Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons™

Open Access. Powered by Scholars. Published by Universities.®

Edith Cowan University

Discipline
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 1081 - 1110 of 1285

Full-Text Articles in Computer Sciences

Mobile Handset Forensic Evidence: A Challenge For Law Enforcement, Marwan Al-Zarouni Apr 2006

Mobile Handset Forensic Evidence: A Challenge For Law Enforcement, Marwan Al-Zarouni

Australian Digital Forensics Conference

Mobile phone proliferation in our societies is on the increase. Advances in semiconductor technologies related to mobile phones and the increase of computing power of mobile phones led to an increase of functionality of mobile phones while keeping the size of such devices small enough to fit in a pocket. This led mobile phones to become portable data carriers. This in turn increased the potential for data stored on mobile phone handsets to be used as evidence in civil or criminal cases. This paper examines the nature of some of the newer pieces of information that can become potential evidence …


A Methodology For The Examination Of The Effectiveness Of Secure Erasure Tools Running On Windows Xp - Research In Progress, Anthony Hadfield, Michael Ahern, Leo Sell, Andrew Woodward Apr 2006

A Methodology For The Examination Of The Effectiveness Of Secure Erasure Tools Running On Windows Xp - Research In Progress, Anthony Hadfield, Michael Ahern, Leo Sell, Andrew Woodward

Australian Digital Forensics Conference

Currently, there appears to be a lack of academic research in the area of testing the efficacy of secure erasure applications and utilities in regard to the activities of an average user in a home or small business context. This research in progress aims to develop a testing methodology that will provide a forensically sound base for which to analyse these tools. It involves the installation of various Internet related applications (for example browsers, instant messaging software and download clients), and the use of these applications for typical Internet activities (e.g. internet banking, instant messaging, web browsing and other activities …


Honeypots: How Do You Know When You Are Inside One?, Simon Innes, Craig Valli Apr 2006

Honeypots: How Do You Know When You Are Inside One?, Simon Innes, Craig Valli

Australian Digital Forensics Conference

This paper will discuss honeypots and their use and effectiveness as a security measure in an IT environment. It will specifically discuss various methods of honeypot implementations. Furthermore, this paper will look into the weaknesses within a honeypot system. This will include attacks against honeypots and methods a hacker may use to detect the presence of a honeypot or the fact that he/she is actually inside one. Finally this paper will discuss methods of further securing honeypots and ways the community is dealing with security flaws as they are identified


Enhancing The Forensic Icq Logfile Extraction Tool, Kim Morfitt Apr 2006

Enhancing The Forensic Icq Logfile Extraction Tool, Kim Morfitt

Australian Digital Forensics Conference

Programmers of forensic tools need to ensure that their tools are of suitable use, robustness and correctness for their output to be used as evidence. One tool for logfile extraction that is currently under development and is intended for forensic use extracts information from ICQ clients has several limitations that need to be overcome before it is of significant value to forensic investigators. This paper covers the process and research involved in further developing the tool, and overcoming a subset of the limitations of the tool. It also documents what was learnt in the process about the logfiles and the …


Structural Analysis Of The Log Files Of The Icq Client Version 2003b, Kim Morfitt Apr 2006

Structural Analysis Of The Log Files Of The Icq Client Version 2003b, Kim Morfitt

Australian Digital Forensics Conference

Instant messenger programs can generate log files of user interactions which are of interest to forensic investigators. Some of the log files are in formats that are difficult for investigators to extract useful and accurate information from. The official ICQ client is one such program. Users log files are stored in a binary format that is difficult to understand and often changes with different client versions. Previous research has been performed that documents the format of the log files, however this research only covers earlier versions of the client. This paper explores the 2003b version of the ICQ client. It …


Taxonomy Of Computer Forensics Methodologies And Procedures For Digital Evidence Seizure, Krishnun Sansurooah Apr 2006

Taxonomy Of Computer Forensics Methodologies And Procedures For Digital Evidence Seizure, Krishnun Sansurooah

Australian Digital Forensics Conference

The increase risk and incidence of computer misuse has raised awareness in public and private sectors of the need to develop defensive and offensives responses. Such increase in incidence of criminal, illegal and inappropriate computer behavior has resulted in organizations forming specialist teams to investigate these behaviors. There is now widespread recognition of the importance of specialised forensic computing investigation teams that are able to operate. Forensics analysis is the process of accurately documenting and interpreting information more precisely digital evidence for the presentation to an authoritative group and in most cases that group would be a court of law. …


Forensic Analysis Of The Contents Of Nokia Mobile Phones, B. Williamson, P. Apeldoorn, B. Cheam, M. Mcdonald Apr 2006

Forensic Analysis Of The Contents Of Nokia Mobile Phones, B. Williamson, P. Apeldoorn, B. Cheam, M. Mcdonald

Australian Digital Forensics Conference

Acquiring information from a mobile phone is now an important issue in many criminal investigations. Mobile phones can contain large amounts of information which can be of use in an investigation. These include typical mobile device data including SMS, phone records and calendar and diary entries. As the difference between a PDA and a mobile phone is now blurred, the data that can reside on a mobile phone is somewhat endless. This report focuses on the performance of different mobile phone forensic software devices, and reports the findings. All aspects of the different software pieces will be reported, as well …


Validation Of Forensic Computing Software Utilizing Black Box Testing Techniques, Tom Wilsdon, Jill Slay Apr 2006

Validation Of Forensic Computing Software Utilizing Black Box Testing Techniques, Tom Wilsdon, Jill Slay

Australian Digital Forensics Conference

The process of validating the correct operation of software is difficult for a variety of reasons. The need to validate software utilised as forensic computing tools suffers the same fate and is hampered to a greater extent with the source code of said tools usually not being accessible. Therefore a testing regime must be developed that offers a high degree of correctness and high probability of finding software faults with limited ability to view source code. Software testing is a complex component of software engineering in its own right. This complexity is encountered with an infinite number of environments posed …


Mediated Identification, D T. Shaw Apr 2006

Mediated Identification, D T. Shaw

Australian Information Warfare and Security Conference

Identity and identification are linked by variable meanings and applications and are essential in many remote transactions. Identification relying on mediation or third party intervention may be modified or withdrawn at will. Creating or reestablishing identity may require time and resources including artefacts such as the identity card usually sourced from a third party. The characteristics of the identification process and artefacts are discussed and the requirements of usermediated identification artefacts are explored. The implicit link between user identity and artefact identity may be broken under certain circumstances.


Electronic Records Management Criteria And Information Security, A Shaw, David T. Shaw Apr 2006

Electronic Records Management Criteria And Information Security, A Shaw, David T. Shaw

Australian Information Warfare and Security Conference

Records management practices are mandatory in many business and government operations. Records management is a mature discipline with extensive body of knowledge, professional associations and clearly defined Australian and international standards. Records systems encompass the hardware, software and people necessary for operation and include records generated by and for the system. The Australian legal system has clearly defined standards for admissible evidence in the Evidence Act. Relevant records may require substantial preparation for submission and yet be inadmissible in legal proceedings. The records and system may be challenged in both theoretical and practical senses and appropriate practices and associated records …


Deception On The Network: Thinking Differently About Covert Channels, Maarten Van Horenbeeck Apr 2006

Deception On The Network: Thinking Differently About Covert Channels, Maarten Van Horenbeeck

Australian Information Warfare and Security Conference

The concept of covert channels has been visited frequently by academia in a quest to analyse their occurrence and prevention in trusted systems. This has lead to a wide variety of approaches being developed to prevent and identify such channels and implement applicable countermeasures. However, little of this research has actually trickled down into the field of operational security management and risk analysis. Quite recently a number of covert channels and enabling tools have appeared that did have a significant impact on the operational security of organizations. This paper identifies a number of those channels and shows the relative ease …


An Information Operation Model And Classification Scheme, D T. Shaw, S Cikara Apr 2006

An Information Operation Model And Classification Scheme, D T. Shaw, S Cikara

Australian Information Warfare and Security Conference

Information systems are used in overt and covert conflict and information operations target an opponent’s ability to manage information in support of operations for political, commercial and military advantage. System level attacks are complicated by logistic problems that require resources, command and control. Node level attacks are practical but of limited value. Collocated equipment comprises a temporary node that may be feasibly attacked. Estimation of IW operation merits may founder on the difficulty of predicting the net benefit for the costs. Starting from with Shannon’s model, a simple costbenefit model is discussed. Existing models are extended by an IW attack …


Enterprise Computer Forensics: A Defensive And Offensive Strategy To Fight Computer Crime, Fahmid Imtiaz Apr 2006

Enterprise Computer Forensics: A Defensive And Offensive Strategy To Fight Computer Crime, Fahmid Imtiaz

Australian Digital Forensics Conference

As days pass and the cyber space grows, so does the number of computer crimes. The need for enterprise computer forensic capability is going to become a vital decision for the CEO’s of large or even medium sized corporations for information security and integrity over the next couple of years. Now days, most of the companies don’t have in house computer/digital forensic team to handle a specific incident or a corporate misconduct, but having digital forensic capability is very important and forensic auditing is very crucial even for small to medium sized organizations. Most of the corporations and organizations are …


A Fuzzy Approach For Detecting Anomalous Behaviour In E-Mail Traffic, Mark Jynhuey Lim, Michael Negnevitsky, Jacky Hartnett Apr 2006

A Fuzzy Approach For Detecting Anomalous Behaviour In E-Mail Traffic, Mark Jynhuey Lim, Michael Negnevitsky, Jacky Hartnett

Australian Digital Forensics Conference

This paper investigates the use of fuzzy inference for detection of abnormal changes in email traffic communication behaviour. Several communication behaviour measures and metrics are defined for extracting information on the traffic communication behaviour of email users. The information from these behaviour measures is then combined using a hierarchy of fuzzy inference systems, to provide an abnormality rating for overall changes in communication behaviour of suspect email accounts. The use of fuzzy inference is then demonstrated with a case study investigating the email traffic behaviour of a person’s email accounts from the Enron email corpus.


Leading Hackers Down The Garden Path, Suen Yek Apr 2006

Leading Hackers Down The Garden Path, Suen Yek

Australian Digital Forensics Conference

Can a hacker be controlled by predetermined deception? Limiting the decision making capabilities of hackers is one technique of network countermeasure that a honeynet enables. By furnishing a honeynet with a realistic range of services but restricted vulnerabilities, a hacker may be forced to direct their attacks to the only available exploits. This research discusses the deployment of a honeynet configured with a deceptive TELNET and TFTP exploit. Four hackers were invited to attack the honeynet and the analysis of their compromise identified if they engaged in a guided pathway to the intended deception. Hand trace analysis was performed on …


Liars - Laptop Inspector And Recovery System, Andrew Woodward Apr 2006

Liars - Laptop Inspector And Recovery System, Andrew Woodward

Australian Digital Forensics Conference

Of the many notebook computers which are stolen, a large number are subsequently recovered. However, if the device is password protected, and the serial number has been removed, then it is difficult for police or other authorities to trace the legitimate owner. The squad dedicated to computer related crime do not have sufficient resources to conduct a thorough forensic examination of every laptop in order to determine its rightful owner. This project aims to produce a tool which can be used by virtually any police officer, or other person, which does not alter the hard drive in any fashion. This …


Bitlocker - The End Of Digital Forensics?, Andrew Woodward Apr 2006

Bitlocker - The End Of Digital Forensics?, Andrew Woodward

Australian Digital Forensics Conference

Microsoft’s upcoming operating system release, Windows Vista, contains the option to encrypt all information on a hard drive. Previous versions of Windows have used the encrypting file system (EFS), allowing users to selectively encrypt files and folders on a drive. The technology is called BitLocker, and poses a problem for forensic investigators, as all information on the drive will be encrypted, and therefore unreadable. The technology has some limitations, such as only 2 versions out of the 5 available contain this technology and it also requires a trusted platform module (TPM) in order to operate. Other inherent limitations, along with …


A Study Of The Compliance Of Alarm Installations In Perth, Western Australia: Are Security Alarm Systems Being Installed To Australian Standard As2201.1 – “Systems Installed In A Client's Premises.”, Robert E. Mclaughlin, David J. Brooks Apr 2006

A Study Of The Compliance Of Alarm Installations In Perth, Western Australia: Are Security Alarm Systems Being Installed To Australian Standard As2201.1 – “Systems Installed In A Client's Premises.”, Robert E. Mclaughlin, David J. Brooks

Australian Information Warfare and Security Conference

This study presented an overview of the training available to intruder alarm installers. A survey of domestic and commercial intruder alarm systems (n=20) were completed across Perth, Western Australia, metropolitan area. The gathered data were evaluated against Australian Standard AS2201.1 for intruder alarm systems, to determine whether alarm installations comply with two parts of the standard, being that of control panel location and zone supervision. AS2201.1 requires that intruder alarm control equipment shall be located within the alarmed area, located outside the entry/exit point and operate as dual endofline supervision. The study presents significant findings into the compliance of installed …


Security Risk Assessment: Group Approach To A Consensual Outcome, Ben Beard, David J. Brooks Apr 2006

Security Risk Assessment: Group Approach To A Consensual Outcome, Ben Beard, David J. Brooks

Australian Information Warfare and Security Conference

AS/NZS4360:2004 suggests that the risk assessment process should not be conducted or information gathered in isolation. This insular method of data collection may lead to inaccurate risk assessment, as stakeholders with vested interests may emphasise their own risks or game the risk assessment process. The study demonstrated how a consensual risk assessment approach may result in a more acceptable risk assessment outcome when compared to individual assessments. The participants were senior managers at a West Australian motel located on the West Coast Highway, Scarborough. The motel consists of four three storey blocks of units, resulting in a total of 75 …


Terrorism As Opiniotainment: Perceptions Warriors And The Public Battlefield, Luke Howie Apr 2006

Terrorism As Opiniotainment: Perceptions Warriors And The Public Battlefield, Luke Howie

Australian Information Warfare and Security Conference

Terrorism continues to have a significant impact on the lives of Australians. Whilst Australian cities remain untargeted during this present wave of terrorism, many Australians perceive the threat to be significant. Terrorism is offered for consumption daily in the news media and many Australians have seen the images of terrorism. In addition to television images, media consumers have been inundated with terrorism reporting on talkback radio, in feature films, and in newspapers. What impact does the perceptions wars on terrorism have on Australian society? Are the public more or less knowledgeable because of public debate? These are questions that need …


Information Terrorism: Networked Influence, W Hutchinson Apr 2006

Information Terrorism: Networked Influence, W Hutchinson

Australian Information Warfare and Security Conference

The advent of digital information technology heralded the concept of information warfare. This ‘preliminary’ stage in the 1990s really consisted of technology warfare where the networks, upon which combat relied, were seen as weapons to gain ‘information superiority’. This was the inception of the technological aspect of Information Warfare. The realisation of the effectiveness of electronic networks to optimize organisational communication was taken up by industry, the military and terrorist groups alike. As society quickly became more reliant on digital networks to run its critical functions, it became apparent that this infrastructure was vulnerable and needed protection (as well as …


The Awareness And Perception Of Spyware Amongst Home Pc Computer Users, M Jaeger, N L. Clarke Apr 2006

The Awareness And Perception Of Spyware Amongst Home Pc Computer Users, M Jaeger, N L. Clarke

Australian Information Warfare and Security Conference

Spyware is a major threat to personal computer based data confidentiality, with criminal elements utilising it as a positive moneymaking device by theft of personal data from security unconscious home internet users. This paper examines the level of understanding and awareness of home computer users to Spyware. An anonymous survey was distributed via email invitation with 205 completed surveys. From an analysis of the survey it was found that the majority of respondents do understand what Spyware is, however, there was found to be a lack of understanding of computer security in defending against Spyware, with 20% of survey respondents …


Assessing End-User Awareness Of Social Engineering And Phishing, A Karakasiliotis,, S M. Furnell, M Papadaki Apr 2006

Assessing End-User Awareness Of Social Engineering And Phishing, A Karakasiliotis,, S M. Furnell, M Papadaki

Australian Information Warfare and Security Conference

Social engineering is a significant problem involving technical and nontechnical ploys in order to acquire information from unsuspecting users. This paper presents an assessment of user awareness of such methods in the form of email phishing attacks. Our experiment used a webbased survey, which presented a mix of 20 legitimate and illegitimate emails, and asked participants to classify them and explain the rationale for their decisions. This assessment shows that the 179 participants were 36% successful in identifying legitimate emails, versus 45% successful in spotting illegitimate ones. Additionally, in many cases, the participants who identified illegitimate emails correctly could not …


Global Reach: Terrorists And The Internet, Simon O'Rourke Apr 2006

Global Reach: Terrorists And The Internet, Simon O'Rourke

Australian Information Warfare and Security Conference

The use of the Internet by terrorists appears to diverge into two distinct modes neither of which is mutually exclusive. The first aligns to the view that terrorists will use the Internet as a platform to launch cyber attacks against critical infrastructure nodes as well as key government and private sector networks. This paper discusses the alternate mode that being the primary use of the Internet by terrorists will be to recruit, train, communicate and gain information about potential targets by conducting virtual reconnaissance. It will examine the nexus between the virtual world and the physical threat that is manifested …


Conceptual Modelling: Choosing A Critical Infrastructure Modelling Methodology, Graeme Pye, Matthew J. Warren Apr 2006

Conceptual Modelling: Choosing A Critical Infrastructure Modelling Methodology, Graeme Pye, Matthew J. Warren

Australian Information Warfare and Security Conference

This paper reports on further research undertaken regarding systems modelling as applied to critical infrastructure systems and networks and builds upon the initial modelling research of Pye and Warren (2006a). We discuss system characteristics, inter-relationships, dynamics and modelling of similar systems and why modelling of a critical infrastructure is important. In overview we compare four modelling methods and techniques previously used to model similar systems and discuss their potential transference to model critical infrastructure systems, before selecting the most promising and suitable for modelling critical infrastructure systems for further research.


Engineering A Suburban Ad-Hoc Network, Mike Tyson, Ronald D. Pose, Carlo Kopp, Mohammad Rokonuzzaman, Muhammad Mahmudul Islam Apr 2006

Engineering A Suburban Ad-Hoc Network, Mike Tyson, Ronald D. Pose, Carlo Kopp, Mohammad Rokonuzzaman, Muhammad Mahmudul Islam

Australian Information Warfare and Security Conference

Networks are growing in popularity, as wireless communication hardware, both fixed and mobile, becomes more common and affordable. The Monash Suburban Ad-Hoc Network (SAHN) project has devised a system that provides a highly secure and survivable ad-hoc network, capable of delivering broadband speeds to co-operating users within a fixed environment, such as a residential neighbourhood, or a campus. The SAHN can be used by residents within a community to exchange information, to share access to the Internet, providing last-mile access, or for local telephony and video conferencing. SAHN nodes are designed to be self-configuring and selfmanaging, relying on no experienced …


Tags At War: A Review Of The United States Department Of Defence Rfid Tag Data Standard, Uros Urosevic, Christopher Bolan Apr 2006

Tags At War: A Review Of The United States Department Of Defence Rfid Tag Data Standard, Uros Urosevic, Christopher Bolan

Australian Information Warfare and Security Conference

The U.S. Department of Defence have mandated the use of RFID technology in their procurement and supply systems. To enable compatibility across civilian contractors and suppliers and military systems the US DOD RFTag Data Format 2.0 specification has been implemented. This paper outlines the features of this standard and the possible security implications of its adoption.


A Systematic Review Of The Roles And Competencies Of Medical Information Professionals(Mips) In Evidence-Based Medicine In Thailand, Somrux Sahapong, Lampang Manmart, Dusadee Ayuvat, Somkiet Potisat Jan 2006

A Systematic Review Of The Roles And Competencies Of Medical Information Professionals(Mips) In Evidence-Based Medicine In Thailand, Somrux Sahapong, Lampang Manmart, Dusadee Ayuvat, Somkiet Potisat

EDU-COM International Conference

The aim of this study was to systematically review the roles and competencies of Medical Information Professionals (MIPs: non-medical personnel who are information technology and medical library literacy) in supporting clinicians in the practice of evidence-based medicine (EBM) as reported in the published literature. It analysed and synthesized information from textbooks on EBM and research and review articles drawn from MEDLINE using the following keywords: ―evidence-based medicine‖, ―information seeking and physician‖, ―information need and physician‖, ―EBM librarian‖, ―clinical librarian‖, ―library service‖, ―informationist‖, and ―knowledge management‖. Information from research articles published in local journals and conference proceedings was also included evidence-based …


The Challenges Of Itil Implementations, Jason Gray Jan 2006

The Challenges Of Itil Implementations, Jason Gray

Theses : Honours

Originating from the UK, the IT Infrastructure Library (ITIL) is an IT Service Management framework whose adoption is rapidly spreading throughout Canada, Netherlands, South Africa, India, USA, and Australia. Promoted as a collection of "Best Practices" in IT service management, ITIL is gaining a reputation as a "silver bullet" to IT Service Management woes and is now .gaining popularity amongst IT vendors and leaders of best practices worldwide. Increased IT productivity, IT accountability, increased compliance and reduced IT costs, are just some of the promised list of benefits. More and more organisations are plam1ing to embark on ITIL implementations as …


Evaluating The Impact Of Peer Review And Participation Awareness In An Online Collaborative Document Authoring Environment, Greg Baatard Jan 2006

Evaluating The Impact Of Peer Review And Participation Awareness In An Online Collaborative Document Authoring Environment, Greg Baatard

Theses : Honours

Online Learning Environments (OLEs) have been widely adopted by higher education facilities, offering distance education with the potential to support the social and collaborative aspects deemed crucial to modern constructivist pedagogy. Groupware, a form of software which aims to facilitate group work, has been the subject of much research, from both educational and enterprise perspectives. This research introduced Reportal, an online groupware system designed to facilitate the collaborative authoring of a document. Reportal's peer review and participation awareness features were the focus of this research, and their impact was measured against the elements of online collaboration, a typology established by …