The Community for Technology Leaders
Computer Security Applications Conference, Annual (1999)
Phoenix, Arizona
Dec. 6, 1999 to Dec. 10, 1999
ISSN: 1063-9527
ISBN: 0-7695-0346-2
TABLE OF CONTENTS

Reviewers (PDF)

pp. xv
Distinguished Lecture
Track A: Electronic Commerce

Modular Fair Exchange Protocols for Electronic Commerce (Abstract)

Holger Vogt , Darmstadt University of Technology
Henning Pagnia , Darmstadt University of Technology
Felix C. Gärtner , Darmstadt University of Technology
pp. 3

Trustworthy Access Control with Untrustworthy Web Servers (Abstract)

Dave Hearn , Defense Evaluation and Research Agency
Simon Wiseman , Defense Evaluation and Research Agency
Tim Wilkinson , Defense Evaluation and Research Agency
pp. 12

A Language for Modeling Secure Business Transactions (Abstract)

Alexander W. Roehm , University of Essen
Guenther Pernul , University of Essen
Gaby Herrmann , University of Essen
pp. 22
Track B: System Engineering

Safe Areas of Computation for Secure Computing with Insecure Applications (Abstract)

André L.M. dos Santos , University of California at Santa Barbara
Richard A. Kemmerer , University of California at Santa Barbara
pp. 35

Using Abuse Case Models for Security Requirements Analysis (Abstract)

Chris Fox , James Madison University
John McDermott , James Madison University
pp. 55
Track A: Networks

Secure Communications in ATM Networks (Abstract)

Ahmed Bouabdallah , ENST de Bretagne
Enrique Areizaga , Fundacion Robotiker
Juàn Manuel Mateos , Inelcom Ingeniera
Christophe Delahaye , ENST de Bretagne
pp. 84
Track A: Security Analysis

Using Checkable Types in Automatic Protocol Analysis (Abstract)

Stephen H. Brackin , Arca Systems / Exodus Communications
pp. 99

SCR: A Practical Approach to Building a High Assurance COMSEC Syste (Abstract)

Myla Archer , Naval Research Laboratory
James Kirby Jr , Naval Research Laboratory
Constance Heitmeyer , Naval Research Laboratory
pp. 109

Application-Level Isolation Using Data Inconsistency Detection (Abstract)

Amgad Fayad , The MITRE Corporation
Catherine D. McCollum , The MITRE Corporation
Sushil Jajodia , The MITRE Corporation
pp. 119
Track B: Workflow

A Prototype Secure Workflow Server (Abstract)

Francis Fung , Odyssey Research Associates
Julie Baker , Odyssey Research Associates
Douglas L. Long , Odyssey Research Associates
pp. 129

Napoleon: A Recipe for Workflow (Abstract)

D. Thomsen , Secure Computing Corporation
J. Bogle , Secure Computing Corporation
C. Payne , Secure Computing Corporation
R. O'Brien , Secure Computing Corporation
pp. 134

Tools to Support Secure Enterprise Computing (Abstract)

Judith N. Froscher , Naval Research Laboratory
Myong H. Kang , Naval Research Laboratory
Brian J. Eppinger , Naval Research Laboratory
pp. 143
Track A: Crypto

Towards a Practical, Secure, and Very Large Scale Online Election (Abstract)

Jared Karro , University of North Carolina at Greensboro
Jie Wang , University of North Carolina at Greensboro
pp. 161

Design of LAN-Lock, A System for Securing Wireless Networks (Abstract)

Richard E. Newman , University of Florida
Mark Sanders , Raytheon Systems Division
Joe Winner , Raytheon Systems Division
Tim Swanson , University of Florida
Phillipe Broccard , Raytheon Systems Division
Mark V. Hoyt , University of Florida
pp. 170
Track A: Security Services

Toward a Taxonomy and Costing Method for Security Services (Abstract)

Tim Levin , Anteon Corporation
Cynthia Irvine , Naval Postgraduate School
pp. 183

TrustedBox: A Kernel-Level Integrity Checker (Abstract)

Pietro Iglio , Fondazione Ugo Bordoni
pp. 189

Adding Availability to Log Services of Untrusted Machines (Abstract)

Emilia Rosti , Universit? degli Studi di Milano
Danilo Bruschi , Universit? degli Studi di Milano
Arianna Arona , Universit? degli Studi di Milano
pp. 199
Track B: Security Policy

Security Policy Coordination for Heterogeneous Information Systems (Abstract)

Mauricio Papa , University of Tulsa
John Hale , University of Tulsa
Pablo Galiasso , University of Tulsa
Sujeet Shenoi , University of Tulsa
pp. 219

The ARBAC99 Model for Administration of Roles (Abstract)

Ravi Sandhu , George Mason University
Qamar Munawer , George Mason University
pp. 229
Track A: Public Key Infrastructures

A Distributed Certificate Management System (DCMS) Supporting Group-Based Access Controls (Abstract)

Rolf Oppliger , Swiss Federal Strategy Unit for Information Technology FSUIT
Andreas Greulich , Swiss Federal Strategy Unit for Information Technology FSUIT
Peter Trachsel , Swiss Federal Strategy Unit for Information Technology FSUIT
pp. 241

Fast Checking of Individual Certificate Revocation on Small Systems (Abstract)

Selwyn Russell , Queensland University of Technology
pp. 249

A Model of Certificate Revocation (Abstract)

David A. Cooper , National Institute of Standards and Technology
pp. 256
Track B: Forum
Track A: Public Key Infrastructures

Generic Support for PKIX Certificate Management in CDSA (Abstract)

Shabnam Erfani , WatchGuard Technologies
Sekar Chandersekaran , Microsoft Corporation
pp. 269
Track B: Mobile Code

User Authentication and Authorization in the Java(tm) Platform (Abstract)

Li Gong , Sun Microsystems, Inc.
Anthony Nadalin , International Business Machines, Inc.
Larry Koved , International Business Machines, Inc.
Charlie Lai , Sun Microsystems, Inc.
pp. 285

Transactions in Java Card (Abstract)

Marcus Oestreicher , IBM Research Laboratory Zurich
pp. 291
Track A: Panel Session
Track B: Middleware

A Resource Access Decision Service for CORBA-Based Distributed Systems (Abstract)

Yi Deng , Florida International University
Konstantin Beznosov , Baptist Health Systems of South Florida
John Barkley , National Institute of Standards and Technology
Bob Blakley , DASCOM
pp. 310

Non-Repudiation Evidence Generation for CORBA Using XML (Abstract)

David Ingham , Newcastle University
Michael Wichert , GMD - German National Research Center for Information Technology
Steve Caughey , Newcastle University
pp. 320
Track A: Security Architectures

Security Relevancy Analysis on the Registry of Windows NT 4.0 (Abstract)

Aditya P. Mathur , Purdue University
Praerit Garg , Microsoft Corporation
Wenliang Du , Purdue University
pp. 331
Track B: Intrusion Detection

An Application of Machine Learning to Network Intrusion Detection (Abstract)

Sara Matzner , University of Texas at Austin
Lyn Pierce , University of Texas at Austin
Chris Sinclair , University of Texas at Austin
pp. 371

A Process State-Transition Analysis and its Application to Intrusion Detection (Abstract)

Samar Singh , La Trobe University
Nittida Nuansri , Prince of Songkla University
Tharam S. Dillon , La Trobe University
pp. 378

Author Index (PDF)

pp. 389
82 ms
(Ver 3.1 (10032016))