The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Reports and Papers Archive


Browse All Papers »       Submit A Paper »

Anonymous Connections and Onion Routing

Paul F. Syverson, David M. Goldschlag, and Michael G. Reed

Onion Routing provides anonymous connections that are strongly resistant to both eavesdropping and traffic analysis.  Unmodified Internet applications can use these anonymous connections by means of proxies…

Added 2002-07-26

Protecting Software Code By Guards

CERIAS TR 2001-49
Hoi Chang and Mikhail J. Atallah
Download: PDF

Protection of software code against illegitimate modifications by its users is a pressing issue to many software developers. Many software-based mechanisms for protecting program code are too weak (e.g., they have single points of failure) or too expensive to apply (e.g., they in-  cur heavy runtime performance penalty to the protected programs). In this paper, we present and explore a methodology that we believe can protect program integrity in a more tamper-resilient and manner. Our approach is based on a distributed scheme, in which protection and tamper-resistance of program code is achieved, not by a single security module, but by a network of (smaller) security units that work together in the program. These security units, or guards, can be programmed to do certain tasks (checksumming the program code is one example) and a network of them can reinforce the protection of each other by creating mutual-protection. We have implemented a system for automating the process of installing guards into Win32 executables. 1 Experimental results show that memory space and run-time performance impacts incurred by guards can be kept very low (as explained later in the paper).

Added 2002-07-26

Flexible Policy-Directed Code Safety

David Evans, Andrew Twyman

This work introduces a new approach to code safety.  We present Naccio, a system architecture that allows a large class of safety policies to be expressed in a general and platform-independent way…

Added 2002-07-26

Execution Monitoring of Security-Critical Programs in Distributed Systems: A Specification-based Approach

Calvin Ko, Manfred Ruschitzka, Karl Levitt

This paper describes a specfication-based approach to detect exploitations of vulnerabilities in security-critical programs.  The approach utilizes security specifications that describe the intended behavior of programs and scans audit trails for operations that are in violation of the specifications…

Added 2002-07-26

Detecting Intrusions Using System Calls: Alternative Data Models

Christina Warrender, Stephanie Forrest, Barak Pearlmutter

Intrusion detection systems rely on a wide variety of observable data to distinguish between legitimate and illegitimate activities.  In this paper we study one such observable - sequences of system calls into the kernel of an operating system…

Added 2002-07-26

Detecting Disruptive Routers: A Distributed Network Monitoring Approach

Kirk A. Bradley, Steven Cheung, Nick Puketza Biswanath Mukherjee, Ronald A. Olsson

An attractive target for a computer system attacker is the router.  An attacker in control of a router can disrupt communication by dropping or misrouting packets passing through the router.  We present a protocol called Watchers that detects and reacts to routers that drop or misroute packets…

Added 2002-07-26

Why Cryptography is Harder Than it Looks

Counterpane Systems
Added 2002-07-26

Crowds: Anonymity for Web Transactions

Michael K. Reiter and Aviel D. Rubin
Added 2002-07-26

Goal Mining to Examine Health Care Privacy Policies

Annie I. Ant
Download: PDF
Added 2002-07-26

On Watermarking Numeric Sets

CERIAS TR 2001-60
Radu Sion and Mikhail Atallah and Sunil Prabhakar
Download: PDF

We\‘re looking into the fundamental problem of watermarking finite numeric sets. The wide area of applicability of the problem ranging from numeric database content to stock market analysis data, makes it especially intriguing when considering a generic solution and particularities of its various applications. Given a range of associated numeric constraints and assumptions we provide a generic solution and analyze associated attacks. We further present several problem applicability domains and relate it to some of our past and ongoing research in watermarking semistructures.

Added 2002-07-26

An Architecture for Secure Wireless Networking

CERIAS TR 2001-56
Yi Lu, Bharat Bhargava, Mohamed Hefeeda
Download: PDF
Added 2002-07-26

Achieving Flexibility and Scalability: A New Architecture for Wireless Network

CERIAS TR 2001-01
Yi Lu, Bharat Bhargava
Download: PDF

We present a Hierarchical Hybrid Network architecture for wireless networks.  In such a network, mobile nodes are hierarchically organized into groups.  Different groups can have different routing protocols.  Mobile nodes communicate with nodes outside their groups through the group agents.  The groups are highly autonomous.  This architecture is flexible and scalable.  We conduct experiments to compare the new architecture with Ad Hoc networks.  The new architecture has a more stable topology and higher throughput when the number of mobile nodes is large.  The objective of our research is to set up a survivable, secure mobile wireless network.

Added 2002-07-26

CONTEXT OF INFORMATION ASSURANCE IN INTER-NETWORKED ENTERPRISES

CERIAS TR 2001-57
Thomas Bellocci, and Shimon Y. Nof
Download: PDF

The development of inter-networked enterprises created a new computing environment in which information assurance is critical. The objective of this article is to investigate the information assurance needs of today

Added 2002-07-26

AGENTS AND PROTOCOLS FOR VARIABLE INFORMATION ASSURANCE IN WORKFLOW SYSTEMS

CERIAS TR 2001-58
Thomas Bellocci, and Shimon Y. Nof
Download: PDF

The design and operation of autonomous agents to assure information in ERP systems of inter-networked enterprises are investigated. A variable information assurance implementation model is proposed based on the AIMIS model, and a risk assessment procedure is applied. The protocols and models needed to support variable assurance are introduced and their performance is assessed. Experimentation shows the possibility to reduce the processing time of requests without decreasing the proportion of trusted requests, compared to a systematic total assurance approach.

Added 2002-07-26

INFORMATION ASSURANCE IN AGENT-BASED WORKFLOW SYSTEM: AN OVERVIEW

CERIAS TR 2001-59
Thomas Bellocci, Chwee Beng Ang, Parbati Ray, and Shimon Y. Nof
Download: PDF
Added 2002-07-26