EDBT 2026 Demo / reviewers in the wild / expert
B. Clifford Neuman
dblp:27/4485 · also Clifford Neuman
· DBLP profile ↗
17ranked-venue papers
6as first author
0since 2021 · last 2013
0000-0002-4318-0721ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-authorSystems, architecture and hardware · 6 · 3 first-authorComputer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2Applied, interdisciplinary, general and emerging computing · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
7 papers |
Authentication and access control · 51% Network security · 16% Web and mobile security · 13% | |
| Computer architecture, parallel and distributed computing, and storage systems
4 papers |
Distributed systems · 53% Cloud and datacenter computing · 43% Parallel and multicore computing · 4% |
Topics — the 20 heaviest of 22, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Authentication and access control
access control |
0.0 | 1 | 2003 | Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003 |
Authentication and access control › authorization
dynamic authorization |
0.0 | 1 | 2003 | Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003 |
Network security › intrusion detection and prevention
intrusion detection |
0.0 | 1 | 2003 | Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003 |
Web and mobile security
e-commerce security |
0.0 | 1 | 1998 | Implementation Issues for E-Commerce · NDSS 1998 |
Cloud and datacenter computing › cluster resource management and scheduling
cluster resource management |
0.0 | 1 | 1998 | Authorization for Metacomputing Applications · HPDC 1998 |
Distributed systems › distributed system security
distributed authorization |
0.0 | 1 | 1998 | Authorization for Metacomputing Applications · HPDC 1998 |
Authentication and access control › authorization
distributed authorization |
0.0 | 1 | 1996 | A flexible distributed authorization protocol · NDSS 1996 |
Cryptographic protocols and secure computation
secure payment |
0.0 | 2 | 1995 | NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993 Security, Payment, and Privacy for Network Commerce (Invited Paper) · IEEE J. Sel. Areas Commun. 1995 |
Web and mobile security › web security
web server security |
0.0 | 1 | 2003 | Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003 |
Distributed systems › distributed system security
trust management |
0.0 | 1 | 1994 | Endorsements, Licensing, and Insurance for Distributed System Services · CCS 1994 |
Blockchain and cryptocurrency security
electronic cash |
0.0 | 1 | 1993 | NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993 |
Cryptographic primitives and cryptanalysis › boolean functions
strict avalanche criterion |
0.0 | 1 | 1993 | NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993 |
Cloud and datacenter computing
resource management |
0.0 | 1 | 1993 | Resource Management for Distributed Parallel Systems · HPDC 1993 |
Authentication and access control
access control models |
0.0 | 1 | 1998 | Authorization for Metacomputing Applications · HPDC 1998 |
Authentication and access control › access control
conditional access |
0.0 | 1 | 1998 | Authorization for Metacomputing Applications · HPDC 1998 |
Distributed systems
distributed object systems |
0.0 | 1 | 1998 | Implementation Issues for E-Commerce · NDSS 1998 |
Authentication and access control › authorization
delegation |
0.0 | 1 | 1996 | A flexible distributed authorization protocol · NDSS 1996 |
Authentication and access control
authorization |
0.0 | 1 | 1994 | Endorsements, Licensing, and Insurance for Distributed System Services · CCS 1994 |
Malware analysis
anti-virus |
0.0 | 1 | 1993 | NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993 |
Parallel and multicore computing
multiprocessor system |
0.0 | 1 | 1993 | Resource Management for Distributed Parallel Systems · HPDC 1993 |
Methods — techniques the papers use, named apart from their topics
implementation issues · 0.0GAA-API · 0.0restricted proxies · 0.0survey · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2013 | Deconstructing the Assessment of Anomaly-based Intrusion Detectors
Arun Viswanathan, Kymie Tan, B. Clifford Neuman |
RAID | 3 |
| 2005 | Adaptive trust negotiation and access controlabstractElectronic transactions regularly occur between business partners in separate security domains. Trust negotiation is an approach that provides an open authentication and access-control environment for such transactions, but it is vulnerable to malicious attacks leading to denial of service or leakage of sensitive information. This paper introduces an Adaptive Trust Negotiation and Access Control (ATNAC) framework to solve these problems. The framework combines two existing systems, TrustBuilder and GAA-API, to create a system with more flexibility and responsiveness to attack than either system currently provides. Tatyana Ryutov, B. Clifford Neuman, Travis Leithead, Kent E. Seamons |
SACMAT | 3 |
| 2003 | A Flexible Framework for Replication in Distributed SystemsabstractThe goal of the work described in this paper was to build a flexible framework for different replication mechanisms in distributed systems that would be suitable for a wide variety of users and applications. A framework was developed that supports multiple replication mechanisms, allows different objects to be maintained with different replication mechanisms, and enables application programmers to provide their own replication mechanisms. It will be argued that this framework allowed the needs of diverse users and applications in large distributed systems to be met. Our work has produced two significant contributions. First, after an examination of replication mechanisms used in distributed systems, a flexible framework that supports multiple replication mechanisms together was designed and developed. Second, following an examination of different levels of replication between replicas, a unified framework for them was produced. This multi-level replication allows the framework to work well with mobile computing by placing different replicas on mobile sites. Eul-Gyu Im, B. Clifford Neuman |
COMPSAC | 2 |
| 2003 | Distributed Garbage Collection by Timeouts and Backward InquiryabstractWe present a practical and efficient garbage collection mechanism for large scale distributed systems. The mechanism collects all garbage including distributed cyclic garbage without global synchronization or backward links. The primary method used for local and remote garbage collection is timeouts: each object has a time-to-live, and clients which have a link to an object must refresh the target object within the time-to-live to guarantee that the link will remain valid. For cyclic garbage collection: objects suspected to be garbage are detected by last referenceable timestamp propagation; and cyclic garbage is reclaimed by backward inquiry (back-tracing). Since, without additional overhead, the information about backward references can be obtained during the refreshing process, and since messages necessary for cyclic garbage collection are bundled with the messages used for the refreshing, communication, computation and storage overhead is minimized. This mechanism has been implemented and evaluated on Prospero directory service, and the performance results show that it works well for large scale distributed systems. Sung-Wook Ryu, Eul-Gyu Im, B. Clifford Neuman |
COMPSAC | 3 |
| 2003 | Integrated Access Control and Intrusion Detection for Web ServersabstractCurrent intrusion detection systems work in isolation front access control for the application the systems aim to protect. The lack of coordination and inter-operation between these components prevents detecting and responding to ongoing attacks in real time, before they cause damage. To address this, we apply dynamic authorization techniques to support fine-grained access control and application level intrusion detection and response capabilities. This paper describes our experience with integration of the Generic Authorization and Access Control API (GAA-API) to provide dynamic intrusion detection and response for the Apache Web Server The GAA-API is a generic interface which may be used to enable such dynamic authorization and intrusion response capabilities for many applications. Tatyana Ryutov, B. Clifford Neuman |
ICDCS | 2 |
| 2003 | Integrated Access Control and Intrusion Detection for Web ServersabstractCurrent intrusion detection systems work in isolation from access control for the application the systems aim to protect. The lack of coordination and interoperation between these components prevents detecting and responding to ongoing attacks in real-time before they cause damage. To address this, we apply dynamic authorization techniques to support fine-grained access control and application level intrusion detection and response capabilities. This paper describes our experience with integration of the Generic Authorization and Access Control API (GAA-API) to provide dynamic intrusion detection and response for the Apache Web server. The GAA-API is a generic interface which may be used to enable such dynamic authorization and intrusion response capabilities for many applications. Tatyana Ryutov, B. Clifford Neuman |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2001 | Condition-Driven Integration of Security Services
B. Clifford Neuman |
ACISP | 1 |
| 1999 | The Performance of a Reliable, Request-Response Transport ProtocolabstractThis paper studies the behavior of ARDP, a request response transport protocol, when operating in a shared communication infrastructure like the Internet. Our experiments demonstrate that ARDP backs off in the presence of congestion, yet tries to take advantage of available bandwidth. We also show that ARDP is well-behaved when competing for network resources with TCP. Nader Salehi, Katia Obraczka, B. Clifford Neuman |
ISCC | 3 |
| 1998 | Authorization for Metacomputing ApplicationsabstractOne of the most difficult problems to be solved by metacomputing systems is to ensure strong authentication and authorization. The problem is complicated since the hosts involved in a metacomputing environment often span multiple administrative domains, each with its own security policy. This paper presents a distributed authorization model used by our resource allocation system, the Prospero resource manager. The main components of our design are extended access control lists (EACLs) and a general authorization and access application programming interface (GAA API). EACLs extend conventional ACLs to allow conditional restrictions on access rights. In the case of the Prospero resource manager, specific restrictions include limits on the computational resources to be consumed and on the characteristics of the applications to be executed by the system, such as name, version or endorser. The GAA API provides a general framework for applications to access the EACLs. We have built a prototype of the system. Grig Gheorghiu, Tatyana Ryutov, B. Clifford Neuman |
HPDC | 3 |
| 1998 | Implementation Issues for E-Commerce
B. Clifford Neuman |
NDSS | 1 |
| 1996 | A flexible distributed authorization protocolabstractWhile there has been considerable effort in creating a single sign-on solution for interoperability among authentication methods, such interoperability across authorization methods has received little attention. This paper presents a flexible distributed authorization protocol that provides the full generality of restricted proxies while supporting the functionality of and interoperability with existing authorization models including OSF DCE and SESAME V2. Our authorization protocol includes a delegation method that is well suited for certain electronic commerce applications. Jonathan T. Trostle, B. Clifford Neuman |
NDSS | 2 |
| 1995 | Security, Payment, and Privacy for Network Commerce (Invited Paper)abstractAs the Internet is used to a greater extent in business, issues of protection and privacy will have more importance. Users and organizations must have the ability to control reads and writes to network accessible information, they must be assured of the integrity and confidentiality of the information accessed over the net, and they must have a means to determine the security, competence, and honesty of the commercial service providers with which they interact. They must also be able to pay for purchases made on the network, and they should be free from excessive monitoring of their activities. This paper discusses characteristics of the Internet that make it difficult to provide such assurances and surveys some of the techniques that can used to protect users of the network.> B. Clifford Neuman |
IEEE J. Sel. Areas Commun. | 1 |
| 1994 | Endorsements, Licensing, and Insurance for Distributed System ServicesabstractClients in a distributed system place their confidence in many servers, and servers themselves rely on other servers for file storage, authentication, authorization, and payment. When a system spans administrative boundaries it becomes harder to assess the security and competence of potential service providers. This paper examines the issue of confidence in large distributed systems. Gennady Medvinsky, Charlie Lai, B. Clifford Neuman |
CCS | 3 |
| 1994 | The Prospero Resource Manager: A scalable framework for processor allocation in distributed systemsabstractAbstract Existing techniques for allocating processors in parallel and distributed systems are not suitable for use in large distributed systems. In such systems, dedicated multiprocessors should exist as an integral component of the distributed system, and idle processors should be available to applications that need them. The Prospero Resource Manager (PRM) is a scalable resource allocation system that supports the allocation of processing resources in large networks and on multiprocessor systems. PRM employs three types of managers‐the job manager, the system manager and the node manager‐to manage resources in a distributed system. Multiple independent instances of each type of manager exist, reducing bottlenecks. When making scheduling decisions each manager utilizes information most closely associated with the entities for which it is responsible. B. Clifford Neuman, Santosh Rao |
Concurr. Pract. Exp. | 1 |
| 1993 | NetCash: A Design for Practical Electronic Currency on the InternetabstractLicensing is a topic of increasing importance for software publishers and users. More and more, the magnitude of financial transfers between these two partners are determined by some electronic licensing service being part of the system on which the licensed software is running. In order to ease the use and management of such licensing schemes and to enable economic software usage in enterprise-wide computer systems through flexible and fair billing structures, various organizations are working on formulating requirements, defining architectures, and building standard interfaces for so called license brokerage systems. The trustworthiness of these services is essential because large amounts of money can depend on them. Most of these licensing services are currently operating independently of access control and rely on proprietary and unpublished security algorithms. This paper proposes an extension of access control to integrate licensing called Stateful Access Control and it addresses some aspects of virus protection. Gennady Medvinsky, B. Clifford Neuman |
CCS | 2 |
| 1993 | Resource Management for Distributed Parallel SystemsabstractMultiprocessor systems should exist in the larger context of distributed systems, allowing multiprocessor resources to be shared by those that need them. Unfortunately, typical multiprocessor resource management techniques do not scale to large networks. The Prospero Resource Manager (PRM) is a scalable resource allocation system that supports the allocation of processing resources in large networks and multiprocessor systems. To manage resources in such distributed parallel systems, PRM employs three types of managers: system managers, job managers, and node managers. There exist multiple independent instances of each type of manager, reducing bottlenecks. The complexity of each manager is further reduced because each is designed to utilize information at an appropriate level of abstraction.> B. Clifford Neuman, Santosh Rao |
HPDC | 1 |
| 1993 | Proxy-Based Authorization and Accounting for Distributed SystemsabstractA unified model is presented for authentication, authorization, and accounting that is based on proxies. It is shown that the proxy model for authorization can be used to support a wide range of authorization and accounting mechanisms. The proxy model strikes a balance between access-control-list anti capability-based mechanisms, allowing each to be used where appropriate and allowing their use in combination. The author describes how restricted proxies can be supported using existing authentication methods.> B. Clifford Neuman |
ICDCS | 1 |