George Yee

dblp:35/1212 · also George O. M. Yee · DBLP profile ↗
← Back
37ranked-venue papers
26as first author
3since 2021 · last 2025
0000-0001-6002-5101ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 12 first-authorSoftware engineering, systems software and programming languages · 12 · 10 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 7 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Designs for Reducing Data Breach Impact
abstract
Today, breaches of personal data are common place and lead to heavy costs for the organizations which have suffered the losses. Such costs may be expenditures incurred to resume normal operations, including the loss of reputation and trust. For data owners (persons described by the data), the losses may also be financial, and may include identity theft. This work presents three data architecture designs determined by how the storage of personal data is distributed. The goal of each design is to reduce the impact of a breach, which is mostly determined by the amount of personal data lost. The designs are applicable to client-server systems such as e-services, and are compared in terms of their effectiveness at achieving the above goal along with other factors, such as the cost of implementation and their abilities to satisfy a service’s purposes for collecting the personal data.
George Yee
COMPSAC1
2022 Improving the Derivation of Sound Security Metrics
abstract
We continue to tackle the problem of poorly defined security metrics by building on and improving our previous work on designing sound security metrics. We reformulate the previous method into a set of conditions that are clearer and more widely applicable for deriving sound security metrics. We also modify and enhance some concepts that led to an unforeseen weakness in the previous method that was subsequently found by users, thereby eliminating this weakness from the conditions. We present examples showing how the conditions can be used to obtain sound security metrics. To demonstrate the conditions' versatility, we apply them to show that an aggregate security metric made up of sound security metrics is also sound. This is useful where the use of an aggregate measure may be preferred, to more easily understand the security of a system.
George Yee
COMPSAC1
2021 Analyzing Structural Security Posture to Evaluate System Design Decisions
abstract
Software systems are increasing in complexity, with attendant increases in the number of vulnerabilities they contain. Remediating these vulnerabilities, ideally during the early requirements and design phases, has been highly resource-intensive, and is often omitted due to lack of knowledge, time, and/or funds. We propose an approach, applied in these early phases, to address the following issues: 1) to enhance the developer's security knowledge of the system, we introduce the notion of structural security posture, which uses a collection of metrics to assess a system's security based on its structural view, 2) to guide the identification of vulnerabilities, we leverage external security data sources, and 3) to address the issue of resource intensiveness, we offer a tool for evaluating and analyzing a system's structural security posture. We illustrate how our approach facilitates the evaluation of design decisions to improve security using an example.
Joe Samuel, Jason Jaskolka, George Yee
QRS3
2019 Designing Good Security Metrics
abstract
This paper begins with an introduction to security metrics, describing the need for security metrics, followed by a discussion of the nature of security metrics, including the challenges found with some security metrics used in the past. The paper then discusses what makes a good security metric and proposes a rigorous step-by-step method that can be applied to design good security metrics, and to test existing security metrics to see if they are good metrics. Application examples are included to illustrate the method.
George Yee
COMPSAC (2)1
2019 Modeling and reducing the attack surface in software systems
abstract
In today's world, software is ubiquitous and relied upon to perform many important and critical functions. Unfortunately, software is riddled with security vulnerabilities that invite exploitation. Attackers are particularly attracted to software systems that hold sensitive data with the goal of compromising the data. For such systems, this paper proposes a modeling method applied at design time to identify and reduce the attack surface, which arises due to the locations containing sensitive data within the software system and the accessibility of those locations to attackers. The method reduces the attack surface by changing the design so that the number of such locations is reduced. The method performs these changes on a graphical model of the software system. The changes are then considered for application to the design of the actual system to improve its security.
George Yee
MiSE@ICSE1
2018 Removing Software Vulnerabilities During Design
abstract
The importance of software in the world today cannot be overstated. Unfortunately, software is riddled with security vulnerabilities that invite exploitation. Attackers are particularly attracted to software systems that hold sensitive data with the goal of compromising the data. This paper proposes a method to identify and remove sensitive data vulnerabilities in such systems at the time they are designed, based on the observation that different vulnerabilities arise due to the location of the sensitive data and the risks to the data at those locations. The method removes vulnerabilities by adding protection for the sensitive data at its locations or by changing the locations of the sensitive data. The method performs these modifications on an easy to use graphical model of the software system, and then translates the modifications back to the actual design of the system.
George Yee
COMPSAC (2)1
2017 Model for Reducing Risks to Private or Sensitive Data
abstract
Software systems can be found in almost every aspect of our lives, as can be seen in social media, online banking and shopping, as well as electronic health monitoring. This widespread involvement in our lives has led to the need to protect privacy, as the use of the software often requires us to input our personal information. Software systems can also hold sensitive data (e.g., a trade secret) that is vulnerable to theft. The key to protecting private or sensitive data in software systems is the knowledge of where the data resides in the system. This paper proposes a new model for visualizing a software system that focuses on the location of private or sensitive data, in order to gain insight into the attendant risks to attacks on the data. The model can then be modified to suggest ways of reducing these risks in the software system.
George Yee
MiSE@ICSE1
2017 Adding Privacy Protection to Distributed Software Systems
George Yee
SECRYPT1
2010 Automated Threat Identification for UML
George Yee, Xingli Xie, Shikharesh Majumdar
SECRYPT1
2009 An Automatic Privacy Policy Agreement Checker for E-services
abstract
An effective way of managing privacy for an e-service user is to make use of user and service provider privacy policies. The user privacy policy expresses the user's privacy preferences for personal information that is to be shared with the e-service provider. The provider privacy policy expresses the privacy requirements of the providerpsilas service, in terms of what personal information the service requires and how the information will be used. The e-service may proceed only if the user privacy policy "agrees" with the provider privacy policy. However, checking for policy agreement needs to be relatively fast in an e-services environment. How can this checking be automated? This paper defines user and provider privacy policies based on legal considerations. It then proposes a privacy policy agreement checker that can automatically determine if the user privacy policy agrees with the corresponding provider privacy policy. An example application of the checker is included.
George Yee
ARES1
2008 Private Data Discovery for Privacy Compliance in Collaborative Environments
Larry Korba, Yunli Wang, Liqiang Geng, Ronggong Song, George Yee, Andrew S. Patrick, Scott Buffett, Yonghua You
CDVE5
2008 Cooperative Visualization of Privacy Risks
George Yee, Larry Korba, Ronggong Song
CDVE1
2008 Assessing the Likelihood of Privacy Policy Compliance
George Yee, Larry Korba, Ronggong Song
SEC1
2008 Guest Editors' Introduction
George Yee, Ali A. Ghorbani 0001, Patrick C. K. Hung
J. Comput. Secur.1
2008 Guest Editors' Introduction
George Yee, Chunming Rong, Laurence T. Yang
J. Comput. Secur.1
2007 Private Data Management in Collaborative Environments
Larry Korba, Ronggong Song, George Yee, Andrew S. Patrick, Scott Buffett, Yunli Wang, Liqiang Geng
CDVE3
2007 Visual Analysis of Privacy Risks in Web Services
abstract
The growth of the Internet has been accompanied by the growth of web services (e.g. e-commerce, e- health) leading to the need to protect the privacy of web service users. However, before privacy can be protected, it is necessary to understand the risks to privacy that come with the service. Indeed, such understanding is key to protecting privacy throughout the service lifecycle. Unfortunately, there does not appear to be any existing method for privacy risk analysis specifically designed for web services. This paper presents a straightforward method for web services privacy risk analysis that uses visual techniques to improve effectiveness and illustrates the method with an example.
George Yee
ICWS1
2007 Privacy management system using social networking
abstract
The worldwide growth of e-services has brought to the forefront the importance of private data management for an organization. However, the advancement of computer and networking technologies has made privacy management very challenging. In this paper, we expose the limitations of existing privacy management systems, and present a privacy management system that exploits social network analysis, which can automatically discover the privacy-related workflow models, and support automated privacy management within an organization.
Ronggong Song, Larry Korba, George Yee
SMC3
2007 Protect Virtual Property in Online Gaming System
abstract
Massively multiplayer role-playing gaming (MMORPG) has become a very popular entertainment in Asia. Along with the success of the massively multiplayer role-playing gaming industry in Asia, online gaming-related crimes have grown at an amazing rate. Most of the criminal cases are related to virtual properties since markets have developed for the virtual properties giving them real world values. There has been little research and resulting technologies for MMORPG virtual property protection. In order to reduce the crimes and protect online gaming systems, one potential solution is protecting the virtual properties in online gaming systems. In this paper, we propose a virtual property management language to meter the use of virtual property. The language provides a framework for managing the use of virtual properties and recording the history of transactions to trace the life of virtual properties.
Ronggong Song, Larry Korba, George Yee, Ying-Chieh Chen
Int. J. Softw. Eng. Knowl. Eng.3
2006 Personalized Security for E-Services
abstract
The growth of the Internet has been accompanied by a proliferation of e-services. The increasing attacks on these services by malicious individuals have highlighted the need for security. The security requirements of an e-service may be specified by the service provider in a security policy. However, a service consumer may have security preferences that are not reflected in this policy. In order for service providers to reach a wider market, a way of personalizing a security policy to a particular consumer is needed. We introduce the concept of security personalization, derive the content of an e-service security policy suitable for personalization, and describe four approaches for such personalization, including the design and use of a context-aware security policy agent (CASPA) that personalizes an e-service security policy to the needs of the consumer on-the-fly. We further give recommendations on applying the personalization approaches based on their advantages and disadvantages.
George Yee
ARES1
2006 Ensuring Privacy for E-Health Services
abstract
The growth of the Internet has been accompanied by the growth of e-health services (e.g. online medical advice, online pharmacies). This proliferation of services and the increasing regulatory and legal requirements for personal privacy have fueled the need to protect the personal privacy of service users. Existing approaches for privacy protection such as access control are predicated on the e-service provider having possession and control over the user's personal data. In this paper, we propose a new approach to protecting personal privacy for e-health services: keeping possession and control over the user's personally identifiable information in the hands of the user as much as possible. Our approach can also be characterized as distributing personally identifiable information only on a "need to know" basis.
George Yee, Larry Korba, Ronggong Song
ARES1
2006 Towards Designing Secure Online Games
abstract
The multiplayer gaming industry has become very successful in Asia. With the growth of online gaming, there has been an amazing growth in online gamingrelated crime, especially in Massively Multiplayer Online Role-Playing Games (MMORPGs) [1]. In Taiwan, more than 37% of criminal cases relate to online gaming crime with most offenders in the age range of 15-20 years [5]. Most of these crimes can be attributed to the fact that these online games were not designed to be secure. This paper applies a design for security approach to MMORPGs and then examines what crimes could have been avoided if the games were designed to be secure from the beginning. The approach also uncovers some potential new threats and gives countermeasures for them.
George Yee, Larry Korba, Ronggong Song, Ying-Chieh Chen
AINA (2)1
2006 Automated Social Network Analysis for Collaborative Work
Larry Korba, Ronggong Song, George Yee, Andrew S. Patrick
CDVE3
2006 Measuring Privacy Protection in Web Services
abstract
The growth of the Internet has been accompanied by the growth of Web services (e.g. e-commerce, e-health) leading to the need to protect the personal privacy of Web service users. However, it is also important to be able to measure a Web service in terms of how well it protects personal privacy. Such a capability would benefit both users and developers. Users would benefit from being able to choose (assuming that such measures were made public) the service that has the greatest ability to protect user privacy (this would in turn encourage Web service providers to pay more attention to privacy). Developers would benefit by being able to incrementally measure and modify their services during development until certain target levels of privacy protection are reached. This paper presents an approach for measuring how well a Web service protects personal privacy and illustrates the approach with an example
George Yee
ICWS1
2006 A privacy-preserving UBICOMP architecture
abstract
With the increasing deployment of sensors, intelligent devices of all sizes, and wireless networking, ubiquitous computing (UBICOMP) environments are getting closer to reality. Research in UBICOMP has focused on enabling technologies, such as networking, data management, security, and user interfaces. However, privacy for UBICOMP has been a contentious issue and the privacy concerns that have been raised suggest that privacy may be the greatest barrier to the long-term success of UBICOMP. This paper proposes a hybrid (locally centralized but peer-to-peer across the Internet) UBICOMP architecture that respects personal privacy preferences expressed in the form of personal privacy policies.
George Yee
PST1
2006 Ensuring Privacy for Buyer-Seller E-Commerce
George Yee, Larry Korba, Ronggong Song
SEC1
2006 Visualization for privacy compliance
abstract
The growth of the Internet has been accompanied by the growth of e-services (e.g. e-commerce, e-health). This proliferation of e-services has put large quantities of consumer private information in the hands of the service providers, who in many cases have mishandled the information, either intentionally or unintentionally, to the detriment of consumer privacy. As a result, government bodies have put in place privacy legislation that spells out a consumer's privacy rights and how consumer private information is to be handled. Providers are required to comply with such privacy legislation. This paper proposes visualization as a tool that can be used by security or privacy analysts to understand how private information flows within and between provider organizations, as a way of identifying vulnerabilities that can lead to non-compliance. A model of private information flow and a graphical notation for visualizing this flow are proposed. An application example of using the notation to identify privacy vulnerabilities is given.
George Yee
VizSEC1
2005 Applying Word Sense Disambiguation to Question Answering System for e-Learning
abstract
Interaction between the student and the instructor is important for the student to gain knowledge. Also, one of the major tasks on the instructor in e-learning is to reply student e-mails and posted messages. Students usually raise their questions by these two methods in an e-learning environment. In this paper, we introduce a semantic-based automated question answering system that can act like a virtual teacher to respond to student questions online. With the system, not only the instructor can be relieved from the load of answering lots of questions, but also the student can mostly get answers promptly without waiting for the instructor to get online and provide an answer. This would be a big help for both the instructor and the student in e-learning environment. Through the process of raising questions and getting answers, the knowledge base will be enriched for future questions answering. Further, not only the students can get answers for their questions, but also the instructors could know what problems students encounter in learning. These would be big aids to both the teaching and the learning.
Jason C. Hung, Ching-Sheng Wang, Che-Yu Yang, Mao-Shuen Chiu, George Yee
AINA5
2005 Applying Petri Nets to Model SCORM Learning Sequence Specification in Collaborative Learning
abstract
With the rapid development of Internet technology and Web-based education, distance learning provides a novel learning style, which is different from traditional education. In order to adapt different teaching strategies in accordance to individual students' abilities in a distance learning environment, system directed navigation of students was proposed in a distance learning standard called SCORM (sharable content object reference model). We introduce the distance-learning color Petri net (DCPN), applying the features of Petri nets, to decrease the complexity of the sequencing definition model in the SCORM 2004 specification. We thus construct a sequencing framework for various instructional strategies by piecing DPCN subnets together.
Hsiau Wen Lin, Wen-Chih Chang, George Yee, Timothy K. Shih, Chun-Chia Wang, Hsuan-Che Yang
AINA3
2005 Using Privacy Policies to Protect Privacy in UBICOMP
abstract
With the increasing deployment of sensors, intelligent devices of all sizes, and wireless networking, ubiquitous computing environments are getting closer and closer to reality. Research in UBICOMP has focused on enabling technologies, such as networking, data management, security, and user interfaces (Bodupalli et al., 2003). However, privacy for UBICOMP has been a contentious issue and the privacy concerns that have been raised suggest that privacy may be the greatest barrier to the long-term success of UBICOMP (Hong et al., 2004). In this paper, we propose that privacy in UBICOMP can be managed using privacy policies. We propose a UBICOMP model for protecting privacy using privacy policies and derive the content of a UBICOMP privacy policy.
George Yee
AINA1
2005 An Agent Architecture for e-Services Privacy Policy Compliance
abstract
The growth of the Internet has been accompanied by the growth of e-services (e.g. e-commerce, e-health). This proliferation of e-services and the increasing regulatory and legal requirements for personal privacy have fueled the need to protect the personal privacy of e-service users. Approaches are needed to ensure that providers of e-services comply with the privacy policies of service users. In this paper, we examine privacy legislation to derive requirements for privacy policy compliance systems. We then propose an agent-based architecture for a privacy policy compliance system that satisfies many of the requirements and discuss the strengths and weaknesses of our proposed architecture.
George Yee, Larry Korba
AINA1
2005 Environmentally-Aware Security Enforcement (EASE) for Cooperative Design and Engineering
Larry Korba, Yuefei Xu, Ronggong Song, George Yee
CDVE4
2005 Negotiated Security Policies for E-Services and Web Services
abstract
The growth of the Internet has been accompanied by the growth of e-services (e.g. e-commerce, e-health). This proliferation of e-services and the increasing attacks on them by malicious individuals have highlighted the need for e-service security. The security requirements of an e-service may be specified in an e-service security policy. The provider of the e-service is then responsible for implementing the security measures contained in the policy. However, a service consumer may have security preferences that are not reflected in the provider's e-service security policy (e.g. defense contractors may require higher levels of security). In order for service providers to reach a wider market, a way of customizing a security policy to a particular consumer is needed. We derive the content of an e-service security policy and propose a flexible approach that allows an e-service provider and consumer to negotiate to an agreed-upon e-service security policy. In addition, we examine how our approach may be implemented in a Web services environment and briefly describe the design of our security policy negotiation prototype.
George Yee, Larry Korba
ICWS1
2005 Specifying Personal Privacy Policies to Avoid Unexpected Outcomes
George Yee, Larry Korba
PST1
2004 Security and Privacy Technologies for Distance Education Applications
abstract
While there has been considerable development of tools for distance education, there has been relatively little work focused on how to offer users security and privacy during learning activities. This paper focuses on how tool development can combine with security to provide a safe, efficient, and effective learning environment. We present a number of distance education applications developed in our lab and show how security and privacy may be integrated into these applications.
Nigel H. Lin, Larry Korba, George Yee, Timothy K. Shih, Hsiau Wen Lin
AINA (1)3
2004 Multistory Annotation System: a Novel Application of Distance Learning
abstract
For effectively browsing and navigation, the semantic annotation is essential for the visual content of movies. It is very important to show the particular object that the movie producer wants to highlight in educational videos or commercials. We propose an interactive and structure-based video annotation system, in which we can describe the video object and make multistory movies. The system provides a manual object-based interface for film producers to select the meaningful object and annotate it. We also provide a video story constructing function to interact with the audience.
Timothy K. Shih, Han-Bin Chang, Mei-Yen Kuan, George Yee
AINA (2)5
2004 Privacy Policy Compliance for Web Services
abstract
The growth of the Internet has been accompanied by the growth of Web services (e.g. e-commerce, e-health). This proliferation of Web services and the increasing regulatory and legal requirements for personal privacy have fueled the need to protect the personal privacy of Web service users. We advocate a privacy policy negotiation approach to protecting personal privacy (Yee and Korba, 2003; ). We provided semiautomated approaches for deriving personal privacy policies (Yee and Korba, 2004). However, it is evident that approaches are also needed to ensure that providers of Web services comply with the privacy policies of service users. In this paper, we examine privacy legislation to derive requirements for privacy policy compliance systems. We then propose an architecture for a privacy policy compliance system that satisfies the requirements and discuss the strengths and weaknesses of our proposed architecture.
George Yee, Larry Korba
ICWS1