{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,12]],"date-time":"2025-07-12T01:30:26Z","timestamp":1752283826784,"version":"3.40.3"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319663982"},{"type":"electronic","value":"9783319663999"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-66399-9_15","type":"book-chapter","created":{"date-parts":[[2017,8,11]],"date-time":"2017-08-11T14:03:24Z","timestamp":1502460204000},"page":"265-285","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["LeaPS: Learning-Based Proactive Security Auditing for Clouds"],"prefix":"10.1007","author":[{"given":"Suryadipta","family":"Majumdar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yosr","family":"Jarraya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Momen","family":"Oqaily","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Alimohammadifar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Makan","family":"Pourzandi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,8,12]]},"reference":[{"key":"15_CR1","unstructured":"Amazon: Amazon virtual private cloud. https:\/\/aws.amazon.com\/vpc"},{"key":"15_CR2","unstructured":"BayesFusion: GeNIe and SMILE. https:\/\/www.bayesfusion.com"},{"key":"15_CR3","unstructured":"Bellare, M., Yee, B.: Forward integrity for secure audit logs. Technical report, Citeseer (1997)"},{"key":"15_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"392","DOI":"10.1007\/978-3-642-23822-2_22","volume-title":"Computer Security \u2013 ESORICS 2011","author":"S Bleikertz","year":"2011","unstructured":"Bleikertz, S., Gro\u00df, T., Schunter, M., Eriksson, K.: Automated information flow analysis of virtualized infrastructures. In: Atluri, V., Diaz, C. (eds.) ESORICS 2011. LNCS, vol. 6879, pp. 392\u2013415. Springer, Heidelberg (2011). doi:10.1007\/978-3-642-23822-2_22"},{"key":"15_CR5","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T., Radar, C.: Near real-time detection of security failures in dynamic virtualized infrastructures. In: ACSAC (2014)"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T., M\u00f6dersheim, S.: Proactive security analysis of changes in virtualized infrastructure. In: ACSAC (2015)","DOI":"10.1145\/2818000.2818034"},{"key":"15_CR7","unstructured":"Cloud Auditing Data Federation: PyCADF: a Python-based CADF library (2015). https:\/\/pypi.python.org\/pypi\/pycadf"},{"key":"15_CR8","unstructured":"Cloud Security Alliance: Cloud control matrix CCM v3.0.1 (2014). https:\/\/cloudsecurityalliance.org\/research\/ccm\/"},{"key":"15_CR9","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1111\/j.2517-6161.1977.tb01600.x","volume":"39","author":"AP Dempster","year":"1977","unstructured":"Dempster, A.P., Laird, N.M., Rubin, D.B.: Maximum likelihood from incomplete data via the EM algorithm. J. Roy. Stat. Soc. 39, 1\u201338 (1977)","journal-title":"J. Roy. Stat. Soc."},{"key":"15_CR10","doi-asserted-by":"crossref","unstructured":"Doelitzscher, F., Fischer, C., Moskal, D., Reich, C., Knahl, M., Clarke, N.: Validating cloud infrastructure changes by cloud audits. In: IEEE Services (2012)","DOI":"10.1109\/SERVICES.2012.12"},{"issue":"1","key":"15_CR11","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/s10207-014-0239-8","volume":"14","author":"E Dolzhenko","year":"2014","unstructured":"Dolzhenko, E., Ligatti, J., Reddy, S.: Modeling runtime enforcement with mandatory results automata. Int. J. Inf. Secur. 14(1), 47\u201360 (2014)","journal-title":"Int. J. Inf. Secur."},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Foley, S.N., Neville, U.: A firewall algebra for OpenStack. In: IEEE CNS (2015)","DOI":"10.1109\/CNS.2015.7346867"},{"key":"15_CR13","unstructured":"Google: Google cloud platform. https:\/\/cloud.google.com"},{"key":"15_CR14","unstructured":"Guha, S.: Attack detection for cyber systems and probabilistic state estimation in partially observable cyber environments. Ph.D. thesis, Arizona State University (2016)"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Heckerman, D.: A tutorial on learning with Bayesian networks. In: Learning in graphical models (1998)","DOI":"10.1007\/978-94-011-5014-9_11"},{"key":"15_CR16","unstructured":"Hemmat, R.A., Hafid, A.: SLA violation prediction in cloud computing: a machine learning perspective. Technical report (2016)"},{"key":"15_CR17","first-page":"626","volume":"12","author":"H Holm","year":"2015","unstructured":"Holm, H., Shahzad, K., Buschle, M., Ekstedt, M.: $$P^2$$ CySeMoL: predictive, probabilistic cyber security modeling language. IEEE TDSC 12, 626\u2013639 (2015)","journal-title":"IEEE TDSC"},{"key":"15_CR18","unstructured":"ISO Std IEC. ISO 27017: Information technology- security techniques- code of practice for information security controls based on ISO\/IEC 27002 for cloud services (DRAFT) (2012). http:\/\/www.iso27001security.com\/html\/27017.html"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Jiang, Y., Zhang, E.Z., Tian, K., Mao, F., Gethers, M., Shen, X., Gao, Y.: Exploiting statistical correlations for proactive prediction of program behaviors. In: Proceedings of 8th Annual IEEE\/ACM International Symposium on Code Generation and Optimization. ACM (2010)","DOI":"10.1145\/1772954.1772989"},{"issue":"2","key":"15_CR20","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1016\/0167-9473(93)E0056-A","volume":"19","author":"SL Lauritzen","year":"1995","unstructured":"Lauritzen, S.L.: The EM algorithm for graphical association models with missing data. Comput Stat. Data Anal. 19(2), 191\u2013201 (1995)","journal-title":"Comput Stat. Data Anal."},{"key":"15_CR21","doi-asserted-by":"crossref","unstructured":"Li, M., Zang, W., Bai, K., Yu, M., Liu, P.: MyCloud: supporting user-configured privacy protection in cloud computing. In: ACSAC (2013)","DOI":"10.1145\/2523649.2523680"},{"key":"15_CR22","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1145\/1455526.1455532","volume":"12","author":"J Ligatti","year":"2009","unstructured":"Ligatti, J., Bauer, L., Walker, D.: Run-time enforcement of nonsafety policies. ACM TISSEC 12, 19 (2009)","journal-title":"ACM TISSEC"},{"key":"15_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/978-3-642-15497-3_6","volume-title":"Computer Security \u2013 ESORICS 2010","author":"J Ligatti","year":"2010","unstructured":"Ligatti, J., Reddy, S.: A theory of runtime enforcement, with results. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol. 6345, pp. 87\u2013100. Springer, Heidelberg (2010). doi:10.1007\/978-3-642-15497-3_6"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Madi, T., Majumdar, S., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L.: Auditing security compliance of the virtualized infrastructure in the cloud: application to OpenStack. In: ACM CODASPY (2016)","DOI":"10.1145\/2857705.2857721"},{"key":"15_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-319-45744-4_3","volume-title":"Computer Security \u2013 ESORICS 2016","author":"S Majumdar","year":"2016","unstructured":"Majumdar, S., Jarraya, Y., Madi, T., Alimohammadifar, A., Pourzandi, M., Wang, L., Debbabi, M.: Proactive verification of security compliance for clouds through pre-computation: application to OpenStack. In: Askoxylakis, I., Ioannidis, S., Katsikas, S., Meadows, C. (eds.) ESORICS 2016. LNCS, vol. 9878, pp. 47\u201366. Springer, Cham (2016). doi:10.1007\/978-3-319-45744-4_3"},{"key":"15_CR26","doi-asserted-by":"crossref","unstructured":"Majumdar, S., Madi, T., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L., Debbabi, M.: Security compliance auditing of identity and access management in the cloud: application to OpenStack. In: IEEE CloudCom (2015)","DOI":"10.1109\/CloudCom.2015.80"},{"key":"15_CR27","doi-asserted-by":"crossref","unstructured":"Mehnaz, S., Bertino, E.: Ghostbuster: a fine-grained approach for anomaly detection in file system accesses. In: ACM CODASPY (2017)","DOI":"10.1145\/3029806.3029809"},{"key":"15_CR28","unstructured":"Microsoft: Microsoft Azure virtual network. https:\/\/azure.microsoft.com"},{"key":"15_CR29","first-page":"16","volume":"12","author":"R Mitchell","year":"2015","unstructured":"Mitchell, R., Chen, R.: Behavior rule specification-based intrusion detection for safety critical medical cyber physical systems. IEEE TDSC 12, 16\u201330 (2015)","journal-title":"IEEE TDSC"},{"key":"15_CR30","unstructured":"Murphy, K.: A brief introduction to graphical models and Bayesian networks (1998)"},{"key":"15_CR31","unstructured":"OpenStack: Nova network security group changes are not applied to running instances (2015). https:\/\/security.openstack.org\/ossa\/OSSA-2015-021.html"},{"key":"15_CR32","unstructured":"OpenStack: OpenStack Congress (2015). https:\/\/wiki.openstack.org\/wiki\/Congress"},{"key":"15_CR33","unstructured":"OpenStack: OpenStack open source cloud computing software (2015). http:\/\/www.openstack.org"},{"key":"15_CR34","unstructured":"OpenStack: OpenStack audit middleware (2016). http:\/\/docs.openstack.org\/developer\/keystonemiddleware\/audit.html"},{"key":"15_CR35","unstructured":"OpenStack: OpenStack user survey (2016). https:\/\/www.openstack.org\/assets\/survey\/October2016SurveyReport.pdf"},{"key":"15_CR36","unstructured":"Pearl, J.: Causality: models, reasoning and inference (2000)"},{"key":"15_CR37","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1109\/MIC.2012.14","volume":"1","author":"K Ren","year":"2012","unstructured":"Ren, K., Wang, C., Wang, Q.: Security challenges for the public cloud. IEEE Internet Comput. 1, 69\u201373 (2012)","journal-title":"IEEE Internet Comput."},{"key":"15_CR38","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1145\/353323.353382","volume":"3","author":"FB Schneider","year":"2000","unstructured":"Schneider, F.B.: Enforceable security policies. ACM TISSEC 3, 30\u201350 (2000)","journal-title":"ACM TISSEC"},{"key":"15_CR39","unstructured":"Solanas, M., Hernandez-Castro, J., Dutta, D.: Detecting fraudulent activity in a cloud using privacy-friendly data aggregates. Technical report, arXiv preprint (2014)"},{"key":"15_CR40","doi-asserted-by":"crossref","unstructured":"Ullah, K., Ahmed, A., Ylitalo, J.: Towards building an automated security compliance tool for the cloud. In: IEEE TrustCom 2013 (2013)","DOI":"10.1109\/TrustCom.2013.195"},{"key":"15_CR41","first-page":"362","volume":"62","author":"C Wang","year":"2013","unstructured":"Wang, C., Chow, S.S., Wang, Q., Ren, K., Lou, W.: Privacy-preserving public auditing for secure cloud storage. IEEE TC 62, 362\u2013375 (2013)","journal-title":"IEEE TC"},{"key":"15_CR42","first-page":"940","volume":"12","author":"Y Wang","year":"2017","unstructured":"Wang, Y., Wu, Q., Qin, B., Shi, W., Deng, R.H., Hu, J.: Identity-based data outsourcing with comprehensive auditing in clouds. IEEE TIFS 12, 940\u2013953 (2017)","journal-title":"IEEE TIFS"},{"key":"15_CR43","doi-asserted-by":"crossref","unstructured":"Yau, S.S., Buduru, A.B., Nagaraja, V.: Protecting critical cloud infrastructures with predictive capability. In: IEEE CLOUD (2015)","DOI":"10.1109\/CLOUD.2015.165"},{"key":"15_CR44","doi-asserted-by":"crossref","unstructured":"Zhu, X., Song, S., Wang, J., Philip, S.Y., Sun, J.: Matching heterogeneous events with patterns. In: IEEE ICDE (2014)","DOI":"10.1109\/ICDE.2014.6816666"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2017"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-66399-9_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T05:14:15Z","timestamp":1719378855000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-66399-9_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319663982","9783319663999"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-66399-9_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"12 August 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Oslo","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Norway","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 September 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 September 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/deic.uab.cat\/conferences\/dpm\/dpm2017\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}