Network


Latest external collaboration on country level. Dive into details by clicking on the dots.

Hotspot


Dive into the research topics where Daniel Ricardo dos Santos is active.

Publication


Featured researches published by Daniel Ricardo dos Santos.


network operations and management symposium | 2014

A dynamic risk-based access control architecture for cloud computing

Daniel Ricardo dos Santos; Carla Merkle Westphall; Carlos Becker Westphall

Cloud computing is a distributed computing model that still faces problems. New ideas emerge to take advantage of its features and among the research challenges found in the cloud, we can highlight Identity and Access Management. The main problems of the application of access control in the cloud are the necessary flexibility and scalability to support a large number of users and resources in a dynamic and heterogeneous environment, with collaboration and information sharing needs. This paper proposes the use of risk-based dynamic access control for cloud computing. The proposal is presented as an access control model based on an extension of the XACML standard with three new components: the Risk Engine, the Risk Quantification Web Services and the Risk Policies. The risk policies present a method to describe risk metrics and their quantification, using local or remote functions. The risk policies allow users and cloud service providers to define how to handle risk-based access control for their resources, using different quantification and aggregation methods. The model reaches the access decision based on a combination of XACML decisions and risk analysis. A prototype of the model is implemented, showing it has enough expressivity to describe the models of related work. In the experimental results, the prototype takes between 2 and 6 milliseconds to reach access decisions using a risk policy. A discussion on the security aspects of the model is also presented.


computer and communications security | 2015

Automated Synthesis of Run-time Monitors to Enforce Authorization Policies in Business Processes

Clara Bertolissi; Daniel Ricardo dos Santos; Silvio Ranise

Run-time monitors are crucial to the development of security-aware workflow management systems, which need to mediate access to their resources by enforcing authorization policies and constraints, such as Separation of Duty. In this paper, we introduce a precise technique to synthesize run-time monitors capable of ensuring the successful termination of workflows while enforcing authorization policies and constraints. An extensive experimental evaluation shows the scalability of our technique on the important class of hierarchically specified security-sensitive workflows with several hundreds of tasks.


tools and algorithms for construction and analysis of systems | 2016

Cerberus: Automated Synthesis of Enforcement Mechanisms for Security-Sensitive Business Processes

Luca Compagna; Daniel Ricardo dos Santos; Serena Elisa Ponta; Silvio Ranise

Cerberus is a tool to automatically synthesize run-time enforcement mechanisms for security-sensitive Business Processes BPs. The tool is capable of guaranteeing that the execution constraints


Journal of Network and Computer Applications | 2016

A framework and risk assessment approaches for risk-based access control in the cloud

Daniel Ricardo dos Santos; Roberto Marinho; Gustavo Roecker Schmitt; Carla Merkle Westphall; Carlos Becker Westphall


symposium on access control models and technologies | 2016

Modular Synthesis of Enforcement Mechanisms for the Workflow Satisfiability Problem: Scalability and Reusability

Daniel Ricardo dos Santos; Serena Elisa Ponta; Silvio Ranise

EC


IFIP Annual Conference on Data and Applications Security and Privacy | 2015

Assisting the Deployment of Security-Sensitive Workflows by Finding Execution Scenarios

Daniel Ricardo dos Santos; Silvio Ranise; Luca Compagna; Serena Elisa Ponta


International Journal of Security and Networks | 2014

Privacy-preserving identity federations in the cloud: a proof of concept

Daniel Ricardo dos Santos; Tiago Jaime Nascimento; Carla Merkle Westphall; Marcos Aurélio Pedroso Leandro; Carlos Becker Westphall

on the tasks together with the authorization policy


Information Management & Computer Security | 2014

A cyclical evaluation model of information security maturity

Evandro Alencar Rigon; Carla Merkle Westphall; Daniel Ricardo dos Santos; Carlos Becker Westphall


conference on data and application security and privacy | 2017

Aegis: Automatic Enforcement of Security Policies in Workflow-driven Web Applications

Luca Compagna; Daniel Ricardo dos Santos; Serena Elisa Ponta; Silvio Ranise

AP


workshop on cyber physical systems | 2017

From System Specification to Anomaly Detection (and back)

Davide Fauri; Daniel Ricardo dos Santos; Elisa Costante; Jerry den Hartog; Sandro Etalle; Stefano Tonetta

Collaboration


Dive into the Daniel Ricardo dos Santos's collaboration.

Top Co-Authors

Avatar

Silvio Ranise

fondazione bruno kessler

View shared research outputs
Top Co-Authors

Avatar
Top Co-Authors

Avatar
Top Co-Authors

Avatar
Top Co-Authors

Avatar

Davide Fauri

Eindhoven University of Technology

View shared research outputs
Top Co-Authors

Avatar

Elisa Costante

Eindhoven University of Technology

View shared research outputs
Top Co-Authors

Avatar

Jerry den Hartog

Eindhoven University of Technology

View shared research outputs
Top Co-Authors

Avatar

Sandro Etalle

Eindhoven University of Technology

View shared research outputs
Top Co-Authors

Avatar
Top Co-Authors

Avatar
Researchain Logo
Decentralizing Knowledge