VLDB 2026 Research / reviewers in the wild / expert
Andrew P. Martin
dblp:82/6684 · also Andrew Martin 0002
· DBLP profile ↗
43ranked-venue papers
5as first author
2since 2021 · last 2022
0000-0002-8236-980XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 11 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 6 · 1 first-authorTheory of computation · 5 · 2 first-authorSystems, architecture and hardware · 4Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Towards Comparative Evaluation of DDoS DefencesabstractDDoS defence evaluation provides a way to capture the usefulness of defensive solutions to one of the most notorious Internet attacks of our computing generation. An alternative approach to evaluation offers a valuable mechanism by which different DDoS defences can be commensurably and objectively compared. Such a development would not only enable individual organizations to make better informed decisions on which defences to implement but could also aid collaborations to realize global solutions; and reveal insights into aspects requiring further investigation. We present CED3 (pronounced “Seed”), a DDoS defence evaluation framework designed to facilitate the commensurable comparison between DDoS defences in a way that captures their strengths and weaknesses. Firstly, CED3 introduces the notion of true effectiveness, which addresses the problem, identified in the literature, of previously validated defences subsequently being shown to be ineffective when evaluated under different attack conditions. CED3 leverages a structured theoretical analysis process to drive empirical data acquisition in order to enhance consistency, transparency and, ultimately, longevity of evaluation conclusions. Lastly, CED3 introduces the concept of defence maps, which applies the idea of true effectiveness to “scopes” in order to communicate the strengths and weaknesses of defences in a way that allows them to be visually compared. We demonstrate the CED3 framework by applying it to comparatively evaluate three DDoS defences. Using results obtained from extensive simulations in NS-3, we show how the strengths and weaknesses of different defences can be visually compared. We conclude by discussing the merits and limitations of CED3. Andikan Otung, Andrew P. Martin |
SIN | 2 |
| 2021 | Towards a framework for trustworthy data security level agreement in cloud procurement
Yudhistira Nugraha, Andrew P. Martin |
Comput. Secur. | 2 |
| 2020 | Distributed Defence of Service (DiDoS): A Network-layer Reputation-based DDoS Mitigation ArchitectureabstractThe predominant strategy for DDoS mitigation involves resource enlargement so that victim services can handle larger demands, however, with growing attack strengths, this approach alone is unsustainable. This paper proposes DiDoS (Distributed Defence of Service), a collaborative DDoS defence architecture that leverages victim feedback to build network-level sender reputations that are applied to identify and thwart attack traffic - thus alleviating the need for resource enlargement. Since attack traffic is dropped at points of contention in the Internet, (rather than rote blocking at source) DiDoS reduces the impact of false positives and enables the traversal of legitimate traffic from said devices across the Internet. Through anti-spoofing protection and preferential treatment of DiDoS-compliant devices, DiDoS offers adoption incentives that help offset the Tragedy of the Commons effect of DDoS mitigation, which commonly sees non-victim intermediary entities benefit little from DDoS defence expenditure. In this paper, the tenets and fundamentals of the architecture are described, before being analysed against the presented threat model. Simulation results, demonstrating the effectiveness of the reputation convergence of the scheme, in the use-case of a local access network, are also presented and discussed. Andikan Otung, Andrew P. Martin |
ICISSP | 2 |
| 2020 | Exploring HTTPS security inconsistencies: A cross-regional perspective
Eman Salem Alashwali, Pawel Szalachowski, Andrew P. Martin |
Comput. Secur. | 3 |
| 2019 | Does "www." Mean Better Transport Layer Security?abstractExperience shows that most researchers and developers tend to treat plain-domains (those that are not prefixed with "www" subdomains, e.g. "example.com") as synonyms for their equivalent www-domains (those that are prefixed with "www" sub-domains, e.g. "www.example.com"). In this paper, we analyse datasets of nearly two million plain-domains against their equivalent www-domains to answer the following question: Do plain-domains and their equivalent www-domains differ in TLS security configurations and certificates? If so, to what extent? Our results provide evidence of an interesting phenomenon: plain-domains and their equivalent www-domains differ in TLS security configurations and certificates in a non-trivial number of cases. Furthermore, www-domains tend to have stronger security configurations than their equivalent plain-domains. Interestingly, this phenomenon is more prevalent in the most-visited domains than in randomly-chosen domains. Further analysis of the top domains dataset shows that 53.35% of the plain-domains that show one or more weakness indicators (e.g. expired certificate) that are not shown in their equivalent www-domains perform HTTPS redirection from HTTPS plain-domains to their equivalent HTTPS www-domains. Additionally, 24.71% of these redirections contains plain-text HTTP intermediate URLs. In these cases, users see the final www-domains with strong TLS configurations and certificates, but in fact, the HTTPS request has passed through plain-domains that have less secure TLS configurations and certificates. Clearly, such a set-up introduces a weak link in the security of the overall interaction. Eman Salem Alashwali, Pawel Szalachowski, Andrew P. Martin |
ARES | 3 |
| 2019 | Towards Forward Secure Internet Traffic
Eman Salem Alashwali, Pawel Szalachowski, Andrew P. Martin |
SecureComm (1) | 3 |
| 2019 | Cyber risk assessment in cloud provider environments: Current models and future needs
Olusola Akinrolabu, Jason R. C. Nurse, Andrew P. Martin, Steve New |
Comput. Secur. | 3 |
| 2019 | Managing confidentiality leaks through private algorithms on Software Guard eXtensions (SGX) enclavesabstractMany applications are built upon private algorithms, and executing them in untrusted, remote environments poses confidentiality issues. To some extent, these problems can be addressed by ensuring the use of secure hardware in the execution environment; however, an insecure software-stack can only provide limited algorithm secrecy. This paper aims to address this problem, by exploring the components of the Trusted Computing Base (TCB) in hardware-supported enclaves. First, we provide a taxonomy and give an extensive understanding of trade-offs during secure enclave development. Next, we present a case study on existing secret-code execution frameworks; which have bad TCB design due to processing secrets with commodity software in enclaves. This increased attack surface introduces additional footprints on memory that breaks the confidentiality guarantees; as a result, the private algorithms are leaked. Finally, we propose an alternative approach for remote secret-code execution of private algorithms. Our solution removes the potentially untrusted commodity software from the TCB and provides a minimal loader for secret-code execution. Based on our new enclave development paradigm, we demonstrate three industrial templates for cloud applications: ① computational power as a service, ② algorithm querying as a service, and ③ data querying as a service. Kubilay Ahmet Küçük, David Grawrock, Andrew P. Martin |
EURASIP J. Inf. Secur. | 3 |
| 2017 | Towards the Classification of Confidentiality Capabilities in Trustworthy Service Level AgreementsabstractMany governments are increasingly reliant on externalservice providers to process, store or transmit sensitivedata on behalf of the government. This study is motivated by the problem of preserving the confidentiality of sensitive government data, particularly following Edward Snowden's revelations of alleged pervasive surveillance, a problem posed by foreign intelligence services to the Indonesian government in 2013. In this paper, we discuss the idea of proposing TrustworthyService Level Agreements (TSLA) as a means of incorporating security considerations (considering confidentiality) into a Service Level Agreement (SLA) between a service provider and the customer (e.g. government). In particular, we classify confidentialityrequirements and capabilities according to a typical threat profile for government data classification, by describing five discrete levels of security precautions that can be negotiated between the government and service providers to ensure the confidentiality of sensitive data handled by the providers. It further provides an evaluation framework for assessing and clarifying security considerations in SLAs. The levels of assurance should serve as a foundation for expressing security considerations (including threats, requirements, and capabilities) in SLAs as well as fordesigning information system services regarding security. The contribution of this paper is in developing five distinctive levels of increasing assurance that can be applied to the formulation of security-related SLAs, as well as in discussing the discrete levels, using the context of a government cloud. Yudhistira Nugraha, Andrew P. Martin |
IC2E | 2 |
| 2017 | A framework for application partitioning using trusted execution environmentsabstractSummary The size and complexity of modern applications are the underlying causes of numerous security vulnerabilities. In order to mitigate the risks arising from such vulnerabilities, various techniques have been proposed to isolate the execution of sensitive code from the rest of the application and from other software on the platform (such as the operating system). New technologies, notably Intel's Software Guard Extensions (SGX), are becoming available to enhance the security of partitioned applications. SGX provides a trusted execution environment (TEE), called an enclave, that protects the integrity of the code and the confidentiality of the data inside it from other software, including the operating system (OS). However, even with these partitioning techniques, it is not immediately clear exactly how they can and should be used to partition applications. How should a particular application be partitioned? How many TEEs should be used? What granularity of partitioning should be applied? To some extent, this is dependent on the capabilities and performance of the partitioning technology in use. However, as partitioning becomes increasingly common, there is a need for systematisation in the design of partitioning schemes. To address this need, we present a novel framework consisting of four overarching types of partitioning schemes through which applications can make use of TEEs. These schemes range from coarse‐grained partitioning, in which the whole application is included in a single TEE, through to ultra‐fine partitioning, in which each piece of security‐sensitive code and data is protected in an individual TEE. Although partitioning schemes themselves are application specific, we establish application‐independent relationships between the types we have defined. Because these relationships have an impact on both the security and performance of the partitioning scheme, we envisage that our framework can be used by software architects to guide the design of application partitioning schemes. To demonstrate the applicability of our framework, we have carried out case studies on two widely used software packages, the Apache Web server and the OpenSSL library. In each case study, we provide four high‐level partitioning schemes—one for each of the types in our framework. We also systematically review the related work on hardware‐enforced partitioning by categorising previous research efforts according to our framework. Copyright © 2017 John Wiley & Sons, Ltd. Ahmad Atamli-Reineh, Andrew Paverd, Giuseppe Petracca, Andrew P. Martin |
Concurr. Comput. Pract. Exp. | 4 |
| 2017 | RepCloud: Attesting to Cloud Service DependencyabstractSecurity enhancements to the emerging IaaS (Infrastructure as a Service) cloud computing systems have become the focus of much research, but little of this targets the underlying infrastructure. Trusted cloud systems are proposed to integrate trusted computing infrastructure with cloud systems. With remote attestations, cloud customers are able to determine the genuine behaviors of their applications' hosts; and therefore they establish trust to the cloud. However, the current trusted clouds have difficulties in effectively attesting to the cloud service dependency for customers' applications, due to the cloud's complexity, heterogeneity and dynamism. In this paper, we present RepCloud, a decentralized cloud trust management framework, inspired by the reputation systems from the research in peer-to-peer systems. With RepCloud, cloud customers are able to determine the properties of the exact nodes that may affect the genuine functionalities of their applications, without obtaining much internal information of the cloud. Experiments showed that besides achieving fine-grained cloud service dependency attestation, RepCloud incurred lower trust management overhead than the existing trusted cloud systems. Anbang Ruan, Andrew P. Martin |
IEEE Trans. Serv. Comput. | 2 |
| 2016 | Breaking Down the Monarchy: Achieving Trustworthy and Open Cloud Ecosystem Governance with Separation-of-PowersabstractThe cloud computing ecosystem is in urgent need of effective and practical trust establishment schemes. Cloud customers currently lack approaches to effectively verify the genuine behaviours of cloud services. They can only blindly believe that the Cloud Service Providers (CSPs) are honest enough to not tamper with their data, while many others have avoided using the cloud entirely. Trust establishment schemes, such as cloud auditing and cloud attestation systems, lack controls and transparency over their trust building processes, which only blur the effectiveness of the proclaimed trustworthiness. We argue that these problems ultimately result from the CSPs' autocratic governance over all the activities inside the cloud. In this paper, we present a Separation-of-Powers (SoP) model by referencing the similar concepts from the discipline of the political philosophy. We define three independent roles to separate the powers of definition, enforcement, and inspection from the CSPs. These roles form the collaborative-restrictive relationship to facilitate trustworthy cloud services and achieve the balance-of-powers. We believe a model of this kind will open new opportunities for achieving trustworthy and open cloud ecosystem governance. Anbang Ruan, Andrew P. Martin, David Blundell, David Wallom |
CLOUD | 3 |
| 2015 | Security-Aware Virtual Machine Allocation in the Cloud: A Game Theoretic ApproachabstractWith the growth of cloud computing, many businesses, both small and large, are opting to use cloud services compelled by a great cost savings potential. This is especially true of public cloud computing which allows for quick, dynamic scalability without many overhead or long-term commitments. However, one of the largest dissuasions from using cloud services comes from the inherent and unknown danger of a shared platform such as the hyper visor. An attacker can attack a virtual machine (VM) and then go on to compromise the hyper visor. If successful, then all virtual machines on that hyper visor can become compromised. This is the problem of negative externalities, where the security of one player affects the security of another. This work shows that there are multiple Nash equilibria for the public cloud security game. It also demonstrates that we can allow the players' Nash equilibrium profile to not be dependent on the probability that the hyper visor is compromised, reducing the factor externality plays in calculating the equilibrium. Finally, by using our allocation method, the negative externality imposed onto other players can be brought to a minimum compared to other common VM allocation methods. Luke Kwiat, Charles A. Kamhoua, Kevin A. Kwiat, Jian Tang 0008, Andrew P. Martin |
CLOUD | 5 |
| 2015 | Cyber-Threats Information Sharing in Cloud Computing: A Game Theoretic ApproachabstractCybersecurity is among the highest priorities in industries, academia and governments. Cyber-threats information sharing among different organizations has the potential to maximize vulnerabilities discovery at a minimum cost. Cyber-threats information sharing has several advantages. First, it diminishes the chance that an attacker exploits the same vulnerability to launch multiple attacks in different organizations. Second, it reduces the likelihood an attacker can compromise an organization and collect data that will help him launch an attack on other organizations. Cyberspace has numerous interconnections and critical infrastructure owners are dependent on each other's service. This well-known problem of cyber interdependency is aggravated in a public cloud computing platform. The collaborative effort of organizations in developing a countermeasure for a cyber-breach reduces each firm's cost of investment in cyber defense. Despite its multiple advantages, there are costs and risks associated with cyber-threats information sharing. When a firm shares its vulnerabilities with others there is a risk that these vulnerabilities are leaked to the public (or to attackers) resulting in loss of reputation, market share and revenue. Therefore, in this strategic environment the firms committed to share cyber-threats information might not truthfully share information due to their own self-interests. Moreover, some firms acting selfishly may rationally limit their cybersecurity investment and rely on information shared by others to protect themselves. This can result in under investment in cybersecurity if all participants adopt the same strategy. This paper will use game theory to investigate when multiple self-interested firms can invest in vulnerability discovery and share their cyber-threat information. We will apply our algorithm to a public cloud computing platform as one of the fastest growing segments of the cyberspace. Charles A. Kamhoua, Andrew P. Martin, Deepak K. Tosh, Kevin A. Kwiat, Chad Heitzenrater, Shamik Sengupta |
CSCloud | 2 |
| 2015 | An evolutionary game-theoretic framework for cyber-threat information sharingabstractThe initiative to protect against future cyber crimes requires a collaborative effort from all types of agencies spanning industry, academia, federal institutions, and military agencies. Therefore, a Cybersecurity Information Exchange (CYBEX) framework is required to facilitate breach/patch related information sharing among the participants (firms) to combat cyber attacks. In this paper, we formulate a non-cooperative cybersecurity information sharing game that can guide: (i) the firms (players)1to independently decide whether to “participate in CYBEX and share” or not; (ii) the CYBEX framework to utilize the participation cost dynamically as incentive (to attract firms toward self-enforced sharing) and as a charge (to increase revenue). We analyze the game from an evolutionary game-theoretic strategy and determine the conditions under which the players' self-enforced evolutionary stability can be achieved. We present a distributed learning heuristic to attain the evolutionary stable strategy (ESS) under various conditions. We also show how CYBEX can wisely vary its pricing for participation to increase sharing as well as its own revenue, eventually evolving toward a win-win situation. Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat, Andrew P. Martin |
ICC | 5 |
| 2015 | Experiences in Developing and Delivering a Programme of Part-Time Education in Software and Systems SecurityabstractWe report upon our experiences in developing and delivering a programme of part-time education in Software and Systems Security at the University of Oxford. The MSc in Software and Systems Security is delivered as part of the Software Engineering Programme at Oxford - a collection of one-week intensive courses aimed at individuals who are responsible for the procurement, development, deployment and maintenance of large-scale software-based systems. We expect that our experiences will be useful to those considering a similar journey. Andrew C. Simpson, Andrew P. Martin, Cas Cremers, Ivan Flechais, Ivan Martinovic, Kasper Bonne Rasmussen |
ICSE (2) | 2 |
| 2015 | Securing Application with Software Partitioning: A Case Study Using SGX
Ahmad Atamli-Reineh, Andrew P. Martin |
SecureComm | 2 |
| 2014 | TrustFound: Towards a Formal Foundation for Model Checking Trusted Computing Platforms
Guangdong Bai, Jianan Hao, Jianliang Wu 0002, Yang Liu 0003, Zhenkai Liang, Andrew P. Martin |
FM | 6 |
| 2012 | On the Design and Development of webinos: A Distributed Mobile Application Middleware
John Lyle, Shamal Faily, Ivan Flechais, André Paul, Ayse Göker, Hans I. Myrhaug, Heiko Desruelle, Andrew P. Martin |
DAIS | 8 |
| 2012 | TMR: Towards a Trusted MapReduce InfrastructureabstractMapReduce systems deployed over an open infrastructure such as a cloud have attracted much attention, due to the significant reductions in the costs entailed in satisfying both the computation and storage demands. However, in these systems, the integrity of MapReduce applications is subject to significant threats. Recent research mainly focuses on replication-based integrity verification schemes. However, inevitable critical deficiencies restrict its usage. In this paper, we propose a Trusted MapReduce (TMR) framework to integrate MapReduce systems with the TCG Trusted Computing infrastructure. TMR effectively uses remote attestations to achieve efficient and deterministic integrity verification. We propose a split and parallel attestation schema to reduce latency and eliminate scalability limitations when employing the Trusted Computing mechanisms. We implemented TMR on the Hadoop MapReduce system. Experiments showed that a high strength integrity assurance has been achieved, and the overheads can easily be managed to less than 1% for an industry-strength implementation. Anbang Ruan, Andrew P. Martin |
SERVICES | 2 |
| 2012 | SWSpec: The Requirements Specification Language in Service Workflow EnvironmentsabstractAdvanced technologies have changed the nature of business processes in the form of services. In coordinating services to achieve a particular objective, service workflow is used to control service composition, execution sequences as well as path selection. Since existing mechanisms are insufficient for addressing the diversity and dynamicity of the requirements in a large-scale distributed environment, developing formal requirements specification is necessary. In this paper, we propose a Service Workflow Specification language, called SWSpec, which allows arbitrary services in a workflow to formally and uniformly impose their requirements. As such, the solution will provide a formal way to regulate and control workflows as well as enrich the proliferation of service provisions and consumptions in opened environments. Wattana Viriyasitavat, Andrew P. Martin |
IEEE Trans. Ind. Informatics | 3 |
| 2012 | Using Propositional Logic for Requirements Verification of Service WorkflowabstractThis paper presents a requirement-oriented automated framework for formal verification of service workflows. It is based on our previous work describing the requirement-oriented service workflow specification language called SWSpec. This language has been developed to facilitate workflow composer as well as arbitrary services willing to participate in a workflow to formally and uniformly impose their own requirements. As such, SWSpec provides a formal way to regulate and control workflows. The key component of the to-be-proposed framework centers on verification algorithms that rely on propositional logic. We demonstrate that logic-based workflow verification can be applied to SWSpec which is capable of checking compliance and also detecting conflicts of the imposed requirements. By automating compliance checking process, this framework will support scalable services interoperation in the form of workflows in opened environments. Wattana Viriyasitavat, Puripant Ruchikachorn, Andrew P. Martin |
IEEE Trans. Ind. Informatics | 4 |
| 2011 | myTrustedCloud: Trusted Cloud Infrastructure for Security-critical Computation and Data ManagmentabstractCloud Computing provides an optimal infrastructure to utilise and share both computational and data resources whilst allowing a pay-per-use model, useful to cost-effectively manage hardware investment or to maximise its utilisation. Cloud Computing also offers transitory access to scalable amounts of computational resources, something that is particularly important due to the time and financial constraints of many user communities. The growing number of communities that are adopting large public cloud resources such as Amazon Web Services [1] or Microsoft Azure [2] proves the success and hence usefulness of the Cloud Computing paradigm. Nonetheless, the typical use cases for public clouds involve non-business critical applications, particularly where issues around security of utilization of applications or deposited data within shared public services are binding requisites. In this paper, a use case is presented illustrating how the integration of Trusted Computing technologies into an available cloud infrastructure -- Eucalyptus -- allows the security-critical energy industry to exploit the flexibility and potential economical benefits of the Cloud Computing paradigm for their business-critical applications. David Wallom, Matteo Turilli, Andrew P. Martin, Anbang Ruan, Gareth A. Taylor, Nigel Hargreaves, Alan McMoran |
CloudCom | 3 |
| 2011 | Secure Virtual Layer Management in CloudsabstractClouds are composed of enormous resources and are associated with attractive properties, e.g. scalability and resilience. Such properties are the result of Clouds dynamic nature. Cloud dynamism is desirable property for different reasons such as resilience, resource consolidation, and maintenance windows. However, such dynamism exposes many security and management concerns for Cloud providers as well as for Cloud users. For example how can Cloud providers assure users that: (a.) dependent applications running on different VMs (Virtual Machines) are hosted within physical proximity (performance reasons); (b.) mutually exclusive VMs are not hosted at the same physical server (e.g. availability and security reasons); and (c.) when migrating VMs the new allocated physical servers satisfy users application requirements and security and privacy criteria. In this paper we explore this important problem. We then propose a framework, which at this foundation stage focuses on providing secure environment for the management of Clouds' virtual layer. It also helps in establishing trust in Cloud's operational management. We also propose our planned implementation layout using Open Stack. Imad M. Abbadi, Muntaha Alawneh, Andrew P. Martin |
TrustCom | 3 |
| 2011 | A multiple comparative study of test-with development product changes and their effects on team speed and product quality
Steve Bannerman, Andrew P. Martin |
Empir. Softw. Eng. | 2 |
| 2011 | Managing application whitelists in trusted distributed systems
Jun-Ho Huh, John Lyle, Cornelius Namiluko, Andrew P. Martin |
Future Gener. Comput. Syst. | 4 |
| 2011 | Trust in the Cloud
Imad M. Abbadi, Andrew P. Martin |
Inf. Secur. Tech. Rep. | 2 |
| 2010 | Towards a Framework for Security in eScienceabstractThis paper describes an approach to the formulation and classification of security requirements in eScience. It explains why it is untenable to suggest that `one size fits all', and that what is an appropriate security solution in one context may not be at all appropriate in another. It proposes a framework for the description of eScience security in a number of different dimensions, in terms of measures taken and controls achieved. A distinctive feature of the framework is that these descriptions are organised into a set of discrete criteria, in most cases presented as levels of increasing assurance. The intended framework should serve as a basis for the systematic analysis of security solutions, facilitating the processes of design and approval, as well as for the identification of expectations and best practice in particular domains. The possible usage of the framework, and the value of the approach, is demonstrated in the paper through application to the design of a national data sharing service. Andrew P. Martin, Jim Davies, Steve Harris |
eScience | 1 |
| 2010 | Formal Trust Specification in Service WorkflowsabstractThe emergence of the Internet has changed the nature of face-to-face towards online interactions. This leads to the concept of virtual interoperation such as Web Services, Grid, and Cloud Computing. Since existing security mechanisms are insufficient to cover the diversity of workflow application domains, trust is considered as an adaptive, high-level abstraction, and platform-independent solution that fits into this context. This paper proposes a formal trust specification which covers a wide range of intuitive trust characteristics such as trust transitivity and mutual relationship. We develop a new trust definition and three modes of trust with algebraic operators to form specification formulas. A method for determining the closeness of a matched trust value on a service using Euclidean Distance is presented and the basic analysis is conducted. Wattana Viriyasitavat, Andrew P. Martin |
EUC | 2 |
| 2010 | A verification system for interval-based specification languagesabstractInterval-based specification languages have been used to formally model and rigorously reason about real-time computing systems. This usually involves logical reasoning and mathematical computation with respect to continuous or discrete time. When these systems are complex, analyzing their models by hand becomes error-prone and difficult. In this article, we develop a verification system to facilitate the formal analysis of interval-based specification languages with machine-assisted proof support. The verification system is developed using a generic theorem prover, Prototype Verification System (PVS). Our system elaborately encodes a highly expressive set-based notation, Timed Interval Calculus (TIC), and can rigorously carry out the verification of TIC models at an interval level. We validated all TIC reasoning rules and discovered subtle flaws in the original rules. We also apply TIC to model Duration Calculus (DC), which is a popular interval-based specification language, and thus expand the capacity of the verification system. We can check the correctness of DC axioms, and execute DC proofs in a manner similar to the corresponding pencil-and-paper DC arguments. Chunqing Chen, Jin Song Dong 0001, Jun Sun 0001, Andrew P. Martin |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2009 | Towards a Trustable Virtual OrganisationabstractIn many scientific disciplines, the models, data and methods used to produce results have significant commercial value. Researchers in these sectors are often unwilling to exploit the full potential of grid computing because there remains a `trust gap' between their security requirements and present solutions. We describe two trustable architectures, one applicable for a computational grid and the other for a data grid. Both allow the participants to verify the security configurations of others as well as report their own through a remote configuration management service. The grid jobs are dispatched to only those trustworthy, and guaranteed to run in protected execution environments. Furthermore, our trustworthy analysis server enables statistical analyses to be performed on sensitive raw data --- collected from multiple domains --- without disclosing it to anyone. Jun-Ho Huh, Andrew P. Martin |
ISPA | 2 |
| 2007 | Grid security: Next steps
Andrew P. Martin, Po-Wah Yau |
Inf. Secur. Tech. Rep. | 1 |
| 2006 | Towards a Secure, Tamper-Proof Grid PlatformabstractSecurity concerns currently deter or prohibit many organisations from leveraging the benefits of the grid. When sensitive data is placed under the control of third-party infrastructure it is difficult to obtain assurances that it will be appropriately protected. We develop a grid platform architecture based on a secure root of trust. This component provides a tamper-resistant environment for grid job execution that resists attack even if the host itself is compromised. We use trusted computing, a security technology currently being integrated into an increasing number of mainstream PCs, for dynamic trust establishment within the grid. These elements are combined to create a novel and practical solution for the grid malicious host problem, ensuring that data integrity and confidentiality are appropriately protected for jobs that span multiple administrative domains. Andrew Cooper, Andrew P. Martin |
CCGRID | 2 |
| 2006 | Towards an open, trusted digital rights management platformabstractTrusted computing has received criticism from those who fear it will be used by influential market forces to exert power over the software used on consumer platforms. This paper describes an open architecture for digital rights management (DRM) enforcement on trusted computing platforms that empowers the consumer to select their operating-system and applications, including open-source options, without weakening the strength of the security functions. A key component in the architecture is a security manager that enforces mandatory access controls on shared devices, restricted information flows between virtual machines, and DRM policy on protected objects. The paper describes two use-cases: a DRM scenario with protected media content and remote home-working on sensitive medical data. Andrew Cooper, Andrew P. Martin |
Digital Rights Management Workshop | 2 |
| 2006 | ShibGrid: Shibboleth Access for the UK National Grid ServiceabstractThis paper presents work undertaken to integrate the future UK national Shibboleth infrastructure with the UK's National Grid Service (NGS). Our work, ShibGrid, provides both transparent authentication for portal based Grid access and a credential transformation service for users of other Grid access methods. The ShibGrid support for portal-based transparent Grid authentication is provided as a set of standards-based drop-in modules which can be used with any project portal as well as the NGS project in which they are initially deployed. The ShibGrid architecture requires no changes to the UK national Shibboleth authentication infrastructure or the NGS security infrastructure and provides access for users both with and without UK e-Science certificates. In addition to presenting both the architecture of Shib- Grid and its implementation, we additionally place the ShibGrid project within the context of other efforts to integrate Shibboleth with Grids. David Spence, Neil Geddes, Jens Jensen, Andrew Richards, Matthew Viljoen, Andrew P. Martin, Matthew J. Dovey, Mark Norman, Kang Tang, Anne E. Trefethen, David Wallom, Rob Allan, David Meredith 0003 |
e-Science | 6 |
| 2005 | Editorial
Howard Chivers, Andrew P. Martin |
Softw. Pract. Exp. | 2 |
| 2003 | Generalising the Z Schema Calculus: Database Schemas and BeyondabstractThe theory of relational databases has much in common with the mathematical structures central to the Z notation. Many authors have noted these connections in the past, but the development of the Z standard has provided a more natural way of making these links explicit. We explore extensions to the schema calculus that may help to model the familiar relational algebra operations in a clear way. Potential areas of application for this work include pedagogy, practical database design, and helping to point the way towards a more general means for defining a broader class of schema calculus operations. Andrew P. Martin, Andrew C. Simpson |
APSEC | 1 |
| 2003 | On The Supervision and Assessment Of Part-Time Postgraduate Software Engineering ProjectsabstractThis paper describes existing practices in the supervision and assessment of projects undertaken by part-time, postgraduate students in Software Engineering. It considers this aspect of the learning experience, and the educational issues raised, in the context of existing literature-much of which is focussed upon the experience of full-time, undergraduate students. The importance of these issues will increase with the popularity of part-time study at a postgraduate level; the paper presents a set of guidelines for project supervision and assessment. Andrew C. Simpson, Andrew P. Martin, Jeremy Gibbons, Jim Davies, Steve McKeever |
ICSE | 2 |
| 2002 | e-Science Experiences: Software Engineering Practice and the EU DataGridabstractThe conduct of collaborative scientific study mediated by the internet -e-science - is giving rise to a new type of large distributed software project. This paper reports initial experiences of one such project: the European DataGrid. We record observations about the intended lifecycle and process, compared with actual practice. The paper explores the applicability of current software development practices from academic, commercial, and open source sectors in the context of such Grid projects. Lee Momtahan, Andrew P. Martin |
APSEC | 2 |
| 2000 | Relating Z and First-Order LogicabstractAbstract. Despite being widely regarded as a gloss on first-order logic and set theory, Z has not been found to be very supportive of proof. This paper attempts to distinguish between the different philosophies of proof in Z. It discusses some of the issues which must be addressed in creating a proof technology for Z, namely schemas, undefinedness, and what kind of logic to use. Andrew P. Martin |
Formal Aspects Comput. | 1 |
| 2000 | A Calculus for Schemas in Z
S. M. Brien, Andrew P. Martin |
J. Symb. Comput. | 2 |
| 1998 | A Set-Theoretic Model for Real-Time Specification and Reasoning
Colin J. Fidge, Ian J. Hayes, Andrew P. Martin, Axel Wabenhorst |
MPC | 3 |
| 1996 | A Tactic Calculus-Abridged VersionabstractAbstract We present a very general language for expressing tactic programs. The paper describes some essential tactic combinators (tacticals), and gives them a formal semantics. Those definitions are used to produce a complete calculus for reasoning about tactics written in this language. The language is extended to cover structural combinators which enable the tactics to be precisely targeted upon particular sub-expressions. Andrew P. Martin, Paul H. B. Gardiner, Jim Woodcock 0001 |
Formal Aspects Comput. | 1 |