The heart of any enterprise is its databases where the application data is stored. Organizations frequently place certain access control mechanisms to prevent access by unauthorized employees. However, there is persistent concern about malicious insiders. Anomaly-based intrusion detection systems are known to have the potential to detect insider attacks. Accurate modelling of insiders behaviour within the framework of Relational Database Management Systems (RDBMS) requires attention. The majority of past research considers SQL queries in isolation when modelling insiders behaviour. However, a query in isolation can be safe, while a sequence of queries might result in malicious access. In this work, we consider sequences of SQL queries when modelling behaviours to detect malicious RDBMS accesses using frequent and rare item-sets mining. Preliminary results demonstrate that the proposed approach has the potential to detect malicious RDBMS accesses by insiders.
Timely detection of an insider attack is prevalent among challenges in database security. Research on anomaly-based database intrusion detection systems has received significant attention because of its potential to detect zero-day insider attacks. Such approaches differ mainly in their construction of normative behavior of (insider) role/user. In this paper, a different perspective on the construction of normative behavior is presented, whereby normative behavior is captured instead from the perspective of the DBMS itself. Using techniques from Statistical Process Control, a model of DBMS-oriented normal behavior is described that can be used to detect frequency based anomalies in database access. The approach is evaluated using a synthetic dataset and we also demonstrate this DBMS-oriented profile can be transformed into the more traditional role-oriented profiles.
Achieving informed consent in online and digital contexts is challenging for several reasons. One reason is that conveying the meaning and implications of agreements to individuals is hindered by legalistic formats obscuring the potential harm that can ensue from analytics of data collected in a socio-technical context, such as online. Furthermore, as technical capability advances, what can be achieved with data mining and initiatives outpaces statutory regulation, as well as the social norms that frame individual human understandings. It is argued that the paradigm that currently underpins informed consent in online settings draws on ethical positions that are either utilitarian or legalistic. In contrast, the adoption of an ethics of virtue approach as a new paradigm provides a framework for reconceptualising informed consent. Characteristics that are material for informed consent, shared by Online Analytics and Qualitative Longitudinal Research, provide the inspiration and basis for this interdisciplinary approach, with the application of lessons learned in the practice and theory of one discipline to another.
Contemporary systems are built from complex arrangements of interoperating components implementing functional and other non-functional concerns that are necessary to ensure continuing service delivery. One of these concerns—resilience—relies on components that implement a variety of mechanisms, such as access controls, adaptability and redundancy. How these mechanisms interoperate with each other and the systems’ functional components to provide resilience is considered in this paper. External consistency, defined as the extent to which data in the system corresponds to its real-world value, provides a natural interpretation for the definition of resilience. A model of resilience is developed that can be used to trace how the functional and non-functional components in a system contribute to the determination of our confidence in the external consistency of the data that they process.
Purpose In this paper, the authors consider how qualitative research techniques that are used in applied psychology to understand a person’s feelings and needs provides a means to elicit their security needs. Design/methodology/approach Recognizing that the codes uncovered during a grounded theory analysis of semi-structured interview data can be interpreted as policy attributes, the paper develops a grounded theory-based methodology that can be extended to elicit attribute-based access control style policies. In this methodology, user-participants are interviewed and machine learning is used to build a Bayesian network-based policy from the subsequent (grounded theory) analysis of the interview data. Findings Using a running example – based on a social psychology research study centered around photograph sharing – the paper demonstrates that in principle, qualitative research techniques can be used in a systematic manner to elicit security policy requirements. Originality/value While in principle qualitative research techniques can be used to elicit user requirements, the originality of this paper is a systematic methodology and its mapping into what is actionable, that is, providing a means to generate a machine-interpretable security policy at the end of the elicitation process.
Recognising that the codes uncovered during a Grounded Theory analysis of semi-structured interview data can be interpreted as policy attributes, this paper describes how a Qualitative Research-based methodology can be extended to elicit Attribute Based Access Control style policies. In this methodology, user-participants are interviewed, and machine-learning is used to build a Bayesian Network based policy from the subsequent (Grounded Theory) analysis of the interview data.
In contemporary software development anybody can become a developer, sharing, building and interacting with software components and services in a virtual free for all. In this environment, it is not feasible to expect these developers to be expert in every security detail of the software they use, and we discuss how difficult it can be to build secure software. In this respect, the practical challenges of the emerging paradigm of developer-centered security are explored, where developers would be required to consider security from the perspective of those other developers who use their software. We question whether current user-centered security techniques are adequate for this task and suggest that new thinking will be required. Two directions---symmetry of ignorance and security archaeology-are offered as a new way to consider this challenge.
Access controls for Semantic Web applications are commonly considered at the level of the application-domain and do not necessarily consider the security controls of the underlying infrastructure to any great extent. Low-level network access controls such as firewalls and proxies are considered part of providing a generic network infrastructure that hosts a variety of Semantic Web applications and is independent of the application-level access control services. For example, it is unusual to include firewall policy rules in an application policy that constrain the kinds of application information different principals may access. As a consequence, an improperly configured infrastructure may unintentionally hinder the normal operation of a Semantic Web application. Simply opening a firewall for HTTP and HTTPS services does not necessarily result in a proper configuration. Taking an ontology-based approach, this paper considers how a firewall configuration should be analyzed with respect to the Semantic Web application(s) that it hosts.
Secure Semantic Web applications, particularly those involving access control, are typically focused at the application-domain only, rather than taking a more holistic approach to also include the underlying infrastructure (for example, firewalls). As a result, infrastructure configurations may unintentionally hinder and prohibit the normal operation of the Semantic Web. This paper, discusses an approach involving Description Logic and the Semantic Web Rule Language to provide synergy and alignment between firewall configurations and semantic-aware application configurations.
This panel highlights a selection of the most interesting and provocative papers from the 2004 New Security Paradigms Workshop. This workshop was held September 2004 - the URL for more information is (http://www.nspw.org). The panel consists of authors of the selected papers, and the session is moderated by the workshop's general chairs. We present selected papers focusing on exciting major themes that emerged from the workshop. These are the papers that will provoke the most interesting discussion at ACSAC.
EmoBot fabricates emotional behavior with fuzzy logic in the extended logic programming language: FRIL — Fuzzy Relational Inference Language (Baldwin, et. al. 1995). The deployment of fuzzy logic is primarily justified by the fuzziness of personality, and its great success in control applications analogous to EmoBot tasks.
Summary form only given. With the advent of Web services, achieving seamless interoperability between heterogeneous middleware technologies has become increasingly important. While much work investigating functional interoperability between different middleware architectures has been reported, little practical work has been done on providing a unified and/or interoperable view of security between the different approaches. We describe how Secure WebCom - a distributed metacomputing system - provides interoperability support between the COM+/.NET, CORBA and Enterprise Java Beans middleware security architectures. Secure WebCom uses the KeyNote trust management system to help coordinate the trust relationships between the different middleware systems and their associated security policies. Middleware authorisation policies can be encoded in terms of KeyNote cryptographic certificates, and vice-versa. This provides a unified view of security across heterogeneous middleware systems and also provides the basis for decentralised support of middleware security policies.
This paper considers a new security protocol paradigm whereby principals negotiate and on-the-fly generate security protocols according to their needs. When principals wish to interact then, rather than offering each other a fixed menu of 'known' protocols, they negotiate and, possibly with the collaboration of other principles, synthesise a new protocol that is tailored specifically to their current security environment and requirements. This approach provides a basis for autonomic security protocols. Such protocols are self-configuring since only principal assumptions and protocol goals need to be a-priori configured. The approach has the potential to survive security compromises that can be modelled as changes in the beliefs of the principals. A compromise of a key or a change in the trust relationships between principals can result in a principal self-healing and synthesising a new protocol to survive the event.
A hash-chain based micropayment scheme is cast within a trust management framework. Cryptographic delegation credentials are used to manage the transfer of micropayment contracts between public keys. Micropayments can be efficiently generated and determining whether a contract and/or micropayment should be trusted (accepted) can be described in terms of a trust management compliance check. A consequence is that it becomes possible to consider authorisation based, in part, on monetary concerns. The KeyNote trust management system is used to illustrate the approach.
WebCom is a distributed computing architecture that may be used to. distribute application components for execution over a network. A practical trust management system for the WebCom architecture is described. KeyNote-based authorization credentials are used to determine whether a WebCom server is authorised to schedule, and whether a WebCom client is authorised to execute, mobile application components. Secure WebCom provides a meta-language for bringing together the components of a distributed application in such a way that the components need not concern themselves with security issues.
Synchronizing Personal Digital Assistants with host systems can result in indirect accesses that bypass security requirements. In this paper we propose a framework for analyzing the security vulnerabilities that can arise from synchronization. This framework provides us with the basis of a paradigm for analyzing the access-control vulnerabilities of systems comprised of secure and non-secure components. 1 I n t r o d u c t i o n Personal Digital Assistants (PDAs) such as the Palm handheld are small hand-held computing devices that support a variety of applications, ranging from conventional electronic organizer programs to spreadsheets, electronic mail and web browser clients. A PDA is commonly viewed as an extension of a User's workstation (or server); carrying data and programs that often mirror data and programs from the workstation. Synchronization between the workstation and the PDA is performed on a regular basis, ensuring that changes made to data stored on the PDA are reflected on the workstation, and vice-versa. Little consideration has been given to the security policy implications of using these devices as part of an application system. While PDAs are typically Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. To copy otherwise, to republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. New Security Paradigm Workshop 9•00 Ballycotton, Co. Cork, Ireland © 2001 ACM ISBN 1-58113-260-3/01/0002...$5.00 single-user systems supporting little or no accesscontrol, they are expected to synchronize with multiuser host systems that do have access-control requirements. This synchronization may be used to bypass host system access-controls. For example, an employee working in sales and engineering departments is subject to the security requirement that sales data may not be written to engineering datasets. If we are not confident about the employee's PDA upholding this requirement then synchronization must ensure that at any one time, either sales or engineering information is carried on the employee's PDA, but not both. Other scenarios are possible, for example, the PDA carries both engineering and sales datasets for information purposes. However, only sales data can be two-way synchronized with the host system. In this paper we consider the analysis of accesscontrol vulnerabilities that can arise from synchronizing host systems with PDAs. The approach first considers our confidence in the access constraints of the individual components and then analyzes whether that confidence can be maintained when the components synchronize. While a component such as a Palm does not have an access-control mechanism, we can still specify, albeit with low confidence, the access limitations that we believe the installed software implicitly provides. Our framework provides us with the basis of a paradigm for analyzing the security vulnerabilities of systems comprised of secure and nonsecure components. Arbitrary access policies can be abstractly represented in terms of directed graphs [7] or as reflexive orderings [5]. We use reflexive orderings to represent
Conventional models of system integrity tend to be implementation-oriented in that they define integrity in terms of specific controls such as separation of duties, well-formed transactions, and so forth. In this paper we propose a formal definition of integrity that is based on the notion of dependability and is implementation independent. Using a series of examples, we argue that separation of duties, assured pipelines, fault-tolerance, and cryptography may be viewed as implementation techniques for achieving integrity.
In the proposed mandatory access control model, arbitrary, label changing policies can be expressed. The relatively simple model can capture a wide variety of security policies, including high-water marks, downgrading, separation of duties, and Chinese Walls. The model forms the basis for a tiered approach to the formal development of secure systems, whereby security verification can be spread across what makes up the reference monitor and the security requirement specification. The advantage of this approach is that once a trusted computing base (TCB) is in place, reconfiguring it for different security requirements requires verification of just the new requirements. We illustrate the approach with a number of examples, including one policy that permits high-level subjects to make relabelling requests on low-level objects; the policy is multilevel secure.
Reflexive flow policies provide abstract characterizations of certain multilevel confidentiality requirements. This paper describes how reflexive flow policies can be used to construct and reason about large/complex multilevel policies. In particular, we describe how reflexive policies can be used to develop and reason about security policies for multilevel relational databases. Our approach facilitates a study of the relationship between security policy design and database design.< >