Ryan Kok Leong Ko

dblp:75/11480 · also Ryan K. L. Ko · DBLP profile ↗
← Back
45ranked-venue papers
9as first author
21since 2021 · last 2026
0000-0003-0804-1176ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 2 first-author · 8 since 2021Software engineering, systems software and programming languages · 7 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 SoK: Navigating the Privacy-UX Trade-offs in Extended Reality (XR) - A Socio-Technical Taxonomy and Research Roadmap
Shunyao Wang, Mahawaga Arachchige Pathum Chamikara, Mohan Baruwal Chhetri, Zhenchang Xing, Ryan Kok Leong Ko
AsiaCCS5
2026 Multi-agent reinforcement curriculum learning for real unmanned ground vehicles
abstract
This paper investigates the use of deep reinforcement learning (DRL) for the control of mobile robot teams within the context of navigation and task-based collaborative scenarios. We apply a DRL policy with a tailored neural network architecture as a solution to control, path planning, and higher-level guidance tasks. Our network architecture was trained using a unique multi-stage curriculum that progresses from single-agent navigation, to multi-agent pathfinding with obstacles, and finally to a complex collaborative firefighting scenario. This structured approach accelerates training convergence by systematically building sophisticated collaborative behaviours upon foundational skills, which enhances training stability and guides the agents towards learning effective and coordinated strategies The policy evaluation was conducted in both simulation and hybrid simulation-physical demonstrations utilising a real unmanned ground vehicle (UGV). The policy presented is capable of achieving multi-agent navigation tasks with a 95.83% accuracy in our testing environments, and has demonstrated emergent multi-agent behaviours. In more complex collaborative firefighting scenarios, the policy also demonstrated superior performance than baselines in reaching goals, e.g., navigating and extinguishing two fires with a 99.67% success rate, suggesting its strong potential for real-world deployment.
Timothy Mead, Zhe Wang 0001, Ernest Foo, Jin Song Dong 0001, Naipeng Dong, Ryan Kok Leong Ko, Abigail M. Y. Koay, Kien Nguyen Thanh, Yue Xu 0001, Junae Kim, Stephen Bornstein
Eng. Appl. Artif. Intell.6
2026 SEED: A Minimal‑Footprint TEE Framework for Verifiable, Confidential Microservice Deployment
abstract
We present SEED, a system that enables the deployment of distributed privacy-preserving micro-services in the cloud while maintaining the secrecy of user code and data and ensuring correct, complete results. Unlike prior approaches that minimize the TCB by pushing large parts of the software stack outside the enclave, SEED includes the entire container software stack—from the application layer up to the operating system—inside the TCB. This holistic design protects proprietary software, datasets, and optional ML models from exposure; prevents leakage of sensitive inputs or queries; and thwarts metadata-inference attacks that could reveal workload identity or versioning. Yet we achieve an optimized TCB (22 MB in total), over 30× smaller than the typical 690 MB TCB for confidential privacy-enhancing VMs. In practice, SEED runs on AMD SEV-SNP–capable machines and supports real container workloads (i.e., TensorFlow, OpenVINO inference, PyTorch training, Redis, NGINX, Apache httpd). We demonstrate that SEEDCore matches or outperforms mainstream runtime workload deployment, staying within 5% of native throughput and reaching up to 6× higher performance on CPU-bound jobs. Finally, we conduct a thorough privacy and security evaluation against 11 cloud attack vectors and show that SEED blocks or confines every exploit that remains possible even under the state-of-the-art Gramine-TDX model, thanks to late binding, per-container PCR chains, and continuous in-TEE attestation throughout the workload’s lifetime.
Omar Jarkas, Ryan Kok Leong Ko, Naipeng Dong, Md. Redowan Mahmud
Proc. Priv. Enhancing Technol.2
2025 Practical Poisoning Attacks with Limited Byzantine Clients in Clustered Federated Learning
abstract
The presence of non-independent and identically distributed (non-IID) data among clients poses a critical challenge to the deployment of Federated Learning (FL) in practice. In response, state-of-the-art solutions known as Clustered Federated Learning (CFL) schemes, such as FL+HC and PACFL, have emerged to tackle this issue. Their main innovation is to cluster non-IID clients into groups of IID clients, such that techniques designated for IID scenarios can be easily applicable. Nonetheless, the robustness of CFL schemes remains largely unexplored, and existing Byzantine-robust defence mechanisms prove inadequate in CFL schemes and non-IID data settings. In this work, we present novel powerful CFL-specific poisoning attacks, named Cluster-U-M and Cluster-U-D. These attacks are designed to significantly reduce the model utility, measured in terms of test accuracy, for benign clients participating in the CFL schemes. Notably, these attacks remain agnostic, requiring no adversarial knowledge regarding defense solutions and benign clients themselves. At a high level, the attacks involve two steps, including cluster poisoning attacks and client-drift exploitation within clusters. The former induces the grouping of clients with different training distributions, and the latter amplifies the difference between each client's optimum and their group's average aggregation. We extensively evaluate the impact of these attacks using FL+HC and PACFL schemes on both small and large scales. The evaluation results demonstrate that the attacks can compromise up to 54% of clients, with a maximum accuracy loss of 48%. Even with only 0.1% clients compromised, which represents a minimal practical adversarial effort, these attacks can still victimize around 4% clients. We evaluate the effectiveness of two state-of-the-art Byzantine-robust defence mechanisms, i.e., FLTrust and FLAME, in countering Cluster-U-M and Cluster-U-D, and find that the attacks can victimize up to 38% of clients with an accuracy loss of 18-38% under the FL+HC scheme.
Viet Vo, Mengyao Ma, Guangdong Bai, Ryan Kok Leong Ko, Surya Nepal
SP4
2025 Contrasting the optimal resource allocation to cybersecurity controls and cyber insurance using prospect theory versus expected utility theory
abstract
Protecting against cyber-threats is essential for every organization and can be achieved by investing in cybersecurity controls and purchasing cyber insurance. These two alternatives are interlinked, as insurance premiums can be reduced by investing more in cybersecurity controls. However, cyber insurance remains under-utilized, a puzzle that Expected Utility Theory (EUT) cannot explain. In this paper, we analyze how decision-makers allocate resources between cybersecurity controls and cyber insurance, comparing optimal allocation under Prospect Theory (PT) to that under EUT. We propose a new functional form of risk curves to model the relationship between investment in cybersecurity controls and cyber risk , demonstrating how a bespoke risk curve can be fitted for an organization. We derive the optimal allocation strategy of resources to cybersecurity controls and cyber insurance under EUT and PT paradigms. Using mathematical results and numerical examples, we identify specific behavioral considerations in PT that lead to different resource allocations compared to EUT. We show that decision-makers aligned with EUT are generally indifferent to purchasing insurance, whereas those aligned with PT favor full insurance coverage; otherwise, they invest more in self-protection. Our results indicate that, in addition to a challenging cybersecurity environment and the nature of insurance coverage, behavioral aspects (diminished sensitivity to losses and probability weights) play a key role in determining the optimal level of investment in cybersecurity.
Chaitanya Joshi, Sergeja Slapnicar, Ryan Kok Leong Ko
Comput. Secur.4
2025 Adapting to the stream: an instance-attention GNN method for irregular multivariate time series data
abstract
Abstract Multivariate time series (MTS) data are vital for various applications, particularly in machine learning tasks. However, challenges such as sensor failures can result in irregular and misaligned data with missing values, thereby complicating their analysis. While recent advancements use graph neural networks (GNNs) to manage these Irregular Multivariate Time Series (IMTS) data, they generally require a reliable graph structure, either pre-existing or inferred from adequate data to properly capture node correlations. This poses a challenge in applications where IMTS data are often streamed and waiting for future data to estimate a suitable graph structure becomes impractical. To overcome this, we introduce a dynamic GNN model suited for streaming characteristics of IMTS data, incorporating an instance-attention mechanism that dynamically learns and updates graph edge weights for realtime analysis. We also tailor strategies for high-frequency and low-frequency data to enhance prediction accuracy. Empirical results on real-world datasets demonstrate the superiority of our proposed model in both classification and imputation tasks.
Abigail M. Y. Koay, Ryan Kok Leong Ko, Weitong Chen 0001, Miao Xu 0001
Frontiers Comput. Sci.3
2024 Scp-bp Framework: Situational Crime Prevention for Managing Data Breaches in Business Processes
Cheng Miao, Heemeng Ho, Elinor Tsen, John Gilmour, Ryan Kok Leong Ko
BPM5
2024 Privacy-Preserving and Fairness-Aware Federated Learning for Critical Infrastructure Protection and Resilience
abstract
The energy industry is undergoing significant transformations as it strives to achieve net-zero emissions and future-proof its infrastructure, where every participant in the power grid has the potential to both consume and produce energy resources. Federated learning -- which enables multiple participants to collaboratively train a model without aggregating the training data -- becomes a viable technology. However, the global model parameters that have to be shared for optimization are still susceptible to training data leakage. In this work, we propose confined gradient descent (CGD) that enhances the privacy of federated learning by eliminating the sharing of global model parameters. CGD exploits the fact that a gradient descent optimization can start with a set of discrete points and converges to another set in the neighborhood of the global minimum of the objective function. As such, each participant can independently initiate its own private global model~(referred to as the confined model ), and collaboratively learn it towards the optimum. The updates to their own models are worked out in a secure collaborative way during the training process.In such a manner, CGD retains the ability of learning from distributed data but greatly diminishes information sharing. Such a strategy also allows the proprietary confined models to adapt to the heterogeneity in federated learning, providing inherent benefits of fairness. We theoretically and empirically demonstrate that decentralized CGD øne provides a stronger differential privacy (DP) protection; \two is robust against the state-of-the-art poisoning privacy attacks; þree results in bounded fairness guarantee among participants; and \four provides high test accuracy (comparable with centralized learning) with a bounded convergence rate over four real-world datasets.
Yanjun Zhang 0002, Ruoxi Sun 0001, Liyue Shen, Guangdong Bai, Minhui Xue 0001, Mark Huasong Meng, Xue Li 0001, Ryan Kok Leong Ko, Surya Nepal
WWW8
2023 TypeScript's Evolution: An Analysis of Feature Adoption Over Time
abstract
TypeScript is a quickly evolving superset of JavaScript with active development of new features. Our paper seeks to understand how quickly these features are adopted by the developer community. Existing work in JavaScript shows the adoption of dynamic language features can be a major hindrance to static analysis. As TypeScript evolves the addition of features makes the underlying standard more and more difficult to keep up with. In our work we present an analysis of 454 open source TypeScript repositories and study the adoption of 13 language features over the past three years. We show that while new versions of the TypeScript compiler are aggressively adopted by the community, the same cannot be said for language features. While some experience strong growth others are rarely adopted by projects. Our work serves as a starting point for future study of the adoption of features in TypeScript. We also release our analysis and data gathering software as open source in the hope it helps the programming languages community.
Joshua D. Scarsbrook, Mark Utting, Ryan Kok Leong Ko
MSR3
2023 ResNet and Yolov5-enabled non-invasive meat identification for high-accuracy box label verification
abstract
Compliance issues riddle the agricultural sector despite being an essential industry for the human race. Many factors contribute to compliance issues; however, meat cut label verification is one of the most critical concerns due to its erroneous nature. In addition, meat cut identification is complex for the human eye. Thus, access to a skilled labor force is challenging. Nevertheless, meat compliance is essential since it has export compliance ramifications. These factors, along with others, are pushing for a digital alternative. An alternative that can augment human decision-making in verifying meat cut box labels. Artificial Intelligence (AI) is a digital alternative that can boost quality assurance tasks. One of AI’s potential quality assurance solutions is a Meat Box Labeling Verification (BLV) solution that can verify the boxed meat type against the label to ensure no mismatch. Two major components make up the BLV solution: Meat Identification and Label Analysis. This work aims to solve the former component by exploring different meat-type identification techniques. It explores them by building, evaluating, and testing different computer vision solutions. Hence, the novel contribution of this work is three folds. We first build, test, and design computer vision solutions that detect meat boxes and pieces accurately. These solutions include deep learning methods in classification and object detection techniques. Following that, we evaluate these models and derive key insights. Such insights are valuable for prototyping such solutions in production environments. For example, classification models achieve a 99% testing accuracy in identifying box types. In contrast, object detection achieved 89% [email protected]:.95 in identified individual meat cuts. Finally, we prototype an object detection model in a natural meat processing environment—the demonstration showed comparable object detection precision at 85% [email protected]:.95.
Omar Jarkas, Josh Hall 0001, Stuart Smith, Md. Redowan Mahmud, Parham Khojasteh, Joshua D. Scarsbrook, Ryan Kok Leong Ko
Eng. Appl. Artif. Intell.7
2023 Machine learning in industrial control system (ICS) security: current landscape, opportunities and challenges
abstract
Abstract The advent of Industry 4.0 has led to a rapid increase in cyber attacks on industrial systems and processes, particularly on Industrial Control Systems (ICS). These systems are increasingly becoming prime targets for cyber criminals and nation-states looking to extort large ransoms or cause disruptions due to their ability to cause devastating impact whenever they cease working or malfunction. Although myriads of cyber attack detection systems have been proposed and developed, these detection systems still face many challenges that are typically not found in traditional detection systems. Motivated by the need to better understand these challenges to improve current approaches, this paper aims to (1) understand the current vulnerability landscape in ICS, (2) survey current advancements of Machine Learning (ML) based methods with respect to the usage of ML base classifiers (3) provide insights to benefits and limitations of recent advancement with respect to two performance vectors; detection accuracy and attack variety. Based on our findings, we present key open challenges which will represent exciting research opportunities for the research community.
Abigail M. Y. Koay, Ryan Kok Leong Ko, Hinne Hettema, Kenneth Radke
J. Intell. Inf. Syst.2
2023 Preserving Privacy for Distributed Genome-Wide Analysis Against Identity Tracing Attacks
abstract
Genome-wide analysis has demonstrated both health and social benefits. However, large scale sharing of such data may reveal sensitive information about individuals. One of the emerging challenges is identity tracing attack that exploits correlations among genomic data to reveal the identity of DNA samples. In this paper, we first demonstrate that the adversary can narrow down the sample's identity by detecting his/her genetic relatives and quantify such privacy threat by employing a Shannon entropy-based measurement. For example, we exemplify that when the dataset size reaches 30% of the population, for any target from that population, the uncertainty of the target's identity is reduced to merely 2.3 bits of entropy (i.e., the identity is pinned down within 5 people). Direct application of existing approaches such as differential privacy (DP), secure multiparty computation (MPC) and homomorphic encryption (HE) may not be applicable to this challenge in genome-wide analysis because of the compromise on utility (i.e., accuracy or efficiency). Towards addressing this challenge, this paper proposes a framework named$\upsilon$Fragto facilitate privacy-preserving data sharing and computation in genome-wide analysis.$\upsilon$Fragmitigates privacy risks by using a vertical fragmentation to disrupt the genetic architecture on which the adversary relies for identity tracing without sacrificing the capability of genome-wide analysis. We theoretically prove that it preserves the correctness of the primitive functionalities and algorithms ranging from basic summary statistics to advanced neural networks. Our experiments demonstrate that$\upsilon$Fragoutperforms secure multiparty computation (MPC) and homomorphic encryption (HE) protocols, with a speedup of more than 221x for training neural networks, and also traditional non-private algorithms and a state-of-the-art noise-based differential privacy (DP) solution in most settings.
Yanjun Zhang 0002, Guangdong Bai, Xue Li 0001, Surya Nepal, Marthie Grobler, Chen Chen 0056, Ryan Kok Leong Ko
IEEE Trans. Dependable Secur. Comput.7
2022 SATB: A Testbed of IoT-Based Smart Agriculture Network for Dataset Generation
Liuhuo Wan, Yanjun Zhang 0002, Ryan Kok Leong Ko, Louwrens Christiaan Hoffman, Guangdong Bai
ADMA (1)4
2022 Positive-Unlabeled Learning using Random Forests via Recursive Greedy Risk Minimization
abstract
The need to learn from positive and unlabeled data, or PU learning, arises in many applications and has attracted increasing interest. While random forests are known to perform well on many tasks with positive and negative data, recent PU algorithms are generally based on deep neural networks, and the potential of tree-based PU learning is under-explored. In this paper, we propose new random forest algorithms for PU-learning. Key to our approach is a new interpretation of decision tree algorithms for positive and negative data as \emph{recursive greedy risk minimization algorithms}. We extend this perspective to the PU setting to develop new decision tree learning algorithms that directly minimizes PU-data based estimators for the expected risk. This allows us to develop an efficient PU random forest algorithm, PU extra trees. Our approach features three desirable properties: it is robust to the choice of the loss function in the sense that various loss functions lead to the same decision trees; it requires little hyperparameter tuning as compared to neural network based PU learning; it supports a feature importance that directly measures a feature's contribution to risk minimization. Our algorithms demonstrate strong performance on several datasets. Our code is available at \url{https://github.com/puetpaper/PUExtraTrees}.
Jonathan Wilton, Abigail M. Y. Koay, Ryan Kok Leong Ko, Miao Xu 0001
NeurIPS3
2022 Evaluating Performance and Security of a Hybrid Moving Target Defense in SDN Environments
abstract
As cyberattacks are rising, Moving Target Defense (MTD) can be a countermeasure to proactively protect a networked system against cyber-attacks. Despite the fact that MTD systems demonstrate security effectiveness against the reconnaissance of Cyber Kill Chain (CKC), a time-based MTD has a limitation when it comes to protecting a system against the next phases of CKC. In this work, we propose a novel hybrid MTD technique, its implementation and evaluation. Our hybrid MTD system is designed on a real SDN testbed and it uses an intrusion detection system (IDS) to provide an additional MTD triggering condition. This in itself presents an extra layer of system protection. Our hybrid MTD technique can enhance security in the response to multi-phased cyber-attacks. The use of the reactive MTD triggering from intrusion detection alert shows that it is effective to thwart the further phase of detected cyber-attacks. We also investigate the performance degradation due to more frequent MTD triggers.This work contributes to (1) proposing an ML-based rule classification model for predicting identified attacks which helps a decision-making process for security enhancement; (2) developing a hybrid-based MTD integrated with a Network Intrusion Detection System (NIDS) with the consideration of performance and security; and (3) assessment of the performance degradation and security effectiveness against potential real attacks (i.e., scanning, dictionary, and SQL injection attack) in a physical testbed.
Minjune Kim, Jin-Hee Cho, Hyuk Lim, Terrence J. Moore, Frederica Free-Nelson, Ryan Kok Leong Ko, Dong Seong Kim 0001
QRS6
2022 Situational Crime Prevention (SCP) techniques to prevent and control cybercrimes: A focused systematic review
abstract
Situational Crime Prevention (SCP) is a criminological approach that is shown to reduce crime opportunities drawing from five different strategies comprising 25 techniques. With the global increase in cybercrime, practitioners and researchers are increasingly investigating opportunities for applying SCP strategies and techniques to prevent cyber-focused and cyber-enabled crimes. Recent research proposes ways that SCP can be applied to cybercrime. Yet most of this research utilizes only a few of the SCP techniques and the linkages between the SCP techniques and opportunities for reducing cybercrimes are rarely made explicit. In this paper we evaluate the relevance of the full spectrum of SCP techniques to cybercrime and explicate how computer scientists, cybercrime and cybersecurity researchers and practitioners apply SCP principles to prevent and control cyber-enabled crime. Through a focused systematic review of 352 articles across computer science, criminal justice and criminology literature using the PRISMA method, this paper clarifies terminologies, explores the rise of cybercrimes, and explains the value of SCP for responding to cybercrimes. We provide a review of the current research undertaken to apply SCP to cybercrimes and conclude with a discussion on research gaps and potential future areas of research.
Heemeng Ho, Ryan Kok Leong Ko, Lorraine Mazerolle
Comput. Secur.2
2022 Introduction to the Special Section on Resiliency for AI-enabled Smart Critical Infrastructures for 5G and Beyond
abstract
introduction Share on Introduction to the Special Section on Resiliency for AI-enabled Smart Critical Infrastructures for 5G and Beyond Authors: Laizhong Cui Shenzhen University, China Shenzhen University, ChinaView Profile , Yulei Wu University of Exeter, UK University of Exeter, UKView Profile , Ryan Ko University of Queensland, Australia University of Queensland, AustraliaView Profile , Alex Ladur CTEK - Combined Technologies Ltd, New Zealand CTEK - Combined Technologies Ltd, New ZealandView Profile , Jianping Wu Tsinghua University, China Tsinghua University, ChinaView Profile Authors Info & Claims ACM Transactions on Sensor NetworksVolume 18Issue 319 September 2022Article No.: 40epp 1–3https://doi.org/10.1145/3538515Published:19 September 2022Publication History 0citation78DownloadsMetricsTotal Citations0Total Downloads78Last 12 Months78Last 6 weeks4 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Laizhong Cui, Yulei Wu, Ryan Kok Leong Ko, Alex Ladur
ACM Trans. Sens. Networks3
2021 On Random Editing in LZ-End
abstract
LZ-End is a variant of the LZ77 compression algorithm which allows random access to the compressed data. In this paper, we use the random-access capability of LZ-End to perform random edits on the compressed data.
Daniel Roodt, Ulrich Speidel, Vimal Kumar 0001, Ryan Kok Leong Ko
DCC4
2021 Privacy-Preserving Gradient Descent for Distributed Genome-Wide Analysis
Yanjun Zhang 0002, Guangdong Bai, Xue Li 0001, Caitlin Curtis, Chen Chen 0056, Ryan Kok Leong Ko
ESORICS (2)6
2021 It's Not Just the Site, It's the Contents: Intra-domain Fingerprinting Social Media Websites Through CDN Bursts
abstract
The website fingerprinting (or inter-domain WSF), enhanced by various machine learning techniques, has shown its power to identify websites a user has visited. To our best knowledge, a finer-grained problem of web page fingerprinting (or intra-domain WPF) has not been systematically studied by our research community. The WPF attackers, such as government agencies enforcing Internet censorship, are keen to identify the particular web pages (e.g., a political dissident’s social media page) visited by the target user.
Kailong Wang 0001, Guangdong Bai, Ryan Kok Leong Ko, Jin Song Dong 0001
WWW4
2021 Security and Privacy in Smart Cities
abstract
International audience
Chalee Vorakulpipat, Ryan Kok Leong Ko, Qi Li 0002, Ahmed Meddahi
Secur. Commun. Networks2
2020 PrivColl: Practical Privacy-Preserving Collaborative Machine Learning
Yanjun Zhang 0002, Guangdong Bai, Xue Li 0001, Caitlin Curtis, Chen Chen 0056, Ryan Kok Leong Ko
ESORICS (1)6
2020 An Analytics Framework for Heuristic Inference Attacks against Industrial Control Systems
abstract
Industrial control systems (ICS) of critical infrastructure are increasingly connected to the Internet for remote site management at scale. However, cyber attacks against ICS - especially at the communication channels between human-machine interface (HMIs) and programmable logic controllers (PLCs) - are increasing at a rate which outstrips the rate of mitigation. In this paper, we introduce a vendor-agnostic analytics framework which allows security researchers to analyse attacks against ICS systems, even if the researchers have zero control automation domain knowledge or are faced with a myriad of heterogenous ICS systems. Unlike existing works that require expertise in domain knowledge and specialised tool usage, our analytics framework does not require prior knowledge about ICS communication protocols, PLCs, and expertise of any network penetration testing tool. Using `digital twin' scenarios comprising industry-representative HMIs, PLCs and firewalls in our test lab, our framework's steps were demonstrated to successfully implement a stealthy deception attack based on false data injection attacks (FDIA). Furthermore, our framework also demonstrated the relative ease of attack dataset collection, and the ability to leverage well-known penetration testing tools. We also introduce the concept of `heuristic inference attacks', a new family of attack types on ICS which is agnostic to PLC and HMI brands/models commonly deployed in ICS. Our experiments were also validated on a separate ICS dataset collected from a cyber-physical scenario of water utilities. Finally, we utilized time complexity theory to estimate the difficulty for the attacker to conduct the proposed packet analyses, and recommended countermeasures based on our findings.
Taejun Choi, Guangdong Bai, Ryan Kok Leong Ko, Naipeng Dong, Wenlu Zhang, Shunyao Wang
TrustCom3
2019 A Scalable Approach to Joint Cyber Insurance and Security-as-a-Service Provisioning in Cloud Computing
abstract
As computing services are increasingly cloud-based, corporations are investing in cloud-based security measures. The Security-as-a-Service (SECaaS) paradigm allows customers to outsource security to the cloud, through the payment of a subscription fee. However, no security system is bulletproof, and even one successful attack can result in the loss of data and revenue worth millions of dollars. To guard against this eventuality, customers may also purchase cyber insurance to receive recompense in the case of loss. To achieve cost effectiveness, it is necessary to balance provisioning of security and insurance, even when future costs and risks are uncertain. To this end, we introduce a stochastic optimization model to optimally provision security and insurance services in the cloud. Since the model we design is a mixed integer problem, we also introduce a partial Lagrange multiplier algorithm that takes advantage of the total unimodularity property to find the solution in polynomial time. We also apply sensitivity analysis to find the exact tolerance of decision variables to parameter changes. We show the effectiveness of these techniques using numerical results based on real attack data to demonstrate a realistic testing environment, and find that security and insurance are interdependent.
Jonathan Chase, Dusit Niyato, Ping Wang 0001, Sivadon Chaisiri, Ryan Kok Leong Ko
IEEE Trans. Dependable Secur. Comput.5
2018 MetropolJS: visualizing and debugging large-scale javascript program structure with treemaps
abstract
As a result of the large scale and diverse composition of modern compiled JavaScript applications, comprehending overall program structure for debugging is challenging. In this paper we present our solution: MetropolJS. By using a Treemap-based visualization it is possible to get a high level view within limited screen real estate. Previous approaches to Treemaps lacked the fine detail and interactive features to be useful as a debugging tool. This paper introduces an optimized approach for visualizing complex program structure that enables new debugging techniques where the execution of programs can be displayed in real time from a bird's-eye view. The approach facilitates highlighting and visualizing method calls and distinctive code patterns on top of code segments without a high overhead for navigation. Using this approach enables fast analysis of previously difficult-to-comprehend code bases.
Joshua D. Scarsbrook, Ryan Kok Leong Ko, Bill Rogers 0001, David Bainbridge 0001
ICPC2
2017 Malware Propagation and Prevention Model for Time-Varying Community Networks within Software Defined Networks
abstract
As the adoption of Software Defined Networks (SDNs) grows, the security of SDN still has several unaddressed limitations. A key network security research area is in the study of malware propagation across the SDN-enabled networks. To analyze the spreading processes of network malware (e.g., viruses) in SDN, we propose a dynamic model with a time-varying community network, inspired by research models on the spread of epidemics in complex networks across communities. We assume subnets of the network as communities and links that are dense in subnets but sparse between subnets. Using numerical simulation and theoretical analysis, we find that the efficiency of network malware propagation in this model depends on the mobility rate q of the nodes between subnets. We also find that there exists a mobility rate threshold qc . The network malware will spread in the SDN when the mobility rate q>qc . The malware will survive when q>qc and perish when q
Lan Liu 0003, Ryan Kok Leong Ko, Guangming Ren, Xiaoping Xu
Secur. Commun. Networks2
2014 'Time' for Cloud? Design and Implementation of a Time-Based Cloud Resource Management System
abstract
The current pay-per-use model adopted by public cloud service providers has influenced the perception on how a cloud should provide its resources to end-users, i.e. on-demand and access to an unlimited amount of resources. However, not all clouds are equal. While such provisioning models work for well-endowed public clouds, they may not always work well in private clouds with limited budget and resources such as research and education clouds. Private clouds also stand to be impacted greatly by issues such as user resource hogging and the misuse of resources for nefarious activities. These problems are usually caused by challenges such as (1) limited physical servers/ budget, (2) growing number of users and (3) the inability to gracefully and automatically relinquish resources from inactive users. Currently, cloud resource management frameworks used for private cloud setups, such as OpenStack and CloudStack, only uses the pay-per-use model as the basis when provisioning resources to users. In this paper, we propose OpenStack Café, a novel methodology adopting the concepts of 'time' and booking systems' to manage resources of private clouds. By allowing users to book resources over specific time-slots, our proposed solution can efficiently and automatically help administrators manage users' access to resource, addressing the issue of resource hogging and gracefully relinquish resources back to the pool in resource-constrained private cloud setups. Work is currently in progress to adopt Café into OpenStack as a feature, and results of our prototype show promises. We also present some insights to lessons learnt during the design and implementation of our proposed methodology in this paper.
Ryan Kok Leong Ko, Yu Shyang Tan, Grace P. Y. Ng
IEEE CLOUD1
2014 Progger: An Efficient, Tamper-Evident Kernel-Space Logger for Cloud Data Provenance Tracking
abstract
Cloud data provenance, or "what has happened to my data in the cloud", is a critical data security component which addresses pressing data accountability and data governance issues in cloud computing systems. In this paper, we present Progger (Provenance Logger), a kernel-space logger which potentially empowers all cloud stakeholders to trace their data. Logging from the kernel space empowers security analysts to collect provenance from the lowest possible atomic data actions, and enables several higher-level tools to be built for effective end-to-end tracking of data provenance. Within the last few years, there has been an increasing number of proposed kernel space provenance tools but they faced several critical data security and integrity problems. Some of these prior tools' limitations include (1) the inability to provide log tamper-evidence and prevention of fake/manual entries, (2) accurate and granular timestamp synchronisation across several machines, (3) log space requirements and growth, and (4) the efficient logging of root usage of the system. Progger has resolved all these critical issues, and as such, provides high assurance of data security and data activity audit. With this in mind, the paper will discuss these elements of high-assurance cloud data provenance, describe the design of Progger and its efficiency, and present compelling results which paves the way for Progger being a foundation tool used for data activity tracking across all cloud systems.
Ryan Kok Leong Ko, Mark A. Will
IEEE CLOUD1
2014 Virtual Numbers for Virtual Machines?
abstract
Knowing the number of virtual machines (VMs) that a cloud physical hardware can (further) support is critical as it has implications on provisioning and hardware procurement. However, current methods for estimating the maximum number of VMs possible on a given hardware is usually the ratio of the specifications of a VM to the underlying cloud hardware's specifications. Such naive and linear estimation methods mostly yield impractical limits as to how many VMs the hardware can actually support. It was found that if we base on the naive division method, user experience on VMs at those limits would be severely degraded. In this paper, we demonstrate through experimental results, the significant gap between the limits derived using the estimation method mentioned above and the actual situation. We believe for a more practicable estimation of the limits of the underlying infrastructure, dominant workload of VMs should also be factored in.
Yu Shyang Tan, Ryan Kok Leong Ko, Veena B. Mendiratta
IEEE CLOUD2
2014 A Mantrap-Inspired, User-Centric Data Leakage Prevention (DLP) Approach
abstract
The ease of sharing information through the Internet and Cloud Computing inadvertently introduces a growing problem of data leakages. At the same time, many end-users are unaware that their data was leaked or stolen since most data is leaked by operations running in the background. This paper introduces a novel user-centric, mantrap-inspired data leakage prevention (DLP) approach that can discover, present any sending of data -- both authorized and unauthorized -- to end-users and subsequently provide them the ability to stop the sending process. We implemented our own kernel module to work together with our user-space program in getting user's approval for every sending process -- giving the user full control over all outbound data sending process in their devices. With this, the end-user can always decide which data sending process should be allowed or blocked. This overcomes the limitations of current, often inflexible and inaccurate DLP solutions depending on pre-set rules and content detection. We showcase a proof-of-concept for our new way of detecting data leakages in an end user's device. This paves the way for further research covering more complex data stealing techniques, such as the use of covert channels.
Ryan Kok Leong Ko, Yu Shyang Tan
CloudCom1
2014 Unified Model for Data Security - A Position Paper
abstract
One of the most crucial components of modern Information Technology (IT) systems is data. It can be argued that the majority of IT systems are built to collect, store, modify, communicate and use data, enabling different data stakeholders to access and use it to achieve different business objectives. The confidentiality, integrity, availability, audit ability, privacy, and quality of the data is of paramount concern for end-users ranging from ordinary consumers to multi-national companies. Over the course of time, different frameworks have been proposed and deployed to provide data security. Many of these previous paradigms were specific to particular domains such as military or media content providers, while in other cases they were generic to different verticals within an industry. There is a much needed push for a holistic approach to data security instead of the current bespoke approaches. The age of the Internet has witnessed an increased ease of sharing data with or without authorisation. These scenarios have created new challenges for traditional data security. In this paper, we study the evolution of data security from the perspective of past proposed frameworks, and present a novel Unified Model for Data Security (UMDS). The discussed UMDS reduces the friction from several cross-domain challenges, and has the functionality to possibly provide comprehensive data security to data owners and privileged users.
Raja Naeem Akram, Ryan Kok Leong Ko
TrustCom2
2014 Digital Trust - Trusted Computing and Beyond: A Position Paper
abstract
Along with the invention of computers and interconnected networks, physical societal notions like security, trust, and privacy entered the digital environment. The concept of digital environments begins with the trust (established in the real world) in the organisation/individual that manages the digital resources. This concept evolved to deal with the rapid growth of the Internet, where it became impractical for entities to have prior offline (real world) trust. The evolution of digital trust took diverse approaches and now trust is defined and understood differently across heterogeneous domains. This paper looks at digital trust from the point of view of security and examines how valid trust approaches from other domains are now making their way into secure computing. The paper also revisits and analyses the Trusted Platform Module (TPM) along with associated technologies and their relevance in the changing landscape. We especially focus on the domains of cloud computing, mobile computing and cyber-physical systems. In addition, the paper also explores our proposals that are competing with and extending the traditional functionality of TPM specifications.
Raja Naeem Akram, Ryan Kok Leong Ko
TrustCom2
2014 Escrow: A Large-Scale Web Vulnerability Assessment Tool
abstract
The reliance on Web applications has increased rapidly over the years. At the same time, the quantity and impact of application security vulnerabilities have grown as well. Amongst these vulnerabilities, SQL Injection has been classified as the most common, dangerous and prevalent web application flaw. In this paper, we propose Escrow, a large-scale SQL Injection detection tool with an exploitation module that is light-weight, fast and platform-independent. Escrow uses a custom search implementation together with a static code analysis module to find potential target web applications. Additionally, it provides a simple to use graphical user interface (GUI) to navigate through a vulnerable remote database. Escrow is implementation-agnostic, i.e. It can perform analysis on any web application regardless of the server-side implementation (PHP, ASP, etc.). Using our tool, we discovered that it is indeed possible to identify and exploit at least 100 databases per 100 minutes, without prior knowledge of their underlying implementation. We observed that for each query sent, we can scan and detect dozens of vulnerable web applications in a short space of time, while providing a means for exploitation. Finally, we provide recommendations for developers to defend against SQL injection and emphasise the need for proactive assessment and defensive coding practices.
Baden Delamore, Ryan Kok Leong Ko
TrustCom2
2014 End-to-End Secure and Privacy Preserving Mobile Chat Application
Raja Naeem Akram, Ryan Kok Leong Ko
WISTP2
2014 Special issue on trust and security in cloud computing
abstract
Trust and security are the top concerns of cloud computing users and key barriers to widespread uptake of cloud computing services across industries. The resistance towards cloud computing is especially experienced in industries handling sensitive data, such as healthcare, government, banking, and so on. While cloud computing brings about several conveniences for end-users, many new issues surfaced from cloud computing's promise of elasticity and availability. With these new issues, traditional security and trust techniques may not be able to fully resolve cloud computing's trust and security problems. This special issue focuses on a broad range of research challenges and issues in trust and security in cloud computing. By addressing trust management, cloud attack vectors, data sharing, dynamic user privileges and high throughput encryption implementations, we addressed some of the top concerns in trust and security in cloud computing. Cloud providers describe their promised behaviour by way of service level agreements (SLAs). However, providers offering similar functionality may have SLAs that are often inconsistent with the aspects considered important by customers. Customers face problems identifying a trustworthy cloud provider solely on the basis of its SLA. To enable reliable customer identification of trustworthy cloud providers, Habib et al. proposed a multi-faceted trust management system architecture for cloud computing marketplaces and related approaches. Their approach provides the means for identifying trustworthy cloud providers in terms of different attributes, such as compliance, data governance and information security. Their proposed trust management system also utilized real data from the Cloud Security Alliance's Consensus Assessment Initiative Questionnaire as one of the sources of trust information. Cloud services are vulnerable to Internet Protocol (IP) prefix hijacking due to their dependence on routing infrastructure. It is important to understand what impact a prefix hijacking attack can cause and how the number and locations of participants can affect the attacking results. Liu et al. modelled this problem as an attack planning task and solved it by applying a form of genetic algorithm. By analyzing the best solution to the problem, they found that the type of victims plays a more important role in IP prefix hijacking than that of attackers. Attackers can gain great impact even when the prefixes of a small number of victims are hijacked. For attack planning, the degree of an autonomous system is a major criterion to be considered. These findings are critical, as they secure cloud networks by preventing and eliminating IP prefix hijacking attacks. Secure data sharing on Cloud storage is an important emerging area in cloud security research. However in this area, dynamic privileges among user groups are usually not considered. In many circumstances, some users may have unnecessarily higher privileges than others. There may also be cases where the data owner may want to dynamically control the privileges in data sharing. Zhao and Li presented an efficient framework for data sharing systems to achieve dynamic privileges, based on the chameleon hash function and one-way function. With this framework, any data sharing and access control scheme can be turned into a dynamic privileged scheme, in which the data owner can change the group of each user dynamically and change the structure of privileges flexibly when it is needed. The proposed framework also requires much less storage than previous schemes in handling dynamic privileges among users. In cloud computing, the techniques for data protection need to be efficient, that is, high performance and throughput. Rahimunnisa et al. proposed a high throughput architecture for the hardware implementation of Advanced Encryption Standard algorithm. Their work, implemented in a Field Programmable Gate Array (FPGA), mainly targets low-cost embedded applications and introduces parallel operation in folded architectures to obtain better throughput—giving a high 37.1 Gb/s throughput with a maximum frequency of 505.5 MHz—which is 20% higher than the maximum throughput reported in the literature. We would like to thank the Editor-in-Chief, Professor Hsiao-Hwa Chen, and Co-Editor-in-Chief, Professor Hamid R. Sharif, for the opportunity to host this special issue in Wiley's Security and Communication Networks. We also thank all the authors who contributed to this Special Issue for publication consideration. Last but not least, we thank the contributions of expert reviewers who provided invaluable advice and recommendations through the revisions. Dr Ryan Ko is a Senior Lecturer at the University of Waikato, New Zealand, and a Research Advisor for Cloud Security Alliance (CSA)'s Asia Pacific region. He established New Zealand's first Master's Degree in Cyber Security and dedicated Cyber Security Lab at the University of Waikato and is the principal investigator for the STRATUS research project. His main research areas are cyber security, cloud data provenance, and cloud computing security and trust. Prior to joining the faculty, he was a lead computer scientist with Hewlett–Packard (HP) Labs' Cloud and Security Lab. Recipient of the CSA Ron Knode Service Award, he is active as co-chair and board member of several cyber security industry consortia and chapters. He is also active as subject matter expert/item writer in the development of the (ISC)2 Certified Cloud Security Professional certification. He holds a BEng (Hons) (Computer Engineering) and PhD from Nanyang Technological University, Singapore, and is a member of IEEE and ACM. Markus Kirchberg is an Adjunct Associate Professor at the National University of Singapore, Singapore. Markus is the Head of Visa Research, Asia Pacific. He joined VISA Inc. in May 2012 as Lead Research Scientist, and his responsibility is for technology innovation inside Visa Labs. Markus's main technical focus areas include data management, cloud computing, and large-scale data analytics. Markus also holds an Adjunct Associate Professor position with the Department of Computer Science at the National University of Singapore (NUS), where he teaches Master's Degree courses focusing on applied data analytics. Prior to joining VISA Inc., Markus worked as Expert at the Cloud and Security Lab, HP Labs Singapore (2010–2012); Research Fellow and Principal Investigator at the Institute for Infocomm Research, A*STAR in Singapore (2007–2010); and Lecturer at Massey University in New Zealand (2000–2007). He holds a PhD in Information Systems from Massey University, New Zealand (2007, part-time) and a Master of Sciences in Computer Science Degree from the Clausthal University of Technology, Germany (2000). Bu Sung Lee received his BSc (Hons) and PhD from the Electrical and Electronics Department, Loughborough University of Technology, U.K., in 1982 and 1987, respectively. He is currently an Associate Professor in the Nanyang Technological University, Singapore. Bu Sung Lee holds a joint appointment as Director, Service Platform Lab, HP Labs. Singapore from July 2010 till end-June 2012. Bu Sung Lee has been very active in the area of establishing a Research and Education Network locally as well as globally. He is the founding president and current President of Singapore Advanced Research and Education Network (SingAREN) and chair of the TransEurasia Information Network Cooperation Center (TEIN*CC) governors, which manages the TEIN regional network. Bu Sung Lee has published over 200 peer-reviewed papers. His research covers cloud computing, data analytics, and network. His particular interest areas are in data replication, scheduling, and more recently in data fusion as applied to cyber security.
Ryan Kok Leong Ko, Markus Kirchberg, Bu-Sung Lee
Secur. Commun. Networks1
2012 Automating Compliance for Cloud Computing Services
Nikolaos Papanikolaou 0001, Siani Pearson, Marco Casassa Mont, Ryan Kok Leong Ko
CLOSER4
2012 Formal Concept Discovery in Semantic Web Data
Markus Kirchberg, Erwin Leonardi, Yu Shyang Tan, Sebastian Link, Ryan Kok Leong Ko, Bu-Sung Lee
ICFCA5
2012 Overcoming Large Data Transfer Bottlenecks in RESTful Service Orchestrations
abstract
As REST (Representational State Transfer)-ful services are closely coupled to the HTTP (Hypertext Transfer Protocol), which eventually sits above the connection-based TCP (Transmission Control Protocol), it is common for RESTful services to experience latency and transfer inefficiencies especially in situations requiring the services to transfer large-scale data (i.e. above gigabytes of data) in RESTful workflows. Such inefficiencies are undesirable and impractical, and are compounded for RESTful service orchestrations in data-intensive industries such as Big Data analytics, cloud computing and life sciences. In this paper, we propose a non-invasive novel technique, Fast-Optimised-REST (FOREST), which enables RESTful services to overcome the traditional bottlenecks experienced during transfer of large sets of data. The initial experimental results show promise and demonstrated very significant reductions of up to 80% from original REST-ful data transfer times for extremely large data sets.
Ryan Kok Leong Ko, Markus Kirchberg, Bu-Sung Lee, Elroy Chew
ICWS1
2012 Tracking of Data Leaving the Cloud
abstract
Data leakages out of cloud computing environments are fundamental cloud security concerns for both the end-users and the cloud service providers. A literature survey of the existing technologies revealed the inadequacies of current technologies and the need for a new methodology. This position paper discusses the requirements and proposes a novel auditing methodology that enables tracking of data transferred out of Clouds. Initial results from our prototypes are reported. This research is aligned to our vision that by providing transparency, accountability and audit trails for all data events within and out of the Cloud, trust and confidence can be instilled into the industry as users will get to know what exactly is going on with their data in and out of the Cloud.
Yu Shyang Tan, Ryan Kok Leong Ko, Peter Jagadpramana, Chun Hui Suen, Markus Kirchberg, Teck Hooi Lim, Bu-Sung Lee, Anurag Singla, Ken Mermoud, Doron Keller, Ha Duc
TrustCom2
2012 How to Track Your Data: Rule-Based Data Provenance Tracing Algorithms
abstract
As cloud computing and virtualization technologies become mainstream, the need to be able to track data has grown in importance. Having the ability to track data from its creation to its current state or its end state will enable the full transparency and accountability in cloud computing environments. In this paper, we showcase a novel technique for tracking end-to-end data provenance, a meta-data describing the derivation history of data. This breakthrough is crucial as it enhances trust and security for complex computer systems and communication networks. By analyzing and utilizing provenance, it is possible to detect various data leakage threats and alert data administrators and owners; thereby addressing the increasing needs of trust and security for customers' data. We also present our rule-based data provenance tracing algorithms, which trace data provenance to detect actual operations that have been performed on files, especially those under the threat of leaking customers' data. We implemented the cloud data provenance algorithms into an existing software with a rule correlation engine, show the performance of the algorithms in detecting various data leakage threats, and discuss technically its capabilities and limitations.
Qing Zhang 0013, Ryan Kok Leong Ko, Markus Kirchberg, Chun Hui Suen, Peter Jagadpramana, Bu-Sung Lee
TrustCom2
2012 Business-OWL (BOWL) - A Hierarchical Task Network Ontology for Dynamic Business Process Decomposition and Formulation
abstract
Collaborative Business Processes (cBPs) form the backbone of enterprise integration. With the growing reliance on the web as a medium of business collaboration, there is an increasing need to quickly and dynamically form cBPs. However, current Business-to-Business (B2B) information systems are still static in nature, and are unable to dynamically form cBPs based on high-level Business Goals (BGs)and their underlying criteria (e.g., item cost, product name, order quantity, etc). This paper introduces the Business-OWL (BOWL), an ontology rooted in the Web Ontology Language (OWL), and modeled as a Hierarchical Task Network (HTN) for the dynamic formation of business processes. An ontologized extension and augmentation of traditional HTN, BOWL describes business processes as a hierarchical ontology of decomposable business tasks encompassing all possible decomposition permutations. Through BOWL, high-level business goals (e.g., "Buy”) can be easily decomposed right down to the lowest level tasks (e.g., "Send Purchase Order”), effectively bridging the gap between high-level business goals with operational level tasks and complementing currently static business process modeling languages. The design of BOWL and a case study demonstrating its implementation are also discussed.
Ryan Kok Leong Ko, Eng Wah Lee, Stephen Siang Guan Lee
IEEE Trans. Serv. Comput.1
2011 How to Track Your Data: The Case for Cloud Computing Provenance
abstract
Provenance, a meta-data describing the derivation history of data, is crucial for the uptake of cloud computing to enhance reliability, credibility, accountability, transparency, and confidentiality of digital objects in a cloud. In this paper, we survey current mechanisms that support provenance for cloud computing, we classify provenance according to its granularities encapsulating the various sets of provenance data for different use cases, and we summarize the challenges and requirements for collecting provenance in a cloud, based on which we show the gap between current approaches to requirements. Additionally, we propose our approach, Data PROVE, that aims to effectively and efficiently satisfy those challenges and requirements in cloud provenance, and to provide a provenance supplemented cloud for better integrity and safety of customers' data.
Qing Zhang 0013, Markus Kirchberg, Ryan Kok Leong Ko, Bu-Sung Lee
CloudCom3
2011 TrustCloud: A Framework for Accountability and Trust in Cloud Computing
abstract
The key barrier to widespread uptake of cloud computing is the lack of trust in clouds by potential customers. While preventive controls for security and privacy are actively researched, there is still little focus on detective controls related to cloud accountability and audit ability. The complexity resulting from large-scale virtualization and data distribution carried out in current clouds has revealed an urgent research agenda for cloud accountability, as has the shift in focus of customer concerns from servers to data. This paper discusses key issues and challenges in achieving a trusted cloud through the use of detective controls, and presents the Trust Cloud framework, which addresses accountability in cloud computing via technical and policy-based approaches.
Ryan Kok Leong Ko, Peter Jagadpramana, Miranda Mowbray, Siani Pearson, Markus Kirchberg, Qianhui Althea Liang, Bu-Sung Lee
SERVICES1
2011 Flogger: A File-Centric Logger for Monitoring File Access and Transfers within Cloud Computing Environments
abstract
Trust is one of the main obstacles to widespread Cloud adoption. In order to increase trust in Cloud computing, we need to increase transparency and accountability of data in the Cloud for both enterprises and end-users. However, current system tools are unable to log file accesses and transfers effectively within a Cloud environment. In this paper, we present Flogger, a novel file-centric logger suitable for both private and public Cloud environments. Flogger records file- centric access and transfer information from within the kernel spaces of both virtual machines (VMs) and physical machines (PMs) in the Cloud, thus giving full transparency of the entire data landscape in the Cloud. With Flogger, services can be built above it to provide Cloud providers, end-users and regulators with the relevant provenance, e.g. a tool for an end- user to track whether his/ her file was 'touched' by an unauthorized user. We present the initial developments of Flogger, and interesting results from our experiments. We also present compelling future work that will shape the beginnings of a new logging paradigm: distributed VM/ PM file-centric logging.
Ryan Kok Leong Ko, Peter Jagadpramana, Bu-Sung Lee
TrustCom1
2009 Dynamic Collaborative Business Process Formulation via Ontologised Hierarchical Task Network (HTN) Planning
abstract
Increased trade and globalization has created an increasing need for the dynamic formulation and integration of cross-enterprise collaborative business processes (cBP’s). However, current systems and methodologies, being static in nature, are unable to dynamically formulate cBP’s based on business goals and selection criteria. Much of this stems from the current inability to bridge high level strategic business goals to low-level operational tasks, and the inability to dynamically decompose compound business process tasks into primitive operational tasks for direct Web service execution.In this paper, we demonstrate how the concepts from hierarchical task network (HTN) planning are feasible for dynamically creating cBP task sequences ideal for direct Web service execution. We also establish the rationale behind modeling business-to-business (B2B) collaboration tasks as hierarchical Web ontologies. To demonstrate the achievability of dynamic cBP formulation, we developed the Genesis methodology, which consists of (1) Business-OWL (BOWL) - a B2B hierarchical task Web ontology, and (2) the Genesis algorithm – an extension of the hierarchical task network (HTN) planning algorithm to handle business criteria and control flows commonly found in business processes.
Ryan Kok Leong Ko, Stephen Siang Guan Lee, Eng Wah Lee, Andre Jusuf
ICWS1