VLDB 2026 Research / reviewers in the wild / expert
Chandan Mazumdar
dblp:59/6658
· DBLP profile ↗
12ranked-venue papers
0as first author
2since 2021 · last 2023
0000-0002-4252-8861ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | A Novel Software Defined Security Framework for SDN
Srijita Basu, Neha Firdaush Raun, Avishek Ghosal, Debanjan Chatterjee, Debarghya Maitra, Chandan Mazumdar |
CRiSIS | 6 |
| 2021 | Towards an Ontology for Enterprise Level Information Security Policy Analysis
Debashis Mandal, Chandan Mazumdar |
ICISSP | 2 |
| 2018 | Attack Difficulty Metric for Assessment of Network SecurityabstractIn recent days, organizational networks are becoming target of sophisticated multi-hop attacks. Attack Graph has been proposed as a useful modeling tool for complex attack scenarios by combining multiple vulnerabilities in causal chains. Analysis of attack scenarios enables security administrators to calculate quantitative security measurements. These measurements justify security investments in the organization. Different security metrics based on attack graph have been introduced for evaluation of comparable security measurements. Studies show that difficulty of exploiting the same vulnerability changes with change of its position in the causal chains of attack graph. In this paper, a new security metric based on attack graph, namely Attack Difficulty has been proposed to include this position factor. The security metrics are classified in two major categories viz. counting metrics and difficulty-based metrics. The proposed Attack Difficulty Metric employs both categories of metrics as the basis for its measurement. Case studies have been presented for demonstrating applicability of the proposed metric. Comparison of this new metric with other attack graph based security metrics has also been included to validate its acceptance in real life situations. Preetam Mukherjee 0001, Chandan Mazumdar |
ARES | 2 |
| 2017 | A Quantitative Methodology for Cloud Security Risk Assessment
Srijita Basu, Chandan Mazumdar |
CLOSER | 3 |
| 2016 | A Quantitative Methodology for Security Risk Assessment of Enterprise Business Processes
Jaya Bhattacharjee, Anirban Sengupta 0001, Chandan Mazumdar |
ICISSP | 3 |
| 2015 | A Novel Model of Security Policies and RequirementsabstractThe responsibility of controlling, monitoring, analyzing or enforcing security of a system becomes complex due to the interplay among different security policies and requirements. Many of the security requirements have overlap among themselves and they are not exhaustive in nature. For that reason, maintaining security requirements and designing optimal security controls are difficult, and involve wastage of valuable resources. Finding out a set of mutually exclusive and exhaustive security requirements and canonical policies will indeed ease the security management job. From this motivation, in this paper we try to find out a set of mutually exclusive and exhaustive security requirements. To do this, a small set of low-level security policy descriptions are proposed using Process Algebraic notions, by which all kinds of high level security policies can be represented. Non-compliance to this new set of security policies gives rise to a set of security violations. These security violations are mutually exclusive and exhaustive, so all the other security violations can be described by this basic set of security violations. From these security violations, a set of security requirements is determined. To preserve the security for any system it is necessary and sufficient to maintain these requirements. Preetam Mukherjee 0001, Chandan Mazumdar |
ICISSP | 2 |
| 2015 | Modelling of Enterprise Insider ThreatsabstractIn this paper, a position has been taken to include the non-human active agents as insiders of an enterprise, as opposed to only human insiders as found in the literature. This eliminates the necessity of including the psycho-social and criminological behavioural traits to be incorporated in the management of insider threats. A framework of an Enterprise has been developed and it is shown that within the framework, both the human and non-human agents can be modelled as insider threats in a uniform manner. An example case has been analysed as supporting evidences for the point of view. Puloma Roy, Chandan Mazumdar |
ICISSP | 2 |
| 2013 | A formal methodology for Enterprise Information Security risk assessmentabstractAssets are valuable for an enterprise as they help to execute its business activities. They contain vulnerabilities, which, if exploited by threats, can cause harm to an enterprise. Risk assessment is the process of identifying potential harm (risks) that may occur if vulnerabilities are exploited by threats. Existing methodologies for assessing risks are inadequate as they fail to consider important aspects of risk elements, like asset dependency, vulnerability dependency, etc. This paper presents a formal risk assessment methodology that considers these issues during risk computation, and also identifies the actual contributors to risk values. Jaya Bhattacharjee, Anirban Sengupta 0001, Chandan Mazumdar |
CRiSIS | 3 |
| 2012 | A Practical Approach of Fairness in E-ProcurementabstractIn this paper the authors present a practical approach of fairness in E-procurement. A generalized model of E-procurement is also presented here, which includes both E-contracting and E-trading. The model also proposes the generalized methodologies to develop E-procurement protocols that ensure fairness in true sense without using an additional trusted third party. They conclude this paper by indicating the area of applicability for their model. Debajyoti Konar, Chandan Mazumdar |
Int. J. Inf. Secur. Priv. | 2 |
| 2011 | A Mark-Up Language for the Specification of Information Security Governance RequirementsabstractAs enterprises become dependent on information systems, the need for effective Information Security Governance (ISG) assumes significance. ISG manages risks relating to the confidentiality, integrity and availability of information, and its supporting processes and systems, in an enterprise. Even a medium-sized enterprise contains a huge collection of information and other assets. Moreover, risks evolve rapidly in today’s connected digital world. Therefore, the proper implementation of ISG requires automation of the various monitoring, analysis, and control processes. This can be best achieved by representing information security requirements of an enterprise in a standard, structured format. This paper presents such a structured format in the form of Enterprise Security Requirement Markup Language (ESRML) Version 2.0. It is an XML-based language that considers the elements of ISO 27002 best practices. Anirban Sengupta 0001, Chandan Mazumdar |
Int. J. Inf. Secur. Priv. | 2 |
| 2009 | A formal methodology for detection of vulnerabilities in an enterprise information systemabstractFrom information security point of view, an enterprise is considered as a collection of assets and their interrelations. These interrelations may be built into the enterprise information infrastructure, as in the case of connection of hardware elements in network architecture, or installation of software or information assets in hardware. As a result, access to one element may enable access to another if they are connected. An enterprise may specify conditions on the access of certain assets in certain mode (read, write etc.) as policies. The interconnection of assets, along with specified policies, may lead to managerial vulnerabilities in the enterprise information system. These vulnerabilities, if exploited by threats, may cause disruption to the normal functioning of information systems. This paper presents a formal method for detection of managerial vulnerabilities of enterprise information systems in linear time. Anirban Sengupta 0001, Chandan Mazumdar, Aditya Bagchi |
CRiSIS | 2 |
| 1986 | Study of a Simulated Stream Machine for Dataflow Computation
Sukumar Ghosh, Somprakash Bandyopadhyay, Chandan Mazumdar |
Perform. Evaluation | 3 |