VLDB 2026 Research / reviewers in the wild / expert
Adam J. Lee
dblp:62/1373
· DBLP profile ↗
75ranked-venue papers
15as first author
12since 2021 · last 2026
0000-0002-2596-7256ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 46 · 13 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 21 · 8 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-authorSystems, architecture and hardware · 5 · 1 first-authorComputer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VRSafe: A Secure Virtual Keyboard to Mitigate Keystroke Inference in Virtual RealityabstractPassword-based authentication is one of the most commonly used methods for verifying user identities, and its widespread usage continues in virtual reality (VR) applications. As a result, various forms of attacks on password-based authentication in traditional environments such as keystroke inference and shoulder surfing, are still effective in VR applications. While keystroke inference attacks on virtual keyboards have been studied extensively, few efforts have developed an effective and cost-efficient defense strategy to mitigate keystroke inferences in VR. To address this gap, this paper presents a novel QWERTY keyboard called VRSafe that is resilient to keystroke inference attacks. The proposed keyboard carefully introduces false positive keystrokes into the information collected by attackers during the typing process, making the inference of the original password difficult. VRSafe also incorporates a novel malicious login detector that can effectively identify unauthorized login attempts using credentials inferred from keystroke inference attacks with high detection rate and minimal time and memory cost. The proposed design is evaluated through both simulation experiments and a real-world user study, and the results show that VRSafe can significantly reduce the accuracy of keystroke inference attacks while incurring a modest overhead from a usability standpoint. Na Du, Adam J. Lee, Balaji Palanisamy |
CODASPY | 3 |
| 2025 | Relying on Trust to Balance Protection and Performance in Cryptographic Access ControlabstractCryptographic Access Control (CAC) allows organizations to control cloud-hosted data sharing among users while preventing external attackers, malicious insiders, and honest-but-curious cloud providers from accessing the data. However, CAC entails an overhead often impractical for real-world scenarios due to the many cryptographic computations involved. Hence, we put forth a hybrid Access Control (AC) scheme --- combining CAC and (traditional) centralized AC --- that considers trust assumptions (e.g., on users) and data protection requirements of the underlying scenario on a case-by-case basis to reduce the number of cryptographic computations to execute in CAC. Besides, we design a consistency check to ensure the correctness and safety properties of the enforcement of the hybrid AC scheme, provide a proof-of-concept implementation in Prolog, and conduct a preliminary experimental evaluation. Simone Brunello, Stefano Berlato, Roberto Carbone, Adam J. Lee, Silvio Ranise |
SACMAT | 4 |
| 2025 | Detecting Group Configurations in Shared Spaces: A Heuristic for Understanding Space Use BehaviorabstractThe rapid development and deployment of “smart space” technology in commercial and educational buildings has brought efficiencies and comfort to users. Yet, the “smart” is largely limited to knowledge gained from occupancy and activity data. These limited data explain what is happening in a space but nothing about how effectively the space is being used. In this work, we explore how to understand effective space use and how it may impact future smart spaces and their design. As part of this investigation, we design generalizable heuristics derived from observable human behaviors and space usage to detect group configurations in public spaces. The resultant system models similar qualities of a space that end-users will judge and measure themselves before use. The effectiveness of our system is validated against a crowdsourced study. Our system serves as a foundation for applications building upon improving space use efficacy. Andrew Xu, Yuezhong Xu, Jacob T. Biehl, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2024 | "I know what you did last semester": Understanding Privacy Expectations and Preferences in the Smart CampusabstractSensing technologies in smart campuses help make them sustainable and well-connected environments. However, as with other smart environments, smart campuses can cause privacy concerns during and after deployment. We present the results of a 14-day in-situ study designed to understand peoples’ sentiments about sensing capabilities in smart campuses and how they would specify privacy preferences. In contrast to prior work, which reported the importance of sensing modality and purpose, our findings indicate that indoor location type and recipient are primary determinants for comfort, surprise, notification preferences, and allowance of data collection. Further, we observed that indoor location type influences privacy control willingness and how users specify sensor controlling rule. For example, our participants allowed policy-controlled data collection in group areas while denying it in learning areas. Finally, we suggest that academic environments are unique, possibly due to the complex relationships between students, staff, and faculty. Injung Kim 0002, Adam J. Lee |
CHI | 2 |
| 2024 | Understanding Perceived Utility and Comfort of In-Home General-Purpose Sensing through Progressive ExposureabstractA fundamental paradigm shift for in-home sensing is apparent. Special-purpose sensing, where there is a one-to-one relationship between sensors and applications, is evolving into general-purpose sensing, where there is a many-to-many relationship between sensors and applications. This new shift may impact how individuals think about in-home sensing, where utility and comfort are often linked to applications rather than sensed data. We explore the evolution of individuals' perceptions as they become increasingly and contextually aware of sensor capabilities and data characteristics. Through a multi-phase study where 12 participants were progressively led through six exposure conditions across laboratory and home environments, we find that exposure changes represent inflection points for perceptions of utility and comfort with data collection. These changes define opportunities for increasing trust in sensing infrastructures via data- and context-aware interventions, managing over-reliance on awareness notifications, and providing data-enabled "what if" analyses to balance comfort and utility within an individual's unique context and environment. Pranut Jain, Andrew Xu, Thomas Downes, Injung Kim 0002, Jacob T. Biehl, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 7 |
| 2024 | Getting it Just Right: Towards Balanced Utility, Privacy, and Equity in Shared Space SensingabstractLow-cost sensors have enabled a wide array of data-driven applications and insights. As a result, encountering spaces with pervasive sensing has become all but unavoidable. This creates a fundamental tension: the success of smart environments will become increasingly dependent on equity of access to data-driven insights and consideration of the privacy expectations of sensed individuals. These concerns highlight the need to bring equity to all stakeholders of smart environments, which in turn would preserve public trust in these smart spaces. In this work, we explored several approaches to identity-obscuring visual representations through a progressive series of experiments. We designed and validated a series of visual representations through stakeholder interactions and tested the ability of these visual representations to limit identification via a crowdsourced study. An evaluation across three months of data gathered within our organization also showed that the identity-obscured data could still be leveraged to accurately count group size. Our contributions lay the groundwork for sensing frameworks that bring utility to all stakeholders of shared spaces while being cognizant of their diverse privacy expectations. Andrew Xu, Jacob T. Biehl, Adam J. Lee |
ACM Trans. Internet Things | 3 |
| 2023 | Co-Designing with Users the Explanations for a Proactive Auto-Response Messaging AgentabstractExplanations of AI Agents' actions are considered to be an important factor in improving users' trust in the decisions made by autonomous AI systems. However, as these autonomous systems evolve from reactive, i.e., acting on user input, to proactive, i.e., acting without requiring user intervention, there is a need to explore how the explanation for the actions of these agents should evolve. In this work, we explore the design of explanations through participatory design methods for a proactive auto-response messaging agent that can reduce perceived obligations and social pressure to respond quickly to incoming messages by providing unavailability-related context. We recruited 14 participants who worked in pairs during collaborative design sessions where they reasoned about the agent's design and actions. We qualitatively analyzed the data collected through these sessions and found that participants' reasoning about agent actions led them to speculate heavily on its design. These speculations significantly influenced participants' desire for explanations and the controls they sought to inform the agents' behavior. Our findings indicate a need to transform users' speculations into accurate mental models of agent design. Further, since the agent acts as a mediator in human-human communication, it is also necessary to account for social norms in its explanation design. Finally, user expertise in understanding their habits and behaviors allows the agent to learn from the user their preferences when justifying its actions. Pranut Jain, Rosta Farzan, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | Laila is in a Meeting: Design and Evaluation of a Contextual Auto-Response Messaging AgentabstractThe ease of smartphone communications has created an expectation of constant connectivity. While the adoption of virtual assistants has improved, their capabilities for handling proactive communication tasks remain underexplored. We present the design, implementation, and evaluation of a Contextual Auto-Response agent to communicate users’ situational awareness. The agent creates auto-responses by modeling availability using smartphone sensors and sharing contextual information on behalf of the user. In a two-week study with 12 participants, we evaluated the perception of this agent and its impact on device usage behavior. Many participants found the agent useful for signaling unavailability, with some caveats. Participants also reported altering device and agent usage based on their understanding of its functions. Our findings indicate the importance of transparency in proactive agent designs and the need for personalization to enable an enhanced and cooperative human-agent interaction. Pranut Jain, Rosta Farzan, Adam J. Lee |
Conference on Designing Interactive Systems | 3 |
| 2022 | Tangible Privacy for Smart Voice Assistants: Bystanders' Perceptions of Physical Device ControlsabstractSmart voice assistants such as Amazon Alexa and Google Home are becoming increasingly pervasive in our everyday environments. Despite their benefits, their miniaturized and embedded cameras and microphones raise important privacy concerns related to surveillance and eavesdropping. Recent work on the privacy concerns of people in the vicinity of these devices has highlighted the need for 'tangible privacy', where control and feedback mechanisms can provide a more assured sense of whether the camera or microphone is 'on' or 'off'. However, current designs of these devices lack adequate mechanisms to provide such assurances. To address this gap in the design of smart voice assistants, especially in the case of disabling microphones, we evaluate several designs that incorporate (or not) tangible control and feedback mechanisms. By comparing people's perceptions of risk, trust, reliability, usability, and control for these designs in a between-subjects online experiment (N=261), we find that devices with tangible built-in physical controls are perceived as more trustworthy and usable than those with non-tangible mechanisms. Our findings present an approach for tangible, assured privacy especially in the context of embedded microphones. Taslima Akter, Zachary Buher, Rosta Farzan, Apu Kapadia, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2022 | Decaying Photos for Enhanced Privacy: User Perceptions Towards Temporal Redactions and 'Trusted' PlatformsabstractWith the rising popularity of photo sharing in online social media, interpersonal privacy violations, where one person violates the privacy of another, have become an increasing concern. Although applying image obfuscations can be a useful tool for improving privacy when sharing photos, prior studies have found these obfuscation techniques adversely affect viewers' satisfaction. On the other hand, ephemeral photos, popularized by apps such as Snapchat, allow viewers to see the entire photo, which then disappears shortly thereafter to protect privacy. However, people often use workarounds to save these photos before deletion. In this work, we study people's sharing preferences with two proposed 'temporal redactions', which combines ephemerality with redactions to allow viewers to see the entire image, yet make these images safe for longer storage through a gradual or delayed application of redaction on the sensitive portions of the photo. We conducted an online experiment (N=385) to study people's sharing behaviors in different contexts and under different levels of assurance provided by the viewer's platform (e.g., guaranteeing temporal redactions are applied through the use of 'trusted hardware'). Our findings suggest that the proposed temporal redaction mechanisms are often preferred over existing methods. On the other hand, more efforts are needed to convey the benefits of trusted hardware to users, as no significant differences were observed in attitudes towards 'trusted hardware' on viewers' devices. Sabid Bin Habib Pias, Taslima Akter, Apu Kapadia, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2022 | Formal Modelling and Automated Trade-off Analysis of Enforcement Architectures for Cryptographic Access Control in the CloudabstractTo facilitate the adoption of cloud by organizations, Cryptographic Access Control (CAC) is the obvious solution to control data sharing among users while preventing partially trusted Cloud Service Providers (CSP) from accessing sensitive data. Indeed, several CAC schemes have been proposed in the literature. Despite their differences, available solutions are based on a common set of entities—e.g., a data storage service or a proxy mediating the access of users to encrypted data—that operate in different (security) domains—e.g., on-premise or the CSP. However, the majority of these CAC schemes assumes a fixed assignment of entities to domains; this has security and usability implications that are not made explicit and can make inappropriate the use of a CAC scheme in certain scenarios with specific trust assumptions and requirements. For instance, assuming that the proxy runs at the premises of the organization avoids the vendor lock-in effect but may give rise to other security concerns (e.g., malicious insiders attackers). To the best of our knowledge, no previous work considers how to select the best possible architecture (i.e., the assignment of entities to domains) to deploy a CAC scheme for the trust assumptions and requirements of a given scenario. In this article, we propose a methodology to assist administrators in exploring different architectures for the enforcement of CAC schemes in a given scenario. We do this by identifying the possible architectures underlying the CAC schemes available in the literature and formalizing them in simple set theory. This allows us to reduce the problem of selecting the most suitable architectures satisfying a heterogeneous set of trust assumptions and requirements arising from the considered scenario to a decidable Multi-objective Combinatorial Optimization Problem (MOCOP) for which state-of-the-art solvers can be invoked. Finally, we show how we use the capability of solving the MOCOP to build a prototype tool assisting administrators to preliminarily perform a “What-if” analysis to explore the trade-offs among the various architectures and then use available standards and tools (such as TOSCA and Cloudify) for automated deployment in multiple CSPs. Stefano Berlato, Roberto Carbone, Adam J. Lee, Silvio Ranise |
ACM Trans. Priv. Secur. | 3 |
| 2021 | Context-based Automated Responses of Unavailability in Mobile Messaging
Pranut Jain, Rosta Farzan, Adam J. Lee |
Comput. Support. Cooperative Work. | 3 |
| 2020 | Exploring Architectures for Cryptographic Access Control Enforcement in the Cloud for Fun and OptimizationabstractTo facilitate the adoption of cloud by organizations, Cryptographic Access Control (CAC) is the obvious solution to control data sharing among users while preventing partially trusted Cloud Service Providers (CSP) from accessing sensitive data. Indeed, several CAC schemes have been proposed in the literature. Despite their differences, available solutions are based on a common set of entities---e.g., a data storage service or a proxy mediating the access of users to encrypted data---that operate in different (security) domains---e.g., on-premise or the CSP. However, the majority of the CAC schemes assume a fixed assignment of entities to domains; this has security and usability implications that are not made explicit and can make inappropriate the use of a CAC scheme in certain scenarios with specific requirements. For instance, assuming that the proxy runs at the premises of the organization avoids the vendor lock-in effect but may substantially undermine scalability. Stefano Berlato, Roberto Carbone, Adam J. Lee, Silvio Ranise |
AsiaCCS | 3 |
| 2020 | Effective Access Control in Shared-Operator Multi-tenant Data Stream Management Systems
Marian Zaki, Adam J. Lee, Panos K. Chrysanthis |
DBSec | 2 |
| 2020 | Tangible Privacy: Towards User-Centric Sensor Designs for Bystander PrivacyabstractSensor-enabled computers in the form of 'IoT' devices such as home security cameras and voice assistants are increasingly becoming pervasive in our environment. With the embedded cameras and microphones in these devices, this 'invasion' of our everyday spaces can pose significant threats to the privacy of bystanders. Because of their complex functionality, even when people attempt privacy measures (such as asking the owner to "turn the camera off"), these devices may still record information because of the lack of a 'real' off button. With the ambiguities of current designs, a bystander's perceived privacy can diverge from their actual privacy. Indeed, being able to assess one's actual privacy is a key aspect in managing one's privacy according to Altman's theory of boundary regulation, and current designs fall short in assuring people of their privacy. To understand how people as bystanders manage their privacy with IoT devices, we conducted an interview study about people's perceptions of and behaviors around current IoT devices. We find that although participants' behaviors line up with Altman's theory of boundary regulation, in the face of uncertainty about their privacy, they desire or engage in various 'tangible' workarounds. Based on our findings, we identify and introduce the concept of 'tangible privacy' as being essential to boundary regulation with IoT devices. We argue that IoT devices should be designed in a way that clearly and unambiguously conveys sensor states to people around them and make actionable design recommendations to provide strong privacy assurances to bystanders. Rosta Farzan, Apu Kapadia, Adam J. Lee |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2020 | Anchor of trust: towards collusion-resistant trusted indoor location for enterprise and industrial use
Jacob T. Biehl, Adam J. Lee, Gerry Filby |
Pers. Ubiquitous Comput. | 2 |
| 2019 | Behind Enemy Lines: Exploring Trusted Data Stream Processing on Untrusted SystemsabstractData Stream Processing Systems (DSPSs) execute long-running, continuous queries over transient streaming data, often making use of outsourced, third-party computational platforms. However, third-party outsourcing can lead to unwanted violations of data providers' access controls or privacy policies, as data potentially flows through untrusted infrastructure. To address these types of violations, data providers can elect to use stream processing techniques based upon computation-enabling encryption. Unfortunately, this class of solutions can leak information about underlying plaintext values, reduce the possible set of queries that can be executed, and come with detrimental performance overheads. To alleviate the concerns with cryptographically-enforced access controls in DSPSs, we have developed \system, a DSPS that makes use of Intel's Software Guard Extensions (SGX) to protect data being processed on untrusted infrastructure. We show that \system can execute arbitrary queries while leaking no more information than an idealized \baseline system. At the same time, an extensive evaluation shows that the overheads associated with stream processing in \system are comparable to its computation-enabling encryption counterparts for many queries. Cory Thoma, Adam J. Lee, Alexandros Labrinidis |
CODASPY | 2 |
| 2019 | Shoal: Query Optimization and Operator Placement for Access Controlled Stream Processing Systems
Cory Thoma, Alexandros Labrinidis, Adam J. Lee |
DBSec | 3 |
| 2019 | NeXUS: Practical and Secure Access Control on Untrusted Storage Platforms using Client-Side SGXabstractWith the rising popularity of file-sharing services such as Google Drive and Dropbox in the workflows of individuals and corporations alike, the protection of client-outsourced data from unauthorized access or tampering remains a major security concern. Existing cryptographic solutions to this problem typically require server-side support, involve non-trivial key management on the part of users, and suffer from severe re-encryption penalties upon access revocations. This combination of performance overheads and management burdens makes this class of solutions undesirable in situations where performant, platform-agnostic, dynamic sharing of user content is required. We present NEXUS, a stackable filesystem that leverages trusted hardware to provide confidentiality and integrity for user files stored on untrusted platforms. NEXUS is explicitly designed to balance security, portability, and performance: it supports dynamic sharing of protected volumes on any platform exposing a file access API without requiring server-side support, enables the use of fine-grained access control policies to allow for selective sharing, and avoids the key revocation and file re-encryption overheads associated with other cryptographic approaches to access control. This combination of features is made possible by the use of a client-side Intel SGX enclave that is used to protect and share NEXUS volumes, ensuring that cryptographic keys never leave enclave memory and obviating the need to reencrypt files upon revocation of access rights. We implemented a NEXUS prototype that runs on top of the AFS filesystem and show that it incurs ×2 overhead for a variety of common file and database operations. Judicael Briand Djoko, Jack Lange, Adam J. Lee |
DSN | 3 |
| 2019 | Adaptive Modelling of Attentiveness to Messaging: A Hybrid ApproachabstractIdentifying instances when a user will not able to attend to an incoming message and constructing an auto-response with relevant contextual information may help reduce social pressures to immediately respond that many users face. Mobile messaging behavior often varies from one person to another. As a result, compared to a generic model considering profiles of several users, a personalized model can capture a user's messaging behavior more accurately to predict their inattentive states. However, creating accurate personalized models requires a non-trivial amount of individual data, which is often not available for new users. In this work, we investigate a weighted hybrid approach to model users' attention to messaging. Through dynamic performance-based weighting, we combine the predictions of three types of models, a general model, a group model and a personalized model to create an approach which can work through the lack of initial data while adapting to the user's behavior. We present the details of our modeling approach and the evaluation of the model with over three weeks of data from 274 users. Our results highlight the value of hybrid weighted modeling to predict when a user cannot attend to their messages. Pranut Jain, Rosta Farzan, Adam J. Lee |
UMAP | 3 |
| 2018 | Sensing or Watching?: Balancing Utility and Privacy in Sensing Systems via Collection and Enforcement MechanismsabstractDevices with embedded sensors are permeating the computing landscape, allowing the collection and analysis of rich data about individuals, smart spaces, and their interactions. This class of devices enables a useful array of home automation and connected workplace functionality to individuals within instrumented spaces. Unfortunately, the increasing pervasiveness of sensors can lead to perceptions of privacy loss by their occupants. Given that many instrumented spaces exist as platforms outside of a user's control---e.g., IoT sensors in the home that rely on cloud infrastructure or connected workplaces managed by one's employer---enforcing access controls via a trusted reference monitor may do little to assuage individuals' privacy concerns. This calls for novel enforcement mechanisms for controlling access to sensed data. In this paper, we investigate the interplay between sensor fidelity and individual comfort, with the goal of understanding the design space for effective, yet palatable, sensors for the workplace. In the context of a common space contextualization task, we survey and interview individuals about their comfort with three common sensing modalities: video, audio, and passive infrared. This allows us to explore the extent to which discomfort with sensor platforms is a function of detected states or sensed data. Our findings uncover interesting interplays between content, context, fidelity, history, and privacy. This, in turn, leads to design recommendations regarding how to increase comfort with sensing technologies by revisiting the mechanisms by which user preferences and policies are enforced in situations where the infrastructure itself is not trusted. Adam J. Lee, Jacob T. Biehl, Conor Curry |
SACMAT | 1 |
| 2017 | 16th Workshop on Privacy in the Electronic Society (WPES 2017)abstractThe 16th Workshop on Privacy in the Electronic Society was held on October 30, 2017 in conjunction with the 24th ACM Conference on Computer and Communications Security (CCS 2017) in Dallas, Texas, USA. The goal of WPES is to bring together a diverse group of privacy researchers and practitioners to discuss privacy problems that arise in global, interconnected societies, and potential solutions to them. The program for the workshop contains 14 full papers and 5 short papers selected from a total of 56 submissions. Specific topics covered in the program include but are not limited to: de-anonymization, fingerprinting and profiling, location privacy, and private memory systems. Adam J. Lee |
CCS | 1 |
| 2017 | Was my message read?: Privacy and Signaling on Facebook MessengerabstractMajor online messaging services such as Facebook Messenger and WhatsApp are starting to provide users with real-time information about when people read their messages, while useful, the feature has the potential to negatively impact privacy as well as cause concern over access to self. We report on two surveys using Mechanical Turk which looked at senders' (N=402} use of and reactions to the `message seen' feature, and recipients' (N=316) privacy and signaling behaviors in the face of such visibility. Our findings indicate that senders experience a range of emotions when their message is not read, or is read but not answered immediately. Recipients also engage in various signaling behaviors in the face of visibility by both replying or not replying immediately. Roberto Hoyle, Srijita Das 0001, Apu Kapadia, Adam J. Lee, Kami Vaniea |
CHI | 4 |
| 2017 | Viewing the Viewers: Publishers' Desires and Viewers' Privacy Concerns in Social NetworksabstractSocial networking sites are starting to provide users with services that expose information about their audiences' composition and behavior, such as LinkedIn's 'Who's viewed my profile' feature. Providing information about content viewers to content publishers, however, raises new privacy concerns for viewers themselves, possibly creating a chilling effect on viewer behavior. We report on a study of 718 respondents using Mechanical Turk across two surveys to study publishers' (N=402) use and expectations of information about their viewers, and viewers' (N=316) privacy behaviors and concerns in the face of such visibility. Our findings indicate that publishers are generally mindful of viewers' privacy; viewers engage in various self-censorship behaviors in the face of visibility; and in some cases (e.g., dating sites) significant gender differences exist about what information respondents felt should be shared with publishers and required of viewers. Roberto Hoyle, Srijita Das 0001, Apu Kapadia, Adam J. Lee, Kami Vaniea |
CSCW | 4 |
| 2016 | TPRIVEXEC: Private Execution in Virtual Memory
Judicael Briand Djoko, Brandon Jennings, Adam J. Lee |
CODASPY | 3 |
| 2016 | Panel Security and Privacy in the Age of Internet of Things: Opportunities and ChallengesabstractIn response to the new security and privacy concerns raised by emerging Internet of Things (IoT) technology, this panel discusses the current efforts and challenges to secure the IoT devices and to protect the integrity and privacy of users' data. Jianwei Niu 0001, Yier Jin, Adam J. Lee, Ravi S. Sandhu, Wenyuan Xu 0005 |
SACMAT | 3 |
| 2016 | PolyStream: Cryptographically Enforced Access Controls for Outsourced Data Stream ProcessingabstractWith data becoming available in larger quantities and at higher rates, new data processing paradigms have been proposed to handle high-volume, fast-moving data. Data Stream Processing is one such paradigm wherein transient data streams flow through sets of continuous queries, only returning results when data is of interest to the querier. To avoid the large costs associated with maintaining the infrastructure required for processing these data streams, many companies will outsource their computation to third-party cloud services. This outsourcing, however, can lead to private data being accessed by parties that a data provider may not trust. The literature offers solutions to this confidentiality and access control problem but they have fallen short of providing a complete solution to these problems, due to either immense overheads or trust requirements placed on these third-party services. Cory Thoma, Adam J. Lee, Alexandros Labrinidis |
SACMAT | 2 |
| 2016 | On the Practicality of Cryptographically Enforcing Dynamic Access Control Policies in the CloudabstractThe ability to enforce robust and dynamic access controls on cloud-hosted data while simultaneously ensuring confidentiality with respect to the cloud itself is a clear goal for many users and organizations. To this end, there has been much cryptographic research proposing the use of (hierarchical) identity-based encryption, attribute-based encryption, predicate encryption, functional encryption, and related technologies to perform robust and private access control on untrusted cloud providers. However, the vast majority of this work studies static models in which the access control policies being enforced do not change over time. This is contrary to the needs of most practical applications, which leverage dynamic data and/or policies. In this paper, we show that the cryptographic enforcement of dynamic access controls on untrusted platforms incurs computational costs that are likely prohibitive in practice. Specifically, we develop lightweight constructions for enforcing role-based access controls (i.e., RBAC0) over cloud-hosted files using identity-based and traditional public-key cryptography. This is done under a threat model as close as possible to the one assumed in the cryptographic literature. We prove the correctness of these constructions, and leverage real-world RBAC datasets and recent techniques developed by the access control community to experimentally analyze, via simulation, their associated computational costs. This analysis shows that supporting revocation, file updates, and other state change functionality is likely to incur prohibitive overheads in even minimally-dynamic, realistic scenarios. We identify a number of bottlenecks in such systems, and fruitful areas for future work that will lead to more natural and efficient constructions for the cryptographic enforcement of dynamic access controls. Our findings naturally extend to the use of more expressive cryptographic primitives (e.g., HIBE or ABE) and richer access control models (e.g., RBAC1 or ABAC). William C. Garrison III, Adam Shull, Steven Myers, Adam J. Lee |
IEEE Symposium on Security and Privacy | 4 |
| 2015 | Interrupt Now or Inform Later?: Comparing Immediate and Delayed Privacy FeedbackabstractFeedback about privacy-affecting system operations is important for informed end-user privacy management. While feedback is most relevant if provided immediately, such delivery interrupts the user and risks disrupting ongoing tasks. The timing, volume, and nature of feedback is therefore critical for avoiding inopportune interruption. We varied the timing and actionability of feedback regarding accesses to a user's physical location. We found that the sense of privacy violation was heightened when feedback was immediate, but not actionable. While immediate and actionable feedback may sometimes be necessary, our findings suggest that moderately delayed feedback is often acceptable. A moderate delay may serve as a compromise to minimize interruption and avoid overly alarming reaction to immediate feedback. However, immediate and actionable feedback could still be beneficial when privacy sensitivity is high or ambiguous. Sameer Patil 0001, Roberto Hoyle, Roman Schlegel, Apu Kapadia, Adam J. Lee |
CHI | 5 |
| 2015 | CryptStream: Cryptographic Access Controls for Streaming DataabstractWith data becoming available in larger quantities and at higher rates, new data processing paradigms have been proposed to handle large and fast data. Data Stream Processing is one such paradigm wherein transient data flows as streams through sets of continuous queries, only returning results when data is of interest to the querier, allowing uninteresting data to be ignored. To process these data streams, users are employing third party computational platforms or large private platforms to reduce the individual cost for querying and computing over data streams. Utilizing third parties for outsourcing computation means data being processed is available to the third party as well, which could violate the data provider's privacy. There has been research done into access control for streaming data, and these works provide a good first step, but fall short of a complete system. In this paper, we introduce CryptStream for cryptographically enforcing access controls over streaming data. CryptStream combines data providers access control policies with ones prescribed by the data consumer and the server as well. We show that CryptStream improves over earlier work in the same design space while providing smaller overheads and more flexibility. Cory Thoma, Adam J. Lee, Alexandros Labrinidis |
CODASPY | 2 |
| 2015 | Decomposing, Comparing, and Synthesizing Access Control Expressiveness SimulationsabstractAccess control is fundamental to computer security, and has thus been the subject of extensive formal study. In particular, relative expressiveness analysis techniques have used formal mappings called simulations to explore whether one access control system is capable of emulating another, thereby comparing the expressive power of these systems. Unfortunately, the notions of expressiveness simulation that have been explored vary widely, which makes it difficult to compare results in the literature, and even leads to apparent contradictions between results. Furthermore, some notions of expressiveness simulation make use of non-determinism, and thus cannot be used to define mappings between access control systems that are useful in practical scenarios. In this work, we define the minimum set of properties for an implementable access control simulation, i.e., a deterministic "recipe" for using one system in place of another. We then define a wide range of properties spread across several dimensions that can be enforced on top of this minimum definition. These properties define a taxonomy that can be used to separate and compare existing notions of access control simulation, many of which were previously incomparable. We position existing notions of simulation within our properties lattice by formally proving each simulation's equivalence to a corresponding set of properties. Lastly, we take steps towards bridging the gap between theory and practice by exploring the systems implications of points within our properties lattice. This shows that relative expressive analysis is more than just a theoretical tool, and can also guide the choice of the most suitable access control system for a specific application or scenario. William C. Garrison III, Adam J. Lee |
CSF | 2 |
| 2015 | You're where? prove it!: towards trusted indoor location estimation of mobile devicesabstractLocation-enabled applications now permeate the mobile computing landscape. As technologies like Bluetooth Low Energy (BLE) and Apple's iBeacon protocols begin to see widespread adoption, we will no doubt see a proliferation of indoor location enabled application experiences. While not essential to each of these applications, many will require that the location of the device be true and verifiable. In this paper, we present LocAssure, a new framework for trusted indoor location estimation. The system leverages existing technologies like BLE and iBeacons, making the solution practical and compatible with technologies that are already in use today. In this work, we describe our system, situate it within a broad location assurance taxonomy, describe the protocols that enable trusted localization in our system, and provide an analysis of early deployment and use characteristics. Through developer APIs, LocAssure can provide critical security support for a broad range of indoor location applications. Jacob T. Biehl, Adam J. Lee, Gerry Filby, Matthew Cooper 0002 |
UbiComp | 2 |
| 2015 | Interactive preference-aware query optimizationabstractPASQL is an extension to SQL that allows users of a distributed database to specify privacy constraints on an SQL query evaluation plan. However, privacy constraints can be difficult for users to specify, and worse yet, all possible situations that could lead to a privacy violation may not be known to the user a priori. To address these challenges, we propose a GUI-based interactive process for detecting such violations and generating appropriate constraints. In this work, we demonstrate two approaches to implementing such a GUI that provide different ways of analyzing and interactively optimizing a PASQL query plan. N. R. Ong, S. E. Rojcewicz, Nicholas L. Farnan, Adam J. Lee, Panos K. Chrysanthis, Ting Yu 0001 |
ICDE | 4 |
| 2015 | Human Mobility Computing and Privacy: Fad or Reality?abstractThe advent of mobile computing and sensing technologies, in conjunction with omni-present and high-speed mobile networks, allow nowadays the capture of human mobility data at an extremely high fidelity. Modern mobile computing services not only have the capacity to store spatio-temporal mobile data, these nowadays also have the capability to process incoming data in near-real time. As a result, we have a better chance to develop effective strategies and build intelligent systems that play critical roles in areas like public health, traffic engineering, urban planning and economic forecasting. On the other hand, detailed movement data often poses a threat to the privacy and security of users and companies, given that mobile devices are associated with real human custodians. One fundamental question is whether human mobility computing and privacy can co-exist under the same roof, given different cultural, religious, legal, technological and socio-economic backgrounds of societies. This panel will explore how the academia and industry are tackling human mobility computing and privacy challenges at a global scale. It will also identify and debate the key challenges and opportunities, in terms of applications, queries, architectures, to which the mobile data management community should contribute. Adam J. Lee, Konstantinos Pelechrinis, Demetris Zeinalipour |
MDM (2) | 1 |
| 2015 | CE-Storm: Confidential Elastic Processing of Data StreamsabstractData Stream Management Systems (DSMS) are crucial for modern high-volume/high-velocity data-driven applications, necessitating a distributed approach to processing them. In addition, data providers often require certain levels of confidentiality for their data, especially in cases of user-generated data, such as those coming out of physical activity/health tracking devices (i.e., our motivating application). This demonstration will showcase Synefo, an infrastructure that enables elastic scaling of DSMS operators, and CryptStream, a framework that provides confidentiality and access controls for data streams while allowing computation on untrusted servers, fused as CE-Storm. We will demonstrate both systems working in tandem and also visualize their behavior over time under different scenarios. Nikos R. Katsipoulakis, Cory Thoma, Eric A. Gratta, Alexandros Labrinidis, Adam J. Lee, Panos K. Chrysanthis |
SIGMOD Conference | 5 |
| 2014 | Reflection or action?: how feedback and control affect location sharing decisionsabstractOwing to the ever-expanding size of social and professional networks, it is becoming cumbersome for individuals to configure information disclosure settings. We used location sharing systems to unpack the nature of discrepancies between a person's disclosure settings and contextual choices. We conducted an experience sampling study (N = 35) to examine various factors contributing to such divergence. We found that immediate feedback about disclosures without any ability to control the disclosures evoked feelings of oversharing. Moreover, deviation from specified settings did not always signal privacy violation; it was just as likely that settings prevented information disclosure considered permissible in situ. We suggest making feedback more actionable or delaying it sufficiently to avoid a knee-jerk reaction. Our findings also make the case for proactive techniques for detecting potential mismatches and recommending adjustments to disclosure settings, as well as selective control when sharing location with socially distant recipients and visiting atypical locations. Sameer Patil 0001, Roman Schlegel, Apu Kapadia, Adam J. Lee |
CHI | 4 |
| 2014 | On the suitability of dissemination-centric access control systems for group-centric sharingabstractThe Group-centric Secure Information Sharing (g-SIS) family of models has been proposed for modeling environments in which group dynamics dictate information-sharing policies and practices. This is in contrast to traditional, dissemination-centric sharing models, which focus on attaching policies to resources that limit their flow from producer to consumer. The creators of g-SIS speculate that it may not be strictly more expressive than dissemination-centric models, but that it nevertheless has pragmatic efficiency advantages in group-centric scenarios [12]. In this paper, we formally and systematically test these characteristics of an access control system's suitability for a scenario - expressiveness and cost - to evaluate the capabilities of dissemination-centric systems within group-centric workloads. We show that several common dissemination-centric systems lack the expressiveness to meet all security guarantees while implementing the wide range of behavior that is characteristic of the g-SIS models, except via impractical, convoluted encodings. Further, even more efficient implementations (admissible under relaxed security requirements) suffer from high storage and computational overheads. These observations support the practical and theoretical significance of the g-SIS models, and provide insight into techniques for evaluating and comparing access control systems in terms of both expressiveness and cost. William C. Garrison III, Yechen Qiao, Adam J. Lee |
CODASPY | 3 |
| 2014 | PAQO: Preference-aware query optimization for decentralized database systemsabstractThe declarative nature of SQL has traditionally been a major strength. Users simply state what information they are interested in, and the database management system determines the best plan for retrieving it. A consequence of this model is that should a user ever want to specify some aspect of how their queries are evaluated (e.g., a preference to read data from a specific replica, or a requirement for all joins to be performed by a single server), they are unable to. This can leave database administrators shoehorning evaluation preferences into database cost models. Further, for distributed database users, it can result in query evaluation plans that violate data handling best practices or the privacy of the user. To address such issues, we have developed a framework for declarative, user-specified constraints on the query optimization process and implemented it within PosgreSQL. Our Preference-Aware Query Optimizer (PAQO) upholds both strict requirements and partially ordered preferences that are issued alongside of the queries that it processes. In this paper, we present the design of PAQO and thoroughly evaluate its performance. Nicholas L. Farnan, Adam J. Lee, Panos K. Chrysanthis, Ting Yu 0001 |
ICDE | 2 |
| 2014 | An actor-based, application-aware access control evaluation frameworkabstractTo date, most work regarding the formal analysis of access control schemes has focused on quantifying and comparing the expressive power of a set of schemes. Although expressive power is important, it is a property that exists in an *absolute* sense, detached from the application context within which an access control scheme will ultimately be deployed. By contrast, we formalize the access control *suitability analysis problem*, which seeks to evaluate the degree to which a set of candidate access control schemes can meet the needs of an application-specific workload. This process involves both reductions to assess whether a scheme is *capable* of implementing a workload (qualitative analysis), as well as cost analysis using ordered measures to quantify the *overheads* of using each candidate scheme to service the workload (quantitative analysis). We formalize the two-facet suitability analysis problem, which formally describes this task. We then develop a mathematical framework for this type of analysis, and evaluate this framework both formally, by quantifying its efficiency and accuracy properties, and practically, by exploring an academic program committee workload. William C. Garrison III, Adam J. Lee, Timothy L. Hinrichs |
SACMAT | 2 |
| 2014 | Private aggregation for presence streams
Eleanor Gilbert Rieffel, Jacob T. Biehl, Adam J. Lee, William van Melle |
Future Gener. Comput. Syst. | 3 |
| 2014 | Balancing Performance, Accuracy, and Precision for Secure Cloud TransactionsabstractIn distributed transactional database systems deployed over cloud servers, entities cooperate to form proofs of authorizations that are justified by collections of certified credentials. These proofs and credentials may be evaluated and collected over extended time periods under the risk of having the underlying authorization policies or the user credentials being in inconsistent states. It therefore becomes possible for policy-based authorization systems to make unsafe decisions that might threaten sensitive resources. In this paper, we highlight the criticality of the problem. We then define the notion of trusted transactions when dealing with proofs of authorization. Accordingly, we propose several increasingly stringent levels of policy consistency constraints, and present different enforcement approaches to guarantee the trustworthiness of transactions executing on cloud servers. We propose a Two-Phase Validation Commit protocol as a solution, which is a modified version of the basic Two-Phase Validation Commit protocols. We finally analyze the different approaches presented using both analytical evaluation of the overheads and simulations to guide the decision makers to which approach to use. Marian Kamal Iskander, Tucker Trainor, Dave W. Wilkinson, Adam J. Lee, Panos K. Chrysanthis |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2013 | Insured access: an approach to ad-hoc information sharing for virtual organizationsabstractA virtual organization (VO) is a group of organizations that have banded together to achieve a common goal. Often a VO could function more effectively if its members were willing to share certain information. However, a typical VO member will not want to share its own information because the member will not benefit directly from the information's reuse, yet will be blamed if the reuse turns out badly. Naoki Tanaka, Marianne Winslett, Adam J. Lee, David K. Y. Yau, Feng Bao 0001 |
CODASPY | 3 |
| 2013 | Application-Sensitive Access Control Evaluation Using Parameterized ExpressivenessabstractAccess control schemes come in all shapes and sizes, which makes choosing the right one for a particular application a challenge. Yet today's techniques for comparing access control schemes completely ignore the setting in which the scheme is to be deployed. In this paper, we present a formal framework for comparing access control schemes with respect to a particular application. The analyst's main task is to evaluate an access control scheme in terms of how well it implements a given access control workload (a formalism that we introduce to represent an application's access control needs). One implementation is better than another if it has stronger security guarantees, and in this paper we introduce several such guarantees: correctness, homomorphism, AC-preservation, safety, administration-preservation, and compatibility. The scheme that admits the implementation with the strongest guarantees is deemed the best fit for the application. We demonstrate the use of our framework by evaluating two workloads on ten different access control schemes. Timothy L. Hinrichs, Diego Martinoia, William C. Garrison III, Adam J. Lee, Alessandro Panebianco, Lenore D. Zuck |
CSF | 4 |
| 2013 | Combining social authentication and untrusted clouds for private location sharingabstractRecently, many location-sharing services (LSSs) have emerged that share data collected using mobile devices. However, research has shown that many users are uncomfortable with LSS operators managing their location histories, and that the ease with which contextual data can be shared with unintended audiences can lead to regrets that sometimes outweigh the benefits of these systems. In an effort to address these issues, we have developed SLS: a secure location sharing system that combines location-limited channels, multi-channel key establishment, and untrusted cloud storage to hide user locations from LSS operators while also limiting unintended audience sharing. In addition to describing the key agreement and location-sharing protocols used by SLS, we discuss an iOS implementation of SLS that enables location sharing at tunable granularity through an intuitive policy interface on the user's mobile device. Andrew K. Adams, Adam J. Lee |
SACMAT | 2 |
| 2013 | Enabling intensional access control via preference-aware query optimizationabstractAlthough the declarative nature of SQL provides great utility to database users, its use in distributed database management systems can result in unintended consequences to user privacy over the course of query evaluation. By allowing users to merely say what data they are interested in accessing without providing guidance regarding how to retrieve it, query optimizers can generate plans that leak sensitive query intension. To address these types of issues, we have created a framework that empowers users with the ability to specify access controls on the intension of their queries through extensions to the SQL SELECT statement. In this demonstration, we present a version of PostgreSQL's query optimizer that we have modified to produce plans that respect these constraints while optimizing user-specified SQL queries in terms of performance. Nicholas L. Farnan, Adam J. Lee, Panos K. Chrysanthis, Ting Yu 0001 |
SACMAT | 2 |
| 2013 | Bounding Trust under Uncertain Topology Information in Reputation-Based Trust Systems
Xi Gong, Ting Yu 0001, Adam J. Lee |
WAIM | 3 |
| 2013 | When privacy and utility are in harmony: towards better design of presence technologies
Jacob T. Biehl, Eleanor Gilbert Rieffel, Adam J. Lee |
Pers. Ubiquitous Comput. | 3 |
| 2013 | PAQO: A Preference-Aware Query Optimizer for PostgreSQLabstractAlthough the declarative nature of SQL provides great utility to database users, its use in distributed database management systems can leave users unaware of which servers in the system are evaluating portions of their queries. By allowing users to merely say what data they are interested in accessing without providing guidance regarding how to retrieve it, query optimizers can generate plans with unintended consequences to the user (e.g., violating user privacy by revealing sensitive portions of a user's query to untrusted servers, or impacting result freshness by pulling data from stale data stores). To address these types of issues, we have created a framework that empowers users with the ability to specify constraints on the kinds of plans that can be produced by the optimizer to evaluate their queries. Such constraints are specified through an extended version of SQL that we have developed which we call PASQL. With this proposal, we aim to demonstrate PAQO, a version of PostgreSQL's query optimizer that we have modified to produce plans that respect constraints specified through PASQL while optimizing user-specified SQL queries in terms of performance. Nicholas L. Farnan, Adam J. Lee, Panos K. Chrysanthis, Ting Yu 0001 |
Proc. VLDB Endow. | 2 |
| 2012 | Bounding trust in reputation systems with incomplete informationabstractReputation mechanisms represent a major class of techniques for managing trust in decentralized systems. Quite a few reputation-based trust functions have been proposed in the literature for use in many different application domains. However, in many situations, one cannot always obtain all of the information required by the trust evaluation process. For example, access control restrictions or high collection costs might limit one's ability to gather every possible feedback that could be aggregated. Thus, one key question is how to analytically quantify the quality of reputation scores computed using incomplete information. Xi Gong, Ting Yu 0001, Adam J. Lee |
CODASPY | 3 |
| 2012 | Confidentiality-preserving and fault-tolerant in-network aggregation for Collaborative WSNsabstractIn Collaborative WSNs, sensing devices are owned and operated by different stakeholders with incentive to preserve the confidentiality of their individual sensors readings while contributing to statistics computed by the group. In this paper, we present and analyze a new protocol that allows for con Marian Kamal Iskander, Adam J. Lee, Daniel Mossé |
CollaborateCom | 2 |
| 2012 | The need for application-aware access control evaluationabstractAccess control is an area where one size does not fit all. However, previous work in access control has focused solely on expressiveness as an absolute measure. Thus, we discuss and justify the need for a new type of evaluation framework for access control, one that is application-aware. To this end, we apply previous work in access control evaluation, as well as lessons learned from evaluation frameworks used in other domains. We describe the analysis components required by such a framework, the challenges involved in building it, and our preliminary work in realizing this ambitious goal. We then theorize about other areas within the security domain that display a similar absence of such evaluation tools, and consider ways in which we can adapt our framework to analyze these broader types of security workloads. William C. Garrison III, Adam J. Lee, Timothy L. Hinrichs |
NSPW | 2 |
| 2012 | PlexC: a policy language for exposure controlabstractWith the widespread use of online social networks and mobile devices, it is not uncommon for people to continuously broadcast contextual information such as their current location or activity. These technologies present both new opportunities for social engagement and new risks to privacy, and traditional static "write once" disclosure policies are not well suited for controlling aggregate exposure risks in the current technological landscape. Yann Le Gall, Adam J. Lee, Apu Kapadia |
SACMAT | 2 |
| 2012 | Reasons, rewards, regrets: privacy considerations in location sharing as an interactive practiceabstractRapid growth in the usage of location-aware mobile phones has enabled mainstream adoption of location-sharing services (LSS). Integration with social-networking services (SNS) has further accelerated this trend. To uncover how these developments have shaped the evolution of LSS usage, we conducted an online study (N = 362) aimed at understanding the preferences and practices of LSS users in the US. We found that the main motivations for location sharing were to connect and coordinate with one's social and professional circles, to project an interesting image of oneself, and to receive rewards offered for 'checking in.' Respondents overwhelmingly preferred sharing location only upon explicit action. More than a quarter of the respondents recalled at least one instance of regret over revealing their location. Our findings suggest that privacy considerations in LSS are affected due to integration within SNS platforms and by transformation of location sharing into an interactive practice that is no longer limited only to finding people based on their whereabouts. We offer design suggestions, such as delayed disclosure and conflict detection, to enhance privacy-management capabilities of LSS. Sameer Patil 0001, Gregory Norcie, Apu Kapadia, Adam J. Lee |
SOUPS | 4 |
| 2011 | Receipt-mode trust negotiation: efficient authorization through outsourced interactionsabstractIn trust negotiation approaches to authorization, previously unacquainted entities establish trust in one another gradually via the bilateral and iterative exchange of policies and digital credentials. Although this affords resource providers with an expressive means of access control for open systems, the trust negotiation process incurs non-trivial computational and communications costs. In this paper, we propose Receipt-Mode Trust Negotiation (RMTN) as a means of mitigating the performance penalties on servers that use trust negotiation. RMTN provides a means of off-loading the majority of the trust negotiation process to delegated receipt-generating helper servers. RMTN ensures that helpers produce correct trust negotiation protocol receipts, and that the helpers are incapable of impersonating the resource server outside of the RMTN protocol. We describe an initial implementation of our RMTN protocol on a Linux testbed, discuss the security of this protocol, and present experimental results indicating that the receipt-mode protocol does indeed enhance the performance of resource servers that rely on trust negotiation approaches to authorization. Andrew K. Adams, Adam J. Lee, Daniel Mossé |
AsiaCCS | 2 |
| 2011 | Poster: on trust evaluation with missing information in reputation systems
Xi Gong, Ting Yu 0001, Adam J. Lee |
CCS | 3 |
| 2011 | Confidentiality-preserving proof theories for distributed proof systemsabstractA distributed proof system is an effective way for deriving useful information by combining data from knowledge bases managed by multiple different principals across different administrative domains. As such, many researchers have proposed using these types of systems as a foundation for distributed authorization and trust management in decentralized systems. However, to account for the potentially sensitive nature of the underlying information, it is important that such proof systems be able to protect the confidentiality of the logical facts and statements. Kazuhiro Minami, Nikita Borisov, Marianne Winslett, Adam J. Lee |
AsiaCCS | 4 |
| 2011 | Don't Reveal My Intension: Protecting User Privacy Using Declarative Preferences during Distributed Query Processing
Nicholas L. Farnan, Adam J. Lee, Panos K. Chrysanthis, Ting Yu 0001 |
ESORICS | 2 |
| 2011 | Eyeing your exposure: quantifying and controlling information sharing for improved privacyabstractA large body of research has focused on disclosure policies for controlling information release in social sharing (e.g., location-based) applications. However, less work has considered how exposed these policies actually leave users; i.e., to what extent are disclosures in compliance with these policies actually being made? For instance, consider a disclosure policy granting Alice's coworkers access to her location during work hours. Alice might feel that this policy appropriately controls her exposure, but may feel differently if she learned that her boss was accessing her location every 5 minutes. In addition to specifying who has access to personal information, users need a way to quantify, interpret, and control the extent to which this data is shared. Roman Schlegel, Apu Kapadia, Adam J. Lee |
SOUPS | 3 |
| 2010 | Privacy and robustness for data aggregation in wireless sensor networksabstractposter Share on Privacy and robustness for data aggregation in wireless sensor networks Authors: Marian Kamal Iskander University of Pittsburgh, Pittsburgh, PA, USA University of Pittsburgh, Pittsburgh, PA, USAView Profile , Adam J. Lee University of Pittsburgh, Pittsburgh, PA, USA University of Pittsburgh, Pittsburgh, PA, USAView Profile , Daniel Moss é University of Pittsburgh, Pittsburgh, PA, USA University of Pittsburgh, Pittsburgh, PA, USAView Profile Authors Info & Claims CCS '10: Proceedings of the 17th ACM conference on Computer and communications securityOctober 2010Pages 699–701https://doi.org/10.1145/1866307.1866402Published:04 October 2010Publication History 1citation472DownloadsMetricsTotal Citations1Total Downloads472Last 12 Months7Last 6 weeks1 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Marian Kamal Iskander, Adam J. Lee, Daniel Mossé |
CCS | 2 |
| 2010 | Effective trust management through a hybrid logical and relational approachabstractDespite a plethora of recent research regarding trust management approaches to authorization, relatively little attention has been given to exactly how these technologies can be effectively deployed. In this paper, we investigate one way in which well-established logical trust management systems described in the literature can be deployed within enterprise environments. Specifically, we develop a framework within which logical trust management policies can be managed using a relational DBMS. We describe a correct and complete procedure for compiling CTM credentials into dynamic views within a database, and show how the resulting system can be used to perform role membership checks or to enumerate the members of a given role. We then propose a hybrid algorithm that leverages the logical ruleset and the underlying DBMS to efficiently enumerate the capabilities ascribed to a given user. We also present an evaluation of a prototype implementation of our framework that demonstrates the practicality of our approach. As CTM extends the RT family of trust management languages---which are representative of a large class of Datalog-based trust management systems---our work is likely generalizable to other trust management approaches. Adam J. Lee, Ting Yu 0001, Yann Le Gall |
AsiaCCS | 1 |
| 2010 | Oblivious enforcement of hidden information release policiesabstractIn a computing system, sensitive data must be protected by release policies that determine which principals are authorized to access that data. In some cases, such a release policy could refer to information about the requesting principal that is unavailable to the information provider. Furthermore, the release policy itself may contain sensitive information about the resource that it protects. In this paper we describe a scheme for enforcing information release policies whose satisfaction cannot be verified by the entity holding the protected information, but only by the entity requesting this information. Not only does our scheme prevent the information provider from learning whether the policy was satisfied, but it also hides the information release policy being enforced from the requesting principal. Unlike previous approaches, our construction requires no guesswork or wasted computation on the part of the information requester. The information release policies that we consider can contain third-party assertions that themselves have release conditions that must be satisfied; we show that our system functions correctly even when these dependencies form cycles. Brian Wongchaowart, Adam J. Lee |
AsiaCCS | 2 |
| 2010 | Towards Quantitative Analysis of Proofs of Authorization: Applications, Framework, and TechniquesabstractAlthough policy compliance testing is generally treated as a binary decision problem, the evidence gathered during the trust management process can actually be used to examine these outcomes within a more continuous space. In this paper, we develop a formal model that allows us to quantitatively reason about the outcomes of the policy enforcement process in both absolute (i.e., user to ideal case) and relative (i.e., user to user) terms. Within this framework, it becomes possible to quantify, e.g., the robustness of a user's proof of authorization to possible perturbations in the system, how close an unauthorized user is to satisfying a particular policy, and relative “top-k” style rankings of the best users to carry out a particular task. To this end, we explore several interesting classes of scoring functions for assessing the robustness of authorization decisions, and develop criteria under which these types of functions can be composed with one another. We further show that these types of functions can be extended to quantify how close unauthorized users are to satisfying policies, which can be a useful risk metric for decision making under unexpected circumstances. Adam J. Lee, Ting Yu 0001 |
CSF | 1 |
| 2010 | Solving the access-control puzzle: finding the pieces and putting them togetherabstractNo abstract available. Lujo Bauer, Adam J. Lee |
SACMAT | 2 |
| 2010 | On the consistency of distributed proofs with hidden subtreesabstractPrevious work has shown that distributed authorization systems that fail to sample a consistent snapshot of the underlying system during policy evaluation are vulnerable to a number of attacks. Unfortuantely, the consistency enforcement solutions presented in previous work were designed for systems in which only CA-certified evidence is used during the decision-making process, all of which is available to the decision-making node at runtime. In this article, we generalize previous results and present light-weight mechanisms through which consistency constraints can be enforced in proof systems in which the full details of a proof may be unavailable to the querier due to information release policies, and the existence of certificate authorities for certifying evidence is unlikely; these types of distributed proof systems are likely candidates for use in pervasive computing and sensor network environments. We present modifications to one such distributed proof system that enable three types of consistency constraints to be enforced while still respecting the same confidentiality and integrity policies as the original proof system. We then discuss how these techniques can be adapted and applied to other, less restrictive, distributed proof systems. Further, we detail a performance analysis that illustrates the modest overheads of our consistency enforcement schemes. Adam J. Lee, Kazuhiro Minami, Marianne Winslett |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2009 | Confidentiality-preserving distributed proofs of conjunctive queriesabstractDistributed proof construction protocols have been shown to be valuable for reasoning about authorization decisions in open distributed environments such as pervasive computing spaces. Unfortunately, existing distributed proof protocols offer only limited support for protecting the confidentiality of sensitive facts, which limits their utility in many practical scenarios. In this paper, we propose a distributed proof construction protocol in which the release of a fact's truth value can be made contingent upon facts managed by other principals in the system. We formally prove that our protocol can safely prove conjunctions of facts without leaking the truth values of individual facts, even in the face of colluding adversaries and fact release policies with cyclical dependencies. This facilitates the definition of context-sensitive release policies that enable the conditional use of sensitive facts in distributed proofs. Adam J. Lee, Kazuhiro Minami, Nikita Borisov |
AsiaCCS | 1 |
| 2009 | Towards a dynamic and composable model of trustabstractDuring their everyday decision making, humans consider the interplay between two types of trust: vertical trust and horizontal trust. Vertical trust captures the trust relationships that exist between individuals and institutions, while horizontal trust represents the trust that can be inferred from the observations and opinions of others. Although researchers are actively exploring both vertical and horizontal trust within the context of distributed computing (e.g., credential-based trust and reputation-based trust, respectively), the specification and enforcement of composite trust management policies involving the flexible composition of both types of trust metrics is currently an unexplored area. Adam J. Lee, Ting Yu 0001 |
SACMAT | 1 |
| 2008 | Towards an efficient and language-agnostic compliance checker for trust negotiation systemsabstractTo ensure that a trust negotiation succeeds whenever possible, authorization policy compliance checkers must be able to find all minimal sets of their owners' credentials that can be used to satisfy a given policy. If all of these sets can be found efficiently prior to choosing which set should be disclosed, many strategic benefits can also be realized. Unfortunately, solving this problem using existing compliance checkers is too inefficient to be useful in practice. Specifically, the overheads of finding all satisfying sets using existing approaches have been shown to rapidly grow exponentially in the size of the union of all satisfying sets of credentials for the policy, even after optimizations have been made to prune the search space for potential satisfying sets. Adam J. Lee, Marianne Winslett |
AsiaCCS | 1 |
| 2008 | Enforcing Safety and Consistency Constraints in Policy-Based Authorization SystemsabstractIn trust negotiation and other forms of distributed proving, networked entities cooperate to form proofs of authorization that are justified by collections of certified attribute credentials. These attributes may be obtained through interactions with any number of external entities and are collected and validated over an extended period of time. Although these collections of credentials in some ways resemble partial system snapshots, current trust negotiation and distributed proving systems lack the notion of a consistent global state in which the satisfaction of authorization policies should be checked. In this article, we argue that unlike the notions of consistency studied in other areas of distributed computing, the level of consistency required during policy evaluation is predicated solely upon the security requirements of the policy evaluator. As such, there is little incentive for entities to participate in complicated consistency preservation schemes like those used in distributed computing, distributed databases, and distributed shared memory. We go on to show that the most intuitive notion of consistency fails to provide basic safety guarantees under certain circumstances and then propose several more refined notions of consistency that provide stronger safety guarantees. We provide algorithms that allow each of these refined notions of consistency to be attained in practice with minimal overheads and formally prove several security and privacy properties of these algorithms. Lastly, we explore the notion of strategic design trade-offs in the consistency enforcement algorithm space and propose several modifications to the core algorithms presented in this article. These modifications enhance the privacy-preservation or completeness properties of these algorithms without altering the consistency constraints that they enforce. Adam J. Lee, Marianne Winslett |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2008 | The Traust Authorization ServiceabstractIn recent years, trust negotiation has been proposed as a novel authorization solution for use in open-system environments, in which resources are shared across organizational boundaries. Researchers have shown that trust negotiation is indeed a viable solution for these environments by developing a number of policy languages and strategies for trust negotiation that have desirable theoretical properties. Further, existing protocols, such as TLS, have been altered to interact with prototype trust negotiation systems, thereby illustrating the utility of trust negotiation. Unfortunately, modifying existing protocols is often a time-consuming and bureaucratic process that can hinder the adoption of this promising technology. In this paper, we present Traust, a third-party authorization service that leverages the strengths of existing prototype trust negotiation systems. Traust acts as an authorization broker that issues access tokens for resources in an open system after entities use trust negotiation to satisfy the appropriate resource access policies. The Traust architecture was designed to allow Traust to be integrated either directly with newer trust-aware applications or indirectly with existing legacy applications; this flexibility paves the way for the incremental adoption of trust negotiation technologies without requiring widespread software or protocol upgrades. We discuss the design and implementation of Traust, the communication protocol used by the Traust system, and its performance. We also discuss our experiences using Traust to broker access to legacy resources, our proposal for a Traust-aware version of the GridFTP protocol, and Traust's resilience to attack. Adam J. Lee, Marianne Winslett, Jim Basney, Von Welch |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2007 | Lightweight cnsistency enforcement schemes for distributed proofs with hidden subtreesabstractIn distributed proof construction systems, information release policies can make it unlikely that any single node in the system is aware of the complete structure of any particular proof tree. This property makes it difficult for queriers to determine whether the proofs constructed using these protocols sampled a consistent snapshot of the system state; this has previously been shown to have dire consequences in decentralized authorization systems. Unfortunately, the consistency enforcement solutions presented in previous work were designed for systems in which only information encoded in certificates issued by certificate authorities is used during the decision-making process. Further, they assume that each piece of certified evidence used during proof construction is available to the decision-making node at runtime. Adam J. Lee, Kazuhiro Minami, Marianne Winslett |
SACMAT | 1 |
| 2006 | Safety and consistency in policy-based authorization systemsabstractIn trust negotiation and other distributed proving systems, networked entities cooperate to form proofs that are justi?ed by collections of certi?ed attributes. These attributes may be obtained through interactions with any number of external entities and are collected and validated over an extended period of time. Though these collections of credentials in some ways resemble partial system snapshots,these systems currently lack the notion of a consistent global state in which the satisfaction of authorization policies should be checked. In this paper, we argue that unlike the notions of consistency studied in other areas of distributed computing, the level of consistency required during policy evaluation is predicated solely upon the security requirements of the policy evaluator. As such,there is little incentive for entities to participate in complicated consistency preservation schemes like those used in distributed computing,distributed databases, and distributed shared memory. We go on to show that the most intuitive notion of consistency fails to provide basic safety guarantees under certain circumstances and then propose several more refined notions of consistency which provide stronger safety guarantees. We provide algorithms that allow each of these re ?ned notions of consistency to be attained in practice with minimal overheads. Adam J. Lee, Marianne Winslett |
CCS | 1 |
| 2006 | Traust: a trust negotiation-based authorization service for open systemsabstractIn recent years, trust negotiation (TN) has been proposed as a novel access control solution for use in open system environments in which resources are shared across organizational boundaries. Researchers have shown that TN is indeed a viable solution for these environments by developing a number of policy languages and strategies for TN which have desirable theoretical properties. Further, existing protocols, such as TLS, have been altered to interact with prototype TN systems, thereby illustrating the utility of TN. Unfortunately, modifying existing protocols is often a time-consuming and bureaucratic process which can hinder the adoption of this promising technology.In this paper, we present Traust, a third-party authorization service that leverages the strengths of existing proto-type TN systems. Traust acts as an authorization broker that issues access tokens for resources in an open system after entities use TN to satisfy the appropriate resource access policies. The Traust architecture was designed to allow Traust to be integrated either directly with newer trust-aware applications or indirectly with existing legacy applications; this exibility paves the way for the incremental adoption of TN technologies without requiring widespread software or protocol upgrades. We discuss the design and implementation of Traust, the communication protocol used by the Traust system, and its performance. We also discuss our experiences using Traust to broker access to legacy resources, our proposal for a Traust-aware version of the GridFTP protocol, and Traust's resilience to attack. Adam J. Lee, Marianne Winslett, Jim Basney, Von Welch |
SACMAT | 1 |
| 2005 | Cluster security with NVisionCC: process monitoring by leveraging emergent propertiesabstractWe have observed that supercomputing clusters made up of commodity off-the-shelf computers possess emergent properties that are apparent when these systems are considered as an indivisible entity rather than as a collection of independent nodes. By exploiting predicatable characteristics inherent to supercomputing clusters coupled with these emergent properties, we propose several mechanisms by which cluster security may be enhanced. In this paper, we describe NVisionCC, a cluster security tool that monitors processes across cluster nodes and raises alerts when deviations from a predefined profile of expected processes are noted. Additionally, we demonstrate that the monitoring infrastructure used by NVisionCC incurs a negligible performance penalty on the computational and network resources of the cluster. Gregory A. Koenig, Adam J. Lee, Michael Treaster, Nadir Kiyanclar, William Yurcik |
CCGRID | 3 |
| 2005 | Searching for open windows and unlocked doors: port scanning in large-scale commodity clustersabstractCurrent methods for monitoring the security of large-scale commodity clusters tend to treat these clusters as nothing more than collections of independent nodes. As such, the techniques used to secure these clusters have, for the most part, been adaptations of techniques developed for securing and monitoring enterprise computing environments. We have previously proposed the idea of monitoring the security-state of large-scale commodity clusters by examining their emergent properties, that is, properties that are only visible when one ceases to look at a cluster as a collection of disparate nodes and begins to look at the properties of the cluster as a whole. We show that by correlating the open network ports observed on cluster nodes with other emergent properties - such as active processes and the contents of important system files - security analysts can make insightful observations that can greatly restrict the actions that an attacker can carry out undetected. Adam J. Lee, Gregory A. Koenig, William Yurcik |
CCGRID | 1 |
| 2004 | NVisionIP: netflow visualizations of system state for security situational awarenessabstractThe number of attacks against large computer systems is currently growing at a rapid pace. Despite the best efforts of security analysts, large organizations are having trouble keeping on top of the current state of their networks. In this paper, we describe a tool called NVisionIP that is designed to increase the security analyst's situational awareness. As humans are inherently visual beings, NVisionIP uses a graphical representation of a class-B network to allow analysts to quickly visualize the current state of their network. We present an overview of NVisionIP along with a discussion of various types of security-related scenarios that it can be used to detect. Kiran Lakkaraju, William Yurcik, Adam J. Lee |
VizSEC | 3 |