Reverse Engineering A Nit That Unmasks Tor Users,
2016
University of Nebraska at Kearney
Reverse Engineering A Nit That Unmasks Tor Users, Matthew Miller, Joshua Stroschein, Ashley Podhradsky
Annual ADFSL Conference on Digital Forensics, Security and Law
This paper is a case study of a forensic investigation of a Network Investigative Technique (NIT) used by the FBI to deanonymize users of a The Onion Router (Tor) Hidden Service. The forensic investigators were hired by the defense to determine how the NIT worked. The defendant was ac- cused of using a browser to access illegal information. The authors analyzed the source code, binary files and logs that were used by the NIT. The analysis was used to validate that the NIT collected only necessary and legally authorized information. This paper outlines the publicly available case details, how the …
Malware In The Mobile Device Android Environment,
2016
Coventry University, School of Computing, Electronics and Maths
Malware In The Mobile Device Android Environment, Diana Hintea, Robert Bird, Andrew Walker
Annual ADFSL Conference on Digital Forensics, Security and Law
exploit smartphone operating systems has exponentially expanded. Android has become the main target to exploit due to having the largest install base amongst the smartphone operating systems and owing to the open access nature in which application installations are permitted. Many Android users are unaware of the risks associated with a malware infection and to what level current malware scanners protect them. This paper tests how efficient the currently available malware scanners are. To achieve this, ten representative Android security products were selected and tested against a set of 5,560 known and categorized Android malware samples. The tests were carried …
Forensic Analysis Of Smartphone Applications For Privacy Leakage,
2016
Coventry University, School of Computing, Electronics and Maths
Forensic Analysis Of Smartphone Applications For Privacy Leakage, Diana Hintea, Chrysanthi Taramonli, Robert Bird, Rezhna Yusuf
Annual ADFSL Conference on Digital Forensics, Security and Law
Smartphone and tablets are personal devices that have diffused to near universal ubiquity in recent years. As Smartphone users become more privacy-aware and -conscious, research is needed to understand how “leakage” of private information (personally identifiable information – PII) occurs. This study explores how leakage studies in Droid devices should be adapted to Apple iOS devices. The OWASP Zed Attack Proxy (ZAP) is examined for 50 apps in various categories. This study confirms that: (1) most apps transmit unencrypted sensitive PII, (2) SSL is used by some recipient websites, but without corresponding app compliance with SSL, and (3) most apps …
Inferring Previously Uninstalled Applications From Residual Partial Artifacts,
2016
George Mason University, Fairfax, Virginia, United States
Inferring Previously Uninstalled Applications From Residual Partial Artifacts, Jim Jones, Tahir Khan, Kathryn Laskey, Alex Nelson, Mary Laamanen, Douglas White
Annual ADFSL Conference on Digital Forensics, Security and Law
In this paper, we present an approach and experimental results to suggest the past presence of an application after the application has been uninstalled and the system has remained in use. Current techniques rely on the recovery of intact artifacts and traces, e.g., whole files, Windows Registry entries, or log file entries, while our approach requires no intact artifact recovery and leverages trace evidence in the form of residual partial files. In the case of recently uninstalled applications or an instrumented infrastructure, artifacts and traces may be intact and complete. In most cases, however, digital artifacts and traces are al- …
One-Time Pad Encryption Steganography System,
2016
Embry-Riddle Aeronautical University, Daytona Beach, FL
One-Time Pad Encryption Steganography System, Michael J. Pelosi, Gary Kessler, Michael Scott S. Brown
Annual ADFSL Conference on Digital Forensics, Security and Law
In this paper we introduce and describe a novel approach to adaptive image steganography which is combined with One-Time Pad encryption, and demonstrate the software which implements this methodology. Testing using the state-of-the-art steganalysis software tool StegExpose concludes the image hiding is reliably secure and undetectable using reasonably-sized message payloads (≤25% message bits per image pixel; bpp). Payload image file format outputs from the software include PNG, BMP, JP2, JXR, J2K, TIFF, and WEBP. A variety of file output formats is empirically important as most steganalysis programs will only accept PNG, BMP, and possibly JPG, as the file inputs.
Keywords: …
Applying Grounded Theory Methods To Digital Forensics Research,
2016
Faculty of Technology, De Montfort University
Applying Grounded Theory Methods To Digital Forensics Research, Ahmed Almarzooqi, Andrew Jones, Richard Howley
Annual ADFSL Conference on Digital Forensics, Security and Law
Deciding on a suitable research methodology is challenging for researchers. In this paper, grounded theory is presented as a systematic and comprehensive qualitative methodology in the emergent field of digital forensics research. This paper applies grounded theory in a digital forensics research project undertaken to study how organisations build and manage digital forensics capabilities. This paper gives a step-by-step guideline to explain the procedures and techniques of using grounded theory in digital forensics research. The paper gives a detailed explanation of how the three grounded theory coding methods (open, axial, and selective coding) can be used in digital forensics research. …
Covert6: A Tool To Corroborate The Existence Of Ipv6 Covert Channels,
2016
Department of Computer and Information Technology, Purdue University
Covert6: A Tool To Corroborate The Existence Of Ipv6 Covert Channels, Raymond A. Hansen, Lourdes Gino, Dominic Savio
Annual ADFSL Conference on Digital Forensics, Security and Law
Covert channels are any communication channel that can be exploited to transfer information in a manner that violates the system’s security policy. Research in the field has shown that, like many communication channels, IPv4 and the TCP/IP protocol suite have been susceptible to covert channels, which could be exploited to leak data or be used for anonymous communications. With the introduction of IPv6, researchers are acutely aware that many vulnerabilities of IPv4 have been remediated in IPv6. However, a proof of concept covert channel system was demonstrated in 2006. A decade later, IPv6 and its related protocols have undergone major …
Acceleration Of Statistical Detection Of Zero-Day Malware In The Memory Dump Using Cuda-Enabled Gpu Hardware,
2016
Independent Researchers, Moscow, Russia
Acceleration Of Statistical Detection Of Zero-Day Malware In The Memory Dump Using Cuda-Enabled Gpu Hardware, Igor Korkin, Iwan Nesterow
Annual ADFSL Conference on Digital Forensics, Security and Law
This paper focuses on the anticipatory enhancement of methods of detecting stealth software. Cyber security detection tools are insufficiently powerful to reveal the most recent cyber-attacks which use malware. In this paper, we will present first an idea of the highest stealth malware, as this is the most complicated scenario for detection because it combines both existing anti-forensic techniques together with their potential improvements. Second, we will present new detection methods which are resilient to this hidden prototype. To help solve this detection challenge, we have analyzed Windows’ memory content using a new method of Shannon Entropy calculation; methods of …
Using Computer Behavior Profiles To Differentiate Between Users In A Digital Investigation,
2016
Indiana University Purdue University Indianapolis
Using Computer Behavior Profiles To Differentiate Between Users In A Digital Investigation, Shruti Gupta, Marcus Rogers
Annual ADFSL Conference on Digital Forensics, Security and Law
Most digital crimes involve finding evidence on the computer and then linking it to a suspect using login information, such as a username and a password. However, login information is often shared or compromised. In such a situation, there needs to be a way to identify the user without relying exclusively on login credentials. This paper introduces the concept that users may show behavioral traits which might provide more information about the user on the computer. This hypothesis was tested by conducting an experiment in which subjects were required to perform common tasks on a computer, over multiple sessions. The …
Current Challenges And Future Research Areas For Digital Forensic Investigation,
2016
School of Computer Science, University College Dublin, Ireland
Current Challenges And Future Research Areas For Digital Forensic Investigation, David Lillis, Brett A. Becker, Tadhg O’Sullivan, Mark Scanlon
Annual ADFSL Conference on Digital Forensics, Security and Law
Given the ever-increasing prevalence of technology in modern life, there is a corresponding increase in the likelihood of digital devices being pertinent to a criminal investigation or civil litigation. As a direct consequence, the number of investigations requiring digital forensic expertise is resulting in huge digital evidence backlogs being encountered by law enforcement agencies throughout the world. It can be anticipated that the number of cases requiring digital forensic analysis will greatly increase in the future. It is also likely that each case will require the analysis of an increasing number of devices including computers, smartphones, tablets, cloud-based services, Internet …
Forensic Analysis Of Ares Galaxy Peer-To-Peer Network,
2016
Politieacademie, The Netherlands
Forensic Analysis Of Ares Galaxy Peer-To-Peer Network, Frank Kolenbrander, Nhien-An Le-Khac, Tahar Kechadi
Annual ADFSL Conference on Digital Forensics, Security and Law
Child Abuse Material (CAM) is widely available on P2P networks. Over the last decade several tools were made for 24/7 monitoring of peer-to-peer (P2P) networks to discover suspects that use these networks for downloading and distribution of CAM. For some countries the amount of cases generated by these tools is so great that Law Enforcement (LE) just cannot handle them all. This is not only leading to backlogs and prioritizing of cases but also leading to discussions about the possibility of disrupting these networks and sending warning messages to potential CAM offenders. Recently, investigators are reporting that they are creating …
Keynote Speaker,
2016
Computer Security and Forensics Expert
Keynote Speaker, Chuck Easttom
Annual ADFSL Conference on Digital Forensics, Security and Law
Conference Keynote Speaker, Chuck Easttom
Applying Gis Technology In Airport Management,
2016
Bowling Green State University
Applying Gis Technology In Airport Management, Eleanor Clark
Honors Projects
This honors project involved applying two disciplines to aid in advancing the efficiency of airport management at the Toledo Express Airport. I utilized my geography and aviation knowledge and geographic information system (GIS) skills to create a GIS, a webmap, and a 3-in-1 map-based program that had the capabilities of executing Part 139 Self Inspections, asset management, and work orders. The GIS system and webmap were successfully created to aid in management, cohesiveness, and efficiency within the Toledo-Lucas County Port Authority, the managing entity of the Toledo Express Airport. For the 3-in-1 map-based program, I worked closely alongside a programmer …
Smart Gate Driver Design For Silicon (Si) Igbts And Silicon-Carbide (Sic) Mosfets,
2016
University of Arkansas, Fayetteville
Smart Gate Driver Design For Silicon (Si) Igbts And Silicon-Carbide (Sic) Mosfets, Abdulaziz Alghanem
Electrical Engineering Undergraduate Honors Theses
The design of an efficient and smart gate driver for a Si IGBT and SiC MOSFET is addressed in thesis. First, the main IGBT parameters are evaluated thoroughly in order to understand their effects in the design of the gate driver. All known consequences of previously designed gate drivers are studied in order to achieve an optimum gate driver. As a result of this assessment, the designer is able to determine whether adding or removing components from the gate driver circuit are beneficial or not. Then, exhaustive research is done to identify suitable integrated circuits to use for the power …
Flight Physician - May, 2016,
2016
Wright State University
Flight Physician - May, 2016, Civil Aviation Medical Association
Browse all Civil Aviation Medical Association Newsletters
A nineteen page newsletter of the Civil Aviation Medical Association. The newsletter provided news about civil aviation medicine and information related to the organization.
Predicting The Market Share Of A New Airport In Multi-Airport Cities: The Case Of Lagos,
2016
Embry-Riddle Aeronautical University
Predicting The Market Share Of A New Airport In Multi-Airport Cities: The Case Of Lagos, Samson Oladele Fatokun
Doctoral Dissertations and Master's Theses
The primary objective of the study was to develop an empirical model that combines the contingent valuation method (CVM) with the isochrone analysis to predict the market shares of new airports in multi-airport cities and to apply the model to the case of Lekki International Airport (LIA), the proposed second airport in Lagos, Nigeria. In addition to predicting the market share that LIA could attain, the study also identified and analyzed the catchment areas as well as the willingness to pay (WTP) of would-be LIA passengers. Furthermore, the research identified the determinants of airport choice in the Nigerian market. The …
Safte-Vat Functionality Effects On Flight Instructors' Situation Awareness And Instrument Student Pilots' Performance During Ftd Training,
2016
Embry-Riddle Aeronautical University
Safte-Vat Functionality Effects On Flight Instructors' Situation Awareness And Instrument Student Pilots' Performance During Ftd Training, Rafael E. Abreu Vega
Doctoral Dissertations and Master's Theses
SAFTE-VAT is a virtual air traffic control systems that adds the capability to integrate automated air traffic control functionality and generate semiautonomous and autonomous air traffic to the Frasca 172S level 6 plus FTD to improve behavioral fidelity and to facilitate flight instructors the capacity to focus more on instructing student pilots instead of role-playing ATC duties. While SAFTE-VAT may offer a more realistic ATC interaction experience onboard the FTD that may result in a positive transfer of training increase, the effects on flight instructors’ situation awareness and overall student pilot performance are uncertain. In this small study, flight instructors …
Enterprise Network Design And Implementation For Airports,
2016
Valparaiso University
Enterprise Network Design And Implementation For Airports, Ashraf H. Ali
Information Technology Master Theses
The aim of this project was airports network design and implementation and the introduction of a suitable network for most airports around the world. The following project focused on three main parts: security, quality, and safety. The project has been provided with different utilities to introduce a network with a high security level for the airport. These utilities are hardware firewalls, an IP access control list, Mac address port security, a domain server and s proxy server. All of these utilities have been configured to provide a secure environment for the entire network and to prevent hackers from entering sensitive …
Exploits Of A Helicopter Tv Journalist,
2016
Embry-Riddle Aeronautical University
Exploits Of A Helicopter Tv Journalist, Jerry Foster
ERAU Prescott Aviation History Program
Jerry Foster was the first TV helicopter pilot/reporter in the country; the first to go live over the scene of a breaking story. High speed police chases; devastating floods and daring rescues now splashed all over cable TV, started in the early 1970s in Phoenix. Hear this fascinating story from a remarkable aviator who won the Harmon Trophy for his flying exploits. What he pioneered would later be copied by medical and law enforcement agencies throughout the country leading to the saving of countless lives.
The United States Aviation Industry And The Professional Pilot Training Environment,
2016
Western Michigan University
The United States Aviation Industry And The Professional Pilot Training Environment, Andrew Marvin
Honors Theses
This study provides background and analysis of the legislation enacted following the crash of Colgan Air 3407, and the impact that the more stringent qualifications have had on aspiring professional pilots. Participants in the study include professional pilots and aspiring professional pilots, governmental law-making agencies such as the United States (U.S.) Congress and the Federal Aviation Administration (FAA), major and regional airlines, and collegiate flight training programs. The study drew from the National Transportation Safety Board investigation (NTSB) of Colgan Air 3407, federal regulations regarding pilot training and certification standards, and current airline hiring and training programs.
Findings of this …
