Maryam Davari

dblp:198/9702 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
3since 2021 · last 2022
0000-0001-8834-0672ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2022 Classification-Based Anomaly Prediction in XACML Policies
Maryam Davari, Mohammad Zulkernine
SecureComm1
2021 Policy Modeling and Anomaly Detection in ABAC Policies
Maryam Davari, Mohammad Zulkernine
CRiSIS1
2021 ProFact: A Provenance-Based Analytics Framework for Access Control Policies
abstract
Policy-based access control systems are crucial for secure information sharing in collaborative applications. However, policy management needs to be flexible in order to adapt to different environments and be able to support policy evolution. However, when dealing with large sets of evolving policies, it is critical that policies meet certainpolicy quality requirements. Policy sets must be complete, free of inconsistencies, and relevant. In this paper, we propose a framework to analyze policies to determine whether they meet such requirements. Our framework uses provenance techniques to collect comprehensive data about actions which were either triggered due to a network context or a user (i.e., a human or a device) action. The framework includes two approaches for policy analysis: structure-based and classification-based. For the structure-based approach, we designed tree structures to organize and assess the policy set efficiently. For the classification-based approach, we employed the classification techniques to learn the characteristics of policies and predict their quality. In addition, the framework includes the policy evolution module which mainly consists of recommendation and re-evaluation services for policy changes which both aim at fulfilling the policy quality requirements. The analysis framework has been implemented and experimental results from the prototype are reported.
Amani Abu Jabal, Maryam Davari, Elisa Bertino, Christian Makaya, Seraphin B. Calo, Dinesh C. Verma, Christopher Williams 0001
IEEE Trans. Serv. Comput.2
2019 Access Control Model Extensions to Support Data Privacy Protection based on GDPR
abstract
The General Data Protection Regulation (GDPR) gives control of data to the data owner. It imposes several requirements and obligations on organizations that process and manage personal data of EU citizens. GDPR uses consent as a legal basis for personal data processing. We design a semantic model to represent GDPR consents; our model is explicit, understandable, and reusable. Ensuring that organizations comply with GDPR with respect to user consents is a critical issue. To address such an issue, we propose a Blockchain-based model for compliance verification. Our decentralized model ensures that only parties authorized based on users' consent can access users' data and that all activities are logged in an immutable distributed ledger. Our GDPR privacy protection framework is cast into the XACML reference architecture.
Maryam Davari, Elisa Bertino
IEEE BigData1
2018 Reactive Access Control Systems
abstract
In context-aware applications, user's access privileges rely on both user's identity and context. Access control rules are usually statically defined while contexts and the system state can change dynamically. Changes in contexts can result in service disruptions. To address this issue, this poster proposes a reactive access control system that associates contingency plans with access control rules. Risk scores are also associated with actions part of the contingency plans. Such risks are estimated by using fuzzy inference. Our approach is cast into the XACML reference architecture.
Maryam Davari, Elisa Bertino
SACMAT1
2016 Analysing vulnerability reproducibility for Firefox browser
abstract
Fixing some security failures are difficult because they cannot be easily reproduced. To address Hardly Reproducible Vulnerabilities (HRVs), security experts spend a significant amount of time, effort, and budget. Sometimes they do not succeed in the reproduction step and ignore some security failures. The exploitation of a vulnerability due to its irreproducibility may cause severe consequences. An efficient solution is to explore the behaviour of both hardly and easily reproducible security issues at the code level. We use linear regression techniques to build models based on the classical software complexity metrics and a set of attributes related to the environment of the system. The results show that the considered metrics and the vulnerability types do not have significant linear correlations with each other. Also, predicting the HRV-prone parts of large systems is a great help for security experts to focus their effort on the top-ranked vulnerable files. After identifying the suitable indicators based on linear regression, different machine learning techniques such as Random Forest, Logistic Regression, C4.5 Decision Tree, and Naive Bayes are employed to build HRV prediction models. The Random Forest technique achieves the precision of 82% and recall of 84% to classify vulnerable files into HRV-prone or non HRV-prone files. We believe that the results encourage the use of software metrics for vulnerability prediction in some projects.
Maryam Davari, Mohammad Zulkernine
PST1