Gov4You is a federal government agency responsible for managing and sharing citizen information for large groups of the population. The Gov4You department was created almost 15 years ago to meet the election promise of providing better information services to the citizens. The department was setup to provide complete digital services for citizens. The digital citizen services must cater to the large demographic differences, and for those that are digitally savvy as well as those without any access to the Internet. These services are currently provided by several different departments that sometimes require physical visits by the citizens to the departments with a lot of paper work for identification and service request forms. However, citizens demand better services that use digital platforms in 24 × 7 formats. This concept of providing service using a digital transformation is referred to as ‘Smart …
This book presents the concepts, algorithms and components of high performance semantic cloud auditing systems to improve performance and security. Coverage includes auditing techniques, data collection techniques and storage and sharing techniques.
Bring Your Own Device (BYOD) is an enterprise information technology (IT) policy that encourages employees to use their own devices to access sensitive corporate data at work through the enterprise IT infrastructure. Many current BYOD security practices are costly to implement and intrusive to employees, which, to some degree, negate BYOD's perceived benefits. To address such tension, we propose prioritized defense deployment: Instead of employing the same costly and intrusive security measures on each BYOD smartphone, more stringent threat detection/mitigation mechanisms are deployed on those representative smartphones, each of which represents, security-wise, a group of smartphones in the whole BYOD device pool. To this end, we propose a concept and a distributed algorithm, both named T-dominance, to capture the temporal-spatial pattern in an enterprise environment. We identify a few desirable properties of prioritized defense deployment, and analytically show that T-dominance satisfies such properties. We complement our analysis with simulations on real Wi-Fi association traces.
Multi-tenancy, elasticity and dynamicity pose several novel challenges for access control in mobile smartphone clouds such as the Android $\textsuperscript\texttrademark$ cloud. Accessing subjects may dynamically change, resources requiring protection may be created or modified, and a subject's access requirements to resources may change during the course of the application execution. Cloud tenants may need to acquire permissions from different administrative domains based on the services they require. Moreover, all the entities participating in a cloud may not be trusted to the same degree. Traditional access control models are not adequate for mobile clouds. In this work, we propose a new access control framework for mobile smartphone clouds. We formalize a trust-based access control model with delegation for providing fine-grained access control. Our model incorporates the notion of trust in the Role-Based Access Control RBAC model and also formalizes the concept of trustworthy delegation.
Due to the rapid emergence of Information Technology, cloud computing provides assorted advantages to service providers, developers, organizations, and customers with respect to scalability, flexibility, cost-effectiveness, and availability. However, it also introduces new challenges and concerns, especially in terms of security and privacy. One of the major security obstacles to widespread adoption of cloud computing is the lack of near-real-time audit ability. In particular, near-real-time cloud auditing, which provides timely evaluation results and rapid response, is the key to assuring the cloud. In this paper, we discuss security and privacy concerns in cloud computing and the current status of cloud auditing efforts. Next, we address the strategies for reliable cloud auditing and analyze the deficiencies of current approaches. We then discuss the summary of our case study with Amazon Cloud Watch, which is one of the most developed cloud-monitoring APIs.
In today's ever-increasingly digital world, the concept of data privacy has become more and more important. Researchers have developed many privacy-preserving technologies, particularly in the area of data mining and data sharing. These technologies can compute exact data mining models from private data without revealing private data, but are generally slow. We therefore present a framework for implementing efficient privacy-preserving secure approximations of data mining tasks. In particular, we implement two sketching protocols for the scalar (dot) product of two vectors which can be used as sub-protocols in larger data mining tasks. These protocols can lead to approximations which have high accuracy, low data leakage, and one to two orders of magnitude improvement in efficiency. We show these accuracy and efficiency results through extensive experimentation. We also analyze the security properties of these approximations under a security definition which, in contrast to previous definitions, allows for very efficient approximation protocols.
The ability to localize Internet hosts is appealing for a range of applications from online advertising to localizing cyber attacks. Recently, measurement-based approaches have been proposed to accurately identify the location of Internet hosts. These approaches typically produce erroneous results due to measurement errors. In this paper, we propose an Enhanced Learning Classifier approach for estimating the geolocation of Internet hosts with increased accuracy. Our approach extends an exisiting machine learning based approach by extracting six features from network measurements and implementing a new landmark selection policy. These enhancements allow us to mitigate problems with measurement errors and reduces average error distance in estimating location of Internet hosts. To demonstrate the accuracy of our approach, we evaluate the performance on network routers using ping measurements from PlanetLab nodes with known geographic placement. Our results demonstrate that our approach improves average accuracy by geolocating internet hosts 100 miles closer to the true geographic location versus prior measurement-based approaches.
Botnets have become the top threat to Internet security. Botnets generate and transmit huge amounts of malicious traffic for various purposes. In this paper, we propose a dynamic programming based algorithm to calculate a set of appropriate routers for placing early filters of malicious traffic in the network in order to maximize the benefits of early malicious traffic filtering. Moreover, we discuss how to combine our early filtering approach and the QoS routing of traffic so that the bandwidth saved by early filtering of malicious traffic can be efficiently utilized by legitimate traffic.
In general, network traffic data has a heavy-tailed probability distribution. The Entropy-Based Heavy Tailed Distribution Transformation (EHTDT) has been developed to convert the heavy tailed network traffic data distribution into a transformed probability distribution. In practice, the entropy distribution of the transformed probability distribution exhibits a type of linearity that gives rise to an eigenstructure that allows the characterization of network traffic data to effectively lossily compress network traffic data via the Rate Controlled Eigen-Based Coding. The aforementioned eigenstructure is motivated by singular value decomposition theory. A very high compression ratio can be achieved by the proposed method. Results of applying the methods to real network traffic data network traffic data are presented.
: The annual accomplishments include new algorithms that use network coding for: data hiding without the use of a key - ensuring sufficient degrees of freedom to decode over the receiver in variable settings, creating efficient coding schemes for Byzantine attacks, and providing quantification of the benefits to network coding.
Recent research has shown that network coding can be used in content distribution systems to improve the speed of downloads and the robustness of the systems. However, such systems are very vulnerable to attacks by malicious nodes, and we need to have a signature scheme that allows nodes to check the validity of a packet without decoding. In this paper, we propose such a signature scheme for network coding. Our scheme makes use of the linearity property of the packets in a coded system, and allows nodes to check the integrity of the packets received easily. We show that the proposed scheme is secure, and its overhead is negligible for large files.
Database management system (DBMS) controls and manages data to eliminate data redundancy and to ensure integrity, consistency and availability of the data, among other features. Even though DBMS vendors continue to offer greater automation and simplicity in managing databases, the need for specialized intrusion detection database compression technology has not yet been addressed. Our research focuses on developing such technology. The focus is not only on compression but also on database management through planning and best practice adoption to improve operational efficiency, and provide lower costs, privacy and security. The focus in this summary is on the compression part of the DMBS system for intrusion detection. We present a methodology employing grammar-based and large alphabet compression techniques which involves the generation of multiple dictionaries for compressing clustered subfiles of a very large data file. One of the dictionaries is a common dictionary which models features common to the subfiles. In addition, non-common features of each subfile are modeled via an auxiliary dictionary. Each clustered subfile is compressed using the augmented dictionary consisting of the common dictionary together with the auxiliary dictionary for that subfile.
The use of network coding in military networks opens many interesting issues for security. The mixing of data inherent to network coding may at first appear to pose challenges, but it also enables new security approaches. In this paper, we overview the recent current theoretical understanding and application areas for network-coding based security in the areas of robustness to Byzantine attackers and of distributed signature schemes for downloads.
We consider the problem of network coding across multiple unicasts. We develop, for wired and wireless networks, off-line and online back pressure algorithms for finding approximately throughput-optimal network codes within the class of network codes restricted to XOR coding between pairs of flows. Our online algorithm incorporates real-time control signaling with delays, and random exploration approaches for reducing computation. I. I NTRODUCTION In this paper we consider network coding across multiple unicasts, using the class of pairwise XOR codes introduced in [12], [13] for wired networks. While this class of codes is not optimal in all cases 1, it covers a substantial number of common known cases including “reverse carpooling” and two-flow “star coding” for wireless networks [6]. In this class of codes, network coding is limited to XOR coding between pairs of uncoded packets. Two uncoded packets of different sessions can be coded together to form a joint poisonpacket in order to share capacity on one or more hops. The joint poison packet is subsequently replicated to form two identicalindividual poisonpackets whose routes branch (diverge). These are met by corresponding remedypackets and decoded to form the original uncoded packets. Decoded packets can be subsequently re-encoded. We consider the problem of constructing throughputoptimal network codes within this class on wired and wireless networks. In an off-line setting we develop, for a given network and communication demands, a combinatorial approximation algorithm that finds a solution for the proble m with rates (rc) if there exists a solution for the problem with slightly higher rates((1 + 2ǫ)rc) for any ǫ > 0. In a dynamic online setting, we incorporate real-time control signaling with delays, and approaches for reducing computation through random exploration of the optimization spac e. Our approach is inspired by back pressure techniques originally introduced for the multiple unicasts problem withou t coding [1], [14], which maintain a queue for each session’s packets at each node, and route based on queue gradients that form by the addition of packets to sources and their removal from sinks. Extension of this approach to incorporate codin g is not straightforward due to some significant complicating features. Firstly, since the path taken by a packet affects its future coding possibilities, uncoded packets of the sam e session that have arrived at the same node via different path s This work was supported by the Caltech Lee Center for Network ing and AFOSR Grant 5710001972. T. Ho is with the California Institute of Technology. Y. Chang is with the University of Southern California. K. J. Han is with the Air Force Research Laboratory. 1Linear coding is not sufficient in general for multiple unicas ts [4], [5]. may have to be treated as separate commodities (where a commodity is a class of packets that are treated interchange ably from the standpoint of scheduling, routing and coding decisions, without affecting the throughput of each sessio n).2 Secondly, a poison packet is removed by its corresponding remedy packet when they meet at any node in the network, unlike the no coding case where all packets of a session are removed independently at a fixed location. Consequently , the choice of how different commodities are defined has important bearing on the optimality and complexity of the algorithm. A. Other related work For brevity we do not list many other works on network coding and on back pressure techniques in networking, but mention here a few that are most closely related to this work. Back pressure has previously been applied to multicas t network coding [8]. Opportunistic XOR coding is proposed in [9]. A more general approach for multiple unicast network coding based on state space realizations is given in [13]. Constructive XOR coding across pairs of unicasts is considered in [13], [15] using a linear optimization approach. Independent work by [7] also considers back pressure for the same problem; while their algorithm superficially resemble s ours, it differs in a number of significant aspects. For instance, [7] defines commodities solely by their destinati on and multicast group (poison flows are multicast), i.e. at eac h nodei, packets intended for a particular destination node d within a multicast groupD are placed in a queue Q i . We define commodities quite differently, as described in the following sections. In [7] a coding node remotely chooses the remedy origination locations as well as the decoding locations based on the queue lengths at these locations; in our algorithms the decoding locations are not predetermine d by the coding node but are chosen locally. II. PROBLEM STATEMENT AND DEFINITIONS K unicast sessions are transmitted over a network represented as a directed graph G = (N ,L) of N = |N | nodes andM = |L| links. We refer to a unit of flow as a packet. The off-line version of the problem specifies the demanded communication raterc for each sessionc = 1, . . . ,K, and a set of link rates (in the wireline case) or link rate constrai nts (in the wireless case). A solution specifies different types of packets and the average rates at which they are transmitted, coded, decoded, etc., at different nodes and links. 2A poison packet must nonetheless be labeled with the identifie rs of its constituent packets, since remedy and poison packets must be c orr ctly matched for actual decoding purposes. In the online version of the problem, the instantaneous source arrival rates and link capacities/constraints may v ar ergodically. For simplicity of exposition we assume that th e channel and arrival processes are independent and identica lly distributed across time slots; a straightforward generali zation to ergodic processes is possible using a similar approach as that in [11]. Here we give a dynamic policy that depends on the state of the network. In both cases, we show optimality of our algorithms by comparison with an assumed, but unknown, pairwise XORcoding solution. A solution is made up of elementary flows such that all packets in an elementary flow undergo the same routing and coding operations. Each elementary flow has a set of links comprising a singleprimary path from sc to dc and a remedy path associated with each node at which decoding occurs. III. O FF-LINE PROBLEM A. Commodities We define a number of commodities, each with its own conceptual “queue”, at each node i: • U cv i : uncoded session c packets also stored at node v • P {c,c}j i : joint poison packets from sessions c, c ′ coded at nodej meant for both sinks • P cc j i : individual poison packets from sessions c, c ′ coded at nodej meant for sinkdc • R j i : remedy for session c packets that has been coded with sessionc packets at nodej B. Modified problem Off-line, we can reduce complexity by considering a modified problem which reverses the direction of the poison flows while not changing the link capacity usage. Thus, any solution of the modified problem can be translated to a solution of the original problem and vice versa. In the modified problem, coding two uncoded packets p1, p2 together produces two remedy packets, each at some node previously traversed by p1, p2 respectively. Each remedy packet is transformed by a decodingoperation at some node into an uncoded packet and an individual poison packet. Two individual poison packets can be transformed by a branchingoperation into a joint poison packet, and all poison packets are removed at their original coding node, as shown in Figure 1 and described formally below. For each link (a, b) such thatCab > ∑ c rc, set Cab to ∑ c rc, and let C̄a be the larger of the total incoming capacity and total outgoing capacity of each node a ∈ N . At each source node sc we define two additional queues: a source queueU c and an overflow queuē U . We also define a number of virtual links: at each source node sc a virtual source link of capacityC̄sc from U c to U csc sc , and at each nodea a virtual coding link, a virtual decoding link and a virtual branching link, each of capacitȳ Ca/2. Each real and virtual link e is associated with a transmission set Pe of pairs (O,D) such that packets from each queue in the set O are transformed into an equivalent number of packets in each queue in the set D via e: S r c A U ( A , v 1 ) P ( B , A , v 3 ) U ( B , v 2 ) P ( A , B , v 3 ) R ( A , B , v 3 ) R ( B , A , v 3 ) S r c B R c v B R c v A P ( { A , B } , v 3 ) v 1 v 2 v 3 Fig. 1. Illustration of commodities in off-line case. The dire ction of the poison flows (labeledP ) is the reverse of their physical (causal) direction from the canonical butterfly example. • if e is the virtual source link for session c, Pe = (U , U csc sc ) • if e is a real link (a, b) ∈ L, Pe = {(U cv a , U cv b ), (U cv a , U ca b ), (P {c,c}j b , P {c,c}j a ), (P cc j b , P ccj a ), (R ccj a , R ccj b )} • if e is the virtual coding link at nodea, Pe = {( {U cv a , U cv a }, {R cca v′ , R cca v } ) : c 6= c; a 6= v, v } • if e is the virtual decoding link at nodea, Pe = {( R j a , {P ccj a , U cj a } )
Database management system (DBMS) controls and manages the data to eliminate data redundancy and to ensure data integrity, consistency and availability, among other features. Even though DBMS vendors continue to offer greater automation and simplicity in managing databases, the need for intrusion database modeling and management practices have not been considered. Our research focuses on not only anomaly detection but also intrusion database management through planning and best practice adoption to improve operational efficiency, lower costs, privacy and security
Computer security has become the main stream issue to protect the sensitive information in open networks. The complete secure system is hard to design these days due to vulnerabilities in firewalls, file and application servers, email servers, and Web servers. The solution to problems of computer security and privacy can be achieved by the cryptography mechanism. A popular way to implement security protocols uses a combination of several cryptographic schemes to overcome various limitations of security primitives. The design of scalable security protocols that are interrelated with a single cryptosystem for multimedia is a challenging cryptographic technology in the cryptologic research community. We propose the scalable cryptographic scheme for security services. The proposed eigen-based security primitives solves a wide range of secrecy, non-repudiation, authenticity, and integrity problems in many security aware multimedia applications. The new cryptography technology may play an important role in the trusted network interpretation environments
Shot boundary detection is an important for retrieval of visual media in multimedia systems. Video temporal segmentation algorithms use thresholding techniques to identify both abrupt shot changes and gradual shot transitions. Thresholding methods frequently provide false positives due to large variations in gradual transition regions. The principal component decomposition and progressive nonlinear filter (PNF) have been developed to suppress spurious temporal information in gradual transition regions while preserving abrupt shot changes. The spurious shot boundary information can be further minimized by a multistage shot boundary detection approach.
Important issues in multimedia information systems are the development of efficient storage layout models and effective retrieval system to manage multimedia databases. In multimedia information systems, the capability for interaction with video media type is still extremely limited due to a huge amount of video databases. We present the Fast Polynomial Regression Transform (FPRT) based metadata scheme for manipulating the large video database in the paper. This new metadata scheme provides the simplification of the query mechanism and the improvement of communication in multimedia systems. The main advantage of the proposed approach is the reduction of the data storage space while preserving much video content information. Other advantages are computational simplicity for video information coding and accuracy for video indexing. Visual tools for video representation and browsing are also presented
A new low complexity approach to motion estimation for video indexing is proposed. The fast polynomial regression transform (FPRT) is utilized to provide the efficient storage layout model and effective video database for manipulating the multimedia information system. The video content information of video image is compressed by FPRT. Global translational motion vectors and location of dynamic regions are computed from the compressed data. Our experiments show that this approach is very efficient for fast motion based video indexing
Ralf Koetter合作论文数Institute for Communications Engineering, Department of Electrical and Computer Engineering, Technical University of Munich2