Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Monday, November 7, 2011

Situational Awareness-as-a -Service

I am working (along with colleagues) on a new HPL demonstrator, focusing on “Situational Awareness as a Service”.

This demonstrator will show how it is possible to combine flexible cloud computing resources, secure, policy-driven analytics nodes and visualization to provide configurable information sharing and situational awareness, to a variety of stakeholders.

We are currently exploring a few scenarios, including document sharing and military/government ones. We are also looking for public data feeds of relevance for global information sharing.

Input and requirements are welcome from the industry, government and academia.




--- Posted by Marco Casassa Mont(here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Security Analytics for Incident Management and Remediation Processes

A Security Analytics solution is now available for strategic risk assessment and decision support in the area of organisations’ Incident Management and Remediation Processes.

This solution has been fully transferred to HP Enterprise Security Solutions.

It is now available an overview of the Security Analytics Report that will be created and customised for customers.

In case you’d like to get a copy, learn more and/or are interested in carrying out a Security Analytics assessment in your organisation, please let me know.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

TSB Project Directory: Ensuring Trust in Digital Services

The Technology Strategy Board (TSB) has just released this Project Directory illustrating more than 20 funded projects in the space of trust, security, privacy and digital services.

The EnCoRe project is listed along with the current status and plans.

This document has been released in the contest of a joint event organised by TSB and the UK Cabinet Office/IDA Programme.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---The Technology Strategy Board (TSB) has just released this Project Directory illustrating more than 20 funded projects in the space of trust, security, privacy and digital services.

The EnCoRe project is listed along with the current status and plans.

This document has been released in the contest of a joint event organised by TSB and the UK Cabinet Office/IDA Programme.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Labs R&D Service Framework for Privacy and Consent Management

A fully working, new demonstrator has been built by HP Labs to illustrate EnCoRe capabilities in the space of consent and privacy management.

This demonstrator leverages the HP Labs R&D Service Framework (and a related prototype) i.e. a flexible and configurable service framework based on REST/RESTFul technologies. It is based on the EnCoRe Technical Architecture and can potentially be deployed in the context of an organisation, across organisations and the cloud.

It has been shown to the attendees of a recent joint Technology Strategy Board (TSB) and UK Cabinet Office/Identity Assurance (IDA) Programme event.

The demonstrator specifically showed how EnCoRe can be deployed in the IDA framework to support citizens and people in defining their privacy preferences as well as organisations in explicitly enforcing them.

HP Labs, along with EnCoRe, is actively engaging in the IDA Programme as well as looking for exploitation opportunities.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Sticky Policies: An Approach for Managing Privacy across Multiple Parties

We recently published an article on IEEE Computer Magazine, September 2011 issue, about “Sticky Policies: An Approach for Managing Privacy across Multiple Parties”:

“Machine-readable policies can stick to data to define allowed usage and obligations as it travels across multiple parties, enabling users to improve control over their personal information. The EnCoRe project has developed such a technical solution for privacy management that is suitable for use in a broad range of domains.”

--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---

Sunday, August 14, 2011

On the Next Generation of Cloud Computing and Cloud Operations Centres

I am going to spend more R&D time in the intersection of Cloud Computing & Security.
The area of cloud computing is getting increasingly busy, with various organisations providing solutions targeting the IaaS, PaaS and SaaS levels.
However, in my view there are still major outstanding questions and issues to be addressed, including:
  • Security and Privacy across various boundaries
  • Assurance and governance for the involved parties
  • Dynamic management of SLAs and policies across the involved parties
  • Effective Cloud Operation Centres
  • Effective migration of services and information in the Cloud
From a security and privacy perspective it becomes increasingly relevant a trustworthy and reliable exchange of information between the involved parties (organisations, service providers in the cloud, etc.), as well as sharing of threat intelligence.
In this context, I am exploring:
  • The next generation of Security Event & Incident Management Processes in the Cloud
  • Models for the provision of Cloud Operation Centres
  • Information flow exchange, to underpin some of the above aspects
  • Application of Security Analytics methodology in the Cloud
All these capabilities could be offered as a Service, in the context of the next generation of Cloud Operations Centres.
What is your view? What is coming next in the Cloud?
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---

Security Analytics applied to Security Event & Incident Management Processes

I just finished carrying out a case study with a key HP customer, involving the usage of the HP Security Analytics methodology for risk assessment and productivity analysis of their Security Event and Incident Management Processes.

This is a complex area, that goes beyond the simple usage of Security Event & Incident Management (SIEM) solutions and involves people, skills and processes to analyse events, identify false positives and/or security incidents to remediate. These processes are very important to minimise organisations’ exposure to additional security risks.

The case study has been successful. Models and simulations indentified (and provided evidence about) key process bottlenecks and root causes of risk exposure. A full Security Analytics report has been produced for the customer.

Template Security Analytics models and result diagrams have also been produced, in order to support a repeatable analytics service for other customers.

This Security Analytics area is now ready to be offered as a service.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Coordination of EnCoRe Project: Ensuring Consent and Revocation

I recently become the coordinator of the UK collaborative (TSB co-funded) EnCoRe project. This project focuses on ensuring consent & revocation to users, along with privacy management capabilities integrated with state-of-the-art IT frameworks.

This is a great opportunity. The project is now in its exploitation phase. We are setting up a strategic collaboration with the UK Cabinet Office/Identity Assurance programme, to leverage EnCoRe technical capabilities in their framework.

Further progress has been made to further develop the EnCoRe compliance checking and risk assessment capabilities, as well as in finalising the second case study in a Biobanking context.

In addition to various demonstrators built by EnCoRe partners, HP Labs are also developing a R&D EnCoRe Service Framework to provide a reference implementation, exploitable by third parties as well as a R&D platform for advanced research. This framework will be compliant with current EnCoRe Architecture and the coming third release.

Other exploitation opportunities are emerging with business groups and other UK agencies. More information to be provided soon on the EnCoRe web site ...

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Book – PRIME: Privacy and Identity Management for Europe

The PRIME Book is now available online.

This book documents the R&D outcomes of the EU PRIME project. It presents 28 detailed chapters organized in five parts:

- Introductory summary

- Legal, social, and economic aspects

- Realization of privacy-enhancing user-centric identity management

- Exploitation of PRIME results for applications

- Conclusions drawn and an outlook on future work


I specifically contributed to this book with two chapters:

· - Privacy Models and Languages: Obligation Policies

· - Privacy-Aware Identity Lifecycle Management


My R&D work on obligations policies and privacy-aware identity lifecycle management is also available here.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Information Security – Inform Magazine – Available Online

The latest issue of Inform, the HP Information Security Magazine, is available online.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Updated HPL Personal Web Page

I just finished to update my HPL Web Page, with the latest information about my research, public activities, publications and presentations.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, July 1, 2011

Towards A “Social Network” of Monitoring and Incident Management in the Cloud?

I recently read a very interesting article called “Log files – are you reviewing yours?”. Organisations often fail to fully leverage and analyse the audit log information that is collected within their IT and business environment …

Things might get worse when more and more organisational services and IT infrastructure is outsources in the Cloud …

This triggered a few thoughts about how assurance could be provided in the Cloud and how this could be done effectively to handle various degrees of risks.

Interestingly, when outsourcing in the Cloud, part of the organisational control on IT and processes is lost. This might include the ability of logging information at the desired level of granularity and timely acting on it, e.g. in case on incidents …

Which mechanisms should be put in place to enable organisations to get timely information, including logs and incidents, from their Cloud Service Providers?

This has an impact not only on SLAs and contractual agreements but also on technical solutions that needs to be deployed to:

- enable Cloud service providers to flexibly collect log information, at different level of abstractions in the IT stack – for specific customers - and provide it to organisations
- enable organisations to deal with mixed sources of log files, with potentially different level of accuracy and trust, to drive their audit & compliance management activities as well as incident management processes

It is going to be a “recursive” issue, as Cloud Service providers might rely on other providers in the Cloud …

I envisage a situation where enterprises’ business and governance requirements will dictate a wider collaboration between various Service Providers in order to collect, process, sanitise and share “logs information” and incidents.

Are we moving towards Federated Monitoring in the Cloud i.e. a sort of “Social Network” of Monitoring and Incident Management in the Cloud? …


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Labs’ EnCoRe Service Framework for Privacy Management

HP Labs are developing an R&D Service Framework for the management of Consent/Revocation and Privacy, in the context of the EnCoRe project.

This work aims to provide a flexible, general purpose, agile and extensible R&D platform to further support the exploitation of EnCoRe technologies and solutions. We envisage using this Service Framework in the context of the EnCoRe engagement with the Cabinet Office, in their Identity Assurance Programme.

More details about this work are going to be published in the coming EnCoRe Newsletter.


References

[1] EnCoRe Architecture D2.1, http://www.encore-project.info/deliverables_material/D2.1%20EnCoRe%20Architecture%20V1.0.pdf, 2010

[2] EnCoRe Architecture D2.2, http://www.encore-project.info/deliverables_material/D2_2_EnCoRe_Architecture_V1.0.pdf, 2011

[3] UK Cabinet Office’s Identity Assurance Programme, http://www.publications.parliament.uk/pa/cm201011/cmhansrd/cm110518/wmstext/110518m0001.htm#11051863000116, 2011



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

UK Cabinet Office’s Identity Assurance Programme

The UK Cabinet Office has provided further updates about their Identity Assurance Programme.

This article provides additional information and analysis:

“Government is hard at work with IT industry partners to crack the problem of identity assurance, says Nigel Harrison of the Office of Cyber Security and Information Assurance (OCSIA).
The initiative, being led by the Cabinet Office, is essential to government commitment to delivering services online, he told Computer Weekly.
In May, the Cabinet Office announced government plans to help create a market of private sector identity assurance services.
Nigel Harrison says it is likely the UK will soon see the emergence of multiple providers of identity assurance services specialising in different types or levels of assurance.
This will enable citizens to choose their own identity assurance providers depending on what level of assurance is required. Harrison said no single provider would necessarily have guardianship of all identity information about any individual, he said.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Presentation: Risk Assessment and Decision Support for Enterprise Security Policies

I recently gave a presentation at the IEEE Policy 2011 Symposium, about “Risk Assessment and Decision Support for Enterprise Security Policies”. Good discussions and debates.

My presentation is now available online. The abstract of the related paper follows:

“This paper presents and discusses our work to provide organizations with risk assessment and decision support capabilities when dealing with their strategic security policies. We aim at achieving this by using a rigorous and scientific methodology (and tools) which leverages modeling and simulation techniques. This methodology helps organizations to assess their risk exposure. It factors in policy implementation at the operational level along with relevant threats, processes, interactions and people behaviors. It provides “what-if” analysis by illustrating the consequences of making policy changes and investments. We introduce our methodology and tools and then illustrate how this approach has been successfully used in a real case study with one of our major customers. This case study focused on the organization’s access management processes and related policies: it helped to inform strategic security policies and support changes of current processes. Additional work is planned in this space.”



--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---