Giovanni Russello

dblp:43/4123 · DBLP profile ↗
← Back
64ranked-venue papers
11as first author
22since 2021 · last 2026
0000-0001-6987-0803ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 41 · 5 first-author · 16 since 2021Computer networks · 6 · 2 since 2021Software engineering, systems software and programming languages · 6 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Genius-Coin: A Deployable Crypto Reward System for Student Engagement
abstract
Student disengagement remains a persistent challenge in higher education. This paper presents Genius-Coin, an open-source, self-hostable blockchain courseware designed to promote student motivation and engagement through gamification and token-economy mechanisms. The system connects verifiable learning activities to digital rewards: classroom attendance is recorded through dynamic QR code scanning, while online participation from learning management and discussion platforms is also captured. Once participation is verified, digital tokens and achievement badges are automatically distributed through smart contracts and can later be redeemed for rewards through an online store. Designed for practical institutional use, Genius-Coin supports straightforward deployment on institutional servers and provides a dedicated wallet application that simplifies student onboarding. A pilot deployment with 65 postgraduate students suggests that the system fostered intrinsic engagement, as many students appeared more motivated to attend class and participate in course activities than to redeem tokens for external rewards; only 33.1% of distributed tokens were redeemed.
Elliott Wen, Jun O. Seo, Yousong Sun, Yu-Cheng Tu 0001, Paul Denny 0001, Giovanni Russello
ITiCSE (2)6
2026 AGentVLM: Access control policy generation and verification framework with language models
abstract
• We introduce AGentVLM, a novel access control policy generation and verification framework. • We introduce a novel access control-specific structured information extraction method for translating complex natural language access requirements into access control policies. • We introduce a novel access control policy verification technique. • We evaluate AGentVLM, showing it achieves state-of-the-art accuracy. • We release two annotated datasets, addressing the data scarcity. Manual generation of access control policies from high-level organizational requirements is labor-intensive and error-prone, often leading to critical failures and data breaches. While automated frameworks have been proposed, existing approaches struggle with complex access requirements due to poor domain adaptation, limiting their accuracy. To address these challenges, we propose AGentVLM, a novel access control policy generation and verification framework based on small, open-source language models (LMs). Our framework enables its efficient on-premise deployment, preserving data confidentiality by avoiding reliance on third-party black-box LMs. AGentVLM excels in identifying natural language access control policies (NLACPs) from high-level requirements, achieving an average F1 score of 90.6 %. Unlike existing frameworks limited to generating simple policies with three components (subject, action, resource), AGentVLM effectively extracts complex elements such as purposes and conditions using an access control-specific structured information extraction technique. This method captures both word-level and semantic information at the same time from NLACPs, leading to a state-of-the-art policy generation F1 score of 80.6 %. Additionally, AGentVLM introduces a verification technique that provides actionable feedback, allowing administrators to refine inaccurate policies before deployment. To support future research, we also release two annotated datasets addressing the scarcity of domain-specific data.
Sakuna Harinda Jayasundara, Nalin Arachchilage, Giovanni Russello
J. Inf. Secur. Appl.3
2026 Toward Reliable and Secure Cloud Services With Fault-Tolerant Searchable Encryption
abstract
Dynamic Searchable Symmetric Encryption (DSSE) plays a crucial role in secure cloud-based database systems, as it enables efficient keyword search and dynamic updates over encrypted data. However, practical deployment of DSSE schemes faces two significant challenges. First, clients may inadvertently perform faulty updates—such as re-adding an existing keyword-identifier pair or attempting to delete a non-existent one—which can compromise the correctness of subsequent search results. Second, even with correctly issued updates, malicious servers may return incorrect or incomplete search results, undermining data integrity. To address these challenges, we propose FVDSSE, the first fault-tolerant DSSE scheme that tolerates client-side operational faults and provides result verifiability against malicious servers. Moreover, it simultaneously ensures strong privacy by guaranteeing forward and backward privacy—two essential properties for any practical DSSE. To further optimize performance, we present FVDSSE-C, an enhanced variant that leverages caching techniques. Experimental evaluations on a real-world dataset show that FVDSSE-C achieves up to 130× improvement in search efficiency and 3× reduction in communication overhead compared to the state-of-the-art scheme (YCR22-C).
Cong Zuo 0001, Bingjing Wang, Jianghua Liu 0001, Shujie Cui, Jun Shao 0001, Huaxiong Wang, Liehuang Zhu, Giovanni Russello
IEEE Trans. Serv. Comput.8
2025 Precision Email Simulator for Research on Safety-Critical Phishing Behaviour
abstract
Email is ubiquitous, and in the context of phishing, it becomes critical, as risky behaviours like clicking on phishing links or downloading malicious files can lead to severe consequences.While much research exists on phishing susceptibility, there is still a gap in understanding factors that influence user micro-behaviour when interacting with phishing emails.To address this, we offer a tool, the Precision Email Simulator, to support phishing researchers, as well as considerations in conceptualising controlled 'experimental simulation' studies, which are currently underutilised in phishing research.The Precision Email Simulator simulates real-world email inboxes and tracks precision user data, such as time spent on messages and eye-tracking for key areas like URLs and sender addresses.We discuss the practical uses of our simulator, and provide recommendations and guidelines of using our email simulator. CCS Concepts• Security and privacy → Phishing
Sijie Zhuo, Robert Biddle, Giovanni Russello, Danielle Lottridge
CHI3
2025 Guard-GBDT: Efficient Privacy-Preserving Approximated GBDT Training on Vertical Dataset
abstract
In light of increasing privacy concerns and stringent legal regulations, using secure multiparty computation (MPC) to enable collaborative GBDT model training among multiple data owners has garnered significant attention. Despite this, existing MPC-based GBDT frameworks face efficiency challenges due to high communication costs and the computation burden of non-linear operations, such as division and sigmoid calculations. In this work, we introduce Guard-GBDT, an innovative framework tailored for efficient and privacy-preserving GBDT training on vertical datasets. Guard-GBDT bypasses MPC-unfriendly division and sigmoid functions by using more streamlined approximations and reduces communication overhead by compressing the messages exchanged during gradient aggregation. We implement a prototype of Guard-GBDT and extensively evaluate its performance and accuracy on various real-world datasets. The results show that Guard-GBDT outperforms state-of-the-art HEP-XGB (CIKM’21) and SiGBDT (ASIA CCS’24) by up to $2.71 \times$ and $12.21 \times$ on LAN network and up to $2.7 \times$ and $8.2 \times$ on WAN network. Guard-GBDT also achieves comparable accuracy with SiGBDT and plaintext XGBoost (better than HEP-XGB), which exhibits a deviation of ±1% to ±2% only. Our implementation code is provided at https://github.com/XidianNSS/Guard-GBDT.git
Anxiao Song, Shujie Cui, Jianli Bai, Ke Cheng 0001, Yulong Shen 0001, Giovanni Russello
RAID6
2025 Language as Lure: A Naturalistic Study on Pasifika Phishing Susceptibility
Eric Spero 0001, Isa Seow, Lucas Betts, Eddie Fuatimau, Robert Biddle, Danielle Lottridge, Giovanni Russello
SOUPS7
2025 XGT: Fast and Secure Decision Tree Training and Inference on GPUs
abstract
The decision tree (DT) model is widely usedin various applications due to its versatility, speed, and interpretability. However, outsourcing DT training and inference to cloud platforms raises data privacy concerns. While significant strides have been made in developing private DT training and inference using cryptography such as Secure Multi-Party Computation (MPC), the performance is still not ideal in real-world applications. Only a few recent works have explored using GPUs to enhance the performance of MPC-based deep learning. Nevertheless, data-dependent operations and the high communication costs inherent in MPC-based DT make the integration of GPUs a challenge. We introduce the eXpress GPU-based Tree (XGT), a fast MPC-based framework for private DT training and inference on GPUs.XGTconverts the majority of operations in training and inference into parallelizable matrix operations, supplemented by various optimizations, including matrix dimension reductions. This innovative design leads to substantial reductions in communication overhead while maintaining the critical property of obliviousness.XGTalso achieves a stronger security guarantee, where all data items, the tree shape, access patterns, and data distributions generated during the training and inference are protected.XGTonly reveals the tree depth. The experimental results show thatXGTis up to$278{\times }$faster than the previous most efficient CPU-based approach.XGToutperforms the latest GPU-based DT work by$41{\times }$. For inference,XGTis up to$2,800{\times }$faster than previous CPU-based inference schemes and at least$18 \times$faster than GPU-based.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello
IEEE Trans. Dependable Secur. Comput.7
2024 Keep Me Updated: An Empirical Study on Embedded JavaScript Engines in Android Apps
abstract
Although JavaScript (JS) has been widely used in mobile development, little is known about the security implications of utilizing JS engines shipped as native app libraries. In this paper, we conduct an empirical study by designing a JS-Inspector pipeline to identify the embedded JS engines in Android apps and assess their security. We investigate over 65,000 Android apps released between Jan 2018 and July 2023. The results show that many popular apps use embedded JS engines, and their engines remain outdated for extended periods. Moreover, approximately 85% of apps have not received updates since their initial release. As such, over 70% of the identified embedded engines are vulnerable to known exploits. We further present case studies of popular apps catering to millions of users. By exploiting their unpatched JS engines through various strategies, such as man-in-the-middle attacks, intent abuse, and malicious mini-apps, we can easily seize control of the targeted apps and execute arbitrary code. This work highlights critical security concerns associated with embedded JS engines. It emphasizes the urgency for timely updates and enhanced security measures during app development.
Elliott Wen, Jiaxiang Zhou, Xiapu Luo, Giovanni Russello, Jens Dietrich 0001
MSR4
2024 GTree: GPU-friendly Privacy-preserving Decision Tree Training and Inference
abstract
Outsourcing Decision tree (DT) training and inference to cloud platforms raises privacy concerns. Recent Secure Multi-Party Computation (MPC)-based methods are hindered by heavy overhead. Few recent studies explored GPUs to improve MPC-protected deep learning, yet integrating GPUs into MPC-protected DT with massive data-dependent operations remains challenging, raising question: can MPC-protected DT training and inference fully leverage GPUs for optimal performance?We present GTree, the first scheme that exploits GPU to accelerate MPC-protected secure DT training and inference. GTree is built across 3 parties who jointly perform DT training and inference with GPUs. GTree is secure against semi-honest adversaries, ensuring that no sensitive information is disclosed. GTree offers enhanced security than prior solutions, which only reveal tree depth and data size while prior solutions also leak tree structure. With our oblivious array access, access patterns on GPU are also protected. To harness the full potential of GPUs, we design a novel tree encoding method and craft our MPC protocols into GPU-friendly versions. GTree achieves ~11× and ~21× improvements in training SPECT and Adult datasets, compared to prior most efficient CPU-based work. For inference, GTree outperforms the prior most efficient work by 126× when inferring 104instances with a 7-level tree.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello
TrustCom7
2023 Mostree: Malicious Secure Private Decision Tree Evaluation with Sublinear Communication
abstract
A private decision tree evaluation (PDTE) protocol allows a feature vector owner (FO) to classify its data using a tree model from a model owner (MO) and only reveals an inference result to the FO. This paper proposes Mostree, a PDTE protocol secure in the presence of malicious parties with sublinear communication. We design Mostree in the three-party honest-majority setting, where an (untrusted) computing party (CP) assists the FO and MO in the secure computation. We propose two low-communication oblivious selection (OS) protocols by exploiting nice properties of three-party replicated secret sharing (RSS) and distributed point function. Mostree combines OS protocols with a tree encoding method and three-party secure computation to achieve sublinear communication. We observe that most of the protocol components already maintain privacy even in the presence of a malicious adversary, and what remains to achieve is correctness. To ensure correctness, we propose a set of lightweight consistency checks and seamlessly integrate them into Mostree. As a result, Mostree achieves sublinear communication and malicious security simultaneously. We implement Mostree and compare it with the state-of-the-art. Experimental results demonstrate that Mostree is efficient and comparable to semi-honest PDTE schemes with sublinear communication. For instance, when evaluated on the MNIST dataset in a LAN setting, Mostree achieves an evaluation using approximately 768 ms with communication of around 168 KB.
Jianli Bai, Xiangfu Song, Qifan Wang 0003, Shujie Cui, Ee-Chien Chang, Giovanni Russello
ACSAC7
2023 Selective Encryption Framework for Securing Communication in Industrial Control Systems
abstract
Industrial Control Systems (ICS) implement a distributed process control framework with legacy controllers and proprietary protocols, enabling a wide range of cyber-attacks. The ICS research community and industrial security practitioners recommend implementing TLS/DTLS or bump-in-the-wire techniques for communicating confidential information. In this paper, we discuss how such techniques fail to provide the purpose-built security required in control applications. We examine the proprietary application-layer protocols and how they access the controller memory for performing read/write operations and claim that custom-made ICS security solutions require application-level access to the controller. To this end, we propose SelEnc, a general-purpose modular framework for securely communicating a subset of control information, deemed critical by the process engineer of a controlled environment, with minimal access to the controller memory. We provide a proof-of-concept implementation of the proposed framework over an example testbed and evaluate our construction with two use cases and five different datasets. Our micro-benchmarks indicate a significant reduction in computational overhead (less than 1.5% of overhead incurred due to TLS and other state-of-art approaches), with guarantees of purpose-built security acknowledged at the target control environment.
Shalini Banerjee, Tariq Khan, John H. Castellanos, Giovanni Russello
ICC4
2023 CryptoMask: Privacy-Preserving Face Recognition
Jianli Bai, Xiangfu Song, Shujie Cui, Giovanni Russello
ICICS7
2023 AppBox: A Black-Box Application Sandboxing Technique for Mobile App Management Solutions
abstract
Several Mobile Device Management (MDM) and Mobile Application Management (MAM) services have been launched on the market. However, these services suffer from two important limitations: reduced granularity and need for app developers to include third party SDKs. We present AppBox, a novel black-box app-sandboxing solution for app customisation for stock Android devices. AppBox enables enterprises to select any app, even highly-obfuscated, from any market and perform a set of target customisations by means of fine-grained security policies. We have implemented and tested AppBox on various smartphones and Android versions. The evaluation shows that AppBox can effectively enforce fine-grained policies on a wide set of existing apps, with an acceptable overhead.
Maqsood Ahmad 0001, Francesco Bergadano, Valerio Costamagna, Bruno Crispo, Giovanni Russello
ISCC5
2023 HT2ML: An efficient hybrid framework for privacy-preserving Machine Learning using HE and TEE
abstract
Outsourcing Machine Learning (ML) tasks to cloud servers is a cost-effective solution when dealing with distributed data. However, outsourcing these tasks to cloud servers could lead to data breaches. Secure computing methods, such as Homomorphic Encryption (HE) and Trusted Execution Environments (TEE), have been used to protect outsourced data. Nevertheless, HE remains inefficient in processing complicated functions (e.g., non-linear functions) and TEE (e.g., Intel SGX) is not ideal for directly processing ML tasks due to side-channel attacks and parallel-unfriendly computation. In this paper, we propose a hybrid framework integrating SGX and HE, called HT2ML, to protect user's data and models. In HT2ML, HE-friendly functions are protected with HE and performed outside the enclave, while the remaining operations are performed inside the enclave obliviously. HT2ML leverages optimised HE matrix multiplications to accelerate HE computations outside the enclave while using oblivious blocks inside the enclave to prevent access-pattern-based attacks. We evaluate HT2ML using Linear Regression (LR) training and Convolutional Neural Network (CNN) inference as two instantiations. The performance results show that HT2ML is up to ∼11× faster than HE only baseline with 6-dimensional data in LR training. For CNN inference, HT2ML is ∼196× faster than the most recent approach (Xiao et al., ICDCS'21).
Qifan Wang 0003, Lei Zhou 0023, Jianli Bai, Yun Sing Koh, Shujie Cui, Giovanni Russello
Comput. Secur.6
2023 Result-pattern-hiding Conjunctive Searchable Symmetric Encryption with Forward and Backward Privacy
abstract
Dynamic searchable symmetric encryption (DSSE) enables the data owner to outsource its database (document sets) to an untrusted server and make searches and updates securely and efficiently. Conjunctive DSSE can process conjunctive queries that return the documents containing multiple keywords. However, a conjunctive search could leak the keyword pair result pattern (KPRP), where attackers can learn which documents contain any two keywords involved in the query. File-injection attack shows that KPRP can be utilized to recover searched keywords. To protect data effectively, DSSE should also achieve forward privacy, i.e., hides the link between updates to previous searches, and backward privacy, i.e., prevents deleted entries being accessed by subsequent searches. Otherwise, the attacker could recover updated/searched keywords and records. However, no conjunctive DSSE scheme in the literature can hide KPRP in sub-linear search efficiency while guaranteeing forward and backward privacy. In this work, we propose the first sub-linear KPRP-hiding conjunctive DSSE scheme (named HDXT) with both forward and backward privacy guarantees. To achieve these three security properties, we introduce a new cryptographic primitive: Attribute-updatable Hidden Map Encryption (AUHME). AUHME enables HDXT to efficiently and securely perform conjunctive queries and update the database in an oblivious way. In comparison with previous work that has weaker security guarantees, HDXT shows comparable, and in some cases, even better performance.
Dandan Yuan, Cong Zuo 0001, Shujie Cui, Giovanni Russello
Proc. Priv. Enhancing Technol.4
2023 SoK: Human-centered Phishing Susceptibility
abstract
Phishing is recognized as a serious threat to organizations and individuals. While there have been significant technical advances in blocking phishing attacks, end-users remain the last line of defence after phishing emails reach their email inboxes. Most of the existing literature on this subject has focused on the technical aspects related to phishing. The factors that cause humans to be susceptible to phishing attacks are still not well-understood. To fill this gap, we reviewed the available literature and systematically categorized the phishing susceptibility variables studied. We classify variables based on their temporal scope, which led us to propose a three-stage Phishing Susceptibility Model (PSM) for explaining how humans are vulnerable to phishing attacks. This model reveals several research gaps that need to be addressed to understand and improve protection against phishing susceptibility. Our review also systematizes existing studies by their sample size and generalizability and further suggests a practical impact assessment of the value of studying variables: Some more easily lead to improvements than others. We believe that this article can provide guidelines for future phishing susceptibility research to improve experiment design and the quality of findings.
Sijie Zhuo, Robert Biddle, Yun Sing Koh, Danielle Lottridge, Giovanni Russello
ACM Trans. Priv. Secur.5
2022 Scalable Private Decision Tree Evaluation with Sublinear Communication
abstract
Private decision tree evaluation (PDTE) allows a decision tree holder to run a secure protocol with a feature provider. By running the protocol, the feature provider will learn a classification result. Nothing more is revealed to either party. In most existing PDTE protocols, the required communication grows exponentially with the tree's depth d, which is highly inefficient for large trees. This shortcoming motivated us to design a sublinear PDTE protocol with $O(d)$ communication complexity. The core of our construction is a shared oblivious selection (SOS) functionality, allowing two parties to perform a secret-shared oblivious read operation from an array. We provide two SOS protocols, both of which achieve sublinear communication and propose optimizations to further improve their efficiency. Our sublinear PDTE protocol is based on the proposed SOS functionality and we prove its security under a semi-honest adversary. We compare our protocol with the state-of-the-art, in terms of communication and computation, under various network settings. The performance evaluation shows that our protocol is practical and more scalable over large trees than existing solutions.
Jianli Bai, Xiangfu Song, Shujie Cui, Ee-Chien Chang, Giovanni Russello
AsiaCCS5
2022 EnclaveTree: Privacy-preserving Data Stream Training and Inference Using TEE
abstract
The classification service over a stream of data is becoming an important offering for cloud providers, but users may encounter obstacles in providing sensitive data due to privacy concerns. While Trusted Execution Environments (TEEs) are promising solutions for protecting private data, they remain vulnerable to side-channel attacks induced by data-dependent access patterns. We propose a Privacy-preserving Data Stream Training and Inference scheme, called EnclaveTree, that provides confidentiality for user's data and the target models against a compromised cloud service provider. We design a matrix-based training and inference procedure to train the Hoeffding Tree (HT) model and perform inference with the trained model inside the trusted area of TEEs, which provably prevent the exploitation of access-pattern-based attacks. The performance evaluation shows that EnclaveTree is practical for processing the data streams with small or medium number of features. When there are less than 63 binary features,EnclaveTree is up to ~10x and ~9 faster than naïve oblivious solution on training and inference, respectively.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ocean Wu, Yonghua Zhu, Giovanni Russello
AsiaCCS6
2022 We Can Make Mistakes: Fault-tolerant Forward Private Verifiable Dynamic Searchable Symmetric Encryption
abstract
Verifiable Dynamic Searchable Symmetric Encryption (VDSSE) enables users to securely outsource databases (document sets) to cloud servers and perform searches and updates. The verifiability property prevents users from accepting incorrect search results returned by a malicious server. However, we discover that the community currently only focuses on preventing malicious behavior from the server but ignores incorrect updates from the client, which are very likely to happen since there is no record on the client to check. Indeed most existing VDSSE schemes are not sufficient to tolerate incorrect updates from the client. For instance, deleting a nonexistent keyword-identifier pair can break their correctness and soundness. In this paper, we demonstrate the vulnerabilities of a type of existing VDSSE schemes that fail them to ensure correctness and soundness properties on incorrect updates. We propose an efficient fault-tolerant solution that can consider any DSSE scheme as a black-box and make them into a fault-tolerant VDSSE in the malicious model. Forward privacy is an important property of DSSE that prevents the server from linking an update operation to previous search queries. Our approach can also make any forward secure DSSE scheme into a fault-tolerant VDSSE without breaking the forward security guarantee. In this work, we take FAST [1] (TDSC 2020), a forward secure DSSE, as an example, implement a prototype of our solution, and evaluate its performance. Even when compared with the previous fastest forward private construction that does not support fault tolerance, the experiments show that our construction saves 9× client storage and has better search and update efficiency.
Dandan Yuan, Shujie Cui, Giovanni Russello
EuroS&P3
2021 Collusion Defender: Preserving Subscribers' Privacy in Publish and Subscribe Systems
abstract
The Publish and Subscribe (pub/sub) system is an established paradigm to disseminate the data from publishers to subscribers in a loosely coupled manner using a network of dedicated brokers. However, sensitive data could be exposed to malicious entities if brokers get compromised or hacked; or even worse, if brokers themselves are curious to learn about the data. A viable mechanism to protect sensitive publications and subscriptions is to encrypt the data before it is disseminated through the brokers. State-of-the-art approaches allow brokers to perform encrypted matching without revealing publications and subscriptions. However, if malicious brokers collude with malicious subscribers or publishers, they can learn the interests of innocent subscribers, even when the interests are encrypted. In this article, we present a pub/sub system that ensures confidentiality of publications and subscriptions in the presence of untrusted brokers. Furthermore, our solution resists collusion attacks between untrusted brokers and malicious subscribers (or publishers). Finally, we have implemented a prototype of our solution to show its feasibility and efficiency.
Shujie Cui, Sana Belguith, Pramodya De Alwis, Muhammad Rizwan Asghar, Giovanni Russello
IEEE Trans. Dependable Secur. Comput.5
2021 e-PRNU: Encrypted Domain PRNU-Based Camera Attribution for Preserving Privacy
abstract
Photo Response Non-Uniformity (PRNU) noise-based source camera attribution is a popular digital forensic method. In this method, a camera fingerprint computed from a set of known images of the camera is matched against the extracted noise of an anonymous questionable image to find out if the camera had taken the anonymous image. The possibility of privacy leak, however, is one of the main concerns of the PRNU-based method. Using the camera fingerprint (or the extracted noise), an adversary can identify the owner of the camera by matching the fingerprint with the noise of an image (or with the fingerprint computed from a set of images) crawled from a social media account. In this article, we address this privacy concern by encrypting both the fingerprint and the noise using the Boneh-Goh-Nissim (BGN) encryption scheme, and performing the matching in encrypted domain. To overcome leakage of privacy from the content of an image that is used in the fingerprint calculation, we compute the fingerprint within a trusted environment, such as ARM TrustZone. We present e-PRNU that aims at minimizing privacy loss and allows authorized forensic experts to perform camera attribution. The security analysis shows that the proposed approach is semantically secure. Experimental results show that the run-time computational overhead is 10.26 seconds when a cluster of 64 computing nodes are used.
Manoranjan Mohanty, Muhammad Rizwan Asghar, Giovanni Russello
IEEE Trans. Dependable Secur. Comput.4
2021 Privacy-preserving Dynamic Symmetric Searchable Encryption with Controllable Leakage
abstract
Searchable Encryption (SE) is a technique that allows Cloud Service Providers to search over encrypted datasets without learning the content of queries and records. In recent years, many SE schemes have been proposed to protect outsourced data. However, most of them leak sensitive information, from which attackers could still infer the content of queries and records by mounting leakage-based inference attacks, such as the count attack and file-injection attack . In this work, first we define the leakage in searchable encrypted databases and analyse how the leakage is leveraged in existing leakage-based attacks. Second, we propose a Privacy-preserving Multi-cloud based dynamic symmetric SE scheme for relational Database ( P-McDb ). P-McDb has minimal leakage, which not only ensures confidentiality of queries and records but also protects the search, intersection, and size patterns. Moreover, P-McDb ensures both forward and backward privacy of the database. Thus, P-McDb could resist existing leakage-based attacks, e.g., active file/record-injection attacks. We give security definition and analysis to show how P-McDb hides the aforementioned patterns. Finally, we implemented a prototype of P-McDb and tested it using the TPC-H benchmark dataset. Our evaluation results show that users can get the required records in 2.16 s when searching over 4.1 million records.
Shujie Cui, Xiangfu Song, Muhammad Rizwan Asghar, Steven D. Galbraith, Giovanni Russello
ACM Trans. Priv. Secur.5
2020 GPU-based State Adaptive Random Forest for Evolving Data Streams
abstract
Random forest is an ensemble method used to improve the performance of single tree classifiers. In evolving data streams, the classifier needs to be adaptive and work under constraints of space and time. One benefit of random forest is its ability to be executed in parallel. In our research we introduce a random forest model utilizing a hybrid of both GPU and CPU, called GPU-based State-Adaptive Random Forest (GSARF). We address the pre-existing challenges of adapting random forest for data streams, specifically in the area of continual learning. Our novel approach reuses previously seen trees in the random forest when previous concepts reappear. This allows us to retain prior knowledge and provide a more stable predictive accuracy when changes occur in the data stream. Our random forest for data streams stores three types of trees, foreground trees which are trees that are currently used in prediction, background trees which are trees that are built when we are aware of possible changes in the data streams, and candidate trees which are trees that had been highly used in the previous concepts, but are now discarded due to changes in the data stream. We store candidate trees as they may be potentially useful at a later period in a repository and can be accessed when needed. We empirically show our technique performs up to 138 times the speed compared to current CPU-based random forest benchmarks. Our approach has shown to outperform a baseline GPU-based approach in terms of cumulative accuracy performance.
Ocean Wu, Yun Sing Koh, Giovanni Russello
IJCNN3
2020 Towards a Theory of Special-Purpose Program Obfuscation
abstract
Most recent theoretical literature on program obfuscation is based on notions like virtual black box (VBB) obfuscation and indistinguishability obfuscation (iO). These notions are very strong and are hard to satisfy. Further, they offer far more protection than is typically required in practical applications. On the other hand, the security notions introduced by software security researchers are suitable for practical designs but are not formal or precise enough to enable researchers to provide a quantitative security assurance. Hence, in this paper, we introduce a new formalism for practical program obfuscation that still allows rigorous security proofs. We believe our formalism will make it easier to analyse the security of obfuscation schemes. To show the flexibility and power of our formalism, we give a number of examples. Moreover, we explain the close relationship between our formalism and the task of providing obfuscation challenges.
Muhammad Rizwan Asghar, Steven D. Galbraith, Andrea Lanzi, Giovanni Russello, Lukas Zobernig
TrustCom4
2020 Multi-CDN: Towards Privacy in Content Delivery Networks
abstract
A Content Delivery Network (CDN) is a distributed system composed of a large number of nodes that allows users to request objects from nearby nodes. CDN not only reduces end-to-end latency on the user side but also offloads Content Providers (CPs), providing resilience against Distributed Denial of Service (DDoS) attacks. However, by caching objects and processing user requests, CDN providers could infer user preferences and the popularity of objects, thus resulting in information leakage. Unfortunately, such information leakage may result in loss of user privacy and reveal business-specific information to untrusted or compromised CDN providers. State-of-the-art solutions can protect the content of sensitive objects but cannot prevent CDN providers from inferring user preferences and the popularity of objects. In this work, we present a privacy-preserving encrypted CDN system to hide not only the content of objects and user requests, but also protect user preferences and the popularity of objects from curious CDN providers. We employ encryption to protect the objects and user requests in a way that both the CDNs and CPs can perform the search operations without accessing objects and requests in cleartext. Our proposed system is based on a scalable key management approach for multi-user access, where no key regeneration and data re-encryption are needed for user revocation. We have implemented a prototype of the system and show its practical efficiency.
Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello
IEEE Trans. Dependable Secur. Comput.3
2019 On the Fairness of Multiple-Variant Multiple-Choice Examinations
abstract
Academic dishonesty is a widely acknowledged problem in tertiary education, and a range of safeguards and tools exist to both deter and detect cheating. During tests and examinations students are often monitored closely by invigilators, however incidents of misconduct still occur. Multiple-choice questions (MCQs) are particularly susceptible in this regard due to the simplicity with which answers can be communicated. Nonetheless, they are commonly used in large classes due to their convenience. In this work we investigate multiple-variant MCQs, where answer options are randomly selected from predefined sets. This format is less prone to student cheating and overcomes several weaknesses of similar methods. We evaluate this approach in two large computer science courses through student questionnaires and simple item analysis. We find that multiple-variant MCQ exams are perceived as an effective way to reduce cheating behavior, however not all question variants are equally difficult. This introduces concerns around fairness and we discuss approaches to mitigate these issues in the future.
Paul Denny 0001, Sathiamoorthy Manoharan, Ulrich Speidel, Giovanni Russello, Angela Chang
SIGCSE4
2018 PU-ABE: Lightweight Attribute-Based Encryption Supporting Access Policy Update for Cloud Assisted IoT
abstract
Cloud-assisted IoT applications are gaining an expanding interest, such that IoT devices are deployed in different distributed environments to collect and outsource sensed data to remote servers for further processing and sharing among users. On the one hand, in several applications, collected data are extremely sensitive and need to be protected before outsourcing. Generally, encryption techniques are applied at the data producer side to protect data from adversaries as well as curious cloud provider. On the other hand, sharing data among users requires fine grained access control mechanisms. To ensure both requirements, Attribute Based Encryption (ABE) has been widely applied to ensure encrypted access control to outsourced data. Although, ABE ensures fine grained access control and data confidentiality, updates of used access policies after encryption and outsourcing of data remains an open challenge. In this paper, we design PU-ABE, a new variant of key policy attribute based encryption supporting efficient access policy update that captures attributes addition to access policies. PU-ABE contributions are multifold. First, access policies involved in the encryption can be updated without requiring sharing secret keys between the cloud server and the data owners neither re-encrypting data. Second, PU-ABE ensures privacy preserving and fine grained access control to outsourced data. Third, ciphertexts received by the end-user are constant sized and independent from the number of attributes used in the access policy which affords low communication and storage costs.
Sana Belguith, Nesrine Kaaniche, Giovanni Russello
IEEE CLOUD3
2018 Towards Blockchain-Based Scalable and Trustworthy File Sharing
abstract
In blockchain-based systems, malicious behaviour can be detected using auditable information in transactions managed by distributed ledgers. Besides cryptocurrency, blockchain technology has recently been used for other applications, such as file storage. However, most of existing blockchain- based file storage systems can not revoke a user efficiently when multiple users have access to the same file that is encrypted. Actually, they need to update file encryption keys and distribute new keys to remaining users, which significantly increases computation and bandwidth overheads. In this work, we propose a blockchain and proxy re-encryption based design for encrypted file sharing that brings a distributed access control and data management. By combining blockchain with proxy re-encryption, our approach not only ensures confidentiality and integrity of files, but also provides a scalable key management mechanism for file sharing among multiple users. Moreover, by storing encrypted files and related keys in a distributed way, our method can resist collusion attacks between revoked users and distributed proxies.
Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello
ICCCN3
2018 Preserving Access Pattern Privacy in SGX-Assisted Encrypted Search
abstract
Outsourcing sensitive data and operations to untrusted cloud providers is considered a challenging issue. To perform a search operation, even if both the data and the query are encrypted, attackers still can learn which data locations match the query and what results are returned to the user. This kind of leakage is referred to as data access pattern. Indeed, using access pattern leakage, attackers can easily infer the content of the data and the query. Oblivious RAM (ORAM), Fully Homomorphic Encryption (FHE), and secure Multi- Party Computation (MPC) offer a higher level of security but incur high computation and communication overheads. One promising practical approach to process the outsourced data efficiently and securely is leveraging trusted hardware like Intel SGX. Recently, several SGX- based solutions have been proposed in the literature. However, those solutions suffer from side channel attacks, high overheads of context switching, or limited SGX memory. In this paper, we present an SGX-assisted scheme for performing search over encrypted data. Our solution protects access pattern against side channel attacks while ensuring search efficiency. It can process large databases without requiring any long-term storage on SGX. We have implemented a prototype of the scheme and evaluated its performance using a dataset of 1 million records. The equality query and range query can be completed in 11 and 40 milliseconds, respectively. Comparing with ORAM- based solutions, such as ObliDB, our scheme is more than 10x faster.
Shujie Cui, Sana Belguith, Muhammad Rizwan Asghar, Giovanni Russello
ICCCN5
2018 SECOD: SDN sEcure control and data plane algorithm for detecting and defending against DoS attacks
abstract
Although the popularity of Software-Defined Networking (SDN) is increasing, it is also vulnerable to security attacks such as Denial of Service (DoS) attacks. Since in SDN, the control plane is isolated from the data plane, DoS attackers can easily target the control plane to impair the network infrastructure in addition to the data plane to degrade the user's Quality of Service (QoS). In our previous work, we introduced SECO, an SDN Secure Controller algorithm to detect and defend SDN against DoS attacks. Simulation results showed that SECO successfully defends SDN networks from DoS attacks. In this paper, we present SDN sEcure COntrol and Data Plane (SECOD), which is an improved version of SECO. Basically, SECOD introduces new triggers to detect and prevent DoS attacks in both control and data planes. Moreover, SECOD is implemented and tested using SDN-based hardware testbed, OpenFlow-based switch, and RYU controller to capture the dynamics of realistic hardware and software. The results show that SECOD successfully detects and effectively mitigates DoS attacks on SDN networks keeping data plane performance at 99.72% compared to a network not under attack.
Song Wang 0020, Sathyanarayanan Chandrasekharan, Karina Mabell Gomez, Kandeepan Sithamparanathan, Akram Al-Hourani, Muhammad Rizwan Asghar, Giovanni Russello, Paul Zanna
NOMS7
2018 EMA-LAB: Efficient Multi Authorisation Level Attribute Based Access Control
Nesrine Kaaniche, Sana Belguith, Giovanni Russello
NSS3
2018 Internet of Things: A survey on the security of IoT frameworks
Mahmoud Ammar, Giovanni Russello, Bruno Crispo
J. Inf. Secur. Appl.2
2017 P-McDb: Privacy-Preserving Search Using Multi-Cloud Encrypted Databases
abstract
Searchable Symmetric Encryption (SSE) allows users to execute encrypted queries over encrypted databases. A large number of SSE schemes have been proposed in the literature. However, most of them leak a significant amount of information that could lead to inference attacks. In this work, we propose an SSE scheme for a Privacy-preserving Multi-cloud encrypted Database (P-McDb), which aims at preventing inference attacks. P-McDb allows users to execute SQL-like queries in an efficient sub-linear manner without leaking search, access and size patterns. We have implemented a prototype of P-McDb and show its practical efficiency.
Shujie Cui, Muhammad Rizwan Asghar, Steven D. Galbraith, Giovanni Russello
CLOUD4
2017 Secure and Practical Searchable Encryption: A Position Paper
Shujie Cui, Muhammad Rizwan Asghar, Steven D. Galbraith, Giovanni Russello
ACISP (1)4
2017 A Review of Privacy and Consent Management in Healthcare: A Focus on Emerging Data Sources
abstract
The emergence of New Data Sources (NDS) in healthcare is revolutionising traditional electronic health records in terms of data availability, storage, and access. Increasingly, clinicians are using NDS to build a virtual holistic image of a patients health condition. This research is focused on a review and analysis of the current legislation and privacy rules available for healthcare professionals. NDS in this project refers to and includes patient-generated health data, consumer device data, wearable health and fitness data, and data from social media. This project reviewed legal and regulatory requirements for New Zealand, Australia, the European Union, and the United States to establish the ground reality of existing mechanisms in place concerning the use of NDS. The outcome of our research is to recommend changes and enhancements required to better prepare for the ’tsunami’ of NDS and applications in the currently evolving data-driven healthcare area and precision or personalised health initiatives such as Precision Driven Health (PDH) in New Zealand.
Muhammad Rizwan Asghar, TzeHowe Lee, Mirza Mansoor Baig, Ehsan Ullah, Giovanni Russello, Gillian Dobbie
eScience5
2017 Privacy-Preserving Content Delivery Networks
abstract
A Content Delivery Network (CDN) is a distributed system composed of a large number of nodes that allows users to request objects from nearby nodes. CDN not only reduces the end-to-end latency on the user side but also offloads Content Providers (CPs) providing resilience against Distributed Denial of Service (DDoS) attacks. However, by caching objects and processing users' requests, CDN service providers could infer user preferences and the popularity of objects, thus resulting in information leakage. Unfortunately, such information leakage may result in compromising users' privacy and reveal business-specific information to untrusted or potentially malicious CDN providers. State-of-the-art Searchable Encryption (SE) schemescan protect the content of sensitive objects but cannot preventthe CDN providers from inferring users' preferences and thepopularity of objects. In this work, we present a privacy-preserving encrypted CDN system not only to hide the content of objects and users' requests, but also to protect users' preferences and the popularity of objects from curious CDN providers. We encrypt the objects and user requests in a way that both the CDNs and CPs can perform the search operations without accessing those objects and requests in cleartext. Our proposed system is based on a scalable key management approach for multi-user access, where no key regeneration and data re-encryption are needed for user revocation.
Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello
LCN3
2017 Long White Cloud (LWC): A Practical and Privacy-Preserving Outsourced Database
Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello
WISTP4
2016 3DCrypt: Privacy-preserving Pre-classification Volume Ray-casting of 3D Images in the Cloud
abstract
With the evolution of cloud computing, organizations are outsourcing the storage and rendering of volume (i.e., 3D data) to cloud servers. Data confidentiality at the third-party cloud provider, however, is one of the main challenges. In this paper, we address this challenge by proposing – 3DCrypt – a modified Paillier cryptosystem scheme for multi-user settings that allows cloud datacenters to render the encrypted volume. The rendering technique we consider in this work is pre-classification volume ray-casting. 3DCrypt is such that multiple users can render volumes without sharing any encryption keys. 3DCrypt’s storage and computational overheads are approximately 66.3 MB and 27 seconds, respectively when rendering is performed on a 256 × 256 × 256 volume for a 256×256 image space.
Manoranjan Mohanty, Muhammad Rizwan Asghar, Giovanni Russello
SECRYPT3
2016 $2DCrypt$ : Image Scaling and Cropping in Encrypted Domains
abstract
The evolution of cloud computing and a drastic increase in image size are making the outsourcing of image storage and processing an attractive business model. Although this outsourcing has many advantages, ensuring data confidentiality in the cloud is one of the main concerns. There are state-of-the-art encryption schemes for ensuring confidentiality in the cloud. However, such schemes do not allow cloud datacenters to perform operations over encrypted images. In this paper, we address this concern by proposing 2DCrypt, a modified Paillier cryptosystem-based image scaling and cropping scheme for multi-user settings that allows cloud datacenters to scale and crop an image in the encrypted domain. To anticipate a high storage overhead resulted from the naive per-pixel encryption, we propose a space-efficient tiling scheme that allows tile-level image scaling and cropping operations. Basically, instead of encrypting each pixel individually, we are able to encrypt a tile of pixels. 2DCrypt is such that multiple users can view or process the images without sharing any encryption keys-a requirement desirable for practical deployments in real organizations. Our analysis and results show that 2DCrypt is INDistinguishable under Chosen Plaintext Attack secure and incurs an acceptable overhead. When scaling a 512×512 image by a factor of two, 2DCrypt requires an image user to download approximately 5.3 times more data than the un-encrypted scaling and need to work approximately 2.3 s more for obtaining the scaled image in a plaintext.
Manoranjan Mohanty, Muhammad Rizwan Asghar, Giovanni Russello
IEEE Trans. Inf. Forensics Secur.3
2014 PIDGIN: privacy-preserving interest and content sharing in opportunistic networks
abstract
Opportunistic networks have recently received considerable attention from both industry and researchers. These networks can be used for many applications without the need for a dedicated IT infrastructure. In the context of opportunistic networks, content sharing in particular has attracted significant attention. To support content sharing, opportunistic networks often implement a publish-subscribe system in which users may publish their own content and indicate interest in other content through subscriptions. Using a smartphone, any user can act as a broker by opportunistically forwarding both published content and interests within the network. Unfortunately, opportunistic networks are faced with serious privacy and security issues. Untrusted brokers can not only compromise the privacy of subscribers by learning their interests but also can gain unauthorised access to the disseminated content. This paper addresses the research challenges inherent to the exchange of content and interests without: (i) compromising the privacy of subscribers, and (ii) providing unauthorised access to untrusted brokers. Specifically, this paper presents an interest and content sharing solution that addresses these security challenges and preserves privacy in opportunistic networks. We demonstrate the feasibility and efficiency of the solution by implementing a prototype and analysing its performance on smart phones.
Muhammad Rizwan Asghar, Ashish Gehani, Bruno Crispo, Giovanni Russello
AsiaCCS4
2014 MOSES: Supporting and Enforcing Security Profiles on Smartphones
abstract
Smartphones are very effective tools for increasing the productivity of business users. With their increasing computational power and storage capacity, smartphones allow end users to perform several tasks and be always updated while on the move. Companies are willing to support employee-owned smartphones because of the increase in productivity of their employees. However, security concerns about data sharing, leakage and loss have hindered the adoption of smartphones for corporate use. In this paper we present MOSES, a policy-based framework for enforcing software isolation of applications and data on the Android platform. In MOSES, it is possible to define distinct Security Profiles within a single smartphone. Each security profile is associated with a set of policies that control the access to applications and data. Profiles are not predefined or hardcoded, they can be specified and applied at any time. One of the main characteristics of MOSES is the dynamic switching from one security profile to another. We run a thorough set of experiments using our full implementation of MOSES. The results of the experiments confirm the feasibility of our proposal.
Yury Zhauniarovich, Giovanni Russello, Mauro Conti, Bruno Crispo, Earlence Fernandes
IEEE Trans. Dependable Secur. Comput.2
2013 FireDroid: hardening security in almost-stock Android
abstract
Malware poses a serious threat to Android smartphones. Current security mechanisms offer poor protection and are often too inflexible to quickly mitigate new exploits. In this paper we present FireDroid, a policy-based framework for enforcing security policies by interleaving process system calls. The main advantage of FireDroid is that it is completely transparent to the applications as well as to the Android OS. FireDroid enforces security policies without modifying either the Android OS or its applications. FireDroid is able to perform security checks on third-party and pre-installed applications, as well as malicious native code. We have implemented a novel mechanism that is able to attach, identify, monitor and enforce polices for any process spawned by the Android's mother process Zygote. We have tested the effectiveness of FireDroid against real malware. Moreover, we show how FireDroid can be used as a swift solution for blocking OS and application vulnerabilities before patches are available. Finally, we provide an experimental evaluation of our approach showing that it has only a limited overhead. Given these facts, FireDroid represents a practical solution for strengthening security on Android smartphones.
Giovanni Russello, Arturo Blas Jimenez, Habib Naderi, Wannes van der Mark
ACSAC1
2013 Toward Unified and Flexible Security Policies Enforceable within the Cloud
David M. Eyers, Giovanni Russello
DAIS2
2013 Fair Private Set Intersection with a Semi-trusted Arbiter
Changyu Dong, Liqun Chen 0002, Jan Camenisch, Giovanni Russello
DBSec4
2013 ESPOONERBAC: Enforcing security policies in outsourced environments
Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno Crispo
Comput. Secur.3
2012 Demonstrating the effectiveness of MOSES for separation of execution modes
abstract
In this paper, we describe a demo of a light virtualisation solution for Android phones. We named our solution MOSES (MOde-of-uses SEcurity Separation). MOSES is a policy-based framework for enforcing software isolation of applications and data. In MOSES, it is possible to define distinct security profiles within a single smartphone. Each security profile is associated with a set of policies that control the access to applications and data. One of the main characteristics of MOSES is the dynamic switching from one security profile to another. Each profile is associated with a context as well. Through the smartphones sensors, MOSES is able to detect changes in context and to dynamically switch to the security profile associated with the current context. Our current implementation of MOSES shows minimal overhead compared to standard Android in terms of latencies and battery consumption.
Giovanni Russello, Mauro Conti, Bruno Crispo, Earlence Fernandes, Yury Zhauniarovich
CCS1
2012 MOSES: supporting operation modes on smartphones
abstract
Smartphones are very effective tools for increasing the productivity of business users. With their increasing computational power and storage capacity, smartphones allow end users to perform several tasks and be always updated while on the move. As a consequence, end users require that their personal smartphones are connected to their work IT infrastructure. Companies are willing to support employee-owned smartphones because of the increase in productivity of their employees. However, smartphone security mechanisms have been discovered to offer very limited protection against malicious applications that can leak data stored on them. This poses a serious threat to sensitive corporate data. In this paper we present MOSES, a policy-based framework for enforcing software isolation of applications and data on the Android platform. In MOSES, it is possible to define distinct security profiles within a single smartphone. Each security profile is associated with a set of policies that control the access to applications and data. One of the main characteristics of MOSES is the dynamic switching from one security profile to another.
Giovanni Russello, Mauro Conti, Bruno Crispo, Earlence Fernandes
SACMAT1
2012 Design and implementation of a confidentiality and access control solution for publish/subscribe systems
Mihaela Ion, Giovanni Russello, Bruno Crispo
Comput. Networks2
2011 ESPOON: Enforcing Encrypted Security Policies in Outsourced Environments
abstract
The enforcement of security policies in outsourced environments is still an open challenge for policy-based systems. On the one hand, taking the appropriate security decision requires access to the policies. However, if such access is allowed in an untrusted environment then confidential information might be leaked by the policies. Current solutions are based on cryptographic operations that embed security policies with the security mechanism. Therefore, the enforcement of such policies is performed by allowing the authorised parties to access the appropriate keys. We believe that such solutions are far too rigid because they strictly intertwine authorisation policies with the enforcing mechanism. In this paper, we want to address the issue of enforcing security policies in an untrusted environment while protecting the policy confidentiality. Our solution ESPOON is aiming at providing a clear separation between security policies and the enforcement mechanism. However, the enforcement mechanism should learn as less as possible about both the policies and the requester attributes.
Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno Crispo
ARES3
2011 Poster: ESPOONERBAC: enforcing security policies in outsourced environments with encrypted RBAC
Muhammad Rizwan Asghar, Giovanni Russello, Bruno Crispo
CCS2
2011 Shared and searchable encrypted data for untrusted servers
abstract
Current security mechanisms are not suitable for organisations that outsource their data management to untrusted servers. Encrypting and decrypting sensitive data at the client side is the normal approach in this situation but has high communication and computation overheads if only a subset of the data is required, for example, selecting records in a database table based on a keyword search. New cryptographic schemes have been proposed that support encrypted queries over encrypted data. But they all depend on a single set of secret keys, which implies single user access or sharing keys among multiple users, with key revocation requiring costly data re-encryption. In this paper, we propose an encryption scheme where each authorised user in the system has his own keys to encrypt and decrypt data. The scheme supports keyword search which enables the server to return only the encrypted data that satisfies an encrypted query without decrypting it. We provide a concrete construction of the scheme and give formal proofs of its security. We also report on the results of our implementation.
Changyu Dong, Giovanni Russello, Naranker Dulay
J. Comput. Secur.2
2011 A policy-based publish/subscribe middleware for sense-and-react applications
Giovanni Russello, Leonardo Mostarda, Naranker Dulay
J. Syst. Softw.1
2010 An implementation of event and filter confidentiality in pub/sub systems and its application to e-health
abstract
The publish/subscribe model offers a loosely-coupled communication paradigm where applications interact indirectly and asynchronously. Publisher applications generate events that are forwarded to subscriber applications by a network of brokers. Subscribers register by specifying filters that brokers match against events as part of the routing process. Brokers might be deployed on untrusted servers where malicious entities can get access to events and filters. Supporting confidentiality of events and filters in this setting is still an open challenge. First of all, it is desirable that publishers and subscribers do not share secret keys, such a requirement being against the loose-coupling of the model. Second, brokers need to route events by matching encrypted events against encrypted filters. This should be possible even with very complex filters. Existing solutions do not fully address these issues. This work describes the implementation of a novel schema that supports (i) confidentiality for events and filters; (ii) filters that express very complex constraints on events even if brokers are not able to access any information on both events and filters; (iii) and finally, does not require publishers and subscribers to share keys. We then describe an e-Health application scenario for monitoring patients with chronic diseases and show how our encryption schema can be used to provide confidentiality of the patients' personal and medical data, and control who can receive the patients' data and under which conditions.
Mihaela Ion, Giovanni Russello, Bruno Crispo
CCS2
2010 An opportunistic authority evaluation scheme for data security in crisis management scenarios
abstract
We propose a novel version and implementation of the Policy-based Authority Evaluation Scheme (PAES) to protect data disseminated amongst the responders to an emergency situation when no network connectivity is available. In such situations Delay Tolerant Networks (DTN) are used to disseminate the data by exploiting the peers' mobility in the area. However, existing DTN protection models require recipients to be known in advance. In emergency situations the data may instead be received by unknown responders who might need it while carrying out their duties. Existing data dissemination solutions such Enterprise Rights Management (ERM) systems rely on centralized architectures where recipients must contact the authorities that can grant access to data. Such centralized solutions cannot be deployed when connectivity cannot be guaranteed. Our solution combines data protection schemes such as ERM systems with DTNs. The result allows us to implement a distributed policy evaluation procedure for DTNs. Simulations demonstrate that the approach permits recipients to obtain fast access to protected data even when no authority can be contacted. This is particularly important in crisis situations where timely access to data is necessary.
Enrico Scalavino, Giovanni Russello, Rudi Ball, Vaibhav Gowadia, Emil C. Lupu
AsiaCCS2
2010 Providing Confidentiality in Content-based Publish/subscribe Systems
Mihaela Ion, Giovanni Russello, Bruno Crispo
SECRYPT2
2010 Supporting Publication and Subscription Confidentiality in Pub/Sub Networks
Mihaela Ion, Giovanni Russello, Bruno Crispo
SecureComm2
2010 Exploiting Node Mobility for Coordinating Data Usage in Crisis Scenarios
Giovanni Russello, Enrico Scalavino
WISTP1
2010 Providing data confidentiality against malicious hosts in Shared Data Spaces
Giovanni Russello, Changyu Dong, Naranker Dulay, Michel R. V. Chaudron, Maarten van Steen
Sci. Comput. Program.1
2009 xDUCON: Coordinating Usage Control Policies in Distributed Domains
abstract
In this paper, we present xDUCON a framework for coordinating and enforcing usage control policies across different collaborating organisations. xDUCON allows the specification of usage control policies that concisely capture conditions, authorisations, and obligations on both providers and consumers of resources. The xDUCON framework is based on the Shared Data Space (SDS) abstraction, where collaborating organisations share a data space containing tuples representing subjects, resources and usage policies. The SDS allows the coordination of the decision and enforcement points abstracting from the details of the actual deployment of the framework. As a consequence, xDUCON supports policies able to express richer and finer constraints compared to previous usage control models. Policies support entity mutability that is the changing of related subject and target attributes due to accesses being executed. The decision and enforcement points support ongoing control over long-lived sessions to evaluate the access rights of a subject while the access is being executed. If the context under which the rights were granted changes, xDUCON is able to revoke the access rights preventing the subject to use any longer the resource.
Giovanni Russello, Naranker Dulay
NSS1
2008 Encrypted Shared Data Spaces
Giovanni Russello, Changyu Dong, Naranker Dulay, Michel R. V. Chaudron, Maarten van Steen
COORDINATION1
2008 Shared and Searchable Encrypted Data for Untrusted Servers
Changyu Dong, Giovanni Russello, Naranker Dulay
DBSec2
2007 An experimental evaluation of self-managing availability in shared data spaces
Giovanni Russello, Michel R. V. Chaudron, Maarten van Steen, Ibrahim Bokharouss
Sci. Comput. Program.1
2005 Dynamically Adapting Tuple Replication for Managing Availability in a Shared Data Space
Giovanni Russello, Michel R. V. Chaudron, Maarten van Steen
COORDINATION1
2004 Exploiting Differentiated Tuple Distribution in Shared Data Spaces
Giovanni Russello, Michel R. V. Chaudron, Maarten van Steen
Euro-Par1