Amirreza Masoumzadeh 0001

dblp:86/1567 · also Amir Masoumzadeh 0001 · DBLP profile ↗
← Back
20ranked-venue papers
7as first author
9since 2021 · last 2026
0000-0003-0647-7785ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 5 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Active Learning of Negative Relationship-Based Authorizations
abstract
Relationship-based access control (ReBAC) policies naturally express authorization decisions over complex relationships, but their expressiveness makes them difficult to audit, validate, migrate, and maintain. Learning ReBAC policy using observed authorization decisions can help in these tasks, yet it remains challenging in real deployments where complete authorization logs are hard to obtain and expressive features such as \deny rules are common. Existing ReBAC mining approaches either rely on complete logs to infer \permit and \deny rules or avoid logs via an active learning framework but learn only \permit rules, leaving explicit denials indistinguishable from deny-by-default behavior. This paper extends the earlier active learning framework by introducing ARDEN (Active ReBAC Discovery with Explicit Negatives), a multi-phase active learning and optimization workflow with the goal of minimally exploring the authorization space of a target system and composing an optimal set of \permit and \deny rules that capture its authorization decisions. In contrast to the recent work on offline mining of negative ReBAC policies, ARDEN uses a unified strategy for optimizing the selection of \permit and \deny rules. We also propose enhancements to the earlier active learning architecture such as cache-assisted authorization queries and a state-prefix random walk oracle that significantly impact the performance of the framework. We evaluate ARDEN on 18 configuration-induced policies derived from a controlled deployment of the HotCRP conference management system. We report on the performance of our framework in terms of learning accuracy and cost, as well as a comparative evaluation against three baseline approaches.
Ferhat Demirkiran, Amirreza Masoumzadeh 0001
CODASPY2
2025 Enhancing Relationship-Based Access Control Policies with Negative Rule Mining
abstract
Relationship-based access control (ReBAC) policies often rely solely on positive authorization rules, implicitly denying all other requests by default. However, many scenarios require explicitly stating negative authorization rules to capture exceptions or special restrictions that are not naturally enforced by deny-by-default semantics. This work presents a systematic method to mine ReBAC policies that integrate both positive and negative authorization rules from observed authorizations. We formalize the mining problem, show its NP-hardness, and develop an approach that identifies minimal policies while accurately reflecting observed access decisions. We demonstrate the feasibility and effectiveness of our proposed approach through a set of experiments. Our experimental evaluations on representative datasets demonstrate that including negative rules leads to more concise and semantically complete policies, confirming the necessity of explicit negative authorizations in complex access control settings.
Ferhat Demirkiran, Amirreza Masoumzadeh 0001
CODASPY2
2024 Converting Rule-Based Access Control Policies: From Complemented Conditions to Deny Rules
abstract
Using access control policy rules with deny effects (i.e., negative authorization) can be preferred to using complemented conditions in the rules as they are often easier to comprehend in the context of large policies. However, the two constructs have different impacts on the expressiveness of a rule-based access control model. We investigate whether policies expressible using complemented conditions can be expressed using deny rules instead. The answer to this question is not always affirmative. In this paper, we propose a practical approach to address this problem for a given policy. In particular, we develop theoretical results that allow us to pose the problem as a set of queries to an SAT solver. Our experimental results using an off-the-shelf SAT solver demonstrate the feasibility of our approach and offer insights into its performance based on access control policies from multiple domains.
Josué A. Ruiz, Paliath Narendran, Amirreza Masoumzadeh 0001, Padmavathi Iyer
SACMAT3
2023 Towards Automated Learning of Access Control Policies Enforced by Web Applications
abstract
Obtaining an accurate specification of the access control policy enforced by an application is essential in ensuring that it meets our security/privacy expectations. This is especially important as many of real-world applications handle a large amount and variety of data objects that may have different applicable policies. We investigate the problem of automated learning of access control policies from web applications. The existing research on mining access control policies has mainly focused on developing algorithms for inferring correct and concise policies from low-level authorization information. However, little has been done in terms of systematically gathering the low-level authorization data and applications' data models that are prerequisite to such a mining process. In this paper, we propose a novel black-box approach to inferring those prerequisites and discuss our initial observations on employing such a framework in learning policies from real-world web applications.
Padmavathi Iyer, Amirreza Masoumzadeh 0001
SACMAT2
2022 Effective Evaluation of Relationship-Based Access Control Policy Mining
abstract
Mining algorithms for relationship-based access control policies produce policies composed of relationship-based patterns that justify the input authorizations according to a given system graph. The correct functioning of a policy mining algorithm is typically tested based on experimental evaluations, in each of which the miner is presented with a set of authorizations and a system graph, and is expected to produce the corresponding ground truth policy. In this paper, we propose formal properties that must exist between the system graph and the ground truth policy in an evaluation test so that the miner is challenged to produce the exact ground truth policy. We show that failure to verify these properties in the experiment leads to inadequate evaluation, i.e., not truly testing whether the miner can handle the complexity of the ground truth policy. We also argue that following these properties would provide a computational advantage in the evaluations. We propose algorithms to identify and correct violations of these properties in system graphs. We also present our observations regarding these properties and their enforcement using a set of experimental studies.
Padmavathi Iyer, Amirreza Masoumzadeh 0001
SACMAT2
2022 BlueSky: Physical Access Control: Characteristics, Challenges, and Research Opportunities
abstract
Physical access control (PAC) is an integral part of the physical security system of any organization. However, despite the size of the PAC industry and its importance in securing our physical environments, public research and development regarding PAC are limited. This paper aims to lower the barriers for the access control research community to explore and engage in the research opportunities regarding PAC systems. We characterize PAC systems and present an access control architecture that captures their central concepts, such as physical space models and different levels of policies, and processes such as policy conversion, enforcement, and analysis. We discuss how PAC can be distinguished from logical access control (LAC), which is applicable to cyber environments. We also present several unique challenges and research opportunities that the PAC domain introduces.
Amirreza Masoumzadeh 0001, Hans van der Laan, Albert Dercksen
SACMAT1
2022 On the Expressive Power of Negated Conditions and Negative Authorizations in Access Control Models
Padmavathi Iyer, Amirreza Masoumzadeh 0001, Paliath Narendran
Comput. Secur.2
2022 Learning Relationship-Based Access Control Policies from Black-Box Systems
abstract
Access control policies are crucial in securing data in information systems. Unfortunately, often times, such policies are poorly documented, and gaps between their specification and implementation prevent the system users, and even its developers, from understanding the overall enforced policy of a system. To tackle this problem, we propose the first of its kind systematic approach for learning the enforced authorizations from a target system by interacting with and observing it as a black box. The black-box view of the target system provides the advantage of learning its overall access control policy without dealing with its internal design complexities. Furthermore, compared to the previous literature on policy mining and policy inference, we avoid exhaustive exploration of the authorization space by minimizing our observations. We focus on learning relationship-based access control (ReBAC) policy, and show how we can construct a deterministic finite automaton (DFA) to formally characterize such an enforced policy. We theoretically analyze our proposed learning approach by studying its termination, correctness, and complexity. Furthermore, we conduct extensive experimental analysis based on realistic application scenarios to establish its cost, quality of learning, and scalability in practice.
Padmavathi Iyer, Amirreza Masoumzadeh 0001
ACM Trans. Priv. Secur.2
2021 Towards a Theory for Semantics and Expressiveness Analysis of Rule-Based Access Control Models
abstract
Recent access control models such as attribute-based access control and relationship-based access control allow flexible expression of authorization policies using the concepts of rules and conditional expressions. The independent nature of policy rules from each other and the amount of flexibility that they enjoy (e.g., the type of conditional expressions they support and whether they can permit or deny matching requests) make those policies quite expressive. But how expressive are they? Do we need to enable all possible flexibilities in a rule-based model to achieve the maximum possible expressiveness? Answering such questions is essential in making informed decisions when designing new models or choosing existing models for implementation. In this paper, we propose an approach towards answering those questions by developing a novel theory for capturing the semantics of rule-based policies depending on their support of different constructs such as flexibility of conditional expressions, rule modalities, and conflict resolution. Our formal policy semantics model enjoys an intuitive design that can capture the semantics of various rule-based policies. We show the well-formedness properties of such semantics and how they can be used to analyze the expressive power of a number of rule-based models.
Amirreza Masoumzadeh 0001, Paliath Narendran, Padmavathi Iyer
SACMAT1
2020 Active Learning of Relationship-Based Access Control Policies
abstract
Understanding access control policies is essential in understanding the security behavior of systems. However, often times, a complete and accurate specification of the enforced access control policy in a system is not available. In fact, scale and complexity of a system, or unavailability of its source code, may prevent users and even its developers from having access to such accurate specification. In this paper, we propose a novel, systematic approach for learning access control policies where target systems are treated as black boxes. In particular, we show how we can construct a deterministic finite automaton (DFA) characterizing the relationship-based access control (ReBAC) policy of a system by interacting with its access control engine using minimal number of access requests. Our experiments on realistic application scenarios and their promising results demonstrate the feasibility, scalability and efficiency of our learning approach.
Padmavathi Iyer, Amirreza Masoumzadeh 0001
SACMAT2
2019 Generalized Mining of Relationship-Based Access Control Policies in Evolving Systems
abstract
Relationship-based access control (ReBAC) provides a flexible approach to specify policies based on relationships between system entities, which makes them a natural fit for many modern information systems, beyond online social networks. In this paper we are concerned with the problem of mining ReBAC policies from lower-level authorization information. Mining ReBAC policies can address transforming access control paradigms to ReBAC, reformulating existing ReBAC policies as more information becomes available, as well as inferring potentially unknown policies. Particularly, we propose a systematic algorithm for mining ReBAC authorization policies, and a first of its kind approach to mine graph transition policies that govern the evolution of ReBAC systems. Experimental evaluation manifests efficiency of the proposed approaches.
Padmavathi Iyer, Amirreza Masoumzadeh 0001
SACMAT2
2018 Security Analysis of Relationship-Based Access Control Policies
abstract
Relationship-based access control (ReBAC) policies can express intricate protection requirements in terms of relationships among users and resources (which can be modeled as a graph). Such policies are useful in domains beyond online social networks. However, given the updating graph of user and resources in a system and expressive conditions in access control policy rules, it can be very challenging for security administrators to envision what can (or cannot) happen as the protection system evolves.
Amirreza Masoumzadeh 0001
CODASPY1
2018 Mining Positive and Negative Attribute-Based Access Control Policy Rules
abstract
Mining access control policies can reduce the burden of adopting more modern access control models by automating the process of generating policies based on existing authorization information in a system. Previous work in this area has focused on mining positive authorizations only. That includes the literature on mining role-based access control policies (which are naturally about positive authorization) and even more recent work on mining attribute-based access control (ABAC) policies. However, various theoretical access control models (including ABAC), specification standards (such as XACML), and implementations (such as operating systems and databases) support negative authorization as well as positive authorization. In this paper, we propose a novel approach to mine ABAC policies that may contain both positive and negative authorization rules. We evaluate our approach using two different policies in terms of correctness, quality of rules (conciseness), and time. We show that while achieving the new goal of supporting negative authorizations, our proposed algorithm outperforms existing approach to ABAC mining in terms of time.
Padmavathi Iyer, Amirreza Masoumzadeh 0001
SACMAT2
2017 Modeling Exposure in Online Social Networks
abstract
In online social networks (OSNs), the privacy of users is impacted by exposure of information about those users to other users of the system. Various factors, including design and user behavior, may affect the degree to which information about users is exposed. We propose the notion of knowledge exposure that measures the probability that information about users will be seen by others. We argue that such a measure can give OSN users and designers insight about how privacy is affected based on system design and user behavior. We present exposure as a promising notion that can complement privacy control efforts in an OSN rather than replacing existing measures such as access control. We provide a formal model of exposure in an OSN, and demonstrate through experiments how it can be calculated for various information items.
Andrew Cortese, Amirreza Masoumzadeh 0001
PST2
2013 Privacy settings in social networking systems: what you cannot control
abstract
In this paper, we propose a framework to formally analyze what privacy-sensitive information is protected by the stated policies of a Social Networking System (SNS), based on an expression of ideal protection policies for a user. Our ontology-based framework can capture complex and fine-grained privacy-sensitive information in SNSs, and find out missing policies, given a user's ideal policies, and SNS's privacy settings and described system policies. We propose notions of policy completeness for SNSs to facilitate such an analysis. Our case study of using this approach on Facebook shows that we can effectively identify important missing policies.
Amirreza Masoumzadeh 0001, James B. D. Joshi
AsiaCCS1
2012 Preserving Structural Properties in Edge-Perturbing Anonymization Techniques for Social Networks
abstract
Social networks are attracting significant interest from researchers in different domains, especially with the advent of social networking systems which enable large-scale collection of network information. However, as much as analysis of such social networks can benefit researchers, it raises serious privacy concerns for the people involved in them. To address such privacy concerns, several techniques, such as k-anonymity-based approaches, have been proposed in the literature to provide user anonymity in published social networks. However, these methods usually introduce a large amount of distortion to the original social network graphs, thus, raising serious questions about their utility for useful social network analysis. Consequently, these techniques may never be applied in practice. We propose two methods to enhance edge-perturbing anonymization methods based on the concepts of structural roles and edge betweenness in social network theory. We experimentally show significant improvements in preserving structural properties in an anonymized social network achieved by our approach compared to the original algorithms over several data sets.
Amirreza Masoumzadeh 0001, James B. D. Joshi
IEEE Trans. Dependable Secur. Comput.1
2011 A secure, constraint-aware role-based access control interoperation framework
abstract
With the growing needs for and the benefits of sharing resources and information among different organizations, an interoperation framework that automatically integrates policies to facilitate such cross-domain sharing in a secure way is becoming increasingly important. To avoid security breaches, such policies must enforce the policy constraints of the individual domains. Such constraints may include temporal constraints that limit the times when the users can access the resources, and separation of duty (SoD) constraints. Existing interoperation solutions do not address such cross-domain temporal access control and SoDs requirements. In this paper, we propose a role-based framework to facilitate secure interoperation among multiple domains by ensuring the enforcement of temporal and SoD constraints of individual domains. To support interoperation, we do not modify the internal policies, as most of the current approaches do. We present experimental results to demonstrate our proposed framework is effective and easily realizable.
Nathalie Baracaldo, Amirreza Masoumzadeh 0001, James B. D. Joshi
NSS2
2010 Preserving structural properties in anonymization of social networks
abstract
A social network is a collection of social entities and the relations among them. Collection and sharing of such network data for analysis raise significant privacy concerns for the involved individuals, especially when human users are involved. To address such privacy concerns, several techniques,
Amirreza Masoumzadeh 0001, James B. D. Joshi
CollaborateCom1
2009 LBS (k, T)-anonymity: a spatio-temporal approach to anonymity for location-based service users
abstract
We propose a location-based query anonymization technique, LBS (k, T)-anonymization, that ensures anonymity of user's query in a specific time window against what we call known user attack. We distinguish between our technique and related work on k-anonymity for LBSs by showing that they target different privacy inference attacks. Also, we analyze the inconsistency of the existing predominant approach with the original definition of k-anonymity and its implications on the anonymization. Finally, we present an evaluation framework that assess the applicability and performance of the proposed technique using an evaluation framework.
Amirreza Masoumzadeh 0001, James B. D. Joshi, Hassan A. Karimi
GIS1
2008 RiBAC: Role Interaction Based Access Control Model for Community Computing
Youna Jung, Amirreza Masoumzadeh 0001, James B. D. Joshi, Minkoo Kim
CollaborateCom2