EDBT 2026 Demo / reviewers in the wild / expert
Stuart E. Madnick
dblp:m/StuartEMadnick
· DBLP profile ↗
46ranked-venue papers
7as first author
4since 2021 · last 2025
0000-0001-9240-2573ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 28 · 5 first-author · 1 since 2021Artificial intelligence and machine learning · 8 · 2 first-authorSoftware engineering, systems software and programming languages · 5 · 1 first-authorSecurity and privacy · 4 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2Computer networks · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Weathering the storm: examining how organisations navigate the sea of cybersecurity regulationsabstractGovernments around the world routinely regulate the activities of private enterprises to guide the behaviour of individuals and organisations towards acceptable norms. This holds true in a cybersecurity context. However, practitioners report that cybersecurity regulations are often out of date and compliance is confusing, expensive, and time consuming. As a result, organisational leaders are often uncertain about the practicalities of adopting and implementing the various rules, which can lead to trickle-down effects on the robustness of lower-level cybersecurity controls and compliance activities. In this research, we aim to clarify how cybersecurity regulations are operationalised in organisations, as well as reveal the compliance and performance consequences of cybersecurity regulations. To do so, we interviewed 22 senior leaders with expertise in cybersecurity regulations. Our analysis reveals 7 distinct themes (i.e., concept groupings) that are ordered within four phases (i.e., temporal stages), which we use to create the Institutional Cybersecurity Regulations Model (ICRM). The results provide a holistic view of the cybersecurity regulations process in organisations that can serve to clarify current theory relationships and inform future research. As well, the ICRM can provide a practical roadmap for managers to navigate regulatory cybersecurity challenges in their own companies. Jeffrey Proudfoot, W. Alec Cram, Stuart E. Madnick |
Eur. J. Inf. Syst. | 3 |
| 2023 | Regulating Cyber Incidents: A Review of Recent Reporting Requirements
Angelica Marotta, Stuart E. Madnick |
SECRYPT | 2 |
| 2023 | A Systematic Analysis of the Capital One Data Breach: Critical Lessons LearnedabstractThe 2019 Capital One data breach was one of the largest data breaches impacting the privacy and security of personal information of over a 100 million individuals. In most reports about a cyberattack, you will often hear that it succeeded because a single employee clicked on a link in a phishing email or forgot to patch some software, making it seem like an isolated, one-off, trivial problem involving maybe one person, committing a mistake or being negligent. But that is usually not the complete story. By ignoring the related managerial and organizational failures, you are leaving in place the conditions for the next breach. Using our Cybersafety analysis methodology, we identified control failures spanning control levels, going from rather technical issues up to top management, the Board of Directors, and Government regulators. In this analysis, we reconstruct the Capital One hierarchical cyber safety control structure, identify what parts failed and why, and provide recommendations for improvements. This work demonstrates how to discover the true causes of security failures in complex information systems and derive systematic cybersecurity improvements that likely apply to many other organizations. It also provides an approach that individuals can use to evaluate and better secure their organizations. Shaharyar Khan, Ilya Kabanov, Yunke Hua, Stuart E. Madnick |
ACM Trans. Priv. Secur. | 4 |
| 2022 | Cybersafety: A System-Theoretic Approach to Identify Cyber-Vulnerabilities & Mitigation Requirements in Industrial Control SystemsabstractRecent cyber-physical attacks, such asStuxnet, Tritonetc., have invoked an ominous realization about the vulnerability of critical infrastructure, including water, power and gas distribution systems. Traditional IT security-biased protection methods that focus on improvingcyber hygieneare largely impotent in the face of targeted attacks by advanced cyber-adversaries. Thus, there is an urgent need to analyze the safety and security of critical infrastructure in a holistic fashion, leveraging thephysicsof the cyber-physical system. System-Theoretic Accident Model & Processes (STAMP) offers a powerful framework to analyze complex systems; hitherto, STAMP has been used extensively to perform safety analyses but an integrated safety and cybersecurity analysis of industrial control systems (ICS) has not been published. This paper uses the electrical generation and distribution system of an archetypal industrial facility to demonstrate the application of a STAMP-based method – calledCybersafety– to identify and mitigate cyber-vulnerabilities in ICS. The key contribution of this work is to differentiate the additional steps required to perform a holistic cybersecurity analysis for an ICS of significant size and complexity and to present the analysis in a structured format that can be emulated for larger systems with many interdependent subsystems. Shaharyar Khan, Stuart E. Madnick |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Decision-making and biases in cybersecurity capability development: Evidence from a simulation game experimentabstractWe developed a simulation game to study the effectiveness of decision-makers in overcoming two complexities in building cybersecurity capabilities: potential delays in capability development; and uncertainties in predicting cyber incidents. Analyzing 1479 simulation runs, we compared the performances of a group of experienced professionals with those of an inexperienced control group. Experienced subjects did not understand the mechanisms of delays any better than inexperienced subjects; however, experienced subjects were better able to learn the need for proactive decision-making through an iterative process. Both groups exhibited similar errors when dealing with the uncertainty of cyber incidents. Our findings highlight the importance of training for decision-makers with a focus on systems thinking skills, and lay the groundwork for future research on uncovering mental biases about the complexities of cybersecurity. Mohammad S. Jalali, Michael D. Siegel, Stuart E. Madnick |
J. Strateg. Inf. Syst. | 3 |
| 2018 | A Systems Theoretic Approach to the Security Threats in Cyber Physical Systems Applied to StuxnetabstractCyber physical systems (CPSs) are increasingly being adopted in a wide range of industries such as smart power grids. Even though the rapid proliferation of CPSs brings huge benefits to our society, it also provides potential attackers with many new opportunities to affect the physical world such as disrupting the services controlled by CPSs. Stuxnet is an example of such an attack that was designed to interrupt the Iranian nuclear program. In this paper, we show how the vulnerabilities exploited by Stuxnet could have been addressed at the design level. We utilize a system theoretic approach, based on prior research on system safety, that takes both physical and cyber components into account to analyze the threats exploited by Stuxnet. We conclude that such an approach is capable of identifying cyber threats towards CPSs at the design level and provide practical recommendations that CPS designers can utilize to design a more secure CPS. Arash Nourian, Stuart E. Madnick |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | A Context-Based Approach to Reconciling Data Interpretation Conflicts in Web Services CompositionabstractWe present a comprehensive classification of data misinterpretation problems and develop an approach to automatic detection and reconciliation of data interpretation conflicts in Web services composition. The approach uses a lightweight ontology augmented with modifiers, contexts, and atomic conversions between the contexts. The WSDL descriptions of Web services are annotated to establish correspondences to the ontology. Given the naive Business Process Execution Language (BPEL) specification of the desired Web services composition with data interpretation conflicts, the approach can automatically detect the conflicts and produce the corresponding mediated BPEL. Finally, we develop a prototype to validate and evaluate the approach. Xitong Li, Stuart E. Madnick, Hongwei Zhu 0002 |
ACM Trans. Internet Techn. | 2 |
| 2012 | Semantic distances for technology landscape visualization
Wei Lee Woon, Stuart E. Madnick |
J. Intell. Inf. Syst. | 2 |
| 2010 | A pattern-based approach to protocol mediation for web services composition
Xitong Li, Yushun Fan, Stuart E. Madnick, Quan Z. Sheng |
Inf. Softw. Technol. | 3 |
| 2009 | An Approach to Composing Web Services with Context HeterogeneityabstractThe potential benefits of Web services composition heavily rely on semantic interoperability, i.e., the ability to exchange data meaningfully amongst Web services. Context heterogeneity, which refers to different implicit assumptions about interpreting the exchanged data, hampers the automatic composition of Web services. However, existing initiatives of semantic Web services (SWSs) often ignore context heterogeneity. In this paper, we introduce an approach to address this issue. The contexts of the involved Web services are defined in a lightweight ontology and their WSDL descriptions are annotated by an extension of a W3C standard, i.e., semantic annotation for WSDL and XML schema (SAWSDL). The composition of Web services is described using BPEL specification. Given a BPEL file that ignores context heterogeneity, the approach automatically detects all context differences among the involved services, and reconciles them by producing a mediated BPEL file that incorporates necessary conversions using Xpath functions and/or Web services. Xitong Li, Stuart E. Madnick, Hongwei Zhu 0002, Yushun Fan |
ICWS | 2 |
| 2009 | General Strategy for Querying Web Sources in a Data Federation EnvironmentabstractModern database management systems are supporting the inclusion and querying of non-relational sources within a data federation environment via wrappers. Wrapper development for Web sources, however, is a convolution of code with extraction and query planning knowledge and becomes a daunting task. We use IBM DB2 federation engine to demonstrate the challenges of incorporating Web sources into a data federation. We, then, present a practical and general strategy for the inclusion and querying of Web sources without requiring any changes in the underlying data federation technology. This strategy separates the code and knowledge in wrapper development by introducing a general-purpose capabilities-aware mini query-planner and a data extraction engine. As a result, Web sources can be included in a data federation system faster, and maintained easier. Aykut Firat, Lynn Wu, Stuart E. Madnick |
J. Database Manag. | 3 |
| 2009 | Asymmetric information distances for automated taxonomy construction
Wei Lee Woon, Stuart E. Madnick |
Knowl. Inf. Syst. | 2 |
| 2006 | Improving data quality through effective use of data semantics
Stuart E. Madnick, Hongwei Zhu 0002 |
Data Knowl. Eng. | 1 |
| 2004 | Effective Data Integration in the Presence of Temporal Semantic ConflictsabstractThe change in meaning of data over time poses significant challenges for the use of that data. These challenges exist in the use of an individual data source and are further compounded with the integration of multiple sources. In this paper, we identify three types of temporal semantic heterogeneities. We propose a solution based on extensions to the context interchange framework, which has mechanisms for capturing semantics using ontology and temporal context. It also provides a mediation service that automatically resolves semantic conflicts. We show the feasibility of this approach with a prototype that implements a subset of the proposed extensions. Hongwei Zhu 0002, Stuart E. Madnick, Michael D. Siegel |
TIME | 2 |
| 2004 | Asynchronous Backup and Initialization of a Database Server for Replicated Database Systems
Subhash Bhalla, Stuart E. Madnick |
J. Supercomput. | 2 |
| 2003 | Oh, so That Is What You Meant! The Interplay of Data Quality and Data Semantics
Stuart E. Madnick |
ER | 1 |
| 2002 | DIRECT: a system for mining data value conversion rules from disparate data sources
Weiguo Fan, Hongjun Lu, Stuart E. Madnick, David Wai-Lok Cheung |
Decis. Support Syst. | 3 |
| 2001 | Discovering and reconciling value conflicts for numerical data integration
Weiguo Fan, Hongjun Lu, Stuart E. Madnick, David Wai-Lok Cheung |
Inf. Syst. | 3 |
| 2000 | Context Knowledge Representation and Reasoning in the Context Interchange System
Stéphane Bressan, Cheng Hian Goh, Natalia Levina, Stuart E. Madnick, Ahmed Shah, Michael D. Siegel |
Appl. Intell. | 4 |
| 1999 | Information Integration with Attributio Support for Corporate ProfilesabstractThe proliferation of electronically available data within large organizations as well as publicly available data (e.g. over the World Wide Web) poses challenges for users who wish to efficiently interact with and integrate multiple heterogeneous sources. This paper presents CI3, a corporate information integrator, which applies XML as a tool to facilitate data mediation and integration amongst heterogeneous sources in the context of financial analysts creating corporate profiles. Sources include Lotus Notes, relational databases, and the World Wide Web. CI3 applies a unified XML data model to automate integration. By preserving metadata about the source of each datum in the integrated result set, CI3 supports source attribution. Users may trace the attribution metadata from the result back to the underlying sources and leverage their expertise in interpreting the data and, if necessary, use their judgment in assessing the authenticity and veracity of results. We present a functional overview of CI3, its system architecture including the XML data model, and the integration procedures. We conclude by reflecting on lessons learned. Thomas Lee, Melanie Chams, Robert A. Nado, Michael D. Siegel, Stuart E. Madnick |
CIKM | 5 |
| 1999 | e-Commerce Bargain-Hunting with an UnBun ModelabstractFirst-generation comparison-shopping software tools in general have limitations in dealing with bundled products. A new generic model for e-commerce comparison-shopping, based on a logical unBundling of sellers' offerings, is presented. The model captures dominance relationship between offerings and consumer requirements and may serve as a foundation for a variety of shopping decision support software tools. The model provides a basis for defining notions of bargains and designing algorithms for searching for them. Various implications and remaining challenges are outlined. Raphael Yahalom, Stuart E. Madnick |
CoopIS | 2 |
| 1999 | Context Interchange: New Features and Formalisms for the Intelligent Integration of InformationabstractTheContext Interchange strategypresents a novel perspective for mediated data access in which semantic conflicts among heterogeneous systems are not identified a priori, but are detected and reconciled by acontext mediatorthrough comparison ofcontexts axiomscorresponding to the systems engaged in data exchange. In this article, we show that queries formulated on shared views, export schema, and shared “ontologies” can be mediated in the same way using theContext Interchange framework. The proposed framework provides a logic-based object-oriented formalsim for representing and reasoning about data semantics in disparate systems, and has been validated in a prototype implementation providing mediated data access to both traditional and web-based information sources. Cheng Hian Goh, Stéphane Bressan, Stuart E. Madnick, Michael D. Siegel |
ACM Trans. Inf. Syst. | 3 |
| 1998 | Context Mediation on Wall StreetabstractThe paper reports on a practical implementation of a context mediator for the fixed income securities industry. The authors describe industry circumstances and the data and calculation services (DCS) mediator developed and deployed in the early 1990s. The mediator was designed as an interpretive engine controlled by a static declarative knowledge structure and client preference data. In addition to heterogeneous, autonomous data sources, the mediator integrated autonomously developed local and remote procedural components. Client access to both data and computational resources were provided through an active conceptual model. Structural and semantic context conversions were used to integrate disparate components and to support varying client needs. Lessons learned from the implementation and usage of this mediator provide insight into the requirements for a successful context mediator. Allen Moulton, Stuart E. Madnick, Michael D. Siegel |
CoopIS | 2 |
| 1998 | An Active Conceptual Model for Fixed Income Securities Analysis for Multiple Financial Institutions
Allen Moulton, Stéphane Bressan, Stuart E. Madnick, Michael D. Siegel |
ER | 3 |
| 1997 | The COntext INterchange Mediator PrototypeabstractThe Context Interchange strategy presents a novel approach for mediated data access in which semantic conflicts among heterogeneous systems are not identified a priori, but are detected and reconciled by a context mediator through comparison of contexts. This paper reports on the implementation of a Context Interchange Prototype which provides a concrete demonstration of the features and benefits of this integration strategy. Stéphane Bressan, Cheng Hian Goh, Kofi Fynn, Marta Jessica Jakobisiak, Karim Hussein, Henry B. Kon, Thomas Lee, Stuart E. Madnick, Tito Pena, Jessica Qu, Annie W. Shum, Michael D. Siegel |
SIGMOD Conference | 8 |
| 1996 | Are We Moving Toward an Information SuperHighway or a Tower of Babel? The Challenge of Large-Scale Semantic HeterogeneityabstractThe popularity and growth of the "information superhighway" have dramatically increased the number of information sources available for use. Unfortunately, there are significant challenges to be overcome. One particular problem is context interchange, whereby each source of information and potential receiver of that information may operate with a different context, leading to large-scale semantic heterogeneity. A context is the collection of implicit assumptions about the context definition (i.e. meaning) and context characteristics (i.e. quality) of the information. This paper describes various forms of context challenges and examples of potential context mediation services, such as data semantics acquisition, data quality attributes and evolving semantics and quality, that can mitigate the problem. Stuart E. Madnick |
ICDE | 1 |
| 1996 | Conceptualizing Semantic Interoperability: A Perspective From the Knowledge LevelabstractCurrently, there is a proliferation of database integration approaches in response to the need to achieve semantic interoperability in heterogeneous, distributed and autonomous environments. To date, however, we lack abstract, formal descriptions of the task of semantic interoperation, independent of idiosyncratic implementation details. Such abstract descriptions are needed to aid our understanding of these various complex systems that are being constructed. Therefore, we argue that a knowledge level perspective of interoperable systems is desirable. The knowledge level serves as an abstract specification of what a system should do and facilitates the design and analysis of complex systems. In this paper, we show how an interoperable system, based on the Context Interchange Architecture, may be specified in terms of first-order logic which is an ideal specification language at the knowledge level. This specification represents a theoretical ideal which serves to formalize and communicate the key ideas behind the Context Interchange Approach, unencumbered by the details, limitations and compromises of specific implementations. As such, it provides a rigorous basis for implementing such systems. Similar specifications may also be developed for other models of interoperable systems. As a result, we have a rigorous means of understanding, comparing and analyzing these complex systems. Jacob L. Lee, Stuart E. Madnick, Michael D. Siegel |
Int. J. Cooperative Inf. Syst. | 2 |
| 1995 | From VLDB to VMLDB (Very MANY Large Data Bases): Dealing with Large-Scale Semantic Heterogenity
Stuart E. Madnick |
VLDB | 1 |
| 1995 | Why not one big database? Principles for data ownership
Marshall W. van Alstyne, Erik Brynjolfsson, Stuart E. Madnick |
Decis. Support Syst. | 3 |
| 1995 | Integration technology: The reinvention of the linkage between information systems and computer science
Stuart E. Madnick |
Decis. Support Syst. | 1 |
| 1994 | Context Interchange: Overcoming the Challenges of Large-Scale Interoperable Database Systems in a Dynamic EnvironmentabstractResearch in database interoperability has primarily focused on circumventing schematic and semantic incompatibility arising from autonomy of the underlying databases. We argue that, while existing integration strategies might provide satisfactory support for small or static systems, their inadequacies rapidly become evident in large-scale interoperable database systems operating in a dynamic environment. This paper highlights the problem of receiver heterogeneity, scalability, and evolution which have received little attention in the literature, provides an overview of the Context Interchange approach to interoperability, illustrates why this is able to better circumvent the problems identified, and forges the connections to other works by suggesting how the context interchange framework differs from other integration approaches in the literature. Cheng Hian Goh, Stuart E. Madnick, Michael D. Siegel |
CIKM | 2 |
| 1994 | Context interchange in a client-server architecture
Michael D. Siegel, Stuart E. Madnick, Edward Sciore |
J. Syst. Softw. | 2 |
| 1993 | Data Quality Requirements Analysis and ModelingabstractA set or premises, terms, and definitions for data quality management are established, and a step-by-step methodology for defining and documenting data quality parameters important to users is developed. These quality parameters are used to determine quality indicators about the data manufacturing process, such as data source creation time, and collection method, that are tagged to data items. Given such tags, and the ability to query over them, users can filter out data having undesirable characteristics. The methodology provides a concrete approach to data quality requirements collection and documentation. It demonstrates that data quality can be an integral part of the database design process. A perspective on the migration towards quality management of data in a database environment is given.> Richard Y. Wang, Henry B. Kon, Stuart E. Madnick |
ICDE | 3 |
| 1993 | The Voice of the Customer: Innovative and Useful Research Directions (Panel)
Stuart E. Madnick |
VLDB | 1 |
| 1991 | A Metadata Approach to Resolving Semantic Conflicts
Michael D. Siegel, Stuart E. Madnick |
VLDB | 2 |
| 1990 | A Polygen Model for Heterogeneous Database Systems: The Source Tagging Perspective
Richard Y. Wang, Stuart E. Madnick |
VLDB | 2 |
| 1989 | The Inter-Database Instance Identification Problem in Integrating Autonomous SystemsabstractThe issue of joining information about the same instance across disparate databases in a composite information system (CIS) environment is discussed. A technique called interdatabase instance identification is presented that is a combination of database management systems and artificial intelligence techniques. Common attributes in the disparate databases are applied first to reduce the number of potential candidates for the same instance. Other attributes in these databases, auxiliary databases, and inferencing rules are utilized next to identify the same instance. A detailed example of the interdatabase instance identification technique is presented using an operational research prototype.> Richard Y. Wang, Stuart E. Madnick |
ICDE | 2 |
| 1989 | Hierarchical timestamping algorithm
Meichun Hsu, Stuart E. Madnick |
Inf. Syst. | 2 |
| 1988 | Shifting Timestamps for Concurrency Control in an Information Hierarchy
Meichun Hsu, Stuart E. Madnick |
Inf. Process. Lett. | 2 |
| 1987 | On the portability of quantitative software estimation models
Tarek K. Abdel-Hamid, Stuart E. Madnick |
Inf. Manag. | 2 |
| 1986 | Modeling Multiprocessor Computer Systems with Unbalanced FlowsabstractA performance analysis methodology using certain aspects of queueing theory to evaluate computer system speed performance is presented. This methodology specifically focuses on modeling multiprocessor computer systems with unbalanced flows (i.e., number of transactions leaving a server is not the same as number of transactions entering that server) due to asynchronously spawned parallel tasks. This unbalanced flow phenomenon, which has a significant effect on performance, cannot be solved analytically by classical queueing network models. Stuart E. Madnick, Richard Y. Wang |
SIGMETRICS | 1 |
| 1983 | Hierarchical Database Decomposition - A Technique for Database Concurrency ControlabstractThe classical approaches to enforcing serializability are the two-phase locking technique and the timestamp ondering technique. Either approach requires that a read operation from a transaction be negistered (in the form of either a read timestamp or a read lock), so that a write operation from a concurrent transaction will not interfere improperly with the read operation. However, setting a lock or leaving a timestamp with a data element is an expensive operation. The purpose of the current research is to seek ways to reduce the overhead of synchronizing certain types of read accesses while achieving the goal of serializability.To this end, a new technique of concurrency control for database management systems has been proposed. The technique makes use of a hierarchical database decomposition, a procedure which decomposes the entire database into data segments based on the access pattern of the update transactions to be run in the system. A corresponding classification of the update transactions is derived where each transaction class is 'rooted' in one of the data segments. The technique requires a timestamp ordering protocol be observed for acesses within an update transaction's own root segment, but enables read accesses to other data segments to proceed without ever having to wait or to leave any trace of these accesses, thereby reducing the overhead of concurrency control. An algorithm for handling ad-hoc read-only transactions in this environment is also devised, which does not require read-only transactions to wait or set any read timestamp. Meichun Hsu, Stuart E. Madnick |
PODS | 2 |
| 1979 | Properties of Storage Hierarchy Systems with Multiple Page Sizes and Redundant DataabstractThe need for high performance, highly reliable storage for very large on-line databases, coupled with rapid advances in storage device technology, has made the study of generalized storage hierarchies an important area of research. This paper analyzes properties of a data storage hierarchy system specifically designed for handling very large on-line databases. To attain high performance and high reliability, the data storage hierarchy makes use of multiple page sizes in different storage levels and maintains multiple copies of the same information across the storage levels. Such a storage hierarchy system is currently being designed as part of the INFOPLEX database computer project. Previous studies of storage hierarchies have primarily focused on virtual memories for program storage and hierarchies with a single page size across all storage levels and/or a single copy of information in the hierarchy. In the INFOPLEX design, extensions to the least recently used (LRU) algorithm are used to manage the storage levels. The read-through technique is used to initially load a referenced page of the appropriate size into all storage levels above the one in which the page is found. Since each storage level is viewed as an extension of the immediate higher level, an overflow page from level i is always placed in level i + 1. Important properties of these algorithms are derived. It is shown that depending on the types of algorithms used and the relative sizes of the storage levels, it is not always possible to guarantee that the contents of a given storage level i is always a superset of the contents of its immediate higher storage level i - 1. The necessary and sufficient conditions for this property to hold are identified and proved. Furthermore, it is possible that increasing the size of intermediate storage levels may actually increase the number of references to lower storage levels, resulting in reduced performance. Conditions necessary to avoid such an anomaly are also identified and proved. Chat-Yu Lam, Stuart E. Madnick |
ACM Trans. Database Syst. | 2 |
| 1978 | Operating system security a tutorial of current researchabstractThis tutorial is extracted from the recently completed monograph, Computer Security: Its Problems and Solutions [3], and is intended as a technical review of research in the areas of operating system security. Furthermore, it is intended to provide some assessment and evaluation of the work reviewed. Some projections and speculations of future activities in operating system research are also included. Because the tutorial is written for technical people who are not directly conducting such research, we have tried to present the review in an illustrative manner with intuitive and informal definitions of the necessary technology. The tutorial expounds the notion of surveillance in terms of logging and threat monitoring. It conceptualizes the problems and solutions of access control. To achieve security, the operating system relies on isolation. The tutorial points out the trade-off between security and cost of isolation. Furthermore, it illustrates two impor tant isolation methods. In order to provide security, the operating system must be designed and implemented as a secure system. The use of verification techniques for proving the correctness of secure operating system design and implementation is examined. When the operating system is large and the security requirements are elaborate, it may be necessary to concentrate the secure elements in a kernel. The notion of secure kernel is therefore examined. Other methods such as penetration tests are also examined An up-to-date bibliography since 1974 is included. To allow the readers to have a coherent coverage of various topics of operating system security, we have endeavored to give our personal views of various subject matters. We would like the reader to bear with us in the expression of these views. David K. Hsiao, Douglas S. Kerr, Stuart E. Madnick |
COMPSAC | 3 |
| 1978 | Privacy and Security of Data Communications and Data Bases
David K. Hsiao, Douglas S. Kerr, Stuart E. Madnick |
VLDB | 3 |
| 1977 | Database Machine Architecture in the Context of Information Technology Evolution
David K. Hsiao, Stuart E. Madnick |
VLDB | 2 |