VLDB 2026 Research / reviewers in the wild / expert
Elena Ferrari 0001
dblp:389/7043-1
· DBLP profile ↗
171ranked-venue papers
8as first author
28since 2021 · last 2026
0000-0002-7312-6769ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 71 · 3 first-author · 11 since 2021Databases, data management, data science and information retrieval · 50 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 14Software engineering, systems software and programming languages · 14 · 1 since 2021Human-computer interaction and ubiquitous computing · 13 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 since 2021Computer networks · 9 · 5 since 2021Systems, architecture and hardware · 5 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AUTOMal: An LLM-Based Automated Feature Engineering Framework for Efficient Malware Detection at the EdgeabstractEdge computing supports real-time decision making and is crucial for applications such as the Internet of Things (IoT), autonomous systems, and smart manufacturing. Securing these devices against malware attacks is essential. Many machine learning (ML) based approaches for malware detection at the edge have been developed so far. However, at the initial stage, extracting features from raw data to train ML models remains a significant challenge, as it often requires substantial domain expertise and is time-consuming. Existing automated frameworks using traditional transformation techniques often fail to incorporate domain knowledge, attempt to transform all features, and frequently spend excessive time processing unnecessary ones. In this paper, we introduce a novel automated feature engineering framework for ML-based malware detection that exploits domain knowledge encoded in Large Language Models (LLMs) to identify subsets of features appropriate for specific transformations, thereby avoiding indiscriminate transformation of the entire dataset. Experimental results demonstrate that the proposed framework outperforms state-of-the-art methods on multiple IoT malware detection datasets. Moreover, the framework achieves a substantial reduction in computational overhead, exhibiting an approximate 90-fold improvement in processing efficiency relative to existing approaches. Nguyen Khanh Son, Christian Rondanini, Barbara Carminati, Elena Ferrari 0001 |
CODASPY | 4 |
| 2026 | PrivacyAssist: A User-Centric Agent Framework for Detecting Privacy Inconsistencies in Android Apps
Tran Thanh Lam Nguyen, Edoardo Di Tullio, Barbara Carminati, Elena Ferrari 0001 |
WISEC | 4 |
| 2026 | BlackoutADR: Exploiting adaptive data rate vulnerabilities in LoRaWAN-based FANETsabstractThis paper introduces BlackoutADR , a novel adversarial attack exploiting LoRaWAN’s Adaptive Data Rate (ADR) mechanism in cellular-connected UAV networks, with applicability to other IoT systems as well. By subtly manipulating Received Signal Strength Indicator (RSSI) and Signal-to-Noise Ratio (SNR), BlackoutADR increases UAV transmission power, causing 45% faster battery depletion within 100 s of simulation time and disrupting network operations. Using NS-3 simulations with a 20-UAV FANET, we evaluate its evasion of multiple ML-based IDSs (CNN, LSTM, BiLSTM, FNN, LoRaWAN-specific). Results show BlackoutADR remains undetected due to its subtle manipulations evading even dynamic thresholds, outperforming traditional jamming attacks. To address the identified vulnerability, we outline reactive measures, including dynamic threshold-based IDSs, secure ADR mechanisms, and recommendations for drone manufacturers. Khaoula Hidawi, Sabrine Ennaji, Elena Ferrari 0001 |
J. Netw. Comput. Appl. | 3 |
| 2026 | ALIBIS: Assessing and mitigating the risk of sensitive metadata Leakage In moBile Image SharingabstractSmartphones have become necessary in modern life and can replace traditional devices like cameras. The high demand for taking and sharing photos via smartphones, especially with the explosion of social networks and instant messaging, highlights the importance of smartphones. Android, the leading smartphone operating system, has continuously improved user security and privacy over its 17 years of development (2008–2025). However, security vulnerabilities still exist because of its open-source nature. This paper introduces ALIBIS, a framework that automatically estimates the risk of leakage of sensitive data contained in EXIF metadata when users share images online by combining static analysis and Large Language Models (LLMs). ALIBIS demonstrates consistent and robust estimation capabilities, achieving an average accuracy, precision, recall, and f1 score in k-fold cross-validation (k=5) of 0.8686, 0.8902, 0.881, and 0.8854, respectively. In addition, a survey of 130 global participants, including Android app developers and end-users, revealed a significant lack of awareness about image metadata and its risks: 82.3% of participants (user role) do not delete sensitive metadata before sharing images, and 62.3% do not know how to remove metadata. Furthermore, only 1.9% of participants (developer role) proactively remove EXIF metadata during programming. We propose ExifMetadataLib, a lightweight library for easy integration with Android OS, to mitigate sensitive metadata leakage. Tran Thanh Lam Nguyen, Barbara Carminati, Elena Ferrari 0001 |
Pervasive Mob. Comput. | 3 |
| 2026 | Big Data-Driven UAV Regulatory Compliance: Frameworks, Challenges, and OpportunitiesabstractUnmanned aerial vehicles (UAVs) are increasingly integral to various applications, generating vast data like high resolution imagery and environmental metrics, yet they face challenges in real-time regulatory compliance. As a vision paper, UAVSync-BD proposes a conceptual synchronization process, with implementation details, testbeds, and datasets deferred to future research for reproducibility. This position paper conducts a meta-analysis of UAV technology, compares regional regulations, and proposes a reference architecture for a Big Data framework leveraging distributed processing, edge computing, and AI-driven analytics to ensure UAV regulatory compliance. It also discusses open research challenges in the field. Huu Phuoc Dai Nguyen, Khaoula Hidawi, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Big Data | 4 |
| 2026 | Malware Detection at the Edge with Lightweight LLMs: A Performance EvaluationabstractThe rapid evolution of malware attacks calls for the development of innovative detection methods, especially in resource-constrained edge computing. Traditional detection techniques struggle to keep up with modern malware’s sophistication and adaptability, prompting a shift towards advanced methodologies like those leveraging Large Language Models (LLMs) for enhanced malware detection. However, deploying LLMs for malware detection directly at edge devices raises several challenges, including ensuring accuracy in constrained environments and addressing edge devices’ energy and computational limits. To tackle these challenges, this article proposes an architecture leveraging lightweight LLMs’ strengths while addressing limitations like reduced accuracy and insufficient computational power. To evaluate the effectiveness of the proposed lightweight LLM-based approach for edge computing, we perform an extensive experimental evaluation using several state-of-the-art lightweight LLMs. We test them with several publicly available datasets specifically designed for edge and IoT scenarios, and different edge nodes with varying computational power and characteristics. Christian Rondanini, Barbara Carminati, Elena Ferrari 0001, Ashish Kundu, Antonio Gaudiano |
ACM Trans. Internet Techn. | 3 |
| 2025 | Efficient Enforcement of Fine-grained Access Control in Sparkplug-based Industrial Internet of ThingsabstractSparkplug [1] is an emergent open-source software specification for Industrial Internet of Things (IIoT) systems, designed to favor data integration and device interoperability in an MQTT infrastructure. Although the security issues of IIoT systems can have relevant safety implications, Sparkplug only provides basic security features and essential, coarse-grained access control (AC) mechanisms. Effective AC solutions for Sparkplug-based IIoT systems still need to be designed, and, due to the Sparkplug’s increasing popularity and its recent definition as an ISO Standard [1], this has become a crucial need. To fill this void, this paper proposes an approach to efficiently enforcing fine-grained AC in Sparkplug-based IIoT systems. In particular, we define a fine-grained discretionary AC model and a related reference monitor implementing an efficient enforcement mechanism. Early performance evaluations show a reasonably low time overhead. Pietro Colombo, Elena Ferrari 0001 |
SMC | 2 |
| 2025 | Detecting Privacy Non-Compliance in Wearable Apps via Knowledge Graphs and LLMsabstractWearable devices are becoming increasingly popular in modern life, making significant contributions to human health monitoring. While security and privacy violations in standard apps have been extensively studied in many previous work, wearable apps have received comparatively little attention. This paper presents an automated framework that leverages Large Language Models (LLM) to identify privacy violations in Android wearable apps. The method evaluates both declared practices by extracting third-party services and shared data types from a Knowledge graph generated from the Manifest and Data Safety sections, and actual behaviors by analyzing sent-out network traffic. We evaluated the proposal on 711 popular companion apps and found that 67.5 % violate the declared data collection and sharing practices, with$\mathbf{4. 8 \%}$leaking data to undeclared third-party services. Tran Thanh Lam Nguyen, Barbara Carminati, Elena Ferrari 0001 |
WiMob | 3 |
| 2025 | A comprehensive survey on stegomalware detection in digital media, research challenges and future directionsabstractStegomalware is a malicious activity that employs steganography techniques to hide malicious code within innocent-looking files. The hidden code can then be executed to launch attacks on the victim’s computer or network. Unlike traditional malware, which performs malicious activities by executing its code, stegomalware is specifically designed to evade detection by hiding its malicious payload within seemingly harmless media files, making it difficult to detect using traditional anti-virus and anti-malware tools. To counter stegomalware, numerous steganalysis techniques have been developed for different digital media, such as images, audio, video, text, and networks. This survey presents a comprehensive and detailed overview of stegomalware, covering its background, techniques, modes of attacks, and evasion techniques in various digital media applications. It also provides notable case studies of stegomalware attacks and in-depth review of recent steganalysis approaches. In addition, the survey reviews widely used stegomalware tools and datasets. Finally, it discusses the limitations of state-of-the-art approaches and outlines related research trends. Laila Tul Badar, Barbara Carminati, Elena Ferrari 0001 |
Signal Process. | 3 |
| 2025 | ProMark: Ensuring Transparency and Privacy-Awareness in Proximity Marketing Advertising CampaignsabstractAdvertising campaigns are crucial in business development, but most marketing techniques target online purchases (e.g., Google Adsense) and rely on a centralized architecture to store and process the campaign's data and check its effectiveness. Recently, proximity marketing has become more popular thanks to the widespread use of smartphones. It exploits the short-range communication (e.g., Bluetooth) between smartphones and beacon devices to collect and send marketing information to customers. However, this might create privacy issues for customers due to the potential leakage of sensitive information (such as locations associated with time). In this paper, we propose ProMark, a privacy-aware blockchain-based platform to verify the effectiveness of proximity marketing campaigns by ensuring transparency, decentralization, and privacy in the measurement process. We implemented ProMark and carried out experiments that show that ProMark can be used in super-regional malls even during peak hours. Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | MetaLeak: Assessing Image Metadata Leakage in Android AppsabstractAlthough modern smartphone platforms emphasize user privacy protection by continually improving security mechanisms, vulnerabilities still exist, especially in the case of the Android operating system. The Android security mechanism almost delegates the entire responsibility of granting access permissions to apps to end users, who often are unaware of all the possible consequences of granting permission. Additionally, the loose protection mechanism regulating access to media files (images, videos, audio, etc.) can be exploited by attackers as a side-channel to gather sensitive data. This paper shows how sharing images containing sensitive metadata may result in an intentional or unintentional leakage of users' personal or confidential information. We designed MetaLeak, a system based on apps' hybrid analysis, to assess the identified risks. We used MetaLeak to analyze 5,000 popular apps and found that 21.9% of them sent at least one type of sensitive metadata over the internet. Moreover, for only 10.4% of the apps in our dataset, the app's actual behavior w.r.t. collecting GPS data is compliant with the developer's claims. Tran Thanh Lam Nguyen, Barbara Carminati, Elena Ferrari 0001 |
AICCSA | 3 |
| 2024 | Human Digital Twins: Efficient Privacy-Preserving Access Control Through Views Pre-materialisation
Giorgia Sirigu, Barbara Carminati, Elena Ferrari 0001 |
DBSec | 3 |
| 2024 | Access Control Integration in Sparkplug-Based Industrial Internet of Things Systems: Requirements and Open Challenges
Pietro Colombo, Elena Ferrari 0001 |
WEBIST | 2 |
| 2024 | Protecting Privacy in Knowledge Graphs With Personalized AnonymizationabstractKnowledge graphs (KGs) are emerging data models allowing data providers to share data. This data sharing might bring new knowledge and collaborations, with evident benefits for providers. However, since KGs might contain sensitive information about users, it is of utmost importance to ensure KG anonymization before publishing. Recently, some proposals have addressed the problem of KGs' anonymization based on the$k$-anonymity principle. These techniques propose to anonymize the whole dataset with the same anonymization level. However, in a contest where data are collected from different users, it is crucial to consider also users' preferences on the anonymization level to adopt for their data. To cope with this requirement, this paper presents the Personalized$k$-Attribute Degree (p-$k$-ad) principle. It allows users to specify their anonymity levels (the$k$values) while preventing adversaries from re-identifying them with a confidence higher than$\frac{1}{k}$with their specified$k$. Moreover, we design the Personalized Cluster-Based Knowledge Graph Anonymization Algorithm (PCKGA) to generate anonymized KGs satisfying p-$k$-ad. We conduct experiments on four real-life datasets and show that PCKGA greatly improves the quality of anonymized KGs comparing to previous algorithms. Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Early-Stage Ransomware Detection Based on Pre-attack Internal API Calls
Filippo Coglio, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001 |
AINA (2) | 4 |
| 2023 | MalCon: A blockchain-based malware containment framework for Internet of ThingsabstractIoT devices have become a primary medium for malware (e.g., botnets) to launch Distributed Denial of Service (DDoS) attacks. Such malware exploit low-security measures in IoT devices to spread in networks and recruit new victims. Thus, there is a need for malware countermeasures that consider both the security and operability of the network. Indeed, some IoT devices might run critical processes that do not tolerate interruptions. This paper proposes MalCon, a blockchain-based malware containment framework for IoT. It aims to stop malware from spreading in a network by a set of containment strategies encoded into smart contracts to be executed by the infected devices. Moreover, MalCon provides a monitoring service that ensures trustworthy behavior in the network and reports to the system administrator any fraudulent activity of the monitored devices. MalCon was tested extensively with real-life malware and use cases. It quickly and drastically reduces the number of infected devices in a network, even in an extreme case of a fully connected network. Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 3 |
| 2022 | MalRec: A Blockchain-based Malware Recovery Framework for Internet of ThingsabstractIoT devices have been considered an attractive target for malware (e.g., botnets) due to their low computational resources and lack of security measures. The literature focuses on detecting malware, but less attention is given to recovery solutions. In addition, with the development of data processing regulations in different countries, a need for transparent recovery systems that can help organizations present their due diligence arises. This work proposes a blockchain-based backup policy enforcement framework for IoT where an organization can formalize backup policies and enforce them. We have run our solution under extensive tests that show that it can be deployed in real-life IoT environments, despite the limited computational resources of IoT devices. Ahmed Lekssays, Giorgia Sirigu, Barbara Carminati, Elena Ferrari 0001 |
ARES | 4 |
| 2022 | A Blockchain-based Framework in Support of Privacy Preferences Enforcement for Scientific Workflows : (Invited Paper)abstractScientific workflows are today a vital tool for computational science, enabling the definition and execution of complex applications in heterogeneous and often distributed environments. A key characteristic of scientific workflow applications is that they often require the massive processing of an enormous amount of data that, in many cases, convey personal information. To allow an efficient and transparent privacy compliance check process, in this paper, we propose a blockchain-based solution coupled with an ad-hoc index structure that makes it possible an efficient compliance check for a massive amount of data. Federico Daidone, Barbara Carminati, Elena Ferrari 0001 |
ICWS | 3 |
| 2022 | PriApp-Install: Learning User Privacy Preferences on Mobile Apps' Installation
Ha Xuan Son, Barbara Carminati, Elena Ferrari 0001 |
ISPEC | 3 |
| 2022 | Efficient ABAC based information sharing within MQTT environments under emergenciesabstractRecent emergencies, such as the COVID-19 pandemic have shown how timely information sharing is essential to promptly and effectively react to emergencies. Internet of Things has magnified the possibility of acquiring information from different sensors and using it for emergency management and response. However, it has also amplified the potential of information misuse and unauthorized access to information by untrusted users. Therefore, this paper proposes an access control framework tailored to MQTT-based IoT ecosystems. By leveraging Complex Event Processing, we can enforce controlled and timely data sharing in emergency and ordinary situations. The system has been tested with a case study that targets patient monitoring during the COVID-19 pandemic, showing promising results. Pietro Colombo, Elena Ferrari 0001, Engin Deniz Tümer |
Comput. Secur. | 2 |
| 2022 | A Risk Estimation Mechanism for Android Apps based on Hybrid AnalysisabstractAbstract Mobile apps represent essential tools in our daily routines, supporting us in almost every task. However, this assistance might imply a high cost in terms of privacy. Indeed, mobile apps gather a massive amount of data about individuals (e.g., users’ profiles and habits) and their devices (e.g., locations), where not all are strictly needed for app execution. According to privacy laws, apps’ providers must inform end-users on adopted data usage practices (e.g., which data are collected and for which purpose). Unfortunately, understanding these practices is a complex task for average end-users. The result is that they install apps without understanding their privacy implications. To support users in making more privacy-aware decisions on app usage, we propose a risk estimation approach based on an analysis of the app’s code. This analysis adopts a hybrid strategy, exploiting static and dynamic code analyses. Static analysis aims at discovering which personal data an app is collecting to determine whether the target app is asking more than required. This gives the first estimation of the app’s risk level. In addition, we also perform a dynamic analysis of the target app’s code. This further analysis helps determining whether the collected personal data is consumed locally on the mobile device or sent out to external services. If this happens, the risk level has to be increased, as personal data are more exposed. To prove the proposal’s effectiveness, we run several experiments involving different groups of participants. The obtained accuracy results are promising and outperform those obtained with static analysis only. Ha Xuan Son, Barbara Carminati, Elena Ferrari 0001 |
Data Sci. Eng. | 3 |
| 2022 | Blockchain-Based Privacy Enforcement in the IoT DomainabstractThe Internet of Things (IoT) pervades our lives every day and has given end users the opportunity of accessing personalized and advanced services based on the analysis of the sensed data. However, IoT services are also characterized by new challenges related to security and privacy because end users often share sensitive data with different consumers without precise knowledge of how they will be managed and used. To cope with these issues, we propose a blockchain-based privacy enforcement framework where users can define how their data can be used and check if their will is respected without relying on a centralized manager. The preliminary tests we performed, simulating different scenarios, show the feasibility of our approach. Federico Daidone, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | LiMNet: Early-Stage Detection of IoT Botnets with Lightweight Memory Networks
Lodovico Giaretta, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas |
ESORICS (1) | 4 |
| 2021 | Privacy-Preserving Sequential Publishing of Knowledge GraphsabstractKnowledge graphs (KGs) are widely shared because they can model both users' attributes as well as their relationships. Unfortunately, adversaries can re-identify their victims in these KGs by using a rich background knowledge about not only the victims' attributes but also their relationships. A preliminary work to deal with this issue has been proposed in [1] which anonymizes both user attributes and relationships, but this is not enough. Indeed, adversaries can still re-identify target users if data providers publish new versions of their anonymized KGs. We remedy this problem by presenting the kw-Time-Varying Attribute Degree (kw-tad) principle that prevents adversaries from re-identifying any user appearing in w continuous anonymized KGs with a confidence higher than rac{1}{k}. Moreover, we introduce the Cluster-based Time-Varying Knowledge Graph Anonymization Algorithm to generate anonymized KGs satisfying kw-tad. Finally, we prove that even if data providers insert/re-insert/update/delete their users, the users are protected by kw-tad. Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
ICDE | 3 |
| 2021 | PAutoBotCatcher: A blockchain-based privacy-preserving botnet detector for Internet of Things
Ahmed Lekssays, Luca Landa, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 4 |
| 2021 | Evaluating the effects of access control policies within NoSQL systems
Pietro Colombo, Elena Ferrari 0001 |
Future Gener. Comput. Syst. | 2 |
| 2021 | Regulating data sharing across MQTT environments
Pietro Colombo, Elena Ferrari 0001, Engin Deniz Tümer |
J. Netw. Comput. Appl. | 2 |
| 2021 | Privacy-Aware Personal Data Storage (P-PDS): Learning how to Protect User Privacy from External ApplicationsabstractRecently, Personal Data Storage (PDS) has inaugurated a substantial change to the way people can store and control their personal data, by moving from a service-centric to a user-centric model. PDS offers individuals the capability to keep their data in a unique logical repository, that can be connected and exploited by proper analytical tools, or shared with third parties under the control of end users. Up to now, most of the research on PDS has focused on how to enforce user privacy preferences and how to secure data when stored into the PDS. In contrast, in this paper we aim at designing a Privacy-aware Personal Data Storage (P-PDS), that is, a PDS able to automatically take privacy-aware decisions on third parties access requests in accordance with user preferences. The proposed P-PDS is based on preliminary results presented in [1] , where it has been demonstrated that semi-supervised learning can be successfully exploited to make a PDS able to automatically decide whether an access request has to be authorized or not. In this paper, we have deeply revised the learning process in order to have a more usable P-PDS, in terms of reduced effort for the training phase, as well as a more conservative approach w.r.t. users privacy, when handling conflicting access requests. We run several experiments on a realistic dataset exploiting a group of 360 evaluators. The obtained results show the effectiveness of the proposed approach. Bikash Chandra Singh, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Cluster-Based Anonymization of Knowledge Graphs
Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
ACNS (2) | 3 |
| 2020 | Mammoth: Monitoring the ABAC Monitor of MQTT-based Internet of Things ecosystemsabstractData confidentiality and privacy are becoming primary concerns for Internet of Things applications. A variety of access control approaches have been proposed to address this issue. In this demonstration we present a tool, called Mammoth, which complements an ABAC framework for MQTT-based IoT ecosystems, with a dashboard of analysis services designed for security administrators. Mammoth supports the real-time analysis of target MQTT ecosystems, allowing security administrators to analyze the effects of the enforcement mechanisms on the flow of exchanged messages. The demonstration will allow participants to try Mammoth services in a simulated MQTT-based scenario. Pietro Colombo, Elena Ferrari 0001, Samuele Salvia |
SACMAT | 2 |
| 2019 | Access control technologies for Big Data management systems: literature review and future trendsabstractData security and privacy issues are magnified by the volume, the variety, and the velocity of Big Data and by the lack, up to now, of a reference data model and related data manipulation languages. In this paper, we focus on one of the key data security services, that is, access control, by highlighting the differences with traditional data management systems and describing a set of requirements that any access control solution for Big Data platforms may fulfill. We then describe the state of the art and discuss open research issues. Pietro Colombo, Elena Ferrari 0001 |
Cybersecur. | 2 |
| 2018 | Detecting Spam Accounts on TwitterabstractSocial networks have become a popular way for internet surfers to interact with friends and family members, reading news, and also discuss events. Users spend more time on well-known social platforms (e.g., Facebook, Twitter, etc.) storing and sharing their personal information. This information together with the opportunity of contacting thousands of users attract the interest of malicious users. They exploit the implicit trust relationships between users in order to achieve their malicious aims, for example, create malicious links within the posts/tweets, spread fake news, send out unsolicited messages to legitimate users, etc. In this paper, we investigate the nature of spam users on Twitter with the goal to improve existing spam detection mechanisms. For detecting Twitter spammers, we make use of several new features, which are more effective and robust than existing used features (e.g., number of followings/followers, etc.). We evaluated the proposed set of features by exploiting very popular machine learning classification algorithms, namely k-Nearest Neighbor (k-NN), Decision Tree (DT), Naive Bayesian (NB), Random Forest (RF), Logistic Regression (LR), Support Vector Machine (SVM), and eXtreme Gradient Boosting (XG-Boost). The performance of these classifiers are evaluated and compared based on different evaluation metrics. We compared the performance of our proposed approach with four latest state of art approaches. The experimental results show that the proposed set of features gives better performance than existing state of art approaches. Md. Zulfikar Alom, Barbara Carminati, Elena Ferrari 0001 |
ASONAM | 3 |
| 2018 | Confidential Business Process Execution on BlockchainabstractOne of the main issues in service collaborations among business partners is the possible lack of trust among them. A promising approach to cope with this issue is leveraging on blockchain technology by encoding with smart contracts the business process workflow. This brings the benefits of trust decentralization, transparency, and accountability of the service composition process. However, data in the blockchain are public, implying thus serious consequences on confidentiality and privacy. Moreover, smart contracts can access data outside the blockchain only through Oracles, which might pose new confidentiality risks if no assumptions are made on their trustworthiness. For these reasons, in this paper, we are interested in investigating how to ensure data confidentiality during business process execution on blockchain even in the presence of an untrusted Oracle. Barbara Carminati, Christian Rondanini, Elena Ferrari 0001 |
ICWS | 3 |
| 2018 | Access Control in the Era of Big Data: State of the Art and Research DirectionsabstractData security and privacy issues are magnified by the volume, the variety, and the velocity of Big Data and by the lack, up to now, of a standard data model and related data manipulation language. In this paper, we focus on one of the key data security services, that is, access control, by highlighting the differences with traditional data management systems and describing a set of requirements that any access control solution for Big Data platforms may fulfill. We then describe the state of the art and discuss open research issues. Pietro Colombo, Elena Ferrari 0001 |
SACMAT | 2 |
| 2018 | Access Control Enforcement within MQTT-based Internet of Things EcosystemsabstractConfidentiality and privacy of data managed by IoT ecosystems is becoming a primary concern. This paper targets the design of a general access control enforcement mechanism for MQTT-based IoT ecosystems. The proposed approach is presented with ABAC, but other access control models can be similarly supported. The solution is based on an enforcement monitor that has been designed to operate as a proxy between MQTT clients and an MQTT server. The monitor enforces access control constraints by intercepting and possibly manipulating the flow of exchanged MQTT control packets. Early experimental evaluations have overall shown low enforcement overhead. Pietro Colombo, Elena Ferrari 0001 |
SACMAT | 2 |
| 2018 | Decentralizing privacy enforcement for Internet of Things smart objects
Gokhan Sagirlar, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 3 |
| 2018 | Risk Assessment in Social Networks Based on User Anomalous BehaviorsabstractAlthough the dramatic increase in Online Social Network (OSN) usage, there are still a lot of security and privacy concerns. In such a scenario, it would be very beneficial to have a mechanism able to assign a risk score to each OSN user. For this reason, in this paper, we propose a risk assessment based on the idea that the more a user behavior diverges from what it can be considered as a `normal behavior', the more it should be considered risky. In doing this, we have taken into account that OSN population is really heterogeneous in observed behaviors. As such, it is not possible to define a unique standard behavioral model that fits all OSN users' behaviors. However, we expect that similar people tend to follow similar rules with the results of similar behavioral models. For this reason, we propose a risk assessment approach organized into two phases: similar users are first grouped together, then, for each identified group, we build one or more models for normal behavior. The carried out experiments on a real Facebook dataset show that the proposed model outperforms a simplified behavioral-based risk assessment where behavioral models are built over the whole OSN population, without a group identification phase. Naeimeh Laleh, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | Enhanced Audit Strategies for Collaborative and Accountable Data Sharing in Social NetworksabstractData sharing and access control management is one of the issues still hindering the development of decentralized online social networks (DOSNs), which are now gaining more research attention with the recent developments in P2P computing, such as the secure public ledger–based protocols (Blockchains) for monetary systems. In a previous work, we proposed an initial audit–based model for access control in DOSNs. In this article, we focus on enhancing the audit strategies and the privacy issues emerging from records kept for audit purposes. We propose enhanced audit and collaboration strategies, for which experimental results, on a real online social network graph with simulated sharing behavior, show an improvement in the detection rate of bad behavior of more than 50% compared to the basic model. We also provide an analysis of the related privacy issues and discuss possible privacy-preserving alternatives. Leila Bahri, Barbara Carminati, Elena Ferrari 0001, Andrea Bianco |
ACM Trans. Internet Techn. | 3 |
| 2018 | Privacy in Web Service Transactions: A Tale of More than a Decade of WorkabstractThe web service computing paradigm has introduced great benefits to the growth of e-markets, both under the customer to business and the business to business models. The value capabilities allowed by the conception of web services, such as interoperability, efficiency, just-in-time integration, etc., have made them the most common way of doing business online. With the maturation of the web services underlying functional properties and facilitating standards, and with the proliferation of the amounts of data they use and they generate, researchers and practitioners have been dedicating considerable efforts to the related emerging privacy concerns. The literature contains number of research works on these privacy concerns, each addressing them from a different focal point. We have explored the available literature on web services privacy during transactions, to present, in this paper, a thorough survey of the most relevant published proposals. We identified 20 works that address privacy related problems in web services consumption. We categorize them based on the approach they take and we compare them based on a proposed evaluation framework, derived from the adopted techniques and addressed requirements. Leila Bahri, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2017 | SAMPAC: Socially-Aware collaborative Multi-Party Access ControlabstractAccording to the current design of content sharing services, such as Online Social Networks (OSNs), typically (i) the service provider has unrestricted access to the uploaded resources and (ii) only the user uploading the resource is allowed to define access control permissions over it. This results in a lack of control from other users that are associated, in some way, with that resource. To cope with these issues, in this paper, we propose a privacy-preserving system that allows users to upload their resources encrypted, and we design a collaborative multi-party access control model allowing all the users related to a resource to participate in the specification of the access control policy. Our model employs a threshold-based secret sharing scheme, and by exploiting users' social relationships, sets the trusted friends of the associated users responsible to partially enforce the collective policy. Through replication of the secret shares and delegation of the access control enforcement role, our model ensures that resources are timely available when requested. Finally, our experiments demonstrate that the performance overhead of our model is minimal and that it does not significantly affect user experience. Panagiotis Ilia, Barbara Carminati, Elena Ferrari 0001, Paraskevi Fragopoulou, Sotiris Ioannidis |
CODASPY | 3 |
| 2017 | Learning Privacy Habits of PDS OwnersabstractThe concept of Personal Data Storage (PDS) has recently emerged as an alternative and innovative way of managing personal data w.r.t. the service-centric one commonly used today. The PDS offers a unique logical repository, allowing individuals to collect, store, and give access to their data to third parties. The research on PDS has so far mainly focused on the enforcement mechanisms, that is, on how user privacy preferences can be enforced. In contrast, the fundamental issue of preference specification has been so far not deeply investigated. In this paper, we do a step in this direction by proposing different learning algorithms that allow a fine-grained learning of the privacy aptitudes of PDS owners. The learned models are then used to answer third party access requests. The extensive experiments we have performed show the effectiveness of the proposed approach. Bikash Chandra Singh, Barbara Carminati, Elena Ferrari 0001 |
ICDCS | 3 |
| 2017 | Towards a Unifying Attribute Based Access Control Approach for NoSQL DatastoresabstractNoSQL datastores allow the efficient management of high volumes of heterogeneous and unstructured data, meeting the requirements of a variety of today ICT applications. However, most of these systems poorly support data security, and recent surveys show that their simplistic support for data protection is considered as a reason not to use them.1 In recent years, Attribute Based Access Control (ABAC) is getting more and more popularity, for its ability to provide highly flexible and customized forms of data protection at different granularity levels. In the current work, with the aim to raise users' confidence in the protection of data managed by NoSQL systems, we define a general approach to enforce ABAC within NoSQL systems. Our approach relies on SQL++[20], a unifying query language for NoSQL platforms. In particular, we develop a novel SQL++ query rewriting mechanism able to enforce heterogeneous types of ABAC policies specified up to cell level. Experimental results show an overhead which is not negligible for policies covering high percentage of the fields characterizing the protected documents, but which is far more contained when field level policies are more sparsely specified. Pietro Colombo, Elena Ferrari 0001 |
ICDE | 2 |
| 2017 | Enhancing MongoDB with Purpose-Based Access ControlabstractPrivacy has become a key requirement for data management systems. Nevertheless, NoSQL datastores, namely highly scalable non relational database management systems, which often support data management of Internet scale applications,still do not provide support for privacy policies enforcement. With this work, we begin to address this issue, by proposing an approach for the integration of purpose based policy enforcement capabilities into MongoDB, a popular NoSQL datastore. Our contribution consists of the enhancement of the MongoDB role based access control model with privacy concepts and related enforcement monitor. The proposed monitor is easily integrable into any MongoDB deployment through simple configurations. Experimental results show that our monitor enforces purpose-based access control with low overhead. Pietro Colombo, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | Trust and privacy correlations in social networks: A deep learning frameworkabstractOnline Social Networks (OSNs) remain the focal point of Internet usage. Since the beginning, networking sites tried best to have right privacy mechanisms in place for users, enabling them to share the right content with the right audience. With all these efforts, privacy customizations remain hard for users across the sites. Existing research that address this problem mainly focus on semi-supervised strategies that introduce extra complexity by requiring the user to manually specify initial privacy preferences for their friends. In this work, we suggest an adaptive solution that can dynamically generate privacy labels for users in OSNs. To this end, we introduce a deep reinforcement learning framework that targets two key problems in OSNs like Facebook: the exposure of users' interactions through the network to less trusted direct friends, and the possibility of propagating user updates through direct friends' interactions to indirect friends. By implementing this framework, we aim at understanding how social trust and privacy could be correlated, specifically in a dynamic fashion. We report the ranked dependence between the generated privacy labels and the estimated user trust values, which indicate the ability of the framework to identify the highly trusted users and share with them higher percentages of data. Shatha Jaradat, Nima Dokoohaki, Mihhail Matskin, Elena Ferrari 0001 |
ASONAM | 4 |
| 2016 | Beat the DIVa - decentralized identity validation for online social networksabstractFake accounts in online social networks (OSNs) have known considerable sophistication and are now attempting to gain network trust by infiltrating within honest communities. Honest users have limited perspective on the truthfulness of new online identities requesting their friendship. This facilitates the task of fake accounts in deceiving honest users to befriend them. To address this, we have proposed a model that learns hidden correlations between profile attributes within OSN communities, and exploits them to assist users in estimating the trustworthiness of new profiles. To demonstrate our method, we suggest, in this demo, a game application through which players try to cheat the system and convince nodes in a simulated OSN to befriend them. The game deploys different strategies to challenge the players and to reach the objectives of the demo. These objectives are to make participants aware of how fake accounts can infiltrate within their OSN communities, to demonstrate how our suggested method could aid in mitigating this threat, and to eventually strengthen our model based on the data collected from the moves of the players. Leila Bahri, Amira Soliman 0001, Jacopo Squillaci, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas |
ICDE | 5 |
| 2016 | Towards Virtual Private NoSQL datastoresabstractMany modern applications use context related information to provide highly personalized services, and use NoSQL databases for data management, as these systems show outstanding performance and support high volumes of data. However, NoSQL databases integrate poor data protection features with basic coarse grained access control and no support for context aware policies. Therefore, we believe that a general approach is required to enhance NoSQL datastores with fine grained context aware access control. In this paper, we start to fill this void by targeting MongoDB, a very popular datastore. The contribution is twofold. We enhance MongoDB's access control model with advanced features and we define an enforcement monitor for the proposed enhanced model, which can be straightforwardly used in any MongoDB deployment. Technological limitations of MongoDB do not allow implementing the same efficient enforcement mechanism for all query types. As a consequence, experimental results show an enforcement overhead that is significant for aggregate queries, which contrasts with a low overhead measured for find and map-reduce queries. Pietro Colombo, Elena Ferrari 0001 |
ICDE | 2 |
| 2016 | Efficient enforcement of action-aware purpose-based access control within relational database management systemsabstractAlthough database management systems (DBMSs) enforce access control according to a variety of models (see [2] for an overview), the majority of them do not integrate native privacy protection mechanisms. This void has been partially filled out with the advent of purpose based access control, as this access control model has brought to the integration of basic privacy preservation functionalities into DBMSs. Even though purposes represent a key feature of privacy policies, DBMSs' privacy awareness can be significantly increased considering additional privacy related aspects. With this work we do a step to achieve this goal by focusing on the actions performed by queries on data and the categories of the accessed data. We propose an access control model that supports highly customized privacy-aware access control policies and significantly improves the basic privacy preservation capabilities of the purpose based model. The proposed model is complemented with an efficient enforcement monitor, which can be easily integrated into relational DBMSs. Early experimental evaluations show the efficiency of the proposed framework. Pietro Colombo, Elena Ferrari 0001 |
ICDE | 2 |
| 2016 | A Language and an Inference Engine for Twitter Filtering RulesabstractWe consider the problem of the filtering of Twitter posts, that is, the hiding of those posts which the user prefers not to visualize on his/her timeline. We define a language for specifying filtering policies suitable for Twitter posts. The language allows each user to decide which posts to filter out based on his/her sensibility and preferences. Since average users may not have the skills necessary to translate their filtering needs into a set of rules, we also propose a method for inferring a policy automatically, based solely on examples of the desired filtering behavior. The method is based on an evolutionary approach driven by a multi-objective optimization scheme. We assess our proposal experimentally on a real Twitter dataset and the results are highly promising. Alberto Bartoli, Barbara Carminati, Elena Ferrari 0001, Eric Medvet |
WI | 3 |
| 2016 | LAMP - Label-Based Access-Control for More Privacy in Online Social Networks
Leila Bahri, Barbara Carminati, Elena Ferrari 0001, William Lucia |
WISTP | 3 |
| 2016 | Fine-Grained Access Control Within NoSQL Document-Oriented DatastoresabstractThe recent years have seen the birth of several NoSQL datastores, which are getting more and more popularity for their ability to handle high volumes of heterogeneous and unstructured data in a very efficient way. In several cases, NoSQL databases proved to outclass in terms of performance, scalability, and ease of use relational database management systems, meeting the requirements of a variety of today ICT applications. However, recent surveys reveal that, despite their undoubted popularity, NoSQL datastores suffer from some weaknesses, among which the lack of effective support for data protection appears among the most serious ones. Proper data protection mechanisms are therefore required to fill this void. In this work, we start to address this issue by focusing on access control and discussing the definition of a fine-grained access control framework for document-oriented NoSQL datastores. More precisely, we first focus on issues and challenges related to the definition of such a framework, considering theoretical, implementation, and integration aspects. Then, we discuss the reasons for which state-of-the-art fine-grained access control solutions proposed for relational database management systems cannot be used within the NoSQL scenario. We then introduce possible strategies to address the identified issues, which are at the basis of the framework development. Finally, we shortly report the outcome of an experience where the proposed framework has been used to enhance the data protection features of a popular NoSQL database. Pietro Colombo, Elena Ferrari 0001 |
Data Sci. Eng. | 2 |
| 2016 | Trustworthy and effective person-to-person payments over multi-hop MANETs
Barbara Carminati, Elena Ferrari 0001, Ngoc Hong Tran |
J. Netw. Comput. Appl. | 2 |
| 2016 | Detection of Unspecified Emergencies for Controlled Information SharingabstractDuring emergency situations one of the key requirements to handle the crisis is information sharing among organizations involved in the emergency management. When emergency situations are well known, it is possible to specify a priori these situations and to plan the information sharing needs in advance. However, there are many situations where it is not possible to describe these emergencies and their information sharing requirements beforehand. Therefore, in this paper, we present a framework able to deal with both specified and unspecified emergencies. The idea is to detect unspecified emergencies and related information sharing needs through denied access request analysis, anomaly detection techniques, and analysis of the history of permitted access requests. Besides presenting the techniques, the paper also presents experiments to verify their effectiveness. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | Guest Editorial: Special Section on the International Conference on Data EngineeringabstractThe papers in this special section were presented at the 30th IEEE International Conference on Data Engineering (ICDE) took place in Chicago, IL, from March 31 to April 4, 2014. This special section is comprised of the long versions of five exceptional papers selected from the research program. Isabel F. Cruz, Elena Ferrari 0001, Yufei Tao 0001 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2016 | COIP - Continuous, Operable, Impartial, and Privacy-Aware Identity Validity Estimation for OSN ProfilesabstractIdentity validation of Online Social Networks’ (OSNs’) peers is a critical concern to the insurance of safe and secure online socializing environments. Starting from the vision of empowering users to determine the validity of OSN identities, we suggest a framework to estimate the trustworthiness of online social profiles based only on the information they contain. Our framework is based on learning identity correlations between profile attributes in an OSN community and on collecting ratings from OSN community members to evaluate the trustworthiness of target profiles. Our system guarantees utility, user anonymity, impartiality in rating, and operability within the dynamics and continuous evolution of OSNs. In this article, we detail the system design, and we prove its correctness against these claimed quality properties. Moreover, we test its effectiveness, feasibility, and efficiency through experimentation on real-world datasets from Facebook and Google+, in addition to using the Adults UCI dataset. Leila Bahri, Barbara Carminati, Elena Ferrari 0001 |
ACM Trans. Web | 3 |
| 2015 | DIVa: Decentralized Identity Validation for Social NetworksabstractOnline Social Networks exploit a lightweight process to identify their users so as to facilitate their fast adoption. However, such convenience comes at the price of making legitimate users subject to different threats created by fake accounts. Therefore, there is a crucial need to empower users with tools helping them in assigning a level of trust to whomever they interact with. To cope with this issue, in this paper we introduce a novel model, DIVa, that leverages on mining techniques to find correlations among user profile attributes. These correlations are discovered not from user population as a whole, but from individual communities, where the correlations are more pronounced. DIVa exploits a decentralized learning approach and ensures privacy preservation as each node in the OSN independently processes its local data and is required to know only its direct neighbors. Extensive experiments using real-world OSN datasets show that DIVa is able to extract fine-grained community-aware correlations among profile attributes with average improvements up to 50% than the global approach. Amira Soliman 0001, Leila Bahri, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas |
ASONAM | 4 |
| 2015 | GuardMR: Fine-grained Security Policy Enforcement for MapReduce SystemsabstractExecuting data analytics tasks in MapReduce systems introduces new security and privacy concerns as the processed unstructured datasets may contain sensitive information (e.g., social security numbers, business sensitive information) at the level of individual records, and the existing file-level access control mechanisms provide all or nothing access to the entire dataset. To address these concerns, we propose GUARDMR which is a novel, modular framework that can enforce fine-grained security policies at the key-value level in MapReduce systems. The presented security policies can dynamically create authorized views of data resources based on the organizational roles of the MapReduce users. GUARDMR further simplifies the specification of authorized views via automatically generating the bytecode of the functions necessary for creating the views, from the high level specification language (i.e., OCL). It facilitates enforcement of a broad, flexible set of policies that can handle the complexity demanded by high volume, high variety, unstructured datasets and general MapReduce computation without any modification to the underlying MapReduce system and operating system. Our evaluation results indicate that GUARDMR provides fine-grained access control for Apache Hadoop system with easy maintainability and very low overhead Huseyin Ulusoy, Pietro Colombo, Elena Ferrari 0001, Murat Kantarcioglu, Erman Pattuk |
AsiaCCS | 3 |
| 2015 | Evolutionary Inference of Attribute-Based Access Control Policies
Eric Medvet, Alberto Bartoli, Barbara Carminati, Elena Ferrari 0001 |
EMO (1) | 4 |
| 2015 | A Privacy-Preserving Framework for Constrained Choreographed Service CompositionabstractOne of the major goals of Web services is to make easier their composition to form more complex services, modeled as workflows. A key role in the Web services composition is the selection of a proper service for each activity in the workflow. In general, this requires the exchange of sensitive information of users, requiring the composition, as well as of involved service providers. So far this problem has been investigated in the setting of orchestrated service composition, under the assumption of the presence of a broker coordinating the composition. However, a promising alternative approach is the one of choreography, where each service involved in the service composition has to locally manage service selection and invocation. In this paper, we propose a framework to enforce user and provider requirements in the scenario of service choreography in a privacy-preserving way, that is, without the releasing of any private information of users and providers. To achieve this result we make use of different privacy-preserving protocols. As it will be shown in the paper, the proposed solution does not implies relevant overhead. Barbara Carminati, Elena Ferrari 0001, Ngoc Hong Tran |
ICWS | 2 |
| 2015 | Efficient Enforcement of Action-Aware Purpose-Based Access Control within Relational Database Management SystemsabstractAmong the variety of access control models proposed for database management systems (DBMSs) a key role is covered by the purpose-based access control model, which, while enforcing access control, also achieves basic privacy preservation. We believe that DBMSs could greatly take benefit from the integration of an enhanced purpose based model supporting highly customized and efficient access control. Therefore, in this paper, we propose a purpose-based model that supports action-aware policy specification and a related efficient enforcement framework to be integrated into relational DBMSs. The experimental evaluation we have performed shows the feasibility and efficiency of the proposed framework. Pietro Colombo, Elena Ferrari 0001 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2014 | Discovering trust patterns in ego networksabstractIn the past decade, online social networks have provided invaluable data in understanding how social networks change in time while attracting new users and fostering relationships among members. The concept of social trust was developed to explain why and how much users trust each other to become friends or expose their personal data. Existing work on social trust analyze behavioral features and profile attributes to find trust between pairs of users. Although useful, these works suffer from the problem of incomplete, inaccurate and inconsistent social network data. We approach the problem of analyzing trust from an ego network perspective. We observe new friendships, group formations and structural roles of users in ego networks to outline three trust questions. Answers to these questions provide insights into how social trust can be measured from user connections. Cuneyt Gurcan Akcora, Elena Ferrari 0001 |
ASONAM | 2 |
| 2014 | EgoCentric: Ego Networks for Knowledge-based Short Text ClassificationabstractClassification of short text messages is becoming more and more relevant in these years, where billion of users use online social networks to communicate with other people. Understanding message content can have a huge impact on many data analysis processes, ranging from the study of online social behavior to targeted advertisement, to security and privacy purposes. In this paper, we propose a new unsupervised knowledge-based classifier for short text messages, where each category is represented by an ego-network. A short text is classified into a category depending on how far its words are from the ego of that category. We show how this technique can be used both in single label and in multi-label classification, and how it outperforms the state of the art for short text messages classification. William Lucia, Elena Ferrari 0001 |
CIKM | 2 |
| 2014 | Community-Based Identity Validation on Online Social NetworksabstractIdentity management in online social networks (OSNs) is a challenging, yet important requirement for effective privacy protection and trust management. Literature offers several proposals addressing issues related to identity breaches and/or identity related attacks on OSNs, but only a few aim at giving means to judge users' reliability in terms of trustworthiness of their claimed identities. In this paper, we propose an identity validation process that relies on OSN community feedback to assign to OSN users identity trustworthiness levels. For this purpose, we define a community based supervised learning process to detect the set of attributes in a user profile for which it is expected to see a correlation among their values (e.g., job and salary). Once these correlated attribute sets are identified, the profile of a target user is judged by a selected group of raters to estimate her identity trustworthiness level. We demonstrate the effectiveness of our proposal through experimentation under two different scenarios and using real data. The experiments' results under the two scenarios demonstrate the effectiveness and meaningfulness of our proposal. Leila Bahri, Barbara Carminati, Elena Ferrari 0001 |
ICDCS | 3 |
| 2014 | Secure Web Service Composition with Untrusted BrokerabstractComposite web services are usually coordinated according to a workflow, composed by several activities, each of which carried out by a service. A way to coordinate this cooperation is orchestration, which implies that the workflow underlying the composite web service is processed by a broker hosting a workflow engine (e.g., BPEL engine). According to the orchestration paradigm, the broker coordinates the invocation of services involved in the composition by passing the needed parameters. In general, all previous proposals for the service orchestration model consider the broker as a trusted entity. As such, they never payed attention to the fact that the broker is able to access several pieces of sensitive data. We believe there is the need to protect them against improper access and usage from partner services as well as the broker. To cope with these issues, in this paper, we propose a protocol based on a selective encryption able to ensure that both the broker and service partners can access only the information needed to fulfill their activities. Barbara Carminati, Elena Ferrari 0001, Ngoc Hong Tran |
ICWS | 2 |
| 2014 | Special issue on secure and privacy-aware data management
Elena Ferrari 0001, Murat Kantarcioglu |
Distributed Parallel Databases | 1 |
| 2014 | Enforcing Obligations within RelationalDatabase Management SystemsabstractWithin Database Management Systems (DBMS), privacy policies regulate the collection, access and disclosure of the stored personal, identifiable and sensitive data. Policies often specify obligations which represent actions that must be executed or conditions that must be satisfied before and/or after data are accessed. Although numerous policies specification languages allow the specification, no systematic support is provided to enforce obligations within relational DBMS. In this paper, we make a step to fill this void presenting an approach to the definition of an enforcement monitor which handles privacy policies that include obligations. Such a monitor is derived from the same set of policies that must be enforced, and regulates the execution of SQL code based on the satisfaction of a variety of obligation types. The proposed solution is systematic, has been automated, does not require any programming activity and can be used with most of the existing relational DBMSs. Pietro Colombo, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2014 | Enforcement of Purpose Based Access Control within Relational Database Management SystemsabstractPrivacy is becoming a key requirement for ICT applications that handle personal data. However, Database Management Systems (DBMSs), which are devoted to data collection and processing by definition, still do not provide the proper support for privacy policies. Policies are enforced by ad-hoc programmed software modules that complement DBMS access control services. This practice is time consuming, error prone, and neither general nor scalable. This work does a first step to overcome these limits. We propose a systematic approach to the automatic development of a monitor that regulates the execution of SQL queries based on purpose based privacy policies. The proposed solution does not require programming, it is general, platform independent and usable with most of the existing relational DBMSs. Pietro Colombo, Elena Ferrari 0001 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2014 | Privacy-Preserving Enhanced Collaborative TaggingabstractCollaborative tagging is one of the most popular services available online, and it allows end user to loosely classify either online or offline resources based on their feedback, expressed in the form of free-text labels (i.e., tags). Although tags may not be per se sensitive information, the wide use of collaborative tagging services increases the risk of cross referencing, thereby seriously compromising user privacy. In this paper, we make a first contribution toward the development of a privacy-preserving collaborative tagging service, by showing how a specific privacy-enhancing technology, namely tag suppression, can be used to protect end-user privacy. Moreover, we analyze how our approach can affect the effectiveness of a policy-based collaborative tagging system that supports enhanced web access functionalities, like content filtering and discovery, based on preferences specified by end users. Javier Parra-Arnau, Andrea Perego, Elena Ferrari 0001, Jordi Forné, David Rebollo-Monedero |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2013 | Controlled information sharing for unspecified emergenciesabstractDuring emergency situations a key requirement is information sharing. If emergencies are known a-priori, it is possible to specify them using emergency policies, modeling the extra sharing needs usually arising during emergencies. However, there are many situations where emergencies can be unspecified and yet they require a timely information sharing. Therefore, in this paper, we present an extended model which is able to deal with such emergencies. The idea is to open the system to some controlled violations, i.e., those denied access requests that signal the occurrence of an unspecified emergency. We have defined measures to determine whether a denied access request represents an information need for an unspecified emergency or the risk of an attempted abuse, and we have carried out experiments to verify the effectiveness of the proposed measures comparing them with a human-based evaluation. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
CRiSIS | 2 |
| 2013 | SHARE: Secure information sharing framework for emergency managementabstract9/11, Katrina, Fukushima and other recent emergencies demonstrate the need for effective information sharing across government agencies as well as non-governmental and private organizations to assess emergency situations, and generate proper response plans. In this demo, we present a system to enforce timely and controlled information sharing in emergency situations. The framework is able to detect emergencies, enforce temporary access control policies and obligations to be activated during emergencies, simulate emergency situations for demonstrational purposes and show statistical results related to emergency activation/deactivation and consequent access control policies triggering. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
ICDE | 2 |
| 2013 | A System for Timely and Controlled Information Sharing in Emergency SituationsabstractDuring natural disasters or emergency situations, an essential requirement for an effective emergency management is the information sharing. In this paper, we present an access control model to enforce controlled information sharing in emergency situations. An in-depth analysis of the model is discussed throughout the paper, and administration policies are introduced to enhance the model flexibility during emergencies. Moreover, a prototype implementation and experiments results are provided showing the efficiency and scalability of the system. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | A System to Filter Unwanted Messages from OSN User WallsabstractOne fundamental issue in today's Online Social Networks (OSNs) is to give users the ability to control the messages posted on their own private space to avoid that unwanted content is displayed. Up to now, OSNs provide little support to this requirement. To fill the gap, in this paper, we propose a system allowing OSN users to have a direct control on the messages posted on their walls. This is achieved through a flexible rule-based system, that allows users to customize the filtering criteria to be applied to their walls, and a Machine Learning-based soft classifier automatically labeling messages in support of content-based filtering. Marco Vanetti, Elisabetta Binaghi, Elena Ferrari 0001, Barbara Carminati, Moreno Carullo |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2012 | Privacy in Social Networks: How Risky is Your Social Graph?abstractSeveral efforts have been made for more privacy aware Online Social Networks (OSNs) to protect personal data against various privacy threats. However, despite the relevance of these proposals, we believe there is still the lack of a conceptual model on top of which privacy tools have to be designed. Central to this model should be the concept of risk. Therefore, in this paper, we propose a risk measure for OSNs. The aim is to associate a risk level with social network users in order to provide other users with a measure of how much it might be risky, in terms of disclosure of private information, to have interactions with them. We compute risk levels based on similarity and benefit measures, by also taking into account the user risk attitudes. In particular, we adopt an active learning approach for risk estimation, where user risk attitude is learned from few required user interactions. The risk estimation process discussed in this paper has been developed into a Facebook application and tested on real data. The experiments show the effectiveness of our proposal. Cuneyt Gurcan Akcora, Barbara Carminati, Elena Ferrari 0001 |
ICDE | 3 |
| 2012 | Trust and Share: Trusted Information Sharing in Online Social NetworksabstractAt the beginning of Web 2.0 era, Online Social Networks (OSNs) appeared as just another phenomenon among wikis, blogs, video sharing, and so on. However, they soon became one of the biggest revolution of the Internet era. Statistics confirm the continuing rise in the importance of social networking sites in terms of number of users (e.g., Facebook reaches 750 millions users, Twitter 200 millions, LinkedIn 100 millions), time spent in social networking sites, and amount of data flowing (e.g., Facebook users interact with about 900 million piece of data in terms of pages, groups, events and community pages). This successful trend lets OSNs to be one of the most promising paradigms for information sharing on the Web. Barbara Carminati, Elena Ferrari 0001, Jacopo Girardi |
ICDE | 2 |
| 2012 | Risks of Friendships on Social NetworksabstractIn this paper, we explore the risks of friends in social networks caused by their friendship patterns, by using real life social network data and starting from a previously defined risk model. Particularly, we observe that risks of friendships can be mined by analyzing users' attitude towards friends of friends. This allows us to give new insights into friendship and risk dynamics on social networks. Cuneyt Gurcan Akcora, Barbara Carminati, Elena Ferrari 0001 |
ICDM | 3 |
| 2012 | A multi-layer framework for personalized social tag-based applications
Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
Data Knowl. Eng. | 2 |
| 2012 | Guest Editors' Introduction: Special Section on Data and Applications Security and PrivacyabstractThe four papers in this special section focus on the latest advancements in data and application systems in the information security and privacy industry. Elena Ferrari 0001, Bhavani Thuraisingham |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | A probability-based approach to modeling the risk of unauthorized propagation of information in on-line social networksabstractThe unauthorized propagation of information is an important problem in the Internet, especially because of the increasing popularity of On-line Social Networks. To address this issue, many access control mechanisms have been proposed so far, but there is still a lack of techniques to evaluate the risk of unauthorized flow of information within social networks. This paper introduces a probability-based approach to modeling the likelihood that information propagates from one social network user to users who are not authorized to access it. The approach is demonstrated via an example, to show how it can be applied in practical cases. Barbara Carminati, Elena Ferrari 0001, Sandro Morasca, Davide Taibi 0001 |
CODASPY | 2 |
| 2011 | Collaborative access control in on-line social networksabstractTopology-based access control is today a de-facto standard for protecting resources in On-line Social Networks (OSNs) both within the research community and commercial OSNs. According to this paradigm, authorization constraints specify the relationships (and possibly their depth and trust level) tha Barbara Carminati, Elena Ferrari 0001 |
CollaborateCom | 2 |
| 2011 | P3D - Privacy-Preserving Path Discovery in Decentralized Online Social NetworksabstractOne of the key service of social networks is path discovery, in that release of a resource or delivering of a service is usually constrained by the existence of a path with given characteristics in the social network graph. One fundamental issue is that path discovery should preserve relationship privacy. In this paper, we address this issue by proposing a Privacy-Preserving Path Discovery protocol, called P3D. Relevant features of P3D are that: (1) it computes only aggregate information on the discovered paths, whereas details on single relationships are not revealed to anyone, (2) it is designed for a decentralized social network. Moreover, P3D is designed such to reduce the drawbacks that offline nodes may create to path discovery. In the paper, besides giving the details of the protocol, we provide an extensive performance study. We also present the security analysis of P3D, showing its robustness against the main security threats. Mingqiang Xue, Barbara Carminati, Elena Ferrari 0001 |
COMPSAC | 3 |
| 2011 | Semantic web-based social network access control
Barbara Carminati, Elena Ferrari 0001, Raymond Heatherly, Murat Kantarcioglu, Bhavani Thuraisingham |
Comput. Secur. | 2 |
| 2011 | CASTLE: Continuously Anonymizing Data StreamsabstractMost of the existing privacy-preserving techniques, such as k-anonymity methods, are designed for static data sets. As such, they cannot be applied to streaming data which are continuous, transient, and usually unbounded. Moreover, in streaming applications, there is a need to offer strong guarantees on the maximum allowed delay between incoming data and the corresponding anonymized output. To cope with these requirements, in this paper, we present Continuously Anonymizing STreaming data via adaptive cLustEring (CASTLE), a cluster-based scheme that anonymizes data streams on-the-fly and, at the same time, ensures the freshness of the anonymized data by satisfying specified delay constraints. We further show how CASTLE can be easily extended to handle ℓ-diversity. Our extensive performance study shows that CASTLE is efficient and effective w.r.t. the quality of the output data. Jianneng Cao, Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2010 | Combining access control and trust negotiations in an On-line Social NetworkabstractProtection of On-line Social Networks (OSNs) resources has become a primary need since today OSNs are the hugest repository of personal information on the Web. This has resulted in the definition of some access control models tailored to the protection of OSN resources. One of the key parameter on w Stefano Braghin, Elena Ferrari 0001, Alberto Trombetta |
CollaborateCom | 2 |
| 2010 | A framework to enforce access control over data streamsabstractAlthough access control is currently a key component of any computational system, it is only recently that mechanisms to guard against unauthorized access to streaming data have started to be investigated. To cope with this lack, in this article, we propose a general framework to protect streaming data, which is, as much as possible, independent from the target stream engine. Differently from RDBMSs, up to now a standard query language for data streams has not yet emerged and this makes the development of a general solution to access control enforcement more difficult. The framework we propose in this article is based on an expressive role-based access control model proposed by us. It exploits a query rewriting mechanism, which rewrites user queries in such a way that they do not return tuples/attributes that should not be accessed according to the specified access control policies. Furthermore, the framework contains a deployment module able to translate the rewritten query in such a way that it can be executed by different stream engines, therefore, overcoming the lack of standardization. In the article, besides presenting all the components of our framework, we prove the correctness and completeness of the query rewriting algorithm, and we present some experiments that show the feasibility of the developed techniques. Barbara Carminati, Elena Ferrari 0001, Jianneng Cao, Kian-Lee Tan |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2010 | A General Framework for Web Content Filtering
Elisa Bertino, Elena Ferrari 0001, Andrea Perego |
World Wide Web | 2 |
| 2009 | Compatibility-driven and adaptable service compositionabstractServices participating in the composition are usually co-ordinated according to a workflow, composed by several activities, each of which carried out by a service. The binding of services to workflow activities may be affected by several parameters (e.g., QoS, price, reputation, etc.). In this paper, we propose a service binding driven by a further important requirement, that is, the incompatibilities among services participating into the composition. To achieve a compatibility-driven composition we propose a solution where services assignment is configured directly by the engine coordinating the composite service. Moreover, the composition is generated such to implement a failure recovery strategy, that is, in case of some service failure the engine dynamically replaces the unavailable service. Barbara Carminati, Chihung Chi, Elena Ferrari 0001, Lianghuan Yu |
APSCC | 3 |
| 2009 | Database as a Service: Challenges and solutions for privacy and securityabstractThis paper analyzes the most relevant privacy and security breaches that may arise in the Database as a Service model. Then, it reviews the state of the art in view of the identified privacy and security requirements. The analysis of the state of the art shows that many open problems still remain to be solved. Elena Ferrari 0001 |
APSCC | 1 |
| 2009 | Enforcing relationships privacy through collaborative access control in web-based Social NetworksabstractWeb-based social networks (WBSNs) are today one of the hugest data source available on the Web and therefore data protection has become an urgent need. This has resulted in the proposals of some access control models for social networks. Quite all the models proposed so far enforce a relationship-ba Barbara Carminati, Elena Ferrari 0001 |
CollaborateCom | 2 |
| 2009 | The Quality Social Network: A collaborative environment for personalizing Web accessabstractIn this paper, we present a collaborative social networking environment, referred to as quality social network (QSN), which enhances the social tagging paradigm by using it as a basis to evaluate the quality of Web resources, on the basis of the user preferences specified by each QSN member. Such fe Andrea Perego, Barbara Carminati, Elena Ferrari 0001 |
CollaborateCom | 3 |
| 2009 | ACStream: Enforcing Access Control over Data StreamsabstractIn this demo proposal, we illustrate ACStream, a system built on top of Stream Base, to specify and enforce access control policies over data streams. ACStream supports a very flexible role-based access control model specifically designed to protect against unauthorized access to streaming data. The core component of ACStream is a query rewriting mechanism that, by exploiting a set of secure operators proposed by us in, rewrites a user query in such a way that it does not violate the specified access control policies during its execution. The demo will show how policies modelling a variety of access control requirements can be easily specified and enforced using ACStream. Jianneng Cao, Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
ICDE | 3 |
| 2009 | A semantic web based framework for social network access controlabstractThe existence of on-line social networks that include person specific information creates interesting opportunities for various applications ranging from marketing to community organization. On the other hand, security and privacy concerns need to be addressed for creating such applications. Improving social network access control systems appears as the first step toward addressing the existing security and privacy concerns related to on-line social networks. To address some of the current limitations, we propose an extensible fine grained access control model based on semantic web tools. In addition, we propose authorization, admin and filtering policies that depend on trust relationships among various users, and are modeled using OWL and SWRL. Besides describing the model, we present the architecture of the framework in its support. Barbara Carminati, Elena Ferrari 0001, Raymond Heatherly, Murat Kantarcioglu, Bhavani Thuraisingham |
SACMAT | 2 |
| 2009 | Enforcing access control in Web-based social networksabstractIn this article, we propose an access control mechanism for Web-based social networks, which adopts a rule-based approach for specifying access policies on the resources owned by network participants, and where authorized users are denoted in terms of the type, depth, and trust level of the relationships existing between nodes in the network. Different from traditional access control systems, our mechanism makes use of a semidecentralized architecture, where access control enforcement is carried out client-side. Access to a resource is granted when the requestor is able to demonstrate being authorized to do that by providing a proof. In the article, besides illustrating the main notions on which our access control model relies, we present all the protocols underlying our system and a performance study of the implemented prototype. Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2008 | Combining Social Networks and Semantic Web Technologies for Personalizing Web Access
Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
CollaborateCom | 2 |
| 2008 | Privacy-Aware Collaborative Access Control in Web-Based Social Networks
Barbara Carminati, Elena Ferrari 0001 |
DBSec | 2 |
| 2008 | CASTLE: A delay-constrained scheme for ks-anonymizing data streamsabstractMost of existing privacy preserving techniques, such as k-anonymity methods, are designed for static data sets. As such, they cannot be applied to streaming data which are continuous, transient and usually unbounded. Moreover, in streaming applications, there is a need to offer strong guarantees on the maximum allowed delay between an incoming data and its anonymized output. To cope with these requirements, in this paper, we present CASTLE (Continuously Anonymizing STreaming data via adaptive cLustEring), a cluster-based scheme that anonymizes data streams on-the-fly and, at the same time, ensures the freshness of the anonymized data by satisfying specified delay constraints. We further show how CASTLE can be easily extended to handle l-diversity [1]. Our extensive performance study shows that CASTLE is efficient and effective. Jianneng Cao, Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
ICDE | 3 |
| 2008 | A Decentralized Security Framework for Web-Based Social NetworksabstractThe wide diffusion and usage of social networking Web sites in the last years have made publicly available a huge amount of possible sensitive information, which can be used by third-parties with purposes different from the ones of the owners of such information. Currently, this issue has been addressed by enforcing into Web-based Social Networks (WBSNs) very simple protection mechanisms, or by using anonymization techniques, thanks to which it is possible to hide the identity of WBSN members while performing analysis on social network data. However, we believe that further solutions are needed, to allow WBSN members themselves to decide who can access their personal information and resources. To cope with this issue, in this article we illustrate a decentralized security framework for WBSNs, which provide both access control and privacy protection mechanisms. In our system, WBSN members can denote who is authorized to access the resources they publish and the relationships they participate in, in terms of the type, depth, and trust level of the relationships existing between members of a WBSN. Cryptographic techniques are then used to provide a controlled sharing of resources while preserving relationship privacy. Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
Int. J. Inf. Secur. Priv. | 2 |
| 2007 | Specifying Access Control Policies on Data Streams
Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
DASFAA | 2 |
| 2007 | Towards Secure Execution Orders for CompositeWeb ServicesabstractRecently, there has been a growing interest in web service composition and the related security issues. In this paper, we propose a framework for the decentralized execution of composite web services capable to ensure the correctness as well as the security of the execution. Our framework relies on a data structure, called container, which is passed among the web services participating in the composition. The container is encrypted and authenticated in such a way to ensure the correctness of the execution flow as well as a set of relevant security requirements. Joachim Biskup, Barbara Carminati, Elena Ferrari 0001, Sandra Wortmann |
ICWS | 3 |
| 2007 | Enforcing access control over data streamsabstractAccess control is an important component of any computational system. However, it is only recently that mechanisms to guard against unauthorized access for streaming data have been proposed. In this paper, we study how to enforce the role-based access control model proposed by us in [5]. We design a set of novel secure operators, that basically filter out tuples/attributes from results of the corresponding (non-secure) operators that are not accessible according to the specified access control policies. We further develop an access control mechanism to enforce the access control policies based on these operators. We show that our method is secure according to the specified policies. Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
SACMAT | 2 |
| 2007 | PP-trust-X: A system for privacy preserving trust negotiationsabstractTrust negotiation is a promising approach for establishing trust in open systems, in which sensitive interactions may often occur between entities with no prior knowledge of each other. Although, to date several trust negotiation systems have been proposed, none of them fully address the problem of privacy preservation. Today, privacy is one of the major concerns of users when exchanging information through the Web and thus we believe that trust negotiation systems must effectively address privacy issues in order to be widely applicable. For these reasons, in this paper, we investigate privacy in the context of trust negotiations. We propose a set of privacy-preserving features for inclusion in any trust negotiation system, such as the support for the P3P standard, as well as a number of innovative features, such as a novel format for encoding digital credentials specifically designed for preserving privacy. Further, we present a variety of interoperable strategies to carry on the negotiation with the aim of improving both privacy and efficiency. Anna Cinzia Squicciarini, Elisa Bertino, Elena Ferrari 0001, Federica Paci, Bhavani Thuraisingham |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2006 | Security Conscious Web Service CompositionabstractA Web service is a software system designed to support interoperable application-to-application interactions over the Internet. Web services are based on a set of XML standards, such as Web Services Description Language (WSDL), Simple Object Access Protocol (SOAP) and Universal Description, Discovery and Integration (UDDI). Recently, there has been a growing interest in Web service composition, and some languages (e.g., WSBPEL, BPML) for modeling the composition have been proposed. In this paper, we focus on security constraints of Web service composition, which have not been deeply investigated so far. We propose a method for modeling security constraints and a brokered architecture to build composite Web services according to the specified security constraints. Barbara Carminati, Elena Ferrari 0001, Patrick C. K. Hung |
ICWS | 2 |
| 2006 | Achieving Privacy in Trust Negotiations with an Ontology-Based ApproachabstractThe increasing use of Internet in a variety of distributed multiparty interactions and transactions with strong real-time requirements has pushed the search for solutions to the problem of attribute-based digital interactions. A promising solution today is represented by automated trust negotiation systems. Trust negotiation systems allow subjects in different security domains to securely exchange protected resources and services. These trust negotiation systems, however, by their nature, may represent a threat to privacy in that credentials, exchanged during negotiations, often contain sensitive personal information that may need to be selectively released. In this paper, we address the problem of preserving privacy in trust negotiations. We introduce the notion of privacy preserving disclosure, that is, a set that does not include attributes or credentials, or combinations of these, that may compromise privacy. To obtain privacy preserving disclosure sets, we propose two techniques based on the notions of substitution and generalization. We argue that formulating the trust negotiation requirements in terms of disclosure policies is often restrictive. To solve this problem, we show how trust negotiation requirements can be expressed as property-based policies that list the properties needed to obtain a given resource. To better address this issue, we introduce the notion of reference ontology, and formalize the notion of trust requirement. Additionally, we develop an approach to derive disclosure policies from trust requirements and formally state some semantics relationships (i.e., equivalence, stronger than) that may hold between policies. These relationships can be used by a credential requestor to reason about which disclosure policies he/she should use in a trust negotiation. Anna Cinzia Squicciarini, Elisa Bertino, Elena Ferrari 0001, Indrakshi Ray |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2006 | Controlled and cooperative updates of XML documents in byzantine and failure-prone distributed systemsabstractThis paper proposes an infrastructure and related algorithms for the controlled and cooperative updates of XML documents. Key components of the proposed system are a set of XML-based languages for specifying access-control policies and the path that the document must follow during its update. Such path can be fully specified before the update process begins or can be dynamically modified by properly authorized subjects while being transmitted. Our approach is fully distributed in that each party involved in the process can verify the correctness of the operations performed until that point on the document without relying on a central authority. More importantly, the recovery procedure also does not need the participation of a central authority. Our approach is based on the use of some special control information that is transmitted together with the document and a suite of protocols. We formally specify the structure of such control information and the protocols. We also analyze security and complexity of the proposed protocols. Giovanni Mella, Elena Ferrari 0001, Elisa Bertino, Yunhua Koglin |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2006 | Guest editorial: special issue on privacy preserving data management
Elena Ferrari 0001, Bhavani Thuraisingham |
VLDB J. | 1 |
| 2005 | Securing XML data in third-party distribution systemsabstractWeb-based third-party architectures for data publishing are today receiving growing attention, due to their scalability and the ability to efficiently manage large numbers of users and great amounts of data. A third-party architecture relies on a distinction between the Owner and the Publisher of information. The Owner is the producer of information, whereas Publisher provides data management services and query processing functions for (a portion of) the Owner's information. In such architecture, there are important security concerns especially if we do not want to make any assumption on the trustworthy of the Publishers. Although approaches have been proposed [4, 5] providing partial solutions to this problem, no comprehensive framework has been so far developed able to support all the most important security properties in the presence of an untrusted Publisher. In this paper, we develop an XML-based solution to such problem, which makes use of non-conventional digital signature techniques and queries over encrypted data. Barbara Carminati, Elena Ferrari 0001, Elisa Bertino |
CIKM | 2 |
| 2005 | An Update Protocol for XML Documents in Distributed and Cooperative SystemsabstractSecuring data is becoming a crucial need for most Internet-based applications. Whereas the problem of data confidentiality has been widely investigated, the problem of how to ensure that data, when moving among different parties, are modified only according to the stated policies has been so far not deeply investigated. In this paper, the authors proposed an approach supporting parallel and distributed secure updates to XML documents. The approach, based on the use of a security region-object parallel flow (S-RPF) graph protocol, is particularly suited for all environments requiring cooperative updates to XML documents. It allows different users to simultaneously update different portions of the same document, according to the specified access control policies. Additionally, it supports a decentralized management of update operations in that a subject can exercise its privileges and verify the correctness of the operations performed so far on the document without interacting, in most of the cases, with the document server Yunhua Koglin, Giovanni Mella, Elisa Bertino, Elena Ferrari 0001 |
ICDCS | 4 |
| 2005 | Assuring Security Properties in Third-party ArchitecturesabstractWeb-based third-party architectures for data publishing are today receiving growing attention, due to their scalability and the ability of efficiently managing large numbers of users and great amounts of data. In such architecture security is a primary challenge. Main security properties that should be considered are: confidentiality, integrity, and authenticity. Additionally to these traditional security requirements, we are interested in a further security property, that is, completeness. By completeness we mean that the user receiving a portion of data can verify whether he/she has received all the information is allowed to see according to the specified access control policies. In this paper, we propose a comprehensive framework for a secure third party distribution of XML data. In particular, the framework is able to enforce all the above-mentioned properties, by exploiting encryption and non-conventional signature techniques. Barbara Carminati, Elena Ferrari 0001, Elisa Bertino |
ICDE | 2 |
| 2005 | A Constraint-Based Approach for the Authoring of Multi-Topic Multimedia PresentationsabstractSynchronized multimedia applications play an important role in a Digital Library environment, since they allow one to efficiently disseminate knowledge among differently skilled users through an approach which is more direct than the classic ‘ static’ documents. In this paper, we propose a new authoring approach based on an innovative presentation structure and a new class of content based constraints. Thanks to a flexible heuristic process, such fea tures allow the author to easily combine several multimedia objects into a multi-topic presentation, whose different contents can be freely chosen by end users according to their preferences or skills. Elisa Bertino, Elena Ferrari 0001, Andrea Perego, Diego Santi |
ICME | 2 |
| 2005 | An Integrated Approach to Rating and Filtering Web Content
Elisa Bertino, Elena Ferrari 0001, Andrea Perego, Gian Piero Zarri |
IEA/AIE | 2 |
| 2005 | AC-XML documents: improving the performance of a web access control moduleabstractProtecting information over the Web is today becoming a primary need. Although many access control models have been so far proposed to address the specific protection requirements of the web environment, no comparable amount of work has been done for finding efficient techniques for performing access control. We believe that the availability of techniques for speeding-up access control is a key issue to make an access control model widely acceptable. This is particularly crucial in an environment such as the web, characterized by thousands of users and thousands of documents. For these reasons, in this paper we propose a technique for speeding-up access control, which can be applied to credential-based access control models. We propose a data structure that keeps track of the policies that apply to the various portions of a data source, and which does not require the scanning of the policy base for performing access control. In the paper, besides giving the algorithms for building such data structure and for performing access control, we present a complexity analysis of the proposed approach, which demonstrates the benefits with traditional methods. Barbara Carminati, Elena Ferrari 0001 |
SACMAT | 2 |
| 2005 | An approach to cooperative updates of XML documents in distributed systemsabstractProtection and secure exchange of Web documents is becoming a crucial need for many Internet-based applications. Securing Web documents entail addressing two main issues: confidentiality and integrity. Ensuring document confidentiality means that document contents can only be disclosed to subjects authorized according to specified security policies, whereas by document integrity we mean that the document contents are correct with respect to a given application domain and that the document contents are modified only by authorized subjects. While the problem of document confidentiality has been widely investigated in the literature, the problem of how to ensure that a document, when moving among different parties, is modified only according to the stated policies still lacks comprehensive solutions. In this paper we present a solution to this problem by proposing a model for specifying update policies, and an infrastructure supporting the specification and enforcement of these policies in a distributed and cooperative environment, in which subjects in different organizational roles can modify possibly different portions of the same document. The key aspect of our proposal is that, by using a combination of hash functions and digital signature techniques, we create a distributed environment that enables subjects, in most cases, to verify, upon receiving a document, whether the update operations performed on the document up to that point are correct with respect to the update policies, without interacting with the document server. Our approach is particularly suited for environments, such as mobile systems, pervasive systems, decentralized workflows, and peer-to-peer systems. Elisa Bertino, Elena Ferrari 0001, Giovanni Mella |
J. Comput. Secur. | 2 |
| 2005 | Guest editorial: Special issue on access control models and technologiesabstractNo abstract available. Elena Ferrari 0001 |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2004 | Security and Privacy for Web Databases and Services
Elena Ferrari 0001, Bhavani Thuraisingham |
EDBT | 1 |
| 2004 | Towards Standardized Web Services Privacy TechnologiesabstractA Web service is defined as an autonomous unit of application logic that provides either some business functionality or information to other applications through an Internet connection. Web services are based on a set of XML standards such as universal description, discovery and integration (UDDI), Web services description language (WSDL), and simple object access protocol (SOAP). Recently there are increasing demands and discussions about Web services privacy technologies in the industry and research community. In general, privacy policies describe an organization's data practices what information they collect from individuals (e.g., consumers) and what (e.g., purposes) they do with it. To enable privacy protection for Web service consumers across multiple domains and services, the World Wide Web Consortium (W3C) published a document called "Web services architecture (WSA) requirements" that defines some specific privacy requirements for Web services as a future research topic. At this moment, there is still no standardized Web services privacy technology. This paper briefly overviews the research issues of Web services privacy technologies. Patrick C. K. Hung, Elena Ferrari 0001, Barbara Carminati |
ICWS | 2 |
| 2004 | Flow policies: specification and enforcementabstractThis paper deals with the problem of secure cooperative updates for XML documents in distributed systems. In particular, we introduce the basic notions underlying a flow language by using which a user can specify the flow that a given XML document has to follow within a group of cooperating subjects. A key feature of the flow language is to be based on the notion of subject credentials. In addition, we describe a policy language to specify special-purpose authorizations allowing selected subjects to modify or extend a given document flow. Finally, we briefly describe the protocols for verifying that the path followed by a document in a collaborative group agrees with the specified flow and to verify that modifications on a given flow are in accordance with the specified authorizations. Elisa Bertino, Elena Ferrari 0001, Giovanni Mella |
IPCCC | 2 |
| 2004 | An XML-Based Approach to Document Flow Verification
Elisa Bertino, Elena Ferrari 0001, Giovanni Mella |
ISC | 2 |
| 2004 | Access control for XML documents and data
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
Inf. Secur. Tech. Rep. | 3 |
| 2004 | Selective and Authentic Third-Party Distribution of XML DocumentsabstractThird-party architectures for data publishing over the Internet today are receiving growing attention, due to their scalability properties and to the ability of efficiently managing large number of subjects and great amount of data. In a third-party architecture, there is a distinction between the Owner and the Publisher of information. The Owner is the producer of information, whereas Publishers are responsible for managing (a portion of) the Owner information and for answering subject queries. A relevant issue in this architecture is how the Owner can ensure a secure and selective publishing of its data, even if the data are managed by a third-party, which can prune some of the nodes of the original document on the basis of subject queries and access control policies. An approach can be that of requiring the Publisher to be trusted with regard to the considered security properties. However, the serious drawback of this solution is that large Web-based systems cannot be easily verified to be secure and can be easily penetrated. For these reasons, we propose an alternative approach, based on the use of digital signature techniques, which does not require the Publisher to be trusted. The security properties we consider are authenticity and completeness of a query response, where completeness is intended with regard to the access control policies stated by the information Owner. In particular, we show that, by embedding in the query response one digital signature generated by the Owner and some hash values, a subject is able to locally verify the authenticity of a query response. Moreover, we present an approach that, for a wide range of queries, allows a subject to verify the completeness of query results. Elisa Bertino, Barbara Carminati, Elena Ferrari 0001, Bhavani Thuraisingham, Amar Gupta |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2004 | Trust-X: A Peer-to-Peer Framework for Trust EstablishmentabstractWe present Trust-/spl Xscr/;, a comprehensive XML-based framework for trust negotiations, specifically conceived for a peer-to-peer environment. Trust negotiation is a promising approach for establishing trust in open systems like the Internet, where sensitive interactions may often occur between entities at first contact, with no prior knowledge of each other. The framework we propose takes into account all aspects related to negotiations, from the specification of the profiles and policies of the involved parties to the selection of the best strategy to succeed in the negotiation. Trust-/spl Xscr/; presents a number of innovative features, such as the support for protection of sensitive policies, the use of trust tickets to speed up the negotiation, and the support of different strategies to carry on a negotiation. In this paper, besides presenting the language to encode security information, we present the system architecture and algorithms according to which negotiations take place. Elisa Bertino, Elena Ferrari 0001, Anna Cinzia Squicciarini |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2003 | Supporting Delegation in Secure Workflow Management Systems
Vijayalakshmi Atluri, Elisa Bertino, Elena Ferrari 0001, Pietro Mazzoleni |
DBSec | 3 |
| 2003 | A Decentralized Approach for Controlled Sharing of Resources in Virtual Communities
Elisa Bertino, Elena Ferrari 0001, Anna Cinzia Squicciarini |
DBSec | 2 |
| 2003 | Signature and Access Control Policies for XML Documents
Elisa Bertino, Elena Ferrari 0001, Loredana Parasiliti Provenza |
ESORICS | 2 |
| 2003 | A Flexible Authentication Method for UDDI Registries
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
ICWS | 3 |
| 2003 | An infrastructure for managing secure update operations on XML dataabstractSecure exchange of data over the web is becoming more and more important today. By secure data exchange we mean that privacy and integrity are ensured when documents flow among different parties. A key issue in this scenario is how to ensure that web documents, when moving among different parties, are modified only according to the stated access control policies. To cope with such an issue, in this paper we propose a distributed infrastructure that enable subjects to verify, upon receiving a document, whether the update operations performed on the document till that point are correct with respect to the stated access control policies, without interacting, in most cases, with the document server. Elisa Bertino, Giovanni Mella, Gianluca Correndo, Elena Ferrari 0001 |
SACMAT | 4 |
| 2003 | ViRdB: integrating virtual reality and multimedia databases for customized visualization of cultural heritageabstractNo abstract available. Pietro Mazzoleni, Elisa Bertino, Stefano Valtolina, Elena Ferrari 0001, Chiara Boeri |
SIGGRAPH | 4 |
| 2003 | T-ODMG: an ODMG compliant temporal object model supporting multiple granularity management
Elisa Bertino, Elena Ferrari 0001, Giovanna Guerrini, Isabella Merlo |
Inf. Syst. | 2 |
| 2003 | A logical framework for reasoning about access control modelsabstractThe increased awareness of the importance of data protection has made access control a relevant component of current data management systems. Moreover, emerging applications and data models call for flexible and expressive access control models. This has led to an extensive research activity that has resulted in the definition of a variety of access control models that differ greatly with respect to the access control policies they support. Thus, the need arises for developing tools for reasoning about the characteristics of these models. These tools should support users in the tasks of model specification, analysis of model properties, and authorization management. For example, they must be able to identify inconsistencies in the model specification and must support the administrator in comparing the expressive power of different models. In this paper, we make a first step in this direction by proposing a formal framework for reasoning about access control models. The framework we propose is based on a logical formalism and is general enough to model discretionary, mandatory, and role-based access control models. Each instance of the proposed framework corresponds to a C-Datalog program, interpreted according to a stable model semantics. In the paper, besides giving the syntax and the formal semantics of our framework, we show some examples of its application. Additionally, we present a number of dimensions along which access control models can be analyzed and compared. For each dimension, we show decidability results and we present some examples of its application. Elisa Bertino, Barbara Catania, Elena Ferrari 0001, Paolo Perlasca |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2003 | A hierarchical access control model for video database systemsabstractContent-based video database access control is becoming very important, but it depends on the progresses of the following related research issues: (a) efficient video analysis for supporting semantic visual concept representation; (b) effective video database indexing structure; (c) the development of suitable video database models; and (d) the development of access control models tailored to the characteristics of video data. In this paper, we propose a novel approach to support multilevel access control in video databases. Our access control technique combines a video database indexing mechanism with a hierarchical organization of visual concepts (i.e., video database indexing units), so that different classes of users can access different video elements or even the same video element with different quality levels according to their permissions. These video elements, which, in our access control mechanism, are used for specifying the authorization objects, can be a semantic cluster, a subcluster, a video scene, a video shot, a video frame, or even a salient object (i.e., region of interest). In the paper, we first introduce our techniques for obtaining these multilevel video access units. We also propose a hierarchical video database indexing technique to support our multilevel video access control mechanism. Then, we present an innovative access control model which is able to support flexible multilevel access control to video elements. Moreover, the application of our multilevel video database modeling, representation, and indexing for MPEG-7 is discussed. Elisa Bertino, Jianping Fan 0001, Elena Ferrari 0001, Mohand-Said Hacid, Ahmed K. Elmagarmid, Xingquan Zhu 0001 |
ACM Trans. Inf. Syst. | 3 |
| 2002 | A temporal key management scheme for secure broadcasting of XML documentsabstractSecure broadcasting of web documents is becoming a crucial need for many web-based applications. Under the broadcast document dissemination strategy a web document source periodically broad-casts (portions of) its documents to a possibly large community of subjects, without the need of explicit subject requests. By secure broadcasting we mean that the delivery of information to sub-jects must obey the access control policies of the document source. Since different subjects may have the right to access different portions of the same document, enforcing secure broadcasting requires to efficiently manage a large number of different physical views of the requested document and sending them to the proper subjects. In this paper we present an approach to secure broadcasting of web documents, based on the use of encryption techniques, and supporting the specification of fine-grained temporal access control policies. The idea is to generate a unique encrypted copy of the document to be released, where different portions of the docu-ment are encrypted with different keys, on the basis of the specified access control policies. Each subject then obtains the secret keys corresponding to document portions he/she is authorized to access. The key aspect of our approach is that the number of keys to be generated does not depend on the number of subjects nor on the document dimension, but only on the number of specified access control policies and the associated temporal constraints. Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
CCS | 3 |
| 2002 | Ma X : An Access Control System for Digital Libraries and the WebabstractDigital libraries (DLs) introduce several challenging requirements with respect to the formulation, specification and enforcement of adequate access control policies. Unlike conventional database environments, a DL typically is characterised by a dynamic subject population, often making accesses from remote locations, and by an extraordinarily large amount of information, stored in a variety of formats. Additionally, protecting a DL does not only mean protecting documents that reside at the DL site, but also protecting accesses that the DL subscribers made to external Web documents. We present MaX, a comprehensive system for enforcing access control, specifically tailored to both DL and Web environments. Key features of MaX are the support for credential and content-based access control to DL and Web documents, and its full integration with standard Internet rating systems. Elisa Bertino, Elena Ferrari 0001, Andrea Perego |
COMPSAC | 2 |
| 2002 | Web and Information Security: Workshop Summary
Bhavani Thuraisingham, Elena Ferrari 0001 |
COMPSAC | 2 |
| 2002 | Distributed Cooperative Updates of XML Documents
Elisa Bertino, Elena Ferrari 0001, Giovanni Mella |
DBSec | 2 |
| 2002 | Protection and administration of XML data sources
Elisa Bertino, Silvana Castano, Elena Ferrari 0001, Marco Mesiti |
Data Knowl. Eng. | 3 |
| 2002 | Secure and selective dissemination of XML documentsabstractXML ( eXtensible Markup Language ) has emerged as a prevalent standard for document representation and exchange on the Web. It is often the case that XML documents contain information of different sensitivity degrees that must be selectively shared by (possibly large) user communities. There is thus the need for models and mechanisms enabling the specification and enforcement of access control policies for XML documents. Mechanisms are also required enabling a secure and selective dissemination of documents to users, according to the authorizations that these users have. In this article, we make several contributions to the problem of secure and selective dissemination of XML documents. First, we define a formal model of access control policies for XML documents. Policies that can be defined in our model take into account both user profiles, and document contents and structures. We also propose an approach, based on an extension of the Cryptolope™ approach [Gladney and Lotspiech 1997], which essentially allows one to send the same document to all users, and yet to enforce the stated access control policies. Our approach consists of encrypting different portions of the same document according to different encryption keys, and selectively distributing these keys to the various users according to the access control policies. We show that the number of encryption keys that have to be generated under our approach is minimal and we present an architecture to support document distribution. Elisa Bertino, Elena Ferrari 0001 |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2002 | A Content-Based Authorization Model for Digital LibrariesabstractDigital libraries (DLs) introduce several challenging requirements with respect to the formulation, specification and enforcement of adequate data protection policies. Unlike conventional database environments, a DL environment is typically characterized by a dynamic user population, often making accesses from remote locations, and by an extraordinarily large amount of multimedia information, stored in a variety of formats. Moreover, in a DL environment, access policies are often specified based on user qualifications and characteristics, rather than on user identity (e.g. a user can be given access to an R-rated video only if he/ she is more than 18 years old). Another crucial requirement is the support for content-dependent authorizations on digital library objects (e.g. all documents containing discussions on how to operate guns must be made available only to users who are 18 or older). Since traditional authorization models do not adequately meet the access control requirements typical of DLs, we propose a content-based authorization model that is suitable for a DL environment. Specifically, the most innovative features of our authorization model are: (1) flexible specification of authorizations based on the qualifications and (positive and negative) characteristics of users, (2) both content-dependent and content-independent access control to digital library objects, and (3) the varying granularity of authorization objects ranging from sets of library objects to specific portions of objects. Nabil R. Adam, Vijayalakshmi Atluri, Elisa Bertino, Elena Ferrari 0001 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2002 | An authorization system for digital libraries
Elena Ferrari 0001, Nabil R. Adam, Vijayalakshmi Atluri, Elisa Bertino, Ugo Capuozzo |
VLDB J. | 1 |
| 2001 | A Secure Publishing Service for Digital Libraries of XML Documents
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
ISC | 3 |
| 2001 | On specifying security policies for web documents with an XML-based languageabstractThe rapid growth of the Web and the ease with which data can be accessed facilitate the distribution and sharing of information. Information dissemination often takes the form of documents that are made available at Web servers, or that are actively broadcasted by Web servers to interested clients. In this paper, we present an XML-compliant formalism for specifying security-related information for Web document protection. In particular, we introduceX-Sec, an XML-based language for specifying subject credentials and security policies and for organizing them into subject profiles and policy bases, respectively. The language is complemented by a set of subscription-based schemes for accessing distributed Web documents, which rely on defined XML subject profiles and XML policy bases. Elisa Bertino, Silvana Castano, Elena Ferrari 0001 |
SACMAT | 3 |
| 2001 | A logical framework for reasoning about access control modelsabstractThe increased availability of tools and technologies to access and use the data has made more urgent the needs for data protection. Moreover, emerging applications and data models call for more flexible and expressive access control models. This has lead to an extensive research activity that has resulted in the definition of a variety of access control models, that greatly differ with respect to the access control policies they can support. The need thus arises of developing some sort of tools that make it possible to reason about the expressive power of such models and to make a comparison among the various proposals. In this paper we make a first step in this direction by proposing a formal framework for reasoning about access control models. The framework we propose is based on a logical formalism and is general enough to model both discretionary and mandatory access control policies. Each instance of the proposed framework corresponds to a C-Datalog program [8], interpreted according to a stable model semantics. In the paper, besides giving the syntax and the formal semantic of our framework, we show some examples of its application. Elisa Bertino, Barbara Catania, Elena Ferrari 0001, Paolo Perlasca |
SACMAT | 3 |
| 2001 | Securing XML Documents: the Author-X Project DemonstrationabstractNo abstract available. Elisa Bertino, Silvana Castano, Elena Ferrari 0001 |
SIGMOD Conference | 3 |
| 2001 | Navigating Through Multiple Temporal Granularity ObjectsabstractManaging and relating temporal information at different time units is an important issue in many applications and research areas, among them temporal object-oriented databases. Due to the semantic richness of the object-oriented data model, the introduction of multiple temporal granularities in such a model poses several interesting issues. In particular, object-oriented query languages provide a navigational approach to data access, performed via path expressions. We present an extension to path expressions to a multi-granularity context. The syntax and semantics of the proposed path expressions are formally defined. Elisa Bertino, Elena Ferrari 0001, Giovanna Guerrini, Isabella Merlo |
TIME | 2 |
| 2001 | Special Issue: Object-oriented Databases
Giovanna Guerrini, Isabella Merlo, Elena Ferrari 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2001 | Role Based Access Control Models
Carlo Bellettini, Elisa Bertino, Elena Ferrari 0001 |
Inf. Secur. Tech. Rep. | 3 |
| 2001 | XML security
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
Inf. Secur. Tech. Rep. | 3 |
| 2001 | TRBAC: A temporal role-based access control modelabstractRole-based access control (RBAC) models are receiving increasing attention as a generalized approach to access control. Roles may be available to users at certain time periods, and unavailable at others. Moreover, there can be temporal dependencies among roles. To tackle such dynamic aspects, we introduce Temporal-RBAC (TRBAC), an extension of the RBAC model. TRBAC supports periodic role enabling and disabling---possibly with individual exceptions for particular users---and temporal dependencies among such actions, expressed by means of role triggers. Role trigger actions may be either immediately executed, or deferred by an explicitly specified amount of time. Enabling and disabling actions may be given a priority, which is used to solve conflicting actions. A formal semantics for the specification language is provided, and a polynomial safeness check is introduced to reject ambiguous or inconsistent specifications. Finally, a system implementing TRBAC on top of a conventional DBMS is presented. Elisa Bertino, Piero A. Bonatti, Elena Ferrari 0001 |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2001 | A nested transaction model for multilevel secure database management systemsabstractThis article presents an approach to concurrency control for transactions in a Multilevel Secure Database Management System (MLS/DBMS). The major problem is that concurrency control mechanisms used in traditional DBMSs are not adequate in a MLS/DBMS, since they may be exploited to establish covert channels. The approach presented in this article, which uses single-version data items, is based on the use of nested transactions, application-level recovery, and notification-based locking protocols. All these features allow us to develop a concurrency control mechanism that is free of timing channels and avoids many of the shortcomings of the concurrency control mechanisms so far developed for conventional (i.e., flat) transactions, such as transaction starvation and resource wastage. Elisa Bertino, Barbara Catania, Elena Ferrari 0001 |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2001 | Correction to 'MPGS: An Interactive Tool for the Specification and Generation of Multimedia Presentations'
Elisa Bertino, Elena Ferrari 0001, Marco Stolf |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2000 | Author-X: A Java-Based System for XML Data Protection
Elisa Bertino, Silvana Castano, Elena Ferrari 0001, Marco Mesiti |
DBSec | 4 |
| 2000 | A Logic-Based Approach for Enforcing Access ControlabstractThis paper describes an advanced authorization mechanism based on a logic formalism. The model supports both positive and negative authorizations. It also supports derivation rules by which an authorization can be granted on the basis of the presence Elisa Bertino, Francesco Buccafurri, Elena Ferrari 0001, Pasquale Rullo |
J. Comput. Secur. | 3 |
| 2000 | Temporal Authorization Bases: From Specification to IntegrationabstractIn this paper we present a powerful authorization mechanism which provides support for: (1) periodic authorizations (both positive and negative), that is, authorizations that hold only in specific periods of time; (2) user-defined deductive temporal rules, by which new authorizations can be derived from those explicitly specified; (3) a hierarchical organization of subjects and objects, supporting a more adequate representation of their semantics. From the authorizations explicitly specified, additional authorizations are automatically derived by the system based on those hierarchies. The resulting model is therefore very flexible in terms of the kinds of protection requirements that it can represent. The flexibility provided to the users requires a non trivial underlying formal model where temporal constraints, derivation rules and object and subject hierarchies can be represented. In particular, when inheritance and derivation rules are used simultaneously, there is need for conditions ensuring that the authorization base is free from ambiguities. In this paper, we introduce a notion of safeness , and prove that it guarantees the absence of ambiguities and inconsistencies in the specification. Moreover, we define an efficient algorithm for computing authorizations from safe specifications. Finally, we provide a methodology for supporting temporal authorizations in heterogeneous, distributed systems. Elisa Bertino, Piero A. Bonatti, Elena Ferrari 0001, Maria Luisa Sapino |
J. Comput. Secur. | 3 |
| 2000 | MPGS: An Interactive Tool for the Specification and Generation of Multimedia PresentationsabstractMultimedia presentations are composed of objects belonging to different data types such as video, audio, text and image. An important aspect is that, quite often, the user defining a presentation needs to express sophisticated temporal and spatial constraints among the objects composing the presentation. We present a system (called MPGS-Multimedia Presentation Generator System) which supports the specification of constraints among multimedia objects and the generation of multimedia presentations according to the specified constraints. The constraint model provided by MPGS is very flexible and powerful in terms of the kinds of object constraints it can represent. A large number of innovative features are supported including: asynchronous and simultaneous spatial constraints; components of interest and priority levels; motion functions. Obviously, the flexibility provided to the users requires the development of nontrivial techniques to check constraint consistency and to generate a presentation satisfying the specified constraints. We illustrate the solutions we have devised in the framework of MPGS. Elisa Bertino, Elena Ferrari 0001, Marco Stolf |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2000 | Specifying and enforcing access control policies for XML document sources
Elisa Bertino, Silvana Castano, Elena Ferrari 0001, Marco Mesiti |
World Wide Web | 3 |
| 1999 | A Logical Framework for Reasoning on Data Access Control PoliciesabstractWe propose a logic formalism that naturally supports the encoding of complex security specifications. This formalism relies on a hierarchically structured domain made of subjects, objects and privileges. Authorizations are expressed by logic rules. The formalism supports both negation by failure (possibly unstratified) and true negation. The latter is used to express negative authorizations. It turns out that conflicts may result from a set of authorization rules. Dealing with such conflicts requires the knowledge of the domain structure, such as grantor priorities and object/subject hierarchies, which is used in the deductive process to determine which authorization prevails, if any, on the others. Often, however, conflicts are unsolvable, as they express intrinsic ambiguities. We have devised two semantics as an extension of the well-founded and the stable model semantics of logic programming. We have also defined a number of access policies, each based on two orthogonal choices: one is related to the way of how we cope with multiplicity of authorization sets in case of stable model semantics; the other is concerned with the open/closed assumption. A comparative analysis of the proposed authorization policies, based on their degree of permissivity shows that they form a complete lattice. Elisa Bertino, Elena Ferrari 0001, Francesco Buccafurri, Pasquale Rullo |
CSFW | 2 |
| 1999 | Specifying and Computing Hierarchies of Temporal Authorizations
Elisa Bertino, Piero A. Bonatti, Elena Ferrari 0001, Maria Luisa Sapino |
DBSec | 3 |
| 1999 | Modeling Spatio-Temporal Constraints for Multimedia Objects
Yong-Moo Kwon, Elena Ferrari 0001, Elisa Bertino |
Data Knowl. Eng. | 2 |
| 1999 | Secure Object Deletion and Garbage Collection in Multilevel Object BasesabstractThis paper introduces guidelines aiming at the prevention of illegal information flows due to object deletion in multilevel secure object database management systems (ODBMSs). Although a delete operation can be viewed as a kind of write operation, th Elisa Bertino, Elena Ferrari 0001 |
J. Comput. Secur. | 2 |
| 1999 | The Specification and Enforcement of Authorization Constraints in Workflow Management SystemsabstractIn recent years, workflow management systems (WFMSs) have gained popularity in both research and commercial sectors. WFMSs are used to coordinate and streamline business processes. Very large WFMSs are often used in organizations with users in the range of several thousands and process instances in the range of tens and thousands. To simplify the complexity of security administration, it is common practice in many businesses to allocate a role for each activity in the process and then assign one or more users to each role—granting an authorization to roles rather than to users. Typically, security policies are expressed as constraints (or rules) on users and roles; separation of duties is a well-known constraint. Unfortunately, current role-based access control models are not adequate to model such constraints. To address this issue we (1) present a language to express both static and dynamic authorization constraints as clauses in a logic program; (2) provide formal notions of constraint consistency; and (3) propose algorithms to check the consistency of constraints and assign users and roles to tasks that constitute the workflow in such a way that no constraints are violated. Elisa Bertino, Elena Ferrari 0001, Vijayalakshmi Atluri |
ACM Trans. Inf. Syst. Secur. | 2 |
| 1998 | Data SecurityabstractMaintaining data quality is an important requirement in any organization. It requires measures for access control, semantic integrity, fault tolerance and recovery. Access control regulates the access to the system by users to ensure that all accesses are authorized according to some specified policies. We briefly survey the state of the art in access control for database systems, discuss the main research issues, and outline possible directions for future research. Elisa Bertino, Elena Ferrari 0001 |
COMPSAC | 2 |
| 1998 | Extending the ODMG Object Model with Time
Elisa Bertino, Elena Ferrari 0001, Giovanna Guerrini, Isabella Merlo |
ECOOP | 2 |
| 1998 | An Authorization Model and Its Formal Semantics
Elisa Bertino, Francesco Buccafurri, Elena Ferrari 0001, Pasquale Rullo |
ESORICS | 3 |
| 1998 | Exception-Based Information Flow Control in Object-Oriented SystemsabstractWe present an approach to control information flow in object-oriented systems. The decision of whether an information flow is permitted or denied depends on both the authorizations specified on the objects and the process by which information is obtained and transmitted. Depending on the specific computations, a process accessing sensitive information could still be allowed to release information to users who are not allowed to directly access it. Exceptions to the permissions and restrictions stated by the authorizations are specified by means of exceptions associated with methods. Two kinds of exceptions are considered: invoke exceptions, applicable during a mehtod execution and reply exceptions applicable to the information returned by a method. Information flowing from one object into another or returned to the user is subject to the different exceptions specified for the methods enforcing the transmission. We formally characterize information transmission and flow in a transaction and define the conditions for safe information flow. We define security specifications and characterize safe information flows. We propose an approach to control unsafe flows and present an algorithm to enforce it. We also illustrate an efficient implementation of our controls and present some experimental results evaluating its performance. Elisa Bertino, Sabrina De Capitani di Vimercati, Elena Ferrari 0001, Pierangela Samarati |
ACM Trans. Inf. Syst. Secur. | 3 |
| 1998 | Temporal Synchronization Models for Multimedia DataabstractMultimedia information systems are considerably more complex than traditional ones in that they deal with very heterogeneous data such as text, video, and audio-characterized by different characteristics and requirements. One of the central characteristics of multimedia data is that of being heavily time-dependent, in that they are usually related by temporal relationships that must be maintained during playout. We discuss problems related to modeling temporal synchronization specifications for multimedia data. We investigate the characteristics that a model must possess to properly express the timing relationships among multimedia data, and we provide a classification for the various models proposed in the literature. For each devised category, several examples are presented, whereas the most representative models of each category are illustrated in detail. Then, the presented models are compared with respect to the devised requirements, and future research issues are discussed. Elisa Bertino, Elena Ferrari 0001 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1998 | Navigational Accesses in a Temporal Object ModelabstractA considerable research effort has been devoted in past years to query languages for temporal data in the context of both the relational and the object oriented model. Object oriented databases provide a navigational approach for data access based on object references. We investigate the navigational approach to querying object oriented databases. We formally define the notion of temporal path expression, and we address on a formal basis issues related to the correctness of such expressions. In particular, we focus on static analysis and give a set of conditions ensuring that an expression always results in a correct access at runtime. Elisa Bertino, Elena Ferrari 0001, Giovanna Guerrini |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1998 | An Access Control Model Supporting Periodicity Constraints and Temporal ReasoningabstractAccess control models, such as the ones supported by commercial DBMSs, are not yet able to fully meet many application needs. An important requirement derives from the temporal dimension that permissions have in many real-world situations. Permissions are often limited in time or may hold only for specific periods of time. In this article, we present an access control model in which periodic temporal intervals are associated with authorizations. An authorization is automatically granted in the specified intervals and revoked when such intervals expire. Deductive temporal rules with periodicity and order constraints are provided to derive new authorizations based on the presence or absence of other authorizations in specific periods of time. We provide a solution to the problem of ensuring the uniqueness of the global set of valid authorizations derivable at each instant, and we propose an algorithm to compute this set. Moreover, we address issues related to the efficiency of access control by adopting a materialization approach. The resulting model provides a high degree of flexibility and supports the specification of several protection requirements that cannot be expressed in traditional access control models. Elisa Bertino, Claudio Bettini, Elena Ferrari 0001, Pierangela Samarati |
ACM Trans. Database Syst. | 3 |
| 1997 | A Principled Approach to Object Deletion and Garbage Collection in a Multi-Level Secure Object Bases
Elisa Bertino, Elena Ferrari 0001 |
DBSec | 2 |
| 1997 | Administration Policies in a Multipolicy Autorization System
Elisa Bertino, Elena Ferrari 0001 |
DBSec | 2 |
| 1997 | Providing flexibility in information flow control for object oriented systemsabstractThis paper presents an approach to control information flow in object-oriented systems that takes into account, besides authorizations on objects, also how the information has been obtained and/or transmitted. These aspects are considered by allowing exceptions to the restrictions stated by the authorizations. Exceptions are specified by means of waivers associated with methods. Two kinds of waivers are supported: invoke-waivers, specifying exceptions applicable during a method's execution, and reply-waivers, specifying exceptions applicable to the information returned by a method. Information flowing from one object into another object is subject to the different waivers of the methods enforcing the transmission. We formally characterize information transmission and flow in a transaction taking into consideration different interaction modes among objects. We then define security specifications, meaning authorizations and waivers, and characterize safe information flows. We formally define conditions whose satisfaction ensures absence of unsafe flows and present an algorithm enforcing these conditions. Elena Ferrari 0001, Pierangela Samarati, Elisa Bertino, Sushil Jajodia |
S&P | 1 |
| 1997 | Decentralized Administration for a Temporal Access Control Model
Elisa Bertino, Claudio Bettini, Elena Ferrari 0001, Pierangela Samarati |
Inf. Syst. | 3 |
| 1996 | A Formal Temporal Object-Oriented Data Model
Elisa Bertino, Elena Ferrari 0001, Giovanna Guerrini |
EDBT | 2 |
| 1996 | A decentralized temporal autoritzation model
Elisa Bertino, Claudio Bettini, Elena Ferrari 0001, Pierangela Samarati |
SEC | 3 |
| 1996 | Supporting Periodic Authorizations and Temporal Reasoning in Database Access Control
Elisa Bertino, Claudio Bettini, Elena Ferrari 0001, Pierangela Samarati |
VLDB | 3 |
| 1996 | A Temporal Access Control Mechanism for Database SystemsabstractThe paper presents a discretionary access control model in which authorizations contain temporal intervals of validity. An authorization is automatically revoked when the associated temporal interval expires. The proposed model provides rules for the automatic derivation of new authorizations from those explicitly specified. Both positive and negative authorizations are supported. A formal definition of those concepts is presented, together with the semantic interpretation of authorizations and derivation rules as clauses of a general logic program. Issues deriving from the presence of negative authorizations are discussed. We also allow negation in rules: it is possible to derive new authorizations on the basis of the absence of other authorizations. The presence of this type of rule may lead to the generation of different sets of authorizations, depending on the evaluation order. An approach is presented, based on establishing an ordering among authorizations and derivation rules, which guarantees a unique set of valid authorizations. Moreover, we give an algorithm detecting whether such an ordering can be established for a given set of authorizations and rules. Administrative operations for adding, removing, or modifying authorizations and derivation rules are presented and efficiency issues related to these operations are also tackled in the paper. A materialization approach is proposed, allowing to efficiently perform access control. Elisa Bertino, Claudio Bettini, Elena Ferrari 0001, Pierangela Samarati |
IEEE Trans. Knowl. Data Eng. | 3 |