EDBT 2026 Demo / reviewers in the wild / expert
Peter Amthor 0001
dblp:65/5286-1
· DBLP profile ↗
10ranked-venue papers
8as first author
3since 2021 · last 2024
0000-0001-7711-4450ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 7 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | APP-CEP: Adaptive Pattern-Level Privacy Protection in Complex Event Processing SystemsabstractAlthough privacy-preserving mechanisms endeavor to safeguard sensitive information at the attribute level, detected event patterns can still disclose privacy-sensitive knowledge in distributed complex event processing systems (DCEP). Events might not be inherently sensitive, but their aggregation into a pattern could still breach privacy. In this paper, we study in the context of APP-CEP the problem of integrating pattern-level privacy in event-based systems by selective assignment of obfuscation techniques to conceal private information. Compared to state-of-the-art techniques, we seek to enforce privacy independent of the actual events in streams. To support this, we acquire queries and privacy requirements using CEP-like patterns. The protection of privacy is accomplished through generating pattern dependency graphs, leading to dynamically appointing those techniques that have no consequences on detecting other sensitive patterns, as well as non-sensitive patterns required to provide acceptable Quality of Service. Besides, we model the knowledge that might be possessed by potential adversaries to violate privacy and its impacts on the obfuscation procedure. We assessed the performance of APP-CEP in a real-world scenario involving an online retailer’s transactions. Our evaluation results demonstrate that APP-CEP successfully provides a privacy-utility trade-off. Modeling the background knowledge also effectively prevents adversaries from realizing the modifications in the input streams. Majid Lotfian Delouee, Viktoriya Degeler, Peter Amthor 0001, Boris Koldehofe |
ICISSP | 3 |
| 2024 | A Composition Algebra for Decentralized Enforcement of Access Control Policies with an Application to Vehicular NetworksabstractHighly volatile and open distributed systems typically incorporate a significant amount of secure interactions between autonomous agents. This is especially true for vehicular networks, where smart or autonomous vehicles rely on information shared with each other or traffic infrastructure. However, controlling such decentralized interaction with respect to security restrictions requires a common definition of a temporary composite policy. As a first step towards this goal, this paper presents ACCA, a lightweight extension of Boolean algebra which allows to precisely specify how access control policies should be composed. It enables to build vehicular network systems that retain independence and autonomy of their participants while reducing the amount of communication about policy knowledge. An implementation of a simulation prototype of ACCA serves as a first, promising step towards tailoring the compositional semantics to specific use cases. Peter Amthor 0001, René Gorges |
SECRYPT | 1 |
| 2021 | The Missing Piece of the ABAC Puzzle: A Modeling Scheme for Dynamic AnalysisabstractAttribute-based access control (ABAC) has made its way into the mainstream of engineering secure IT systems. At the same time, ABAC models are still lagging behind well-understood, yet more basic access control models in terms of dynamic analyzability. This has led to a plethora of methods, languages, and tools for designing and integrating ABAC policies, but only few to formally reason about them in the process. We present DABAC, a modeling scheme to pick up that missing piece and put it right into its place in the security engineering workflow. Based on an automaton calculus, we demonstrate how DABAC can be leveraged as a holistic formal basis for engineering ABAC models, analyzing their dynamic properties, and providing a functional specification for their implementation. This sets the stage for comprehensive tool support in building future ABAC systems. Marius Schlegel, Peter Amthor 0001 |
SECRYPT | 2 |
| 2019 | Automated Cyber Threat Sensing and Responding: Integrating Threat Intelligence into Security-Policy-Controlled SystemsabstractCyber security management requires fast and cost efficient responses to threat alerts. Automation of cyber threat sensing and responding is one way to achieve immediate reactions to imminent threats. There are already tools for an extensive automation of threat sensing, e.g. threat intelligence sharing platforms. Methods, techniques and tools for reacting to menacing states and events, e.g. security-policy-controlled systems, have also been explored and published for some time. What is still missing, however, is the integration of these two approaches. This paper describes first steps towards an integration of threat intelligence sharing platforms and security-policy-controlled systems. We present a conceptual design for threat reaction strategies, security architectures and mechanisms and information representation requirements. We use two exemplary threat scenarios to demonstrate our proposals. Peter Amthor 0001, Daniel Fischer 0003, Winfried E. Kühnhauser, Dirk Stelzer |
ARES | 1 |
| 2017 | Efficient Heuristic Safety Analysis of Core-based Security PoliciesabstractBeing of paramount importance for the correctness of a security policy, the property of safety has received decades of attention in the field of model-based security engineering. To analyze the safety of a security model, heuristic approaches are used to avoid restrictions of the model calculus while accepting semi-decidability of this property. Within this field, this paper addresses three open problems concerning the DEPSEARCH heuristic safety analysis framework: Inefficient state-space exploration, static verification of unsafety-unsatisfiability, and parameter dependency analysis. We describe these problems on a formal basis, specify solution proposals, and implement these in the current, model-independent fDS framework. A practical evaluation based on SELinux is performed to study effectiveness and future optimization of the framework. Peter Amthor 0001 |
SECRYPT | 1 |
| 2015 | A Uniform Modeling Pattern for Operating Systems Access Control Policies with an Application to SELinuxabstractModern operating systems increasingly rely on enforcing mandatory access control through the use of security policies. Given the critical property of policy correctness in such systems, formal methods and models are applied for both specification and verification of these policies. Due to the heterogeneity of their respective semantics, this is an intricate and error-prone engineering process. However, diverse access control systems on the one hand and diverse formal criteria of correctness on the other hand have so far impeded a unifying framework for this task. This paper presents a step towards this goal. We propose to leverage core-based model engineering, a uniform approach to security policy formalization, and refine it by adding typical semantic abstractions of contemporary policy-controlled operating systems. This results in a simple, yet highly flexible framework for formalization, specification and analysis of operating system security policies. We substantiate this claim by applying our method to the SELinux system and practically demonstrate how to map policy semantics to an instance of the model. Peter Amthor 0001 |
SECRYPT | 1 |
| 2015 | Security Policy Synthesis in Mobile SystemsabstractContemporary mobile devices have become universal and versatile tools that increasingly are used in sensitive application scenarios. They inevitably carry confidential information such as passwords, encryption keys, mission-critical company data, or location information in combat areas. In order to meet sophisticated security requirements, recent technology focuses on policy-oriented approaches that allow for the definition and enforcement of rigorous and precise rules for protecting confidential information. State-of-the-art development of security policies is a critical process, because of the involved quality assurance measures, it is quite heavy-weighted and tends to antagonize the distinguished virtues of mobile devices for lightweight, spontaneous communication and cooperation. This paper presents an approach to support secure, mobile device based cooperation in temporary, sporadically and spontaneously fashioned cliques within open communication infrastructures. The approach is based upon light-weight security domains protected by security policies that are dynamically and automatically composed during group formation. Due to the volatile nature of such groups simplicity, adaptability, efficiency and compatibility with today's security policy implementation techniques have been a major design goal. Peter Amthor 0001, Winfried E. Kühnhauser |
SERVICES | 1 |
| 2014 | WorSE: A Workbench for Model-based Security Engineering
Peter Amthor 0001, Winfried E. Kühnhauser, Anja Pölck |
Comput. Secur. | 1 |
| 2013 | Heuristic safety analysis of access control modelsabstractModel-based security engineering uses formal security models for specifying and analyzing access control systems. Tool-based model analysis encounters a fundamental difficulty here: on the one hand, real-world access control systems generally are quite large and complex and require models that have high expressive power. On the other hand, analysis of such models is often pestered by computational complexity or even non-decidability, making it difficult to devise algorithms for automated analysis tools. One approach to this problem is to limiting the expressive power of the modeling calculus, resulting in restrictions to the spectrum of application scenarios that can be modeled. In this paper we propose a different approach: a heuristic-based method for analyzing the safety properties of access control models with full expressive power. Aiming at generality, the paper focuses on the lineage of HRU-style, automaton-based access control models that are fundamental for modeling the dynamic behavior of contemporary role-based or attribute-based access control systems. Peter Amthor 0001, Winfried E. Kühnhauser, Anja Pölck |
SACMAT | 1 |
| 2011 | Model-based safety analysis of SELinux security policiesabstractSince security has become an essential asset in numerous application areas, the integration of security policies has become a major issue in the design of security architectures, and many commodity operating systems have been furnished with abstractions to support policy protection and enforcement. Given a security policy's key position in defining and implementing a system's security properties, quality attributes such as policy correctness, completeness, or consistency are essential objectives in policy engineering. On the other hand, considering the large amount of their responsibilities, security policies often are large and complex, rendering the analysis and proof of crucial quality attributes difficult. This paper is a step towards tool-supported security policy analysis. It presents a model-based approach to analyze the dynamic proliferation of access rights in a policy-controlled SELinux access control system. Peter Amthor 0001, Winfried E. Kühnhauser, Anja Pölck |
NSS | 1 |