent of roles and role hierarchies, with a refined prerequisite condition specification. In addition, we present a bottom-up approach of permission-role administration in contrast to the top-down approach in ARBAC97. As a general solution, we illustrate the applications of organization structured-based security administration with other access control models, such as access control list model and lattice-based access control model. Sejong Oh, Ravi S. Sandhu, Xinwen Zhang |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2005 | Peer-to-peer access control architecture using trusted computing technologyabstractIt has been recognized for some time that software alone does not provide an adequate foundation for building a high-assurance trusted platform. The emergence of industry-standard trusted computing technologies promises a revolution in this respect by providing roots of trust upon which secure applications can be developed. These technologies offer a particularly attractive platform for security in peer-to-peer environments. In this paper we propose a trusted computing architecture to enforce access control policies in such applications. Our architecture is based on an abstract layer of trusted hardware which can be constructed with emerging trusted computing technologies. A trusted reference monitor (TRM) is introduced beyond the trusted hardware. By monitoring and verifying the integrity and properties of running applications in a platform using the functions of trusted computing, the TRM can enforce various policies on behalf of object owners. We further extend this platform-based architecture to support user-based control policies, cooperating with existing services for user identity and attributes. This architecture and its refinements can be extended in future work to support general access control models such as lattice-based access control, role-based access control, and usage control. Ravi S. Sandhu, Xinwen Zhang |
SACMAT | 2 |
| 2005 | Formal model and policy specification of usage controlabstractThe recent usage control model (UCON) is a foundation for next-generation access control models with distinguishing properties of decision continuity and attribute mutability. A usage control decision is determined by combining authorizations, obligations, and conditions, presented as UCON ABC core models by Park and Sandhu. Based on these core aspects, we develop a formal model and logical specification of UCON with an extension of Lamport's temporal logic of actions (TLA). The building blocks of this model include: (1) a set of sequences of system states based on the attributes of subjects, objects, and the system, (2) authorization predicates based on subject and object attributes, (3) usage control actions to update attributes and accessing status of a usage process, (4) obligation actions, and (5) condition predicates based on system attributes. A usage control policy is defined as a set of temporal logic formulas that are satisfied as the system state changes. A fixed set of scheme rules is defined to specify general UCON policies with the properties of soundness and completeness. We show the flexibility and expressive capability of this formal model by specifying the core models of UCON and some applications. Xinwen Zhang, Francesco Parisi-Presicce, Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2004 | Attribute Mutability in Usage ControlabstractThe notion of Usage Control (UCON) has been introduced recently to extend traditional access controls by including three decision factors called authorizations, obligations , and conditions . Usage control also recognize two important decision properties of continuity and mutability . In access control literature, an authorization decision is commonly made by utilizing some form of subject and object attributes. Identities, security labels and roles are some examples of attributes. Traditionally these attributes are assigned to subjects and objects by a security officer and can be modified only by administrative actions. However, in modern information systems these attributes are often required to be changed as a side effect of subject’s usage on object. This requirement of updates has been recognized and defined as mutability property in usage control. In this paper, we discuss issues of this attribute mutability and show how usage control can apply this mutability property in various traditional and modern access control policies. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Xinwen Zhang, Ravi S. Sandhu |
DBSec | 2 |
| 2004 | A logical specification for usage controlabstractRecently presented usage control (UCON) has been considered as the next generation access control model with distinguishing properties of decision continuity and attribute mutability. Ausage control decision is determined by combining authorizations, obligations, and conditions, presented as UCONABC core models by Park and Sandhu. Based on these core aspects, we develop afirst-order logic specification of UCON with Lamport's temporallogic of actions (TLA). The building blocks of this model include:(1) a sequence of states expressed by attributes of subjects, objects, and the system, (2) state predicates on subject andobject attributes, (3) pre-defined authorization actions performed by the security system and subjects, (4) obligation actions, and(5) condition predicates on system attributes. For a UCON model we define a set of temporal logic formulas that hold as usage control policies. We show the flexibility and expressive capability of this logic model by specifying the new features and core models of UCON. Xinwen Zhang, Francesco Parisi-Presicce, Ravi S. Sandhu |
SACMAT | 1 |
| 2003 | Schema Based XML Security: RBAC Approach
Xinwen Zhang, Ravi S. Sandhu |
DBSec | 1 |
| 2003 | PBDM: a flexible delegation model in RBACabstractRole-based access control (RBAC) is recognized as an efficient access control model for large organizations. Most organizations have some business rules related to access control policy. Delegation of authority is among these rules. RBDM0 and RDM2000 models are recently published models for role-based delegation. They deal with user-to-user delegation. The unit of delegation in them is a role. But in many cases users may want to delegate a piece of permission from a role. This paper proposes a flexible delegation model named Permission-based Delegation Model (PBDM), which is built on the well known RBAC96 model. PBDM supports user-to-user and role-to-role delegations with features of multi-step delegation and multi-option revocation. It also supports both role and permission level delegation, which provides great flexibility in authority management. In PBDM, a security administrator specify the permissions that a user (delegator) has authority to delegate to others (delegatee), then the delegator creates one or more temporary delegation roles and assigns delegatees to particular roles. This gives us clear separation of security administration and delegation. Xinwen Zhang, Sejong Oh, Ravi S. Sandhu |
SACMAT | 1 |