{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T06:48:29Z","timestamp":1743144509320,"version":"3.40.3"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030299613"},{"type":"electronic","value":"9783030299620"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-29962-0_12","type":"book-chapter","created":{"date-parts":[[2019,9,14]],"date-time":"2019-09-14T23:03:29Z","timestamp":1568502209000},"page":"239-262","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Proactivizer: Transforming Existing Verification Tools into Efficient Solutions for Runtime Security Enforcement"],"prefix":"10.1007","author":[{"given":"Suryadipta","family":"Majumdar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Azadeh","family":"Tabiban","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meisam","family":"Mohammady","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alaa","family":"Oqaily","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yosr","family":"Jarraya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Makan","family":"Pourzandi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,9,15]]},"reference":[{"issue":"3","key":"12_CR1","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1109\/MSP.2017.80","volume":"15","author":"J Aikat","year":"2017","unstructured":"Aikat, J., et al.: Rethinking security in the era of cloud computing. IEEE Secur. Priv. 15(3), 60\u201369 (2017)","journal-title":"IEEE Secur. Priv."},{"unstructured":"Amazon. Amazon virtual private cloud. https:\/\/aws.amazon.com\/vpc. Accessed 14 Feb 2018","key":"12_CR2"},{"unstructured":"Bellare, M., Yee, B.: Forward integrity for secure audit logs. Technical report, Citeseer (1997)","key":"12_CR3"},{"key":"12_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"392","DOI":"10.1007\/978-3-642-23822-2_22","volume-title":"Computer Security \u2013 ESORICS 2011","author":"S Bleikertz","year":"2011","unstructured":"Bleikertz, S., Gro\u00df, T., Schunter, M., Eriksson, K.: Automated information flow analysis of virtualized infrastructures. In: Atluri, V., Diaz, C. (eds.) ESORICS 2011. LNCS, vol. 6879, pp. 392\u2013415. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23822-2_22"},{"doi-asserted-by":"crossref","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T.: Cloud radar: near real-time detection of security failures in dynamic virtualized infrastructures. In: Proceedings of the 30th Annual Computer Security Applications Conference (ACSAC), pp. 26\u201335. ACM (2014)","key":"12_CR5","DOI":"10.1145\/2664243.2664274"},{"doi-asserted-by":"crossref","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T., M\u00f6dersheim, S.: Proactive security analysis of changes in virtualized infrastructures. In: Proceedings of the 31st Annual Computer Security Applications Conference (ACSAC), pp. 51\u201360. ACM (2015)","key":"12_CR6","DOI":"10.1145\/2818000.2818034"},{"doi-asserted-by":"crossref","unstructured":"Celik, Z.B., Tan, G., McDaniel, P.: IoTGuard: dynamic enforcement of security and safety policy in commodity IoT. In: Proceedings of 2019 Annual Network and Distributed System Security Symposium (NDSS 2019), February 2019","key":"12_CR7","DOI":"10.14722\/ndss.2019.23326"},{"doi-asserted-by":"crossref","unstructured":"Doelitzscher, F., Fischer, C., Moskal, D., Reich, C., Knahl, M., Clarke, N.: Validating cloud infrastructure changes by cloud audits. In: Eighth World Congress on Services (SERVICES), pp. 377\u2013384. IEEE (2012)","key":"12_CR8","DOI":"10.1109\/SERVICES.2012.12"},{"issue":"1","key":"12_CR9","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/s10207-014-0239-8","volume":"14","author":"E Dolzhenko","year":"2015","unstructured":"Dolzhenko, E., Ligatti, J., Reddy, S.: Modeling runtime enforcement with mandatory results automata. Int. J. Inf. Secur. 14(1), 47\u201360 (2015)","journal-title":"Int. J. Inf. Secur."},{"unstructured":"Elasticsearch. Logstash. https:\/\/www.elastic.co\/products\/logstash. Accessed 14 Feb 2018","key":"12_CR10"},{"doi-asserted-by":"crossref","unstructured":"Foley, S.N., Neville, U.: A firewall algebra for OpenStack. In: Conference on Communications and Network Security (CNS), pp. 541\u2013549. IEEE (2015)","key":"12_CR11","DOI":"10.1109\/CNS.2015.7346867"},{"unstructured":"Google. Google cloud platform. https:\/\/cloud.google.com. Accessed 14 Feb 2018","key":"12_CR12"},{"unstructured":"Hamed, H., Al-Shaer, E., Marrero, W.: Modeling and verification of IPSEC and VPN security policies. In: 13th IEEE International Conference on Network Protocols (ICNP 2005), pp. 10\u2013pp. IEEE (2005)","key":"12_CR13"},{"unstructured":"Hamilton, J.D.: Time series analysis. Economic Theory. II, pp. 625\u2013630. Princeton University Press, USA (1995)","key":"12_CR14"},{"doi-asserted-by":"crossref","unstructured":"Hong, S., Xu, L., Wang, H., Gu, G.: Poisoning network visibility in software-defined networks: new attacks and countermeasures. In: Proceedings of 2015 Annual Network and Distributed System Security Symposium (NDSS 2015), February 2015","key":"12_CR15","DOI":"10.14722\/ndss.2015.23283"},{"doi-asserted-by":"crossref","unstructured":"Li, M., Zang, W., Bai, K., Yu, M., Liu, P.: Mycloud: supporting user-configured privacy protection in cloud computing. In: Proceedings of the 29th Annual Computer Security Applications Conference (ACSAC), pp. 59\u201368. ACM (2013)","key":"12_CR16","DOI":"10.1145\/2523649.2523680"},{"issue":"3","key":"12_CR17","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1145\/1455526.1455532","volume":"12","author":"J Ligatti","year":"2009","unstructured":"Ligatti, J., Bauer, L., Walker, D.: Run-time enforcement of nonsafety policies. ACM Trans. Inf. Syst. Secur. (TISSEC) 12(3), 19 (2009)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"12_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/978-3-642-15497-3_6","volume-title":"Computer Security \u2013 ESORICS 2010","author":"J Ligatti","year":"2010","unstructured":"Ligatti, J., Reddy, S.: A theory of runtime enforcement, with results. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol. 6345, pp. 87\u2013100. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15497-3_6"},{"unstructured":"Lopes, N.P., Bj\u00f8rner, N., Godefroid, P., Jayaraman, K., Varghese, G.: Checking beliefs in dynamic networks. In: 12th USENIX Symposium on Networked Systems Design and Implementation (NSDI 2015), pp. 499\u2013512 (2015)","key":"12_CR19"},{"doi-asserted-by":"crossref","unstructured":"Luo, Y., Luo, W., Puyang, T., Shen, Q., Ruan, A., Wu, Z.: OpenStack security modules: a least-invasive access control framework for the cloud. In: IEEE 9th International Conference on Cloud Computing (CLOUD) (2016)","key":"12_CR20","DOI":"10.1109\/CLOUD.2016.0017"},{"issue":"1","key":"12_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3267339","volume":"22","author":"T Madi","year":"2018","unstructured":"Madi, T., et al.: ISOTOP: auditing virtual networks isolation across cloud layers in OpenStack. ACM Trans. Priv. Secur. (TOPS) 22(1), 1 (2018)","journal-title":"ACM Trans. Priv. Secur. (TOPS)"},{"doi-asserted-by":"crossref","unstructured":"Madi, T., Majumdar, S., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L.: Auditing security compliance of the virtualized infrastructure in the cloud: application to OpenStack. In: Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy (CODASPY), pp. 195\u2013206. ACM (2016)","key":"12_CR22","DOI":"10.1145\/2857705.2857721"},{"key":"12_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-319-45744-4_3","volume-title":"Computer Security \u2013 ESORICS 2016","author":"S Majumdar","year":"2016","unstructured":"Majumdar, S., et al.: Proactive verification of security compliance for clouds through pre-computation: application to OpenStack. In: Askoxylakis, I., Ioannidis, S., Katsikas, S., Meadows, C. (eds.) ESORICS 2016. LNCS, vol. 9878, pp. 47\u201366. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-45744-4_3"},{"key":"12_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/978-3-319-66399-9_15","volume-title":"Computer Security \u2013 ESORICS 2017","author":"S Majumdar","year":"2017","unstructured":"Majumdar, S., et al.: LeaPS: learning-based proactive security auditing for clouds. In: Foley, S.N., Gollmann, D., Snekkenes, E. (eds.) ESORICS 2017. LNCS, vol. 10493, pp. 265\u2013285. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-66399-9_15"},{"doi-asserted-by":"crossref","unstructured":"Majumdar, S., et al.: Security compliance auditing of identity and access management in the cloud: application to OpenStack. In: 7th International Conference on Cloud Computing Technology and Science (CloudCom), pp. 58\u201365. IEEE (2015)","key":"12_CR25","DOI":"10.1109\/CloudCom.2015.80"},{"issue":"5","key":"12_CR26","doi-asserted-by":"publisher","first-page":"1185","DOI":"10.1109\/TIFS.2017.2779444","volume":"13","author":"S Majumdar","year":"2018","unstructured":"Majumdar, S., et al.: User-level runtime security auditing for the cloud. IEEE Trans. Inf. Forensics Secur. 13(5), 1185\u20131199 (2018)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"12_CR27","doi-asserted-by":"publisher","first-page":"165","DOI":"10.3233\/JCS-181137","volume":"27","author":"S Majumdar","year":"2019","unstructured":"Majumdar, S., et al.: Learning probabilistic dependencies among events for proactive security auditing in clouds. J. Comput. Secur. 27(2), 165\u2013202 (2019)","journal-title":"J. Comput. Secur."},{"unstructured":"Microsoft. Microsoft Azure virtual network. https:\/\/azure.microsoft.com. Accessed 14 Feb 2018","key":"12_CR28"},{"doi-asserted-by":"crossref","unstructured":"Nitta, N., Takata, Y., Seki, H.: An efficient security verification method for programs with stack inspection. In: Proceedings of the 8th ACM Conference on Computer and Communications Security, pp. 68\u201377. ACM (2001)","key":"12_CR29","DOI":"10.1145\/501983.501994"},{"unstructured":"OpenStack. OpenStack Congress (2015). https:\/\/wiki.openstack.org\/wiki\/Congress. Accessed 14 Feb 2018","key":"12_CR30"},{"unstructured":"OpenStack. OpenStack open source cloud computing software (2015). http:\/\/www.openstack.org. Accessed 14 Feb 2018","key":"12_CR31"},{"unstructured":"OpenStack. OpenStack user survey (2018). https:\/\/www.openstack.org\/user-survey\/2018-user-survey-report\/. Accessed 24 Apr 2019","key":"12_CR32"},{"issue":"1","key":"12_CR33","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1109\/MIC.2012.14","volume":"16","author":"K Ren","year":"2012","unstructured":"Ren, K., Wang, C., Wang, Q.: Security challenges for the public cloud. IEEE Internet Comput. 16(1), 69\u201373 (2012)","journal-title":"IEEE Internet Comput."},{"doi-asserted-by":"crossref","unstructured":"Schear, N., Cable II, P.T., Moyer, T.M., Richard, B., Rudd, R.: Bootstrapping and maintaining trust in the cloud. In: Proceedings of the 32nd Annual Conference on Computer Security Applications. ACM (2016)","key":"12_CR34","DOI":"10.1145\/2991079.2991104"},{"issue":"1","key":"12_CR35","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1145\/353323.353382","volume":"3","author":"FB Schneider","year":"2000","unstructured":"Schneider, F.B.: Enforceable security policies. Trans. Inf. Syst. Secur. (TISSEC) 3(1), 30\u201350 (2000)","journal-title":"Trans. Inf. Syst. Secur. (TISSEC)"},{"doi-asserted-by":"crossref","unstructured":"Skowyra, R., et al.: Effective topology tampering attacks and defenses in software-defined networks. In: Proceedings of the 48th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN 2018), June 2018","key":"12_CR36","DOI":"10.1109\/DSN.2018.00047"},{"doi-asserted-by":"crossref","unstructured":"Tabiban, A., Majumdar, S., Wang, L., Debbabi, M.: Permon: an openstack middleware for runtime security policy enforcement in clouds. In: Proceedings of the 4th IEEE Workshop on Security and Privacy in the Cloud (SPC 2018), June 2018","key":"12_CR37","DOI":"10.1109\/CNS.2018.8433180"},{"unstructured":"Tamura, N., Banbara, M.: Sugar: a CSP to SAT translator based on order encoding. In: Proceedings of the Second International CSP Solver Competition, pp. 65\u201369 (2008)","key":"12_CR38"},{"doi-asserted-by":"crossref","unstructured":"Ullah, K.W., Ahmed, A.S., Ylitalo, J.: Towards building an automated security compliance tool for the cloud. In: 12th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 1587\u20131593. IEEE (2013)","key":"12_CR39","DOI":"10.1109\/TrustCom.2013.195"},{"issue":"2","key":"12_CR40","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1109\/TC.2011.245","volume":"62","author":"C Wang","year":"2013","unstructured":"Wang, C., Chow, S.S., Wang, Q., Ren, K., Lou, W.: Privacy-preserving public auditing for secure cloud storage. IEEE Trans. Comput. 62(2), 362\u2013375 (2013)","journal-title":"IEEE Trans. Comput."},{"issue":"4","key":"12_CR41","doi-asserted-by":"publisher","first-page":"940","DOI":"10.1109\/TIFS.2016.2646913","volume":"12","author":"Y Wang","year":"2017","unstructured":"Wang, Y., Wu, Q., Qin, B., Shi, W., Deng, R.H., Hu, J.: Identity-based data outsourcing with comprehensive auditing in clouds. IEEE Trans. Inf. Forensics Secur. 12(4), 940\u2013952 (2017)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"12_CR42","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1016\/j.procs.2016.09.289","volume":"95","author":"DC Wardell","year":"2016","unstructured":"Wardell, D.C., Mills, R.F., Peterson, G.L., Oxley, M.E.: A method for revealing and addressing security vulnerabilities in cyber-physical systems by modeling malicious agent interactions with formal verification. Procedia Comput. Sci. 95, 24\u201331 (2016)","journal-title":"Procedia Comput. Sci."},{"unstructured":"WSGI. Middleware and libraries for WSGI (2016). http:\/\/wsgi.readthedocs.io\/en\/latest\/libraries.html. Accessed 15 Feb 2018","key":"12_CR43"},{"doi-asserted-by":"crossref","unstructured":"Yau, S.S. Buduru, A.B., Nagaraja, V.: Protecting critical cloud infrastructures with predictive capability. In: 8th International Conference on Cloud Computing (CLOUD), pp. 1119\u20131124. IEEE (2015)","key":"12_CR44","DOI":"10.1109\/CLOUD.2015.165"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2019"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-29962-0_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,15]],"date-time":"2024-09-15T00:12:57Z","timestamp":1726359177000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-29962-0_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030299613","9783030299620"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-29962-0_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"15 September 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Luxembourg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Luxembourg","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 September 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 September 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/conf.laas.fr\/esorics\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"344","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"67","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3,2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"11","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}