VLDB 2026 Research / reviewers in the wild / expert
Alex Ng
dblp:16/3523
· DBLP profile ↗
8ranked-venue papers
0as first author
4since 2021 · last 2023
0000-0002-5809-2150ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Applying staged event-driven access control to combat ransomwareabstractThe advancement of modern Operating Systems (OSs), and the popularity of personal computing devices with Internet connectivity, have facilitated the proliferation of ransomware attacks. Ransomware has evolved from executable programs encrypting user files, to novel attack vectors including fileless command scripts, information exfiltration and human-operated ransomware. Many anti-ransomware studies have been published, but many of them assumed newer ransomware variants only performed file encryption, were similar to existing variants, and often did not consider those novel attack vectors. We have defined an updated ransomware threat model to include those novel attack vectors, and redefined false positives and false negatives in the context of ransomware mitigation. We proposed to apply both program-centric and user-centric access control to combat ransomware, but only delegate access control decisions that users are capable of making to users, while enforcing non-negotiable access control decisions by OS and software developers. We have designed a Staged Event-Driven Access Control (SEDAC) approach to incorporate both program-centric and user-centric access control measures, and demonstrated a prototype on Windows OS. Our prototype was able to intercept more types of ransomware attack vectors than existing proposals. We hope to convince OS and software architects to incorporate our design to better combat ransomware. Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters |
Comput. Secur. | 4 |
| 2023 | Harnessing GPT-4 for generation of cybersecurity GRC policies: A focus on ransomware attack mitigationabstractThis study investigated the potential of Generative Pre-trained Transformers (GPTs), a state-of-the-art large language model, in generating cybersecurity policies to deter and mitigate ransomware attacks that perform data exfiltration. We compared the effectiveness, efficiency, completeness, and ethical compliance of GPT-generated Governance, Risk and Compliance (GRC) policies, with those from established security vendors and government cybersecurity agencies, using game theory, cost-benefit analysis, coverage ratio, and multi-objective optimization. Our findings demonstrated that GPT-generated policies could outperform human-generated policies in certain contexts, particularly when provided with tailored input prompts. To address the limitations of our study, we conducted our analysis with thorough human moderation, tailored input prompts, and the inclusion of legal and ethical experts. Based on these results, we made recommendations for corporates considering the incorporation of GPT in their GRC policy making. Timothy R. McIntosh, Tong Liu 0016, Teo Susnjak, Hooman Alavizadeh, Alex Ng, Raza Nowrozy, Paul A. Watters |
Comput. Secur. | 5 |
| 2021 | Dynamic user-centric access control for detection of ransomware attacks
Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters |
Comput. Secur. | 4 |
| 2021 | Enforcing situation-aware access control to build malware-resilient file systems
Timothy R. McIntosh, Paul A. Watters, A. S. M. Kayes, Alex Ng, Yi-Ping Phoebe Chen |
Future Gener. Comput. Syst. | 4 |
| 2019 | Trust Modeling for Blockchain-Based Wearable Data MarketabstractWearable devices continuously produce physiological data that can provide individuals critical information about their daily routine or fitness level in combination with their smartphones without requiring manual calculations or maintaining log-books. Real-time participant-generated data can enable large scale observational studies of health conditions, provide better insights into medical conditions of individuals and streamline clinical trial processes in medical research. However, privacy is a major concern for health data and there can be a lack of trust among different parties in the health data collection process. In addition, individuals often do not have sufficient control over the sharing of their data from the wearable devices. The lack of control, trust and privacy are key barriers to research participants being prepared to share their personal data from wearable devices. In this work, we propose a trust model to overcome the trust deficit among different parties. Then, we present a reference system architecture, rooted on the developed trust model, that provides incentive for individuals to securely share their health data through a data marketplace. By encouraging individuals to share their real-time health data, researchers will have access to large data sets at low cost. Mohammad Jabed Morshed Chowdhury, Md Sadek Ferdous, Kamanashis Biswas, Niaz Chowdhury, A. S. M. Kayes, Paul A. Watters, Alex Ng |
CloudCom | 7 |
| 2013 | A performance evaluation of distributed database architecturesabstractSUMMARY The globally integrated contemporary business environment has prompted new challenges to database architectures in order to enable organizations to improve database applications performance, scalability, reliability and data privacy in adapting to the evolving nature of business. Although a number of distributed database architectures are available for choice, there is a lack of an in‐depth understanding of the performance characteristics of these database architectures in a comparison way. In this paper, we report a performance study of three typical (centralized, partitioned and replicated) database architectures. We used the TPC‐C as the evaluation benchmark to simulate a contemporary business environment, and a commercially available database management system that supports the three architectures. We compared the performance of the partitioned and replicated architectures against the centralized database, which results in some interesting observations and practical experience. The findings and the practice presented in this paper provide useful information and experience for the enterprise architects and database administrators in determining the appropriate database architecture in moving from centralized to distributed environments. Copyright © 2012 John Wiley & Sons, Ltd. Shiping Chen 0001, Alex Ng, Paul Greenfield |
Concurr. Comput. Pract. Exp. | 2 |
| 2008 | Forensic Characteristics of Phishing - Petty Theft or Organized Crime?
Stephen McCombie, Paul A. Watters, Alex Ng, Brett Watson |
WEBIST (1) | 3 |
| 2006 | Evaluation and Modeling of Web Services PerformanceabstractWhile Web services have been widely accepted as a platform-independent services-oriented technology, its performance remains a concern due to the verbosity and inefficiency inherent from using text-based XML. This paper presents a study of Web services performance by evaluating the current implementations of Web services and comparing them with a number of alternative technologies. This study gives a picture of the current Web services performance behaviors and develops a simple performance model that can be used to estimate Web services latencies Shiping Chen 0001, John Zic, Ren Ping Liu 0001, Alex Ng |
ICWS | 5 |