EDBT 2026 Demo / reviewers in the wild / expert
Eduardo B. Fernández
dblp:f/EBFernandez · also Eduardo B. Fernández-Buglioni
· DBLP profile ↗
75ranked-venue papers
25as first author
2since 2021 · last 2022
0000-0002-5109-4591ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 12 first-author · 2 since 2021Software engineering, systems software and programming languages · 20 · 5 first-authorDatabases, data management, data science and information retrieval · 14 · 5 first-authorSystems, architecture and hardware · 8 · 3 first-authorArtificial intelligence and machine learning · 4Computer networks · 2Theory of computation · 2Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Abstract security patterns and the design of secure systemsabstractAbstract During the initial stages of software development, the primary goal is to define precise and detailed requirements without concern for software realizations. Security constraints should be introduced then and must be based on the semantic aspects of applications, not on their software architectures, as it is the case in most secure development methodologies. In these stages, we need to identify threats as attacker goals and indicate what conceptual security defenses are needed to thwart these goals, without consideration of implementation details. We can consider the effects of threats on the application assets and try to find ways to stop them. These threats should be controlled with abstract security mechanisms that can be realized by abstract security patterns (ASPs), that include only the core functions of these mechanisms, which must be present in every implementation of them. An abstract security pattern describes a conceptual security mechanism that includes functions able to stop or mitigate a threat or comply with a regulation or institutional policy. We describe here the properties of ASPs and present a detailed example. We relate ASPs to each other and to Security Solution Frames, which describe families of related patterns. We show how to include ASPs to secure an application, as well as how to derive concrete patterns from them. Finally, we discuss their practical value, including their use in “security by design” and IoT systems design. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki, Joseph W. Yoder |
Cybersecur. | 1 |
| 2021 | Security in microservice-based systems: A Multivocal literature review
Anelis Pereira Vale, Eduardo B. Fernández, Raúl Monge, Hernán Astudillo, Gastón Marquez |
Comput. Secur. | 2 |
| 2020 | Refining the evaluation of the degree of security of a system built using security patternsabstractEvaluating the degree of security of a specific software system is a difficult problem and many metrics have been proposed. However, if the system has been built with a methodology that uses patterns as artifacts, a systematic and rather simple evaluation is possible and a metric has been proposed for this evaluation: perform threat enumeration, check if the patterns in the system can stop the identified threats, and calculate the coverage of these threats by the patterns. We refine here that approach by considering the additional effect of the policies (requirements) defined for the system and by using weights for threats and policies. Olga Villagrán-Velasco, Eduardo B. Fernández, Jorge Luis Ortega-Arjona |
ARES | 2 |
| 2020 | Landscape of Architecture and Design Patterns for IoT SystemsabstractDue to the widespread proliferation of today's Internet of Things (IoT), a system designer needs the IoT system and software design patterns to assist in designing scalable and replicable solutions. Patterns are encapsulations of reusable common problems and solutions under specific contexts. Many IoT patterns have been published, such as IoT design patterns and IoT architecture patterns to document the successes (and failures) in IoT systems and software development. However, because these patterns are not well classified, their adoption does not live up to their potential. To understand the reasons, we conducted a systematic literature review. From the 32 identified papers, 143 IoT architecture and design patterns were extracted. We analyzed these patterns according to several characteristics and outlined directions for improvements when publishing and adopting IoT patterns. Of the extracted patterns, 57% are non-IoT patterns, suggesting that IoT systems and software are often designed via conventional architecture and design patterns that are not specific to IoT design. Although most IoT design patterns are applicable to any domain, IoT architecture patterns tend to be domain specific, implying that the unique nature of IoT adoption in specific domains appears at the architecture level. As more domains adopt IoT, the number of domain-specific IoT design patterns should increase. In terms of quality attributes, many IoT patterns address compatibility, security, and maintainability. Hironori Washizaki, Shinpei Ogata, Atsuo Hazeyama, Takao Okubo, Eduardo B. Fernández, Nobukazu Yoshioka |
IEEE Internet Things J. | 5 |
| 2020 | Application of security reference architecture to Big Data ecosystems in an industrial scenarioabstractSummary Big Data environments are typically very complex ecosystems; this means that implementing them is complicated. One possible technique with which to address this complexity is the use of abstraction. Reference architecture (RA) can be useful for an improved understanding of the main components of Big Data. Herein, we propose a security RA that includes the management of security concerns and provides the main elements of a Big Data ecosystem. Application of this architecture to real‐world scenarios facilitates its refinement and improves its usefulness. In this article, we present a case study of a real‐world Big Data ecosystem implemented in a banking environment. This ecosystem was developed by everis, an NTT company with which we collaborated for this study. To conduct this validation case study, a map was established between the elements of the Big Data ecosystem implemented and our proposal. Consequently, a series of valuable lessons that can improve both our architecture and the security of the Big Data environment were obtained. These include recommendations for a set of best practices such as the use of security patterns. Julio Moreno, Manuel A. Serrano, Eduardo B. Fernández, Eduardo Fernández-Medina |
Softw. Pract. Exp. | 4 |
| 2019 | A Misuse Pattern for Compromising VMs via Virtual Machine Escape in NFVabstractCloud computing has provided many services to potential consumers; one of these services being the provision of network functions using virtualization. Network Function Virtualization (NFV) is an emerging network technology that decouples the software implementation of network functions from the underlying hardware providing flexible and energy-efficient network services. However, it also comes with vulnerabilities that attackers can exploit to disrupt the network service. In this paper, we use misuse patterns to study the Virtual Machine (VM) Escape attack. The possible misuses resulting from the VM Escape are compromising victims' VMs, stealing resources from co-resident VMs, and accessing host OS files. Misuse patterns describe how an attack is performed from the point view of the attacker. In the future, we aim to build a partial catalog of misuse patterns for the NFV virtual machine environment (VME). This catalog would be useful to build a Security Reference Architecture for NFV. Abdulrahman Khalid Alnaim, Ahmed Alwakeel, Eduardo B. Fernández |
ARES | 3 |
| 2019 | A Pattern for a Virtual Network Function (VNF)abstractNetwork Function Virtualization (NFV), produces the functions of the network through virtualization of hardware resources. Different networking components such as firewalls, load balancers, and IDS are provided as a service and rely purely on the cloud, which makes expanding and upgrading the network an easy and fast process. Network Functions (NF) normally require a tightly coupled infrastructure making the process of enhancing and expanding the network difficult. In NFV, the services are provided through different Virtual Network Function (VNF), which are combined into a Network Graph (NG) and delivered to the user as a package. We present here a pattern to describe VNFs. A pattern is an encapsulated solution to a problem in a given context; this pattern should be of value to system designers and users of NFV systems. Ahmed Alwakeel, Abdulrahman Khalid Alnaim, Eduardo B. Fernández |
ARES | 3 |
| 2019 | Security Mechanisms Used in Microservices-Based Systems: A Systematic MappingabstractMicroservices is an architectural style that conceives systems as a modular, costumer, independent and scalable suite of services; it offers several advantages but its growing popularity has given rise to security challenges. Building secure systems is greatly helped by deploying existing security mechanisms, but current literature does not guide developers about which mechanisms are actually used by developers of microservices-based systems. This article describes the design and results of a systematic mapping study to identify the security mechanisms used in microservices-based systems described in the literature. The study yielded 321 articles, of which 26 are primary studies. Key findings are that (i) the studies mention 18 security mechanisms; (ii) the most mentioned security mechanisms are authentication, authorization and credentials; and (iii) almost 2/3 of security mechanisms focus on stopping or mitigating attacks, but none on recovering from them. Additionally, it emerges that experiments and case studies are the most used empirical strategies in microservices security research. The clear identification of most-used security solutions will facilitate the reuse of existing architectural knowledge to address security problems in microservices-based systems. Anelis Pereira Vale, Gastón Marquez, Hernán Astudillo, Eduardo B. Fernández |
CLEI | 4 |
| 2018 | Evaluating the degree of security of a system built using security patternsabstractA variety of methodologies to build secure systems have been proposed. However, most of them do not say much about how to evaluate the degree of security of their products. In fact, we have no generally-accepted ways to measure if the product of some methodology has reached some degree of security. However, if the system has been built with a methodology that uses patterns as artifacts, we believe that a simple evaluation is possible. We propose a metric for the security of systems that have been built using security patterns: We perform threat enumeration, we check if the patterns in the product have stopped the threats, and calculate the coverage of these threats by the patterns. We indicate how to take advantage of the Twin Peaks approach to arrive to a refined measure of security. In early work, we have proposed a secure systems development methodology that uses security patterns and we use it as example. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki |
ARES | 1 |
| 2018 | A reference architecture for the container ecosystemabstractContainers have gained immense popularity as a portable and lightweight virtualization solution. They facilitate application development, deployment and distribution across computing environments. Their success is also attributed to the support they offer for DevOps teams and for applications developed using a microservices architecture style. Containers are not the only components in the environment but work closely with other components for managing and supporting them, forming an ecosystem. Architectural modeling can be used as a powerful tool to represent ecosystems which helps understand, build and secure such complex systems. We describe in this paper several models we have created for container ecosystem components. These models are abstract, and they help generalize the systems to handle complexity and heterogeneity; they provide a common vocabulary and build holistic and unified views of the systems. The use of UML for modeling improves precision. This can lead to better implementations with respect to reliability, security and interoperability compared to ad hoc methods. A reference architecture will not just facilitate the work of developers and security engineers but also of anyone who aims to ensure compliance, privacy, safety, reliability and/or governance for container ecosystems and we show how to build one. We also describe relationships between container, cloud and IoT ecosystems. This paper is part of our work on developing a security reference architecture for container ecosystems. Madiha H. Syed, Eduardo B. Fernández |
ARES | 2 |
| 2018 | Towards a Security Reference Architecture for Big Data
Julio Moreno, Manuel A. Serrano, Eduardo Fernández-Medina, Eduardo B. Fernández |
DOLAP | 4 |
| 2018 | Cloud Security and Privacy Metamodel - Metamodel for Security and Privacy Knowledge in Cloud Services
Hironori Washizaki, Takehisa Kato, Haruhiko Kaiya, Shinpei Ogata, Eduardo B. Fernández, Hideyuki Kanuka, Masayuki Yoshino, Dan Yamamoto, Takao Okubo, Nobukazu Yoshioka, Atsuo Hazeyama |
MODELSWARD | 6 |
| 2018 | Assessing and improving the quality of security methodologies for distributed systemsabstractAbstract Security methodologies represent systematic approaches for introducing security attributes into a system throughout the development lifecycle. While isolated attempts have been made to demonstrate the value of particular security methodologies, the “quality” of security methodologies, as such, has never been given due consideration; indeed, it has never been studied as a self‐standing topic. The literature therefore entirely lacks supportive artifacts that can provide a basis for assessing, and hence for improving, a security methodology's quality. In this paper, we fill the aforementioned gap by proposing a comprehensive quality framework and accompanying process, within the context of an existing approach to engineering security methodologies, which can be used for both (bottom‐up) quality assessment and (top‐down) quality improvement. The main framework elements can be extended and customized to allow an essentially arbitrary range of methodology features to be considered, thus forming a basis for flexible, fine‐grained quality control. We demonstrate the bottom‐up application of the latter framework and process on three real‐life security methodologies for distributed systems, taken as case studies. Based on the assessment results, we subsequently show in detail (for one) and briefly discuss (for the remaining set) how the case study methodologies can be re‐engineered to improve their quality. Anton V. Uzunov, Eduardo B. Fernández, Katrina Falkner |
J. Softw. Evol. Process. | 2 |
| 2016 | Building Compliance and Security Reference Architectures (CSRA) for Cloud SystemsabstractAppealing features of cloud services motivate consumers to migrate their core businesses to them. However, there are challenges about security, privacy, and compliance. Building compliant systems is difficult because of the complex nature of regulations and cloud systems. In addition, the lack of reference architectures (RAs) makes compliance even harder. RAs should be complete, precise, abstract, vendor neutral, platform independent, with no implementation details, however, their levels of detail and abstraction are still debatable and there is no accepted definition about what an RA should contain. Existing approaches used to build RAs lack structured templates and systematic procedures. In addition, most approaches do not take full advantage of patterns and best practices that promote architectural qualities such as modularity, reusability, flexibility and usability. We propose here a five-step approach to build an RA that can improve the quality of the concrete architectures derived from it and from which we can derive more specialized RAs. These RAs take advantage of patterns and best practices that promote software quality. Dereje Yimam, Eduardo B. Fernández |
IC2E | 2 |
| 2016 | A Metamodel for Security and Privacy Knowledge in Cloud ServicesabstractWe propose a metamodel for handling security and privacy in cloud service development and operation. The metamodel is expected to be utilized for building a knowledge base to accumulate, classify and reuse existing cloud security and privacy patterns and practices in a consistent and uniform way. Moreover the metamodel and knowledge base are expected to be utilized for designing and maintaining architectures for cloud service systems incorporating security and privacy. Hironori Washizaki, Sota Fukumoto, Misato Yamamoto, Masatoshi Yoshizawa, Yoshiaki Fukazawa, Takehisa Kato, Shinpei Ogata, Haruhiko Kaiya, Eduardo B. Fernández, Hideyuki Kanuka, Yuki Kondo, Nobukazu Yoshioka, Takao Okubo, Atsuo Hazeyama |
SERVICES | 9 |
| 2016 | Building a security reference architecture for cloud systems
Eduardo B. Fernández, Raúl Monge, Keiko Hashizume |
Requir. Eng. | 1 |
| 2015 | Revisiting Architectural Tactics for Security
Eduardo B. Fernández, Hernán Astudillo, Gilberto Pedraza-Garcia |
ECSA | 1 |
| 2015 | Towards Compliant Reference Architectures by Finding Analogies and Overlaps in Compliance RegulationsabstractBusiness software is subject to a variety of regulations depending on the type of application. For example, software handling of medical records must follow HIPAA; software for financial applications must comply with Sarbanes Oxley, and so on. A close examination of the policies included in those regulations shows that they have analog and common aspects. Analog parts of regulations can be expressed as Semantic Analysis Patterns (SAPs), which can lead to building similar parts in other regulations. Overlapping parts usually correspond to security patterns and can be used to add security to other regulations. If we collect SAPs and security patterns in a catalog we can build reference architectures (RAs) for existing and new regulations. The resultant Compliant RAs (CRAs) can be used as guidelines for building compliant applications. Eduardo B. Fernández, Dereje Yimam |
SECRYPT | 1 |
| 2015 | Security solution frames and security patterns for authorization in distributed, collaborative systems
Anton V. Uzunov, Eduardo B. Fernández, Katrina Falkner |
Comput. Secur. | 2 |
| 2015 | A comprehensive pattern-oriented approach to engineering security methodologies
Anton V. Uzunov, Katrina Falkner, Eduardo B. Fernández |
Inf. Softw. Technol. | 3 |
| 2014 | Enterprise security pattern: a new type of security patternabstractABSTRACT In recent years, most organizations have suffered attacks against their information systems. For this reason, organizations should seek support from enterprise security architectures (ESAs) in order to secure their information assets. Security patterns can help when building complex ESAs, but they have some limitations that reduce their usability. In this paper, we define the metapattern of a new type of security pattern called Enterprise Security Pattern. This new metapattern provides a model‐driven environment and combines all elements that must be considered when designing and building ESAs. We present here a precise meta‐model and four diagrams to describe the metapattern of the enterprise security patterns. When avoiding a security problem, organizations could use enterprise security patterns to provide their designers with an optimal and proven security guideline and so standardize the design and building of the ESA for that problem. Enterprise security patterns could also facilitate the selection and tailoring of security policies, patterns, mechanisms, and technologies when a designer is building ESAs. To illustrate our ideas, we present an instance of this new type of pattern, showing how it can be used. Copyright © 2014 John Wiley & Sons, Ltd. Santiago Moral-García, Santiago Moral-Rubio, David Garcia Rosado, Eduardo B. Fernández, Eduardo Fernández-Medina |
Secur. Commun. Networks | 4 |
| 2012 | Securing distributed systems using patterns: A survey
Anton V. Uzunov, Eduardo B. Fernández, Katrina Falkner |
Comput. Secur. | 2 |
| 2011 | An Approach to Model-based Development of Secure and Reliable SystemsabstractA good way to obtain secure systems is to build applications in a systematic way where security is an integral part of the lifecycle. The same applies to reliability. If we want a system which is secure and reliable, both security and reliability must be built together. If we build not only applications but also middleware and operating systems in the same way, we can build systems that not only are inherently secure but also can withstand attacks from malicious applications and resist errors. In addition, all security and reliability constraints should be defined in the application level, where their semantics is understood and propagated to the lower levels. The lower levels provide the assurance that the constraints are being followed. In this approach all security constraints are defined at the conceptual or application level. The lower levels just enforce that there are no ways to bypass these constraints. By mapping to a highly secure platform, e.g., one using capabilities, we can produce a very secure system. Our approach is based on security patterns that are mapped through the architectural levels of the system. We make a case for this approach and we present here three aspects to further develop it. These aspects include a metamodel for security requirements, a mapping of models across architectural levels, and considerations about the degree of security of the system. Eduardo B. Fernández, Hironori Washizaki, Nobukazu Yoshioka, Michael VanHilst |
ARES | 1 |
| 2011 | Two patterns for distributed systems: enterprise service bus (ESB) and distributed publish/subscribeabstractHironori Washizaki, Waseda University/GRACE Center, National Institute of Informatics, 3-4-1, Okubo, Shinjuku-ku, Tokyo, Japan, [email protected] present two common patterns for distributed systems: Enterprise Service Bus (ESB) and Distributed Publish/Subscribe (P/S). ESB defines a common bus structure that provides basic brokerage functions as well as a set of other appropriate services. The ESB has been used mostly for web services but it can be used for any distributed system. The P/S realizes a system structure where subscribers register to receive events produced by a publisher. The P/S has been described usually in a centralized environment and we emphasize here its distributed nature. These patterns are mainly intended for web services application and distributed systems architects and designers. In those applications, the ESB and the Distributed P/S are architectural units that need to be combined with other architectural units. Eduardo B. Fernández, Nobukazu Yoshioka |
PLoP | 1 |
| 2011 | P2N: a pedagogical <u>p</u>attern for teaching computer <u>p</u>rogramming to <u>n</u>on-CS majorsabstractWe introduce a new method for non-computer-science majors to learn computer programming, in order to quickly prepare them for their own major study or research work. Traditional computer science programs ignore the need for such quick training, forcing them to take several semesters and many foundation courses with computer-science (CS) majors. Because those students lack sufficient background knowledge, they cannot achieve the education goal as a CS graduate may have in those courses. On the other hand, the existing entry-level training focuses on the systematic study of fundamental materials for the long-term CS career. It lacks attraction to students who are pursuing immediate support for their specified applications. An effective approach is needed to attract non-CS majors and to keep them working hard on those materials with a significant technical depth. Loops are one of the basic programming structures but we often overlook the challenge in its learning process. By using our practice at West Chester University as an example, we demonstrate the challenges as well as our success for our non-CS majors to quickly learn to develop loops correctly. On one hand, we adopt the disciplined training model with many subtasks that is commonly used in China m order to cover all the required materials. On the other hand, we adopt the model that is commonly used in American classes and use commercial off-the-shelf products, games, work templates, etc. in order to help students form the abstractions, understand the corresponding materials, gain the appropriate skills, and achieve each intermediate task goal. This pattern provides a solution for a complex education problem in a short time scale. Eduardo B. Fernández, Liang Cheng 0001 |
PLoP | 2 |
| 2011 | Misuse Patterns for Cloud Computing
Keiko Hashizume, Eduardo B. Fernández, Nobukazu Yoshioka |
SEKE | 2 |
| 2011 | Wkc-OWA, a New Neat-OWA Operator to Aggregate Information in Democratic Decision ProblemsabstractIn all decision making processes, the use of aggregation operators is necessary. Democratic decision problems cannot be considered a usual decision task due to the subjectivity of human' opinions and the complexity of social environments. To model these processes, the concept of work committee is used, where every citizen's opinion is represented in heterogeneous groups and aggregated to obtain a representative final opinion for the problem. In these environments, traditional operators don't represent the concept of discussion groups used in social models producing inadequate aggregations for these types of problems. The purpose of this paper is to present a new OWA operator where the weights are a function of the aggregate values in order to model the work committee and aggregate the citizens' opinions in democratic decision problems. David La Red, Jesús M. Doña, José Ignacio Peláez, Eduardo B. Fernández |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 4 |
| 2010 | Measuring the Level of Security Introduced by Security PatternsabstractIt is possible to reasonably measure the security quality of individual security patterns. However, more interesting is to ask: Can we show that a system built using security patterns is secure in some sense? We discuss here some issues about evaluating the security of a system built using security patterns. We consider the use of threats and misuse patterns to perform this evaluation. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki, Michael VanHilst |
ARES | 1 |
| 2010 | Refining the Pattern-Based Reference Model for Electronic Invoices by Incorporating ThreatsabstractAlmost every company needs to process invoices to either claim money from their customers or to pay for products or services. Although companies are allowed to electronically process their invoices, most of them still rely on the paper-based invoice process. Within this paper we built upon existing work to develop a methodology for defining a reference model for the electronic invoice based on security patterns. This paper identifies threats of the e-invoice process in order to create a context for the security problem, which allows us to refine our methodology. Michael Netter, Eduardo B. Fernández, Günther Pernul |
ARES | 2 |
| 2010 | A pattern system of underlying theories for process improvementabstractAn underlying theory is a framework of goals, solutions, and assumptions that guide how we observe situations and define problems. In science, the underlying theories, like particles, waves, relativity, plate tectonics, and evolution, are well known and well understood. In process improvement, the underlying theories are not so well understood. To address that problem, we present a system of patterns. The system includes six patterns for theories that underlie many of the well known practices in process improvement. The patterns are Plan, Best Practices, Flow, Feedback, Systems Thinking, and Living System. These patterns are found in ISO 9000, PMBOK, CMMI, SPICE, Lean, TQM, Six Sigma, and Agile. Like all patterns, the patterns in this system are structural configurations that solve a problem in a context. Michael VanHilst, Eduardo B. Fernández |
PLoP | 2 |
| 2010 | A pattern for a sensor nodeabstractSensors are widely used in everyday life in household appliances, fire alarms, traffic control systems, battlefields, banks, and museums. Sensors are used either as standalone devices or in networks. Understanding the basic structure of a sensor node is essential to be able to use the sensors in different types of devices and different kinds of environments. Many applications require different types of sensor nodes that communicate with each other to perform a specific function. We present a pattern that describes an abstract view of the architecture of a sensor node. This description would help the application designer to choose from different types of sensor nodes for his application and to integrate it with other functional units. Moreover, this model also helps the designer to reuse, combine, or modify the architecture of a node to suit more complex needs. Anupama Sahu, Eduardo B. Fernández, Mihaela Cardei, Michael VanHilst |
PLoP | 2 |
| 2009 | Modeling Misuse PatternsabstractSecurity patterns are now starting to be accepted by industry. Security patterns are useful to guide the security design of systems by providing generic solutions that can stop a variety of attacks but it is not clear to an inexperienced designer what pattern should be applied to stop a specific attack. They are not useful either for forensics because they do not emphasize the modus operandi of the attack. To complement security patterns, we have proposed a new type of pattern, the misuse pattern. This pattern describes, from the point of view of the attacker, how a type of attack is performed (what units it uses and how), defines precisely the context of the attack, analyzes the ways of stopping the attack by enumerating possible security patterns that can be applied for this purpose, and describes how to trace the attack once it has happened by appropriate collection and observation of forensics data. We present here a model that characterizes the precise structure of this type of pattern. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki |
ARES | 1 |
| 2009 | Patterns to Support the Development of Privacy PoliciesabstractThis paper presents patterns for privacy policies to be used in web sites, in particular e-commerce and e-business sites. Because of their financial aspects, the users accessing those sites need to provide personal information, and expect integrity, security, and privacy. The patterns are derived from a study of the 33 most accessed e-commerce sites in Brazil, where it was possible to observe that they do not use a systematic approach to develop privacy policies which are clear, friendly, and with relevant contents. Luanna Lopes Lobato, Eduardo B. Fernández, Sérgio Donizetti Zorzo |
ARES | 2 |
| 2009 | Web Services Reliability Patterns
Ingrid A. Buckley, Eduardo B. Fernández, Gustavo Rossi, Seyed Masoud Sadjadi |
SEKE | 2 |
| 2009 | Misuse patterns in VoIPabstractAbstract To protect against security attacks, it is necessary to be aware of typical risks and to have a good understanding of how vulnerabilities can be exploited. Security patterns are useful to guide the security design of systems by providing generic solutions that can stop a variety of attacks, but it is not clear to an inexperienced designer what pattern should be applied to stop a specific attack. Additionally, security patterns are not useful for network forensics purposes because they do not emphasize the modus operandi of the attack. As a complement and improvement, we have proposed a new type of pattern, the misuse pattern. This pattern describes, from the point of view of the attacker, how a type of information misuse is performed, analyzes the ways of stopping the attack, and considers how to trace the attack once it has happened. To apply this approach, we need a catalog of misuse patterns. In this paper, we restrict our interest to voice over Internet protocol (VoIP) and we present a set of typical and frequent misuse patterns for VoIP: denial of service (DoS), call interception, theft of service, and call hijacking on VoIP. These patterns could be the start of a comprehensive catalog that would be of practical value to developers, testers, users, and researchers. Published in 2009 by John Wiley & Sons, Ltd. Juan C. Pelaez, Eduardo B. Fernández, María M. Larrondo-Petrie |
Secur. Commun. Networks | 2 |
| 2008 | A Pattern-Driven Security Process for SOA ApplicationsabstractSOA enables the design of flexible and modular software applications that can be used in a cross- organization context. Unfortunately, those qualities have a negative impact on the security of the software application. In this paper, we investigate the production of secure SOA applications. In particular, we provide an approach to build secure SOA applications that takes into account the new security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of security patterns. Nelly A. Delessy, Eduardo B. Fernández |
ARES | 2 |
| 2008 | Classifying Security Patterns
Eduardo B. Fernández, Hironori Washizaki, Nobukazu Yoshioka, Atsuto Kubo, Yoshiaki Fukazawa |
APWeb | 1 |
| 2008 | The Secure Three-Tier Architecture PatternabstractThe three-tier architecture pattern and its variants have been around for a while and there are several discussions of their properties as well as several patterns. None of these discussions considers security. However, several real systems implement this approach including security. We revisit this pattern to explicitly separate and analyze its security aspects. Eduardo B. Fernández, Mihai Fonoage, Michael VanHilst, Mirela Marta |
CISIS | 1 |
| 2008 | Patterns and Pattern Diagrams for Access Control
Eduardo B. Fernández, Günther Pernul, María M. Larrondo-Petrie |
TrustBus | 1 |
| 2007 | Security Patterns for Physical Access Control Systems
Eduardo B. Fernández, Jose Ballesteros, Ana C. Desouza-Doucet, María M. Larrondo-Petrie |
DBSec | 1 |
| 2007 | Attack Patterns: A New Forensic and Design Tool
Eduardo B. Fernández, Juan C. Pelaez, María M. Larrondo-Petrie |
IFIP Int. Conf. Digital Forensics | 1 |
| 2007 | Panel Discussion: Managing Digital Identities - Challenges and Opportunities
Günther Pernul, Marco Casassa Mont, Eduardo B. Fernández, Sokratis K. Katsikas, Alfred Kobsa, Rolf Oppliger |
TrustBus | 3 |
| 2007 | Secure and efficient key management in mobile ad hoc networks
Jie Wu 0001, Eduardo B. Fernández, Mohammad Ilyas, Spyros S. Magliveras |
J. Netw. Comput. Appl. | 3 |
| 2004 | A Pattern System for Access ControlabstractIn order to develop trustworthy information systems, security aspects should be considered from the early project stages. This is particularly true for authorization and access control services, which decide which users can access which parts of the system and in what ways. Software patterns have been used with success to encapsulate best practices in software design. A good collection of patterns is an invaluable aid in designing new systems by inexperienced developers and is also useful to teach and understand difficult problems. Following in this direction, this paper presents a pattern system to describe authorization and access control models. First, we present a set of patterns that include a basic authorization pattern that is the basis for patterns for the well-established discretionary and role-based access control models. Metadata access control models have appeared recently to address the high flexibility requirements of open, heterogeneous systems, such as enterprise or e-commerce portals. These models are complex and we use the basic patterns to develop a set of patterns for metadata-based access control. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Torsten Priebe, Eduardo B. Fernández, Jens Ingo Mehlau, Günther Pernul |
DBSec | 2 |
| 2000 | Semantic Analysis Patterns
Eduardo B. Fernández, Xiaohong Yuan |
ER | 1 |
| 1998 | Optimal Fault-Secure SchedulingabstractWe consider here two basic fault-secure scheduling problems for multiprocessor systems. First, given the number of processors in the system and a set of computational tasks of unit length expressed as a complete binary tree, a scheduling algorithm is proposed such that the total execution time is a minimum and no undetected single error result will be delivered. Second, given a deadline and a computation tree, another algorithm is given which generates a fault-secure scheduling using a minimum number of processors. We show that two previous approaches are special cases of these algorithms. We also discuss the way to modify our scheduling to ensure a given fault latency requirement. Finally, extensions that cover multiple errors, non-unit length tasks and computation graphs of arbitrary binary trees are discussed. Jie Wu 0001, Eduardo B. Fernández, Donglai Dai |
Comput. J. | 2 |
| 1998 | Embedding of Binomial Treas in Hypercubes with Link Faults
Jie Wu 0001, Eduardo B. Fernández, Yingqui Lo |
J. Parallel Distributed Comput. | 2 |
| 1997 | Embedding of binomial trees in hypercubes with link faultsabstractWe study the embedding of binomial trees with variable roots in n-dimensional hypercubes (n-cubes) with faulty links. A simple embedding algorithm is first proposed that can embed an n-level binomial tree in an n-cube with up to n-1 faulty links in log(n-1) steps. We then extend the result to show that spanning binomial trees exist in a connected n-cube with up to [3(n-1)/2]-1 faulty links. Our results reveal the fault tolerance property of hypercubes and they can be used to predict the performance of broadcasting and reduction operations, where the binomial tree structure is commonly used. Jie Wu 0001, Eduardo B. Fernández, Yingquiu Luo |
ICPP | 2 |
| 1996 | Design and Modeling of Hybrid Fault-Tolerant Software With Cost Constraints
W. Jie, Eduardo B. Fernández, Z. Manxia |
J. Syst. Softw. | 2 |
| 1995 | A Formal Specification of an Authorization Model for Object-Oriented Databases
Eduardo B. Fernández, Robert B. France, D. Wei |
DBSec | 1 |
| 1995 | Formal specification of real-time dependable systemsabstractThe complex and critical nature of real-time, dependable systems (henceforth referred to as RTD systems) necessitates the use of analyzable specifications and specification analysis techniques supporting the assessment of behavioral, safety-critical, security, and fault-tolerant qualities of systems. The need to rigorously state and analyze RTD system specifications suggests the use of formal specification techniques (FSTs), that is techniques that provide a precise specification language and specification analysis mechanisms based on formal reasoning systems. Unfortunately, most current FSTs focus on specifying functionality, and neglect non-functional qualities such as fault tolerance and security. While there is much research on extending FSTs so that they can be applied to non-functional properties, little work has gone into developing integrated sets of FSTs that can be applied throughout the development of RTD systems. We discuss how FSTs can be utilized in a multilevel description of RTD systems. FST's make possible rigorous analysis at each level and rigorous consistency check across the levels. Eduardo B. Fernández, Robert B. France |
ICECCS | 1 |
| 1995 | A combined functional and object-oriented approach to software designabstractLarge and complex software systems contain a variety of entities (objects) and a complex control system (transformation function). The pure object-oriented design and structured design approaches concentrate on either objects or the transformation function separately. As such they may not be adequate in isolation, to deal with the design of complex systems. Therefore, it makes sense to study their combination. We propose a combined functional and object-oriented design approach (CFOOD) based on the extended object-oriented design method proposed by P. Jalote (1989, 1991). The CFOOD approach makes full use of the object-oriented design and structured design techniques combining the object view and the functional view to provide a more complete view of a system. We demonstrate the use of our approach by a design example of a hospital patient monitoring system. Haifeng Qian, Eduardo B. Fernández, Jie Wu 0001 |
ICECCS | 2 |
| 1994 | User Group Structures in Object-Oriented Database Authorization
Eduardo B. Fernández, Jie Wu 0001, Minjie H. Fernandez |
DBSec | 1 |
| 1994 | A uniform approach to software and hardware fault tolerance
Jie Wu 0001, Eduardo B. Fernández |
J. Syst. Softw. | 3 |
| 1994 | A Model for Evaluation and Administration of Security in Object-Oriented DatabasesabstractThe integration of object-oriented programming concepts with databases is one of the most significant advances in the evolution of database systems. Many aspects of such a combination have been studied, but there are few models to provide security for this richly structured information. We develop an authorization model for object-oriented databases. This model consists of a set of policies, a structure for authorization rules, and algorithms to evaluate access requests against the authorization rules. User access policies are based on the concept of inherited authorization applied along the class structure hierarchy. We propose also a set of administrative policies that allow the control of user access and its decentralization. Finally, we study the effect of class structuring changes on authorization.> Eduardo B. Fernández, Ehud Gudes, Haiyan Song |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1994 | Using Petri Nets for the Design of Conversation Boundaries in Fault-Tolerant SoftwareabstractOnly a few mechanisms have been proposed for the design of fault-tolerant software. One of these is the conversation, which, though it has some drawbacks, is a potentially promising structure. One of the problems with conversations is that they must be defined and verified by the user. In this short note, a systematic method for generating the boundaries of conversations directly from the specification is proposed. This method can also be used to verify conversations selected by the user. The specification is described by a high-level modified Petri net which can easily be transformed into a state model called an action-ordered tree. The conversation boundaries are then determined from this tree. It is proved that the method proposed is complete in the sense that all of the possible boundaries can be determined, and it has the merit of simplicity. A robot arm control system is used to illustrate the idea. The proposed method can serve as the basis of a tool to assist in conversation designs.> Jie Wu 0001, Eduardo B. Fernández |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 1993 | A Model of Methods Access Authorization in Object-oriented Databases
Nurit Gal-Oz, Ehud Gudes, Eduardo B. Fernández |
VLDB | 3 |
| 1993 | Broadcasting in faulty hypercubes
Jie Wu 0001, Eduardo B. Fernández |
Microprocess. Microprogramming | 2 |
| 1992 | Reliable Broadcasting in Faulty Hypercube ComputersabstractA nonredundant broadcasting algorithm for faulty hypercube computers is proposed. The concept of unsafe nodes is introduced to identify those nonfaulty nodes that will cause a detour or backtracking because of their proximity to faulty nodes. It is assumed that each healthy node, safe or unsafe, knows the status of all the neighboring nodes. The broadcasting is optimal, meaning that a message is sent to each node via a Hamming distance path if the broadcasting is initiated from a safe node. It is also shown that when the source node is unsafe and there is an adjacent safe node, then the broadcasting can be achieved with only one more time step than the fault-free case.> Jie Wu 0001, Eduardo B. Fernández |
SRDS | 2 |
| 1992 | Some extensions to the lattice model for computer security
Jie Wu 0001, Eduardo B. Fernández, Ruiguang Zhang |
Comput. Secur. | 2 |
| 1992 | A workload model for frame-based real-time applications on distributed systems
Khoa D. Huynh, Eduardo B. Fernández, Taghi M. Khoshgoftaar |
J. Syst. Softw. | 2 |
| 1989 | A Security Model for Object-Oriented DatabasesabstractAn authorization model for object-oriented databases is developed. This model consists of a set of policies, a structure for authorization rules, and an algorithm to evaluate access requests against the authorization rules. The model is illustrated by a specific database system intended for CAD/CAM (computer-aided design/manufacturing) applications, and incorporates knowledge rules with a database of objects combined through an object-oriented semantic association model (OSAM). The database is composed of objects that include a collection of facts and a collection of relevant rules. All the knowledge manipulation operations can be used to express the rules. Some of these rules could be integrity or security rule, i.e. they could be the basis for a mechanism to enforce integrity or security.> Eduardo B. Fernández, Ehud Gudes, Haiyan Song |
S&P | 1 |
| 1989 | A Simplification of a Conversation Design Scheme Using Petri NetsabstractIn the conversation design procedure, the definition of the state of the system is one of the most important aspects. The question is how to identify transitions in Occam programs in order to express them as Petri nets. In the paper, a simplified transition identification method is proposed. Using the robot arm control program of A.M. Tyrrell and D.J. Holding it is shown that the correspondent Petri net graph is simpler than theirs, but the communication state change table is the same. It is also shown that these two methods are equivalent.> Jie Wu 0001, Eduardo B. Fernández |
IEEE Trans. Software Eng. | 2 |
| 1987 | Using different language levels for implementing fault tolerant programs
Massimo Ancona, Andrea Clematis, Gabriella Dodero, Eduardo B. Fernández, Vittoria Gianuzzi |
Microprocessing and Microprogramming | 4 |
| 1983 | Minimization of Demand Paging for the LRU Stack Model of Program Behavior
Christopher Wood, Eduardo B. Fernández, Tomás Lang |
Inf. Process. Lett. | 2 |
| 1979 | Decentralized Authorization in a Database System
Christopher Wood, Eduardo B. Fernández |
VLDB | 2 |
| 1979 | Authorization in multilevel database models
Christopher Wood, Rita C. Summers, Eduardo B. Fernández |
Inf. Syst. | 3 |
| 1978 | Architectural Support for System Protection and Database SecurityabstractA set of architectural extensions to a machine of the type of IBM System/370 is proposed. The proposal involves hardware/software interaction to constrain the execution-time behavior of application and higher authority programs. The extensions consist of new states of privilege, enforcement of disciplined transition between states, hardware distinction of information types, and a mechanism to control data transfers between main and external storage. Application of the extensions to a shared database system, where users interact through a high-level language, shows that protection of the operating system and the database can be enhanced significantly with respect to errors or deliberate attacks from users Eduardo B. Fernández, Rita C. Summers, Tomás Lang, Charles D. Coleman |
IEEE Trans. Computers | 1 |
| 1977 | An Architectural Extension for a Large Database System Incorporating a Processor for Disk Search
E. Nahouraii, K. Kasuga, Eduardo B. Fernández |
VLDB | 4 |
| 1977 | Database Buffer Paging in Virtual Storage SystemsabstractThree models, corresponding to different sets of assumptions, are analyzed to study the behavior of a database buffer in a paging environment. The models correspond to practical situations and vary in their search strategies and replacement algorithms. The variation of I/O cost with respect to buffer size is determined for the three models. The analysis is valid for arbitrary database and buffer sizes, and the I/O cost is obtained in terms of the miss ratio, the buffer size, the number of main memory pages available for the buffer, and the relative buffer and database access costs. Tomás Lang, Christopher Wood, Eduardo B. Fernández |
ACM Trans. Database Syst. | 3 |
| 1976 | Architecture Support for System Protection
Eduardo B. Fernández, Rita C. Summers, Charles D. Coleman |
ISCA | 1 |
| 1976 | Scheduling of Unit-Length Independent Tasks with Execution Constraints
Tomás Lang, Eduardo B. Fernández |
Inf. Process. Lett. | 2 |
| 1975 | An Authorization Model for a Shared Data BaseabstractAn authorization model is presented, applicable to a shared data base with well defined data structures. Access to this data base is made through a high level language, which is extended to permit data manipulation and to provide data views for different applications. The authorization model includes: 1) the explicit introduction of the concept of application into the definition of user rights; and 2) the use of predicates that can depend on any data in the system to control access at the data field level. Enforcement of authorization is distributed along time (mostly at compile time), and uses the view mechanism to make evident the application program data requests, which are checked by a centralized procedure that consults the access matrix. The system is shown to provide comprehensive authorization, including implementation of levels and compartments, special access restrictions, content-dependent, context-dependent and functional access. Eduardo B. Fernández, Rita C. Summers, Charles D. Coleman |
SIGMOD Conference | 1 |
| 1975 | Definition and Evaluation of Access Rules in Data Management SystemsabstractA data structuring scheme for authorization purposes is presented, that: Eduardo B. Fernández, Rita C. Summers, Tomás Lang |
VLDB | 1 |
| 1973 | Bounds on the Number of Processors and Time for Multiprocessor Optimal SchedulesabstractTwo problems of importance for the scheduling of multiprocessing systems composed of identical units are discussed in this paper. 1) Given a partially ordered set of computations represented by the vertices of an acyclic directed graph with their associated execution times, find the minimum number of processors in order to execute them in a time not exceeding the length of the critical path of this graph. 2) Determine the minimum time to process this set of computations when a fixed number of processors is available. A unified formulation for lower bounds on the minimum number of processors and on time is presented. These lower bounds are sharper than previously known values and provide a general framework that gives insight for deriving simplified expressions. A new upper bound on the minimum number of processors is presented, which is sharper than the known bounds. The computational aspects of these bounds are also discussed. Eduardo B. Fernández, Bertram Bussell |
IEEE Trans. Computers | 1 |