Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons™

Open Access. Powered by Scholars. Published by Universities.®

Edith Cowan University

Discipline
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 601 - 630 of 1285

Full-Text Articles in Computer Sciences

The Mobile Execution Environment: A Secure And Non-Intrusive Approach To Implement A Bring You Own Device Policy For Laptops, Peter James, Don Griffiths Dec 2012

The Mobile Execution Environment: A Secure And Non-Intrusive Approach To Implement A Bring You Own Device Policy For Laptops, Peter James, Don Griffiths

Australian Information Security Management Conference

Bring Your Own Device (BYOD) has become an established business practice, however the practice can increase an organisation’s information security risks. The implementation of a BYOD policy for laptops must consider how the information security risks can be mitigated or managed. The selection of an appropriate secure laptop software configuration is an important part of the information security risk mitigation/management strategy. This paper considers how a secure laptop software configuration, the Mobile Execution Environment (MEE) can be used to minimise risks when a BYOD policy for laptops is implemented. In this paper the security and business risks associated with the …


Territorial Behavior And The Economics Of Botnets, Craig S. Wright Dec 2012

Territorial Behavior And The Economics Of Botnets, Craig S. Wright

Australian Information Security Management Conference

This paper looks at the economics associated with botnets. This research can be used to calculate territorial sizes for online criminal networks. Looking at the types of systems we can compare the time required to maintain the botnet against the benefits received. In doing this it will be possible to formulate economic defence strategies that reduce the benefits received through the control of the botnet. We look at the decision to be territorial or not from the perspective of the criminal bot-herder. This is extended to an analysis of territorial size. The criminal running a botnet seeks to maximize profit. …


Protective Emblems In Cyber Warfare, Iain Sutherland, Konstantinos Xynos, Andrew Jones, Andrew Blyth Dec 2012

Protective Emblems In Cyber Warfare, Iain Sutherland, Konstantinos Xynos, Andrew Jones, Andrew Blyth

Australian Information Warfare and Security Conference

The Tallinn Manual will be released in February 2013 and makes a significant step towards defining the concepts of cyber warfare. The early draft of the manual is available and the expert working party have interpreted the existing international agreements, instruments and conventions and applied them to the field of cyber warfare. The manual makes a number of interpretations on the legal position of civilians and other parties. The manual makes it clear that the existing conventions are applicable and that civilian / religious and medical systems should be viewed as non-combatants in a cyber conflict. In the kinetic warfare …


Mobile Device Management For Personally Controlled Electronic Health Records: Effective Selection Of Evaluation Criteria, Murray Brand, Patricia Williams Jan 2012

Mobile Device Management For Personally Controlled Electronic Health Records: Effective Selection Of Evaluation Criteria, Murray Brand, Patricia Williams

Australian eHealth Informatics and Security Conference

Enterprises are faced with the task of managing a plethora of mobile computing devices in the workplace that are employed for both business purposes and private use. This integration can contribute to the demands of security protection and add significant threats to the enterprise. The introduction of the Personally Controlled Electronic Health Record (PCEHR) system is a significant step in e-health for Australia and will likely result in sensitive information being accessed from mobile computing devices. Mobile Device Management (MDM) offers a potential solution to manage these devices, however there is a variety of vendors with a range of solutions. …


Building Patient Trust In Electronic Health Records, Helen Cripps, Craig Standing Jan 2012

Building Patient Trust In Electronic Health Records, Helen Cripps, Craig Standing

Australian eHealth Informatics and Security Conference

While electronic medical records have the potential to vastly improve a patient’s health care, their introduction also raises new and complex security and privacy issues. The challenge of preserving what patients’ believe as their privacy in the context of the introduction of the Personally Controlled Electronic Health Record (PCEHR), into the multi-layered and decentralised Australian health system is discussed. Based on a number of European case studies the paper outlines the institutional measures for privacy and security that have been put in place, and compares them with the current status in Australia. The implementation of the PCEHR has not been …


Cloud Security: A Case Study In Telemedicine, Michael Johnstone Jan 2012

Cloud Security: A Case Study In Telemedicine, Michael Johnstone

Australian eHealth Informatics and Security Conference

Security as part of requirements engineering is now seen as an essential part of systems development in several modern methodologies. Unfortunately, medical systems are one domain where security is seen as an impediment to patient care and not as an essential part of a system. Cloud computing may offer a seamless way to allow medical data to be transferred from patient to medical practitioners, whilst maintaining security requirements. This paper uses a case study to investigate the use of cloud computing in a mobile application for Parkinson Disease. It was found that functionality took precedence over security requirements and standards.


Legal Issues Related To Accountable-Ehealth Systems In Australia, Randike Gajanayake, Bill Lane, Tony Iannella, Tony Sahama Jan 2012

Legal Issues Related To Accountable-Ehealth Systems In Australia, Randike Gajanayake, Bill Lane, Tony Iannella, Tony Sahama

Australian eHealth Informatics and Security Conference

Information privacy requirements of patients and information requirements of healthcare providers (HCP) are competing concerns. Reaching a balance between these requirements have proven difficult but is crucial for the success of eHealth systems. The traditional approaches to information management have been preventive measures which either allow or deny access to information. We believe that this approach is inappropriate for a domain such as healthcare. We contend that introducing information accountability (IA) to eHealth systems can reach the aforementioned balance without the need for rigid information control. IA is a fairly new concept to computer science, hence, there are no unambiguously …


A Holistic Approach To Ehealth Security In Australia: Developing A National Ehealth Sercurity And Access Framework (Nesaf), Yvette Lejins, John Leitch Jan 2012

A Holistic Approach To Ehealth Security In Australia: Developing A National Ehealth Sercurity And Access Framework (Nesaf), Yvette Lejins, John Leitch

Australian eHealth Informatics and Security Conference

The Australian ehealth landscape is confronted with new challenges for healthcare providers in appropriately managing and protecting personal health information. The vision of the National eHealth Security and Access Framework (NESAF) is to adopt a consistent approach to the application of health information security standards and provide better practice guidance in relation to eHealth specific security and access practices. The eHealth information security landscape has a number of unique attributes, many that are faced by other business that provide a service or products – but we see that there is no industry in Australia where such widespread changes in the …


A Method For Securing Online Community Service: A Study Of Selected Western Australian Councils, Sunsern Limwiriyakul Jan 2012

A Method For Securing Online Community Service: A Study Of Selected Western Australian Councils, Sunsern Limwiriyakul

Theses: Doctorates and Masters

Since the Internet was made publicly accessible, it has become increasingly popular and its deployment has been broad and global thereby facilitating a range of available online services such as Electronic Mail (email), news or bulletins, Internet Relay Chat (IRC) and World Wide Web (WWW). Progressively, other online services such as telephony, video conference, video on demand, Interactive Television (ITV) and Geographic Information System (GIS) have been integrated with the Internet and become publicly available. Presently, Internet broadband communication services incorporating both wired and wireless network technologies has seen the emergence of the concept of a digital community which has …


Security Specialists Are From Mars; Healthcare Practitioners Are From Venus: The Case For A Community-Of-Practice Approach To Security Architectures For Healthcare, Elizabeth Coles-Kemp, Patricia Williams Jan 2012

Security Specialists Are From Mars; Healthcare Practitioners Are From Venus: The Case For A Community-Of-Practice Approach To Security Architectures For Healthcare, Elizabeth Coles-Kemp, Patricia Williams

Australian eHealth Informatics and Security Conference

Information security is a necessary requirement of information sharing in the healthcare environment. Research shows that the application of security in this setting is sometimes subject to work-arounds where healthcare practitioners feel forced to incorporate practices that they have not had an input into and with which they have not engaged with. This can result in a sense of security practitioners and healthcare practitioners being culturally very different in their approach to information systems. As a result such practices do not constitute part of their community of practice nor their identity. In order to respond to this, systems designers typically …


Accountable-Ehealth Systems: The Next Step Forward For Privacy, Randike Gajanayake, Tony Iannella, Bill Lane, Tony Sahama Jan 2012

Accountable-Ehealth Systems: The Next Step Forward For Privacy, Randike Gajanayake, Tony Iannella, Bill Lane, Tony Sahama

Australian eHealth Informatics and Security Conference

EHealth systems promise enviable benefits and capabilities for healthcare, yet the technologies that make these capabilities possible brings with them undesirable drawback such as information security related threats which need to be appropriately addressed. Lurking in these threats are patient privacy concerns. Resolving these privacy concerns have proven to be difficult since they often conflict with information requirements of healthcare providers. It is important to achieve a proper balance between these requirements. We believe that information accountability can achieve this balance. In this paper we introduce accountable-eHealth systems. We will discuss how our designed protocols can successfully address the aforementioned …


Developing Governance Capability To Improve Information Security Resilience In Healthcare, Rachel Mahncke, Patricia Williams Jan 2012

Developing Governance Capability To Improve Information Security Resilience In Healthcare, Rachel Mahncke, Patricia Williams

Australian eHealth Informatics and Security Conference

General medical practices’ in Australia are vulnerable to information security threats and insecure practices. It is becoming well accepted in the healthcare environment that information security is both a technical and a human endeavour, and that the human behaviours, particularly around integration with healthcare workflow, are key barriers to good information security practice. This paper develops a holistic capability approach to information security by completing a preliminary iteration of mapping operational capabilities to governance capabilities. Using an operational backup capability matrix exemplar, the approach is analysed against the governance policy capability matrix. The resultant mapping between the operational and governance …


The Detection Of Abnormal Events In Activities Of Daily Living Using A Kinect Sensor, Laurence Da Luz Jan 2012

The Detection Of Abnormal Events In Activities Of Daily Living Using A Kinect Sensor, Laurence Da Luz

Theses : Honours

The growing elderly population presents a challenge on the resources of carers and assisted living communities. This has led to various projects in remote automated home monitoring in order to keep the elderly in their own home environment longer. These have the promise of alleviating the strain on support services, and the benefits of keeping people in their existing familiar community environment. Such monitoring typically involves a myriad of sensors attached to the environment and person, so as to acquire rich enough data to determine the actions of the person being monitored. In this research, an algorithm based around the …


A Survey Of Computer And Network Security Support From Computer Retailers To Consumers In Australia, Patryk Szewczyk Jan 2012

A Survey Of Computer And Network Security Support From Computer Retailers To Consumers In Australia, Patryk Szewczyk

Australian Information Security Management Conference

Previously undertaken research suggests that novice end-users rely on computer retailers for security advice and support during and after a sale has occurred. This paper documents the survey results of computer and network security support provided to consumers by retailers in Perth, Western Australia between 2011 and 2012. The conducted survey shows that in the majority of cases, computers retailers were favourable in providing support and recommendations. However, these views were found to be flawed, confusing and do little to ensure that end-users are not victimized by cyber crime.


Corporate Security: Using Knowledge Construction To Define A Practising Body Of Knowledge, David Brooks Jan 2012

Corporate Security: Using Knowledge Construction To Define A Practising Body Of Knowledge, David Brooks

Research outputs 2012

Security is a multidimensional concept, with many meanings, practising domains, and heterogeneous occupations. Therefore, it is difficult to define security as a singular concept, although understanding may be achieved by its applied context in presenting a domicile body of knowledge. There have been studies that have presented a number of corporate security bodies of knowledge; however, there is still restricted consensus. From these past body of knowledge studies, and supported by multidimensional scaling knowledge mapping, a body of knowledge framework is put forward, integrating core and allied knowledge categories. The core knowledge categories include practise areas such as risk management, …


An Overview Of Cloud Computing Challenges And Its Security Concerns, Krishnun Sansurooah Jan 2012

An Overview Of Cloud Computing Challenges And Its Security Concerns, Krishnun Sansurooah

Research outputs 2012

There has been an increasing advancement about Cloud computing during the past couple of years. Cloud computing has become a new computer model which aims to deliver reliable, customizable and scalable computing environment for end-users. Companies are choosing to move their data, applications and services to the Cloud. The advantages are significant ranging from increasing the availability, reliability, light weight, easily accessible applications, and low cost but so are the risks associated with. Companies that require application hosting could potentially benefit from the provisioning of computing infrastructure resources as a service. In addition to the economic advantages of an on-demand …


A Proposed Method For Examining Wireless Device Vulnerability To Brute Force Attacks Via Wps External Registrar Pin Authentication Design Vulnerability, Symon Aked, Christopher Bolan, Murray Brand Jan 2012

A Proposed Method For Examining Wireless Device Vulnerability To Brute Force Attacks Via Wps External Registrar Pin Authentication Design Vulnerability, Symon Aked, Christopher Bolan, Murray Brand

Research outputs 2012

Wi-Fi Protected Setup (WPS) is a certification scheme introduced in 2007 to ensure that wireless SOHO (Small Office, Home Office) and home networks could be connected to in a trusted, yet user friendly manner. Recently, WPS was shown to have a design and implementation flaw which makes the feature highly susceptible to attack. Although open-source tools have been written and released, no formal testing methodology has been developed. This research presents a proposed method for the testing of this vulnerability in a measured and systematic way.


User Reaction Towards End User License Agreements On Android Smartphones, Hamish Cotton, Christopher Bolan Jan 2012

User Reaction Towards End User License Agreements On Android Smartphones, Hamish Cotton, Christopher Bolan

Research outputs 2012

Smartphones are increasingly recognized as the most popular computing platform, forming an integral part of the way users interact with the online world. Accompanied with the advent of user-installed content, End User License Agreements have surfaced mirroring issues previously arising on more traditional platforms. This survey conducted in Perth, Western Australia looked at user behavior when viewing and accepting EULAs on smartphone devices. The results show that a majority of users do not read such agreements citing issues of readability and length.


Online Course Content Auditing: Templates And Practices, Justin Brown, Gregory Baatard Jan 2012

Online Course Content Auditing: Templates And Practices, Justin Brown, Gregory Baatard

Research outputs 2012

This paper introduces and discusses the Blackboard Content Audit tool developed by a CS school within an Australian university. Based upon the key sections of a unit’s site in the Blackboard LMS, the tool establishes sets of basic, intermediate and advanced criteria and a rating scale upon which to assess the criteria. By specifying the basic criteria as a minimum standard, the consistency of unit sites can be improved. This helps to close the perceived quality gap between the schools online unit offerings, where in the past some staff had engaged more than others with the features of Blackboard. The …


Utilizing The Rfid Lock Command Against Multiple Targets, Christopher Bolan Jan 2012

Utilizing The Rfid Lock Command Against Multiple Targets, Christopher Bolan

Research outputs 2012

An unlocked Electronic Product Code (EPC) tag allows for issuance of most commands without the need for any authorization. This means that a system with unlocked tags would allow any attacker to modify tag data at will, whilst also opening the door to a range of other misuse. One possible avenue of active misuse against unlocked tags would be to issue LockID commands and ‘permanently’ lock some or all of a system‘s RFID tags. As this attack is simply an issuance of a valid command it fits firmly in the category of an active misuse and could also be considered …


Web Accessibility In Corporate Australia: Perceptions Versus Reality, Justin Brown, Vivienne Conway Jan 2012

Web Accessibility In Corporate Australia: Perceptions Versus Reality, Justin Brown, Vivienne Conway

Research outputs 2012

In this paper we describe the results of website audits and survey responses for organizations involved in the Australia Web Awards for 2011. 160 organizations entered their sites or sites they had developed as part of the awards, and in doing so were required to select the level of WCAG compliance for their site. Audits conducted on these sites after the awards completion showed that very few of the entrants actually met their selected level of accessibility compliance, regardless of the organization type. Survey responses from participating entrants in the AWA indicated that they were aware of the WCAG guidelines …


The Application Of A Visual Data Mining Framework To Determine Soil, Climate And Land-Use Relationships, Yunous Vagh Jan 2012

The Application Of A Visual Data Mining Framework To Determine Soil, Climate And Land-Use Relationships, Yunous Vagh

Research outputs 2012

In this research study, the methodology of action research dynamics and a case study was employed in constructing a visual data mining framework for the processing and analysis of geographic land-use data in an agricultural context. The geographic data was made up of a digital elevation model (DEM), soil and land use profiles that were juxtaposed with previously captured climatic data from fixed weather stations in Australia. In this pilot study, monthly rainfall profiles for a selected study area were used to identify areas of soil variability. The rainfall was sampled for the beginning (April) of the rainy season for …


A Data Mining Perspective Of The Dual Effect Of Rainfall And Temperature On Wheat Yield, Yunous Vagh, Jitian Xiao Jan 2012

A Data Mining Perspective Of The Dual Effect Of Rainfall And Temperature On Wheat Yield, Yunous Vagh, Jitian Xiao

Research outputs 2012

This paper presents the final investigation within the series of qualitative and quantitative investigations carried out for the processing and analysis of geographic land-use data in an agricultural context. The geographic data was made up of crop and cereal production land use profiles. These were linked to previously recorded climatic data from fixed weather stations in Australia that was interpolated using ordinary krigeing to fit a grid surface. In this study, the profiles for the stochastic average monthly temperature and rainfall for a selected study area were used to determine their simultaneous effects on crop production at the shire level. …


Security Specialists Are From Mars; Healthcare Practitioners Are From Venus: The Case For A Community-Of-Practice Approach To Security Architectures For Healthcare, Elizabeth Coles-Kemp, Patricia Williams Jan 2012

Security Specialists Are From Mars; Healthcare Practitioners Are From Venus: The Case For A Community-Of-Practice Approach To Security Architectures For Healthcare, Elizabeth Coles-Kemp, Patricia Williams

Research outputs 2012

Information security is a necessary requirement of information sharing in the healthcare environment. Research shows that the application of security in this setting is sometimes subject to work-arounds where healthcare practitioners feel forced to incorporate practices that they have not had an input into and with which they have not engaged with. This can result in a sense of security practitioners and healthcare practitioners being culturally very different in their approach to information systems. As a result such practices do not constitute part of their community of practice nor their identity. In order to respond to this, systems designers typically …


Developing Governance Capability To Improve Information Security Resilience In Healthcare, Rachel Mahncke, Patricia Williams Jan 2012

Developing Governance Capability To Improve Information Security Resilience In Healthcare, Rachel Mahncke, Patricia Williams

Research outputs 2012

General medical practices’ in Australia are vulnerable to information security threats and insecure practices. It is becoming well accepted in the healthcare environment that information security is both a technical and a human endeavour, and that the human behaviours, particularly around integration with healthcare workflow, are key barriers to good information security practice. This paper develops a holistic capability approach to information security by completing a preliminary iteration of mapping operational capabilities to governance capabilities. Using an operational backup capability matrix exemplar, the approach is analysed against the governance policy capability matrix. The resultant mapping between the operational and governance …


Cloud Security: A Case Study In Telemedicine, Michael Johnstone Jan 2012

Cloud Security: A Case Study In Telemedicine, Michael Johnstone

Research outputs 2012

Security as part of requirements engineering is now seen as an essential part of systems development in several modern methodologies. Unfortunately, medical systems are one domain where security is seen as an impediment to patient care and not as an essential part of a system. Cloud computing may offer a seamless way to allow medical data to be transferred from patient to medical practitioners, whilst maintaining security requirements. This paper uses a case study to investigate the use of cloud computing in a mobile application for Parkinson Disease. It was found that functionality took precedence over security requirements and standards.


Building Patient Trust In Electronic Health Records, Helen Cripps, Craig Standing Jan 2012

Building Patient Trust In Electronic Health Records, Helen Cripps, Craig Standing

Research outputs 2012

While electronic medical records have the potential to vastly improve a patient’s health care, their introduction also raises new and complex security and privacy issues. The challenge of preserving what patients’ believe as their privacy in the context of the introduction of the Personally Controlled Electronic Health Record (PCEHR), into the multi-layered and decentralised Australian health system is discussed. Based on a number of European case studies the paper outlines the institutional measures for privacy and security that have been put in place, and compares them with the current status in Australia. The implementation of the PCEHR has not been …


Mobile Device Management For Personally Controlled Electronic Health Records: Effective Selection Of Evaluation Criteria, Murray Brand, Patricia Williams Jan 2012

Mobile Device Management For Personally Controlled Electronic Health Records: Effective Selection Of Evaluation Criteria, Murray Brand, Patricia Williams

Research outputs 2012

Enterprises are faced with the task of managing a plethora of mobile computing devices in the workplace that are employed for both business purposes and private use. This integration can contribute to the demands of security protection and add significant threats to the enterprise. The introduction of the Personally Controlled Electronic Health Record (PCEHR) system is a significant step in e-health for Australia and will likely result in sensitive information being accessed from mobile computing devices. Mobile Device Management (MDM) offers a potential solution to manage these devices, however there is a variety of vendors with a range of solutions. …


Legal Issues Related To Accountable-Ehealth Systems In Australia, Randike Gajanayake, Bill Lane, Tony Iannella, Tony Sahama Jan 2012

Legal Issues Related To Accountable-Ehealth Systems In Australia, Randike Gajanayake, Bill Lane, Tony Iannella, Tony Sahama

Research outputs 2012

Information privacy requirements of patients and information requirements of healthcare providers (HCP) are competing concerns. Reaching a balance between these requirements have proven difficult but is crucial for the success of eHealth systems. The traditional approaches to information management have been preventive measures which either allow or deny access to information. We believe that this approach is inappropriate for a domain such as healthcare. We contend that introducing information accountability (IA) to eHealth systems can reach the aforementioned balance without the need for rigid information control. IA is a fairly new concept to computer science, hence, there are no unambiguously …


A Holistic Approach To Ehealth Security In Australia: Developing A National Ehealth Sercurity And Access Framework (Nesaf), Yvette Lejins, John Leitch Jan 2012

A Holistic Approach To Ehealth Security In Australia: Developing A National Ehealth Sercurity And Access Framework (Nesaf), Yvette Lejins, John Leitch

Research outputs 2012

The Australian ehealth landscape is confronted with new challenges for healthcare providers in appropriately managing and protecting personal health information. The vision of the National eHealth Security and Access Framework (NESAF) is to adopt a consistent approach to the application of health information security standards and provide better practice guidance in relation to eHealth specific security and access practices. The eHealth information security landscape has a number of unique attributes, many that are faced by other business that provide a service or products – but we see that there is no industry in Australia where such widespread changes in the …