Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Sunday, August 14, 2011

Book – PRIME: Privacy and Identity Management for Europe

The PRIME Book is now available online.

This book documents the R&D outcomes of the EU PRIME project. It presents 28 detailed chapters organized in five parts:

- Introductory summary

- Legal, social, and economic aspects

- Realization of privacy-enhancing user-centric identity management

- Exploitation of PRIME results for applications

- Conclusions drawn and an outlook on future work


I specifically contributed to this book with two chapters:

· - Privacy Models and Languages: Obligation Policies

· - Privacy-Aware Identity Lifecycle Management


My R&D work on obligations policies and privacy-aware identity lifecycle management is also available here.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Information Security – Inform Magazine – Available Online

The latest issue of Inform, the HP Information Security Magazine, is available online.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Updated HPL Personal Web Page

I just finished to update my HPL Web Page, with the latest information about my research, public activities, publications and presentations.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, July 1, 2011

Towards A “Social Network” of Monitoring and Incident Management in the Cloud?

I recently read a very interesting article called “Log files – are you reviewing yours?”. Organisations often fail to fully leverage and analyse the audit log information that is collected within their IT and business environment …

Things might get worse when more and more organisational services and IT infrastructure is outsources in the Cloud …

This triggered a few thoughts about how assurance could be provided in the Cloud and how this could be done effectively to handle various degrees of risks.

Interestingly, when outsourcing in the Cloud, part of the organisational control on IT and processes is lost. This might include the ability of logging information at the desired level of granularity and timely acting on it, e.g. in case on incidents …

Which mechanisms should be put in place to enable organisations to get timely information, including logs and incidents, from their Cloud Service Providers?

This has an impact not only on SLAs and contractual agreements but also on technical solutions that needs to be deployed to:

- enable Cloud service providers to flexibly collect log information, at different level of abstractions in the IT stack – for specific customers - and provide it to organisations
- enable organisations to deal with mixed sources of log files, with potentially different level of accuracy and trust, to drive their audit & compliance management activities as well as incident management processes

It is going to be a “recursive” issue, as Cloud Service providers might rely on other providers in the Cloud …

I envisage a situation where enterprises’ business and governance requirements will dictate a wider collaboration between various Service Providers in order to collect, process, sanitise and share “logs information” and incidents.

Are we moving towards Federated Monitoring in the Cloud i.e. a sort of “Social Network” of Monitoring and Incident Management in the Cloud? …


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Labs’ EnCoRe Service Framework for Privacy Management

HP Labs are developing an R&D Service Framework for the management of Consent/Revocation and Privacy, in the context of the EnCoRe project.

This work aims to provide a flexible, general purpose, agile and extensible R&D platform to further support the exploitation of EnCoRe technologies and solutions. We envisage using this Service Framework in the context of the EnCoRe engagement with the Cabinet Office, in their Identity Assurance Programme.

More details about this work are going to be published in the coming EnCoRe Newsletter.


References

[1] EnCoRe Architecture D2.1, http://www.encore-project.info/deliverables_material/D2.1%20EnCoRe%20Architecture%20V1.0.pdf, 2010

[2] EnCoRe Architecture D2.2, http://www.encore-project.info/deliverables_material/D2_2_EnCoRe_Architecture_V1.0.pdf, 2011

[3] UK Cabinet Office’s Identity Assurance Programme, http://www.publications.parliament.uk/pa/cm201011/cmhansrd/cm110518/wmstext/110518m0001.htm#11051863000116, 2011



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

UK Cabinet Office’s Identity Assurance Programme

The UK Cabinet Office has provided further updates about their Identity Assurance Programme.

This article provides additional information and analysis:

“Government is hard at work with IT industry partners to crack the problem of identity assurance, says Nigel Harrison of the Office of Cyber Security and Information Assurance (OCSIA).
The initiative, being led by the Cabinet Office, is essential to government commitment to delivering services online, he told Computer Weekly.
In May, the Cabinet Office announced government plans to help create a market of private sector identity assurance services.
Nigel Harrison says it is likely the UK will soon see the emergence of multiple providers of identity assurance services specialising in different types or levels of assurance.
This will enable citizens to choose their own identity assurance providers depending on what level of assurance is required. Harrison said no single provider would necessarily have guardianship of all identity information about any individual, he said.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Presentation: Risk Assessment and Decision Support for Enterprise Security Policies

I recently gave a presentation at the IEEE Policy 2011 Symposium, about “Risk Assessment and Decision Support for Enterprise Security Policies”. Good discussions and debates.

My presentation is now available online. The abstract of the related paper follows:

“This paper presents and discusses our work to provide organizations with risk assessment and decision support capabilities when dealing with their strategic security policies. We aim at achieving this by using a rigorous and scientific methodology (and tools) which leverages modeling and simulation techniques. This methodology helps organizations to assess their risk exposure. It factors in policy implementation at the operational level along with relevant threats, processes, interactions and people behaviors. It provides “what-if” analysis by illustrating the consequences of making policy changes and investments. We introduce our methodology and tools and then illustrate how this approach has been successfully used in a real case study with one of our major customers. This case study focused on the organization’s access management processes and related policies: it helped to inform strategic security policies and support changes of current processes. Additional work is planned in this space.”



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Monday, May 30, 2011

Focusing on the Cloud and the Intersection of Cloud with Security

An area I am interested in spending more R&D time is the Cloud and the intersection of the Cloud with Security.

In particular I am interested exploring and contributing in the space of “Cloud middleware”. Some initial questions:

Which “middleware” services can be provided in the cloud to support various Cloud applications and services?
Which identity maangemet, security and privacy capabilities need to be in place?
How ensure accountability and assurance?
How to exploit recent Identity and Security Analytics capabilities, developed by HP Labs, in that space

I am currently gathering various information and documents in this space, related to business opportunities, current solution offering and technological approaches.

Any input and links to publicly available information are really welcome.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

EnCoRe Project: Architecture Version 2 released

The second EnCoRe Architecture, D2.2, has been officially released and it is available online.

This architectural document updates and refines the first Architecture about the explicit management of Privacy, Consent and Revocation by introducing – among many things - refined internal and external workflow management capabilities, the explicit management of obligation policies and the support for sticky policies.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Various papers accepted at International Conferences

I successfully managed to get, along with colleagues of mine, a few papers accepted at various international conferences – including WEIS 2011, STAVE 2011 and eChallenges 2011 focusing on aspects of Security Economics, Security and Privacy:

Simon Shiu, Adrian Baldwin, Yolanta Beres, Marco Casassa Mont, Geoff Duggan - Economic Methods and Decision Making by Security Professionals, WEIS 2011, George Mason University, 14-15 June 2011, US
Siani Pearson, Marco Casassa Mont and Gina Kounga, “Enhancing Accountability in the Cloud via Sticky Policies”, STAVE, Springer, June 2011.
Nick Papanikalaou, Siani Pearson and Marco Casassa Mont, “Towards Natural-Language Understanding and Automated Enforcement of Privacy Rules and Regulations in the Cloud: Survey and Bibliography”, STAVE, Springer, June 2011.
Nick Papanikolaou, Siani Pearson, Marco Casassa Mont and Ryan Ko, “Towards Greater Accountability in Cloud Computing through Natural-Language Analysis and Automated Policy Enforcement”, Proc. eChallenges, 2011.

Hopefully good debates and discussions will follow the presentations of these papers.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Presentation - Centre for Cybercrime and Computer Security Conference 2011

I was invited to attend and present at the Centre for Cybercrime and Computer Security Conference 2011, Newcastle, UK, as an HP Labs representative.

My presentation, on "Risk Exposure to Social Networks in Enterprises", is now available online.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, April 29, 2011

Applying Security Analytics in the Space of SOC and Incident Management

Here is another exciting area in the space of Security Analytics.

I and colleagues of mine have been carrying out a few case studies, jointly with HP Customers and HP businesses, in the space of situational awareness by using Security Analytics.

This is an exciting area, very suitable for the HP Labs and HP IS Security Analytics methodology and tools, as it involves modelling critical processes, people behaviours and dealing with risk assessment issues.

The aim is to provide decision support to strategic decision makers (CISOs, CIOs, risk managers, etc.) and support the definition of related security policies.

Of particular interest and relevance is the application of our modelling & simulation methodology (along with related tools) to the processes involved in Security Operations Centres (SOCs) and related Incident Management & Remediation.

Specifically, we aim at assessing the risk exposure of organisations due to their SOC/incident management processes and the involved performance (e.g. time wasted in handling false positives). A series of metrics have been identified to measure the involved risks, e.g. time to fully manage incidents (the higher the wider the risk exposure window).

We used our analytics models to explore “what-if” scenarios e.g. the impact of changing SOC/incident management process steps, introducing automation and/or changing the number of involved personnel.

Interesting trade-offs are currently explored based on the priorities of decision makers, e.g. costs vs productivity vs security risks.



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Identity and Security Analytics: Paper Accepted at IEEE Policy 2011 Symposium

We got a paper accepted at the IEEE Policy 2011 Symposium focusing on the Identity and Security Analytics work we did with a major HP customer:

“Marco Casassa Mont, Richard Brown
Risk Assessment and Decision Support for Security Policies and Related Enterprise Operational Processes”

The abstract of the paper follows:

“This paper presents and discusses our work to provide organizations with risk assessment and decision support capabilities when dealing with their strategic security policies. We aim at achieving this by using a rigorous and scientific methodology (and tools) which leverages modeling and simulation techniques. This methodology helps organizations to assess their risk exposure. It factors in policy implementation at the operational level along with relevant threats, processes, interactions and people behaviors. It provides “what-if” analysis by illustrating the consequences of making policy changes and investments. We introduce our methodology and tools and then illustrate how this approach has been successfully used in a real case study with one of our major customers. This case study focused on the organization’s access management processes and related policies: it helped to inform strategic security policies and support changes of current processes. Additional work is planned in this space.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

EnCoRe General Meeting in Venice and Networking Event for EU Framework 7 Call 8

On April 12th-14th we had an excellent General Meeting of the EnCoRe project, in Venice.

Good discussions on the third case study, system framework design and architectural aspects.

In this context, a networking event has been held to explore collaboration opportunities for the coming EU FP7 Call 8. It has been a very successful meeting with exciting opportunities, in particular in the area of “Cloud Accountability”.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

EnCoRe Project – 11th Quarter Summary

A summary of the project’s 11th quarter activities is available here.

In this context, the EnCoRe Architecture v.2 has now been fully completed and a related document will be published shortly. This release will feature new capabilities, including Obligation Management, support for Sticky Policies and improved Internal and external workflows for the management of consent and revocations.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---