EDBT 2026 Demo / reviewers in the wild / expert
Emil C. Lupu
dblp:l/ECLupu · also Emil Constantine Lupu, Emil Lupu
· DBLP profile ↗
74ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0002-2844-3917ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 7 since 2021Computer networks · 13 · 2 first-authorArtificial intelligence and machine learning · 10 · 4 since 2021Systems, architecture and hardware · 7 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4Human-computer interaction and ubiquitous computing · 3Software engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Incident Response Planning Using a Lightweight Large Language Model with Reduced Hallucination
Kim Hammar, Tansu Alpcan, Emil C. Lupu |
NDSS | 3 |
| 2026 | Adaptive Network Security Policies via Belief Aggregation and RolloutabstractEvolving security vulnerabilities and shifting operational conditions require frequent updates to network security policies. These updates include adjustments to incident response procedures and modifications to access controls, among others. Reinforcement learning methods have been proposed for automating such policy adaptations, but most methods in the research literature lack performance guarantees and adapt slowly to changes. In this paper, we address these limitations and present a method for computing security policies that is scalable, offers theoretical guarantees, and adapts quickly to changes. The method uses a model or simulator of the system, which is updated when changes occur, and combines three components: belief estimation through particle filtering, offline policy computation through feature-based aggregation, and online policy adaptation through rollout. In particular, feature-based aggregation enables scalable offline optimization of a policy, while rollout adapts the policy online to changes in the system model without repeating the offline optimization. We analyze the approximation error of the aggregation and show that the rollout efficiently adapts policies to changes under certain conditions. Simulations and testbed results demonstrate that our method outperforms state-of-the-art methods on several benchmarks, including CAGE-2. Kim Hammar, Tansu Alpcan, Emil C. Lupu, Dimitri P. Bertsekas |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | GhostLite: Data Minimization with Applications to Real-Time LiDAR AttacksabstractLiDAR-based object detection plays a crucial role in autonomous driving, yet remains vulnerable to ghost object attacks, where adversarially crafted point clouds trigger false detections. Traditional attack methods often require a large number of points and substantial computational resources, making them inapplicable in real-world scenarios. Although prior research has explored reducing the number of required attack points, real-world feasibility remains a challenge due to the high computational cost and attack generation time. While LiDAR object detection can be compromised given enough adversarially crafted points, we believe there are some critical points, which we call reduced attack budget, which are sufficient to attack the detector. Motivated by this consideration, we propose a novel geometric- and heuristic-based approach capable of generating effective ghost object attacks by leveraging the target’s contour characteristics. By strategically selecting a minimal set of adversarial points, as few as 20 points, our approach maintains high detection confidence, reduces attack execution time and attack budget by up to 4 and 73 times, respectively, in this paper. Our method has been verified on both simulated and real-world datasets (KITTI). The experimental results demonstrate that our optimized attack significantly reduces computational overhead and consequently improves the attack’s real-time feasibility. Richard Capraru, Emil C. Lupu, Jian-Gang Wang 0001, Boon-Hee Soong |
VTC2025-Fall | 2 |
| 2024 | Rain-Reaper: Unmasking LiDAR-based Detector Vulnerabilities in RainabstractLIDAR-based 3D object detection aims to enhance the situational awareness of autonomous vehicles. Despite recent advancements in this technology, there has been evidence that the susceptibility of 3D object detectors to signal spoofing is high, leading to the erroneous detection of "ghost objects" or the failure to detect genuine ones. While prior work has investigated the design of these new attacks and new defenses, the effect of weather conditions, which is a hot topic in autonomous vehicle research, on both attacks and defenses has never been studied. Inspired by this observation, in this paper, we present a novel genetic algorithm-based attack, entitled Rain-Reaper, that leverages on the effect of rain and identifies critical detection points used by 3D detectors. We show that adverse weather conditions not only diminish detection distance and accuracy but also expose the limitations of existing defenses. We have found that the unique characteristics of wet roads lead to underperforming defenses, thus, leading to a false sense of confidence in them. The effectiveness and efficiency of the attack and the robustness of the defenses have been evaluated with both simulated and real data. Our Rain-Reaper demonstrates a high attack success rate while successfully evading existing defenses with an adversarial point budget of up to 8.8 times smaller than previously demonstrated state-of-the-art attacks. Richard Capraru, Emil C. Lupu, Soteris Demetriou, Jian-Gang Wang 0001, Boon-Hee Soong |
IROS | 2 |
| 2024 | Which Attacks Lead to Hazards? Combining Safety and Security Analysis for Cyber-Physical SystemsabstractCyber-Physical Systems (CPS) are exposed to a plethora of attacks and their attack surface is only increasing. However, whilst many attack paths are possible, only some can threaten the system's safety and potentially lead to loss of life. Identifying them is of essence. We propose a methodology and develop a tool-chain to systematically analyse and enumerate the attacks leading to safety violations. This is achieved by lazily combining threat modelling and safety analysis with formal verification and with attack graph analysis. We also identify the minimum sets of privileges that must be protected to preserve safety. We demonstrate the effectiveness of our methodology to discover threat scenarios by applying it to a Communication Based Train Control System. Our design choices emphasise compatibility with existing safety and security frameworks, whilst remaining agnostic to specific tools or attack graphs representations. Luca Maria Castiglione, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Hyperparameter Learning Under Data Poisoning: Analysis of the Influence of Regularization via Multiobjective Bilevel OptimizationabstractMachine learning (ML) algorithms are vulnerable to poisoning attacks, where a fraction of the training data is manipulated to deliberately degrade the algorithms’ performance. Optimal attacks can be formulated as bilevel optimization problems and help to assess their robustness in worst case scenarios. We show that current approaches, which typically assume that hyperparameters remain constant, lead to an overly pessimistic view of the algorithms’ robustness and of the impact of regularization. We propose a novel optimal attack formulation that considers the effect of the attack on the hyperparameters and models the attack as amultiobjectivebilevel optimization problem. This allows us to formulate optimal attacks, learn hyperparameters, and evaluate robustness under worst case conditions. We apply this attack formulation to several ML classifiers using$L_2$and$L_1$regularization. Our evaluation on multiple datasets shows that choosing an “a priori” constant value for the regularization hyperparameter can be detrimental to the performance of the algorithms. This confirms the limitations of previous strategies and evidences the benefits of using$L_2$and$L_1$regularization to dampen the effect of poisoning attacks, when hyperparameters are learned using a small trusted dataset. Additionally, our results show that the use of regularization plays an important robustness and stability role in complex models, such as deep neural networks (DNNs), where the attacker can have more flexibility to manipulate the decision boundary. Javier Carnerero-Cano, Luis Muñoz-González, Phillippa Spencer, Emil C. Lupu |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2023 | Redundancy Planning for Cost Efficient Resilience to Cyber AttacksabstractWe investigate the extent to which redundancy (including with diversity) can help mitigate the impact of cyber attacks that aim to reduce system performance. Using analytical techniques, we estimate impacts, in terms of monetary costs, of penalties from breaching Service Level Agreements (SLAs), and find optimal resource allocations to minimize the overall costs arising from attacks. Our approach combines attack impact analysis, based on performance modeling using queueing networks, with an attack model based on attack graphs. We evaluate our approach using a case study of a website, and show how resource redundancy and diversity can improve the resilience of a system by reducing the likelihood of a fully disruptive attack. We find that the cost-effectiveness of redundancy depends on the SLA terms, the probability of attack detection, the time to recover, and the cost of maintenance. In our case study, redundancy with diversity achieved a saving of up to around 50 percent in expected attack costs relative to no redundancy. The overall benefit over time depends on how the saving during attacks compares to the added maintenance costs due to redundancy. Jukka Soikkeli, Giuliano Casale, Luis Muñoz-González, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | A Hybrid Threat Model for Smart SystemsabstractCyber-physical systems and their smart components have a pervasive presence in all our daily activities. Unfortunately, identifying the potential threats and issues in these systems and selecting enough protection is challenging given that such environments combine human, physical and cyber aspects to the system design and implementation. Current threat models and analysis do not take into consideration all three aspects of the analyzed system, how they can introduce new vulnerabilities or protection measures to each other. In this work, we introduce a novel threat model for cyber-physical systems that combines the cyber, physical, and human aspects. Our model represents the system's components relations and security properties by taking into consideration these three aspects. Together with the threat model we also propose a threat analysis method that allows understanding the security state of the system's components. The threat model and the threat analysis have been implemented into an automatic tool, called TAMELESS, that automatically analyzes threats to the system, verifies its security properties, and generates a graphical representation, useful for security architects to identify the proper prevention/mitigation solutions. We show and prove the use of our threat model and analysis with three cases studies from different sectors. Fulvio Valenza, Erisa Karafili, Rodrigo Vieira Steiner, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Jacobian Ensembles Improve Robustness Trade-Offs to Adversarial Attacks
Kenneth T. Co, David Martínez-Rego, Zhongyuan Hau, Emil C. Lupu |
ICANN (3) | 4 |
| 2021 | Shadow-Catcher: Looking into Shadows to Detect Ghost Objects in Autonomous Vehicle 3D Sensing
Zhongyuan Hau, Soteris Demetriou, Luis Muñoz-González, Emil C. Lupu |
ESORICS (1) | 4 |
| 2021 | Jacobian Regularization for Mitigating Universal Adversarial Perturbations
Kenneth T. Co, David Martínez-Rego, Emil C. Lupu |
ICANN (4) | 3 |
| 2021 | Universal Adversarial Robustness of Texture and Shape-Biased ModelsabstractIncreasing shape-bias in deep neural networks has been shown to improve robustness to common corruptions and noise. In this paper we analyze the adversarial robustness of texture and shape-biased models to Universal Adversarial Perturbations (UAPs). We use UAPs to evaluate the robustness of DNN models with varying degrees of shape-based training. We find that shape-biased models do not markedly improve adversarial robustness, and we show that ensembles of texture and shape-biased models can improve universal adversarial robustness while maintaining strong performance. Kenneth T. Co, Luis Muñoz-González, Leslie Kanthan, Ben Glocker, Emil C. Lupu |
ICIP | 5 |
| 2021 | Extracting Randomness from the Trend of IPI for Cryptographic Operations in Implantable Medical DevicesabstractAchieving secure communication between an Implantable Medical Device (IMD) and a gateway or programming device outside the body has showed its criticality in recent reports of vulnerabilities in cardiac devices, insulin pumps and neural implants, amongst others. The use of asymmetric cryptography is typically not a practical solution for IMDs due to the scarce computational and power resources. Symmetric key cryptography is preferred but its security relies on agreeing and using strong keys, which are difficult to generate. A solution to generate strong shared keys without using extensive resources, is to extract them from physiological signals already present inside the body such as the Inter-Pulse interval (IPI). The physiological signals must therefore be strong sources of randomness that meet five conditions: Universality (available on all people), Liveness (available at any-time), Robustness (strong random number), Permanence (independent from its history) and Uniqueness (independent from other sources). However, these conditions (mainly the last three) have not been systematically examined in current methods for randomness extraction from IPI. In this study, we first propose a methodology to measure the last three conditions: Information secrecy measures for Robustness, Santha-Vazirani Source delta value for Permanence and random sources dependency analysis for Uniqueness. Then, using a large dataset of IPI values (almost 900,000,000 IPIs), we show that IPI does not have Robustness and Permanence as a randomness source. Thus, extraction of a strong uniform random number from IPI values is impossible. Third, we propose to use the trend of IPI, instead of its value, as a source for a new randomness extraction method named Martingale Randomness Extraction from IPI (MRE-IPI). We evaluate MRE-IPI and show that it satisfies the Robustness condition completely and Permanence to some level. Finally, we use the NIST STS and Dieharder test suites and show that MRE-IPI is able to outperform all recent randomness extraction methods from IPIs and achieves a quality roughly half that of the AES random number generator. MRE-IPI is still not a strong random number and cannot be used as key to secure communications in general. However, it can be used as a one-time pad to securely exchange keys between the communication parties. The usage of MRE-IPI will thus be kept at a minimum and reduces the probability of breaking it. To the best of our knowledge, this is the first work in this area which uses such a comprehensive method and large dataset to examine the randomness of physiological signals. Hassan Chizari, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Towards a Framework for Automatic Firewalls Configuration via Argumentation ReasoningabstractFirewalls have been widely used to protect not only small and local networks but also large enterprise networks. The configuration of firewalls is mainly done by network administrators, thus, it suffers from human errors. This paper aims to solve the network administrators’ problem by introducing a formal approach that helps to configure centralized and distributed firewalls and automatically generate conflict-free firewall rules. We propose a novel framework, called ArgoFiCo, which is based on argumentation reasoning. Our framework automatically populates the firewalls of a network, given the network topology and the high-level requirements that represent how the network should behave. ArgoFiCo provides two strategies for firewall rules distribution. Erisa Karafili, Fulvio Valenza, Emil C. Lupu |
NOMS | 4 |
| 2019 | Efficient Attack Countermeasure Selection Accounting for Recovery and Action CostsabstractThe losses arising from a system being hit by cyber attacks can be staggeringly high, but defending against such attacks can also be costly. This work proposes an attack countermeasure selection approach based on cost impact analysis that takes into account the impacts of actions by both the attacker and the defender. Jukka Soikkeli, Luis Muñoz-González, Emil C. Lupu |
ARES | 3 |
| 2019 | Procedural Noise Adversarial Examples for Black-Box Attacks on Deep Convolutional NetworksabstractDeep Convolutional Networks (DCNs) have been shown to be vulnerable to adversarial examples---perturbed inputs specifically designed to produce intentional errors in the learning algorithms at test time. Existing input-agnostic adversarial perturbations exhibit interesting visual patterns that are currently unexplained. In this paper, we introduce a structured approach for generating Universal Adversarial Perturbations (UAPs) with procedural noise functions. Our approach unveils the systemic vulnerability of popular DCN models like Inception v3 and YOLO v3, with single noise patterns able to fool a model on up to 90% of the dataset. Procedural noise allows us to generate a distribution of UAPs with high universal evasion rates using only a few parameters. Additionally, we propose Bayesian optimization to efficiently learn procedural noise parameters to construct inexpensive untargeted black-box attacks. We demonstrate that it can achieve an average of less than 10 queries per successful attack, a 100-fold improvement on existing methods. We further motivate the use of input-agnostic defences to increase the stability of models to adversarial perturbations. The universality of our attacks suggests that DCN models may be sensitive to aggregations of low-level class-agnostic features. These findings give insight on the nature of some universal adversarial perturbations and how they could be generated in other applications. Kenneth T. Co, Luis Muñoz-González, Sixte de Maupeou, Emil C. Lupu |
CCS | 4 |
| 2019 | Defending against poisoning attacks in online learning settings
Greg Collinge, Emil C. Lupu, Luis Muñoz-González |
ESANN | 2 |
| 2019 | Towards more practical software-based attestation
Rodrigo Vieira Steiner, Emil C. Lupu |
Comput. Networks | 2 |
| 2019 | Exact Inference Techniques for the Analysis of Bayesian Attack GraphsabstractAttack graphs are a powerful tool for security risk assessment by analysing network vulnerabilities and the paths attackers can use to compromise network resources. The uncertainty about the attacker's behaviour makes Bayesian networks suitable to model attack graphs to perform static and dynamic analysis. Previous approaches have focused on the formalization of attack graphs into a Bayesian model rather than proposing mechanisms for their analysis. In this paper we propose to use efficient algorithms to make exact inference in Bayesian attack graphs, enabling the static and dynamic network risk assessments. To support the validity of our approach we have performed an extensive experimental evaluation on synthetic Bayesian attack graphs with different topologies, showing the computational advantages in terms of time and memory use of the proposed techniques when compared to existing approaches. Luis Muñoz-González, Daniele Sgandurra, Martín Barrère, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2018 | Helping Forensic Analysts to Attribute Cyber-Attacks: An Argumentation-Based Reasoner
Erisa Karafili, Linna Wang, Antonis C. Kakas, Emil C. Lupu |
PRIMA | 4 |
| 2018 | Self-Generation of Access Control PoliciesabstractAccess control for information has primarily focused on access statically granted to subjects by administrators usually in the context of a specific system. Even if mechanisms are available for access revocation, revocations must still be executed manually by an administrator. However, as physical devices become increasingly embedded and interconnected, access control needs to become an integral part of the resource being protected and be generated dynamically by resources depending on the context in which the resource is being used. In this paper, we discuss a set of scenarios for access control needed in current and future systems and use that to argue that an approach for resources to generate and manage their access control policies dynamically on their own is needed. We discuss some approaches for generating such access control policies that may address the requirements of the scenarios. Seraphin B. Calo, Dinesh C. Verma, Supriyo Chakraborty, Elisa Bertino, Emil C. Lupu, Gregory H. Cirincione |
SACMAT | 5 |
| 2018 | Determining Resilience Gains From Anomaly Detection for Event Integrity in Wireless Sensor NetworksabstractMeasurements collected in a wireless sensor network (WSN) can be maliciously compromised through several attacks, but anomaly detection algorithms may provide resilience by detecting inconsistencies in the data. Anomaly detection can identify severe threats to WSN applications, provided that there is a sufficient amount of genuine information. This article presents a novel method to calculate an assurance measure for the network by estimating the maximum number of malicious measurements that can be tolerated. In previous work, the resilience of anomaly detection to malicious measurements has been tested only against arbitrary attacks, which are not necessarily sophisticated. The novel method presented here is based on an optimization algorithm, which maximizes the attack’s chance of staying undetected while causing damage to the application, thus seeking the worst-case scenario for the anomaly detection algorithm. The algorithm is tested on a wildfire monitoring WSN to estimate the benefits of anomaly detection on the system’s resilience. The algorithm also returns the measurements that the attacker needs to synthesize, which are studied to highlight the weak spots of anomaly detection. Finally, this article presents a novel methodology that takes in input the degree of resilience required and automatically designs the deployment that satisfies such a requirement. Vittorio P. Illiano, Andrea Paudice, Luis Muñoz-González, Emil C. Lupu |
ACM Trans. Sens. Networks | 4 |
| 2017 | Research challenges in dynamic policy-based autonomous securityabstractGenerative policies enable devices to generate their own policies that are validated, consistent and conflict free. This autonomy is required for security policy generation to deal with the large number of smart devices per person that will soon become reality. In this paper, we discuss the research issues that have to be addressed in order for devices involved in security enforcement to automatically generate their security policies - enabling policy-based autonomous security management. We discuss the challenges involved in the task of automatic security policy generation, and outline some approaches based om machine learning that may potentially provide a solution to the same. Seraphin B. Calo, Emil C. Lupu, Elisa Bertino, Saritha Arunkumar, Gregory H. Cirincione, Brian Rivera, Alan Cullen |
IEEE BigData | 2 |
| 2017 | Improving data sharing in data rich environmentsabstractThe increasing use of big data comes along with the problem of ensuring correct and secure data access. There is a need to maximise the data dissemination whilst controlling their access. Depending on the type of users different qualities and parts of data are shared. We introduce an alteration mechanism, more precisely a restriction one, based on a policy analysis language. The alteration reflects the level of trust and relations the users have, and are represented as policies inside the data sharing agreements. These agreements are attached to the data and are enforced every time the data are accessed, used or shared. We show the use of our alteration mechanism with a military use case, where different parties are involved during the missions, and they have different relations of trust and partnership. Erisa Karafili, Emil C. Lupu, Alan Cullen, Bill Williams, Saritha Arunkumar, Seraphin B. Calo |
IEEE BigData | 2 |
| 2017 | Tracking the bad guys: An efficient forensic methodology to trace multi-step attacks using core attack graphsabstractIn this paper, we describe an efficient methodology to guide investigators during network forensic analysis. To this end, we introduce the concept of core attack graph, a compact representation of the main routes an attacker can take towards specific network targets. Such compactness allows forensic investigators to focus their efforts on critical nodes that are more likely to be part of attack paths, thus reducing the overall number of nodes (devices, network privileges) that need to be examined. Nevertheless, core graphs also allow investigators to hierarchically explore the graph in order to retrieve different levels of summarised information. We have evaluated our approach over different network topologies varying parameters such as network size, density, and forensic evaluation threshold. Our results demonstrate that we can achieve the same level of accuracy provided by standard logical attack graphs while significantly reducing the exploration rate of the network. Martín Barrère, Rodrigo Vieira Steiner, Rabih Mohsen, Emil C. Lupu |
CNSM | 4 |
| 2017 | Enabling Data Sharing in Contextual Environments: Policy Representation and AnalysisabstractInternet of Things environments enable us to capture more and more data about the physical environment we live in and about ourselves. The data enable us to optimise resources, personalise services and offer unprecedented insights into our lives. However, to achieve these insights data need to be shared (and sometimes sold) between organisations imposing rights and obligations upon the sharing parties and in accordance with multiple layers of sometimes conflicting legislation at international, national and organisational levels. In this work, we show how such rules can be captured in a formal representation called "Data Sharing Agreements". We introduce the use of abductive reasoning and argumentation based techniques to work with context dependent rules, detect inconsistencies between them, and resolve the inconsistencies by assigning priorities to the rules. We show how through the use of argumentation based techniques use-cases taken from real life application are handled flexibly addressing trade-offs between confidentiality, privacy, availability and safety. Erisa Karafili, Emil C. Lupu |
SACMAT | 2 |
| 2017 | Unity is strength!: combining attestation and measurements inspection to handle malicious data injections in WSNsabstractAttestation and measurements inspection are different but complementary approaches towards the same goal: ascertaining the integrity of sensor nodes in wireless sensor networks. In this paper we compare the benefits and drawbacks of both techniques and seek to determine how to best combine them. However, our study shows that no single solution exists, as each choice introduces changes in the measurements collection process, affects the attestation protocol, and gives a different balance between the high detection rate of attestation and the low power overhead of measurements inspection. Therefore, we propose three strategies that combine measurements inspection and attestation in different ways, and a way to choose between them based on the requirements of different applications. We analyse their performance both analytically and in a simulator. The results show that the combined strategies can achieve a detection rate close to attestation, in the range 96--99%, whilst keeping a power overhead close to measurements inspection, in the range 1--10%. Vittorio P. Illiano, Rodrigo Vieira Steiner, Emil C. Lupu |
WISEC | 3 |
| 2017 | Don't fool Me!: Detection, Characterisation and Diagnosis of Spoofed and Masked Events in Wireless Sensor NetworksabstractWireless Sensor Networks carry a high risk of being compromised, as their deployments are often unattended, physically accessible and the wireless medium is difficult to secure. Malicious data injections take place when the sensed measurements are maliciously altered to trigger wrong and potentially dangerous responses. When many sensors are compromised, they can collude with each other to alter the measurements making such changes difficult to detect. Distinguishing between genuine and malicious measurements is even more difficult when significant variations may be introduced because of events, especially if more events occur simultaneously. We propose a novel methodology based on wavelet transform to detect malicious data injections, to characterise the responsible sensors, and to distinguish malicious interference from faulty behaviours. The results, both with simulated and real measurements, show that our approach is able to counteract sophisticated attacks, achieving a significant improvement over state-of-the-art approaches. Vittorio P. Illiano, Luis Muñoz-González, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | Efficient Attack Graph Analysis through Approximate InferenceabstractAttack graphs provide compact representations of the attack paths an attacker can follow to compromise network resources from the analysis of network vulnerabilities and topology. These representations are a powerful tool for security risk assessment. Bayesian inference on attack graphs enables the estimation of the risk of compromise to the system’s components given their vulnerabilities and interconnections and accounts for multi-step attacks spreading through the system. While static analysis considers the risk posture at rest, dynamic analysis also accounts for evidence of compromise, for example, from Security Information and Event Management software or forensic investigation. However, in this context, exact Bayesian inference techniques do not scale well. In this article, we show how Loopy Belief Propagation—an approximate inference technique—can be applied to attack graphs and that it scales linearly in the number of nodes for both static and dynamic analysis, making such analyses viable for larger networks. We experiment with different topologies and network clustering on synthetic Bayesian attack graphs with thousands of nodes to show that the algorithm’s accuracy is acceptable and that it converges to a stable solution. We compare sequential and parallel versions of Loopy Belief Propagation with exact inference techniques for both static and dynamic analysis, showing the advantages and gains of approximate inference techniques when scaling to larger attack graphs. Luis Muñoz-González, Daniele Sgandurra, Andrea Paudice, Emil C. Lupu |
ACM Trans. Priv. Secur. | 4 |
| 2016 | Formalizing Threat Models for Virtualized Systems
Daniele Sgandurra, Erisa Karafili, Emil C. Lupu |
DBSec | 3 |
| 2015 | Compositional Reliability Analysis for Probabilistic Component AutomataabstractIn this paper we propose a modelling formalism, Probabilistic Component Automata (PCA), as a probabilistic extension to Interface Automata to represent the probabilistic behaviour of component-based systems. The aim is to support composition of component-based models for both behaviour and non-functional properties such as reliability. We show how additional primitives for modelling failure scenarios, failure handling and failure propagation, as well as other algebraic operators, can be combined with models of the system architecture to automatically construct a system model by composing models of its subcomponents. The approach is supported by the tool LTSA-PCA, an extension of LTSA, which generates a composite DTMC model. The reliability of a particular system configuration can then be automatically analysed based on the corresponding composite model using the PRISM model checker. This approach facilitates configurability and adaptation in which the software configuration of components and the associated composition of component models are changed at run time. Emil C. Lupu, Jeff Kramer |
MiSE@ICSE | 2 |
| 2015 | On re-assembling self-managed componentsabstractSelf-managed systems need to adapt to changes in requirements and in operational conditions. New components or services may become available, others may become unreliable or fail. Non-functional aspects, such as reliability or other quality-of-service parameters usually drive the selection of new architectural configurations. However, in existing approaches, the link between non-functional aspects and software models is established through manual annotations that require human intervention on each re-configuration and adaptation is enacted through fixed rules that require anticipation of all possible changes. We propose here a methodology to automatically re-assemble services and component-based applications to preserve their reliability. To achieve this we define architectural and behavioural models that are composable, account for non-functional aspects and correspond closely to the implementation. Our approach enables autonomous components to locally adapt and control their internal configuration whilst exposing interface models to upstream components. Jeff Kramer, Emil C. Lupu |
IM | 3 |
| 2015 | Detecting Malicious Data Injections in Event Detection Wireless Sensor NetworksabstractWireless sensor networks (WSNs) are vulnerable and can be maliciously compromised, either physically or remotely, with potentially devastating effects. When sensor networks are used to detect the occurrence of events such as fires, intruders, or heart attacks, malicious data can be injected to create fake events, and thus trigger an undesired response, or to mask the occurrence of actual events. We propose a novel algorithm to identify malicious data injections and build measurement estimates that are resistant to several compromised sensors even when they collude in the attack. We also propose a methodology to apply this algorithm in different application contexts and evaluate its results on three different datasets drawn from distinct WSN deployments. This leads us to identify different tradeoffs in the design of such algorithms and how they are influenced by the application context. Vittorio P. Illiano, Emil C. Lupu |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2014 | Associating locations from wearable cameras
Jose Rivera-Rubio, Ioannis Alexiou, Luke Dickens, Riccardo Secoli, Emil C. Lupu, Anil A. Bharath |
BMVC | 5 |
| 2011 | Policy refinement: Decomposition and operationalization for dynamic domains
Robert Craven, Jorge Lobo 0001, Emil C. Lupu, Alessandra Russo, Morris Sloman |
CNSM | 3 |
| 2011 | Inductive Logic Programming in Answer Set Programming
Domenico Corapi, Alessandra Russo, Emil C. Lupu |
ILP | 3 |
| 2010 | An opportunistic authority evaluation scheme for data security in crisis management scenariosabstractWe propose a novel version and implementation of the Policy-based Authority Evaluation Scheme (PAES) to protect data disseminated amongst the responders to an emergency situation when no network connectivity is available. In such situations Delay Tolerant Networks (DTN) are used to disseminate the data by exploiting the peers' mobility in the area. However, existing DTN protection models require recipients to be known in advance. In emergency situations the data may instead be received by unknown responders who might need it while carrying out their duties. Existing data dissemination solutions such Enterprise Rights Management (ERM) systems rely on centralized architectures where recipients must contact the authorities that can grant access to data. Such centralized solutions cannot be deployed when connectivity cannot be guaranteed. Our solution combines data protection schemes such as ERM systems with DTNs. The result allows us to implement a distributed policy evaluation procedure for DTNs. Simulations demonstrate that the approach permits recipients to obtain fast access to protected data even when no authority can be contacted. This is particularly important in crisis situations where timely access to data is necessary. Enrico Scalavino, Giovanni Russello, Rudi Ball, Vaibhav Gowadia, Emil C. Lupu |
AsiaCCS | 5 |
| 2010 | Decomposition techniques for policy refinementabstractThe automation of policy refinement, whilst promising great benefits for policy-based management, has hitherto received relatively little treatment in the literature, with few concrete approaches emerging. In this paper we present initial steps towards a framework for automated distributed policy refinement for both obligation and authorization policies. We present examples drawn from military scenarios, describe details of our formalism and methods for action decomposition, and discuss directions for future research. Robert Craven, Jorge Lobo 0001, Emil C. Lupu, Alessandra Russo, Morris Sloman |
CNSM | 3 |
| 2010 | A Labelling System for Derived Data Control
Enrico Scalavino, Vaibhav Gowadia, Emil C. Lupu |
DBSec | 3 |
| 2010 | Secure cross-domain data sharing architecture for crisis managementabstractCrisis management requires rapid sharing of data among organizations responders. Existing crisis management practices rely on ad hoc or centralized data sharing based on agreements written in natural language. The ambiguity of natural language specifications often leads to errors and can hinder data availability. Therefore, it is desirable to develop automatic data sharing systems. This also presents additional challenges, such as evaluation of security constraints in different administrative domains and in situations with intermittent network connectivity. We compare two different architectural approaches to develop secure data sharing solutions. The first approach assumes reliable network connectivity, while the second approach works in ad hoc networks. We then suggest a unified architecture that caters for both scenarios. Vaibhav Gowadia, Enrico Scalavino, Emil C. Lupu, Dmitry Starostin, Alexey Orlov |
Digital Rights Management Workshop | 3 |
| 2010 | Engineering Policy-Based Ubiquitous SystemsabstractThe advent of miniaturized sensors that can be carried on the body or embedded in the environment, together with ubiquitous ‘smartphones’ with various sensors means that ubiquitous computing systems already pervade our lives. However, for them to ‘disappear’ in the background, they need to be adaptive, autonomous and self-managing. We present an architectural model based on policy-based self-managed cells for engineering ubiquitous computing systems, and discuss issues of security and fault management. We indicate the need for learning adaptive behaviour from users and the importance of formal methods within the engineering design process. Morris Sloman, Emil C. Lupu |
Comput. J. | 2 |
| 2009 | Expressive policy analysis with enhanced system dynamicityabstractDespite several research studies, the effective analysis of policy based systems remains a significant challenge. Policy analysis should at least (i) be expressive (ii) take account of obligations and authorizations, (iii) include a dynamic system model, and (iv) give useful diagnostic information. We present a logic-based policy analysis framework which satisfies these requirements, showing how many significant policy-related properties can be analysed, and we give details of a prototype implementation. Robert Craven, Jorge Lobo 0001, Jiefei Ma, Alessandra Russo, Emil C. Lupu, Arosha K. Bandara |
AsiaCCS | 5 |
| 2009 | PAES: Policy-Based Authority Evaluation Scheme
Enrico Scalavino, Vaibhav Gowadia, Emil C. Lupu |
DBSec | 3 |
| 2009 | Using argumentation logic for firewall configuration managementabstractFirewalls remain the main perimeter security protection for corporate networks. However, network size and complexity make firewall configuration and maintenance notoriously difficult. Tools are needed to analyse firewall configurations for errors, to verify that they correctly implement security requirements and to generate configurations from higher-level requirements. In this paper we extend our previous work on the use of formal argumentation and preference reasoning for firewall policy analysis and develop means to automatically generate firewall policies from higher-level requirements. This permits both analysis and generation to be done within the same framework, thus accommodating a wide variety of scenarios for authoring and maintaining firewall configurations. We validate our approach by applying it to both examples from the literature and real firewall configurations of moderate size (ap 150 rules). Arosha K. Bandara, Antonis C. Kakas, Emil C. Lupu, Alessandra Russo |
Integrated Network Management | 3 |
| 2009 | A Policy-Based Management Architecture for Mobile Collaborative TeamsabstractMany missions are deemed dangerous or impractical to perform by humans, but can use collaborating, self-managing unmanned autonomous vehicles (UAVs) which adapt their behaviour to current context, recover from component failure or optimise performance. This paper describes a policy-based distributed self-management framework for both individual and teams of UAVs. We use three levels of specifications - policy, mission class and mission instance to enable reuse of both policies and mission classes. The architecture has been tested on devices ranging from small laptops to body area networks. Initial evaluation shows the distributed architecture is scalable and outperforms a centralised mission management scheme. Eskindir Asmare, Anandha Gopalan, Morris Sloman, Naranker Dulay, Emil C. Lupu |
PerCom | 5 |
| 2009 | Securing Body Sensor Networks: Sensor Association and Key ManagementabstractBody Sensor Networks can be used to continuously monitor patients' health. However, secure association of sensors with the patient and key management for providing integrity and confidentiality to the sensor readings are essential. We propose a secure discovery protocol based on the synchronised LED blinking pattern, to enable healthcare workers to authorise the sensor-to-patient association. We also propose a novel key distribution and management scheme that uses keychains to establish group keys for body sensor networks and caters for group key update and re-keying to adapt to membership changes. These protocols have been implemented to demonstrate their feasibility and an initial performance evaluation is presented. Sye Loong Keoh, Emil C. Lupu, Morris Sloman |
PerCom | 2 |
| 2009 | Policy conflict analysis for diffserv quality of service managementabstractPolicy-based management provides the ability to (re-)configure differentiated services networks so that desired Quality of Service (QoS) goals are achieved. This requires implementing network provisioning decisions, performing admission control, and adapting bandwidth allocation to emerging traffic demands. A policy-based approach facilitates flexibility and adaptability as policies can be dynamically changed without modifying the underlying implementation. However, inconsistencies may arise in the policy specification. In this paper we provide a comprehensive set of QoS policies for managing Differentiated Services (DiffServ) networks, and classify the possible conflicts that can arise between them. We demonstrate the use of Event Calculus and formal reasoning for the analysis of both static and dynamic conflicts in a semi-automated fashion. In addition, we present a conflict analysis tool that provides network administrators with a user-friendly environment for determining and resolving potential inconsistencies. The tool has been extensively tested with large numbers of policies over a range of conflict types. Marinos Charalambides, Paris Flegkas, George Pavlou, Javier Rubio-Loyola, Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Naranker Dulay, Morris Sloman |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2009 | A lightweight policy system for body sensor networksabstractBody sensor networks (BSNs) for healthcare have more stringent security and context adaptation requirements than required in large-scale sensor networks for environment monitoring. Policy-based management enables flexible adaptive behavior by supporting dynamic loading, enabling and disabling of policies without shutting down nodes. This overcomes many of the limitations of sensor operating systems, such as TinyOS, which do not support dynamic modification of code. Alternative schemes for adaptation, such as network programming, have a high communication cost and suffer from operational interruption. In addition, a policy-driven approach enables fine-grained access control through specifying authorization policies. This paper presents the design, implementation and evaluation of an efficient policy system called Finger which enables policy interpretation and enforcement on distributed sensors to support sensor level adaptation and fine-grained access control. It features support for dynamic management of policies, minimization of resources usage, high responsiveness and node autonomy. The policy system is integrated as a TinyOS component, exposing simple, well-defined interfaces which can easily be used by application developers. The system performance in terms of processing latency and resource usage is evaluated. Yanmin Zhu 0006, Sye Loong Keoh, Morris Sloman, Emil C. Lupu |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2008 | Panel Session: What Are the Key Challenges in Distributed Security?
Steve Barker, David W. Chadwick, Jason Crampton, Emil C. Lupu, Bhavani Thuraisingham |
DBSec | 4 |
| 2008 | An Efficient Policy System for Body Sensor NetworksabstractBody sensor networks (BSNs) have become a promising technology for healthcare, in which biosensors continuously monitor physiological parameters of a user. Distinct from conventional sensor networks for environmental monitoring, such networks need to be adaptive and can therefore be easily managed. In addition, security becomes a necessity. To this end, we design a policy system that implements policy-driven management on the sensor level. Biosensor adaptability is realized through support of dynamic loading, enabling and disabling of policies without shutting down nodes. In addition, fine-grained access control becomes possible through authorization policies on biosensors. Design and implementation details of the policy system are presented. Experimental results demonstrate that the policy system is viable and can accelerate application development of biosensor networks for healthcare. Yanmin Zhu 0006, Sye Loong Keoh, Morris Sloman, Emil C. Lupu, Naranker Dulay, Nat Pryce |
ICPADS | 4 |
| 2008 | Finger: An efficient policy system for body sensor networksabstractBody sensor networks (BSNs) for healthcare put more emphasis on security and adaptation to changes in context and application requirement. Policy-based management enables flexible adaptive behaviour by supporting dynamic loading, enabling and disabling of policies without shutting down nodes. This overcomes many of the limitations of sensor operating systems, such as TinyOS, which do not support dynamic modification of code. Alternative schemes for network adaptation, such as networking programming, suffer from high communication cost and operational interruption. In addition, the policy-driven approach enables fine-grained access control through specifying authorization policies. This paper presents an efficient policy system called finger which enables policy interpretation and enforcement on distributed sensors to support sensor level adaptation and fine-grained access control. It features support for dynamic management of policies, minimization of resources usage, high responsiveness and node autonomy. The policy system is integrated as a TinyOS component, exposing simple, well-defined interfaces which can easily be used by application developers. The system performance in terms of processing latency and resource usage is evaluated. Yanmin Zhu 0006, Sye Loong Keoh, Morris Sloman, Emil C. Lupu, Naranker Dulay, Nat Pryce |
MASS | 4 |
| 2008 | AMUSE: autonomic management of ubiquitous e-Health systemsabstractAbstract Future e‐Health systems will consist of low‐power on‐body wireless sensors attached to mobile users that interact with an ubiquitous computing environment to monitor the health and well being of patients in hospitals or at home. Patients or health practitioners have very little technical computing expertise so these systems need to be self‐configuring and self‐managing with little or no user input. More importantly, they should adapt autonomously to changes resulting from user activity, device failure, and the addition or loss of services. We propose the Self‐Managed Cell (SMC) as an architectural pattern for all such types of ubiquitous computing applications and use an e‐Health application in which on‐body sensors are used to monitor a patient living in their home as an exemplar. We describe the services comprising the SMC and discuss cross‐SMC interactions as well as the composition of SMCs into larger structures. Copyright © 2007 John Wiley & Sons, Ltd. Emil C. Lupu, Naranker Dulay, Morris Sloman, Joseph S. Sventek, Steven Heeps, Stephen D. Strowes, Kevin P. Twidle, Sye Loong Keoh, Alberto E. Schaeffer Filho |
Concurr. Comput. Pract. Exp. | 1 |
| 2008 | Reconfigurable Architecture for Network Flow AnalysisabstractThis paper describes a reconfigurable architecture based on field-programmable gate-array (FPGA) technology for monitoring and analyzing network traffic at increasingly high network data rates. Our approach maps the performance-critical tasks of packet classification and flow monitoring into reconfigurable hardware, such that multiple flows can be processed in parallel. We explore the scalability of our system, showing that it can support flows at multi-gigabit rate; this is faster than most software-based solutions where acceptable data rates are typically no more than 100 million bits per second. Sherif Yusuf, Wayne Luk, Morris Sloman, Naranker Dulay, Emil C. Lupu, Geoffrey Brown |
IEEE Trans. Very Large Scale Integr. Syst. | 5 |
| 2007 | Self-Managed Cell: A Middleware for Managing Body-Sensor NetworksabstractBody sensor networks consisting of low-power on- body wireless sensors attached to mobile users will be used in the future to monitor the health and well being of patients in hospitals or at home. Such systems need to adapt autonomously to changes in context, user activity, device failure, and the availability or loss of services. To this end, we propose a policy- based architecture that uses the concept of a Self-Managed Cell (SMC) to integrate services, managed resources and a policy interpreter by means of an event bus. Policies permit the declarative specification of adaptation strategy for self- configuration and self-management. We present the design and implementation of the SMC and describe its potential use in a scenario for management of heart monitoring. Preliminary performance measurements are also presented and discussed. Sye Loong Keoh, Naranker Dulay, Emil C. Lupu, Kevin P. Twidle, Alberto E. Schaeffer Filho, Morris Sloman, Steven Heeps, Stephen D. Strowes, Joseph S. Sventek |
MobiQuitous | 3 |
| 2006 | Dynamic Policy Analysis and Conflict Resolution for DiffServ Quality of Service ManagementabstractPolicy-based dynamic resource management may involve interaction between independent decision-making components which can lead to conflicts. For example, conflicts can occur between the policies for allocating resources and those setting quotas for users or classes of service. These policy conflicts cannot be detected by static analysis of the policies at specification-time as the conflicts arise from the current state of the resources within the system and so can only be detected at run-time. In this paper we use policies related to quality of service (QoS) provisioning for configuring differentiated services (DiffServ) networks to illustrate techniques for the dynamic detection and resolution of conflicts. Configuration includes implementing network provisioning decisions, performing admission control, and adapting bandwidth allocation dynamically according to emerging traffic demands. We identify possible conflicts between policies that manage the allocation of resources, and we also investigate conflicts that may arise between these policies and higher-level directives refined at the dynamic resource management level, acting as constraints. The paper shows how event calculus can be used to detect conflicts, focusing on the ones that emerge at run-time, and provides an approach for specifying policies to automate conflict resolution. The latter is demonstrated through our initial implementation of a dynamic conflict analysis tool Marinos Charalambides, Paris Flegkas, George Pavlou, Javier Rubio-Loyola, Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Morris Sloman, Naranker Dulay |
NOMS | 6 |
| 2006 | Policy refinement for IP differentiated services Quality of Service managementabstractPolicy-based management provides the ability to dynamically re-configure DiffServ networks such that desired Quality of Service (QoS) goals are achieved. This includes network provisioning decisions, performing admission control, and adapting bandwidth allocation dynamically. QoS management aims to satisfy the Service Level Agreements (SLAs) contracted by the provider and therefore QoS policies are derived from SLA specifications and the provider's business goals. This policy refinement is usually performed manually with no means of verifying that the policies written are supported by the network devices and actually achieve the desired QoS goals. Tool support is lacking and policy refinement has rarely been addressed in the literature. This paper extends our previous approach to policy refinement and shows how to apply it to the domain of DiffServ QoS management. We make use of goal elaboration and abductive reasoning to derive strategies that will achieve a given high-level goal. By combining these strategies with events and constraints, we show how policies can be refined, and what tool support can be provided for the refinement process using examples from the QoS management domain. The approach presented here can be used in other application domains such as storage area networks or security management. Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Naranker Dulay, Morris Sloman, Paris Flegkas, Marinos Charalambides, George Pavlou |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2005 | Toward Web Services Profiles for Trust and Security in Virtual OrganisationsabstractThe rise in practical Virtual Organisations (VOs) requires secure access to data and interactions between their partners. Ad hoc solutions to meet these requirements are possible, but Web services hold out the potential for generic security solutions whose cost can be spread across several short lived dynamic VOs. This paper identifies trust and security requirements throughout the VO lifecycle and analyse current Web Services specifications to show their suitability to meet these requirements. Although they demonstrate the potential for generic security support, there are uncertainties concerning different level of interoperability and stability of implementation for different specifications, which may slow down their exploitation for security-critical business applications. However, research in Web services developments are well timed to avoid losing first adopter advantage when they become stable. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Álvaro Enrique Arenas, Ivan Djordjevic, Theodosis Dimitrakos, Leonid Titkov, Joris Claessens, Christian Geuer-Pollmann, Emil C. Lupu, Nilufer Tuptuk, Stefan Wesner, Lutz Schubert |
PRO-VE | 7 |
| 2005 | Policy refinement for DiffServ quality of service managementabstractPolicy-based management provides the ability to dynamically re-configure DiffServ networks such that desired quality of service (QoS) goals are achieved. This includes network provisioning decisions, performing admission control, and adapting bandwidth allocation dynamically. QoS management aims to satisfy the service level agreements (SLAs) contracted by the provider and therefore QoS policies are derived from SLA specifications and the provider's business goals. This policy refinement is usually performed manually with no means of verifying that the policies written are supported by the network devices and actually achieve the desired QoS goals. Tool support is lacking and policy refinement has rarely been addressed in the literature. This paper extends our previous approach to policy refinement and shows how to apply it to the domain of DiffServ QoS management. We make use of goal elaboration and abductive reasoning to derive strategies that achieves a given high-level goal. By combining these strategies with events and constraints, we show how policies can be refined, and what tool support can be provided for the refinement process using examples from the QoS management domain. However, the approach presented here can be used in other application domains such as storage area networks or security management. Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Naranker Dulay, Morris Sloman, Paris Flegkas, Marinos Charalambides, George Pavlou |
Integrated Network Management | 2 |
| 2004 | PEACE: A Policy-Based Establishment of Ad-hoc CommunitiesabstractAd-hoc networks are perceived as communities of autonomous devices that interconnect with each other. Typically, they have dynamic topologies and cannot rely on a continuous connection to the Internet. Users' devices often do not have a priori knowledge of each other and cannot rely upon pre-existing shared information. This introduces difficult security issues when attempting to provide authentication, membership management and access control. Designing a framework, which allows the secure establishment and management of ad-hoc communities, remains a significant challenge. In this paper, we propose a novel policy-based security framework to facilitate the establishment, evolution and management of mobile ad-hoc networks. We introduce a community specification, called doctrine, which defines the roles of the participants in the community, the characteristics that participants must exhibit in order to be eligible to play a role, as well as the policies governing their behaviour within the community. Based on the doctrine, we propose a set of security protocols to bootstrap the community, manage the membership, and govern the access to the services provided by the participants. We have investigated the impact of mobility on the proposed security protocols and observed that the protocol is robust to changes in the network topology. Sye Loong Keoh, Emil C. Lupu, Morris Sloman |
ACSAC | 2 |
| 2004 | PONDER policy implementation and validation in a CIM and differentiated services frameworkabstractPolicies are often used to define management strategies for networks, storage services or applications. Validation determines whether the policy implementation is feasible for the specific environment to which it applies and requires checking that the policy is consistent with the functional or resource constraints within the target environment. For example, do the policies assume functionality or specific operations which do not exist in target routers, or bandwidth in excess of the capacity of data links? Where possible, static checking should be done prior to policy deployment in order to detect invalid policies at design time, but there are some policies, related to resource allocation, that depend on the current state of the system, and require policy constraints that must be checked dynamically at execution time. We show how PONDER policies can be implemented and validated for differentiated services (DiffServ) by using CIM (Common Information Model) as the modelling framework for network resources, as this is device independent. We describe a CIM DiffServ-metrics sub-model extension of the CIM Network sub-model which represents DiffServ traffic statistics and a Linux driver which translates CIM classes and variables to Linux traffic control classes and variables respectively. Leonidas Lymberopoulos, Emil C. Lupu, Morris Sloman |
NOMS (1) | 2 |
| 2003 | Compiling Policy Descriptions into Reconfigurable Firewall ProcessorsabstractWe describe a framework for capturing firewall requirements as high-level descriptions based on the policy specification language Ponder. The framework provides abstraction from hardware implementation while allowing performance control through constraints. Our hardware compilation strategy for such descriptions involves a rule reduction step to produce a hardware firewall rule representation. Three main methods have also been developed for resource optimization: partitioning; elimination; and sharing. A case study involving five sets of filter rules indicates that it is possible to reduce 67-80% of hardware resources over techniques based on regular content-addressable memory, and 24-63% over methods based on irregular content-addressable memory. Sherif Yusuf, Wayne Luk, Morris Sloman, Emil C. Lupu, Naranker Dulay |
FCCM | 5 |
| 2003 | Irregular Reconfigurable CAM Structures for Firewall Applications
Sherif Yusuf, Wayne Luk, Morris Sloman, Emil C. Lupu, Naranker Dulay |
FPL | 5 |
| 2003 | Indoor location estimation using multiple wireless technologiesabstractFuture mobile devices will increasingly have multiple sources of location information associated with them, such as GPS, cellular cell-sector ID, Bluetooth or 802.11 wireless LAN. In fact, cellular phones with GPS receivers and 802.11 wireless LAN are already becoming available. However, not all location technologies will operate everywhere (e.g. GPS typically will not work indoors whereas 802.11 coverage may be available) and they typically have different accuracies and range. This paper presents an experimental study of the feasibility of using multiple wireless technologies simultaneously for location estimation. We have collected signal strength information from both IEEE 802.11 and Bluetooth wireless network technologies, developed and applied algorithms for determining location using data for each wireless technology, and then used a simple algorithm for fusing the location estimates from both technologies to try to enhance the accuracy of the location estimates. Dhruv Pandya, Ravi Jain, Emil C. Lupu |
PIMRC | 3 |
| 2002 | Workflow-Based Composition of Web-Services: A Business Model or a Programming Paradigm?abstractWhile SOAP/XML is perceived as the appropriate interoperability level for Web-services, companies compete to provide workflow-based tools for Web-service integration. This paper presents the design and implementation of a prototype workflow management system for building new Web-services from a workflow of existing Web-services. This enables the creation of multiple layers of value-added service providers and provides fast service creation, customisation and deployment. The system caters for multiple workflow paradigms, provides an extensible language for workflow specification and emphasises encapsulation and tight constraints on workflow execution. To expose a workflow of Web-services as a Web-service, several design steps have been required including the deployment as a Web-service of the generic workflow engine and a generalisation of the Visitor Pattern to concurrent visitors. Dinesh Ganesarajah, Emil C. Lupu |
EDOC | 2 |
| 2002 | Development framework for firewall processorsabstractHigh-performance firewalls can benefit from the increasing size, speed and flexibility of advanced reconfigurable hardware. However direct translation of conventional firewall rules in a router-based rule set often leads to inefficient hardware implementation. Moreover, such lowlevel description of firewall rules tends to be difficult to manage and to extend. We describe a framework, based on the high-level policy specification language Ponder for capturing firewall rules as authorization policies with user-definable constraints. Our framework supports optimisations to achieve efficient utilisation of hardware resources. A pipelined firewall implementation developed using this approach running at 10 MHz is capable of processing 2.5 million packets per second, which provides similar performance to a version without optimisation and is about 50 times faster than a software implementation running on a 700 MHz PIII processor. Sherif Yusuf, Wayne Luk, Morris Sloman, Emil C. Lupu, Naranker Dulay |
FPT | 5 |
| 2002 | Tools for domain-based policy management of distributed systemsabstractThe management of policies in large-scale systems is complex because of the potentially large number of policies and administrators, as well as the diverse types of information that need to be managed. Appropriate tool support is essential to make management practical and feasible. In this paper we present the implementation of an integrated toolkit for the specification, deployment and management of policies specified in the PONDER language. PONDER policies provide a powerful framework for managing distributed systems which includes explicit domain-based subject and target specifications as well as a flexible life-cycle and deployment model. Domains, implemented using LDAP directories, are used for storing policies and grouping resources, people, and the entities which implement policy, thus facilitating the automated dissemination of policy information. The toolkit presented in this paper comprises: a policy compiler, used to generate implementation code for heterogeneous management and security platforms, a hyperbolic tree viewer for efficient manipulation of the domain structure and effective navigation across the domains, and various tools for deploying and managing the policy life-cycle. Nicodemos Damianou, Naranker Dulay, Emil C. Lupu, Morris Sloman, Toshio Tonouchi |
NOMS | 3 |
| 2001 | A Policy Deployment Model for the Ponder LanguageabstractPolicies are rules that govern the choices in behaviour of a system. Security policies define what actions are permitted or not permitted, for what or for whom, and under what conditions. Management policies define what actions need to be carried out when specific events occur within a system or what resources must be allocated under specific conditions. There is considerable interest in the use of policies for the security and management of large-scale networks and distributed services. Existing policy work has focussed on specification, information models and application-specific policy enforcement. We address the important goal of providing a general-purpose deployment model for policies that is independent of the underlying policy enforcement mechanisms and can be employed in mixed policy environments. In this paper, we present a deployment model that is object-oriented and addresses the instantiation, distribution and enabling of policies as well as the disabling, unloading and deletion of policies. The model defines objects for policies, for domains, and for the policy enforcement agent and outlines the interactions needed between them. The model also caters for changes in the memberships of domains since such changes also effect policy enforcement. The model forms part of the run-time support for Ponder; a new policy language that combines structuring ideas from object-oriented languages with a common set of policy basic types. Naranker Dulay, Emil C. Lupu, Morris Sloman, Nicodemos Damianou |
Integrated Network Management | 2 |
| 2001 | Selected Topics in Network and Systems Management
Emil C. Lupu, Subrata Mazumdar, Rolf Stadler |
Comput. Networks | 1 |
| 2000 | A Flexible Access Control Service for Java Mobile CodeabstractMobile code (MC) technologies provide appealing solutions for the development of Internet applications. For instance, Java technology facilitates dynamic loading of application code from remote servers on to heterogeneous clients distributed all over the Internet. However, executing foreign code that has been loaded from the network raises significant security concerns which limit the diffusion of these technologies. Substantial work has already been done to provide security solutions for protecting both hosting nodes and MC. For example, the Java security architecture evolved from a rigid sandbox model to a more flexible solution where downloaded code can perform any kind of operation, depending on its source location and signature. However, the most widespread security solutions for MC platforms today do not support the sophisticated security policies required in modern inter-organisational environments. This requires expressive languages to specify the policy and flexible mechanisms for policy implementation which cater for code mobility. This paper shows how access control policies for MC-based applications can be specified in a concise and declarative language called Ponder, and how these policies can be implemented within the Java security architecture. Antonio Corradi, Rebecca Montanari, Cesare Stefanelli, Emil C. Lupu, Morris Sloman |
ACSAC | 4 |
| 2000 | Ponder: Realising Enterprise Viewpoint ConceptsabstractThis paper introduces the Ponder language for specifying distributed object enterprise concepts. Ponder, is a declarative language, which permits the specification of policies in terms of obligations, permissions and prohibitions and provides the means for defining roles, relationships and their configurations in nested communities. Ponder provides a concrete representation of most of the concepts of the Enterprise Viewpoint. The design of the language incorporates lessons drawn from several years of research on policy for security and distributed systems management as well as policy conflict analysis. The various language constructs are presented through a scenario for the operation, administration and maintenance of a mobile telecommunication network. Emil C. Lupu, Morris Sloman, Naranker Dulay, Nicodemos Damianou |
EDOC | 1 |
| 1999 | Can Corba save a fringe language from becoming obsolete?
Susan Eisenbach, Emil C. Lupu, Karen Meidl, Hani Rizkallah |
DAIS | 2 |
| 1999 | Conflicts in Policy-Based Distributed Systems ManagementabstractModern distributed systems contain a large number of objects and must be capable of evolving, without shutting down the complete system, to cater for changing requirements. There is a need for distributed, automated management agents whose behavior also has to dynamically change to reflect the evolution of the system being managed. Policies are a means of specifying and influencing management behavior within a distributed system, without coding the behavior into the manager agents. Our approach is aimed at specifying implementable policies, although policies may be initially specified at the organizational level and then refined to implementable actions. We are concerned with two types of policies. Authorization policies specify what activities a manager is permitted or forbidden to do to a set of target objects and are similar to security access-control policies. Obligation policies specify what activities a manager must or must not do to a set of target objects and essentially define the duties of a manager. Conflicts can arise in the set of policies. Conflicts may also arise during the refinement process between the high level goals and the implementable policies. The system may have to cater for conflicts such as exceptions to normal authorization policies. The paper reviews policy conflicts, focusing on the problems of conflict detection and resolution. We discuss the various precedence relationships that can be established between policies in order to allow inconsistent policies to coexist within the system and present a conflict analysis tool which forms part of a role based management framework. Software development and medical environments are used as example scenarios. Emil C. Lupu, Morris Sloman |
IEEE Trans. Software Eng. | 1 |
| 1997 | A Policy Based Role Object ModelabstractEnterprise roles define the duties and responsibilities of the individuals which are assigned to them. This paper introduces a framework for the management of large distributed systems which makes use of the concepts developed in role theory. Our concept of a role groups the specifications of management policies which define the rights and duties corresponding to that role. Individuals may then be assigned to or withdrawn from a role, to enable rapid and flexible organisational change, without altering the specification of the policies. We extend this role concept to include relationships as means of specifying required interactions, duties and rights between related roles. Organisations may contain large numbers of similar roles with multiple relationships between them, so there is a need for reuse of specifications. Role and relationship classes permit multiple instantiation and inheritance used for incremental extension of the organisational structure with minimal specification effort. We also briefly examine consistency and auditing issues related to this role framework. Emil C. Lupu, Morris Sloman |
EDOC | 1 |
| 1997 | Conflict Analysis for Management Policies
Emil C. Lupu, Morris Sloman |
Integrated Network Management | 1 |