Oleksii Osliak

dblp:234/5904 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
3since 2021 · last 2024
0000-0003-4128-0136ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 Obligation Management Framework for Usage Control
abstract
Obligations were introduced in access and usage control as a mechanism to specify mandatory actions to be fulfilled as part of authorization. In this paper, we address challenges related to obligation management in access and usage control, focusing on the Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) standards. Firstly, we provide a comprehensive analysis of Combining Algorithms (CAs) to determine their influence on the selection and ordering of obligations and identify nondeterminism. We then propose solutions to eliminate such nondeterminism enabling policy authors to explicitly specify the intended behavior. Secondly, we discuss the recurrence of obligations in usage control that occurs due to policy re-evaluations, highlighting the need to execute some obligations only once. We address this problem by introducing a parameter that enables policy authors to explicitly specify whether they intend an obligation to recur or not. Thirdly, we highlight an ambiguity in obligation applicability to lifecycle phases (e.g., ongoing) in usage control, arising from the lack of explicit associations between obligations and phases in particular cases. To address this issue, we introduce a parameter that explicitly specifies the scope of an obligation, allowing policy authors to restrict obligations to a single phase or apply them to the entire authorization. Finally, we extend the functionality of the Obligation Manager (OM) component to combine all three solutions, providing deterministic obligation management.
Hussein Joumaa, Ali Hariri, Ana Petrovska, Oleksii Osliak, Theodosis Dimitrakos, Bruno Crispo
SACMAT4
2023 Cyber threat intelligence for critical infrastructure security
abstract
Summary Cyber‐attacks are considered the most significant threat to organizations from different sectors, including critical infrastructure. Access to critical assets, including industrial control systems, and control over their usage is one of the security approaches implemented to protect those systems from unauthorized access. However, existing implementations do not support the enforcement of fine‐grained authorization policies and do not provide continuous control over data access. Furthermore, existing implementations of the access control paradigm require policy‐makers to perform a manual update of policies that do not consider information about potential or ongoing cyber attacks. In this work, we propose a framework that enables continuous control on the execution of access rights in the industrial domain. Furthermore, the framework relies on cyber incident information shared by trusted entities. This information is used for updating security policies in order to prevent possible incidents within the smart factory infrastructure. We also provide experimental results that show the operability and the efficiency of the proposed framework.
Oleksii Osliak, Andrea Saracino, Fabio Martinelli, Paolo Mori
Concurr. Comput. Pract. Exp.1
2021 Towards Collaborative Cyber Threat Intelligence for Security Management
Oleksii Osliak, Andrea Saracino, Fabio Martinelli, Theodosis Dimitrakos
ICISSP1
2020 Improving security in industry 4.0 by extending OPC-UA with usage control
abstract
This work presents a framework that provides ongoing control on actions execution in the industrial environment exploiting the OPC Unified Architecture (OPC-UA) framework and the Usage Control (UCON) paradigm. We present a fine-grained usage control model, referred as OPC-UCON, satisfying security and privacy needs of the OPC-UA framework. Our proposed framework exploits the OPC-UA connectivity between simulated industrial components and uses the UCON paradigm for dynamically controlling actions execution according to fine-grained policies reported in the standardized format. The UCON paradigm, in a form of the system, is in charge of controlling the process of dynamic policy reevaluation and the possibility of revoking already granted authorization by stopping previously authorized actions if conditions do not satisfy policy anymore. We presented the implementation and deployment of the proposed framework in a simulated industrial environment with relevant security policies to reflect the advantages of the OPC-UCON model.
Fabio Martinelli, Oleksii Osliak, Paolo Mori, Andrea Saracino
ARES2
2019 A scheme for the sticky policy representation supporting secure cyber-threat intelligence analysis and sharing
abstract
Purpose This paper aims to propose a structured threat information expression (STIX)-based data representation for privacy-preserving data analysis to report format and semantics of specific data types and to represent sticky policies in the format of embedded human-readable data sharing agreements (DSAs). More specifically, the authors exploit and extend the STIX standard to represent in a structured way analysis-ready pieces of data and the attached privacy policies. Design/methodology/approach The whole scheme is designed to be completely compatible with the STIX 2.0 standard for cyber-threat intelligence (CTI) representation. The proposed scheme will be implemented in this work by defining the complete scheme for representing an email, which is more expressive than the standard one defined for STIX, designed specifically for spam email analysis. Findings Moreover, the paper provides a new scheme for general DSA representation that has been practically applied for the process of encoding specific attributes in different CTI reports. Research limitations/implications Because of the chosen approach, the research results may have limitations. Specifically, current practice for entity recognition has the limitation that was discovered during the research. However, its effect on process time was minimized and the way for improvement was proposed. Originality/value This paper has covered the existing gap including the lack of generality in DSA representation for privacy-preserving analysis of structured CTI. Therefore, the new model for DSA representation was introduced, as well as its practical implementation.
Oleksii Osliak, Andrea Saracino, Fabio Martinelli
Inf. Comput. Secur.1