On the Prevention of Fraud and Privacy Exposure in Process Information Flow

Published Online:https://doi.org/10.1287/ijoc.1110.0461

References

  • Adam N. R., Alturi V., Huang W.-K. Modeling and analysis of workflows using Petri nets. J. Intelligent Inform. Systems (1998) 10(2):131–158CrossrefGoogle Scholar
  • Association of Certified Fraud Examiners Report to the nations on occupational fraud and abuse. (2010) . Report, ACFE, Austin, TX. http://butest.acfe.com/rttn/rttn-2010.pdfGoogle Scholar
  • Atluri V., Chun S. A., Mazzoleni P. Chinese wall security for decentralized workflow management systems. J. Comput. Security (2004) 12(6):799–840CrossrefGoogle Scholar
  • Berman O., Larson R. C., Pinker E. Scheduling workforce and workflow in a high volume factory. Management Sci. (1997) 43(2):158–172LinkGoogle Scholar
  • Bertino E., Bonatti P. A., Ferrari E. TRBAC: A temporal role-based access control model. ACM Trans. Inform. System. Security (2001) 4(3):191–233CrossrefGoogle Scholar
  • Bertino E., Ferrari E., Atluri V. The specification and enforcement of authorization constraints in workflow management systems. ACM Trans. Inform. System Security (1999) 2(1):65–104CrossrefGoogle Scholar
  • Bhat U. N.An Introduction to Queueing Theory: Modeling and Analysis in Applications (2008) (Birhäuser Boston, Boston) CrossrefGoogle Scholar
  • Biennier F., Favrel J. Collaborative business and data privacy: Toward a cyber-control? Comput. Indust. (2005) 56(4):361–370CrossrefGoogle Scholar
  • Bolch S., Greiner G., de Meer H., Trivedi K. S.Queueing Networks and Markov Chains: Modeling and Performance Evaluation with Computer Science Applications (1998) (John Wiley & Sons, New York) CrossrefGoogle Scholar
  • Botha R. A., Eloff J. H. P. Separation of duties for access control enforcement in workflow environments. IBM Systems J. (2001) 40(3):666–682CrossrefGoogle Scholar
  • Brandic I., Pllana S., Benkner S. Specification, planning, and execution of QoS-aware grid workflows within the Amadeus environment. Concurrency Comput.: Practice Experience (2008) 20(4):331–345CrossrefGoogle Scholar
  • Bussler C. J. Policy resolution in workflow management systems. Digital Tech. J. (1994) 6(4):26–49Google Scholar
  • Casati F., Castano S., Fugini M. Managing workflow authorization constraints through active database technology. Inform. Systems Frontiers (2001) 3(3):319–338CrossrefGoogle Scholar
  • Chen H., Yao D. D.Fundamentals of Queueing Networks: Performance, Asymptotics, and Optimization (2001) (Springer, New York) CrossrefGoogle Scholar
  • Chen W. N., Zhang J. An ant colony optimization approach to a grid workflow scheduling problem with various QoS requirements. IEEE Trans. Systems, Man, Cybernetics (2009) 39(1):29–43CrossrefGoogle Scholar
  • Computer Security Institute The 14th annual CSI computer crime and security survey. (2009) . Report, CSI, New York. http://www.pathmaker.biz/whitepapers/CSISurvey2009.pdfGoogle Scholar
  • Coombes A. IRS employee sentenced for snooping. (2008) . MarketWatch (August 20), http://www.marketwatch.com/story/irs-worker-snooped-on-tax-records-of-almost-200-celebritiesGoogle Scholar
  • Culnan M. J., Armstrong P. K. Information privacy concerns, procedural fairness and impersonal trust: An empirical investigation. Organ. Sci. (1999) 10(1):104–115LinkGoogle Scholar
  • Dewan R., Seidmann A., Walter Z. Workflow optimization through task redesign in business information processes. Proc. 31st Annual Hawaii Internat. Conf. System Sci., Vol. 1 (1998) (IEEE Computer Society, Washington, DC) 240–252CrossrefGoogle Scholar
  • Domingos D., Rito-Silva A., Veiga P., Snekkenes E., Gollmann D. Authorization and access control in adaptive workflows. Comput. Security—ESORICS 2003, Vol. 2808 (2003) (Springer, Berlin) 23–38Lecture Notes Computer ScienceCrossrefGoogle Scholar
  • Eder J., Ninaus M., Pichler H., ter Hofstede A., Weske M. Personal schedules for workflow systems. Proc. Internat. Conf. Bus. Process Management, Vol. 2678 (2003) (Springer, Berlin) 216–231Lecture Notes Computer ScienceCrossrefGoogle Scholar
  • Fischer L.BPM and Workflow Handbook (2007) (Future Strategies Inc., Lighthouse Point, FL) Google Scholar
  • Garey M. R., Johnson D. S.Computers and Intractability: A Guide to the Theory of NP-Completeness (2002) (W. H. Freeman and Company, New York) Google Scholar
  • Garfinkel R., Gopal R. D., Goes P. Privacy protection of binary confidential data against deterministic, stochastic, and insider threat. Management Sci. (2002) 48(6):749–764LinkGoogle Scholar
  • Garfinkel R., Gopal R. D., Nunez M. A., Rice D. O. Secure electronic markets for private information. IEEE Trans. Systems, Man Cybernetics (2006) 36(3):461–471CrossrefGoogle Scholar
  • Gong L., Qian X. Computational issues in secure interoperation. IEEE Trans. Software Engrg. (1996) 22(1):43–52CrossrefGoogle Scholar
  • Gross D., Shortle J. F., Thompson J. M., Harris C. M.Fundamentals of Queueing Theory (2008) 4th ed.(John Wiley & Sons, New York) CrossrefGoogle Scholar
  • GVU Center GVU's seventh WWW user survey. (1997) . Georgia Institute of Technology, Atlanta. http://www.cc.gatech.edu/gvu/user_surveys/survey-1997-04Google Scholar
  • Hong J. I., Ng J. D., Lederer S., Landay J. A. Privacy risk models for designing privacy-sensitive ubiquitous computing systems. DIS '04: Proc. 5th Conf. Designing Interactive Systems (2004) (ACM, New York) 91–100CrossrefGoogle Scholar
  • Hung P. C. K., Karlapalem K. A secure workflow model. Proc. Australasian Inform. Security Workshop, Vol. 21 (2003) (Australian Computer Society, Darlinghurst, Australia) 33–41Google Scholar
  • Kang M. H., Park J. S., Froscher J. N. Access control mechanisms for inter-organizational workflow. Proc. 6th ACM Sympos. Access Control Models Tech. (2001) (SACMAT, New York, USA) 66–74CrossrefGoogle Scholar
  • Menon S., Sarkar S. Minimizing information loss and preserving privacy. Management Sci. (2007) 53(1):101–116LinkGoogle Scholar
  • Mohajer S. T. Former UCLA hospital worker admits selling records. (2008) . Associated Press. (December 1), http://www.breitbart.com/article.php?id=D94Q8LJ80&show_article=1Google Scholar
  • Olivero N., Lunt P. Privacy versus willingness to disclose in e-commerce exchanges: The effect of risk awareness on the relative role of trust and control. J. Econom. Psych. (2004) 25(2):243–262CrossrefGoogle Scholar
  • Povey D. Optimistic security: A new access control paradigm. Proc. 1999 Workshop on New Security Paradigms (2000) (ACM, New York) 40–45CrossrefGoogle Scholar
  • Serfozo R.Introduction to Stochastic Networks (1999) (Springer, New York) CrossrefGoogle Scholar
  • Sharp A., McDermott P.Workflow Modeling: Tools for Process Improvement and Applications Development (2009) 2nd ed.(Artech House, Norwood, MA) Google Scholar
  • Shen M., Tzeng G.-H., Liu D.-R. Multi-criteria task assignment in workflow management systems. 36th Annual Hawaii Internat. Conf. System Sci. (2003) Big Island, HI:6–9Google Scholar
  • Thomas R. K. Team-based access control (TMAC): A primitive for applying role-based access controls in collaborative environments. Proc. 2nd ACM Workshop Role-Based Access Control (1997) (ACM, New York) 13–19CrossrefGoogle Scholar
  • Tolone W., Ahn G.-J., Pai T., Hong S.-P. Access control in collaborative systems. ACM Comput. Surveys (2005) 37(1):29–41CrossrefGoogle Scholar
  • van der Aalst W., van Hee K.Workflow Management: Models, Methods, and Systems (2004) (MIT Press, Cambridge, MA) Google Scholar
  • Verjee Z., Yellin J., Frieden T., Barrett T. Obama urges inquiry into passport snooping. (2008) . CNN (March 21), http://www.cnn.com/2008/POLITICS/03/21/obama.passport/index.htmlGoogle Scholar
  • Wainer J., Kumar A., Barthelmess P. DW-RBAC: A formal security model of delegation and revocation in workflow systems. Inform. Syststems (2007) 3(3):365–384CrossrefGoogle Scholar
  • Wu S., Sheth A., Miller J., Luo Z. Authorization and access control of application data in workflow systems. J. Intelliegent Inform. Systems. (2002) 18(1):71–94CrossrefGoogle Scholar
  • Yu J., Buyya R. A taxonomy of workflow management systems for grid computing. J. Grid Comput. (2005) 3(3–4):171–200CrossrefGoogle Scholar
  • Yu J., Buyya R. Scheduling scientific workflow applications with deadline and budget constraints using genetic algorithms. Sci. Programming J. (2006) 14(3–4):217–230CrossrefGoogle Scholar
INFORMS site uses cookies to store information on your computer. Some are essential to make our site work; Others help us improve the user experience. By using this site, you consent to the placement of these cookies. Please read our Privacy Statement to learn more.