Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons

Open Access. Powered by Scholars. Published by Universities.®

2013

Discipline
Institution
Keyword
Publication
Publication Type
File Type

Articles 31 - 60 of 2092

Full-Text Articles in Computer Sciences

Cartoons For E-Health Informatics, Moira Sim, Eric Khong, Ashleigh Mcevoy, Toni Wain, Mick Sim, Patricia A.H. Williams Dec 2013

Cartoons For E-Health Informatics, Moira Sim, Eric Khong, Ashleigh Mcevoy, Toni Wain, Mick Sim, Patricia A.H. Williams

Australian eHealth Informatics and Security Conference

Not only is Hepatitis B serology often misunderstood because of its complex serological implications, but advances in medical science have revolutionised screening and treatment of hepatitis B. To maximise such evolution however, this new information must be relayed effectively and efficiently to current and future medical professionals. Cartoons have been well regarded as a teaching tool in a variety of different settings as is the use of web based technology. Therefore the delivery of a cartoon based learning tool, accessed via on-line learning modules was considered a novel and potentially effective way of disseminating new knowledge. To increase health professionals’ …


The Syrian Calling: Western Jihad Recruitment And Martyrdom, Robyn Torok Dec 2013

The Syrian Calling: Western Jihad Recruitment And Martyrdom, Robyn Torok

Australian Counter Terrorism Conference

The crisis in Syria has attracted worldwide attention as well as condemnation and has degraded into a violent civil conflict. Not only are there more than a thousand rebel groups including a number of hard‐line jihadist groups operating within Syria, but these jihadist groups are attracting a significant number of foreigners including Australians. This study examined social media discourses from Facebook and embedded YouTube links for recruiting Westerners to the war in Syria. Findings suggest that the perceived inaction of the international community and in particular the West coupled with the atrocities committed has become a platform for jihadi recruitment. …


An Investigation Into The Efficiency Of Forensic Data Erasure Tools For Removable Usb Flash Memory Storage Devices, Krishnun Sansurooah, Haydon Hope, Hani Almutairi, Fayadh Alnazawi, Yunhan Jiang Dec 2013

An Investigation Into The Efficiency Of Forensic Data Erasure Tools For Removable Usb Flash Memory Storage Devices, Krishnun Sansurooah, Haydon Hope, Hani Almutairi, Fayadh Alnazawi, Yunhan Jiang

Australian Digital Forensics Conference

Securely erasing data is of key importance to anyone that is concerned with the security of their sensitive information, whether an individual or an organization. Simply deleting the data in question or formatting the storage device is not enough to ensure that the data cannot be recovered. Furthermore, with the uptake of Universal Serial Bus drives (USBs) flash memory based storage devices have replaced previous portable secondary storage media. Therefore, it is of a major concern whether these tools and products developed for securely erasing data secondary storage Hard Disk Drives (HDDs) would be as efficient when targeting the USB …


Volatile Memory Acquisition Tools – A Comparison Across Taint And Correctness, William Campbell Dec 2013

Volatile Memory Acquisition Tools – A Comparison Across Taint And Correctness, William Campbell

Australian Digital Forensics Conference

The growth in volatile memory forensics has steadily increased in recent times. With this growth comes a need to test the tools associated with this practise. Although there appears to be a large amount of effort in testing static memory capture tools, there is perhaps less so for volatile memory capture. This paper describes the attempts at categorizing criteria for testing, and then introduces and extends upon a methodology proposed by Lempereur and colleagues in 2012. Four tools (Windows Memory Reader, WinPmem, FTK Imager and DumpIt) are tested against two criteria (impact and completeness). WMR and DumpIt were found to …


Verification Of Primitive Sub Ghz Rf Replay Attack Techniques Based On Visual Signal Analysis, Maxim Chernyshev Dec 2013

Verification Of Primitive Sub Ghz Rf Replay Attack Techniques Based On Visual Signal Analysis, Maxim Chernyshev

Australian Digital Forensics Conference

As the low cost options for radio traffic capture, analysis and transmission are becoming available, some security researchers have developed open source tools that potentially make it easier to assess the security of the devices that rely on radio communications without the need for extensive knowledge and understanding of the associated concepts. Recent research in this area suggests that primitive visual analysis techniques may be applied to decode selected radio signals successfully. This study builds upon the previous research in the area of sub GHz radio communications and aims to outline the associated methodology as well as verify some of …


Acquisition Of Evidence From Network Intrusion Detection Systems, Brian Cusack, Muteb Alqahtani Dec 2013

Acquisition Of Evidence From Network Intrusion Detection Systems, Brian Cusack, Muteb Alqahtani

Australian Digital Forensics Conference

The literature reviewed suggests that Network Intrusion Systems (NIDS) are valuable tools for the detection of malicious behaviour in network environments. NIDS provide alerts and the trigger for rapid responses to attacks. Our previous research had shown that NIDS performance in wireless networks had a wide variation under different workloads. In this research we chose wired networks and asked the question: What is the evidential value of NIDS? Three different NIDS were tested under two different attacks and with six different packet rates. The results were alarming. As the work loading increased the NIDS detection capability fell rapidly and as …


Steganographic Checks In Digital Forensic Investigation: A Social Networking Case, Brian Cusack, Aimie Chee Dec 2013

Steganographic Checks In Digital Forensic Investigation: A Social Networking Case, Brian Cusack, Aimie Chee

Australian Digital Forensics Conference

Steganography is an ancient art that has received a mega boost in the digital age. Electronic communications are easily accessible by most people and have a wide range of opportunities to embed secret messages in a diverse range of cover objects. Our research questions were: What can an investigator do to check for hidden messages in social media? And, how much searching is enough? The testing was conducted in replicated social networking sites and digital images were selected as the cover objects. The research findings showed that steganography is as easy as sending an email and not much more difficult …


A Forensic Analysis And Comparison Of Solid State Drive Data Retention With Trim Enabled File Systems, Alastair Nisbet, Scott Lawrence, Matthew Ruff Dec 2013

A Forensic Analysis And Comparison Of Solid State Drive Data Retention With Trim Enabled File Systems, Alastair Nisbet, Scott Lawrence, Matthew Ruff

Australian Digital Forensics Conference

Solid State Drives offer significant advantages over traditional hard disk drives. No moving parts, superior resistance to shock, reduced heat generation and increased battery life for laptops. However, they are susceptible to cell failure within the chips. To counter this, wear levelling is used so that cells are utilised for data at approximately the same rate. An improvement to the original wear levelling routine is TRIM, which further enhances the lifetime of the cells by allowing the garbage collection process as one operation rather than an on going process. The advantages of TRIM for the user is that it increases …


A Privacy-Preserving Framework For Personally Controlled Electronic Health Record (Pcehr) System, Mahmuda Begum, Quazi Mamun, Mohammed Kaosar Dec 2013

A Privacy-Preserving Framework For Personally Controlled Electronic Health Record (Pcehr) System, Mahmuda Begum, Quazi Mamun, Mohammed Kaosar

Australian eHealth Informatics and Security Conference

The electronic health record (eHR) system has recently been considered one of the biggest advancements in healthcare services. A personally controlled electronic health record (PCEHR) system is proposed by the Australian government to make the health system more agile, secure, and sustainable. Although the PCEHR system claims the electronic health records can be controlled by the patients, healthcare professionals and database/system operators may assist in disclosing the patients’ eHRs for retaliation or other ill purposes. As the conventional methods for preserving the privacy of eHRs solely trust the system operators, these data are vulnerable to be exploited by the authorised …


Ehealth Security Australia: The Solution Lies With Frameworks And Standards, Bryan Foster, Yvette Lejins Dec 2013

Ehealth Security Australia: The Solution Lies With Frameworks And Standards, Bryan Foster, Yvette Lejins

Australian eHealth Informatics and Security Conference

Security is a key foundation for eHealth in Australia, driving benefits in healthcare quality, safety, and efficiency towards improved health outcomes for all Australians. To this end, the National eHealth Transition Authority (NEHTA), the Royal Australian College of General Practitioners (RACGP), and Standards Australia have each produced security-related publications to assist Australian healthcare organisations protect their data. These publications provide standards, tools, and guides for the healthcare industry to build and implement secure systems that protect patient data and eHealth-related assets, while providing the provenance required to help ensure patient safety and privacy. This paper outlines some of the current …


A Rapidly Moving Target: Conformance With E-Health Standards For Mobile Computing, Patricia A.H. Williams, Vincent B. Mccauley Dec 2013

A Rapidly Moving Target: Conformance With E-Health Standards For Mobile Computing, Patricia A.H. Williams, Vincent B. Mccauley

Australian eHealth Informatics and Security Conference

The rapid adoption and evolution of mobile applications in health is posing significant challenges in terms of standards development, standards adoption, patient safety, and patient privacy. This is a complex continuum to navigate. There are many competing demands from the standards development process, to the use by clinicians and patients. In between there are compliance and conformance measures to be defined to ensure patient safety, effective use with integration into clinical workflow, and the protection of data and patient privacy involved in data collection and exchange. The result is a composite and intricate mixture of stakeholders, legislation, and policy together …


A Study On Information Induced Medication Errors, Rebecca Hermon, Patricia A.H. Williams Dec 2013

A Study On Information Induced Medication Errors, Rebecca Hermon, Patricia A.H. Williams

Australian eHealth Informatics and Security Conference

Preventable medical adverse events are a serious concern for healthcare. Medication errors form a significant part of these concerns and it is evident that these errors can have serious consequences such as death or disability. Many medication errors are a consequence of information failure. Therefore to prevent such adverse events, the associated information flow must be understood. This research used a systematic review methodology to conduct an analysis of medication error as a result of information failure. Its aim was to suggest solutions on reducing information induced medication errors. The results indicate that is apparent that human error such as …


The Contemporary Australian Intelligence Domain - A Multi Dimension Examination, Alan Davies, Jeff Corkill Dec 2013

The Contemporary Australian Intelligence Domain - A Multi Dimension Examination, Alan Davies, Jeff Corkill

Australian Security and Intelligence Conference

In the complex and interconnected post 9/11 world the roles and functions of intelligence have evolved beyond being a secret capability of governments focused on national security needs. Intelligence has become recognised as a critical function necessary to support decision making across the full breadth of government and corporate activity. The concept of an intelligence community being purely national security centric and bounded by secrecy has become limited. Intelligence in support of decision making has become a far broader domain than previously believed. This paper investigates the degree of intelligence embedded‐ness across government agencies and departments at the federal, state …


Physical Security Barrier Selection: A Decision Support Analysis, Agnieszka Kiszelewska, Michael Coole Dec 2013

Physical Security Barrier Selection: A Decision Support Analysis, Agnieszka Kiszelewska, Michael Coole

Australian Security and Intelligence Conference

Physical security controls aim to reduce risk through their ability to systematically deter, or detect, delay and respond against deviant acts within a risk context. Holistically the aim is to increase the difficulty and risks while reducing the rewards associated with an act of deviance as captured in Clarke’s Situational Crime Prevention (SCP) framework. The efficacious implementation of such controls commensurate with the risk context requires a considered undertaking referred as informed decision‐making. Informed decision‐making is effective when a suitable choice is made accordant with base rate data that achieves its defined objectives within costs versus benefits framework. The study …


3d Visual Method Of Variant Logic Construction For Random Sequence, Huan Wang, Jeffrey Zheng Dec 2013

3d Visual Method Of Variant Logic Construction For Random Sequence, Huan Wang, Jeffrey Zheng

Australian Information Warfare and Security Conference

As Internet security threats continue to evolve, in order to ensure information transmission security, various encrypt and decrypt has been used in channel coding and decoding of data communication. While cryptography requires a very high degree of apparent randomness, Random sequences play an important role in cryptography. Both CA (Cellular Automata) and RC4 contain pseudo‐random number generators and may have intrinsic properties respectively. In this paper, a 3D visualization model (3DVM) is proposed to display spatial characteristics of the random sequences from CA or RC4 keystream. Key components of this model and core mechanism are described. Every module and their …


Exchanging Demands: Weaknesses In Ssl Implementations For Mobile Platforms, Peter Hannay, Clinton Carpene, Craig Valli, Andrew Woodward, Mike Johnstone Dec 2013

Exchanging Demands: Weaknesses In Ssl Implementations For Mobile Platforms, Peter Hannay, Clinton Carpene, Craig Valli, Andrew Woodward, Mike Johnstone

Australian Information Security Management Conference

The ActiveSync protocol’s implementation on some embedded devices leaves clients vulnerable to unauthorised remote policy enforcement. This paper discusses a proof of concept attack against the implementation of ActiveSync in common Smart phones including Android devices and iOS devices. A two‐phase approach to exploiting the ActiveSync protocol is introduced. Phase 1 details the usage of a man‐in‐the‐middle attack to gain a vantage point over the client device, whilst Phase 2 involves spoofing the server‐side ActiveSync responses to initiate the unauthorised policy enforcement. These vulnerabilities are demonstrated by experiment, highlighting how the system can be exploited to perform a remote factory …


A Simulation-Based Study Of Server Location Selection Rules In Manets Utilising Threshold Cryptography, Alastair Nisbet Dec 2013

A Simulation-Based Study Of Server Location Selection Rules In Manets Utilising Threshold Cryptography, Alastair Nisbet

Australian Information Security Management Conference

Truly Ad Hoc wireless networks where a spontaneous formation of a network occurs and there is no prior knowledge of nodes to each other present significant security challenges, especially as entirely online configuration of nodes with encryption keys must be performed. Utilising threshold cryptography in this type of MANET can greatly increase the security by requiring servers to collaborate to form a single Certificate Authority (CA). In this type of CA responsibility for certificate services is shared between a threshold of servers, greatly increasing security and making attack against the CA considerably more difficult. Choosing which nodes to take on …


Breaking The Theft-Chain-Cycle: Property Marking As A Defensive Tool, William J. Bailey, David J. Brooks Dec 2013

Breaking The Theft-Chain-Cycle: Property Marking As A Defensive Tool, William J. Bailey, David J. Brooks

Australian Security and Intelligence Conference

Any viable method of protecting property, dissuading the theft of property or ensuring the swift recovery of stolen property could be considered essential to general society. A number of crime preventive measures have been used in an attempt to achieve this objective. One such measure is property marking, employing various techniques to make property more readily identifiable. The study assesses technology to investigate effectiveness, both for dissuasion and for tracing once stolen. Mechanism for the disposal of stolen property forms an important part of this study, commencing with the mapping of the theft‐supply‐chain. Using a mixed methods approach, the research …


An Exploratory Study Of The Lived Experience Of Being An Intelligence Analyst, Sharon Moss, Jeff Corkill, Eyal Gringart Dec 2013

An Exploratory Study Of The Lived Experience Of Being An Intelligence Analyst, Sharon Moss, Jeff Corkill, Eyal Gringart

Australian Security and Intelligence Conference

Since the World Trade Centre terror attacks of 2001 the intelligence domain has grown rapidly. In keeping with this growth has been a significant increase of scholarly interest in the domain. The intelligence literature is dominated by research into the failures of the discipline, organisational structure and the politics of intelligence. The intelligence analyst is a critical component of the intelligence domain yet is remarkably absent from the intelligence literature. This research seeks to address that imbalance by examining the lived experience of the analyst operating in the law enforcement intelligence domain. To this end, interpretive phenomenology was employed to …


Twitter Influence And Cumulative Perceptions Of Extremist Support: A Case Study Of Geert Wilders, Gabrielle Blanquart, David M. Cook Dec 2013

Twitter Influence And Cumulative Perceptions Of Extremist Support: A Case Study Of Geert Wilders, Gabrielle Blanquart, David M. Cook

Australian Counter Terrorism Conference

The advent of Social media has changed the manner in which perceptions about power and information can be influenced. Twitter is used as a fast‐paced vehicle to deliver short, succinct pieces of information, creating the perception of acceptance, popularity and authority. In the case of extremist groups, Twitter is one of several avenues to create the perception of endorsement of values that would otherwise gain less prominence through mainstream media. This study examines the use of Twitter in augmenting the status and reputation of anti‐Islam and anti‐immigration policy through the controlled release of social media information bursts. The paper demonstrates …


Towards An Automated Forensic Examiner (Afe) Based Upon Criminal Profiling & Artificial Intelligence, M Al Fahdi, N L. Clarke, S M. Furnell Dec 2013

Towards An Automated Forensic Examiner (Afe) Based Upon Criminal Profiling & Artificial Intelligence, M Al Fahdi, N L. Clarke, S M. Furnell

Australian Digital Forensics Conference

Digital forensics plays an increasingly important role within society as the approach to the identification of criminal and cybercriminal activities. It is however widely known that a combination of the time taken to undertake a forensic investigation, the volume of data to be analysed and the number of cases to be processed are all significantly increasing resulting in an ever growing backlog of investigations and mounting costs. Automation approaches have already been widely adopted within digital forensic processes to speed up the identification of relevant evidence – hashing for notable files, file signature analysis and data carving to name a …


Including Network Routers In Forensic Investigation, Brian Cusack, Raymond Lutui Dec 2013

Including Network Routers In Forensic Investigation, Brian Cusack, Raymond Lutui

Australian Digital Forensics Conference

Network forensics concerns the identification and preservation of evidence from an event that has occurred or is likely to occur. The scope of network forensics encompasses the networks, systems and devices associated with the physical and human networks. In this paper we are assessing the forensic potential of a router in investigations. A single router is taken as a case study and analysed to determine its forensic value from both static and live investigation perspectives. In the live investigation, tests using steps from two to seven routers were used to establish benchmark expectations for network variations. We find that the …


Identifying Bugs In Digital Forensic Tools, Brian Cusack, Alain Homewood Dec 2013

Identifying Bugs In Digital Forensic Tools, Brian Cusack, Alain Homewood

Australian Digital Forensics Conference

Bugs can be found in all code and the consequences are usually managed through upgrade releases, patches, and restarting operating systems and applications. However, in mission critical systems complete fall over systems are built to assure service continuity. In our research we asked the question, what are the professional risks of bugs in digital forensic tools? Our investigation reviewed three high use professional proprietary digital forensic tools, one in which we identified six bugs and evaluated these bug in terms of potential impacts on an investigator’s work. The findings show that yes major brand name digital forensic tools have software …


Forensic Memory Dump Analysis And Recovery Of The Artefacts Of Using Tor Bundle Browser – The Need, Divya Dayalamurthy Dec 2013

Forensic Memory Dump Analysis And Recovery Of The Artefacts Of Using Tor Bundle Browser – The Need, Divya Dayalamurthy

Australian Digital Forensics Conference

The Onion Routing (TOR) project is a network of virtual tunnels that facilitates secure, private communications on the internet. A recent article published in “The Registry” claims that TOR bundle browser usage has increased in recent years; statistics show that in January 2012, there were approximately 950,000 users globally and now in August 2013 that figure is estimated to have reached 1,200,000 users. The report also illustrates that The United states of America and the United Kingdom are major contributors towards the massive increase in TOR usage. Similarly, other countries like India and Brazil have increased usage to 32,000 and …


Robust Watermarking Method By Systematic Block Diffusion Using Discrete Cosine Transform, Kazuo Ohzeki, Kazutaka Bannai, Yutaka Hirakawa, Kiyotsugu Sato Dec 2013

Robust Watermarking Method By Systematic Block Diffusion Using Discrete Cosine Transform, Kazuo Ohzeki, Kazutaka Bannai, Yutaka Hirakawa, Kiyotsugu Sato

Australian Digital Forensics Conference

Digital watermarks have long been considered as a security feature. A watermarking method that involves the diffusion of limited watermark information into a large part of an image’s data has high robustness. The diffused information is summed up to a single component before detecting the watermark. The summing up process eliminates small noises by an averaging effect, which improves the robustness of the embedded watermark against attack. In this field, thus far, only an asymmetrical Chirp transformation with a small block size has been attempted. In this study, a new verification experiment for a large block size of 256 × …


Security Of Internet Protocol Cameras – A Case Example, William Campbell Dec 2013

Security Of Internet Protocol Cameras – A Case Example, William Campbell

Australian Digital Forensics Conference

The interaction of consumer devices and the internet, especially in relation to security, has always been tenuous. Where it is in the best interests of companies to produce products that are cheap and accessible, these traits often go against that of security. This investigation undertakes an analysis of one such device – the DCS 930L internet protocol camera from D Link. This camera is analysed for vulnerabilities, with an emphasis on those relating to authentication mechanisms. Several vulnerabilities are identified, and potential attacks based on these are discussed. Solutions or mitigations to these vulnerabilities are presented.


Information Security Management: Factors That Influence Security Investments In Smes, Zhi Xian Ng, Atif Ahmad, Sean B. Maynard Dec 2013

Information Security Management: Factors That Influence Security Investments In Smes, Zhi Xian Ng, Atif Ahmad, Sean B. Maynard

Australian Information Security Management Conference

In the modern information economy, the security of information is critically important to organizations. Information‐security risk assessments (ISRAs) allow organizations to identify key information assets and security risks so security expenditure can be directed cost‐effectively. Unfortunately conducting ISRAs requires special expertise and tends to be complex and costly for small to medium sized organizations (SMEs). Therefore, it remains unclear in practice, and unknown in literature, how SMEs address information security imperatives without the benefit of an ISRA process. This research makes a contribution to theory in security management by identifying the factors that influence key decision-makers in SMEs to address …


A Comparison Of Information Security Curricula In China And The Usa, Huaying Chen, Sean B. Maynard, Atif Ahmad Dec 2013

A Comparison Of Information Security Curricula In China And The Usa, Huaying Chen, Sean B. Maynard, Atif Ahmad

Australian Information Security Management Conference

Information Security (InfoSec) education varies in its content, focus and level of technicality across the world. In this paper we investigate the differences between graduate InfoSec programs in top universities in China and in the United States of America (USA). In China, curriculum emphasises Telecommunication, Computer Science and InfoSec Technology, whilst in the USA in addition to Computer Science and InfoSec Technology the curriculum also emphasises Enterprise‐level Security Strategy and Policy, InfoSec Management, and Cyber Law. The differences are significant and will have a profound impact on both the perceptions and capabilities of future generations of information security professionals on …


Is Emergency Management Considered A Component Of Business Continuity Management?, Kenny Frohde, David J. Brooks Dec 2013

Is Emergency Management Considered A Component Of Business Continuity Management?, Kenny Frohde, David J. Brooks

Australian Security and Intelligence Conference

Emergency Management (EM) and Business Continuity Management (BCM) frameworks incorporate measures of strategic and operational aspects. Defined within a number of Australian and international standards as well as guidelines, such concepts may be integrated to provide increased resilience for disruptive events. However, it has been found that there is some degree of misalignment of concept integration amongst security and EM bodies of knowledge. In line with cognitive psychology exemplar‐based concepts, such misalignments may be associated with a lack of precision in communality in the approach to EM and BCM. This article presents stage 1 of a two‐stage study. Stage 1 …


Procedures And Tools For Acquisition And Analysis Of Volatile Memory On Android Smartphones, Andri P. Heriyanto Dec 2013

Procedures And Tools For Acquisition And Analysis Of Volatile Memory On Android Smartphones, Andri P. Heriyanto

Australian Digital Forensics Conference

Mobile phone forensics have become more prominent since mobile phones have become ubiquitous both for personal and business practice. Android smartphones show tremendous growth in the global market share. Many researchers and works show the procedures and techniques for the acquisition andanalysisthe non volatile memory inmobile phones. On the other hand, the physical memory (RAM) on the smartphone might retain incriminating evidence that could be acquired and analysed by the examiner. This study reveals the proper procedure for acquiring the volatile memory inthe Android smartphone and discusses the use of Linux Memory Extraction (LiME) for dumping the volatile memory. The …