
This paper describes an application of computational trust techniques to enhance the water-supply service information system of the Town of Cava de’ Tirreni, Italy. The study case covers a population of almost 52 000 people and about 23 000 consumption contracts. The Town Council is responsible for the water supply service and its billing process. A correct billing process requires gathering water consumption data of each citizen, task that is partially not controllable by Town Council personnel and therefore cannot be accomplished properly without the citizen’s cooperation. Bad or malicious data are potentially harmful for both parties. The aim of this experimentation is to exploit computational trust techniques to better manage the process of validation of the received data. Computational Trust added value is represented by its autonomic implementation and by its in-depth consideration of social and environmental variables that go beyond simple data validation. The evaluation section, covering 6 years of data, will present the encouraging results obtained.
The use of reputation systems has been proposed for various applications, e. g., to estimate the trustworthiness of sellers and buyers in electronic transactions. Reputation systems collect opinions of users about properties of certain services, subjects and other users and evaluate these opinions. It is important that the results of reputation systems are consistent with intuitive expectations of its users, which highly depends on the properties of the underlying trust model. The trust model defines the representation of the trust values as well as the computation of trust values for derived trust relations.
Global satellite navigation systems such as GPS enable precise tracking of vessels worldwide and pervasive global networks such as the Internet allow sharing of this information almost instantaneously between locations anywhere on Earth. This ability to monitor vessels globally is a topic of current debate among those concerned with national security, those who are mainly interested in safety at sea and those who advocate for privacy rights at the personal, commercial and national level. In this paper we discuss two maritime self-reporting systems, namely the Automatic Identification System and Long Range Identification and Tracking, which have given rise to this debate. The benefits and drawbacks of each are discussed with safety, security and privacy in mind. Also, some connections are drawn between these systems and Mobile Ad Hoc Networks and Radio Frequency Identification where security and privacy are also of current interest.
In this paper, we first present a private distributed scalar product protocol that can be used for obtaining trust values from private recommendations. Our protocol allows Alice to infer the trustworthiness of Bob based on what Alice’s friends think about Bob and Alice’s confidence in her friends. In addition, the private information of Alice and her friends are not revealed during the computation. We also propose a credential-based trust model where the trustworthiness of a user is computed based on his or her affiliations and role assignments. The trust model is simple to compute, yet it is scalable as it classifies large groups of users
Most small and medium-sized enterprises (SME) operate from a single address, which means that backups are normally kept at the same physical location as the company's computers. This means that fire, flooding or other disasters are likely to destroy both computers and the backups that were meant to ensure the continued operation of the company. The price per Giga-byte of hard disk storage is falling and at the same time the bandwidth of the connection from small companies to the Internet is increasing, so it appears logical for small companies to achieve improved availability of their backups by storing backups on the hard disk of one or more remote computers. However, storing business-critical information or customer data on a foreign computer requires a mechanism that preserves the secrecy and ensures the integrity of the stored data. This paper presents Resilia, which is a safe and secure backup system that allows a company to distribute its backup among a number of remote servers, thereby ensuring availability, without compromising the confidentiality and the integrity of the backup. The confidentiality of data in Resilia is ensured with an encryption technique known as threshold cryptography, which means that a backup can be restored even if all cryptographic keys are lost in a disaster. We describe a working prototype of Resilia and report initial performance numbers for the developed prototype.
In virtual organisations, the authorisation and expression of policies in terms of direct trust relationships between providers and consumers have the problems of scalability, flexibility, expressibility, and lack of policy hierarchy because of interdependent institutions and policies [7]. This paper proposes a bilateral negotiation protocol and an English auction to negotiate a list of credentials to be exchanged after a service level agreement has been drafted, and that would provide sufficient trustworthiness. for the parties in the negotiation. We implement and evaluate our algorithms as grid services in a virtual organisation (VO) to show the effect of negotiation on the trustworthiness achieved within a VO.
Pervasive environments are composed of devices with particular hardware characteristics, running various software and connected to diverse networks. In such environments, heterogeneous devices must cooperate to offer meaningful services to users, regardless of technological choices such as service discovery and access protocols. Interoperability thus is a critical issue for the success of pervasive computing. In this context, we have previously introduced the MUSDAC middleware for interoperable service discovery and access across heterogeneous networks. Still, data exchanged in pervasive environments may be sensitive, and as service information is forwarded to unknown or untrusted networks, privacy issues arise. In this paper we present a privacy-aware solution for service discovery in heterogeneous networks, based on the MUSDAC platform. Specifically, we discuss privacy issues that arise during service discovery and mechanisms to control disclosure of private information contained in service-related data
Purpose appears in all privacy guidelines, codes, policies, and legislations. It plays a central role in many privacy-related systems such as P3P, Hippocratic databases, EPAL, and XACML. We show that the P3P 12 standard purposes mix uses of personal information with acts on personal information and mix uses of personal information privacy with other states of affairs that have several interpretations. Some purposes are not even strongly privacy-related purposes. In this paper, P3P is singled out as the object of study; however, the implication applies similarly to other projects. We propose to use chains of information handling that let the user exercise more control on the use of his/her PI and allow the personal information gatherer to excise more control on the processing and accessing of information in its procession.
The resource constraints and unattended operation of wireless sensor networks make it difficult to protect nodes against capture and compromise. While cryptographic techniques provide some protection, they do not address the complementary problem of resilience to corrupted sensor data generated by failed or compromised sensors. Trusting data from unattended sensor nodes in critical applications can have disastrous consequences. We propose a behavior-based trust mechanism to address this problem in static sensor networks, in which the location of nodes is known. We take advantage of domain knowledge which includes: (i) physical constraints imposed by the local environment where sensors are located, (ii) expectations of the monitored physical phenomena; and (iii) sensor design and deployment characteristics. The system diagnoses and isolates faulty/malicious nodes even when readings of neighboring nodes are faulty. The goal of this system is to increase work effort and capabilities required by an attacker. The framework and related techniques of behavior-based trust are discussed in this paper.
A CAPTCHA is a special kind of AI hard test to prevent bots from logging into computer systems. We define an AI hard test to be a problem which is intractable for a computer to solve as a matter of general consensus of the AI community. On the Internet, CAPTCHAs are typically used to prevent bots from signing up for illegitimate e-mail accounts or to prevent ticket scalping on e-commerce web sites. We have found that a popular and distributed architecture for implementing CAPTCHAs used on the Internet has a flawed protocol. Consequently, the security that the CAPTCHA ought to provide does not work and is ineffective at keeping bots out. This paper discusses the flaw in the distributed architecture’s protocol. We propose an improved protocol while keeping the current architecture intact. We implemented a bot, which is 100
Can we trust without any reliable truth information? Most trust architectures work in a similar way: a trustor makes some observations, rates the trustee, and makes recommendations to his friends. When he faces a new case, he checks his trust table and uses recommendations given by trustworthy friends to decide whether he will undertake a given action. But what if the observations that are used to update the trust tables are wrong? How to deal with what we call the "uncertainty of the truth"? This paper presents how people that publish and remove virtual tags are able to create trust relations between them. A simulator as well as a concrete and widely deployed application have been used to validate our model. We observed good and encouraging results in general, but also some weaknesses, brought out through specific scenarios.
Trust is an interesting criterion for analyzing and comparing network protocols. The goal of this paper is to explicit the different types of trust relations between entities which exchange routing information and establish a routing infra-structure based on the OLSR protocol. One such entity assumes the other entities will behave in a particular way and the relations coming from this trust behavior are expressed in this paper using a formal language. This approach. highlights the process of trust construction in OLSR and allows the analysis of trust requirements for this protocol, as well as the expression of attacks related to the betrayal of trust relations. Besides, this analysis allows the description of indicators for OLSR entities to have a protective mistrust behavior when effectively acting based on trust relations.
We describe two techniques for reducing the effectiveness of sybil attacks, in which an attacker uses a large number of fake user accounts to increase his reputation. The first technique uses a novel transformation of the ranks returned by the PageRank system. This transformation not only reduces susceptibility to sybil attacks but also provides an intuitive and easily interpreted reputation score. The second technique, called RAW, eliminates remaining vulnerabilities and allows full personalization of reputations, a necessary condition for a sybilproof reputation system.
Trust transfer is a common technique employed in trust management systems to establish relationships between parties that are strangers. It is also well known that trust is not always transferable. That is, given an existing trust relationship, it may or may not be possible to derive new trust from it. In particular, it is not known under which constraints trust is transferable. In this paper we investigate trust transfer and identify when trust is transferable. Our analysis starts with a simple trust model. By using the model, we find that trust transfer is related to trust policy entailment. We then present a modal logic system which captures how trust and beliefs evolve in distributed systems. With the modal logic system we identify the key constraints on trust transfer regarding the communication between the trustor and the recommender and the trustor's belief state.
Reputation systems appear to be inherently biased towards better than-average ratings. We explain this as a consequence of self-selection, where reviewers are drawn disproportionately from the subset of potential consumers favorably predisposed toward the resource. Inflated ratings tend to attract consumers with lower expected value, who have a greater chance of disappointment. Paradoxically, the more accurate the ratings, the greater the degree of self-selection, and the faster the ratings become biased. We derive sufficient conditions under which biased ratings occur. Finally, we outline a potential solution to this problem that involves stating expectations before interaction with the resource, and expressing subsequent ratings in terms of delight or disappointment.
We describe the application of our collaboration-oriented software engineering approach to the design of trust-aware systems. In this model-based technique, a specification does not describe a physical system component but the collaboration between various components which achieve system functions by cooperation. A system model is composed from these collaboration specifications. By a set of transformations, executable code can be automatically generated. As a modeling language, we use UML 2.0 collaborations and activities, for which we defined a semantics based on temporal logic. Thus, formal refinement and property proofs can be provided by applying model checkers as well. We consider our approach to be well-suited for the development of trust-based systems since the trust relations between different parties can be nicely modeled by the collaborations. This ability facilitates also a tight cooperation between trust management and software engineering experts which are both needed to create scalable trust-aware applications. The engineering approach is introduced by means of an electronic auction system executing different policies which are guided by the mutual trust of its principals. While the approach can be used for various trust models, we apply Jøsang’s Subjective Logic in the example.
In this paper, we present two new control flow based point-cuts to Aspect-Oriented Programming (AOP) languages that are needed for systematic hardening of security concerns. They allow to identify particular join points in a program’s control flow graph (CFG). The first proposed primitive is the GAFlow, the closest guaranteed ancestor, which returns the closest ancestor join point to the pointcuts of interest that is on all their runtime paths. The second proposed primitive is the GDFlow, the closest guaranteed descendant, which returns the closest child join point that can be reached by all paths starting from the pointcuts of interest. We find these pointcuts to be necessary because they are needed to perform many security hardening practices and, to the best of our knowledge, none of the existing pointcuts can provide their functionalities. Moreover, we show the viability and correctness of our proposed pointcuts by elaborating and implementing their algorithms and presenting the results of a testing case study.
A connection-chain refers to the set of connections created by sequentially logging into a series of hosts. Attackers typically use connection chains to indirectly carry their attacks and stay anonymous. In this paper, we proposed a host-based algorithm to detect connection chains by passively monitoring inbound and outbound packets. In particular, we employ concepts from association rule mining in the data mining literature. The proposed approach is first explained in details. We then present our evaluations of the approach in terms of real-time and detection performance. Our experimentations suggest that the algorithm is suitable for real-time operation, because the average processing time per packet is both constant and low. We also show that by appropriately setting underlying parameters we can achieve perfect detection.
Over the last few years researchers have recognized the need for adaptive access control mechanisms for dynamic collaborative environments. As a result, several mechanisms have been proposed and demonstrated in academic literature. Although these mechanisms have been verified to perform as advertised, few of them have been validated to work within an operational environment. Using a decentralized trust-based access control system of their own design, the authors validated their system using a narrative technique to develop a realistic operational scenario. They tested the system within the scenario and then applied a cost and a success metric to the results to determine the efficiency of their mechanism. The results show how the authors' narrative approach and success metric combine to provide more efficient and effective analysis of how an access control mechanisms will perform when used in an operational environment.
E-learning systems have made considerable progress within the last few years. Nonetheless, the issue of learner privacy has been practically ignored. The security of E-learning systems offers some privacy protection, but remains unsatisfactory on several levels. In this work, we corroborate the need for privacy in E-learning systems. In particular, we introduce a framework for privacy preserving E-learning to provide the learner with the possibility of combining different levels of Privacy and Tracking to satisfy his personal privacy concerns. This allows the learner to perform learning activities and to prove his achievements (such as with anonymous transcripts and anonymous degrees) without exposing various aspects of his private data. In addition, we introduce the Blind Digital Certificate, a digital certificate that does not reveal the learner’s identity. Finally, we report on the implementation and validation of our approach in the context of an E-testing system.