Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons™

Open Access. Powered by Scholars. Published by Universities.®

Information Security

Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 3451 - 3480 of 4675

Full-Text Articles in Computer Sciences

Rule-Based Conditional Trust With Openpgp., Andrew Jackson Nov 2013

Rule-Based Conditional Trust With Openpgp., Andrew Jackson

Theses

This thesis describes a new trust model for OpenPGP encryption. This trust model uses conditional rule-based trust to establish key validity and trust. This thesis describes "Trust Rules" that may be used to sort and categorize keys automatically without user interaction. "Trust Rules" are also capable of integrating key revocation status into its calculations so it too is automated. This thesis presents that conditional trust established through "Trust Rules" can enforce stricter security while reducing the burden of use and automating the process of key validity, trust, and revocation.


Meeting Minutes, Wku University Senate Nov 2013

Meeting Minutes, Wku University Senate

Faculty Senate

Meeting regarding meeting procedures, budget, faculty vacancies, accreditation, Information Technology policies, electronic mail, Colonnade plan, SITE evaluations, and faculty governance.


Defending Against Heap Overflow By Using Randomization In Nested Virtual Clusters, Chee Meng Tey, Debin Gao Nov 2013

Defending Against Heap Overflow By Using Randomization In Nested Virtual Clusters, Chee Meng Tey, Debin Gao

Research Collection School Of Computing and Information Systems

Heap based buffer overflows are a dangerous class of vulnerability. One countermeasure is randomizing the location of heap memory blocks. Existing techniques segregate the address space into clusters, each of which is used exclusively for one block size. This approach requires a large amount of address space reservation, and results in lower location randomization for larger blocks.


A Forensic Comparison: Windows 7 And Windows 8, Peter J. Wilson Nov 2013

A Forensic Comparison: Windows 7 And Windows 8, Peter J. Wilson

Theses

Whenever a new operating system or new version of an operating system is released, forensic investigators must re-examine the new operating system or new version. They do so to determine if there are significant differences that will impact and change the way they perform their investigations. With the release of Microsoft's latest operating system, Windows 8, and its update, Windows 8.1, understanding the similarities and differences between Windows 8 and previous operating systems such as Windows 7 is critical. This paper forensically examines Windows 7 and Windows 8 to determine those similarities and differences.


A Novel Defense Mechanism Against Web Crawler Intrusion, Alireza Aghamohammadi Nov 2013

A Novel Defense Mechanism Against Web Crawler Intrusion, Alireza Aghamohammadi

Master's Theses and Doctoral Dissertations

Web robots also known as crawlers or spiders are used by search engines, hackers and spammers to gather information about web pages. Timely detection and prevention of unwanted crawlers increases privacy and security of websites. In this research, a novel method to identify web crawlers is proposed to prevent unwanted crawler to access websites. The proposed method suggests a five-factor identification process to detect unwanted crawlers. This study provides the pretest and posttest results along with a systematic evaluation of web pages with the proposed identification technique versus web pages without the proposed identification process. An experiment was performed with …


Self-Blindable Credential: Towards Anonymous Entity Authentication Upon Resource-Constrained Devices, Yanjiang Yang, Xuhua Ding, Haibing Lu, Jian Weng, Jianying Zhou Nov 2013

Self-Blindable Credential: Towards Anonymous Entity Authentication Upon Resource-Constrained Devices, Yanjiang Yang, Xuhua Ding, Haibing Lu, Jian Weng, Jianying Zhou

Research Collection School Of Computing and Information Systems

We are witnessing the rapid expansion of smart devices in our daily life. The need for individual privacy protection calls for anonymous entity authentication techniques with affordable efficiency upon the resource-constrained smart devices. Towards this objective, in this paper we propose self-blindable credential, a lightweight anonymous entity authentication primitive.We provide a formulation of the primitive and present two concrete instantiations. The first scheme implements verifier-local revocation and the second scheme enhances the former with forward security. Our analytical performance results show that our schemes outperform relevant existing schemes.


Achieving Revocable Fine-Grained Cryptographic Access Control Over Cloud Data, Yanjiang Yang, Xuhua Ding, Haibing Lu, Zhiguo Wan, Jianying Zhou Nov 2013

Achieving Revocable Fine-Grained Cryptographic Access Control Over Cloud Data, Yanjiang Yang, Xuhua Ding, Haibing Lu, Zhiguo Wan, Jianying Zhou

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) is well suited for finegrained access control for data residing on a cloud server. However, existing approaches for user revocation are not satisfactory. In this work, we propose a new approach which works by splitting an authorized user’s decryption capability between the cloud and the user herself. User revocation is attained by simply nullifying the decryption ability at the cloud, requiring neither key update nor re-generation of cloud data. We propose a concrete scheme instantiating the approach, which features lightweight computation at the user side. This makes it possible for users to use resource-constrained devices such as …


Adaptable Ciphertext-Policy Attribute-Based Encryption, Junzuo Lai, Robert H. Deng, Yanjiang Yang, Jian Weng Nov 2013

Adaptable Ciphertext-Policy Attribute-Based Encryption, Junzuo Lai, Robert H. Deng, Yanjiang Yang, Jian Weng

Research Collection School Of Computing and Information Systems

In this paper, we introduce a new cryptographic primitive, called adaptable ciphertext-policy attribute-based encryption (CP-ABE). Adaptable CP-ABE extends the traditional CP-ABE by allowing a semi-trusted proxy to modify a ciphertext under one access policy into ciphertexts of the same plaintext under any other access policies; the proxy, however, learns nothing about the underlying plaintext. With such “adaptability” possessed by the proxy, adaptable CP-ABE has many real world applications, such as handling policy changes in CP-ABE encryption of cloud data and outsourcing of CP-ABE encryption. Specifically, we first specify a formal model of adaptable CP-ABE; then, based on the CP-ABE scheme …


Efficient Lossy Trapdoor Functions Based On Subgroup Membership Assumptions, Haiyang Xue, Bao Li, Xianhui Lu, Dingding Jia, Yamin Liu Nov 2013

Efficient Lossy Trapdoor Functions Based On Subgroup Membership Assumptions, Haiyang Xue, Bao Li, Xianhui Lu, Dingding Jia, Yamin Liu

Research Collection School Of Computing and Information Systems

We propose a generic construction of lossy trapdoor function from the subgroup membership assumption. We present three concrete constructions based on the k-DCR assumption over Z∗ N2 , the extended psubgroup assumption over Z∗ N2 , and the decisional RSA subgroup membership assumption over Z∗ N . Our constructions are more efficient than the previous construction from the DCR assumption over Z∗ Ns (s ≥ 3).


A Collusion-Resistant Conditional Access System For Flexible-Pay-Per-Channel Pay-Tv Broadcasting, Zhiguo Wan, June Liu, Rui Zhang, Robert H. Deng Oct 2013

A Collusion-Resistant Conditional Access System For Flexible-Pay-Per-Channel Pay-Tv Broadcasting, Zhiguo Wan, June Liu, Rui Zhang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Pay-TV Broadcasting system, an extensively de- ployed application, charges its subscribers when receiving the broadcasted video. A conditional access system (CAS) ensures security for the Pay-TV broadcasting system, which is designed to control TV channel/program access to only authorized subscribers. There are mainly three CAS models: pay-per-channel (PPC), pay-per-view (PPV), and flexible-pay-per-channel (F- PPC). F-PPC is a novel model which combines the properties and advantages of both PPC and PPV. Several key management schemes with four-level hierarchical key structure have been proposed for this model. In this paper, we point out a severe security weakness of these schemes against collusion …


K-Time Proxy Signature: Formal Definition And Efficient Construction, Weiwei Liu, Guomin Yang, Yi Mu, Jiannan Wei Oct 2013

K-Time Proxy Signature: Formal Definition And Efficient Construction, Weiwei Liu, Guomin Yang, Yi Mu, Jiannan Wei

Research Collection School Of Computing and Information Systems

Proxy signature, which allows an original signer to delegate his/her signing right to another party (or proxy signer), is very useful in many applications. Conventional proxy signature only allows the original signer to specify in the warrant the validity time period of the delegation but not the number of proxy signatures the proxy signer can generate. To address this problem, in this paper, we provide a formal treatment for k-time proxy signature. Such a scheme allows a designated proxy signer to produce only a fixed number of proxy signatures on behalf of the original signer. We provide the formal definitions …


Masthead Sep 2013

Masthead

Journal of Digital Forensics, Security and Law

No abstract provided.


Front Matter Sep 2013

Front Matter

Journal of Digital Forensics, Security and Law

No abstract provided.


Back Matter Sep 2013

Back Matter

Journal of Digital Forensics, Security and Law

No abstract provided.


Money Laundering Detection Framework To Link The Disparate And Evolving Schemes, Murad Mehmet, Duminda Wijesekera, Miguel F. Buchholtz Sep 2013

Money Laundering Detection Framework To Link The Disparate And Evolving Schemes, Murad Mehmet, Duminda Wijesekera, Miguel F. Buchholtz

Journal of Digital Forensics, Security and Law

Money launderers hide traces of their transactions with the involvement of entities that participate in sophisticated schemes. Money laundering detection requires unraveling concealed connections among multiple but seemingly unrelated human money laundering networks, ties among actors of those schemes, and amounts of funds transferred among those entities. The link among small networks, either financial or social, is the primary factor that facilitates money laundering. Hence, the analysis of relations among money laundering networks is required to present the full structure of complex schemes. We propose a framework that uses sequence matching, case-based analysis, social network analysis, and complex event processing …


A Robust Rgbd Slam System For 3d Environment With Planar Surfaces, Po-Chang Su, Ju Shen, Sen-Ching S. Cheung Sep 2013

A Robust Rgbd Slam System For 3d Environment With Planar Surfaces, Po-Chang Su, Ju Shen, Sen-Ching S. Cheung

Computer Science Faculty Publications

With the increasing popularity of RGB-depth (RGB-D) sensors such as the Microsoft Kinect, there have been much research on capturing and reconstructing 3D environments using a movable RGB-D sensor. The key process behind these kinds of simultaneous location and mapping (SLAM) systems is the iterative closest point or ICP algorithm, which is an iterative algorithm that can estimate the rigid movement of the camera based on the captured 3D point clouds. While ICP is a well-studied algorithm, it is problematic when it is used in scanning large planar regions such as wall surfaces in a room. The lack of depth …


A Highly Efficient Rfid Distance Bounding Protocol Without Real-Time Prf Evaluation, Yunhui Zhuang, Anjia Yang, Duncan S. Wong, Guomin Yang, Qi Xie Sep 2013

A Highly Efficient Rfid Distance Bounding Protocol Without Real-Time Prf Evaluation, Yunhui Zhuang, Anjia Yang, Duncan S. Wong, Guomin Yang, Qi Xie

Research Collection School Of Computing and Information Systems

There is a common situation among current distance bounding protocols in the literature: they set the fast bit exchange phase after a slow phase in which the nonces for both the reader and a tag are exchanged. The output computed in the slow phase is acting as the responses in the subsequent fast phase. Due to the calculation constrained RFID environment of being lightweight and efficient, it is the important objective of building the protocol which can have fewer number of message flows and less number of cryptographic operations in real time performed by the tag. In this paper, we …


Driverguard: Virtualization Based Fine-Grained Protection On I/O Flows, Yueqiang Cheng, Xuhua Ding, Robert H. Deng Sep 2013

Driverguard: Virtualization Based Fine-Grained Protection On I/O Flows, Yueqiang Cheng, Xuhua Ding, Robert H. Deng

Research Collection School Of Computing and Information Systems

Most commodity peripheral devices and their drivers are geared to achieve high performance with security functions being opted out. The absence of strong security measures invites attacks on the I/O data and consequently posts threats to those services feeding on them, such as fingerprint-based biometric authentication. In this article, we present a generic solution called DriverGuard, which dynamically protects the secrecy of I/O flows such that the I/O data are not exposed to the malicious kernel. Our design leverages a composite of cryptographic and virtualization techniques to achieve fine-grained protection without using any extra devices and modifications on user applications. …


A Forward-Secure Certificate-Based Signature Scheme, Jiguo Li, Huiyun Teng, Xinyu Huang, Yichen Zhang, Jianying Zhou Aug 2013

A Forward-Secure Certificate-Based Signature Scheme, Jiguo Li, Huiyun Teng, Xinyu Huang, Yichen Zhang, Jianying Zhou

Faculty Publications

Cryptographic computations are often carried out on insecure devices for which the threat of key exposure raises a serious concern. In an effort to address the key exposure problem, the notion of forward security was first presented by Günther in 1990. In a forward-secure scheme, secret keys are updated at regular periods of time; exposure of the secret key corresponding to a given time period does not enable an adversary to ‘break’ the scheme for any prior time period. In this paper, we first introduce forward security into certificate-based cryptography and define the security model of forward-secure certificate-based signatures (CBSs). …


Is Security Sustainable?, Jeremy W. Crampton Aug 2013

Is Security Sustainable?, Jeremy W. Crampton

Geography Faculty Publications

No abstract provided.


Segmentation And Model Generation For Large-Scale Cyber Attacks, Steven E. Strapp Aug 2013

Segmentation And Model Generation For Large-Scale Cyber Attacks, Steven E. Strapp

Theses

Raw Cyber attack traffic can present more questions than answers to security analysts. Especially with large-scale observables it is difficult to identify which packets are relevant and what attack behaviors are present. Many existing works in Host or Flow Clustering attempt to group similar behaviors to expedite analysis; these works often phrase the problem directly as offline unsupervised machine learning. This work proposes online processing to simultaneously model coordinating actors and segment traffic that is relevant to a target of interest, all while it is being received. The goal is not just to aggregate similar attack behaviors, but to provide …


Innovation-Ict-Cybersecurity: The Triad Relationship And Its Impact On Growth Competitiveness, Manal M. Yunis Aug 2013

Innovation-Ict-Cybersecurity: The Triad Relationship And Its Impact On Growth Competitiveness, Manal M. Yunis

Theses and Dissertations - UTB/UTPA

This study examines the global growth competitiveness of countries using the dynamics of growth, ICT, and innovation. It also introduces a new dynamic, cybersecurity, and argues that within a growth competitiveness framework, ICT, innovation, and cybersecurity mechanisms allow some countries to achieve higher ranks on the competitiveness ladder than others. Based on a theoretical framework that encompasses the economic growth model, the complementarity theory, and the international law theory, a model that integrates ICT, innovation, and cybersecurity, depicts the relationships amongst them and with growth competitiveness, and incorporates complementary factors with possible moderating effect is presented. The model proposed relationships …


Attribute-Based Encryption With Verifiable Outsourced Decryption, Junzuo Lai, Robert H. Deng, Chaowen Guan, Jian Weng Aug 2013

Attribute-Based Encryption With Verifiable Outsourced Decryption, Junzuo Lai, Robert H. Deng, Chaowen Guan, Jian Weng

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) is a public-keybased one-to-many encryption that allows users to encrypt and decrypt data based on user attributes. A promising application of ABE is flexible access control of encrypted data stored in the cloud, using access polices and ascribed attributes associated with private keys and ciphertexts.One of themain efficiency drawbacks of the existing ABE schemes is that decryption involves expensive pairing operations and the number of such operations grows with the complexity of the access policy. Recently, Green et al. proposed an ABE system with outsourced decryption that largely eliminates the decryption overhead for users. In such a …


Cost-Sensitive Online Active Learning With Application To Malicious Url Detection, Peilin Zhao, Steven C. H. Hoi Aug 2013

Cost-Sensitive Online Active Learning With Application To Malicious Url Detection, Peilin Zhao, Steven C. H. Hoi

Research Collection School Of Computing and Information Systems

Malicious Uniform Resource Locator (URL) detection is an important problem in web search and mining, which plays a critical role in internet security. In literature, many existing studies have attempted to formulate the problem as a regular supervised binary classification task, which typically aims to optimize the prediction accuracy. However, in a real-world malicious URL detection task, the ratio between the number of malicious URLs and legitimate URLs is highly imbalanced, making it very inappropriate for simply optimizing the prediction accuracy. Besides, another key limitation of the existing work is to assume a large amount of training data is available, …


The Case For Mobile Forensics Of Private Data Leaks: Towards Large-Scale User-Oriented Privacy Protection, Joseph Joo Keng Chan, Kiat Wee Tan, Lingxiao Jiang, Rajesh Krishna Balan Jul 2013

The Case For Mobile Forensics Of Private Data Leaks: Towards Large-Scale User-Oriented Privacy Protection, Joseph Joo Keng Chan, Kiat Wee Tan, Lingxiao Jiang, Rajesh Krishna Balan

Research Collection School Of Computing and Information Systems

Privacy protection against mobile applications on mobile devices is becoming a serious concern as user sensitive data may be leaked without proper justification. Most current leak detection tools only report leaked private data, but provide inadequate information about the causes of the leaks for end users to take preventive measures. Hence, users often cannot reconcile the way they have used an application to a reported leak — i.e., they are unable to comprehend the (il)legitimacy of the leak or make a decision on whether to allow the leak. This paper aims to demonstrate the feasibility and benefits of identifying the …


Technique For Authenticating H.264/Svc Streams In Surveillance Applications, Wei Zhuo, Robert H. Deng, Jialie Shen, Yongdong Wu, Xuhua Ding, Swee Won Lo Jul 2013

Technique For Authenticating H.264/Svc Streams In Surveillance Applications, Wei Zhuo, Robert H. Deng, Jialie Shen, Yongdong Wu, Xuhua Ding, Swee Won Lo

Research Collection School Of Computing and Information Systems

Surveillance codestreams coded by H.264/SVC (scalable video coding), which consists of one base layer and one or more enhancement layers, supply flexible and various quality, resolution, and temporal (sub)codestreams such that clients with different network bandwidth and terminal devices can seamlessly access them. In this paper, we present a robust authentication scheme for them in order to insure the integrity of SVC surveillance codestreams, named AUSSC (Authenticating SVC Surveillance Codestreams). AUSSC exploits cryptographic-based authentication for base layer and content-based authentication for enhancement layers. For content-based authentication, AUSSC extracts full features from the first frame of each GOP (group of picture) …


Back Matter Jun 2013

Back Matter

Journal of Digital Forensics, Security and Law

No abstract provided.


Masthead Jun 2013

Masthead

Journal of Digital Forensics, Security and Law

No abstract provided.


Front Matter Jun 2013

Front Matter

Journal of Digital Forensics, Security and Law

No abstract provided.


Keystroke Timing Analysis Of On-The-Fly Web Apps, Chee Meng Tey, Payas Gupta, Debin Gao, Yan Zhang Jun 2013

Keystroke Timing Analysis Of On-The-Fly Web Apps, Chee Meng Tey, Payas Gupta, Debin Gao, Yan Zhang

Research Collection School Of Computing and Information Systems

The Google Suggestions service used in Google Search is one example of an interactivity rich Javascript application. In this paper, we analyse the timing side channel of Google Suggestions by reverse engineering the communication model from obfuscated Javascript code. We consider an attacker who attempts to infer the typing pattern of a victim. From our experiments involving 11 participants, we found that for each keypair with at least 20 samples, the mean of the inter-keystroke timing can be determined with an error of less than 20%.