Ian Welch

dblp:w/IanWelch · also Ian S. Welch, Ian Shawn Welch · DBLP profile ↗
← Back
46ranked-venue papers
3as first author
9since 2021 · last 2025
0000-0002-5968-182XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 2 first-author · 6 since 2021Computer networks · 8 · 1 since 2021Systems, architecture and hardware · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-authorArtificial intelligence and machine learning · 3Software engineering, systems software and programming languages · 3Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 A Cost-Effective AIR System for Browser-Based Geolocation and Cloaking Attacks
Masood Mansoori, Junaid Haseeb, Ian Welch
AINA (5)3
2025 Feature Identification and Study of Attackers' Behaviours Using Honeypots
Junaid Haseeb, Masood Mansoori, Ian Welch
DBSec3
2025 Genetic programming for enhanced detection of Advanced Persistent Threats through feature construction
Harith Al-Sahaf, Ian Welch, Seyit Ahmet Çamtepe
Comput. Secur.3
2023 Evolving malice scoring models for ransomware detection: An automated approach by utilising genetic programming and cooperative coevolution
abstract
Malice scoring is a technique that is present throughout the literature to quantify a software malignance through the assignment of a malice score. However, the majority of existing malice scoring models are synthesised using manually selected features and weights, where a domain specialist is needed. Hence, this paper aim at utilising Genetic Programming and cooperative coevolution to automatically evolve an ensemble of symbolic regression functions to assign a malice score to an instance of software data. Using a publicly available dataset, the effectiveness of the proposed method is assessed and compared to that of the state-of-the-art malice scoring method. The experimental results show that the proposed method has significantly outperformed the benchmark method and exhibits the best-performing model that produces an overall balanced accuracy of 95.80%, correctly classifying 94.21% and 97.39% of unseen malicious and benign instances, respectively. Furthermore, various aspects of the proposed method and experimental results have been analysed in-depth to provide insight into the evolutionary process and some of the automatically evolved models.
Taran Cyriac John, Muhammad Shabbir Abbasi, Harith Al-Sahaf, Ian Welch, Julian Jang
Comput. Secur.4
2022 Probabilistic modelling of deception-based security framework using markov decision process
Junaid Haseeb, Saif Ur Rehman Malik, Masood Mansoori, Ian Welch
Comput. Secur.4
2022 Corrigendum to 'Probabilistic modelling of deception-based security framework using markov decision process' [Computers & Security 115 (2022)/102599]
Junaid Haseeb, Saif Ur Rehman Malik, Masood Mansoori, Ian Welch
Comput. Secur.4
2022 A few-shot meta-learning based siamese neural network using entropy features for ransomware classification
Jinting Zhu, Julian Jang, Amardeep Singh, Ian Welch, Harith Al-Sahaf, Seyit Ahmet Çamtepe
Comput. Secur.4
2022 Autoencoder-based feature construction for IoT attacks clustering
Junaid Haseeb, Masood Mansoori, Yuichi Hirose, Harith Al-Sahaf, Ian Welch
Future Gener. Comput. Syst.5
2021 Failure Modes and Effects Analysis (FMEA) of Honeypot-Based Cybersecurity Experiment for IoT
abstract
Failure Modes and Effects Analysis (FMEA) is the process of identifying potential failure modes, their causes and effects associated with a product, process or system. In this paper, we discuss the application of FMEA in the design of cybersecurity experiments using a medium interaction server honeypot in an Internet of Things (IoT) environment. Through FMEA analysis, we identify the factors affecting the outcome or contributing to the potential failures of the cybersecurity experiment. We discuss the causes of failures, their effects and how to minimise or mitigate them.
Junaid Haseeb, Masood Mansoori, Ian Welch
LCN3
2020 Particle Swarm Optimization: A Wrapper-Based Feature Selection Method for Ransomware Detection and Classification
Muhammad Shabbir Abbasi, Harith Al-Sahaf, Ian Welch
EvoApplications3
2020 Achieving IoT Devices Secure Sharing in Multi-User Smart Space
abstract
Multiple users often share their Internet of Things (IoT) devices in a smart space. However, existing IoT systems do not support IoT sharing between multiple users or take into account the security risks associated with using shared devices. We address this problem by proposing a new multi-user IoT Secure Sharing (IoTSS) system supported by a newly designed sharing policy language. Our approach treats the policies as constraints in the context of an optimisation problem to fulfil user activities using the least vulnerable devices. We show how IoT sharing can be transformed into an equivalent Integer Linear Programming (ILP) problem, which can be solved efficiently and effectively by off-the-shelf Integer ILP solvers. To study the practical feasibility of IoTSS, we have implemented a proof-of-concept proxy-based prototype for the popularly used Mozilla WebThings Gateway. We found that the proxy service can achieve policies enforcement without incurring statistically significant time overhead.
Mohammed Al-Shaboti, Gang Chen 0002, Ian Welch
LCN3
2020 IoT Attacks: Features Identification and Clustering
abstract
The exponential growth in the Internet of Things (IoT) market has led to the proliferation of cyber threats as millions of vulnerable IoT devices are connected to the Internet each year. Security practitioners and researchers capture attacks on IoT devices using honeypots to explore the attack process, identify the types of attacks and analyse the interaction of the attackers with IoT devices. Several studies have focused on the classification of attacks on IoT devices, however, they are limited to performing manual analysis on command data by assigning skill levels to the attackers and looking at the purpose of executing specific commands. In this paper, we report our analysis of the captured attacks on IoT devices for four months using a medium-interaction server honeypot. We extract a new feature set by analysing the attacks according to the depth of interaction by the attackers, their behaviour in the attack process and the resources they utilised to perform these attacks. We apply unsupervised learning (i.e. clustering) to automatically group captured attacks and build a model to highlight the important features that contribute to understanding the relationship between various attacks grouped in the same cluster.
Junaid Haseeb, Masood Mansoori, Harith Al-Sahaf, Ian Welch
TrustCom4
2020 A Measurement Study of IoT-Based Attacks Using IoT Kill Chain
abstract
Manufacturing limitations, configuration and maintenance flaws associated with the Internet of Things (IoT) devices have resulted in an ever-expanding attack surface. Attackers exploit IoT devices to steal private information, take part in botnets, perform Denial of Service (DoS) attacks and use their resources for the mining of cryptocurrency. In this paper, we experimentally evaluate a hypothesis that attacks on IoT devices follow the generalised Cyber Kill Chain (CKC) model. We used a medium-interaction honeypot to capture and analyse more than 30,000 attacks targeting IoT devices. We classified the steps taken by the attackers using the CKC model and extended CKC to an IoT Kill Chain (IoTKC) model. The IoTKC provides details about IoT-specific attack characteristics and attackers' activities in the exploitation of IoT devices.
Junaid Haseeb, Masood Mansoori, Ian Welch
TrustCom3
2020 How do they find us? A study of geolocation tracking techniques of malicious web sites
Masood Mansoori, Ian Welch
Comput. Secur.2
2019 IoT Application-Centric Access Control (ACAC)
abstract
As smart environments become more common, IoT applications can automate more complex and dynamic activities. Users can define their activities as abstract workflows and suitable devices will be selected dynamically to execute them based on user quality of experience (QoE) requirements. However, many of such applications violate the principle of least privilege in terms of the allowed interactions between the IoT devices. We propose an Application-Centric Access Control (ACAC) framework to enable least privilege network access control for dynamic workflows while considering users' QoE. ACAC enables automatic derivation of an access control policy for an IoT application and allow this to be adjusted dynamically as new devices come and go in order to maintain user QoE.
Mohammed Al-Shaboti, Ian Welch, Gang Chen 0002
AsiaCCS2
2019 Geolocation Tracking and Cloaking of Malicious Web Sites
abstract
Web site cloaking is a process in which varying HTML content is delivered to end users based on the attributes associated with the client agent and its interaction patterns. Cloaking poses significant challenges in detection of malicious web sites. The challenge arises due to its simplicity in implementation and its effectiveness in bypassing the detection engines. A malicious web site can deliver a benign content to a requesting client on the server side and consequently bypass detection, regardless of the detection engine used by the client. We performed large-scale real-world experiments to study cloaking techniques used by malicious web sites. We focused our research on malicious web sites using geographical information associated and derived from the IP address and language preferences of a visiting client's browser. Our study validated our hypothesis that client browser's preferred language settings and geographical information of an IP address taken in isolation, change the behaviour of a malicious web site. We also measured the effects of IP geolocation and language settings on the behaviour of malicious web sites irrespective of other factors.
Masood Mansoori, Ian Welch
LCN2
2018 Towards Secure Smart Home IoT: Manufacturer and User Network Access Control Framework
abstract
Insecure smart home IoT network is growing in number and size, and enforcing standard security solutions in IoT is a challenge due to its limited resources. The vulnerable smart home IoT poses huge security threats. It puts smart home network security at risk as it can be used as an entry point into the network, also it exposes users' privacy due to the amount of personal data it collects. Meanwhile, as IoT increases in popularity, it has a significant impact on the security of the rest of the Internet community (e.g. forming botnets). Previous research delegates IoT security to a third party (e.g. ISP) and ignores social and contextual factor. In this paper, we propose an SDN-based framework for enforcing network static and dynamic access control, where manufacturers, security providers, and users can cooperate to enhance the smart home IoT security. Proposed approach has three features: a) it allows the manufacturers to enforce the least privileged policy for IoT, and hence reduce the risk associated with exposing IoT to the Internet; b) it enables to enforce access policy as a feedback from security services; c) it enables users to customize IoT access based on social and contextual needs (e.g. only permits LAN access to the IoT through his/her mobile), which reduce the attack surface within the network. We also proposed IPv4 ARP server as an NFV security service to mitigate ARP spoofing attack by replying to ARP requests in the network. We implement a prototype to demonstrate the functionality of the framework against common attack scenarios (i.e. network scanning, ARP spoofing).
Mohammed Al-Shaboti, Ian Welch, Gang Chen 0002, Muhammad Adeel Mahmood
AINA2
2018 Enhanced Event Reliability in Wireless Sensor Networks
abstract
Event detecting Wireless Sensor Networks (WSNs) with overlapping sensor nodes generate many redundant packets. Resource constraints in WSNs require minimizing the number of packets transmitted, so we want to eliminate all redundant packets. But this must be done carefully if we need to ensure reliable detection of all events happening across the network. Ensuring reliable transport of data is an important concern in resource-constrained WSNs. In a densely deployed sensor network, the sensing region of the sensor nodes often overlap with one another. Thus, data from sensor nodes that are in close proximity tend to be highly correlated. This introduces the concept of event reliability, where a reliable transfer of event data from each sensing region in a sensor network is sufficient. This paper proposes a distributed approach, i.e. Enhanced Event Reliability Protocol (EERP), that enables reliable transmission of event information to the sink node while minimizing redundant packets from nodes in close vicinity of one another. EERP builds on the spatio-temporal information of the originating nodes and employs an efficient combination of a greedy strategy with the use of multilateration algorithm in a unique way to perform event identification before reliably transmitting the event information towards the sink node. The performance of EERP is evaluated and compared against a base model, ERP and a commonly used scheme (SWIA). Our results show that EERP significantly improves event information delivery and energy efficiency while maintaining good coverage of events throughout the network.
Muhammad Adeel Mahmood, Ian Welch, Peter Andreae
AINA2
2017 Cluster-than-Label: Semi-Supervised Approach for Domain Adaptation
abstract
The performance of a conventional machine learning model trained on a source domain degrades poorly when they are tested on a different data distribution (target domain). These traditional models deal with this problem by training a new paradigm for the particular different data distribution (target domain). Therefore, training of a new paradigm for the individual data distribution is computationally expensive. This paper demonstrates that how to adapt to a new data distribution (target domain), utilising the model trained on source domain and avoiding the cost of re-training and the need for access to the source labelled data. In particular, we introduce an Efficient Semi-supervised Cluster-than-Label Cross-domain Adaptation Algorithm (SCTLCDA) to address the cross-domain adaptation classification problem in which we utilised both labelled and unlabelled data samples in the target domain, as well as completely unlabelled data samples in the source domain. Subsequently, we also describe that our proposed method can manage large datasets and easily lead to cross-domain adaptation problem. The effectiveness and performance of our method are confirmed by experiments on two real-world applications: Crossdomain sentiments and Web-Spam classification problem.
Xiaoying Gao, Ian Welch
AINA3
2017 Impacts of Power Factor Control Schemes in Time Series Power Flow Analysis for Centralized PV Plants Using Wavelet Variability Model
abstract
This paper presents impacts of three power factor control strategies (fixed power factor, power factor schedule, and power factor function) on the power output of a centralized utility-interactive photovoltaic (PV) plant deployed close to the feeder end and source using the wavelet variability model (WVM) at various penetration levels. The upscaling advantage from a single module and point irradiance sensor to geographic smoothing over the entire PV footprint in WVM is used to simulate effects of a grid-connected large PV system on the IEEE-34 distribution feeder. Also, this study uses high-frequency solar irradiance data (1 s) to show impacts of PV output variability on voltage regulator tap changing operations, feeder voltage, active power profile, and reactive power profile at various penetration levels until the voltage constraint is violated. Results showed that, although variability increases with PV system deployment close to the feeder source and end, it is higher at the feeder end than source.
Michael Emmanuel, Ramesh Rayudu, Ian Welch
IEEE Trans. Ind. Informatics3
2016 A Machine Learning Based Web Spam Filtering Approach
abstract
Web spam has the effect of polluting search engine results and decreasing the usefulness of search engines.Web spam can be classified according to the methods used to raise the web page's ranking by subverting web search engine's algorithms used to rank search results. The main types are: content spam, link spam and cloaking spam. There has been little or no work on automatically classifying web spam by type. This paper has two contributions, (i) we propose a Dual-Margin Multi-Class Hypersphere Support Vector Machine (DMMH- SVM) classifier approach to automatically classifying web spam by type, (ii) we introduce novel cloaking-based spam features which help our classifier model to achieve high precision and recall rate, thereby reducing the false positive rates. The effectiveness of the proposed model is justified analytically. Our experimental results demonstrated that DMMH-SVM outperforms existing algorithms with novel cloaking features.
Xiaoying Gao, Ian Welch, Masood Mansoori
AINA3
2016 Empirical Analysis of Impact of HTTP Referer on Malicious Website Behaviour and Delivery
abstract
Referer is a HTTP header field transmitted to a webserver, which allows the webserver to identify the origin of the request and the path taken by the visiting user to reach the final resource. Although referer is an optional field within an HTTP protocol header, many webservers use the information for logging, marketing and analytical purposes. Referer has, however, been abused in web spam cloaking and search engine optimization (SEO) attacks. The latter increases a malicious website's ranking in a search engine result with the aims of delivering spam to unwitting users. In this paper, we undertake a quantitative study to determine the effects of referer information on delivery of malicious content (excluding spam) and whether different referer values, mimicking an average user will yield dissimilar results in terms of the number and type of attacks. Our study of 500,000 suspicious websites confirms that similar to web spam, referer information is a HTTP header variable used by malicious websites to distinguish regular users from automated crawlers and security tools, and is abused to deliver malicious content accordingly.
Masood Mansoori, Yuichi Hirose, Ian Welch, Kim-Kwang Raymond Choo
AINA3
2016 Application of HAZOP to the Design of Cyber Security Experiments
abstract
Hazard and Operability studies have been extensively used in chemical engineering and designing safety critical systems. Its rigorous analysis based on discovering deviations and hazard makes it ideal in the study of designs and experiments with confounding variables. In this paper, HAZOP methodology is applied to a case study of network security experiment to reliably measure the IP tracking behavior of malicious websites using a low interaction client honeypot. The experiment's design involves a large number of factors and components which could potentially introduce bias in the study and result in invalid analysis. We demonstrate that HAZOP can be applied to security experiments to create a proper experimental design and properly control potential bias of confounding variables.
Masood Mansoori, Ian Welch, Kim-Kwang Raymond Choo, Roy A. Maxion
AINA2
2016 Towards SDN Network Proofs - Taming a Complex System
abstract
Currently the SDN research community considers in-line dynamic network functions too complex for SDN, leading to calls to purge them from the forwarding plane. This paper introduces a comprehensive framework that tames this complexity and allows network administrators to deploy complex network functions into the SDN forwarding plane to provide enhanced and provable network properties. We first illustrate mapping complex network functions to a network to determine location and their sphere of influence. Through analysis we identify properties common to all network functions and we provide formalisms to specify the behaviour of a generic network function using typed functions, the basis of many modern programming languages. We extend this generic network function to demonstrate two types of firewall providing security properties and also demonstrate chaining which is the basis of Unified Threat Management firewalls and Deep Packet Inspection. This paper is a foundation for ongoing research into proving properties of black box implementations of network functions.
Matt Stevens, Bryan C. K. Ng, David Streader, Ian Welch
ICECCS4
2016 Novel Features for Web Spam Detection
abstract
Recent research on web spam detection has shown promising results, and many new and efficient detection algorithms have been developed. While most research focuses on developing algorithms, our investigation shows that the features used in the algorithms are in fact very important, and different features can lead to very different results. This paper investigates three types of web spam, content-based, link-based and cloaking, and introduces new features for identifying the three types of spam. Our experimental results show that the introduction of new features significantly improves the detection performance.
Xiaoying Gao, Ian Welch
ICTAI3
2016 Learning Under Data Shift for Domain Adaptation: A Model-Based Co-clustering Transfer Learning Solution
Xiaoying Gao, Ian Welch
PKAW3
2015 VisRAID: Visualizing Remote Access for Intrusion Detection
Leliel Trethowen, Craig Anslow, Stuart Marshall, Ian Welch
ACISP4
2015 Reliability in wireless sensor networks: A survey and challenges ahead
Muhammad Adeel Mahmood, Winston Khoon Guan Seah, Ian Welch
Comput. Networks3
2014 Restrictions Affecting New Zealanders' Access to the Internet: A Local Study
abstract
The advent of the Internet has provided people around the world with access to information and services from across the globe that is published without any mediation by governments or other agencies. However, access to this information and services may be restricted within the viewer's own country by their Government, Internet Service Providers, employers and families among others. The motivations for restrictions on access may involve politics and power, social norms and morals, security concerns, or protecting intellectual property rights and economic interests. This filtering or service blocking, whether for security or for network efficiency, has significant effects on people's access to services and information, which may not be considered when implementing restrictions. Although studies have been conducted about Internet blocking in many countries, no one has yet examined what is being filtered or blocked in New Zealand. This paper describes a tool we have developed to investigate this issue and the results from an initial study examining organizations providing wireless access within Wellington, New Zealand.
Shadi Esnaashari, Ian Welch, Brenda Chawner
AINA2
2013 Detecting heap-spray attacks in drive-by downloads: Giving attackers a hand
abstract
In the anatomy of drive-by download attacks, one of the key steps is to place malicious code (shellcode) in the memory of the browser process in order to carry out a drive-by download attack. There are two common techniques to carry out this task: stack-based and heap-based injections. However, introduction of stack protection makes the stack-based injection harder to carry out successfully. The heap-based injections become common methods to deliver shellcode to the heap memory of the web browsers. This paper presents the role of heap-spray in drive-by download attacks. We propose a new detection mechanism which makes shellcode in heap-spray executed in order to detect drive-by download attack. The solution not only benefits detection of drive-by download attacks but also analysis of malware behavior.
Van Lam Le, Ian Welch, Xiaoying Gao, Peter Komisarczuk
LCN2
2013 Security analysis of a protocol for pollution attack detection
abstract
Network coding is a technique for maximizing the use of available bandwidth capacity. This is achieved by having nodes not just forwarding packets but combining several incoming packets into a single outgoing packet for transmission. Unfortunately, network coding is vulnerable to pollution attacks where a single malicious node can disrupt the operation of the complete network. Several protocols to detect pollution attacks have been proposed in the literature. In this paper we describe a new pollution attack detection protocol that extends the existing SpaceMac protocol. This paper describes how we have modeled the protocol in order to carry out a security analysis and presents the results of that analysis.
Kiattikul Sooksomsatarn, Ian Welch, Winston Khoon Guan Seah
LCN2
2012 A Novel Scoring Model to Detect Potential Malicious Web Pages
abstract
Malicious web pages have embedded within them active contents that exploit vulnerabilities in users' browsers and plug-ins in order to compromise the users' machines. Approaches from research into identifying malicious web pages can be classified into two groups depending upon the types of web page features used: either run-time features based upon observing what happens when the web page is loaded (slow but accurate) or static features based upon the content, structure or property of the web page (fast but inaccurate). Hybrid approaches combine the best of both to provide scalable systems with good accuracy by using the static feature based approach as a pre-filter for the run-time feature based approach. One of critical challenges for such hybrid approaches is to build effective pre-filter which has a capability to make the trade-off between reducing number of web pages passed through to the run-time feature detector and misidentifying malicious web pages as benign. This paper presents a novel scoring model to filter potential malicious web pages by using static features from various sources of information about malicious web pages, finding suitable algorithms to score maliciousness of each source of information, and finally finding the best ways to combine scores from different sources of information in order to achieve the best accuracy. The result shows that our novel scoring model can combine knowledge from various sources of information about web pages very effectively in order to filter potential malicious web pages.
Van Lam Le, Ian Welch, Xiaoying Gao, Peter Komisarczuk
TrustCom2
2012 Security threats and solutions in MANETs: A case study using AODV and SAODV
Jan von Mulert, Ian Welch, Winston Khoon Guan Seah
J. Netw. Comput. Appl.2
2011 Two-Stage Classification Model to Detect Malicious Web Pages
abstract
Malicious web pages are an emerging security concern on the Internet due to their popularity and their potential serious impacts. Detecting and analyzing them is very costly because of their qualities and complexities. There has been some research approaches carried out in order to detect them. The approaches can be classified into two main groups based on their used analysis features: static feature based and run-time feature based approaches. While static feature based approach shows it strengthens as light-weight system, run-time feature based approach has better performance in term of detection accuracy. This paper presents a novel two-stage classification model to detect malicious web pages. Our approach divided detection process into two stages: Estimating maliciousness of web pages and then identifying malicious web pages. Static features are light-weight but less valuable so they are used to identify potential malicious web pages in the first stage. Only potential malicious web pages are forwarded to the second stage for further investigation. On the other hand, run-time features are costly but more valuable so they are used in the final stage to identify malicious web pages.
Van Lam Le, Ian Welch, Xiaoying Gao, Peter Komisarczuk
AINA2
2009 Measurement Study on Malicious Web Servers in the .nz Domain
Christian Seifert, Vipul Delwadia, Peter Komisarczuk, David Stirling, Ian Welch
ACISP5
2009 Automating Malware Scanning Using Workflows
abstract
Identifying websites hosting malicious code is a priority for helping protect consumers using the web and for the collection of malicious code for analysis by malware researchers. We have been running an InternetNZ sponsored study where homepages of almost all New Zealand Web servers are scanned on a regular basis by a set of client honeypots. This paper reflects upon our experience of running moderate scale scans over a period of several months manually and identifies some requirements for automation of such a system using workflow and related middleware.
David Stirling, Ian Welch, Peter Komisarczuk, Christian Seifert
CCGRID2
2008 Designing Workflows for Grid Enabled Internet Instruments
abstract
To analyse malicious activity on the Internet, instruments such as network telescopes and honeypots are effective tools that can be deployed. Such tools can be deployed in large scale using Grid computing. Manual deployment of instruments wastes resources because common tasks and solutions are reinvented by different deployers and the resulting architectures are often not interoperable or sufficiently scalable. Research is underway to develop a framework for scalable and automated deployment, with Grid technologies providing a promising basis. The integration of Grid technology with instrumentation has two initiatives. These are CIMA and GRIDCC, with GRIDCC being available as open source. A key area is workflow within the framework, for which BPEL (Business Process Execution Language) is used in GRIDCC and considered for initial use for Grid Enabled Internet Instruments. We have found BPEL has limitations when implementing such as framework, particularly in the areas of concurrency and statefullness. We propose implementation independent workflows and identify extensions to BPEL in order to realise them. We believe that BPEL with modification can be used to implement a framework for Internet instruments-Grid computing integration.
David Stirling, Ian Welch, Peter Komisarczuk
CCGRID2
2008 Identifying and Analyzing Web Server Attacks
Christian Seifert, Barbara Endicott-Popovsky, Deborah A. Frincke, Peter Komisarczuk, Radu Muschevici, Ian Welch
IFIP Int. Conf. Digital Forensics6
2008 Identification of malicious web pages through analysis of underlying DNS and web server relationships
abstract
Malicious Web pages that launch drive-by-download attacks on Web browsers have increasingly become a problem in recent years. High-interaction client honeypots are security devices that can detect these malicious Web pages on a network. However, high-interaction client honeypots are both resource-intensive and unable to handle the increasing array of vulnerable clients. This paper presents a novel classification method for detecting malicious Web pages that involves inspecting the underlying server relationships. Because of the unique structure of malicious front-end Web pages and centralized exploit servers, merely counting the number of domain name extensions and Domain Name System (DNS) servers used to resolve the host names of all Web servers involved in rendering a page is sufficient to determine whether a Web page is malicious or benign, independent of the vulnerable Web browser targeted by these pages. Combining high-interaction client honeypots and this new classification method into a hybrid system leads to performance improvements.
Christian Seifert, Ian Welch, Peter Komisarczuk, Chiraag Uday Aval, Barbara Endicott-Popovsky
LCN2
2006 Trustworthy Auctions for Grid-Style Economies
abstract
Commercialisation or globalisation of large scale grids requires the provision of mechanisms to share the wide pool of grid brokered resources such as computers, software, licences and peripherals amongst many users and organisations. Quickly and efficiently servicing resource requests is critical to the efficiency of such grid based utility computing and communication providers. The CORA architecture is a market based resource reservation system that utilises a trustworthy Vickrey auction to make combinatorial allocations of resources. The primary advantage of such a scheme is that a trusted auctioneer is no longer necessary, and any system entity can safely host a trustworthy auction. This approach results in more flexibility in the design of large economic systems, with the potential for wide distribution of load amongst many auctioneers. In addition, only the winners of the auction and the prices they pay are revealed while all other bid values are kept secret. This paper also provides performance results for our implementation, that identify the constraints within which a practical trustworthy auction scheme can be implemented in a grid-style economy.
Kris Bubendorfer, Ian Welch, Blayne Chard
CCGRID2
2004 A Qualitative Analysis of the Intrusion-Tolerance Capabilities of the MAFTIA Architecture
abstract
MAFTIA was a three-year European research project that explored the use of fault-tolerance techniques to build intrusion-tolerant systems. The MAFTIA architecture embodies a number of key design principles for building intrusion-tolerant systems, such as the notion of distributing trust throughout the system and limiting the extent to which individual components are trusted, and the aim of this paper is to illustrate these principles and demonstrate MAFTIA s intrusion-tolerance capabilities by showing how MAFTIA mechanisms and protocols might be deployed in a realistic context. We discuss the relationship between intrusion tolerance and fault tolerance, and then describe how the MAFTIA architecture could be used to build an intrusion-tolerant version of a hypothetical e-commerce application. Using fault trees, we analyse possible attack scenarios and show how MAFTIA mechanisms protect against them. We conclude the paper with a discussion of related work and identify areas for future research.
Robert J. Stroud, Ian Welch, John P. Warne, Peter Y. A. Ryan
DSN2
2003 Re-engineering Security as a Crosscutting Concern
abstract
We have re-engineered a third-party application using a reflective security architecture that allows security to be treated as a crosscutting concern. This has resulted in a considerable reduction in tangling between application code and security code. Prior to the re-engineering, the application was secured using a conventional approach based upon the application of inheritance and the proxy pattern, and we are thus able to compare both approaches. Our experience highlights some general points that are applicable to any attempt to engineer security using advanced separation of concerns technology and some possible improvements to Kava, used to implement the crosscutting concerns.
Ian Welch, Robert J. Stroud
Comput. J.1
2002 A Structured Approach to Handling On-Line Interface Upgrades
abstract
The integration of complex systems out of existing systems is an active area of research and development. There are many practical situations in which the interfaces of the component systems, for example belonging to separate organisations, are changed dynamically and without notification. In this paper we propose an approach to handling such upgrades in a structured and disciplined fashion. All interface changes are viewed as abnormal events and general fault tolerance mechanisms (exception handling, in particular) are applied to dealing with them. The paper outlines general ways of detecting such interface upgrades and recovering after them. An Internet Travel Agency is used as a case study.
Cliff B. Jones, Alexander B. Romanovsky, Ian Welch
COMPSAC3
2002 Using Reflection as a Mechanism for Enforcing Security Policies on Compiled Code
abstract
Securing application resources or defining finer-grained access control for system resources using the Java security architecture requires manual changes to source code. This is error-prone and cannot be done if only compiled code is present. We show
Ian Welch, Robert J. Stroud
J. Comput. Secur.1
2000 Using Reflection as a Mechanism for Enforcing Security Policies in Mobile Code
Ian Welch, Robert J. Stroud
ESORICS1
1999 Using Coordinated Atomic Actions to Design Safety-Critical Systems: a Production Cell Case Study
abstract
Coordinated Atomic actions (CA actions) are a unified approach to structuring complex concurrent activities and supporting error recovery between multiple interacting objects in object-oriented systems. This paper explains how we have used the CA action concept to design and implement a safety-critical application. We have used the Production Cell model that was developed in the Forschungszentrum Informatik (FZI), Karlsruhe, Germany, to present a realistic industry-oriented problem, where safety requirements play a significant role. Our design consists of two levels: the first level deals with the scheduling of CA actions, and the second level deals with the interactions between devices. Both the scheduling mechanism and the device interactions are enclosed by CA actions. Exception handling and error recovery are incorporated into CA actions in order to satisfy high safety and fault tolerance requirements. A controlling program based on our design was developed in the Java language and used to drive a graphical simulator provided by the FZI. Copyright © 1999 John Wiley & Sons, Ltd.
Avelino Francisco Zorzo, Alexander B. Romanovsky, Jie Xu 0007, Brian Randell, Robert J. Stroud, Ian Welch
Softw. Pract. Exp.6