VLDB 2026 Research / reviewers in the wild / expert
Dan Thomsen
dblp:85/3428 · also D. J. Thomsen, Dan J. Thomsen
· DBLP profile ↗
11ranked-venue papers
6as first author
2since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 6 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | NEUTRON: A Graph-based Pipeline for Zero-trust Network ArchitecturesabstractThe Zero-Trust Architecture (ZTA) security paradigm deploys comprehensive user- and resource-aware defenses both at the network's perimeter and inside the network. However, deploying a ZTA approach requires specifying and managing a large, network spanning set of fine-grained security policies, which will increase administrators' workloads and increase the chance of errors. This paper presents the design and prototype implementation of the NEUTRON policy framework, which provides an automated end-to-end policy pipeline, specification, management, testing, and deployment. NEUTRON uses a flexible, graph-based approach to specify and share complex, fine-grained network security policies. NEUTRON provides a software structure so that policy patterns may be easily shared between organizations, reducing the burden of creating the policy. Administrators assemble the software for their site, and the NEUTRON policy generator creates the entire network-wide security policy. Treating the security policy like software also allows new approaches to policy verification and policy change impact analysis. Thus we designed the Security Policy Regression Tool (SPRT), which uses our novelRuleset Aggregation Algorithm to perform scalable verification of the network-wide security policy across the network model. Moreover, our graph-based framework allows for efficient computation and visualization of the policy change impact. Charalampos Katsis, Fabrizio Cicala, Dan Thomsen, Nathan Ringo, Elisa Bertino |
CODASPY | 3 |
| 2021 | Can I Reach You? Do I Need To? New Semantics in Security Policy Specification and TestingabstractThe zero trust principle only allows authorized and authenticated actions in a computer network. A network policy satisfies the least privilege principle by minimizing the network permissions to only those needed by users and applications. However, administrators face many challenges in creating a least privilege policy since it requires a detailed understanding of the network topology and knowing the communication requirements of every network application and user. This paper addresses those challenges by introducing a graph-based policy specification framework to capture a network's communication requirements and a network compiler that turns those requirements into an enforceable policy. To offset the effort of building such a stringent policy, we incorporate patterns to spread the work of policy creation over time and people. In the paper, we first elaborate on how our framework's semantics enhances network security and resilience. We then introduce a Security Policy Regression Testing tool (SPRT), which leverages our framework's semantics, to test and reason about consistency, correctness, and relevance of network security policies. Finally, we outline relevant research directions. Charalampos Katsis, Fabrizio Cicala, Dan Thomsen, Nathan Ringo, Elisa Bertino |
SACMAT | 3 |
| 2018 | Network Policy Enforcement Using Transactions: The NEUTRON ApproachabstractWe propose a tool to capture applications requirements with respect to the enforcement of network security policies in an object-oriented design language. Once a design captures clear, concise, easily understood network requirements new technologies become possible, including network transactions and user-driven policies to remove rarely used network permissions until needed, creating a least privilege in time policy. Existing security enforcement policies represent a model of all allowable behavior. Only modeling allowable behavior requires that any entity that may need a permission, be granted it permanently. Refining the modeling to distinguish between common behavior and rare behavior will increase security. The increased security comes with costs, such as requiring users to strongly authenticate more often. This paper discusses those costs and the complexity of increasing security enforcement models. Dan Thomsen, Elisa Bertino |
SACMAT | 1 |
| 2011 | Practical policy patternsabstractThe paper attempts to encourage deeper thinking about the nature of security enforcement policies with the intent of fostering a practical engineering design approach for building security enforcement policy. The paper suggests several approaches to lower the cost of developing security enforcement policies by developing technology to share enforcement policies like open source software, including patterns, isolation of site specific policy and tools to increase the ability of humans to understand the implemented policy. The paper also suggests research avenues for increasing human understanding of enforcement policy. Dan Thomsen |
CODASPY | 1 |
| 2001 | Introduction to Classic PapersabstractPliny the Elder, 23 to 79 CE, is best known for writing a thirty-seven volume series called the Historia Naturalis. Had Pliny the Elder written a thirty seven volume survey of computer security there is no law of the physical universe that prevents us from benefiting from his insights. Physical laws aside the very real laws of human nature tend to render the past as a fuzzy and indistinct blur. Which brings us to this collection of three papers. The Internet has fostered a new surge in computer security practitioners. In a mature field of study many of the classic contributions are well known, and have been summarized and restated countless times. Computer security is a relatively new field that spans a wide range of topics. The question arises “How do new practitioners sort through computer security history to find the data they need, when they are swamped with just the data published in the past year?” Our answer is to dust off papers that influenced computer security thought and print them again. Today we have one benefit that was not available when the papers were originally published: hindsight. Rather than simply republishing the original papers, the authors have updated them, placing the papers in historical perspective. The authors also let us know what happened to the work after publication. After our initial excitement about including classic papers with a modern perspective died down we were faced with a tough dilemma. How do we choose? The thoughts that have shaped the computer security field are spread throughout hundreds of papers, and technical reports. Would classic papers be measured by the number of references in other papers? The degree of influence the paper had? The degree of innovation? Or the amount of additional funding? We quickly realized there would be no way to quantify all the papers and rank them by contribution. Thus we came up with a simple approach 1. Create an unordered list of high impact papers that were more than ten years old 2. Start asking the original authors if they could commit to writing a historical perspective for the paper Based on this approach we are grateful to have received three papers dealing with some the basic components of computer security • Information flow • System composition • Application specific security policies The classic papers retrospectives represent a great deal of work by the original authors and we wish to thank Carl Landwehr, John Dobson and John McHugh for their commitment. The classic papers are an experiment for this year’s conference. We hope to not only revisit the concepts presented in the paper, but also appreciate how the concepts and approaches impacted the field in general. What assumptions were made then and should they be rethought in today’s context? We welcome comments on the classic paper session so we can shape and revise the session for future conferences. Hopefully you will find these papers useful tools in creating future classic papers. Dan Thomsen |
ACSAC | 1 |
| 1999 | Napoleon: A Recipe for WorkflowabstractThe paper argues that Napoleon, a flexible, role-based access control (RBAC) modeling environment, is also a practical solution for enforcing business process control, or workflow policies. Napoleon provides two important benefits for workflow: simplified policy management and support for heterogeneous, distributed systems. We discuss our strategy for modeling workflow in Napoleon, and we present an architecture that incorporates Napoleon into a workflow management system. Charles N. Payne, Dan Thomsen, J. Bogle, Richard C. O'Brien |
ACSAC | 2 |
| 1998 | Role-Based Access Control Framework for Network EnterprisesabstractA business's success depends on its ability to protect valuable business assets in an increasingly hostile environment. Protecting information requires a cost, not only in purchasing security components, but also in ensuring that those security components are properly managed. Role based access control (RBAC) shows promise for making security administration easier, thus reducing the cost of managing security components. RBAC provides a convenient layer of abstraction by describing access control patterns. This paper presents an RBAC framework comprised of seven abstract layers. Multiple layers allow users to work with a layer they understand. Thus a balance can be struck between fine grained access control and ease of management. The goal is to provide easy security management for a wide variety of network applications. The NAPOLEON tool which implements parts of the framework is also described. Dan Thomsen, D. O'Brien, J. Bogle |
ACSAC | 1 |
| 1990 | A comparison of type enforcement and Unix setuid implementation of well-formed transactionsabstractTwo security mechanisms are compared and contrasted based on their implementation of the concept of well-formed transactions (D. Clark et al., 1987). They introduced the notion of transformation procedures which are intended to perform integrity preserving or enhancing operations on various classes of data. These operations are called well-formed transactions. This paper compares the effectiveness of two mechanisms for implementing the concept of a well-formed transaction, the Secure Ada Target (SAT) type enforcement mechanism and the Unix setuid mechanism.> Dan Thomsen, J. Thomas Haigh |
ACSAC | 1 |
| 1989 | Multi-party conflict: the problem and its solutionsabstractCurrently there is a great deal of interest concerning polyinstantiation in database management systems (DBMSs). However, polyinstantiation is a specific solution to a problem faced by all secure systems, and the problem itself is not well characterized. The problem stems from the interference between subjects of different security compartments. The authors focus on this problem, which they call multiparty update conflict (MUC). They discuss and evaluate some solutions to the MUC problem, such as polyinstantiation and rigid classification. A framework for a class of MUC solutions based on polyinstantiation is described, and several intermediate solutions between rigid classification and polyinstantiation are enumerated.> Thomas F. Keefe, Dan Thomsen, Wei-Tek Tsai, M. R. Hansch |
ACSAC | 2 |
| 1989 | A summary of the LDV solution to the homework problemabstractAt the 2nd RADC Database Security Workshop the requirements for a small secure application were presented as a homework problem. This paper highlights how LDV (LOCK Data Views, a prototype trusted DBMS from Honeywell) enforces the security requirements of this application. The results were simulated on a small LDV prototype written in LISP. Rather than present LDV's whole solution to the homework problem this paper presents some of the unique security features of LDV that were used to solve the problem.> Paul D. Stachour, Dan Thomsen |
ACSAC | 2 |
| 1989 | Prototyping to explore MLS/DBMS design
Dan Thomsen, Wei-Tek Tsai, Bhavani Thuraisingham |
Comput. Secur. | 1 |