{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,6]],"date-time":"2025-06-06T17:50:37Z","timestamp":1749232237923,"version":"3.40.3"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031107689"},{"type":"electronic","value":"9783031107696"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,8,1]],"date-time":"2022-08-01T00:00:00Z","timestamp":1659312000000},"content-version":"vor","delay-in-days":212,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>We present new results on the application of semantic- and knowledge-based reasoning techniques to the analysis of cloud deployments. In particular, to the security of <jats:italic>Infrastructure as Code<\/jats:italic> configuration files, encoded as description logic knowledge bases. We introduce an action language to model <jats:italic>mutating actions<\/jats:italic>; that is, actions that change the structural configuration of a given deployment by adding, modifying, or deleting resources. We mainly focus on two problems: the problem of determining whether the execution of an action, no matter the parameters passed to it, will not cause the violation of some security requirement (<jats:italic>static verification<\/jats:italic>), and the problem of finding sequences of actions that would lead the deployment to a state where (un)desirable properties are (not) satisfied (<jats:italic>plan existence<\/jats:italic> and <jats:italic>plan synthesis<\/jats:italic>). For all these problems, we provide definitions, complexity results, and decision procedures.<\/jats:p>","DOI":"10.1007\/978-3-031-10769-6_17","type":"book-chapter","created":{"date-parts":[[2022,8,1]],"date-time":"2022-08-01T01:02:56Z","timestamp":1659315776000},"page":"281-299","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Actions over\u00a0Core-Closed Knowledge Bases"],"prefix":"10.1007","author":[{"given":"Claudia","family":"Cauli","sequence":"first","affiliation":[]},{"given":"Magdalena","family":"Ortiz","sequence":"additional","affiliation":[]},{"given":"Nir","family":"Piterman","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2022,8,1]]},"reference":[{"key":"17_CR1","doi-asserted-by":"crossref","unstructured":"Ahmetaj, S., Calvanese, D., Ortiz, M., Simkus, M.: Managing change in graph-structured data using description logics. ACM Trans. Comput. Log. 18(4), 27:1\u201327:35 (2017)","DOI":"10.1145\/3143803"},{"key":"17_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1613\/jair.2820","volume":"36","author":"A Artale","year":"2009","unstructured":"Artale, A., Calvanese, D., Kontchakov, R., Zakharyaschev, M.: The DL-lite family and relations. J. Artif. Intell. Res. 36, 1\u201369 (2009)","journal-title":"J. Artif. Intell. Res."},{"key":"17_CR3","doi-asserted-by":"publisher","DOI":"10.1017\/9781139025355","volume-title":"An Introduction to Description Logic","author":"F Baader","year":"2017","unstructured":"Baader, F., Horrocks, I., Lutz, C., Sattler, U.: An Introduction to Description Logic. Cambridge University Press, Cambridge (2017)"},{"key":"17_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1007\/978-3-030-25543-5_14","volume-title":"Computer Aided Verification","author":"J Backes","year":"2019","unstructured":"Backes, J., et al.: Reachability analysis for AWS-based networks. In: Dillig, I., Tasiran, S. (eds.) CAV 2019. LNCS, vol. 11562, pp. 231\u2013241. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-25543-5_14"},{"key":"17_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/978-3-030-53288-8_9","volume-title":"Computer Aided Verification","author":"J Backes","year":"2020","unstructured":"Backes, J., et al.: Stratified abstraction of access control policies. In: Lahiri, S.K., Wang, C. (eds.) CAV 2020. LNCS, vol. 12224, pp. 165\u2013176. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-53288-8_9"},{"key":"17_CR6","doi-asserted-by":"publisher","unstructured":"Backes, J., et al.: Semantic-based automated reasoning for AWS access policies using SMT. In: Bj\u00f8rner, N., Gurfinkel, A. (eds.) 2018 Formal Methods in Computer Aided Design, FMCAD 2018, Austin, TX, USA, 30 October\u20132 November 2018, pp. 1\u20139. IEEE (2018). https:\/\/doi.org\/10.23919\/FMCAD.2018.8602994","DOI":"10.23919\/FMCAD.2018.8602994"},{"key":"17_CR7","doi-asserted-by":"publisher","unstructured":"Bouchet, M., et al.: Block public access: trust safety verification of access control policies. In: Devanbu, P., Cohen, M.B., Zimmermann, T. (eds.) ESEC\/FSE 2020: 28th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Virtual Event, USA, 8\u201313 November 2020, pp. 281\u2013291. ACM (2020). https:\/\/doi.org\/10.1145\/3368089.3409728","DOI":"10.1145\/3368089.3409728"},{"key":"17_CR8","unstructured":"Calvanese, D., Giacomo, G.D., Lembo, D., Lenzerini, M., Rosati, R.: EQL-lite: effective first-order query processing in description logics. In: Veloso, M.M. (ed.) Proceedings of the 20th International Joint Conference on Artificial Intelligence, IJCAI 2007, Hyderabad, India, 6\u201312 January 2007, pp. 274\u2013279 (2007). http:\/\/ijcai.org\/Proceedings\/07\/Papers\/042.pdf"},{"key":"17_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1007\/978-3-642-39666-3_5","volume-title":"Web Reasoning and Rule Systems","author":"D Calvanese","year":"2013","unstructured":"Calvanese, D., De Giacomo, G., Montali, M., Patrizi, F.: Verification and synthesis in description logic based dynamic systems. In: Faber, W., Lembo, D. (eds.) RR 2013. LNCS, vol. 7994, pp. 50\u201364. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-39666-3_5"},{"key":"17_CR10","unstructured":"Calvanese, D., Montali, M., Patrizi, F., Giacomo, G.D.: Description logic based dynamic systems: modeling, verification, and synthesis. In: Yang, Q., Wooldridge, M.J. (eds.) Proceedings of the Twenty-Fourth International Joint Conference on Artificial Intelligence, IJCAI 2015, Buenos Aires, Argentina, 25\u201331 July 2015, pp. 4247\u20134253. AAAI Press (2015). http:\/\/ijcai.org\/Abstract\/15\/604"},{"key":"17_CR11","unstructured":"Calvanese, D., Montali, M., Patrizi, F., Stawowy, M.: Plan synthesis for knowledge and action bases. In: Kambhampati, S. (ed.) Proceedings of the Twenty-Fifth International Joint Conference on Artificial Intelligence, IJCAI 2016, New York, NY, USA, 9\u201315 July 2016, pp. 1022\u20131029. IJCAI\/AAAI Press (2016). http:\/\/www.ijcai.org\/Abstract\/16\/149"},{"key":"17_CR12","unstructured":"Calvanese, D., Ortiz, M., Simkus, M.: Evolving graph databases under description logic constraints. In: Eiter, T., Glimm, B., Kazakov, Y., Kr\u00f6tzsch, M. (eds.) Informal Proceedings of the 26th International Workshop on Description Logics, Ulm, Germany, 23\u201326 July 2013. CEUR Workshop Proceedings, vol. 1014, pp. 120\u2013131. CEUR-WS.org (2013). http:\/\/ceur-ws.org\/Vol-1014\/paper_82.pdf"},{"key":"17_CR13","doi-asserted-by":"publisher","unstructured":"Calvanese, D., Ortiz, M., Simkus, M.: Verification of evolving graph-structured data under expressive path constraints. In: Martens, W., Zeume, T. (eds.) 19th International Conference on Database Theory, ICDT 2016, Bordeaux, France, 15\u201318 March 2016. LIPIcs, vol. 48, pp. 15:1\u201315:19. Schloss Dagstuhl - Leibniz-Zentrum f\u00fcr Informatik (2016). https:\/\/doi.org\/10.4230\/LIPIcs.ICDT.2016.15","DOI":"10.4230\/LIPIcs.ICDT.2016.15"},{"key":"17_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"767","DOI":"10.1007\/978-3-030-81685-8_36","volume-title":"Computer Aided Verification","author":"C Cauli","year":"2021","unstructured":"Cauli, C., Li, M., Piterman, N., Tkachuk, O.: Pre-deployment security assessment for cloud services through semantic reasoning. In: Silva, A., Leino, K.R.M. (eds.) CAV 2021. LNCS, vol. 12759, pp. 767\u2013780. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-81685-8_36"},{"key":"17_CR15","doi-asserted-by":"crossref","unstructured":"Cauli, C., Ortiz, M., Piterman, N.: Closed- and open-world reasoning in dl-lite for cloud infrastructure security. In: Proceedings of the 18th International Conference on Principles of Knowledge Representation and Reasoning, KR 2021, Hanoi, Vietnam (2021)","DOI":"10.24963\/kr.2021\/17"},{"key":"17_CR16","doi-asserted-by":"publisher","unstructured":"Cauli, C., Ortiz, M., Piterman, N.: Actions over core-closed knowledge bases (2022). https:\/\/doi.org\/10.48550\/ARXIV.2202.12592. https:\/\/arxiv.org\/abs\/2202.12592","DOI":"10.48550\/ARXIV.2202.12592"},{"issue":"3","key":"17_CR17","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1016\/0004-3702(87)90092-0","volume":"32","author":"D Chapman","year":"1987","unstructured":"Chapman, D.: Planning for conjunctive goals. Artif. Intell. 32(3), 333\u2013377 (1987). https:\/\/doi.org\/10.1016\/0004-3702(87)90092-0","journal-title":"Artif. Intell."},{"key":"17_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1007\/978-3-319-96145-3_3","volume-title":"Computer Aided Verification","author":"B Cook","year":"2018","unstructured":"Cook, B.: Formal reasoning about the security of amazon web services. In: Chockler, H., Weissenbacher, G. (eds.) CAV 2018. LNCS, vol. 10981, pp. 38\u201347. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-96145-3_3"},{"issue":"1\u20132","key":"17_CR19","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1016\/0004-3702(94)00080-K","volume":"76","author":"K Erol","year":"1995","unstructured":"Erol, K., Nau, D.S., Subrahmanian, V.S.: Complexity, decidability and undecidability results for domain-independent planning. Artif. Intell. 76(1\u20132), 75\u201388 (1995). https:\/\/doi.org\/10.1016\/0004-3702(94)00080-K","journal-title":"Artif. Intell."},{"issue":"2","key":"17_CR20","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1142\/S0218843012500025","volume":"21","author":"GD Giacomo","year":"2012","unstructured":"Giacomo, G.D., Masellis, R.D., Rosati, R.: Verification of conjunctive artifact-centric services. Int. J. Cooperative Inf. Syst. 21(2), 111\u2013140 (2012). https:\/\/doi.org\/10.1142\/S0218843012500025","journal-title":"Int. J. Cooperative Inf. Syst."},{"key":"17_CR21","doi-asserted-by":"publisher","first-page":"651","DOI":"10.1613\/jair.3826","volume":"46","author":"BB Hariri","year":"2013","unstructured":"Hariri, B.B., Calvanese, D., Montali, M., Giacomo, G.D., Masellis, R.D., Felli, P.: Description logic knowledge and action bases. J. Artif. Intell. Res. 46, 651\u2013686 (2013)","journal-title":"J. Artif. Intell. Res."},{"issue":"6","key":"17_CR22","doi-asserted-by":"publisher","first-page":"835","DOI":"10.1016\/j.jcss.2013.01.006","volume":"79","author":"E Kharlamov","year":"2013","unstructured":"Kharlamov, E., Zheleznyakov, D., Calvanese, D.: Capturing model-based ontology evolution at the instance level: the case of dl-lite. J. Comput. Syst. Sci. 79(6), 835\u2013872 (2013). https:\/\/doi.org\/10.1016\/j.jcss.2013.01.006","journal-title":"J. Comput. Syst. Sci."},{"issue":"18","key":"17_CR23","doi-asserted-by":"publisher","first-page":"2170","DOI":"10.1016\/j.artint.2011.08.003","volume":"175","author":"H Liu","year":"2011","unstructured":"Liu, H., Lutz, C., Milicic, M., Wolter, F.: Foundations of instance level updates in expressive description logics. Artif. Intell. 175(18), 2170\u20132197 (2011). https:\/\/doi.org\/10.1016\/j.artint.2011.08.003","journal-title":"Artif. Intell."},{"key":"17_CR24","unstructured":"Milicic, M.: Planning in action formalisms based on DLS: first results. In: Calvanese, D., et al. (eds.) Proceedings of the 2007 International Workshop on Description Logics (DL2007), Brixen-Bressanone, near Bozen-Bolzano, Italy, 8\u201310 June 2007. CEUR Workshop Proceedings, vol. 250. CEUR-WS.org (2007). http:\/\/ceur-ws.org\/Vol-250\/paper_59.pdf"},{"issue":"5","key":"17_CR25","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1093\/logcom\/4.5.467","volume":"4","author":"EPD Pednault","year":"1994","unstructured":"Pednault, E.P.D.: ADL and the state-transition model of action. J. Logic Comput. 4(5), 467\u2013512 (1994). https:\/\/doi.org\/10.1093\/logcom\/4.5.467","journal-title":"J. Logic Comput."},{"key":"17_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/3-540-48168-0_21","volume-title":"Computer Science Logic","author":"S Tobies","year":"1999","unstructured":"Tobies, S.: A NExpTime-complete description logic strictly contained in $$C^{2}$$. In: Flum, J., Rodriguez-Artalejo, M. (eds.) CSL 1999. LNCS, vol. 1683, pp. 292\u2013306. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48168-0_21"}],"container-title":["Lecture Notes in Computer Science","Automated Reasoning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-10769-6_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,1]],"date-time":"2022-08-01T01:14:04Z","timestamp":1659316444000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-10769-6_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031107689","9783031107696"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-10769-6_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"1 August 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IJCAR","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Joint Conference on Automated Reasoning","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Haifa","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Israel","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ijcar2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/easychair.org\/smart-program\/FLoC2022\/IJCAR-index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"85","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"32","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"9","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5.2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}