VLDB 2026 Research / reviewers in the wild / expert
Ping Yang 0002
dblp:86/2711-2
· DBLP profile ↗
35ranked-venue papers
9as first author
6since 2021 · last 2026
0000-0001-9058-2822ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 8 · 6 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-authorSystems, architecture and hardware · 3 · 2 since 2021Computer networks · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2Theory of computation · 2 · 1 first-authorArtificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Secure Multi-Timescale Orchestration for Zero-Trust Cross-Datacenter Networks
Yahuza Bello, Ping Yang 0002 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Graphite: Real-Time Graph-Based Detection of Windows Fileless Malware Attacks
Priti Prabhakar Wakodikar, Joon-Young Gwak, Guanhua Yan, Xiaokui Shu, Scott D. Stoller, Ping Yang 0002 |
SecureComm (3) | 7 |
| 2023 | V-Recover: Virtual Machine Recovery When Live Migration FailsabstractLive migration is a critical technology used in cloud infrastructures to transfer running virtual machines (VMs). When live migration fails, as it often does, it is critical that any VMs in transit are not lost. There are two primary live migration techniques – pre-copy and post-copy. Pre-copy transfers a VM's memory to the destination before its virtual CPUs are transferred, whereas post-copy does the reverse. Both pre-copy and post-copy will lose the VM if the source machine fails during migration. Additionally, post-copy can lose the VM if the destination machine or network fail since the VM's memory and execution state are split across the source and destination machines. We present V-Recover, an approach to recover a VM when the source, destination, or network fails during live migration. V-Recover consists of two techniques: (1) aforward incremental checkpointing(FIC) mechanism to handle source machine failure during both pre-copy and post-copy, and (2) areverse incremental checkpointing(RIC) mechanism to handle destination or network failure during post-copy. We present the design, implementation, and evaluation of V-Recover in the KVM/QEMU virtualization platform. Our evaluations show that V-Recover effectively recovers a VM upon migration failure with acceptable overheads on migration metrics and application performance. Dinuni K. Fernando, Jonathan Terner, Ping Yang 0002, Kartik Gopalan |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | CFGExplainer: Explaining Graph Neural Network-Based Malware Classification from Control Flow GraphsabstractWith the ever increasing threat of malware, extensive research effort has been put on applying Deep Learning for malware classification tasks. Graph Neural Networks (GNNs) that process malware as Control Flow Graphs (CFGs) have shown great promise for malware classification. However, these models are viewed as black-boxes, which makes it hard to validate and identify malicious patterns. To that end, we propose CFG-Explainer, a deep learning based model for interpreting GNN-oriented malware classification results. CFGExplainer identifies a subgraph of the malware CFG that contributes most towards classification and provides insight into importance of the nodes (i.e., basic blocks) within it. To the best of our knowledge, CFGExplainer is the first work that explains GNN-based mal-ware classification. We compared CFGExplainer against three explainers, namely GNNExplainer, SubgraphX and PGExplainer, and showed that CFGExplainer is able to identify top equisized subgraphs with higher classification accuracy than the other three models. Jerome Dinal Herath, Priti Prabhakar Wakodikar, Ping Yang 0002, Guanhua Yan |
DSN | 3 |
| 2022 | Securing Big Data Scientific Workflows via Trusted Heterogeneous EnvironmentsabstractBig data workflow management systems (BDWMS)s have recently emerged as popular data analytics platforms to conduct large-scale data analytics in the cloud. However, the protection of data confidentiality and secure execution of workflow applications remains an important and challenging problem. Although a few data analytics systems, such as VC3 and Opaque, were developed to address security problems, they are limited to specific domains such as Map-Reduce-style and SQL query workflows. A generic secure framework for BDWMSs is still missing. In this article, we propose SecDATAVIEW, a distributed BDWMS that employs heterogeneous workers, such as Intel SGX and AMD SEV, to protect both workflow and workflow data execution, addressing three major security challenges: (1) Reducing the TCB size of the big data workflow management system in the untrusted cloud by leveraging the hardware-assisted TEE and software attestation; (2) Supporting Java-written workflow tasks to overcome the limitation of SGX’s lack of support for Java programs; and (3) Reducing the adverse impact of SGX enclave memory paging overhead through a “Hybrid” workflow task scheduling system that selectively deploys sensitive tasks to a mix of SGX and SEV worker nodes. Our experimental results show that SecDATAVIEW imposes moderate overhead on the workflow execution time. Saeid Mofrad, Ishtiaq Ahmed, Fengwei Zhang, Shiyong Lu, Ping Yang 0002, Heming Cui |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Real-Time Evasion Attacks against Deep Learning-Based Anomaly Detection from Distributed System LogsabstractDistributed system logs, which record states and events that occurred during the execution of a distributed system, provide valuable information for troubleshooting and diagnosis of its operational issues. Due to the complexity of such systems, there have been some recent research efforts on automating anomaly detection from distributed system logs using deep learning models. As these anomaly detection models can also be used to detect malicious activities inside distributed systems, it is important to understand their robustness against evasive manipulations in adversarial environments. Although there are various attacks against deep learning models in domains such as natural language processing and image classification, they cannot be applied directly to evade anomaly detection from distributed system logs. In this work, we explore the adversarial robustness of deep learning-based anomaly detection models on distributed system logs. We propose a real-time attack method called LAM (Log Anomaly Mask) to perturb streaming logs with minimal modifications in an online fashion so that the attacks can evade anomaly detection by even the state-of-the-art deep learning models. To overcome the search space complexity challenge, LAM models the perturber as a reinforcement learning agent that operates in a partially observable environment to predict the best perturbation action. We have evaluated the effectiveness of LAM on two log-based anomaly detection systems for distributed systems: DeepLog and an AutoEncoder-based anomaly detection system. Our experimental results show that LAM significantly reduces the true positive rate of these two models while achieving attack imperceptibility and real-time responsiveness. Jerome Dinal Herath, Ping Yang 0002, Guanhua Yan |
CODASPY | 2 |
| 2019 | SecDATAVIEW: a secure big data workflow management system for heterogeneous computing environmentsabstractBig data workflow management systems (BDWFMSs) have recently emerged as popular platforms to perform large-scale data analytics in the cloud. However, the protection of data confidentiality and secure execution of workflow applications remains an important and challenging problem. Although a few data analytics systems were developed to address this problem, they are limited to specific structures such as Map-Reduce-style workflows and SQL queries. This paper proposes SecDATAVIEW, a BDWFMS that leverages Intel Software Guard eXtensions (SGX) and AMD Secure Encrypted Virtualization (SEV) to develop a heterogeneous trusted execution environment for workflows. SecDATAVIEW aims to (1) provide the confidentiality and integrity of code and data for workflows running on public untrusted clouds, (2) minimize the TCB size for a BDWFMS, (3) enable the trade-off between security and performance for workflows, and (4) support the execution of Java-based workflow tasks in SGX. Our experimental results show that SecDATAVIEW imposes 1.69x to 2.62x overhead on workflow execution time on SGX worker nodes, 1.04x to 1.29x overhead on SEV worker nodes, and 1.20x to 1.43x overhead on a heterogeneous setting in which both SGX and SEV worker nodes are used. Saeid Mofrad, Ishtiaq Ahmed, Shiyong Lu, Ping Yang 0002, Heming Cui, Fengwei Zhang |
ACSAC | 4 |
| 2019 | RAMP: Real-Time Anomaly Detection in Scientific WorkflowsabstractResearch integrity is crucial to ensuring the trustworthiness of scientific discoveries. This work is aimed at detecting misbehaviors targeting scientific workflows, which are computing paradigms widely used to facilitate scientific collaborations across multiple geographically distributed research sites. We develop a new system called RAMP(Real-Time Aggregated Matrix Profile) for real-time anomaly detection in scientific workflow systems. RAMP builds upon an existing time series data analysis technique called Matrix Profile to detect anomalous distances among subsequences of event streams collected from scientific workflows in an online manner. Using an adaptive uncertainty function, the anomaly detection model is dynamically adjusted to prevent high false alarm rates. RAMP can incorporate user feedback on reported anomalies and modify model parameters to improve anomaly detection accuracy. Our experimental results from applying RAMP to the logs generated by DATAVIEW, a scientific workflow platform, show that RAMP is able to identify a varied range of anomalies with high accuracy for both interleaved and non-interleaved workflow executions in real time. Jerome Dinal Herath, Changxin Bai, Guanhua Yan, Ping Yang 0002, Shiyong Lu |
IEEE BigData | 4 |
| 2019 | ContainerVisor: Customized Control of Container ResourcesabstractCloud platforms are increasingly using containers for lightweight virtualization. Unlike full system virtual machines (VMs) that each runs its own operating system, containers share a stateful operating system to reduce their memory footprint and execution overheads. However, mainstream operating systems are currently limited in their ability to customize a container's memory management, since they lack the necessary abstractions and mechanisms to accurately track and isolate a container's memory footprint. We propose a new abstraction, called the Container-Level Address Space (CLAS), that provides a unified view of a container's memory across all of its constituent processes. We present the design of ContainerVisor, a per-container resource management system that leverages CLAS to provide customized memory management services. We describe a ContainerVisor prototype on Linux for running unmodified applications and demonstrate three proof-of-concept customized services, namely process-level memory limits and reservations, container-specific page replacement policies, and privacy-aware memory de-allocation. Our evaluations show that ContainerVisor can provide these customized services within reasonable overheads. Tianlin Li, Kartik Gopalan, Ping Yang 0002 |
IC2E | 3 |
| 2019 | Live Migration Ate My VM: Recovering a Virtual Machine after Failure of Post-Copy Live MigrationabstractPost-copy is one of the two key techniques (besides pre-copy) for live migration of virtual machines in data centers. Post-copy provides deterministic total migration time and low downtime for write-intensive VMs. However, if post-copy migration fails for any reason, the migrating VM is lost because the VM's latest consistent state is split between the source and destination nodes during migration. In this paper, we present PostCopyFT, a new approach to recover a VM after a destination or network failure during post-copy live migration using an efficient reverse incremental checkpointing mechanism. We have implemented and evaluated our approach in the KVM/QEMU platform. Our experimental results show that the total migration time of post-copy remains unchanged while maintaining low failover time, downtime, and application performance overhead. Dinuni K. Fernando, Jonathan Terner, Kartik Gopalan, Ping Yang 0002 |
INFOCOM | 4 |
| 2017 | Security Analysis of Email SystemsabstractElectronic mail (email) is universally used by businesses, government agencies, and individual users. Out of necessity, users trust their email systems to keep their emails safe and secure. However, email systems are often complex and exhaustive testing is almost impossible for such systems. As a result, email systems often contain bugs and security vulnerabilities. In this paper, we analyze the security and usability of five popular public email systems. Our analysis shows that there are several security vulnerabilities in multiple sign-in and password composition and recovery policy of some of the email systems. Tianlin Li, Amish Mehta, Ping Yang 0002 |
CSCloud | 3 |
| 2016 | Quick Eviction of Virtual Machines through Proactive SnapshotsabstractLive migration of Virtual Machines (VMs) is a key technique to quickly migrate workloads in response to events such as impending failure or load changes. Despite extensive research, state-of-the-art live migration approaches take a long time to migrate a VM, which in turn negatively impacts the application performance during migration. We present, Quick Eviction, a new approach to significantly speed up the eviction of a VM from the source host with low impact on VM's performance during migration. Before migration, Quick Eviction regularly snapshots the VM's memory to a destination or a failover node. During the actual migration, Quick Eviction has to transfer only a small amount of dirtied memory resulting in a very short time to completely evict the VM out of the source. Our experimental results show that Quick Eviction in the KVM/QEMU platform significantly reduces the eviction time. Dinuni K. Fernando, Hardik Bagdi, Yaohui Hu, Ping Yang 0002, Kartik Gopalan, Charles A. Kamhoua, Kevin A. Kwiat |
CLUSTER | 4 |
| 2015 | Performance Analysis of Encryption in Securing the Live Migration of Virtual MachinesabstractVirtual machine (VM) migration is a technique for transferring the execution state of a VM from one physical host to another. While VM migration is critical for load balancing, consolidation, and server maintenance in virtualized data centers, it can also increase security risks. During VM migration, an attacker with sufficient privileges can compromise a VM by modifying its memory contents during transit to subvert its applications or the guest operating system. One could maintain dedicated, and presumably more secure, control networks to carry the migration traffic, but at significant hardware and administrative complexity. Alternatively, one could encrypt the migration traffic, which eliminates the need for dedicated control networks, but might introduce performance overheads. To date, there has been no systematic study of how encryption affects VM migration, especially in high-bandwidth low-delay networks that are common within data centers. In this paper, we present a study of the impact of AES and 3DES encryption algorithms on two widely used live VM migration approaches - pre-copy and post-copy. Our key findings are as follows. The encryption algorithm used can have a significant impact on the total migration time. The impact of encryption on downtime varies with the type of the migration technique. The overhead of encryption also depends upon the relative speeds of source and target machines. Finally, an application's performance within a VM during encrypted migration varies with the type of the application and the migration mechanism. Yaohui Hu, Sanket Panhale, Tianlin Li, Emine Kaynar, Danny Chan, Umesh Deshpande, Ping Yang 0002, Kartik Gopalan |
CLOUD | 7 |
| 2015 | Privacy-preserving Virtual MachineabstractCloud computing systems routinely process users' confidential data, but the underlying virtualization software in use today is not constructed to minimize the exposure of such data. For instance, virtual machine (VM) checkpointing can drastically prolong the lifetime and vulnerability of confidential data without users' knowledge by storing such data as part of a persistent snapshot. A key requirement for minimizing the exposure of any data is the ability to cleanly isolate such data for either exclusion or processing. Traditional mechanisms for memory taint tracking are expensive whereas those for isolating application footprint in VM-based sandboxes are not transparent. In this paper, we propose a transparent and lightweight mechanism for isolating a confidential application's memory footprint in a VM. The key idea is for a parent VM to spawn a child VM, called a Privacy-preserving Virtual Machine (PPVM) within which the confidential application executes. Hypervisor features, such as VM checkpointing, that need to exclude the memory of a confidential application can safely ignore the child VM's memory footprint. Alternatively, features such as checkpoint encryption or malware tracking can operate only on the child VM's memory. We implement memory isolation for PPVM through a lightweight VM fork operation that uses copy-on-write to reduce the memory and filesystem overhead of the PPVM. Transparency is achieved through a confidential shell that allows the parent VM to spawn the confidential application in the PPVM and exercise control over it during runtime. We demonstrate the effectiveness of PPVM through its use with VM checkpointing, which can safely checkpoint the parent VM while excluding or encrypting the associated PPVM. We show that our PPVM implementation achieves effective memory isolation with low overheads on memory, CPU, and network performance. Tianlin Li, Yaohui Hu, Ping Yang 0002, Kartik Gopalan |
ACSAC | 3 |
| 2015 | Policy analysis for administrative role based access control without separate administrationabstractRole based access control (RBAC) is a widely used approach to access control with well-known advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration. Ping Yang 0002, Mikhail I. Gofman, Scott D. Stoller, Zijiang Yang 0006 |
J. Comput. Secur. | 1 |
| 2014 | Satisfiability Analysis of Workflows with Control-Flow Patterns and Authorization ConstraintsabstractWorkflow security has become increasingly important and challenging in today's open service world. While much research has been conducted on various security issues of workflow systems, the workflow satisfiability problem, which asks whether a set of users together can complete a workflow, is recently identified as an important research problem that needs more investigation. In this paper, we study the computational complexity of the problem along two directions: one is by considering either one path or all paths of a workflow, and the other is by considering the possible patterns in a workflow. We have shown that the general workflow satisfiability analysis problem is intractable. This result motivates us to consider restrictions on workflow control-flow patterns and access control policies, and to identify tractable cases of practical interest. Ping Yang 0002, Xing Xie 0002, Indrakshi Ray, Shiyong Lu |
IEEE Trans. Serv. Comput. | 1 |
| 2013 | An Application-Level Approach for Privacy-Preserving Virtual Machine CheckpointingabstractVirtualization has been widely adopted in recent years in the cloud computing platform to improve server consolidation and reduce operating cost. Virtual Machine (VM) checkpointing refers to the act of saving a persistent snapshot (or checkpoint) of a VM's state at any instant. VM checkpointing can drastically prolong the lifetime and vulnerability of confidential or private user data in applications that execute within VMs. Simply encrypting the checkpoint does not reduce the lifetime of confidential data that should be quickly discarded after its use. In this paper, we present an application-level approach, called Privacy-preserving Checkpointing (PPC), which excludes confidential data from VM checkpoints, instead of encrypting such data. PPC enables an application programmer to register memory locations that represent the origins of confidential data. During the VM's execution, PPC performs information flow analysis to automatically track the propagation of confidential data through the application and various components of the VM, including the guest operating system. During VM checkpointing, the locations identified during the information flow analysis are excluded from the persistent checkpoint. We present the design and implementation of the PPC system in VirtualBox VMs running the commodity Linux operating system. We demonstrate the use of our system using the vim and gedit text editors. We also show that PPC introduces acceptable performance overhead. Yaohui Hu, Tianlin Li, Ping Yang 0002, Kartik Gopalan |
IEEE CLOUD | 3 |
| 2013 | Policy Analysis for Administrative Role Based Access Control without Separate Administration
Ping Yang 0002, Mikhail I. Gofman, Zijiang Yang 0006 |
DBSec | 1 |
| 2011 | Symbolic reachability analysis for parameterized administrative role-based access control
Scott D. Stoller, Ping Yang 0002, Mikhail I. Gofman, C. R. Ramakrishnan 0001 |
Comput. Secur. | 2 |
| 2011 | Policy analysis for Administrative Role-Based Access Control
Amit Sasturkar, Ping Yang 0002, Scott D. Stoller, C. R. Ramakrishnan 0001 |
Theor. Comput. Sci. | 2 |
| 2010 | User-Role Reachability Analysis of Evolving Administrative Role Based Access Control
Mikhail I. Gofman, Ruiqi Luo, Ping Yang 0002 |
ESORICS | 3 |
| 2010 | Information flow analysis of scientific workflows
Ping Yang 0002, Shiyong Lu, Mikhail I. Gofman, Zijiang Yang 0006 |
J. Comput. Syst. Sci. | 1 |
| 2010 | Secure Abstraction Views for Scientific Workflow Provenance QueryingabstractProvenance has become increasingly important in scientific workflows and services computing to capture the derivation history of a data product, including the original data sources, intermediate data products, and the steps that were applied to produce the data product. In many cases, both scientific results and the used protocol are sensitive and effective access control mechanisms are essential to protect their confidentiality. In this paper, we propose: 1) a formal scientific workflow provenance model as the basis for querying and access control for workflow provenance; 2) a security model for fine-grained access control for multilevel provenance and an algorithm for the derivation of a full security specification based on inheritance, overriding, and conflict resolution; 3) a formalization of the notion of security views and an algorithm for security view derivation; and 4) a formalization of the notion of secure abstraction views and an algorithm for its computation. A prototype called SecProv has been developed, and experiments show the effectiveness and efficiency of our approach. Artem Chebotko, Shiyong Lu, Seunghan Chang, Farshad Fotouhi, Ping Yang 0002 |
IEEE Trans. Serv. Comput. | 5 |
| 2009 | Symbolic reachability analysis for parameterized administrative role based access controlabstractRole based access control (RBAC) is a widely used access control paradigm. In large organizations, the RBAC policy is managed by multiple administrators. An administrative role based access control (ARBAC) policy specifies how each administrator may change the RBAC policy. It is often difficult to fully understand the effect of an ARBAC policy by simple inspection, because sequences of changes by different administrators may interact in unexpected ways. ARBAC policy analysis algorithms can help by answering questions, such as user-role reachability, which asks whether a given user can be assigned to given roles by given administrators. Allowing roles and permissions to have parameters significantly enhances the scalability, flexibility, and expressiveness of ARBAC policies. This paper defines PARBAC, which extends the classic ARBAC97 model to support parameters, and presents an analysis algorithm for PARBAC. To the best of our knowledge, this is the first analysis algorithm specifically for parameterized ARBAC policies. We evaluate its efficiency by analyzing its parameterized complexity and benchmarking it on case studies and synthetic policies. Scott D. Stoller, Ping Yang 0002, Mikhail I. Gofman, C. R. Ramakrishnan 0001 |
SACMAT | 2 |
| 2009 | RBAC-PAT: A Policy Analysis Tool for Role Based Access Control
Mikhail I. Gofman, Ruiqi Luo, Ayla C. Solomon, Yingbin Zhang, Ping Yang 0002, Scott D. Stoller |
TACAS | 5 |
| 2008 | Control Message Reduction Techniques in Backward Learning Ad Hoc Routing ProtocolsabstractMost existing wireless ad hoc routing protocols rely upon the use of backward learning technique with explicit control messages to route packets. In this paper we propose a set of techniques that can be applied in a backward learning routing algorithm in order to minimize or even eliminate explicit control messages for route discovery, setup, and maintenance, while minimally using implicit data-like control messages that need no special processing. We also show that such an algorithm does not need to prevent routing loops at all costs, such as by means of extensive network-wide spanning trees in traditional LAN bridges, or destination sequence numbers in AODV, or source- routing in DSR. In fact, we prove that transient loops can be safely allowed to occur when a simple route refresh mechanism is coupled with the use of packet identification field to effectively bound the lifetime of such transient loops without negatively impacting the network performance. Results demonstrate that even a routing algorithm without explicit control messages can perform competitively in comparison to AODV and DSR protocols while significantly reducing the protocol complexity. Navodaya Garepalli, Kartik Gopalan, Ping Yang 0002 |
ICCCN | 3 |
| 2008 | Scientific Workflow Provenance Querying with Security ViewsabstractProvenance, the metadata that pertains to the derivation history of a data product, has become increasingly important in scientific workflow environments. In many cases, both data products and their provenance can be sensitive and effective access control mechanisms are essential to protect their confidentiality. In this paper, we propose i) a formalization of scientific workflow provenance as the basis for querying and access control; ii) a security specification mechanism for provenance at various granularity levels and the derivation of a full security specification based on inheritance, overriding, and conflict resolution rules; iii) a formalization of security views that are derived from a scientific workflow run provenance for different roles of users; and iv) a framework that integrates abstraction views and security views such that a user can examine provenance at different abstraction levels while respecting the security policy prescribed for her. We have developed the SecProv prototype to validate the effectiveness of our approach. Artem Chebotko, Seunghan Chang, Shiyong Lu, Farshad Fotouhi, Ping Yang 0002 |
WAIM | 5 |
| 2007 | Efficient policy analysis for administrative role based access controlabstractAdministrative RBAC (ARBAC) policies specify how Role-Based Access Control (RBAC) policies may be changed by each administrator. It is often difficult to fully understand the effect of an ARBAC policy by simple inspection, because sequences of changes by different administrators may interact in unexpected ways. ARBAC policy analysis algorithms can help by answering questions, such a suser-role reachability, which asks whether a given user can be assigned to given roles by given administrators. This problem is intractable in general. This paper identifies classes of policies of practical interest, develops analysis algorithms for them, and analyzes their parameterized complexity, showing that the algorithms may have high complexity with respect to some parameter k characterizing the hardness of the input (such that k is often small in practice) but have polynomial complexity in terms of the overall input size when the value of k is fixed. Scott D. Stoller, Ping Yang 0002, C. R. Ramakrishnan 0001, Mikhail I. Gofman |
CCS | 2 |
| 2007 | Formal Modeling and Analysis of Scientific Workflows Using Hierarchical State MachinesabstractScientific workflows have recently emerged as a new paradigm for representing and managing complex distributed scientific computations and data analysis, and have enabled and accelerated many scientific discoveries. Many scientific workflows are distributed and collaborative as they result from some collaborative research projects that involve a number of geographically distributed organizations. In these workflows, information flow control becomes a key security problem. In this paper, we propose to model a scientific workflow using a hierarchical state machine and present techniques for verifying and controlling information propagation in scientific workflow environments based on hierarchical state machines. To the best of our knowledge, this is the first effort for information flow analysis in the area of scientific workflows. Ping Yang 0002, Zijiang Yang 0006, Shiyong Lu |
eScience | 1 |
| 2006 | Policy Analysis for Administrative Role Based Access ControlabstractRole-based access control (RBAC) is a widely used model for expressing access control policies. In large organizations, the RBAC policy may be collectively managed by many administrators. Administrative RBAC (ARBAC) is a model for expressing the authority of administrators, thereby specifying how an organization's RBAC policy may change. Changes by one administrator may interact in unintended ways with changes by other administrators. Consequently, the effect of an ARBAC policy is hard to understand by simple inspection. In this paper, we consider the problem of analyzing ARBAC policies, in particular to determine reachability properties (e.g., whether a user can eventually be assigned to a role by a group of administrators) and availability properties (e.g., whether a user cannot be removed from a role by a group of administrators) implied by a policy. We first establish the connection between security policy analysis and planning in artificial intelligence. Based partly on this connection, we show that reachability analysis for ARBAC is PSPACE-complete. We also give algorithms and complexity results for reachability and related analysis problems for several categories of ARBAC policies, defined by simple restrictions on the policy language Amit Sasturkar, Ping Yang 0002, Scott D. Stoller, C. R. Ramakrishnan 0001 |
CSFW | 2 |
| 2006 | Runtime Security Verification for Itinerary-Driven Mobile AgentsabstractWe present a new approach to ensure the secure execution of itinerary-driven mobile agents, in which the specification of the navigational behavior of an agent is separated from the specification of its computational behavior. We empower each host with an access control policy so that the host will deny the access from an agent whose itinerary does not conform to the host's access control policy. A host uses model checking algorithms to check if the itinerary of the agent conforms to its access control policy written in mu-calculus, and if so, grant access permission. In order to address the state explosion problem for model checking itineraries, we propose an approach called model generation code. In this approach, instead of verifying the itinerary itself, a host actually checks the conservative models of a mobile agent. If a conservative model does not satisfy the host's access control policy, the mobile agent will provide refined models for further verification. Our preliminary results show that this is a practical and promising approach to ensure the secure execution of mobile agents Zijiang Yang 0006, Shiyong Lu, Ping Yang 0002 |
DASC | 3 |
| 2006 | Parameterized Verification of pi-Calculus Systems
Ping Yang 0002, Samik Basu 0001, C. R. Ramakrishnan 0001 |
TACAS | 1 |
| 2005 | A Provably Correct Compiler for Efficient Model Checking of Mobile Processes
Ping Yang 0002, C. R. Ramakrishnan 0001, Scott A. Smolka |
PADL | 1 |
| 2004 | A logical encoding of the pi-calculus: model checking mobile processes using tabled resolution
Ping Yang 0002, C. R. Ramakrishnan 0001, Scott A. Smolka |
Int. J. Softw. Tools Technol. Transf. | 1 |
| 2003 | A Logical Encoding of the pi-Calculus: Model Checking Mobile Processes Using Tabled Resolution
Ping Yang 0002, C. R. Ramakrishnan 0001, Scott A. Smolka |
VMCAI | 1 |