EDBT 2026 Demo / reviewers in the wild / expert
Ashish Kundu
dblp:65/4168
· DBLP profile ↗
56ranked-venue papers
10as first author
32since 2021 · last 2026
0000-0003-1499-5558ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 3 first-author · 15 since 2021Databases, data management, data science and information retrieval · 10 · 2 first-author · 1 since 2021Systems, architecture and hardware · 8 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 7 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-authorComputer networks · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Silent Fallbacks and Semantic Gaps: Evaluating the Functional Soundness of LLM-Generated Linux Password Policies
Vivek Vaidya 0003, Aditya Patwardhan, Sudiksha Das, Ashish Kundu |
DBSec | 4 |
| 2026 | Classifying Implementations of Cryptographic Primitives and Protocols that Use Post-Quantum AlgorithmsabstractClassification techniques can be used to analyze system behaviors, network protocols, and cryptographic primitives based on identifiable traits. While useful for defense, such classification can also be leveraged by attackers to infer system configurations, detect vulnerabilities, and tailor attacks such as denial-of-service, key recovery, or downgrade attacks. In this paper, we study the feasibility of classifying post-quantum (PQ) algorithms by analyzing implementations of key exchange and digital signatures, their use within secure protocols, and their integration into SNARK generation libraries. Unlike traditional cryptography, PQ algorithms have larger memory requirements and variable computational costs. Our research examines two post-quantum cryptography libraries, liboqs and CIRCL, evaluating TLS, SSH, QUIC, OpenVPN, and OpenID Connect (OIDC) across Windows, Ubuntu, and macOS. We also analyze pysnark and lattice_zksnark for SNARK generation and verification on Ubuntu. Experimental results show that (1) classical and PQ key exchange and signature algorithms can be distinguished with accuracies of 98% and 100%; (2) specific PQ algorithms can be identified with 97% accuracy for key exchange and 86% for signatures; (3) implementations of the same algorithm in liboqs and CIRCL are distinguishable with up to 100% accuracy; and (4) within CIRCL, PQ and hybrid key exchange implementations can be distinguished with 97% accuracy. For secure protocols, we can determine whether key exchange is classical or PQ and identify the PQ algorithm used. SNARK generation and verification in pysnark and lattice_zksnark are distinguishable with 100% accuracy. We demonstrate real-world applicability by identifying PQ-enabled TLS domains in the Tranco dataset and integrating our methods into QUARTZ, an open-source risk and threat analyzer by Cisco. Tushin Mallick, Ashish Kundu, Ramana Rao Kompella, Cristina Nita-Rotaru |
SACMAT | 2 |
| 2026 | Malware Detection at the Edge with Lightweight LLMs: A Performance EvaluationabstractThe rapid evolution of malware attacks calls for the development of innovative detection methods, especially in resource-constrained edge computing. Traditional detection techniques struggle to keep up with modern malware’s sophistication and adaptability, prompting a shift towards advanced methodologies like those leveraging Large Language Models (LLMs) for enhanced malware detection. However, deploying LLMs for malware detection directly at edge devices raises several challenges, including ensuring accuracy in constrained environments and addressing edge devices’ energy and computational limits. To tackle these challenges, this article proposes an architecture leveraging lightweight LLMs’ strengths while addressing limitations like reduced accuracy and insufficient computational power. To evaluate the effectiveness of the proposed lightweight LLM-based approach for edge computing, we perform an extensive experimental evaluation using several state-of-the-art lightweight LLMs. We test them with several publicly available datasets specifically designed for edge and IoT scenarios, and different edge nodes with varying computational power and characteristics. Christian Rondanini, Barbara Carminati, Elena Ferrari 0001, Ashish Kundu, Antonio Gaudiano |
ACM Trans. Internet Techn. | 4 |
| 2025 | QRSec 2025: ACM CCS First Workshop on Quantum-Resistant Cryptography and SecurityabstractQuantum computing poses transformative opportunities and challenges, with cryptography at the forefront of its impact. The ACM CCS Workshop on Quantum-Resistant Cryptography and Security (QRSec 2025) provides a forum for researchers, practitioners, and industry leaders to explore advances in post-quantum cryptography (PQC) and its integration into secure systems. Building on the momentum of the NIST PQC standardization process and the release of the first standards in 2024, QRSec 2025 highlights theoretical foundations, algorithm design, engineering, and deployment strategies alongside emerging topics such as machine learning for cryptanalysis, quantum-resistant networks, blockchain, IoT, and cloud security. The program features keynotes from leading experts, technical paper sessions, and interactive panels bridging academia, industry, and government. By fostering dialogue across these communities, QRSec 2025 aims to advance the state of the art in quantum-resistant security and chart practical paths for migration and compliance in the post-quantum era. Ashish Kundu, Attila A. Yavuz, Cristina Nita-Rotaru |
CCS | 1 |
| 2025 | PLRV-O: Advancing Differentially Private Deep Learning via Privacy Loss Random Variable OptimizationabstractDifferentially Private Stochastic Gradient Descent (DP-SGD) is a standard method for enforcing privacy in deep learning, typically using the Gaussian mechanism to perturb gradient updates. However, conventional mechanisms such as Gaussian and Laplacian noise are parameterized only by variance or scale. This single degree of freedom ties the magnitude of noise directly to both privacy loss and utility degradation, preventing independent control of these two factors. The problem becomes more pronounced when the number of composition rounds T and batch size B vary across tasks, as these variations induce task-dependent shifts in the privacy–utility trade-off, where small changes in noise parameters can disproportionately affect model accuracy. To address this limitation, we introduce PLRV-O, a framework that defines a broad search space of parameterized DP-SGD noise distributions, where privacy loss moments are tightly characterized yet can be optimized more independently with respect to utility loss. This formulation enables systematic adaptation of noise to task-specific requirements, including (i) model size, (ii) training duration, (iii) batch sampling strategies, and (iv) clipping thresholds under both training and fine-tuning settings. Empirical results demonstrate that PLRV-O substantially improves utility under strict privacy constraints. On CIFAR-10, a fine-tuned ViT achieves 94.03% accuracy at ∈ ≈ 0.5, compared to 83.93% with Gaussian noise. On SST-2, RoBERTa-large reaches 92.20% accuracy at ∈ ≈ 0.2, versus 50.25% with Gaussian. Source code is available at https://github.com/datasec-lab/plrvo. Qin Yang 0009, Nicholas Stout, Meisam Mohammady, Han Wang 0021, Ayesha Samreen, Christopher J. Quinn, Yan Yan 0002, Ashish Kundu, Yuan Hong 0001 |
CCS | 8 |
| 2025 | Harmonizing Differential Privacy Mechanisms for Federated Learning: Boosting Accuracy and ConvergenceabstractDifferentially private federated learning (DP-FL) offers a compelling approach to collaborative model training by ensuring robust privacy for clients. Despite its potential, current methods face challenges in effectively balancing privacy, utility, and performance across diverse federated learning scenarios. Addressing these challenges, we introduce UDP-FL, to our knowledge the first DP-FL framework that universally harmonizes any randomization mechanism, including those considered optimal, by employing the Gaussian Moments Accountant (viz. DP-SGD). Central to UDP-FL is the 'Harmonizer,' a dynamic module engineered to intelligently select and apply the most suitable DP mechanism tailored to each client's specific privacy requirements, data sensitivities, and computational capacities. This selection process is driven by the principle of Rényi Differential Privacy, which serves as a crucial mediator for aligning privacy budgets effectively. Our comprehensive evaluation of UDP-FL, benchmarked against established baseline methods, demonstrates superior performance in upholding privacy guarantees and enhancing model functionality. The framework's robustness has been rigorously tested against a broad spectrum of privacy attacks, making it one of the most thorough validations of a DP-FL framework to date. Shuya Feng, Meisam Mohammady, Hanbin Hong, Shenao Yan, Ashish Kundu, Binghui Wang, Yuan Hong 0001 |
CODASPY | 5 |
| 2025 | IoTDSCreator: A Framework to Create Labeled Datasets for IoT Intrusion Detection SystemsabstractIntrusion detection systems (IDSes) are critical building blocks for securing Internet-of-Things (IoT) devices and networks. Advances in AI techniques are contributing to enhancing the efficiency of IDSes, but their performance typically depends on high-quality training datasets. The scarcity of such datasets is a major concern for the effective use of machine learning for IDSes in IoT networks. To address such a need, we present IoTDSCreator - a tool for the automatic generation of labeled datasets able to support various devices, connectivity technologies, and attacks. IoTDSCreator provides a user with DC-API, an API by which the user can describe a target network and an attack scenario against it. Based on the description, the framework configures the network, leveraging virtualization techniques on user-provided physical machines, performs single or multi-step attacks, and finally returns labeled datasets. Thereby, IoTDSCreator dramatically reduces the manual effort for generating labeled and diverse datasets. We release the source code of IoTDSCreator and 16 generated datasets with 193 features based on 26 types of IoT devices, 2 types of communication links, and 15 types of IoT applications. Hyunwoo Lee 0001, Charalampos Katsis, Alireza Lotfi, Taejun Choi, Soeun Kim, Ashish Kundu, Elisa Bertino |
CODASPY | 6 |
| 2025 | Security Opportunities and Challenges for Disaggregated Architectures (Invited)abstractDisaggregated computer architectures are an interesting paradigm according to which the components of a traditional monolithic server, such as CPU, memory, storage, and networking, are separated into distinct, often independently managed units that communicate over a network. Disaggregation not only offers benefits such as greater flexibility, scalability, and resource optimization but can also improve security. For example, in the context of enterprise routing, it can offer fine-grained control over the network that allows one to deploy security policies, access control rules, and threat detection mechanisms more precisely, ensuring that only authorized traffic flows through the enterprise environment. It makes patch management easier because its modularity allows different components to be patched independently. The same benefits also apply to cellular networks. Disaggregation is a key feature of the Open Radio Access Network (O-RAN) paradigm, whose goal is to make the radio access network intelligent, virtualized, and fully interoperable. However, disaggregation also introduces several unique security risks, such as increased attack surfaces, increased exposure of sensitive data, increased difficulty in tracing data provenance, insecure isolation among different components, and insecure APIs. In addition, well-known security technologies, such as trusted execution environments, may have to be redesigned in the context of disaggregated architectures. In this paper, after an overview of these benefits and concerns, we focus on the research approaches proposed to address some of these concerns for network fabric, O-RAN, and trusted execution environments. Elisa Bertino, Imtiaz Karim, Ashish Kundu |
DAC | 3 |
| 2025 | Quantum-Resistant Security: PQC Readiness and Research Challenges (Invited)abstractWhat is your PQC-readiness” - in this paper, we have explored this problem, some of the key challenges to address it and how ciphersuite dependency graphs alongwith observability plays a vital role in addressing some of those challenges. Quantum computing capabilities are evolving fast and on course to develop a cryptographically relevant quantum computer (CRQC). With that several widely used classical cryptography protocols such as RSA are poised to be broken in the next few years. NIST has announced three cryptography protocols as part of the first batch of post-quantum cryptography standards. However, implementation and adoption of quantum-resistant cryptography is a hard problem given the complexities of today’s internet and computing stack. Our work has led to development of algorithms and a system Quartz (Quantum Risk and Threat Analyzer) for observability for quantum vulnerabilities for cryptography suites, where they are used, and analyzing their risks. In that context, we used observability, and the concept of ciphersuite dependency graphs in order to determine use of quantum-unsafe cryptography, and its influence on cryptography supply chain, and generation of cryptography bill of materials (CBOM). Ashish Kundu, Ramana Rao Kompella |
DAC | 1 |
| 2025 | Towards Secure Data Management using Multi-Cryptographic Solutions (Invited)abstractSeveral secure data outsourcing systems incorporate various cryptographic techniques to balance security, functionalities, and efficiency. However, their security properties can be ad hoc and sometimes obscure. Our recent work, Secure Normal Form (SNF) [ICDE’24], presents a principled approach that allows data owners to define acceptable leakages of nonsensitive aspects of their data. This approach enables efficient processing of queries while ensuring no unintended leakage of sensitive information. In this paper, we discuss the benefits and challenges of implementing SNF within advanced computational environments and modern data management architectures. We argue that its applicability may extend beyond merely offloading secure query execution to the cloud. Shufan Zhang 0001, Xi He 0001, Ashish Kundu, Sujaya Maiyya, Sharad Mehrotra, Shantanu Sharma 0001 |
DAC | 3 |
| 2025 | Automated Privacy Policy Analysis Using Large Language Models
Mian Yang, Vijayalakshmi Atluri, Shamik Sural, Ashish Kundu |
DBSec | 4 |
| 2025 | On the Vulnerability of Applying Retrieval-Augmented Generation within Knowledge-Intensive Application DomainsabstractRetrieval-Augmented Generation (RAG) has been empirically shown to enhance the performance of large language models (LLMs) in knowledge-intensive domains such as healthcare, finance, and legal contexts. Given a query, RAG retrieves relevant documents from a corpus and integrates them into the LLMs’ generation process. In this study, we investigate the adversarial robustness of RAG, focusing specifically on examining the retrieval system. First, across 225 different setup combinations of corpus, retriever, query, and targeted information, we show that retrieval systems are vulnerable to universal poisoning attacks in medical Q&A. In such attacks, adversaries generate poisoned documents containing a broad spectrum of targeted information, such as personally identifiable information. When these poisoned documents are inserted into a corpus, they can be accurately retrieved by any users, as long as attacker-specified queries are used. To understand this vulnerability, we discovered that the deviation from the query’s embedding to that of the poisoned document tends to follow a pattern in which the high similarity between the poisoned document and the query is retained, thereby enabling precise retrieval. Based on these findings, we develop a new detection-based defense to ensure the safe use of RAG. Through extensive experiments spanning various Q&A domains, we observed that our proposed method consistently achieves excellent detection rates in nearly all cases. Xun Xian, Ganghua Wang, Xuan Bi, Rui Zhang 0028, Jayanth Srinivasa, Ashish Kundu, Charles Fleming, Mingyi Hong 0001, Jie Ding 0002 |
ICML | 6 |
| 2025 | Revisiting Concept Drift in Windows Malware Detection: Adaptation to Real Drifted Malware with Minimal Samples
Adrian Shuai Li, Arun Iyengar, Ashish Kundu, Elisa Bertino |
NDSS | 3 |
| 2025 | Translating C To Rust: Lessons from a User Study
Ruishi Li, Prateek Saxena, Ashish Kundu |
NDSS | 5 |
| 2025 | Extraction of Machine Enforceable ABAC Policies from Natural Language Text using LLM Knowledge DistillationabstractNatural Language Access Control Policies (NLACPs) define who can access specific information within an organization and under what conditions. While these policies are typically written in semi-formal or informal natural language, making them easily interpretable by humans, they cannot be directly enforced by access control systems. Their unstructured nature introduces ambiguities and inconsistencies, making automated extraction and translation into structured, machine-enforceable security rules a significant challenge. Mian Yang, Vijayalakshmi Atluri, Shamik Sural, Ashish Kundu |
SACMAT | 4 |
| 2025 | SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks
Kaiyuan Zhang 0002, Siyuan Cheng 0005, Hanxi Guo, Yuetian Chen, Zian Su, Shengwei An, Yuntao Du 0002, Charles Fleming, Ashish Kundu, Xiangyu Zhang 0001, Ninghui Li 0001 |
USENIX Security Symposium | 9 |
| 2025 | Oblivious and distributed firewall policies for securing firewalls from malicious attacksabstractFirewalls are effective in preventing attacks initiated from outside of an organization’s network, but they are vulnerable to external threats, e.g. ransomware attacks may expose sensitive firewall data to malicious entities or disable network protection from the firewall. In this paper, we present Obliv-FW: a novel distributed architecture and a suite of protocols to obliviously manage and evaluate firewall rules and policies to prevent external attacks oriented to the firewall data. Obliv-FW alleviates this issue by obfuscating the blacklist or whitelist and distributing the function of evaluating these lists across multiple servers residing in different access control zones of the organization’s internal network. Thus, both accessing and altering the rules are considerably more difficult thereby providing better protection to the local network as well as greater security for the firewall itself. Obliv-FW is developed by leveraging the existing secure multi-party computation techniques. Our empirical results show that the overhead of Obliv-FW is small, and it can be a very valuable tool to mitigate the ever-increasing threats to a private network from external attacks including ransomware attacks. Ali A. Allami, Tyler Nicewarner, Ken Goss, Ashish Kundu, Wei Jiang 0026, Dan Lin 0001 |
Comput. Secur. | 4 |
| 2024 | POSTER: Seccomp profiling with Dynamic Analysis via ChatGPT-assisted Test Code GenerationabstractThe effectiveness of Seccomp kernel feature depends on how tightly and accurately the necessary system calls are specified in the seccomp policy. Static code analysis may miss out or over-approximate required system calls. With dynamic analysis, it is difficult to cover all possible execution paths. In this work, we aim to advance the state-of-the-art dynamic analysis approach by enabling it to increase the coverage of the target application's functionalities. Our approach takes as input the application's online documentation and leverages ChatGPT to generate a large number of test codes for functionalities in the documentation. This automated process eliminates the barrier to manually writing a large number of test codes for conducting dynamic analysis. Through our preliminary evaluation, we confirmed that ChatGPT can be used effectively to automatically generate a large number of test codes. Also, we observed early evidence that the seccomp policy generated from running the test codes could be more sound than the ones generated by static analysis. Somin Song, Ashish Kundu, Byung-Chul Tak |
AsiaCCS | 2 |
| 2024 | Poster: Secure Data Sharing with Decentralised Data Ring FencingabstractThe explosion of data and digital technologies has exacerbated privacy concerns. Traditional access control struggles to keep pace with the complexity of multi-party data sharing, where varying data access rules and privacy policies across institutions create significant challenges - leading to unauthorized and unintended access, especially in multi-party scenarios. Data Ring Fencing, inspired by the financial sector's concept of isolating assets, offers a multi-layered security framework for secure data sharing. It governs data access privileges, regulating who can access what data, for what purpose, and at what cost. However, the current model relies on a central system, requiring complete trust from all participating institutions. This paper addresses these limitations by proposing a Decentralized Data Ring Fencing approach that leverages permissioned blockchains. This eliminates the need for a central authority, a critical factor as it removes the inherent single point of failure and the requirement for absolute trust in a central system. Aditya Nangia, Saksham Bhupal, Kushagra Mittal, Mukesh K. Mohania, Ashish Kundu |
ICDCS | 5 |
| 2024 | Poster: CrystalBall - Attack Graphs Using Large Language Models and RAGsabstractAttack graphs provide a way to model multiple attack vectors and multi-step attacks in a holistic manner that a malicious actor could use to compromise a system. Traditional methods of generating attack graphs involve expert knowledge, manual curation, and computational algorithms that might not cover the entire threat landscape due to the ever-evolving nature of vulnerabilities and exploits. This paper explores the approach of leveraging large language models (LLMs), such as GPT4, to automate the generation of attack graphs by intelligently chaining CVEs based on their preconditions and effects. It also shows how to utilize LLMs to create attack graphs from threat reports. Renascence Tarafder Prapty, Ashish Kundu, Arun Iyengar |
ICDCS | 2 |
| 2024 | Poster: Benchmarking of Code Generative LLMsabstractGenerative LLMs have proven to be valuable code generators, thus enabling code copilots and meeting several requirements in software engineering. However, several questions arise: How good an LLM is as a software engineer? How secure is the code generated or fixed by an LLM? These are complex questions to address; however, addressing them is critical for enabling trustworthy software development ecosystems. Addressing those questions requires a designing rigorous benchmark to evaluate: (i) the code that is generated/completed, and (ii) the generative LLMs themselves. In this paper, we propose an automated benchmarking system covering the different aspects of the generated code and the LLMs that generate the code. We also propose the concept of a benchmark dependency graph, coupled with an automated benchmark scoring process that provides a vector of scores on how “good” or how “bad” an LLM is, or the code generated/modified by it is, additionally the artifacts generated or modified around the code. Mirza Masfiqur Rahman, Ashish Kundu, Elisa Bertino |
ICDCS | 2 |
| 2024 | Secure Normal Form: Mediation Among Cross Cryptographic Leakages in Encrypted DatabasesabstractExisting secure data outsourcing systems offer users ways to select from different cryptographic primitives supported by the system to encrypt their data to strike a balance between data confidentiality and query performance. Though prior work have identified the danger of mixing cryptographic primitives, they fall short of providing a systematic approach to guide users to prevent such cross-cryptographic leakages. Inspired by the database design theory, we envision Secure Normal Form, a new approach to normalize encrypted databases such that the leakages of the partitioned databases are limited to the users' specifications. In this work, we propose a new architecture to support secure normal form. This system includes several new components for secure data outsourcing: (i) an inference mechanism that reasons about additional leakages from weaker encryption techniques, based on semantic data properties (e.g., dependence between attribute values); (ii) a normalization mechanism that converts relational data into secure normal forms, so that the information leaked by the representation is limited to that specified by the user; and (iii) a secure query execution approach over encrypted data in secure normal forms. Our initial experimental results validate the performance improvement over naïve baseline and show that a careful data representation can be allowed without compromising security. We believe that our paper opens a new direction in secure data management. Shufan Zhang 0001, Xi He 0001, Ashish Kundu, Sharad Mehrotra, Shantanu Sharma 0001 |
ICDE | 3 |
| 2024 | Demystifying Poisoning Backdoor Attacks from a Statistical PerspectiveabstractBackdoor attacks pose a significant security risk to machine learning applications due to their stealthy nature and potentially serious consequences. Such attacks involve embedding triggers within a learning model with the intention of causing malicious behavior when an active trigger is present while maintaining regular functionality without it. This paper derives a fundamental understanding of backdoor attacks that applies to both discriminative and generative models, including diffusion models and large language models. We evaluate the effectiveness of any backdoor attack incorporating a constant trigger, by establishing tight lower and upper boundaries for the performance of the compromised model on both clean and backdoor test data. The developed theory answers a series of fundamental but previously underexplored problems, including (1) what are the determining factors for a backdoor attack's success, (2) what is the direction of the most effective backdoor attack, and (3) when will a human-imperceptible trigger succeed. We demonstrate the theory by conducting experiments using benchmark datasets and state-of-the-art backdoor attack scenarios. Our code is available \href{https://github.com/KeyWgh/DemystifyBackdoor}{here}. Ganghua Wang, Xun Xian, Ashish Kundu, Jayanth Srinivasa, Xuan Bi, Mingyi Hong 0001, Jie Ding 0002 |
ICLR | 3 |
| 2024 | RAW: A Robust and Agile Plug-and-Play Watermark Framework for AI-Generated Images with Provable GuaranteesabstractSafeguarding intellectual property and preventing potential misuse of AI-generated images are of paramount importance. This paper introduces a robust and agile plug-and-play watermark detection framework, referred to as RAW.
As a departure from existing encoder-decoder methods, which incorporate fixed binary codes as watermarks within latent representations, our approach introduces learnable watermarks directly into the original image data. Subsequently, we employ a classifier that is jointly trained with the watermark to detect the presence of the watermark.
The proposed framework is compatible with various generative architectures and supports on-the-fly watermark injection after training. By incorporating state-of-the-art smoothing techniques, we show that the framework also provides provable guarantees regarding the false positive rate for misclassifying a watermarked image, even in the presence of adversarial attacks targeting watermark removal.
Experiments on a diverse range of images generated by state-of-the-art diffusion models demonstrate substantially improved watermark encoding speed and watermark detection performance, under adversarial attacks, while maintaining image quality. Our code is publicly available [here](https://github.com/jeremyxianx/RAWatermark). Xun Xian, Ganghua Wang, Xuan Bi, Jayanth Srinivasa, Ashish Kundu, Mingyi Hong 0001, Jie Ding 0002 |
NeurIPS | 5 |
| 2024 | AI/ML, Graphs and Access Control: Towards Holistic Identity and Access ManagementabstractVulnerabilities in identity and access management (IAM) are one of the most common reasons for data breaches leading to adversarial impacts on security, privacy and compliance postures. Account breaches, incorrectly designed access control policies, weaknesses in authentication and credential management, vulnerable session management are some of the several security issues that lead to eventual compromise of the crown jewels leading to data breaches. The lifecycles of subjects and their identities, of objects and re- sources, and of the permissions and authorization policies are in- tertwined in a complex manner for each specific scenario. Often subjects, objects and permissions often are hard to be defined or isolated from each other, especially in the context of machine learn-ing. The evolution of these entities, and how their provenance is analyzed often is essential not only for forensic analysis of a breach but also should be a proactive ongoing process. Ashish Kundu |
SACMAT | 1 |
| 2024 | MetaFL: Privacy-preserving User Authentication in Virtual Reality with Federated LearningabstractThe increasing popularity of virtual reality (VR) has stressed the importance of authenticating VR users while preserving their privacy. Behavioral biometrics, owing to their robustness and ease of collection, compared to traditional modes such as passwords, have become a favored authentication choice. While current approaches that utilize behavioral biometrics to train classifiers for authentication yield promising accuracy, they cause privacy breaches by sharing sensitive data with a server to train a central model. In this paper, we present MetaFL, a first-of-its-kind privacy-preserving VR authentication framework that leverages federated learning (FL) on multi-modal motion data. The design of MetaFL is motivated by our key insight that various modalities of motion data uniquely affect authentication performance for individual users and among different users. It is attributed to the fundamental challenge of privacy-preserving user authentication: users can access only their own data with limited global knowledge. To tackle this issue, MetaFL judiciously selects the most suitable modalities for each user, which is decomposed into within-user ordering and between-user selection to eliminate the complex interplay between various conflicting factors. Moreover, we develop a personalized strategy to initialize FL models, further improving authentication accuracy. Our extensive performance evaluation on six public datasets shows that MetaFL outperforms state-of-the-art FL-based models (e.g., 17--28% higher authentication accuracy), and its accuracy gap with the non-privacy-preserving central model is small (i.e., only <2%). Ruizhi Cheng, Yuetong Wu, Ashish Kundu, Hugo Latapie, Myungjin Lee, Songqing Chen, Bo Han 0001 |
SenSys | 3 |
| 2024 | ARIoTEDef: Adversarially Robust IoT Early Defense System Based on Self-Evolution against Multi-step AttacksabstractInternet of Things (IoT) cyber threats, exemplified by jackware and crypto mining, underscore the vulnerability of IoT devices. Due to the multi-step nature of many attacks, early detection is vital for a swift response and preventing malware propagation. However, accurately detecting early-stage attacks is challenging, as attackers employ stealthy, zero-day, or adversarial machine learning to evade detection. To enhance security, we propose ARIoTEDef, an Adversarially Robust IoT Early Defense system, which identifies early-stage infections and evolves autonomously. It models multi-stage attacks based on a cyber kill chain and maintains stage-specific detectors. When anomalies in the later action stage emerge, the system retroactively analyzes event logs using an attention-based sequence-to-sequence model to identify early infections. Then, the infection detector is updated with information about the identified infections. We have evaluated ARIoTEDef against multi-stage attacks, such as the Mirai botnet. Results show that the infection detector’s average F1 score increases from 0.31 to 0.87 after one evolution round. We have also conducted an extensive analysis of ARIoTEDef against adversarial evasion attacks. Our results show that ARIoTEDef is robust and benefits from multiple rounds of evolution. Mengdie Huang, Hyunwoo Lee 0001, Ashish Kundu, Xiaofeng Chen 0001, Anand Mudgerikar, Ninghui Li 0001, Elisa Bertino |
ACM Trans. Internet Things | 3 |
| 2023 | Understanding Backdoor Attacks through the Adaptability HypothesisabstractA poisoning backdoor attack is a rising security concern for deep learning. This type of attack can result in the backdoored model functioning normally most of the time but exhibiting abnormal behavior when presented with inputs containing the backdoor trigger, making it difficult to detect and prevent. In this work, we propose the adaptability hypothesis to understand when and why a backdoor attack works for general learning models, including deep neural networks, based on the theoretical investigation of classical kernel-based learning models. The adaptability hypothesis postulates that for an effective attack, the effect of incorporating a new dataset on the predictions of the original data points will be small, provided that the original data points are distant from the new dataset. Experiments on benchmark image datasets and state-of-the-art backdoor attacks for deep neural networks are conducted to corroborate the hypothesis. Our finding provides insight into the factors that affect the attack’s effectiveness and has implications for the design of future attacks and defenses. Xun Xian, Ganghua Wang, Jayanth Srinivasa, Ashish Kundu, Xuan Bi, Mingyi Hong 0001, Jie Ding 0002 |
ICML | 4 |
| 2023 | A Unified Detection Framework for Inference-Stage Backdoor DefensesabstractBackdoor attacks involve inserting poisoned samples during training, resulting in a model containing a hidden backdoor that can trigger specific behaviors without impacting performance on normal samples. These attacks are challenging to detect, as the backdoored model appears normal until activated by the backdoor trigger, rendering them particularly stealthy. In this study, we devise a unified inference-stage detection framework to defend against backdoor attacks. We first rigorously formulate the inference-stage backdoor detection problem, encompassing various existing methods, and discuss several challenges and limitations. We then propose a framework with provable guarantees on the false positive rate or the probability of misclassifying a clean sample. Further, we derive the most powerful detection rule to maximize the detection power, namely the rate of accurately identifying a backdoor sample, given a false positive rate under classical learning scenarios. Based on the theoretically optimal detection rule, we suggest a practical and effective approach for real-world applications based on the latent representations of backdoored deep nets. We extensively evaluate our method on 14 different backdoor attacks using Computer Vision (CV) and Natural Language Processing (NLP) benchmark datasets. The experimental findings align with our theoretical results. We significantly surpass the state-of-the-art methods, e.g., up to 300\% improvement on the detection power as evaluated by AUCROC, over the state-of-the-art defense against advanced adaptive backdoor attacks. Xun Xian, Ganghua Wang, Jayanth Srinivasa, Ashish Kundu, Xuan Bi, Mingyi Hong 0001, Jie Ding 0002 |
NeurIPS | 4 |
| 2023 | On the Dual Nature of Necessity in Use of Rust Unsafe CodeabstractRust offers both safety guarantees and high performance. Thus, it has gained significant popularity in the industry. To extend its capability as a system programming language, Rust allows unsafe blocks where the execution has low-level controls but loses the safety guarantees. In principle, unsafe blocks should only be used when necessary. However, preliminary evidence shows a different situation. This paper aims to establish a deeper view of this matter and bring endeavors toward improvement. Yuchen Zhang 0006, Ashish Kundu, Georgios Portokalidis, Jun Xu 0024 |
ESEC/SIGSOFT FSE | 2 |
| 2022 | BeautifAI - Personalised Occasion-based Makeup Recommendation
Kshitij Gulati, Mukesh K. Mohania, Ashish Kundu |
ACML | 4 |
| 2022 | An Infection-Identifying and Self-Evolving System for IoT Early Defense from Multi-Step Attacks
Hyunwoo Lee 0001, Anand Mudgerikar, Ashish Kundu, Ninghui Li 0001, Elisa Bertino |
ESORICS (2) | 3 |
| 2019 | PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity AssetsabstractUser's digital identity information has privacy and security requirements. Privacy requirements include confidentiality of the identity information itself, anonymity of those who verify and consume a user's identity information and unlinkability of online transactions which involve a user's identity. Security requirements include correctness, ownership assurance and prevention of counterfeits of a user's identity information. Such privacy and security requirements, although conflicting, are critical for identity management systems enabling the exchange of users' identity information between different parties during the execution of online transactions. Addressing all such requirements, without a centralized party managing the identity exchange transactions, raises several challenges. This paper presents a decentralized protocol for privacy preserving exchange of users' identity information addressing such challenges. The proposed protocol leverages advances in blockchain and zero knowledge proof technologies, as the main building blocks. We provide prototype implementations of the main building blocks of the protocol and assess its performance and security. Hasini Gunasinghe, Ashish Kundu, Elisa Bertino, Hugo Krawczyk, Suresh Chari, Kapil Singh, Dong Su |
WWW | 2 |
| 2018 | Research Directions in Blockchain Data Management and Analytics
Hoang Tam Vo, Ashish Kundu, Mukesh K. Mohania |
EDBT | 2 |
| 2018 | A Trusted Healthcare Data Analytics Cloud PlatformabstractThis paper presents a cloud-based system for health care applications. Our system has advanced features for preserving privacy which are essential for health care applications that deal with confidential data. We describe some of the bioinformatics applications which our system is designed for. Performance is significantly enhanced by caching, and enhanced clients for performing part of the computations are a key component of our system. Cloud, due to its pay-as-you-go pricing and API based deployment model, has become widely used for delivering and maintaining infrastructure technology for businesses. However, there are significant challenges with using the cloud for applications with strict privacy and compliance requirements; health care applications fall in this domain. This paper describes an architecture and solutions for handling these types of applications. Arun Iyengar, Ashish Kundu, Upendra Sharma, Ping Zhang 0016 |
ICDCS | 2 |
| 2018 | Efficient and Scalable Integrity Verification of Data and Query Results for Graph DatabasesabstractGraphs are used for representing and understanding objects and their relationships for numerous applications such as social networks, semantic webs, and biological networks. Integrity assurance of data and query results for graph databases is an essential security requirement. In this paper, we propose two efficient integrity verification schemes - HMACs for graphs (gHMAC) for two-party data sharing, and redactable HMACs for graphs (rgHMAC) for third-party data sharing, such as a cloud-based graph database service. The proposed schemes have linear complexity in terms of the number of vertices and edges in the graphs, which is shown to be optimal. Our experimental results corroborate that the proposed HMAC-based schemes for graphs are highly efficient as compared to the digital signature-based schemes - computation of HMAC tags is about 10 times faster than the computation of digital signatures. Muhammad Umer Arshad, Ashish Kundu, Elisa Bertino, Arif Ghafoor, Chinmay Kundu |
ICDE | 2 |
| 2018 | Efficient and Scalable Integrity Verification of Data and Query Results for Graph DatabasesabstractGraphs are used for representing and understanding objects and their relationships for numerous applications such as social networks, Semantic Webs, and biological networks. Integrity assurance of data and query results for graph databases is an essential security requirement. In this paper, we propose two efficient integrity verification schemes-HMACs for graphs (gHMAC) for two-party data sharing, and redactable HMACs for graphs (rgHMAC) for third-party data sharing, such as a cloud-based graph database service. We compute one HMAC value for both the schemes and two other verification objects for rgHMAC scheme that are shared with the verifier. We show that the proposed schemes are provably secure with respect to integrity attacks on the structure and/or content of graphs and query results. The proposed schemes have linear complexity in terms of the number of vertices and edges in the graphs, which is shown to be optimal. Our experimental results corroborate that the proposed HMAC-based schemes for graphs are highly efficient as compared to the digital signature-based schemes-computation of HMAC tags is about 10 times faster than the computation of digital signatures. Muhammad Umer Arshad, Ashish Kundu, Elisa Bertino, Arif Ghafoor, Chinmay Kundu |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2017 | Compliance-Aware Provisioning of Containers on CloudabstractDeploying applications in containers has several advantages, such as rapid development, portability across different machines, and simplified maintenance. In a cloud computing environment, container scheduling algorithms coordinate with different aspects of physical systems, such as memory allocation for tasks of different users. The scheduled containers on a host may process sensitive data. For instance, containers may process healthcare information. In that case, diverse cloud environments with different components and subsystems may lead to a potential personal health information leakage and violation of data privacy. In this paper, we introduce a novel compliance-aware analysis model for provisioning containers in the cloud, that provides a HIPAA compliance model. The proposed method dynamically analyzes different requirements of HIPAA complaint containers (HIPAA parameters) and their associated risk values. Based on the risk optimization of the compliance parameters for data security and data privacy of the containers, our proposed method determines scheduling of containers that offer the lowest risk to healthcare data and to the compliance posture of the container. The model describes the resources that are associated with highlevel risks and provides real-time resource recommendation for a container scheduler to decrease the risk of HIPAA compliance violation. Mehdi Bahrami, Abhishek Malvankar, Karan Kumar Budhraja, Chinmay Kundu, Mukesh Singhal, Ashish Kundu |
CLOUD | 6 |
| 2017 | Risk-Based Packet Routing for Privacy and Compliance-Preserving SDNabstractSoftware Defined Networking (SDN) is increasingly being used in data centers as well as enterprise networks. In an environment that has strict compliance requirements, such as HIPAA compliance, a critical role for an SDN controller is to route all data packets while considering data privacy preservation and compliance-preservation. In this paper, we address this problem by proposing a routing protocol for SDN which is an efficient risk-based swarm routing protocol. The programmable capability of controllers is exploited in order to minimize privacy and compliance risks in data transmission. The proposed routing protocol is based on the Ant Colony Optimization technique and machine learning, while the data for learning is obtained from OVSDB and the OpenvSwitch Database management protocol. We collect a history of packet transfers for training purposes and learn from the training data to efficiently and intelligently route sensitive data packets while it preserves the target compliance. This routing is obtained by intelligent eviction of rules that are downloaded to the switches. We have implemented the proposed schemes based on an RYU controller. Karan Kumar Budhraja, Abhishek Malvankar, Mehdi Bahrami, Chinmay Kundu, Ashish Kundu, Mukesh Singhal |
CLOUD | 5 |
| 2016 | Security, Compliance, and Agile Deployment of Personal Identifiable Information Solutions on a Public CloudabstractA public cloud platform offers economy of scale, ease of management, and elasticity to solutions. In addition, regulatory compliance and security must be assured for solutions handling sensitive data, such as student and healthcare data. With the steep rise in data breaches at large enterprises, it is a requirement to emphasize the security, privacy, and compliance of cloud-delivered solutions that hold personally identifiable information (PII). An example of a solution in need of such assurances is an education and learning-related analytics service that handles confidential student data on a public cloud platform. In this paper, we propose an approach for managing the security and privacy of an education and learning-analytics solution on a public cloud platform while assuring compliance with the Family Educational Rights and Privacy Act (FERPA). We also propose a new agile deployment approach that is both rapid and automatic. A prototype of a learning-analytics solution was implemented on a SoftLayer public cloud, and the new deployment method was evaluated in comparison with existing methods. Yasuharu Katsuno, Ashish Kundu, Koushik K. Das, Hitomi Takahashi, Robert Schloss, Mukesh K. Mohania |
CLOUD | 2 |
| 2014 | Security of graph data: hashing schemes and definitionsabstractUse of graph-structured data models is on the rise - in graph databases, in representing biological and healthcare data as well as geographical data. In order to secure graph-structured data, and develop cryptographically secure schemes for graph databases, it is essential to formally define and develop suitable collision resistant one-way hashing schemes and show them they are efficient. The widely used Merkle hash technique is not suitable as it is, because graphs may be directed acyclic ones or cyclic ones. In this paper, we are addressing this problem. Our contributions are: (1) define the practical and formal security model of hashing schemes for graphs, (2) define the formal security model of perfectly secure hashing schemes, (3) describe constructions of hashing and perfectly secure hashing of graphs, and (4) performance results for the constructions. Our constructions use graph traversal techniques, and are highly efficient for hashing, redaction, and verification of hashes graphs. We have implemented the proposed schemes, and our performance analysis on both real and synthetic graph data sets support our claims. Muhammad Umer Arshad, Ashish Kundu, Elisa Bertino, Krishna Madhavan, Arif Ghafoor |
CODASPY | 2 |
| 2014 | Service Usage Metering in Hybrid Cloud EnvironmentsabstractWith the proliferation of cloud based services - IaaS, PaaS, and SaaS - enterprises are increasingly consuming all type of IT services delivered by cloud providers. These cloud services are increasingly being used to create integrated solutions where some of the component services are delivered from on-premise private cloud environments and the remaining are provided by off-premise providers. While this best-of-breed approach results in flexible and agile business solutions, it also raises significant problems related to metering, billing, charge back and accounting. In this paper, after reviewing common hybrid cloud integration patterns, we discuss the importance of usage metering and the associated challenges in hybrid cloud environments. We then present a novel solution for metering of services delivered from multiple cloud providers. In this approach, service metering is keyed off of the life-cycle events generated by the service management controls across the hybrid cloud. By identifying life-cycle events associated with services consumed, service usage is tracked from all sources and then filtered and aggregated in a centralized manner. The aggregated information can then be used in an on-line manner for policy-based service delivery, charge-back, billing and reporting, and auditing. Based on this approach we have developed an end-to-end service usage metering and billing system for hybrid cloud environments. Some of the key underlying technologies have been incorporated in IBM SmartCloud Orchestrator - an IBM offering for managing workload patterns in multi cloud environments. Vijay K. Naik, Kirk A. Beaty, Ashish Kundu |
IC2E | 3 |
| 2014 | Towards a Systematic Study of the Covert Channel Attacks in Smartphones
Swarup Chandra, Zhiqiang Lin 0001, Ashish Kundu, Latifur Khan |
SecureComm (1) | 3 |
| 2013 | Network-Level Access Control Management for the CloudabstractOne of the major security threats that public cloud computing platforms face today is that the active cloud virtual machine instances are visible and accessible via the public internet, which allows hackers to carry out several types of attacks such as Denial of Service (DoS) and intrusion over along durations which increases the probabilities of successful penetration. Security logs of the failed attempts attest to the real threat and the intensity and duration of these. Most systems running on public cloud instances today are not security hardened to withstand such persistent and long attacks. It is not only dangerous but also disastrous for the enterprise that uses such instances to deliver cloud services, for the users that use such services, and for the cloud provider that provides the cloud infrastructure. Therefore, what is required is a network level access control solution that facilitates delivery of cloud services while protecting the network perimeter of the solution in a useable and dynamically customisable manner. In this paper, we have described such a network-based access control solution for public cloud services that we have designed and developed and is applicable to any of the various cloud platforms available today. We have deployed our solution as part of the "Security-as-a-Service" model on IBM Smart Cloud Enterprise (SCE), and has been used for commercial delivery of cloud services. These applications have led to not only high level of security with no security attacks via network exposure on the services, but also significant savings on the cost of maintaining the security of such instances and services. We have also studied the challenges that network address translators (NATs) pose for network-based access control on public cloud, and have developed solutions for such challenges. Kirk A. Beaty, Ashish Kundu, Vijay K. Naik, Arup Acharya |
IC2E | 2 |
| 2013 | Towards Authenticated Objects
Daniele Midi, Ashish Kundu, Elisa Bertino |
NSS | 2 |
| 2012 | Leakage-free redactable signaturesabstractRedactable signatures for linear-structured data such as strings have already been studied in the literature. In this paper, we propose a formal security model for leakage-free redactable signatures (LFRS) that is general enough to address authentication of not only trees but also graphs and forests. LFRS schemes have several applications, especially in enabling secure data management in the emerging cloud computing paradigm as well as in healthcare, finance and biological applications. We have also formally defined the notion of secure names. Such secure names facilitate leakage-free verification of ordering between siblings/nodes. The paper also proposes a construction for secure names, and a construction for leakagefree redactable signatures based on the secure naming scheme. The proposed construction computes a linear number of signatures with respect to the size of the data object, and outputs only one signature that is stored, transmitted and used for authentication of any tree, graph and forest. Ashish Kundu, Mikhail J. Atallah, Elisa Bertino |
CODASPY | 1 |
| 2011 | A New Class of Buffer Overflow AttacksabstractIn this paper, we focus on a class of buffer overflow vulnerabilities that occur due to the "placement new'' expression in C++. "Placement new'' facilitates placement of an object/array at a specific memory location. When appropriate bounds checking is not in place, object overflows may occur. Such overflows can lead to stack as well as heap/data/bss overflows, which can be exploited by attackers in order to carry out the entire range of attacks associated with buffer overflow. Unfortunately, buffer overflows due to "placement new'' have neither been studied in the literature nor been incorporated in any tool designed to detect and/or address buffer overflows. In this paper, we show how the "placement new'' expression in C++ can be used to carry out buffer overflow attacks - on the stack as well as heap/data/bss. We show that overflowing objects and arrays can also be used to carry out virtual table pointer subterfuge, as well as function and variable pointer subterfuge. Moreover, we show how "placement new" can be used to leak sensitive information, and how denial of service attacks can be carried out via memory leakage. Ashish Kundu, Elisa Bertino |
ICDCS | 1 |
| 2010 | How to authenticate graphs without leakingabstractSecure data sharing in multi-party environments requires that both authenticity and confidentiality of the data be assured. Digital signature schemes are commonly employed for authentication of data. However, no such technique exists for directed graphs, even though such graphs are one of the most widely used data organization structures. Existing schemes for DAGs are authenticity-preserving but not confidentiality-preserving, and lead to leakage of sensitive information during authentication. In this paper, we propose two schemes on how to authenticate DAGs and directed cyclic graphs without leaking, which are the first such schemes in the literature. It is based on the structure of the graph as defined by depth-first graph traversals and aggregate signatures. Graphs are structurally different from trees in that they have four types of edges: tree, forward, cross, and back-edges in a depth-first traversal. The fact that an edge is a forward, cross or a back-edge conveys information that is sensitive in several contexts. Moreover, back-edges pose a more difficult problem than the one posed by forward, and cross-edges primarily because back-edges add bidirectional properties to graphs. We prove that the proposed technique is both authenticity-preserving and non-leaking. While providing such strong security properties, our scheme is also efficient, as supported by the performance results. Ashish Kundu, Elisa Bertino |
EDBT | 1 |
| 2009 | SN2K Attacks and Honest ServicesabstractIn this paper, we define and illustrate a new form of attack in the context of software services: the software-based need-to-know (SN2K) attack. SN2K attacks can be carried out by dishonest provider of a software service so that it can maliciously gain access to sensitive information, even if the service does {\em not need to know} such data in order to compute the functionalities offered by it. We prove that it is generally undecidable to detect whether a given implementation of a service is dishonest, i.e., it implements an SN2K attack. A certification scheme for honest services is also proposed; our scheme relies on program slicing and certain other aspects of static program analysis. Ashish Kundu |
COMPSAC (2) | 1 |
| 2008 | Efficient Data Authentication in an Environment of Untrusted Third-Party DistributorsabstractIn the third-party model for the distribution of data, the trusted data creator or owner provides an untrusted party V with data and integrity verification (IV) items for that data. When a user U gets a subset of the data at D or is already in possession of that subset, U may request from D the IV items that make it possible for U to verify the integrity of its data: D must then provide U with the (hopefully small) number of needed IVs. Most of the published work in this area uses the Merkle tree or variants thereof. For the problem of 2-dimensional range data, the best published solutions require V to store O(n log n) IV items for a database of n items, and allow a user IA to be sent only O(log n) of those IVs for the purpose of verifying the integrity of the data it receives from D (regardless of the size of lA's query rectangle). For data that is modeled as a 2-dimensional grid (such as GIS or image data), this paper shows that better bounds are possible: The number of IVs stored at D (and the time it takes to compute them) can be brought down to O(n), and the number of IVs sent to IA for verification can be brought down to a constant. Mikhail J. Atallah, YounSun Cho, Ashish Kundu |
ICDE | 3 |
| 2008 | A tree-covering problem arising in integrity of tree-structured data
Mikhail J. Atallah, Greg N. Frederickson, Ashish Kundu |
Inf. Process. Lett. | 3 |
| 2008 | Structural signatures for tree data structuresabstractData sharing with multiple parties over a third-party distribution framework requires that both data integrity and confidentiality be assured. One of the most widely used data organization structures is the tree structure. When such structures encode sensitive information (such as in XML documents), it is crucial that integrity and confidentiality be assured not only for the content, but also for the structure. Digital signature schemes are commonly used to authenticate the integrity of the data. The most widely used such technique for tree structures is the Merkle hash technique, which however is known to be "not hiding", thus leading to unauthorized leakage of information. Most techniques in the literature are based on the Merkle hash technique and thus suffer from the problem of unauthorized information leakages. Assurance of integrity and confidentiality (no leakages) of tree-structured data is an important problem in the context of secure data publishing and content distribution systems. In this paper, we propose a signature scheme for tree structures, which assures both confidentiality and integrity and is also efficient, especially in third-party distribution environments. Our integrity assurance technique, which we refer to as the "Structural signature scheme", is based on the structure of the tree as defined by tree traversals (pre-order, post-order, in-order) and is defined using a randomized notion of such traversal numbers. In addition to formally defining the technique, we prove that it protects against violations of content and structural integrity and information leakages. We also show through complexity and performance analysis that the structural signature scheme is efficient; with respect to the Merkle hash technique, it incurs comparable cost for signing the trees and incurs lower cost for user-side integrity verification. Ashish Kundu, Elisa Bertino |
Proc. VLDB Endow. | 1 |
| 2008 | A New Model for Secure Dissemination of XML ContentabstractThe paper proposes an approach to content dissemination that exploits the structural properties of an Extensible Markup Language (XML) document object model in order to provide an efficient dissemination and at the same time assuring content integrity and confidentiality. Our approach is based on the notion of encrypted postorder numbers that support the integrity and confidentiality requirements of XML content as well as facilitate efficient identification, extraction, and distribution of selected content portions. By using such notion, we develop a structure-based routing scheme that prevents information leaks in the XML data dissemination, and assures that content is delivered to users according to the access control policies, that is, policies specifying which users can receive which portions of the contents. Our proposed dissemination approach further enhances such structure-based, policy-based routing by combining it with multicast in order to achieve high efficiency in terms of bandwidth usage and speed of data delivery, thereby enhancing scalability. Our dissemination approach thus represents an efficient and secure mechanism for use in applications such as publish--subscribe systems for XML Documents. The publish--subscribe model restricts the consumer and document source information to the routers to which they register with. Our framework facilitates dissemination of contents with varying degrees of confidentiality and integrity requirements in a mix of trusted and untrusted networks, which is prevalent in current settings across enterprise networks and the web. Also, it does not require the routers to be aware of any security policy in the sense that the routers do not need to implement any policy related to access control. Ashish Kundu, Elisa Bertino |
IEEE Trans. Syst. Man Cybern. Part C | 1 |
| 2006 | Secure Dissemination of XML Content Using Structure-based RoutingabstractThe paper proposes an approach to content dissemination that exploits the structural properties of XML document object model in order to provide efficient dissemination by at the same time assuring content integrity and confidentiality. Our approach is based on the notion of encrypted post-order numbers that support the integrity and confidentiality requirements of XML content as well as facilitate efficient identification, extraction and distribution of selected content portions. By using such notion, we develop a structure-based routing scheme that prevents information leaks in XML-data dissemination and assures that content is delivered to users according to the access control policies, that is, policies specifying which users can receive which portions of the contents. Our proposed dissemination approach further enhances such structure-based, policy-based routing by combining it with multicast in order to provide high efficiency in terms of bandwidth usage and speed of data delivery, thereby enhancing scalability Ashish Kundu, Elisa Bertino |
EDOC | 1 |
| 2005 | Building Applications Using End to End Composition of Web Services
Vikas Agarwal, Girish Chafle, Koustuv Dasgupta, Neeran M. Karnik, Arun Kumar 0002, Ashish Kundu, Anupam Mediratta, Sumit Mittal, Biplav Srivastava |
AAAI | 6 |
| 2005 | A service creation environment based on end to end composition of Web servicesabstractThe demand for quickly delivering new applications is increasingly becoming a business imperative today. Application development is often done in an ad hoc manner, without standard frameworks or libraries, thus resulting in poor reuse of software assets. Web services have received much interest in industry due to their potential in facilitating seamless business-to-business or enterprise application integration. A web services composition tool can help automate the process, from creating business process functionality, to developing executable workflows, to deploying them on an execution environment. However, we find that the main approaches taken thus far to standardize and compose web services are piecemeal and insufficient. The business world has adopted a (distributed) programming approach in which web service instances are described using WSDL, composed into flows with a language like BPEL and invoked with the SOAP protocol. Academia has propounded the AI approach of formally representing web service capabilities in ontologies, and reasoning about their composition using goal-oriented inferencing techniques from planning. We present the first integrated work in composing web services end to end from specification to deployment by synergistically combining the strengths of the above approaches. We describe a prototype service creation environment along with a use-case scenario, and demonstrate how it can significantly speed up the time-to-market for new services. Vikas Agarwal, Koustuv Dasgupta, Neeran M. Karnik, Arun Kumar 0002, Ashish Kundu, Sumit Mittal, Biplav Srivastava |
WWW | 5 |