<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-8241500262281272192</atom:id><lastBuildDate>Sat, 14 Nov 2009 05:23:28 +0000</lastBuildDate><title>Marco Casassa Mont's "Research on Security and Identity Management" (Mirror)</title><description>The focus of this blog is on trends, new technologies/solutions and innovative aspects of Security and Identity Management - in a variety of contexts. I am a researcher at HP Labs: I am very keen to explore and discuss technical and social aspects of Security and Identity Management that are going to affect individuals, enterprises and other organizations in the medium/long terms. What is the next big thing in this space?</description><link>http://research-on-identitymanagement.blogspot.com/</link><managingEditor>noreply@blogger.com (Marco Casassa Mont)</managingEditor><generator>Blogger</generator><openSearch:totalResults>276</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><image><url>http://www.feedburner.com/fb/images/pub/fb_pwrd.gif</url></image><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/MarcoCasassaMontsresearchOnIdentityManagementmirror" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-4607715783841450699</guid><pubDate>Mon, 02 Nov 2009 18:02:00 +0000</pubDate><atom:updated>2009-11-02T18:05:21.482Z</atom:updated><category domain="http://www.blogger.com/atom/ns#">Phishing Attacks</category><title>Security Trends Report by Microsoft and McAfee: Phishing Scams Relying More Heavily on Worms and Trojans</title><description>Based on a recent &lt;a href="http://www.microsoft.com/security/portal/Threat/SIR.aspx"&gt;security trends report by Microsoft and MAfee&lt;/a&gt;, it looks like that social networks have been targeted with phishing scams and relying more heavily on worms and Trojans to attack computers. Rogue security software also remains a big issue.&lt;br /&gt;&lt;br /&gt;Some related articles on this topic can also be found &lt;a href="http://news.cnet.com/8301-27080_3-10387768-245.html?tag=newsEditorsPicksArea.0"&gt;here&lt;/a&gt; and &lt;a href="http://www.theregister.co.uk/2009/11/02/microsoft_security_report/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-4607715783841450699?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/UxamDvQQn7c" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/UxamDvQQn7c/security-trends-report-by-microsoft-and.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/11/security-trends-report-by-microsoft-and.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-6554714932434328141</guid><pubDate>Mon, 02 Nov 2009 18:00:00 +0000</pubDate><atom:updated>2009-11-02T18:02:38.017Z</atom:updated><category domain="http://www.blogger.com/atom/ns#">PrivacyOS</category><title>3rd PrivacyOS meeting</title><description>The 3rd PrivacyOS meeting has taken place in Vienna, 26-27 October 2009.&lt;br /&gt;&lt;br /&gt;I attended, along with a few colleagues from HP Labs Bristol, the 3rd PrivacyOS meeting, in Vienna.&lt;br /&gt;&lt;br /&gt;It has been a very interesting meeting, with presentations from various stakeholders of the privacy community and debates.&lt;br /&gt;&lt;br /&gt;A summary of presentations and related notes can be found &lt;a href="https://www.privacyos.eu/wiki/index.php/Main_Page"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-6554714932434328141?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/Wk2tOwpIcp0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/Wk2tOwpIcp0/3rd-privacyos-meeting.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/11/3rd-privacyos-meeting.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-6776948029198628479</guid><pubDate>Mon, 02 Nov 2009 17:56:00 +0000</pubDate><atom:updated>2009-11-02T17:59:17.046Z</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">smartphones</category><title>Article - Malware is bound to hit smartphone devices as users do not consider security</title><description>Interesting &lt;a href="http://www.scmagazineuk.com/Malware-is-bound-to-hit-smartphone-devices-as-users-do-not-consider-security/article/156858/"&gt;article&lt;/a&gt;, by Dan Raywood (called “Malware is bound to hit smartphone devices as users do not consider security”):&lt;br /&gt;“Smartphone attacks are likely to increase, as users are encouraged to take as much care with their device as with their PC. According to a report by CNN, smartphone security threats are likely to rise as the popularity of smartphones is on the rise and malware could be heading for them. …”&lt;br /&gt;I believe this is a real threat.  At risk, among many, are business corporate executives and senior people relying in and using more and more smartphones as their core device for their communications, including handling emails and storing confidential data.&lt;br /&gt;&lt;br /&gt;I predict that more efforts (in terms of products, solutions, services) will be paid to address these issues, at least at a corporate level  …&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-6776948029198628479?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/mfFVDBTpr68" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/mfFVDBTpr68/article-malware-is-bound-to-hit.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/11/article-malware-is-bound-to-hit.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-1705630723884055079</guid><pubDate>Mon, 02 Nov 2009 17:52:00 +0000</pubDate><atom:updated>2009-11-02T17:56:31.496Z</atom:updated><category domain="http://www.blogger.com/atom/ns#">EnCoRe</category><title>Update about TSB UK EnCoRe Project – Ensuring Consent and Revocation</title><description>The 5th Quarter Summary of EnCoRe (&lt;a href="http://www.encore-project.info/"&gt;http://www.encore-project.info&lt;/a&gt;) R&amp;amp;D activities in the space of Consent and Revocation management is now available online at: &lt;a href="http://www.encore-project.info/press_archive/Q5%20summary.pdf"&gt;http://www.encore-project.info/press_archive/Q5%20summary.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In addition, a new “service” has been launched, about “Latest EnCoRe Tidbits” aiming at providing links to snippets of news related to consent and revocation: &lt;a href="http://www.encore-project.info/news.html#story1"&gt;http://www.encore-project.info/news.html#story1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More to come. Enjoy.&lt;br /&gt;&lt;br /&gt;]--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-1705630723884055079?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/OQTrLWOf6PY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/OQTrLWOf6PY/update-about-tsb-uk-encore-project.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/11/update-about-tsb-uk-encore-project.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-2557743064102476279</guid><pubDate>Fri, 09 Oct 2009 17:22:00 +0000</pubDate><atom:updated>2009-10-09T18:24:44.232+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">security</category><category domain="http://www.blogger.com/atom/ns#">identity management</category><category domain="http://www.blogger.com/atom/ns#">privacy</category><title>Research on Security and Identity Management</title><description>The time has come to update the topic (and focus) of this blog.&lt;br /&gt;&lt;br /&gt;In the last few years my R&amp;amp;D work and research at HP Labs has been involving a variety of aspects, including security, identity management and privacy.&lt;br /&gt;&lt;br /&gt;Most of my posts have actually been reflecting this – hence my decision to update my blog. Hope this will further increase the community of people that are interested and follow my blog.&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-2557743064102476279?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/Ur5hAkR4hVI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/Ur5hAkR4hVI/research-on-security-and-identity.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/10/research-on-security-and-identity.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-9131789151458599458</guid><pubDate>Fri, 09 Oct 2009 17:20:00 +0000</pubDate><atom:updated>2009-10-09T18:22:02.186+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">W3C PLING</category><title>New W3C PLING General Phone Call – 14 October 2009, 12:00 UTC</title><description>The next W3C Policy Language Interest Group (PLING) general meeting is going to happen on October, 14th – 12:00 UTC.&lt;br /&gt;&lt;br /&gt;Topics to be discussed include: (1) Best practices for privacy awareness; (2) web policy language working group proposal.&lt;br /&gt;&lt;br /&gt;Please consider attending.&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-9131789151458599458?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/MySBfOuc9p8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/MySBfOuc9p8/new-w3c-pling-general-phone-call-14.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/10/new-w3c-pling-general-phone-call-14.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-2854682117201416407</guid><pubDate>Fri, 09 Oct 2009 17:18:00 +0000</pubDate><atom:updated>2009-10-09T18:20:15.534+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">password phishing</category><title>Article – Phishing or not, leaked passwords show lazy habits</title><description>This article, called &lt;a href="http://news.cnet.com/8301-27080_3-10371499-245.html?tag=newsEditorsPicksArea.0"&gt;Phishing or not, leaked passwords show lazy habits&lt;/a&gt;, by Elinor Mills, is quite interesting.&lt;br /&gt;&lt;br /&gt;It is not a novelty the fact that there are bad practices when dealing with passwords – but it is also true that people are usually good at making risk assessments and judge which level of protection to choose, depending on the value of the asset to protect …&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt;&lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-2854682117201416407?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/I9uepqsfMt8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/I9uepqsfMt8/article-phishing-or-not-leaked.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/10/article-phishing-or-not-leaked.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-4739739866256773153</guid><pubDate>Mon, 28 Sep 2009 16:43:00 +0000</pubDate><atom:updated>2009-09-28T17:44:48.065+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">PrivacyOS</category><title>3rd PrivacyOS Conference, Vienna, 25-27 October 2009</title><description>The Third PrivacyOS conference is going to take place in Vienna, 25-27 October 2009:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.amiando.com/3rdprivacyos.html"&gt;http://www.amiando.com/3rdprivacyos.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;“The third PrivacyOS Conference focuses on “rising awareness – functions and impact of data protection”.&lt;br /&gt;&lt;br /&gt;Participants are invited to join the Austrian Big Brother Awards Gala on the evening of the 25th of October and to discuss about privacy issues or their experiences in this field. The conference provides a unique opportunity to articulate and exchange best practices, challenges and solutions in privacy and data protection on the 26th and 27th of October.&lt;br /&gt;&lt;br /&gt;The conference primarily addresses legal and technical IT experts, interested manufacturers of IT products or services as well as data protection authorities. All persons interested in privacy or data protection aspects are welcome to register for the event. “&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-4739739866256773153?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/F94ksLslLww" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/F94ksLslLww/3rd-privacyos-conference-vienna-25-27.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/09/3rd-privacyos-conference-vienna-25-27.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-6040443265111869563</guid><pubDate>Mon, 28 Sep 2009 16:36:00 +0000</pubDate><atom:updated>2009-09-28T17:42:28.901+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">access contol</category><category domain="http://www.blogger.com/atom/ns#">privacy</category><title>Workshop on Access Control (and Privacy) Application Scenarios</title><description>Please consider submitting a position paper at the W3C Workshop on Access Control (and Privacy) Application Scenarios, by October 23rd:&lt;br /&gt;&lt;br /&gt;&lt;a title="http://www.w3.org/2009/policy-ws/cfp.html" href="http://www.w3.org/2009/policy-ws/cfp.html"&gt;http://www.w3.org/2009/policy-ws/cfp.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"W3C invites people to participate in a Workshop on Access Control Application Scenarios on 17-18 November 2009 in Luxembourg. This Workshop is intended to explore evolving application scenarios for access control technologies, such as XACML. Results from a number of recent European research projects in the grid, cloud computing, and privacy areas show overlapping use cases for these technologies that extend beyond classical intra-enterprise applications. The Workshop, co-financed by the European Commission 7th framework program via the PrimeLife project, is free of charge and open to anyone, subject to review of their statement of interest and space availability.&lt;br /&gt;&lt;br /&gt;The workshop is intended to discuss issues around access control in very wide sense, encompassing conditions and rules derived from the fact of accessing information. Topics that might serve as appropriate discussion points for position papers include, but are not limited to:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;interaction between access control and privacy policies &lt;/li&gt;&lt;li&gt;language extensions to connect access control languages to novel types of credentials &lt;/li&gt;&lt;li&gt;large-scale cloud and grid computing use cases for access control technologies &lt;/li&gt;&lt;li&gt;policy management &lt;/li&gt;&lt;li&gt;mechanisms for controlling progressive disclosure of information by user agents and servers &lt;/li&gt;&lt;li&gt;the emerging role of trust delegation and supportive mechanisms in cloud computing, grid, and Web use cases &lt;/li&gt;&lt;li&gt;mechanisms for richer user control over downstream data controllers &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The workshop will examine experiences and recent research results in these areas, their need for agreed semantics, the need for extensions to existing access control languages, and perhaps for radically new approaches.&lt;br /&gt;&lt;br /&gt;Position papers are due 23 October. See the call for participation for more information."&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt;&lt;br /&gt;--- NOTE:  use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site  ---&lt;br /&gt;&lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-6040443265111869563?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/j9b9BW1cvjY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/j9b9BW1cvjY/workshop-on-access-control-and-privacy.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/09/workshop-on-access-control-and-privacy.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-3599264366715743765</guid><pubDate>Mon, 28 Sep 2009 16:33:00 +0000</pubDate><atom:updated>2009-09-28T17:35:19.338+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">phishing</category><title>Interesting article – “Phishing Fraud hits two year high”</title><description>&lt;a href="http://www.theregister.co.uk/2009/09/28/phishing_fraud_trends/"&gt;http://www.theregister.co.uk/2009/09/28/phishing_fraud_trends/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;“Phishing attacks reached a record high during the second quarter of 2009, with 151,000 unique attacks, according to a study by brand reputation firm MarkMonitor. …”&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-3599264366715743765?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/jqbhVH7Pwys" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/jqbhVH7Pwys/interesting-article-phishing-fraud-hits.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/09/interesting-article-phishing-fraud-hits.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-7924047844982798072</guid><pubDate>Tue, 08 Sep 2009 16:25:00 +0000</pubDate><atom:updated>2009-09-08T17:26:37.762+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Playbook</category><title>On Enterprise Security Playbooks</title><description>I am interested in getting a few real-world examples of enterprise “Security Playbooks” and explore them.&lt;br /&gt;&lt;br /&gt;What is an enterprise Security Playbook? It is the “outcome” of organisation’s scenario planning and security risk assessment exercises, describing what should be done in presence of specific events and threats, for given contexts.&lt;br /&gt;&lt;br /&gt;A security playbook can relate both to current and foreseeable situations where decisions must be taken by one or more “decision makers” and courses of actions carried out by specific people.&lt;br /&gt;&lt;br /&gt;Why are “security playbooks” important? They are strategic for organisations as they synthesize what has to be done in critical situations (and who has to carry out actions) when very little time is allowed for debates and reactions.&lt;br /&gt;&lt;br /&gt;Interestingly enough, “playbooks” are available in many fields, related to traditional business risk management (in case of faults, natural disasters, etc.).&lt;br /&gt;&lt;br /&gt;I am interested in learning more about enterprise playbook that specifically focus on “IT security and cybercrime” aspects: I am wondering if any public template, example or guideline has ever been produced. I struggled to find anything really relevant …&lt;br /&gt;&lt;br /&gt;I am also interested in better understanding what the implications are in the IAM space, which impact playbooks have on people, IAM processes and related IT operations …&lt;br /&gt;&lt;br /&gt;Any input or links would be greatly appreciated.&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-7924047844982798072?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/I3BGT3qOMSI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/I3BGT3qOMSI/on-enterprise-security-playbooks.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/09/on-enterprise-security-playbooks.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-4750231515523451937</guid><pubDate>Tue, 08 Sep 2009 16:22:00 +0000</pubDate><atom:updated>2009-09-08T17:23:51.374+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Twitter</category><title>On my Experience in Using Twitter …</title><description>I’ve now been using &lt;a href="http://twitter.com/MCasassaMont"&gt;my Twitter account&lt;/a&gt; for a few months, in order to provide quick updates about my work and activities.&lt;br /&gt;&lt;br /&gt;My overall experience is positive. The 140 chars limitation is actually a pros, imposing some discipline on what to say and focus.&lt;br /&gt;&lt;br /&gt;I have used Twitter many times to complement my blogging activities, to provide short pointers to blog posts of interest, to a wide community of followers.&lt;br /&gt;&lt;br /&gt;I noticed that the communities operating in Twitter are nowadays much more active and dynamic than the ones operating in the traditional blogging space.&lt;br /&gt;&lt;br /&gt;But this is just based on my personal experience and discussed topics …&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-4750231515523451937?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/TzcGt6bAF6Q" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/TzcGt6bAF6Q/on-my-experience-in-using-twitter.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/09/on-my-experience-in-using-twitter.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-7399815782587570165</guid><pubDate>Tue, 08 Sep 2009 16:18:00 +0000</pubDate><atom:updated>2009-09-08T17:21:58.916+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">W3C PLING</category><title>W3C Policy Languages Interest Group (PLING) - Public Teleconference - 09 September 2009 – 12:00 AM (UTC)</title><description>The next &lt;a href="http://www.w3.org/Policy/pling/wiki/Main_Page"&gt;W3C Policy Languages Interest Group&lt;/a&gt; (PLING) public teleconference is going to be held on 09 September 2009, at 12:00 AM (UTC).&lt;br /&gt;&lt;br /&gt;Among many other topics, the agenda includes:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;PLING Note on &lt;a title="http://www.w3.org/Policy/pling/wiki/PLINGNOTEBestPracticesForPrivacyAwareness" href="http://www.w3.org/Policy/pling/wiki/PLINGNOTEBestPracticesForPrivacyAwareness"&gt;Best Practices for Privacy Awareness&lt;/a&gt;. See &lt;a title="http://www.w3.org/TR/geolocation-API/" href="http://www.w3.org/TR/geolocation-API/"&gt;W3C GeoLocation API WD&lt;/a&gt; and &lt;a title="http://www.mozilla.com/en-US/firefox/geolocation/" href="http://www.mozilla.com/en-US/firefox/geolocation/"&gt;FireFox Location-Aware Browsing&lt;/a&gt; for inspiration&lt;/li&gt;&lt;li&gt;&lt;a title="http://dev.w3.org/html5/spec/Overview.html#licensing-works" href="http://dev.w3.org/html5/spec/Overview.html#licensing-works"&gt;HTML 5 Licensing Works&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Proposal for a new Web Policy Language Working Group&lt;br /&gt; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please consider attending this teleconference.&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-7399815782587570165?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/EMMyfqHvSYA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/EMMyfqHvSYA/w3c-policy-languages-interest-group.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/09/w3c-policy-languages-interest-group.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-818732768139341827</guid><pubDate>Tue, 25 Aug 2009 12:11:00 +0000</pubDate><atom:updated>2009-08-25T13:17:41.757+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Identity Analytics</category><title>Good R&amp;D Progress in the Space of Identity (and Security) Analytics</title><description>&lt;p&gt;Good progress has been made in the R&amp;amp;D space of Identity Analytics at HP Labs (in the broader context of Security Analytics).&lt;br /&gt;&lt;br /&gt;Various IAM case studies have been explored, investigating how event-driven probabilistic modelling, coupled with economic studies, can be used to help decision makers to make decision on investments, identify suitable metrics &amp;amp; policies, better understand the impact of choices, trade-offs and risk implications.&lt;br /&gt;&lt;br /&gt;We got a few papers accepted in international conferences, in particular at IEEE Policy 2009 Symposium, Trust Economics 2009 Workshop and IEEE MetriSec 2009 – covering various IAM aspects.&lt;br /&gt;&lt;br /&gt;A few HP Labs Technical Reports are now publicly available:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-173.html"&gt;HPL-2009-173&lt;/a&gt; Adrian Baldwin, Marco Casassa Mont, David Pym, Simon Shiu - System Modelling for Economic Analysis of Security Investments: A Case Study in Identity and Access Management - HPL-2009-173&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-142.html"&gt;HPL-2009-142&lt;/a&gt; Yolanta Beres, Marco Casassa Mont, Jonathan Griffin, Simon Shiu - Using Security Metrics Coupled with Predictive Modelling and Simulation to Assess Security Processes - HPL-2009-142&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-138.html"&gt;HPL-2009-138&lt;/a&gt; Anna Squicciarini, Marco Casassa Mont, Sathya Dev Rajasekaran - Towards an Analytic Approach to Evaluate Enterprises’ Risk Exposure to Social Networks - HPL-2009-138 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-57.html"&gt;HPL-2009-57&lt;/a&gt; Marco Casassa Mont, Adrian Baldwin, Simon Shiu - Identity Analytics - User provisioning Case Study: Using Modelling and Simulation for Policy Decision Support - HPL-2009-57, 2009 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-56.html"&gt;HPL-2009-56&lt;/a&gt; Adrian Baldwin, Marco Casassa Mont, Simon Shiu - Using Modelling and Simulation for Policy Decision Support in Identity Management - HPL-2009-56, 2009 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;HPL-2008-&lt;/a&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;84&lt;/a&gt; Marco Casassa Mont, Adrian Baldwin, Simon Shiu - On Identity Analytics: Setting the Context- HPL-2008-84, 2008&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;I am looking for input and feedback, in particular additional case studies where to apply our approach and techniques.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;) ---&lt;br /&gt;&lt;br /&gt;--- NOTE: my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; ---&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-818732768139341827?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/cBNtOB6fZfE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/cBNtOB6fZfE/good-r-progress-in-space-of-identity.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/08/good-r-progress-in-space-of-identity.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-4980431992957333528</guid><pubDate>Tue, 25 Aug 2009 12:05:00 +0000</pubDate><atom:updated>2009-08-25T13:06:44.173+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Conferences</category><title>Serving in the Technical Program Committee of International Conferences</title><description>This year I have been serving as a member of many Technical Program Committees, in various International (IEEE, ACM, etc.)  Conferences, including: &lt;a href="http://www.acsac.org/"&gt;ACSAC 2009&lt;/a&gt;,  &lt;a href="http://ieee-biometrics.org/bids2009/"&gt;IEEE BIDS 2009&lt;/a&gt;,  &lt;a href="http://sesar.dti.unimi.it/InSPEC2009/"&gt;IEEE InSpec 2009&lt;/a&gt;, &lt;a href="http://www2.pflab.ecl.ntt.co.jp/dim2009/"&gt;ACM DIM 2009&lt;/a&gt;, &lt;a href="http://www.icsi.berkeley.edu/icsc/"&gt;IEEE ICSC 2009&lt;/a&gt;, &lt;a href="http://www.icsd.aegean.gr/trustbus2009/"&gt;TrustBus 2009 &lt;/a&gt;and &lt;a href="http://www.iaria.org/conferences2009/ComICIMP09.html"&gt;ICIMP 2009&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I found this experience very rewarding. Despite the need to allocate some amount of time for peer reviewing papers, this really provides good overviews of the state-of-art of research (and applied research) in the field of interest – in my case security, identity management and privacy.&lt;br /&gt;&lt;br /&gt;I would encourage the members of this community in having a similar role, especially the one interested in R&amp;amp;D and research.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-4980431992957333528?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/an4qDWNUQ3U" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/an4qDWNUQ3U/serving-in-technical-program-committee.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/08/serving-in-technical-program-committee.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-2310582779719240792</guid><pubDate>Tue, 25 Aug 2009 12:03:00 +0000</pubDate><atom:updated>2009-08-25T13:04:01.833+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">W3C PLING</category><title>Call for Actions: W3C Policy Languages Interest Group (PLING)</title><description>We are looking for active contributions in the context of the &lt;a href="http://www.w3.org/Policy/pling/wiki/Main_Page"&gt;W3C PLING Interest Group&lt;/a&gt;, in the space of: use cases, policy language reviews, policy initiatives and open issues.&lt;br /&gt; &lt;br /&gt;Of particular interest are any input related to the implication of using policies and policy management in the space of cloud computing.&lt;br /&gt;&lt;br /&gt;The charter of W3C PLING ha now been extended to December 2009. We are looking for your input and contributions.&lt;br /&gt;&lt;br /&gt;The next general phone meeting (open to everybody) is planned to happen on 09 September 2009, 12:00 AM (UTC)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-2310582779719240792?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/LiB2apwojaQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/LiB2apwojaQ/call-for-actions-w3c-policy-languages.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/08/call-for-actions-w3c-policy-languages.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-6320116561427251586</guid><pubDate>Tue, 25 Aug 2009 12:00:00 +0000</pubDate><atom:updated>2009-08-25T13:02:13.525+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">EnCoRe</category><title>Good progress in the TSB EnCoRe Project – Ensuring Consent and Revocation</title><description>The &lt;a href="http://www.encore-project.info/"&gt;TSB EnCoRe project&lt;/a&gt; (Ensuring Consent and Revocation) is making good progress towards his various objectives, involving the provision and management of consent and revocation.&lt;br /&gt;&lt;br /&gt;This topic has been tackled from various perspectives including: legal and social aspects, user requirements, architectural and technological aspects, risk assessment and compliance.&lt;br /&gt;&lt;br /&gt;More information is available on the EnCoRe web site, including a brief &lt;a href="http://www.encore-project.info/press_archive/Q4%20summary.pdf"&gt;summary of the project’s fourth quarter activities&lt;/a&gt;.&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-6320116561427251586?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/8-iylf-lwGU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/8-iylf-lwGU/good-progress-in-tsb-encore-project.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/08/good-progress-in-tsb-encore-project.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-6437492498010826788</guid><pubDate>Tue, 25 Aug 2009 11:58:00 +0000</pubDate><atom:updated>2009-08-25T12:59:59.433+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Secure Delivery</category><title>New HP Labs Technical Report – “Secure Delivery of Services: The HP Labs Vision and Framework”</title><description>A new HP Labs Technical Report has been released, in the area of Security management, called &lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-191.html"&gt;“Secure Delivery of Services: The HP Labs Vision and Framework”&lt;/a&gt; by Marco Casassa Mont and Patrick Goldsack:&lt;br /&gt;&lt;br /&gt;“The secure delivery and management of services and information is complex and subject to a multitude of factors and issues. Key challenges are posed by current trends towards outsourcing of services/decentralization, loss of control over the IT infrastructure, remote access to services by citizens and civil servants, an increasingly mobile workforce along with mutable threat environments and new risks posed by new devices and ways to store, process and transport information. Traditional approaches to security and related controls (e.g. Vulnerability Management, Identity and Access Management, Data Protection, etc.) need to be reassessed and adapted to cope with this ever changing IT environment. To ensure secure delivery, IT consultants, government planners, decision makers and IT Operations teams need to have a holistic approach to security and understand the implications and impact of these aspects. At HP Labs we are developing a vision and framework for the secure delivery of services and related information, based on an integrated approach underpinned by four core capabilities and technologies developed in HP Laboratories: Security Analytics to model policy and reason about the security and other risks; Secure IT Configuration and Deployment to act as the automated engine of policy implementation; Trusted Infrastructure which is the basic building block for the secure delivery of services; and finally Continuous Compliance and Monitoring which ensures that the systems behave as intended in the policy description.”&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-6437492498010826788?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/WKYRlQ6eRls" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/WKYRlQ6eRls/new-hp-labs-technical-report-secure.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/08/new-hp-labs-technical-report-secure.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-5919562758336708263</guid><pubDate>Wed, 22 Jul 2009 11:03:00 +0000</pubDate><atom:updated>2009-07-22T12:04:44.241+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">IEEE Policy 2009</category><title>About IEEE Policy 2009 Symposium</title><description>I attended the 10th edition of the IEEE Policy 2009 Symposium - &lt;a href="http://www.policy-workshop.org/program.html"&gt;http://www.policy-workshop.org/program.html&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This year it has been a particularly interesting conference. Good Keynotes and very interesting presentations, covering various aspects of policies and their management – including IT Governance, Analytics, Security and Privacy, Access Control, Formal Representations, Reasoning, Semantic Web and extensions of current languages (e.g. XACML).&lt;br /&gt;&lt;br /&gt;I gave a presentation on “Using Modeling and Simulation for Policy Decision Support in Identity Management.  This is part of ongoing HP Labs work on Security and Identity Analytics. My presentation slideset is available &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Documents/Papers/HPL-%20IEEE%20Policy%202009%20-%20marcocasassamont.ppt"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;All other presentations are also going to be made available online, in the Policy 2009 web site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-5919562758336708263?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/08xBjk0xoxk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/08xBjk0xoxk/about-ieee-policy-2009-symposium.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/07/about-ieee-policy-2009-symposium.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-6290766697732099028</guid><pubDate>Wed, 22 Jul 2009 10:55:00 +0000</pubDate><atom:updated>2009-07-22T12:01:27.035+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Analytics</category><category domain="http://www.blogger.com/atom/ns#">Identity Analytics</category><title>New HP Labs Technical Report – “Systems Modelling for Economic Analyses of Security Investments: A Case Study in Identity and Access Management”</title><description>A new HP Labs Technical Report has been released, in the area of Security and Identity Analytics, called &lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-173.html"&gt;“Systems Modelling for Economic Analyses of Security Investments: A Case Study in Identity and Access Management”&lt;/a&gt; by Adrian Baldwin, Marco Casassa Mont,  David Pym and Simon Shiu:&lt;br /&gt;&lt;br /&gt;“Identity and Access Management (IAM) is a key issue for systems security managers such as CISOs. More specifically, it is a difficult problem to understand how different investments in people, process, and technology affect the intended security outcomes. We position this problem within the framework of optimal control models in macroeconomics, and use a process model to understand the dynamics of the utility of possible trade-offs between investment, access, and security incidents (breaches). A utility function is used to express the security manager's IAM preferences, and the functional behaviour of its components is described via a process model. Executing our process model as Monte Carlo simulations, we illustrate the behaviour of the utility function for varying levels of investment and threat, and so provide the beginnings of a decision-support tool for systems security managers.”&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-6290766697732099028?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/gvCVjVAd3zM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/gvCVjVAd3zM/new-hp-labs-technical-report-systems.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/07/new-hp-labs-technical-report-systems.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-5819076251238804404</guid><pubDate>Wed, 15 Jul 2009 09:24:00 +0000</pubDate><atom:updated>2009-07-15T10:26:00.704+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Blog Spamming</category><title>Blog under spamming attack – end of anonymous comments?</title><description>I just noticed that my blog on &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;“Research on Identity Management”&lt;/a&gt;, hosted by the HP portal, is under “comment spamming” attack.&lt;br /&gt;&lt;br /&gt;This is not a major issue as the current blog platform’s security controls just filter these undesired comments.&lt;br /&gt;&lt;br /&gt;However, in my view, this shows how the capability of having anonymous posting of comments can be easily abused. &lt;br /&gt;&lt;br /&gt;I believe this capability will be increasingly disabled in most blog sites. The same could happen for “authenticated” comments, as most of the time this just requires a user setting an account with a fake profile, hence enabling spammers to post again their comments.&lt;br /&gt;&lt;br /&gt;Switching-off the capability of posting comments or introducing further controls will make the blog experience harder and harder …&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-5819076251238804404?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/Hbtyi-IDEx4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/Hbtyi-IDEx4/blog-under-spamming-attack-end-of.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/07/blog-under-spamming-attack-end-of.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-5143409350871265390</guid><pubDate>Wed, 15 Jul 2009 09:22:00 +0000</pubDate><atom:updated>2009-07-15T10:23:52.574+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Cybercrime</category><title>Interesting BBC article – “Cyber crooks get business savvy”</title><description>This &lt;a href="http://news.bbc.co.uk/1/hi/technology/8149034.stm"&gt;article&lt;/a&gt;, called “Cyber crooks get business savvy” is particularly interesting as it illustrates how cybercrime is evolving and maturing:&lt;br /&gt;&lt;br /&gt;“Cyber crooks are increasingly operating like successful businesses, deploying the same tools legitimate companies use to boost their profits. Networking giant Cisco said online criminals were increasingly using proven business practices.&lt;br /&gt;In its mid-year security report, Cisco said this new approach puts the bad guys way ahead. "When your enemy is financially motivated you have to be on alert," said Cisco fellow Patrick Peterson.”&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-5143409350871265390?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/NyfFbvzbsb8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/NyfFbvzbsb8/interesting-bbc-article-cyber-crooks.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/07/interesting-bbc-article-cyber-crooks.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-2409497173103231903</guid><pubDate>Wed, 15 Jul 2009 09:18:00 +0000</pubDate><atom:updated>2009-07-15T10:21:46.026+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">IEEE Policy 2009</category><title>IEEE Policy 2009 Symposium – Ready to Go</title><description>The 10th IEEE Policy 2009 Symposium (&lt;a href="http://www.ieee-policy.org/"&gt;www.ieee-policy.org&lt;/a&gt;) is coming, 20-22 July 2009, Imperial College, London, UK.&lt;br /&gt;&lt;br /&gt;This &lt;a href="http://www.ieee-policy.org/program.html"&gt;year’s programme&lt;/a&gt; is particularly interesting, with Keynote Speeches from Dr. Anne Adams (The Open University), Dr. Claudio Bartolini (HP Labs) and Dr. Mark Ryan (University of Birmingham).&lt;br /&gt;&lt;br /&gt;I will present a paper describing recent HP Labs work on &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt;, i.e. on how to use modeling and simulation to explore investment trade-offs and predict the impact of decisions in the space of Identity and Access Management. A related HPL Technical Report, on this topic, can be found &lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-57.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Registrations to the conference are still open.&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-2409497173103231903?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/k44YHp3BWec" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/k44YHp3BWec/ieee-policy-2009-symposium-ready-to-go.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/07/ieee-policy-2009-symposium-ready-to-go.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-141878549399325676</guid><pubDate>Mon, 29 Jun 2009 22:30:00 +0000</pubDate><atom:updated>2009-06-29T23:34:10.244+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Analytics</category><category domain="http://www.blogger.com/atom/ns#">identity management</category><category domain="http://www.blogger.com/atom/ns#">Identity Analytics</category><title>EEMA e-Identity: Presentation on the Future of the Identity in the Cloud</title><description>I recently attended the &lt;a href="http://www.revolutionevents.plus.com/eema/index.htm"&gt;EEMA e-Identity Conference&lt;/a&gt;, in London, 25-26 June 2009. There have been interesting presentation and good talks.&lt;br /&gt;&lt;br /&gt;I also gave a presentation on “&lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Documents/Papers/HPL-IdentityCloud%20-%20EEMA-%20marcocasassamont.ppt"&gt;The Future of Identity in the Cloud: Requirements, Risks and Opportunities&lt;/a&gt;”:&lt;br /&gt;&lt;br /&gt;“This presentation aims at: setting the context about Identity in the Cloud; discussing related identity management issues along with core requirements (coming from users and organisations); illustrating, from an HP Labs’ perspective, future possible models, approaches and IT infrastructures to handle Identity in the Cloud.&lt;br /&gt;The introduction of the presentation sets some background: it gives an overview of Cloud Computing and its implications, in terms of service provisioning, security, privacy and identity management. In particular it discusses the paradigm shift from a close &amp;amp; controlled approach (within enterprises) to potentially, on-the-fly composable and customisable services, in the Cloud.&lt;br /&gt;Use cases are introduced to illustrate “common” usage and management tasks involving Identity in the Cloud - from both user and organisational perspectives, including the implications of having to deal with Identity in composable and dynamic services. New emerging, related threats and risks are briefly discussed, such as the potential growth of bogus service providers, targeted attacks to the weakest points in the service provisioning chain and identity thefts.&lt;br /&gt;This will lead to a discussion of key requirements, determined by new interaction models and service-provisioning paradigms in the Cloud, including: control of identity flows and management of distributed user accounts; trust and reputation about service providers in the Cloud; identity assurance; transparency about security practices; privacy (including consent and revocation).&lt;br /&gt;I will then discuss current (categories of) identity management solutions and approaches that deal with aspects of Identity in the Cloud (such as identity federation, identity brokering, Identity 2.0, etc.), along with their pros and cons and failures to address some of the core requirements (such as assurance, trust and privacy control).&lt;br /&gt;The final part of this presentation challenges current assumptions and approaches and illustrates future directions, by presenting HP Labs’ medium and long–term vision about how the underlying Cloud infrastructure is going to evolve along with its implication in terms of Identity and Identity Management. This includes the paradigm shifts introduced by the usage of trusted virtualisation, remote attestation of platform capabilities (Trusted Computing Platforms) and identity-driven computational environment (coming from the cloud) that could run on local systems (e.g. at the user side); new emerging identity management models driven by identity-aware platforms and policy-driven delegation of credentials; the role that Security and Identity Analytics can play, by using modelling and simulation, to help organisations to evaluating and predicting the consequences of using services in the Cloud, based on assumptions made on the underlying identity management model and existing threats.”&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt; &lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-141878549399325676?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/by3z6QSsJM4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/by3z6QSsJM4/eema-e-identity-presentation-on-future.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/06/eema-e-identity-presentation-on-future.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8241500262281272192.post-625413718328410474</guid><pubDate>Mon, 29 Jun 2009 22:26:00 +0000</pubDate><atom:updated>2009-06-29T23:28:39.152+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Analytics</category><title>Another New HP Labs Technical Report: Using Security Metrics Coupled with Predictive Modelling and Simulation to Assess Security Processes</title><description>Another new HP Labs Technical Report has been recently released, called “&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-142.html"&gt;Using Security Metrics Coupled with Predictive Modelling and Simulation to Assess Security Processes&lt;/a&gt;” (authors: Yolanta Beres, Marco Casassa Mont, Jonathan Griffin, Simon Shiu):&lt;br /&gt;&lt;br /&gt;“It is hard for security practitioners and decision-makers to know what level of protection they are getting from their investments in security, especially when they have invested in a number of technologies and processes which interact and combine together. It is even harder to estimate how well these investments can be expected to protect their organizations in the future as security policies, regulations and the threat environment are constantly changing. In this paper we propose that for measuring the effectiveness of security processes in large organizations, a greater emphasis needs to be put on process-based metrics, in contrast to the more commonly used symptomatic lagging indicators. We show how these process-based metrics can be combined with executable, predictive models, based on a sound mathematical foundation, to both assess organizations' security processes under current conditions and predict how well they are likely to perform in potential future scenarios, which may include changes in working practices, policies or threat levels, or new investments in security. We present two case studies, in the areas of vulnerability threat management, and identity and access management, as significant examples to illustrate how this modeling and simulation-based approach can be used to provide a rich picture of how well existing security processes are protecting the organization and to answer "what- if" questions, such as exploring the effects of a change in security policy or an investment in new security technology. Our approach enables the organization to apply the metrics that are most relevant to its business, and provide a comprehensive view that shows the benefits and losses to the different stakeholders”&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)  ---&lt;br /&gt;&lt;br /&gt;--- NOTE:  my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;  ---&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8241500262281272192-625413718328410474?l=research-on-identitymanagement.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~4/kOZe1i3iqbE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MarcoCasassaMontsresearchOnIdentityManagementmirror/~3/kOZe1i3iqbE/another-new-hp-labs-technical-report.html</link><author>noreply@blogger.com (Marco Casassa Mont)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://research-on-identitymanagement.blogspot.com/2009/06/another-new-hp-labs-technical-report.html</feedburner:origLink></item></channel></rss>
