EDBT 2026 Demo / reviewers in the wild / expert
James Kirby
dblp:33/5006
· DBLP profile ↗
7ranked-venue papers
1as first author
1since 2021 · last 2022
0000-0002-0502-5245ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 3Theory of computation · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
1 paper |
Software-defined and programmable networks · 67% Network management and operations · 33% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Cloud and datacenter computing · 100% | |
| Software engineering, system software, and programming languages
3 papers |
Requirements engineering and software design · 100% |
Topics — the 11 heaviest of 15, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network management and operations
policy-based management |
0.6 | 1 | 2022 | Object Oriented Policy Conflict Checking Framework in Cloud Networks (OOPC) · IEEE Trans. Dependable Secur. Comput. 2022 |
Software-defined and programmable networks › network policy
policy conflict detection |
0.6 | 1 | 2022 | Object Oriented Policy Conflict Checking Framework in Cloud Networks (OOPC) · IEEE Trans. Dependable Secur. Comput. 2022 |
Software-defined and programmable networks › network function virtualization
virtualized network functions |
0.6 | 1 | 2022 | Object Oriented Policy Conflict Checking Framework in Cloud Networks (OOPC) · IEEE Trans. Dependable Secur. Comput. 2022 |
Requirements engineering and software design
requirements specification |
0.0 | 2 | 1998 | SCR*: A Toolset for Specifying and Analyzing Software Requirements · CAV 1998 The SCR Method for Formally Specifying, Verifying, and Validating Requirements: Tool Support · ICSE 1997 |
Requirements engineering and software design › inconsistency management
consistency checking |
0.0 | 1 | 1998 | Using Abstraction and Model Checking to Detect Safety Violations in Requirements Specifications · IEEE Trans. Software Eng. 1998 |
Requirements engineering and software design
requirements analysis |
0.0 | 1 | 1998 | SCR*: A Toolset for Specifying and Analyzing Software Requirements · CAV 1998 |
Requirements engineering and software design › requirements analysis
requirements specification analysis |
0.0 | 1 | 1998 | Using Abstraction and Model Checking to Detect Safety Violations in Requirements Specifications · IEEE Trans. Software Eng. 1998 |
Automated reasoning and model checking › model checking › state space reduction
abstract model checking |
0.0 | 1 | 1998 | Using Abstraction and Model Checking to Detect Safety Violations in Requirements Specifications · IEEE Trans. Software Eng. 1998 |
Automated reasoning and model checking
model checking |
0.0 | 1 | 1998 | Using Abstraction and Model Checking to Detect Safety Violations in Requirements Specifications · IEEE Trans. Software Eng. 1998 |
Requirements engineering and software design
formal specification |
0.0 | 1 | 1997 | The SCR Method for Formally Specifying, Verifying, and Validating Requirements: Tool Support · ICSE 1997 |
Requirements engineering and software design › requirements engineering
requirements verification and validation |
0.0 | 1 | 1997 | The SCR Method for Formally Specifying, Verifying, and Validating Requirements: Tool Support · ICSE 1997 |
Methods — techniques the papers use, named apart from their topics
object-oriented dependency analysis · 1.1VNF graph · 1.1simulation · 0.0model checking · 0.0abstraction · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Object Oriented Policy Conflict Checking Framework in Cloud Networks (OOPC)abstractSoftware-Defined Networking (SDN) provides a programmable framework for multi-tenant cloud network management and orchestration. The end-to-end packet processing induced by virtual network functions (VNFs) like stateless firewall, load balancer, intrusion detection, and prevention system (IDPS) in a network involves the processing of network traffic through security policies matching the traffic pattern defined in security rules of individual VNF. The conflicting rules in terms of traffic match and conflicting actions can lead to a) violation of security requirements (authentication and authorization bypass) b) mission requirements - the presence of redundant rules (increased latency, reduced throughput). We present a new object-oriented policy conflict detection and resolution framework (OOPC), which analyzes the rule dependency relationships between the rules of heterogeneous virtual network functions (VNFs) and creates a VNF-Graph. The rules are analyzed using object-oriented dependencies between the address space and actions of VNF rules. OOPC utilizes a compact VNF-Graph, which leads to a reduction in search complexity when analyzing new security policies. Our security policy composition in our framework OOPC achieves 37 percent lower latency in policy graph composition than previous work. The proposed solution performs 20 percent faster security policy conflict detection on a cloud network with 60k OpenFlow rules than prior frameworks that serve a similar purpose. Ankur Chowdhary, Abdulhakim Sabur, Dijiang Huang, Myong H. Kang, James Kirby |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2012 | Separation virtual machine monitorsabstractSeparation kernels are the strongest known form of separation for virtual machines. We agree with NSA's Information Assurance Directorate that while separation kernels are stronger than any other alternative, their construction on modern commodity hardware is no longer justifiable. This is because of orthogonal feature creep in modern platform hardware. We introduce the separation VMM as a response to this situation and explain how we prototyped one. John P. McDermott, Bruce E. Montrose, Margery Li, James Kirby, Myong H. Kang |
ACSAC | 4 |
| 2008 | Re-engineering Xen internals for higher-assurance security
John P. McDermott, James Kirby, Bruce E. Montrose, Travis Johnson, Myong H. Kang |
Inf. Secur. Tech. Rep. | 2 |
| 1999 | SCR: A Practical Approach to Building a High Assurance COMSEC SystemabstractTo date, the tabular based SCR (Software Cost Reduction) method has been applied mostly to the development of embedded control systems. The paper describes the successful application of the SCR method, including the SCR* toolset, to a different class of system, a COMSEC (Communications Security) device called CD that must correctly manage encrypted communications. The paper summarizes how the tools in SCR* were used to validate and to debug the SCR specification and to demonstrate that the specification satisfies a set of critical security properties. The development of the CD specification involved many tools in SCR*: a specification editor, a consistency checker, a simulator, the TAME interface to the theorem prover PVS, and various other analysis tools. Our experience provides evidence that use of the SCR* toolset to develop high quality requirements specifications of moderately complex COMSEC systems is both practical and low cost. James Kirby, Myla Archer, Constance L. Heitmeyer |
ACSAC | 1 |
| 1998 | SCR*: A Toolset for Specifying and Analyzing Software Requirements
Constance L. Heitmeyer, James Kirby, Bruce G. Labaw, Ramesh Bharadwaj |
CAV | 2 |
| 1998 | Using Abstraction and Model Checking to Detect Safety Violations in Requirements SpecificationsabstractExposing inconsistencies can uncover many defects in software specifications. One approach to exposing inconsistencies analyzes two redundant specifications, one operational and the other property-based, and reports discrepancies. This paper describes a "practical" formal method, based on this approach and the SCR (software cost reduction) tabular notation, that can expose inconsistencies in software requirements specifications. Because users of the method do not need advanced mathematical training or theorem-proving skills, most software developers should be able to apply the method without extraordinary effort. This paper also describes an application of the method which exposed a safety violation in the contractor-produced software requirements specification of a sizable, safety-critical control system. Because the enormous state space of specifications of practical software usually renders direct analysis impractical, a common approach is to apply abstraction to the specification. To reduce the state space of the control system specification, two "pushbutton" abstraction methods were applied, one which automatically removes irrelevant variables and a second which replaces the large, possibly infinite, type sets of certain variables with smaller type sets. Analyzing the reduced specification with the model checker Spin uncovered a possible safety violation. Simulation demonstrated that the safety violation was not spurious but an actual defect in the original specification. Constance L. Heitmeyer, James Kirby, Bruce G. Labaw, Myla Archer, Ramesh Bharadwaj |
IEEE Trans. Software Eng. | 2 |
| 1997 | The SCR Method for Formally Specifying, Verifying, and Validating Requirements: Tool SupportabstractNo abstract available. Constance L. Heitmeyer, James Kirby, Bruce G. Labaw |
ICSE | 2 |