ENGLISH

Data and Applications Security and Privacy XXXVI: 36th Annual IFIP WG 11.3 Conference, DBSec 2022 Newark, NJ, USA, July 18–20, 2022 Proceedings

Book information

Publisher
Springer
Year
2022
ISBN
9783031106835, 9783031106842
Language
english
Format
PDF
Filesize
15 MB (15314923 bytes)
Series
Lecture Notes in Computer Science, 13883
Pages
329\330
Time added
2022-11-27 00:49:00

Description

This book constitutes the refereed proceedings of the 36th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2022, held in Newark, NJ, USA, in July 2022. The 12 full papers and 6 short papers presented were carefully reviewed and selected from 33 submissions. The conference covers research in data and applications security and privacy. Preface Organization Contents Data Privacy Assessing Differentially Private Variational Autoencoders Under Membership Inference 1 Introduction 2 Preliminaries 3 Accuracy and Privacy for Variational Autoencoders 4 Evaluation 4.1 Datasets and Learning Tasks 4.2 Labeled Faces in the Wild 4.3 MotionSense 5 Related Work 6 Discussion References Utility and Privacy Assessment of Synthetic Microbiome Data 1 Introduction 2 Preliminaries and Related Work 3 Threat Model and Goal of Synthetization 4 Evaluation 4.1 Task Utility 4.2 Sample Similarity and Privacy Risks 5 Conclusions and Future Work References Combining Defences Against Data-Poisoning Based Backdoor Attacks on Neural Networks 1 Introduction 1.1 Threat Model 2 Related Work 2.1 Backdoor Attacks 2.2 Backdoor Defences 3 Evaluation Setup 3.1 Datasets and Models 3.2 Backdoor Triggers 3.3 Evaluation and Metrics 3.4 Evaluated Defences and Implementation 4 Results 4.1 Activation Clustering Defence 4.2 Fine Pruning Defence 4.3 Combined Defence 4.4 Discussion 5 Conclusions and Future Work References MCoM: A Semi-Supervised Method for Imbalanced Tabular Security Data 1 Introduction 2 Background 2.1 Vulnerability Complexity 2.2 Data Set and Challenges 2.3 Data Augmentation 2.4 Semi-Supervised Learning and Contrastive Learning 3 Preliminaries 3.1 Contrastive Loss 3.2 Semi-Supervised Loss 4 Methodology 4.1 Triplet Mixup Data Augmentation 4.2 Contrastive and Feature Reconstruction Loss 4.3 Pseudo-labeling 4.4 Downstream Tasks 4.5 Algorithm 5 Experiments 5.1 Results 5.2 Ablation Study 5.3 Parameter Analysis 6 Conclusion and Future Work References Mitigating Privacy Vulnerability Caused by Map Asymmetry 1 Introduction 2 Preliminary 2.1 Differential Privacy 2.2 Exponential Mechanism 2.3 dX-privacy 2.4 Differential Privacy over the Graph 3 Related Work 3.1 Application of Differential Privacy to Location Information 3.2 Local Differential Privacy 4 Problem Definition 4.1 Privacy Vulnerability in GeoI and GeoGI 4.2 Exponential Mechanism Which Considers Weights 5 Methods to Mitigate the Vulnerability Problem 5.1 Weight Reduction Method 5.2 AE Optimization Method 5.3 Comparison of the Two Methods 5.4 Performance Analysis 6 Conclusion A Proof of Proposition 1 References Distributed Systems Liberate Your Servers: A Decentralized Content Compliance Validation Protocol 1 Introduction 2 Background 2.1 Blockchain and Smart Contract 2.2 Secure Communication Channels 2.3 Content Compliance Validation 3 Protocol Overview 3.1 System Architecture 3.2 Threat Model 3.3 Protocol Requirements 4 Protocol Details 4.1 Initialization 4.2 Content Validation 4.3 Proofs Issuance 4.4 Deliver Content with Token 4.5 Content Compliance Validation Policy 5 Incentives 5.1 Financial Penalties and Disputes 5.2 Reward Consideration 6 Implementation and Evaluation 6.1 Real-World Use Cases 6.2 Transaction Cost 6.3 Performance 6.4 Efficiency and Features Comparisons 7 Security Analysis and Discussion 8 Related Work 9 Conclusion A Detailed Interactions of DeCCV B Secure Communication Handshake Performance C Discussions C.1 Secure Communication Design Choices C.2 Towards A Fine-Grained Reward Design C.3 Generalizability References Knowledge Mining in Cybersecurity: From Attack to Defense 1 Introduction 2 Problem Statement 2.1 A Dive into Statistics: Offense and Defense 2.2 Challenges for Recommendation 3 Approach 3.1 Common Techniques 3.2 Proposed Method 4 Experimental Results 4.1 Experimental Setup 4.2 Results 4.3 Results with Pruned Ontology 4.4 Use Case 5 Related Works 6 Conclusion References Attack-Resilient Blockchain-Based Decentralized Timed Data Release 1 Introduction 2 Background and Motivation 2.1 Decentralized Timed-release of Self-emerging Data Using Ethereum Blockchain 2.2 Adversary Model 2.3 Limitations of Existing Solutions 3 Reputation-Aware Timed-Release Protocol 3.1 Uncertainty-Aware Reputation Measure 3.2 Reputation-Aware Timed-Release Protocol 4 Evaluations 4.1 Simulation Evaluations 4.2 Prototype Implementation 5 Related Work 6 Conclusion References IoT Security Local Intrinsic Dimensionality of IoT Networks for Unsupervised Intrusion Detection 1 Introduction 1.1 Limitations of Prior Attempts 1.2 Proposed Approach 1.3 Problem Statement 2 Related Work 2.1 Intrusion Detection Systems 2.2 IoT 2.3 State-of-the-Art Network Intrusion Models 2.4 Complexity and Anomaly Detection in Deep Learning 2.5 Complexity and Anomaly Detection in Security 3 Proposed Approach 3.1 Intrinsic Dimensionality 3.2 Local Intrinsic Dimensionality 3.3 Weighted Hamming Distance LID Estimator 3.4 Baseline Models 3.5 Experimental Setup 4 Datasets 4.1 TON IoT 4.2 NF Bot-IoT 4.3 IoT-23 4.4 IoT Dataset Features 5 Anomaly Detection Results 5.1 Algorithm Comparison Results 5.2 Attacks Specific Results 6 Conclusion References On the Data Privacy, Security, and Risk Postures of IoT Mobile Companion Apps 1 Introduction 2 Threat Model 3 Data Collection and Analysis 4 Data Privacy Posture 4.1 Methods 4.2 Tools and Analyses 4.3 Results 5 Security Posture 5.1 Methods 5.2 Tools and Analyses 5.3 Results 6 Risk Posture 6.1 Methods 6.2 Tools and Analyses 6.3 Results 7 Discussion 7.1 Cross-Dimension Analysis 7.2 State of Measuring Tools 8 Related Work 9 Conclusions References Verification and Validation Methods for a Trust-by-Design Framework for the IoT 1 Introduction 2 Background 3 Related Work 4 Verification 5 Validation 6 Verification Scenario: Smart Cake Machine 7 Validation Scenario: Smart Cake Machine 8 Conclusion and Future Work References Privacy-Preserving Access and Computation Robust and Provably Secure Attribute-Based Encryption Supporting Access Revocation and Outsourced Decryption 1 Introduction 2 Related Work 3 Preliminaries 4 System and Security Models 4.1 System Model 4.2 Definition of Our Construction 4.3 Threat Model 4.4 Security Requirements 5 Our Proposed Scheme 5.1 System Initialization 5.2 Data Sharing 5.3 User Registration and Key Generation 5.4 Access Revocation 5.5 Outsourced Pre-decryption and User Decryption 6 Security Results 7 The Complexity 7.1 Storage Complexity 7.2 Communication Complexity 7.3 Computation Complexity 8 Conclusion References Libertas: Backward Private Dynamic Searchable Symmetric Encryption Supporting Wildcards 1 Introduction 2 Preliminaries 2.1 Searchable Symmetric Encryption (SSE) 2.2 Leakage Functions 2.3 Security Model 2.4 Forward Privacy 2.5 Backward Privacy (BP) 3 Wildcards 3.1 Wildcard Security 4 Libertas: Constructing Wildcard Supporting Update Pattern Revealing Backward Private Schemes 4.1 Construction 4.2 Analysis 4.3 Security 5 Evaluation 5.1 Setup 5.2 Experiments 5.3 Results 6 Discussion 7 Conclusion A Z&N: Construction A.1 Keyword Characteristic Set A.2 Token Characteristic Set References End-to-End Protection of IoT Communications Through Cryptographic Enforcement of Access Control Policies 1 Introduction 2 Related Work 3 Background 3.1 Access Control 3.2 MQTT 4 Overview 4.1 Smart Lock Service 4.2 Securing the Smart Lock Service 5 Cryptographic Access Control for MQTT 5.1 Role-Based Access Control to MQTT 5.2 Full Construction 5.3 Security Considerations 6 Implementation and Experimental Evaluation 6.1 CryptoAC 6.2 MQTT Broker 6.3 Public Repository 6.4 Performance Evaluation 7 Conclusion and Future Directions A Pseudocode of the Cryptographic Access Control Scheme References Quantum Security Integrating and Evaluating Quantum-safe TLS in Database Applications 1 Introduction 2 Preliminary 2.1 Post-quantum Cryptography 2.2 Open Quantum Safe 2.3 Transport Layer Security 3 PostgreSQL 3.1 Overview 3.2 Database Server 3.3 Client Interface 3.4 Frontend-Backend Protocol 4 Integration 4.1 Architecture 4.2 Configuration 4.3 Digital Signature 4.4 Key Exchange and Key Encapsulation Mechanisms 5 Evaluation 5.1 Test Methodology 5.2 Setup 5.3 Test Program 5.4 Results 6 Related Work 7 Conclusion A Results for the WAN Setting References Feel the Quantum Functioning: Instantiating Generic Multi-Input Functional Encryption from Learning with Errors 1 Introduction 2 Related Work 3 Preliminaries 3.1 Public-Key Encryption 3.2 Multi-Input Functional Encryption 3.3 Background on LWE 4 Base Construction 5 Instantiation from DDH 5.1 Verifiable Decryption 5.2 Instantiation from CL Framework 6 MIFE for Sums 6.1 Instantiation from LWE 7 From Single-Client to Multi-client MIFE 8 Experimental Results 9 Conclusion A Proof of Theorem 4 B Proof of Theorem 6 References Security Operations and Policies ReLOG: A Unified Framework for Relationship-Based Access Control over Graph Databases 1 Introduction 2 Background 3 Relationship-Based Access Control 4 ReLOG: A Graph Query Language for ReBAC 5 Application of the ReLOG Framework to ReBAC Models 6 Conclusion References Security Operations Center Roles and Skills: A Comparison of Theory and Practice 1 Introduction 2 Related Work 3 Roles in a SOC 4 Approach Qualitative Research 5 Evaluation of the Qualitative Research 5.1 SOC Role Structure 5.2 SOC Analysts 5.3 Interfaces of a SOC in Practice 5.4 Alignment of Theory and Practice of SOC Roles 5.5 Minimal Configuration SOC Roles 6 Conclusion and Future Research References Author Index

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF