Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons

Open Access. Powered by Scholars. Published by Universities.®

2007

Discipline
Institution
Keyword
Publication
Publication Type
File Type

Articles 31 - 60 of 1355

Full-Text Articles in Computer Sciences

Teaching Php With Security In Mind, Greg Baatard Dec 2007

Teaching Php With Security In Mind, Greg Baatard

Australian Information Security Management Conference

The PHP server-side scripting language has found significant popularity due to its accessibility, simplicity and affordability. With the deployment of PHP-inclusive web development environments becoming easier, universities have begun to offer units of study in the language. However, students coming from a background of HTML-based web development will often not be adequately prepared to consider the security implications associated with a powerful scripting language. It is important that students are taught to recognise and respond to the security implications of their code from an early stage, as a matter of good programming practice. This paper demonstrates how security teachings can …


A Comprehensive Firewall Testing Methodology, Murray Brand Dec 2007

A Comprehensive Firewall Testing Methodology, Murray Brand

Australian Information Security Management Conference

This paper proposes an all encompassing test methodology for firewalls. It extends the life cycle model to revisit the major phases of the life cycle after a firewall is in service as foundations for the tests. The focus of the tests is to show that the firewall is, or isn’t, still fit for purpose. It also focuses on the traceability between business requirements through to policy, rule sets, physical design, implementation, egress and ingress testing, monitoring and auditing. The guidelines are provided by a Test and Evaluation Master Plan (TEMP). The methodology is very much process driven and in keeping …


Increasing Security In The Physical Layer Of Wireless Communication, Luke Golygowski Dec 2007

Increasing Security In The Physical Layer Of Wireless Communication, Luke Golygowski

Australian Information Security Management Conference

This paper introduces a concept of increasing securing in the Physical layer (PHY) of wireless communication. It gives a short description of current status of wireless standards and their security. Despite the existence of advanced security protocols such as IEEE 802.11i or WLAN VPNs, wireless networks still remain vulnerable to denial-of-service (DoS) attacks aiming at PHY and Data Link Layers. The new solution challenges the problems with the currently defined PHY and Data Link layers. The concept introduced here, holds a promise of descending with some of the security measures to the lower layers of the TCP/IP and in this …


The Importance Of Human Factors When Assessing Outsourcing Security Risks, Carl Colwill, Andy Jones Dec 2007

The Importance Of Human Factors When Assessing Outsourcing Security Risks, Carl Colwill, Andy Jones

Australian Information Security Management Conference

The word is becoming increasingly interconnected and ways of doing business are evolving rapidly. Communications technology is ubiquitous and reliable and businesses are continuously seeking ways in which systems can be exploited to improve resilience, become more efficient and reduce costs. One way in which organisations seek to achieve this is by concentrating their efforts on core business processes and outsourcing non-core functions. However, outsourcing - and particularly offshoring - presents many security issues that must be considered throughout the lifetime of contracts. The scale of outsourcing and increasing technological and security complexity is making this task more difficult. Often …


The Need For An Investigation Into Possible Security Threats Associated With Sql Based Emr Software, Lee Heinke Dec 2007

The Need For An Investigation Into Possible Security Threats Associated With Sql Based Emr Software, Lee Heinke

Australian Information Security Management Conference

An increasing amount of E-health software packages are being bundled with Standard Query Language (SQL) databases as a means of storing Electronic Medical Records (EMR’s). These databases allow medical practitioners to store, change and maintain large volumes of patient information. The software that utilizes these databases pulls data directly from fields within the database based on standardized query statements. These query statements use the same methods as web-based applications to dynamically pull data from the database so it can be manipulated by the Graphical User Interface (GUI). This paper proposes a study for an investigation into the susceptibility of popular …


Securing Voip: A Framework To Mitigate Or Manage Risks, Peter James, Andrew Woodward Dec 2007

Securing Voip: A Framework To Mitigate Or Manage Risks, Peter James, Andrew Woodward

Australian Information Security Management Conference

In Australia, the past few years have seen Voice over IP (VoIP) move from a niche communications medium used by organisations with the appropriate infrastructure and capabilities to a technology that is available to any one with a good broadband connection. Driven by low cost and no cost phone calls, easy to use VoIP clients and increasingly reliable connections, VoIP is replacing the Public Switch Telephone Network (PSTN) in a growing number of households. VoIP adoption appears to be following a similar path to early Internet adoption, namely little awareness by users of the security implications. Lack of concern about …


How Safe Is Azeroth, Or, Are Mmorpgs A Security Risk?, An Hilven, Andrew Woodward Dec 2007

How Safe Is Azeroth, Or, Are Mmorpgs A Security Risk?, An Hilven, Andrew Woodward

Australian Information Security Management Conference

Massive Multiplayer Online Role Playing Games (MMORPGs) are at a basic level a networked application. Blizzard’s World of Warcraft is currently the largest example of such a type of application, with over nine million subscribers at last count. Whilst the idea of researching a game for network security may sound trivial, nine million potential backdoors into home and business computers is not. The ports used by the game, as well as authentication methods and client update programs were examined using packet analysis software. No obvious vulnerabilities were discovered as a result of this analysis. In addition to this analysis, an …


The Need For A Security/Privacy Model For The Health Sector In Ghana, James Tetteh Ami-Narh, Patricia A. Williams Dec 2007

The Need For A Security/Privacy Model For The Health Sector In Ghana, James Tetteh Ami-Narh, Patricia A. Williams

Australian Information Security Management Conference

Many developing countries around the world are faced with the dilemma “brain-drain” as their healthcare professionals seek better economic opportunities in other countries. This problem is compounded by a lack of robust healthcare infrastructure requiring substantive improvements to bring them up to date. This impacts a countries ability to understand morbidity and mortality patterns which impact health care policy and program planning. The lack of IT infrastructure also negatively affects the safety, quality, and efficiency of health care delivery in these countries. Ghana is faced with this precise set of circumstances as it struggles to adopt policies to overcome these …


Intrusion Detection System (Ids) Techniques And Responses For Mobile Wireless Networks, Krishnun Sansurooah Dec 2007

Intrusion Detection System (Ids) Techniques And Responses For Mobile Wireless Networks, Krishnun Sansurooah

Australian Information Security Management Conference

In recent years, the rapidly expanding area of mobile and wireless computing applications was definitely redefined the concept of network security. Even though that wireless had opened a new and exiting world with its advancing technology it is no doubt that it is popularity is on the rise. However, the biggest concern with either wireless or mobile computing applications in security. It can no longer be effective in the traditional way of securing networks with the use of firewalls and even with the use of stronger encryption algorithm keys. The need to develop and research for new structures and methods …


An Investigation Into The Usability Of Graphical Authentication Using Authentigraph, Paul Minne, Jason Wells, Damien Hutchinson, Justin Pierce Dec 2007

An Investigation Into The Usability Of Graphical Authentication Using Authentigraph, Paul Minne, Jason Wells, Damien Hutchinson, Justin Pierce

Australian Information Security Management Conference

There is increasing coverage in the literature relating to the different facets surrounding the security service of authentication, but there is a need for further research into the usability of graphical authentication. Specifically, the usability and viability of graphical authentication techniques for providing increased security needs to be further explored. There is a significant amount of evidence relating to traditional authentication techniques which highlight the fact that as technological advances grip modern societies, the requirement for more advanced authentication and security approaches increases. The exponential growth in the number of people using the Internet carries with it the high potential …


Medical Identity Theft – Not Feeling Like Yourself?, Darren Webb Dec 2007

Medical Identity Theft – Not Feeling Like Yourself?, Darren Webb

Australian Information Security Management Conference

Hospital and general practice healthcare providers today rely heavily on the information and communication technologies they employ to provide access to patient and associated data. The continuing migration to wireless means of data transfer has afforded system users more convenient and timely access to information via the use of 802.11 based wireless network capable devices. Through the increased digital connectivity of these internet and wireless based networks, new avenues of criminal activity such as medical identity theft have been steadily increasing as malicious individuals and organisations seek to abuse the digital ubiquity of the electronic medical record. The increased need …


The Impact Of Security Surveys Within Australia And New Zealand, Matthew J. Warren, Shona Leitch Dec 2007

The Impact Of Security Surveys Within Australia And New Zealand, Matthew J. Warren, Shona Leitch

Australian Information Security Management Conference

Information security is portrayed as a global problem that impacts all countries that are considered as part of the Information Society. Recent surveys show that there are increased concerns about computer crime. The paper will focus upon recent national security surveys from Australia and New Zealand and the trends that this research shows. Is it fair to assume the security practices are the same all over the world? The paper looks at security practices from a number of different countries perspectives and shows that security practices are not generic and vary from country to country. The paper will also evaluate …


Goal-Oriented Job Scheduling For Parallel Computer Systems, Sangsuree Vasupongayya Dec 2007

Goal-Oriented Job Scheduling For Parallel Computer Systems, Sangsuree Vasupongayya

Dissertations and Theses

System administrators for parallel computers face many difficulties when managing job scheduling systems. First, current production job schedulers use many parameters, which seem flexible but it is highly challenging to configure and tune these parameters. Second, fair share is an important scheduling goal, but it is not clear what kind of fair share can be expected under current schedulers and how fair share impacts scheduling performance. Third, several job runtime prediction methods were proposed to improve inaccurate user-estimated runtimes, but these methods could under-estimate runtimes by a large amount and it is not clear whether they are practical for use …


Virtual Radicalisation: Challenges For Police, Simon O'Rourke Dec 2007

Virtual Radicalisation: Challenges For Police, Simon O'Rourke

Australian Information Warfare and Security Conference

Recent advances in communications technology are providing a medium for individuals or groups to subscribe to extremist worldviews and form networks, access training and obtain information, whilst remaining virtually undetected in the online world. Whilst the Internet is facilitating global virtual communities like Second Life, MySpace and Facebook it is also providing an anonymous meeting place for disenfranchised individuals to gather, share ideas, post and exchange information regarding their particular ideology. This virtual community provides a sense of belonging to a global cause in which the actions of an individual can be aligned to, and seen to contribute towards something …


Critical Infrastructure Systems Modelling: Benchmarking Cpntools, Graeme Pye, Matthew J. Warren Dec 2007

Critical Infrastructure Systems Modelling: Benchmarking Cpntools, Graeme Pye, Matthew J. Warren

Australian Information Warfare and Security Conference

This paper reports on the application of systems modelling benchmarks to determine the viability of systems modelling software and its suitability for modelling critical infrastructure systems. This research applies the earlier research that related to developing benchmarks that when applied to systems modelling software will indicate its likely suitability to modelling critical infrastructure systems. In this context, the systems modeling benchmarks will assess the practicality of CPNTools to the task of modelling critical infrastructure systems.


Managing Analysis, David Shaw Dec 2007

Managing Analysis, David Shaw

Australian Information Warfare and Security Conference

The Intelligence profession requires effective management to function properly and professional discourse highlights the changing nature of intelligence work. Highlighted “failures” are linked to organizational structures and ethos, and proposals to address the problems include discussion of human and organizational factors with recommendations that address the issues. However, optimising the intelligence process may not be a simple case of applying management techniques as the work relies substantially on individual endeavour. Innovative management techniques are needed and these should be grounded in recognising the peculiar nature of analysis and the skill set required.


Commercial Critical Systems And Critical Infrastructure Protection: A Future Research Agenda, Matthew J. Warren, Shona Leitch Dec 2007

Commercial Critical Systems And Critical Infrastructure Protection: A Future Research Agenda, Matthew J. Warren, Shona Leitch

Australian Information Warfare and Security Conference

Secure management of Australia’s commercial critical infrastructure presents ongoing challenges to owners and the government. Although it is currently managed through high-level information sharing via collaboration, but does this suit the commercial sector. One of the issues facing Australia is that the majority of critical infrastructure resides under the control of the business sector and certain aspects such of the critical infrastructure such as Supply Chain Management (SCM) systems are distributed entities and not a single entity. The paper focuses upon the security issues associated with SCM systems and critical infrastructure protection


Space As A New Sphere Of Future Information Warfare, Martti Lehto Dec 2007

Space As A New Sphere Of Future Information Warfare, Martti Lehto

Australian Information Warfare and Security Conference

Air power has seen constant development from the Wright Flyer’s first flight at Kitty Hawk on December 17, 1903 via the advent of the jet age with the service entry of the Messerschmitt Me 262 in 1942, to today’s multirole fighters (F-35 Joint Strike Fighter) and stealth aircraft (B-2 Spirit multi-role bomber). As a result of this evolution of one hundred years air power has emerged as a central component in power projection. As General William Mitchell said: ”Neither armies nor navies can exist unless the air is controlled over them.” (Mitchell 1925, xv)We have witnessed a corresponding development in …


Automatically Extract Information From Web Documents, Dipesh Sharma Dec 2007

Automatically Extract Information From Web Documents, Dipesh Sharma

Masters Theses & Specialist Projects

The Internet could be considered to be a reservoir of useful information in textual form — product catalogs, airline schedules, stock market quotations, weather forecast etc. There has been much interest in building systems that gather such information on a user's behalf. But because these information resources are formatted differently, mechanically extracting their content is difficult. Systems using such resources typically use hand-coded wrappers, customized procedures for information extraction. Structured data objects are a very important type of information on the Web. Such data objects are often records from underlying databases and displayed in Web pages with some fixed templates. …


Enlightened Computing: An Architecture For Co-Allocating Network, Compute, And Other Grid Resources For High-End Applications, Lina Battestilli, Andrei Hutanut, Gigi Karmous-Edwards, Daniel S. Katz, Jon Maclarent, Joe Mambretti, John H. Moore, Seung Jong Park, Harry G. Perros, Syam Sundar, Savera Tanwir, Steven R. Thorpe, Yufeng Xin Dec 2007

Enlightened Computing: An Architecture For Co-Allocating Network, Compute, And Other Grid Resources For High-End Applications, Lina Battestilli, Andrei Hutanut, Gigi Karmous-Edwards, Daniel S. Katz, Jon Maclarent, Joe Mambretti, John H. Moore, Seung Jong Park, Harry G. Perros, Syam Sundar, Savera Tanwir, Steven R. Thorpe, Yufeng Xin

Computer Science Faculty Research & Creative Works

Many emerging high-performance applications require distributed infrastructure that is significantly more powerful and flexible than traditional Grids. Such applications require the optimization, close integration, and control of all Grid resources, including networks. The EnLIGHTened (ENL) Computing Project has designed an architectural framework that allows Grid applications to dynamically request (in-advance or on-demand) any type of Grid resource: computers, storage, instruments, and deterministic, high-bandwidth network paths, including lightpaths. Based on application requirements, the ENL middleware communicates with Grid resource managers and, when availability is verified, co-allocates all the necessary resources. ENL's Domain Network Manager controls all network resource allocations to dynamically …


A General Boosting Method And Its Application To Learning Ranking Functions For Web Search, Zhaohui Zheng, Hongyuan Zha, Tong Zhang, Olivier Chapelle, Keke Chen, Gordon Sun Dec 2007

A General Boosting Method And Its Application To Learning Ranking Functions For Web Search, Zhaohui Zheng, Hongyuan Zha, Tong Zhang, Olivier Chapelle, Keke Chen, Gordon Sun

Kno.e.sis Publications

We present a general boosting method extending functional gradient boosting to optimize complex loss functions that are encountered in many machine learning problems. Our approach is based on optimization of quadratic upper bounds of the loss functions which allows us to present a rigorous convergence analysis of the algorithm. More importantly, this general framework enables us to use a standard regression base learner such as decision trees for fitting any loss function. We illustrate an application of the proposed method in learning ranking functions for Web search by combining both preference data and labeled data for training. We present experimental …


Markov-Based Lane Positioning Using Intervehicle Communication, Thanh-Son Dao, Keith Yu Kit Leung, Christopher M. Clark, Jan Paul Huissoon Dec 2007

Markov-Based Lane Positioning Using Intervehicle Communication, Thanh-Son Dao, Keith Yu Kit Leung, Christopher M. Clark, Jan Paul Huissoon

Computer Science and Software Engineering

The majority of today's navigation techniques for intelligent transportation systems use global positioning systems (GPS) that can provide position information with bounded errors. However, due to the low accuracy that is experienced with standard GPS, it is difficult to determine a vehicle's position at lane level. Using a Markov-based approach based on sharing information among a group of vehicles that are traveling within communication range, the lane positions of vehicles can be found. The algorithm's effectiveness is shown in both simulations and experiments with real data.


Research Issues And Overview Of Economic Models In Mobile-P2p Networks, Anirban Mondal, Sanjay Kumar Madria, Masaru Kitsuregawa Dec 2007

Research Issues And Overview Of Economic Models In Mobile-P2p Networks, Anirban Mondal, Sanjay Kumar Madria, Masaru Kitsuregawa

Computer Science Faculty Research & Creative Works

The mobile-P2P paradigm is becoming increasingly popular. Existing mobile-P2P solutions largely do not consider economic incentive models for enticing peer participation without eliminating free-riders and for effectively handling mobile resource constraints such as energy. This paper presents an executive summary of the existing solutions and an overview of some of the important issues for handling problems in mobile-P2P networks using economic models. We also present our perspectives on building 'real' mobile-P2P applications using economic models. © 2007 IEEE.


An Integrated Social Actor And Service Oriented Architecture (Soa) Approach For Improved Electronic Health Record (Ehr) Privacy And Confidentiality In The Us National Healthcare Information Network (Nhin), Gondy Leroy, Elliot Sloane, Steven Sheetz Dec 2007

An Integrated Social Actor And Service Oriented Architecture (Soa) Approach For Improved Electronic Health Record (Ehr) Privacy And Confidentiality In The Us National Healthcare Information Network (Nhin), Gondy Leroy, Elliot Sloane, Steven Sheetz

CGU Faculty Publications and Research

The emerging US National Healthcare Information Network (NHIN) will improve healthcare’s efficacy, efficiency, and safety. The first-generation NHIN being developed has numerous advantages and limitations. One of the most difficult aspects of today’s NHIN is ensuring privacy and confidentiality for personal health data, because family and caregivers have multiple complex legal relationships to a patient. A Social Actor framework is suggested to organize and manage these legal roles, but the Social Actor framework would be very difficult to implement in today’s NHIN. Social Actor Security Management could, however, be effectively implemented using Service Oriented Architectures (SOAs), which are rapidly becoming …


Video On The Semantic Sensor Web, Cory Andrew Henson, Amit P. Sheth, Prateek Jain, Josh Pschorr, Terry Rapoch Dec 2007

Video On The Semantic Sensor Web, Cory Andrew Henson, Amit P. Sheth, Prateek Jain, Josh Pschorr, Terry Rapoch

Kno.e.sis Publications

Millions of sensors around the globe currently collect avalanches of data about our world. The rapid development and deployment of sensor technology is intensifying the existing problem of too much data and not enough knowledge. With a view to alleviating this glut, we propose that sensor data, especially video sensor data, can be annotated with semantic metadata to provide contextual information about videos on the Web. In particular, we present an approach to annotating video sensor data with spatial, temporal, and thematic semantic metadata. This technique builds on current standardization efforts within the W3C and Open Geospatial Consortium (OGC) and …


Time-Adaptive Numerical Simulation For High Speed Networks, Suman Kumar, Seung Jong Park, S. Sitharama Iyengar, Jung Han Kimn Dec 2007

Time-Adaptive Numerical Simulation For High Speed Networks, Suman Kumar, Seung Jong Park, S. Sitharama Iyengar, Jung Han Kimn

Computer Science Faculty Research & Creative Works

As the bandwidth of networks is increasing exponentially, the computational cost to simulate such type of networks is also growing in a similar fashion. This paper presents a scalable simulation method, called time-adaptive numerical simulation, which can be used to represent dynamics of high-speed networks using fluid-based models. The new method dynamically adjusts the size of a time step for a numerical solver which solves a system of differential equations representing dynamics of protocols and nodes' behaviors. The simulation results show that the time-adaptive-method reduces the computational time while achieving the same accuracy compared to that of a fixed step-size …


Unfolding Polyhedra Via Cut-Tree Truncation, Alex Benton, Joseph O'Rourke Dec 2007

Unfolding Polyhedra Via Cut-Tree Truncation, Alex Benton, Joseph O'Rourke

Computer Science: Faculty Publications

We prove that an infinite class of convex polyhedra, produced by restricted vertex truncations, always unfold without overlap. The class includes the "domes," providing a simpler proof that these unfold without overlap.


The Slider-Pinning Problem, Audrey Lee, Ileana Streinu, Louis Theran Dec 2007

The Slider-Pinning Problem, Audrey Lee, Ileana Streinu, Louis Theran

Computer Science: Faculty Publications

A Laman mechanism is a flexible planar bar-and-joint framework with m ≤ 2n-3 edges and exactly k = 2n-m degrees of freedom. The slider-pinning problem is to eliminate all the degrees of freedom of a Laman mechanism, in an optimal fashion, by individually fixing x or y coordinates of vertices. We describe two easy to implement O(n2) time algorithms.


What Is Rcu, Fundamentally?, Paul E. Mckenney, Jonathan Walpole Dec 2007

What Is Rcu, Fundamentally?, Paul E. Mckenney, Jonathan Walpole

Computer Science Faculty Publications and Presentations

Read-copy update (RCU) is a synchronization mechanism that was added to the Linux kernel in October of 2002. RCU achieves scalability improvements by allowing reads to occur concurrently with updates. In contrast with conventional locking primitives that ensure mutual exclusion among concurrent threads regardless of whether they be readers or updaters, or with reader-writer locks that allow concurrent reads but not in the presence of updates, RCU supports concurrency between a single updater and multiple readers. RCU ensures that reads are coherent by maintaining multiple versions of objects and ensuring that they are not freed up until all pre-existing read-side …


Stochastic Models For In-Silico Event-Based Biological Network Simulation, Preetam Ghosh Dec 2007

Stochastic Models For In-Silico Event-Based Biological Network Simulation, Preetam Ghosh

Computer Science and Engineering Dissertations - Archive

The multi-scale biological system model is a new research direction to capture the dynamic measurements of complex biological systems. The current statistical thermodynamic models can not scale to this challenge due to the explosion of state-spaces of the system, where a biological organ may have billions of cells, each with millions of molecule types and each type may have a few million molecules. We seek to propose a phenomenological theory that will require a smaller number of state variables to address this multi-scaling problem. Discrete Markov statistical process is used to understand the system dynamics in the networking community for …