T. Paul Parker

dblp:73/3085 · also Timothy Paul Parker · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
0since 2021 · last 2012
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Network security · 28% Systems and software security · 21% Cryptographic primitives and cryptanalysis · 16%
Computer networks
1 paper
Network management and operations · 100%

Topics — the 7 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures
0.112012
Enhancing Data Trustworthiness via Assured Digital Signing · IEEE Trans. Dependable Secur. Comput. 2012
Systems and software security
trusted computing
0.112012
Enhancing Data Trustworthiness via Assured Digital Signing · IEEE Trans. Dependable Secur. Comput. 2012
Hardware security and side channels
trusted execution environments
0.112012
Enhancing Data Trustworthiness via Assured Digital Signing · IEEE Trans. Dependable Secur. Comput. 2012
Network security › attack modeling
attack graph analysis
0.112011
A Stochastic Model for Quantitative Security Analyses of Networked Systems · IEEE Trans. Dependable Secur. Comput. 2011
Cryptographic protocols and secure computation
threshold cryptography
0.112011
Exploiting Trust-Based Social Networks for Distributed Protection of Sensitive Data · IEEE Trans. Inf. Forensics Secur. 2011
Systems and software security
virtualization security
0.012012
Enhancing Data Trustworthiness via Assured Digital Signing · IEEE Trans. Dependable Secur. Comput. 2012
Privacy and data protection
social network privacy
0.012011
Exploiting Trust-Based Social Networks for Distributed Protection of Sensitive Data · IEEE Trans. Inf. Forensics Secur. 2011

Methods — techniques the papers use, named apart from their topics

stochastic modeling · 0.2simulation · 0.2virtualization · 0.1trusted computing · 0.1threshold cryptography · 0.1
YearPublicationVenuePosition
2012 Enhancing Data Trustworthiness via Assured Digital Signing
abstract
Digital signatures are an important mechanism for ensuring data trustworthiness via source authenticity, integrity, and source nonrepudiation. However, their trustworthiness guarantee can be subverted in the real world by sophisticated attacks, which can obtain cryptographically legitimate digital signatures without actually compromising the private signing key. This problem cannot be adequately addressed by a purely cryptographic approach, by the revocation mechanism of Public Key Infrastructure (PKI) because it may take a long time to detect the compromise, or by using tamper-resistant hardware because the attacker does not need to compromise the hardware. This problem will become increasingly more important and evident because of stealthy malware (or Advanced Persistent Threats). In this paper, we propose a novel solution, dubbed Assured Digital Signing (ADS), to enhancing the data trustworthiness vouched by digital signatures. In order to minimize the modifications to the Trusted Computing Base (TCB), ADS simultaneously takes advantage of trusted computing and virtualization technologies. Specifically, ADS allows a signature verifier to examine not only a signature's cryptographic validity but also its system security validity that the private signing key and the signing function are secure, despite the powerful attack that the signing application program and the general-purpose Operating System (OS) kernel are malicious. The modular design of ADS makes it application-transparent (i.e., no need to modify the application source code in order to deploy it) and almost hypervisor-independent (i.e., it can be implemented with any Type I hypervisor). To demonstrate the feasibility of ADS, we report the implementation and analysis of an Xen-based ADS system.
Weiqi Dai, T. Paul Parker, Hai Jin 0001, Shouhuai Xu
IEEE Trans. Dependable Secur. Comput.2
2011 A Stochastic Model for Quantitative Security Analyses of Networked Systems
abstract
Traditional security analyses are often geared toward cryptographic primitives or protocols. Although such analyses are necessary, they cannot address a defender's need for insight into which aspects of a networked system having a significant impact on its security, and how to tune its configurations or parameters so as to improve security. This question is known to be notoriously difficult to answer, and the state of the art is that we know little about it. Toward ultimately addressing this question, this paper presents a stochastic model for quantifying security of networked systems. The resulting model captures two aspects of a networked system: 1) the strength of deployed security mechanisms such as intrusion detection systems and 2) the underlying vulnerability graph, which reflects how attacks may proceed. The resulting model brings the following insights: 1) How should a defender “tune” system configurations (e.g., network topology) so as to improve security? 2) How should a defender “tune” system parameters (e.g., by upgrading which security mechanisms) so as to improve security? 3) Under what conditions is the steady-state number of compromised entities of interest below a given threshold with a high probability? Simulation studies are conducted to confirm the analytic results, and to show the tightness of the bounds of certain important metric that cannot be resolved analytically.
Xiaohu Li, T. Paul Parker, Shouhuai Xu
IEEE Trans. Dependable Secur. Comput.2
2011 Exploiting Trust-Based Social Networks for Distributed Protection of Sensitive Data
abstract
How can we protect sensitive data of average users? In this paper, we propose taking advantage of real-life social trust between average users (called “trust-based social networks”) as well as threshold cryptography. This leads to a new type of complex systems, for which we define and characterize the following novel properties: 1) attack-resilience, which captures the consequences of computers getting compromised; 2) security utility of anonymous social networks, which captures the security gained when the underlying social network links are not known to the attacker; 3) security utility of psychological soundness, which captures the security gained when a user keeps a decisive share of its sensitive data; 4) availability, which captures the effect when computers are not always responsive; 5) the trade-off between attack-resilience and availability.
Shouhuai Xu, Xiaohu Li, T. Paul Parker
IEEE Trans. Inf. Forensics Secur.3
2008 Exploiting social networks for threshold signing: attack-resilience vs. availability
abstract
Digital signatures are an important security mechanism, especially when non-repudiation is desired. However, non-repudiation is meaningful only when the private signing keys and functions are adequately protected --- an assumption that is very difficult to accommodate in the real world because computers (and thus cryptographic keys and functions) could be relatively easily compromised. One approach to resolving, or at least alleviating, this problem is to use threshold cryptography. But how should such techniques be employed in the real world? In this paper we propose exploiting social networks whereby average users take advantage of their trusted ones to help secure their cryptographic keys. While the idea is simple from an individual user's perspective, we aim to understand the resulting systems from a whole-system perspective. Specifically, we propose and investigate two measures of the resulting systems: attack-resilience, which captures the security consequences due to the compromise of some computers and thus the compromise of the cryptographic key shares stored on them; availability, which captures the effect when computers are not always responsive (due to the peer-to-peer nature of social networks).
Shouhuai Xu, Xiaohu Li, T. Paul Parker
AsiaCCS3
2007 Towards Quantifying the (In)Security of Networked Systems
abstract
Traditional security analyses are often geared towards cryptographic primitives or protocols. Although such analyses are absolutely necessary, they do not provide much insight for answering an equally important question: what is the security assurance of a physically or logically networked system when we consider it as a whole? This question is known to be notoriously difficult, and the state-of-the-art is that we know very little about it. In this paper, we make a step towards resolving it with a new modeling approach.
Xiaohu Li, T. Paul Parker, Shouhuai Xu
AINA2
2007 How to Secure Your Email Address Book and Beyond
Erhan J. Kartaltepe, T. Paul Parker, Shouhuai Xu
CANS2
2007 Towards an analytic model of epidemic spreading in heterogeneous systems
abstract
Mathematical models have been utilized to help understand the epidemic spreading of malicious codes (e.g., computer virus and worms). However, existing such models are either adapted from the ones developed to capture the epidemic spreading of biologically infectious diseases in homogeneous systems, or suitable only for a very specific class of heterogeneous systems. In this paper we present an attempt at building an analytic model of epidemic spreading of malicious codes in arbitrary heterogeneous systems.
Xiaohu Li, T. Paul Parker, Shouhuai Xu
QSHINE2
2006 Towards Understanding the (In)security of Networked Systems under Towards Understanding the (In)security of Networked Systems under Topology-Directed Stealthy Attacks
abstract
Consider a networked system of interest, where "networked" may be in a physical sense, meaning that the nodes are physically connected by point-to-point communication channels, or in a logical sense, meaning that the nodes are connected via edges that reflect certain relationships between the nodes (e.g., trust relationships). In such a system, once some nodes have been compromised, the attack would be directed by the network topology because compromise of a node may cause the compromise of its neighbors. Furthermore, the attack could be crafty or stealthy, meaning that it would always try not to trigger the intrusion detection alarm of the networked system. In such a setting, a question of particular interest to the system administrator is: What is the quantitative security assurance of the networked system? This problem is notoriously known to be difficult, and the state-of-the-art is that we know very little about it. This paper aims to move a step towards resolving this problem
T. Paul Parker, Shouhuai Xu
DASC1