James B. D. Joshi

dblp:j/JamesJoshi · also James Joshi · DBLP profile ↗
← Back
87ranked-venue papers
13as first author
9since 2021 · last 2026
0000-0003-4519-9802ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 40 · 6 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 16 · 1 since 2021Computer networks · 10 · 1 first-authorSoftware engineering, systems software and programming languages · 10 · 4 first-author · 2 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 6 · 1 first-authorArtificial intelligence and machine learning · 4 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorSystems, architecture and hardware · 1
YearPublicationVenuePosition
2026 Editorial: TSC Celebrates IEEE Computer Society's 80th Anniversary
Liang-Jie Zhang, Ling Liu 0001, James B. D. Joshi, Ernesto Damiani, Surya Nepal, Marco Aiello 0001
IEEE Trans. Serv. Comput.3
2024 Dual Defense: Enhancing Privacy and Mitigating Poisoning Attacks in Federated Learning
abstract
Federated learning (FL) is inherently susceptible to privacy breaches and poisoning attacks. To tackle these challenges, researchers have separately devised secure aggregation mechanisms to protect data privacy and robust aggregation methods that withstand poisoning attacks. However, simultaneously addressing both concerns is challenging; secure aggregation facilitates poisoning attacks as most anomaly detection techniques require access to unencrypted local model updates, which are obscured by secure aggregation. Few recent efforts to simultaneously tackle both challenges offen depend on impractical assumption of non-colluding two-server setups that disrupt FL's topology, or three-party computation which introduces scalability issues, complicating deployment and application. To overcome this dilemma, this paper introduce a Dual Defense Federated learning (DDFed) framework. DDFed simultaneously boosts privacy protection and mitigates poisoning attacks, without introducing new participant roles or disrupting the existing FL topology. DDFed initially leverages cutting-edge fully homomorphic encryption (FHE) to securely aggregate model updates, without the impractical requirement for non-colluding two-server setups and ensures strong privacy protection. Additionally, we proposes a unique two-phase anomaly detection mechanism for encrypted model updates, featuring secure similarity computation and feedback-driven collaborative selection, with additional measures to prevent potential privacy breaches from Byzantine clients incorporated into the detection process. We conducted extensive experiments on various model poisoning attacks and FL scenarios, including both cross-device and cross-silo FL. Experiments on publicly available datasets demonstrate that DDFed successfully protects model privacy and effectively defends against model poisoning threats.
Runhua Xu, Shiqi Gao, Chao Li 0023, James B. D. Joshi, Jianxin Li 0002
NeurIPS4
2024 TAPFed: Threshold Secure Aggregation for Privacy-Preserving Federated Learning
abstract
Federated learning is a computing paradigm that enhances privacy by enabling multiple parties to collaboratively train a machine learning model without revealing personal data. However, current research indicates that traditional federated learning platforms are unable to ensure privacy due to privacy leaks caused by the interchange of gradients. To achieve privacy-preserving federated learning, integrating secure aggregation mechanisms is essential. Unfortunately, existing solutions are vulnerable to recently demonstrated inference attacks such as the disaggregation attack. This paper proposesTAPFed, an approach for achieving privacy-preserving federated learning in the context of multiple decentralized aggregators with malicious actors.TAPFeduses a proposed threshold functional encryption scheme and allows for a certain number of malicious aggregators while maintaining security and privacy. We provide formal security and privacy analyses ofTAPFedand compare it to various baselines through experimental evaluation. Our results show thatTAPFedoffers equivalent performance in terms of model quality compared to state-of-the-art approaches while reducing transmission overhead by 29%-45% across different model training scenarios. Most importantly,TAPFedcan defend against recently demonstrated inference attacks caused by curious aggregators, which the majority of existing approaches are susceptible to.
Runhua Xu, Bo Li 0005, Chao Li 0023, James B. D. Joshi, Shuai Ma 0001, Jianxin Li 0002
IEEE Trans. Dependable Secur. Comput.4
2023 Blockchain-Based Transparency Framework for Privacy Preserving Third-Party Services
abstract
Increasingly, information systems rely on computational, storage, and network resources deployed in third-party facilities such as cloud centers and edge nodes. Such an approach further exacerbates cybersecurity concerns constantly raised by numerous incidents of security and privacy attacks resulting in data leakage and identity theft, among others. These have, in turn, forced the creation of stricter security and privacy-related regulations and have eroded the trust in cyberspace. In particular, security-related services and infrastructures, such as Certificate Authorities (CAs) that provide digital certificate services and Third-Party Authorities (TPAs) that provide cryptographic key services, are critical components for establishing trust in crypto-based privacy-preserving applications and services. To address such trust issues, various transparency frameworks and approaches have been recently proposed in the literature. This paper proposes TAB framework that provides transparency and trustworthiness of third-party authority and third-party facilities using blockchain techniques for emerging crypto-based privacy-preserving applications. TAB employs the Ethereum blockchain as the underlying public ledger and also includes a novel smart contract to automate accountability with an incentive mechanism that motivates users to participate in auditing, and punishes unintentional or malicious behaviors. We implement TAB and show through experimental evaluation in the Ethereum official test network, Rinkeby, that the framework is efficient. We also formally show the security guarantee provided by TAB, and analyze the privacy guarantee and trustworthiness it provides.
Runhua Xu, Chao Li 0023, James B. D. Joshi
IEEE Trans. Dependable Secur. Comput.3
2022 An Automatic Attribute-Based Access Control Policy Extraction From Access Logs
abstract
With the rapid advances in computing and information technologies, traditional access control models have become inadequate in terms of capturing fine-grained, and expressive security requirements of newly emerging applications. An attribute-based access control (ABAC) model provides a more flexible approach to addressing the authorization needs of complex and dynamic systems. While organizations are interested in employing newer authorization models, migrating to such models pose as a significant challenge. Many large-scale businesses need to grant authorizations to their user populations that are potentially distributed across disparate and heterogeneous computing environments. Each of these computing environments may have its own access control model. The manual development of a single policy framework for an entire organization is tedious, costly, and error-prone. In this article, we present a methodology for automatically learning ABAC policy rules from access logs of a system to simplify the policy development process. The proposed approach employs an unsupervised learning-based algorithm for detecting patterns in access logs and extracting ABAC authorization rules from these patterns. In addition, we present two policy improvement algorithms, including rule pruning and policy refinement algorithms to generate a higher quality mined policy. Finally, we implement a prototype of the proposed approach to demonstrate its feasibility.
Leila Karimi, Maryam Aldairi, James B. D. Joshi, Mai Abdelhakim
IEEE Trans. Dependable Secur. Comput.3
2022 NN-EMD: Efficiently Training Neural Networks Using Encrypted Multi-Sourced Datasets
abstract
Training complex neural network models using third-party cloud-based infrastructure among multiple data sources is a promising approach among existing machine learning solutions. However, privacy concerns of large-scale data collections and recent regulations have restricted the availability and use of privacy sensitive data in the third-party infrastructure. To address such privacy issues, a promising emerging approach is to train a neural network model over an encrypted dataset. Specifically, the model training process can be outsourced to a third party such as a cloud service that is backed by significant computing power, while the encrypted training data keeps the data confidential from the third party. Compared to training a traditional machine learning model over encrypted data, however, it is extremely challenging to train a deep neural network (DNN) model over encrypted data for two reasons: first, it requires large-scale computation over huge datasets; second, the existing solutions for computation over encrypted data, such as using homomorphic encryption, is inefficient. Further, for enhanced performance of a DNN model, we also need to use huge training datasets composed of data from multiple data sources that may not have pre-established trust relationships among each other. We propose a novel framework,NN-EMD, to train DNN overencrypted multiple datasetscollected from multiple sources. Toward this, we propose a set of secure computation protocols using hybrid functional encryption schemes. We evaluate our framework for performance with regards to the training time and model accuracy on the MNIST datasets. We show that compared to other existing frameworks, our proposedNN-EMDframework can significantly reduce the training time, while providing comparable model accuracy and privacy guarantees as well as supporting multiple data sources. Furthermore, the depth and complexity of neural networks do not affect the training time despite introducing a privacy-preservingNN-EMDsetting.
Runhua Xu, James B. D. Joshi, Chao Li 0023
IEEE Trans. Dependable Secur. Comput.2
2022 Guest Editorial: Special Issue on Services Computing for COVID-19 and Future Pandemics
abstract
THE COVID-19 pandemic has brought the global society to a historic turning point. While the current pandemic is transforming our normal lives in an unprecedented way, the computing and information services ecosystem have provided the much-needed support to the continuity of the social interactions and the organizational functions. As COVID-19 continues to transform the global society, it is also exposing the weaknesses of the current services ecosystems and newer research challenges to further leveraging emerging computing and services technologies to provide secure, privacy-aware and resilient infrastructure and services during pandemics. The goal of this special issue has been to solicit impactful research papers that will be of immediate value to the ongoing COVID-19 pandemic as well as for future pandemic and crises.
Mei-Ling Shyu, Surya Nepal, Valérie Issarny, James B. D. Joshi
IEEE Trans. Serv. Comput.4
2021 Cybersecurity Education in the Age of Artificial Intelligence
abstract
The 2019 Federal Cybersecurity Research and Development Strategic Plan highlighted the mutual needs and benefits of artificial intelligence (AI) and cybersecurity. AI techniques are expected to enhance cybersecurity by assisting human system managers with automated monitoring, analysis, and responses to cybersecurity attacks. Conversely, it is essential to guard AI technologies from unintended uses and hostile exploitation by leveraging cybersecurity practices. Research results at the intersection of AI and cybersecurity can help us to be better equipped with tools and techniques to tackle the growing cybersecurity challenges, while also presenting an opportunity to devise fundamentally new ways to motivate and educate students about cybersecurity in the age of AI. Likewise, a June 2019 technical workshop on 'Artificial Intelligence and Cybersecurity: Opportunities and Challenges' noted how the interplay between AI, machine learning, and cybersecurity will continue to introduce new opportunities and challenges in the security of AI as well as AI for cybersecurity. Basic research at the intersection of AI, cybersecurity, and education has the potential to expand existing AI opportunities and resources in cybersecurity education and workforce development. Education efforts are needed to foster workforce knowledge and skills about applying AI expertise to cybersecurity as well as building robust and trustworthy AI. This BOF session will bring together researchers who are interested in these collaborative explorations.
Nigamanth Sridhar, James B. D. Joshi, Victor Piotrowski
SIGCSE3
2021 An Integrated Privacy Preserving Attribute-Based Access Control Framework Supporting Secure Deduplication
abstract
Recent advances in information technologies have facilitated applications to generate, collect or process large amounts of sensitive personal data. Emerging cloud storage services provide a better paradigm to support the needs of such applications. Such cloud based solutions introduce additional security and privacy challenges when dealing with outsourced data including that of supporting fine-grained access control over such data stored in the cloud. In this paper, we propose an integrated, privacy-preserving user-centric attribute based access control framework to ensure the security and privacy of users' data outsourced and stored by a cloud service provider (CSP). The core component of the proposed framework is a novel privacy-preserving, revocable ciphertext policy attribute-based encryption (PR-CP-ABE) scheme. To support advanced access control features like write access on encrypted data and privacy-preserving access policy updates, we propose extended Path-ORAM access protocol that can also prevent privacy disclosure of access patterns. We also propose an integrated secure deduplication approach to improve the storage efficiency of CSPs while protecting data privacy. Finally, we evaluate the proposed framework and compare it with other existing solutions with regards to the security and performance issues.
Runhua Xu, James B. D. Joshi, Prashant Krishnamurthy
IEEE Trans. Dependable Secur. Comput.2
2020 A constraint and risk-aware approach to attribute-based access control for cyber-physical systems
Nuray Baltaci Akhuseyinoglu, James B. D. Joshi
Comput. Secur.2
2020 Trustworthy and Transparent Third-party Authority
abstract
Recent advances in cryptographic approaches, such as Functional Encryption and Attribute-based Encryption and their variants, have shown significant promise for enabling public clouds to provide secure computation and storage services for users’ sensitive data. A crucial component of these approaches is a third-party authority (TPA) that must be trusted to set up public parameters, provide private key service, and so on. Components of deployed cryptographic mechanisms such as the certificate authorities (CAs) , which are the TPAs of the underlying PKI for the SSL/TLS protocol, have faced several types of attacks (e.g., stealthy targeted and censorship attacks), and certificate mis-issuance problems. Such practical challenges indicate that the successful deployment of newer emerging cryptographic schemes will also significantly depend on the trustworthiness of the TPAs. Furthermore, recently proposed decentralized TPA approaches that lower the threshold on the conditions required for an entity to become an authority can make the trust issue much worse. To address this issue, we propose an authority transparency framework to ensure the trustworthiness of TPAs of recent and emerging advanced cryptographic schemes. The framework includes a formal model and a secure logging -based approach to implement the framework. Further, to address the issues related to privacy, we also present a privacy-preserving authority transparency approach. We present security analysis and performance evaluation to show that authority transparency achieves the security and performance goals.
Runhua Xu, James B. D. Joshi
ACM Trans. Internet Techn.2
2020 Editorial
abstract
Presents the introductory editorial for this issue of the publication.
James B. D. Joshi
IEEE Trans. Serv. Comput.1
2019 CryptoNN: Training Neural Networks over Encrypted Data
abstract
Emerging neural networks based machine learning techniques such as deep learning and its variants have shown tremendous potential in many application domains. However, they raise serious privacy concerns due to the risk of leakage of highly privacy-sensitive data when data collected from users is used to train neural network models to support predictive tasks. To tackle such serious privacy concerns, several privacy-preserving approaches have been proposed in the literature that use either secure multi-party computation (SMC) or homomorphic encryption (HE) as the underlying mechanisms. However, neither of these cryptographic approaches provides an efficient solution towards constructing a privacy-preserving machine learning model, as well as supporting both the training and inference phases. To tackle the above issue, we propose a CryptoNN framework that supports training a neural network model over encrypted data by using the emerging functional encryption scheme instead of SMC or HE. We also construct a functional encryption scheme for basic arithmetic computation to support the requirement of the proposed CryptoNN framework. We present performance evaluation and security analysis of the underlying crypto scheme and show through our experiments that CryptoNN achieves accuracy that is similar to those of the baseline neural network models on the MNIST dataset.
Runhua Xu, James B. D. Joshi, Chao Li 0023
ICDCS2
2019 G-SIR: An Insider Attack Resilient Geo-Social Access Control Framework
abstract
Insider attacks are among the most dangerous and costly attacks to organizations. These attacks are carried out by individuals who are legitimately authorized to access the system. Preventing insider attacks is a daunting task. The recent proliferation of social media and mobile devices offer new opportunities to collect geo-social information that can help in detecting and deterring insider attacks. In particular, such geo-social information allows us to better understand the context and behavior of users. In this paper, we propose a Geo-Social Insider Threat Resilient Access Control Framework (G-SIR) to deter insider threats by including current and historic geo-social information as part of the access control decision process. We include policy constraints to manage the risks of colluding communities, proximity threats, and suspicious users while leveraging the presence of users around the requester to make an access decision. By examining users' geo-social behavior, we can detect those users whose access behavior deviates from the expected patterns; such suspicious behaviors can point to potential insider attackers who may deliberately or inadvertently carry out malicious activities. We use such information to establish how trustworthy a user is before granting access. We evaluate the G-SIR framework through extensive simulations and our results show that the proposed approach is efficient, scalable and effective.
Nathalie Baracaldo, Balaji Palanisamy, James B. D. Joshi
IEEE Trans. Dependable Secur. Comput.3
2019 Introduction to the Special Section on Advances in Internet-based Collaborative Technologies
abstract
Individuals, organizations, and government agencies are increasingly relying on Internet-enabled collaboration among distributed teams of humans, computer applications, and autonomous entities such as robots to develop products and deliver services. Technology trends in areas such as networking, data analytics, and distributed systems have significantly shifted the landscape of Internet-based collaborative tools and services. This particular special issue contains articles describing novel and innovative Internet-based collaborative technologies that leverage emerging technologies and enable seamless collaboration.
Schahram Dustdar, Surya Nepal, James B. D. Joshi
ACM Trans. Internet Techn.3
2019 Editorial
abstract
Presents the introductory editorial for this issue of the publication.
James B. D. Joshi
IEEE Trans. Serv. Comput.1
2018 An Unsupervised Learning Based Approach for Mining Attribute Based Access Control Policies
abstract
An Attribute-Based Access Control (ABAC) model provides a flexible and promising approach for large, dynamic systems/applications and helps overcome the limitations of other prevalent AC approaches. However, the cost of migrating to an ABAC based system is a significant obstacle for organizations. Many large enterprises/applications need to grant access privileges to a huge number of users distributed across disparate computing environments and applications including legacy systems. Each of these applications may have its own access control model. Manual development of a single access control policy through a set of attribute-based policy rules is expensive and time consuming. In this paper, we present a methodology for automatically learning ABAC policy rules from access logs in a system to facilitate the AC policy development process. The proposed approach uses an unsupervised learning-based technique for detecting patterns in a set of access records and extracting ABAC policy rules from these patterns. We present two algorithms, rule pruning, and policy refinement, to improve the quality of the mined policy. Policy refinement algorithms are useful in ABAC policy maintenance, as well. We evaluate our proposed approach on three different sample policies as well as a randomly synthesized policy to show its effectiveness.
Leila Karimi, James B. D. Joshi
IEEE BigData2
2018 k-Trustee: Location injection attack-resilient anonymization for location privacy
Lei Jin 0003, Chao Li 0023, Balaji Palanisamy, James B. D. Joshi
Comput. Secur.4
2017 Editorial: A Message from the New Editor-in-Chief
abstract
Presents the introductory editorial for this issue of the publication.
James B. D. Joshi
IEEE Trans. Serv. Comput.1
2016 An Integrated Privacy Preserving Attribute Based Access Control Framework
abstract
Recent advances in IT have enabled many applications that generate/collect huge amounts of personal data. While these advances have made many personalized applications such as personalized user-centric healthcare possible there are significant system maintenance cost related to data management, and security and privacy issues that need to be first addressed. Although cloud computing presents a new paradigm that helps maintaining users aggregated information distributed in different Internet enabled applications in one place, it also introduces new challenges in security and privacy. In this paper, we propose an integrated user-centric (or an organization-centric) privacy preserving attribute based access control approach to protect the security and privacy of a user's(or the organization's) data stored by a cloud service provider. The proposed approach includes a novel privacypreserving revocable ciphertext policy attribute-based encryption (PR-CP-ABE) scheme. We also propose an extended Path-ORAM protocol that addresses the access pattern privacy as users access the protected data on cloud. We present security and privacy analysis and compare the performance parameters with other existing approaches.
Runhua Xu, James B. D. Joshi
CLOUD2
2016 SocialMix: Supporting Privacy-Aware Trusted Social Networking Services
abstract
Online Social Networks (OSNs) have been one of the most successful web-based communication models. In the recent years, a new category of OSNs namely anonymous social networks are becoming popular. Unlike traditional Online Social Networks, anonymous social networks allow users to communicate without exposing their identity. This paper presents a trusted anonymous social network service that can anonymize user identities during interaction even though the communication happens with the user's own trusted friends and contacts on the social network. A fundamental requirement of such a trusted anonymous social networks is to protect the user's identity under the guarantees of anonymity. However, in existing approaches, even though the user information is anonymized, by continuously aggregating the information from the messages posted by a user, it is possible to re-identify the user with high probability. In this paper, we propose SocialMix that anonymizes the users of a trusted social network such that the aggregation of messages can be prevented. We make three original contributions. First, we develop the SocialMix model for trusted anonymous social networks so that communication privacy can be protected by k-anonymization. Second, by considering the features of OSNs, we analyze the vulnerabilities of the naive methods that might be exploited to break the privacy. We develop new techniques to improve the attack-resilience of the SocialMix approach. Third, we propose intelligent mix node selection methods to significantly reduce the required number of social mix nodes while still keeping high anonymization rate. Our experiments shows that SocialMix provides high attack resilience and keeps high anonymization rate with few mix nodes under the trusted social network model.
Chao Li 0023, Balaji Palanisamy, James B. D. Joshi
ICWS3
2016 Characterizing users' check-in activities using their scores in a location-based social network
Lei Jin 0003, Xuelian Long, Ke Zhang 0013, Yu-Ru Lin, James B. D. Joshi
Multim. Syst.5
2015 Towards complexity analysis of User Authorization Query problem in RBAC
Jianfeng Lu 0002, James B. D. Joshi, Lei Jin 0003
Comput. Secur.2
2014 POSTER: Compromising Cloaking-based Location Privacy Preserving Mechanisms with Location Injection Attacks
abstract
Cloaking-based location privacy preserving mechanisms have been widely adopted to protect users' location privacy while traveling on road networks. However, a fundamental limitation of such mechanisms is that users in the system are inherently trusted and assumed to always report their true locations. Such vulnerability can lead to a new class of attacks called location injection attacks which can successfully break users' anonymity among a set of users through the injection of fake user accounts and incorrect location updates. In this paper, we characterize location injection attacks, demonstrate their effectiveness through experiments on real-world geographic maps and discuss possible defense mechanisms to protect against such attacks.
Lei Jin 0003, Balaji Palanisamy, James B. D. Joshi
CCS3
2014 Geo-Social-RBAC: A Location-Based Socially Aware Access Control Framework
Nathalie Baracaldo, Balaji Palanisamy, James B. D. Joshi
NSS3
2014 CPBAC: Property-based access control model for secure cooperation in online social networks
Youna Jung, James B. D. Joshi
Comput. Secur.2
2014 Editorial
Lakshmish Ramaswamy, Barbara Carminati, Lujo Bauer, Dongwan Shin, James B. D. Joshi, Calton Pu, Dimitris Gritzalis
Comput. Secur.5
2014 Preface
Barbara Carminati, Lakshmish Ramaswamy, Anna Cinzia Squicciarini, James B. D. Joshi, Calton Pu
Int. J. Cooperative Inf. Syst.4
2014 Editorial: Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom 2012)
Lakshmish Ramaswamy, Barbara Carminati, James B. D. Joshi, Calton Pu
Mob. Networks Appl.3
2013 A HITS-based POI recommendation algorithm for location-based social networks
abstract
Location-Based Social Networks (LBSNs), (also called as Geo-Social Networks), has been attracting more and more users by providing services that integrate social activities with location information. LBSN systems usually provide support for indicating various Points of Interest (POIs) but there is no straightforward rating mechanism for POIs in most LBSNs [1]. POI recommendations in LBSNs, thus, is an important and challenging research topic. In this paper, we first investigate the dataset crawled from Foursquare to explore the features that attract and influence users to check in at various POIs. Based on the analysis results, we propose a HITS (Hypertext Induced Topic Search)-based POI recommendation algorithm to recommend POIs to LBSN users that can also incorporate the impact of the social relationships on recommendations. We evaluate our proposed model on Foursquare dataset and compare our results with the latest POI recommendation algorithm. The experimental results show that our approach performs better.
Xuelian Long, James B. D. Joshi
ASONAM2
2013 Privacy settings in social networking systems: what you cannot control
abstract
In this paper, we propose a framework to formally analyze what privacy-sensitive information is protected by the stated policies of a Social Networking System (SNS), based on an expression of ideal protection policies for a user. Our ontology-based framework can capture complex and fine-grained privacy-sensitive information in SNSs, and find out missing policies, given a user's ideal policies, and SNS's privacy settings and described system policies. We propose notions of policy completeness for SNSs to facilitate such an analysis. Our case study of using this approach on Facebook shows that we can effectively identify important missing policies.
Amirreza Masoumzadeh 0001, James B. D. Joshi
AsiaCCS2
2013 Understanding venue popularity in Foursquare
abstract
Recently, social media has become an increasingly important part of business and marketing. More and more businesses use social media as part of their marketing platforms. Moreover, the fast development of the 4th generation mobile network and the ubiquity of the advanced mobile devices in which GP
Xuelian Long, Lei Jin 0003, James B. D. Joshi
CollaborateCom3
2013 Towards understanding traveler behavior in Location-based Social Networks
abstract
Understanding users' behavior in Location-based Social Networks (LBSNs) is becoming an interesting research topic. In LBSNs, users can explore the places of interest around their current locations, check in at these locations and share such check-ins with their friends or the public. Therefore, the check-ins are valuable information for studying user behavior. Many services would benefit from the research of user behavior. For example, it can help the urban design and development based on the user mobility patterns and it could also improve the location recommendations to help users to find their places of interests. Intrinsically, traveler's activities in LBSN are distinctive, especially when compared with the a local user's activities. Therefore, a study of travelers' activities in LBSNs can help understand traveler behavior and then help LBSNs provider to improve their services, e.g. location recommendation service to new visitors. The location recommendation is especially important for a new visitor to a city. However, in the literature, there is little work specially focusing on the research of travelers' behavior in LBSNs. In this paper, we take the first step towards understanding such user behavior in LBSNs. Our research is based on the travelers' check-in information created in the greater Pittsburgh area in Foursquare. At first, we empirically study the venues and the check-ins created on such venues based on venue category information. After that, we investigate the temporal features of travelers' check-ins, and examine the evolution of check-ins created at the venues related to four categories using spatio-temporal information. Besides the empirical study, we employ the notion of user entropy to investigate the diversity of the travelers' check-ins. Through the research of the user entropy as a function of the user's check-ins, we find that the majority travelers usually exhibit higher diversity in their activities. Moreover, we also use the Latent Dirichlet Allocation (LDA) to generate travelers' mobility patterns. These human centric latent topics cannot only help to cluster the venues but also address the hot spots in a city based on the crowd level.
Xuelian Long, Lei Jin 0003, James B. D. Joshi
GLOBECOM3
2013 Beyond accountability: using obligations to reduce risk exposure and deter insider attacks
abstract
Recently, the importance of including obligations as part of access control systems for privilege management, for example, in healthcare information systems, has been well recognized. In an access control system, an a posteriori obligation states which actions need to be performed by a user after he has accessed a resource. There is no guarantee that a user will fulfill a posteriori obligations. Not fulfilling these obligations may incur financial loss, or loss of goodwill and productivity to the organization. In this paper, we propose a trust-and-obligation based framework that reduces the risk exposure of an organization associated with a posteriori obligations. We propose a methodology to assign trust values to users to indicate how trustworthy they are with regards to fulfilling their obligations. When access requests that trigger a posteriori obligations are evaluated, the requesting users' trust values and the criticality of the associated obligations are used. Our framework detects and mitigates insider attacks and unintentional damages that may result from violating a posteriori obligations. Our framework also provides mechanisms to determine misconfigurations of obligation policies. We evaluate our framework through simulations and demonstrate its effectiveness.
Nathalie Baracaldo, James B. D. Joshi
SACMAT2
2013 An adaptive risk management and access control framework to mitigate insider threats
Nathalie Baracaldo, James B. D. Joshi
Comput. Secur.2
2013 Mutual-friend based attacks in social network systems
Lei Jin 0003, James B. D. Joshi, Mohd Anwar
Comput. Secur.2
2013 Editorial for CollaborateCom 2011 Special Issue
James Caverlee, Calton Pu, Dimitrios Georgakopoulos 0001, James B. D. Joshi
Mob. Networks Appl.4
2012 Preface
Barbara Carminati, Lakshmish Ramaswamy, Calton Pu, James B. D. Joshi
CollaborateCom4
2012 Towards secure cooperation in online social networks
abstract
The rapid growth of online social networks (OSNs) has brought a revolutionary change in the way geographically dispersed people interact and cooperate with each other towards achieving some common goals. Recently, some new ways of ad-hoc cooperation have been demonstrated during the hurricane Irene
Youna Jung, James B. D. Joshi
CollaborateCom3
2012 Exploring trajectory-driven local geographic topics in foursquare
abstract
The location based social networking services (LBSNSs) are becoming very popular today. In LBSNSs, such as Foursquare, users can explore their places of interests around their current locations, check in at these places to share their locations with their friends, etc. These check-ins contain rich information and imply human mobility patterns; thus, they can greatly facilitate mining and analysis of local geographic topics driven by users' trajectories. The local geographic topics indicate the potential and intrinsic relations among the locations in accordance with users' trajectories. These relations are useful for users in both location and friend recommendations. In this paper, we focus on exploring the local geographic topics through check-ins in Pittsburgh area in Foursquare. We use the Latent Dirichlet Allocation (LDA) model to discover the local geographic topics from the checkins. We also compare the local geographic topics on weekdays with those at weekends. Our results show that LDA works well in finding the related places of interests.
Xuelian Long, Lei Jin 0003, James B. D. Joshi
UbiComp3
2012 A trust-and-risk aware RBAC framework: tackling insider threat
abstract
Insider Attacks are one of the most dangerous threats organizations face today. An insider attack occurs when a person authorized to perform certain actions in an organization decides to abuse the trust, and harm the organization. These attacks may negatively impact the reputation of the organization, its productivity, and may produce losses in revenue and clients. Avoiding insider attacks is a daunting task. While it is necessary to provide privileges to employees so they can perform their jobs efficiently, providing too many privileges may backfire when users accidentally or intentionally abuse their privileges. Hence, finding a middle ground, where the necessary privileges are provided and malicious usage are avoided, is necessary. In this paper, we propose a framework that extends the role-based access control (RBAC) model by incorporating a risk assessment process, and the trust the system has on its users. Our framework adapts to suspicious changes in users' behavior by removing privileges when users' trust falls below a certain threshold. This threshold is computed based on a risk assessment process that includes the risk due to inference of unauthorized information. We use a Coloured-Petri net to detect inferences. We also redefine the existing role activation problem, and propose an algorithm that reduces the risk exposure. We present experimental evaluation to validate our work.
Nathalie Baracaldo, James B. D. Joshi
SACMAT2
2012 CRiBAC: Community-centric role interaction based access control model
Youna Jung, James B. D. Joshi
Comput. Secur.2
2012 ACM/Springer Mobile Networks and Applications (MONET) Special Issue on "Collaborative Computing: Networking, Applications and Worksharing"
Songqing Chen, Le Gruenwald, James B. D. Joshi, Karl Aberer
Mob. Networks Appl.3
2012 ACM/Springer Mobile Networks and Applications (MONET) Special Issue on "Collaborative Computing: Networking, Applications and Worksharing"
James B. D. Joshi, Elisa Bertino, Calton Pu, Heri Ramampiaro
Mob. Networks Appl.1
2012 ACM/Springer Mobile Networks and Applications (MONET) Special Issue on "Collaborative Computing: Networking, Applications and Worksharing"
Weisong Shi, James B. D. Joshi, Tao Zhang 0005, Eun K. Park, Juan Quemada
Mob. Networks Appl.2
2012 Preserving Structural Properties in Edge-Perturbing Anonymization Techniques for Social Networks
abstract
Social networks are attracting significant interest from researchers in different domains, especially with the advent of social networking systems which enable large-scale collection of network information. However, as much as analysis of such social networks can benefit researchers, it raises serious privacy concerns for the people involved in them. To address such privacy concerns, several techniques, such as k-anonymity-based approaches, have been proposed in the literature to provide user anonymity in published social networks. However, these methods usually introduce a large amount of distortion to the original social network graphs, thus, raising serious questions about their utility for useful social network analysis. Consequently, these techniques may never be applied in practice. We propose two methods to enhance edge-perturbing anonymization methods based on the concepts of structural roles and edge betweenness in social network theory. We experimentally show significant improvements in preserving structural properties in an anonymized social network achieved by our approach compared to the original algorithms over several data sets.
Amirreza Masoumzadeh 0001, James B. D. Joshi
IEEE Trans. Dependable Secur. Comput.2
2011 Towards active detection of identity clone attacks on online social networks
abstract
Online social networks (OSNs) are becoming increasingly popular and Identity Clone Attacks (ICAs) that aim at creating fake identities for malicious purposes on OSNs are becoming a significantly growing concern. Such attacks severely affect the trust relationships a victim has built with other users if no active protection is applied. In this paper, we first analyze and characterize the behaviors of ICAs. Then we propose a detection framework that is focused on discovering suspicious identities and then validating them. Towards detecting suspicious identities, we propose two approaches based on attribute similarity and similarity of friend networks. The first approach addresses a simpler scenario where mutual friends in friend networks are considered; and the second one captures the scenario where similar friend identities are involved. We also present experimental results to demonstrate flexibility and effectiveness of the proposed approaches. Finally, we discuss some feasible solutions to validate suspicious identities.
Lei Jin 0003, Hassan Takabi, James B. D. Joshi
CODASPY3
2011 A trust-based approach to mitigate rerouting attacks
abstract
One of the ways a malicious router can launch a Denial of Service (DoS) attack is by rerouting IP-packets of other destinations to the victim node. In this paper, based on the observed traffic anomalies, we ropose using a Markov chain model to calculate trustworthiness of routers in order to isolate
Jesus M. Gonzalez, Mohd Anwar, James B. D. Joshi
CollaborateCom3
2011 DCDIDP: A distributed, collaborative, and data-driven intrusion detection and prevention framework for cloud computing environments
abstract
With the growing popularity of cloud computing, the exploitation of possible vulnerabilities grows at the same pace; the distributed nature of the cloud makes it an attractive target for potential intruders. Despite security issues delaying its adoption, cloud computing has already become an unstopp
Saman Taghavi Zargar, Hassan Takabi, James B. D. Joshi
CollaborateCom3
2011 A secure, constraint-aware role-based access control interoperation framework
abstract
With the growing needs for and the benefits of sharing resources and information among different organizations, an interoperation framework that automatically integrates policies to facilitate such cross-domain sharing in a secure way is becoming increasingly important. To avoid security breaches, such policies must enforce the policy constraints of the individual domains. Such constraints may include temporal constraints that limit the times when the users can access the resources, and separation of duty (SoD) constraints. Existing interoperation solutions do not address such cross-domain temporal access control and SoDs requirements. In this paper, we propose a role-based framework to facilitate secure interoperation among multiple domains by ensuring the enforcement of temporal and SoD constraints of individual domains. To support interoperation, we do not modify the internal policies, as most of the current approaches do. We present experimental results to demonstrate our proposed framework is effective and easily realizable.
Nathalie Baracaldo, Amirreza Masoumzadeh 0001, James B. D. Joshi
NSS3
2011 A trust-based approach against IP-spoofing attacks
abstract
IP-spoofing attacks remain one of the most damaging attacks in which an attacker replaces the original source IP address with a new one. Using the existing attacking tools to launch IP spoofing attacks, an attacker can now easily compromise access routers and not only the end-hosts. In this paper, we propose a trust-based approach using a Bayesian inference model that evaluates the trustworthiness of an access router with regards to forwarding packets without modifying their source IP address. The trust values for the access routers is computed by a judge router that samples all traffic being forwarded by the access routers. The simulation results show that our approach effectively detects malicious access routers. The results also show that our approach has a low impact on the network performance when no attack is present, and that it introduces little overhead traffic.
Jesus M. Gonzalez, Mohd Anwar, James B. D. Joshi
PST3
2011 Trust-Based Approaches to Solve Routing Issues in Ad-Hoc Wireless Networks: A Survey
abstract
Trust is important in Ad-hoc networks because collaboration and cooperation among nodes are critical towards achieving the system's goals, such as routing reliability. In this paper, we seek to provide an understanding of the process of reputation-based trust approaches and related issues as they apply to routing in ad-hoc networks. We discuss the concept and properties of trust. We survey the following issues: the way wireless ad-hoc nodes first assume trust; the evidences that are collected to calculate trust; the calculations that are performed over the evidences; the way the decision is made to determine a trusted node; and how trust is updated to maintain a trusted environment. We provide a comparison of three well-established approaches and discuss some potential attacks against reputation-based trust.
Jesus M. Gonzalez, Mohd Anwar, James B. D. Joshi
TrustCom3
2011 Editorial
Dimitris Gritzalis, James B. D. Joshi
Comput. Secur.2
2011 Guest Editorial SACMAT 2009 and 2010
abstract
No abstract available.
James B. D. Joshi, Barbara Carminati
ACM Trans. Inf. Syst. Secur.1
2010 Message from the general chairs
Karl Aberer, James B. D. Joshi
CollaborateCom2
2010 Preserving structural properties in anonymization of social networks
abstract
A social network is a collection of social entities and the relations among them. Collection and sharing of such network data for analysis raise significant privacy concerns for the involved individuals, especially when human users are involved. To address such privacy concerns, several techniques,
Amirreza Masoumzadeh 0001, James B. D. Joshi
CollaborateCom2
2010 A collaborative approach to facilitate intrusion detection and response against DDoS attacks
abstract
Intrusion detection and response systems (IPSs) for protecting against distributed denial-of-service (DDoS) attacks will beneflit significantly if all the routers within each autonomous system (AS) are capable of detection and response in addition to sampling. However, DDoS detection and response wi
Saman Taghavi Zargar, James B. D. Joshi
CollaborateCom2
2010 Enhanced One-Pass IP Multimedia Subsystem Authentication Protocol for UMTS
abstract
Universal Mobile Telecommunications System (UMTS) can support IP Multimedia services by including the IP Multimedia Subsystem (IMS) as part of its core network. To use IMS services, a user equipment needs to first authenticate itself with the UMTS and then with the IMS. However, these two authentication protocols share many similar operations. Recent research efforts have highlighted this issue and hence researchers have proposed one-pass authentication protocols to reduce the number of such overlapping steps and to address security vulnerabilities in the original IMS protocol. In this paper, we propose an enhanced one-pass authentication protocol that addresses the weaknesses of the two previously proposed one-pass authentication protocols. We also provide comparative analysis of our proposed work with the existing approaches in terms of performance, security and compatibility.
Xuelian Long, James B. D. Joshi
ICC2
2010 StateMiner: an efficient similarity-based approach for optimal mining of role hierarchy
abstract
Recently, there is a growing trend of organizations migrating to RBAC because of the economic benefits that RBAC provides, and the ease of administration. In order to deploy an RBAC system, one requires to first identify a complete set of roles. This process, known as role engineering, has been identified as one of the costliest tasks in migrating to RBAC. Several approaches have been proposed that mostly use data mining techniques to discover roles. However, most of them do not consider the existing roles and try to define everything from scratch, which is not acceptable for organizations that already have an RBAC system in place. In this paper, we formally define the problem of mining role hierarchy with minimal perturbation and present StateMiner, a heuristic solution to find an RBAC state as similar as possible to both the existing state and the optimal state. We present experiments to demonstrate the effectiveness of our approach.
Hassan Takabi, James B. D. Joshi
SACMAT2
2009 A collaborative k-anonymity approach for location privacy in location-based services
abstract
Considering the growth of wireless communication and mobile positioning technologies, location-based services (LBSs) have been generating increasing research interest in recent years. One of the critical issues for the deployment of LBS applications is how to reconcile their quality of service with
Hassan Takabi, James B. D. Joshi, Hassan A. Karimi
CollaborateCom2
2009 LBS (k, T)-anonymity: a spatio-temporal approach to anonymity for location-based service users
abstract
We propose a location-based query anonymization technique, LBS (k, T)-anonymization, that ensures anonymity of user's query in a specific time window against what we call known user attack. We distinguish between our technique and related work on k-anonymity for LBSs by showing that they target different privacy inference attacks. Also, we analyze the inconsistency of the existing predominant approach with the original definition of k-anonymity and its implications on the anonymization. Finally, we present an evaluation framework that assess the applicability and performance of the proposed technique using an evaluation framework.
Amirreza Masoumzadeh 0001, James B. D. Joshi, Hassan A. Karimi
GIS2
2008 RiBAC: Role Interaction Based Access Control Model for Community Computing
Youna Jung, Amirreza Masoumzadeh 0001, James B. D. Joshi, Minkoo Kim
CollaborateCom3
2008 Access Control for Cooperation Systems Based on Group Situation
Minsoo Kim 0001, James B. D. Joshi, Minkoo Kim
CollaborateCom2
2008 Message from the IWSSE 2008 Workshop Organizers
abstract
Presents the introductory welcome message from the conference proceedings.
James B. D. Joshi
COMPSAC2
2008 IWSSE 2008 Workshop Organization
abstract
Provides a listing of current committee members and society officers.
James B. D. Joshi
COMPSAC2
2008 UAQ: a framework for user authorization query processing in RBAC extended with hybrid hierarchy and constraints
abstract
A key issue in RBAC systems is how to efficiently handle the user authorization process. That is, whether or not to grant a user's request to acquire a set of requested permissions or to activate a set of requested roles in a single session. The presence of hybrid hierarchies as well as the cardinality and dynamic separation of duty constraints make the issue more complex. In this paper, we define this issue as the user authorization query problem consisting of a role mapping problem and an activation checking problem. We also propose a set of algorithms to solve the role mapping and the activation checking problems. We show that our model is practical and flexible, and can deal with various cases in presence of the hybrid hierarchy and cardinality/DSoD constraints.
Yue Zhang 0002, James B. D. Joshi
SACMAT2
2008 Formal foundations for hybrid hierarchies in GTRBAC
abstract
A role hierarchy defines permission acquisition and role-activation semantics through role--role relationships. It can be utilized for efficiently and effectively structuring functional roles of an organization having related access-control needs. The focus of this paper is the analysis of hybrid role hierarchies in the context of the generalized temporal role-based access control (GTRBAC) model that allows specification of a comprehensive set of temporal constraints on role, user-role, and role-permission assignments. We introduce the notion of uniquely activable set (UAS) associated with a role hierarchy that indicates the access capabilities of a user resulting from his membership to a role in the hierarchy. Identifying such a role set is essential, while making an authorization decision about whether or not a user should be allowed to activate a particular combination of roles in a single session. We formally show how UAS can be determined for a hybrid hierarchy. Furthermore, within a hybrid hierarchy, various hierarchical relations may be derived between an arbitrary pair of roles. We present a set of inference rules that can be used to generate all the possible derived relations that can be inferred from a specified set of hierarchical relations and show that it is sound and complete . We also present an analysis of hierarchy transformations with respect to role addition, deletion, and partitioning, and show how various cases of these transformations allow the original permission acquisition and role-activation semantics to be managed. The formal results presented here provide a basis for developing efficient security administration and management tools.
James B. D. Joshi, Elisa Bertino, Arif Ghafoor, Yue Zhang 0002
ACM Trans. Inf. Syst. Secur.1
2007 SARBAC07: A Scoped Administration Model for RBAC with Hybrid Hierarchy
abstract
Recently, administration of RBAC systems using a role-based approach has become very appealing because of the benefits that such an approach typically brings. This approach uses RBAC itself to manage RBAC policies so that the administration functions can be decentralized and made more efficient. Existing RBAC administration models, however, fail to deal with RBAC systems with hybrid hierarchy, which has been shown to be necessary to specify fine-grained RBAC policies. In this paper, we propose a Scoped Administration model for RBAC with Hybrid Hierarchy (SARBAC07) by using the notion of an administrative scope that was earlier proposed in the SARBAC model. We show that our model keeps all the advantages of the original model and can deal with more complex situations where hybrid hierarchy is needed.
Yue Zhang 0002, James B. D. Joshi
IAS2
2007 A request-driven secure interoperation framework in loosely-coupled multi-domain environments employing RBAC policies
abstract
Multi-domain environments where distributed multiple organizations interoperate with each other are becoming a reality as witnessed by emerging Internet-based enterprise applications. Ensuring secure interoperation in such multi-domain environments has drawn considerable research works in the past, especially in tightly coupled, federated environments. However, methods applied to such environments are not suitable in emerging loosely-coupled environments where the inter-domain interactions are transient and based on specific requirements within a given context (e.g., time, location), which is typical in web service, P2P and Grid-based applications. In this paper, we propose a request-driven secure interoperation framework to facilitate secure interoperation in loosely-coupled environments where the individual domains employ role-based access control policies. In particular, our proposed framework is driven by the service requirements and dynamically integrates relevant policy components between interacting domains.
Yue Zhang 0002, James B. D. Joshi
CollaborateCom2
2007 CT-RBAC: A Temporal RBAC Model with Conditional Periodic Time
abstract
Many emerging applications show the need for a fine-grained context based access control requirements. The generalized temporal RBAC model has been proposed to capture fine-grained time-based access control requirements using periodic time expression to capture recurring intervals of time. In this paper, we present conditional temporal RBAC (CT-RBAC) model that extends GTRBAC model by extending the periodic time expression. In particular, the extension allows fine-grained extension to capture other logical conditions that restricts the validity of the temporal constraints. CT-RBAC uses a symbolic representation of conditional periodic time that can be used to define a set of conditions to qualify the components of a periodic time expression, using the concurrent transaction logic. Because of the conditional set introduced, CT-RBAC extends the time control dimension to the (condition, time) control plane and the (time, constraint) plane of the GTRBAC framework to the (condition, time, constraint) three-dimensional control space, thus providing more flexibility in the access control model. We analyze conflicts introduced by the constraint set and the complexity of evaluating the conditional set.
Kai Ouyang, James B. D. Joshi
IPCCC2
2006 An Integrated Framework for Trust-Based Access Control for Open Systems
abstract
An important requirement of systems or application domains in emerging open environments is the capability to share information and services with other application domains that have different sets of protection requirements. When a domain needs to allow entities from previously unknown domains to access its resources, mechanisms should be in place to allow negotiating trust and services based on the sharing requirements of the interacting domains. We emphasize that a holistic framework for requirements-driven trust based secure interoperation is needed to facilitate interacting domains to access each other's local resources through access control policy mapping between the domains. In this paper, we present our ongoing work on developing a comprehensive framework for a trust based access control for secure interoperation, which tightly integrates role-based access control and inter-domain policy mapping mechanism with an integrated, game-theory based trust and service negotiation process. The framework being developed aims to address the complex requirements of an environment that represents the convergence of grid, peer-to-peer and mobile environments and workflow and multimedia technologies.
Michael Chuang, Suronapee Phoomvuthisarn, James B. D. Joshi
CollaborateCom3
2006 Supporting authorization query and inter-domain role mapping in presence of hybrid role hierarchy
abstract
The role hierarchy is one of the most distinguished features of an RBAC approach to securing large systems as it facilitates efficient administration of permissions. However, the role hierarchy as defined in the currently standardized RBAC model has limitations in capturing generic policy requirements such as separation of duty, time-based and cardinality constraints. To address such limitations, permission inheritance and activation inheritance semantics have been introduced to define three different types of role hierarchies. In presence of a hybrid hierarchy that allows all the three types of hierarchies to coexist, the overall hierarchy administration problem becomes quite complex. A key problem is to efficiently handle authorization queries to decide whether a user's request to activate a set of roles should be granted. A hybrid hierarchy also makes the problem of mapping a request for a set of permissions to a minimal set of roles difficult. Such a mapping is crucial in multidomain environments where different security domains have to establish and engage in secure interoperation by first mapping their security policies. In this paper, we investigate these two problems and present solutions that are efficient and practical.
Siqing Du, James B. D. Joshi
SACMAT2
2006 Fine-grained role-based delegation in presence of the hybrid role hierarchy
abstract
Delegation of authority is an important process that needs to be captured by any access control model. In role-based access control models, delegation of authority involves delegating roles that a user can assume or the set of permissions that he can acquire, to other users. Several role-based delegation models have been proposed in the literature. However, these models consider delegation in presence of the general hierarchy type. Multiple hierarchy types have been proposed in the context of Generalized Temporal Role-based Access Control (GTRBAC) model, where it has been shown that multiple hierarchy semantics is desirable to express fine-grained access control policies. In this paper, we address role-based delegation schemes in the of hybrid hierarchies and elaborate on fine-grained delegation schemes. In particular, we show that upward delegation, which has been considered as having no practical use, is a desirable feature. Furthermore, we show that accountability must be considered as an important factor during the delegation process. The delegation framework proposed subsumes delegations schemes proposed in earlier role-based delegation models and provide much more fine-grained control of delegation semantics.
James B. D. Joshi, Elisa Bertino
SACMAT1
2005 LoT-RBAC: A Location and Time-Based RBAC Model
Suroop Mohan Chandran, James B. D. Joshi
WISE2
2005 An Analysis of Expressiveness and Design Issues for the Generalized Temporal Role-Based Access Control Model
abstract
The generalized temporal role-based access control (GTRBAC) model provides a comprehensive set of temporal constraint expressions which can facilitate the specification of fine-grained time-based access control policies. However, the issue of the expressiveness and usability of this model has not been previously investigated. In this paper, we present an analysis of the expressiveness of the constructs provided by this model and illustrate that its constraints-set is not minimal. We show that there is a subset of GTRBAC constraints that is sufficient to express all the access constraints that can be expressed using the full set. We also illustrate that a nonminimal GTRBAC constraint set can provide better flexibility and lower complexity of constraint representation. Based on our analysis, a set of design guidelines for the development of GTRBAC-based security administration is presented.
James B. D. Joshi, Elisa Bertino, Arif Ghafoor
IEEE Trans. Dependable Secur. Comput.1
2005 X-GTRBAC: an XML-based policy specification framework and architecture for enterprise-wide access control
abstract
Modern day enterprises exhibit a growing trend toward adoption of enterprise computing services for efficient resource utilization, scalability, and flexibility. These environments are characterized by heterogeneous, distributed computing systems exchanging enormous volumes of time-critical data with varying levels of access control in a dynamic business environment. The enterprises are thus faced with significant challenges as they endeavor to achieve their primary goals, and simultaneously ensure enterprise-wide secure interoperation among the various collaborating entities. Key among these challenges are providing effective mechanism for enforcement of enterprise policy across distributed domains, ensuring secure content-based access to enterprise resources at all user levels, and allowing the specification of temporal and nontemporal context conditions to support fine-grained dynamic access control. In this paper, we investigate these challenges, and present X-GTRBAC, an XML-based GTRBAC policy specification language and its implementation for enforcing enterprise-wide access control. Our specification language is based on the GTRBAC model that incorporates the content- and context-aware dynamic access control requirements of an enterprise. An X-GTRBAC system has been implemented as a Java application. We discuss the salient features of the specification language, and present the software architecture of our system. A comprehensive example is included to discuss and motivate the applicability of the X-GTRBAC framework to a generic enterprise environment. An application level interface for implementing the policy in the X-GTRBAC system is also provided to consolidate the ideas presented in the paper.
Rafae Bhatti, Arif Ghafoor, Elisa Bertino, James B. D. Joshi
ACM Trans. Inf. Syst. Secur.4
2005 X-gtrbac admin: A decentralized administration model for enterprise-wide access control
abstract
The modern enterprise spans several functional units or administrative domains with diverse authorization requirements. Access control policies in an enterprise environment typically express these requirements as authorization constraints. While desirable for access control, constraints can lead to conflicts in the overall policy in a multidomain environment. The administration problem for enterprise-wide access control, therefore, not only includes authorization management for users and resources within a single domain but also conflict resolution among heterogeneous access control policies of multiple domains to allow secure interoperation within the enterprise. This work presents design and implementation of X-GTRBAC Admin, an administration model that aims at enabling administration of role-based access control (RBAC) policies in the presence of constraints with support for conflict resolution in a multidomain environment. A key feature of the model is that it allows decentralization of policy administration tasks through the abstraction of administrative domains, which not only simplifies authorization management, but is also fundamental to the concept of decentralized conflict resolution presented. The paper also illustrates the applicability of the outlined administrative concepts in a realistic enterprise environment using an implementation prototype that facilitates policy administration in large enterprises.
Rafae Bhatti, Basit Shafiq, Elisa Bertino, Arif Ghafoor, James B. D. Joshi
ACM Trans. Inf. Syst. Secur.5
2005 A Generalized Temporal Role-Based Access Control Model
abstract
Role-based access control (RBAC) models have generated a great interest in the security community as a powerful and generalized approach to security management. In many practical scenarios, users may be restricted to assume roles only at predefined time periods. Furthermore, roles may only be invoked on prespecified intervals of time depending upon when certain actions are permitted. To capture such dynamic aspects of a role, a temporal RBAC (TRBAC) model has been recently proposed. However, the TRBAC model addresses the role enabling constraints only. In This work, we propose a generalized temporal role-based access control (GTRBAC) model capable of expressing a wider range of temporal constraints. In particular, the model allows expressing periodic as well as duration constraints on roles, user-role assignments, and role-permission assignments. In an interval, activation of a role can further be restricted as a result of numerous activation constraints including cardinality constraints and maximum active duration constraints. The GTRBAC model extends the syntactic structure of the TRBAC model and its event and trigger expressions subsume those of TRBAC. Furthermore, GTRBAC allows expressing role hierarchies and separation of duty (SoD) constraints for specifying fine-grained temporal semantics.
James B. D. Joshi, Elisa Bertino, Usman Latif, Arif Ghafoor
IEEE Trans. Knowl. Data Eng.1
2005 Secure Interoperation in a Multidomain Environment Employing RBAC Policies
abstract
Multidomain application environments where distributed multiple organizations interoperate with each other are becoming a reality as witnessed by emerging Internet-based enterprise applications. Composition of a global coherent security policy that governs information and resource accesses in such environments is a challenging problem. In this paper, we propose a policy integration framework for merging heterogeneous role-based access control (RBAC) policies of multiple domains into a global access control policy. A key challenge in composition of this policy is the resolution of conflicts that may arise among the RBAC policies of individual domains. We propose an integer programming (IP)-based approach for optimal resolution of such conflicts. The optimality criterion is to maximize interdomain role accesses without exceeding the autonomy losses beyond the acceptable limit.
Basit Shafiq, James B. D. Joshi, Elisa Bertino, Arif Ghafoor
IEEE Trans. Knowl. Data Eng.2
2004 Security for grid-based computing systems issues and challenges
abstract
Grid systems were initially developed for supporting scientific computations. Today, companies, users and researchers are looking at ways to use the Grid approach to commercial uses and for applications in many different areas. Security in grid systems however has not been much addressed and yet is an important prerequisite to really make grid systems usable in a variety of commercial applications.The goal of this panel is to explore relevant security issues, with special emphasis on access control, for grid-based computing systems. The panel will discuss security requirements that are specific to grid-based systems and set these systems apart from conventional distributed systems, and outline directions for future research. Questions addressed by the panel include the following ones:
Elisa Bertino, Bruno Crispo, James B. D. Joshi, Wengliang (Kevin) Du, Ravi S. Sandhu
SACMAT3
2004 X-GTRBAC admin: a decentralized administration model for enterprise wide access control
abstract
Access control in enterprises is a key research area in the realm of Computer Security because of the unique needs of the target enterprise. As the enterprise typically has large user and resource pools, administering the access control based on any framework could in itself be a daunting task. This work presents X-GTRBAC Admin, an administration model that aims at enabling policy administration within a large enterprise. In particular, it simplifies the process of user-to-role and permission-to-role assignments, and thus allows decentralization of the policy administration tasks. Secondly, it also allows for specifying the domain of authority of the system administrators, and hence provides mechanism to distribute the administrative authority over multiple domains within the enterprise. The paper also illustrates the applicability of the administrative concepts presented in our framework for enterprise-wide access control.
Rafae Bhatti, James B. D. Joshi, Elisa Bertino, Arif Ghafoor
SACMAT2
2003 Access Control in Dynamic XML-Based Web-Services with X-RBAC
Rafae Bhatti, James B. D. Joshi, Elisa Bertino, Arif Ghafoor
ICWS2
2003 Dependencies and separation of duty constraints in GTRBAC
abstract
A Generalized Temporal Role Based Access Control (GTRBAC) model that captures an exhaustive set of temporal constraint needs for access control has recently been proposed. GTRBAC's language constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. In this paper, we identify various time-constrained cardinality, control flow dependency and separation of duty constraints (SoDs). Such constraints allow specification of dynamically changing access control requirements that are typical in today's large systems. In addition to allowing specification of time, the constraints introduced here also allow expressing access control policies at a finer granularity. The inclusion of control flow dependency constraints allows defining much stricter dependency requirements that are typical in workflow types of applications.
James B. D. Joshi, Basit Shafiq, Arif Ghafoor, Elisa Bertino
SACMAT1
2002 Hybrid Role Hierarchy for Generalized Temporal Role Based Access Control Model
abstract
A generalized temporal role based access control (GTRBAC) model that captures an exhaustive set of temporal constraint needs for access control has been proposed. GTRBAC's language constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. We present the notion of different types of role hierarchies based on the permission-inheritance and role activation semantics. In particular, we look at how new hierarchical relations between a pair of roles that are not directly related can be derived through other well-defined hierarchically related roles. When the different hierarchy types coexist in a role hierarchy, inferring such derived hierarchical relations between a pair of roles can be complex. The results presented provide a basis for formally analyzing the derived inheritance and activation semantics between every pair of roles in a hierarchy.
James B. D. Joshi, Elisa Bertino, Arif Ghafoor
COMPSAC1
2002 Temporal hierarchies and inheritance semantics for GTRBAC
abstract
A Generalized Temporal Role Based Access Control (GTRBAC) model that allows specification of a comprehensive set of temporal constraint for access control has recently been proposed. The model constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. However, Temporal constraints on role enablings and role activations can have various implications on a role hierarchy. In this paper, we present an analysis of the effects of GTRBAC temporal constraints on a role hierarchy and introduce various kinds of temporal hierarchies. In particular, we show that there are certain distinctions that need to be made in permission inheritance and role activation semantics in order to capture all the effects of GTRBAC constraints such as role enablings and role activations on a role hierarchy.
James B. D. Joshi, Elisa Bertino, Arif Ghafoor
SACMAT1
2002 A model for secure multimedia document database system in a distributed environment
abstract
The Internet provides a universal platform for large-scale distribution of information and supports inter-organizational services, system integration, and collaboration. Use of multimedia documents for dissemination and sharing of massive amounts of information is becoming a common practice for Internet-based applications and enterprises. With the rapid proliferation of multimedia data management technologies over the Internet, there is growing concern about security and privacy of information. Composing multimedia documents in a distributed heterogeneous environment involves integrating media objects from multiple security domains that may employ different access control policies for media objects. In this paper, we present a security model for distributed document management system that allows creation, storage, indexing, and presentation of secure multimedia documents. The model is based on a time augmented Petri-net and provides a flexible, multilevel access control mechanism that allows clearance-based access to different levels of information in a document. In addition, the model provides detailed multimedia synchronization requirements including deterministic and non-deterministic temporal relations and incomplete timing information among media objects.
James B. D. Joshi, Zhaohui Kevin Li, Husni Fahmi, Basit Shafiq, Arif Ghafoor
IEEE Trans. Multim.1
1998 Evaluation of Filtering Mechanisms for MPEG Video Communications
abstract
In this paper, we evaluate two video filtering mechanisms for MPEG-1 video, namely low-pass filtering and selective frame dropping. The evaluation provides tradeoffs between the reduction achieved in bandwidth requirements and the perceptual quality of the video sequences delivered to the client. Extensive experiments revealed that these filtering mechanisms result in a significant reduction in bandwidth requirements while maintaining acceptable perceptual quality.
Sahra Sedigh Sarvestani, James B. D. Joshi, Ahmed R. Bashandy, Arif Ghafoor
SRDS2