Access control is a critical feature of many systems, including networks of services, processes within a computer, and objects within a running process. The security consequences of a particular architecture or access control policy are often difficult to determine, especially where some components are not under our control, where components are created dynamically, or where access policies are updated dynamically. The SERSCIS Access Modeller (SAM) takes a model of a system and explores how access can propagate through it. It can both prove defined safety properties and discover unwanted properties. By defining expected behaviours, recording the results as a baseline, and then introducing untrusted actors, SAM can discover a wide variety of design flaws. SAM is designed to handle dynamic systems (i.e., at runtime, new objects are created and access policies modified) and systems where some objects are not trusted. It extends previous approaches such as Scollar and Authodox to provide a programmer-friendly syntax for specifying behaviour, and allows modelling of services with mutually suspicious clients. Taking the Confused Deputy example from Authodox we show that SAM detects the attack automatically; using a web-based backup service, we show how to model RBAC systems, detecting a missing validation check; and using a proxy certificate system, we show how to extend it to model new access mechanisms. On discovering that a library fails to follow an RFC precisely, we re-evaluate our existing models under the new assumption and discover that the proxy certificate design is not safe with this library.
In this chapter we present a survey of research work related to the semantic modelling of security, semantic SLA modelling, and the current state of the art in SLA-based system governance. Based on this survey, and after observing the essential aspects needed to semantically model an SLA, we first propose a semantic model of resource dependability. This model can be used to semantically encode in SLA the service commitments (to customers) and resource capacity (from suppliers) in terms of usage, performance, and other QoS characteristics that represent non-functional properties. On the basis of this model, we propose a flexible approach to SLA-based system governance that allows for elastic provisioning of resources (by autonomic processes) that meet NFP requirements. This approach can be used to monitor and manage services such that they meet (and continue to meet) agreed levels of QoS.
The temporal relation between beat gestures and accompanying speech is examined in two experiments. In the first, we find that subjects are very quick to spot altered timing between gesture and speech if the gesture is later than normal, but are considerably less sensitive to alterations that result in an earlier gesture. This suggests an asymmetry in the expectation on the part of listeners/watchers and raises immediate questions about which elements within the speech are being perceived as linked to which elements in the gestural series. We therefore examine the variability between several kinematic landmarks in a beat gesture, and three potential anchor points in the accompanying speech. We find the least variable relationship obtains between the point of maximum extension of the gesture and the accompanying pitch accent. Together, these findings contribute to our understanding of both the production and perception of beat gestures along with speech, and support an account of speech communication as a strongly embodied activity.
Los Angeles - Laser Toner Zone, a popular importer of compatible and remanufactured printer cartridges, introduces their newly launched Brother TN-115 compatible laser toners. Manufactured from their ISO 9001 certified facility, these cartridges are made entirely of new parts and are not sourced from used or refurbished units. Laser Tone Zone's TN115 toners are available in cyan, magenta, yellow and black. All color cartridges (CMY) have a page yield of 4,000 at 5% coverage, while black cartridges have a page yield of 5,000 at 5% coverage. Strict quality control procedures have been adopted to guarantee compatibility with Brother HL-4040CN, HL-4070CDW, and MFC-9440CN laser printers.
Secure, distributed collaboration between different organizations is a key challenge in Grid computing today. The GDCD project has produced a grid-based demonstrator virtual collaborative facility (VCF) for the European Space Agency. The purpose of this work is to show the potential of Grid technology to support fully distributed concurrent design, while addressing practical considerations including network security, interoperability, and integration of legacy applications. The VCF allows domain engineers to use the concurrent design methodology in a distributed fashion to perform studies for future space missions. To demonstrate the interoperability and integration capabilities of Grid computing in concurrent design, we developed prototype VCF components based on ESA's current excel-based concurrent design facility (a non-distributed environment), using a STEP-compliant database that stores design parameters. The database was exposed as a secure GRIA 5.1 Grid service, whilst a .NET/WSE3.0-based library was developed to enable secure communication between the Excel client and STEP database.
Two nested or non-nested candidate sampling models for an observed data set may be compared by consideration of summaries of a probability plot, which contrasts the posterior quantiles of the log-likelihoods under the two models. The procedures address both preference inference and refutation inference, and extensions to DIC and alternatives to AIC are developed. Preference inference favors models with more parameters, perhaps on a tentative basis when further data are anticipated, while refutation inference emphasizes parameter parsimony. A characterization relating to an α-profile motivates the comparison of the posterior medians of the log-likelihoods, when considering simple model preference. For nested models, a stronger omega-preference procedure is developed via a Bayes-frequency compromise. The Bayes-frequency performances of the different preference and refutation inference procedures are investigated when the models are nested. While attention is primarily confined to model inference within the linear paradigm, most of the methods are approximately applicable in a range of non-linear cases. A Gamma approximation to an Upsilon distribution facilitates a general approach, for the linear model with unknown variance. A data set for 71 hypertensive diabetic patients is analyzed, and a symptom of high blood pressure is related to four out of the eight explanatory variables available. of Statistics at the Universities of Wisconsin-Madison and Edinburgh, is retired and lives at 4/3 Hopetoun Crescent, Edinburgh, Scotland, EH7 4AY. The authors would like to thank Angelika van der Linde for her helpful advice on the literature.
As the technical infrastructure to support Grid environments matures, attention must be focused on integrating such technical infrastructure with technologies to support more dynamic access to services, and ensuring that such access is appropriately monitored and secured. Current approaches for securing organisations through conventional firewalls are insufficient; access is either enabled or disabled for a given port, whereas access to Grid services may be conditional on dynamic factors. This paper reports on the Semantic Firewall (SFW) project, which investigated a policy-based security mechanism responsible for mediating interactions with protected services given a set of dynamic access policies, which define the conditions in which access may be granted to services. The aims of the project are presented, and results and contributions described.
Grids are becoming economically viable and productive tools. They provide a way of utilizing a vast array of linked resources such as computing systems, databases and services online within Virtual Organizations (VO). However, today's Grid architectures are not capable of supporting dynamic, agile federation across multiple administrative domains and the main barrier, which hinders dynamic federation over short time scales is security. Federating security and trust is one of the most significant architectural issues in Grids. Existing relevant standards and specifications can be used to federate security services, but do not directly address the dynamic extension of business trust relationships into the digital domain. In this paper we describe an experiment which highlights those challenging architectural issues and forms the basis of an approach that combines a dynamic trust federation and a dynamic authorization mechanism for addressing dynamic security trust federation in Grids. The experiment made with the prototype described in this paper is used in the NextGRID project to define the requirements of next generation Grid architectures adapted to business application needs.
The ARTEMIS project is developing a semantic web service based P2P interoperability infrastructure for healthcare information systems that will allow healthcare providers to securely share patient records within virtual healthcare organisations. Authorisation decisions to access patient records across organisation boundaries can be very dynamic and must Occur within a strict legislative framework. In ARTEMIS we are developing a dynamic authorisation mechanism called PBAC that provides a means of contextual and process oriented access control to enforce healthcare business processes. PBAC demonstrates how healthcare providers can dynamically share patient records for care pathways across organisation boundaries.
When performing a meta analysis, it is often necessary to combine results from several 2 × 2 contingency tables. The Mantel–Haenszel model assumes a common measure of association between the treatment and outcome variables across the tables. A Bayesian method is described for drawing inferences regarding the measure of association, for checking the plausibility of the Mantel–Haenszel model, and for drawing inferences regarding the success rates for the individual studies. While the methodology is readily extendable to random effects models, a fixed effects approach avoids the complex statistical modelling of a mixture distribution which is required for the good application of random effects models. Copyright © 2002 John Wiley & Sons, Ltd.
Although different web sites structure their pages differently, the pages within a single site are often generated from a database and have a regular layout from which it is possible to extract information automatically. Dome is a visual tool for manipulating tree-structured documents. It can import and export in XML or HTML formats, making it ideal for harvesting information from web pages. Editing is performed using a direct manipulation interface and the operations are recorded for later playback. The knowledge extracted from a web page may be updated by replaying the recorded sequence when the source page changes. The same sequence can be applied to other pages with a similar format, and facilities are provided to batch process a large collection of pages in one operation. In this paper we describe how Dome may be used to extract knowledge from web sites in such a way that the extraction process may be reliably replayed.
Constrained parameter situations arise in a wide variety of practical problems and the corresponding order restricted inference has been extensively researched. In previous work, order restrictions have always been imposed on the estimates of the ordered parameters, the data may, however, provide strong evidence that the constraints are untrue, in which case it might be more sensible for the estimates to contradict the constraints, or to compromise between unconstrained estimates and estimates based on the constraint. In this paper, we consider finite sample inference for the one-way layout normal means problem with unknown common variance and we assume that the treatment means are hypothesized to be ordered but with a degree of uncertainty in this hypothesis via prior assumptions that we express. This flexibility will permit the data to play a more substantive role in the inferential procedure. The posterior distribution of the treatment means is estimated using the Gibbs sampler. An illustrative analysis using a real data set is provided.
A simple procedure is proposed for exact computation to smooth Bayesian estimates for logistic regression functions, when these are not constrained to lie on a fitted regression surface. Exact finite sample inferences and predictions are available, together with an exact residual analysis. The prior distribution relates to O'Hagan's assumptions for a normal regression function. A global shrinkage parameter and local smoothness parameter can be evaluated from the current data by hierarchical Bayesian procedures. Consideration of the shrinkage parameter permits an overall check regarding a hypothesised regression model. No optimisation technique is needed, since Monte Carlo simulations from independent logistic distributions can be directly employed. The complexity of the computations does not substantively increase with the dimensionality of the design space.
Although dierent web sites structure their pages dierently, the pages within a single site are often generated from a database and have a regular layout from which it is possible to extract information automatically. Dome is a visual tool for manipulating tree-structured docu- ments. It can import and export in XML or HTML formats, making it ideal for harvesting information from web pages. Editing is performed using a direct manipulation interface and the operations are recorded for later playback. The knowledge extracted from a web page may be updated by replaying the recorded sequence when the source page changes. The same sequence can be applied to other pages with a similar format, and facilities are provided to batch process a large collection of pages in one operation. In this paper we describe how Dome may be used to extract knowledge from web sites in such a way that the extraction process may be reliably replayed.
Martin Hall-May合作论文数3
Olle Mulmo合作论文数Center for Parallel1