VLDB 2026 Research / reviewers in the wild / expert
Indrajit Ray
dblp:r/IndrajitRay
· DBLP profile ↗
98ranked-venue papers
15as first author
14since 2021 · last 2026
0000-0002-3612-7738ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 68 · 13 first-author · 11 since 2021Databases, data management, data science and information retrieval · 12 · 1 first-authorArtificial intelligence and machine learning · 5 · 1 first-authorSystems, architecture and hardware · 3Software engineering, systems software and programming languages · 3 · 2 since 2021Computer networks · 2Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "Room for More?": Behavior Adaptive IoT Device-type Fingerprinting
Maxwel Bar-on, Bezawada Bruhadeshwar, Indrakshi Ray, Indrajit Ray |
DBSec | 4 |
| 2025 | Proof of Compliance (PoC): A Consensus Mechanism to Verify the Compliance with Informed Consent Policy in HealthcareabstractHealthcare industries are subject to various laws and regulatory oversight, just like other industries, such as pharmaceuticals, telecommunications, education, and financial services. Compliance with these regulations is essential for the organization's operation and growth. To help organizations detect early non-compliance issues, this paper proposes a consensus mechanism, Proof of Compliance (PoC), where a set of distributed, decentralized, and independent auditor nodes perform audit operations to determine the compliance status of any logical operations or accesses that have already been approved, granted, or executed in the system. The Proof of Compliance consensus mechanism helps organizations minimize compliance challenges. Organizations can consider PoC outputs to take further actions to reduce non-compliance cases and avoid compliance issues and business losses. The PoC reports do not support final regulatory compliance certification. However, it is possible if one or more multiple audit nodes are deployed and maintained in the consensus mechanism by the corresponding regulatory, government, or compliance authority. Md Al Amin, Hemanth Tummala, Rushabh Shah, Indrajit Ray |
CODASPY | 4 |
| 2025 | Jibber-Jabber!: Encoding the (Un-)Natural Language of Network Devices and Applications
Maxwel Bar-on, Kiley Krosky, Federico Larrieu, Bezawada Bruhadeshwar, Indrakshi Ray, Indrajit Ray |
DBSec | 6 |
| 2025 | "Bring your own device!": Adaptive IoT Device-type Fingerprinting using Automatic Behavior Extraction [Work In Progress Paper]abstractInternet-of-Things (IoT) is playing a key role in modern society by offering enhanced functionalities and services. As IoT devices may introduce new security risks to the network, network administrators profile the behavior of IoT devices using device fingerprinting. Device fingerprinting typically involves training a machine learning model using the network behavioral data of existing devices. If a new device is added, the network becomes vulnerable to attacks until the time that the machine learning model is trained and updated to integrate the new device. Furthermore, if many devices are regularly added to the network, the cost of adapting the machine learning model can be significant. To address the challenges of security and scalability in fingerprinting, we create a collection of observed behaviors of IoT devices from existing devices and use this collection to construct a fingerprint for a new device. In our approach, we design a bi-component neural network architecture consisting of a transformer-based behavior-extractor (BE) and a fingerprinting interpreter.We perform a one-time training of the BE to extract behaviors from known devices. We use the generated BE for (a) fingerprinting existing devices and (b) adapting the existing fingerprinting model to new device data. In our experiments on 22 diverse IoT devices, we show that our model can identify newly introduced devices as well as known devices with a high identification rate. Our approach improves the time to adapt a model by a factor of 78.3× with no loss of accuracy, achieving recall over 98%. Maxwel Bar-on, Katherine Patterson, Bezawada Bruhadeshwar, Indrakshi Ray, Indrajit Ray |
SACMAT | 5 |
| 2025 | SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity HypergraphsabstractGraph-based frameworks are often used in network hardening to help a cyber defender understand how a network can be attacked and how the best defenses can be deployed. However, incorporating network connectivity parameters in the attack graph, reasoning about the attack graph when we do not have access to complete information, providing system administrator suggestions in an understandable format, and allowing them to do what-if analysis on various scenarios and attacker motives is still missing. We fill this gap by presenting SPEAR, a formal framework with tool support for security posture evaluation and analysis that keeps human-in-the-loop. SPEAR uses the causal formalism of AI planning to model vulnerabilities and configurations in a networked system. It automatically converts network configurations and vulnerability descriptions into planning models expressed in the Planning Domain Definition Language (PDDL). SPEAR identifies a set of diverse security hardening strategies that can be presented in a manner understandable to the domain expert. These allow the administrator to explore the network hardening solution space in a systematic fashion and help evaluate the impact and compare the different solutions. Rakesh Podder, Turgay Caglar, Shadaab Kawnain Bashir, Sarath Sreedharan, Indrajit Ray, Indrakshi Ray |
SACMAT | 5 |
| 2025 | Did You Break the Glass Properly? A Policy Compliance Framework for Protected Health Information (PHI) Emergency Access
Md Al Amin, Rushabh Shah, Hemanth Tummala, Indrajit Ray |
SECRYPT | 4 |
| 2025 | VKG2AG : Generating Automated Knowledge-Enriched Attack Graph (AG) from Vulnerability Knowledge Graph (VKG)
Md. Rakibul Hasan Talukder, Rakesh Podder, Indrajit Ray |
SECRYPT | 3 |
| 2025 | Correctness and security analysis of the protection in transit (PIT) protocol
Rakesh Podder, Mahmoud Abdelgawad, Indrakshi Ray, Indrajit Ray, Madhan B. Santharam, Stefano Righi |
J. Syst. Softw. | 4 |
| 2024 | The PIT-Cerberus Framework: Preventing Device Tampering During TransitabstractWhen a computing device, such as a server, workstation, laptop, tablet, etc. is shipped from one site to another (for example, from a vendor to a customer or from one branch location of an organization to another) it can potentially be subjected to unauthorized firmware modifications. The industry has sought to partially address this issue by focusing on securing the boot process. Secure boot provides attestation methods by a hardware root-of-trust to confirm the integrity of the device’s BIOS/UEFI firmware. However, once a device boots up, it is relatively easy for a malicious adversary to tamper with the firmware. In this paper, we address this problem by preventing a secure boot unless done by an authorized user. We extend a hardware root of trust (HRoT) processor’s ability to perform secure attestation by implementing a new functionality to securely lock and unlock the BIOS/UEFI or the BMC (Baseboard Management Controller) and implementing an authentication mechanism in the HRoT for determining authorized users. This ensures that the secure boot process won’t commence unless authorized appropriately and provides a robust mechanism for securing the device’s firmware during transit. The proposed PIT-Cerberus framework (PIT = Protection In Transit) leverages strong cryptographic techniques and has been implemented within a trusted microcontroller. We have contributed the PIT-Cerberus framework’s libraries to Project Cerberus, an open-source project that offers a security platform for server hardware. Rakesh Podder, Jack Sovereign, Indrajit Ray, Madhan B. Santharam, Stefano Righi |
QRS | 3 |
| 2024 | Balancing Patient Privacy and Health Data Security: The Role of Compliance in Protected Health Information (PHI) Sharing
Md Al Amin, Hemanth Tummala, Rushabh Shah, Indrajit Ray |
SECRYPT | 4 |
| 2023 | Worst Attack Vulnerability and Fortification for IoT Security Management: An approach and An Illustration for Smart Home IoTabstractIn the domain of IoT security management, we consider attack vulnerabilities and how to identify those so as to prevent attacks from spreading. More specifically, inspired by this problem for Smart Home Internet of Things (SHIoT), we take a complex network framework in which an IoT system attack graph can be cast. We then address the problem of assessing the worst vulnerability, that is the one that has the potential to cause maximum damage, in the SHIoT. Due to the non-additive nature of an attack path’s attack probability, we show how the problem can be modeled so that a shortest path-based algorithm approach can be used to determine the worst vulnerability. We then illustrate an approach to iteratively fortify the environment to reduce impact from vulnerability. Finally, we show an approach to use Common Vulnerability Scoring System (CVSS) to determine attack probabilities on arcs in the attack graph and present analysis on representative attack graphs for small to large attack graphs. Fathima James, Indrajit Ray, Deep Medhi |
NOMS | 2 |
| 2023 | SAFE-PASS: Stewardship, Advocacy, Fairness and Empowerment in Privacy, Accountability, Security, and Safety for Vulnerable GroupsabstractOur vision is to achieve societally responsible secure and trustworthy cyberspace that puts algorithmic and technological checks and balances on the indiscriminate sharing and analysis of data. We achieve this vision in a holistic manner by framing research directions with four major considerations: (i) Expanding knowledge and understanding of security and privacy perceptions and expectations in vulnerable groups, which significantly contribute to their unwillingness to share data, and use that knowledge to drive research in (a) mitigating missing/imbalanced data problems, (b) understanding and modeling security and privacy risks of data sharing, and (c) modeling utility of data sharing. (ii) Developing a risk-adaptive, policy model capable of capturing and articulating security and privacy expectations of users that are relevant in a particular context and develops associated technology to ensure provenance and accountability. (iii) Developing robust AI/ML algorithms that are transparent and explainable with respect to fairness and bias to reduce/eliminate discrimination, misuse, privacy violations, or other cyber-crimes. (iv) Developing models and techniques for a nuanced, contextually adaptive, and graded privacy paradigm that allows trade-offs between privacy and utility. Towards this, in this paper we present the SAFE-PASS framework to provide Stewardship, Advocacy, Fairness and Empowerment in Privacy, Accountability, Security, and Safety for Vulnerable Groups. Indrajit Ray, Bhavani Thuraisingham, Jaideep Vaidya, Sharad Mehrotra, Vijayalakshmi Atluri, Indrakshi Ray, Murat Kantarcioglu, Ramesh Raskar, Babak Salimi, Steven J. Simske, Nalini Venkatasubramanian, Vivek K. Singh 0001 |
SACMAT | 1 |
| 2023 | Informed Consent as Patient Driven Policy for Clinical Diagnosis and Treatment: A Smart Contract Based Approach
Md Al Amin, Amani Altarawneh, Indrajit Ray |
SECRYPT | 3 |
| 2022 | Protecting Cyber-Physical System Testbeds from Red-Teaming/Blue-Teaming Experiments Gone Awry
Md. Rakibul Hasan Talukder, Md Al Amin, Indrajit Ray |
ISPEC | 3 |
| 2020 | Synthesizing DNA molecules with identity-based digital signatures to prevent malicious tampering and enabling source attributionabstractDNA molecules are increasingly being synthesized in the laboratory. A major concern in this domain is that a malicious actor can potentially tweak a benevolent synthesized DNA molecule and create a DNA molecule with harmful properties ( Biodefense in the Age of Synthetic Biology ( 2018 ) The National Academies Press). To detect if a synthesized DNA molecule has been modified from the original version created in the laboratory, the authors in (In Proceedings of the New Security Paradigms Workshop ( 2018 ) ACM) proposed a digital signature protocol for creating a signed DNA molecule. However, several challenges arise in more complex molecules because of various forms of DNA mutations as well as size restrictions of the molecule that impact its properties. The current work extends (In Proceedings of the New Security Paradigms Workshop ( 2018 ) ACM) in several directions to address these problems. A second concern with synthesized DNA is that it is an intellectual property. In order to allow its use by third parties, an annotated document of the molecule needs to be distributed. However, since the molecule and document are two different entities, one being a physical product and the other being a digital one, ensuring that both are distributed correctly together without tampering is challenging. This work also addresess this problem by transforming the document into a DNA molecule and embedding it within the original molecule together with the signature. Diptendu Mohan Kar, Indrajit Ray, Jenna Gallegos, Jean Peccoud, Indrakshi Ray |
J. Comput. Secur. | 2 |
| 2020 | TruckSTM: Runtime Realization of Operational State Transitions for Medium and Heavy Duty VehiclesabstractEmbedded computing devices play an integral role in the mechanical operations of modern-day vehicles. These devices exchange information containing critical vehicle parameters that reflect the current state of operations. Such information can be captured for various purposes, such as diagnostics, fleet management, and analytics. Although monitoring individual parameters can be useful for some applications, monitoring distinct combinations of parameters can reveal more complex and higher-level states that may give useful information. Existing monitoring systems either lack user configurability and control or present simple user interfaces that make it difficult to monitor and collate different parameters to observe high-level vehicle states. In this work, we present TruckSTM, a novel application that realizes user-defined states from messages seen in the embedded networks of medium and heavy duty vehicles and displays state transitions on an interactive user interface. We begin by symbolically formulating some of the in-vehicle networking concepts and formally defining the concept of operational states and state transitions. We then elaborate on the operations performed by TruckSTM in mapping network-obtained vehicle parameters to states that can be defined in standard JSON format. Finally, we evaluate TruckSTM’s asymptotic performance and present the results for the worst-case scenario and demonstrate that in a real world scenario such high level state visualization constraints of an operational truck. Subhojeet Mukherjee, Jeffrey C. Van Etten, Namburi Rani Samyukta, Jacob Walker, Indrakshi Ray, Indrajit Ray |
ACM Trans. Cyber Phys. Syst. | 6 |
| 2019 | AGBuilder: An AI Tool for Automated Attack Graph Building, Analysis, and Refinement
Bezawada Bruhadeshwar, Indrajit Ray, Kushagra Tiwary |
DBSec | 2 |
| 2019 | That's My DNA: Detecting Malicious Tampering of Synthesized DNA
Diptendu Mohan Kar, Indrajit Ray |
DBSec | 2 |
| 2018 | Digital Signatures to Ensure the Authenticity and Integrity of Synthetic DNA MoleculesabstractDNA synthesis has become increasingly common, and many synthetic DNA molecules are licensed intellectual property (IP). DNA samples are shared between academic labs, ordered from DNA synthesis companies and manipulated for a variety of different purposes, mostly to study their properties and improve upon them. However, it is not uncommon for a sample to change hands many times with very little accompanying information and no proof of origin. This poses significant challenges to the original inventor of a DNA molecule, trying to protect her IP rights. More importantly, following the anthrax attacks of 2001, there is an increased urgency to employ microbial forensic technologies to trace and track agent inventories. However, attribution of physical samples is next to impossible with existing technologies. In this paper, we describe our efforts to solve this problem by embedding digital signatures in DNA molecules synthesized in the laboratory. We encounter several challenges that we do not face in the digital world. These challenges arise primarily from the fact that changes to a physical DNA molecule can affect its properties, random mutations can accumulate in DNA samples over time, DNA sequencers can sequence (read) DNA erroneously and DNA sequencing is still relatively expensive (which means that laboratories would prefer not to read and re-read their DNA samples to get error-free sequences). We address these challenges and present a digital signature technology that can be applied to synthetic DNA molecules in living cells. Diptendu Mohan Kar, Indrajit Ray, Jenna Gallegos, Jean Peccoud |
NSPW | 2 |
| 2018 | Privacy Preserving Probabilistic Record Linkage Without Trusted Third PartyabstractFor the purpose of research, organizations often need to share and link data belonging to a single individual while protecting her privacy. This problem, referred to as privacy preserving record linkage (PPRL), has been investigated by researchers. Most PPRL works focus on deterministic linkages where the identifying attributes of two records must be equal in order to declare them to belong to the same individual. Moreover, most of these methods require the active participation of a trusted third party (TTP). If this TTP is compromised, it makes the data from all participating parties vulnerable to information leakage. The proposed work improves upon the existing methods in two ways. First, we propose a protocol which does not require two records to have an exact match on identifying attributes in order to be declared as belonging to the same individual. Second, we investigate probabilistic PPRL in the two-party setting without resorting to any TTP. We use Bloom filters for probabilistic matching and Yao's garbled circuit to perform the computation needed for the matching on encrypted data. To alleviate the computation and communication overhead of Yao's protocol, we leverage data blocking methods and optimize the computation. We provide a security proof of our method and experimentally evaluate the performance gained on large benchmark datasets. Ibrahim Lazrig, Toan Ong, Indrajit Ray, Indrakshi Ray, Xiaoqian Jiang, Jaideep Vaidya |
PST | 3 |
| 2018 | On Sybil Classification in Online Social Networks Using Only Structural FeaturesabstractSybil attack is a problem that seriously affects Online Social Networks (OSNs). These attacks are made possible by the openness of OSN platforms that allows an attacker to create multiple fake accounts, called Sybils, which are then used to compromise the underlining trust pinnings of the OSN. Early Sybil account detection mechanisms involved classification of users into benign and malicious based on various attributes collected from the user profiles. One challenge affecting these classification methods is that user attributes can often be in-complete or inaccurate. In addition, these classification methods can be evaded by sophisticated attackers. More importantly, user profiles can often reveal sensitive user information that can potentially be misused causing privacy violation. In this work, we propose a Sybil detection method that is based on the classification of users into malicious and benign based on the inherent topology or structure of the underlining OSN graph. We propose a new set of structural features for a graph. Using this new feature set, we perform several experiments on both synthetic as well as real-world OSN data. Our results show that the proposed detection method is very effective in correctly classifying Sybil accounts without running the risk of being evaded by a sophisticated attacker and without compromising privacy of users. Dieudonne Mulamba, Indrajit Ray, Indrakshi Ray |
PST | 2 |
| 2018 | Independent Key Distribution Protocols for Broadcast AuthenticationabstractBroadcast authentication is an important problem in several network settings such as wireless sensor networks and ad-hoc networks. We focus on the problem of independent key distribution protocols, which use efficient symmetric key signatures in distributed systems to permit (local) broadcast authentication. We focus on five types of communication graphs: (1) star, (2) acyclic, (3) planar, (4) complete bipartite, and (5) fully connected graphs. A star graph is the simplest network topology where a central node is transmitting authenticated broadcast messages to several satellite nodes. For star graphs, we show that as n, the number of satellite nodes in the star network, tends to infinity, it suffices to maintain logn+1/2loglogn + 1 keys at the center node, but logn+1/2loglogn keys do not suffice. We establish that this is the optimal lower bound on the number of keys for a star graph. Building on this result, we describe storage efficient key distribution for acyclic, planar, and complete bipartite graphs, when compared to existing key distribution schemes. We extend our scheme for fully connected graphs and show that it is sufficient to store O(c log2 N) keys per node where c<1. We perform a detailed analysis of collusion resistance of our protocols and show the trade-offs against internal and external attacks depending on the size of storage. Finally, we demonstrate the practical applicability of our protocols for wireless sensor networks. Bezawada Bruhadeshwar, Sandeep S. Kulkarni, Indrajit Ray, Indrakshi Ray, Rui Li 0020 |
SACMAT | 3 |
| 2018 | On the design and analysis of protocols for Personal Health Record storage on Personal Data Server devices
Kirill Belyaev, Wuliang Sun, Indrakshi Ray, Indrajit Ray |
Future Gener. Comput. Syst. | 4 |
| 2018 | Substring search over encrypted dataabstractWe propose a general solution to the problem of efficient substring search over encrypted data. The solution enhances existing “keyword” searchable encryption schemes by allowing searching for any part of encrypted keywords without requiring one to store all possible combinations of substrings from a given dictionary. The proposed technique is based on the idea of letter orthogonalization that allows testing of string membership by performing efficient inner products. We first propose SED-1, the base protocol for substring search. We then identify some attacks on SED-1 that demonstrate the complexity of the substring search problem under different threat scenarios. This leads us to propose our second and main protocol SED-2. The protocol is also efficient in that the search complexity is linear in the size of the keyword dictionary. We run several experiments on a sizeable real world dataset to evaluate the performance of our protocol. Tarik Moataz, Indrajit Ray, Indrakshi Ray, Abdullatif Shikfa, Frédéric Cuppens, Nora Cuppens |
J. Comput. Secur. | 2 |
| 2017 | POSTER: PriReMat: A Distributed Tool for Privacy Preserving Record Linking in HealthcareabstractMedical institutions must comply with various federal and state policies when they share sensitive medical data with others. Traditionally, such sharing is performed by sanitizing the identifying information from individual records. However, such sanitization removes the ability to later link the records belonging to the same patient across multiple institutions which is essential for medical cohort discovery. Currently, human honest brokers assume stewardship of non sanitized data and manually facilitate such cohort discovery. However, this is slow and prone to error, not to mention that any compromise of the honest broker breaks the system. In this work, we describe PriReMat, a toolset that we have developed for privacy preserving record linkage. The underlying protocol is based on strong security primitives that we had presented earlier. This work describes the distributed implementation over untrusted machines and networks. Diptendu Mohan Kar, Ibrahim Lazrig, Indrajit Ray, Indrakshi Ray |
CCS | 3 |
| 2017 | POSTER: PenJ1939: An Interactive Framework for Design and Dissemination of Exploits for Commercial VehiclesabstractVehicle security has been receiving a lot of attention from both the black hat and white hat community of late. Research in this area has already led to the fabrication of different attacks, of which some have been shown to have potentially grave consequences. Vehicle vendors and original equipment manufacturers (OEM)s are thus presented with the additional responsibility of ensuring in-vehicular communication level security. In this poster paper, we present a framework, which allows any individual to write, test, and store exploit scripts which could then be run by any interested party on in-vehicular networks of commercial vehicles like trucks and buses. Subhojeet Mukherjee, Noah Cain, Jacob Walker, Indrajit Ray, Indrakshi Ray |
CCS | 5 |
| 2017 | Resilient Reference Monitor for Distributed Access Control via Moving Target Defense
Dieudonne Mulamba, Indrajit Ray |
DBSec | 2 |
| 2016 | To Fear or Not to Fear That is the Question: Code Characteristics of a Vulnerable Functionwith an Existing ExploitabstractNot all vulnerabilities are equal. Some recent studies have shown that only a small fraction of vulnerabilities that have been reported has actually been exploited. Since finding and addressing potential vulnerabilities in a program can take considerable time and effort, recently effort has been made to identify code that is more likely to be vulnerable. This paper tries to identify the attributes of the code containing a vulnerability that makes the code more likely to be exploited. We examine 183 vulnerabilities from the National Vulnerability Database for Linux Kernel and Apache HTTP server. These include eighty-two vulnerabilities that have been found to have an exploit according to the Exploit Database. We characterize the vulnerable functions that have no exploit and the ones that have an exploit using eight metrics. The results show that the difference between a vulnerability that has no exploit and the one that has an exploit can potentially be characterized using the chosen software metrics. However, predicting exploitation of vulnerabilities is more complex than predicting just the presence of vulnerabilities and further research is needed using metrics that consider security domain knowledge for enhancing the predictability of vulnerability exploits. Awad A. Younis, Yashwant K. Malaiya, Charles W. Anderson, Indrajit Ray |
CODASPY | 4 |
| 2016 | Privacy Preserving Probabilistic Record Linkage Using Locality Sensitive Hashes
Ibrahim Lazrig, Toan Ong, Indrajit Ray, Indrakshi Ray, Michael G. Kahn |
DBSec | 3 |
| 2016 | SybilRadar: A Graph-Structure Based Framework for Sybil Detection in On-line Social Networks
Dieudonne Mulamba, Indrajit Ray, Indrakshi Ray |
SEC | 2 |
| 2016 | Evaluating CVSS Base Score Using Vulnerability Rewards Programs
Awad A. Younis, Yashwant K. Malaiya, Indrajit Ray |
SEC | 3 |
| 2016 | Assessing vulnerability exploitability risk using software properties
Awad A. Younis, Yashwant K. Malaiya, Indrajit Ray |
Softw. Qual. J. | 3 |
| 2015 | CCSW 2015: The 7th ACM Cloud Computing Security WorkshopabstractNotwithstanding the latest buzzwords (grid, cloud, utility computing, SaaS, etc.), large-scale computing and cloud-like deployment are the fastest growing computing infrastructures today. How exactly they will look like tomorrow is still for the markets to decide, yet one thing has already been identified: clouds have new, untested deployment, associated adversarial models and vulnerabilities and hence a very different threat landscape. It is essential that our community becomes involved in shaping the future security of cloud computing. The CCSW workshop aims to bring together researchers and practitioners in all security and privacy aspects of cloud-centric and outsourced computing. Florian Kerschbaum, Cristina Nita-Rotaru, Indrajit Ray |
CCS | 3 |
| 2015 | POSTER: PsychoRithm: A Framework for Studying How Human Traits Affect User Response to Security SituationsabstractUser studies to investigate which human traits affect a user's response to cyber security related situations are typically conducted via self-reported surveys. However, it has been observed that factors such as peer perception, socially desirable responding, and responder bias etc. frequently impact the results, which then do not necessarily reflect the actual behavior of the user when subjected to real world security incidents. To mitigate such biases, we developed PsychoRithm - a software system that presents different real-world security scenarios for the subjects and records their real-time reactions to these scenarios. This paper describes the architecture of PsychoRithm, the design choices we had to make, and the challenges we faced in the design process. Subhojeet Mukherjee, Sachini S. Weerawardhana, Chancey Dunn, Indrajit Ray, Adele E. Howe |
CCS | 4 |
| 2015 | DEMO: Action Recommendation for Cyber ResilienceabstractWe demonstrate an unifying graph-based model for representing the infrastructure, behavior and missions of an enterprise. We introduce an algorithm for recommending resilience establishing actions based on dynamic updates to the models and show its effectiveness both through software simulation as well as live demonstration inside a cloud testbed. Our demonstrate will illustrate the effectiveness of the algorithm for preserving latency based quality of service (QoS). Luke Rodriguez, Darren S. Curtis, Sutanay Choudhury, Kiri Oler, Peter Nordquist, Indrajit Ray |
CCS | 7 |
| 2015 | Privacy Preserving Record Matching Using Automated Semi-trusted Broker
Ibrahim Lazrig, Tarik Moataz, Indrajit Ray, Indrakshi Ray, Toan Ong, Michael G. Kahn, Frédéric Cuppens, Nora Cuppens |
DBSec | 3 |
| 2015 | Substring Position Search over Encrypted Cloud Data Using Tree-Based IndexabstractExisting Searchable Encryption (SE) solutions are able to handle simple boolean search queries, such as single or multi-keyword queries, but cannot handle substring search queries over encrypted data that also involves identifying the position of the substring within the document. These types of queries are relevant in areas such as searching DNA data. In this paper, we propose a tree-based Substring Position Searchable Symmetric Encryption (SSP-SSE) to overcome the existing gap. Our solution efficiently finds occurrences of a substrings over encrypted cloud data. We formally define the leakage functions and security properties of SSP-SSE. Then, we prove that the proposed scheme is secure against chosen-keyword attacks that involve an adaptive adversary. Our analysis demonstrates that SSP-SSE introduces very low overhead on computation and storage. Mikhail Strizhov, Indrajit Ray |
IC2E | 2 |
| 2014 | ELITE: zEro Links Identity managemenT systEm
Tarik Moataz, Nora Cuppens, Frédéric Cuppens, Indrajit Ray, Indrakshi Ray |
DBSec | 4 |
| 2014 | Privacy-Preserving Multiple Keyword Search on Outsourced Data in the Clouds
Tarik Moataz, Benjamin Justus, Indrakshi Ray, Nora Cuppens, Frédéric Cuppens, Indrajit Ray |
DBSec | 6 |
| 2014 | Multi-keyword Similarity Search over Encrypted Cloud Data
Mikhail Strizhov, Indrajit Ray |
SEC | 2 |
| 2013 | Accepting the inevitable: factoring the user into home computer securityabstractHome computer users present unique challenges to computer security. A user's actions frequently affect security without the user understanding how. Moreover, whereas some home users are quite adept at protecting their machines from security threats, a vast majority are not. Current generation security tools, unfortunately, do not tailor security to the home user's needs and actions. In this work, we propose Personalized Attack Graphs (PAG) as a formal technique to model the security risks for the home computer informed by a profile of the user attributes such as preferences, threat perceptions and activities. A PAG also models the interplay between user activities and preferences, attacker strategies, and system activities within the system risk model. We develop a formal model of a user profile to personalize a single, monolithic PAG to different users, and show how to use the user profile to predict user actions. Malgorzata Urbanska, Mark Roberts, Indrajit Ray, Adele E. Howe, Zinta S. Byrne |
CODASPY | 3 |
| 2013 | Personal health record storage on privacy preserving green cloudsabstractWith digitization there is a plethora of personal information, such as, health records and personal artifacts, that are stored on the data servers provided by the Internet companies. Such a solution is resource-intensive as the servers should be up and running. Moreover, the users no longer have com Kirill Belyaev, Indrakshi Ray, Indrajit Ray, Gary Luckasen |
CollaborateCom | 3 |
| 2013 | A Model for Trust-Based Access Control and Delegation in Mobile Clouds
Indrajit Ray, Dieudonne Mulamba, Indrakshi Ray, Keesook J. Han |
DBSec | 1 |
| 2013 | Hypervisor Event Logs as a Source of Consistent Virtual Machine Evidence for Forensic Cloud Investigations
Sean S. E. Thorpe, Indrajit Ray, Tyrone Grandison, Abbie Barbir, Robert B. France |
DBSec | 2 |
| 2013 | Towards a network-of-networks framework for cyber securityabstractNetwork-of-networks (NoN) is a graph-theoretic model of interdependent networks that have distinct dynamics at each network (layer). By adding special edges to represent relationships between nodes in different layers, NoN provides a unified mechanism to study interdependent systems intertwined in a complex relationship. While NoN based models have been proposed for cyber-physical systems, in this position paper we build towards a three-layered NoN model for an enterprise cyber system. Each layer captures a different facet of a cyber system. We present in-depth discussion for four major graph-theoretic applications to demonstrate how the three-layered NoN model can be leveraged for continuous system monitoring and mission assurance. A longer version of this paper can be accessed from arXiv [1]. Mahantesh Halappanavar, Sutanay Choudhury, Emilie Hogan, Peter Hui, John R. Johnson, Indrajit Ray, Lawrence B. Holder |
ISI | 6 |
| 2013 | Towards a Forensic-Based Service Oriented Architecture Framework for Auditing of Cloud LogsabstractCloud computing log digital investigations relate to the investigation of a potential crime using the digital forensic evidence from a virtual machine (VM) host operating system using the hypervisor event logs. In cloud digital log forensics, work on the forensic reconstruction of evidence on VM hosts system is required, but with the heterogeneous complexity involved with an enterprise's private cloud not to mention public cloud distributed environments, a possible Web Services-centric approach may be required for such log supported investigations. A data cloud log forensics service oriented architecture (SOA) audit framework for this type of forensic examination needs to allow for the reconstruction of transactions spanning multiple VM hosts, platforms and applications. This paper explores the requirements of a cloud log forensics SOA framework for performing effective digital investigation examinations in these abstract web services environments. This framework will be necessary in order to develop investigative and forensic auditing tools and techniques for use in cloud based log-centric SOAs. Sean S. E. Thorpe, Tyrone Grandison, Arnett Campbell, Janet Williams, Khalilah Burrell, Indrajit Ray |
SERVICES | 6 |
| 2012 | The Psychology of Security for the Home Computer UserabstractThe home computer user is often said to be the weakest link in computer security. They do not always follow security advice, and they take actions, as in phishing, that compromise themselves. In general, we do not understand why users do not always behave safely, which would seem to be in their best interest. This paper reviews the literature of surveys and studies of factors that influence security decisions for home computer users. We organize the review in four sections: understanding of threats, perceptions of risky behavior, efforts to avoid security breaches and attitudes to security interventions. We find that these studies reveal a lot of reasons why current security measures may not match the needs or abilities of home computer users and suggest future work needed to inform how security is delivered to this user group. Adele E. Howe, Indrajit Ray, Mark Roberts, Malgorzata Urbanska, Zinta S. Byrne |
IEEE Symposium on Security and Privacy | 2 |
| 2012 | Dynamic Security Risk Management Using Bayesian Attack GraphsabstractSecurity risk assessment and mitigation are two vital processes that need to be executed to maintain a productive IT infrastructure. On one hand, models such as attack graphs and attack trees have been proposed to assess the cause-consequence relationships between various network states, while on the other hand, different decision problems have been explored to identify the minimum-cost hardening measures. However, these risk models do not help reason about the causal dependencies between network states. Further, the optimization formulations ignore the issue of resource availability while analyzing a risk model. In this paper, we propose a risk management framework using Bayesian networks that enable a system administrator to quantify the chances of network compromise at various levels. We show how to use this information to develop a security mitigation and management plan. In contrast to other similar models, this risk model lends itself to dynamic analysis during the deployed phase of the network. A multiobjective optimization platform provides the administrator with all trade-off information required to make decisions in a resource constrained environment. Nayot Poolsappasit, Rinku Dewri, Indrajit Ray |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2011 | Formal Parameterization of Log Synchronization Events within a Distributed Forensic Compute Cloud Database Environment
Sean S. E. Thorpe, Indrakshi Ray, Indrajit Ray, Tyrone Grandison, Abbie Barbir, Robert B. France |
ICDF2C | 3 |
| 2011 | Exploring privacy versus data quality trade-offs in anonymization techniques using multi-objective optimizationabstractData anonymization techniques have received extensive attention in the privacy research community over the past several years. Various models of privacy preservation have been proposed: k-anonymity, ℓ-diversity and t-closeness, to name a few. An oft-cited drawback of these models is that there is considerable loss in data quality arising from the use of generalization and suppression techniques. Optimization attempts in this context have so far focused on maximizing the data utility for a pre-specified level of privacy. To determine if better privacy levels are obtainable with the same level of data utility, majority of the existing formulations require exhaustive analysis. Further, the data publisher's perspective is often missed in the process. The publisher wishes to maintain a given level of data utility (since the data utility is the revenue earner) and then maximize the level of privacy within acceptable limits. In this paper, we explore this privacy versus data quality trade-off as a multi-objective optimization problem. Our goal is to provide substantial information to a data publisher about the trade-offs available between the privacy level and the information content of an anonymized data set. Rinku Dewri, Indrajit Ray, Indrakshi Ray, L. Darrell Whitley |
J. Comput. Secur. | 2 |
| 2011 | k-Anonymization in the Presence of Publisher PreferencesabstractPrivacy constraints are typically enforced on shared data that contain sensitive personal attributes. However, owing to its adverse effect on the utility of the data, information loss must be minimized while sanitizing the data. Existing methods for this purpose modify the data only to the extent necessary to satisfy the privacy constraints, thereby asserting that the information loss has been minimized. However, given the subjective nature of information loss, it is often difficult to justify such an assertion. In this paper, we propose an interactive procedure to generate a data generalization scheme that optimally meets the preferences of the data publisher. A data publisher guides the sanitization process by specifying aspirations in terms of desired achievement levels in the objectives. A reference direction based methodology is used to investigate neighborhood solutions if the generated scheme is not acceptable. This approach draws its power from the constructive input received from the publisher about the suitability of a solution before finding a new one. Rinku Dewri, Indrajit Ray, Indrakshi Ray, L. Darrell Whitley |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2010 | On the Identification of Property Based Generalizations in Microdata Anonymization
Rinku Dewri, Indrajit Ray, Indrakshi Ray, L. Darrell Whitley |
DBSec | 2 |
| 2010 | Using Trust-Based Information Aggregation for Predicting Security Level of Systems
Siv Hilde Houmb, Sudip Chakraborty, Indrakshi Ray, Indrajit Ray |
DBSec | 4 |
| 2010 | Query m-Invariance: Preventing Query Disclosures in Continuous Location-Based ServicesabstractLocation obfuscation using cloaking regions preserves location anonymity by hiding the true user among a set of other equally likely users. Furthermore, a cloaking region should also guarantee that the type of queries issued by users within the region are mutually diverse enough. The first requirement is fulfilled by satisfying location k-anonymity while the second one is ensured by satisfying query l-diversity. However, these two models are not sufficient to prevent the association of queries to users when the service depends on continuous location updates. Successive cloaking regions for a user may be k-anonymous and query l-diverse but still be prone to correlation attacks. In this paper, we provide a formal analysis of the privacy risks involved in a continuous location-based service, and show how continuous queries can invalidate the privacy guarantees provided by k-anonymity and l-diversity. Drawing upon the principle of m-invariance in database privacy, we show how query m-invariance can provide location and query privacy in continuous services. Rinku Dewri, Indrakshi Ray, Indrajit Ray, L. Darrell Whitley |
Mobile Data Management | 3 |
| 2010 | On the Formation of Historically k-Anonymous Anonymity Sets in a Continuous LBS
Rinku Dewri, Indrakshi Ray, Indrajit Ray, L. Darrell Whitley |
SecureComm | 3 |
| 2010 | Secure Personal Data Servers: a Vision PaperabstractAn increasing amount of personal data is automatically gathered and stored on servers by administrations, hospitals, insurance companies, etc. Citizen themselves often count on internet companies to store their data and make them reliable and highly available through the internet. However, these benefits must be weighed against privacy risks incurred by centralization. This paper suggests a radically different way of considering the management of personal data. It builds upon the emergence of new portable and secure devices combining the security of smart cards and the storage capacity of NAND Flash chips. By embedding a full-fledged Personal Data Server in such devices, user control of how her sensitive data is shared by others (by whom, for how long, according to which rule, for which purpose) can be fully reestablished and convincingly enforced. To give sense to this vision, Personal Data Servers must be able to interoperate with external servers and must provide traditional database services like durability, availability, query facilities, transactions. This paper proposes an initial design for the Personal Data Server approach, identifies the main technical challenges associated with it and sketches preliminary solutions. We expect that this paper will open exciting perspectives for future database research. Tristan Allard, Nicolas Anciaux, Luc Bouganim, Yanli Guo, Lionel Le Folgoc, Benjamin Nguyen, Philippe Pucheral, Indrajit Ray, Indrakshi Ray, Shaoyi Yin |
Proc. VLDB Endow. | 8 |
| 2010 | Real time stochastic scheduling in broadcast systems with decentralized data storage
Rinku Dewri, Indrakshi Ray, Indrajit Ray, L. Darrell Whitley |
Real Time Syst. | 3 |
| 2009 | POkA: identifying pareto-optimal k-anonymous nodes in a domain hierarchy latticeabstractData generalization is widely used to protect identities and prevent inference of sensitive information during the public release of microdata. The k-anonymity model has been extensively applied in this context. The model seeks a generalization scheme such that every individual becomes indistinguishable from at least k-1 other individuals and the loss in information while doing so is kept at a minimum. The search is performed on a domain hierarchy lattice where every node is a vector signifying the level of generalization for each attribute. An effort to understand privacy and data utility trade-offs will require knowing the minimum possible information losses of every possible value of k. However, this can easily lead to an exhaustive evaluation of all nodes in the hierarchy lattice. In this paper, we propose using the concept of Pareto-optimality to obtain the desired trade-off information. A Pareto-optimal generalization is one in which no other generalization can provide a higher value of k without increasing the information loss. We introduce the Pareto-Optimal k-Anonymization (POkA) algorithm to traverse the hierarchy lattice and show that the number of node evaluations required to find the Pareto-optimal generalizations can be significantly reduced. Results on a benchmark data set show that the algorithm is capable of identifying all Pareto-optimal nodes by evaluating only 20% of nodes in the lattice. Rinku Dewri, Indrajit Ray, Indrakshi Ray, L. Darrell Whitley |
CIKM | 2 |
| 2009 | A Trust-Based Access Control Model for Pervasive Computing Applications
Manachai Toahchoodee, Ramadan Abdunabi, Indrakshi Ray, Indrajit Ray |
DBSec | 4 |
| 2009 | On the comparison of microdata disclosure control algorithmsabstractPrivacy models such as k-anonymity and l-diversity typically offer an aggregate or scalar notion of the privacy property that holds collectively on the entire anonymized data set. However, they fail to give an accurate measure of privacy with respect to the individual tuples. For example, two anonymizations achieving the same value of k in the k-anonymity model will be considered equally good with respect to privacy protection. However, it is quite possible that for one of the anonymizations a majority of the individual tuples have lesser probabilities of privacy breaches than their counterparts in the other anonymization. We therefore reject the notion that all anonymizations satisfying a particular privacy property, such as k-anonymity, are equally good. The scalar or aggregate value used in privacy models is often biased towards a fraction of the data set, resulting in higher privacy for some individuals and minimalistic for others. Consequently, to better compare anonymization algorithms, there is a need to formalize and measure this bias. Towards this end, we advocate the use of vector-based methods for representing privacy and other measurable properties of an anonymization. We represent the measure of a given property for an anonymized data set using a property vector. Anonymizations are then compared using quality index functions that quantify the effectiveness of the property vectors. A formal analysis with respect to their scope and limitations is provided. Finally, we present preference based techniques when comparisons are to be made across multiple properties induced by anonymizations. Rinku Dewri, Indrajit Ray, Indrakshi Ray, L. Darrell Whitley |
EDBT | 2 |
| 2009 | A multi-objective approach to data sharing with privacy constraints and preference based objectivesabstractPublic data sharing is utilized in a number of businesses to facilitate the exchange of information. Privacy constraints are usually enforced to prevent unwanted inference of information, specially when the shared data contain sensitive personal attributes. This, however, has an adverse effect on the utility of the data for statistical studies. Thus, a requirement while modifying the data is to minimize the information loss. Existing methods employ the notion of "minimal distortion" where the data is modified only to the extent necessary to satisfy the privacy constraint, thereby asserting that the information loss has been minimized. However, given the subjective nature of information loss, it is often difficult to justify this assertion. In this paper, we propose an evolutionary algorithm to explicitly minimize an achievement function given constraints on the privacy level of the transformed data. Privacy constraints specified in terms of anonymity models are modeled as additional objectives and an evolutionary multi-objective approach is proposed. We highlight the requirement to minimize any bias induced by the anonymity model and present a scalarization incorporating preferences in information loss and privacy bias as the achievement function. Rinku Dewri, L. Darrell Whitley, Indrajit Ray, Indrakshi Ray |
GECCO | 3 |
| 2009 | An interoperable context sensitive model of trust
Indrakshi Ray, Indrajit Ray, Sudip Chakraborty |
J. Intell. Inf. Syst. | 2 |
| 2008 | An Opinion Model for Evaluating Malicious Activities in Pervasive Computing Systems
Indrajit Ray, Nayot Poolsappasit, Rinku Dewri |
DBSec | 1 |
| 2008 | Optimizing on-demand data broadcast scheduling in pervasive environmentsabstractData dissemination in pervasive environments is often accomplished by on-demand broadcasting. The time critical nature of the data requests plays an important role in scheduling these broadcasts. Most research in on-demand broadcast scheduling has focused on the timely servicing of requests so as to minimize the number of missed deadlines. However, there exists many pervasive environments where the utility of the data is an equally important criterion as its timeliness. Missing the deadline reduces the utility of the data but does not make it zero. In this work, we address the problem of scheduling on-demand data broadcasts with soft deadlines. We investigate search based optimization techniques to develop broadcast schedulers that make explicit attempts to maximize the utility of data requests as well as service as many requests as possible within the acceptable time limit. Our analysis shows that heuristic driven methods for such problems can be improved by hybridizing them with local search algorithms. We further investigate the option of employing a dynamic optimization technique to facilitate utility gain, thereby surpassing the requirement of a heuristic in the process. An evolution strategy based stochastic hill climber is investigated in this context. Rinku Dewri, Indrakshi Ray, Indrajit Ray, L. Darrell Whitley |
EDBT | 3 |
| 2008 | Security Provisioning in Pervasive Environments Using Multi-objective Optimization
Rinku Dewri, Indrakshi Ray, Indrajit Ray, L. Darrell Whitley |
ESORICS | 3 |
| 2008 | Evolution strategy based optimization of on-demand dependent data broadcast schedulingabstractData broadcasting makes effective use of low bandwidth and is commonly used in applications involving mobile devices. We consider the case where data must be broadcast in a particular order and within a specified response time. However, communication bottlenecks prohibit the timely serving of all requests; although, missing the deadline does not make the data utility zero. In this work, we consider the problem of real-time data broadcast scheduling in the presence of soft deadlines together with constraints on the order in which data-items should be broadcast to be useful. We explore the method of evolution strategy to solve the problem, keeping in view that the real-time scheduler has to effectively trade-off between its running time and the quality of schedules generated. Rinku Dewri, L. Darrell Whitley, Indrakshi Ray, Indrajit Ray |
GECCO | 4 |
| 2008 | On the Optimal Selection of k in the k-Anonymity ProblemabstractWhen disseminating data involving human subjects, researchers have to weigh in the requirements of privacy of the individuals involved in the data. A model widely used for enhancing individual privacy is k-anonymity, where an individual data record is rendered similar to k - 1 other records in the data set by using generalization and/or suppression operations on the data attributes. The drawback of this model is that such transformations result in considerable loss of information that is proportional to the choice of k. Studies in this context have so far focused on minimizing the information loss for some given value of k. However, owing to the presence of outliers, a specified k value may or may not be obtainable. Further, an exhaustive analysis is required to determine a k value that fits the loss constraint specified by a data publisher. In this paper, we formulate a multi-objective optimization problem to illustrate that the decision on k can be much more informed than being a choice solely based on the privacy requirement. The optimization problem is intended to resolve the issue of data privacy when data suppression is not allowed in order to obtain a particular value of k. An evolutionary algorithm is employed here to provide this insight. Rinku Dewri, Indrajit Ray, Indrakshi Ray, L. Darrell Whitley |
ICDE | 2 |
| 2008 | Key pre-distribution based secure backbone formation in wireless sensor networksabstractSecurity is a prime concern in large-scale wireless sensor networks used for collaborative mission critical applications. A backbone network in the form of a cluster tree can enhance upper layer functions such as routing, broadcasting, in-network query processing and network management. A secure backbone based on the cluster tree enables secure upper layer functions and dynamic distribution of cryptographic keys among different nodes and users of collaborative networks. A secure cluster tree formation algorithm is presented that is independent of key pre-distribution scheme, network topology, and does not require a-priori neighborhood information or location awareness. Simulation based results show that the algorithm retains most of the desirable cluster and cluster tree characteristics while building the secure cluster tree. Availability of neighborhood information further improves the performance. Our simulations also suggest that hierarchical networks are more vulnerable to node capture than non-hierarchical networks. H. M. N. Dilum Bandara, Anura P. Jayasumana, Indrajit Ray |
LCN | 3 |
| 2008 | Optimizing Real-Time Ordered-Data Broadcasts in Pervasive Environments Using Evolution Strategy
Rinku Dewri, L. Darrell Whitley, Indrajit Ray, Indrakshi Ray |
PPSN | 3 |
| 2008 | Facilitating Privacy Related Decisions in Different Privacy Contexts on the Internet by Evaluating Trust in Recipients of Private Data
Indrajit Ray, Sudip Chakraborty |
SEC | 1 |
| 2007 | Optimal security hardening using multi-objective optimization on attack tree models of networksabstractResearchers have previously looked into the problem of determining if a given set of security hardening measures can effectively make a networked system secure. Many of them also addressed the problem of minimizing the total cost of implementing these hardening measures, given costs for individual measures. However, system administrators are often faced with a more challenging problem since they have to work within a fixed budget which may be less than the minimum cost of system hardening. Their problem is how to select a subset of security hardening measures so as to be within the budget and yet minimize the residual damage to the system caused by not plugging all required security holes. In this work, we develop a systematic approach to solve this problem by formulating it as a multi-objective optimization problem on an attack tree model of the system and then use an evolutionary algorithm to solve it. Rinku Dewri, Nayot Poolsappasit, Indrajit Ray, L. Darrell Whitley |
CCS | 3 |
| 2007 | Reliable Delivery of Event Data from Sensors to Actuators in Pervasive Computing Environments
Sudip Chakraborty, Nayot Poolsappasit, Indrajit Ray |
DBSec | 3 |
| 2007 | Investigating Computer Attacks Using Attack TreesabstractSystem log files contain valuable evidence pertaining to computer attacks. However, the log files are often massive, and much of the information they contain is not relevant to the investigation. Furthermore, the files almost always have a flat structure, which limits the ability to query them. Thus, digital forensic investigators find it extremely difficult and time consuming to extract and analyze evidence of attacks from log files. This paper describes an automated attack-tree-based approach for filtering irrelevant information from system log files and conducting systematic investigations of computer attacks. Nayot Poolsapassit, Indrajit Ray |
IFIP Int. Conf. Digital Forensics | 2 |
| 2007 | Measuring, analyzing and predicting security vulnerabilities in software systems
Omar Hussain Alhazmi, Yashwant K. Malaiya, Indrajit Ray |
Comput. Secur. | 3 |
| 2006 | A Trust Model for Pervasive Computing EnvironmentsabstractWith the growth of mobile and sensor devices, embedded systems, and communication technologies, we are moving towards an era of pervasive computing. Pervasive computing applications typically involve interactions between a large number of entities that span different organizations. Uncontrolled disclosure of information or unconstrained interaction among entities may have extremely grave consequences. Traditional security policies and mechanisms are inadequate for pervasive computing applications. Unlike traditional applications, pervasive computing applications have no definite security perimeters and are dynamic in nature. Pervasive computing applications may need to interact with entities that are not known a priori and therefore cannot be trusted. The traditional binary notion of trust where known entities are completely trusted and unknown entities are distrusted are not suitable for such applications. To fill this gap, we develop a trust model useful for pervasive computing applications and develop strategies for establishing trust between entities. The model must accommodate the notion of different degrees of trust, identify how to determine the trust value, and define how trust changes over time Shuxin Yin, Indrakshi Ray, Indrajit Ray |
CollaborateCom | 3 |
| 2006 | A Framework for Flexible Access Control in Digital Library Systems
Indrajit Ray, Sudip Chakraborty |
DBSec | 1 |
| 2006 | Remote Upload of Evidence over Mobile Ad Hoc Networks
Indrajit Ray |
IFIP Int. Conf. Digital Forensics | 1 |
| 2006 | TrustBAC: integrating trust relationships into the RBAC model for access control in open systemsabstractConventional access control are suitable for regulating access to resources by known users.However,these models have often found to be inadequate for open and decentralized multi-centric systems where the user population is dynamic and the identity of all users are not known in advance.For such systems, credential based access control has been proposed. Credential based systems achieve access control by implementing a binary notion of trust.If a user is trusted by virtue of successful evaluation of its credentials it is allowed access, otherwise not. However,such credential based models have also been found to be lacking because of certain inherent drawbacks with the notion of credentials.In this work,we propose a trust based access control model called TrustBAC. It extends the conventional role based access control model with the notion of trust levels.Users are assigned to trust levels instead of roles based on a number of factors like user credentials,user behavior history,user recommendation etc. Trust levels are assigned to roles which are assigned to permissions as in role based access control.The TrustBAC model thus incorporates the advantages of both the role based access control model and credential based access control models. Sudip Chakraborty, Indrajit Ray |
SACMAT | 2 |
| 2005 | Security Vulnerabilities in Software Systems: A Quantitative Perspective
Omar Hussain Alhazmi, Yashwant K. Malaiya, Indrajit Ray |
DBSec | 3 |
| 2005 | Using Attack Trees to Identify Malicious Attacks from Authorized Insiders
Indrajit Ray, Nayot Poolsapassit |
ESORICS | 1 |
| 2005 | Global Internet Routing Forensics: Validation of BGP Paths Using ICMP Traceback
Eunjong Kim, Daniel Massey, Indrajit Ray |
IFIP Int. Conf. Digital Forensics | 3 |
| 2005 | An anonymous and failure resilient fair-exchange e-commerce protocol
Indrajit Ray, Indrakshi Ray, Natarajan Narasimhamurthi |
Decis. Support Syst. | 1 |
| 2004 | Securely Distributing Centralized Multimedia Content Utilizing Peer-to-Peer CooperationabstractThe ability of peer-to-peer networks to distribute multimedia content efficiently has been demonstrated many times by services such as Napster, Gnutella, and KaZaa. However, such services still suffer from two major disadvantages, viz., providing easy search facilities with little network overhead and providing secure services with the ability to audit the system. The latter feature is increasingly becoming critical as evidenced by the numerous law suites that have been brought against services such as Napster in recent months. In this work, we propose a new system that combines a centralized storage and distribution system with peer cooperation to help distribute multimedia content efficiently. Our system adds security, source verification, and an auditing ability to content distribution while reducing centralized bandwidth usage. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Indrajit Ray, Tomas Hajek |
DBSec | 1 |
| 2004 | A Vector Model of Trust for Developing Trustworthy Systems
Indrajit Ray, Sudip Chakraborty |
ESORICS | 1 |
| 2004 | Collective Signature for Efficient Authentication of XML DocumentsabstractXML (eXtensible Markup Language) is the de-facto standard for document representation and exchange on the Web. Researchers have previously proposed access control models and schemes for XML documents that allow one to disseminate selectively, portions of an XML document to the user community based on different policies. Such selective dissemination of an XML document creates a new problem, namely, how to authenticate portions of the XML document independent of other portions andlor the complete document. In this paper, we present a novel scheme based on one-way accumulator functions that allows the user to have a guarantee that a portion of an XML document does indeed belong to the original document. Indrajit Ray, Eunjong Kim |
SEC | 1 |
| 2003 | A certified e-mail protocol suitable for mobile environmentsabstractA novel certified e-mail protocol that is particularly suitable for mobile environments is described. Our protocol uses an off-line trusted third party (TTP). Protocols with an off-line TTP-also known as optimistic protocols-have numerous practical advantages over protocols with an on-line TTP. Nonetheless, many protocols adopt an on-line TTP primarily because optimistic protocols often entail intricate cryptographic primitives that incur considerable overhead. By using a novel signature paradigm, which we call gradational signatures, we show that it is possible to construct optimistic protocols that are comparable to on-line protocols in terms of computation and communication overhead. This makes our scheme especially desirable in the mobile setting. Jung-Min Park 0001, Indrajit Ray, Edwin K. P. Chong, Howard Jay Siegel |
GLOBECOM | 2 |
| 2002 | Anonymous and Secure Multicast Subscription
Indrajit Ray, Indrakshi Ray |
DBSec | 1 |
| 2002 | A cryptographic solution to implement access control in a hierarchy and moreabstractThe need for access control in a hierarchy arises in several different contexts. One such context is managing the information of an organization where the users are divided into different security classes depending on who has access to what. Several cryptographic solutions have been proposed to address this problem --- the solutions are based on generating cryptographic keys for each security class such that the key for a lower level security class depends on the key for the security class that is higher up in the hierarchy. Most solutions use complex cryptographic techniques: integrating these into existing systems may not be trivial. Others have impractical requirement: if a user at a security level wants to access data at lower levels, then all intermediate nodes must be traversed. Moreover, if there is an access control policy that does not conform to the hierarchical structure, such policy cannot be handled by existing solutions. We propose a new solution that overcomes the above mentioned shortcomings. Our solution not only addresses the problem of access control in a hierarchy but also can be used for general cases. It is a scheme similar to the RSA cryptosystem and can be easily incorporated in existing systems. Indrakshi Ray, Indrajit Ray, Natarajan Narasimhamurthi |
SACMAT | 2 |
| 2001 | Detecting Termination of Active Database Rules Using Symbolic Model Checking
Indrakshi Ray, Indrajit Ray |
ADBIS | 2 |
| 2001 | An Anomymous Fair Exchange E-commerce ProtocolabstractIn this paper we propose an e-commerce protocol for trading digital products over the Internet. The novel features of our protocol include: (1) ensuring fair exchange, (2) not requiring manual dispute resolution in case of unfair behavior by any party, (3) assuring each party that the item he is about to receive is indeed the correct one, (4) not requiring the active involvement of a trusted third party unless a problem occurs, and (5) ensuring anonymity for both the customer and the merchant. No existing e-commerce protocol that we know of has all these features. 1 Indrakshi Ray, Indrajit Ray |
IPDPS | 2 |
| 2000 | A Fair-exchange E-commerce Protocol with Automated Dispute Resolution
Indrajit Ray, Indrakshi Ray, Natarajan Narasimhamurthy |
DBSec | 1 |
| 2000 | Flexible Transaction Dependencies in Database Systems
Luigi V. Mancini, Indrajit Ray, Sushil Jajodia, Elisa Bertino |
Distributed Parallel Databases | 2 |
| 2000 | ASEP: A Secure and Flexible Commit Protocol for MLS Distributed Database SystemsabstractThe classical Early Prepare (EP) commit protocol, used in many commercial systems, is not suitable for use in multi-level secure (MLS) distributed database systems that employ a locking protocol for concurrency control. This is because EP requires that read locks are not released by a participant during their window of uncertainty; however, it is not possible for a locking protocol to provide this guarantee in a MLS system (since the read lock of a higher-level transaction on a lower-level data object must be released whenever a lower-level transaction wants to write the same data). The only available work in the literature, namely the Secure Early Prepare (SEP) protocol, overcomes this difficulty by aborting those distributed transactions that release their low-level read locks prematurely. We see this approach as being too restrictive. One of the major benefits of distributed processing is its robustness to failures, and SEP fails to take advantage of this. In this paper, we propose the Advanced Secure Early Prepare (ASEP) commit protocol to solve the above problem, together with a number of language primitives that can be used as system calls in distributed transactions. These primitives permit features like partial rollback and forward recovery to be incorporated within the transaction model, and allow a distributed transaction to proceed even when a participant has released its low-level read locks prematurely. This not only offers flexibility, but can also be used, if desired, by a sophisticated programmer to trade off consistency for atomicity of the distributed transaction. Indrajit Ray, Luigi V. Mancini, Sushil Jajodia, Elisa Bertino |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1998 | Advanced Transaction Processing in Multilevel Secure File StoresabstractThe concurrency control requirements for transaction processing in a multilevel secure file system are different from those in conventional transaction processing systems. In particular, there is the need to coordinate transactions at different security levels avoiding both potential timing covert channels and the starvation of transactions at higher security levels. Suppose a transaction at a lower security level attempts to write a data item that is being read by a transaction at a higher security level. On the one hand, a timing covert channel arises if the transaction at the lower security level is either delayed or aborted by the scheduler. On the other hand, the transaction at the high security level may be subjected to an indefinite delay if it is forced to abort repeatedly. This paper extends the classical two-phase locking mechanism to multilevel secure file systems. The scheme presented here prevents potential timing covert channels and avoids the abort of higher level transactions nonetheless guaranteeing serializability. The programmer is provided with a powerful set of linguistic constructs that supports exception handling, partial rollback, and forward recovery. The proper use of these constructs can prevent the indefinite delay in completion of a higher level transaction, and allows the programmer to trade off starvation with transaction isolation. Elisa Bertino, Sushil Jajodia, Luigi V. Mancini, Indrajit Ray |
IEEE Trans. Knowl. Data Eng. | 4 |
| 1997 | A Two-tier Coarse Indexing Scheme for MLS Database Systems
Sushil Jajodia, Ravi Mukkamala, Indrajit Ray |
DBSec | 3 |
| 1996 | An Advanced Commit Protocol for MLS Distributed Database SystemsabstractThe classical Early Prepare commit protocol (EP), used in many commercial systems, is not suitable for use in multilevel secure distributed database systems that employ a locking protocol for concurrency control. This is because EP requires that read locks be not released by a subtransaction during its window of uncertainty; however, it is not possible for a locking protocol to provide this guarantee in a multilevel secure system (since read lock of a higher level transaction on a lower level data object must be released whenever a lower level transaction wants to write it). The Secure Early Prepare protocol (SEP) overcomes this difficulty by aborting those distributed transactions that release their low level read locks prematurely. We see this approach as being too restrictive. One of the major benefits of distributed processing is its robustness to failures, and SEP fails to take advantage of this. In this work, we propose the Advanced Secure Early Prepare commit protocol (ASEP) to... Indrajit Ray, Elisa Bertino, Sushil Jajodia, Luigi V. Mancini |
CCS | 1 |
| 1996 | Secure Locking Protocols for Multilevel Database Management Systems
Sushil Jajodia, Luigi V. Mancini, Indrajit Ray |
DBSec | 3 |
| 1996 | Secure Concurrency Control in MLS Databases with Two Versions of Data
Luigi V. Mancini, Indrajit Ray |
ESORICS | 2 |