Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons™

Open Access. Powered by Scholars. Published by Universities.®

2008

Discipline
Institution
Keyword
Publication
Publication Type
File Type

Articles 841 - 870 of 1335

Full-Text Articles in Computer Sciences

Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver Jan 2008

Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver

Australian Information Security Management Conference

This paper proposes to address the need for more innovation in organisational information security by adding a security requirement engineering focus. Based on the belief that any heavyweight security requirements process in organisational security will be doomed to fail, we developed a security requirement approach with three dimensions. The use of a simple security requirements process in the first dimension has been augmented by an agile security approach. However, introducing this second dimension of agile security does provide support for, but does not necessarily stimulate, innovation. A third dimension is, therefore, needed to ensure there is a proper focus in …


Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce Jan 2008

Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce

Australian Information Security Management Conference

There is increasing coverage in the literature highlighting threats to online financial systems. Attacks range from the prevalent reverse social engineering technique known as phishing; where spam emails are sent to customers with links to fake websites, to Trojans that monitor a customer’s account log on process that captures authentication details that are later replayed for financial gain. This ultimately results in loss of monetary funds for affected victims. As technological advances continue to influence the way society makes payment for goods and services, the requirement for more advanced security approaches for transaction verification in the online environment increases. This …


Rfid Communications - Who Is Listening?, Christopher Bolan Jan 2008

Rfid Communications - Who Is Listening?, Christopher Bolan

Australian Information Security Management Conference

Radio Frequency Identification (RFID) is seeing a surge in awareness across a range of industries as a successor to barcoding. The nature of this technology promises a wide range of benefits but it appears to be at the expense of security. This paper investigates an eavesdropping attack against an EPC RFID system and shows how a simple device may be used to record interactions between both Tag and Readers. The device is used to record and decode signals within range and its output is analysed to verify that the attack was indeed successful. The findings verify previous assertions by other …


Secure Portable Execution Environments: A Review Of Available Technologies, Peter James Jan 2008

Secure Portable Execution Environments: A Review Of Available Technologies, Peter James

Australian Information Security Management Conference

Live operating systems and virtualisation allow a known, defined, safe and secure execution environment to be loaded in to a PC’s memory and executed with either minimal or possibly no reliance on the PC’s internal hard disk drive. The ability to boot a live operating system or load a virtual environment (containing an operating system) from a USB storage device allows a secure portable execution environment to be created. Portable execution environments have typically been used by technologists, for example to recover data from a failing PC internal hard disk drive or to perform forensic analysis. However, with the commercial …


Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew Jan 2008

Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew

Australian Information Security Management Conference

In an environment where technical solutions for securing networked systems are commonplace, there still exist problems in implementation of such solutions for home and small business users. One component of this protection is the use of intrusion detection systems. Intrusion detection monitors network traffic for suspicious activity, performs access blocking and alerts the system administrator or user of potential attacks. This paper reviews the basic function of intrusion detection systems and maps them to an existing end-user capability framework. Using this framework, implementation guidance and systematic improvement in implementation of this security measure are defined.


Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong Jan 2008

Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong

Australian Information Security Management Conference

Video over IP (VIP) is becoming a tool of communication in corporate environments to reduce the time spent conducting meetings face-to-face. This has been driven by efficiencies of time saving, management’s monitoring of staff and to communicate with flexibilities - without placing additional disadvantages on employees who must regularly attend personal meetings amongst hectic business schedules. With technology excelling beyond the old telegraphy of analogy video over hard copper wire to dark fibre technology, VIP is a technology that is starting to receive more attention in the corporate world as more organisations have the equipment to support this additional plug-in. …


Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke Jan 2008

Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke

Australian Information Security Management Conference

The current security on mobile devices is often limited to the Personal Identification Number (PIN), a secretknowledge based technique that has historically demonstrated to provide ineffective protection from misuse. Unfortunately, with the increasing capabilities of mobile devices, such as online banking and shopping, the need for more effective protection is imperative. This study proposes the use of two-factor authentication as an enhanced technique for authentication on a Smartphone. Through utilising secret-knowledge and keystroke analysis, it is proposed a stronger more robust mechanism will exist. Whilst keystroke analysis using mobile devices have been proven effective in experimental studies, these studies have …


Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari Jan 2008

Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari

Australian Information Security Management Conference

This paper presents a critique of emergent views on the roles of the boards of directors in relation to information security. The analysis highlights several concerns about the separation and validation of proper theory and business assertions of information security at board level. New requirements articulated by industry bodies – represented by a selected group of experts and evident in literature – are compared to the underlying theory of corporate governance to identify possible discrepancies. The discussion shows in particular the importance of staying within the theoretical underpinnings of corporate governance when discussing the topic of governance in general and …


Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones Jan 2008

Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones

Australian Information Security Management Conference

Smartphones face the same threats as traditional computers. As long as a device has the capabilities to perform logic processing, the threat of running malicious logic exists. The only difference between security threats on traditional computers versus security threats on smartphones is the challenge to understand the inner workings of the operating system on different hardware processor architectures. To improve upon the security of smartphones, anomaly detection capabilities can be implemented at different functional layers of a smartphone in a coherent manner; instead of just looking at individual functional layers. This paper will focus on identifying conceptual points for measuring …


Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao Jan 2008

Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao

Australian Information Security Management Conference

The prepaid card market in Australia is growing rapidly. Its features not only attract customers from all sorts of backgrounds but also expose it to numerous risks. Using the methodology of the Australian Risk Management Standard AS/NZS4360, this paper looks at the risks inherent in prepaid cards. Concentrating on two major risks, the paper details the regulations governing the industry in the USA as well the technical controls employed by the credit/debit card industry. We suggest risk mitigation strategies from these two view-points, aiming to become an important reference both for industry as it adopts better risk mitigation techniques, and …


Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong Jan 2008

Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong

Australian Information Security Management Conference

During a denial of service attack, it is difficult for a firewall to differentiate legitimate packets from rogue packets, particularly in large networks carrying substantial levels of traffic. Large networks commonly use network intrusion detection systems to identify such attacks, however new viruses and worms can escape detection until their signatures are known and classified as an attack. Commonly used IDS are rule based and static, and produce a high number of false positive alerts. The aim of this research was to determine if it is possible for a firewall to analyse its own traffic patterns to identify attempted denial …


Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward Jan 2008

Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward

Australian Information Security Management Conference

In the arena of wireless security, EAP-TLS is considered one of the most secure protocols. However since its inception the uptake has been poor and the investigation into the reasons for this are sparse. There is an industry perception that EAP-TLS is complex as well as difficult to configure and manage. One of the major barriers is in the use of public key infrastructure and the perceived difficulties in its application. The paper discusses why it is seemingly difficult to implement and how this may differ from the reality of its implementation. This premise is investigated using Windows Server 2003 …


Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward Jan 2008

Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward

Australian Information Security Management Conference

In the world of online gaming, information is exchanged as a matter of course. What information is exchanged behind the scenes is something that is not obvious to the casual user. People who play these games trust that the applications they are using are securely written and in this case, communicate securely. This paper looks at the traffic that is transmitted by the game Team Fortress 2 and incidentally the supporting authentication traffic of the Steam network. It was discovered through packet analysis that there is quite a lot of information which should be kept private being broadcast in the …


Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli Jan 2008

Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli

Australian Information Security Management Conference

Primary care medical practices in Australia have been identified as a profession in need of assistance with information security practices. Whilst guidelines exist, there is little assistance in an accessible and easily implemented form for medical practices. This research presents the preliminary findings of a study which advocates that information security practices can be improved using a capability operational framework which is contextualised to its target environment.


System And Process For Providing Auxiliary Information For A Packet-Switched Network Of Shared Nodes Using Dedicated Associative Store, Kenneth L. Calver, James N. Griffieon Jan 2008

System And Process For Providing Auxiliary Information For A Packet-Switched Network Of Shared Nodes Using Dedicated Associative Store, Kenneth L. Calver, James N. Griffieon

Computer Science Faculty Patents

A system and process for providing auxiliary information about a distributed network of shared nodes, at least a plurality of the nodes being adapted for receiving at least one type of ESP-(associative ephemeral store processing) packet. Available for access at each of the plurality of ESP-adapted nodes is a dedicated associative store wherein a value, if bound to a tag, is only accessible as a bound (tag, value) pair for a short time period, τ. Different types of packets are contemplated for routing through the ESP-capable plurality of nodes such as those arbitrarily identified herein as a ‘first’ and ‘second’ …


Wireless Authentication Using Remote Passwords, Andrew S. Harding Jan 2008

Wireless Authentication Using Remote Passwords, Andrew S. Harding

Theses and Dissertations

Current authentication methods for wireless networks are difficult to maintain. They often rely on globally shared secrets or heavyweight public-key infrastructure. Wireless Authentication using Remote Passwords (WARP) mitigates authentication woes by providing usable mechanisms for both administrators and end-users. Administrators grant access by simply adding users' personal messaging identifiers (e.g., email addresses, IM handles, cell phone numbers) to an access control list. There is no need to store passwords or other account information. Users simply prove ownership of their authorized identifier to obtain wireless access.


The Online Transportation Problem: On The Exponential Boost Of One Extra Server, Christine Chung, Patchrawat Uthaisombut, Kirk Pruhs Jan 2008

The Online Transportation Problem: On The Exponential Boost Of One Extra Server, Christine Chung, Patchrawat Uthaisombut, Kirk Pruhs

Computer Science Faculty Publications

No abstract provided.


The Price Of Stochastic Anarchy, Christine Chung, Katrina Ligett, Kirk Pruhs, Aaron Roth Jan 2008

The Price Of Stochastic Anarchy, Christine Chung, Katrina Ligett, Kirk Pruhs, Aaron Roth

Computer Science Faculty Publications

No abstract provided.


Dynamic Web Tools For Trigonometry, Steven J. Wilson Jan 2008

Dynamic Web Tools For Trigonometry, Steven J. Wilson

Innovations in Math Technology

In the last 20 years, computer technology having mathematical capability has been developed, improved, and become widely available, but textbook presentations are still largely free of any discussion that might require technology. Technology could be used in mathematical instruction for student drill and practice, for instructor demonstrations that promote conceptual understanding, or for the exploration of mathematical ideas, but software is often designed to be pedagogically generic, leaving its use to the creativity of the instructor. Technological solutions for local machines can be quite extensive, but cost and time constraints then limit availability for student use. The internet has the …


Tr-2008007: Degeneration Of Structured Integer Matrices Modulo An Integer, Victor Y. Pan, Xinmao Wang Jan 2008

Tr-2008007: Degeneration Of Structured Integer Matrices Modulo An Integer, Victor Y. Pan, Xinmao Wang

Computer Science Technical Reports

No abstract provided.


Tr-2008008: Schur Aggregation For Linear Systems And Determinants, V. Y. Pan, D. Grady, B. Murphy, G. Qian, R. E. Rosholt, A. D. Ruslanov Jan 2008

Tr-2008008: Schur Aggregation For Linear Systems And Determinants, V. Y. Pan, D. Grady, B. Murphy, G. Qian, R. E. Rosholt, A. D. Ruslanov

Computer Science Technical Reports

No abstract provided.


A Primer On Spreadsheet Analytics, Thomas A. Grossman Jr. Jan 2008

A Primer On Spreadsheet Analytics, Thomas A. Grossman Jr.

Business Analytics and Information Systems

This paper provides guidance to an analyst who wants to extract insight from a spreadsheet model. It discusses the terminology of spreadsheet analytics, how to prepare a spreadsheet model for analysis, and a hierarchy of analytical techniques. These techniques include sensitivity analysis, tornado charts, and backsolving (or goal-seeking). This paper presents native-Excel approaches for automating these techniques, and discusses add-ins that are even more efficient. Spreadsheet optimization and spreadsheet Monte Carlo simulation are briefly discussed. The paper concludes by calling for empirical research, and describing desired features spreadsheet sensitivity analysis and spreadsheet optimization add-ins.


Quadrilateral Meshes With Bounded Minimum Angle, F. Betul Atalay, Suneeta Ramaswami, Dianna Xu Jan 2008

Quadrilateral Meshes With Bounded Minimum Angle, F. Betul Atalay, Suneeta Ramaswami, Dianna Xu

Computer Science Faculty Research and Scholarship

This paper presents an algorithm that utilizes a quadtree to construct a strictly convex quadrilateral mesh for a simple polygonal region in which no newly created angle is smaller than . This is the first known result, to the best of our knowledge, on quadrilateral mesh generation with a provable guarantee on the minimum angle.


Extracting, Representing And Mining Semantic Metadata From Text: Facilitating Knowledge Discovery In Biomedicine, Cartic Ramakrishnan Jan 2008

Extracting, Representing And Mining Semantic Metadata From Text: Facilitating Knowledge Discovery In Biomedicine, Cartic Ramakrishnan

Browse all Theses and Dissertations

The information access paradigm offered by most contemporary text information systems is a search-and-sift paradigm where users have to manually glean and aggregate relevant information from the large number of documents that are typically returned in response to keyword queries. Expecting the users to glean and aggregate information has lead to several inadequacies in these information systems. Owing to the size of many text databases, search-and-sift is a very tedious often requiring repeated keyword searches refining or generalizing queries terms. A more serious limitation arises from the lack of automated mechanisms to aggregate content across different documents to discover new …


Effective Progression Of Temporary Virtual Teams Over Time: A Pragmatic Investigation Towards The Development Of An Internal Structure To Support Knowledge Sharing, Jon F. Davis Jan 2008

Effective Progression Of Temporary Virtual Teams Over Time: A Pragmatic Investigation Towards The Development Of An Internal Structure To Support Knowledge Sharing, Jon F. Davis

Regis University Student Publications (comprehensive collection)

Enabled by communications and information technology, temporary virtual teams are able to utilize talent from anywhere in the globe to service customers, solve business problems, and provide unique educational experiences. Temporary virtual teams, however, face many challenges to their effectiveness. In particular, many challenges to effective communication and knowledge sharing exist. To be effective, methods intended to address the unique challenges presented in the temporary virtual team environment are needed. This paper presents practical methodologies that can be used towards the development of an internal structure to support knowledge sharing between temporary virtual teams.


Ontology Driven Semantic Provenance For Heterogeneous Bionomics Experimental Data, Satya S. Sahoo, Michael L. Raymer, Cory Andrew Henson, Amit P. Sheth, William S. York Jan 2008

Ontology Driven Semantic Provenance For Heterogeneous Bionomics Experimental Data, Satya S. Sahoo, Michael L. Raymer, Cory Andrew Henson, Amit P. Sheth, William S. York

Kno.e.sis Publications

Scientific experimental data generated by all the bionomic technologies is characterized by heterogeneity in its representation formats, constituents, and generation processes and, therefore, also in its usage. Using the proteomics domain we demonstrate the important role of provenance information o manage, interpret and analyze experimental data. We present a novel approach that employs an ontology as a knowledge model to automatically create semantic provenance information for high-throughput mass spectrometry (MS) data in the glycoproteomics domain. The Semantic Provenance Annotation of Data in protEomics (SPADE) implementation is based on the ProPreO ontology, a large-process ontology ( ~500 classes, 40 named relationships …


Enabling Synergy Between Psychology And Natural Language Processing For E-Government: Crime Reporting And Investigative Interview System, Alicia Iriberri '06, Chih Hao Ku '12, Gondy Leroy Jan 2008

Enabling Synergy Between Psychology And Natural Language Processing For E-Government: Crime Reporting And Investigative Interview System, Alicia Iriberri '06, Chih Hao Ku '12, Gondy Leroy

CGU Faculty Publications and Research

We are developing an automated crime reporting and investigative interview system. The system incorporates cognitive interview techniques to maximize witness memory recall, and information extraction technology to extract and annotate crime entities from witness narratives and interview responses. Evaluations of the IE components of the system show that it captures 70 to 77% of information from witness narratives with 93 to 100% precision. Our development goal is for the system to approximate progressively the performance effectiveness of a human investigative interviewer and to generate graphical visualizations of crime report information.


The Impact Of Directionality In Predications On Text Mining, Gondy Leroy, Marcelo Fiszman, Thomas C. Rindflesch Jan 2008

The Impact Of Directionality In Predications On Text Mining, Gondy Leroy, Marcelo Fiszman, Thomas C. Rindflesch

CGU Faculty Publications and Research

The number of publications in biomedicine is increasing enormously each year. To help researchers digest the information in these documents, text mining tools are being developed that present co-occurrence relations between concepts. Statistical measures are used to mine interesting subsets of relations. We demonstrate how directionality of these relations affects interestingness. Support and confidence, simple data mining statistics, are used as proxies for interestingness metrics. We first built a test bed of 126,404 directional relations extracted from biomedical abstracts, which we represent as graphs containing a central starting concept and 2 rings of associated relations. We manipulated directionality in four …


An Online Community For Teachers Of Children With Autism To Support, Observe, And Evaluate Communication Enabled With Smartphones, Gianluca De Leo, Gondy Leroy Jan 2008

An Online Community For Teachers Of Children With Autism To Support, Observe, And Evaluate Communication Enabled With Smartphones, Gianluca De Leo, Gondy Leroy

CGU Faculty Publications and Research

We are developing an online community for teachers of children diagnosed with autism spectrum disorder that will provide tools to share, analyze, and evaluate assisted communication. The data will be collected from software on smartphones that allows children to communicate with teachers using images. Since this is the first approach towards systematic data collection for children with ASD, we expect a significant impact on current teaching methods.


Making Primarily Professional Terms More Comprehensible To The Lay Audience, Sergey Goryachev, Qing Zeng-Treitler, Catherine Arnott Smith, Allen C. Browne, Guy Divita, Alla Keselman, Gondy Leroy, Rosa Figueroa Jan 2008

Making Primarily Professional Terms More Comprehensible To The Lay Audience, Sergey Goryachev, Qing Zeng-Treitler, Catherine Arnott Smith, Allen C. Browne, Guy Divita, Alla Keselman, Gondy Leroy, Rosa Figueroa

CGU Faculty Publications and Research

Certain texts, such as clinical reports and clinical trial records, are written by professionals for professionals while being increasingly accessed by lay people. To improve the comprehensibility of such documents to the lay audience, we conducted a pilot study to analyze terms used primarily by health professionals, and explore ways to make them more comprehensible to lay people.