Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (550)
- Computer Engineering (416)
- Databases and Information Systems (233)
- Social and Behavioral Sciences (193)
- Electrical and Computer Engineering (191)
-
- Information Security (142)
- Software Engineering (136)
- Life Sciences (93)
- Communication (77)
- Numerical Analysis and Scientific Computing (75)
- OS and Networks (74)
- Mathematics (72)
- Business (69)
- Law (68)
- Artificial Intelligence and Robotics (67)
- Graphics and Human Computer Interfaces (67)
- Computer Law (61)
- Bioinformatics (59)
- Communication Technology and New Media (57)
- Programming Languages and Compilers (53)
- Theory and Algorithms (52)
- Legal Studies (51)
- Forensic Science and Technology (49)
- Science and Technology Studies (47)
- Arts and Humanities (46)
- Other Computer Sciences (42)
- Statistics and Probability (42)
- Operations Research, Systems Engineering and Industrial Engineering (36)
- Institution
-
- Singapore Management University (310)
- Wright State University (226)
- TÜBİTAK (100)
- Edith Cowan University (78)
- Embry-Riddle Aeronautical University (62)
-
- University of Nebraska - Lincoln (62)
- San Jose State University (58)
- Missouri University of Science and Technology (49)
- University of Texas at El Paso (49)
- Old Dominion University (45)
- Air Force Institute of Technology (43)
- University of Nebraska at Omaha (39)
- University for Business and Technology in Kosovo (38)
- University of Texas at Arlington (33)
- City University of New York (CUNY) (31)
- University of Nevada, Las Vegas (31)
- Technological University Dublin (30)
- Brigham Young University (29)
- Marquette University (29)
- Dartmouth College (23)
- Washington University in St. Louis (23)
- California Polytechnic State University, San Luis Obispo (21)
- Smith College (20)
- Wayne State University (20)
- Utah State University (19)
- University of Central Florida (18)
- Clemson University (17)
- University of South Carolina (17)
- Portland State University (16)
- University of Arkansas, Fayetteville (16)
- Keyword
-
- Security (20)
- Privacy (19)
- Data mining (17)
- Data representation (15)
- Robert Hooke (15)
-
- Scientific imaging (15)
- Applied sciences (14)
- Cloud computing (14)
- Computer security (13)
- Twitter (13)
- Classification (11)
- College for Professional Studies (11)
- School of Computer & Information Science (11)
- Software engineering (11)
- Wireless sensor networks (11)
- Android (10)
- Clustering (10)
- Computer Science (10)
- Digital forensics (10)
- Optimization (10)
- Simulation (10)
- Visualization (10)
- Algorithms (8)
- Artificial intelligence (8)
- Cloud Computing (8)
- Uncertainty (8)
- [RSTDPub] (8)
- AHRC New York City (7)
- Answer set programming (7)
- Collaboration (7)
- Publication
-
- Research Collection School Of Computing and Information Systems (294)
- Computer Science & Engineering Syllabi (164)
- Theses and Dissertations (100)
- Turkish Journal of Electrical Engineering and Computer Sciences (100)
- Master's Projects (58)
-
- Journal of Digital Forensics, Security and Law (45)
- Kno.e.sis Publications (37)
- Computer Science Faculty Research & Creative Works (31)
- Research outputs 2012 (31)
- Computer Science Faculty Publications (28)
- Mathematics, Statistics and Computer Science Faculty Research and Publications (25)
- Electronic Theses and Dissertations (24)
- All Computer Science and Engineering Research (23)
- Computer Science and Engineering Theses - Archive (23)
- Computer Science Technical Reports (22)
- Departmental Technical Reports (CS) (22)
- Computer Science: Faculty Publications (20)
- The R Journal (20)
- Open Access Theses & Dissertations (16)
- USF Tampa Graduate Theses and Dissertations (16)
- Dissertations and Theses (15)
- Electrical and Computer Engineering Publications (15)
- School of Computing: Dissertations, Theses, and Student Research (15)
- CCAC Theses and Dissertations (14)
- Dissertations (14)
- School of Computing: Conference and Workshop Papers (14)
- UNLV Theses, Dissertations, Professional Papers, and Capstones (14)
- Annual ADFSL Conference on Digital Forensics, Security and Law (13)
- Australian Information Security Management Conference (13)
- Browse all Theses and Dissertations (13)
- Publication Type
- File Type
Articles 31 - 60 of 1947
Full-Text Articles in Computer Sciences
Visualizing Digital Collections At Archive-It, Michele C. Weigle, Michael L. Nelson
Visualizing Digital Collections At Archive-It, Michele C. Weigle, Michael L. Nelson
Computer Science Presentations
PDF of a powerpoint presentation from a Archive-It Partners Meeting in Annapolis, Maryland, December 3, 2012. Also available on Slideshare.
Representing Variable Source Credibility In Intelligence Analysis With Bayesian Networks, Ken Mcnaught, Peter Sutovsky
Representing Variable Source Credibility In Intelligence Analysis With Bayesian Networks, Ken Mcnaught, Peter Sutovsky
Australian Security and Intelligence Conference
Assessing the credibility of an evidential source is an important part of intelligence analysis, particularly where human intelligence is concerned. Furthermore, it is frequently necessary to combine multiple items of evidence with varying source credibilities. Bayesian networks provide a powerful probabilistic approach to the fusion of information and are increasingly being applied in a wide variety of settings. In this paper we explore their application to intelligence analysis and provide a simple example concerning a potential attack on an infrastructure target. Our main focus is on the representation of source credibility. While we do not advocate the routine use of …
The Intelligence Game: Assessing Delphi Groups And Structured Question Formats, Bonnie Wintle, Steven Mascaro, Fiona Fidler, Marissa Mcbride, Mark Burgman, Louisa Flander, Geoff Saw, Charles Twardy, Aidan Lyon, Brian Manning
The Intelligence Game: Assessing Delphi Groups And Structured Question Formats, Bonnie Wintle, Steven Mascaro, Fiona Fidler, Marissa Mcbride, Mark Burgman, Louisa Flander, Geoff Saw, Charles Twardy, Aidan Lyon, Brian Manning
Australian Security and Intelligence Conference
In 2010, the US Intelligence Advanced Research Projects Activity (IARPA) announced a 4-year forecasting “tournament”. Five collaborative research teams are attempting to outperform a baseline opinion pool in predicting hundreds of geopolitical, economic and military events. We are contributing to one of these teams by eliciting forecasts from Delphi-style groups in the US and Australia. We elicit probabilities of outcomes for 3-5 monthly questions, such as: Will Australia formally transfer uranium to India by 1 June 2012? Participants submit probabilities in a 3-step interval format, view those of others in their group, share, rate and discuss information, and then make …
Harms: Hierarchical Attack Representation Models For Network Security Analysis, Jin Hong, Dong-Seong Kim
Harms: Hierarchical Attack Representation Models For Network Security Analysis, Jin Hong, Dong-Seong Kim
Australian Information Security Management Conference
Attack models can be used to assess network security. Purely graph based attack representation models (e.g., attack graphs) have a state-space explosion problem. Purely tree-based models (e.g., attack trees) cannot capture the path information explicitly. Moreover, the complex relationship between the host and the vulnerability information in attack models create difficulty in adjusting to changes in the network, which is impractical for modern large and dynamic network systems. To deal with these issues, we propose hierarchical attack representation models (HARMs). The main idea is to use two-layer hierarchy to separate the network topology information (in the upper layer) from the …
The Reception, Incorporation And Employment Of Informatin Operations By The Australia Defence Force: 1990-2012, Jeff Malone
The Reception, Incorporation And Employment Of Informatin Operations By The Australia Defence Force: 1990-2012, Jeff Malone
Australian Information Warfare and Security Conference
The paper investigates the Australian Defence Force’s (ADF) approach – understood here as the reception, incorporation and operational employment – to military information operations (IO), from 1990 to 2012. The paper identifies key characteristics of the ADF’s approach to IO, and proposes explanatory factors to account for the specific form the ADF’s approach to IO has been manifested. The paper concludes with predictions regarding the future form of IO within the ADF, in the context of the increasing significance of social media, the upcoming 2013 Defence White Paper (WP13) and the US ‘pivot’ to the Asia-Pacific region. The paper is …
The 2012 Analysis Of Information Remaining On Computer Hard Disks Offered For Sale On The Second Hand Market In The Uae, Andy Jones, Thomas Martin, Mohammed Alzaabi
The 2012 Analysis Of Information Remaining On Computer Hard Disks Offered For Sale On The Second Hand Market In The Uae, Andy Jones, Thomas Martin, Mohammed Alzaabi
Australian Digital Forensics Conference
The growth in the use of computers in all aspects of our lives has continued to increase to the point where desktop, laptop, netbook or tablet computers are now almost essential in the way that we communicate and work. As a result of this, and the fact that these devices have a limited lifespan, enormous numbers of computers are being disposed of at the end of their useful life by individuals or/and organisations. As the cost of computing has reduced, the level of ‘consumerisation’ has increased together with the requirement for mobility. This has led to an increasing use of …
A Model Of Psychological Disengagement, Kira J. Harris
A Model Of Psychological Disengagement, Kira J. Harris
Australian Counter Terrorism Conference
This paper presents the preliminary findings of research into the disengagement from highly entitative and ideological social groups, such as one percent motorcycle clubs, military special forces and fundamental ideological groups. Using a grounded theory approach, the discourse of 25 former members identified the discrepancy between group membership and the self-concept as the core theme in the disengagement experience. This model presents the process of experiencing a threat, self-concept discrepancy and management, physical disengagement and the post-exit identity. The findings indicate a consistent experience of disengagement and allow further understanding to the factors influencing membership appraisal.
Cyberterrorism: Addressing The Challenges For Establishing An International Legal Framework, Krishna Prasad
Cyberterrorism: Addressing The Challenges For Establishing An International Legal Framework, Krishna Prasad
Australian Counter Terrorism Conference
The increase of international cyberterrorism in recent years has resulted in computer-based criminal activities that generate worldwide fear, destruction and disruption. National laws and policies that address cyberterrorism are mainly limited to developed nations and are not cohesive in managing 21st century cyberterrorism. Given the absence of an international legal framework to address cyberterrorism, authorities and governments around the world face extreme challenges in finding and prosecuting those responsible for cyberterrorism. This article argues for the need for a cohesive international legal framework; highlights key elements to establish an effective international legal framework; and identifies existing international treaties and cross-border …
Commitment And The 1% Motorcycle Club: Threats To The Brotherhood, Kira J. Harris
Commitment And The 1% Motorcycle Club: Threats To The Brotherhood, Kira J. Harris
Australian Counter Terrorism Conference
The brotherhood ethos is the founding principle of the 1% motorcycle clubs community. Interviews with former members and partners show how threatening this social bond can reduce satisfaction and lead to doubts over involvement with the club.
Boko Haram: Terrorist Organization, Freedom Fighters Or Religious Fanatics? An Analysis Of Boko Haram Within Nigeria, An Australian Perspective And The Need For Counter Terrorism Responses That Involves Prescribing Them As A Terrorist Organization., Gabrielle Blanquart
Australian Counter Terrorism Conference
The adoption of Sharia law and the creation of an Islamic government are prominent motivations for religious terrorism within the current climate. Throughout history, Nigeria has been exposed to ethno religious violence and political discontent and has recently seen an escalation in associated violence threatening its sovereignty, territorial integrity, peace and stability. This paper explores Boko Haram, a Nigerian Islamist sect, responsible for numerous attacks in northern and central Nigeria on infrastructure and people. The origins and ideological motivations of this group are examined and compared to the current wave of religious terrorism in relation to tactics, leadership and objectives. …
Al-Jihad Fi Sabilillah: In The Heart Of Green Birds, Robyn Torok
Al-Jihad Fi Sabilillah: In The Heart Of Green Birds, Robyn Torok
Australian Counter Terrorism Conference
With an increasing focus on lone-wolf operations, al-Qaeda is becoming increasingly focussed on its internet discourses and propaganda. One of its most significant discourses is the importance of jihad and martyrdom in carrying out a terrorist attack. This study looks at Facebook pages and profiles and examines the discourses presented in relation to jihad and martyrdom. Three important concepts including their justification are considered: Al-Jihad fi Sabilillah (just fight for the sake of Allah), Istishhad (operational heroism of loving death more than the West love life) and Shaheed (becoming a martyr). Results supported previous studies indicating the strong seductive nature …
Secure Key Deployment And Exchange Protocol For Manet Information Management, Brian Cusack, Alastair Nisbet
Secure Key Deployment And Exchange Protocol For Manet Information Management, Brian Cusack, Alastair Nisbet
Australian Digital Forensics Conference
Secure Key Deployment and Exchange Protocol (SKYE) is an innovative encryption Key Management Scheme (KMS) based on a combination of features from recent protocols combined with new features for Mobile Ad Hoc Networks (MANETs). The design focuses on a truly ad hoc networking environment where geographical size of the network, numbers of network members and mobility of the members is all unknown before deployment. This paper describes the process of development of the protocol and the application to system design to assure information security and potential evidential retention for forensic purposes. Threshold encryption key management is utilized and simulation results …
What Is The Proper Forensics Approach On Trojan Banking Malware Incidents?, Andri P. Heriyanto
What Is The Proper Forensics Approach On Trojan Banking Malware Incidents?, Andri P. Heriyanto
Australian Digital Forensics Conference
Digital forensics procedures should be developed to obtain digital evidence with regard to legal requirements such as admissibility, authenticity, completeness, reliability and believability. On the other hand, Trojan banking malware incident has grown significantly and creates a great threat to online banking users globally. This type of malware is known to use anti-forensic technique to avoid forensic detection. Moreover, there are numerous works and researches that impose the drawbacks on post-mortem forensics approach in dealing with evidence that only resided on non-persistence memory or non-volatile memory. There are works that reveal the disadvantage of live-response approach on incident response that …
The 2012 Investigation Into Remnant Data On Second Hand Memory Cards Sold In Australia, Patryk Szewczyk, Krishnun Sansurooah
The 2012 Investigation Into Remnant Data On Second Hand Memory Cards Sold In Australia, Patryk Szewczyk, Krishnun Sansurooah
Australian Digital Forensics Conference
This study investigates the remnant data on memory cards that were purchased through Australian second hand auctions sites in 2012. Memory cards are increasing in capacity and are commonly used amongst many consumer orientated electronic devices including mobile phones, tablet computers, cameras and multimedia devices. This study examined 78 second hand memory cards. The investigation shows that confidential data is present on many of the memory cards and that in many instances there is no evidence to suggest that the seller attempted to erase data. In many instances the sellers are asking the buyer to erase the data on the …
Defence In Depth, Protection In Depth And Security In Depth: A Comparative Analysis Towards A Common Usage Language, Michael Coole, Jeff Corkill, Andrew Woodward
Defence In Depth, Protection In Depth And Security In Depth: A Comparative Analysis Towards A Common Usage Language, Michael Coole, Jeff Corkill, Andrew Woodward
Australian Security and Intelligence Conference
A common language with consistency of meaning is a critical step in the evolution of a profession. Whilst the debate as to whether or not security should be considered a profession is ongoing there is no doubt that the wider community of professionals operating in the security domain are working towards achieving recognition of security as a profession. The concepts of defence in depth, protection in depth and security in depth have been used synonymously by different groups across the domain. These concepts represent the very foundation of effective security architecture are hierarchical in nature and have specific meaning. This …
Understanding The Vulnerabilities In Wi-Fi And The Impact On Its Use In Cctv Systems, Michael Coole, Andrew Woodward, Craig Valli
Understanding The Vulnerabilities In Wi-Fi And The Impact On Its Use In Cctv Systems, Michael Coole, Andrew Woodward, Craig Valli
Australian Security and Intelligence Conference
Modern surveillance devices are increasingly being taken off private networks and placed onto networks connected via gateway to the Internet or into Wi-Fi based local area wireless networks (LAWN). The devices are also increasingly using IPv4 and IPv6 network stacks and some form of embedded processing or compute built in. Additionally, some specialist devices are using assistive technologies such as GPS or A-GPS. This paper explored the issues with use of the technologies in a networked environment, both wireless and internetworked. Analysis of these systems shows that the use of IP based CCTV systems carries greater risk than traditional CCTV …
The Regulation Of Space And Cyberspace: One Coin, Two Sides, Brett Biddington
The Regulation Of Space And Cyberspace: One Coin, Two Sides, Brett Biddington
Australian Information Warfare and Security Conference
In the 1960s, during some very tense days in the Cold War the United States of America (USA) and the Union of Socialist Soviet Republics (USSR) brokered a deal in the United Nations for a treaty regime to govern human activities in outer space. This regime has served well enough for almost 50 years. In recent years, however, fears of space weaponisation, the proliferation of space debris in the Low Earth Orbits (LEO) and increasing demands on the electromagnetic spectrum (EMS) have led to demands for regulatory reform. Some nations now consider space to be the fourth domain of modern …
Exterminating The Cyber Flea: Irregular Warfare Lessons For Cyber Defence, Ben Whitham
Exterminating The Cyber Flea: Irregular Warfare Lessons For Cyber Defence, Ben Whitham
Australian Information Warfare and Security Conference
Traditional approaches to tactical Computer Network Defence (CND), drawn from the lessons and doctrine of conventional warfare, are based on a team of deployed security professionals countering the adversary’s cyber forces. The concept of the adversary in cyberspace does not fit neatly into the conventional military paradigms. Rather than fighting an identifiable foe, cyber adversaries are clandestine, indistinguishable from legitimate users or external services, operate across state boundaries, and from safe havens that provide sanctuary from prosecution. The defender also faces imbalances with rules of engagement and a severe disparity between the cost of delivering the defence and the attackers …
An Information Security Awareness Capability Model (Isacm), Robert Poepjes, Michael Lane
An Information Security Awareness Capability Model (Isacm), Robert Poepjes, Michael Lane
Australian Information Security Management Conference
A lack of information security awareness within some parts of society as well as some organisations continues to exist today. Whilst we have emerged from the threats of late 1990s of viruses such as Code Red and Melissa, through to the phishing emails of the mid 2000’s and the financial damage some such as the Nigerian scam caused, we continue to react poorly to new threats such as demanding money via SMS with a promise of death to those who won’t pay. So is this lack of awareness translating into problems within the workforce? There is often a lack of …
Human-Readable Real-Time Classifications Of Malicious Executables, Anselm Teh, Arran Stewart
Human-Readable Real-Time Classifications Of Malicious Executables, Anselm Teh, Arran Stewart
Australian Information Security Management Conference
Shafiq et al. (2009a) propose a non–signature-based technique for detecting malware which applies data mining techniques to features extracted from executable files. Their technique has a high level of accuracy, a low false positive rate, and a speed on par with commercial anti-virus products. One portion of their technique uses a multi-layer perceptron as a classifier, which provides little insight into the reasons for classification. Our experience is that network security analysts prefer tools which provide human-comprehensible reasons for a classification, rather than operating as “black boxes”. We therefore build on the results of Shafiq et al. by demonstrating a …
Implementing A Secure Academic Grid System - A Malaysian Case, Mohd Samsu Sajat, Suhaidi Hassan, Adi Affandi Ahmad, Ali Yusny Daud, Amran Ahmad
Implementing A Secure Academic Grid System - A Malaysian Case, Mohd Samsu Sajat, Suhaidi Hassan, Adi Affandi Ahmad, Ali Yusny Daud, Amran Ahmad
Australian Information Security Management Conference
Computational grids have become very popular in the recent times due to their capabilities and flexibility in handling large computationally intensive jobs. When it comes to the implementation of practical grid systems, security plays a major role due to the confidentiality of the information handled and the nature of the resources employed. Also due to the complex nature of the grid operations, grid systems face unique security threats compared to other distributed systems. This paper describes how to implement a secure grid system with special emphasis on the steps to be followed in obtaining, implementing and testing PKI certificates.
Creating A Counter-Insurgency Plan: Elements Required Based Upon A Comparative Analysis Of Research Findings, William J. Bailey
Creating A Counter-Insurgency Plan: Elements Required Based Upon A Comparative Analysis Of Research Findings, William J. Bailey
Australian Security and Intelligence Conference
The development of a counter-insurgency doctrine is an evolutionary process: no two insurgencies are the same. However, certain fundamental principals remain consistent and these can be applied to meet the required circumstances. The creation of an overarching plan encompassing a combination of military, political and social actions under the strong control of a single authority is central. Therefore, understanding the basics allows for the development of a tactical strategy based upon a structured plan. Compiling the ‘Plan’ should be based upon the lessons learnt from the past. To this end, the methodology used is supported by a literature review and …
The Emergence Of Boko Haram: An Analysis Of Terrorist Characteristics, Peter L. Lacey
The Emergence Of Boko Haram: An Analysis Of Terrorist Characteristics, Peter L. Lacey
Australian Counter Terrorism Conference
Boko Haram (BH) is a Nigerian extremist group which emerged only in the last decade, but has rapidly established a reputation for violence. This paper reviews the development and behaviour of BH in recent years, concluding that the group’s activities meet the definition of terrorism as systematic use of fear-evoking violence against civilians to achieve political goals. This characterisation is justified in terms of four definitional elements of terrorism, and further supported by comparison of BH with contemporary terrorist groups such as Abu Sayyaf Group and Caucasus Emirate, which espouse an ostensibly similar ideology. BH should not be mistaken for …
Forensic Readiness For Wireless Medical Systems, Brian Cusack, Ar Kar Kyaw
Forensic Readiness For Wireless Medical Systems, Brian Cusack, Ar Kar Kyaw
Australian Digital Forensics Conference
Wireless medical devices and related information systems are vulnerable to use and abuse by unauthorized users. Medical systems are designed for a range of end users in different professional skill groups and also people who carry the devices in and on their bodies. Open, accurate and efficient communication is the priority for medical systems and as a consequence strong protection costs are traded against the utility benefits for open systems. Flexible security provisions are required and strong forensic capabilities built into the systems to treat the risk. In this paper we elaborate the problem area and discuss potential solutions to …
Applying Feature Selection To Reduce Variability In Keystroke Dynamics Data For Authentication Systems, Mark Abernethy, Shri Rai
Applying Feature Selection To Reduce Variability In Keystroke Dynamics Data For Authentication Systems, Mark Abernethy, Shri Rai
Australian Information Warfare and Security Conference
Authentication systems enable the verification of claimed identity. Password-based authentication systems are ubiquitous even though such systems are amenable to numerous attack vectors and are therefore responsible for a large number of security breaches. Biometrics has been increasingly researched and used as an alternative to password-based systems. There are a number of alternative biometric characteristics that can be used for authentication purposes, each with different positive and negative implementation factors. Achieving a successful authentication performance requires effective data processing. This study investigated the use of keystroke dynamics for authentication purposes. A feature selection process, based on normality statistics, was applied …
Necessary And Sufficient Informativity Conditions For Robust Network Reconstruction Using Dynamical Structure Functions, Vasu Nephi Chetty
Necessary And Sufficient Informativity Conditions For Robust Network Reconstruction Using Dynamical Structure Functions, Vasu Nephi Chetty
Theses and Dissertations
Dynamical structure functions were developed as a partial structure representation of linear time-invariant systems to be used in the reconstruction of biological networks. Dynamical structure functions contain more information about structure than a system's transfer function, while requiring less a priori information for reconstruction than the complete computational structure associated with the state space realization. Early sufficient conditions for network reconstruction with dynamical structure functions severely restricted the possible applications of the reconstruction process to networks where each input independently controls a measured state. The first contribution of this thesis is to extend the previously established sufficient conditions to incorporate …
Evidence Examination Tools For Social Networks, Brian Cusack, Jung Son
Evidence Examination Tools For Social Networks, Brian Cusack, Jung Son
Australian Digital Forensics Conference
Social networking (SNS) involves computer networks and billions of users who interact for a multiplicity of purposes. The web based services allow people to communicate using many media sources and to build relationship networks that have personalized meanings. Businesses and Governments also exploit the opportunity for economical consumer interaction. With the valued use of SNS services also comes the potential for misuse and legal liability. In this paper three software tools are tested in the laboratory to assess the capability of the tools to extract files from the four most popular web browsers while browsers are being used to surf …
Web-Based Risk Analysis For Home Users, R. T. Magaya, N. L. Clarke
Web-Based Risk Analysis For Home Users, R. T. Magaya, N. L. Clarke
Australian Information Security Management Conference
The advancement of the Internet has provided access to a wide variety of online services such as banking, e-commerce, social networking and entertainment. The wide availability and popularity of the Internet has also led to the rise in risks and threats to users, as criminals have taken an increasingly active role in abusing innocent users. Current risk analysis tools, techniques and methods available do not cater for home users but are tailored for large organisations. The tools require expertise to use them and they are expensive to purchase. What is available for home users are generic information portals that provide …
An Investigation Into The Wi-Fi Protected Setup Pin Of The Linksys Wrt160n V2, Symon Aked, Christopher Bolan, Murray Brand
An Investigation Into The Wi-Fi Protected Setup Pin Of The Linksys Wrt160n V2, Symon Aked, Christopher Bolan, Murray Brand
Australian Information Security Management Conference
Wi-Fi Protected Setup (WPS) is a method of allowing a consumer to set up a secure wireless network in a user friendly way. However, in December 2011 it was discovered that a brute force attack exists that reduces the WPS key space from 108 to 104+103. This resulted in a proof of concept tool that was able to search all possible combinations of PINs within a few days.This research presents a methodology to test wireless devices to determine their susceptibility to the external registrar PIN authentication design vulnerability. A number of devices were audited, and the Linksys WRT160N v2 router …
Exposing Potential Privacy Issues With Ipv6 Address Construction, Clinton Carpene, Andrew Woodward
Exposing Potential Privacy Issues With Ipv6 Address Construction, Clinton Carpene, Andrew Woodward
Australian Information Security Management Conference
The usage of 128 bit addresses with hexadecimal representation in IPv6 poses significant potential privacy issues. This paper discusses the means of allocating IPv6 addresses, along with the implications each method may have upon privacy in different usage scenarios. The division of address space amongst the global registries in a hierarchal fashion can provide geographical information about the location of an address, and its originating device. Many IPv6 address configuration methods are available, including DHCPv6, SLAAC (with or without privacy extensions), and Manual assignment. These assignment techniques are dissected to expose the identifying characteristics of each technique. It is seen …