B. Clifford Neuman

dblp:27/4485 · also Clifford Neuman · DBLP profile ↗
← Back
17ranked-venue papers
6as first author
0since 2021 · last 2013
0000-0002-4318-0721ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-authorSystems, architecture and hardware · 6 · 3 first-authorComputer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2Applied, interdisciplinary, general and emerging computing · 2

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
7 papers
Authentication and access control · 51% Network security · 16% Web and mobile security · 13%
Computer architecture, parallel and distributed computing, and storage systems
4 papers
Distributed systems · 53% Cloud and datacenter computing · 43% Parallel and multicore computing · 4%

Topics — the 20 heaviest of 22, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
access control
0.012003
Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003
Authentication and access control › authorization
dynamic authorization
0.012003
Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003
Network security › intrusion detection and prevention
intrusion detection
0.012003
Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003
Web and mobile security
e-commerce security
0.011998
Implementation Issues for E-Commerce · NDSS 1998
Cloud and datacenter computing › cluster resource management and scheduling
cluster resource management
0.011998
Authorization for Metacomputing Applications · HPDC 1998
Distributed systems › distributed system security
distributed authorization
0.011998
Authorization for Metacomputing Applications · HPDC 1998
Authentication and access control › authorization
distributed authorization
0.011996
A flexible distributed authorization protocol · NDSS 1996
Cryptographic protocols and secure computation
secure payment
0.021995
NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993
Security, Payment, and Privacy for Network Commerce (Invited Paper) · IEEE J. Sel. Areas Commun. 1995
Web and mobile security › web security
web server security
0.012003
Integrated Access Control and Intrusion Detection for Web Servers · IEEE Trans. Parallel Distributed Syst. 2003
Distributed systems › distributed system security
trust management
0.011994
Endorsements, Licensing, and Insurance for Distributed System Services · CCS 1994
Blockchain and cryptocurrency security
electronic cash
0.011993
NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993
Cryptographic primitives and cryptanalysis › boolean functions
strict avalanche criterion
0.011993
NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993
Cloud and datacenter computing
resource management
0.011993
Resource Management for Distributed Parallel Systems · HPDC 1993
Authentication and access control
access control models
0.011998
Authorization for Metacomputing Applications · HPDC 1998
Authentication and access control › access control
conditional access
0.011998
Authorization for Metacomputing Applications · HPDC 1998
Distributed systems
distributed object systems
0.011998
Implementation Issues for E-Commerce · NDSS 1998
Authentication and access control › authorization
delegation
0.011996
A flexible distributed authorization protocol · NDSS 1996
Authentication and access control
authorization
0.011994
Endorsements, Licensing, and Insurance for Distributed System Services · CCS 1994
Malware analysis
anti-virus
0.011993
NetCash: A Design for Practical Electronic Currency on the Internet · CCS 1993
Parallel and multicore computing
multiprocessor system
0.011993
Resource Management for Distributed Parallel Systems · HPDC 1993

Methods — techniques the papers use, named apart from their topics

implementation issues · 0.0GAA-API · 0.0restricted proxies · 0.0survey · 0.0
YearPublicationVenuePosition
2013 Deconstructing the Assessment of Anomaly-based Intrusion Detectors
Arun Viswanathan, Kymie Tan, B. Clifford Neuman
RAID3
2005 Adaptive trust negotiation and access control
abstract
Electronic transactions regularly occur between business partners in separate security domains. Trust negotiation is an approach that provides an open authentication and access-control environment for such transactions, but it is vulnerable to malicious attacks leading to denial of service or leakage of sensitive information. This paper introduces an Adaptive Trust Negotiation and Access Control (ATNAC) framework to solve these problems. The framework combines two existing systems, TrustBuilder and GAA-API, to create a system with more flexibility and responsiveness to attack than either system currently provides.
Tatyana Ryutov, B. Clifford Neuman, Travis Leithead, Kent E. Seamons
SACMAT3
2003 A Flexible Framework for Replication in Distributed Systems
abstract
The goal of the work described in this paper was to build a flexible framework for different replication mechanisms in distributed systems that would be suitable for a wide variety of users and applications. A framework was developed that supports multiple replication mechanisms, allows different objects to be maintained with different replication mechanisms, and enables application programmers to provide their own replication mechanisms. It will be argued that this framework allowed the needs of diverse users and applications in large distributed systems to be met. Our work has produced two significant contributions. First, after an examination of replication mechanisms used in distributed systems, a flexible framework that supports multiple replication mechanisms together was designed and developed. Second, following an examination of different levels of replication between replicas, a unified framework for them was produced. This multi-level replication allows the framework to work well with mobile computing by placing different replicas on mobile sites.
Eul-Gyu Im, B. Clifford Neuman
COMPSAC2
2003 Distributed Garbage Collection by Timeouts and Backward Inquiry
abstract
We present a practical and efficient garbage collection mechanism for large scale distributed systems. The mechanism collects all garbage including distributed cyclic garbage without global synchronization or backward links. The primary method used for local and remote garbage collection is timeouts: each object has a time-to-live, and clients which have a link to an object must refresh the target object within the time-to-live to guarantee that the link will remain valid. For cyclic garbage collection: objects suspected to be garbage are detected by last referenceable timestamp propagation; and cyclic garbage is reclaimed by backward inquiry (back-tracing). Since, without additional overhead, the information about backward references can be obtained during the refreshing process, and since messages necessary for cyclic garbage collection are bundled with the messages used for the refreshing, communication, computation and storage overhead is minimized. This mechanism has been implemented and evaluated on Prospero directory service, and the performance results show that it works well for large scale distributed systems.
Sung-Wook Ryu, Eul-Gyu Im, B. Clifford Neuman
COMPSAC3
2003 Integrated Access Control and Intrusion Detection for Web Servers
abstract
Current intrusion detection systems work in isolation front access control for the application the systems aim to protect. The lack of coordination and inter-operation between these components prevents detecting and responding to ongoing attacks in real time, before they cause damage. To address this, we apply dynamic authorization techniques to support fine-grained access control and application level intrusion detection and response capabilities. This paper describes our experience with integration of the Generic Authorization and Access Control API (GAA-API) to provide dynamic intrusion detection and response for the Apache Web Server The GAA-API is a generic interface which may be used to enable such dynamic authorization and intrusion response capabilities for many applications.
Tatyana Ryutov, B. Clifford Neuman
ICDCS2
2003 Integrated Access Control and Intrusion Detection for Web Servers
abstract
Current intrusion detection systems work in isolation from access control for the application the systems aim to protect. The lack of coordination and interoperation between these components prevents detecting and responding to ongoing attacks in real-time before they cause damage. To address this, we apply dynamic authorization techniques to support fine-grained access control and application level intrusion detection and response capabilities. This paper describes our experience with integration of the Generic Authorization and Access Control API (GAA-API) to provide dynamic intrusion detection and response for the Apache Web server. The GAA-API is a generic interface which may be used to enable such dynamic authorization and intrusion response capabilities for many applications.
Tatyana Ryutov, B. Clifford Neuman
IEEE Trans. Parallel Distributed Syst.2
2001 Condition-Driven Integration of Security Services
B. Clifford Neuman
ACISP1
1999 The Performance of a Reliable, Request-Response Transport Protocol
abstract
This paper studies the behavior of ARDP, a request response transport protocol, when operating in a shared communication infrastructure like the Internet. Our experiments demonstrate that ARDP backs off in the presence of congestion, yet tries to take advantage of available bandwidth. We also show that ARDP is well-behaved when competing for network resources with TCP.
Nader Salehi, Katia Obraczka, B. Clifford Neuman
ISCC3
1998 Authorization for Metacomputing Applications
abstract
One of the most difficult problems to be solved by metacomputing systems is to ensure strong authentication and authorization. The problem is complicated since the hosts involved in a metacomputing environment often span multiple administrative domains, each with its own security policy. This paper presents a distributed authorization model used by our resource allocation system, the Prospero resource manager. The main components of our design are extended access control lists (EACLs) and a general authorization and access application programming interface (GAA API). EACLs extend conventional ACLs to allow conditional restrictions on access rights. In the case of the Prospero resource manager, specific restrictions include limits on the computational resources to be consumed and on the characteristics of the applications to be executed by the system, such as name, version or endorser. The GAA API provides a general framework for applications to access the EACLs. We have built a prototype of the system.
Grig Gheorghiu, Tatyana Ryutov, B. Clifford Neuman
HPDC3
1998 Implementation Issues for E-Commerce
B. Clifford Neuman
NDSS1
1996 A flexible distributed authorization protocol
abstract
While there has been considerable effort in creating a single sign-on solution for interoperability among authentication methods, such interoperability across authorization methods has received little attention. This paper presents a flexible distributed authorization protocol that provides the full generality of restricted proxies while supporting the functionality of and interoperability with existing authorization models including OSF DCE and SESAME V2. Our authorization protocol includes a delegation method that is well suited for certain electronic commerce applications.
Jonathan T. Trostle, B. Clifford Neuman
NDSS2
1995 Security, Payment, and Privacy for Network Commerce (Invited Paper)
abstract
As the Internet is used to a greater extent in business, issues of protection and privacy will have more importance. Users and organizations must have the ability to control reads and writes to network accessible information, they must be assured of the integrity and confidentiality of the information accessed over the net, and they must have a means to determine the security, competence, and honesty of the commercial service providers with which they interact. They must also be able to pay for purchases made on the network, and they should be free from excessive monitoring of their activities. This paper discusses characteristics of the Internet that make it difficult to provide such assurances and surveys some of the techniques that can used to protect users of the network.>
B. Clifford Neuman
IEEE J. Sel. Areas Commun.1
1994 Endorsements, Licensing, and Insurance for Distributed System Services
abstract
Clients in a distributed system place their confidence in many servers, and servers themselves rely on other servers for file storage, authentication, authorization, and payment. When a system spans administrative boundaries it becomes harder to assess the security and competence of potential service providers. This paper examines the issue of confidence in large distributed systems.
Gennady Medvinsky, Charlie Lai, B. Clifford Neuman
CCS3
1994 The Prospero Resource Manager: A scalable framework for processor allocation in distributed systems
abstract
Abstract Existing techniques for allocating processors in parallel and distributed systems are not suitable for use in large distributed systems. In such systems, dedicated multiprocessors should exist as an integral component of the distributed system, and idle processors should be available to applications that need them. The Prospero Resource Manager (PRM) is a scalable resource allocation system that supports the allocation of processing resources in large networks and on multiprocessor systems. PRM employs three types of managers‐the job manager, the system manager and the node manager‐to manage resources in a distributed system. Multiple independent instances of each type of manager exist, reducing bottlenecks. When making scheduling decisions each manager utilizes information most closely associated with the entities for which it is responsible.
B. Clifford Neuman, Santosh Rao
Concurr. Pract. Exp.1
1993 NetCash: A Design for Practical Electronic Currency on the Internet
abstract
Licensing is a topic of increasing importance for software publishers and users. More and more, the magnitude of financial transfers between these two partners are determined by some electronic licensing service being part of the system on which the licensed software is running. In order to ease the use and management of such licensing schemes and to enable economic software usage in enterprise-wide computer systems through flexible and fair billing structures, various organizations are working on formulating requirements, defining architectures, and building standard interfaces for so called license brokerage systems. The trustworthiness of these services is essential because large amounts of money can depend on them. Most of these licensing services are currently operating independently of access control and rely on proprietary and unpublished security algorithms. This paper proposes an extension of access control to integrate licensing called Stateful Access Control and it addresses some aspects of virus protection.
Gennady Medvinsky, B. Clifford Neuman
CCS2
1993 Resource Management for Distributed Parallel Systems
abstract
Multiprocessor systems should exist in the larger context of distributed systems, allowing multiprocessor resources to be shared by those that need them. Unfortunately, typical multiprocessor resource management techniques do not scale to large networks. The Prospero Resource Manager (PRM) is a scalable resource allocation system that supports the allocation of processing resources in large networks and multiprocessor systems. To manage resources in such distributed parallel systems, PRM employs three types of managers: system managers, job managers, and node managers. There exist multiple independent instances of each type of manager, reducing bottlenecks. The complexity of each manager is further reduced because each is designed to utilize information at an appropriate level of abstraction.>
B. Clifford Neuman, Santosh Rao
HPDC1
1993 Proxy-Based Authorization and Accounting for Distributed Systems
abstract
A unified model is presented for authentication, authorization, and accounting that is based on proxies. It is shown that the proxy model for authorization can be used to support a wide range of authorization and accounting mechanisms. The proxy model strikes a balance between access-control-list anti capability-based mechanisms, allowing each to be used where appropriate and allowing their use in combination. The author describes how restricted proxies can be supported using existing authentication methods.>
B. Clifford Neuman
ICDCS1