Thomas F. Keefe

dblp:39/898 · DBLP profile ↗
← Back
22ranked-venue papers
8as first author
0since 2021 · last 2002
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 4 first-authorSoftware engineering, systems software and programming languages · 4 · 2 first-authorDatabases, data management, data science and information retrieval · 3 · 2 first-authorSystems, architecture and hardware · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Databases, data mining, and information retrieval
5 papers
Transaction processing and concurrency control · 46% Database system architecture and tuning · 45% Data models and query languages · 10%
Network and information security
3 papers
Systems and software security · 72% Authentication and access control · 18% Network security · 11%
Software engineering, system software, and programming languages
1 paper
Software testing · 100%

Topics — the 12 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Database system architecture and tuning › database security
multilevel secure databases
0.031995
Version pool management in a multilevel secure multiversion transaction manager · S&P 1995
Database Concurrency Control in Multilevel Secure Database Management Systems · IEEE Trans. Knowl. Data Eng. 1993
Multilevel Secure Database Concurrency Control · ICDE 1990
Transaction processing and concurrency control › concurrency control
multiversion concurrency control
0.021995
Version pool management in a multilevel secure multiversion transaction manager · S&P 1995
Multiversion Concurrency Control for Multilevel Secure Database Systems · S&P 1990
Systems and software security
multilevel security
0.011993
Database Concurrency Control in Multilevel Secure Database Management Systems · IEEE Trans. Knowl. Data Eng. 1993
Systems and software security › information flow control
noninterference
0.011993
Database Concurrency Control in Multilevel Secure Database Management Systems · IEEE Trans. Knowl. Data Eng. 1993
Data models and query languages
relational algebra
0.011990
Automated Test Case Generation for Programs Specified by Relational Algebra Queries · IEEE Trans. Software Eng. 1990
Systems and software security
database security
0.011990
Multiversion Concurrency Control for Multilevel Secure Database Systems · S&P 1990
Authentication and access control › access control
multilevel database security
0.011990
Multiversion Concurrency Control for Multilevel Secure Database Systems · S&P 1990
Software testing › test generation
specification-based test generation
0.011990
Automated Test Case Generation for Programs Specified by Relational Algebra Queries · IEEE Trans. Software Eng. 1990
Software testing
test generation
0.011990
Automated Test Case Generation for Programs Specified by Relational Algebra Queries · IEEE Trans. Software Eng. 1990
Processor architecture and microarchitecture
scheduler
0.011993
Database Concurrency Control in Multilevel Secure Database Management Systems · IEEE Trans. Knowl. Data Eng. 1993
Network security
covert channel
0.011990
Multilevel Secure Database Concurrency Control · ICDE 1990
Network security › covert channel
covert channel analysis
0.011990
Multiversion Concurrency Control for Multilevel Secure Database Systems · S&P 1990

Methods — techniques the papers use, named apart from their topics

noninterference · 0.0DC-security · 0.0serializability theory · 0.0relational algebra · 0.0prototype measurement · 0.0multiversion scheduling · 0.0black-box testing · 0.0analytical modeling · 0.0
YearPublicationVenuePosition
2002 Authorization Model for Summary Schemas Model
abstract
Security issues in multidatabases are complicated due to autonomy and heterogeneity of local databases. Deriving global authorizations by integrating underlying local authorizations is difficult since subjects and objects at each local database may not be compatible. In addition, local authorizations may conflict and could not be combined to form common global authorizations. This paper proposes an authorization model for a multidatabase system. The summary schemas model (SSM) is used as the underlying paradigm. The SSM resolves name differences in multidatabases using word relationships defined in a standard dictionary. Hypernyms and hyponyms of access terms exported from local databases are the main components of the SSM as they form a hierarchical metadata structure. SSM global authorizations tagged to hypernyms are derived from local authorizations using global roles and a role hierarchy defined in multidatabases. The model considers roles as common global subjects onto which local subjects can be mapped. Since the mapping can be done independently and autonomously among local databases, authorization autonomy is preserved. The paper also evaluates the performance of the proposed model. The simulation results show that the proposed model offers better performance than the original SSM since user queries with insufficient authority are rejected earlier. This results in less communication and less query response time.
Sudsanguan Ngamsuriyaroj, Ali R. Hurson, Thomas F. Keefe
IDEAS3
2001 Multilevel Security Transaction Processing
abstract
Since 1990, transaction processing in multilevel secure database management systems (DBMSs) has been receiving a great deal of attention from the security community. Transaction processing in these systems requires modification of conventional scheduling algorithms and commit protocols. These modifications are necessary because preserving the usual transaction properties when transactions are executing at different security levels often conflicts with the enforcement of the security policy. Considerable effort has been devoted to the development of efficient, secure algorithms for the major types of secure DBMS architectures: kernelized, replicated, and distributed. An additional problem that arises uniquely in multilevel secure DBMSs is that of secure, correct execution when data at multiple security levels must be written within one transaction. Significant progress has been made in a number of these areas, and a few of the techniques have been incorporated into commercial trusted DBMS products. However, there are many open problems remain to be explored. This paper reviews the achievements to date in transaction processing for multilevel secure DBMSs. The paper provides an overview of transaction processing needs and solutions in conventional DBMSs as background, explains the constraints introduced by multilevel security, and then describes the results of research in multilevel secure transaction processing. Research results and limitations in concurrency control, multilevel transaction management, and secure commit protocols are summarized. Finally, important new areas are identified for secure transaction processing research.
Sushil Jajodia, Vijayalakshmi Atluri, Thomas F. Keefe, Catherine D. McCollum, Ravi Mukkamala
J. Comput. Secur.3
1998 Version Management in the STAR MLS Database System
Ramprasad Sripada, Thomas F. Keefe
DBSec2
1996 Multilevel Secure Transaction Processing: Status and Prospects
Vijayalakshmi Atluri, Sushil Jajodia, Thomas F. Keefe, Catherine D. McCollum, Ravi Mukkamala
DBSec3
1996 The Impact of Multilevel Security on Database Buffer Management
Andrew Warner, Thomas F. Keefe, Shankar Pal
ESORICS3
1995 Concurrency control for federated multilevel secure database systems
Iwen E. Kang, Thomas F. Keefe
CSFW2
1995 Version pool management in a multilevel secure multiversion transaction manager
abstract
The paper presents initial results of an ongoing project to develop an experimental prototype of a multilevel secure (MLS) database system (DBS) based upon a multiversion scheduling protocol. The purpose of the project is to explore design alternatives and demonstrate feasibility. The work focuses on the mechanisms needed to provide efficient access to multiple versions of data as required by the protocol. With this protocol, strictly dominating transactions are serialized before active dominated transactions to avoid contention. These dominating transactions require access to old snapshots. The purpose of this work is to characterize the storage and access cost associated with the approach. We describe a prototype featuring an untrusted version pool mechanism to study this question. An analytical model is developed to predict storage and search costs. The analytical model is validated through measurements made on the prototype.>
Andrew Warner, Thomas F. Keefe
S&P2
1995 Transaction Management for Multilevel Secure Replicated Databases
abstract
A multilevel secure (MLS) replicated database system consists of a set of untrusted databases, one at each security level. Each database contains object replicas from dominated levels. To ensure consistency, the transaction scheduler at each level mu
Iwen E. Kang, Thomas F. Keefe
J. Comput. Secur.2
1995 Covert Channel Secure Hypercube Message Communication
Sourav Bhattacharya, Thomas F. Keefe, Wei-Tek Tsai
J. Parallel Distributed Comput.2
1993 The Concurrency Control and Recovery Problem for Multilevel Update Transactions in MLS System
abstract
The problem is addressed of a transaction reading and writing data at multiple classification levels in a multilevel secure (MLS) database. The authors refer to such transactions as multilevel update transactions. They show that no scheduler can ensure atomicity of multilevel update transactions in the presence of transaction aborts and at the same time be secure. There are essentially two ways of scheduling multilevel update transactions. The first method, which ensures strong atomicity, involves delaying low-level subtransactions until the fats of the sibling high-level subtransactions are known. The second scheme, which ensures only semantic atomicity, involves compensating the effects of any committed subtransactions. Analysis of these schemes indicates that the compensation approach leads to lower covert channel bandwidths. A concurrency control and recovery protocol based on compensation is proposed for multilevel update transactions. The security and correctness of the protocol is considered.>
Amit G. Mathur, Thomas F. Keefe
CSFW2
1993 Supporting Reliable and Atomic Transaction Management in Multidatabase Systems
abstract
Transaction management in multidatabase systems (MDBSs) is complicated by the autonomy requirement, especially in the case of failure. We demonstrate necessary and sufficient conditions for supporting reliable and atomic transaction management in MDBSs. Most previous work assumes single version histories and conflict serializability; this precludes the use of multiversion scheduling protocols in the local database systems. To deal with multiple versions, it is necessary to extend conflict serializability to one-copy serializability. A decentralized transaction management scheme is presented for use in MDBSs which assumes local histories are one-copy serializable and cascadeless. Only a minimum access restriction is imposed on global update subtransactions. Our scheme not only ensures global serializability in the face of failures, but also ensures freedom from global deadlocks.>
Iwen E. Kang, Thomas F. Keefe
ICDCS2
1993 Reconciling Objects and Multilevel Security (Panel)
abstract
No abstract available.
Thomas F. Keefe
OOPSLA1
1993 Database Concurrency Control in Multilevel Secure Database Management Systems
abstract
Concurrent execution of transactions in database management systems (DBMSs) may lead to contention for access to data, which in a multilevel secure DBMS (MLS/DBMS) may lead to insecurity. Security issues involved in database concurrency control for MLS/DBMSs are examined, and it is shown how a scheduler can affect security. Data conflict security, (DC-security), a property that implies a system is free of covert channels due to contention for access to data, is introduced. A definition of DC-security based on noninterference is presented. Two properties that constitute a necessary condition for DC-security are introduced along with two simpler necessary conditions. A class of schedulers called output-state-equivalent is identified for which another criterion implies DC-security. The criterion considers separately the behavior of the scheduler in response to those inputs that cause rollback and those that do not. The security properties of several existing scheduling protocols are characterized. Many are found to be insecure.>
Thomas F. Keefe, Wei-Tek Tsai, Jaideep Srivastava
IEEE Trans. Knowl. Data Eng.1
1992 On Transaction Processing for Multilevel Secure Replicated Databases
Iwen E. Kang, Thomas F. Keefe
ESORICS2
1991 SODA: a security model for object-oriented database management systems
abstract
A security model for a multilevel secure object-oriented database (SODA) is described. The author demonstrates that the model satisfies the simple security condition and the *-property. Data classification is based on inheritance with the enforcement of data classification rules assured by the TCB. SODA allows the use of polyinstantiation or rigid classification as a solution to the multiparty update conflict problem with the selection being made on a class by class basis. The SODA model is compatible with a property called modifiability. This property insures that every object which is reachable within the database can be modified by some subject.>
Thomas F. Keefe
COMPSAC1
1990 Multilevel Secure Database Concurrency Control
abstract
The implications of multilevel security on database concurrency control are explored. Transactions are vital for multilevel secure database management systems (MLS/DBMSs) because they provide transparency to concurrency and to failure. Concurrent execution of transactions may lead to contention among subjects for access to data, which in MLS/DBMSs may lead to security problems. An abstraction of security models in terms of the transactions which they produce is presented. The notion of DC-Security which identifies a class of covert channels that are caused by contention for access to shared data, is introduced. This notion is useful for evaluating the security of transaction schedulers. A framework for multilevel secure schedulers which allows analysis of a schedulers' security properties at the protocol level is presented. Necessary and sufficient conditions are developed for DC-Security in this framework and proved using noninterference. A wide range of schedulers is evaluated against these conditions.>
Thomas F. Keefe, Wei-Tek Tsai, Jaideep Srivastava
ICDE1
1990 Multiversion Concurrency Control for Multilevel Secure Database Systems
abstract
Consideration is given to the application of multiversion schedulers in multilevel secure database management systems (MLS/DBMSs). Transactions are vital for MLS/DBMSs because they provide transparency to concurrency and failure. Concurrent execution of transactions may lead to contention among subjects for access to data, which in MLS/DBMSs may lead to security problems. Multiversion schedulers reduce the contention for access to data by maintaining multiple versions. A description is given of the relation between schedules produced in MLS/DBMSs and those which are multiversion serializable. The authors also propose a secure multiversion scheduler. They show that the scheduling protocol gives correct schedules and is free of covert channels due to contention for access to data, i.e. the scheduler is data-conflict-secure.>
Thomas F. Keefe, Wei-Tek Tsai
S&P1
1990 Automated Test Case Generation for Programs Specified by Relational Algebra Queries
abstract
Black-box software testing requires test cases to be generated from specifications alone. However, it is impossible to automate the process completely for arbitrary specifications. Specifications are thus restricted to being written entirely in terms of relational algebra expressions. An automated test case generation method is developed for such specifications.>
Wei-Tek Tsai, Dmitry Volovik, Thomas F. Keefe
IEEE Trans. Software Eng.3
1989 Security model consistency in secure object-oriented systems
abstract
Examines three techniques for evaluating the logical consistency of an object-oriented Database security model. The first technique consists of judging the model with respect to a set of general consistency properties for database security models. The second technique compares the SODA model against two other database security models. The third technique consists of defining a set of entities and mechanisms fundamental to the object-oriented model and considering the effect on them by the security model. Each of these techniques are applied to the Secure Object-Oriented Database (SODA) security model and are evaluated with respect to their applicability difficulty and usefulness. Using the results of this analysis the authors characterize the consistency of the SODA security model.>
Thomas F. Keefe, Wei-Tek Tsai
ACSAC1
1989 Multi-party conflict: the problem and its solutions
abstract
Currently there is a great deal of interest concerning polyinstantiation in database management systems (DBMSs). However, polyinstantiation is a specific solution to a problem faced by all secure systems, and the problem itself is not well characterized. The problem stems from the interference between subjects of different security compartments. The authors focus on this problem, which they call multiparty update conflict (MUC). They discuss and evaluate some solutions to the MUC problem, such as polyinstantiation and rigid classification. A framework for a class of MUC solutions based on polyinstantiation is described, and several intermediate solutions between rigid classification and polyinstantiation are enumerated.>
Thomas F. Keefe, Dan Thomsen, Wei-Tek Tsai, M. R. Hansch
ACSAC1
1989 SODA: A secure object-oriented database system
Thomas F. Keefe, Wei-Tek Tsai, Bhavani Thuraisingham
Comput. Secur.1
1988 Automatic test case generation from relational algebra queries
abstract
The authors: develop mapping rules from the relational algebra to linear predicates defining relations in the (output) domain; describe how these predicates can be interpreted in the (input) domain using f/sub Q/, a specified query relation; describe a translation from these predicates to sets of systems of linear inequalities; and discuss the use of a set of systems of linear inequalities to generate complete test cases, inputs, and expected outputs from the queries using the domain testing theory. The proposed techniques support software development based on specification testing, specification-directed testing, and rapid prototyping.>
Wei-Tek Tsai, Dmitry Volovik, Thomas F. Keefe, Mohamed Fayad
COMPSAC3