EDBT 2026 Demo / reviewers in the wild / expert
Gail-Joon Ahn
dblp:a/GailJoonAhn
· DBLP profile ↗
158ranked-venue papers
22as first author
23since 2021 · last 2026
0000-0002-4271-1666ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 103 · 8 first-author · 21 since 2021Human-computer interaction and ubiquitous computing · 18 · 3 first-author · 1 since 2021Computer networks · 15 · 6 first-author · 1 since 2021Software engineering, systems software and programming languages · 12 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 2 first-authorSystems, architecture and hardware · 5 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Deception by Design: A Configurable Platform for Flexible Cyber Deception Strategy Testing and Evaluation
Sukwha Kyung, Souradip Nath, Jaejong Baek, Gail-Joon Ahn |
ACNS (3) | 4 |
| 2026 | Attack Path Inferences for Quantum-Safe FutureG Network Security
Alena Chang, Sukwha Kyung, Guoliang Xue, Gail-Joon Ahn, Stephen S. Yau |
ICC | 4 |
| 2026 | Towards Agentic AI for Access Control in Cyber-infrastructures: Exploring the Security and Human Factors: [BlueSky Paper]abstractAccess Control (AC) remains one of the fundamental paradigms of computer security due to its potential to mitigate serious threats by restricting access to sensitive resources within emerging technologies. However, despite decades of research, the life-cycle, i.e., specification, evaluation, and enforcement, of AC policies in modern cyber-infrastructures remains incomplete, inaccurate, and unverified, which largely decreases their effectiveness and efficiency to counteract emerging threats and vulnerabilities. Carlos E. Rubio-Medrano, Souradip Nath, Ananta Soneji, Jennifer Mondragon, Jaejong Baek, Gail-Joon Ahn |
SACMAT | 6 |
| 2026 | Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit
Souradip Nath, Chih-Yi Huang, Aditi Ganapathi, Kashyap Thimmaraju, Jaron Mink, Gail-Joon Ahn |
SOUPS | 6 |
| 2025 | SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website Campaigns
Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest, Dhruv Kuchhal, Muhammad Saad 0001, Gail-Joon Ahn, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé |
NDSS | 7 |
| 2025 | Dependable Code Repair with LLMs: AI-Driven Vulnerability Detection and Automated PatchingabstractThe rapid proliferation of software vulnerabilities has created an urgent need for intelligent, automated methods to detect and mitigate security flaws at scale. Traditional vulnerability analysis depends heavily on manual inspection and domain-specific expertise, which are increasingly inadequate in the era of generative AI-driven code development. This research proposes an AI-based automated vulnerability detection and secure code generation framework that leverages multi-modal datasets, including source code and binaries, to achieve end-to- end automation across the vulnerability lifecycle: detection, patch generation, and validation. The system integrates explainable AI (XAI)-based vulnerability cause analysis, generative patch synthesis, system-level defensive code generation, Rust-based memory safety transformation, and differential privacy mechanisms for model confidentiality. Developed through a Korea- U.S. joint research initiative, this project aims to establish an internationally deployable platform for trustworthy and privacy- preserving AI -driven software security. The proposed research contributes both foundational methods and operational tools toward self-healing, explainable, and secure-by-design software ecosystems. Sungmin Han, Hyoungshick Kim, Hojoon Lee 0001, Hyungon Moon, Yuseok Jeon, Ho Bae, Donghyun Yeo, Gail-Joon Ahn, Sangkyun Lee 0002 |
PRDC | 8 |
| 2025 | "It's almost like Frankenstein": Investigating the Complexities of Scientific Collaboration and Privilege Management within Research Computing InfrastructuresabstractResearch Computing Infrastructures (RCIs) inte-grate high-performance computing, advanced data storage solutions, and sophisticated network protocols, connecting people, data, and computing resources to facilitate scientific collaboration in today's data-driven world. Access control is essential in such highly collaborative environments to prevent resource misutilization, safeguard data integrity, and allocate resources effectively, thereby enabling secure and trusted in-teractions among different users. However, unlocking the full potential of RCIs for collaborative research through effective access control requires more than technological exploration-it demands a deep, human-centered understanding of the stakeholders who operate and utilize these systems. In this paper, we present the first qualitative study that explores the human dimensions of RCI interactions, drawing insights from 24 key stakeholders, including researchers and system administrators, across 12 research institutions to ex-amine the collaborative practices, challenges, and needs with a focus on access control. Our findings reveal operational complexities and project-specific, trust-based resource-sharing dynamics, highlighting tensions between security and usability. Based on these insights, we provide stakeholder-driven rec-ommendations and requirements for adaptive, user-centered access control for RCIs, laying the groundwork for advancing human-centered security practices in RCIs. Souradip Nath, Ananta Soneji, Jaejong Baek, Tiffany Bao, Adam Doupé, Carlos E. Rubio-Medrano, Gail-Joon Ahn |
SP | 7 |
| 2024 | Nothing Personal: Understanding the Spread and Use of Personally Identifiable Information in the Financial EcosystemabstractOnline services leverage various authentication methods with differing usability and reliability trade-offs, such as password-based or multi-factor authentication (MFA). However, financial service providers face a unique challenge; authenticating the user's legal identity, which involves verifying Personally Identifiable Information (PII), which we call PII-based authentication (PII-BA). These methods assume that PII is private; however, identity theft victimizes millions annually and exposes their PII to criminals. Mehrnoosh Zaeifi, Faezeh Kalantari, Adam Oest, Gail-Joon Ahn, Yan Shoshitaishvili, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé |
CODASPY | 5 |
| 2024 | From Victims to Defenders: An Exploration of the Phishing Attack Reporting EcosystemabstractReporting phishing attacks can significantly shorten the time required to take down their operations and deter further victimization by the same phishing websites. However, little research has been conducted to understand the phishing reporting ecosystem and its effectiveness. In this paper, we comprehensively evaluate the phishing reporting ecosystem to identify the critical challenges people face and their concerns when reporting smishing, vishing, and phishing email attacks. First, we analyze the existing security advice and channels for reporting phishing attacks in both the public and private sectors. Then, we conduct a scenario-based experiment involving 89 participants to investigate what factors affect a participant’s decision to report a phishing attack and what challenges they face in preparing the report. Third, we report phishing attacks ourselves and monitor the status of the reported phishing websites to empirically measure how reports are acted upon and how that affects the reported phishing websites. Finally, we propose approaches under five major concern categories to mitigate the challenges that we discover in the phishing reporting ecosystem. Faris Bugra Kokulu, Adam Oest, Gianluca Stringhini, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
RAID | 10 |
| 2024 | "Watching over the shoulder of a professional": Why Hackers Make Mistakes and How They Fix ThemabstractThe complex and diverse nature of software systems necessitates a careful manual approach to unveil vulnerabilities, involving deep analysis, creative problem-solving, and specialized expertise. Like all complex tasks, it’s susceptible to mistakes stemming from cognitive limitations and behavioral factors that hinder optimal performance. Although there are significant research efforts focused on vulnerability discovery, little attention has been given to comprehending mistakes within the process. Understanding these mistakes could pave the way for better-designed education programs and automated tools, aiming to mitigate and prevent potential mistakes and enhance the efficiency of vulnerability research.In this paper, we leverage social media, specifically YouTube, to examine mistakes made by security content creators exploiting vulnerabilities in CTF-style challenges. Analyzing 30 screencasts from 11 hackers, we identified 124 distinct issues and investigated their types, underlying causes, and time investments. Additionally, we delved into the cognitive and behavioral aspects associated with these issues. Irina Ford, Ananta Soneji, Faris Bugra Kokulu, Jayakrishna Vadayath, Zion Leonahenahe Basque, Gaurav Vipat, Adam Doupé, Ruoyu Wang 0001, Gail-Joon Ahn, Tiffany Bao, Yan Shoshitaishvili |
SP | 9 |
| 2024 | Guaranteeing anonymity in attribute-based authorization
Erin Lanus, Charles J. Colbourn, Gail-Joon Ahn |
J. Inf. Secur. Appl. | 3 |
| 2023 | Targeted Privacy Attacks by Fingerprinting Mobile Apps in LTE Radio LayerabstractWe investigate the feasibility of targeted privacy attacks using only information available in physical channels of LTE mobile networks and propose three privacy attacks to demonstrate this feasibility: mobile-app fingerprinting attack, history attack, and correlation attack. These attacks can reveal the geolocation of targeted mobile devices, the victim's app usage patterns, and even the relationship between two users within the same LTE network cell. An attacker also may launch these attacks stealthily by capturing radio signals transmitted over the air, using only a passive sniffer as equipment. To ensure the impact of these attacks on mobile users' privacy, we perform evaluations in both laboratory and real-world settings, demonstrating their practicality and dependability. Furthermore, we argue that these attacks can target not only 4G/LTE but also the evolving 5G standards. Jaejong Baek, Pradeepkumar Duraisamy, Sukwha Kyung, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
DSN | 7 |
| 2023 | SpaceMediator: Leveraging Authorization Policies to Prevent Spatial and Privacy Attacks in Mobile Augmented RealityabstractMobile Augmented Reality (MAR) is a portable, powerful, and suitable technology that integrates digital content, e.g., 3D virtual objects, into the physical world, which not only has been implemented for multiple intents such as shopping, entertainment, gaming, etc., but it is also expected to grow at a tremendous rate in the upcoming years. Unfortunately, the applications that implement MAR, hereby referred to as MAR-Apps, bear security issues, which have been imaged in worldwide incidents such as robberies, which has led authorities to ban MAR-Apps at specific locations. Existing problems with MAR-Apps can be classified into three categories: first, Space Invasion, which implies the intrusive modification through MAR of sensitive spaces, e.g., hospitals, memorials, etc. Second, Space Affectation, which involves the degradation of users' experience via interaction with undesirable MAR or malicious entities. Finally, MAR-Apps mishandling sensitive data leads to Privacy Leaks. Luis Claramunt, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
SACMAT | 4 |
| 2022 | ViK: practical mitigation of temporal memory safety violations through object ID inspectionabstractTemporal memory safety violations, such as use-after-free (UAF) vulnerabilities, are a critical security issue for software written in memory-unsafe languages such as C and C++. Haehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
ASPLOS | 8 |
| 2022 | I'm SPARTACUS, No, I'm SPARTACUS: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking BehaviorabstractPhishing is a ubiquitous and increasingly sophisticated online threat. To evade mitigations, phishers try to "cloak" malicious content from defenders to delay their appearance on blacklists, while still presenting the phishing payload to victims. This cat-and-mouse game is variable and fast-moving, with many distinct cloaking methods---we construct a dataset identifying 2,933 real-world phishing kits that implement cloaking mechanisms. These kits use information from the host, browser, and HTTP request to classify traffic as either anti-phishing entity or potential victim and change their behavior accordingly. Sukwha Kyung, Hans Behrens, Zion Leonahenahe Basque, Haehyun Cho, Adam Oest, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Gail-Joon Ahn, Adam Doupé |
CCS | 11 |
| 2022 | Towards Automated Content-based Photo Privacy Control in User-Centered Social NetworksabstractA large number of photos shared online often contain private user information, which can cause serious privacy breaches when viewed by unauthorized users. Thus, there is a need for more efficient privacy control that requires automatic detection of users' private photos. However, the automatic detection of users' private photos is a challenging task, since different users may have different privacy concerns and a generalized one-size-fits-all approach for private photo detection would not be suitable for most users. User-specific detection of private photos should, therefore, be investigated. Furthermore, for effective privacy control, the exact sensitive regions in private photos need to be pinpointed, so that sensitive content can be protected via different privacy control methods. In this paper, we propose a novel system, AutoPri, to enable automatic and user-specific content-based photo privacy control in online social networks. We collect a large dataset of 31, 566 private and public photos from real-world users and present important observations on photo privacy concerns. Our system can automatically detect private photos in a user-specific manner using a detection model based on a multimodal variational autoencoder and pinpoint sensitive regions in private photos with an explainable deep learning-based approach. Our evaluations show that AutoPri can effectively determine user-specific private photos with high accuracy (94.32%) and pinpoint exact sensitive regions in them to enable effective privacy control in user-centered online social networks. Nishant Vishwamitra, Yifang Li, Hongxin Hu, Kelly Caine, Long Cheng 0005, Ziming Zhao 0001, Gail-Joon Ahn |
CODASPY | 7 |
| 2021 | Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing EcosystemabstractPhishing attacks are causing substantial damage albeit extensive effort in academia and industry. Recently, a large volume of phishing attacks transit toward adopting HTTPS, leveraging TLS certificates issued from Certificate Authorities (CAs), to make the attacks more effective. In this paper, we present a comprehensive study on the security practices of CAs in the HTTPS phishing ecosystem. We focus on the CAs, critical actors under-studied in previous literature, to better understand the importance of the security practices of CAs and thwart the proliferating HTTPS phishing. In particular, we first present the current landscape and effectiveness of HTTPS phishing attacks comparing to traditional HTTP ones. Then, we conduct an empirical experiment on the CAs' security practices in terms of the issuance and revocation of the certificates. Our findings highlight serious conflicts between the expected security practices of CAs and reality, raising significant security concerns. We further validate our findings using a longitudinal dataset of abusive certificates used for real phishing attacks in the wild. We confirm that the security concerns of CAs prevail in the wild and these concerns can be one of the main contributors to the recent surge of HTTPS phishing attacks. Doowon Kim, Haehyun Cho, Yonghwi Kwon 0001, Adam Doupé, Sooel Son, Gail-Joon Ahn, Tudor Dumitras |
AsiaCCS | 6 |
| 2021 | Poster: Preventing Spatial and Privacy Attacks in Mobile Augmented Reality TechnologiesabstractThe growing popularity of applications featuring Mobile Augmented Reality (MAR) raises serious concerns regarding the use of such a game-changing technology inside sensitive physical spaces, e.g., memorials, hospitals, museums, etc., such that the safety and privacy of users is preserved. To address such concerns, we present our ongoing work for mediating the way MAR Content, e.g., digital objects rendered on top of a video stream, is generated, distributed, and consumed by applications. We introduce a theoretical model, a supporting framework, as well as SpaceMediator, a proof-of-concept application implementing our approach. Luis Claramunt, Larissa Pokam Epse, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 5 |
| 2021 | Poster: DyPolDroid: User-Centered Counter-Policies Against Android Permission-Abuse AttacksabstractAndroid applications are extremely popular, as they are used for banking, social media, e-commerce, etc. However, several malicious applications have recently carried out data leaks and spurious credit card charges by abusing the Android Permissions granted initially to them by unaware users in good faith. To alleviate this pressing concern, we present DyPolDroid, a dynamic, semi-automated security framework that builds upon Android Enterprise, a device-management framework for organizations, allowing for users to design and enforce custom Counter-Policies, effectively protecting against such malicious applications without requiring advanced security and/or technical expertise. Matthew Hill, Carlos E. Rubio-Medrano, Luis Claramunt, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 5 |
| 2021 | Favocado: Fuzzing the Binding Code of JavaScript Engines Using Semantically Correct Test Cases
Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Kyle Zeng, Alexandros Kapravelos, Gail-Joon Ahn, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé, Yan Shoshitaishvili |
NDSS | 7 |
| 2021 | CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in PhishingabstractPhishing is a critical threat to Internet users. Although an extensive ecosystem serves to protect users, phishing websites are growing in sophistication, and they can slip past the ecosystem’s detection systems—and subsequently cause real-world damage—with the help of evasion techniques. Sophisticated client-side evasion techniques, known as cloaking, leverage JavaScript to enable complex interactions between potential victims and the phishing website, and can thus be particularly effective in slowing or entirely preventing automated mitigations. Yet, neither the prevalence nor the impact of client-side cloaking has been studied.In this paper, we present CrawlPhish, a framework for automatically detecting and categorizing client-side cloaking used by known phishing websites. We deploy CrawlPhish over 14 months between 2018 and 2019 to collect and thoroughly analyze a dataset of 112,005 phishing websites in the wild. By adapting state-of-the-art static and dynamic code analysis, we find that 35,067 of these websites have 1,128 distinct implementations of client-side cloaking techniques. Moreover, we find that attackers’ use of cloaking grew from 23.32% initially to 33.70% by the end of our data collection period. Detection of cloaking by our framework exhibited low false-positive and false-negative rates of 1.45% and 1.75%, respectively. We analyze the semantics of the techniques we detected and propose a taxonomy of eight types of evasion across three high-level categories: User Interaction, Fingerprinting, and Bot Behavior.Using 150 artificial phishing websites, we empirically show that each category of evasion technique is effective in avoiding browser-based phishing detection (a key ecosystem defense). Additionally, through a user study, we verify that the techniques generally do not discourage victim visits. Therefore, we propose ways in which our methodology can be used to not only improve the ecosystem’s ability to mitigate phishing websites with client-side cloaking, but also continuously identify emerging cloaking techniques as they are launched by attackers. Adam Oest, Haehyun Cho, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
SP | 13 |
| 2021 | Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service
Adam Oest, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang 0001, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
USENIX Security Symposium | 10 |
| 2021 | Semantics-Aware Privacy Risk Assessment Using Self-Learning Weight Assignment for Mobile AppsabstractMost of the existing mobile application (app) vetting mechanisms only estimate risks at a coarse-grained level by analyzing app syntax but not semantics. We propose a semantics-aware privacy risk assessment framework (SPRisk), which considers the sensitivity discrepancy of privacy-related factors at semantic level. Our framework can provide qualitative (i.e., risk level) and quantitative (i.e., risk score) assessment results, both of which help users make decisions to install an app or not. Furthermore, to find the reasonable weight distribution of each factor automatically, we exploit a self-learning weight assignment method, which is based on fuzzy clustering and knowledge dependency theory. We implement a prototype system and evaluate the effectiveness of SPRisk with 192,445 normal apps and 7,111 malicious apps. A measurement study further reveals some interesting findings, such as the privacy risk distribution of Google Play Store, the diversity of official and unofficial marketplaces, which provide insights into understanding the seriousness of privacy threat in the Android ecosystem. Jing Chen 0003, Chiheng Wang, Kun He 0008, Ziming Zhao 0001, Min Chen 0003, Ruiying Du, Gail-Joon Ahn |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2020 | HoneyPLC: A Next-Generation Honeypot for Industrial Control SystemsabstractIndustrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step7 Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis. Efrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili, Ruoyu Wang 0001, Tiffany Bao, Gail-Joon Ahn |
CCS | 7 |
| 2020 | SmokeBomb: effective mitigation against cache side-channel attacks on the ARM architectureabstractCache side-channel attacks abuse microarchitectural designs meant to optimize memory access to infer information about victim processes, threatening data privacy and security. Recently, the ARM architecture has come into the spotlight of cache side-channel attacks with its unprecedented growth in the market. Haehyun Cho, Jinbum Park, Donguk Kim 0003, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
MobiSys | 7 |
| 2020 | Proactive Risk Assessment for Preventing Attribute-Forgery Attacks to ABAC PoliciesabstractRecently, the use of well-defined, security-relevant pieces of runtime information, a.k.a., attributes, has emerged as a convenient paradigm for writing, enforcing, and maintaining authorization policies, allowing for extended flexibility and convenience. However, attackers may try to bypass such policies, along with their enforcement mechanisms, by maliciously forging the attributes listed on them, e.g., by compromising the attribute sources : operative systems, software modules, remote services, etc., thus gaining unintended access to protected resources as a result. In such a context, performing a proper risk assessment of authorization policies, taking into account their inner structure: rules, attributes, combining algorithms, etc., along with their corresponding sources, becomes highly convenient to overcome \emphzero-day vulnerabilities, before they can be later exploited by attackers. With this in mind, we introduce \toolname, an automated risk assessment framework for authorization policies, which, besides being inspired by well-established techniques for vulnerability analysis such as symbolic execution, also introduces the very first approach for proactively assessing risks in the context of a series of attacks based on unintended attribute manipulation via forgery. We validate our approach by resorting to a set of case studies we performed on both real-life policies originally written in the English language, as well as a set of policies obtained from the literature, which show not only the convenience of our approach for risk assessment, but also reveal that some of those policies are vulnerable to attribute-forgery attacks by just compromising one or two of their attributes. Carlos E. Rubio-Medrano, Luis Claramunt, Shaishavkumar Jogani, Gail-Joon Ahn |
SACMAT | 4 |
| 2020 | Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at Scale
Adam Oest, Brad Wardman, Eric Nunes, Jakub Burgis, Ali Zand, Kurt Thomas, Adam Doupé, Gail-Joon Ahn |
USENIX Security Symposium | 9 |
| 2019 | Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesabstractOrganizations, such as companies and governments, created Security Operations Centers (SOCs) to defend against computer security attacks. SOCs are central defense groups that focus on security incident management with capabilities such as monitoring, preventing, responding, and reporting. They are one of the most critical defense components of a modern organization's defense. Despite their critical importance to organizations, and the high frequency of reported security incidents, only a few research studies focus on problems specific to SOCs. In this study, to understand and identify the issues of SOCs, we conducted 18 semi-structured interviews with SOC analysts and managers who work for organizations from different industry sectors. Through our analysis of the interview data, we identified technical and non-technical issues that exist in SOC. Moreover, we found inherent disagreements between SOC managers and their analysts that, if not addressed, could entail a risk to SOC efficiency and effectiveness. We distill these issues into takeaways that apply both to future academic research and to SOC management. We believe that research should focus on improving the efficiency and effectiveness of SOCs. Faris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CCS | 7 |
| 2019 | Understanding and Predicting Private Interactions in Underground ForumsabstractThe studies on underground forums and marketplaces have significantly advanced our understandings of cybercrime workflows and underground economies. Researchers of underground economies have conducted comprehensive studies on public interactions. However, little research focuses on private interactions. The lack of the investigation on private interactions may cause misunderstandings on underground economies, as users in underground forums and marketplaces tend to share the minimal amount of information in public interactions and resort to private messages for follow-up conversations. In this paper, we propose methods to investigate the underground private interactions and we analyze a recently leaked dataset from Nulled.io. We present analyses on the contents and purposes of private messages. In addition, we design machine learning-based models that only use the publicly available information to detect if two underground users privately communicate with each other. Finally, we perform adversarial analysis to evaluate the robustness of the detector to different types of attacks. Carlos E. Rubio-Medrano, Ziming Zhao 0001, Tiffany Bao, Adam Doupé, Gail-Joon Ahn |
CODASPY | 6 |
| 2019 | Effectively Enforcing Authorization Constraints for Emerging Space-Sensitive TechnologiesabstractRecently, applications that deliver customized content to end-users, e.g., digital objects on top of a video stream, depending on information such as their current physical location, usage patterns, personal data, etc., have become extremely popular. Despite their promising future, some concerns still exist with respect to the proper use of such space-sensitive applications (S-Apps) inside independently-run physical spaces, e.g., schools, museums, hospitals, memorials, etc. Based on the idea that innovative technologies should be paired with novel (and effective) security measures, this paper proposes space-sensitive access control (SSAC), an approach for restricting space-sensitive functionality in such independently-run physical spaces, allowing for the specification, evaluation and enforcement of rich and flexible authorization policies, which, besides meeting the specific needs for S-Apps, are also intended to avoid the need for interruptions in their normal use as well as repetitive policy updates, thus providing a convenient solution for both policy makers and end-users. We present a theoretical model, a proof-of-concept S-App, and a supporting API framework, which facilitate the policy crafting, storage, retrieval and evaluation processes, as well as the enforcement of authorization decisions. In addition, we present a performance case study depicting our proof-of-concept S-App in a set of realistic scenarios, as well as a user study which resulted in 90% of participants being able to understand and write authorization policies using our approach, and 93% of them also recognizing the need for restricting functionality in the context of emerging space-sensitive technologies, thus providing evidence that encourages the adoption of SSAC in practice. Carlos E. Rubio-Medrano, Shaishavkumar Jogani, Maria Leitner, Ziming Zhao 0001, Gail-Joon Ahn |
SACMAT | 5 |
| 2019 | PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsabstractPhishing attacks have reached record volumes in recent years. Simultaneously, modern phishing websites are growing in sophistication by employing diverse cloaking techniques to avoid detection by security infrastructure. In this paper, we present PhishFarm: a scalable framework for methodically testing the resilience of anti-phishing entities and browser blacklists to attackers' evasion efforts. We use PhishFarm to deploy 2,380 live phishing sites (on new, unique, and previously-unseen .com domains) each using one of six different HTTP request filters based on real phishing kits. We reported subsets of these sites to 10 distinct anti-phishing entities and measured both the occurrence and timeliness of native blacklisting in major web browsers to gauge the effectiveness of protection ultimately extended to victim users and organizations. Our experiments revealed shortcomings in current infrastructure, which allows some phishing sites to go unnoticed by the security community while remaining accessible to victims. We found that simple cloaking techniques representative of real-world attacks- including those based on geolocation, device type, or JavaScript- were effective in reducing the likelihood of blacklisting by over 55% on average. We also discovered that blacklisting did not function as intended in popular mobile browsers (Chrome, Safari, and Firefox), which left users of these browsers particularly vulnerable to phishing attacks. Following disclosure of our findings, anti-phishing entities are now better able to detect and mitigate several cloaking techniques (including those that target mobile users), and blacklisting has also become more consistent between desktop and mobile platforms- but work remains to be done by anti-phishing entities to ensure users are adequately protected. Our PhishFarm framework is designed for continuous monitoring of the ecosystem and can be extended to test future state-of-the-art evasion techniques used by malicious websites. Adam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn, Brad Wardman, Kevin Tyers |
IEEE Symposium on Security and Privacy | 4 |
| 2019 | Users Really Do Answer Telephone Scams
Huahong Tu, Adam Doupé, Ziming Zhao 0001, Gail-Joon Ahn |
USENIX Security Symposium | 4 |
| 2019 | Towards a reliable firewall for software-defined networks
Hongxin Hu, Wonkyu Han, Sukwha Kyung, Juan Wang 0006, Gail-Joon Ahn, Ziming Zhao 0001, Hongda Li 0002 |
Comput. Secur. | 5 |
| 2019 | Guest Editors' Introduction: Special Section on Security in Emerging Networking TechnologiesabstractThe papers in this special section examine security in emerging networking technologies. Network infrastructure is undergoing a major shift away from ossified hardware-based networks to programmable software-based networks. One compelling example of this paradigm shift is the advent of Software- Defined Networking (SDN). A traditional network mixes control and traffic processing logic in single hardware devices, making the network more complex and harder to manage. SDN has addressed this issue by decoupling the control plane in network devices from the data plane to simplify production networks. On the other hand, enterprise networks are populated with a large number of proprietary and expensive hardware-based middleboxes, such as firewall, IDS/IPS, and load balancing. Hardware-based middleboxes present significant drawbacks such as high costs, management complexity, slow time to market, and unscalability. Network Function Virtualization (NFV) was proposed as another new network paradigm to address those drawbacks by replacing hardware-based network functions with virtualized software systems running on generic and inexpensive commodity hardware. Given their benefits, SDN and NFV have recently attracted significant attention from both academia and industry. Gail-Joon Ahn, Guofei Gu, Hongxin Hu, Seungwon Shin 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2018 | Wi Not Calling: Practical Privacy and Availability Attacks in Wi-Fi CallingabstractWi-Fi Calling, which is used to make and receive calls over the Wi-Fi network, has been widely adopted and deployed to extend the coverage and increase the capacity in weak signal areas by moving traffic from LTE to Wi-Fi networks. However, the security of Wi-Fi Calling mechanism has not been fully analyzed, and Wi-Fi Calling may inherently have greater security risks than conventional LTE calling. To provide secure connections with confidentiality and integrity, Wi-Fi Calling leverages the IETF protocols IKEv2 and IPSec. Jaejong Baek, Sukwha Kyung, Haehyun Cho, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
ACSAC | 7 |
| 2018 | Prime+Count: Novel Cross-world Covert Channels on ARM TrustZoneabstractThe security of ARM TrustZone relies on the idea of splitting system-on-chip hardware and software into two worlds, namely normal world and secure world. In this paper, we report cross-world covert channels, which exploit the world-shared cache in the TrustZone architecture. We design a Prime+Count technique that only cares about how many cache sets or lines have been occupied. The coarser-grained approach significantly reduces the noise introduced by the pseudo-random replacement policy and world switching. Using our Prime+Count technique, we build covert channels in single-core and cross-core scenarios in the TrustZone architecture. Our results demonstrate that Prime+Count is an effective technique for enabling cross-world covert channels on ARM TrustZone. Haehyun Cho, Donguk Kim 0003, Jinbum Park, Choong-Hoon Lee, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
ACSAC | 8 |
| 2018 | AIM-SDN: Attacking Information Mismanagement in SDN-datastoresabstractNetwork Management is a critical process for an enterprise to configure and monitor the network devices using cost effective methods. It is imperative for it to be robust and free from adversarial or accidental security flaws. With the advent of cloud computing and increasing demands for centralized network control, conventional management protocols like SNMP appear inadequate and newer techniques like NMDA and NETCONF have been invented. However, unlike SNMP which underwent improvements concentrating on security, the new data management and storage techniques have not been scrutinized for the inherent security flaws. In this paper, we identify several vulnerabilities in the widely used critical infrastructures which leverage the Network Management Datastore Architecture design (NMDA). Software Defined Networking (SDN), a proponent of NMDA, heavily relies on its datastores to program and manage the network. We base our research on the security challenges put forth by the existing datastore's design as implemented by the SDN controllers. The vulnerabilities identified in this work have a direct impact on the controllers like OpenDayLight, Open Network Operating System and their proprietary implementations (by CISCO, Ericsson, RedHat, Brocade, Juniper, etc). Using our threat detection methodology, we demonstrate how the NMDA-based implementations are vulnerable to attacks which compromise availability, integrity, and confidentiality of the network. We finally propose defense measures to address the security threats in the existing design and discuss the challenges faced while employing these countermeasures. Vaibhav Hemant Dixit, Adam Doupé, Yan Shoshitaishvili, Ziming Zhao 0001, Gail-Joon Ahn |
CCS | 5 |
| 2018 | vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection SystemsabstractTraditional Network Intrusion Detection Systems (NIDSes) are generally implemented on vendor proprietary appliances or middleboxes with poor versatility and flexibility. Emerging Network Function Virtualization (NFV) and Software-Defined Networking (SDN) technologies can virtualize NIDSes and elastically scale them to deal with attack traffic variations. However, such an elasticity feature must not come at the cost of decreased detection effectiveness and expensive provisioning. In this paper, we propose an innovative NIDS architecture, vNIDS, to enable safe and efficient virtualization of NIDSes. vNIDS addresses two key challenges with respect to effective intrusion detection and non-monolithic NIDS provisioning in virtualizing NIDSes. The former challenge is addressed by detection state sharing while minimizing the sharing overhead in virtualized environments. In particular, static program analysis is employed to determine which detection states need to be shared. vNIDS addresses the latter challenge by provisioning virtual NIDSes as microservices and employing program slicing to partition the detection logic programs so that they can be executed by each microservice separately. We implement a prototype of vNIDS to demonstrate the feasibility of our approach. Our evaluation results show that vNIDS could offer both effective intrusion detection and efficient provisioning for NIDS virtualization. Hongda Li 0002, Hongxin Hu, Guofei Gu, Gail-Joon Ahn |
CCS | 4 |
| 2018 | SeCore: Continuous Extrospection with High Visibility on Multi-core ARM PlatformsabstractWe present SeCore, which is a novel continuous extrospection system on multi-core ARM platform. SeCore leverages ARM TrustZone technology to keep one core in the secure world and assure the integrity of the static kernel data and code in the normal world. By breaking the original time-sharing paradigm of such systems, SeCore enables continuous coprocessor-like monitoring with high visibility into the rich execution environment on mobile and IoT platforms. By ensuring that secure tools execute on certain physical CPU cores, the system's attack surface is also significantly reduced. Bernard Ngabonziza, Haehyun Cho, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CODASPY | 6 |
| 2018 | Challenges, Opportunities and a Framework for Web Environment Forensics
Mike Mabey, Adam Doupé, Ziming Zhao 0001, Gail-Joon Ahn |
IFIP Int. Conf. Digital Forensics | 4 |
| 2018 | Risk assessment of mobile applications based on machine learned malware dataset
Hyunki Kim, Taejoo Cho, Gail-Joon Ahn, Jeong Hyun Yi |
Multim. Tools Appl. | 3 |
| 2018 | Efficient Anonymous Message SubmissionabstractIn online surveys, many people are reluctant to provide true answers due to privacy concerns. Thus, anonymity is important for online message collection. Existing solutions let each member blindly shuffle the submitted messages by using an IND-CCA2 secure cryptosystem. In the end, the message sender's identities are protected since no one knows the message submission order. These approaches cannot efficiently handle groups of large size.In this paper, we propose an efficient anonymous message submission protocol aimed at a practical group size. Our protocol is based on a secret sharing scheme and a symmetric key cryptosystem. We propose a novel method to aggregate members' messages into a message vector such that a group member knows only his own position in the submission sequence. The protocol is accountable for capturing malicious members breaking the protocol execution. We provide a theoretical proof showing that our protocol is anonymous under malicious attacks. We also discuss our simulation results to demonstrate the efficiency of our protocol. Xinxin Zhao, Lingjun Li, Guoliang Xue, Gail-Joon Ahn |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2018 | Uncovering the Face of Android Ransomware: Characterization and Real-Time DetectionabstractIn recent years, we witnessed a drastic increase of ransomware, especially on popular mobile platforms including Android. Ransomware extorts victims for a sum of money by taking control of their devices or files. In light of their rapid growth, there is a pressing need to develop effective countermeasure solutions. However, the research community is still constrained by the lack of a comprehensive data set, and there exists no insightful understanding of mobile ransomware in the wild. In this paper, we focus on the Android platform and aim to characterize existing Android ransomware. Specifically, we have managed to collect 2,721 ransomware samples that cover the majority of existing Android ransomware families. Based on these samples, we systematically characterize them from several aspects, including timeline and malicious features. In addition, the detection results of existing anti-virus tools are rather disappointing, which clearly calls for customized anti-mobile-ransomware solutions. To detect ransomware that extorts users by encrypting data, we propose a novel real-time detection system, called RansomProber. By analyzing the user interface widgets of related activities and the coordinates of users' finger movements, RansomProber can infer whether the file encryption operations are initiated by users. The experimental results show that RansomProber can effectively detect encrypting ransomware with high accuracy and acceptable runtime performance. Jing Chen 0003, Chiheng Wang, Ziming Zhao 0001, Kai Chen 0012, Ruiying Du, Gail-Joon Ahn |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2017 | Deep Android Malware DetectionabstractIn this paper, we propose a novel android malware detection system that uses a deep convolutional neural network (CNN). Malware classification is performed based on static analysis of the raw opcode sequence from a disassembled program. Features indicative of malware are automatically learned by the network from the raw opcode sequence thus removing the need for hand-engineered malware features. The training pipeline of our proposed system is much simpler than existing n-gram based malware detection methods, as the network is trained end-to-end to jointly learn appropriate features and to perform classification, thus removing the need to explicitly enumerate millions of n-grams during training. The network design also allows the use of long n-gram like features, not computationally feasible with existing methods. Once trained, the network can be efficiently executed on a GPU, allowing a very large number of files to be scanned quickly. Niall McLaughlin, Jesús Martínez del Rincón, Boojoong Kang, Suleiman Y. Yerima, Paul Miller 0003, Sakir Sezer, Yeganeh Safaei, Erik Trickel, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CODASPY | 11 |
| 2017 | On the Safety and Efficiency of Virtual Firewall Elasticity Control
Juan Deng, Hongda Li 0002, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao 0001, Wonkyu Han |
NDSS | 5 |
| 2017 | Poster: On the Safety and Efficiency of Virtual Firewall Elasticity ControlabstractFirewalls have been typically used to enforce network access control. Network Functions Virtualization (NFV) envisions to implement firewall function as software instance (a.k.a virtual firewall). Virtual firewall provides great flexibility and elasticity, which are necessary to protect virtualized environments. In this poster, we propose an innovative virtual firewall controller, VFW Controller, which enables safe, efficient and cost-effective virtual firewall elasticity control. In addition, we implement the core components of VFW Controller on top of NFV and SDN environments. Our experimental results demonstrate that VFW Controller is efficient to provide safe elasticity control of virtual firewalls. Hongda Li 0002, Juan Deng, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao 0001, Wonkyu Han |
SACMAT | 5 |
| 2017 | Towards PII-based Multiparty Access Control for Photo Sharing in Online Social NetworksabstractThe privacy control models of current Online Social Networks (OSNs) are biased towards the content owners' policy settings. Additionally, those privacy policy settings are too coarse-grained to allow users to control access to individual portions of information that is related to them. Especially, in a shared photo in OSNs, there can exist multiple Personally Identifiable Information (PII) items belonging to a user appearing in the photo, which can compromise the privacy of the user if viewed by others. However, current OSNs do not provide users any means to control access to their individual PII items. As a result, there exists a gap between the level of control that current OSNs can provide to their users and the privacy expectations of the users. In this paper, we propose an approach to facilitate collaborative control of individual PII items for photo sharing over OSNs, where we shift our focus from entire photo level control to the control of individual PII items within shared photos. We formulate a PII-based multiparty access control model to fulfill the need for collaborative access control of PII items, along with a policy specification scheme and a policy enforcement mechanism. We also discuss a proof-of-concept prototype of our approach as part of an application in Facebook and provide system evaluation and usability study of our methodology. Nishant Vishwamitra, Yifang Li, Hongxin Hu, Kelly Caine, Gail-Joon Ahn |
SACMAT | 6 |
| 2017 | Defining and Detecting Environment Discrimination in Android Apps
Yunfeng Hong, Yongjian Hu, Chun-Ming Lai, Shyhtsun Felix Wu, Iulian Neamtiu, Patrick D. McDaniel, Paul L. Yu, Hasan Çam, Gail-Joon Ahn |
SecureComm | 9 |
| 2016 | Checking Intent-based Communication in Android with Intent Space AnalysisabstractIntent-based communication is an inter-application communication mechanism in Android. While its importance has been proven by plenty of security extensions that protect it with policy-driven mandatory access control, an overlooked problem is the verification of the security policies. Checking one security extension's policy is indeed complex. Furthermore, intent-based communication introduces even more complexities because it is mediated by multiple security extensions that respectively enforce their own incompatible, distributed, and dynamic policies. Yiming Jing, Gail-Joon Ahn, Adam Doupé, Jeong Hyun Yi |
AsiaCCS | 2 |
| 2016 | State-aware Network Access Management for Software-Defined NetworksabstractOpenFlow, as the prevailing technique for Software-Defined Networks (SDNs), introduces significant programmability, granularity, and flexibility for many network applications to effectively manage and process network flows. However, because OpenFlow attempts to keep the SDN data plane simple and efficient, it focuses solely on L2/L3 network transport and consequently lacks the fundamental ability of stateful forwarding for the data plane. Also, OpenFlow provides a very limited access to connection-level information in the SDN controller. In particular, for any network access management applications on SDNs that require comprehensive network state information, these inherent limitations of OpenFlow pose significant challenges in supporting network services. To address these challenges, we propose an innovative connection tracking framework called STATEMON that introduces a global state-awareness to provide better access control in SDNs. STATEMON is based on a lightweight extension of OpenFlow for programming the stateful SDN data plane, while keeping the underlying network devices as simple as possible. To demonstrate the practicality and feasibility of STATEMON, we implement and evaluate a stateful network firewall and port knocking applications for SDNs, using the APIs provided by STATEMON. Our evaluations show that STATEMON introduces minimal message exchanges for monitoring active connections in SDNs with manageable overhead (3.27% throughput degradation). Wonkyu Han, Hongxin Hu, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn, Kuang-Ching Wang, Juan Deng |
SACMAT | 5 |
| 2016 | SoK: Everyone Hates Robocalls: A Survey of Techniques Against Telephone SpamabstractTelephone spam costs United States consumers $8.6 billion annually. In 2014, the Federal Trade Commission has received over 22 million complaints of illegal and wanted calls. Telephone spammers today are leveraging recent technical advances in the telephony ecosystem to distribute massive automated spam calls known as robocalls. Given that anti-spam techniques and approaches are effective in the email domain, the question we address is: what are the effective defenses against spam calls? In this paper, we first describe the telephone spam ecosystem, specifically focusing on the differences between email and telephone spam. Then, we survey the existing telephone spam solutions and, by analyzing the failings of the current techniques, derive evaluation criteria that are critical to an acceptable solution. We believe that this work will help guide the development of effective telephone spam defenses, as well as provide a framework to evaluate future defenses. Huahong Tu, Adam Doupé, Ziming Zhao 0001, Gail-Joon Ahn |
IEEE Symposium on Security and Privacy | 4 |
| 2016 | TripleMon: A multi-layer security framework for mediating inter-process communication on AndroidabstractAs smartphones have become an indispensable part of daily life, mobile users are increasingly relying on them to process personal information with feature-rich applications. This situation requires robust security mechanisms for protecting sensitive applications and data on mobile devices. Android, as one the most popular smartphone operating systems, provides two core security mechanisms, application sandboxing and a permission system. However, recent studies show that these mechanisms are vulnerable to be passed by a variety of attacks. In this paper, we argue for the need of designing and implementing more comprehensive security mechanisms for Android. We realize that mediating Inter-Process Communication (IPC) channels used by Android applications can mitigate prominent attacks effectively and efficiently. Based on this observation, we propose a practical multi-layer security framework called TripleMon to support policy-based mediation on Android IPC. We also discuss and evaluate a proof-of-concept prototype of TripleMon along with the experimental results derived from real malware samples and synthetic attacks. Yiming Jing, Gail-Joon Ahn, Hongxin Hu, Haehyun Cho, Ziming Zhao 0001 |
J. Comput. Secur. | 2 |
| 2015 | Federated Access Management for Collaborative Network Environments: Framework and Case StudyabstractWith the advent of various collaborative sharing mechanisms such as Grids, P2P and Clouds, organizations including private and public sectors have recognized the benefits of being involved in inter-organizational, multi-disciplinary, and collaborative projects that may require diverse resources to be shared among participants. In particular, an environment that often makes use of a group of high-performance network facilities would involve large-scale collaborative projects and tremendously seek a robust and flexible access control for allowing collaborators to leverage and consume resources, e.g., computing power and bandwidth. In this paper, we propose a federated access management scheme that leverages the notion of attributes. Our approach allows resource-sharing organizations to provide distributed provisioning (publication, location, communication, and evaluation) of both attributes and policies for federated access management purposes. Also, we provide a proof-of-concept implementation that leverages distributed hash tables (DHT) to traverse chains of attributes and effectively handle the federated access management requirements devised for inter-organizational resource sharing and collaborations. Carlos E. Rubio-Medrano, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
SACMAT | 4 |
| 2015 | Preface - WISA 2014
Jeong Hyun Yi, Kyung Hyune Rhee, Gail-Joon Ahn |
Comput. Secur. | 3 |
| 2015 | Towards Automated Risk Assessment and Mitigation of Mobile ApplicationsabstractMobile operating systems, such as Apple's iOS and Google's Android, have supported a ballooning market of feature-rich mobile applications. However, helping users understand and mitigate security risks of mobile applications is still an ongoing challenge. While recent work has developed various techniques to reveal suspicious behaviors of mobile applications, there exists little work to answer the following question: are those behaviors necessarily inappropriate? In this paper, we seek an approach to cope with such a challenge and present a continuous and automated risk assessment framework called RiskMon that uses machine-learned ranking to assess risks incurred by users' mobile applications, especially Android applications. RiskMon combines users' coarse expectations and runtime behaviors of trusted applications to generate a risk assessment baseline that captures appropriate behaviors of applications. With the baseline, RiskMon assigns a risk score on every access attempt on sensitive information and ranks applications by their cumulative risk scores. Furthermore, we demonstrate how RiskMon supports risk mitigation with automated permission revocation. We also discuss a proof-of-concept implementation of RiskMon as an extension of the Android mobile platform and provide both system evaluation and usability study of our methodology. Yiming Jing, Gail-Joon Ahn, Ziming Zhao 0001, Hongxin Hu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2015 | Picture Gesture Authentication: Empirical Analysis, Automated Attacks, and Scheme EvaluationabstractPicture gesture authentication has been recently introduced as an alternative login experience to text-based password on touch-screen devices. In particular, the newly on market Microsoft Windows 8™ operating system adopts such an alternative authentication to complement its traditional text-based authentication. We present an empirical analysis of picture gesture authentication on more than 10,000 picture passwords collected from more than 800 subjects through online user studies. Based on the findings of our user studies, we propose a novel attack framework that is capable of cracking passwords on previously unseen pictures in a picture gesture authentication system. Our approach is based on the concept of selection function that models users’ thought processes in selecting picture passwords. Our evaluation results show the proposed approach could crack a considerable portion of picture passwords under different settings. Based on the empirical analysis and attack results, we comparatively evaluate picture gesture authentication using a set of criteria for a better understanding of its advantages and limitations. Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2014 | Morpheus: automatically generating heuristics to detect Android emulatorsabstractEmulator-based dynamic analysis has been widely deployed in Android application stores. While it has been proven effective in vetting applications on a large scale, it can be detected and evaded by recent Android malware strains that carry detection heuristics. Using such heuristics, an application can check the presence or contents of certain artifacts and infer the presence of emulators. However, there exists little work that systematically discovers those heuristics that would be eventually helpful to prevent malicious applications from bypassing emulator-based analysis. To cope with this challenge, we propose a framework called Morpheus that automatically generates such heuristics. Morpheus leverages our insight that an effective detection heuristic must exploit discrepancies observable by an application. To this end, Morpheus analyzes the application sandbox and retrieves observable artifacts from both Android emulators and real devices. Afterwards, Morpheus further analyzes the retrieved artifacts to extract and rank detection heuristics. The evaluation of our proof-of-concept implementation of Morpheus reveals more than 10,000 novel detection heuristics that can be utilized to detect existing emulator-based malware analysis tools. We also discuss the discrepancies in Android emulators and potential countermeasures. Yiming Jing, Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu |
ACSAC | 3 |
| 2014 | WPES 2014: 13th Workshop on Privacy in the Electronic SocietyabstractThe 13th Workshop on Privacy in the Electronic Society is held on November 3, 2014 in Scottsdale, Arizona, USA in conjunction with the 21st ACM Conference on Computer and Communications Security. The goal of this workshop is to discuss the problems of privacy in global interconnected societies and possible solutions to them. The workshop program includes 17 full papers and 9 short papers on a diverse set of exciting privacy topics selected from a set of 67 total submissions. Specific areas covered include but are not limited to healthcare privacy, censorship circumvention, anonymous communication, web tracking, location and social network privacy. Gail-Joon Ahn, Anupam Datta |
CCS | 1 |
| 2014 | RiskMon: continuous and automated risk assessment of mobile applicationsabstractMobile operating systems, such as Apple's iOS and Google's Android, have supported a ballooning market of feature-rich mobile applications. However, helping users understand security risks of mobile applications is still an ongoing challenge. While recent work has developed various techniques to reveal suspicious behaviors of mobile applications, there exists little work to answer the following question: are those behaviors necessarily inappropriate? In this paper, we seek an approach to cope with such a challenge and present a continuous and automated risk assessment framework called RiskMon that uses machine-learned ranking to assess risks incurred by users' mobile applications, especially Android applications. RiskMon combines users' coarse expectations and runtime behaviors of trusted applications to generate a risk assessment baseline that captures appropriate behaviors of applications. With the baseline, RiskMon assigns a risk score on every access attempt on sensitive information and ranks applications by their cumulative risk scores. We also discuss a proof-of-concept implementation of RiskMon as an extension of the Android mobile platform and provide both system evaluation and usability study of our methodology. Yiming Jing, Gail-Joon Ahn, Ziming Zhao 0001, Hongxin Hu |
CODASPY | 2 |
| 2014 | Discovering and analyzing deviant communities: Methods and experimentsabstractBotnets continue to threaten the security landscape of computer networks worldwide. This is due in part to the time lag present between discovery of botnet traffic and identification of actionable intelligence derived from the traffic analysis. In this article we present a novel method to fill Napoleon Paxton, Dae-il Jang, Ira S. Moskowitz, Gail-Joon Ahn, Stephen Russell 0001 |
CollaborateCom | 4 |
| 2014 | Achieving security assurance with assertion-based application constructionabstractModern software applications are commonly builtby leveraging pre-fabricated modules, e.g. application programming interfaces (APIs), which are essential to implement the desired functionalities of software applications, helping reduce the overall development costs and time. When APIs deal with sec Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
CollaborateCom | 2 |
| 2014 | LPM: Layered Policy Management for Software-Defined Networks
Wonkyu Han, Hongxin Hu, Gail-Joon Ahn |
DBSec | 3 |
| 2014 | Game theoretic analysis of multiparty access control in online social networksabstractExisting online social networks (OSNs) only allow a single user to restrict access to her/his data but cannot provide any mechanism to enforce privacy concerns over data associated with multiple users. This situation leaves privacy conflicts largely unresolved and leads to the potential disclosure of users' sensitive information. To address such an issue, a MultiParty Access Control (MPAC) model was recently proposed, including a systematic approach to identify and resolve privacy conflicts for collaborative data sharing in OSNs. In this paper, we take another step to further study the problem of analyzing the strategic behavior of rational controllers in multiparty access control, where each controller aims to maximize her/his own benefit by adjusting her/his privacy setting in collaborative data sharing in OSNs. We first formulate this problem as a multiparty control game and show the existence of unique Nash Equilibrium (NE) which is critical because at an NE, no controller has any incentive to change her/his privacy setting. We then present algorithms to compute the NE and prove that the system can converge to the NE in only a few iterations. A numerical analysis is also provided for different scenarios that illustrate the interplay of controllers in the multiparty control game. In addition, we conduct user studies of the multiparty control game to explore the gap between game theoretic approaches and real human behaviors. Hongxin Hu, Gail-Joon Ahn, Ziming Zhao 0001, Dejun Yang |
SACMAT | 2 |
| 2014 | Secure and efficient random functions with variable-length output
Yan Zhu 0010, Di Ma 0001, Changjun Hu, Gail-Joon Ahn, Hongxin Hu |
J. Netw. Comput. Appl. | 4 |
| 2013 | Towards comprehensive and collaborative forensics on email evidenceabstractThe digital forensics community has neglected email forensics as a process, despite the fact that email remains an important tool in the commission of crime. At present, there exists little support for discovering, acquiring, and analyzing web-based email, despite its widespread use. In this paper w Justin Paglierani, Mike Mabey, Gail-Joon Ahn |
CollaborateCom | 3 |
| 2013 | Supporting secure collaborations with attribute-based access controlabstractAttribute-based access control (ABAC) has been regarded in recent years as an effective way for providing security guarantees in collaboration environments, due to its alleged flexibility and efficiency for meeting the access control requirements of heterogeneous organizations. Despite the growing Carlos E. Rubio-Medrano, Clinton D'Souza, Gail-Joon Ahn |
CollaborateCom | 3 |
| 2013 | Verifying Access Control Properties with Design by Contract: Framework and Lessons LearnedabstractEnsuring the correctness of high-level security properties including access control policies in mission-critical applications is indispensable. Recent literature has shown how immaturity of such properties has caused serious security vulnerabilities, which are likely to be exploited by malicious parties for compromising a given application. This situation gets aggravated by the fact that modern applications are mostly built on previously developed reusable software modules and any failures in security properties in these reusable modules may lead to vulnerabilities across associated applications. In this paper, we propose a framework to address this issue by adopting Design by Contract (DBC) features. Our framework accommodates security properties in each application focusing on access control requirements. We demonstrate how access control requirements based on ANSI RBAC standard model can be specified and verified at the source code level. Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
COMPSAC | 2 |
| 2013 | On the Security of Picture Gesture Authentication
Ziming Zhao 0001, Gail-Joon Ahn, Jeong-Jin Seo, Hongxin Hu |
USENIX Security Symposium | 2 |
| 2013 | Extensible policy framework for heterogeneous network environmentsabstractSecurity policy management is critical to meet organisational needs and reduce potential risks because almost every organisation depends on computer networks and the internet for their daily operations. It is therefore important to specify and enforce security policies effectively. However, as organisations grow, so do their networks – this increases the difficulty of deploying a security policy, especially across heterogeneous systems. In this paper, we introduce a policy framework called Chameleos-x which is designed to enforce security policies consistently across security-aware systems with network services-primarily operating systems, firewalls, and intrusion detection systems. Throughout this paper, we focus on the design and architecture of Chameleos-x and demonstrate how our policy framework helps organisations implement security policies in changing, diversity-rich environments. We also describe our ongoing work in the experimentation of Chameleos-x, where we have obtained promising results. Lawrence Teo, Gail-Joon Ahn |
Int. J. Inf. Comput. Secur. | 2 |
| 2013 | Discovery and Resolution of Anomalies in Web Access Control PoliciesabstractEmerging computing technologies such as web services, service-oriented architecture, and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services while providing more convenient services to Internet users through such a cutting-edge technological growth. Furthermore, designing and managing web access control policies are often error-prone due to the lack of effective analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly analysis approach for web access control policies, focusing on extensible access control markup language policy. We introduce a policy-based segmentation technique to accurately identify policy anomalies and derive effective anomaly resolutions, along with an intuitive visualization representation of analysis results. We also discuss a proof-of-concept implementation of our method called XAnalyzer and demonstrate how our approach can efficiently discover and resolve policy anomalies. Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | Role-Based Cryptosystem: A New Cryptographic RBAC System Based on Role-Key HierarchyabstractEven though role-based access control (RBAC) can tremendously help us to minimize the complexity in administering users, it still needs to realize the notion of roles at the resource level. In this paper, we propose a practical cryptographic RBAC model, called role-key hierarchy model, to support various security features, including signature, identification, and encryption on role-key hierarchy. In addition, several advanced features, such as role or user revocation, tracing, and anonymity, are implemented as well. With the help of rich algebraic structure of elliptic curves, we introduce a unified and complete construction of role-based cryptosystem to verify the rationality and validity of our proposed model. In addition, a proof-of-concept prototype implementation and performance evaluation is discussed to demonstrate the feasibility and efficiency of our mechanisms. Yan Zhu 0010, Gail-Joon Ahn, Hongxin Hu, Di Ma 0001, Shan-Biao Wang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Multiparty Access Control for Online Social Networks: Model and MechanismsabstractOnline social networks (OSNs) have experienced tremendous growth in recent years and become a de facto portal for hundreds of millions of Internet users. These OSNs offer attractive means for digital social interactions and information sharing, but also raise a number of security and privacy issues. While OSNs allow users to restrict access to shared data, they currently do not provide any mechanism to enforce privacy concerns over data associated with multiple users. To this end, we propose an approach to enable the protection of shared data associated with multiple users in OSNs. We formulate an access control model to capture the essence of multiparty authorization requirements, along with a multiparty policy specification scheme and a policy enforcement mechanism. Besides, we present a logical representation of our access control model that allows us to leverage the features of existing logic solvers to perform various analysis tasks on our model. We also discuss a proof-of-concept prototype of our approach as part of an application in Facebook and provide usability study and system evaluation of our method. Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2013 | Dynamic Audit Services for Outsourced Storages in CloudsabstractIn this paper, we propose a dynamic audit service for verifying the integrity of an untrusted and outsourced storage. Our audit service is constructed based on the techniques, fragment structure, random sampling, and index-hash table, supporting provable updates to outsourced data and timely anomaly detection. In addition, we propose a method based on probabilistic query and periodic verification for improving the performance of audit services. Our experimental results not only validate the effectiveness of our approaches, but also show our audit system verifies the integrity with lower computation overhead and requiring less extra storage for audit metadata. Yan Zhu 0010, Gail-Joon Ahn, Hongxin Hu, Stephen S. Yau, Ho G. An, Changjun Hu |
IEEE Trans. Serv. Comput. | 2 |
| 2012 | Comparison-based encryption for fine-grained access control in cloudsabstractAccess control is one of the most important security mechanisms in cloud computing. However, there has been little work that explores various comparison-based constraints for regulating data access in clouds. In this paper, we present an innovative comparison-based encryption scheme to facilitate fine-grained access control in cloud computing. By means of forward/backward derivation functions, we introduce comparison relation into attribute-based encryption to implement various range constraints on integer attributes, such as temporal and level attributes. Then, we present a new cryptosystem with dual decryption to reduce computational overheads on cloud clients, where the majority of decryption operations are executed in cloud servers. We also prove the security strength of our proposed scheme, and our experiment results demonstrate the efficiency of our methodology. Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Mengyang Yu, Hong-Jia Zhao |
CODASPY | 3 |
| 2012 | Secure sharing of electronic health records in cloudsabstractIn modern healthcare environments, healthcare providers are more willing to shift their electronic medical record systems to clouds. Instead of building and maintaining dedicated data centers, this paradigm enables to achieve lower operational cost and better interoperability with other healthcare p Gail-Joon Ahn, Hongxin Hu |
CollaborateCom | 2 |
| 2012 | SocialImpact: Systematic Analysis of Underground Social Dynamics
Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu, Deepinder Mahi |
ESORICS | 2 |
| 2012 | Enabling Collaborative data sharing in Google+abstractMost of existing online social networks, such as Facebook and Twitter, are designed to bias towards information disclosure to a large audience. Google recently launched a new social network platform, Google+. By introducing the notion of `circles', Google+ enables users to selectively share data with specific groups within their personal network, rather than sharing with all of their social connections at once. Although Google+ can help mitigate the gap between the individuals' expectations and their actual privacy settings, it still only allows a single user to restrict access to her/his data but cannot provide any mechanism to enforce privacy concerns over data associated with multiple users. In this paper, we propose an approach to facilitate collaborative privacy management of shared data in Google+. We extend and formulate a multiparty access control model, named MPAC+, to capture the essence of collaborative authorization requirements in Google+, along with a multiparty policy specification scheme and a policy enforcement mechanism. We also discuss a proof-of-concept prototype of our approach and describe system evaluation and usability study of our prototype. Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
GLOBECOM | 2 |
| 2012 | Secure and efficient constructions of hash, MAC and PRF for mobile devicesabstractNumerous cryptographic techniques have been developed to be used on mobile devices for various security and privacy protections. However, these cryptographic primitives, working under different mathematical assumptions, tend to become more and more complex and intricate, which makes it increasingly more difficult for proper implementation and management. Thus, it is desired to simplify management and improve efficiency by means of designing a general function family to meet a variety of security requirements. In this paper, we present such a family of square functions, including SqHash, SqMAC and SqPRF, based on a specially truncated function (MSB or LSB). We further improve the efficiency of these algorithms by using “circular convolution with carry bits” which makes parallel processing possible. We prove the security of these functions based on the privacy in hidden number problem and hard-core predicate of one-way function. We also show that the proposed schemes achieve better performance with a complexity reduction from O(n2) to O(kn/w) for n-bit message, k-bit output and w-bit word size. Yan Zhu 0010, Shan-Biao Wang, Di Ma 0001, Hongxin Hu, Gail-Joon Ahn |
GLOBECOM | 5 |
| 2012 | Towards temporal access control in cloud computingabstractAbstract—Access control is one of the most important security mechanisms in cloud computing. Attribute-based access control provides a flexible approach that allows data owners to integrate data access policies within the encrypted data. However, little work has been done to explore temporal attributes in specifying and enforcing the data owner’s policy and the data user’s privileges in cloud-based environments. In this paper, we present an efficient temporal access control encryption scheme for cloud services with the help of crypto-graphic integer comparisons and a proxy-based re-encryption mechanism on the current time. We also provide a dual comparative expression of integer ranges to extend the power of attribute expression for implementing various temporal constraints. We prove the security strength of the proposed scheme and our experimental results not only validate the effectiveness of our scheme, but also show that the proposed integer comparison scheme performs significantly better than previous bitwise comparison scheme. Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Dijiang Huang, Shan-Biao Wang |
INFOCOM | 3 |
| 2012 | Efficient construction of provably secure steganography under ordinary covert channels
Yan Zhu 0010, Mengyang Yu, Hongxin Hu, Gail-Joon Ahn, Hong-Jia Zhao |
Sci. China Inf. Sci. | 4 |
| 2012 | Access control for online social networks third party applications
Mohamed Shehab, Anna Cinzia Squicciarini, Gail-Joon Ahn, Irini Kokkinou |
Comput. Secur. | 3 |
| 2012 | Secure Collaborative Integrity Verification for Hybrid Cloud EnvironmentsabstractA hybrid cloud is a cloud computing environment in which an organization provides and manages some internal resources and has others provided externally. However, this new environment could bring irretrievable losses to the clients due to a lack of integrity verification mechanism for distributed data outsourcing. To support scalable service and data migration, in this paper we address the construction of a collaborative integrity verification mechanism in hybrid clouds where we consider the existence of multiple cloud service providers to collaboratively store and maintain the clients' data. We propose a collaborative provable data possession scheme adopting the techniques of homomorphic verifiable responses and hash index hierarchy. In addition, we articulate the performance optimization mechanisms for our scheme and prove the security of our scheme based on multi-prover zero-knowledge proof system, which can satisfy the properties of completeness, knowledge soundness, and zero-knowledge. Our experiments also show that our proposed solution only incurs a small constant amount of communications overhead. Yan Zhu 0010, Shan-Biao Wang, Hongxin Hu, Gail-Joon Ahn, Di Ma 0001 |
Int. J. Cooperative Inf. Syst. | 4 |
| 2012 | Comprehensive two-level analysis of role-based delegation and revocation policies with UML and OCL
Karsten Sohr, Mirco Kuhlmann, Martin Gogolla, Hongxin Hu, Gail-Joon Ahn |
Inf. Softw. Technol. | 5 |
| 2012 | Policy-driven role-based access management for ad-hoc collaborationabstractAd-hoc collaboration is a newly emerged environment enabling distributed collaborators to share resources. The dynamic nature and unique sharing pattern in ad-hoc collaboration poses great challenges for security services to accommodate both access control and trust management requirements in providing controlled resource sharing. In this paper, we propose a comprehensive, integrated and implemented access management framework, called RAMARS, for secure digital information sharing in ad-hoc collaboration. Our framework incorporates a role-based approach to leverage the originator control, delegation and dissemination control. A trust awareness feature is integrated for dynamic user-role assignment based on user attributes. The access control polices are formally specified, and a peer-to-peer scientific information sharing system – ShareEnabler – is presented to demonstrate the feasibility of our approach. The performance evaluation of our prototype system with potential system improvements is also discussed. Gail-Joon Ahn, Mohamed Shehab |
J. Comput. Secur. | 1 |
| 2012 | Efficient audit service outsourcing for data integrity in clouds
Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Stephen S. Yau |
J. Syst. Softw. | 3 |
| 2012 | Enhancing directory virtualization to detect insider activityabstractABSTRACT One of the critical yet lingering issues in computer security is insider threat, and it often takes advantage of some security services based on directory services such as authentication and access control. Detecting these threats is quite challenging because malicious users with the technical ability to leverage these services often have sufficient knowledge and expertise to conceal unauthorized activity. In this article, we present an approach using directory virtualization to monitor various systems across an enterprise for the purpose of detecting malicious insider activity. Specifically, a policy engine that leverages directory virtualization services is proposed to enhance monitoring and detecting capabilities by allowing greater flexibility in analyzing changes for malicious intent. The resulting architecture is a system‐based approach, where the relationships and dependencies between data sources and directory services are used to detect an insider threat, rather than simply relying on point solutions. This paper presents such an architecture in detail, including a description of implementation results. Copyright © 2011 John Wiley & Sons, Ltd. William R. Claycomb, Dongwan Shin, Gail-Joon Ahn |
Secur. Commun. Networks | 3 |
| 2012 | Detecting and Resolving Firewall Policy AnomaliesabstractThe advent of emerging computing technologies such as service-oriented architecture and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services. Firewalls are the most widely deployed security mechanism to ensure the security of private networks in most businesses and institutions. The effectiveness of security protection provided by a firewall mainly depends on the quality of policy configured in the firewall. Unfortunately, designing and managing firewall policies are often error prone due to the complex nature of firewall configurations as well as the lack of systematic analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly management framework for firewalls, adopting a rule-based segmentation technique to identify policy anomalies and derive effective anomaly resolutions. In particular, we articulate a grid-based representation technique, providing an intuitive cognitive sense about policy anomaly. We also discuss a proof-of-concept implementation of a visualization-based firewall policy analysis tool called Firewall Anomaly Management Environment (FAME). In addition, we demonstrate how efficiently our approach can discover and resolve anomalies in firewall policies through rigorous experiments. Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2012 | Remote Attestation with Domain-Based Integrity Model and Policy AnalysisabstractWe propose and implement an innovative remote attestation framework called DR@FT for efficiently measuring a target system based on an information flow-based integrity model. With this model, the high integrity processes of a system are first measured and verified, and these processes are then protected from accesses initiated by low integrity processes. Toward dynamic systems with frequently changed system states, our framework verifies the latest state changes of a target system instead of considering the entire system information. Our attestation evaluation adopts a graph-based method to represent integrity violations, and the graph-based policy analysis is further augmented with a ranked violation graph to support high semantic reasoning of attestation results. As a result, DR@FT provides efficient and effective attestation of a system's integrity status, and offers intuitive reasoning of attestation results for security administrators. Our experimental results demonstrate the feasibility and practicality of DR@FT. Wenjuan Xu, Xinwen Zhang, Hongxin Hu, Gail-Joon Ahn, Jean-Pierre Seifert |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2012 | Risk-Aware Mitigation for MANET Routing AttacksabstractMobile Ad hoc Networks (MANET) have been highly vulnerable to attacks due to the dynamic nature of its network infrastructure. Among these attacks, routing attacks have received considerable attention since it could cause the most devastating damage to MANET. Even though there exist several intrusion response techniques to mitigate such critical attacks, existing solutions typically attempt to isolate malicious nodes based on binary or naïve fuzzy response decisions. However, binary responses may result in the unexpected network partition, causing additional damages to the network infrastructure, and naïve fuzzy responses could lead to uncertainty in countering routing attacks in MANET. In this paper, we propose a risk-aware response mechanism to systematically cope with the identified routing attacks. Our risk-aware approach is based on an extended Dempster-Shafer mathematical theory of evidence introducing a notion of importance factors. In addition, our experiments demonstrate the effectiveness of our approach with the consideration of several performance metrics. Ziming Zhao 0001, Hongxin Hu, Gail-Joon Ahn |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2012 | Cooperative Provable Data Possession for Integrity Verification in Multicloud StorageabstractProvable data possession (PDP) is a technique for ensuring the integrity of data in storage outsourcing. In this paper, we address the construction of an efficient PDP scheme for distributed cloud storage to support the scalability of service and data migration, in which we consider the existence of multiple cloud service providers to cooperatively store and maintain the clients' data. We present a cooperative PDP (CPDP) scheme based on homomorphic verifiable response and hash index hierarchy. We prove the security of our scheme based on multiprover zero-knowledge proof system, which can satisfy completeness, knowledge soundness, and zero-knowledge properties. In addition, we articulate performance optimization mechanisms for our scheme, and in particular present an efficient method for selecting optimal parameter values to minimize the computation costs of clients and storage service providers. Our experiments show that our solution introduces lower computation and communication overheads in comparison with noncooperative approaches. Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Mengyang Yu |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2011 | Detecting and resolving privacy conflicts for collaborative data sharing in online social networksabstractWe have seen tremendous growth in online social networks (OSNs) in recent years. These OSNs not only offer attractive means for virtual social interactions and information sharing, but also raise a number of security and privacy issues. Although OSNs allow a single user to govern access to her/his data, they currently do not provide any mechanism to enforce privacy concerns over data associated with multiple users, remaining privacy violations largely unresolved and leading to the potential disclosure of information that at least one user intended to keep private. In this paper, we propose an approach to enable collaborative privacy management of shared data in OSNs. In particular, we provide a systematic mechanism to identify and resolve privacy conflicts for collaborative data sharing. Our conflict resolution indicates a tradeoff between privacy protection and data sharing by quantifying privacy risk and sharing loss. We also discuss a proof-of-concept prototype implementation of our approach as part of an application in Facebook and provide system evaluation and usability study of our methodology. Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
ACSAC | 2 |
| 2011 | Poster: temporal attribute-based encryption in clouds
Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Xiaorui Gong, Shimin Chen |
CCS | 3 |
| 2011 | Ontology-based policy anomaly management for autonomic computingabstractThe advent of emerging computing technologies such as service-oriented architecture and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services. Moreover, des Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
CollaborateCom | 2 |
| 2011 | Collaborative integrity verification in hybrid cloudsabstractA hybrid cloud is a cloud computing environment in which an organization provides and manages some internal resources and the others provided externally. However, this new environment could bring irretrievable losses to the clients due to a lack of integrity verification mechanism for distribute Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Yujing Han, Shimin Chen |
CollaborateCom | 3 |
| 2011 | MasterBlaster: Identifying Influential Players in Botnet TransactionsabstractBotnets continue to be a critical tool for hackers in exploiting vulnerabilities of systems and destructing computer networks. Botnet monitoring is a method used to study and identify malicious capabilities of a botnet, but current botnet monitoring projects mainly identify the magnitude of the botnet problem and tend to overt some fundamental problems, such as the diversified sources of the attacks. Most malicious botnets have the ability to be rented out to a broad range of potential customers, allowing each customer to launch different attacks from the other. Consequently, under the control of multiple botmasters, various attacks and transactions at different times attempt to damage networked infrastructures. In this paper we propose a multi-layered analysis system called Master Blaster which identifies the communication characteristics of a botmaster in botnet transactions and correlates those characteristics with evolutionary changes within botnet communication channels. Our results show the level of involvement of the monitored botmasters within a botnet as well as their general motives. Our system clearly indicates that the investigation of each botmaster and analysis of botmaster interactions are essential to cope with net-centric attacks caused by botnets. Napoleon Paxton, Gail-Joon Ahn, Mohamed Shehab |
COMPSAC | 2 |
| 2011 | Multiparty Authorization Framework for Data Sharing in Online Social Networks
Hongxin Hu, Gail-Joon Ahn |
DBSec | 2 |
| 2011 | Examining Social Dynamics for Countering Botnet AttacksabstractEven though promising results have been obtained from existing research on bots and associated command and control channels, there is little research in exploring the ways on how bots are created and distributed by adversaries. Consequently, innovative methods that help determine the linkage between the rogue programs and adversaries are imperative for mitigating and combating botnet attacks. Recent study discovers that rogue programs are sold in black markets in online social networks and adversaries use online social networks to coordinate attacks. Correlation of botnet attacks and activities in online underground social networks is crucial to tactically cope with net-centric threats. In this paper, we take the first step toward adversarial behavior identification by modeling social dynamics of underground adversarial communities and tracing the origin of certain malwares and attack events in underground communities. We also describe our evaluation to demonstrate the effectiveness of our approach. Ziming Zhao 0001, Gail-Joon Ahn, Hongxin Hu |
GLOBECOM | 2 |
| 2011 | Ontology-Based Risk Evaluation in User-Centric Identity ManagementabstractRecent trends in the area of identity management have evolved from a traditional identification solution to a distributed user-centric identity management mechanism. The major goal of user-centric identity management is to enable the users to have control over their own digital identities. Even though existing identity management systems attempt to offer user-centricity where users possess complete control on their identity disclosure, however, it does not signify the consequences of the users' behavior. It is necessary to assist the users on the risk involved in disclosing their identity attributes. In this paper, we propose a risk-aware mechanism to help the users decide the degree of identity disclosure risk using ontology-based evaluation and privacy preference evaluation. We demonstrate the feasibility of our approach on dynamic online social networks where the user's identity plays a major role for access control and privacy management. Gail-Joon Ahn, Pradeep Sekar |
ICC | 1 |
| 2011 | Anomaly discovery and resolution in web access control policiesabstractThe advent of emerging technologies such as Web services, service-oriented architecture, and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services while providing more convenient services to Internet users through such a cutting-edge technological growth. Furthermore, designing and managing Web access control policies are often error-prone due to the lack of effective analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly analysis approach for Web access control policies. We focus on XACML (eXtensible Access Control Markup Language) policy since XACML has become the de facto standard for specifying and enforcing access control policies for various Web-based applications and services. We introduce a policy-based segmentation technique to accurately identify policy anomalies and derive effective anomaly resolutions. We also discuss a proof-of-concept implementation of our method called XAnalyzer and demonstrate how efficiently our approach can discover and resolve policy anomalies. Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
SACMAT | 2 |
| 2011 | Zero-knowledge proofs of retrievability
Yan Zhu 0010, Huaixi Wang, Zexing Hu, Gail-Joon Ahn, Hongxin Hu |
Sci. China Inf. Sci. | 4 |
| 2011 | Patient-centric authorization framework for electronic healthcare services
Gail-Joon Ahn, Hongxin Hu, Michael J. Covington, Xinwen Zhang |
Comput. Secur. | 2 |
| 2011 | Assured resource sharing in Grid environmentsabstractIn Grid-based collaborations, a number of data sharing services in Grid are established to provide a unified platform for dynamic discovery, access and replication of distributed data. Controlling access to Grid data in these services requires the ability to dynamically make authorisation decisions based on the data owners’ policies and users’ credentials across administrative domains. In this paper, we present a flexible policy-driven authorisation system, called RamarsAuthZ, for secure data sharing services in Grid systems. RamarsAuthZ adopts a flexible role-based approach with trust-aware feature to advocate originator control, delegation and dissemination control. A case study based on Globus data replication service (DRS) is presented to provide effective access control both at the service level and at the data level. Our system is flexible and interoperable with multiple Grid services with little reliance on static policy and attribute management. Gail-Joon Ahn |
Int. J. Inf. Comput. Secur. | 2 |
| 2011 | Provably Secure Role-Based Encryption with Revocation Mechanism
Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Huaixi Wang, Shan-Biao Wang |
J. Comput. Sci. Technol. | 3 |
| 2010 | Cryptographic role-based security mechanisms based on role-key hierarchyabstractEven though role-based access control (RBAC) can tremendously help us minimize the complexity in administering users, it is still needed to realize the notion of roles at the resource level. In this paper, we propose a practical cryptographic RBAC model, called role-key hierarchy model, to support various security features including signature and encryption based on role-key hierarchy. With the help of rich algebraic structure of elliptic curve, we introduce a role-based cryptosystem construction to verify the rationality and validity of our proposed model. Also, a proof-of-concept prototype implementation and performance evaluation are discussed to demonstrate the feasibility and efficiency of our mechanisms. Yan Zhu 0010, Gail-Joon Ahn, Hongxin Hu, Huaixi Wang |
AsiaCCS | 2 |
| 2010 | Efficient provable data possession for hybrid cloudsabstractProvable data possession is a technique for ensuring the integrity of data in outsourcing storage service. In this paper, we propose a cooperative provable data possession scheme in hybrid clouds to support scalability of service and data migration, in which we consider the existence of multiple cloud service providers to cooperatively store and maintain the clients' data. Our experiments show that the verification of our scheme requires a small, constant amount of overhead, which minimizes communication complexity. Yan Zhu 0010, Huaixi Wang, Zexing Hu, Gail-Joon Ahn, Hongxin Hu, Stephen S. Yau |
CCS | 4 |
| 2010 | Information flow control in cloud computingabstractCloud computing is an emerging computing paradigm where computing resources are provided as services over Internet while residing in a large data center. Even though it enables us to dynamically provide servers with the ability to address a wide range of needs, this paradigm brings forth many new ch Gail-Joon Ahn, Hongxin Hu, Mukesh Singhal |
CollaborateCom | 2 |
| 2010 | A collaborative framework for privacy protection in online social networksabstractWith the wide use of online social networks (OSNs), the problem of data privacy has attracted much attention. Several approaches have been proposed to address this issue. One of privacy management approaches for OSN leverages a key management technique to enable a user to simply post encrypted conte Yan Zhu 0010, Zexing Hu, Huaixi Wang, Hongxin Hu, Gail-Joon Ahn |
CollaborateCom | 5 |
| 2010 | Representing and Reasoning about Web Access Control PoliciesabstractThe advent of emerging technologies such as Web services, service-oriented architecture, and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized services while providing more convenient services to Internet users through such a cutting-edge technological growth. Furthermore, designing and managing Web access control policies are often error-prone due to the lack of logical and formal foundation. In this paper, we attempt to introduce a logic-based policy management approach for Web access control policies especially focusing on XACML (eXtensible Access Control Markup Language) policies, which have become the de facto standard for specifying and enforcing access control policies for various applications and services in current Web-based computing technologies. Our approach adopts Answer Set Programming (ASP) to formulate XACML that allows us to leverage the features of ASP solvers in performing various logical reasoning and analysis tasks such as policy verification, comparison and querying. In addition, we propose a policy analysis method that helps identify policy violations in XACML policies accommodating the notion of constraints in role-based access control (RBAC). We also discuss a proof-of-concept implementation of our method called XACMLl2ASP with the evaluation of several XACML policies from real-world software systems. Gail-Joon Ahn, Hongxin Hu, Joohyung Lee 0002, Yunsong Meng |
COMPSAC | 1 |
| 2010 | DR@FT: Efficient Remote Attestation Framework for Dynamic Systems
Wenjuan Xu, Gail-Joon Ahn, Hongxin Hu, Xinwen Zhang, Jean-Pierre Seifert |
ESORICS | 2 |
| 2010 | Risk-Aware Response for Mitigating MANET Routing AttacksabstractMobile Ad hoc Networks (MANET) have been highly vulnerable to attacks due to the dynamic nature of its network infrastructure. Among these attacks, routing attacks have received considerable attention since it could cause the most devastating damage to MANET. Even though there exist several intrusion response techniques to mitigate such critical attacks, existing solutions typically attempt to isolate malicious nodes based on binary or naive fuzzy response decisions. However, binary responses may result in the unexpected network partition, causing additional damages to the network infrastructure, and naive fuzzy responses could lead to uncertainty in countering routing attacks in MANET. In this paper, we propose a risk-aware response mechanism to systematically cope with the identified routing attacks. Our risk-aware approach is based on an extended Dempster-Shafer mathematical theory of evidence introducing a notion of importance factor. In addition, our experiments demonstrate the effectiveness of our approach with the consideration of the packet delivery ratio and routing cost. Ziming Zhao 0001, Hongxin Hu, Gail-Joon Ahn |
GLOBECOM | 3 |
| 2010 | Constructing Authorization Systems Using Assurance Management FrameworkabstractModel-driven approach has recently received much attention in developing secure software and systems. In addition, software developers have attempted to employ such an emerging approach in the early stage of software development life cycle. However, security concerns are rarely considered and practiced due to the lack of appropriate systematic mechanisms and tools. In this paper, we introduce a multilayered software development life cycle (SDLC), which is based on an assurance management framework (AMF), focusing on the development of authorization systems. AMF facilitates comprehensive realization of formal security model, security policy specification and verification, generation of security enforcement codes, and rigorous conformance testing. We also articulate our experience in analyzing role-based authorization requirements and realizing those requirements in constructing a role-based authorization system. Hongxin Hu, Gail-Joon Ahn |
IEEE Trans. Syst. Man Cybern. Part C | 2 |
| 2009 | Towards System Integrity Protection with Graph-Based Policy Analysis
Wenjuan Xu, Xinwen Zhang, Gail-Joon Ahn |
DBSec | 3 |
| 2009 | Privacy-Enhanced User-Centric Identity ManagementabstractUser-centric identity management approaches have received significant attention for managing private and critical identity attributes from the user's perspective. User-centric identity management allows users to control their own digital identities. Users are allowed to select their credentials when responding to an authentication or attribute requester and it gives users more rights and responsibility over their identity information. However, current user-centric approaches mainly focus on interoperable architectures between existing identity management systems and privacy issues have not been considered in depth. In this paper, we propose a category-based privacy preference approach to enhance the privacy of user-centric identity management systems. In addition, we present our proof- of-concept prototype of our approach in the Identity Metasystem. Gail-Joon Ahn, Moonam Ko, Mohamed Shehab |
ICC | 1 |
| 2009 | Patient-centric authorization framework for sharing electronic health recordsabstractIn modern healthcare environments, a fundamental requirement for achieving continuity of care is the seamless access to distributed patient health records in an integrated and unified manner, directly at the point of care. However, Electronic Health Records (EHRs) contain a significant amount of sensitive information, and allowing data to be accessible at many different sources increases concerns related to patient privacy and data theft. Access control solutions must guarantee that only authorized users have access to such critical records for legitimate purposes, and access control policies from distributed EHR sources must be accurately reflected and enforced accordingly in the integrated EHRs. Gail-Joon Ahn, Hongxin Hu, Michael J. Covington, Xinwen Zhang |
SACMAT | 2 |
| 2009 | Security-Enhanced OSGi Service EnvironmentsabstractToday's home and local-area network environments consist of various types of personal equipments, network devices, and corresponding services. Since such prevalent home network environments frequently deal with private and sensitive information, it is crucial to legitimately provide access control for protecting such emerging environments. As a result, the open services gateway initiative (OSGi) attempted to address this critical issue. However, the current OSGi authorization mechanism is not rigorous enough to fulfill security requirements involved in dynamic OSGi environments. In this paper, we provide a systematic way to adopt a role-based access control (RBAC) approach in OSGi environments. We demonstrate how our authorization framework can achieve important RBAC features and enhance existing primitive access control modules in OSGi service environments. Also, we describe a proof-of-concept prototype of the proposed framework to discuss the feasibility of our approach using an open source implementation of OSGi framework known as Knopflerfish. Gail-Joon Ahn, Hongxin Hu |
IEEE Trans. Syst. Man Cybern. Part C | 1 |
| 2008 | Enforcing Role-Based Access Control Policies in Web Services with UML and OCLabstractRole-based access control (RBAC) is a powerful means for laying out higher-level organizational policies such as separation of duty, and for simplifying the security management process. One of the important aspects of RBAC is authorization constraints that express such organizational policies. While RBAC has generated a great interest in the security community, organizations still seek a flexible and effective approach to impose role-based authorization constraints in their security-critical applications. In this paper, we present a Web Services-based authorization framework that can be employed to enforce organization-wide authorization constraints. We describe a generic authorization engine, which supports organization-wide authorization constraints and acts as a central policy decision point within the authorization framework. This authorization engine is implemented by means of the USE system, a validation tool for UML models and OCL constraints. Karsten Sohr, Tanveer Mustafa, Xinyu Bao, Gail-Joon Ahn |
ACSAC | 4 |
| 2008 | Access Control Model for Sharing Composite Electronic Health Records
Gail-Joon Ahn, Michael J. Covington, Xinwen Zhang |
CollaborateCom | 2 |
| 2008 | Risk Evaluation for Personal Identity Management Based on Privacy Attribute Ontology
Mizuho Iwaihara, Kohei Murakami, Gail-Joon Ahn, Masatoshi Yoshikawa |
ER | 3 |
| 2008 | Beyond User-to-User Access Control for Online Social Networks
Mohamed Shehab, Anna Cinzia Squicciarini, Gail-Joon Ahn |
ICICS | 3 |
| 2008 | Enabling verification and conformance testing for access control modelabstractVerification and testing are the important step for software assurance. However, such crucial and yet challenging tasks have not been widely adopted in building access control sys-tems. In this paper we propose a methodology to sup-port automatic analysis and conformance testing for ac-cess control systems, integrating those features to Assur-ance Management Framework (AMF). Our methodology at-tempts to verify formal specifications of a role-based access control model and corresponding policies with selected se-curity properties. Also, we systematically articulate testing cases from formal specifications and validate conformance to the system design and implementation using those cases. In addition, we demonstrate feasibility and effectiveness of our methodology using SAT and Alloy toolset. Hongxin Hu, Gail-Joon Ahn |
SACMAT | 2 |
| 2008 | Visualization based policy analysis: case study in SELinuxabstractDetermining whether a given policy meets a site's high-level security goals can be difficult, due to the low-level nature and complexity of the policy language, and the multiple policy violation patterns. In this paper, we propose a visualization-based policy analysis framework that enables system administrators to visually query and visualize SELinux security policies and to easily identify the policy violations. We propose and formalize both a semantic substrate and adjacency matrix visualization techniques for policy visualization. Furthermore, we propose a visual query language for expressing policy queries in a visual form. Our framework is targeted towards enabling the average administrator by providing an intuitive cognitive sense about the policy, policy queries and policy violations. We also describe our implementation of a visualization-based policy analysis tool that provides the functionalities discussed in our framework. Wenjuan Xu, Mohamed Shehab, Gail-Joon Ahn |
SACMAT | 3 |
| 2008 | Portable User-Centric Identity Management
Gail-Joon Ahn, Moonam Ko, Mohamed Shehab |
SEC | 1 |
| 2008 | Analyzing and Managing Role-Based Access Control PoliciesabstractToday more and more security-relevant data is stored on computer systems; security-critical business processes are mapped to their digital counterparts. This situation applies to various domains such as health care industry, digital government, and financial service institutes requiring that different security requirements must be fulfilled. Authorisation constraints can help the policy architect design and express higher-level organisational rules. Although the importance of authorisation constraints has been addressed in the literature, there does not exist a systematic way to verify and validate authorisation constraints. In this paper, we specify both non-temporal and history-based authorisation constraints in the Object Constraint Language (OCL) and first-order linear temporal logic (LTL). Based upon these specifications, we attempt to formally verify role-based access control policies with the help of a theorem prover and to validate policies with the USE system, a validation tool for OCL constraints. We also describe an authorisation engine, which supports the enforcement of authorisation constraints. Karsten Sohr, Michael Drouineaud, Gail-Joon Ahn, Martin Gogolla |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2007 | Managing heterogeneous network environments using an extensible policy frameworkabstractSecurity policy management is critical to meet organizational needs and reduce potential risks because almost every organization depends on computer networks and the Internet for their daily operations. It is therefore important to specify and enforce security policies effectively. However, as organizations grow, so do their networks increasing the difficulty of deploying a security policy, especially across heterogeneous systems. In this paper, we introduce a policy framework called Chameleos-x which is designed to enforce security policies consistently across security-aware systems with network services-primarily operating systems, firewalls, and intrusion detection systems. Throughout this paper, we focus on the design and architecture of Chameleos-x and demonstrate how our policy framework helps organizations implement security policies in changing, diversity-rich environments. We also describe our experimentation of Chameleos-x to demonstrate the feasibility of the proposed approach. Lawrence Teo, Gail-Joon Ahn |
AsiaCCS | 2 |
| 2007 | User-centric privacy management for federated identity managementabstractWe have witnessed that the Internet is now a prime vehicle for business, community, and personal interactions. The notion of identity is the important component of this vehicle. Identity management has been recently considered to be a viable solution for simplifying user management across enterprise applications. The network identity of each user is the global set of personal credentials and preferences constituting the various accounts. The prevalence of business alliances or coalitions necessitates the further evolution of identity management, named federated identity management (FIM). The main motivation of FIM is to facilitate the federation of identities among business partners emphasizing on ease of user management. In this paper, we propose systematic mechanisms to specify privacy preferences in FIM, attempting to help users facilitate preferences for managing their private information across domains. Gail-Joon Ahn, Moonam Ko |
CollaborateCom | 1 |
| 2007 | Towards trust-aware access management for ad-hoc collaborationsabstractIn an ad-hoc collaborative sharing environment, attribute-based access control provides a promising approach in defining authorization over shared resources based on userspsila properties/attributes rather than their identities. While the userpsilas attributes are always asserted by different authorities in the form of credentials, these authorities may not be accepted by the resource owner with the same degree of trust. In this paper, we present a trust-aware role-based authorization framework, called RAMARS_TM, to address both the access control and the trust management issues in such environment. Central to our approach is the dynamic role assignment based on a userpsilas attributes, and trust management, as a special constraint, is in place to make trust decisions on a userpsilas attributes. Required components and functions are identified and specified in our trust and access management policies. An architecture of prototype system implementation is also discussed. Gail-Joon Ahn, Mohamed Shehab, Hongxin Hu |
CollaborateCom | 2 |
| 2007 | Enabling Role-Based Delegation and Revocation on Security-Enhanced LinuxabstractAn increasing number of attacks experienced in existing enterprise networks and applications have recently created a huge demand for security mechanisms of operating systems. As a consequence, security-enhanced Linux (SELinux) was proposed by NSA and the industries have adopted SELinux at a fast rate. More and more enterprises are planning to move their business operations to such a secure computing environment, re quiring the features of delegation and revocation. In this paper we seek to address the issue of how to leverage a role-based delegation in SELinux while minimizing the modification of SELinux system modules. Our approach is to utilize the flexible policy system used in SELinux that allows for custom rules to be defined for supporting access control requirements. We also demonstrate the feasibility of our framework through a proof-of-concept implementation. Gail-Joon Ahn, Dhruv Gami |
ISCC | 1 |
| 2007 | Towards realizing a formal RBAC model in real systemsabstractThere still exists an open question on how formal models can be fully realized in the system development phase. The Model Driven Development (MDD) approach has been recently introduced to deal with such a critical issue for building high assurance software systems. Gail-Joon Ahn, Hongxin Hu |
SACMAT | 1 |
| 2007 | Towards secure information sharing using role-based delegation
Gail-Joon Ahn, Badrinath Mohan, Seng-Phil Hong |
J. Netw. Comput. Appl. | 1 |
| 2007 | Guest editorial: Special issue on access control models and technologiesabstractNo abstract available. Gail-Joon Ahn |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2006 | Towards Secure Information Sharing and Management in Grid EnvironmentsabstractThe introduction of service-oriented paradigm in grid and corresponding Web services standards has recently demanded the evolution of access control solutions to support finegrained authorization requirements and dynamic natures derived from grid environments. In this paper, we present a role-based authorization infrastructure for data sharing and management services in grid. Our infrastructure advocates a dynamic and flexible resource-centric authorization approach with features of distributed role-based access control and systematic delegation of administrative authority. The infrastructure seamlessly integrates the existing XACML-based policy framework and authorization services in the RAMARS framework. We discuss our proof-of-concept prototype system that supports Web services and SAML based authorization assertions. We also describe how the framework can be deployed in being compatible with an open grid service architecture Gail-Joon Ahn |
CollaborateCom | 2 |
| 2006 | Role-based access management for ad-hoc collaborative sharingabstractUnder scientific collaborations, resource sharing tends to be highly dynamic and often ad hoc. The dynamic characteristics and sharing patterns of ad-hoc collaborative sharing impose a need for comprehensive and flexible approaches to reflect and cope with the unique access control requirements associated with the ad-hoc collaboration. In this paper, we propose a role-based access management framework to enable secure resource sharing,especially focusing on the digital information sharing in the heterogeneous scientific collaboration environments.Our framework incorporates role-based approach to address distributed access control, delegation and dissemination control involved in the resource sharing within such environments. A set of XACML-based policy schemas is proposed to specify policies on our framework. To demonstrate the feasibility of our framework, we design and implement a proof-of-concept prototype system called ShareEnabler, which is based on a peer-to-peer information sharing toolkit developed by Lawrence Berkeley National Laboratory. Gail-Joon Ahn |
SACMAT | 2 |
| 2006 | Building Decision Support Problem Domain Ontology from Natural Language Requirements for Software AssuranceabstractThe process of engineering software-intensive systems that comply with their Certification and Accreditation (C&A) requirements involves many critical decision-making activities for the related stakeholders. Considering the exhaustive nature of C&A activities together with the complexity of software-intensive systems, effective decision making relies heavily on the ways to understand and structure the problem domain concepts concerning decision points for interpretation, applicability, scope, evaluation, and impact of the enforced C&A requirements. These decision points are further complicated by natural language specifications of inherently non-functional C&A requirements scattered across multiple regulatory documents with complex interdependencies at different levels of abstractions in the organizational hierarchy, which often result in subjective interpretations and non-standard implementations of the C&A process. To address these issues, we define a systematic methodology using novel techniques from software Requirements Engineering (RE) and knowledge engineering for understanding and structuring the problem domain concepts based on a uniform representation format that promotes common understanding among stakeholders. Specifically, we use advanced ontological engineering techniques driven by theoretical RE foundations to systematically elicit, model, understand, and analyze problem domain concepts concerning significant and difficult decision points throughout the C&A process. We demonstrate the appropriateness of our methodology in creating decision support problem domain ontology using several examples derived from our experiences on automating the Department of Defense Information Technology Security C&A Process (DITSCAP). Seok Won Lee, Divya Muthurajan, Robin A. Gandhi, Deepak S. Yavagal, Gail-Joon Ahn |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2005 | Specification and Validation of Authorisation Constraints Using UML and OCL
Karsten Sohr, Gail-Joon Ahn, Martin Gogolla, Lars Migge |
ESORICS | 2 |
| 2005 | Active Automation of the DITSCAP
Seok Won Lee, Robin A. Gandhi, Gail-Joon Ahn, Deepak S. Yavagal |
ISI | 3 |
| 2004 | Ensuring information assurance in federated identity managementabstractSurveys and polling data confirm that the Internet is now a prime vehicle for business, community, and personal interactions. The notion of identity is the important component of this vehicle. When users interact with services on the Internet, they often tailor the services in some way for their personal use. For example, a user may establish an account with a username and password and/or set some preferences for what information the user wants displayed and how the user wants it displayed. The network identity of each user is the overall global set of these attributes constituting the various accounts. In this paper, we investigate two well-known federated identity management (FIM) solutions, Microsoft Passport and Liberty Alliance, attempting to identify information assurance (IA) requirements in FIM. In particular, we focus on principal IA requirements for Web services (WS) which plays an integral role in enriching identity management through federation. Dongwan Shin, Gail-Joon Ahn, Prasad Shenoy |
IPCCC | 2 |
| 2004 | Role-Based Privilege Management Using Attribute Certificates and Delegation
Gail-Joon Ahn, Dongwan Shin, Longhua Zhang |
TrustBus | 1 |
| 2004 | Information Assurance in Federated Identity Management: Experimentations and Issues
Gail-Joon Ahn, Dongwan Shin, Seng-Phil Hong |
WISE | 1 |
| 2004 | A role-based infrastructure management system: design and implementationabstractAbstract Over the last decade there has been a tremendous advance in the theory and practice of role‐based access control (RBAC). One of the most significant aspects of RBAC can be viewed from its management of permissions on the basis of roles rather than individual users. Consequently, it reduces administrative costs and potential errors. The management of roles in various RBAC implementations, however, tends to be conducted on an ad hoc basis, closely coupled with a certain context of system environments. This paper discusses the development of a system whose purpose is to help manage a valid set of roles with assigned users and permissions for role‐based authorization infrastructures. We have designed and implemented the system, called RolePartner. This system enables role administrators to build and configure various components of a RBAC model so as to embody organizational access control policies which can be separated from different enforcement mechanisms. Hence the system helps make it possible to lay a foundation for role‐based authorization infrastructures. Three methodological constituents are introduced for our purposes, together with the design and implementation issues. The system has a role‐centric view for easily managing constrained and hierarchical roles as well as assigned users and permissions. An LDAP‐accessible directory service was used for a role database. We show that the system can be seamlessly integrated with an existing privilege‐based authorization infrastructure. Copyright © 2004 John Wiley & Sons, Ltd. Dongwan Shin, Gail-Joon Ahn, Sangrae Cho, Seunghun Jin |
Concurr. Pract. Exp. | 2 |
| 2003 | The role control center: features and case studiesabstractRole-based Access Control (RBAC) models have been implemented not only in self-contained resource management products such as DBMSs and Operating Systems but also in a class of products called Enterprise Security Management Systems (ESMS). ESMS products are used for centralized management of authorizations for resources resident in several heterogeneous systems (called target systems) distributed throughout the enterprise. The RBAC model used in an ESMS is called the Enterprise RBAC model (ERBAC). An ERBAC model can be used to specify not only sophisticated access requirements centrally for resources resident in several target systems, but also administrative data required to map those defined access requirements to the access control structures native to the target platforms. However, the ERBAC model (i.e., the RBAC implementation) supported in many commercial ESMS products has not taken full advantage of policy specification capabilities of RBAC. In this paper we describe an implementation of ESMS called the 'Role Control Center' (RCC) that supports an ERBAC model that includes features such as general role hierarchy, static separation of duty constraints, and an advanced permission review facility (as defined in NIST's proposed RBAC standard). We outline the various modules in the RCC architecture and describe how they collectively provide support for authorization administration tasks at the enterprise and target-system levels. David F. Ferraiolo, Ramaswamy Chandramouli, Gail-Joon Ahn, Serban I. Gavrila |
SACMAT | 3 |
| 2003 | On modeling system-centric information for role engineeringabstractIn this paper we present an approach to modeling system-centric information in order to facilitate role engineering (RE). In particular, we first discuss the general character-istics of the information required in RE. Afterwards, we discuss two informational flow types among authorities in-volved in RE process, forward information flow (FIF) and backward information flow (BIF), together with the intro-duction of an information model which is greatly suitable for use in the backward information flow. System-centric information is incorporated in the information model and UML extension mechanisms are exploited for modeling the information. Not only can the information model provide those different authorities with a method for both analy-sis of resources and communication of knowledge in the RE process, but it can also help lay a foundation for successful implementations of RBAC. Dongwan Shin, Gail-Joon Ahn, Sangrae Cho, Seunghun Jin |
SACMAT | 2 |
| 2003 | Dynamic and risk-aware network access managementabstractTraditional network security technologies such as firewalls and intrusion detection systems usually work according to a static ruleset only. We believe that a better approach to network security can be achieved if we use quantified levels of risk as an input. In this paper, we describe a dynamic access control architecture which uses risk to determine whether to allow or deny access by a source connection into the network. A simulation of our architecture shows favorable and promising results. Lawrence Teo, Gail-Joon Ahn, Yuliang Zheng 0001 |
SACMAT | 2 |
| 2003 | Constrained Role-based Delegation
Longhua Zhang, Gail-Joon Ahn |
SEC | 2 |
| 2003 | Authorization management for role-based collaborationabstractInformation sharing among collaborating organizations usually occurs in broad, highly dynamic network-based environments, and formally accessing the resources in a secure manner poses a difficult challenge. The mechanisms must be provided to protect the resources from adversaries. The proposed delegation framework addresses the issue of how to advocate selective information sharing among collaborating organizations. We introduce a systematic approach to manage delegated privileges with the specification of delegation and revocation policies using a set of rules. We demonstrate the feasibility of our approach by providing a proof-of-concept implementation. We also briefly discuss several issues from our experiment including future directions. Gail-Joon Ahn, Longhua Zhang, Dongwan Shin, Bill Chu |
SMC | 1 |
| 2003 | Locale-based access control: placing collaborative authorization decisions in contextabstractCollaboration systems require an appropriate authorization model to specify and maintain policies that not only facilitate group activities but also enforce restrictions and accountability. Existing models fail to incorporate adequately into authorization decisions the rich notion of context that is inherent to any collaborative setting. In this paper we present the locale-based access control (locale-BAC) model for collaborative systems, a model whose design is based upon the application of Fitzpatrick's locale framework for collaboration to the problem of access control. This model encapsulates the notion of context using locales, allowing for a natural representation of collaborative authorization decisions. William J. Tolone, Robin A. Gandhi, Gail-Joon Ahn |
SMC | 3 |
| 2003 | A rule-based framework for role-based delegation and revocationabstractDelegation is the process whereby an active entity in a distributed environment authorizes another entity to access resources. In today's distributed systems, a user often needs to act on another user's behalf with some subset of his/her rights. Most systems have attempted to resolve such delegation requirements with ad-hoc mechanisms by compromising existing disorganized policies or simply attaching additional components to their applications. Still, there is a strong need in the large, distributed systems for a mechanism that provides effective privilege delegation and revocation management. This paper describes a rule-based framework for role-based delegation and revocation. The basic idea behind a role-based delegation is that users themselves may delegate role authorities to others to carry out some functions authorized to the former. We present a role-based delegation model called RDM2000 (role-based delegation model 2000) supporting hierarchical roles and multistep delegation. Different approaches for delegation and revocation are explored. A rule-based language for specifying and enforcing policies on RDM2000 is proposed. We describe a proof-of-concept prototype implementation of RDM2000 to demonstrate the feasibility of the proposed framework and provide secure protocols for managing delegations. The prototype is a web-based application for law enforcement agencies allowing reliable delegation and revocation. The future directions are also discussed. Longhua Zhang, Gail-Joon Ahn, Bei-tseng Chu |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2002 | An Application of Directory Service Markup Language (DSML) for Role-Based Access Control (RBAC)abstractThe directory service markup language (DSML) prescribes how to manipulate directory services information in XML, and thus it facilitates sharing of directory information as XML fragments among XML-based applications. We describe how to leverage DSML for role-based access control on XML-based Web applications which often need collaboration within or beyond a single enterprise boundary. Compared with previous works in this area, we show that our approach can solve the problems of a previous LDAP-oriented solution. We discuss the security architecture based upon a server-pull model and its components. We also demonstrate the feasibility of our approach through a proof-of-concept implementation. Finally, several issues from our experience are discussed as well. Dongwan Shin, Gail-Joon Ahn, Joon S. Park |
COMPSAC | 2 |
| 2002 | Using X.509 Attribute Certificates for Role-Based EAM
Dongwan Shin, Gail-Joon Ahn, Sangrae Cho |
DBSec | 2 |
| 2002 | A role-based delegation framework for healthcare information systemsabstractAs organizations implement information strategies that call for sharing access to resources in the networked environment, mechanisms must be provided to protect the resources from adversaries. The proposed delegation framework addresses the issue of how to advocate selective information sharing in role-based systems while minimizing the risks of unauthorized access. We introduce a systematic approach to specify delegation and revocation policies using a set of rules. We demonstrate the feasibility of our framework through policy specification, enforcement, and a proof-of-concept implementation on specific domains, e.g. the healthcare environment. We believe that our work can be applied to organizations that rely heavily on collaborative tasks. Longhua Zhang, Gail-Joon Ahn, Bei-tseng Chu |
SACMAT | 2 |
| 2002 | Reconstructing a formal security model
Gail-Joon Ahn, Seng-Phil Hong, Michael Eonsuk Shin |
Inf. Softw. Technol. | 1 |
| 2001 | Role-based Access Control on the Web Using LDAP
Joon S. Park, Gail-Joon Ahn, Ravi S. Sandhu |
DBSec | 2 |
| 2001 | A rule-based framework for role based delegationabstractIn current role-based systems, security officers handle assignments of users to roles. However, fully depending on this functionality may increase management efforts in a distributed environment because of the continuous involvement from security officers. The emerging technology of role-based delegation provides a means for implementing RBAC in a distributed environment with empowerment of individual users. The basic idea behind a role-based delegation is that users themselves may delegate role authorities to other users to carry out some functions on behalf of the former. This paper presents a role-based delegation model called RDM2000 (role-based delegation model 2000), which is an extension of RBDM0 by supporting hierarchical roles and multi-step delegation. The paper explores different approaches for delegation and revocation. Also, a rule-based language for specifying and enforcing the policies based on RDM2000 is introduced. Longhua Zhang, Gail-Joon Ahn, Bei-tseng Chu |
SACMAT | 2 |
| 2001 | CONUGA: Constrained User-Group Assignment
Gail-Joon Ahn, Kwangjo Kim |
J. Netw. Comput. Appl. | 1 |
| 2001 | Decentralized user group assignment in Windows NT
Gail-Joon Ahn, Ravi S. Sandhu |
J. Syst. Softw. | 1 |
| 2001 | Role-based access control on the webabstractCurrent approaches to access control on the Web servers do not scale to enterprise-wide systems because they are mostly based on individual user identities. Hence we were motivated by the need to manage and enforce the strong and efficient RBAC access control technology in large-scale Web environments. To satisfy this requirement, we identify two different architectures for RBAC on the Web, called user-pull and server-pull . To demonstrate feasibility, we implement each architecture by integrating and extending well-known technologies such as cookies, X.509, SSL, and LDAP, providing compatibility with current web technologies. We describe the technologies we use to implement RBAC on the Web in different architectures. Based on our experience, we also compare the tradeoffs of the different approaches. Joon S. Park, Ravi S. Sandhu, Gail-Joon Ahn |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2000 | Role-based access control in DCOM
Gail-Joon Ahn |
J. Syst. Archit. | 1 |
| 2000 | Role-based authorization constraints specificationabstractConstraints are an important aspect of role-based access control (RBAC) and are often regarded as one of the principal motivations behind RBAC. Although the importance of contraints in RBAC has been recogni zed for a long time, they have not recieved much attention. In this article, we introduce an intuitive formal language for specifying role-based authorization constraints named RCL 2000 including its basic elements, syntax, and semantics. We give soundness and completeness proofs for RCL 2000 relative to a restricted form of first-order predicate logic. Also, we show how previously identified role-based authorization constraints such as separtation of duty (SOD) can be expressed in our language. Moreover, we show there are other significant SOD properties that have not been previously identified in the literature. Our work shows that there are many alternate formulations of even the simplest SOD properties, with varying degree of flexibility and assurance. Our language provides us a rigorous foundation for systematic study of role-based authorization constraints. Gail-Joon Ahn, Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 1 |
| 1999 | Towards role-based administration in network information services
Gail-Joon Ahn, Ravi S. Sandhu |
J. Netw. Comput. Appl. | 1 |