VLDB 2026 Research / reviewers in the wild / expert
Simon N. Foley
dblp:f/SNFoley · also Simon Foley 0001
· DBLP profile ↗
58ranked-venue papers
27as first author
2since 2021 · last 2022
0000-0002-0183-1215ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 47 · 22 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 1 first-authorComputer networks · 3 · 2 first-authorDatabases, data management, data science and information retrieval · 3 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Threat-Driven Dynamic Security Policies for Cyber-Physical Infrastructures
Joseph Hallett, Simon N. Foley, David Manda, Joseph Gardiner, Dimitri Jonckers, Wouter Joosen, Awais Rashid |
CRITIS | 2 |
| 2021 | Privacy Interpretation of Behaviour-based Anomaly Detection ApproachesabstractThis paper introduces the notion of ‘Privacy-Anomaly Detection’ and considers the question of whether behaviour-based anomaly detection approaches can have a privacy semantic interpretation and whether the detected anomalies can be related to the conventional (formal) definitions of privacy semantics. The idea is to learn user's past querying behaviour in terms of privacy and then identify deviations from past behaviour in order to detect privacy violations. Privacy attacks, violations of formal privacy definition, based on a sequence of SQL queries (query correlations) are considered in this paper and it is shown that interactive querying settings are vulnerable to privacy attacks based on query sequences. Investigation on whether these types of privacy attacks can potentially manifest themselves as anomalies, specifically as privacy-anomalies was carried out. It is shown, in this paper, that behaviour-based anomaly detection approaches have the potential to detect privacy attacks based on query sequences (violation of formal privacy definition) as privacy-anomalies. Muhammad Imran Khan 0001, Simon N. Foley, Barry O'Sullivan |
SIN | 2 |
| 2018 | Towards Modelling Insiders Behaviour as Rare Behaviour to Detect Malicious RDBMS AccessabstractThe heart of any enterprise is its databases where the application data is stored. Organizations frequently place certain access control mechanisms to prevent access by unauthorized employees. However, there is persistent concern about malicious insiders. Anomaly-based intrusion detection systems are known to have the potential to detect insider attacks. Accurate modelling of insiders behaviour within the framework of Relational Database Management Systems (RDBMS) requires attention. The majority of past research considers SQL queries in isolation when modelling insiders behaviour. However, a query in isolation can be safe, while a sequence of queries might result in malicious access. In this work, we consider sequences of SQL queries when modelling behaviours to detect malicious RDBMS accesses using frequent and rare item-sets mining. Preliminary results demonstrate that the proposed approach has the potential to detect malicious RDBMS accesses by insiders. Muhammad Imran Khan 0001, Barry O'Sullivan, Simon N. Foley |
IEEE BigData | 3 |
| 2018 | Probabilistic Event Graph to Model Safety and Security for Diagnosis Purposes
Edwin Bourget, Frédéric Cuppens, Nora Cuppens, Samuel Dubus, Simon N. Foley, Youssef Laarouchi |
DBSec | 5 |
| 2018 | An Online Consent Maturity Model: Moving from Acceptable Use Towards Ethical PracticeabstractAchieving informed consent in online and digital contexts is challenging for several reasons. One reason is that conveying the meaning and implications of agreements to individuals is hindered by legalistic formats obscuring the potential harm that can ensue from analytics of data collected in a socio-technical context, such as online. Furthermore, as technical capability advances, what can be achieved with data mining and initiatives outpaces statutory regulation, as well as the social norms that frame individual human understandings. It is argued that the paradigm that currently underpins informed consent in online settings draws on ethical positions that are either utilitarian or legalistic. In contrast, the adoption of an ethics of virtue approach as a new paradigm provides a framework for reconceptualising informed consent. Characteristics that are material for informed consent, shared by Online Analytics and Qualitative Longitudinal Research, provide the inspiration and basis for this interdisciplinary approach, with the application of lessons learned in the practice and theory of one discipline to another. Vivien M. Rooney, Simon N. Foley |
NSPW | 2 |
| 2018 | A grounded theory approach to security policy elicitationabstractPurpose In this paper, the authors consider how qualitative research techniques that are used in applied psychology to understand a person’s feelings and needs provides a means to elicit their security needs. Design/methodology/approach Recognizing that the codes uncovered during a grounded theory analysis of semi-structured interview data can be interpreted as policy attributes, the paper develops a grounded theory-based methodology that can be extended to elicit attribute-based access control style policies. In this methodology, user-participants are interviewed and machine learning is used to build a Bayesian network-based policy from the subsequent (grounded theory) analysis of the interview data. Findings Using a running example – based on a social psychology research study centered around photograph sharing – the paper demonstrates that in principle, qualitative research techniques can be used in a systematic manner to elicit security policy requirements. Originality/value While in principle qualitative research techniques can be used to elicit user requirements, the originality of this paper is a systematic methodology and its mapping into what is actionable, that is, providing a means to generate a machine-interpretable security policy at the end of the elicitation process. Simon N. Foley, Vivien M. Rooney |
Inf. Comput. Secur. | 1 |
| 2018 | Reasoning about firewall policies through refinement and compositionabstractNetwork and host-based access controls, for example, firewall systems, are important points of security-demarcation, operating as a front-line defence for networks and networked systems. A firewall policy is conventionally defined as a sequence of order-dependant rules, and when a network packet matches with two or more policy rules, the policy is anomalous. Policies for access-control mechanisms may consist of thousands of access-control rules, and correct management is complex and error-prone. We argue that a firewall policy should be anomaly-free by construction, and as such, there is a need for a firewall policy language that allows for constructing, comparing, and composing anomaly-free policies. In this paper, an algebra is proposed for constructing and reasoning about anomaly-free firewall policies. Based on the notion of refinement as safe replacement, the algebra provides operators for sequential composition, union and intersection of policies. The effectiveness of the algebra is demonstrated by its application to anomaly detection, and standards compliance. The effectiveness of the approach in practice is evaluated through a mapping to/from iptables. The algebra is used to specify and reason about iptables firewall policy configurations. A prototype policy management toolkit has been implemented. Ultan Neville, Simon N. Foley |
J. Comput. Secur. | 2 |
| 2017 | A Semantic Approach to Frequency Based Anomaly Detection of Insider Access in Database Management Systems
Muhammad Imran Khan 0001, Barry O'Sullivan, Simon N. Foley |
CRiSIS | 3 |
| 2017 | Developer-centered security and the symmetry of ignoranceabstractIn contemporary software development anybody can become a developer, sharing, building and interacting with software components and services in a virtual free for all. In this environment, it is not feasible to expect these developers to be expert in every security detail of the software they use, and we discuss how difficult it can be to build secure software. In this respect, the practical challenges of the emerging paradigm of developer-centered security are explored, where developers would be required to consider security from the perspective of those other developers who use their software. We question whether current user-centered security techniques are adequate for this task and suggest that new thinking will be required. Two directions---symmetry of ignorance and security archaeology-are offered as a new way to consider this challenge. Olgierd Pieczul, Simon N. Foley, Mary Ellen Zurko |
NSPW | 2 |
| 2016 | Detecting Anomalous Behavior in DBMS Logs
Muhammad Imran Khan 0001, Simon N. Foley |
CRiSIS | 2 |
| 2016 | Reasoning About Firewall Policies Through Refinement and Composition
Ultan Neville, Simon N. Foley |
DBSec | 2 |
| 2016 | Runtime Detection of Zero-Day Vulnerability Exploits in Contemporary Software Systems
Olgierd Pieczul, Simon N. Foley |
DBSec | 2 |
| 2014 | I'm OK, You're OK, the System's OK: Normative Security for SystemsabstractThe normative security paradigm seeks to view a system as a society in which security is achieved by a combination of legislative provisions and normative behaviors. Drawing solely on legislative provisions is insufficient to achieve a just and orderly society. Similarly, security paradigms that focus solely on security policies and controls are insufficient. We argue that systems have analogous normative behaviors---behavioral norms---that are learnt from system logs.Using this analogy we explore how current theories about social norms in society can provide insight into using normative behavior in systems to help achieve security. Olgierd Pieczul, Simon N. Foley, Vivien M. Rooney |
NSPW | 2 |
| 2013 | Explanations and Relaxations for Policy Conflicts in Physical Access ControlabstractPhysical access control policies define sets of rulesthat govern people's access to physical resources such asrooms and buildings. While simple decision-precedence can be used to reconcile different rules that result in conflicting access decisions, the presence of rule conflicts and other rule anomalies can make it difficult for a policy-administrator to comprehend and effectively manage complex policies. In this paper we are concerned with discovering conflicts and computing relaxations of access policies in order to eliminate conflicting rule instances. We propose several SAT based encodings in which these rule conflicts and anomalies areexpressed as explanation style problems. Relaxation techniques are in turn used to eliminate these anomalies by recommending what rules have to be revoked or what permissions have to beremoved from which rules. Moreover, we discuss a relaxation strategy that preserves most of the access constraints of theoriginal policy. Finally we provide a preliminary performancestudy of our techniques. Our approach is applicable to access control policies in general. Fatih Turkmen, Simon N. Foley, Barry O'Sullivan, William M. Fitzgerald, Tarik Hadzic, Stylianos Basagiannis, Menouer Boubekeur |
ICTAI | 2 |
| 2013 | A Bloom Filter Based Model for Decentralized AuthorizationabstractA decentralized authorization mechanism is proposed that uses Bloom filters to implement authorization delegation. This lightweight mechanism is unlike conventional approaches that typically rely on public key certificates to implement distributed delegation. In taking an approach based on one-way hash functions, the mechanism may be preferable for use in computationally constrained environments where public-key cryptography is not desirable. Simon N. Foley, Guillermo Navarro-Arribas |
Int. J. Intell. Syst. | 1 |
| 2013 | MASON: Mobile autonomic security for network access controls
William M. Fitzgerald, Ultan Neville, Simon N. Foley |
J. Inf. Secur. Appl. | 3 |
| 2012 | Anomaly analysis for Physical Access Control security configurationabstractPhysical Access Controls, such as supervised doors, surveillance cameras and alarms, act as important points of demarcation between physical zones (areas/rooms) of different levels of trust. They do so by controlling personnel flow to and from areas in accordance with the enterprise security policy. A significant challenge in providing physical access control for (restricted) areas is attaining a degree of confidence that a Physical Access Control security configuration adequately addresses the threats. A misconfiguration may result in a threat of unapproved personnel access or the denial of approved personnel access to a restricted zone. In practice, Physical Access Control security configurations typically span multiple zones, involve many users and run to many thousands of access-control rules, and such complexity may increase the likelihood of misconfiguration. In this paper, a formal model for Physical Access Control security configurations is presented. This model, implemented in SAT, captures a number of unique anomalies specific to Physical Access Control domain. A preliminary set of experiments that evaluate our approach is presented. William M. Fitzgerald, Fatih Turkmen, Simon N. Foley, Barry O'Sullivan |
CRiSIS | 3 |
| 2012 | Towards efficient access control in a mobile agent based wireless sensor networkabstractPublic key authorization credentials provide a flexible approach to implementing access control in open distributed systems. Wireless sensor networks, are examples of such systems; however, their low-power sensors have energy efficiency requirements that may mean it is not practical to carry out computationally intensive operations, such as public key operations. This paper describes a distributed access control system for a Wireless Sensor Network application that uses computationally efficient one-way hash-functions to implement authorization credentials. Estanislao Mercadal, Guillermo Navarro-Arribas, Simon N. Foley, Joan Borrell |
CRiSIS | 3 |
| 2012 | Decentralized Semantic Threat Graphs
Simon N. Foley, William M. Fitzgerald |
DBSec | 1 |
| 2012 | Fast automatic security protocol generationabstractAn automatic security protocol generator is described that uses logic-based heuristic rules to guide it in a backward search for suitable protocols from protocol goals. The approach taken is unlike existing automatic protocol generators which typically carry out a forward search for candidate protocols from the protocol assumptions. A prototype generator has been built that performs well in the automatic generation of authentication and key exchange protocols. Hongbin Zhou, Simon N. Foley |
J. Comput. Secur. | 2 |
| 2011 | A Trust Model for Capability Delegation in Federated Policy SystemsabstractFederated policy systems are required to support the emergent complexity and organizational heterogeneity of modern Internet service delivery. This paper presents a distributed policy management approach which utilizes a flexible, tree-based capability authority model to partition and delegate federated capabilities or services. A trust management model and a delegation logic is defined which supports secure decentralized policy reasoning and addresses performance overheads due to distributed rule evaluation, threats from malformed or malicious federated principals and allows flexibility with respect to delegation chain reduction or capability authority re-partitioning. The system is evaluated through a security analysis and a prototype implementation of a federated policy engineering framework based on this logic is described. This framework is based on public key certificates and an extension to the Keynote Trust Management language. It provides practical management services such as key discovery and certificate revocation in addition to the core capability delegation function. Kevin Feeney, Simon N. Foley, Rob Brennan |
CRiSIS | 2 |
| 2011 | Federated autonomic management of HAN servicesabstractManaging a heterogeneous “outer edge” network is complex and error prone. It is typically performed by non-technical users. Effective HAN configuration may be hampered by a poor understanding of HAN service requirements. A challenge is to deploy and maintain meaningful and error-free heterogeneous HAN configurations. This paper explores an integrated solution to address the following requirements: managed capability sharing, usability, and security. A prototype HAN gateway architecture that builds upon explicit user-centric semantics, and enables autonomic management of shared UPnP services with appropriate access controls, is outlined. Rob Brennan, Zohar Etzioni, John Keeney, Kevin Feeney, Declan O'Sullivan, William M. Fitzgerald, Simon N. Foley |
Integrated Network Management | 7 |
| 2011 | Trust management of XMPP federationabstractDeploying an XMPP server requires system security configuration, including firewalls and XMPP security controls. Security threats include DNS spoofing, rogue servers, inadequate authentication/authorization, spambots, etc. An system administrator who understands the threats and their mitigation manages the server configuration. This administrator must also deal with routine requests to update the configuration in order to federate with new XMPP domains. In practice it is non-trivial, time-consuming and costly to get the configuration right. We describe the development of a configuration agent that can automate some of these system administration activities while ensuring that the server is correctly configured and available. The agent is used by individual XMPP servers to (autonomically) configure when and how they should federate to provide end-to-end services. The KeyNote Trust Management system is used by the agent to help manage the trust relationships across the federation and to decide when it is safe to admit a new domain. Simon N. Foley, Wayne Mac Adams |
Integrated Network Management | 1 |
| 2011 | Flexible secure inter-domain interoperability through attribute conversion
Carles Martínez-García, Guillermo Navarro-Arribas, Simon N. Foley, Vicenç Torra, Joan Borrell |
Inf. Sci. | 3 |
| 2011 | Management of security policy configuration using a Semantic Threat Graph approachabstractManaging the configuration of heterogeneous enterprise security mechanisms is a complex task. The effectiveness of a configuration may be constrained by poor understanding and/or management of the overall security policy requirements, which may, in turn, unnecessarily expose the enterprise to known threats. This paper proposes a threat management based approach, whereby knowledge about the effectiveness of mitigating countermeasures is used to guide the autonomic configuration of security mechanisms. This knowledge is modeled in terms of Semantic Threat Graphs, a variation of the traditional Threat/Attack Tree, extended in order to relate semantic information about security configuration with threats, vulnerabilities and countermeasures. An ontology-based approach to representing and reasoning over this knowledge is taken. A case study based on Network Access Controls demonstrates how threats can be analysed and how automated configuration recommendations can be made based on catalogues of countermeasures. These countermeasures are drawn from best-practice standards, including NIST, IETF and PCI-DSS recommendations for firewall configuration. Simon N. Foley, William M. Fitzgerald |
J. Comput. Secur. | 1 |
| 2010 | Virtual environment for the navigation of ideas and concepts in education (V.E.N.I.C.E)abstractThis paper reports on current research into the development of an interactive visualisation tool for postgraduate research students. The aim of the research is to construct a virtual environment that allows students to navigate ideas, which they can then relate to conceptual structures. V. E.N.I.C.E offers users a virtual learning environment, which is at once a concept map, a file manager, and a memory palace. Modelled loosely on the infrastructure of the medieval city of Venice the application encourages users to build metaphorical relationships between conceptual islands of ideas, that are separated by canals, but linked by bridges, which in turn lead to further islands. On each island the user constructs a memory palace, which acts as a repository for data associated with a single idea. The palace is located within a confluence of discursive pathways that allow the student to position, affirm, challenge and expand upon a line of related argument. Simon N. Foley |
AVI | 1 |
| 2010 | A trust model for capability delegation in federated policy systemsabstractFederated policy systems are required to support the complexity and organizational heterogeneity of the modern marketplace. The Community-based Policy Management System (CBPMS) is such a distributed policy management approach. It utilizes a tree-based capability authority model to partition and delegate federated capabilities. However CBPMS delegation chains have limitations such as: performance overheads due to distributed rule evaluation, threats from malformed or malicious federated principals and a lack of flexibility with respect to delegation chain reduction or capability authority re-partitioning. In this paper we introduce a trust management model for CBPMS that addresses all of these issues.. A brief security analysis is presented and a telecommunications service management use case described. Kevin Feeney, Rob Brennan, Simon N. Foley |
CNSM | 3 |
| 2010 | Semiring-based frameworks for trust propagation in small-world networks and coalition formation criteriaabstractAbstract Multitrust provides a flexible approach to encoding trust metrics whereby definitions for trust propagation and aggregation are specified in terms of a semiring. Determining the degree of trust between principals across a trust network (TN) is, in turn, programmed as a (semiring‐based) soft‐constraint satisfaction problem. In this paper, we consider the use of semiring‐based metrics in reasoning about trust between coalition‐forming principals. The configurable nature of multitrust makes it well‐suited to modeling trust within coalitions: whether adding more principals to a coalition increases trust or decreases trust is captured by the definition of trust aggregation within the semiring. Copyright © 2010 John Wiley & Sons, Ltd. Stefano Bistarelli, Simon N. Foley, Barry O'Sullivan, Francesco Santini 0001 |
Secur. Commun. Networks | 2 |
| 2009 | An Approach to Security Policy Configuration Using Semantic Threat Graphs
Simon N. Foley, William M. Fitzgerald |
DBSec | 1 |
| 2009 | Configuring storage-area networks using mandatory securityabstractStorage-area networks are a popular and efficient way of building large storage systems both in an enterprise environment and for multi-domain storage service providers. In both environments the network and the storage has to be configured to ensure that the data is maintained securely and can be delivered efficiently. In this paper, we describe a model of mandatory security for SAN services that incorporates the notion of risk as a measure of the robustness of the SAN's configuration and that formally defines a vulnerability common in systems with mandatory security, i.e. cascaded threats. Our abstract SAN model is flexible enough to reflect the data requirements, tractable for the administrator, and can be implemented as part of an automatic configuration system. The implementation is given as part of a prototype written in OPL. Benjamin Aziz, Simon N. Foley, John Herbert, Garret Swart |
J. Comput. Secur. | 2 |
| 2006 | A Framework for Establishing Decentralized Secure CoalitionsabstractA coalition provides a virtual space across a network that allows its members to interact in a transparent manner. Coalitions may be formed for a variety of purposes. These range from simple spaces used by individuals to share resources and exchange information, to highly structured environments in which businesses and applications operate and may be governed according to regulation and contract (security policy). Coalitions may spawn further coalitions and coalitions may come-together and/or merge. This paper describes a logic-based language that provides a foundation for coalition regulation and contract in a manner that avoids authorization subterfuge and has a number of novel features that make it applicable to open systems. The language provides inter- and intra-coalition delegation, including identity, role and threshold based delegation operations. The logic is used to describe a decentralized infrastructure for establishing and regulating these coalitions. Coalitions are formed with the involvement of founders, constructors and oversight. Constructors are responsible for properly creating a coalition; this service can be provided by a third party. If the service is improperly provided then the constructor is subject to a penalty, which may be collected by another third party providing oversight. Hongbin Zhou, Simon N. Foley |
CSFW | 2 |
| 2005 | Highlights from the 2005 New Security Paradigms WorkshopabstractThis panel highlights a selection of the most interesting and provocative papers from the 2005 New Security Paradigms Workshop. This workshop was held September 2005 - the URL for more information is http://www.nspw.org. The panel consists of authors of the selected papers, and the session is moderated by the workshop's general chairs. We present selected papers focusing on exciting major themes that emerged from the workshop. These are the papers that will provoke the most interesting discussion at ACSAC. Simon N. Foley, Abe Singer, Michael E. Locasto, Stelios Sidiroglou-Douskos, Angelos D. Keromytis, John P. McDermott, Julie Thorpe, Paul C. van Oorschot, Anil Somayaji, Richard Ford, Mark Bush, Alex Boulatov |
ACSAC | 1 |
| 2005 | Trading Off Security in a Service Oriented Architecture
Garret Swart, Benjamin Aziz, Simon N. Foley, John Herbert |
DBSec | 3 |
| 2005 | A soft constraint-based approach to the cascade vulnerability problemabstractThe security of a network configuration is based not just on the security of its individual components and their direct interconnections, but also on the potential for systems to interoperate indirectly across network routes. Such interoperation has Stefano Bistarelli, Simon N. Foley, Barry O'Sullivan |
J. Comput. Secur. | 2 |
| 2004 | Detecting and Eliminating the Cascade Vulnerability Problem from Multilevel Security Networks Using Soft Constraints
Stefano Bistarelli, Simon N. Foley, Barry O'Sullivan |
AAAI | 2 |
| 2004 | Themes and Highlights of the New Security Paradigms Workshop 2004abstractThis panel highlights a selection of the most interesting and provocative papers from the 2004 New Security Paradigms Workshop. This workshop was held September 2004 - the URL for more information is (http://www.nspw.org). The panel consists of authors of the selected papers, and the session is moderated by the workshop's general chairs. We present selected papers focusing on exciting major themes that emerged from the workshop. These are the papers that will provoke the most interesting discussion at ACSAC. Carla Marceau, Simon N. Foley |
ACSAC | 2 |
| 2004 | Configuring Storage Area Networks for Mandatory SecurityabstractStorage-area networks are a popular and efficient way of building large storage systems both in an enterprise environment and for multi-domain storage service providers. In both environments the network and the storage has to be configured to ensure that the data is maintained securely and can be delivered efficiently. In this paper we describe a model of mandatory security for multi-domain storage services that is flexible enough to reflect the data requirements, tractable for the administrator, and implementable as part of an automatic configuration system. We describe the model abstractly, its implementation as part of a prototype SAN configuration system written in OPL, and illustrate its operation on a set of sample configurations. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Benjamin Aziz, Simon N. Foley, John Herbert, Garret Swart |
DBSec | 2 |
| 2004 | A Framework for Heterogeneous Middleware SecurityabstractSummary form only given. With the advent of Web services, achieving seamless interoperability between heterogeneous middleware technologies has become increasingly important. While much work investigating functional interoperability between different middleware architectures has been reported, little practical work has been done on providing a unified and/or interoperable view of security between the different approaches. We describe how Secure WebCom - a distributed metacomputing system - provides interoperability support between the COM+/.NET, CORBA and Enterprise Java Beans middleware security architectures. Secure WebCom uses the KeyNote trust management system to help coordinate the trust relationships between the different middleware systems and their associated security policies. Middleware authorisation policies can be encoded in terms of KeyNote cryptographic certificates, and vice-versa. This provides a unified view of security across heterogeneous middleware systems and also provides the basis for decentralised support of middleware security policies. Simon N. Foley, Thomas B. Quillinan, Maeve O'Connor, Barry P. Mulcahy, John P. Morrison |
IPDPS | 1 |
| 2004 | A collaborative approach to autonomic security protocolsabstractThis paper considers a new security protocol paradigm whereby principals negotiate and on-the-fly generate security protocols according to their needs. When principals wish to interact then, rather than offering each other a fixed menu of 'known' protocols, they negotiate and, possibly with the collaboration of other principles, synthesise a new protocol that is tailored specifically to their current security environment and requirements. This approach provides a basis for autonomic security protocols. Such protocols are self-configuring since only principal assumptions and protocol goals need to be a-priori configured. The approach has the potential to survive security compromises that can be modelled as changes in the beliefs of the principals. A compromise of a key or a change in the trust relationships between principals can result in a principal self-healing and synthesising a new protocol to survive the event. Hongbin Zhou, Simon N. Foley |
NSPW | 2 |
| 2003 | A Constraint Framework for the Qualitative Analysis of Dependability Goals: Integrity
Stefano Bistarelli, Simon N. Foley |
SAFECOMP | 2 |
| 2003 | A nonfunctional approach to system integrityabstractSystems provide integrity protection by ensuring that there is no unauthorized modification of information. Traditional models of protection tend to define integrity in terms of ad hoc authorization techniques whose effectiveness is justified more on the basis of experience and "best practice," rather than on any common theoretical foundation. A formal definition of integrity is proposed that is independent of any particular implementation mechanism. A series of simple examples is used to demonstrate that existing integrity mechanisms such as separation of duties, well-formed transactions, and so forth, can be regarded as implementation techniques for achieving integrity. The proposed characterization of integrity is nonfunctional, that is, it falls into the same category of properties as noninterference and its relatives. As a consequence, validating that a system has integrity can be expected to be as challenging as validating that a system upholds noninterference. Simon N. Foley |
IEEE J. Sel. Areas Commun. | 1 |
| 2002 | Secure Component Distribution Using WebCom
Simon N. Foley, Thomas B. Quillinan, John P. Morrison |
SEC | 1 |
| 2001 | Computational paradigms and protectionabstractWe investigate how protection requirements may be specified and implemented using the imperative, availability and coercion paradigms. Conventional protection mechanisms generally follow the imperative paradigm, requiring explicit and often centralized control over the sequencing and the mediation of security critical operations. This paper illustrates how casting protection in the availability and/or coercion styles provides the basis for more flexible and potentially distributed control over the sequencing and mediation of these operations. Simon N. Foley, John P. Morrison |
NSPW | 1 |
| 2000 | Conduit cascades and secure synchronizationabstractAbstract Synchronizing Personal Digital Assistants with host systems can result in indirect accesses that bypass security requirements. In this paper we propose a framework for analyzing the security vulnerabilities that can arise from synchronization. This framework provides us with the basis of a paradigm for analyzing the access-control vulnerabilities of systems comprised of secure and non-secure components. 1 Introduction Personal Digital Assistants (PDAs) such as the Palm handheld are small hand-held computing devices that support a variety of applications, ranging from conventional electronic organizer programs to spreadsheets, electronic mail and web browser clients. A PDA is commonly viewed as an extension of a user's workstation (or server); carrying data and programs that often mirror data and programs from the workstation. Synchronization between the workstation and the PDA is performed on a regular basis, ensuring that changes made to data stored on the PDA are reflected on the workstation, and vice-versa. Simon N. Foley |
NSPW | 1 |
| 1998 | A Kernelized Architecture for Multilevel Secure Application Policies
Simon N. Foley |
ESORICS | 1 |
| 1997 | Supporting Secure Canonical Upgrade Policies in Multilevel Secure Object StoresabstractSecure canonical upgrade policies are multilevel re-label policies that, under certain conditions, allow high-level subjects to update low-level security labels. This paper describes a scheme whereby these policies can be supported within the message filter model for multilevel secure object-oriented database management systems. Simon N. Foley |
ACSAC | 1 |
| 1997 | The Specification and Implementation of "Commercial" Security Requirements Including Dynamic Segregation of DutiesabstractA framework for the specification of security policies is proposed.It can used to formally specify confidentiality and integrity policies, the latter can be given in terms of Clark-Wilson style access triples.The tiamework extends the Clark-Wilson model in that it can be used to specify dynamic segregation of duty.For application systems where security is critical, a multilevel security based approach is defined.Security policies for less critical applications can be implemented using standard Unix based systems.Both implementation strategies are based on the standard protection mechanisms that are provided by the respective systems.Permission to m&e digitnl/h.udcopies of all or part of this material for personal or classroom use is gmnted without fee provided thnt the copies xc not made or distributed for profit or commercinl advnntnge, the COPYright notice, thetitle ofthe publication and its date appear, and notice is given that copyright is by permission ofthe ACM, Inc.To copy otherwise, to Simon N. Foley |
CCS | 1 |
| 1997 | Building Chinese walls in standard unixTM
Simon N. Foley |
Comput. Secur. | 1 |
| 1996 | A Security Model of Dynamic Labeling Providing a Tiered Approach to VerificationabstractIn the proposed mandatory access control model, arbitrary, label changing policies can be expressed. The relatively simple model can capture a wide variety of security policies, including high-water marks, downgrading, separation of duties, and Chinese Walls. The model forms the basis for a tiered approach to the formal development of secure systems, whereby security verification can be spread across what makes up the reference monitor and the security requirement specification. The advantage of this approach is that once a trusted computing base (TCB) is in place, reconfiguring it for different security requirements requires verification of just the new requirements. We illustrate the approach with a number of examples, including one policy that permits high-level subjects to make relabelling requests on low-level objects; the policy is multilevel secure. Simon N. Foley, Xiaolei Qian |
S&P | 1 |
| 1995 | Specifying security for CSCW systemsabstractCSCW systems provide computer support to facilitate cooperation between users. In this paper we propose an approach for the formal specification of functionality requirements and confidentiality security requirements of a CSCW application. These requirements give rise to safety and confidentiality properties that a CSCW system, supporting the application, should uphold. The specification technique is illustrated with a case study. Simon N. Foley, Jeremy L. Jacob |
CSFW | 1 |
| 1995 | Specifying Security for Computer Supported Collaborative WorkingabstractCSCW systems provide computer support to facilitate cooperation between users. This paper proposes an approach to the formal specification of security requirements for CSCW applications, where a CSCW application is viewed as a collection of activitie Simon N. Foley, Jeremy L. Jacob |
J. Comput. Secur. | 1 |
| 1994 | Reasoning about Confidentiality RequirementsabstractReflexive flow policies provide abstract characterizations of certain multilevel confidentiality requirements. This paper describes how reflexive flow policies can be used to construct and reason about large/complex multilevel policies. In particular, we describe how reflexive policies can be used to develop and reason about security policies for multilevel relational databases. Our approach facilitates a study of the relationship between security policy design and database design.> Simon N. Foley |
CSFW | 1 |
| 1992 | Aggregation and Separation as Noninterference PropertiesabstractThis paper proposes a notation that can be used to describe information flow policies that may have transitivity, aggregation and separation (of duty) exceptions. Operators for comparing, composing and abstracting these policies are described. These Simon N. Foley |
J. Comput. Secur. | 1 |
| 1991 | Separation of Duty using High Water MarksabstractThe paper describes an approach to specifying and enforcing separation of duty policies using information flow controls. Separation flow policies are based on the notion that sufficient information must be present before it may flow to a receiver. These policies also have natural integrity duals. A high water mark mechanism is described that can enforce these policies.> Simon N. Foley |
CSFW | 1 |
| 1991 | A Taxonomy for Information Flow Policies and ModelsabstractA notation for describing information flow policies that can express transitive, aggregation and separation (of duty) exceptions is proposed. Operators for comparing, composing, and abstracting flow policies are described. These allow complex policies to be built from simpler policies. Many existing confidentiality (and by using a dual model, integrity) policies and their models can be captured in this framework. A high water mark model is described that can enforce a large class of these information flow policies. The model provides the basis for a taxonomy of existing high water mark mechanisms.> Simon N. Foley |
S&P | 1 |
| 1990 | Secure Information Flow Using Security GroupsabstractA new model and approach for secure information flow are described. The model is driven by a lattice-based information flow policy which describes the permitted dissemination of information in the system. System entities are allowed to handle different classes of information from the flow policy, and information is permitted to flow between entities as long as the flow policy is not violated. With this conceptually simple notion of security it is possible to describe many interesting security policies, for example, multilevel policies, aggregation policies, and Chinese walls. Details of how secure systems based on the model can be implemented in practice are given. Attention is also given to how other types of security policies, such as integrity and separation of duty, can be defined in terms of lattice-based policies.> Simon N. Foley |
CSFW | 1 |
| 1989 | A Model for Secure Information FlowabstractA model that characterizes systems that restrict information flow is proposed. The model, called the confinement model, provides greater flexibility in the binding of entities to their security classes than the current static case. A consequence of the nature of security class binding in the confinement model is its ability to enforce nontransitive information-flow policies. A framework of information-flow policies is defined which forms a distributive lattice under operations for policy ordering and combination. It is shown that a state-based MAC (mandatory access) version of the confinement model is the same as a traditional Bell and LaPadula MAC model, except that the confinement model includes a special rule on dynamic class change.> Simon N. Foley |
S&P | 1 |
| 1987 | A Universal Theory of Information FlowabstractA new theory of information flow is presented. This theory is used to determine the information flows between the users of a system. Information flows when variety in the actions of a source user can be conveyed to a destination user. This theory is developed around Hoare'a calculus for communicating sequential processes. Information flows due to concurrency, non-determinism and input/output can be examined within the framework of this calculus. Simon N. Foley |
S&P | 1 |