Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Information Security (532)
- Artificial Intelligence and Robotics (92)
- Engineering (48)
- Software Engineering (48)
- Social and Behavioral Sciences (45)
-
- Computer Engineering (33)
- Medicine and Health Sciences (29)
- Databases and Information Systems (28)
- Business (26)
- Other Computer Sciences (23)
- Graphics and Human Computer Interfaces (20)
- Life Sciences (17)
- Theory and Algorithms (16)
- Health Information Technology (14)
- Education (13)
- Electrical and Computer Engineering (12)
- OS and Networks (12)
- Public Affairs, Public Policy and Public Administration (12)
- Systems Architecture (12)
- Plant Sciences (11)
- Agricultural Science (10)
- Legal Studies (10)
- Numerical Analysis and Scientific Computing (9)
- Defense and Security Studies (8)
- Digital Communications and Networking (8)
- Sociology (8)
- Arts and Humanities (7)
- Business Administration, Management, and Operations (6)
- Keyword
-
- [RSTDPub] (145)
- Security (104)
- Digital forensics (41)
- Information security (38)
- Machine learning (38)
-
- Privacy (35)
- Cyber security (28)
- Artificial intelligence (25)
- Computer security (24)
- Cybersecurity (24)
- Deep learning (22)
- Network security (22)
- Intrusion detection (21)
- Australia (20)
- Authentication (20)
- Forensics (20)
- Malware (20)
- [aism] (18)
- Healthcare (17)
- Encryption (16)
- Anomaly detection (14)
- Biometrics (14)
- Blockchain (14)
- Risk (14)
- Computer science (13)
- Forensic (13)
- Risk management (13)
- Vulnerability (13)
- Cloud computing (12)
- Detection (12)
- Publication Year
- Publication
-
- Australian Information Security Management Conference (225)
- Research outputs 2022 to 2026 (201)
- Australian Digital Forensics Conference (177)
- Research outputs pre 2011 (171)
- Research outputs 2014 to 2021 (119)
-
- Theses : Honours (87)
- Theses: Doctorates and Masters (85)
- Australian Information Warfare and Security Conference (58)
- Australian Security and Intelligence Conference (42)
- Research outputs 2012 (31)
- Australian eHealth Informatics and Security Conference (25)
- International Cyber Resilience conference (20)
- Research outputs 2011 (17)
- Australian Counter Terrorism Conference (9)
- Research Datasets (6)
- Research outputs 2013 (6)
- EDU-COM International Conference (3)
- InfoSci@ECU Seminars (2)
- Creative Connections Symposium @ BEAP2004 September 4, 2004 (1)
- Publication Type
- File Type
Articles 901 - 930 of 1285
Full-Text Articles in Computer Sciences
Email 'Message-Ids' Helpful For Forensic Analysis?, Satheesaan Pasupatheeswaran
Email 'Message-Ids' Helpful For Forensic Analysis?, Satheesaan Pasupatheeswaran
Australian Digital Forensics Conference
Finding the source of spoofed email is a challenging task for forensic investigators. Header of an email has several fields that can be used for investigation. An investigator can easily understand the evidences embedded within most of the header fields of an email, except the message-id field. Therefore, there is a need to understand how message-ids are constructed and what useful information can be recovered from them. The immediate aim of the analysis is to find the message-id construction mechanism of ‘Sendmail’ mail transfer agent (MTA) version 8.14 and how the findings can be used successfully in forensic analysis. Source …
Data Hiding In Windows Executable Files, Daemin Shin, Yeog Kim, Keunduck Byun, Sangjin Lee
Data Hiding In Windows Executable Files, Daemin Shin, Yeog Kim, Keunduck Byun, Sangjin Lee
Australian Digital Forensics Conference
A common technique for hiding information in executable files is the embedding a limited amount of information in program binaries. The hiding technique is commonly achieved by using special software tools as e.g. the tools presented by Hydan and Stilo in (Rakan, 2004, Bertrand, 2005). These tools can be used to commit crimes as e.g. industrial spy activities or other forms of illegal data access. In this paper, we propose new methods for hiding information in Portable Executable (PE) files. PE is a file format for executables used in the 32-bit and 64-bit versions of the Windows operating system. In …
Subverting National Internet Censorship - An Investigation Into Existing Tools And Techniques, Jason Smart, Kyle Tedeschi, Daniel Meakins, Peter Hannay, Christopher Bolan
Subverting National Internet Censorship - An Investigation Into Existing Tools And Techniques, Jason Smart, Kyle Tedeschi, Daniel Meakins, Peter Hannay, Christopher Bolan
Australian Digital Forensics Conference
The announcement of a trial of a National level internet filter in Australia has caused renewed interest in the arena of internet censorship. Whilst details on the schemes being tested have been fairly sparse the announcement of the trial itself, has drawn wide condemnation from privacy advocates throughout the world. Given this announcement it was decided to test and compare three of the most popular free tools available that allow for the bypassing of internet censorship devices such as those used within China. Tests were conducted using three software packages, Freegate, GPass and GTunnel which were analysed through packet capture …
Malware, Viruses And Log Visualisation, Iain Swanson
Malware, Viruses And Log Visualisation, Iain Swanson
Australian Digital Forensics Conference
This paper will look at the current state of visualization in relation to mainly malware collector logs, network logs and the possibility of visualizing their payloads. We will show that this type of visualization of activity on the network can help us in the forensic investigation of the traffic, which may contain unwanted pieces of cod, and may identify any patterns within the traffic or payloads that might help us determine the nature of the traffic visually. We will further speculate on a framework that could be built which would be able to finger print any type of malware, based …
Virtual Environments Support Insider Security Violations, Iain Swanson, Patricia A.H. Williams
Virtual Environments Support Insider Security Violations, Iain Swanson, Patricia A.H. Williams
Australian Digital Forensics Conference
This paper describes an investigation into how an employee using a virtual environment can circumvent any or all of the security, policies and procedures within an organization. The paper discusses the fundamental issues that organizations must address to be able to detect such an attack. Attacks of this nature may be malicious with intent to cause disruption by flooding the network or disabling specific equipment, or non-malicious by quietly gathering critical information such as user names and passwords or a colleague’s internet banking details. Identification of potential residual evidence following an attack is presented. Such evidence may be used to …
Malware Detection And Removal: An Examination Of Personal Anti-Virus Software, Patryk Szewczyk, Murray Brand
Malware Detection And Removal: An Examination Of Personal Anti-Virus Software, Patryk Szewczyk, Murray Brand
Australian Digital Forensics Conference
SoHo users are increasingly faced with the dilemma of applying appropriate security mechanisms to their computer with little or no knowledge of which countermeasure will deal with which potential threat. As problematic as it may seem for individuals to apply appropriate safeguards, individuals with malicious intent are advancing methods by which malicious software may operate undetected on a target host. Previous research has identified that there are numerous ways in which malware may go undetected on a target workstation. This paper examines the quality of malware removal programs currently available on the market, which consumers may use whilst utilising the …
The 2008 Australian Study Of Remnant Data Contained On 2nd Hand Hard Disks: The Saga Continues, Craig Valli, Andrew Woodward
The 2008 Australian Study Of Remnant Data Contained On 2nd Hand Hard Disks: The Saga Continues, Craig Valli, Andrew Woodward
Australian Digital Forensics Conference
This study looked for remnant data on enterprise level hard drives that were purchased through auctions. The drives were analysed for information, be it topical or formatted. In the event that drives were formatted, forensic tools were used to recover this data. This years study revealed a high level of not simply un-erased drives, but drives which contained information that related to critical infrastructure providers. That such a small sample size yielded such a high rate of un-erased drives is of considerable concern, and it may be necessary for the government to become involved.
Data Recovery From Palmmsgv001, Satheesaan Pasupatheeswaran
Data Recovery From Palmmsgv001, Satheesaan Pasupatheeswaran
Australian Digital Forensics Conference
Both SMS and MMS data analysis is an important factor in mobile forensic analysis. Author did not find any mobile forensic tool that is capable of extracting short messages (SMS) and multimedia messages (MMS) from Palm Treo 750. SMS file of Palm Treo 750 is called PalmMgeV001 and it is a proprietary file system. A research work done to find a method to recover SMS data from PalmMsgV001 file. This paper is going to describe the research work and its findings. This paper also discusses a methodology that will help recover SMS data from PalmMsgV001. The PalmMsgV001 file is analysed …
Digital Forensics And The Legal System: A Dilemma Of Our Times, James Tetteh Ami-Narh, Patricia A.H. Williams
Digital Forensics And The Legal System: A Dilemma Of Our Times, James Tetteh Ami-Narh, Patricia A.H. Williams
Australian Digital Forensics Conference
Computers have become an important part of our lives and are becoming fundamental to activities in the home and workplace. Individuals use computer technology to send emails, access banking information, pay taxes, purchase products, surf the internet and so on. Business also use computers and the Internet to perform accounting tasks, manage customer information, store trade secrets, and develop new products and services. State, Federal and Local government agencies use the computer and Internet to create and access information. Similarly, digital systems have become the mainstay of criminal activity. Legal proceedings have always been influenced by tradition and court decisions. …
The Malware Analysis Body Of Knowledge (Mabok), Craig Valli
The Malware Analysis Body Of Knowledge (Mabok), Craig Valli
Australian Digital Forensics Conference
The ability to forensically analyse malicious software (malware) is becoming an increasingly important discipline in the field of Digital Forensics. This is because malware is becoming stealthier, targeted, profit driven, managed by criminal organizations, harder to detect and much harder to analyse. Malware analysis requires a considerable skill set to delve deep into malware internals when it is designed specifically to detect and hinder such attempts. This paper presents a foundation for a Malware Analysis Body of Knowledge (MABOK) that is required to successfully forensically analyse malware. This body of knowledge has been the result of several years of research …
Dealing With The Malicious Insider, Andy Jones, Carl Colwill
Dealing With The Malicious Insider, Andy Jones, Carl Colwill
Australian Information Security Management Conference
This paper looks at a number of issues relating to the malicious insider and the nature of motivation, loyalty and the type of attacks that occur. The paper also examines the changing environmental, social, cultural and business issues that have resulted in an increased exposure to the insider threat. The paper then discusses a range of measures that can be taken to reduce both the likelihood of an attack and the impact that such an attack may have. These measures should be driven by focused and effective risk management processes.
Evaluating The Usability Impacts Of Security Interface Adjustments In Word 2007, M Helala, S M. Furnell, M Papadaki
Evaluating The Usability Impacts Of Security Interface Adjustments In Word 2007, M Helala, S M. Furnell, M Papadaki
Australian Information Security Management Conference
Prior research has suggested that integrating security features with user goals and increasing their visibility would improve the usability of the associated functionalities. This paper investigates how these approaches affect the efficiency of use and the level of user satisfaction. The user interface of Word 2007 was modified according to these principles, with usability tests being conducted with both the original and the modified user interfaces. The results suggest that integrating security features with user goals improves the efficiency of use, but the impacts upon user satisfaction cannot be clearly identified based on the collected data. No indications of any …
Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver
Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver
Australian Information Security Management Conference
This paper proposes to address the need for more innovation in organisational information security by adding a security requirement engineering focus. Based on the belief that any heavyweight security requirements process in organisational security will be doomed to fail, we developed a security requirement approach with three dimensions. The use of a simple security requirements process in the first dimension has been augmented by an agile security approach. However, introducing this second dimension of agile security does provide support for, but does not necessarily stimulate, innovation. A third dimension is, therefore, needed to ensure there is a proper focus in …
Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce
Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce
Australian Information Security Management Conference
There is increasing coverage in the literature highlighting threats to online financial systems. Attacks range from the prevalent reverse social engineering technique known as phishing; where spam emails are sent to customers with links to fake websites, to Trojans that monitor a customer’s account log on process that captures authentication details that are later replayed for financial gain. This ultimately results in loss of monetary funds for affected victims. As technological advances continue to influence the way society makes payment for goods and services, the requirement for more advanced security approaches for transaction verification in the online environment increases. This …
Rfid Communications - Who Is Listening?, Christopher Bolan
Rfid Communications - Who Is Listening?, Christopher Bolan
Australian Information Security Management Conference
Radio Frequency Identification (RFID) is seeing a surge in awareness across a range of industries as a successor to barcoding. The nature of this technology promises a wide range of benefits but it appears to be at the expense of security. This paper investigates an eavesdropping attack against an EPC RFID system and shows how a simple device may be used to record interactions between both Tag and Readers. The device is used to record and decode signals within range and its output is analysed to verify that the attack was indeed successful. The findings verify previous assertions by other …
Secure Portable Execution Environments: A Review Of Available Technologies, Peter James
Secure Portable Execution Environments: A Review Of Available Technologies, Peter James
Australian Information Security Management Conference
Live operating systems and virtualisation allow a known, defined, safe and secure execution environment to be loaded in to a PC’s memory and executed with either minimal or possibly no reliance on the PC’s internal hard disk drive. The ability to boot a live operating system or load a virtual environment (containing an operating system) from a USB storage device allows a secure portable execution environment to be created. Portable execution environments have typically been used by technologists, for example to recover data from a failing PC internal hard disk drive or to perform forensic analysis. However, with the commercial …
Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew
Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew
Australian Information Security Management Conference
In an environment where technical solutions for securing networked systems are commonplace, there still exist problems in implementation of such solutions for home and small business users. One component of this protection is the use of intrusion detection systems. Intrusion detection monitors network traffic for suspicious activity, performs access blocking and alerts the system administrator or user of potential attacks. This paper reviews the basic function of intrusion detection systems and maps them to an existing end-user capability framework. Using this framework, implementation guidance and systematic improvement in implementation of this security measure are defined.
Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong
Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong
Australian Information Security Management Conference
Video over IP (VIP) is becoming a tool of communication in corporate environments to reduce the time spent conducting meetings face-to-face. This has been driven by efficiencies of time saving, management’s monitoring of staff and to communicate with flexibilities - without placing additional disadvantages on employees who must regularly attend personal meetings amongst hectic business schedules. With technology excelling beyond the old telegraphy of analogy video over hard copper wire to dark fibre technology, VIP is a technology that is starting to receive more attention in the corporate world as more organisations have the equipment to support this additional plug-in. …
Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke
Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke
Australian Information Security Management Conference
The current security on mobile devices is often limited to the Personal Identification Number (PIN), a secretknowledge based technique that has historically demonstrated to provide ineffective protection from misuse. Unfortunately, with the increasing capabilities of mobile devices, such as online banking and shopping, the need for more effective protection is imperative. This study proposes the use of two-factor authentication as an enhanced technique for authentication on a Smartphone. Through utilising secret-knowledge and keystroke analysis, it is proposed a stronger more robust mechanism will exist. Whilst keystroke analysis using mobile devices have been proven effective in experimental studies, these studies have …
Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari
Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari
Australian Information Security Management Conference
This paper presents a critique of emergent views on the roles of the boards of directors in relation to information security. The analysis highlights several concerns about the separation and validation of proper theory and business assertions of information security at board level. New requirements articulated by industry bodies – represented by a selected group of experts and evident in literature – are compared to the underlying theory of corporate governance to identify possible discrepancies. The discussion shows in particular the importance of staying within the theoretical underpinnings of corporate governance when discussing the topic of governance in general and …
Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones
Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones
Australian Information Security Management Conference
Smartphones face the same threats as traditional computers. As long as a device has the capabilities to perform logic processing, the threat of running malicious logic exists. The only difference between security threats on traditional computers versus security threats on smartphones is the challenge to understand the inner workings of the operating system on different hardware processor architectures. To improve upon the security of smartphones, anomaly detection capabilities can be implemented at different functional layers of a smartphone in a coherent manner; instead of just looking at individual functional layers. This paper will focus on identifying conceptual points for measuring …
Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao
Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao
Australian Information Security Management Conference
The prepaid card market in Australia is growing rapidly. Its features not only attract customers from all sorts of backgrounds but also expose it to numerous risks. Using the methodology of the Australian Risk Management Standard AS/NZS4360, this paper looks at the risks inherent in prepaid cards. Concentrating on two major risks, the paper details the regulations governing the industry in the USA as well the technical controls employed by the credit/debit card industry. We suggest risk mitigation strategies from these two view-points, aiming to become an important reference both for industry as it adopts better risk mitigation techniques, and …
Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong
Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong
Australian Information Security Management Conference
During a denial of service attack, it is difficult for a firewall to differentiate legitimate packets from rogue packets, particularly in large networks carrying substantial levels of traffic. Large networks commonly use network intrusion detection systems to identify such attacks, however new viruses and worms can escape detection until their signatures are known and classified as an attack. Commonly used IDS are rule based and static, and produce a high number of false positive alerts. The aim of this research was to determine if it is possible for a firewall to analyse its own traffic patterns to identify attempted denial …
Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward
Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward
Australian Information Security Management Conference
In the arena of wireless security, EAP-TLS is considered one of the most secure protocols. However since its inception the uptake has been poor and the investigation into the reasons for this are sparse. There is an industry perception that EAP-TLS is complex as well as difficult to configure and manage. One of the major barriers is in the use of public key infrastructure and the perceived difficulties in its application. The paper discusses why it is seemingly difficult to implement and how this may differ from the reality of its implementation. This premise is investigated using Windows Server 2003 …
Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward
Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward
Australian Information Security Management Conference
In the world of online gaming, information is exchanged as a matter of course. What information is exchanged behind the scenes is something that is not obvious to the casual user. People who play these games trust that the applications they are using are securely written and in this case, communicate securely. This paper looks at the traffic that is transmitted by the game Team Fortress 2 and incidentally the supporting authentication traffic of the Steam network. It was discovered through packet analysis that there is quite a lot of information which should be kept private being broadcast in the …
Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli
Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli
Australian Information Security Management Conference
Primary care medical practices in Australia have been identified as a profession in need of assistance with information security practices. Whilst guidelines exist, there is little assistance in an accessible and easily implemented form for medical practices. This research presents the preliminary findings of a study which advocates that information security practices can be improved using a capability operational framework which is contextualised to its target environment.
Ranking Competencies For Software Developers In Thailand, Nantaporn Booneka, Paiboon Kiattikomol
Ranking Competencies For Software Developers In Thailand, Nantaporn Booneka, Paiboon Kiattikomol
EDU-COM International Conference
The purpose of this study was to prioritize/rank 12 existing software developer competencies and to find the pattern correlation among these competencies. A survey was designed to elicit responses from a target group (N=350) of software developers, system analysts, lecturers in Information and Communication Technology (ICT), ICT managers and others related to software industry (e.g. information technologist, software architect, computer technicians) in 14 organizations in Thailand. The return rate was 80.57% or 282 out of 350. Data was analyzed using descriptive statistics. Factor analysis was used to identify correlations among the 12 competencies. The 12 competencies were previously identified in …
Case Analysis Of Information Security Risk Perceptions, Alexis Guillot
Case Analysis Of Information Security Risk Perceptions, Alexis Guillot
Theses : Honours
The scientific rationality used by experts towards risk evaluation is expressed as the product of its likelihood of occurrence with its consequences or impacts (ENISA, 2006a). This directly opposes the subjective nature of risk perception, often appearing as inconsistent if not completely irrational (Byrne, 2003). Risk perception theories are a pathway to explain the subjective nature of risk and a deeper insight into the human's cognitive system. Those theories may help to explain why people see, act and plan for risks in the way that they do, the weaknesses that exist in the human decision mechanisms and their impact on …
The Osi Network Management Model - Capacity And Performance Management, Chompu Nuangjamnong, Stanislaw P. Maj, David Veal
The Osi Network Management Model - Capacity And Performance Management, Chompu Nuangjamnong, Stanislaw P. Maj, David Veal
Research outputs pre 2011
With the rapid growth of large enterprise networks, capacity and performance management issues are becoming increasingly important to both business organizations and the telecommunication industry. Capacity and performance management techniques and methods provide guidance on how to plan, justify and manage network resources. Inappropriate planning for capacity and performance may lead to wasted resources resulting in unnecessary cost, or lack of resources resulting in poor network performance or even the unavailability of IT services. Moreover, it is not uncommon for networks to be equipped with devices from different vendors which potentially add to complexity. Resource management may be assisted by …
Tunable True-Time Delay Unit Based On Opto-Vlsi Processing, Feng Xiao, Budi Juswardy, Kamal Alameh
Tunable True-Time Delay Unit Based On Opto-Vlsi Processing, Feng Xiao, Budi Juswardy, Kamal Alameh
Research outputs pre 2011
A novel tunable true-time delay unit is proposed and demonstrated. The unit is based on the use of an Opto-VLSI processor that dynamically selects a single waveband or multiple wavebands from an RF-modulated broadband optical signal and routes them to a high-dispersion fiber for arbitrary time delay synthesis. Experimental results demonstrate continuously tunable time delay of up to 4 ns.