The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Reports and Papers Archive


Browse All Papers »       Submit A Paper »
3498 results for "all"

Entitled Essays on Information Risk Management in Electronic Markets

CERIAS TR 2010-36
Juhee Kwon
Download: PDF
Added 2012-12-11

Efficient Query Processing for Uncertain Data

CERIAS TR 2011-28
Yinian Qi
Download: PDF
Added 2012-12-11

Accountability for Grid Computing Systems

CERIAS TR 2011-29
Wonjun Lee
Download: PDF
Added 2012-12-11

Analysis of port scanning attacks

CERIAS TR 2009-33
Yu Zhang
Download: PDF
Added 2012-12-11

Architectural approaches for code injection defense at the user and kernel levels

CERIAS TR 2009-34
Riley, Ryan
Download: PDF
Added 2012-12-11

Efficient query processing for rich and diverse real-time data

CERIAS TR 2009-35
Nehme, Rimma
Download: PDF
Added 2012-12-11


Forensic characterization of image capture devices

CERIAS TR 2009-38
Nitin Khanna
Download: PDF
Added 2012-12-11

Analysis of access control policies in operating systems

CERIAS TR 2009-37
Hong Chen
Download: PDF
Added 2012-12-11

A multi-layer approach towards high-performance wireless mesh networks

CERIAS TR 2007-107
Das, Saumitra
Download: PDF
Added 2012-12-11

Adaptive Virtual Distributed Environments for Shared Cyberinfrastructures

CERIAS TR 2007-108
Ruth, Paul
Download: PDF
Added 2012-12-11

Mitigation of control and data traffic attacks in wireless ad-hoc and sensor networks

CERIAS TR 2007-109
Issa Khalil
Download: PDF
Added 2012-12-11

An examination of user behavior for user re-authentication

CERIAS TR 2007-110
Pusara, Maja
Download: PDF
Added 2012-12-11

Privacy-preserving Access Control

CERIAS TR 2012-13
Zahid Pervaiz, Walid G. Aref, Arif Ghafoor, and Nagabhushana Prabhu
Download: PDF

Access control mechanisms protect sensitive information from unauthorized users. However, when sensitive information is shared and a Privacy Protection Mechanism (PPM) is not in place, an authorized insider can still compromise the privacy of a person leading to identity disclosure. A PPM can use suppression and generalization to anonymize and satisfy privacy requirements, e.g., k-anonymity and l-diversity, against identity and attribute disclosure. However, the protection of privacy is achieved at the cost of precision of authorized information. In this paper, we propose a privacy-preserving access control framework. The access control policies define selection predicates available to roles while the privacy requirement is to satisfy the k-anonymity or l-diversity. An additional constraint that needs to be satisfied by the PPM is the imprecision bound for each selection predicate. The techniques for workload-aware anonymization for selection predicates have been discussed in the literature. However, to the best of our knowledge, the problem of satisfying the accuracy constraints for multiple roles has not been studied before. In our formulation of the aforementioned problem, we propose heuristics for anonymization algorithms and show empirically that the proposed approach satisfies imprecision bounds for more permissions and has lower total imprecision than the current state of the art.

Added 2012-10-02

Privacy Preserving Access Control on Third-Party Data Management Systems

CERIAS TR 2012-12
Mohamed Nabeel
Download: PDF

The tremendous growth in electronic media has made publication of information in either open or closed environments easy and effective. However, most application domains (e.g. electronic health records (EHRs)) require that the fine-grained selective access to information be enforced in order to comply with legal requirements, organizational policies, subscription conditions, and so forth. The problem becomes challenging with the increasing adoption of cloud computing technologies where sensitive data reside outside of organizational boundaries. An important issue in utilizing third party data management systems is how to selectively share data based on finegrained attribute based access control policies and/or expressive subscription queries while assuring the confidentiality of the data and the privacy of users from the third party.

In this thesis, we address the above issue under two of the most popular dissemination models: pull based service model and subscription based publish-subscribe model. Encryption is a commonly adopted approach to assure confidentiality of data in such systems. However, the challenge is to support fine grained policies and/or expressive content filtering using encryption while preserving the privacy of users. We propose several novel techniques, including an efficient and expressive group key management scheme, to overcome this challenge and construct privacy preserving dissemination systems.

Added 2012-09-04