Vipin Swarup

dblp:36/2914 · DBLP profile ↗
← Back
12ranked-venue papers
1as first author
3since 2021 · last 2025
0000-0002-7892-4743ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 Detecting Anomalous Communication Behaviors in Dynamically Evolving Networked Systems
Mehedi Hassan, M. Engin Tozal, Vipin Swarup, Steven Noel, Raju N. Gottumukkala, Vijay Raghavan 0001
IEEE Trans. Inf. Forensics Secur.3
2022 A Formal Model for Credential Hopping Attacks
Massimiliano Albanese, Karin Johnsgard, Vipin Swarup
ESORICS (1)3
2022 Dependency-Based Link Prediction for Learning Microsegmentation Policy
Steven Noel, Vipin Swarup
ICICS2
2006 Redirection policies for mission-based information sharing
abstract
When an access decision function denies a data access request by a mission participant in a mission-critical situation, the mission often suffers. In this paper, we propose a sharing control mechanism that computes and executes requests that are mission-related to denied requests. We extend the Flexible Authorization Framework (FAF)with predicates and hierarchies that permit us to specify authorization rules over denied requests and mission-specific relationships. We illustrate our techniques using a prototypical information sharing scenario, namely an emergency first-responder scenario.
David R. Keppler, Vipin Swarup, Sushil Jajodia
SACMAT2
2005 Fingerprinting Relational Databases: Schemes and Specialties
abstract
In this paper, we present a technique for fingerprinting relational data by extending Agrawal et al.'s watermarking scheme. The primary new capability provided by our scheme is that, under reasonable assumptions, it can embed and detect arbitrary bit-string marks in relations. This capability, which is not provided by prior techniques, permits our scheme to be used as a fingerprinting scheme. We then present quantitative models of the robustness properties of our scheme. These models demonstrate that fingerprints embedded by our scheme are detectable and robust against a wide variety of attacks including collusion attacks.
Yingjiu Li, Vipin Swarup, Sushil Jajodia
IEEE Trans. Dependable Secur. Comput.2
2004 Defending Against Additive Attacks with Maximal Errors in Watermarking Relational Databases
abstract
Recently, several database watermarking techniques have been developed to fight against database piracy. In watermarking, a database owner’s identification information is embedded into a database such that proof of ownership can be established by detecting the information in pirated data. However, most watermarking systems are vulnerable to the severe threat of additive attacks and this threat has not been studied formally. In an additive attack, a pirate inserts an additional watermark such that the proof of ownership becomes ambiguous. In this paper, we present an effective approach to defending against additive attacks. Our strategy is to raise the errors introduced during watermark insertion to a predetermined threshold such that any additive attack would introduce more errors than the threshold. Exceeding the error threshold means that the pirated data is less useful or less competitive; thus, the owner does not need to claim ownership for such pirated data. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Yingjiu Li, Vipin Swarup, Sushil Jajodia
DBSec2
2004 Remediation Graphs for Security Patch Management
abstract
Attackers are becoming proficient at reverse engineering security patches and then creating worms or viruses that rapidly attack systems that have not applied the patches. Automated patch management systems are being developed to address this threat. A central function of a patch management system is to decide which patches to install on a computer and to determine the sequence of actions that will cause them to be installed.In this paper, we introduce the notion of a patch remediation graph that depicts ways in which a system can be patched so that the system eventually reaches a desired, secure state. We present a language for specifying patch dependencies, patch conflicts, and user preferences for patch configurations. We then present efficient algorithms that construct and analyze remediation graphs from current computer configurations and various patch constraints. Our analysis algorithms use the graphs to compute maximal preferred configurations and sequences of patch actions that, if executed, will transition computers safely to those configurations.
Vipin Swarup
SEC1
2003 Forum Session: Security for Wireless Sensor Networks
abstract
Wireless networks of low-power sensing devices are poised to become a ubiquitous part of the computing landscape. Proposed applications of these networks range from health care to warfare. The challenge for the information security community is to develop the common security services (confidentiality, integrity, etc.) for sensor networks in a manner that meets the very strict resource constraints of these devices. This forum will describe a broad range of on-going research efforts in order to acquaint the general information security community with the issues and concerns of sensor net security.
David Carman, Daniel Coffin, Bruno Dutertre, Vipin Swarup, Ronald J. Watro
ACSAC4
2003 Securely sharing neuroimagery
abstract
Shared scientific data, such as neuroimagery, offers great benefits to science. However, data owners must exercise custodial responsibilities which can conflict with the unhindered sharing of their data. Given simple choices of sharing widely or not at all, the result will frequently be no sharing. We hypothesize that neuroimagery sharing will be enhanced if data owners are provided with well-defined intermediate levels of data visibility. In this paper, we describe a broadly applicable data sharing model, Structured Sharing Communities (SSC), in which data becomes incrementally visible to communities structured as a complete partial-order; the associated properties of Privacy and Fairness regulate access to shared data. Within SSC, a customized policy space is defined capturing the sharing relationships among specific collaborators.
Kenneth P. Smith, Vipin Swarup, Sushil Jajodia, Donald B. Faatz, Todd Cornett, Jeffrey Hoyt
CIKM2
2003 Constructing a virtual primary key for fingerprinting relational data
abstract
Agrawal and Kiernan's watermarking technique for database relations [1] and Li et al's fingerprinting extension [6] both depend critically on primary key attributes. Hence, those techniques cannot embed marks in database relations without primary key attributes. Further, the techniques are vulnerable to simple attacks that alter or delete the primary key attribute.This paper proposes a new fingerprinting scheme that does not depend on a primary key attribute. The scheme constructs virtual primary keys from the most significant bits of some of each tuple's attributes. The actual attributes that are used to construct then virtual primary key differ from tuple to tuple. Attribute selection is based on a secret key that is known to the merchant only. Further, the selection does not depend on an apriori ordering over the attributes, or on knowledge of the original relation or fingerprint codeword.The virtual primary keys are then used in fingerprinting as in previous work [6]. Rigorous analysis shows that, with high probability, only embedded fingerprints can be detected and embedded fingerprints cannot be modified or erased by a variety of attacks. Attacks include adding, deleting, shuffling, or modifying tuples or attributes (including a primary key attribute if one exists), guessing secret keys, and colluding with other recipients of a relation.
Yingjiu Li, Vipin Swarup, Sushil Jajodia
Digital Rights Management Workshop2
1996 Security for Mobile Agents: Authentication and State Appraisal
William M. Farmer, Joshua D. Guttman, Vipin Swarup
ESORICS3
1993 Integration of security services into the NORAD/USSPACECOM technical infrastructure: a case study
abstract
There is a growing trend to describe information system architectures in terms of reference models. This paper is a case study of how security services and mechanisms were integrated into one specific reference model, the NORAD/USSPACECOM Technical Infrastructure (N/U TI). The identification of security services and their placement in the N/U TI was motivated by a preliminary set of N/U security policy objectives. Issues arising from the integration of security into open systems standards are also identified.>
Deborah J. Bodeau, Vipin Swarup
ACSAC2