Pramod A. Jamkhedkar

dblp:88/3602 · DBLP profile ↗
← Back
13ranked-venue papers
8as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 4 first-authorDatabases, data management, data science and information retrieval · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Databases, data mining, and information retrieval
2 papers
Graph data management · 83% Spatial and temporal data management · 17%
Computer networks
2 papers
Network measurement and analytics · 100%
Network and information security
1 paper
Systems and software security · 50% Hardware security and side channels · 50%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Electronic design automation · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Graph data management
graph database
0.422018
A Graph Database for a Virtualized Network Infrastructure · SIGMOD Conference 2018
Virtualized Network Service Topology Exploration Using Nepal · SIGMOD Conference 2017
Network measurement and analytics
topology discovery
0.422018
Virtualized Network Service Topology Exploration Using Nepal · SIGMOD Conference 2017
A Graph Database for a Virtualized Network Infrastructure · SIGMOD Conference 2018
Hardware security and side channels
hardware information flow tracking
0.112012
A software-hardware architecture for self-protecting data · CCS 2012
Systems and software security
information flow tracking
0.112012
A software-hardware architecture for self-protecting data · CCS 2012
Spatial and temporal data management › temporal query processing
time-travel query
0.112017
Virtualized Network Service Topology Exploration Using Nepal · SIGMOD Conference 2017
Electronic design automation
hardware/software co-design
0.012012
A software-hardware architecture for self-protecting data · CCS 2012

Methods — techniques the papers use, named apart from their topics

hardware policy tags · 0.3dynamic information flow tracking · 0.3
YearPublicationVenuePosition
2018 A Graph Database for a Virtualized Network Infrastructure
abstract
Modern communication networks are large, dynamic, complex, and increasingly use virtualized network infrastructure. To deploy, maintain, and troubleshoot such networks, it is essential to understand how network elements - such as servers, switches, virtual machines, and virtual network functions - are connected to one another, and to be able to discover communication paths between them. For network maintenance applications such as troubleshooting and service quality management, it is also essential to understand how connections change over time, and be able to pose time-travel queries to retrieve information about past network states. With the industry-wide move to Software Defined Networks and Virtualized Network Functions (VNFs) [26][24], maintaining these inventory and topology databases becomes a critical issue.
Pramod A. Jamkhedkar, Theodore Johnson, Yaron Kanza, Aman Shaikh, N. K. Shankaranarayanan, Vladislav Shkapenyuk
SIGMOD Conference1
2017 Virtualized Network Service Topology Exploration Using Nepal
abstract
Modern communication networks are large, dynamic, and complex. To deploy, maintain, and troubleshoot such networks, it is essential to understand how network elements such as servers, switches, virtual machines, and virtual network functions are connected to one another, and to be able to discover communication paths between them. For network maintenance applications such as troubleshooting and service quality management it is also essential to understand how connections change over time, and be able to pose time-travel queries to retrieve information about past network states. With the industry-wide move to SDNs and virtualized network functions [13], maintaining these inventory databases becomes a critical issue.
Pramod A. Jamkhedkar, Theodore Johnson, Yaron Kanza, Aman Shaikh, N. K. Shankaranarayanan, Vladislav Shkapenyuk, Gordon Woodhull
SIGMOD Conference1
2014 Cyber defenses for physical attacks and insider threats in cloud computing
abstract
In cloud computing, most of the computations and data in the data center do not belong to the cloud provider. This leaves owners of applications and data concerned about cyber and physical attacks which may compromise the confidentiality, integrity or availability of their applications or data. While much work has looked at protection from software (cyber) threats, very few have looked at physical attacks and physical security in data centers. In this work, we present a novel set of cyber defense strategies for physical attacks in data centers. We capitalize on the fact that physical attackers are constrained by the physical layout and other features of a data center which provide a time delay before an attacker can reach a server to launch a physical attack, even by an insider. We describe how a number of cyber defense strategies can be activated when an attack is detected, some of which can even take effect before the actual attack occurs. The defense strategies provide improved security and are more cost-effective than always-on protections in the light of the fact that on average physical attacks will not happen often -- but can be very damaging when they do occur.
Jakub Szefer, Pramod A. Jamkhedkar, Diego Perez-Botero, Ruby B. Lee
AsiaCCS2
2013 A Framework for Realizing Security on Demand in Cloud Computing
abstract
In this paper we present our vision for Security on Demand in cloud computing: a system where cloud providers can offer customized security for customers' code and data throughout the term of contract. Security on demand enables security-focussed competitive service differentiation and pricing, based on a threat model that matches the customer's security requirements for the virtual machine he is leasing. It also enables a cloud provider to bring in new secure servers to the data center, and derive revenue from these servers, while still using existing servers. We show a framework where customers' security requests can be expressed and enforced by leveraging the capabilities of servers with different security architectures.
Pramod A. Jamkhedkar, Jakub Szefer, Diego Perez-Botero, Tianwei Zhang 0004, Gina Triolo, Ruby B. Lee
CloudCom (1)1
2012 A software-hardware architecture for self-protecting data
abstract
We propose a software-hardware architecture, DataSafe, that realizes the concept of self-protecting data: data that is protected by a given policy whenever it is accessed by any application -- including unvetted third-party applications. Our architecture provides dynamic instantiations of secure data compartments (SDCs), with hardware monitoring of the information flows from the compartment using hardware policy tags associated with the data at runtime. Unbypassable hardware output control prevents confidential information from being leaked out. Unlike previous hardware information flow tracking systems, DataSafe software architecture bridges the semantic gap by supporting flexible, high-level software policies for the data, seamlessly translating these policies to efficient hardware tags at runtime. Applications need not be modified to interface to these software-hardware mechanisms. DataSafe architecture is designed to prevent illegitimate secondary dissemination of protected plaintext data by authorized recipients, to track and protect data derived from sensitive data, and to provide lifetime enforcement of the confidentiality policies associated with the sensitive data.
Yu-Yuan Chen, Pramod A. Jamkhedkar, Ruby B. Lee
CCS2
2011 Usage Management in Cloud Computing
abstract
User concerns regarding data handling within the cloud will gain increasing importance as cloud computing becomes more pervasive. Existing service level agreement (SLA) frameworks are not designed for flexibly handling even relatively straightforward usage policies. This paper introduces the notion and importance of usage management in cloud computing. It provides an analysis of features and challenges involved in deploying a usage management framework over a distributed cloud environment to enable automated and actionable interpretation, reasoning and enforcement of usage policies. Finally, a preliminary architecture for such a framework is proposed.
Pramod A. Jamkhedkar, Christopher C. Lamb, Gregory L. Heileman
IEEE CLOUD1
2011 A domain specific language for usage management
abstract
In this paper we describe the development of a domain specific language (DSL) for expressing usage management policies and associating those policies with managed artifacts. We begin by framing a model for the language, including generalized use cases, a domain model, a general supported life-cycle, and specific extension requirements. We then develop the language from that model, demonstrating key syntactic elements and highlighting the technology behind the language while tracing features back to the initial model. We then demonstrate how the DSL supports common usage management and DRM-centric environments, including creative commons, the extensible rights markup language (XrML), and the open digital rights language (ODRL).
Christopher C. Lamb, Pramod A. Jamkhedkar, Mathew P. Bohnsack, Viswanath Nandina, Gregory L. Heileman
Digital Rights Management Workshop2
2010 An interoperable usage management framework
abstract
In this paper, we describe a formal framework for usage management that provides a scaffolding upon which interoperable usage management systems can be built. We apply the principles of system design to standardize certain features of the framework, such as the operational semantics, and leave free of standards areas that necessitate choice and innovation. We demonstrate that such an approach enables us to achieve a balance of flexibility and usability for the purpose of interoperability in usage management systems. We provide a formal model that allows us to define formal semantics for interoperability.
Pramod A. Jamkhedkar, Gregory L. Heileman, Christopher C. Lamb
Digital Rights Management Workshop1
2008 A formal conceptual model for rights
abstract
Emergence of different digital rights management (DRM) systems and various rights expression languages (RELs) has led to problems with DRM interoperability and smooth flow of content across different content management systems. The complexity, varied scope, undefined boundaries, and lack of formalism in current RELs pose some of the biggest challenges in addressing DRM interoperability. In this paper, we define a formal language neutral conceptual model for rights expression statements that provides a platform upon which rights statements from different RELs can be mapped, reasoned, and manipulated.
Pramod A. Jamkhedkar, Gregory L. Heileman
Digital Rights Management Workshop1
2007 The drm game
abstract
In this paper we cast DRM in a setting that allows us to model a number of current approaches as games. The DRM game is partitioned into two subgames, one that considers the game associated with content acquisition, and a second that considers how a consumer uses the content, along with a vendor's response to this usage. Examples are provided in order to demonstrate how these subgames correspond to real situations associated with content industries, and the conditions under which Nash equilibria will exist. These subgames form the primary stage of a repeated game that models a number of important long-term interactions between consumers and vendors. We analyze current strategies that attempt to influence the outcome of the repeated game, and we also consider a new type of architectural infrastructure that makes novel use of a trust authority in order to create a suitable environment for constructing DRM games that may prove useful in the future.
Gregory L. Heileman, Pramod A. Jamkhedkar, Joud S. Khoury, Curtis J. Hrncir
Digital Rights Management Workshop2
2006 The problem with rights expression languages
abstract
In this paper we consider the functionality that a rights expression language (REL) should provide within a digital rights management (DRM) environment. We begin by noting the dearth of applications that make use of RELs, despite the fact that they have now been available since the late 1990's. We posit that one of the main impediments to the use of RELs is the complexity associated with understanding and using them. This results from the fact that the functionality needed to handle a wide variety of possible DRM scenarios is typically built into a REL, and it is often difficult to cleanly partition out only those pieces needed by a particular DRM application. Basing DRM system design on a layered architecture provides one way of achieving a partitioning and points to the need for a simple REL that is exclusively responsible for the expression of rights, while pushing much of the functionality found in current RELs into higher system layers. In order to demonstrate the usefulness of this approach, we provide an example implementation dealing with DRM-based negotiation.
Pramod A. Jamkhedkar, Gregory L. Heileman, Iván Martínez-Ortiz
Digital Rights Management Workshop1
2005 DRM interoperability analysis from the perspective of a layered framework
abstract
Interoperability is currently seen as one of the most significant problems facing the digital rights management (DRM) industry. In this paper we consider the problem of interoperability among DRM systems from the perspective of a layered architectural framework. The advantage of looking at the problem from this point of view is that the layered framework provides a certain amount of structure that is very helpful in guiding those working on DRM interoperability issues. Specifically, the layered framework we describe provides a useful design abstraction along architectural lines. One of the advantages of this perspective is that it allows us to consider the level within computing/communication architectures at which certain functionality should be provided, and then to address how the functionality between layers should interact in order to provide specific DRM capabilities. The communications that occur between layers, both within a single system and between two communicating systems, are the places where protocols can be defined and possibly standardized. Thus, they provide focal points for studying and addressing interoperability in DRM systems.
Gregory L. Heileman, Pramod A. Jamkhedkar
Digital Rights Management Workshop2
2004 DRM as a layered system
abstract
The current landscape for digital rights management(DRM) consists of various ad hoc technologies and platforms that largely focus on copy protection. The fragmented nature of the DRM industry in 2004 is somewhat reminiscent of the telecommunications industry in the late 1980's. At that time various networking technologies were available, and what was needed was a technology that could integrate existing networks and provide various services to users. The OSI layered framework and the TCP/IP communications protocol suite provided a solution to this situation. The OSI model divides the process of digital data communications into layers. Likewise, in this paper we divide the process of DRM into layers in which various services are offered to the users of digital content at each layer. Three blocks of layers have been identified. The upper layers deal with the end-to-end functions of the application, the middle layers deal with rights expression and interpretation, and the lower layers ensure rights enforcement. This paper describes how responsibilities might be distributed among the various layers, and considers where in these layers it would be appropriate to define protocols and standards.
Pramod A. Jamkhedkar, Gregory L. Heileman
Digital Rights Management Workshop1