Csilla Farkas

dblp:f/CsillaFarkas · DBLP profile ↗
← Back
31ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0002-6848-1790ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 1 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 Context-aware and adaptive multi-factor authentication model
abstract
In this paper we present a formal and extensible framework for a context-aware, and adaptive multi-factor authentication (CAA-MFA). CAA-MFA supports the selection of k-number of random factors based on the risk of the user’s login context. Each authentication factor in association with its source device has an associated trust score. We use these trust scores to evaluate individual factor’s feasibility for user authentication, and the collective feasibility of the k-number of factors. We use context-based reasoning (Protege) to derive the risk of the user login and therefore the minimum number of required factors and their trust scores. Our system will randomly select a set of factors that satisfies the login requirements. Next, we propose a continuous assessment method of the users login sessions. This serves as a second layer of defense against unauthorized user logins. We classify user logins into suspicious (unauthorized) and non-suspicious (authorized) categories. For this, we use a combination of Risk Level assessment (RLA) computation and known attack patterns. Our empirical results indicate that this integrated RLA guided approach improves resistance to spoofing and phishing attacks without compromising usability. We tested our systems performance using F1-score and CAA-MFA achieves a score of 0.985.
Jonathan Sharp, Baker Womack, Csilla Farkas, Dipankar Dasgupta, Arunava Roy
J. Inf. Secur. Appl.3
2022 Ensuring Consistent Transactions in a Web Service Environment With Prediction-Based Performance Metrics
abstract
In this article, we propose the transaction scheduling for web service database transactions. Our solution ensures consistency while preserving efficiency. We propose a prediction-based metric that promotes transactions with reliable reputations based on the transactions performance metrics. Performance metrics are based on the transactions likelihood to commit and their execution time. We propose a customized lock management solution to guarantee execution consistency in concurrent web service environments. We formally prove that our solution guarantees consistent execution history of concurrent web transactions and increases concurrency and performance over traditional locking methods. We developed a simulation using a multi-threaded approach. We generated sample workloads of simulated concurrent transactions over seven tests. Our results show that the solution works comparatively with traditional locking and no-locking solutions with the added benefit of ensured consistency in some cases and deadlock avoidance in others.
John Ravan, Shankar M. Banik, Csilla Farkas
IEEE Trans. Serv. Comput.3
2021 Database Recovery from Malicious Transactions: A Use of Provenance Information
Theppatorn Rhujittawiwat, John Ravan, Ahmed Saaudi, Shankar M. Banik, Csilla Farkas
DATA5
2021 Review helpfulness evaluation and recommendation based on an attention model of customer expectation
Xianshan Qu, Xiaopeng Li 0001, Csilla Farkas, John R. Rose
Inf. Retr. J.3
2021 Resilient User-Side Android Application Repackaging and Tampering Detection Using Cryptographically Obfuscated Logic Bombs
abstract
Application repackaging is a severe threat to Android users and the market. Not only does it infringe on intellectual property, but it is also one of the most common ways of propagating mobile malware. Existing countermeasures mostly detect repackaging based on app similarity measurement, which tends to be imprecise when obfuscations are applied to repackaged apps. Moreover, they rely on a central party, typically the hosting app store, to perform the detection, but many app stores fail to commit proper effort to piracy detection. We consider building the application repackaging detection capability into apps, such that user devices are made use to detect repackaging in a decentralized fashion.The main challenge is how to protect the detection code from being manipulated by attacks. We propose a creative use oflogic bombs, which are otherwise regularly used in malware. Thetrigger conditionsof bombs are constructed to exploit the differences between the attacker and users, such that a bomb that lies dormant on the attacker side will be activated on the user side. The detection code, which is part of the bombpayload, is executed only if the bomb is activated. We introducecryptographically obfuscated logic bombto enhance the bomb: (1) the detection code iswoveninto the neighboring original app code, (2) the mixed code gets encrypted using a key, and (3) the key is deleted from the app and can only be derived when the bomb is activated. Thus, attacks that try to modify or delete the detection code will corrupt the app itself, and searching the key in the application will be in vain. Moreover, we propose abomb sprayingtechnique that allows many bombs to be injected into an app, multiplying the needed adversary effort for bypassing the detection. In addition to repackaging detection, we present application tampering detection to fight attacks that insert malicious code into repackaged apps. We have implemented a prototype, namedBombDroid, that builds repackaging and tampering detection into apps through bytecode instrumentation. The evaluation and the security analysis show that the technique is effective, efficient, and resilient to various bomb analysis techniques including fuzzing, symbolic execution, multi-path exploration, and program slicing. Ethical issues due to the use of logic bombs are also discussed.
Qiang Zeng 0001, Lannan Luo, Zhiyun Qian, Xiaojiang Du, Zhoujun Li 0001, Chin-Tser Huang, Csilla Farkas
IEEE Trans. Dependable Secur. Comput.7
2020 An Attention Model of Customer Expectation to Improve Review Helpfulness Prediction
Xianshan Qu, Xiaopeng Li 0001, Csilla Farkas, John R. Rose
ECIR (1)3
2019 Detecting Adversarial Attacks in the Context of Bayesian Networks
Emad Alsuwat, Hatim Alsuwat, John R. Rose, Marco Valtorta, Csilla Farkas
DBSec5
2019 Monotonic and Non-monotonic Context Delegation
abstract
Delegating access privileges is a common practice of access control mechanisms. Delegation is usually used for distributing responsibilities of task management among entities. Delegation comes in two forms, GRANT and TRANSFER. In GRANT delegation, a successful delegation operation allows delegated privileges to be available to both the delegator and delegatee. In TRANSFER delegation, delegated privileges are no longer available to the delegator. Although several delegation approaches have been proposed, current models do not consider the issue of context delegation in context-based access control policies. We present two ontology-based context delegation approaches. Monotonic context delegation, which adopts GRANT version of delegation, and non-monotonic for TRANSFER version of delegation. The approach presented here provides a dynamic and adaptive privilege delegation for access control policies. We employ Description logic (DL) and Logic Programming (LP) technologies for modeling contexts, delegation and CBAC privileges. We have designed three lightweight Web Ontology Language (OWL) ontologies, CTX, CBAC, and DEL, for context, Context-Based Access Control (CBAC), and delegation, respectively. We show that semantic-based techniques can be used to support adaptive and dynamic context delegation for CBAC policies. We provide the formal framework of the approaches and show that they are sound, consistent and preserve least-privilege principle.
Mouiad Al-Wahah, Csilla Farkas
ICISSP2
2019 Probabilistic Graphical Model on Detecting Insiders: Modeling with SGD-HMM
Ahmed Saaudi, Csilla Farkas
ICISSP3
2018 Protecting Patients' Data: An Efficient Method for Health Data Privacy
abstract
In this work, we investigate privacy violations that occur when non-confidential medical data is combined with domain ontologies to infer confidential data. We propose enhancements to our existing framework to detect such privacy violations, and to eliminate undesired inferences in an efficient manner. Our enhanced inference channel removal methods are based on disruption covers and heuristic-guided modification of data items that contribute to an inference. We show that our method is sound and complete. Soundness means that we modify only data items that lead to undesired inferences. Completeness means that we remove all inferences leading to undesired data disclosures. Finally, we show that our solution is practical with respect to computational cost. An important aspect of our approach is that it sets the foundation for creating patient-specific privacy policies; an emerging need in the healthcare domain.
Mark Daniels, John R. Rose, Csilla Farkas
ARES3
2015 Risk Aware Query Replacement Approach for Secure Databases Performance Management
abstract
Large amount of data and increased demand to extract, analyze and derive knowledge from data are impairing nowadays performance of enterprise mission-critical systems such as databases. For databases, the challenging problem is to manage complex and sometimes non-optimized queries executed on enormous data sets stored across several tables. This generally results in increased query response time and loss of employees productivity. In this paper, we investigate the problem of enterprise computing resources availability. Our goal is to minimize performance degradation arising from resource intensive queries. We propose a risk aware approach that decouples the process of analyzing resource requirements of sql queries from their execution. We leverage XACML to control users' requests and to monitor database loads. This allows us to adjust available resources in a database system to computing resource needs of queries. A query can therefore run in a database if it does not severely impact the performance of the database. Otherwise, we propose to the requester a replacement query denoted what-if-query. Such query proposes results that are similar to the results of the requester's query, is secure and provides acceptable answers when it executes without compromising the performance of the database.
Ousmane Amadou Dia, Csilla Farkas
IEEE Trans. Dependable Secur. Comput.2
2013 Coarse Grained Web Service Availability, Consistency, and Durability
abstract
In this paper we investigate the problem of providing consistency, availability and durability for Web Service-transactions. We consider each transaction as a black box, with only the corresponding metadata, expressed as UML specifications, as transaction semantics. We refer to these WS transactions as coarse-grained WS-transactions. We propose an approach that guarantees the availability of the popular lazy replica update propagation method while increasing the durability and consistency. In our previous work, we proposed a replica update propagation method, called Buddy System, which required that updates are preserved synchronously in two replicas. In this paper we extend the Buddy System to handle course grained WS transactions, using UML stereotypes that allow scheduling semantics to be embedded into the design model. This design model is then exported and consumed by a service dispatcher to provide: 1.) High availability by distributing service requests across all available clusters. 2.) Consistency by performing the complete transaction on a single set of clusters. 3.) Durability by updating two clusters synchronously.
Aspen Olmsted, Csilla Farkas
ICWS2
2013 Business Driven User Role Assignment: Nimble Adaptation of RBAC to Organizational Changes
abstract
The authors propose a business-oriented approach to support accurate and dynamic user-role assignments for the Role Based Access Control (RBAC) model. Their model, called Business-Driven Role Based Access Control (BD-RBAC), is composed of three layers. The first layer extends the RBAC model with the concepts of business roles, system roles, credentials, and users’ capabilities. The second layer dynamically assigns users to business and system roles, and filters outdated (abnormal) user-role assignments. The third layer supports exception handling and partial authorization. The novel aspect of the work is the adaptation of RBAC-based access control systems to changes in organizational needs, while reducing the burden of security administration. To this end, the authors have developed (1) a series of algorithms to compute internal and external user-role assignments based on organizational policies, users’ requests and capabilities, (2) and shown that their outputs are permissible, i.e., a legitimate user is authorized to activate the role, complete, i.e., a legitimate user can activate the roles necessary to perform all the requested tasks, and minimal, i.e., a legitimate user does not receive any non-authorized or not-needed privileges.
Ousmane Amadou Dia, Csilla Farkas
Int. J. Inf. Secur. Priv.2
2011 Accurate Accident Reconstruction in VANET
Yuliya Kopylova, Csilla Farkas
DBSec2
2010 The inference problem: Maintaining maximal availability in the presence of database updates
Tyrone S. Toland, Csilla Farkas, Caroline M. Eastman
Comput. Secur.2
2009 P2F: A User-Centric Privacy Protection Framework
abstract
In this paper, we present an end-user tool called the privacy protection framework (P2F) which aims to support users in protecting their privacy when obtaining Web-based services. P2F acts as a recommendation tool that analyzes the user's transaction history and privacy preferences in addition to real-world privacy guidelines to prevent undesirable disclosure of personal data. The framework is based on a novel qualitative privacy compromise risk assessment approach designed to support decision-making in settings where server-side support for user-centric privacy protection frameworks is minimal or unkown. Our risk assessment model uses service provider properties, likelihood of collusion between providers, the sensitivity of the personal data to be released, and undesirable transaction linkability to determine the privacy compromise potential of a transaction.
Maryam Jafari-lafti, Chin-Tser Huang, Csilla Farkas
ARES3
2007 PTC-VANET Interactions to Prevent Highway Rail Intersection Crossing Accidents
abstract
Vehicular ad-hoc networks (VANETS) provide distributed real time communication of traffic hazards and road conditions among vehicles in a radio line of sight. We propose using VANETS to securely communicate with positive train control (PTC) systems in order to reduce highway rail intersection (HRI) incidents. This paper illustrates the similarities and differences between the two systems, discusses previous research into the work already done to integrate the two systems, and outlines the additional work necessary to successfully integrate the two systems.
Mark Hartong, Rajni Goel, Csilla Farkas, Duminda Wijesekera
VTC Spring3
2006 An Algebra for Composing Ontologies
Saket Kaushik, Csilla Farkas, Duminda Wijesekera, Paul Ammann
FOIS2
2006 Secure resource description framework: an access control model
abstract
In this paper we propose an access control model for the Resource Description Framework (RDF). We argue that existing access control models, like the ones developed for securing eXtensible Markup Language (XML) documents, do not provide sufficient protection for RDF data. Our security model incorporates RDF and RDF Schema (RDFS) entailments. RDF protection objects are represented as RDF-patterns that are mapped to RDF and RDFS statements to determine their security requirements. We develop methods to assign security classification to entailed statements and to detect unauthorized inferences. We propose a two-level conflict resolution strategy. Simple conflict resolution addresses the problem when more than one pattern can be mapped to the same RDF statement, resulting in conflicting classification. Inference conflict resolution addresses inconsistencies that occur due to entailment.
Csilla Farkas
SACMAT2
2006 A framework for anonymous but accountable self-organizing communities
Gábor Ziegler, Csilla Farkas, András Lörincz
Inf. Softw. Technol.2
2006 Unauthorized inferences in semistructured databases
Csilla Farkas, Alexander Brodsky 0001, Sushil Jajodia
Inf. Sci.1
2005 Multilevel Secure Teleconferencing over Public Switched Telephone Network
Inja Youn, Csilla Farkas, Bhavani Thuraisingham
DBSec2
2005 PAID: A Probabilistic Agent-Based Intrusion Detection system
Vaibhav Gowadia, Csilla Farkas, Marco Valtorta
Comput. Secur.2
2004 THEMIS: Threat Evaluation Metamodel for Information Systems
Csilla Farkas, Thomas C. Wingfield, James Bret Michael, Duminda Wijesekera
ISI1
2004 SECRETS: A Secure Real-Time Multimedia Surveillance System
Naren Kodali, Csilla Farkas, Duminda Wijesekera
ISI2
2004 Ontology Guided XML Security Engine
Andrei Stoica, Csilla Farkas
J. Intell. Inf. Syst.2
2003 Correlated Data Inference
Csilla Farkas, Andrei Stoica
DBSec1
2002 Secure XML Views
Andrei Stoica, Csilla Farkas
DBSec2
2001 The Inference Problem and Updates in Relational Databases
Csilla Farkas, Tyrone S. Toland, Caroline M. Eastman
DBSec1
2000 Constraints, Inference Channels and Secure Databases
Alexander Brodsky 0001, Csilla Farkas, Duminda Wijesekera, Xiaoyang Sean Wang
CP2
2000 Secure Databases: Constraints, Inference Channels, and Monitoring Disclosures
abstract
Investigates the problem of inference channels that occur when database constraints are combined with non-sensitive data to obtain sensitive information. We present an integrated security mechanism, called the Disclosure Monitor, which guarantees data confidentiality by extending the standard mandatory access control mechanism with a Disclosure Inference Engine. This generates all the information that can be disclosed to a user based on the user's past and present queries and the database and metadata constraints. The Disclosure Inference Engine operates in two modes: a data-dependent mode, when disclosure is established based on the actual data items, and a data-independent mode, when only queries are utilized to generate the disclosed information. The disclosure inference algorithms for both modes are characterized by the properties of soundness (i.e. everything that is generated by the algorithm is disclosed) and completeness (i.e. everything that can be disclosed is produced by the algorithm). The technical core of this paper concentrates on the development of sound and complete algorithms for both data-dependent and data-independent disclosures.
Alexander Brodsky 0001, Csilla Farkas, Sushil Jajodia
IEEE Trans. Knowl. Data Eng.2