Ram Krishnan

dblp:84/6470 · DBLP profile ↗
← Back
37ranked-venue papers
8as first author
7since 2021 · last 2026
0000-0002-7402-553XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 4 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 first-authorComputer networks · 4 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 2Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Rethinking Access-Control Policy Authoring as a Multimodal Challenge [BlueSky Paper]
abstract
Access control policies are rarely authored directly as machine-enforceable specifications. Instead, policy intent is developed through meetings in which requirements are communicated through spoken discussion, organizational charts, and policy diagrams. Although recent advances in natural language processing have improved rule extraction from text, current policy engineering pipelines largely ignore visual artifacts, leaving substantial policy information unstructured and difficult to translate into enforceable form.
Sherifdeen Lawal, Xingmeng Zhao, Anthony Rios, Ram Krishnan
SACMAT5
2025 Machine Learning in Access Control: A Taxonomy [Systematization of Knowledge Paper]
abstract
Developing and managing access control systems is challenging due to the dynamic nature of users, resources, and environments. Recent advancements in machine learning (ML) offer promising solutions for automating the extraction of access control attributes, policy mining, verification, and decision-making. Despite these advancements, the application of ML in access control remains fragmented, resulting in an incomplete understanding of best practices. This work aims to systematize the use of ML in access control by identifying key components where ML can address various access control challenges. We propose a novel taxonomy of ML applications within this domain, highlighting current limitations such as the scarcity of public real-world datasets, the complexities of administering ML-based systems, and the opacity of ML model decisions. Additionally, we outline potential future research directions to guide both new and experienced researchers in effectively integrating ML into access control practices.
Mohammad Nur Nobi, Maanak Gupta, Ram Krishnan, Md. Shohel Rana, Lopamudra Praharaj, Mahmoud Abdelsalam
SACMAT3
2023 Utilizing The DLBAC Approach Toward a ZT Score-based Authorization for IoT Systems
abstract
The internet of Things (IoT) refers to a network of physical objects that are equipped with sensors, software, and other technologies in order to communicate with other devices and systems over the internet. IoT has emerged as one of the most important technologies of this century over the past few years. To ensure IoT systems' sustainability and security over the long term, several researchers lately motivated the need to incorporate the recently proposed zero trust (ZT) cybersecurity paradigm when designing and implementing access control models for IoT systems. This poster proposes a hybrid access control approach incorporating traditional and deep learning-based authorization techniques toward score-based ZT authorization for IoT systems.
Safwa Ameer, Ram Krishnan, Ravi S. Sandhu, Maanak Gupta
CODASPY2
2023 An Autoencoder-Based Image Anonymization Scheme for Privacy Enhanced Deep Learning
Ram Krishnan
DBSec2
2022 Toward Deep Learning Based Access Control
abstract
A common trait of current access control approaches is the challenging need to engineer abstract and intuitive access control models. This entails designing access control information in the form of roles (RBAC), attributes (ABAC), or relationships (ReBAC) as the case may be, and subsequently, designing access control rules. This framework has its benefits but has significant limitations in the context of modern systems that are dynamic, complex, and large-scale, due to which it is difficult to maintain an accurate access control state in the system for a human administrator. This paper proposes Deep Learning Based Access Control (DLBAC) by leveraging significant advances in deep learning technology as a potential solution to this problem. We envision that DLBAC could complement and, in the long-term, has the potential to even replace, classical access control models with a neural network that reduces the burden of access control model engineering and updates. Without loss of generality, we conduct a thorough investigation of a candidate DLBAC model, called DLBAC_alpha, using both real-world and synthetic datasets. We demonstrate the feasibility of the proposed approach by addressing issues related to accuracy, generalization, and explainability. We also discuss challenges and future research directions.
Mohammad Nur Nobi, Ram Krishnan, Yufei Huang 0001, Mehrnoosh Shakarami, Ravi S. Sandhu
CODASPY2
2022 Administration of Machine Learning Based Access Control
Mohammad Nur Nobi, Ram Krishnan, Yufei Huang 0001, Ravi S. Sandhu
ESORICS (2)2
2021 Access Control Policy Generation from User Stories Using Machine Learning
John Heaps, Ram Krishnan, Yufei Huang 0001, Jianwei Niu 0001, Ravi S. Sandhu
DBSec2
2019 Online Malware Detection in Cloud Auto-scaling Systems Using Shallow Convolutional Neural Networks
Mahmoud Abdelsalam, Ram Krishnan, Ravi S. Sandhu
DBSec2
2018 Malware Detection in Cloud Infrastructures Using Convolutional Neural Networks
abstract
A major challenge in Infrastructure as a Service (IaaS) clouds is its exposure to malware. Malware can spread rapidly within a datacenter and can cause major disruption to a cloud service provider and its clients. This paper introduces and discusses an effective malware detection approach in cloud infrastructure using Convolutional Neural Network (CNN), a deep learning approach. We initially employ a standard 2d CNN by training on metadata available for each of the processes in a virtual machine (VM) obtained by means of the hypervisor. We enhance the CNN classifier accuracy by using a novel 3d CNN (where an input is a collection of samples over a time interval), which greatly helps reduce mislabelled samples during data collection and training. Our experiments are performed on data collected by running various malware (mostly Trojans and Rootkits) on VMs. The malware used in our experiments are randomly selected. This reduces the selection bias of known-to-be highly active malware for easy detection. We demonstrate that our 2d CNN model reaches an accuracy of ≃ 79%, and our 3d CNN model significantly improves the accuracy to ≃ 90%.
Mahmoud Abdelsalam, Ram Krishnan, Yufei Huang 0001, Ravi S. Sandhu
IEEE CLOUD2
2017 Clustering-Based IaaS Cloud Monitoring
abstract
Organizations increasingly utilize cloud services such as Infrastructure as a Service (IaaS) where virtualized IT infrastructure are offered on demand by cloud providers. A major challenge for cloud providers is the security of virtual resources provided to its customers. In particular, a key concern is whether, for example, virtual machines (VMs) in the datacenter are performing tasks that are not expected of those machines. Given the scale of datacenters, continuous security monitoring of the virtual assets is essential to detect unexpected (and potentially malicious) behavior. In this paper, we develop a continuous monitoring framework for cloud IaaS. The proposed framework uses a modified version of sequential K-means clustering algorithm for anomaly detection based on variations in resource utilization that can be observed when cloud insiders or malware perform malicious tasks on cloud customers' VMs. Our approach assumes no prior knowledge of the installed applications on the VMs. Finally, our experiments are performed on data collected from our OpenStack (a popular open-source cloud IaaS software) testbed based on a standard 3-tier web architecture with the ability to scale-out (i.e., multiple copies of the server are spawned) and scale-back (i.e., the number of copies are reduced) on demand. The experiments are based on real-world as well as synthetically injected anomalies.
Mahmoud Abdelsalam, Ram Krishnan, Ravi S. Sandhu
CLOUD2
2016 A Comparison of Logical-Formula and Enumerated Authorization Policy ABAC Models
Prosunjit Biswas, Ravi S. Sandhu, Ram Krishnan
DBSec3
2016 Toward a framework for detecting privacy policy violations in android application code
abstract
Mobile applications frequently access sensitive personal information to meet user or business requirements. Because such information is sensitive in general, regulators increasingly require mobile-app developers to publish privacy policies that describe what information is collected. Furthermore, regulators have fined companies when these policies are inconsistent with the actual data practices of mobile apps. To help mobile-app developers check their privacy policies against their apps' code for consistency, we propose a semi-automated framework that consists of a policy terminology-API method map that links policy phrases to API methods that produce sensitive information, and information flow analysis to detect misalignments. We present an implementation of our framework based on a privacy-policy-phrase ontology and a collection of mappings from API methods to policy phrases. Our empirical evaluation on 477 top Android apps discovered 341 potential privacy policy violations.
Rocky Slavin, Xiaoyin Wang, Mitra Bokaei Hosseini, James Hester, Ram Krishnan, Jaspreet Bhatia, Travis D. Breaux, Jianwei Niu 0001
ICSE5
2016 Uni-ARBAC: A Unified Administrative Model for Role-Based Access Control
Prosunjit Biswas, Ravi S. Sandhu, Ram Krishnan
ISC3
2016 An Attribute-Based Protection Model for JSON Documents
Prosunjit Biswas, Ravi S. Sandhu, Ram Krishnan
NSS3
2016 Sequence Diagram Aided Privacy Policy Specification
abstract
A fundamental problem in the specification of regulatory privacy policies such as the Health Insurance Portability and Accountability Act (HIPAA) in a computer system is to state the policies precisely, consistent with their high-level intuition. In this paper, we propose UML sequence diagrams as a practical means to graphically express privacy policies. A graphical representation allows decision-makers such as application domain experts and security architects to easily verify and confirm the expected behavior. Once intuitively confirmed, our work in this article introduces an algorithmic approach to formalizing the semantics of sequence diagrams in terms of linear temporal logic (LTL) templates. In all the templates, different semantic aspects are expressed as separate, yet simple LTL formulas that can be composed to define the complex semantics of sequence diagrams. The formalization enables us to leverage the analytical powers of automated decision procedures for LTL formulas to determine if a collection of sequence diagrams is consistent, independent, etc. and also to verify if a system design conforms to the privacy policies. We evaluate our approach by modeling and analyzing a substantial subset of HIPAA rules using sequence diagrams.
Ram Krishnan, Rocky Slavin, Jianwei Niu 0001
IEEE Trans. Dependable Secur. Comput.2
2015 An open NFV and cloud architectural framework for managing application virality behaviour
abstract
One of the key goals of Network Functions Virtualization (NFV) is achieving energy efficiency through workload consolidation. A good example for maximizing energy savings is the Virtualization of Content Delivery Networks (vCDNs) NFV use case where the video streaming workloads exhibit significant difference between prime-time and non-prime-time usage of the infrastructure. This paper examines the practical challenges in maximizing energy efficiency for vCDN workloads. This paper proposes an open NFV architectural framework for conveying content virality information from Cloud applications such as YouTube, Twitter and mechanisms for leveraging it to maximize the energy efficiency for vCDN workloads. This paper also proposes a more general architecture for any Cloud/NFV application that may experience virality.
Dilip Krishnaswamy, Ram Krishnan, Diego R. López, Peter Willis 0001, Asif Qamar
CCNC2
2015 Virtual Resource Orchestration Constraints in Cloud Infrastructure as a Service
abstract
In an infrastructure as a service (IaaS) cloud, virtualized IT resources such as compute, storage and network are offered on demand by a cloud service provider (CSP) to its tenants (customers). A major problem for enterprise-scale tenants that typically obtain significant amount of resources from a CSP concerns orchestrating those resources in a secure manner. For instance, unlike configuring physical hardware, virtual resources in IaaS are configured using software, and hence prone to misconfigurations that can lead to critical security violations. Examples of such resource orchestration operations include creating virtual machines with appropriate operating system and software images depending on their purpose, creating networks, connecting virtual machines to networks, attaching a storage volume to a particular virtual machine, etc. In this paper, we propose attribute-based constraints specification and enforcement as a means to mitigate this issue. High-level constraints specified using attributes of virtual resources prevent resource orchestration operations that can lead to critical misconfigurations. Our model allows tenants to customize the attributes of their resources and specify fine-grained constraints. We further propose a constraint mining approach to automatically generate constraints once the tenants specify the attributes for virtual resources. We present our model, enforcement challenges, and its demonstration in OpenStack, the de facto open-source cloud IaaS software.
Khalid Zaman Bijon, Ram Krishnan, Ravi S. Sandhu
CODASPY2
2015 Secure Information and Resource Sharing in Cloud
abstract
The significant threats from information security breaches in cyber world is one of the most serious security problems. Organizations are facing growing number of sophisticated cyber-attacks every year. Efficient and secure sharing of attack and security information during cyber incident response plays increasingly significant role in fixing the problems as well as helping organizations recover fast. While traditional systems are slow and inefficient in sharing information and resources securely, cloud platform provides us a considerable convenience to facilitate the sharing. In this paper, we propose access control models for secure information and resource sharing (IARS) in cloud Infrastructure as a Service (IaaS).
Ram Krishnan, Ravi S. Sandhu
CODASPY2
2015 Integrating Attributes into Role-Based Access Control
Qasim Mahmood Rajpoot, Christian Damsgaard Jensen, Ram Krishnan
DBSec3
2015 Mitigating Multi-Tenancy Risks in IaaS Cloud Through Constraints-Driven Virtual Resource Scheduling
abstract
A major concern in the adoption of cloud infrastructure-as-a-service (IaaS) arises from multi-tenancy, where multiple tenants share the underlying physical infrastructure operated by a cloud service provider. A tenant could be an enterprise in the context of a public cloud or a department within an enterprise in the context of a private cloud. Enabled by virtualization technology, the service provider is able to minimize cost by providing virtualized hardware resources such as virtual machines, virtual storage and virtual networks, as a service to multiple tenants where, for instance, a tenant's virtual machine may be hosted in the same physical server as that of many other tenants. It is well-known that separation of execution environment provided by the hypervisors that enable virtualization technology has many limitations. In addition to inadvertent misconfigurations, a number of attacks have been demonstrated that allow unauthorized information flow between virtual machines hosted by a hypervisor on a given physical server. In this paper, we present attribute-based constraints specification and enforcement as a mechanism to mitigate such multi-tenancy risks that arise in cloud IaaS. We represent relevant properties of virtual resources (e.g., virtual machines, virtual networks, etc.) as their attributes. Conflicting attribute values are specified by the tenant or by the cloud IaaS system as appropriate. The goal is to schedule virtual resources on physical resources in a conflict-free manner. The general problem is shown to be NP-complete. We explore practical conflict specifications that can be efficiently enforced. We have implemented a prototype for virtual machine scheduling in OpenStack, a widely-used open-source cloud IaaS software, and evaluated its performance overhead, resource requirements to satisfy conflicts, and resource utilization.
Khalid Zaman Bijon, Ram Krishnan, Ravi S. Sandhu
SACMAT2
2015 Attributes Enhanced Role-Based Access Control Model
Qasim Mahmood Rajpoot, Christian Damsgaard Jensen, Ram Krishnan
TrustBus3
2014 Role and attribute based collaborative administration of intra-tenant cloud IaaS
abstract
Cloud Infrastructure as a Service (IaaS), where traditional IT infrastructure resources such as compute, storage and networking are owned by a cloud service provider (CSP) and offered as on-demand virtual resources to customers (tenants), is the fastest maturing service model in cloud computing. The
Ram Krishnan, Ravi S. Sandhu
CollaborateCom2
2014 A Formal Model for Isolation Management in Cloud Infrastructure-as-a-Service
Khalid Zaman Bijon, Ram Krishnan, Ravi S. Sandhu
NSS2
2013 Relational abstraction in community-based secure collaboration
abstract
Users of an online community are willing to share resources because they can expect reasonable behaviour from other members of the community. Such expectations are known as social contracts. In this work, we study the specification and enforcement of social contracts in a computer mediated collaboration environment. Specifically, we examine social contracts that contain both relationship- and history-based elements. A series of policy languages, all based on modal and temporal logics, with increasing expressiveness, have been proposed to express social contracts. Reference monitors are designed to correctly and efficiently enforce the specified policies. A technique called "relational abstraction" is employed to reduce the reference monitor into a purely relationship-based protection system, that is, what is commonly known as a social network system.
Philip W. L. Fong, Pooya Mehregan, Ram Krishnan
CCS3
2012 A lattice interpretation of group-centric collaboration with expedient insiders
abstract
For various reasons organizations need to collaborate with external consultants, e.g. domain specialists, on specific projects. Many security-oriented organizations deploy multi-level systems which enforce one directional information flow in a lattice of security labels. However, traditional lat
Khalid Zaman Bijon, Tahmina Ahmed, Ravi S. Sandhu, Ram Krishnan
CollaborateCom4
2012 A Unified Attribute-Based Access Control Model Covering DAC, MAC and RBAC
Ram Krishnan, Ravi S. Sandhu
DBSec2
2011 RT-based administrative models for community cyber security information sharing
abstract
We develop a series of formal administrative models for recently proposed informal requirements for community cyber security information sharing. Traditional enterprise- oriented administrative models are not suitable for the highly dynamic and distributed nature of
Ravi S. Sandhu, Khalid Zaman Bijon, Ram Krishnan
CollaborateCom4
2011 Group-Centric Secure Information-Sharing Models for Isolated Groups
abstract
Group-Centric Secure Information Sharing (g-SIS) envisions bringing users and objects together in a group to facilitate agile sharing of information brought in from external sources as well as creation of new information within the group. We expect g-SIS to be orthogonal and complementary to authorization systems deployed within participating organizations. The metaphors “secure meeting room” and “subscription service” characterize the g-SIS approach. The focus of this article is on developing the foundations of isolated g-SIS models. Groups are isolated in the sense that membership of a user or an object in a group does not affect their authorizations in other groups. Present contributions include the following: formal specification of core properties that at once help to characterize the family of g-SIS models and provide a “sanity check” for full policy specifications; informal discussion of policy design decisions that differentiate g-SIS policies from one another with respect to the authorization semantics of group operations; formalization and verification of a specific member of the family of g-SIS models; demonstration that the core properties are logically consistent and mutually independent; and identification of several directions for future extensions. The formalized specification is highly abstract. Besides certain well-formedness requirements that specify, for instance, a user cannot leave a group unless she is a member, it constrains only whether user-level read and write operations are authorized and it does so solely in terms of the history of group operations; join and leave for users and add, create, and remove for objects. This makes temporal logic one of the few formalisms in which the specification can be clearly and concisely expressed. The specification serves as a reference point that is the first step in deriving authorization-system component specifications from which a programmer with little security expertise could implement a high-assurance enforcement system for the specified policy.
Ram Krishnan, Jianwei Niu 0001, Ravi S. Sandhu, William H. Winsborough
ACM Trans. Inf. Syst. Secur.1
2010 Towards Secure Information Sharing models for community Cyber Security
abstract
In this paper, we motivate the need for new models for Secure Information Sharing (SIS) in the specific domain of community cyber security. We believe that similar models will be applicable in numerous other domains. The term community in this context refers to a county or larger city size unit with
Ravi S. Sandhu, Ram Krishnan, G. B. White
CollaborateCom2
2009 A conceptual framework for Group-Centric secure information sharing
abstract
In this paper, we propose a conceptual framework for developing a family of models for Group-Centric information sharing. The traditional approach to information sharing, characterized as Dissemination-Centric in this paper, focuses on attaching attributes and policies to an object (sometimes called "sticky policies") as it is disseminated from producers to consumers in a system. In contrast, Group-Centric sharing envisions bringing the subjects and objects together in a group to facilitate sharing. The metaphor is that of a secure meeting room where participants and information come together to "share" information for some common purpose. Another metaphor is that of the subscription model where, depending on policy, joining users may or may not be authorized to access past content. We argue that in such contexts, and in accordance with different application use cases, authorizations are influenced by the temporal ordering of subject and object group membership and by the precise nature of membership operations. For instance some subjects may only get future information added to the group while others may also be able to access previously added information. We develop a lattice of models based on variations of these basic membership operations, and discuss usage scenarios to illustrate practical applications of this lattice. Two principles guide Group-Centric models. First, "share but differentiate" which promotes sharing while differentiating user authorizations depending on temporal aspect of membership. Next, "groups within groups" which advocates relationships (such as a hierarchy) between multiple groups. In this paper, we confine our attention to read accesses in a single group.
Ram Krishnan, Ravi S. Sandhu, Jianwei Niu 0001, William H. Winsborough
AsiaCCS1
2009 Towards a framework for group-centric secure collaboration
abstract
The concept of groups is a natural aspect of most collaboration scenarios. Group-Centric Secure Information Sharing models (g-SIS) have been recently proposed in which users and objects are brought together to promote sharing and collaboration. Users may join, leave and re-join and objects may be ad
Ram Krishnan, Ravi S. Sandhu, Jianwei Niu 0001, William H. Winsborough
CollaborateCom1
2009 Foundations for group-centric secure information sharing models
abstract
We develop the foundations for a theory of Group-Centric Secure Information Sharing (g-SIS), characterize a specific family of models in this arena and identify several directions in which this theory can be extended. Traditional approach to information sharing, characterized as Dissemination-Centric, focuses on attaching attributes and policies to an object as it is disseminated from producers to consumers in a system. In contrast, Group-Centric sharing envisions bringing the users and objects together in a group to facilitate sharing. The metaphors "secure meeting room" and "subscription service" characterize the Group-Centric approach where participants and information come together to share for some common purpose. Our focus in this paper is on semantics of group operations: Join and Leave for users and Add and Remove for objects, each of which can have several variations called types.
Ram Krishnan, Ravi S. Sandhu, Jianwei Niu 0001, William H. Winsborough
SACMAT1
2007 PEI models towards scalable, usable and high-assurance information sharing
abstract
Secure Information Sharing (SIS) or "share but protect" is a challenging and elusive problem both because of its broad scope and complexity ranging right from conception (objective and policy) to culmination (implementation). In this paper, we consider how to solve SIS challenges with three main and conflicting objectives: scalability, usability and high-assurance. In the context of SIS, high-assurance requires strong controls on the client. It is widely accepted that such controls cannot be entirely software-based. In this regard, we consider solutions based on commercially emerging hardware-rooted Trusted Computing Technology. For SIS, we argue super-distribution ("protect once and access wherever authorized") and off-line access are necessary to achieve scalability and usability. We limit super-distribution to occur within a group of Trusted Platform Module [1] or TPM-enabled machine. For simplicity, we assume all content that are distributed to be read-only. Drilling down, we discuss Policy, Enforcement and Implementation (PEI) models for SIS within a group (group-based SIS or g-SIS).
Ram Krishnan, Ravi S. Sandhu, Kumar Ranganathan
SACMAT1
1997 Rate-based control schemes for ABR traffic - Design principles and performance comparison
Ram Krishnan
Comput. Networks ISDN Syst.1
1993 Is There Life beyond Linear Topologies? A Comparison of DQDB and Manhattan Street Network
abstract
The performance and reliability comparison of two networks that have been proposed for use as high-speed metropolitan area networks (MANs)-the Manhattan street network (MS Net) and the distributed-queue dual-bus (DQDB) network-are compared. Both networks use slotted access protocols and have the same number of links, transmitters, and receivers per node. It is shown that the MS Net provides a much higher network throughput for a variety of traffic patterns, both uniform and nonuniform. It is shown that the MS Net can survive more failures than the DQDB network and that failures cause a lesser performance degradation in the MS Net. It is also shown that higher-level mechanisms are required in the DQDB network to recover from link failures, whereas deflection routing is sufficient in the MS Net.>
Ram Krishnan, Nicholas F. Maxemchuk
INFOCOM1
1993 Choice of Allocation Granularity in Multipath Source Routing Schemes
abstract
Multipath source routing schemes can be distinguished by their choice of allocation granularity. The schemes proposed in the literature advocate a per-connection allocation wherein all the packets of a connection are constrained to follow the same path. The authors believe that a smaller allocation granularity permits a finer control to be exerted and would result in improved performance, especially in the presence of bursty traffic sources. A simple two-node network is used to compare the performance of both allocation schemes. An analytical model is developed to compute the resequencing delay distribution for the per-packet allocation. It is observed that as the burstiness of the arrival process increases, the per-packet allocation is able to accommodate bursts in a more graceful fashion, resulting in better performance. The per-packet allocation also permits a more equitable distribution of network resources than the per-connection.>
Ram Krishnan, John A. Silvester
INFOCOM1
1993 A Comparison of Linear and Mesh Topologies - DQDB and the Manhattan Street Network
abstract
The authors make a performance and reliability comparison of two networks that have been proposed for use as high-speed metropolitan area networks (MANs)-the Manhattan street network (MSNet) and the distributed queue dual bus (DQDB) network. Both networks use slotted access protocols and have the same number of links, transmitters, and receivers per node. The DQDB network has been adopted by the IEEE 802.6 committee as the metropolitan area network (MAN) standard. The authors demonstrate the relative superiority of the MSNet over the DQDB network. They show that the MSNet provides a much higher network throughput for a variety of traffic patterns-uniform and nonuniform. They also look at the reliability of both networks and show that the MSNet can survive more failures than the DQDB network and that failures cause a lesser performance degradation in the MSNet. It is also shown that higher-level mechanisms are required in the DQDB network to recover from link failures whereas deflection routing is sufficient in the MSNet.>
Nicholas F. Maxemchuk, Ram Krishnan
IEEE J. Sel. Areas Commun.2