EDBT 2026 Demo / reviewers in the wild / expert
Dinesh C. Verma
dblp:45/4989
· DBLP profile ↗
52ranked-venue papers
12as first author
6since 2021 · last 2025
0000-0003-1933-7343ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 12 · 5 first-authorApplied, interdisciplinary, general and emerging computing · 11 · 6 first-authorSystems, architecture and hardware · 10 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 8 · 4 first-authorSecurity and privacy · 7 · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Generalizable Multi-Model Fusion for Multi-Class DoS Detection Using Cognitive Diversity and Rank-Score AnalysisabstractDetecting and mitigating Denial-of-Service (DoS) attacks is crucial for ensuring the availability and security of online services. While various machine learning (ML) models have been utilized for DoS attack detection, there is a need for innovative approaches to improving their performance, especially for the more challenging multi-class detection problem. In this article, we propose adopting a cutting-edge approach called Combinatorial Fusion Analysis (CFA), which leverages a recently developed framework to combine multiple ML models for improved DoS attack detection. Our methodology involves advanced score combination, rank combination, weighted combination techniques, and the diversity strength of scoring systems. Through rigorous performance evaluations, we showcase the efficacy of the combinatorial fusion approach. Our evaluations encompass key metrics such as detection precision, recall, and F1-score, providing comprehensive insights into the interpretability and effectiveness of our approach. We highlight the challenge faced by individual models in classifying low-profiled attacks, while excelling in other attack types. To overcome this limitation, model fusion techniques were used to create a comprehensive model capable of addressing both low-profiled attacks and other traffic types. Furthermore, our findings highlight the potential of this approach for enhancing DoS attack detection capabilities and contributing to the development of more robust defense mechanisms. Evans Owusu, Mohamed Rahouti, Dinesh C. Verma, Yufeng Xin, D. Frank Hsu, Christina Schweikert |
ACM Trans. Priv. Secur. | 3 |
| 2023 | FLAP - A Federated Learning Framework for Attribute-based Access Control PoliciesabstractTechnology advances in areas such as sensors, IoT, and robotics, enable new collaborative applications (e.g., autonomous devices). A primary requirement for such collaborations is to have a secure system that enables information sharing and information flow protection. A policy-based management system is a key mechanism for secure selective sharing of protected resources. However, policies in each party of a collaborative environment cannot be static as they have to adapt to different contexts and situations. One advantage of collaborative applications is that each party in the collaboration can take advantage of the knowledge of the other parties for learning or enhancing its own policies. We refer to this learning mechanism as policy transfer. The design of a policy transfer framework has challenges, including policy conflicts and privacy issues. Policy conflicts typically arise because of differences in the obligations of the parties, whereas privacy issues result because of data sharing constraints for sensitive data. Hence, the policy transfer framework should be able to tackle such challenges by considering minimal sharing of data and supporting policy adaptation to address conflict. In the paper, we propose a framework that aims at addressing such challenges. We introduce a formal definition of the policy transfer problem for attribute-based access control policies. We then introduce the transfer methodology which consists of three sequential steps. Finally, we report experimental results. Amani Abu Jabal, Elisa Bertino, Jorge Lobo 0001, Dinesh C. Verma, Seraphin B. Calo, Alessandra Russo |
CODASPY | 4 |
| 2022 | Trustable service discovery for highly dynamic decentralized workflowsabstractThe quantity and capabilities of smart devices and sensors deployed as part of the Internet of Things (IoT) and accessible via remote microservices is set to rise dramatically as the provision of interactive data streaming increases. This introduces opportunities to rapidly construct new applications by interconnecting these microservices in different workflow configurations. The challenge is to discover the required microservices, including those from trusted partners and the wider community, whilst being able to operate robustly under diverse networking conditions. This paper outlines a workflow approach that provides decentralized discovery and orchestration of verifiably trustable services in support of multi-party operations. The approach is based on adoption of patterns from self-sovereign identity research, notably Verifiable Credentials, to share information amongst peers based on attestations of service descriptions and prior service usage in a privacy preserving and secure manner. This provides a dynamic, trust-based framework for ratifying and evaluating the qualities of different services. Collating these new service descriptions and integrating with existing decentralized workflow research based on vector symbolic architecture (VSA) provides an enhanced semantic search space for efficient and trusted service discovery that is necessary to support a diverse range of emerging edge-computing environments. An architecture for a dynamic decentralized service discovery system, is designed, and described through application to a scenario which uses trusted peers’ reported experiences of an anomaly detection service to determine service selection. Iain Barclay, Christopher Simpkin, Graham A. Bent, Thomas La Porta, Declan Millar, Alun D. Preece, Ian J. Taylor, Dinesh C. Verma |
Future Gener. Comput. Syst. | 8 |
| 2021 | A Security-Constrained Reinforcement Learning Framework for Software Defined NetworksabstractReinforcement Learning (RL) is an effective technique for building ‘smart’ SDN controllers because of its model-free nature and ability to learn policies online without requiring extensive training data. However, as RL agents are geared to maximize functionality and explore the environment without constraints, security can be breached. In this paper, we propose Jarvis-SDN, a RL framework that constrains explorations by taking security into account. In Jarvis-SDN, the RL agent learns ‘intelligent policies’ which maximize functionality but not at the cost of security. Standard network flow based attack sig-natures obtained from intrusion detection system (IDS) datasets cannot be used as policies because they do not conform to the state model of the RL framework and thus have poor accuracy and high false positives. To address such issue, the security policies for constraining explorations in Jarvis-SDN are learnt in a semi-supervised manner in the form of ‘partial attack signatures’ from packet captures of IDS datasets that are then encoded in the objective function of the RL based optimization framework. These signatures are learnt using Deep Q-Networks (DQN). Our analysis shows that DQN based attack signatures perform better than classical machine learning techniques, like decision trees, random forests and deep neural networks (DNN), for common network attacks. We instantiate our framework for a SDN controller with the goal of intelligent rate control to further analyze the effectiveness of the attack signatures. Anand Mudgerikar, Elisa Bertino, Jorge Lobo 0001, Dinesh C. Verma |
ICC | 4 |
| 2021 | A framework for fostering transparency in shared artificial intelligence models by increasing visibility of contributionsabstractAbstract Increased adoption of artificial intelligence (AI) systems into scientific workflows will result in an increasing technical debt as the distance between the data scientists and engineers who develop AI system components and scientists, researchers and other users grows. This could quickly become problematic, particularly where guidance or regulations change and once‐acceptable best practice becomes outdated, or where data sources are later discredited as biased or inaccurate. This paper presents a novel method for deriving a quantifiable metric capable of ranking the overall transparency of the process pipelines used to generate AI systems, such that users, auditors and other stakeholders can gain confidence that they will be able to validate and trust the data sources and contributors in the AI systems that they rely on. The methodology for calculating the metric, and the type of criteria that could be used to make judgements on the visibility of contributions to systems are evaluated through models published at ModelHub and PyTorch Hub, popular archives for sharing science resources, and is found to be helpful in driving consideration of the contributions made to generating AI systems and approaches toward effective documentation and improving transparency in machine learning assets shared within scientific communities. Iain Barclay, Harrison Taylor, Alun D. Preece, Ian J. Taylor, Dinesh C. Verma, Geeth de Mel |
Concurr. Comput. Pract. Exp. | 5 |
| 2021 | ProFact: A Provenance-Based Analytics Framework for Access Control PoliciesabstractPolicy-based access control systems are crucial for secure information sharing in collaborative applications. However, policy management needs to be flexible in order to adapt to different environments and be able to support policy evolution. However, when dealing with large sets of evolving policies, it is critical that policies meet certainpolicy quality requirements. Policy sets must be complete, free of inconsistencies, and relevant. In this paper, we propose a framework to analyze policies to determine whether they meet such requirements. Our framework uses provenance techniques to collect comprehensive data about actions which were either triggered due to a network context or a user (i.e., a human or a device) action. The framework includes two approaches for policy analysis: structure-based and classification-based. For the structure-based approach, we designed tree structures to organize and assess the policy set efficiently. For the classification-based approach, we employed the classification techniques to learn the characteristics of policies and predict their quality. In addition, the framework includes the policy evolution module which mainly consists of recommendation and re-evaluation services for policy changes which both aim at fulfilling the policy quality requirements. The analysis framework has been implemented and experimental results from the prototype are reported. Amani Abu Jabal, Maryam Davari, Elisa Bertino, Christian Makaya, Seraphin B. Calo, Dinesh C. Verma, Christopher Williams 0001 |
IEEE Trans. Serv. Comput. | 6 |
| 2020 | Preparing Network Intrusion Detection Deep Learning Models with Minimal Data Using Adversarial Domain AdaptationabstractRecent work has shown that deep learning (DL) techniques are highly effective for assisting network intrusion detection systems (NIDS) in identifying malicious attacks on networks. Training DL classification models, however, requires vast amounts of labeled data which is often expensive and time-consuming to collect. Also, DL models trained using data from one type of network may not be able to identify attacks on other types of network or identify new families of attacks discovered over time. In this paper, we propose and evaluate the use of adversarial domain adaptation to address the problem of scarcity of labeled training data in a dataset by transferring knowledge gained from an existing network intrusion detection (NID) dataset. Our approach works for scenarios where the source and target datasets have same or different feature spaces. We demonstrate that our proposed approach can create highly accurate DL classification models even when the number of labeled samples in the target dataset is significantly small. Ankush Singla, Elisa Bertino, Dinesh C. Verma |
AsiaCCS | 3 |
| 2020 | Polisma - A Framework for Learning Attribute-Based Access Control Policies
Amani Abu Jabal, Elisa Bertino, Jorge Lobo 0001, Mark Law, Alessandra Russo, Seraphin B. Calo, Dinesh C. Verma |
ESORICS (1) | 7 |
| 2019 | A Policy-based Approach for Measuring Data QualityabstractWith the growing importance of data in all aspects of the functioning of an enterprise, having good quality of data is crucial in support of business processes. However, there do not exist good metrics to measure the quality of data that is available within an enterprise. While there are several data quality standards, their complexity and their required customization makes them difficult to use in real-world industrial scenarios. In this paper, we discuss the challenges encountered in measuring data quality within asset management systems. We propose a policy-based approach for measuring data quality, and show how such an approach can be customized and interpreted easily by practitioners in the field. Keith Grueneberg, Seraphin B. Calo, P. Dewan, Dinesh C. Verma, Tristan O'Gorman |
IEEE BigData | 4 |
| 2019 | Policy based Ensembles for applying ML on Big DataabstractWhen creating real-world machine learning applications, system developers have to deal with the challenges of a dynamic environment where conditions change frequently, data has uncertainty, and new unanticipated situations are encountered. This requires a flexible approach in deciding how to use, adapt and create an AI model. Ensemble learning, where multiple models are trained, and use concurrently provides one way to address some of the issues. However, ensembles as used within the AI literature have primarily focused on creating a better model in a static environment. If we couple ensemble models with the concept of policy based control, we can create a system that is able to deal better with real-world scenarios. If we further augment the system so that it can generate its own policies, we can make progress towards the goal of a broad AI which can dynamically adapt itself. In this paper, we present an architecture for policy based ensemble, and show how it can lead to an approach towards broad AI. Dinesh C. Verma, Seraphin B. Calo, Elisa Bertino, Alessandra Russo, Graham White 0002 |
IEEE BigData | 1 |
| 2019 | Generating Client Side Policies for Cyber-Physical SafetyabstractCyber phyiscal systems are increasingly connected to the Internet for reasons of convenience and efficiency. However, such cyber-physical systems are exposed to new vulnerabilities since they may be compromised by an attack from the Internet. In addition to traditional network security mechanisms, such systems need additional mechanism which can prevent the exploitation of their physical vulnerabilities. We propose an architecture in which the behavior of the system can be controlled by having it generate the policies for its own protection automatically. Dinesh C. Verma, Seraphin B. Calo, Elisa Bertino, Geeth de Mel, Mudhakar Srivatsa |
ICCCN | 1 |
| 2019 | Generative Policies for Coalition Systems - A Symbolic Learning FrameworkabstractPolicy systems are critical for managing missions and collaborative activities carried out by coalitions involving different organizations. Conventional policy-based management approaches are not suitable for next-generation coalitions that will involve not only humans, but also autonomous computing devices and systems. It is critical that those parties be able to generate and customize policies based on contexts and activities. This paper introduces a novel approach for the autonomic generation of policies by autonomous parties. The framework combines context free grammars, answer set programs, and inductionbased learning. It allows a party to generate its own policies, based on a grammar and some semantic constraints, by learning from examples. The paper also outlines initial experiments in the use of such a symbolic approach and outlines relevant research challenges, ranging from explainability to quality assessment of policies. Elisa Bertino, Graham White 0002, Jorge Lobo 0001, John Ingham, Gregory H. Cirincione, Alessandra Russo, Mark Law, Seraphin B. Calo, Irene Manotas, Dinesh C. Verma, Amani Abu Jabal, Daniel Cunnington, Geeth de Mel |
ICDCS | 10 |
| 2019 | Federated AI for the Enterprise: A Web Services Based ImplementationabstractMany enterprise solutions can greatly benefit from Machine Learning (ML) models that are created from cross-domain enterprise data. However, many enterprises cannot share data freely across different locations due to regulatory restrictions, performance issues in moving large data volumes, or requirements to maintain autonomy. In such situations, the enterprise can benefit from the concept of federated learning in which ML models are created at multiple different geographic sites. These are combined together at a federation server without the need to share data. Motivated by the fact that web-services based architectures provide a means for robust integration of cross-domain information, in this paper, we describe a solution to the federated learning problem using such an architecture. We specifically focus on the problems enterprises encounter in using distributed data and discuss how we solved those problems through the solution architecture. Dinesh C. Verma, Graham White 0002, Geeth de Mel |
ICWS | 1 |
| 2019 | Overcoming the Lack of Labeled Data: Training Intrusion Detection Models Using Transfer LearningabstractDeep learning (DL) techniques have recently been proposed for enhancing the accuracy of network intrusion detection systems (NIDS). However, keeping the DL based detection models up to date requires large amounts of new labeled training data which is often expensive and time-consuming to collect. In this paper, we investigate the viability of transfer learning (TL), an approach that enables transferring learned features and knowledge from a trained source model to a target model with minimal new training data. We compare the performance of a NIDS model trained using TL with a NIDS model trained from scratch. We show that TL enables detection models to perform much better at identifying new attacks when there is relatively less training data available. Ankush Singla, Elisa Bertino, Dinesh C. Verma |
SMARTCOMP | 3 |
| 2019 | On the Impact of Generative Policies on Security MetricsabstractPolicy based Security Management in an accepted practice in the industry, and required to simplify the administrative overhead associated with security management in complex systems. However, the growing dynamicity, complexity and scale of modern systems makes it difficult to write the security policies manually. Using AI, we can generate policies automatically. Security policies generated automatically can reduce the manual burden introduced in defining policies, but their impact on the overall security of a system is unclear. In this paper, we discuss the security metrics that can be associated with a system using generative policies, and provide a simple model to determine the conditions under which generating security policies will be beneficial to improve the security of the system. We also show that for some types of security metrics, a system using generative policies can be considered as equivalent to a system using manually defined policies, and the security metrics of the generative policy based system can be mapped to the security metrics of the manual system and vice-versa. Dinesh C. Verma, Elisa Bertino, Geeth de Mel, John Melrose |
SMARTCOMP | 1 |
| 2018 | A Policy System for Control of Data Fusion Processes and Derived DataabstractThe paper proposes an attribute-based policy framework for a coalition setting in which multiple parties provide data to be used in data fusion processes while at the same time retaining control of how their own data are used in these processes. The framework consists of three main types of policies: (a) access control policies - these allow one to specify controls on the fusion process (e.g., which user can use which data fusion tool) and on the input data to the fusion process; (b) fusion policies - these allow one to specify whether data needs to be pre-processed before being used (for example, whether data must be anonymized before being used, or encrypted and thus fusions must be performed on encrypted data); and, (c) derived data usage policies - these allow one to specify who is authorized to access the data resulting from the fusion. As all these policies are attribute-based policies, they support high-level, flexible, and expressive policy specifications. The paper also briefly discusses technologies for supporting policy enforcement and novel approaches supporting the automatic generation of policies. Elisa Bertino, Dinesh C. Verma, Seraphin B. Calo |
FUSION | 2 |
| 2018 | Security Issues for Distributed Fusion in Coalition EnvironmentsabstractWhen sensor fusion operations are conducted in coalition environments, security of the data and infrastructure used for model fusion are very important. AI enabled sensor fusion infrastructure can be attacked on many fronts, including attacks on the data used for sensor information fusion and disrupting the communication between devices and the fusion nodes, in addition to the traditional security attacks. As the infrastructure for sensor fusion becomes more automated with multiple intelligent assistants for data collection, different types of attacks are possible. AI enabled approaches can be used to improve the security and resiliency of federated networks, and the data that is shared across coalition problems. In this paper, we discuss the challenges associated with security of coalition infrastructures, and approaches to improve the security using AI and machine learning techniques. Gregory H. Cirincione, Dinesh C. Verma, Elisa Bertino, Ananthram Swami |
FUSION | 2 |
| 2018 | How to Prevent Skynet from Forming (A Perspective from Policy-Based Autonomic Device Management)abstractArtificial Intelligence (AI) in the context of military systems has frequently been portrayed as dangerous, and as leading to humanity being put in danger by an errant AI system, such as the Skynet imagined in the Terminator movie series. At the same time, the benefits of using AI in such systems are numerous. Therefore, we need to develop techniques that will let military systems benefit from the advances in AI, while ensuring that a system like Skynet never turns against humanity. In this paper, we examine the problem from the perspective of device management, a set of intelligent systems that manage themselves and determine their own policies. We discuss mechanisms that could be used to prevent these systems from becoming malignant. Seraphin B. Calo, Dinesh C. Verma, Elisa Bertino, John Ingham, Gregory H. Cirincione |
ICDCS | 2 |
| 2018 | Self-Generation of Access Control PoliciesabstractAccess control for information has primarily focused on access statically granted to subjects by administrators usually in the context of a specific system. Even if mechanisms are available for access revocation, revocations must still be executed manually by an administrator. However, as physical devices become increasingly embedded and interconnected, access control needs to become an integral part of the resource being protected and be generated dynamically by resources depending on the context in which the resource is being used. In this paper, we discuss a set of scenarios for access control needed in current and future systems and use that to argue that an approach for resources to generate and manage their access control policies dynamically on their own is needed. We discuss some approaches for generating such access control policies that may address the requirements of the scenarios. Seraphin B. Calo, Dinesh C. Verma, Supriyo Chakraborty, Elisa Bertino, Emil C. Lupu, Gregory H. Cirincione |
SACMAT | 2 |
| 2017 | Community-based self generation of policies and processes for assets: Concepts and research directionsabstractWith the advancement in the technology, deploying connected assets - especially intelligent autonomous assets - to obtain the evolving picture of dynamic environments are fast becoming a reality - and a need - for effective and efficient decision making. In such environments, these assets need to function in unison with each other to achieve the goals, and especially in a collaborative environments (e.g., coalition environments) they need to respect the constraints placed on them by the collective as well as by the owner parties. Typically, policies are used to govern such constraints and interactions, but the existing state-of-the-art relies on predefined user policies to achieve the effect, which is not scalable nor practical in collaborative and dynamic environments. Motivated by this observation and the recent uptake in learning technologies, in this paper, we present our vision on a framework that can (a) employ multiple techniques to create domain knowledge that can help assets to determine which policies are critical for which context, how to solve conflicts among policies, and how to autonomously generate and refine existing policies; (b) represent knowledge in a localized wiki-like approach so that fault tolerant knowledge discovery is supported; (c) provide efficient query interface for assets to discover needed knowledge in a secure manner; and (d) contextualize knowledge so as to enable other similar assets to quickly bootstrap or initialize themselves in unknown contexts when new events occur. Elisa Bertino, Geeth de Mel, Alessandra Russo, Seraphin B. Calo, Dinesh C. Verma |
IEEE BigData | 5 |
| 2017 | Edge computing architecture for applying AI to IoTabstractThe proliferation of connected IoT devices creates a big data problem for AI based approaches. The response time required by such devices necessitates IoT data to be processed at the edge, but the edge typically lacks the resources to learn the AI models. We present an architecture which preserves the advantages of both edge processing and server-based/cloud-centric computing for AI algorithms. We discuss how policy management can be used to improve and support this architecture. Seraphin B. Calo, Maroun Touma, Dinesh C. Verma, Alan Cullen |
IEEE BigData | 3 |
| 2017 | Policy enabled caching for distributed AIabstractWeb Caching has established itself as a key enabling technology within the Internet. It enables efficient browsing of websites and web-based services on networks that are bandwidth constrained. However, similar techniques are not available for AI based solutions. Many AI solutions are based on deep neural networks or similar approaches which require creation of machine learning models trained with huge amounts of data. Such models are best created in centralized locations with significant processing power. In many environments, sending the data to a centralized location is infeasible or undesirable. A judicious combination of ideas borrowed from web-caching paradigm, with ideas from AI and machine learning can provide an effective solution for exploitation of deep learning models in bandwidth constrained environments. Allowing such caches to generate their own policies using a generative policy approach can enable the creation of a generic edge caching system which can be used with a wide variety of backend AI systems. Dinesh C. Verma, Graham A. Bent |
IEEE BigData | 1 |
| 2017 | Measures of network centricity for edge deployment of IoT applicationsabstractEdge Computing is a scheme to improve the performance, latency and security guidelines for IoT applications. However, edge deployment of an application also comes with additional complexity in management, an increased attack surface for security vulnerability, and could potentially result in a more expensive solution. As a result, the conditions under which an edge deployment of IoT applications delivers a better solution is not always obvious. Metrics which would be able to predict whether or not an IoT application is suitable for edge deployment can provide useful insights to address this question. In this paper, we examine the key performance indicators for IoT applications, namely the responsiveness, scalability and cost models for different types of IoT applications. Our analysis identifies that network centrality of an IoT application is a key characteristic which determines whether or not an IoT application is a good candidate for edge deployment. We discuss the different measures of network centrality that can be used to characterize applications, and the relative performance of edge deployment compared to centralized deployment for various IoT applications. Dinesh C. Verma, Geeth de Mel |
IEEE BigData | 1 |
| 2017 | A Cognitive Policy Framework for Next-Generation Distributed Federated Systems: Concepts and Research DirectionsabstractNext-generation collaborative activities and missions will be carried out by autonomous groups of devices with a large variety of cognitive capabilities. These devices will have to operate in environments characterized by uncertainty, insecurity (both physical and cyber), and instability. In such environments, communications may be fragmented. Proper policy-based management of such autonomous device groups is thus critical. However current policy management systems have many limitations, including lack of flexibility. In this paper, we articulate novel architectural approaches addressing the requirements for the effective management of autonomous groups of devices and discuss the notion of generative policies - a novel paradigm that enhances the flexibility of policy-based approaches to management. In this paper, we also survey types of policy that are essential for managing device groups. Even though many such policy types exist in conventional settings, their use in our context poses novel challenges that we articulate in the paper. We also introduce a research roadmap discussing several research directions towards the development of a cognitive and flexible policy-based approach to the management of autonomous groups of devices for collaborative missions. Finally, as our proposed policy paradigm is data-intensive, we discuss the problem of supplying the data required for policy decisions in environments characterized by mobility, uncertainly, and fragmented communications. Elisa Bertino, Seraphin B. Calo, Maroun Touma, Dinesh C. Verma, Christopher Williams 0001, Brian Rivera |
ICDCS | 4 |
| 2017 | Distributed Intelligence: Trends in the Management of Complex SystemsabstractThe ability to incorporate intelligence in even small devices and to make use of contextual information from widely deployed sensors has already begun to change management paradigms. As edge computing and IoT become more prevalent, systems will increasingly consist of cooperating, heterogeneous, distributed, autonomous elements. Architectures for cognitive, collaborative systems are evolving to deal with such complex environments. Concepts from multi-agent systems and autonomic computing are being applied to cope with the scope and breadth of large collections of interacting devices and services. Technologies for security and access control must evolve as well. Policy-based mechanisms are widely used and have been very successful in protecting information and controlling access to systems and services. They tend to rely, however, on a centralized infrastructure and on the automated enforcement of directives. Newer paradigms are being investigated that allow policy structures to be more dynamic and contextual, while still preserving the desired levels of control. We will present trends in the evolution of architectures for distributed, federated systems, and the technologies for managing them. Seraphin B. Calo, Dinesh C. Verma, Elisa Bertino |
SACMAT | 2 |
| 2017 | Provenance-Based Analytics Services for Access Control PoliciesabstractSuccessful collaborations require information and resource sharing and thus adequate access control policy management systems that control sharing among the collaborating entities. Such management systems need to be flexible in order to adapt to different environments and thus be able to support access control policy evolution. However, when dealing with large sets of evolving policies it is critical that policies meet certain "policy quality requirements". Specifically, policies of interest must be up-to-date, complete, free of inconsistencies, relevant. In this paper, we propose an approach to analyze policies in order to determine whether policies meet such requirements. Our approach is based on the use of provenance techniques that collect comprehensive data about actions executed by users in the context of workflows, that is, sets of tasks executed according to some ordering by users. Provenance data are used by services that support various types of analysis to determine whether the policies of interest verify the quality requirements. Elisa Bertino, Amani Abu Jabal, Seraphin B. Calo, Christian Makaya, Maroun Touma, Dinesh C. Verma, Christopher Williams 0001 |
SERVICES | 6 |
| 2015 | Advances in network sciences via collaborative multi-disciplinary research
Dinesh C. Verma, Will E. Leland, Tien Pham, Ananthram Swami, Gregory H. Cirincione |
FUSION | 1 |
| 2012 | Distributed state machines: A declarative framework for the management of distributed systems
Jorge Lobo 0001, Dinesh C. Verma, Seraphin B. Calo |
CNSM | 3 |
| 2012 | More is more: The benefits of denser sensor deploymentabstractPositioning disk-shaped sensors to optimize certain coverage parameters is a fundamental problem in ad hoc sensor networks. The hexagon lattice arrangement is known to be optimally efficient in the plane, even though 20.9% of the area is unnecessarily covered twice, however, the arrangement is very rigid—any movement of a sensor from its designated grid position (due to, e.g., placement error or obstacle avoidance) leaves some region uncovered, as would the failure of any one sensor. In this article, we consider how to arrange sensors in order to guarantee multiple coverage, that is, k -coverage for some value k > 1. A naive approach is to superimpose multiple hexagon lattices, but for robustness reasons, we may wish to space sensors evenly apart. We present two arrangement methods for k -coverage: (1) optimizing a Riesz energy function in order to evenly distribute nodes, and (2) simply shrinking the hexagon lattice and making it denser. The first method often approximates the second, and so we focus on the latter. We show that a density increase tantamount to k copies of the lattice can yield k ′-coverage, for k ′ > k (e.g., k = 11, k ′ = 12 and k = 21, k ′ = 24), by exploiting the double-coverage regions. Our examples' savings provably converge in the limit to the ≈ 20.9% maximum. We also provide analogous results for the square lattice and its ≈ 57% inefficiency (e.g., k = 3, k ′ = 4 and k =5, k ′ = 7) and show that for multi-coverage for some values of k ′, the square lattice can actually be more efficient than the hexagon lattice. We also explore other benefits of shrinking the lattice: Doing so allows all sensors to move about their intended positions independently while nonetheless guaranteeing full coverage and can also allow us to tolerate probabilistic sensor failure when providing 1-coverage or k -coverage. We conclude by construing the shrinking factor as a budget to be divided among these three benefits. Matthew P. Johnson 0001, Deniz Sariöz, Amotz Bar-Noy, Theodore Brown, Dinesh C. Verma, Chai Wah Wu |
ACM Trans. Sens. Networks | 5 |
| 2010 | Dynamic Service Execution in Sensor NetworksabstractSensor networks face a number of challenges when deployed in unpredictable environments under dynamic, quickly changeable demands, and when shared by many partners, which is often the case in military and security applications. To partially address these challenges, we present a novel target tracking algorithm that can be deployed on various sensor nodes and invoked dynamically when needed by the presence of targets. We also demonstrate that an auction-based mechanism can be used to provide efficient and localized wireless sensor network congestion management for bursty traffic of abstract services based just on user-assigned priorities to different services and the quality of information provided by the services. We present results from using this auction mechanism to resolve congestion caused by packets from competing target tracking missions. Lei Chen 0005, Zijian Wang 0004, Boleslaw K. Szymanski, Joel W. Branch, Dinesh C. Verma, Raju Damarla, John Ibbotson |
Comput. J. | 5 |
| 2010 | Understanding the Quality of Monitoring for Network ManagementabstractThe vitality and utility of a network are affected significantly by the network management system (NMS) that is used to administer and monitor the network. However, models that can characterize the quality of a NMS are generally missing in the literature. In this paper, we introduce the concept of quality of monitoring (QoM), provide a mathematical formulation based on stochastic processes that can be used to model a network monitoring system and define QoM metrics based on this formulation. A formal analysis of the proposed framework along various metrics is also provided, along with a case study of its application to network monitoring in a mobile ad hoc network. Dinesh C. Verma, Bong Jun Ko, Petros Zerfos, Kang-Won Lee 0002, Ting He 0001, Matthew Duggan, Kristian D. Stewart, Ananthram Swami, Nikoletta Sofra |
Comput. J. | 1 |
| 2009 | Building principles for a quality of information specification for sensor information
Chatschik Bisdikian, Lance M. Kaplan, Mani Srivastava 0001, David J. Thornley, Dinesh C. Verma, Robert I. Young |
FUSION | 5 |
| 2009 | An end to end life cycle for ISR in coalition networks
Dinesh C. Verma, Tien Pham, Gregory H. Cirincione, Gavin Pearson |
FUSION | 1 |
| 2009 | Muti-scale temporal segmentation and outlier detection in sensor networksabstractMonitoring multimodal data generated by sensor networks for extracting information is a challenging task for the human observer. To manage the barrage of data, one needs to create mechanisms for identifying only those time intervals which are informative and worthy of further highlevel analysis either by machine or the human observer. We regard a time interval to be informative and contain an event if it is uncommon or distinct from routine background. Different events in general may unfold at different temporal scales. Here, we present a non-parametric distribution based approach for event detection in sensor network data. In this approach we employ multiple sliding windows at different scales to obtain the distribution of the data. We segment the temporal data stream and identify the potential event bearing candidates by comparing the present and past statistical behavior of the data. In the experiments we demonstrate the effect of optimum bandwidth selection on accuracy and the range of allowable window sizes and therefore time scales. We analyze the computational speed as well as the supporting empirical results on the bin width. Mandis Beigi, Shih-Fu Chang, Shahram Ebadollahi, Dinesh C. Verma |
ICME | 4 |
| 2009 | More is More: The Benefits of Denser Sensor DeploymentabstractPositioning disk-shaped sensors to optimize certain coverage parameters is a fundamental problem in ad-hoc sensor networks. The hexagon grid lattice is known to be optimally efficient, but the 20.9% of the area covered by two sensors may be considered a waste. Furthermore, any movement of a sensor from its designated grid position or sensor failure, due to placement error or obstacle avoidance, leaves some region uncovered, as would the failure of any one sensor. We explore how shrinking the grid can help to remedy these shortcomings. First, shrinking to obtain a denser hexagonal lattice allows all sensors to move about their intended positions independently while nonetheless guaranteeing full coverage. Second, sufficiently increasing the lattice density will naturally yield k-coverage for k > 1. Moreover, we show that a density increase tantamount to fc copies of the lattice can yield k' -coverage, for kj> k (e.g. k = 11, kj= 12), through the exploitation of the double-coverage regions. Our examples' savings provably converge in the limit to the ap 20.9% maximum. We also provide analogous results for the square lattice and its ap 57% inefficiency, including k = 3, kj= 4, k = 5,kj= 7, indicating that for multi-coverage, the square lattice can actually be more efficient than the hexagon lattice. All these efficiency gains can be used to provide 1-coverage or fc-coverage even in the face of probabilistic sensor failure. We conclude by construing the shrinking factor as a budget to be divided among these three benefits. Matthew P. Johnson 0001, Deniz Sariöz, Amotz Bar-Noy, Theodore Brown, Dinesh C. Verma, Chai Wah Wu |
INFOCOM | 5 |
| 2009 | Application of Halftoning Algorithms to Location Dependent Sensor PlacementabstractWe consider a sensor network placement problem where the sensing range of a sensor depends on its location in order to model the effect of terrain features. We study how sensors should be placed in order to maximize the coverage and illustrate how digital halftoning algorithms from the field of image processing can be useful in this respect. In particular, we reduce the sensor placement problem to a corresponding image halftoning problem and then apply two well known halftoning algorithms to the problem: dither mask halftoning and direct binary search. We illustrate our approach with experimental results and show that this approach is also applicable to the problem of preferential coverage. Dinesh C. Verma, Chai Wah Wu, Theodore Brown, Amotz Bar-Noy, Simon Shamoun, Mark S. Nixon |
ISCAS | 1 |
| 2009 | A circulatory system approach for wireless sensor networks
Vasileios Pappas, Dinesh C. Verma, Bong Jun Ko, Ananthram Swami |
Ad Hoc Networks | 2 |
| 2009 | Guest Editors' Introduction: Special Section on Autonomic Network ComputingabstractThe seven papers in this special section focus on autonomic network computing. Dimiter R. Avresky, Harald Prokop, Dinesh C. Verma |
IEEE Trans. Computers | 3 |
| 2008 | Intelligence, Surveillance, and Reconnaissance fusion for coalition operations
Tien Pham, Gregory H. Cirincione, Dinesh C. Verma, Gavin Pearson |
FUSION | 3 |
| 2008 | A sensor placement algorithm for redundant covering based on Riesz energy minimizationabstractWe present an algorithm for sensor placement with redundancy where each point in a 2-dimensional space is covered by at least k sensors under the constraint that all the sensors are located away from each other. We reduce the problem to distributing points evenly on the surface of a torus manifold and solve it computationally by minimizing the Riesz energy. We also study the case where the coverings are incrementally constructed. We illustrate our approach with numerical results and compare it to similar approaches in dispersed dither mask halftoning. Chai Wah Wu, Dinesh C. Verma |
ISCAS | 2 |
| 2008 | More is more: The benefits of dense sensor deploymentabstractAn ad-hoc sensor network is composed of sensing devices which can measure or detect features of their environment, communicate with one other and possibly with other devices that perform data fusion. One of the problems motivated by ad-hoc sensor networks is to position sensors in order to maximize coverage, or equivalently to minimize the number of sensors required to cover a given area. Amotz Bar-Noy, Theodore Brown, Matthew P. Johnson 0001, Deniz Sariöz, Dinesh C. Verma, Chai Wah Wu |
MASS | 5 |
| 2008 | Measurement and analysis of LDAP performance
Xin Wang 0001, Henning Schulzrinne, Dilip D. Kandlur, Dinesh C. Verma |
IEEE/ACM Trans. Netw. | 4 |
| 2006 | Deployment Time Performance Optimization of Internet ServicesabstractThis paper introduces a novel deployment time optimization (DTO) technology for Internet services. Using the configuration information collected from the target operation environment, the proposed optimization technology attempts to deploy only necessary and most performant components for a service in the target environment. To facilitate DTO, we have developed a framework called blue pencil, which consists of the following modules: configuration discovery module, optimization rule repository, deployment optimization module, proxy generation module, and code transformation module. We present how these modules enable DTO and show the performance benefit of DTP in a client-server binding selection scenario. Kang-Won Lee 0002, Kyung Dong Ryu, Jong-Deok Choi, Dinesh C. Verma |
GLOBECOM | 5 |
| 2005 | Policy management for networked systems and applicationsabstractIn this paper, we present a novel policy middleware architecture for managing IT systems and applications that span multiple networks and administrative domains. The proposed policy middleware provides a standard infrastructure for the creation, storage, distribution, and execution of policies, and helps in reducing the cost of making IT systems policy-aware. In particular, we focus on three aspects of the proposed policy middleware that help in making the middleware fully general: (1) a platform-neutral and extensible specification of policies; (2) the local ratification of policies, which lets system administrators accept, reject, or flag an incoming policy; and (3) the transformation of policies, which allows system administrators to transform incoming policies to match their local environment. We present our experience in building an application on the proposed middleware to audit the configuration of a storage area network. We also present performance results from a prototype and show that our policy middleware design can scale to handle a large number of policies. Dakshi Agrawal, Seraphin B. Calo, James Giles, Kang-Won Lee 0002, Dinesh C. Verma |
Integrated Network Management | 5 |
| 2004 | Service level agreements on IP networksabstractThis paper provides an overview of service level agreements (SLAs) in IP networks. It looks at the typical components of an SLA and identifies three common approaches that are used to satisfy SLAs in IP networks. The implications of using the approaches in the context of a network service provider, a hosting service provider, and an enterprise are examined. While most providers currently offer a static insurance approach toward supporting SLAs, the schemes that can lead to more dynamic approaches are identified. Dinesh C. Verma |
Proc. IEEE | 1 |
| 2002 | Authentication for Distributed Web Caches
James Giles, Reiner Sailer, Dinesh C. Verma, Suresh Chari |
ESORICS | 3 |
| 2001 | Network prediction in a policy-based IP networkabstractIn a quality of service (QoS) enabled network, the Internet service providers (ISPs) need to define the network requirements for the customers by defining a set of policies. Every time a new customer gets added or removed or when a customer's resource requirements change, the administrator needs to modify the policies installed on the routers/servers in the network. However, these modifications will affect the traffic flowing in the network and in turn might take away some of the existing customers' resources. Therefore, there is a need to predict how changing the policies will affect the performance of the existing traffic flows in the network. We present a mechanism for predicting whether adding, removing or changing a policy will degrade the performance of the traffic flows belonging to the previous customers. The network administrator can use this information to decide whether such modifications to the policies are desired. Mandis Beigi, Dinesh C. Verma |
GLOBECOM | 2 |
| 2001 | IPSECvalidate: A Tool to Validate IPSEC Configurations
Reiner Sailer, Arup Acharya, Mandis Beigi, Raymond B. Jennings III, Dinesh C. Verma |
LISA | 5 |
| 2000 | Measurement and analysis of LDAP performanceabstractNo abstract available. Xin Wang 0001, Henning Schulzrinne, Dilip D. Kandlur, Dinesh C. Verma |
SIGMETRICS | 4 |
| 1996 | The Tenet real-time protocol suite: design, implementation, and experiencesabstractMany future applications will require guarantees on network performance, such as bounds on throughput, delay, delay jitter, and reliability. To address this need, the authors have designed, simulated, and implemented a suite of network protocols to support real-time channels (network connections with mathematically provable performance guarantees). The protocols, which constitute the prototype Tenet real-time protocol suite (Suite 1), run on a packet-switching internetwork and can coexist with the popular Internet protocol suite. The authors rely on the use of connection-oriented communication, per-channel admission control, channel rate control, and priority scheduling. This protocol suite is the first set of transport and network-layer communication protocols that can transfer real-time streams with guaranteed quality in packet-switching internetworks. The authors have performed a number of experiments and demonstrations on multiple platforms using continuous-media loads (particularly video). The results show that the approach is both feasible and practical to build, and that it can successfully provide performance guarantees to real-time applications. The paper describes the design and implementation of, the suite, the experiments performed, and some of the lessons learned. Anindo Banerjea, Domenico Ferrari, Bruce A. Mah, Mark Moran, Dinesh C. Verma, Hui Zhang 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 1993 | Routing Reserved Bandwith Multi-Point ConnectionsabstractSome important classes of multi-point bandwidth-intensive applications like video-conferencing with mixing and the distributed classroom can be characterized as consisting of a broadcast from a source node to several destinations nodes, and point-to-point flows from the destination nodes to the source node. Determining a tree in an arbitrary mesh network which satisfies the bandwidth constraints and minimizes the cost of reserved bandwidth is a NP-hard problem. In this paper, we look at some heuristics that can be used to solve the problem of routing these multi-point connections. The heuristics are based on finding the capacity-constrained minimum cost tree which minimizes the cost of bandwidth reserved for point-to-point communication from destinations to the source, and weights are assigned to minimize the number of extra nodes in the tree which increase the cost of bandwidth reserved from the source to the destination. A theoretical bound on the performance of some of the heuristics, as well as simulation results comparing their performance to that of the optimum solution are presented. The results are encouraging, the heuristics find a tree with a cost within 2% of the optimum on the average, and with a cost within 10% of the optimum in those cases when the heuristic fails to find the optimum tree. Dinesh C. Verma, Prabandham M. Gopal |
SIGCOMM | 1 |
| 1990 | A Scheme for Real-Time Channel Establishment in Wide-Area NetworksabstractMultimedia communication involving digital audio and/or digital video has rather strict delay requirements. A real-time channel is defined as a simplex connection between a source and a destination characterized by parameters representing the performance requirements of the client. A study is made of the feasibility of providing real-time services on a packet-switched store-and-forward wide-area network with general topology. A description is given of a scheme for the establishment of channels with deterministic or statistical delay bounds, and the results of the simulation experiments run to evaluate it are presented. The results are judged encouraging: the approach satisfies the guarantees even in worst case situations, uses the network's resources to a fair extent, and efficiently handles channels with a variety of offered load and burstiness characteristics. Also, the packet transmission overhead is quite low, and the channel establishment overhead is small enough to be acceptable in most practical cases.> Domenico Ferrari, Dinesh C. Verma |
IEEE J. Sel. Areas Commun. | 2 |