Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163
Showing posts with label HP Labs. Show all posts
Showing posts with label HP Labs. Show all posts

Sunday, November 24, 2013

Update: HPL R&D work on Big Data for Security

At HP Labs we are making good progress in our R&D work on “Big Data for Security”, aiming at identifying new security threats and issues from large amounts of collected data logs.

We have already identified a few key threats happening within organisations, including last-generation malware infections as well as misconfigured devices. We are actively looking for trials with HP customers, whilst aiming to transfer our new technologies in next generation HP SW security solutions.

Our current work focuses on massive amount of DNS data collected from DNS servers and aiming to subsequently correlate with other types of data logs.

We leverage key HP HAVEn assets to provide integrated real-time and historical analytic solutions along with compelling visualization. Specifically we currently use HP ArcSight Logger, HP ArcSight ESM, HP Vertica and HP TippingPoint RepSM as the underlying “big data infrastructure” to build our security analytical framework.

--- Posted by Marco Casassa Mont (here and here)  ---
--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

My Tweets of the Week (18-24 November 2013)

My tweets of the week (18-24 November 2013) at https://twitter.com/MCasassaMont:

·         Working on next generation HPL "Big Data for Security" R&D solutions. #security #bigdata #in
·         Are large scale Man in The Middle attacks underway? - https://isc.sans.edu/forums/diary/Are+large+scale+Man+in+The+Middle+attacks+underway+/17075 … #security #in
·         More Data Scientists, or Fewer Complex Big Data Applications? - http://www.wired.com/insights/2013/11/more-data-scientists-or-fewer-complex-big-data-applications/ … #bigdata #in
·         HP announces Vertica 7 'Crane' update for better big data insights - http://www.v3.co.uk/v3-uk/news/2307924/hp-announces-vertica-7-crane-update-for-better-big-data-insights … #in
·         Warning! Targeted Internet misdirection on the rise - http://www.computerworld.com/s/article/9244173/Warning_Targeted_Internet_misdirection_on_the_rise … #in
·         NCA warns UK of mass CryptoLocker ransomware attacks - http://www.scmagazineuk.com/nca-warns-uk-of-mass-cryptolocker-ransomware-attacks/article/321576/ … #in
·         The three universal questions companies ask about big data - http://www.citeworld.com/consumerization/22693/andrew-mcafee-big-data-three-questions … #in
·         HP: 90% of Apple iOS mobile apps show security vulnerabilities - http://www.networkworld.com/news/2013/111813-hp-ios-vulnerabilities-276063.html?hpg1=bn … #in
·         10 reasons the browser is becoming the universal OS - http://www.infoworld.com/d/applications/10-reasons-the-browser-becoming-the-universal-os-230812 … #in
·         Cyber attack emergency service launched - http://www.scmagazineuk.com/cyber-attack-emergency-service-launched/article/321222/ … #in

--- Posted by Marco Casassa Mont (here and here)  ---
--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---
--- NOTE:  my original HP blog can be found here  ---


Friday, July 19, 2013

HP Labs Research


HP Labs has updated its Research web page, providing an overview of its 5 key research focus areas. More information is available here.

 

--- Posted by Marco Casassa Mont (here and here)  ---

--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---

--- NOTE:  my original HP blog can be found here  ---

Tuesday, September 11, 2012

HP Labs SAaaS: Situational Awareness-as-a-Service

At HP Labs Bristol we are making good progress towards the development of a futuristic demonstrator in the space of Situational Awareness, named “Situational Awareness-as-a-Service (SAaaS).




This demonstrator focuses on the disaggregated IT of current/future organisations which increasingly rely on third parties (IaaS, SaaS providers in the Cloud, etc.) to carry out their IT and business activities.



We demonstrate the issues and opportunities related to safely handling information sharing between the organisation and its various providers, in a context of a future Next Generation IT Operation Centre and Security Operation Centre (SOC).



This includes illustrating the trade-offs in defining information sharing policies and handling queries to gather data from the involved parties, the clever analytics processing that can be performed on top of shared data (e.g. by leveraging HP Software solutions, HP/HPL SILAS, etc.) and the role of external, trusted information aggregators.



HP Labs will use the SAaaS vision to develop further innovative technologies in the area of controlled analytics and information sharing for large data sets.



The demonstrator currently consists of various storyboards focusing on IT and security information sharing stories. I am looking for public, real stories within organisations highlighting the pain points and issues in current disaggregated IT and security operations. The goal is to showcase them and illustrate how they could improve by leveraging SAaaS and future HPL/HP technologies.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, June 8, 2012

HP Labs at HP Discovery 2012

HP Labs has been a key participant at HP Discovery 2012. Some highlights are available here.



In particular our Cloud & Security Lab has been involved, demonstrating state-of-the art prototypes and solutions in the Security and Risk Management areas.

This includes R&D work we did in Security Analytics, now transferred to HP ESS and offered to customers as a service.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---



Monday, January 9, 2012

Call for Proposals: HP Labs Innovation Research Program 2012 – Deadline: January, 27th

HP Labs' Innovation Research Program (IRP) is designed to create opportunities at colleges, universities and research institutes around the world for collaborative research with HP. Through an annual, open Call for Proposals (CfP), we solicit your best ideas on a range of targeted research topics with the goal of establishing new research collaborations.

The Guide to the 2012 IRP has been published; please read it carefully before submitting your proposal. The submission deadline is January, 27th .

Specifically I am encouraging proposals in the space of The Cloud and Security – see the Guide at Page 5.


--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---

HP Labs: Innovation and Delivery in the areas of Dynamic Consent and Privacy Management

During the last 6 months, HP Labs provided key contributions involving the overall coordination of the UK collaborative EnCoRe project, the release of public architectural documents and the development of fully working R&D solutions in the areas of dynamic consent and privacy management.

Specifically this includes:

1. The Third EnCoRe Technical Architecture (D2.3) document;
2. The final HP Labs’ EnCoRe Service Framework: a General, Reference Implementation for Dynamic Consent and Privacy Management;
3. The HP Labs Demonstrator for Cabinet Office/Identity Assurance;
4. HP Labs papers on EnCoRe, dynamic consent and privacy management.
My previous blog posts provide the details.



--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---

EnCoRe: Third Technical Architecture D2.3

HP Labs led the overall design and delivery of the third EnCoRe Technical Architecture along with the release of a related EnCoRe public architectural document, D2.3 [1]. This architecture focuses on the third EnCoRe case study, centered on the UK Cabinet Office/Identity Assurance Programme [2].

The first EnCoRe Technical Architecture [3] was designed to fulfill the basic privacy management requirements of the first EnCoRe case study, centred on employee data and focusing on an organisational context. The second EnCoRe Technical Architecture [4], based on a Biobank scenario, fulfilled additional requirements including: the need to support more flexible and compelling privacy-aware policies beyond access control such as obligation policies; the need to ensure that data subjects’ privacy preferences are taken into account and enforced when personal data is shared with third parties. This architecture was designed to support future needs such as the ones related to the third case study. The third EnCoRe Technical Architecture primarily refines and finalises previous specifications in the following areas: flexible expression of privacy preferences (choices); tracking of data whereabouts; privacy-aware access control policies and obligation policies; sticky policies; logging, auditing and compliance checking. These refinements are driven by additional knowledge and requirements gathered in EnCoRe, during the second and third case studies.

Various use cases, related to the UK Cabinet Office/Identity Assurance Programme, have been taken into account to illustrate how EnCoRe can provide the desired capabilities in terms of dynamic consent and privacy management.

The third Technical Architecture document describes the resulting final EnCoRe architecture. Although inspired by, and focused on, the specifics of the third EnCoRe case study, this architecture is much more widely applicable than to just that scenario, being suitable for use in other scenarios where an individual (the data subject) discloses his or her personal data to an organisation, which may wish to disclose it to other organisations. Its legal ability to do so may depend on the specific details of the consent, granted by the data subject at the time of disclosure. At that time, the data subject may not be fully aware of the implications of granting consent, and/or may select the simplest consent options offered by the organisation. Later, perhaps after becoming more aware of these implications, or having just changed her mind, the data subject may wish to revoke the previously granted consents and be sure that her new wishes will be respected by all the organisations that have (or have access to) copies of the personal data she disclosed. In order for this to happen, a complex set of interactions, between and within the involved organisations, is required. The EnCoRe architecture provides the framework for these.

The third EnCoRe Technical Architecture document also provides clear and refined guidelines towards the implementation of a related technical solution, consisting of secure and self-standing services to support dynamic consent and privacy management within and across organizations.

These guidelines have been taken into account in the HP Labs’s EnCoRe Service Framework, which provides a general, reference implementation of the EnCoRe architecture and its core capabilities, as well as a framework to carry out additional research & development activities.

[1] D2.3 Technical Architecture for the third realized Case Study,, http://www.encore-project.info/deliverables_material/D2_3_EnCoRe_Architecture_V1.0.pdf
[2] UK Cabinet Office, Identity Assurance (IdA) Programme Statements, http://services.parliament.uk/hansard/Commons/ByDate/20110518/writtenministerialstatements/part003.html
[3] D2.1 Technical Architecture for the first realized Case Study, http://www.encore-project.info/deliverables_material/D2.1%20EnCoRe%20Architecture%20V1.0.pdf
[4] D2.2 Technical Architecture for the second realized Case Study, http://www.encore-project.info/deliverables_material/D2_2_EnCoRe_Architecture_V1.0.pdf

--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---

HP Labs’ EnCoRe Service Framework: a General, Reference Implementation for Dynamic Consent and Privacy Management

HP Labs completed the development of the EnCoRe Service Framework for the management of dynamic consent and privacy within and across organisations [5]. This framework provides a general, reference implementation of EnCoRe technical capabilities, fully consistent and compliant with the third EnCoRe Technical Architecture [1].

The HP Labs Service Framework supports four general use cases that apply to all case studies explored in EnCoRe:

· A data subject (end-user) submits his/her personal data to an organization along with the expression of their consent preferences;
· An entity within the organisation trying to access personal data and being constrained (in so doing) by related data subjects’ consent preferences and policies. The organization uses EnCoRe to explicitly enforce (privacy) preferences and policies;
· The disclosure of personal data to a third party, along with associated consent preferences, via the sticky policy mechanism;
· A data subject subsequently changes their mind and modifies/revokes their consent. Changes are automatically propagated to all the involved parties;

More details about these use cases are available [1].

A fully working prototype has been built by HP Labs, to fully illustrate the capabilities of the EnCoRe Service Framework and the four general use cases.

Specifically, the Service Framework implements the following key EnCoRe Architectural capabilities [1]: module for the configuration of supported Privacy Preferences and Policies; the Consent/Revocation Provisioning module; the Data Registry module; the Privacy-aware Access Control module; the Obligation Management module; Internal and External Workflow Management modules; the Sticky Policy Management module; instantiation of types of Privacy Preferences, various Access Control and Obligation Policies.

The various components of the Service Framework have been implemented to run as self-standing, secure and distributed services within an organisation. The goal is to ensure that early adopters of the EnCoRe toolkits can use this framework to explore its privacy management capabilities and deploy an extended version of it within their IT operational environments.

The implementation uses state-of-the-art technologies based on the Java framework. It uses the REST [6] methodology and approach for a quick and flexible development of service interfaces and the exchange of information between the involved services. The EnCoRe components are implemented as self-standing RESTful services [7]. These service components can be distributed across different IT systems based on needs. Their implementation supports state-of-the art security, including encryption of data and secure SSL communication. The representation of information that is exchanged between these EnCoRe components uses the XML technology to support future extensions and quick adaptation to the needs of different organisations and their IT operational environments.

This framework has been used by HP Labs as a platform for experimentation of innovative privacy management and consent/revocation solutions. Specifically, HP Labs used it to develop and deploy advanced solutions for: the tracking of whereabouts of personal data (via an enhanced version of the Data Registry component); the management of sticky policies by means of a variety of possible technical approaches. The service framework now fully supports sticky policies as the mechanism to exchange personal data and privacy preferences across parties, in a safe and accountable way. A reference implementation is available as described in [8].

The HP Labs Service Framework is also an agile platform to develop demonstrators for a variety of needs, including prototypes of the overall system for the EnCoRe engagement with the Cabinet Office Identity Assurance Programme [2].

HP Labs are exploring the opportunity to release this Service Framework in the context of an Open Source initiative. This option is currently being discussed within EnCoRe and various involved organisations: a decision will be made towards the end of the project (April 2012).

[1] D2.3 Technical Architecture for the third realized Case Study,, http://www.encore-project.info/deliverables_material/D2_3_EnCoRe_Architecture_V1.0.pdf
[2] UK Cabinet Office, Identity Assurance (IdA) Programme Statements, http://services.parliament.uk/hansard/Commons/ByDate/20110518/writtenministerialstatements/part003.html
[3] D2.1 Technical Architecture for the first realized Case Study, http://www.encore-project.info/deliverables_material/D2.1%20EnCoRe%20Architecture%20V1.0.pdf
[4] D2.2 Technical Architecture for the second realized Case Study, http://www.encore-project.info/deliverables_material/D2_2_EnCoRe_Architecture_V1.0.pdf
[5] EnCoRe, HP Labs Service Framework, http://www.encore-project.info/newsletters/newsletter03/EnCoReAUG2011.html
[6] REST, http://en.wikipedia.org/wiki/Representational_state_transfer
[7] RESTLET, RESTful web framework for Java, http://www.restlet.org/
[8] Siani Pearson, Marco Casassa Mont, Sticky Policies: An Approach for Managing Privacy across Multiple Parties, IEEE Computer Magazine, Volume 44, Number 9, September 2011, 2011

--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---

Friday, July 1, 2011

HP Labs’ EnCoRe Service Framework for Privacy Management

HP Labs are developing an R&D Service Framework for the management of Consent/Revocation and Privacy, in the context of the EnCoRe project.

This work aims to provide a flexible, general purpose, agile and extensible R&D platform to further support the exploitation of EnCoRe technologies and solutions. We envisage using this Service Framework in the context of the EnCoRe engagement with the Cabinet Office, in their Identity Assurance Programme.

More details about this work are going to be published in the coming EnCoRe Newsletter.


References

[1] EnCoRe Architecture D2.1, http://www.encore-project.info/deliverables_material/D2.1%20EnCoRe%20Architecture%20V1.0.pdf, 2010

[2] EnCoRe Architecture D2.2, http://www.encore-project.info/deliverables_material/D2_2_EnCoRe_Architecture_V1.0.pdf, 2011

[3] UK Cabinet Office’s Identity Assurance Programme, http://www.publications.parliament.uk/pa/cm201011/cmhansrd/cm110518/wmstext/110518m0001.htm#11051863000116, 2011



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Wednesday, May 7, 2008

HP Labs Opens Research Opportunities to Academia

As announced in a recent press release, HP Labs are opening research opportunities to academia:

“HP today made it possible for colleges, universities and research institutions worldwide to participate in joint research with HP Labs, the company’s central research facility, through an open and competitive process.
The new HP Labs Innovation Research Program invites the worldwide academic community to submit proposals related to current research in the areas of information explosion, dynamic cloud services, content transformation, intelligent infrastructure and sustainability.
The program is the first offering of the HP Labs Open Innovation Office, which was established earlier this year as part of HP Labs’ new approach to research. The office is responsible for deepening HP Labs’ strategic collaborations with academia, the government and the commercial sector to produce mutually beneficial, high-impact research.
…
Program guidelines and the online submission tool are available at www.hpl.hp.com/open_innovation/irp. Proposals will go through an extensive review process within HP Labs. Selected winners will be notified in late 2008.”

--- NOTE: my original HP blog can be found here ---

Saturday, September 29, 2007

Privacy Management in Enterprises? It is a matter of Enforcement and Automation …

Privacy policy enforcement and automation are, in my view, two key aspects necessary to improve enterprise privacy management practices.

Privacy auditing and compliance checking are reactive approaches, definitely important but of little help when violations occur and the “privacy” of people has been compromised (e.g. their personal data has been misused, identity thefts, etc.). More effort is required to enforce privacy policies, in particular by introducing more automation (and integration with current enterprise identity management solutions …).

At HP Labs we have been researching for years in this direction. Some relevant projects have focused on:

In the context of the PRIME project, various Privacy Enhancing Approaches and Technologies have also been researched and developed.

More recently, the Identity Governance Framework (IGF) effort has introduced use cases, approaches and criteria to deal with data governance and enforce privacy both in enterprises and federated identity management contexts.

I argue that the decision on the “actual blend” of policy enforcement and auditing/compliance checking should be the outcome of a “risk analysis” process, which must keep into account the specific enterprise context and the assets to be protected.

--- NOTE: my original HP blog can be found here ---