EDBT 2026 Demo / reviewers in the wild / expert
Arif Ghafoor
dblp:81/1710
· DBLP profile ↗
136ranked-venue papers
21as first author
3since 2021 · last 2023
0000-0002-3707-8173ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 2 first-authorSystems, architecture and hardware · 23 · 9 first-authorSoftware engineering, systems software and programming languages · 21 · 4 first-authorDatabases, data management, data science and information retrieval · 21Applied, interdisciplinary, general and emerging computing · 20 · 6 first-authorSecurity and privacy · 18 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 14 · 3 first-authorArtificial intelligence and machine learning · 3Theory of computation · 3 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | PRISM: A Hierarchical Intrusion Detection Architecture for Large-Scale Cyber NetworksabstractThe increase in scale of cyber networks and the rise in sophistication of cyber-attacks have introduced several challenges in intrusion detection. The primary challenge is the requirement to detect complex multi-stage attacks in realtime by processing the immense amount of traffic produced by present-day networks. In this paper we present PRISM, a hierarchical intrusion detection architecture that uses a novel attacker behavior model-based sampling technique to minimize the realtime traffic processing overhead. PRISM has a unique multi-layered architecture that monitors network traffic distributedly to provide efficiency in processing and modularity in design. PRISM employs a Hidden Markov Model-based prediction mechanism to identify multi-stage attacks and ascertain the attack progression for a proactive response. Furthermore, PRISM introduces a stream management procedure that rectifies the issue of alert reordering when collected from distributed alert reporting systems. To evaluate the performance of PRISM, multiple metrics have been proposed, and various experiments have been conducted on multi-stage attack datasets. The results exhibit up to 7.5x improvement in processing overhead as compared to a standard centralized IDS without the loss of prediction accuracy while demonstrating the ability to predict different attack stages promptly. Yahya Javed, Mosab Khayat, Ali A. Elghariani, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Guard: Attack-Resilient Adaptive Load Balancing in Distributed Streaming SystemsabstractThe performance of distributed streaming systems relies on how even the workload is distributed among their machines. However, data and query workloads are skewed and change rapidly. Therefore, multiple adaptive load-balancing mechanisms have been proposed in the literature to rebalance distributed streaming systems according to the changes in their workloads. This paper introduces a novel attack model that targets adaptive load-balancing mechanisms of distributed streaming systems. The attack reduces the throughput and the availability of the system by making it stay in a continuous state of rebalancing. This paper proposesGuard, a component that detects and blocks attacks that target the adaptive load balancing of distributed streaming systems. Guard uses an unsupervised machine-learning technique to detect malicious users that are involved in the attack. Guard does not block any user unless it detects that the user is malicious. Guard does not depend on a specific application. Experimental evaluation for a high-intensity attack illustrates that Guard improves the throughput and the availability of the system by 85% and 86%, respectively. Moreover, Guard improves the minimum availability that the attacker achieves by 325%. Anas Daghistani, Mosab Khayat, Muhamad Felemban, Walid G. Aref, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Architectures for Detecting Interleaved Multi-Stage Network Attacks Using Hidden Markov ModelsabstractWith the growing amount of cyber threats, the need for development of high-assurance cyber systems is becoming increasingly important. The objective of this article is to address the challenges of modeling and detecting sophisticated network attacks, such as multiple interleaved attacks. We present the interleaving concept and investigate how interleaving multiple attacks can deceive intrusion detection systems. Using one of the important statistical machine learning (ML) techniques, Hidden Markov Models (HMM), we develop two architectures that take into account the stealth nature of the interleaving attacks, and that can detect and track the progress of these attacks. These architectures deploy a database of HMM templates of known attacks and exhibit varying performance and complexity. For performance evaluation, in the presence of multiple multi-stage attack scenarios, various metrics are proposed which include (1) attack risk probability, (2) detection error rate, and (3) the number of correctly detected stages. Extensive simulation experiments are used to demonstrate the efficacy of the proposed architectures. Tawfeeq A. Shawly, Ali A. Elghariani, Jason Kobes, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | TrioStat: Online Workload Estimation in Distributed Spatial Data Streaming SystemsabstractThe wide spread of GPS-enabled devices and the Internet of Things (IoT) has increased the amount of spatial data being generated every second. The current scale of spatial data cannot be handled using centralized systems. This has led to the development of distributed spatial data streaming systems that scale to process in real-time large amounts of streamed spatial data. The performance of distributed streaming systems relies on how even the workload is distributed among their machines. However, it is challenging to estimate the workload of each machine because spatial data and query streams are skewed and rapidly change with time and users' interests. Moreover, a distributed spatial streaming system often does not maintain a global system workload state because it requires high network and processing overheads to be collected from the machines in the system. Anas Daghistani, Walid G. Aref, Arif Ghafoor |
SIGSPATIAL/GIS | 3 |
| 2020 | Real time Application of Malware Patching on Decentralized IoT Systems Through Disease Spread AnalysisabstractIoT networks continue to grow as devices become more accessible and affordable. Due to the mass exodus of production and use, there is room for hackers to take advantage of vulnerabilities in the system. The cloud-based infrastructure although creating an advantage in terms of growing the resources for any given IoT network, the disadvantage in terms of security intrusion are many. In this paper, we analyze a proposed hierarchical distance bound security model. This model takes on a more efficient approach to patching large IoT systems to mitigate the spread of several different types of malware attacks. We utilize SEIR disease spread model to measure the effectiveness of the security model's mitigation of malware spread in the IoT network. Nadra Guizani, Arif Ghafoor |
IWCMC | 2 |
| 2020 | A Network Function Virtualization System for Detecting Malware in Large IoT Based NetworksabstractThe exponential growth in the use of Internet of Things (IoT) devices has introduced numerous challenges, in particular dealing with new security threats. In addition, for connecting heterogeneous devices using different protocols, large networks need resilient software-based security systems that can defend against unprecedented attacks for which the traditional security countermeasures prove to be ineffective. Furthermore, to deal with the ever growing onslaught on data and networks, modern security systems need to utilize novel machine learning mechanisms. This paper proposes a software-based architecture that provides network function virtualization (NFV) capability to combat malware spread for heterogeneous IoT networks. To build a scalable and generalized Intrusion Detection System (IDS), we propose for these networks a RNN-LSTM learning model that can predict malware attacks in a timely manner for the NFV to deploy appropriate countermeasures. In addition, we investigate the scalability of the network and discuss how the generalized IDS can deal with a broad range of malwares that can be detected. The analysis utilizes the susceptible (S), exposed (E), infected (I), and resistant (R) (SEIR) epidemic model to moniter the spread of the malware attack and subsequently provides patching to the system. Our analysis focuses primarily on the feasibility and the performance evaluation of the proposed integrated RNN-LSTM and NFV architecture. Nadra Guizani, Arif Ghafoor |
IEEE J. Sel. Areas Commun. | 2 |
| 2020 | The Validity, Generalizability and Feasibility of Summative Evaluation Methods in Visual AnalyticsabstractMany evaluation methods have been used to assess the usefulness of Visual Analytics (VA) solutions. These methods stem from a variety of origins with different assumptions and goals, which cause confusion about their proofing capabilities. Moreover, the lack of discussion about the evaluation processes may limit our potential to develop new evaluation methods specialized for VA. In this paper, we present an analysis of evaluation methods that have been used to summatively evaluate VA solutions. We provide a survey and taxonomy of the evaluation methods that have appeared in the VAST literature in the past two years. We then analyze these methods in terms of validity and generalizability of their findings, as well as the feasibility of using them. We propose a new metric called summative quality to compare evaluation methods according to their ability to prove usefulness, and make recommendations for selecting evaluation methods based on their summative quality in the VA domain. Mosab Khayat, Morteza Karimzadeh, David S. Ebert, Arif Ghafoor |
IEEE Trans. Vis. Comput. Graph. | 4 |
| 2019 | A Privacy Mechanism for Access Controlled Graph DataabstractThere has been significant interest in the development of anonymization schemes for publishing graph data. However, privacy is a major concern in dealing with graph data. In this paper, an integrated framework for ensuring privacy in the presence of an authorization mechanism is proposed. Access control mechanisms provide additional safeguard against data breaches and ensure that only authorized information is available to end-users based on their assigned roles. The integrated framework highlights a tradeoff between privacy and authorized privileges. To attain a pre-specified privacy level, access privileges might need to be relaxed. For the proposed framework, we formulate the k-anonymous Bi-objective Graph Partitioning (k-BGP) problem and provide its hardness results. Heuristics solutions are developed to solve the constraint problem. The framework provides an anonymous view based on the target class of role-based workloads for graph data. The proposed heuristics are empirically evaluated and a detailed security analysis of the framework in terms of risk associated with re-identification attack is conducted. Muhammad Umer Arshad, Muhamad Felemban, Zahid Pervaiz, Arif Ghafoor, Walid G. Aref |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2019 | Threat Management in Data-centric IoT-Based Collaborative SystemsabstractIn this article, we propose a threat management system (TMS) for Data-centric Internet-of-Things-based Collaborative Systems (DIoTCSs). In particular, we focus on tampering attacks that target shared databases and can affect the execution of the DIoTCS services. The novelty of the proposed system is to isolate the damage caused by tampering attacks into data partitions. We formulate the partitioning problem as a cost-driven optimization problem, prove its NP-hardness, and propose two polynomial-time heuristics. We evaluate a TMS experimentally and demonstrate that intelligent partitioning of the database improves the overall availability of the DIoTCS. Muhamad Felemban, Emad A. Felemban, Jason Kobes, Arif Ghafoor |
ACM Trans. Internet Techn. | 4 |
| 2018 | Efficient and Scalable Integrity Verification of Data and Query Results for Graph DatabasesabstractGraphs are used for representing and understanding objects and their relationships for numerous applications such as social networks, semantic webs, and biological networks. Integrity assurance of data and query results for graph databases is an essential security requirement. In this paper, we propose two efficient integrity verification schemes - HMACs for graphs (gHMAC) for two-party data sharing, and redactable HMACs for graphs (rgHMAC) for third-party data sharing, such as a cloud-based graph database service. The proposed schemes have linear complexity in terms of the number of vertices and edges in the graphs, which is shown to be optimal. Our experimental results corroborate that the proposed HMAC-based schemes for graphs are highly efficient as compared to the digital signature-based schemes - computation of HMAC tags is about 10 times faster than the computation of digital signatures. Muhammad Umer Arshad, Ashish Kundu, Elisa Bertino, Arif Ghafoor, Chinmay Kundu |
ICDE | 4 |
| 2018 | Risk-Aware Management of Virtual Resources in Access Controlled Service-Oriented Cloud DatacentersabstractFor economic benefits and efficient management of resources, organizations are increasingly moving towards the paradigm of “cloud computing” by which they are allowed on-demand delivery of hardware, software and data as services. However, there are many security challenges which are particularly exacerbated by the multitenancy and virtualization features of cloud computing that allow sharing of resources among potentially untrusted tenants in access controlled cloud data centers. This can result in increased risk of data leakage. To address this risk vulnerability, we propose an efficient risk-aware virtual resource assignment mechanism for clouds multitenant environment. In particular, we introduce the notion of sensitivity in data centers and the objective is to minimize the risk of data leakage. In addition, the risk should not exceed in high sensitivity data centers in comparison to low sensitivity data centers. We present three assignment heuristics and compare their relative performance. Abdulrahman Almutairi, Muhammad I. Sarfraz, Arif Ghafoor |
IEEE Trans. Cloud Comput. | 3 |
| 2018 | Efficient and Scalable Integrity Verification of Data and Query Results for Graph DatabasesabstractGraphs are used for representing and understanding objects and their relationships for numerous applications such as social networks, Semantic Webs, and biological networks. Integrity assurance of data and query results for graph databases is an essential security requirement. In this paper, we propose two efficient integrity verification schemes-HMACs for graphs (gHMAC) for two-party data sharing, and redactable HMACs for graphs (rgHMAC) for third-party data sharing, such as a cloud-based graph database service. We compute one HMAC value for both the schemes and two other verification objects for rgHMAC scheme that are shared with the verifier. We show that the proposed schemes are provably secure with respect to integrity attacks on the structure and/or content of graphs and query results. The proposed schemes have linear complexity in terms of the number of vertices and edges in the graphs, which is shown to be optimal. Our experimental results corroborate that the proposed HMAC-based schemes for graphs are highly efficient as compared to the digital signature-based schemes-computation of HMAC tags is about 10 times faster than the computation of digital signatures. Muhammad Umer Arshad, Ashish Kundu, Elisa Bertino, Arif Ghafoor, Chinmay Kundu |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2017 | Composability Verification of Multi-Service Workflows in a Policy-Driven Cloud Computing EnvironmentabstractThe emergence of cloud computing infrastructure and Semantic Web technologies has created unprecedented opportunities for composing large-scale business processes and workflow-based applications that span multiple organizational domains. A key challenge related to composition of such multi-organizational business processes and workflows is posed by the security and access control policies of the underlying organizational domains. In this paper, we propose a framework for verifying secure composability of distributed workflows in an autonomous multi-domain environment. The objective of workflow composability verification is to ensure that all the users or processes executing the designated workflow tasks conform to the time-dependent security policy specifications of all collaborating domains. A key aspect of such verification is to determine the time-dependent schedulability of distributed workflows, assumed to be invoked on a recurrent basis. We use a two-step approach for verifying secure workflow composability. In the first step, a distributed workflow is decomposed into domain-specific projected workflows and is verified for conformance with the respective domain's security and access control policy. In the second step, the cross-domain dependencies amongst the workflow tasks performed by different collaborating domains are verified. Basit Shafiq, Sameera Ghayyur, Ammar Masood, Zahid Pervaiz, Abdulrahman Almutairi, M. Farrukh Khan, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2015 | Precision-Bounded Access Control Using Sliding-Window Query Views for Privacy-Preserving Data StreamsabstractAccess control mechanisms and Privacy Protection Mechanisms (PPM) have been proposed for data streams. The access control for a data stream allows roles access to tuples satisfying an authorized predicate sliding-window query. Sharing the sensitive stream data without PPM can compromise the privacy. The PPM meets privacy requirements, e.g., k-anonymity or l-diversity by generalization of stream data. Imprecision introduced by generalization can be reduced by delaying the publishing of stream data. However, the delay in sharing the stream tuples to achieve better accuracy can lead to false-negatives if the tuples are held by PPM while the query predicate is evaluated. Administrator of an access control policy defines the imprecision bound for each query. The challenge for PPM is to optimize the delay in publishing of stream data so that the imprecision bound for the maximum number of queries is satisfied. We formulate the precision-bounded access control for privacy-preserving data streams problem, present the hardness results, provide an anonymization algorithm, and conduct experimental evaluation of the proposed algorithm. Experiments demonstrate that the proposed heuristic provides better precision for a given data stream access control policy as compared to the minimum or maximum delay heuristics proposed in existing literature. Zahid Pervaiz, Arif Ghafoor, Walid G. Aref |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2015 | A Framework for Composition and Enforcement of Privacy-Aware and Context-Driven Authorization Mechanism for Multimedia Big DataabstractThe proliferation of multimedia big data for dissemination and sharing of massive amounts of information raises important security and privacy concerns. One such concern is the composition and enforcement of privacy policies in order to securely manage access of multimedia big data. Several researchers have pointed out that for proper enforcement of privacy policies, the privacy requirements should be captured in access control systems. In this paper, we propose a hybrid approach where privacy requirements are captured in an access control system and present a framework for composition and enforcement of privacy policies. The focus is to allow a user, not a system or security administrator to compose conflict free policies for their online multimedia data. An additional requirement is that such a policy be context-aware. We also present a methodology for verifying the privacy policy in order to ensure correctness and logical consistency. The verification process is also used to ensure that sensitive security requirements are not violated when privacy rules are enforced. A prototype, named Intelligent Privacy Manager (iPM), has been implemented for sharing of multimedia big data in a secure and private manner. Arjmand Samuel, Muhammad I. Sarfraz, Hammad Haseeb, Saleh M. Basalamah, Arif Ghafoor |
IEEE Trans. Multim. | 5 |
| 2014 | Security of graph data: hashing schemes and definitionsabstractUse of graph-structured data models is on the rise - in graph databases, in representing biological and healthcare data as well as geographical data. In order to secure graph-structured data, and develop cryptographically secure schemes for graph databases, it is essential to formally define and develop suitable collision resistant one-way hashing schemes and show them they are efficient. The widely used Merkle hash technique is not suitable as it is, because graphs may be directed acyclic ones or cyclic ones. In this paper, we are addressing this problem. Our contributions are: (1) define the practical and formal security model of hashing schemes for graphs, (2) define the formal security model of perfectly secure hashing schemes, (3) describe constructions of hashing and perfectly secure hashing of graphs, and (4) performance results for the constructions. Our constructions use graph traversal techniques, and are highly efficient for hashing, redaction, and verification of hashes graphs. We have implemented the proposed schemes, and our performance analysis on both real and synthetic graph data sets support our claims. Muhammad Umer Arshad, Ashish Kundu, Elisa Bertino, Krishna Madhavan, Arif Ghafoor |
CODASPY | 5 |
| 2014 | Modeling and evaluation of disease spread behaviorsabstractWith the frequent appearance and spread of infectious diseases and their casualties in major populated areas, many researchers and organizations became interested to find different ways to forecast the spread behaviors of these diseases before they occur. This can allow them to better prepare and confine the disease in small regions and therefore reduce the loss of human lives. In this paper we study the behavior and the spread of infectious diseases and model their spread in a city. This study helps generate various prevention and control techniques to build a better and a much safer living environment. This is accomplished by using a combination of geographic information system (GIS) tools and environmental controls to create a scalable, two layered; spatio-temporal Agent-Based Model (ABM) that visualizes disease spread throughout any region by showing the interaction between agents/individuals. This specific model will be tested using data from a one thousand seven hundred kilometer square (1,700 Km2) size city with a population of over three hundred thousand individuals (300,000 people). The first layer was to formulate probabilistic models to create a population, synthesizing a population of around two hundred thousand agents that would interact in a geospatial context. The second layer uses another set of probability distributions to predict a disease spread model based on health information that has been provided by the city's health officials. This model has been created with scalability in mind whether it is for a different geographical location or a larger data set. The simulation results show that this system is very efficient and confirms that it could be used in a larger setting. Nadra Guizani, Arif Ghafoor |
IWCMC | 2 |
| 2014 | Accuracy-Constrained Privacy-Preserving Access Control Mechanismfor Relational DataabstractAccess control mechanisms protect sensitive information from unauthorized users. However, when sensitive information is shared and a Privacy Protection Mechanism (PPM) is not in place, an authorized user can still compromise the privacy of a person leading to identity disclosure. A PPM can use suppression and generalization of relational data to anonymize and satisfy privacy requirements, e.g., k-anonymity and l-diversity, against identity and attribute disclosure. However, privacy is achieved at the cost of precision of authorized information. In this paper, we propose an accuracy-constrained privacy-preserving access control framework. The access control policies define selection predicates available to roles while the privacy requirement is to satisfy the k-anonymity or l-diversity. An additional constraint that needs to be satisfied by the PPM is the imprecision bound for each selection predicate. The techniques for workload-aware anonymization for selection predicates have been discussed in the literature. However, to the best of our knowledge, the problem of satisfying the accuracy constraints for multiple roles has not been studied before. In our formulation of the aforementioned problem, we propose heuristics for anonymization algorithms and show empirically that the proposed approach satisfies imprecision bounds for more permissions and has lower total imprecision than the current state of the art. Zahid Pervaiz, Walid G. Aref, Arif Ghafoor, Nagabhushana Prabhu |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2012 | M3: Stream Processing on Main-Memory MapReduceabstractThe continuous growth of social web applications along with the development of sensor capabilities in electronic devices is creating countless opportunities to analyze the enormous amounts of data that is continuously steaming from these applications and devices. To process large scale data on large scale computing clusters, MapReduce has been introduced as a framework for parallel computing. However, most of the current implementations of the MapReduce framework support only the execution of fixed-input jobs. Such restriction makes these implementations inapplicable for most streaming applications, in which queries are continuous in nature, and input data streams are continuously received at high arrival rates. In this demonstration, we showcase M3, a prototype implementation of the MapReduce framework in which continuous queries over streams of data can be efficiently answered. M3 extends Hadoop, the open source implementation of MapReduce, bypassing the Hadoop Distributed File System (HDFS) to support main-memory-only processing. Moreover, M3 supports continuous execution of the Map and Reduce phases where individual Mappers and Reducers never terminate. Ahmed M. Aly, Asmaa Sallam, Bala M. Gnanasekaran, Long-Van Nguyen-Dinh, Walid G. Aref, Mourad Ouzzani, Arif Ghafoor |
ICDE | 7 |
| 2012 | A framework for verification and optimal reconfiguration of event-driven role based access control policiesabstractRole based access control (RBAC) is the de facto model used for advanced access control due to its inherent richness and flexibility. Despite its great success at modeling a variety of organizational needs, maintaining large complex policies is a challenging problem. Conflicts within policies can expose the underlying system to numerous vulnerabilities and security risks. Therefore, more comprehensive verification tools for RBAC need to be developed to enable effective access control. In this paper, we propose a verification framework for detection and resolution of inconsistencies and conflicts in policies modeled through event-driven RBAC, an important subset of generalized temporal RBAC applicable to many domains, such as SCADA systems. We define the conflict resolution problem and propose an integer programming based heuristic. The proposed approach is generic and can be tuned to a variety of optimality measures. Basit Shafiq, Jaideep Vaidya, Arif Ghafoor, Elisa Bertino |
SACMAT | 3 |
| 2010 | A Pattern-Based Temporal XML Query Language
Xuhui Li 0001, Mengchi Liu, Arif Ghafoor, Phillip C.-Y. Sheu |
WISE | 3 |
| 2010 | Fault coverage of Constrained Random Test Selection for access control: A formal analysis
Ammar Masood, Arif Ghafoor, Aditya P. Mathur |
J. Syst. Softw. | 2 |
| 2010 | Conformance Testing of Temporal Role-Based Access Control SystemsabstractWe propose an approach for conformance testing of implementations required to enforce access control policies specified using the Temporal Role-Based Access Control (TRBAC) model. The proposed approach uses Timed Input-Output Automata (TIOA) to model the behavior specified by a TRBAC policy. The TIOA model is transformed to a deterministic se-FSA model that captures any temporal constraint by using two special events Set and Exp. The modified W-method and integer-programming-based approach are used to construct a conformance test suite from the transformed model. The conformance test suite so generated provides complete fault coverage with respect to the proposed fault model for TRBAC specifications. Ammar Masood, Arif Ghafoor, Aditya P. Mathur |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2010 | An optimal bandwidth allocation and data droppage scheme for differentiated services in a wireless networkabstractAbstract This paper presents an optimal proportional bandwidth allocation and data droppage scheme to provide differentiated services (DiffServ) for downlink pre‐orchestrated multimedia data in a single‐hop wireless network. The proposed resource allocation scheme finds the optimal bandwidth allocation and data drop rates under minimum quality‐of‐service (QoS) constraints. It combines the desirable attributes of relative DiffServ and absolute DiffServ approaches. In contrast to relative DiffServ approach, the proposed scheme guarantees the minimum amount of bandwidth provided to each user without dropping any data at the base‐station, when the network has sufficient resources. If the network does not have sufficient resources to provide minimum bandwidth guarantees to all users without dropping data, the proportional data dropper finds the optimal data drop rates within acceptable levels of QoS and thus avoids the inflexibility of absolute DiffServ approach. The optimal bandwidth allocation and data droppage problems are formulated as constrained nonlinear optimization problems and solved using efficient techniques. Simulations are performed to show that the proposed scheme exhibits the desirable features of absolute and relative DiffServ. Copyright © 2009 John Wiley & Sons, Ltd. Waseem Sheikh, Arif Ghafoor |
Wirel. Commun. Mob. Comput. | 2 |
| 2009 | Scalable and Effective Test Generation for Role-Based Access Control SystemsabstractConformance testing procedures for generating tests from the finite state model representation of Role-Based Access Control (RBAC) policies are proposed and evaluated. A test suite generated using one of these procedures has excellent fault detection ability but is astronomically large. Two approaches to reduce the size of the generated test suite were investigated. One is based on a set of six heuristics and the other directly generates a test suite from the finite state model using random selection of paths in the policy model. Empirical studies revealed that the second approach to test suite generation, combined with one or more heuristics, is most effective in the detection of both first-order mutation and malicious faults and generates a significantly smaller test suite than the one generated directly from the finite state models. Ammar Masood, Rafae Bhatti, Arif Ghafoor, Aditya P. Mathur |
IEEE Trans. Software Eng. | 3 |
| 2008 | Proactive Role Discovery in Mediator-Free EnvironmentsabstractThe rapid proliferation of Internet and related technologies has created tremendous possibilities for the interoperability between domains in distributed environments. Interoperability does not come easy at it opens the way for several security and privacy breaches. In this paper, we focus on the distributed authorization discovery problem that is crucial to enable secure interoperability. We present a distributed access path discovery framework that does not require a centralized mediator. We propose and verify a role routing protocol that propagates secure, minimal-length paths to reachable roles in other domains. Finally, we present experimental results of our role routing protocol based on a simulation implementation. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
Peer-to-Peer Computing | 3 |
| 2008 | State of the Art in Information Extraction and Quantitative Analysis for Multimodality Biomolecular ImagingabstractRapid advances in optical instrumentation, high-speed cameras, and fluorescent probes have spurred tremendous growth in the volume of biomolecular imaging data. Various optical imaging modalities are used for probing biological systems in vivo and in vitro. These include traditional two-dimensional imaging, three-dimensional confocal imaging, time-lapse imaging, and multispectral imaging. Many applications require a combination of these imaging modalities, which gives rise to huge data sets. However, lack of powerful information extraction and quantitative analysis tools poses a major hindrance to exploiting the full potential of the information content of these data. In particular, automated extraction of semantic information from multimodality imaging data, crucial for understanding biological processes, poses unique challenges. Information extraction from large sets of biomolecular imaging data requires modeling at multiple levels of detail to allow not only quantitative analysis but also interpretation and extraction of high-level semantic information. In this paper, we survey the state of the art in the area of information extraction and automated analysis tools for in vivo and in vitro biomolecular imaging. The modeling and knowledge extraction for these data require sophisticated image processing and machine learning techniques, as well as formalisms for information extraction and knowledge management. Development of such tools has the potential to significantly improve biological discovery and drug development processes. Wamiq Manzoor Ahmed, Silas J. Leavesley, Bartek Rajwa, Muhammad Naeem Ayyaz, Arif Ghafoor, J. Paul Robinson |
Proc. IEEE | 5 |
| 2008 | Formal foundations for hybrid hierarchies in GTRBACabstractA role hierarchy defines permission acquisition and role-activation semantics through role--role relationships. It can be utilized for efficiently and effectively structuring functional roles of an organization having related access-control needs. The focus of this paper is the analysis of hybrid role hierarchies in the context of the generalized temporal role-based access control (GTRBAC) model that allows specification of a comprehensive set of temporal constraints on role, user-role, and role-permission assignments. We introduce the notion of uniquely activable set (UAS) associated with a role hierarchy that indicates the access capabilities of a user resulting from his membership to a role in the hierarchy. Identifying such a role set is essential, while making an authorization decision about whether or not a user should be allowed to activate a particular combination of roles in a single session. We formally show how UAS can be determined for a hybrid hierarchy. Furthermore, within a hybrid hierarchy, various hierarchical relations may be derived between an arbitrary pair of roles. We present a set of inference rules that can be used to generate all the possible derived relations that can be inferred from a specified set of hierarchical relations and show that it is sound and complete . We also present an analysis of hierarchy transformations with respect to role addition, deletion, and partitioning, and show how various cases of these transformations allow the original permission acquisition and role-activation semantics to be managed. The formal results presented here provide a basis for developing efficient security administration and management tools. James B. D. Joshi, Elisa Bertino, Arif Ghafoor, Yue Zhang 0002 |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2008 | XML-Based Data Model and Architecture for a Knowledge-Based Grid-Enabled Problem-Solving Environment for High-Throughput Biological ImagingabstractHigh-throughput biological imaging uses automated imaging devices to collect a large number of microscopic images for analysis of biological systems and validation of scientific hypotheses. Efficient manipulation of these datasets for knowledge discovery requires high-performance computational resources, efficient storage, and automated tools for extracting and sharing such knowledge among different research sites. Newly emerging grid technologies provide powerful means for exploiting the full potential of these imaging techniques. Efficient utilization of grid resources requires the development of knowledge-based tools and services that combine domain knowledge with analysis algorithms. In this paper, we first investigate how grid infrastructure can facilitate high-throughput biological imaging research, and present an architecture for providing knowledge-based grid services for this field. We identify two levels of knowledge-based services. The first level provides tools for extracting spatiotemporal knowledge from image sets and the second level provides high-level knowledge management and reasoning services. We then present cellular imaging markup language, an extensible markup language-based language for modeling of biological images and representation of spatiotemporal knowledge. This scheme can be used for spatiotemporal event composition, matching, and automated knowledge extraction and representation for large biological imaging datasets. We demonstrate the expressive power of this formalism by means of different examples and extensive experimental results. Wamiq Manzoor Ahmed, Dominik Lenz, J. Paul Robinson, Arif Ghafoor |
IEEE Trans. Inf. Technol. Biomed. | 5 |
| 2008 | Watermarking Relational Databases Using Optimization-Based TechniquesabstractProving ownership rights on outsourced relational databases is a crucial issue in today's internet-based application environments and in many content distribution applications. In this paper, we present a mechanism for proof of ownership based on the secure embedding of a robust imperceptible watermark in relational data. We formulate the watermarking of relational databases as a constrained optimization problem and discuss efficient techniques to solve the optimization problem and to handle the constraints. Our watermarking technique is resilient to watermark synchronization errors because it uses a partitioning approach that does not require marker tuples. Our approach overcomes a major weakness in previously proposed watermarking techniques. Watermark decoding is based on a threshold-based technique characterized by an optimal threshold that minimizes the probability of decoding errors. We implemented a proof of concept implementation of our watermarking technique and showed by experimental results that our technique is resilient to tuple deletion, alteration, and insertion attacks. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2008 | A scalable call admission control algorithm
Zafar Ali, Waseem Sheikh, Edwin K. P. Chong, Arif Ghafoor |
IEEE/ACM Trans. Netw. | 4 |
| 2008 | Secure Collaboration in a Mediator-Free Distributed EnvironmentabstractThe Internet and related technologies have made multidomain collaborations a reality. Collaboration enables domains to effectively share resources; however it introduces several security and privacy challenges. Managing security in the absence of a central mediator is even more challenging. In this paper, we propose a distributed secure interoperability framework for mediator-free collaboration environments. We introduce the idea of secure access paths which enables domains to make localized access control decisions without having global view of the collaboration. We also present a path authentication technique for proving path authenticity. Furthermore, we present an on-demand path discovery algorithms that enable domains to securely discover paths in the collaboration environment. We implemented a simulation of our proposed framework and ran experiments to investigate the effect of several design parameters on our proposed access path discovery algorithm. Mohamed Shehab, Arif Ghafoor, Elisa Bertino |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2007 | XML-Based Policy Engineering Framework for Heterogeneous Network Management
Arjmand Samuel, Shahab Baqai, Arif Ghafoor |
APNOMS | 3 |
| 2007 | Quantitative Analysis of Inter-object Spatial Relationships in Biological ImagesabstractStudy of spatial relations between biological objects is crucial for understanding biological processes. Monitoring drug or particle delivery inside cells and studying the dynamics of subcellular proteins are some of the examples. Biological applications have varying demands in terms of speed and accuracy. While accuracy may be the most important factor for small-scale biology, speed is also a concern for high-content/high-throughput screening applications. In this paper we present a variety of algorithms for inter-object spatial relations in two-and three-dimensional space. These algorithms provide trade-off between speed and accuracy, depending on the requirements of the application. Results for speed and accuracy are reported for real as well as synthetic data sets. Wamiq Manzoor Ahmed, Magdalena Jonczyk, Ali Shamsaie, Arif Ghafoor, J. Paul Robinson |
BIBE | 4 |
| 2007 | Knowledge Modeling for High Content Screening of Multimedia Biological DataabstractHigh-content and high-throughput screening (HCS/HTS) technologies provide powerful imaging tools for analyses of biological processes. These technologies combine sophisticated optics with automation techniques for imaging large populations of cells under different experimental perturbations and produce enormous amount of imaging data, including 2D images, 3D confocal data sets, time-lapse video sequences, and multispectral images. Manual analysis of such data is extremely time consuming, and intelligent image interpretation tools have only recently started to emerge. There is a direct need for powerful automated image understanding and spatio-temporal knowledge extraction techniques for gaining useful semantic information in biological domain consisting of multimodality multimedia data. In this tutorial we highlight key multimedia processing challenges in this domain and present a knowledge extraction and representation framework that is currently underway at Purdue University's Cytometery Laboratories and Distributed Multimedia System Laboratory. The proposed framework is being implemented using XML in order to allow extensibility and standardization. Arif Ghafoor, J. Paul Robinson |
BIBE | 1 |
| 2007 | Quality-of-Service Routing in Heterogeneous Networks with Optimal Buffer and Bandwidth AllocationabstractWe present an interdomain routing protocol for heterogeneous networks employing different queuing service disciplines. Our routing protocol finds optimal interdomain paths with maximum reliability while satisfying the end-to-end jitter and bandwidth constraints in networks employing heterogeneous queuing service disciplines. The quality-of-service (QoS) metrics are represented as functions of link bandwidth, node buffers and the queuing service disciplines employed in the routers along the path. Our scheme allows smart tuning of buffer-space and bandwidth during the routing process to adjust the QoS of the interdomain path. We formulate and solve the bandwidth and buffer allocation problem for a path over heterogeneous networks consisting of different queuing services disciplines such as generalized processor sharing (GPS), packet by packet generalized processor sharing (PGPS) and self-clocked fair queuing (SCFQ). Waseem Sheikh, Arif Ghafoor |
ICC | 2 |
| 2007 | A Policy-Based Authorization Framework for Web Services: Integrating XGTRBAC and WS-PolicyabstractAuthorization and access control in Web services is complicated by the unique requirements of the dynamic Web services paradigm. Current authentication mechanisms for Web services do not differentiate between users in terms of fine-grained access privileges. This results in an all-or-nothing access which is not flexible enough for modern day business processes using Web services to execute. In this paper, we present a policy-based authorization framework to address this requirement. We have designed a profile of the well-known WS-policy specification tailored to meet the access control requirements in Web services by integrating WS-policy with an access control policy specification language, X-GTRBAC. The design of the profile is aimed at bridging the gap between available policy standards for Web services and existing policy specification languages for access control. The profile supports the WS-policy attachment specification, which allows separate policies to be associated with multiple components of a Web service description, and one of our key contributions is the design of an algorithm to compute the effective policy for the Web service given the multiple policy attachments. To allow Web service applications to use our solution, we have adopted a component-based design approach based on well-known UML notations. We have also prototyped our architecture, and implemented it as a loosely coupled Web service providing healthcare information services to physicians subject to applicable authorization policies. Rafae Bhatti, Daniel Sanz, Elisa Bertino, Arif Ghafoor |
ICWS | 4 |
| 2007 | Distributed multimedia information systems: an end-to-end perspective
Arif Ghafoor |
Multim. Tools Appl. | 1 |
| 2007 | Engineering a Policy-Based System for Federated Healthcare DatabasesabstractPolicy-based management for federated healthcare systems has recently gained increasing attention due to strict privacy and disclosure rules. Although the work on privacy languages and enforcement mechanisms, such as Hippocratic databases, has advanced our understanding of designing privacy-preserving policies for healthcare databases, the need to integrate these policies in a practical healthcare framework is becoming acute. Additionally, although most work in this area has been organization oriented, dealing with the exchange of information between healthcare organizations (such as referrals), the requirements for the emerging area of personal healthcare information management have so far not been adequately addressed. These shortcomings arise from the lack of a sophisticated policy specification language and enforcement architecture that can capture the requirement for 1) the integration of privacy and disclosure policies with well-known healthcare standards used in the industry in order to specify the precise requirements of a practical healthcare system and 2) the provision of ubiquitous healthcare services to patients using the same infrastructure that enables federated healthcare management for organizations. In this paper, we have designed a policy-based system to mitigate these concerns. First, we have designed our disclosure and privacy policies by using a requirements specification based on a set of use cases for the Clinical Document Architecture (CDA) standard proposed by the community. Second, we present a context-aware policy specification language, which allows encoding of CDA-based requirements use cases into privacy and disclosure policy rules. We have shown that our policy specification language is effective in terms of handling a variety of expressive constraints on CDA-encoded document contents. Our language enables specification of privacy-aware access control for federated healthcare information across organizational boundaries, whereas the use of contextual constraints allows the incorporation of user and environment context in the access control mechanism for personal healthcare information management. Moreover, the declarative syntax of the policy rules makes the policy adaptable to changes in privacy regulations or patient preferences. We also present an enforcement architecture for the federated healthcare framework proposed in this paper. Rafae Bhatti, Arjmand Samuel, Mohamed Y. Eltabakh, Haseeb Amjad, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2007 | Web services discovery in secure collaboration environmentsabstractMultidomain application environments where distributed domains interoperate with each other is a reality in Web-services-based infrastructures. Collaboration enables domains to effectively share resources; however, it introduces several security and privacy challenges. In this article, we use the current web service standards such as SOAP and UDDI to enable secure interoperability in a service-oriented mediator-free environment. We propose a multihop SOAP messaging protocol that enables domains to discover secure access paths to access roles in different domains. Then we propose a path authentication mechanism based on the encapsulation of SOAP messages and the SOAP-DISG standard. Furthermore, we provide a service discovery protocol that enables domains to discover service descriptions stored in private UDDI registries. Mohamed Shehab, Kamal Bhattacharya, Arif Ghafoor |
ACM Trans. Internet Techn. | 3 |
| 2006 | Technique for Optimal Adaptation of Time-Dependent Workflows with Security ConstraintsabstractDistributed workflow based systems are widely used in various application domains including e-commerce, digital government, healthcare, manufacturing and many others. Workflows in these application domains are not restricted to the administrative boundaries of a single organization [1]. The tasks in a workflow need to be performed in a certain order and often times are subject to temporal constraints and dependencies [1, 2]. A key requirement for such workflow applications is to provide the right data to the right person at the right time. This requirement motivates for dynamic adaptations of workflows for dealing with changing environmental conditions and exceptions. Basit Shafiq, Arjmand Samuel, Elisa Bertino, Arif Ghafoor |
ICDE | 4 |
| 2006 | A semi-static approach to mapping dynamic iterative tasks onto heterogeneous computing systemsabstractMinimization of the execution time of an iterative application in a heterogeneous parallel computing environment requires an appropriate mapping scheme for matching and scheduling the subtasks of a given application onto the processors. Often, some of the characteristics of the application subtasks are unknown a priori or change from iteration to iteration during execution-time based on the inputs being processed. In such a scenario, it may not be feasible to use the same off-line-derived mapping for each iteration of the application. One possibility is to employ a semi-static methodology that starts with an initial mapping but dynamically performs remapping between application iterations by observing the effects of the changing characteristics of the application's input data, called dynamic parameters, on the application's execution time. A contribution in this paper is to implement and evaluate a semi-static methodology involving the on-line use of off-line-derived mappings. The off-line phase is based on a genetic algorithm (GA) to generate high-quality mappings for a range of values for the dynamic parameters. A dynamic parameter space partitioning and sampling scheme is proposed that partitions the parameter space into a number of hyper-rectangles, within which the “best” mapping for each hyper-rectangle is stored in a mapping table. During the on-line phase, the actual dynamic parameters are observed and the off-line-derived mapping table is referenced to choose the most suitable mapping. Experimental results indicate that the semi-static approach outperforms a dynamic on-line approach and performs reasonably close to an infeasible on-line GA approach. Furthermore, the semi-static approach considerably outperforms the method of using the same mapping for all iterations. Yu-Kwong Kwok, Anthony A. Maciejewski, Howard Jay Siegel, Ishfaq Ahmad 0001, Arif Ghafoor |
J. Parallel Distributed Comput. | 5 |
| 2006 | Guest Editors' introduction to the special issue: machine learning approaches to multimedia information retrieval
Arif Ghafoor, Zhongfei Zhang, Michael S. Lew, Zhi-Hua Zhou |
Multim. Syst. | 1 |
| 2006 | X-FEDERATE: A Policy Engineering Framework for Federated Access ManagementabstractPolicy-based management (PBM) has been considered as a promising approach for design and enforcement of access management policies for distributed systems. The increasing shift toward federated information sharing in the organizational landscape, however, calls for revisiting current PBM approaches to satisfy the unique security requirements of the federated paradigm. This presents a twofold challenge for the design of a PBM approach, where, on the one hand, the policy must incorporate the access management needs of the individual systems, while, on the other hand, the policies across multiple systems must be designed in such a manner that they can be uniformly developed, deployed, and integrated within the federated system. In this paper, we analyze the impact of security management challenges on policy design and formulate a policy engineering methodology based on principles of software engineering to develop a PBM solution for federated systems. We present X-FEDERATE, a policy engineering framework for federated access management using an extension of the well-known role-based access control (RBAC) model. Our framework consists of an XML-based policy specification language, its UML-based meta-model, and an enforcement architecture. We provide a comparison of our framework with related approaches and highlight its significance for federated access management. The paper also presents a federation protocol and discusses a prototype of our framework that implements the protocol in a federated digital library environment Rafae Bhatti, Elisa Bertino, Arif Ghafoor |
IEEE Trans. Software Eng. | 3 |
| 2005 | Secure collaboration in mediator-free environmentsabstractThe internet and related technologies have made multidomain collaborations a reality. Collaboration enables domains to effectively share resources; however it introduces several security and privacy challenges. Managing security in the absence of a central mediator is even more challenging. In this paper, we propose a distributed secure interoperability framework for mediator-free collaboration environments. We introduce the idea of secure access paths which enables domains to make localized access control decisions without having global view of the collaboration. We also present a path authentication technique for proving path authenticity. Furthermore, we present both a proactive and on-demand path discovery algorithms that enable domains to securely discover paths in the collaboration environment. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
CCS | 3 |
| 2005 | Efficiently Managing Security Concerns in Component Based System DesignabstractComponent-based software development (CBSD) offers many advantages like reduced product time to market, reduced complexity and cost etc. Despite these advantages its wide scale utilization in developing security critical systems is currently hampered because of lack, of suitable design techniques to efficiently manage the complete system security concerns in the development process. The use of commercial of the shelf (COTS) components can introduce various security and reliability risks in the system. In this paper we propose a methodology for efficient management of all the system security concerns involved in the design of component based systems. Our methodology is based on formally representing the system security specifications and component capabilities. We identify the metrics for correlating both and suggest extensions to a previously proposed software development process, for selection of suitable components and integration mechanisms. The proposed solution ensures due treatment of all the security concerns for the complete system in the acquisition efforts. Ammar Masood, Sahra Sedigh Sarvestani, Arif Ghafoor |
COMPSAC (1) | 3 |
| 2005 | A combined approach for QoS based multicast routing and resource allocationabstractIn this paper, we present a general framework for the problem of QoS multicast routing with resource allocation. Our framework uses functional forms derived from various queuing service disciplines for the QoS parameters rather than static metrics. We give formal definition of the QoS multicast routing problem with resource allocation. This problem is different from the minimum Steiner tree problem in networks which has been considered extensively. We show that QoS multicast routing with resource allocation problem is NP-complete. We present a 2-approximate greedy heuristic based on Prim's minimum spanning tree algorithm which suboptimally solves the multicast routing with. resource allocation problem. Waseem Sheikh, Ahmed R. Bashandy, Arif Ghafoor |
ICC | 3 |
| 2005 | SERAT: SEcure role mApping technique for decentralized secure interoperabilityabstractMulti-domain application environments where distributed domains interoperate with each other are becoming a reality in internet-based and web-services based enterprise applications. The secure interoperation in a multidomain environment is a challenging problem. In this paper, we propose a distributed secure interoperability protocol that ensures secure interoperation of the multiple collaborating domains without compromising the security of collaborating domains. We introduce the idea of access paths and access paths constraints. Furthermore, we device a path discovery algorithm that is capable of querying interoperating domains for the set of secure access paths between different domains. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
SACMAT | 3 |
| 2005 | Efficient hierarchical key generation and key diffusion for sensor networksabstractAbstract — Sensor networks are designed with the assumption that nodes are willing to collaborate. However, the open collaboration of nodes introduces privacy and security issues. Therefore, ensuring privacy in wireless sensor networks is a challenging task. Based on a multilevel security paradigm, in this paper we present a hierarchical key generation and distribution protocol for wireless sensor networks. We show by simulation results that our key generation scheme outperforms the existing hierarchical key generation schemes thus it is suitable for sensor networks with limited computation and energy capabilities. Furthermore, we present an energy efficient key diffusion protocol. We also discuss the possible security threats involved with the proposed protocol and provide suitable solutions to such threats. I. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
SECON | 3 |
| 2005 | A Trust-Based Context-Aware Access Control Model for Web-Services
Rafae Bhatti, Elisa Bertino, Arif Ghafoor |
Distributed Parallel Databases | 3 |
| 2005 | Generalized quality-of-service routing with resource allocationabstractWe present a general framework for the problem of quality-of-service (QoS) routing with resource allocation for data networks. The framework represents the QoS parameters as functions rather than static metrics. The formulation incorporates the hardware/software implementation and its relation to the allocated resources into a single framework. The proposed formulation allows intelligent adaptation of QoS parameters and allocated resources during a path search, rather than decoupling the path search process from resource allocation. We present a dynamic programming algorithm that, under certain conditions, finds an optimal path between a source and destination node and computes the amount of resources needed at each node so that the end-to-end QoS requirements are satisfied. We present jitter and data droppage analyzes of various rate-based service disciplines and use the dynamic programming algorithm to solve the problem of QoS routing with resource allocation for networks that employ these service disciplines. Ahmed R. Bashandy, Edwin K. P. Chong, Arif Ghafoor |
IEEE J. Sel. Areas Commun. | 3 |
| 2005 | An Analysis of Expressiveness and Design Issues for the Generalized Temporal Role-Based Access Control ModelabstractThe generalized temporal role-based access control (GTRBAC) model provides a comprehensive set of temporal constraint expressions which can facilitate the specification of fine-grained time-based access control policies. However, the issue of the expressiveness and usability of this model has not been previously investigated. In this paper, we present an analysis of the expressiveness of the constructs provided by this model and illustrate that its constraints-set is not minimal. We show that there is a subset of GTRBAC constraints that is sufficient to express all the access constraints that can be expressed using the full set. We also illustrate that a nonminimal GTRBAC constraint set can provide better flexibility and lower complexity of constraint representation. Based on our analysis, a set of design guidelines for the development of GTRBAC-based security administration is presented. James B. D. Joshi, Elisa Bertino, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2005 | X-GTRBAC: an XML-based policy specification framework and architecture for enterprise-wide access controlabstractModern day enterprises exhibit a growing trend toward adoption of enterprise computing services for efficient resource utilization, scalability, and flexibility. These environments are characterized by heterogeneous, distributed computing systems exchanging enormous volumes of time-critical data with varying levels of access control in a dynamic business environment. The enterprises are thus faced with significant challenges as they endeavor to achieve their primary goals, and simultaneously ensure enterprise-wide secure interoperation among the various collaborating entities. Key among these challenges are providing effective mechanism for enforcement of enterprise policy across distributed domains, ensuring secure content-based access to enterprise resources at all user levels, and allowing the specification of temporal and nontemporal context conditions to support fine-grained dynamic access control. In this paper, we investigate these challenges, and present X-GTRBAC, an XML-based GTRBAC policy specification language and its implementation for enforcing enterprise-wide access control. Our specification language is based on the GTRBAC model that incorporates the content- and context-aware dynamic access control requirements of an enterprise. An X-GTRBAC system has been implemented as a Java application. We discuss the salient features of the specification language, and present the software architecture of our system. A comprehensive example is included to discuss and motivate the applicability of the X-GTRBAC framework to a generic enterprise environment. An application level interface for implementing the policy in the X-GTRBAC system is also provided to consolidate the ideas presented in the paper. Rafae Bhatti, Arif Ghafoor, Elisa Bertino, James B. D. Joshi |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2005 | X-gtrbac admin: A decentralized administration model for enterprise-wide access controlabstractThe modern enterprise spans several functional units or administrative domains with diverse authorization requirements. Access control policies in an enterprise environment typically express these requirements as authorization constraints. While desirable for access control, constraints can lead to conflicts in the overall policy in a multidomain environment. The administration problem for enterprise-wide access control, therefore, not only includes authorization management for users and resources within a single domain but also conflict resolution among heterogeneous access control policies of multiple domains to allow secure interoperation within the enterprise. This work presents design and implementation of X-GTRBAC Admin, an administration model that aims at enabling administration of role-based access control (RBAC) policies in the presence of constraints with support for conflict resolution in a multidomain environment. A key feature of the model is that it allows decentralization of policy administration tasks through the abstraction of administrative domains, which not only simplifies authorization management, but is also fundamental to the concept of decentralized conflict resolution presented. The paper also illustrates the applicability of the outlined administrative concepts in a realistic enterprise environment using an implementation prototype that facilitates policy administration in large enterprises. Rafae Bhatti, Basit Shafiq, Elisa Bertino, Arif Ghafoor, James B. D. Joshi |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2005 | A Generalized Temporal Role-Based Access Control ModelabstractRole-based access control (RBAC) models have generated a great interest in the security community as a powerful and generalized approach to security management. In many practical scenarios, users may be restricted to assume roles only at predefined time periods. Furthermore, roles may only be invoked on prespecified intervals of time depending upon when certain actions are permitted. To capture such dynamic aspects of a role, a temporal RBAC (TRBAC) model has been recently proposed. However, the TRBAC model addresses the role enabling constraints only. In This work, we propose a generalized temporal role-based access control (GTRBAC) model capable of expressing a wider range of temporal constraints. In particular, the model allows expressing periodic as well as duration constraints on roles, user-role assignments, and role-permission assignments. In an interval, activation of a role can further be restricted as a result of numerous activation constraints including cardinality constraints and maximum active duration constraints. The GTRBAC model extends the syntactic structure of the TRBAC model and its event and trigger expressions subsume those of TRBAC. Furthermore, GTRBAC allows expressing role hierarchies and separation of duty (SoD) constraints for specifying fine-grained temporal semantics. James B. D. Joshi, Elisa Bertino, Usman Latif, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2005 | Secure Interoperation in a Multidomain Environment Employing RBAC PoliciesabstractMultidomain application environments where distributed multiple organizations interoperate with each other are becoming a reality as witnessed by emerging Internet-based enterprise applications. Composition of a global coherent security policy that governs information and resource accesses in such environments is a challenging problem. In this paper, we propose a policy integration framework for merging heterogeneous role-based access control (RBAC) policies of multiple domains into a global access control policy. A key challenge in composition of this policy is the resolution of conflicts that may arise among the RBAC policies of individual domains. We propose an integer programming (IP)-based approach for optimal resolution of such conflicts. The optimality criterion is to maximize interdomain role accesses without exceeding the autonomy losses beyond the acceptable limit. Basit Shafiq, James B. D. Joshi, Elisa Bertino, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2004 | A Trust-based Context-Aware Access Control Model for Web-ServicesabstractA key challenge in Web services security is the design of effective access control schemes that can adequately meet the unique security challenges posed by the Web services paradigm. Despite the recent advances in Web based access control approaches applicable to Web services, there remain issues that impede the development of effective access control models for Web services environment. Amongst them are the lack of context-aware models for access control, and reliance on identity or capability-based access control schemes. In this paper, we motivate the design of an access control scheme that addresses these issues, and propose an extended, trust-enhanced version of our XML-based role based access control (X-RBAC) framework that incorporates context-based access control. We outline the configuration mechanism needed to apply our model to the Web services environment, and also describe the implementation architecture for the system. Rafae Bhatti, Elisa Bertino, Arif Ghafoor |
ICWS | 3 |
| 2004 | X-GTRBAC admin: a decentralized administration model for enterprise wide access controlabstractAccess control in enterprises is a key research area in the realm of Computer Security because of the unique needs of the target enterprise. As the enterprise typically has large user and resource pools, administering the access control based on any framework could in itself be a daunting task. This work presents X-GTRBAC Admin, an administration model that aims at enabling policy administration within a large enterprise. In particular, it simplifies the process of user-to-role and permission-to-role assignments, and thus allows decentralization of the policy administration tasks. Secondly, it also allows for specifying the domain of authority of the system administrators, and hence provides mechanism to distribute the administrative authority over multiple domains within the enterprise. The paper also illustrates the applicability of the administrative concepts presented in our framework for enterprise-wide access control. Rafae Bhatti, James B. D. Joshi, Elisa Bertino, Arif Ghafoor |
SACMAT | 4 |
| 2004 | Special Issue on Multimedia Document Management Systems
Ashfaq Khokhar 0001, Arif Ghafoor |
Multim. Syst. | 2 |
| 2003 | Access Control in Dynamic XML-Based Web-Services with X-RBAC
Rafae Bhatti, James B. D. Joshi, Elisa Bertino, Arif Ghafoor |
ICWS | 4 |
| 2003 | Metrics and Models for Cost and Quality of Component-Based SoftwareabstractQuality and risk concerns currently limit the application of commercial off-the-shelf (COTS) software components to non-critical applications. Software metrics can quantify factors contributing to the overall quality of a component-based system, and models for tradeoffs between cost and various aspects of quality can guide quality and risk management by identifying and eliminating sources of risk. This paper discusses metrics and models that can be used to alleviate quality concerns for COTS-based systems, enabling the use of COTS components in a broader range of applications. Sahra Sedigh Sarvestani, Arif Ghafoor, Raymond A. Paul |
ISORC | 2 |
| 2003 | Dependencies and separation of duty constraints in GTRBACabstractA Generalized Temporal Role Based Access Control (GTRBAC) model that captures an exhaustive set of temporal constraint needs for access control has recently been proposed. GTRBAC's language constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. In this paper, we identify various time-constrained cardinality, control flow dependency and separation of duty constraints (SoDs). Such constraints allow specification of dynamically changing access control requirements that are typical in today's large systems. In addition to allowing specification of time, the constraints introduced here also allow expressing access control policies at a finer granularity. The inclusion of control flow dependency constraints allows defining much stricter dependency requirements that are typical in workflow types of applications. James B. D. Joshi, Basit Shafiq, Arif Ghafoor, Elisa Bertino |
SACMAT | 3 |
| 2002 | Hybrid Role Hierarchy for Generalized Temporal Role Based Access Control ModelabstractA generalized temporal role based access control (GTRBAC) model that captures an exhaustive set of temporal constraint needs for access control has been proposed. GTRBAC's language constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. We present the notion of different types of role hierarchies based on the permission-inheritance and role activation semantics. In particular, we look at how new hierarchical relations between a pair of roles that are not directly related can be derived through other well-defined hierarchically related roles. When the different hierarchy types coexist in a role hierarchy, inferring such derived hierarchical relations between a pair of roles can be complex. The results presented provide a basis for formally analyzing the derived inheritance and activation semantics between every pair of roles in a hierarchy. James B. D. Joshi, Elisa Bertino, Arif Ghafoor |
COMPSAC | 3 |
| 2002 | Temporal Modeling of Software Test CoverageabstractThis paper presents a temporal model for the coverage achieved by software testing. The proposed model, which is applicable at any level of the testing hierarchy, can determine the value of test coverage at any given time, as well as predicting future values. The model is comprised of two main components: coverage functions, and the coverage matrix. The coverage functions represent the coverage of a single entity as a function of time and reflect the test environment through their stochastic parameters. The coverage matrix utilizes the coverage functions to depict the coverage attained for each entity by each test within the test suite. A normalized sum of the elements of the coverage matrix is used to represent the overall coverage achieved by the test suite, as a function of time. The application of the model to multi-phase testing is illustrated In the application section, test coverage values from Y2K compliance testing are used to verify model predictions. Sahra Sedigh Sarvestani, Arif Ghafoor, Raymond A. Paul |
COMPSAC | 2 |
| 2002 | Temporal hierarchies and inheritance semantics for GTRBACabstractA Generalized Temporal Role Based Access Control (GTRBAC) model that allows specification of a comprehensive set of temporal constraint for access control has recently been proposed. The model constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. However, Temporal constraints on role enablings and role activations can have various implications on a role hierarchy. In this paper, we present an analysis of the effects of GTRBAC temporal constraints on a role hierarchy and introduce various kinds of temporal hierarchies. In particular, we show that there are certain distinctions that need to be made in permission inheritance and role activation semantics in order to capture all the effects of GTRBAC constraints such as role enablings and role activations on a role hierarchy. James B. D. Joshi, Elisa Bertino, Arif Ghafoor |
SACMAT | 3 |
| 2002 | A model for secure multimedia document database system in a distributed environmentabstractThe Internet provides a universal platform for large-scale distribution of information and supports inter-organizational services, system integration, and collaboration. Use of multimedia documents for dissemination and sharing of massive amounts of information is becoming a common practice for Internet-based applications and enterprises. With the rapid proliferation of multimedia data management technologies over the Internet, there is growing concern about security and privacy of information. Composing multimedia documents in a distributed heterogeneous environment involves integrating media objects from multiple security domains that may employ different access control policies for media objects. In this paper, we present a security model for distributed document management system that allows creation, storage, indexing, and presentation of secure multimedia documents. The model is based on a time augmented Petri-net and provides a flexible, multilevel access control mechanism that allows clearance-based access to different levels of information in a document. In addition, the model provides detailed multimedia synchronization requirements including deterministic and non-deterministic temporal relations and incomplete timing information among media objects. James B. D. Joshi, Zhaohui Kevin Li, Husni Fahmi, Basit Shafiq, Arif Ghafoor |
IEEE Trans. Multim. | 5 |
| 2001 | Metrics-Guided Quality Management for Component-Based Software SystemsabstractThe growing reliance on commercial-off-the-shelf (COTS) components for developing large-scale projects introduces a new paradigm in software engineering, which requires the design of new software development and business processes. Large scale component reuse leads to savings in development resources, enabling these resources to be applied to areas such as quality improvement. These savings come at the price of integration difficulties, performance constraints, and incompatibility of components from multiple vendors. Relying on COTS components also increases the system's vulnerability to risks arising from third-party development, which can negatively affect the quality of the system, as well as causing expenses not incurred in traditional software development. We aim to alleviate such concerns by using software metrics to accurately quantify factors contributing to the overall quality of a component-based system, guiding quality and risk management by identifying and eliminating sources of risk. Sahra Sedigh Sarvestani, Arif Ghafoor, Raymond A. Paul |
COMPSAC | 2 |
| 2000 | Design of multimedia Web server using a neuro-fuzzy frameworkabstractIn this paper, we propose a neuro-fuzzy scheduler (NFS) for a multimedia Web server to ensures synchronized delivery of multimedia documents. The problem of scheduling multimedia information to ensure media synchronization in a Web environment is identified as a multicriteria scheduling problem which is NP-hard. The proposed NFS makes an intelligent compromise among multicriteria by properly combining some scheduling heuristics. Performance of the NFS is compared with several known heuristics and a branch and bound algorithm. The results show that the proposed neuro-fuzzy scheduler can dynamically adjust to the varying work-load quite well. Zafar Ali, C. S. George Lee, Arif Ghafoor |
FUZZ-IEEE | 3 |
| 2000 | Distributed Framework for Real-Time Multimedia Object CommunicationabstractWe highlight major technical requirements for designing and developing future distributed multimedia information systems using Internet technology. The key requirements of this system are to allow users to access and search and to communicate multimedia documents consisting of text, audio, video and images. We emphasize the role of object-oriented technology for information management and real-time communication protocols to guarantee QoS. We present a reference architecture for a Web-based real-time distributed multimedia system which integrates enabling technologies including real-time streaming, multimedia indexing and searching and distributed object management. Husni Fahmi, Walid G. Aref, Mudassir Latif, Arif Ghafoor, Peiya Liu, Liang H. Hsu |
ISORC | 4 |
| 2000 | Media synchronization in multimedia Web using a neuro-fuzzy frameworkabstractWe consider the problem of multimedia synchronization in a Web environment. The workload generated by the multimedia server during a Web session exhibits variations that are quite different from the traffic fluctuation offered by a single media stream, e.g., a variable bit rate (VBR) video. We propose a set of parameters that can be used to characterize the workload generated by the multimedia server in a Web-type browsing environment. The workload characterization scheme is subsequently used in designing a server-based synchronization scheme. The problem of scheduling multimedia information to ensure media synchronization in a Web environment is identified as a multicriteria scheduling problem, which is NP-hard. The ability of fuzzy control to deal with multivariables makes it a good alternative for the multicriteria scheduling problem considered. Consequently, we propose a neuro-fuzzy scheduler (NFS) that makes an intelligent compromise among multicriteria by properly combining some scheduling heuristics. Performance of the NFS is compared with several known heuristics and a branch and bound algorithm. The results show that the proposed NFS ran dynamically adjust to the varying workload quite well. Zafar Ali, Arif Ghafoor, C. S. George Lee |
IEEE J. Sel. Areas Commun. | 2 |
| 2000 | Models for motion-based video indexing and retrievalabstractWith the rapid proliferation of multimedia applications that require video data management, it is becoming more desirable to provide proper video data indexing techniques capable of representing the rich semantics in video data. In real-time applications, the need for efficient query processing is another reason for the use of such techniques. We present models that use the object motion information in order to characterize the events to allow subsequent retrieval. Algorithms for different spatiotemporal search cases in terms of spatial and temporal translation and scale invariance have been developed using various signal and image processing techniques. We have developed a prototype video search engine, PICTURESQUE (pictorial information and content transformation unified retrieval engine for spatiotemporal queries) to verify the proposed methods. Development of such technology will enable true multimedia search engines that will enable indexing and searching of the digital video data based on its true content. Serhan Dagtas, Wasfi G. Al-Khatib, Arif Ghafoor, Rangasami L. Kashyap |
IEEE Trans. Image Process. | 3 |
| 1999 | Design and Evaluation of Disk Scheduling Policies for High-Demand Multimedia ServersabstractWe propose and evaluate techniques to manage disk storage systems for multimedia document servers with constrained I/O resources. We also evaluate the requirements for the main memory to maintain desired levels of quality of presentation (QoP) for multiple users. This is achieved by attempting to minimize the number of tardy frames in end-to-end delivery of multimedia data. Inter-media and intra-media temporal synchronization at the user-interaction level are essential concerns for multimedia servers. Scheduling of multimedia frames has direct impact on both intra-stream and inter-stream multimedia synchronization. In order to effect such synchronization, we propose several O(n log n+mn) heuristics to schedule multimedia frames between the disks and destination memories of the multimedia systems, where m is the number of logical I/O channels and n is the number of frames of multimedia data. We study the performance of these heuristics via simulations and show the tradeoffs between the system resources and QoP parameters. M. Farrukh Khan, Arif Ghafoor, Muhammad Naeem Ayyaz |
ICDE | 2 |
| 1999 | Network Modeling and Jitter Control for Multimedia Communication over Broadband NetworkabstractFor pre-orchestrated multimedia documents, the important QoS parameters are bandwidth, jitter and reliability. A data network may employ a large number of service disciplines that provide guaranteed QoS. In this paper, we propose a network model, which we call the jitter graph, to capture the bandwidth, jitter and reliability of a large number of service disciplines. The significance of this model is that it abstracts the properties of the network, which allows the design of QoS routing protocols, resource allocation policies, and traffic regulation schemes that are independent of the specific properties of each node. Based on this model, we propose a traffic regulation scheme that reduces, and possibly eliminates, jitter introduced by any service discipline that can be abstracted by the jitter graph network model. The proposed traffic regulation scheme, together with jitter graph model, are analyzed and simulated based on an existing service discipline. Ahmed R. Bashandy, Edwin K. P. Chong, Arif Ghafoor |
INFOCOM | 3 |
| 1999 | An approach for video meta-data modeling and query processingabstractMultimedia databases have been the subject of extensive research for the last several years. In particular, semantic modeling of video data spurred tremendous interest and produced various formalisms for content-based retrieval of video data. In this paper, we propose the use of Hierarchical Petri-nets (HPN's) for multi-level representation of video data with each level consisting of an augmented Petrinet structure. We show how such representation is able to capture video data semantics, from very low level semantics such as scene change and object movements to higher level semantics involving high-level textual description of events. A Petri-net based method for query processing of multi-object spatio-temporal video-data queries is presented. Wasfi G. Al-Khatib, Arif Ghafoor |
ACM Multimedia (1) | 2 |
| 1999 | Indexing and retrieval of video based on spatial relation sequencesabstractArticle Indexing and retrieval of video based on spatial relation sequences Share on Authors: Serhan Dağtaş Philips Research - USA 345, Scarborough Road, Briarcliff Manor, NY Philips Research - USA 345, Scarborough Road, Briarcliff Manor, NYView Profile , Arif Ghafoor School of Electrical and Computer Eng., Purdue University, West Lafayette, IN School of Electrical and Computer Eng., Purdue University, West Lafayette, INView Profile Authors Info & Claims MULTIMEDIA '99: Proceedings of the seventh ACM international conference on Multimedia (Part 2)October 1999 Pages 119–122https://doi.org/10.1145/319878.319910Online:01 October 1999Publication History 4citation388DownloadsMetricsTotal Citations4Total Downloads388Last 12 Months1Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Serhan Dagtas, Arif Ghafoor |
ACM Multimedia (2) | 2 |
| 1999 | Intensive Data Management in Parallel Systems: A Survey
M. Farrukh Khan, Raymond A. Paul, Ishfaq Ahmad 0001, Arif Ghafoor |
Distributed Parallel Databases | 4 |
| 1999 | Media Streams Scheduling for Synchronization in Distributed Multimedia Systems
Miae Woo, Reha Uzsoy, Arif Ghafoor |
J. Parallel Distributed Comput. | 3 |
| 1999 | A Multi-Level Abstraction and Modeling in Video Databases
Young Francis Day, Ashfaq Khokhar 0001, Serhan Dagtas, Arif Ghafoor |
Multim. Syst. | 4 |
| 1999 | Dynamic Resource Allocation for Multimedia Document Retrieval over High Speed LANs
Husni Fahmi, Shahab Baqai, Ahmed R. Bashandy, Arif Ghafoor |
Multim. Tools Appl. | 4 |
| 1999 | Multimedia Document Systems in Perspectives: Guest Editorial Note
Peiya Liu, Arif Ghafoor |
Multim. Tools Appl. | 2 |
| 1999 | Semantic Modeling and Knowledge Representation in Multimedia DatabasesabstractIn this paper, we present the current state of the art in semantic data modeling of multimedia data. Semantic conceptualization can be performed at several levels of information granularity, leading to multilevel indexing and searching mechanisms. Various models at different levels of granularity are compared. At the finest level of granularity, multimedia data can be indexed based on image contents, such as identification of objects and faces. At a coarser level of granularity, indexing of multimedia data can be focused on events and episodes, which are higher level abstractions. In light of the above, we also examine modeling and indexing techniques of multimedia documents. Wasfi G. Al-Khatib, Young Francis Day, Arif Ghafoor, P. Bruce Berra |
IEEE Trans. Knowl. Data Eng. | 3 |
| 1998 | Real Time Resource Allocation for Multimedia Object CommunicationabstractWe propose a dynamic bandwidth management scheme for asynchronous LANs that uses the concept of time division multiple access (TDMA). The scheme is to ensure quality of service (QoS) for multimedia applications. Significant performance improvement is observed through experimental results. In particular, the transmission rates for multimedia hosts improve significantly with low jitter variations in media streams. We also propose a framework for graceful degradation of play-out quality of multimedia objects in case the LAN's total capacity is not sufficient to meet the overall demand. Shahab Baqai, Raymond A. Paul, Husni Fahmi, Ahmed R. Bashandy, Arif Ghafoor |
ISORC | 5 |
| 1998 | Evaluation of Filtering Mechanisms for MPEG Video CommunicationsabstractIn this paper, we evaluate two video filtering mechanisms for MPEG-1 video, namely low-pass filtering and selective frame dropping. The evaluation provides tradeoffs between the reduction achieved in bandwidth requirements and the perceptual quality of the video sequences delivered to the client. Extensive experiments revealed that these filtering mechanisms result in a significant reduction in bandwidth requirements while maintaining acceptable perceptual quality. Sahra Sedigh Sarvestani, James B. D. Joshi, Ahmed R. Bashandy, Arif Ghafoor |
SRDS | 4 |
| 1998 | Guest Editors' Introduction to Part I of the Special Section on Data and Knowledge Management in Multimedia Systems
P. Bruce Berra, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1997 | A Multimedia Information System for Document Authoring, Indexing and PresentationabstractThe authors present a multimedia management system that supports creation, storing, indexing and presentation of complex multimedia objects. An object-oriented data model is proposed to capture the content, spatial and temporal semantics of multimedia data. Based on this model, they design a query processor to perform multi-dimension search on multimedia data. Zhaohui Kevin Li, Young Francis Day, Husni Fahmi, Arif Ghafoor |
COMPSAC | 4 |
| 1997 | Object-Oriented Evolutionary Database Design for Software Metrics DataabstractThe authors present an approach to manage evolutionary changes that take place over time in an object-oriented software metrics database schema. The framework is based on the entity-relation (E-R) model and uses a recursive graph structure, known as R-graph, to support the views of software quality and risk. The fundamental mechanism for abstracting views is the introduction of two semantic operators for the R-graph. These operators are proposed based on graph-based predicates and Petri-net based predicate formalism for view abstraction. Raymond A. Paul, Tosiyasu L. Kunii, Yoshihisa Shinagawa, Arif Ghafoor |
COMPSAC | 4 |
| 1996 | Which Network Will Win?
Arif Ghafoor |
COMPSAC | 1 |
| 1996 | High Assurance Systems EngineeringabstractSummary form only given, as follows. As we aim to develop more and more complex software systems for real time applications, the concern about their safety and reliability is also growing. In the author's opinion, development of these systems require more formal approaches than the development of a general purpose software system. We can draw our analogy from hardware engineering for which we know that in order to develop high performance systems, we must focus on designing highly specialized hardware which has rather little reusability for any other general purpose computation. We provide some critic on various design approaches of such systems. Arif Ghafoor |
COMPSAC | 1 |
| 1996 | Object-Oriented Framework for Metrics Guided Risk ManagementabstractWe present a framework for managing large software projects using metrics. The collection and analysis of metrics data serve as a consistent mechanism for risk identification and quality management. The crux of this mechanism is the temporal modeling of metrics data. We present a comprehensive set of temporal operators which serve as the building block for the formal specification of users' views of risk and quality. The notion of temporal inheritance can be used to define an object oriented query language. Raymond A. Paul, Yoshihisa Shinagawa, Young Francis Day, M. Farrukh Khan, Arif Ghafoor |
COMPSAC | 5 |
| 1996 | A Visual Query Interface for Software Metrics Databases
Raymond A. Paul, Azam Khan, Arif Ghafoor, Young Francis Day, Yoshihisa Shinagawa |
SEKE | 3 |
| 1996 | Quality-Based Evaluation of Multimedia Synchronization Protocols for Distributed Multimedia Information SystemsabstractDistributed, networked multimedia information systems will be a critical component of technology-based information infrastructures in the future. We present an infrastructure for supporting multimedia applications. We discuss various characteristics of multimedia data and the effect of the network on the required quality of presentation for multimedia data. We present a suite of synchronization protocols to support the quality of presentation. The crux of these protocols is the scheduling of multimedia information for synchronized delivery, over broadband networks with limited resources, and is identified as an NP-hard problem. We introduce two parameters which can be used to measure the performance of end-to-end synchronization protocols in a network supporting distributed multimedia applications. We propose and implement several heuristic scheduling algorithms, and compare their performance. We deduce the appropriateness of these algorithms in different types of distributed multimedia environments. Shahab Baqai, M. Farrukh Khan, Miae Woo, Seiichi Shinkai, Ashfaq Khokhar 0001, Arif Ghafoor |
IEEE J. Sel. Areas Commun. | 6 |
| 1995 | An Object-Oriented Conceptual Modeling of Video DataabstractWe propose a graphical data model for specifying spatio-temporal semantics of video data. The proposed model segments a video clip into subsegments consisting of objects. Each object is detected and recognized, and the relevant information of each object is recorded. The motions of objects are modeled through their relative spatial relationships as time evolves. Based on the semantics provided by this model, a user can create his/her own, object-oriented view of the video database. Using the propositional logic, we describe a methodology for specifying conceptual queries involving spatio-temporal semantics and expressing views for retrieving various video clips. Alternatively, a user can sketch the query, by exemplifying the concept. The proposed methodology can be used to specify spatio-temporal concepts at various levels of information granularity.> Young Francis Day, Serhan Dagtas, Mitsutoshi Iino, Ashfaq Khokhar 0001, Arif Ghafoor |
ICDE | 5 |
| 1995 | Special Issue on Multimedia Processing and Technology
Arif Ghafoor, C. Y. Roger Chen |
J. Parallel Distributed Comput. | 1 |
| 1995 | Dynamic Resource Allocation for Multimedia Services in Mobile Communication EnvironmentsabstractAs demand for networked multimedia applications is increasing rapidly, it is important to provide these services in mobile communication environments. In this paper, we identify system requirements for base stations in order to support multimedia services. These requirements include supporting concurrent connections for multiple users, allocation of resources dynamically to satisfy diverse resource requirements for multimedia applications, and reallocation of resources during handoff incurred by user movement or newly generated calls. These requirements can be used to design an interface between land-based and mobile environments to handle one of the most challenging issues in multimedia communication: enforcing interstream and intrastream synchronizations. We propose two quality of presentation (QOP) parameters for evaluating the quality of mobile multimedia connections, and analyze the validity of these requirements.> Miae Woo, Nagabhushana Prabhu, Arif Ghafoor |
IEEE J. Sel. Areas Commun. | 3 |
| 1995 | Special Issue on Multimedia Database Systems
Arif Ghafoor |
Multim. Syst. | 1 |
| 1994 | Massive data management in parallel machinesabstractDiscusses issues related to the design and and usage of database management systems consisting of massive amounts of data in parallel environments. The issues include the placement of the data in the memory, file systems, concurrent access to data, effects on query processing, the implications of specific machine architectures, and the peculiarities of specific parallel systems. Since not all parameters are currently amenable to rigorous analysis, results of performance studies are highlighted wherever they are deemed appropriate. > Raymond A. Paul, M. Farrukh Khan, Ishfaq Admad, Omran A. Bukhres, Imran Ghafoor, Amrit L. Goel, Arif Ghafoor |
COMPSAC | 7 |
| 1994 | Issues in database management of multimedia informationabstractDiscusses the current state-of-the-art issues in multimedia database management systems. The most important aspect of data management is the semantic modeling and indexing of multimedia information. We discuss various schemes to represent temporal synchronization requirements and highlight current research challenges facing the multimedia database community.> Raymond A. Paul, M. Farrukh Khan, Ashfaq Khokhar 0001, Arif Ghafoor |
COMPSAC | 4 |
| 1994 | Distributed synchronization protocols for multimedia services on InternetabstractIn this paper we present a distributed architecture for the existing and the emerging Internet for providing synchronized virtual channels (SVCs) to support presentation of multimedia information. The SVC architecture (SVCA) provides both intra-stream and inter-stream synchronization using resources available over the Internet and implementing distributed transmission scheduling mechanisms. We also propose a set of quality of presentation (QOP) parameters that quantify the quality of multimedia presentation from the user's point of view. Based on these parameters, we evaluate the proposed architecture and provides trade-offs between the QOP parameters and the required network resources to maintain this quality. Subsequently, these trade-offs are used to generate an optimal schedule for transmission of multimedia information over the SVCA. We also present protocol mechanisms to realize the SVCA.> Zafar Ali, Miae Woo, Arif Ghafoor |
ICNP | 3 |
| 1994 | Multichannel Scheduling for Communication of Pre-orchestrated Multimedia InformationabstractProposes a communication model for pre-orchestrated multimedia information. The model is used to determine the optimal number of channels needed to transmit the multimedia information. Subsequently, the authors consider a channel-deficient system and prove that scheduling transmission of multimedia data in this system is an NP-hard problem. Accordingly, they propose a heuristic algorithm with complexity O(nlog nm), where n represents the number of data units to be communicated over m channels.> Miae Woo, Arif Ghafoor |
INFOCOM | 2 |
| 1994 | Performance modeling of load-balancing algorithms using neural networksabstractAbstract The paper presents a new approach that uses neural networks to predict the performance of a number of dynamic decentralized load‐balancing strategies. A distributed multicomputer system using distributed load‐balancing strategies is represented by a unified analytical queuing model. A large simulation data set is used to train a neural network using the back‐propagation learning algorithm based on gradient descent The performance model using the predicted data from the neural network produces the average response time of various load balancing algorithms under various system parameters. The validation and comparison with simulation data show that the neural network is very effective in predicting the performance of dynamic load‐balancing algorithms. Our work leads to interesting techniques for designing load balancing schemes (for large distributed systems) that are computationally very expensive to simulate. One of the important findings is that performance is affected least by the number of nodes, and most by the number of links at each node in a large distributed system. Ishfaq Ahmad 0001, Kishan G. Mehrotra, Chilukuri K. Mohan, Sanjay Ranka, Arif Ghafoor |
Concurr. Pract. Exp. | 5 |
| 1994 | Hierarchical Scheduling of Dynamic Parallel Computaion on Hypercube MulticomputersabstractIn this paper a hierarchical task scheduling strategy for assigning parallel computations with dynamic structures to large hypercube multicomputers is proposed. Such computations represent a wide range of recursive and divide/conquer algorithms for which structure of the problem varies dynamically. To achieve load balancing and reduce processor contentions, the system is divided into multiple regions of processors for which the first level of scheduling is done by the host computer that spreads out the initial computations into these regions. The second level scheduling is done by a set of median processors of these regions which enable the processors of their regions to optimally balance the dynamically created load and to communicate with each other with reduced overhead. The results of an extensive simulation study are presented that exhibit the performance of the proposed strategy under different loading conditions, varying degrees of depth and parallelism, and communication costs. The proposed dual-level hierarchical scheduling is shown to outperform a well known distributed scheduling strategy. Ishfaq Ahmad 0001, Arif Ghafoor, Geoffrey C. Fox |
J. Parallel Distributed Comput. | 2 |
| 1993 | Random Routing of Tasks in Hypercube ArchitecturesabstractWe propose a general technique to study the perfor mance of random routing in a hypercube system. The proposed method is a based on association schemes in stead of using representation theory. Arif Ghafoor |
ICPP (1) | 1 |
| 1993 | Estimation of Execution times on Heterogeneous Supercomputer ArchitecturesabstractFor managing tasks efficiently in a Distributed Het erogeneous Supercomputing System (DHSS) , we re quire a thorough understanding of applications and their intelligent scheduling within the system. For this purpose, an accurate estimation of the execu tion time of applications on various architectures is needed. In this paper we present a framework to ad dress this issue. We propose two techniques, called augmented code profiling and augmented analytical benchmarking, to characterize applications and archi tectures in a DHSS, respectively. These techniques are based on code profiling and analytical benchmarking, respectively and provide a detailed architectural-dependent characterization of DHSS applications. Jaehyung Yang, Ishfaq Ahmad 0001, Arif Ghafoor |
ICPP (1) | 3 |
| 1993 | A Synchronization and Communication Model for Distributed Multimedia Objects
Naveed U. Qazi, Miae Woo, Arif Ghafoor |
ACM Multimedia | 3 |
| 1993 | Interval-Based Conceptual Models for Time-Dependent Multimedia DataabstractMultimedia data often have time dependencies that must be satisfied at presentation time. To support a general-purpose multimedia information system, these timing relationships must be managed to provide utility to both the data presentation system and the multimedia author. New conceptual models for capturing these timing relationships, and managing them as part of a database are proposed. Specifically, n-ary and reverse temporal relations are introduced and defined along with their temporal constraints. These new relations are a generalization of earlier temporal models and establish the basis for conceptual database structures and temporal access control algorithms to facilitate forward, reverse, and partial-interval evaluation during multimedia object playout. The proposed relations are defined to ensure a property of monotonically increasing playout deadlines to facilitate both real-time deadline-driven playout scheduling or optimistic interval-based process playout. A translation of the conceptual models to a structure suitable for a relational database is presented.> Thomas D. C. Little, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1992 | Allocation of Computations with Dynamic Structures on Hypercube Based Distributed SystemsabstractA dual-level dynamic load distribution strategy is proposed for allocating parallel computations with unpredictable structures to hypercube based distributed systems. Computations with dynamic structures represent a wide range of recursive and divide/conquer algorithms. The allocation strategy supports dynamic partitioning of these computations into communicating sub-tasks. Using the topological characteristics of hypercube networks, the system is divided into multiple regions of processors. The first level allocation is done by the central computer that spreads out the initial computations into these regions to reduce processor contention. The second level allocation is done by the median processors of these regions which enable the processors of their regions to optimally balance the dynamically created load and to communicate with each other with reduced overhead. The results of a simulation study are presented illustrating numerous examples that exhibit the performance of the proposed strategy under different loading conditions, varying degrees of depth and parallelism in the task graphs. The proposed allocation strategy is shown to outperform distributed load distribution.> Ishfaq Ahmad 0001, Arif Ghafoor, Geoffrey C. Fox |
HPDC | 2 |
| 1992 | Issues in Networking and Data Management of Distributed Multimedia SystemsabstractThe authors provide an overall assessment of the current state-of-the art in multimedia information technology, the future directions and the engineering challenges faced by the designers and researchers working in this area. They describe how the newly emerging networking and high performance storage technologies can provide unique opportunities for building interesting multimedia applications, which were unconceivable previously.> P. Bruce Berra, C. Y. Roger Chen, Arif Ghafoor, Thomas D. C. Little |
HPDC | 3 |
| 1992 | Fault-Tolerant Task Management and Load Re-Distribution on Massively Parallel Hypercube SystemsabstractThe authors present a scheme for managing real-time task allocation and load redistribution with fault-tolerance for hypercube systems. A set of processors, called fault-control processors (FCPs), can be used for keeping the duplicate copies of tasks and real locating tasks if the original processors of those tasks fail. Two-level task redundancy is used by grouping the FCPs as primary and secondary for each processor. The proposed scheme provides a high degree of fault-tolerance since each FCP itself is monitored by other FCPs. Assuming a failure-repair system environment, the performance of the proposed strategy has been evaluated and compared with a fault-free environment for 256-node and 512-node hypercubes, through simulation experiments. The authors also introduce a measure of goodness, success probability, which represents the probability of reallocated tasks meeting their deadlines despite the failures of processors. It is shown that, using the proposed scheme, a large percentage of the rescheduled tasks can still meet their deadlines. The probability of a task being lost altogether, due to multiple failures, has been shown to be extremely low.> Ishfaq Ahmad 0001, Arif Ghafoor |
SC | 2 |
| 1992 | An Expert System for Diagnosis and Repair
Arif Ghafoor |
Comput. J. | 1 |
| 1992 | Scheduling of bandwidth-constrained multimedia trafficabstractMultimedia applications describe unique requirements that must be met by computer network and operating system components. In particular, the time-dependencies of multimedia data require mechanisms to ensure timely and predictable delivery of data from their sources to destinations. For single medium applications which have relatively constant bandwidth utilization, connections from source to destination can be tailored to moderate ranges of data rates. On the other hand, due to the large variation in multimedia object sizes and concurrency in object presentation, multimedia applications can require a correspondingly large variation in required bandwidth over the life of a connection. Data of these types may not arrive in time to meet the intended playout schedule when the capacity of the channel is exceeded. In this paper we present an approach to remedying this situation by effectively smoothing the bandwidth requirement over time via a scheduling mechanism. Thomas D. C. Little, Arif Ghafoor |
Comput. Commun. | 2 |
| 1992 | Connectivity, Persistence and Fault Diagnosis of Interconnection Networks Based on Ok and 2Ok Graphs
Arif Ghafoor |
Discret. Appl. Math. | 1 |
| 1992 | The Covering Radius of Hadamard Codes in Odd Graphs
Patrick Solé, Arif Ghafoor, Sohail Sheikh |
Discret. Appl. Math. | 2 |
| 1992 | On the Assignment Problem of Arbitrary Process Systems to Heterogeneous Distributed Computer SystemsabstractThe authors propose and evaluate an efficient hierarchical clustering and allocation algorithm that drastically reduces the interprocess communications cost while observing lower and upper bounds of utilization for the individual processors. They compare the algorithm with branch-and-bound-type algorithms that can produce allocations with minimal communication cost, and show a very encouraging time complexity/suboptimality tradeoff in favor of the algorithm, at least for a class of process clusters and their random combinations which it is believed occur naturally in distributed applications. The heuristic allocation is well suited for a changing environment, where processors may fail or be added to the system and where the workload patterns may change unpredictably and/or periodically.> Nicholas S. Bowen, Christos Nikolaou, Arif Ghafoor |
IEEE Trans. Computers | 3 |
| 1991 | Scheduling of Bandwidth-Constrained Multimedia Traffic
Thomas D. C. Little, Arif Ghafoor |
NOSSDAV | 2 |
| 1991 | Performance prediction of distributed load balancing on multicomputer systemsabstractThispaperpresents aperformance evaluation approachto compare different distributed load balancing schemes on Ishfaq Ahmad 0001, Arif Ghafoor, Kishan G. Mehrotra |
SC | 2 |
| 1991 | Dynamic Concurrency Control Algorithms for Large Distributed Database Systems
Arif Ghafoor, F. Y. Farhat |
Comput. J. | 1 |
| 1991 | The covering radius of doubled 2-designs in 2OkabstractThe following problem originated from interconnection network considerations: what is the graphical covering radius of a doubled 2-design in the antipodal double cover of the odd graph 2Ok? In particular, when k is even, we take this design to be a Hadamard design. We obtain upper and lower bounds on this parameter for large values of k. The upper bound is obtained by generalizing the concept of q-covering in Johnson graphs to the graphs 2Ok. We use probabilistic arguments analogous to the Norse bounds of coding theory. Patrick Solé, Arif Ghafoor |
Discret. Appl. Math. | 2 |
| 1991 | Multimedia Synchronization Protocols for Broadband Integrated ServicesabstractProtocols to provide synchronization of data elements with arbitrary temporal relationships of both stream and non-stream broadband traffic types are proposed. It is specified that the provision of a synchronization function be performed within a packet switched network, and, accordingly, a two-level communication architecture is presented. The lower level, called the network synchronization protocol (NSP), provides the ability to establish and maintain individual connections with specified synchronization characteristics. The upper level, the application synchronization protocol (ASP), supports an integrated synchronization service for multimedia applications. The ASP identifies the temporal relationships among an application's data objects and manages the synchronization of arriving data for playout. The proposed NSP and ASP are mapped to the session and application layers of the open-systems-interconnection (OSI) reference model, respectively.> Thomas D. C. Little, Arif Ghafoor |
IEEE J. Sel. Areas Commun. | 2 |
| 1991 | A Study of Odd Graphs as Fault-Tolerant Interconnection NetworksabstractOdd graphs are analyzed to determine their suitable in designing interconnection networks. These networks are shown to possess many features that make them competitive with other architectures, such as ring, star, mesh, the binary n-cube and its generalized form, the chordal ring, and flip-trees. Among the features are small internode distances, a lighter density, simplicity in implementing various self-routing algorithms (both for faulty and nonfaulty networks), capability of maximal fault tolerance, strong resilience, and good persistence. The routing algorithms (both for the faulty and fault-free networks) do not require any table lookup mechanism, and intermediate nodes do not need to modify the message. These graphs are shown to have a partitioning property that is based on Hadamard matrices and can be effectively used for a system's expansion and self-diagnostics.> Arif Ghafoor, Theodore R. Bashkow |
IEEE Trans. Computers | 1 |
| 1991 | Semi-Distributed Load Balancing For Massively Parallel Multicomputer SystemsabstractA semidistributed approach is given for load balancing in large parallel and distributed systems which is different from the conventional centralized and fully distributed approaches. The proposed strategy uses a two-level hierarchical control by partitioning the interconnection structure of a distributed or multiprocessor system into independent symmetric regions (spheres) centered at some control points. The central points, called schedulers, optimally schedule tasks within their spheres and maintain state information with low overhead. The authors consider interconnection structures belonging to a number of families of distance transitive graphs for evaluation, and, using their algebraic characteristics, show that identification of spheres and their scheduling points is in general an NP-complete problem. An efficient solution for this problem is presented by making exclusive use of a combinatorial structure known as the Hadamard matrix. The performance of the proposed strategy has been evaluated and compared with an efficient fully distributed strategy through an extensive simulation study. The proposed strategy yielded much better results.> Ishfaq Ahmad 0001, Arif Ghafoor |
IEEE Trans. Software Eng. | 2 |
| 1990 | An efficient model of dynamic task scheduling for distributed systemsabstractThe authors propose a distributed task scheduling model using a simple processor architecture and a heuristic scheduling algorithm based on small message exchanges between nearest neighbors. An extensive simulation study was used to analyze the proposed model by taking into account a wide range of practical issues. Comparison with other schemes reported in the literature reveals the superiority of the proposed model in terms of various performance measures. The scheduling algorithm supported by some software components improves the response time to a great extent by trying to keep the network nodes equally busy. The exchange of load status information has low complexity. An interesting trade-off between periodic update and non-periodic information update is exhibited. The performance of the proposed algorithms does not degrade when no transfer limit is used. The communication rate of the network has a major influence on the performance but it is shown that further reduction in response time cannot be achieved after a certain increase in communication rate. Simulation experiments on various network topologies showed the adaptive nature of the proposed algorithms.> Arif Ghafoor, Ishfaq Ahmad 0001 |
COMPSAC | 1 |
| 1990 | Multimedia Object Models for Synchronisation and DatabasesabstractThe authors propose a technique for formally specifying and modeling the temporal composition of multimedia data. The proposed model is based on timed Petri nets and the logic of temporal intervals. A strategy based on the inter media timing relationships established by the proposed modeling tool is presented for constructing a database schema to facilitate data storage and retrieval of data elements. An algorithm which allows the retrieval of media elements from the database in a manner which preserves the temporal requirements of the initial specification is proposed. The proposed model accomplishes the specification of synchronization requirements for complex structures of temporally related objects.> Thomas D. C. Little, Arif Ghafoor |
ICDE | 2 |
| 1990 | A semi distributed task allocation strategy for large hypercube supercomputersabstractThe authors present a semi-distributed approach for task scheduling in large parallel and distributed systems which is different from the conventional centralized and fully distributed approaches. The proposed strategy partitions the system into independent regions (spheres) centered at some control points. The central points, called schedulers optimally schedule tasks within their spheres and maintain state information with low overhead. The authors consider hypercube systems for evaluation and, using their algebraic characteristics, show that identification of spheres and their scheduling points is an NP-complete problem. The performance of the proposed strategy was evaluated and compared with an efficient fully distributed strategy. In addition to yielding high performance in terms of response time, better resource utilization, and throughput, the proposed strategy is shown to incur small overhead in terms of network traffic.> Ishfaq Ahmad 0001, Arif Ghafoor |
SC | 2 |
| 1990 | Architecture for distributed multimedia database systems
P. Bruce Berra, C. Y. Roger Chen, Arif Ghafoor, Chin Chung Lin, Thomas D. C. Little |
Comput. Commun. | 3 |
| 1990 | Architecture of an All-Optical Circuit-Switched Multistage Interconnection NetworkabstractAn architecture of an all-optical multistage interconnection network is proposed. The network supports a circuit-switching model of communication and can provide parallel optical paths among input and output ports. It uses an address-based routing algorithm for path setup which, due to its decentralized nature, makes this network suitable for designing high-speed switching systems. These switches are commonly used in telephony and multiprocessor systems. The proposed architecture uses bistable optical devices, such as interference filters, as essential components of its switching modules. Since these devices can be easily fabricated, the implementation of this architecture is feasible. Various design issues related to optical clock generation, its distribution, data synchronization, and intensity restoration are also discussed.> Arif Ghafoor, Mohsen Guizani, Sohail Sheikh |
IEEE J. Sel. Areas Commun. | 1 |
| 1990 | Synchronization and Storage Models for Multimedia ObjectsabstractA technique is presented for the formal specification and modeling of multimedia composition with respect to intermedia timing. The proposed model is based on the logic of temporal intervals and timed Petri nets. A strategy is evinced for constructing a database schema to facilitate data storage and retrieval of media elements based on the temporal relationship established by the proposed modeling tool. An algorithm which allows the retrieval of media elements from the constructed database in a manner which preserves the temporal requirements of the initial specification is presented. Using the proposed model, the synchronization requirements of complex structures of temporally related objects can be easily specified.> Thomas D. C. Little, Arif Ghafoor |
IEEE J. Sel. Areas Commun. | 2 |
| 1989 | Distance-Transitive Graphs for Fault-Tolerant Multiprocessor Systems
Arif Ghafoor, Sohail Sheikh, Patrick Solé |
ICPP (1) | 1 |
| 1989 | The Effect of High Performance Processors in Butterfly Multiprocessor System (Extended Abstract)
Arif Ghafoor, Paul R. Austin, Douglas L. Bray |
SIGMETRICS | 1 |
| 1989 | An efficient communication structure for distributed commit protocolsabstractTo maintain consistency in a distributed database environment, the transactions must be executed atomically. The standard algorithm for ensuring an atomic execution is called the distributed commit protocol. The two-phase commit protocol and its variations, the well-known protocols used for this purpose, are characterized by successive rounds of message exchange, among all the sites of the database, at the time a transaction enters into a completion phase. The performance of these protocols is given by a complexity measure that depends on the communication structure of the protocol. Given N sites, the worst-case complexity of a commit protocol is O(N/sup 2/). A communication structure called maximal binomial structure (MBS) is presented, for which the complexity of the protocol is O(N*log/sup 3/ N). A lower bound for this complexity is also given, which is O(N*log/sup 2/ N). Protocols using the MBS remain symmetric. A scheme for an arbitrary expansion of the MBS to allow communication among a large number of sites is proposed. For the expanded system, the protocol complexity is also shown to be O(N*log/sup 3/ N). These structures are shown to be superior to other known structures.> Arif Ghafoor, P. Bruce Berra |
IEEE J. Sel. Areas Commun. | 1 |
| 1989 | Optics and supercomputingabstractStorage, interconnection, and processing are discussed. Various types of optical disks and page-oriented holographic memories are considered. It is shown that optical storage is advancing rapidly and holds the potential of hundreds of megabytes per second data rates from a single storage unit, which can provide many new opportunities for supercomputing. Module-to-module, board-to-board, and chip-to-chip interconnection and gate-to-gate communication are discussed. It is concluded that optical interconnection is, in many cases, superior to electronic interconnection and holds the key to the development of future electrooptic systems. Optical computing devices are discussed and various application areas where optical processing as well as storage and interconnection are expected to play a role in the future are considered. The authors believe that optical processing, while holding considerable promise, lags behind its electronic counterpart primarily due to the fact that digital optical device development is in its infancy. They predict near-term systems will be electrooptic, with each technology providing its strength to the problem at hand.> P. Bruce Berra, Arif Ghafoor, Mohsen Guizani, Slawomir J. Marcinkowski, Pericles A. Mitkas |
Proc. IEEE | 2 |
| 1989 | Bisectionla Fault-Tolerant Communication Archtecture for Supercomputer SystemsabstractA highly versatile communication architecture, the bisectional interconnection network, is proposed. These networks possess many attractive features such as small internode distances, ability to do self-routing which is easily extendible to failure conditions, and the capability of maximal fault tolerance. The proposed architecture allows optimal implementation of various logical configurations. Furthermore, the authors propose the use of a combinatorial structure, called the symmetric balanced incomplete block design (SBIBD), to partition these networks. This important property of partitioning allows the system's expansion with fault tolerance and is utilized to describe two semidistributed fault-diagnostic strategies which require remarkably low overhead and at the same time identify a large number of faulty nodes. Furthermore, based on SBIBDs, a unique approach for making the diagnostic scheme itself fault tolerant is proposed.> Arif Ghafoor, Theodore R. Bashkow, Imran Ghafoor |
IEEE Trans. Computers | 1 |
| 1989 | Performance of Fault-Tolerant Diagnostics in the Hypercube SystemsabstractThe concept of fault-tolerant self-diagnostics is introduced for distributed systems, and it is shown that there exists a performance tradeoff between the complexity of a self-diagnostic algorithm and the level of fault tolerance inherited by the algorithm. Hypercube systems are selected, and it is shown that designing an optimal algorithm for such systems has an equivalent coding theory formulation which belongs to the case of NP-hard problems. An efficient diagnostic scheme is proposed for these systems, and the performance tradeoff of the proposed algorithm, which is based on a combinatorial structure called the Hadamard matrix, is studied. The tradeoff between the fault tolerance and traffic complexity of the proposed diagnostic algorithm for hypercubes of small size is evaluated. An interesting compromise is exhibited for the hypercube with an arbitrary size.> Arif Ghafoor, Patrick Solé |
IEEE Trans. Computers | 1 |
| 1989 | The Impact of Optics on Data and Knowledge Base SystemsabstractThe authors assess the possible impact of optics on database and knowledge base systems, focusing on storage, interconnection, and processing. Various types of optical disks and page-oriented holographic memories are discussed. In the interconnection section, data communication is discussed at a variety of levels. Under processing, applications involving optical content addressable memories, optical data/knowledge base machines, and optics applied to full text processing will be optoelectronic, with easy technology providing its strength to the problem under consideration. It is noted that optical interconnection is superior to electronic interconnection in many cases and that the rapid advance of optical storage holds the potential of hundreds of megabytes per second data rates from a single storage unit. It is noted that optical processing holds considerable promise but lags behind primarily because digital optical device development is in its infancy.> P. Bruce Berra, Arif Ghafoor, Pericles A. Mitkas, Slawomir J. Marcinkowski, Mohsen Guizani |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1988 | Hierarchial Workload Allocation for Distributed Systems
Nicholas S. Bowen, Christos Nikolaou, Arif Ghafoor |
ICPP (2) | 3 |
| 1987 | An Interconnection Topology for Fault-Tolerant Multiprocessor Systems
Arif Ghafoor, Theodore R. Bashkow, Imran Ghafoor |
ICDCS | 1 |
| 1986 | Fault-Tolerance and Diagnosability of Bisectional Interconnection Networks
Arif Ghafoor, Theodore R. Bashkow, Imran Ghafoor |
ICDCS | 1 |