PathwayTools is a production-quality software environment for creating a type of model-organism database called a Pathway/Genome Database (PGDB). A PGDB such as EcoCyc integrates the evolving understanding of the genes, proteins, metabolic network and regulatory network of an organism. This article provides an overview of Pathway Tools capabilities. The software performs multiple computational inferences including prediction of metabolic pathways, prediction of metabolic pathway hole fillers and prediction of operons. It enables interactive editing of PGDBs by DB curators. It supports web publishing of PGDBs, and provides a large number of query and visualization tools. The software also supports comparative analyses of PGDBs, and provides several systems biology analyses of PGDBs including reachability analysis of metabolic networks, and interactive tracing of metabolites through a metabolic network. More than 800 PGDBs have been created using PathwayTools by scientists around the world, many of which are curated DBs for important model organisms. Those PGDBs can be exchanged using a peerto-peer DB sharing system called the PGDB Registry.
Pathway Tools is a production-quality software environment for creating a type of modelorganism database (MOD) called a Pathway/Genome Database (PGDB). A PGDB such as EcoCyc integrates the evolving understanding of the genes, proteins, metabolic network, and regulatory network of an organism. This article provides an overview of Pathway Tools capabilities. The software performs multiple computational inferences including prediction of metabolic pathways, prediction of metabolic pathway hole fillers, and prediction of operons. It enables interactive editing of PGDBs by database curators. It supports Web publishing of PGDBs, and provides a large number of query and visualization tools. The software also supports comparative analyses of PGDBs, and provides several systems biology analyses of PGDBs including reachability analysis of metabolic networks, and interactive tracing of metabolites through a metabolic network. More than 800 PGDBs have been created using Pathway Tools by scientists around the world, many of which are curated databases for important model organisms. Those PGDBs can be exchanged using a peer-to-peer database sharing system called the PGDB Registry.
16 violations, whether they are initiated by outsiders who attempt to break into a system or by insiders who attempt to misuse their privileges. NIDES is designed to be independent of any particular target system, application environment, level of audit data (e.g., user level or network level), system vulnerability, or type of intrusion, thereby providing a framework for a general-purpose intrusion-detection system using real-time analysis of audit data. Each target system must install an agen facility (see section 4.1) to collect audit data and put them into NIDES's generic audit record format. We have developed a exible audit record format and a protocol for the transmission of audit records from the target system. The NIDES protocol and its audit record format are system-independent; our intent is that NIDES can be used to monitor diierent systems (even simultaneously) without fundamental alteration. 5 Conclusions Intrusions can be detected by detecting departures from users' normal behavior patterns. In addition, a rule-based approach in which rules characterizing intrusive behavior are constructed for evaluation against observed user behavior can be used. The strength of the rst approach is that intrusive behavior that shows up in unforeseen ways can potentially be detected; the weakness is that certain behaviors generally agreed to be abusive or suspicious are not easily monitored for. The strength of the second approach is the ease of stating exactly that behavior that is considered intrusive or undesirable; conversely, its weakness is that only behavior that has been foreseen to be intrusive will be caught: novel or highly sophisticated attacks may go undetected. In addition, the use of other approaches, such as model-based reasoning and neural networks, appears to be promising. In order to eeectively address the various intrusion threats, a system should combine several intrusion-detection approaches. We should begin to see intrusion-detection systems that can intelligently make use of audit data gathered at several diierent levels from the monitored system (e.g., system call level, command line level, and application level). Prool-ing les and programs will give us another dimension along which to characterize expected behavior on a system. And there still remains a signiicant amount of research to be done in determining exactly which aspects of behavior are most indicative of intrusions. To obtain meaningful indicators of intrusive behavior, such research needs to have available many examples of actual intrusions. A library of such examples does not currently exist and is needed. As …
The power of Web Service (WS) technology lies in the fact that it establishes a common, vendor-neutral platform for integrating distributed computing applications, in intranets as well as the Internet at large. Semantic Web Services (SWSs) promise to provide solutions to the challenges associated with automated discovery, dynamic composition, enactment, and other tasks associated with managing and using service-based systems. One of the barriers to a wider adoption of SWS technology is the lack of tools for creating SWS specifications. OWL-S is one of the major SWS description languages. This paper presents an OWL-S Editor, whose objective is to allow easy, intuitive OWL-S service development and to provide a variety of special-purpose capabilities to facilitate SWS design. The editor is implemented as a plugin to the OWL ontology editor, and is being developed as open-source software.
SDTP is an architecture for secure distributed transaction processing. It is based upon X/Open's standard architecture for distributed transaction processing. In addition to the ACID (atomicity, consistency, isolation, and durability) properties provided by X/Open's architecture, SDTP guarantees that the Simple Security Property and the *-Property of the Bell-LaPadula model are satisfied. We have built a reference implementation of SDTP, formally proven the security properties of the implementation using novel verification techniques, and constructed two prototype applications of the architecture. The first application is a law enforcement tracking system, inspired by the FBI's Field Office Information Management System. The second application is an intrusion detection correlation system.
This paper describes the process of implementing an architecture for secure distributed transaction processing, the process of verifying that it has the desired security properties, and the implementation that resulted. The implementation and verification processes provided us with valuable experience relevant to answering several questions posed by our research on transformational development of architectures. To what extent can implementation-level architectural descriptions be derived from abstract description via application of transformations that preserve a broad class of properties, which includes satisfaction of various access control policies? To what extent can a formal derivation of a non-secure implementation-level distributed transaction processing architecture be reused in derivation of a secure architecture? Are the transformation verification techniques that we have developed sufficient for verifying a collection of transformations adequate for implementing complex secure architecture? Do our architecture hierarchies effectively fill the gap between abstract, intellectually manageable models of a complex architecture and the actual implementation? Exploring the answers to these questions resulted in a reference implementation of an architecture for secure distributed transaction processing, and an independently interesting demonstration instance of the reference implementation.
This paper describes the process of implementing an architecture for secure distributed transaction processing, the process of verifying that it has the desired security properties, and the implementation that resulted. The implementation and verification processes provided us with valuable experience relevant to answering several questions posed by our research on transformational development of architectures. To what extent can implementation-level architectural descriptions be derived from abstract description via application of transformations that preserve a broad class of properties, which includes satisfaction of various access control policies? To what extent can a formal derivation of a non-secure implementation-level distributed transaction processing architecture be reused in derivation of a secure architecture? Are the transformation verification techniques that we have developed sufficient for verifying a collection of transformations adequate for implementing complex secure architecture? Do our architecture hierarchies effectively fill the gap between abstract, intellectually manageable models of a complex architecture and the actual implementation? Exploring the answers to these questions resulted in a reference implementation of an architecture for secure distributed transaction processing, and an independently interesting demonstration instance of the reference implementation.
Describes a real-time intrusion-detection expert system (IDES), that observes user behavior on a monitored computer system and adaptively learns what is normal for individual users, groups, remote hosts, and the overall system behavior. Observed behavior is flagged as a potential intrusion if it deviates significantly from the expected behavior or if it triggers a rule in the expert-system rule base
Peter D Karp合作论文数Artificial Intelligence Center, SRI International3
Grit Denker合作论文数Computer Science Laboratory;EL284;SRI International1