Theodosis Dimitrakos

dblp:99/4618 · also Theo Dimitrakos, Theodosis D. Dimitrakos, Theodosis Dimitriou Dimitrakos · DBLP profile ↗
← Back
35ranked-venue papers
7as first author
11since 2021 · last 2025
0000-0002-9522-1863ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 2 first-author · 7 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Systems, architecture and hardware · 3Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Quantifying Calibration Error in Neural Networks Through Evidence-Based Theory
abstract
Trustworthiness in neural networks is crucial for their deployment in critical applications, where reliability, confidence, and uncertainty play a pivotal role in decision-making. Traditional performance metrics such as accuracy and precision fail to capture these aspects, particularly in cases where models exhibit overconfidence. To address these limitations, this paper introduces a novel framework for quantifying the trustworthiness of neural networks by incorporating subjective logic into the evaluation of Expected Calibration Error (ECE). This method provides a comprehensive measure of trust, distrust, and uncertainty by clustering predicted probabilities and fusing opinions using appropriate fusion operators. We demonstrate the effectiveness of this approach through experiments on the MNIST and CIFAR-10 datasets, where post-calibration results indicate improved trustworthiness. The proposed framework offers a more interpretable and nuanced assessment of AI models, with potential applications in sensitive domains such as healthcare and autonomous systems.
Koffi Ismael Ouattara, Ioannis Krontiris, Theodosis Dimitrakos, Frank Kargl
FUSION3
2025 An Optimized Framework for DSPG Synthesis and Trust Network Analysis with Subjective Logic
Koffi Ismael Ouattara, Ana Petrovska, Ioannis Krontiris, Theodosis Dimitrakos, Frank Kargl
RuleML+RR4
2025 Coordinated Enforcement of Obligations in Distributed Usage Control Systems [Work In Progress Paper]
abstract
Access and usage control have evolved to include obligations, which are mandatory actions that must be fulfilled as part of authorization decisions. However, standards such as Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) specify that Policy Enforcement Points (PEPs) are responsible for enforcing obligations but leave execution aspects unspecified. They assume that obligations will be fulfilled without addressing how enforcement should be carried out. This paper introduces an enforcement framework based on structured enforcement messages to address these challenges. It defines two types of messages to coordinate enforcement execution across PEPs: Declaration and Execution Records. These records provide information about PEP capabilities, action dependencies, and fallback strategies for synchronized enforcement. Secondly, we propose a hierarchical policy model to separate concerns between the functionality of policy logic and enforcement. The model is composed of Governance, Authorization, and Enforcement Policies. Constraints flow across these three levels, allowing policy selection and execution to adapt to the authorization context and enforcement. Finally, we illustrate a high-level architecture that integrates the three policy layers with distributed enforcement logic across multiple PEPs.
Hussein Joumaa, Ali Hariri, Theodosis Dimitrakos, Bruno Crispo
SACMAT3
2024 On Subjective Logic Trust Discount for Referral Paths
abstract
Subjective Logic (SL) enriches probabilistic logic by incorporating uncertainty and subjective belief ownership, enabling the expression of uncertainty about subjective beliefs. Unlike traditional probabilistic logics, SL 1) accommodates situations where different agents express beliefs about the same proposition, integrating the subjective nature and ownership of beliefs; and 2) addresses existing limitations in Dempster-Shafer Theory of evidence (DST), particularly in modelling trust transitivity. In modern computer systems, trust assessment extends beyond direct relationships to complex networks, necessitating the consideration of referral and direct trust relationships. This paper introduces a novel trust discount operator for referral edges in complex networks, addressing challenges in discounting trust across two and multiple referral edges. Through our empirical analysis, we demonstrate the effectiveness of the proposed operator and establish a relationship between path length and trustworthiness.
Koffi Ismael Ouattara, Ana Petrovska, Artur Hermann, Natasa Trkulja, Theodosis Dimitrakos, Frank Kargl
FUSION5
2024 Obligation Management Framework for Usage Control
abstract
Obligations were introduced in access and usage control as a mechanism to specify mandatory actions to be fulfilled as part of authorization. In this paper, we address challenges related to obligation management in access and usage control, focusing on the Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) standards. Firstly, we provide a comprehensive analysis of Combining Algorithms (CAs) to determine their influence on the selection and ordering of obligations and identify nondeterminism. We then propose solutions to eliminate such nondeterminism enabling policy authors to explicitly specify the intended behavior. Secondly, we discuss the recurrence of obligations in usage control that occurs due to policy re-evaluations, highlighting the need to execute some obligations only once. We address this problem by introducing a parameter that enables policy authors to explicitly specify whether they intend an obligation to recur or not. Thirdly, we highlight an ambiguity in obligation applicability to lifecycle phases (e.g., ongoing) in usage control, arising from the lack of explicit associations between obligations and phases in particular cases. To address this issue, we introduce a parameter that explicitly specifies the scope of an obligation, allowing policy authors to restrict obligations to a single phase or apply them to the entire authorization. Finally, we extend the functionality of the Obligation Manager (OM) component to combine all three solutions, providing deterministic obligation management.
Hussein Joumaa, Ali Hariri, Ana Petrovska, Oleksii Osliak, Theodosis Dimitrakos, Bruno Crispo
SACMAT5
2024 Static and Dynamic Analysis of a Usage Control System
abstract
The ability to exchange data while maintaining sovereignty is fundamental to emerging decentralized data-driven ecosystems. Data sovereignty refers to the entity's capability to be self-determined concerning data usage. As such, a data usage control system (UCON) is critical for sovereignty. UCON, a generalization of attribute-based access control, enforces continuous authorization, allowing attribute mutability after access is granted. In theory, UCON comprises a policy language to express constraints and obligations of data usage, and a technology to evaluate and enforce them. In practice, realizing the above is challenging and poses trust concerns. Partly, this is due to the complexity of UCON (continuous authorization, obligations) and the advanced usage constraints (stemming from, e.g., regulations or business contracts) combined with the decentralized nature of data ecosystems that allow different actors (e.g., data provider, security engineers) to author policies, and operate UCON. To that end, we propose to aid actors with automated policy analysis and verification methods. We present a new policy analysis method based on the combination of symbolic execution for policy evaluation and SMT solving to compute concrete scenarios answering queries on the policies. Our approach supports symbolic queries, where attribute values may be concrete values, a range of values, or symbolic variables. We also propose a monitoring approach using RTLola tool to verify the correctness of UCON's behavior in terms of decisions, obligations, and user-specified properties. To monitor obligations, we define their essential parameters and show how to monitor their fulfillment based on the configuration. We also present eight templates that allow users to generate the most important properties for monitoring UCON.
Ulrich Schöpp, Fathiyeh Faghih, Subhajit Bandopadhyay, Hussein Joumaa, Amjad Ibrahim, Chuangjie Xu, Xin Ye 0013, Theodosis Dimitrakos
SACMAT8
2023 Specifying a Usage Control System
abstract
Modern system architectures require sophisticated access and usage control mechanisms. The need stems from demanding requirements for security, data sovereignty and privacy regulations, as well as the challenges presented by architectural approaches like zero trust networking. Usage control systems provide one approach to encapsulate and manage the complexities related to access and usage control. In order to trust a usage control system, it is essential to ensure that usage control policies express the intended properties and are enforced correctly. To achieve this, we need a precise specification of the intended behavior of a usage control system. For attribute-based access control, the XACML standard is a sufficient specification of the behavior of policies. Usage control models, such as UCON, extend access control with features for continuous authorization based on mutability of attribute values. This adds significant complexity to the problem of specifying the intended behavior. In this paper, we identify challenges with specifying a practical usage control system regarding continuous control, obligations, and concurrency aspects. We describe an approach to specifying the UCON+ model of Dimitrakos et al. and outline an implementation of the specification with Answer Set Programming.
Ulrich Schöpp, Chuangjie Xu, Amjad Ibrahim, Fathiyeh Faghih, Theodosis Dimitrakos
SACMAT5
2022 WiP: Metamodel for Continuous Authorisation and Usage Control
abstract
Access control has been traditionally used to protect data and privacy. Traditional access control models (e.g., ABAC, RBAC) cannot meet modern security requirements as technologies spread over heterogeneous and dynamic environments that need continuous monitoring. Modern models such as Usage Control (UCON) introduced the concept of continuous authorisation that has a lifecycle consisting of a series of phases through which the authorisation passes during its lifetime. However, such models assume a fixed lifecycle for all authorisations, so they cannot satisfy emerging technologies (e.g., smart vehicles, zero-trust, data flow), which require various and fine-grained lifecycles. Researchers have extended existing models to meet such requirements, but all solutions remain restrictive, as they are specially tailored for specific use-cases. In this paper, we propose an extensible model for continuous authorisations and usage control. The model enables its users to customise and dynamically configure the authorisation lifecycle as required by the use-case. This adds a layer of abstraction, forming a metamodel that can be instantiated into different flavours of continuous authorisation models, each addressing specific requirements. We also show that the authorisation lifecycle can be modelled as Deterministic Finite Automaton (DFA) and expressed in a structured language used by an evaluation engine to dynamically enact and manage the lifecycle. We layout the building blocks of the proposed metamodel and devise future research directions.
Ali Hariri, Amjad Ibrahim, Theodosis Dimitrakos, Bruno Crispo
SACMAT3
2021 Towards Collaborative Cyber Threat Intelligence for Security Management
Oleksii Osliak, Andrea Saracino, Fabio Martinelli, Theodosis Dimitrakos
ICISSP4
2021 SIUV: A Smart Car Identity Management and Usage Control System Based on Verifiable Credentials
Ali Hariri, Subhajit Bandopadhyay, Athanasios Rizos, Theodosis Dimitrakos, Bruno Crispo, Muttukrishnan Rajarajan
SEC4
2021 Certification-Based Cloud Adaptation
abstract
Performance and dependability levels of cloud-based computations are difficult to guarantee by-design due to segregation of visibility and control between applications, data owners, and cloud providers. Lack of predictability increases users' uncertainty about the service levels they will actually achieve. Cloud tenants compete for shared resources/services at all layers of the cloud stack, and pose heterogeneous and conflicting non-functional requirements over them. These requirements have implications for platform and infrastructure layers, which have to be configured to satisfy inter-tenants requirements. We argue that adaptation techniques can play a crucial role in providing a reliable cloud, supporting definite behavior of applications and stable quality of service. Existing adaptation techniques however are unsuitable for cloud use, since they mostly focus on single tenancy, performance requirements, and are based on unverifiable evidence, which is collected in an untrusted way. In this paper, we propose a multi-tenant, general-purpose adaptation technique for the cloud, based on evidence collected by means of a trustworthy certification process. We depart from traditional heavy and comprehensive certification processes, such as ISO/IEC 27017, and consider a flexible and lightweight certification process for the cloud. It is based on authentic evidence and provides accountable validation on the compliance of a cloud-based system. Our approach adapts the cloud at all layers to maintain stable non-functional properties in certificates over time, by continuously verifying certificate validity. We assess the performance and quality of our adaptation approach in a wide range of settings.
Claudio A. Ardagna, Rasool Asal, Ernesto Damiani, Theodosis Dimitrakos, Nabil El Ioini, Claus Pahl
IEEE Trans. Serv. Comput.4
2020 Trust Aware Continuous Authorization for Zero Trust in Consumer Internet of Things
abstract
This work describes the architecture and prototype implementation of a novel trust-aware continuous authorization technology that targets consumer Internet of Things (IoT), e.g., Smart Home. Our approach extends previous authorization models in three complementary ways: (1) By incorporating trust-level evaluation formulae as conditions inside authorization rules and policies, while supporting the evaluation of such policies through the fusion of an Attribute-Based Access Control (ABAC) authorization policy engine with a Trust-Level-Evaluation-Engine (TLEE). (2) By introducing contextualized, continuous monitoring and re-evaluation of policies throughout the authorization life-cycle. That is, mutable attributes about subjects, resources and environment as well as trust levels that are continuously monitored while obtaining an authorization, throughout the duration of or after revoking an existing authorization. Whenever change is detected, the corresponding authorization rules, including both access control rules and trust level expressions, are re-evaluated. (3) By minimizing the computational and memory footprint and maximizing concurrency and modular evaluation to improve performance while preserving the continuity of monitoring. Finally we introduce an application of such model in Zero Trust Architecture (ZTA) for consumer IoT.
Theodosis Dimitrakos, Tezcan Dilshener, Alexander Kravtsov, Antonio La Marra, Fabio Martinelli, Athanasios Rizos, Alessandro Rosetti, Andrea Saracino
TrustCom1
2019 Data Protection as a Service in the Multi-Cloud Environment
abstract
This paper introduces a framework for Data Protection as a Service (DPaaS) to cloud computing users. Compared to the existing Data Encryption as a Service (DEaaS) such as those provided by Amazon and Google, our DPaaS framework provides more flexibility, control and visibility for protecting data in the cloud. In addition to supporting the basic data encryption capability as DEaaS does, this DPaaS framework allows data owners to define fine-grained access control policies to protect their data. Data protected by an access control policy are automatically encrypted and access is granted to user/applications according with the policy. In general, the DPaaS enables the separation of concerns between security and data management, in addition to defining a full cycle of data security automation from encryption to decryption. Our proof-of-concept prototype of the DPaaS works with hybrid multi-cloud environments including private clouds and virtual data-centers using OpenStack, CloudStack and VMWare as well as public clouds being the BT Cloud Compute platform and Amazon (AWS). Experiments on the prototype have proved the efficiency of the framework.
Maurizio Colombo, Rasool Asal, Quang Hieu Hieu, Fadi El-Moussa 0001, Ali Sajjad, Theodosis Dimitrakos
CLOUD6
2015 A scalable and dynamic application-level secure communication framework for inter-cloud services
Ali Sajjad, Muttukrishnan Rajarajan, Andrea Zisman, Theodosis Dimitrakos
Future Gener. Comput. Syst.4
2014 Seamless Enablement of Intelligent Protection for Enterprise Cloud Applications through Service Store
abstract
Cloud IaaS and PaaS providers typically hold Cloud consumers accountable for protecting their applications, while Cloud users often find that protecting their proprietary system, application and data stacks on public or hybrid Cloud environments to be complex, expensive and time-consuming. In this paper we demonstrate, how integration of a security solution such as BT Intelligent Protection with the Service Store, results with security operations capability that can scale accordingly to the Cloud use. By enabling "click-to-buy" security services and "click-to-build" secure applications with a few mouse clicks, this integration creates a new paradigm for self-service Cloud-based integrity and security services.
Joshua Daniel, Theodosis Dimitrakos, Fadi El-Moussa 0001, Gery Ducatel, Pramod S. Pawar, Ali Sajjad
CloudCom2
2014 Context-Aware Multifactor Authentication Based on Dynamic Pin
Yair Diaz-Tellez, Eliane L. Bodanese, Theodosis Dimitrakos, Michael Turner
SEC3
2014 Data Interface All-iN-A-Place (DIANA) for Big Data
abstract
Variety in Big Data means we have a wide range of data types and sources: e.g. File systems and database systems co-exist for decades as two popular data-accessing interfaces. This work is to unify these two interfaces by presenting a Data Interface All-iN-A-place (DIANA). The first challenge lies in distinguishing structured and un-structured data and diverting them to different underlying platforms. It is demonstrated that a speedup of 5000 in indexing has been achieved at the expense of a slowdown of 100 in extracting attributes. A DIANA-based cloud storage system is constructed for versatile, long distance and large volume big data accessing operations to address "Volume" and "Velocity" in Big Data. It encapsulates a dynamic multi-stream/multi-path engine at the socket level, which conforms to Portable Operating System Interface (POSIX).
Frank Wang, Theodosis Dimitrakos, Na Helian, Sining Wu, Yuhui Deng 0001, Rodric Yates
TrustCom2
2013 Privacy-Preserving Collaborative Filtering on the Cloud and Practical Implementation Experiences
abstract
Recommender systems typically use collaborative filtering to make sense of huge and growing volumes of data. An emerging trend in industry has been to use public clouds to deal with the computing and storage requirements of such systems. This, however, comes at a price -- data privacy. Simply ensuring communication privacy does not protect against insider threats or even attacks agagainst the cloud infrastructure itself. To deal with this, several privacy-preserving collaborative filtering algorithms have been developed in prior research. However, these have only been theoretically analyzed for the most part. In this paper, we analyze an existing privacy preserving collaborative filtering algorithm from an engineering perspective, and discuss our practical experiences with implementing and deploying privacy-preserving collaborative filtering on real world Software-as-a-Service enabling Platform-as-a-Service clouds.
Anirban Basu 0001, Jaideep Vaidya, Hiroaki Kikuchi, Theodosis Dimitrakos
IEEE CLOUD4
2012 An Architecture for the Enforcement of Privacy and Security Requirements in Internet-Centric Services
abstract
This paper focuses on the problem of how to protect personal data and privacy in the context of internet-centric services. Two main challenges are considered: how to enable individuals to express data protection requirements on their data in a disclosure request; and how to ensure data is actually protected and processed according to the intended purpose of use after being disclosed. As part of our solution, we introduce the notion of a distinctive online service and architectural component, called the Privacy and Security Broker (PSB), responsible for the protection of personal data. The PSB enables a user to express their data protection requirements and translates them into "Data Protection Property Policies" (DPPPs). A high level architecture and the corresponding protocols involving the interaction of the main actors of our solution are presented.
Yair Diaz-Tellez, Eliane L. Bodanese, Srijith Krishnan Nair, Theodosis Dimitrakos
TrustCom4
2012 OPTIMIS: A holistic approach to cloud service provisioning
Ana Juan Ferrer, Francisco Hernández-Rodriguez, Johan Tordsson, Erik Elmroth, Ahmed Ali-Eldin, Csilla Zsigri, Raül Sirvent, Jordi Guitart, Rosa M. Badia, Karim Djemame, Wolfgang Ziegler, Theodosis Dimitrakos, Srijith Krishnan Nair, George Kousiouris, Kleopatra Konstanteli, Theodora A. Varvarigou, Benoit Hudzia, Alexander Kipp, Stefan Wesner, Marcelo Corrales, Nikolaus Forgó, Tabassum Sharif, Craig Sheridan
Future Gener. Comput. Syst.12
2011 Privacy-preserving Collaborative Filtering for the Cloud
abstract
Rating-based collaborative filtering (CF) enables the prediction of the rating that a user will give to an item, based on the ratings of other items given by other users. However, doing this while preserving the privacy of rating data from individual users is a significant challenge. Several privacy preserving schemes have, so far been proposed in prior work. However, while these schemes are theoretically feasible, there are many practical implementation difficulties on real world public cloud computing platforms. In this paper, we approach the generalised problem of privacy preserving collaborative filtering from the cloud perspective and propose an efficient and secure approach that is built for the cloud. We present our implementation experiences and experimental results based on the Google App Engine for Java (GAE/J) cloud platform.
Anirban Basu 0001, Jaideep Vaidya, Hiroaki Kikuchi, Theodosis Dimitrakos
CloudCom4
2010 Special issue on security and trust management for dynamic coalitions
abstract
There is an increasing interest and uptake of technologies that allow cooperation among entities that may act collectively. Advancements in information and communication technologies at the end of the 20th and the beginning of the 21st century have enabled entities of different kinds to form dynamic coalitions. Crowds of users walking on the streets with advanced context aware converged telecommunication devices. A group of robots, manned and unmanned vehicles equipped with processors, sensors, smart-phones, etc. interacting with each other, with their environment, and with a command or a control node, such as the command and control site of a defence coalition or a civil traffic control. A set of organizations (possibly virtual) sharing resources, infrastructure and collectively contributing provision of a service to a user community. Projects and processes that use resources and services offered by a collection of business partners in a value network. Web 2.0 mash-ups and composite Web Services that are composed of services and applications offered by different service providers over a public network or any other shared communications infrastructure. These dynamic coalitions involve several technologies as peer-to-peer systems (P2P), mobile ad hoc networks (MANETs) and service oriented architectures (SOA) and their information system architectures that are often realized using cloud computing, grid computing and web services frameworks. This special issue covers research results and innovation case studies on security and trust management for dynamic coalitions. We selected the following papers among the many that were submitted. identity federation; distributed usage and access management; context-aware secure messaging, routing and transformation; SOA security governance. It analyses common security requirements for IT infrastructures underpinning business collaborations and it proposes an architecture comprising realizations of SOA security design patterns and a security governance framework that address these challenges. A case study illustrates the operation of a partial implementation of the proposed architecture's security capabilities that was built for the practical validation of the proposed architectural concepts. The paper Secure Information Sharing for Grid Computing proposes a novel mechanism for controlling information sharing between members in a virtual organization. Content can be shared between members of a virtual organization subject to the virtual organization's policy and the content owner organization's policy. The virtual organization managers and collaborating organizations administrators, however, can decide which device can access content. The paper proposes mechanisms aimed at preventing uncontrolled content leakage. These include mechanisms for ensuring that a member in a virtual organization, who is authorized to access content, cannot transfer that content, or the means of accessing it, accidentally or deliberately to others. They also include mechanisms for ensuring that resources and users who leave the virtual organization the resource/user cannot access anymore information shared within the virtual organization. The paper A Guide to Trust in Mobile Ad Hoc Networks examines issues of trust and reputation in Mobile Ad Hoc Networks. It analyses a number of the trust and reputation models that have been proposed and highlights open problems in this area. The paper Secure and Robust Threshold Key Management (SRKM) Scheme for Ad Hoc Networks proposes a secure, robust and fully distributed scheme for public-key certificate management in Mobile Ad Hoc Networks. This scheme, based on threshold cryptography, ensures that the private key of the certificate authority will not be revealed to an adversary, even if the number of compromised shareholders exceeds the threshold of vulnerability, thereby thwarting mobile-adversary attacks. The paper Identity Crisis: On the Problem of Namespace Design for ID-PKC and MANETs explores a relationship between identity-based public key cryptography (ID-PKC) and mobile ad hoc networks (MANETs). In particular it examines the problem of naming and namespace design in an identity-based key infrastructure (IKI), and assesses the potential impact that different types of identifiers may have on the utility of ad hoc networks where an IKI provides the underlying key infrastructure. It also highlights a number of open problems inherent in extending namespaces to allow inter-operability amongst heterogeneous trust domains. The paper Reputation Management in Collaborative Computing Systems focuses in the area of trust for collaborative computing systems. The contributions of this paper include a survey on the main reputation-based systems that fulfil the trust requirements for collaborative systems, including reputation systems designed for e-commerce, agent-based environments, peer-to-peer computing and grid-based systems. Beyond the analysis, this paper also proposes a model for reputation management for Grid Virtual Organizations that is based on concepts from the utility computing paradigm that can be used to rate users according to their resource usage and resources and their providers according to the quality of service they deliver. This paper also presents the results of Grid simulations in order to show how the model can be used for improving completion and welfare in Virtual Organizations. The paper Interoperable Semantic Access Control for Highly Dynamic Coalitions presents a platform-driven approach to highly dynamic coalitions (HDC). The paper proposes an access control model that builds on a formalization of the life cycle of HDC formation and takes advantage of semantic interpretations of partners' requirements in order to provide interoperable access control to resources shared in a coalition. Coalition partners can achieve a high level of service interoperation by enhancing their access control requirements with semantics of usage, and interlinking their semantics using class relations based on a standard ontology. The paper Semiring-Based Frameworks for Trust Propagation in Small-World Networks and Coalition Formation Criteria provides an algebraic approach to encoding trust metrics and reasoning about trust between principals that consider forming a coalition. In this approach, trust propagation and aggregation are specified in terms of a semiring and the degree of trust between principals in a trust network is modelled as a (semiring based) soft-constraint satisfaction problem. The flexibility of this approach makes it well suited to modelling trust within coalitions and analysing the impact in trust of changes in membership and structure of the coalition. We would like to express our gratitude to the Editor-in-Chief, Dr Hsiao-Hwa Chen for his advice, patience, and encouragements since the beginning until the final stage. We thank all anonymous reviewers who spent much of their precious time reviewing in depth all the papers over several iterations. Their timely and accurate reviews and comments greatly helped us select the best papers in this special issue. We also thank all authors who have submitted their papers for consideration for this issue.
Theodosis Dimitrakos, Fabio Martinelli, Bruce Schneier
Secur. Commun. Networks1
2009 A Governance Model for SOA
abstract
Currently, business requirements for rapid operational efficiency, customer responsiveness as well as rapid adaptability are driving the need for ever increasing communication and integration capabilities of the software assets. Service Oriented Architecture (SOA) is generally acknowledged as being a potential solution to expose finely grained pieces of software components on a network that are reusable and composable. Provisioning of business services for different business purposes may require the rapid assembly of their core functionality with different infrastructure capabilities and policies in different contexts. In this paper, the authors propose a SOA based governance model that permits to handle non functional requirements in a dynamic way.
Pierre de Leusse, Theodosis Dimitrakos, David Brossard
ICWS2
2007 Virtualised Trusted Computing Platform for Adaptive Security Enforcement of Web Services Interactions
abstract
Security enforcement framework is an important aspect of any distributed system. With new requirements imposed by SOA-based business models, adaptive security enforcement on the application level becomes even more important. Our work on the enforcement framework to date has resulted in a comprehensive middleware-based solution leveraging on Web services technologies. However, potential merits of hardware-based solutions to further secure application exposure have not been considered so far. This paper describes a method for combining software resource level security features offered by Web services technologies, with the hardware-based security mechanisms offered by trusted computing platform and system virtualisation approaches. In particular, we propose trust-based architecture for protecting the enforcement middleware deployed at the policy enforcement endpoints of Web and grid services. The main motivation is to additionally secure execution environment of the applications, by providing virtual machine level separation that maps from logical domains imposed by Web services level enforcement policies.
Ivan Djordjevic, Srijith Krishnan Nair, Theodosis Dimitrakos
ICWS3
2007 Dynamic security perimeters for inter-enterprise service integration
Ivan Djordjevic, Theodosis Dimitrakos, N. Romano, Damian Mac Randal, Pierluigi Ritrovato
Future Gener. Comput. Syst.2
2005 Toward Web Services Profiles for Trust and Security in Virtual Organisations
abstract
The rise in practical Virtual Organisations (VOs) requires secure access to data and interactions between their partners. Ad hoc solutions to meet these requirements are possible, but Web services hold out the potential for generic security solutions whose cost can be spread across several short lived dynamic VOs. This paper identifies trust and security requirements throughout the VO lifecycle and analyse current Web Services specifications to show their suitability to meet these requirements. Although they demonstrate the potential for generic security support, there are uncertainties concerning different level of interoperability and stability of implementation for different specifications, which may slow down their exploitation for security-critical business applications. However, research in Web services developments are well timed to avoid losing first adopter advantage when they become stable. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Álvaro Enrique Arenas, Ivan Djordjevic, Theodosis Dimitrakos, Leonid Titkov, Joris Claessens, Christian Geuer-Pollmann, Emil C. Lupu, Nilufer Tuptuk, Stefan Wesner, Lutz Schubert
PRO-VE3
2004 An architecture for dynamic security perimeters of virtual collaborative networks
abstract
The convergence of service and telecommunications technology is enabling new and more dynamic forms of virtual collaborations, where networked entities, be them (human) agents, applications, or service instances, share information and resources in order to achieve a common objective. Such collaborations are usually dynamic, often short in duration, and enacted by potentially large groups of collaborating peers which may join or leave the group as needed. They cut across organizational boundaries, therefore taking place on open networks (such as the Internet) and they may involve complex policies constraining possible interactions. This paper introduces a novel architecture that supports the dynamic formation and self-management of virtual collaboration networks understood as coordinated groups of peers which reside in different organisational domains. Our main goal is to allow the enforcement and management of dynamic security perimeters that contain and protect such virtual collaboration networks. This is achieved with the use of certificates to assist the policy distribution, and the multilayered mechanism for the distributed policy enforcement, residing at the each participating entity. The dynamic re-sizing of the security perimeters, and the communication within, is facilitated with the group management protocol that is both scalable and secure.
Ivan Djordjevic, Chris Phillips 0001, Theodosis Dimitrakos
NOMS (1)3
2003 Contract Performance Assessment for Secure and Dynamic Virtual Collaborations
abstract
In this paper we sketch a framework supporting contract enactment within the context of virtual organisation units that are dynamically created in order to achieve a common objective by securely sharing resources, services and information. The framework is built on top of a joint extension of the policy deployment architecture for peer-to-peer communities (Dimitrakos et al., 2002) and the contract enactment capability (Milosevic et al., 2002) that enables monitoring, mediation, arbitration and enforcement of electronic contracts in multiple, simultaneous closed collaborations. A longer-term goal is to deliver a scalable method of setting up contract enforcement and contract performance management infrastructures for interorganisational information systems that allow the on-demand creation and dynamic evolution of secure virtual organizations based on the ad-hoc integration of systems across enterprise boundaries.
Theodosis Dimitrakos, Ivan Djordjevic, Zoran Milosevic, Audun Jøsang, Chris Phillips 0001
EDOC1
2003 An Emerging Architecture Enabling Grid Based Application Service Provision
abstract
In this article we examine the integration of three emerging trends in information technology (utility computing, grid computing, and Web services) new computing paradigm (grid-based application service provision) that is taking place in the context of the European research project GRASP. In the first of the paper, we explain how the integration of emerging trends can support enterprises in creating competitive advantage. In the second part, we focus on grid-based application service provision (GRASP), which builds a new technology-driven business paradigm on top of such integration. We conclude by outlining a plan for prototyping a GRASP platform in the context of an ongoing European research project.
Theodosis Dimitrakos, Damian Mac Randal, Fajin Yuan, Matteo Gaeta, Giuseppe Laria, Pierluigi Ritrovato, Bassem Serhan, Stefan Wesner, Konrad Wulf
EDOC1
2002 Model-Based Risk Assessment to Improve Enterprise Security
abstract
The main objective of the CORAS project is to provide methods and tools for precise, unambiguous, and efficient risk assessment of security critical systems. To this end, we advocate a model-based approach to risk assessment, and define the required models for this. Whereas traditional risk assessment is performed without any formal description of the target of evaluation or results of the risk assessment, CORAS aims to provide a well defined set of models well suited to (1) describe the target of assessment at the right level of abstraction, (2) as a medium for communication between different groups of stakeholders involved in a risk assessment, and (3) to document risk assessment results and the assumptions on which these results depend. We propose models for each step in a risk assessment process and report results of use.
Jan Øyvind Aagedal, Folker den Braber, Theodosis Dimitrakos, Bjørn Axel Gran, Dimitris Raptis, Ketil Stølen
EDOC3
2002 Discretionary Enforcement of Electronic Contracts
abstract
As in traditional commerce, parties to a contract in e-business environments are expected to operate in good faith and comply with mutually agreed terms of the contract. It may be the case however that deviation from the agreed contract obligations occur either intentionally or due to force majeure. We argue that there is value in providing various levels of automated support to deal with contract non-compliance in e-marketplaces in order to reach the best overall outcome for all parties. This includes monitoring contract significant events, simple notifications to the parties about non-compliance events and a range of enforcement mechanisms. These mechanisms can be either nondiscretionary (as in preventive security mechanisms) or discretionary, which rely on a number of control mechanisms that are applied when contract rules are violated. We describe a number of such control mechanisms and how they can be used to extend capabilities of a contract management architecture previously developed.
Zoran Milosevic, Audun Jøsang, Theodosis Dimitrakos, Mary Anne Patton
EDOC3
2002 The CORAS Framework for a Model-Based Risk Management Process
Rune Fredriksen, Monica Kristiansen, Bjørn Axel Gran, Ketil Stølen, Tom Arthur Opperud, Theodosis Dimitrakos
SAFECOMP6
2000 On a generalized modularization theorem
Theodosis Dimitrakos, T. S. E. Maibaum
Inf. Process. Lett.1
1998 Parameterising (Algebraic) Specifications on Diagrams
abstract
The paper presents an extension of previous work on the parameterisation of logical and algebraic specifications leading to a novel formalisation of parameterisation which is general enough to become independent of the specificities of the underlying formalism, and flexible enough to accommodate the manipulation of complex parameterised specifications where the parameters are presented by means of diagrams of specifications.
Theodosis Dimitrakos
ASE1
1997 Notes on Refinement, Interpolation and Uniformity
abstract
The connection between some modularity properties and interpolation is revisited and restated in a general "logic-independent" framework. The presence of uniform interpolants is shown to assist in certain proof obligations, which suffice to establish the composition of refinements. The absence of the desirable interpolation properties from many logics that have been used in refinement motivates a thorough investigation of methods to expand a specification formalism orthogonally, so that the critical uniform interpolants become available. A potential breakthrough is outlined in this paper.
Theodosis Dimitrakos, T. S. E. Maibaum
ASE1