Showing posts with label conference. Show all posts
Showing posts with label conference. Show all posts

Friday, April 23, 2010

Currently in Oak Ridge

Just before Easter, I was notified my submission to CSIIRW '10, 6th Annual Cyber Security and Information Intelligence Research Workshop was accepted. After funding was approved with less than 2 weeks before the start of the workshop, organising travel from Australia to the United States was a bit hectic. But I'm pleased to say, everything worked out and after over 20 hours of flying, I am here in Tennessee.

Location: The workshop itself is held at Oak Ridge National Laboratory, a national research centre with an interesting history. Initially established in 1943, ORNL was part of the secret Manhattan project to pioneer a method for producing and separating plutonium. Apparently I'm sitting near a nuclear reactor right now? The laboratory is in Oak Ridge, where the whole town seems to have been built in support of the research laboratories in the area.

Currently, the lab facilitates six major areas of research: neutron science, energy, high-performance computing, systems biology, materials science at the nanoscale and national security. The workshop that I will be presenting at falls under national security. But while attendees were at ORNL, they had the opportunity to take a tour around the facilities and have a look at both the Jaguar and the Kraken, the first and third fastest supercomputers in the world. We were also shown the type of simulations the computers ran to support the research performed by other parts of the laboratory. Very amazing indeed. Feel free to read up more about the research lab on their official website: http://www.ornl.gov/

Content: As the title of the workshop suggests, the focus was on Cyber Security and Information Security. The plenary speakers spoke on a range of issues including national security, system security and web security. Keynote bios can be found here: http://www.ioc.ornl.gov/csiirw/keynotebios.html. As some of these areas hasn't been the primary focus of my research in the past several years, it raised very many interesting issues that I had not considered. What is the strategy that should be taken to make security less beneficial to the "bad guys" and in more favour of the "good guys"? An aikido approach to redirect threats can be taken; use the force of the attacker to beat them at their own game. We should be making detection systems online and capable of analysing larger volumes of data. Design for failure and have a recovery plan! The keynote speakers really made this conference for me.

The paper sessions looked at design, malware, network, privacy and metrics, enterprise, survivability, formal methods and trust. Most times I had difficulty deciding which room to go to. I usually ended up in the network/malware stream, listening to malware classification, and any sort of categorisations that used data mining tools.

There were also some interesting posters out in the lobby area, available to be read at your leisure during the entire event.

My Work: The paper I had accepted and presented this morning was titled: Graph Based Strategies to Role Engineering. It's the foundations of my current research in graph based role engineering for definition of a set of roles that accurately reflect the internal functionalities of an enterprise for RBAC. To identify the roles, we first map users, permissions and roles to nodes and user-to-permission, user-to-role, role-to-role and role-to-permission assignments to edges in a directed acyclic graph (DAG). There are three graphs:




UPGraph

URPGraph
UHRPGraph

There are three different cost models:
Role minimisation: cost(G)= c1|VR|
Edge minimisation: cost(G)= c2|E|
Role and Edge minimisation: cost(G)= c1|VR| + c2|E|
where cx are the static costs of role and assignment administration, |VR| is the number of role nodes in the graph and |E| is the number of edges in the graph.

Using both the graph model and the cost metrics, we propose a heuristic strategy for optimisation. Please check the paper for more details on the heuristic and some preliminary results.

Friday, June 22, 2007

SACMAT Discussion Panels

22 June 2007 - Sophia Country Club, Sophia Antipolis, France

Panel Discussion - I: Access Control for Assured Information Sharing

Solutions for access control for assured information systems were discussed as a panel session. In general, it was agreed that a variety of solutions need to be provided for sharing needs. Considerations include:

  • Trust
  • Ownership - how this issue is dealt with
  • Responsibility - to share the knowledge and protect everyone


This aspect of research has become especially important after 9/11. We potentially had all the information within different departments to prevent/respond/reduce the severity of the attacks. But the information was restricted and information was not shared between systems.

The solution also needs to be adaptive - generalised event based management.

Some questions and issues raised during the panel:

  • Why can't you have 1 solution for different scenarios, does it have to be a case by case basis?
  • Enforcing sharing obligations infringes decision making
  • Inherently, people do not trust computers
  • DAC - restrict access as much as possible.
  • Selective data sharing - share when you can get credit


Panel Discussion - II: Directions for Access Control and Policy Management

The areas that I paid the most attention to was role engineering. There is a lot of interest in this area, particularly in industry. The main issue for role engineering is definition of a structure is correct and that is good. Measure of correct is simple, measure of good is more difficult. On the day, it was agreed that generally, you should have less roles than users. Otherwise the infrastructure is useless, it would be more optimal to assign permissions to users directly. However, it was also discussed the presence of abstract roles. That is, roles that are not assigned to any users. Are they still useful? They may assigned the design of the infrastructure in hierarchical RBAC. In retrospect, if abstract roles exist, it may be acceptable for the number of roles to be larger than the number of users.

SACMAT Keynote

20 June 2007 - Sophia Country Club, Sophia Antipolis, France

Keynote: Jorge Cuellar - Siemens Corporate Technology, Munich, Germany
Thoughts on Application Layer Access Control


In this keynote, Jorge presented some formal methods representation for the application layer of access control. He motivated the need for formal representation through various research initiatives currently in progress at Siemens, Germany:

  • eHealth Care - ensure confidentiality of patient records
  • Planes - distrusted software
  • Citizen's portal - card to authenticate, management of access to different software.

He also discussed the rational for the need for security using UML system diagrams.

eTransactions were also discussed. Current security for e-Transactions are not enough for eCommerce needs. SSL are currently not made for eTransactions. What kind of access control do we need? What ever is chosen, ease of implementation is an important consideration. The hidden logic needs to consider confidentiality, integrity and atomicity.

Thursday, May 03, 2007

ICDE 2007 Keynotes


IEEE 23rd International Conference on Data Engineering
17-19 April 2007 - The Marmara Hotel, Istanbul, Turkey


Keynote: Yannis Ioannidis

On the first day, Yannis Ioannidis gave a presentation on Emerging Open Agoras of Data and Information. He spoke about competitive markets, sharing of information and the motivation behind allowing the dissemination of information between parties through bargaining or other types of negotiation. I think the use of the term "Agora" was particularly appropriate based on our location (Istanbul). At the end of this presentation, he was asked to compare an Angora model with that of a Mall (US shopping center). Fun times.

Keynote: Ricardo Baeza-Yates

On the second day, Ricardo Baeza-Yates presented Challenges in Distributed Web Retrieval and discussed the issues of increasing Web data and using distributed machines to cope with scalability.

Keynote: Laura M. Haas

On the final day, Laura M. Haas spoke about Information for People, a presentation targeted at ICDE researchers to consider the HCI component of research development. I think this was the presentation I remember most vividly. She gave visual presentations and examples of some algorithm researchers who used GUI components to their research for representation of results. This visually helped anyone who was unfamiliar with the data to make clearer judgements. For example, instead of just looking at the numbers, std, and means, plot them and allow for dynamic modification of graph to anaylse trends in numerical data better. This of course was done in colour. Pretty. And she was right, it did help the comprehension of what was going on a lot.

However, I'm not sure how well it was received on my side of the room. There was some general consensus that while it's a nice idea to make our algorithms "pretty", the reason why HCI and Data Management were two distinctive areas was because the are completely two distinctive areas. I don't think there's another way to put it. So I think the best example I have is the OSI model. You're trying to merge the physical layer with the application layer. It's not quite that extreme but it's close. At ICDE, there were sessions and industry reports on more efficient caching techniques. How do we make that more GUI/user friendly? I think at this point in time in research, there is still a strong distinction between these things and there needs to be, otherwise the scope you start dealing with is just enormous. The point is abstraction and to work with manageable portions. It's a nice idea, but I'm not sure how practical it would be.

Sunday, April 15, 2007

DMBI 2007 Keynote


Workshop on Data Mining and Business Intelligence
15 April 2007 - The Marmara Hotel, Istanbul, Turkey


Keynote: Jiawei Han - University of Illinois at Urbana-Champaign
Research Frontiers in Advanced Data Mining and Business Intelligence


The purpose of this key note address was to give an general overview of current research areas in Data Mining. Technical detail was not covered. Instead, a highlight of the challenges and direction of existing data mining related topics that Jiawei had personal exeriences with was discussed.

Pattern mining was the first topic discussed. Frequent pattern mining was the first approach with apriori, then FPGROWTH, Eclat and so on. Closed mining developed from this due to the large number of patterns that can be generated by frequent pattern approaches. FPClose, Charm and max pattern mining were mentioned. Also mentioned is correlation mining (PageRank from Google) and compression of patterns and more compact representation of large result sets.

Information network analysis was also discussed. Graph mining and mining data with links or cross-relational mining falls into this category. One recent approach that was developed by one of Jiawei students was based on the disabmiguation of different people with the same name. In DBLP, there are 14 distinct people all with the name Wei Wang. All of them are in computer science and a large propotion is in data mining. It is difficult to determing which Wei Wang is being referred to, just by looking at publication type. The solution proposed is to analyse co-author data. Based on this, fairly successeful classifications were made. 13 distinct users were identified (one was misclassified as someone else) and there were 2-3 paper misclassifications for the other 13 people.

Another area of data mining is stream data mining such as internet network traffic. The aim of stream data mining is prompt classification such as in network intrusion detection systems. One recent work is the prompt update of stream data cubes based on statistical analysis.

Mining moving object data is also interesting. While the focus is not yet on prompt classification, moving ships, cars and different objects can identify anomalies or predict future direction. For example, analysis of ship movements can potentially identify anomalies that could be terrorist vehicles or illegal shipping operations. Analysis of trajectory of hurricanes can predict movement and study of seasonal animal movement can be done before construction of major highways for the least amount of disturbance to wildlife.

Spatial, temporal and multimedia data mining need to consider obstacles before correct classification can be performed.

Text and Web mining considers links between pages and key words. It is important to extract the correct information. There is lots of information available. One way to extract important information is to identify key structure components. Graphics algorithms can be used to identify sections of useful information as indicators for the actual information.

Data mining system and software engineering deals with the clustering and classification of software bugs, where they are detected and where the location of the bug actually resides.

Finally, data cube oriented and multi dimensional online analytic process was discussed and separated into four areas: regression cubes, prediction cubes, integration cube and ranking query processing and high dimensional OLAP.

Wednesday, October 11, 2006

2006 Grace Hopper Celebration of Women and Computing Keynote Speakers

It is no great feat to place 1000 women in a room. It is however, somewhat of an accomplishment to place 1000 women with computing professions in a room. This task was realised during the 2006 Grace Hopper Celebration of Women and Computing. I don't think I've ever known 100 women let alone 1000 and never would I have believed there would be this many females doing computer science.

But guess what? There are! And many of them have come together in celebration of past, present and future generations of women and their accomplishments in fields where they are disadvantaged.

The women I met at this event were truly inspirational. The keynote speakers were definitely well selected and as I type, their voices still ring in my head with the messages they send.

On day one, Shirly Tilghman spoke about how when she closes her eyes, she can see women in engineering disciplines. This is how she differs from men referees because when they close their eyes, they cannot mentally picture females in those positions. This limits the candidate pool. Where as women can broaden their views to include women in the vision.

On day two, Sally Ride suggested the only reason women were not choosing engineering careers was because of the conditioning and pressures of the male dominated society. She experienced first hand the reverse of the roles when she became the first female astronaut. Due to the large amount of media surrounding her flight, 5 year old boys wondered if little boys could grow up to become astronauts. To create such questioning implies the media can produce enormous amounts of pressure on how society can perceive certain events.

Finally, on day three Helen Greiner gave us some insight into her company and the journey towards marketing her creations. Anything is possible in computer science and these women prove it.

Thursday, September 14, 2006

Planning my Grace Hopper Trip

Early in May, Professor Alistair Moffat sent an email around informing postgraduate and later year students of a conference opportunity in San Diego for women in computing. This conference is The Grace Hopper Celebration of Women in Computing. Google was offering a Global Community Scholarship to help students outside of the US attend the event. I thought this is something that I could potentially apply for.

The application was due on 1st June 2006 and I remembered to re-read Alistair’s email on the night of 27th May. I of course, was leaving the country at 5am on the morning of 29th May for Infoscale ’06. So instead of preparing for my presentation, I spent 28th May writing an essay about myself. This seemed to pay off as early in August, I was notified of being awarded a full scholarship to attend the 2006 Grace Hopper
Celebration of Women in Computing. Woo. 83 full scholarships were awarded out of 550 applicants. The odds weren’t bad but it’s still exciting to be accepted. Plus, I’ve never been to the states before so I’m fully excited. Yes, I just used the word, “fully”.

After the initial shock and making this face O_O, I realised that I now needed to book flights to the states. I’ve never had to plan a trip like this for myself before so the organisation itself was a learning experience.

I emailed the organisers of the event and received an email back informing me that I required a Visa. This was a bit worrying. Then I received an email asking if I was flying from China because another scholarship recipient was travelling from the China and wanted to know if I wanted to be her travel buddy. This was more worrying. Turns out they knew I was born in China and thought I might be in China right now. I guess I could have been.

After the initial confusion and reading fine print, I do not need a visa and I have no travel buddy. But at least I know the name of a girl who was born in the same country as me and has an interested in computer science. I look forward to meeting her in October.

I am leaving Australia on 28th September and returning 9th October. I will spend my time before the conference in Oakland, California, visiting a David Sun, very good friend at UC Berkeley. He is currently studying towards his PhD in Computer Science at Berkeley and is a very smart cookie. I’ve known him since I was 10 and he used to hate me because I use to channel surf too much when we watched TV together. Hopefully he is over how annoying I used to be and won’t mind too much that I will be hanging around him for the weekend.

I will fly into San Diego on the evening of 2nd October and spend the 3rd October in Tijuana. This decision is based on the fact that San Diego’s main attractions are the zoo and sea world. Shopping for a day in Mexico seems to be more appealing to me. I haven’t told my parents yet but I’m sure they will see the photos after I come back from Mexico.

The 4th-7th October will be dedicated to the conference. I look forward to meeting some awesome women of computing from around the world. It will definitely be an invaluable experience that I will never forget. I especially look forward to the ideas that will be presented to me by the various presenters.

Right after the conference, I will board a flight on the 7th October and arrive back in Melbourne on the 9th. I have tutorials that I have to teach on the 10th.

It is two weeks before I go and everything seems to be organised. I have my travel insurance, I’ve booked my accommodation and my flights have been paid for and confirmed. I have all the receipts I need for reimbursement at the conference. I hope I haven’t forgotten anything. I guess I’ll know in 2-3 weeks time.