Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Embry-Riddle Aeronautical University (486)
- Old Dominion University (107)
- Air Force Institute of Technology (86)
- University of New Haven (62)
- Singapore Management University (33)
-
- Kennesaw State University (27)
- Edith Cowan University (22)
- Wayne State University (20)
- University of Arkansas, Fayetteville (17)
- University of Kentucky (8)
- Purdue University (7)
- University of Nebraska - Lincoln (6)
- University of South Florida (6)
- Sacred Heart University (5)
- Louisiana State University (4)
- Southern Methodist University (4)
- The University of Akron (4)
- University of Central Florida (4)
- City University of New York (CUNY) (3)
- Dartmouth College (3)
- Portland State University (3)
- University of Malaya (3)
- University of South Alabama (3)
- Brigham Young University (2)
- California Polytechnic State University, San Luis Obispo (2)
- California State University, San Bernardino (2)
- Clemson University (2)
- Eastern Michigan University (2)
- Indian Statistical Institute (2)
- Institute of Business Administration (2)
- Keyword
-
- Cybersecurity (67)
- Digital forensics (55)
- Security (36)
- Computer security (27)
- Computer forensics (22)
-
- Computer networks--Security measures (21)
- Forensics (20)
- Digital Forensics (19)
- Privacy (19)
- Machine learning (18)
- Android (16)
- Digital evidence (15)
- Information security (14)
- Blockchain (13)
- Cyber security (12)
- Cryptography (10)
- Encryption (10)
- Network security (10)
- Approximate matching (9)
- Cloud computing (9)
- Computer Forensics (9)
- Internet (9)
- Artificial intelligence (8)
- Authentication (8)
- Cyber forensics (8)
- Internet of things (8)
- IoT (8)
- Mobile device forensics (8)
- Mrsh-v2 (8)
- Network forensics (8)
- Publication Year
- Publication
-
- Journal of Digital Forensics, Security and Law (300)
- Annual ADFSL Conference on Digital Forensics, Security and Law (174)
- Theses and Dissertations (84)
- Electrical & Computer Engineering and Computer Science Faculty Publications (58)
- Research Collection School Of Computing and Information Systems (33)
-
- Cybersecurity Undergraduate Research Showcase (26)
- Electrical & Computer Engineering Faculty Publications (21)
- Chemical Engineering and Materials Science Faculty Research Publications (20)
- Journal of Cybersecurity Education, Research and Practice (14)
- Australian Digital Forensics Conference (12)
- Graduate Theses and Dissertations (10)
- Engineering Technology Faculty Publications (9)
- VMASC Publications (9)
- KSU Proceedings on Cybersecurity Education, Research and Practice (8)
- Engineering Management & Systems Engineering Faculty Publications (7)
- Computer Science and Computer Engineering Undergraduate Honors Theses (6)
- Electronic Theses and Dissertations (6)
- Engineering Management & Systems Engineering Theses & Dissertations (6)
- School of Cybersecurity Faculty Publications (6)
- Computer Ethics - Philosophical Enquiry (CEPE) Proceedings (5)
- Information Science Faculty Publications (5)
- Master's Theses (5)
- Military Cyber Affairs (5)
- Publications (5)
- Research outputs 2014 to 2021 (5)
- Computer Science Faculty Publications (4)
- Department of Electrical and Computer Engineering Faculty Publications (4)
- Faculty Publications (4)
- SMU Data Science Review (4)
- School of Computer Science & Engineering Faculty Publications (4)
- Publication Type
- File Type
Articles 961 - 988 of 988
Full-Text Articles in Information Security
The Design Of An Undergraduate Degree Program In Computer & Digital Forensics, Gary C. Kessler, Michael E. Schirling
The Design Of An Undergraduate Degree Program In Computer & Digital Forensics, Gary C. Kessler, Michael E. Schirling
Journal of Digital Forensics, Security and Law
Champlain College formally started an undergraduate degree program in Computer & Digital Forensics in 2003. The underlying goals were that the program be multidisciplinary, bringing together the law, computer technology, and the basics of digital investigations; would be available as on online and oncampus offering; and would have a process-oriented focus. Success of this program has largely been due to working closely with practitioners, maintaining activity in events related to both industry and academia, and flexibility to respond to ever-changing needs. This paper provides an overview of how this program was conceived, developed, and implemented; its evolution over time; and …
The Role Of Power And Negotiation In Online Deception, Chad Albrecht, Conan C. Albrecht, Jonathan Wareham, Paul Fox
The Role Of Power And Negotiation In Online Deception, Chad Albrecht, Conan C. Albrecht, Jonathan Wareham, Paul Fox
Journal of Digital Forensics, Security and Law
The purpose of this paper is to advance theoretical understanding of the important role of both power and negotiation during online deception. By so doing, the paper provides insight into the relationship between perpetrator and victim in Internet fraud. The growing prevalence of Internet Fraud continues to be a burden to both society and individuals. In an attempt to better understand Internet fraud and online deception, this article attempts to build an interactive model, based upon the dimensions of power and negotiation from the management and psychology literature. Using the model presented, the article examines the effects of the Internet …
A Curriculum For Teaching Information Technology Investigative Techniques For Auditors, Grover S. Kearns
A Curriculum For Teaching Information Technology Investigative Techniques For Auditors, Grover S. Kearns
Journal of Digital Forensics, Security and Law
Recent prosecutions of highly publicized white-collar crimes combined with public outrage have resulted in heightened regulation of financial reporting and greater emphasis on systems of internal control. Because both white-collar and cybercrimes are usually perpetrated through computers, internal and external auditors’ knowledge of information technology (IT) is now more vital than ever. However, preserving digital evidence and investigative techniques, which can be essential to fraud examinations, are not skills frequently taught in accounting programs and instruction in the use of computer assisted auditing tools and techniques – applications that might uncover fraudulent activity – is limited. Only a few university-level …
Development Of A National Repository Of Digital Forensic Intelligence, Mark Weiser, David P. Biros, Greg Mosier
Development Of A National Repository Of Digital Forensic Intelligence, Mark Weiser, David P. Biros, Greg Mosier
Journal of Digital Forensics, Security and Law
Many people do all of their banking online, we and our children communicate with peers through computer systems, and there are many jobs that require near continuous interaction with computer systems. Criminals, however, are also “connected”, and our online interaction provides them a conduit into our information like never before. Our credit card numbers and other fiscal information are at risk, our children's personal information is exposed to the world, and our professional reputations are on the line.
The discipline of Digital Forensics in law enforcement agencies around the nation and world has grown to match the increased risk and …
Electronic Data Discovery: Integrating Due Process Into Cyber Forensic Practice, John W. Bagby, John C. Ruhnka
Electronic Data Discovery: Integrating Due Process Into Cyber Forensic Practice, John W. Bagby, John C. Ruhnka
Journal of Digital Forensics, Security and Law
Most organizations and government agencies regularly become engaged in litigation with suppliers, customers, clients, employees, competitors, shareholders, prosecutors or regulatory agencies that nearly assures the need to organize, retain, find and produce business records and correspondence, emails, accounting records or other data relevant to disputed issues. This article discusses some high visibility cases that constrain how metadata and content is routinely made available to opposing parties in civil litigation, to prosecutors in criminal prosecutions and to agency staff in regulatory enforcement litigation. Public policy, as implemented in the rules of evidence and pretrial discovery, restrict electronic data discovery (EDD) as …
Forensic Tools For Mobile Phone Subscriber Identity Modules, Wayne Jansen, Rick Ayers
Forensic Tools For Mobile Phone Subscriber Identity Modules, Wayne Jansen, Rick Ayers
Journal of Digital Forensics, Security and Law
Mobile phones and other handheld devices incorporating cellular capabilities, such as Personal Digital Assistants, are ubiquitous. Besides placing calls, these devices allow users to perform other useful tasks, including text messaging and phonebook entry management. When cell phones and cellular devices are involved in a crime or other incident, forensic specialists require tools that allow the proper retrieval and speedy examination of data present on the device. For devices conforming to the Global System for Mobile Communications (GSM) standards, certain data such as dialed numbers, text messages, and phonebook entries are maintained on a Subscriber Identity Module (SIM). This paper …
Development And Delivery Of Coursework: The Legal/Regulatory/Policy Environment Of Cyberforensics, John W. Bagby, John C. Ruhnka
Development And Delivery Of Coursework: The Legal/Regulatory/Policy Environment Of Cyberforensics, John W. Bagby, John C. Ruhnka
Journal of Digital Forensics, Security and Law
This paper describes a cyber-forensics course that integrates important public policy and legal issues as well as relevant forensic techniques. Cyber-forensics refers to the amalgam of multi-disciplinary activities involved in the identification, gathering, handling, custody, use and security of electronic files and records, involving expertise from the forensic domain, and which produces evidence useful in the proof of facts for both commercial and legal activities. The legal and regulatory environment in which electronic discovery takes place is of critical importance to cyber-forensics experts because the legal process imposes both constraints and opportunities for the effective use of evidence gathered through …
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
Is Forensic Computing A Profession? Revisiting An Old Debate In A New Field, Bernd C. Stahl
Is Forensic Computing A Profession? Revisiting An Old Debate In A New Field, Bernd C. Stahl
Journal of Digital Forensics, Security and Law
Forensic Computing is a new and quickly developing field. It is in the process of becoming an academic discipline or sub-discipline with all the features from full undergraduate and postgraduate course provision to conferences and journals. An important question in this process of turning into an established discipline is whether it will coincide with the recognition of the graduates as professionals. This paper hopes to stimulate the debate as to whether forensic computing is or should be a discipline. In order to approach this question, the paper will discuss the concept of forensic computing including the most salient topics of …
Development Of An Ontology Based Forensic Search Mechanism: Proof Of Concept, Jill Slay, Fiona Schulz
Development Of An Ontology Based Forensic Search Mechanism: Proof Of Concept, Jill Slay, Fiona Schulz
Journal of Digital Forensics, Security and Law
This paper examines the problems faced by Law Enforcement in searching large quantities of electronic evidence. It examines the use of ontologies as the basis for new forensic software filters and provides a proof of concept tool based on an ontological design. It demonstrates that efficient searching is produced through the use of such a design and points to further work that might be carried out to extend this concept.
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
The 2006 Analysis Of Information Remaining On Disks Offered For Sale On The Second Hand Market, Andy Jones, Craig Valli, Iain Sutherland, Paula Thomas
The 2006 Analysis Of Information Remaining On Disks Offered For Sale On The Second Hand Market, Andy Jones, Craig Valli, Iain Sutherland, Paula Thomas
Journal of Digital Forensics, Security and Law
All organisations, whether in the public or private sector, use computers for the storage and processing of information relating to their business or services, their employees and their customers. A large proportion of families and individuals in their homes now also use personal computers and, both intentionally and inadvertently, often store on those computers personal information. It is clear that most organisations and individuals continue to be unaware of the information that may be stored on the hard disks that the computers contain, and have not considered what may happen to the information after the disposal of the equipment.
In …
Computer Forensics Field Triage Process Model, Marcus K. Rogers, James Goldman, Rick Mislan, Timothy Wedge, Steve Debrota
Computer Forensics Field Triage Process Model, Marcus K. Rogers, James Goldman, Rick Mislan, Timothy Wedge, Steve Debrota
Journal of Digital Forensics, Security and Law
With the proliferation of digital based evidence, the need for the timely identification, analysis and interpretation of digital evidence is becoming more crucial. In many investigations critical information is required while at the scene or within a short period of time - measured in hours as opposed to days. The traditional cyber forensics approach of seizing a system(s)/media, transporting it to the lab, making a forensic image(s), and then searching the entire system for potential evidence, is no longer appropriate in some circumstances. In cases such as child abductions, pedophiles, missing or exploited persons, time is of the essence. In …
Secured Network Model For Management Information System Based On Ip Security (Ipsec) Encryption Using Multilayered Approach Of Network Security, Dr. Amir Hassan Pathan, Muniza Irshad
Secured Network Model For Management Information System Based On Ip Security (Ipsec) Encryption Using Multilayered Approach Of Network Security, Dr. Amir Hassan Pathan, Muniza Irshad
International Conference on Information and Communication Technologies
Secured flow of information through the network and play important role in the management information systems. In this paper I describe Secured Network Model For Corporate & Business Organization In Based On Network Level IP Security (IPSec) Encryption & Its Physical Layout Using Multilayered Approach. I have four important considerations for adoption of secured network model as secured network model for management information system.
Passwords: A Survey On Usage And Policy, Kurt W. Martinson
Passwords: A Survey On Usage And Policy, Kurt W. Martinson
Theses and Dissertations
Computer password use is on the rise. Passwords have become one of the primary authentication methods used today. It is because of their high use that organizations have started to place parameters on passwords. Are password restrictions a nuisance? What are some of the consequences that result as organizations place the burden of their computer security on passwords? This thesis analyzes the results of a survey instrument that was used to determine if individuals are using similar techniques or patterns when choosing or remembering their passwords. It also looks at how individuals feel about using passwords. In addition, the authors …
An Analysis Of A Private-Key Cryptosystem, Wei-Wey Tan
An Analysis Of A Private-Key Cryptosystem, Wei-Wey Tan
Student Works (2000-2009)
In this dissertation, we have presented a new block cipher. The proposed block cipher is a Substitution-Permutation network cryptosystem with a block length of 128 bits and key length of 256 bits. With the increased key length and block size, the proposed block cipher has greater security over DES. A modular design approach was applied. The cipher has three major building blocks and their interaction has been carefully chosen to achieve better security and performance. Algorithmic S-Boxes are used to provide confusion and nonlinearity in the cipher. The proposed cipher uses a highly diffusive diffusion layer, which is a combination …
Internet Information Server Scanner : Scanning On Url Vulnerabilities, Yu Jin Tan
Internet Information Server Scanner : Scanning On Url Vulnerabilities, Yu Jin Tan
Student Works (2000-2009)
This dissertation analyzes weaknesses on web servers, focusing on Microsoft's Internet Information Server (HS). As part of the research, an HS scanner (HS-SCAN) has been implemented to probe only on URL vulnerabilities. The need for a vulnerability scanner stems from the alarming number of successful attacks on computer systems that are connected to the Internet. The security flaws threatening e-businesses and the Internet community has prompted bona fide defense measures. Internet firewalls - gateways controlling access between one network and all the others - became a must-have for any organization connecting to the Net. If the firewall is considered the …
A Process For Vectoring Offensive Information Warfare As A Primary Weapon Option Within The United States Air Force, Sheila G. Bennett
A Process For Vectoring Offensive Information Warfare As A Primary Weapon Option Within The United States Air Force, Sheila G. Bennett
Theses and Dissertations
Consistently and comprehensively using Information Operations (IO) capabilities as primary weapon option within the Air Force is the next step to operationalizing IO within the Air Force. Doctrine and official guidance has set the variables of mission and concepts of operations, organizational structure, and IW players in place. The missing variable to operationalizing IO and probably the most difficult is the 'how' or process of the equation. This research will introduce a useable process that can be incorporated within the Air Force for integrating offensive IW activities into the current and given environment. The process is the basis for further …
Malicious Hackers: A Framework For Analysis And Case Study, Laura J. Kleen
Malicious Hackers: A Framework For Analysis And Case Study, Laura J. Kleen
Theses and Dissertations
Recent years have seen an increase in the number and severity of Information Operations (IO) attacks upon DoD resources. At a higher level, the US as a whole has come under cyber attack by individuals and groups seeking thrills, monetary gain, publicity for their causes, and myriad other goals. This effort develops a first cut model of individual hacker mentality that can be utilized to improve threat assessment, mitigate Information Assurance (IA) vulnerabilities, and improve risk assessment. Further, it is a first step toward automated characterization of Information Warfare (IW) attacks based upon hacker types. All hackers are not the …
Modeling Information Assurance, Joseph E. Beauregard
Modeling Information Assurance, Joseph E. Beauregard
Theses and Dissertations
The ever-increasing speed of information systems allows decision-makers around the world to gather, process, and disseminate information almost instantaneously. However, with this benefit there comes a price. Information is valuable and therefore a target to those who do not have it or wish to destroy it. The Internet has allowed information to flow freely, but it has also made information vulnerable to many forms of corruption. The U. S. military controls much of the world's most sensitive information, and since it cannot sacrifice losing the speed at which this information is currently processed and disseminated, it must find a way …
Mpls Vpn Simulation Using Mp-Ibgp, Tan Fong Ang
Mpls Vpn Simulation Using Mp-Ibgp, Tan Fong Ang
Student Works (2000-2009)
As Internet traffic continues to increase, companies are demanding greater speeds and better services to disseminate information to their customers, partners and employees. In order to provide reliable services and to support a variety of secure communications among a wide range of locations, Multiprotocol Label Switching Virtual Private Network (MPLS VPN) has been introduced. MPLS is an emerging technology that aims to address many of the existing issues associated with packet forwarding in today's internetworking environment. Whereas, VPN provides secure private connections through public infrastructure amongst multiple locations. MPLS based VPN provides isolation. security, simplified routing, easier provisioning as well …
A Distributed Agent Architecture For A Computer Virus Immune System, Paul K. Harmer
A Distributed Agent Architecture For A Computer Virus Immune System, Paul K. Harmer
Theses and Dissertations
Information superiority is identified as an Air Force core competency and is recognized as a key enabler for the success of future missions. Information protection and information assurance are vital components required for achieving superiority in the Infosphere, but these goals are threatened by the exponential birth rate of new computer viruses. The increased global interconnectivity that is empowering advanced information systems is also increasing the spread of malicious code and current anti-virus solutions are quickly becoming overwhelmed by the burden of capturing and classifying new viral stains. To overcome this problem, a distributed computer virus immune system (CVIS) based …
Security In Distributed Systems - A Framework For Different Application Types, Ingo Stengel
Security In Distributed Systems - A Framework For Different Application Types, Ingo Stengel
Theses
Security is a factor which decides upon the applicability of distributed applications. Therefore this thesis deals with security in distributed systems. The complexity of the existing distributed technologies makes it necessary to reduce the number of distributed technologies considered in this thesis, i.e. concentrating on: Java, Mobile Agents and CORBA, where only Java-based mobile agents will be considered.
After a short review of basic security principles including firewalls, existing security problems in the above mentioned distributed technologies are analysed. Additional generic problems in distributed systems are outlined.
Solutions are referring to two different areas: those regarding security problems with firewalls …
Network Security Versus Network Connectivity: A Framework For Addressing The Issues Facing The Air Force Medical Community, Franklin E. Cunningham Jr.
Network Security Versus Network Connectivity: A Framework For Addressing The Issues Facing The Air Force Medical Community, Franklin E. Cunningham Jr.
Theses and Dissertations
The Air Force has instituted Barrier Reef to protect its networks. The Air Force medical community operates network connections that are incompatible with Barrier Reef. To overcome this problem, OASD(HA) directed the Tri-Service Management Program Office (TIMPO) to develop an architecture that protects all military health systems and allows them to link with all three services and outside partners. This research studied the underlying networking issues and formed a framework based on data from network experts from the Air Force's medical centers and their base network organizations. The findings were compared TIMPO and a composite framework was developed that more …
Stackguard: Automatic Adaptive Detection And Prevention Of Buffer-Overflow Attacks, Crispin Cowan, Calton Pu, David Maier, Heather Hinton, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, Qian Zhang
Stackguard: Automatic Adaptive Detection And Prevention Of Buffer-Overflow Attacks, Crispin Cowan, Calton Pu, David Maier, Heather Hinton, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, Qian Zhang
Computer Science Faculty Publications and Presentations
This paper presents a systematic solution to the persistent problem of buffer overflow attacks. Buffer overflow attacks gained notoriety in 1988 as part of the Morris Worm incident on the Internet. While it is fairly simple to fix individual buffer overflow vulnerabilities, buffer overflow attacks continue to this day. Hundreds of attacks have been discovered, and while most of the obvious vulnerabilities have now been patched, more sophisticated buffer overflow attacks continue to emerge.
We describe StackGuard: a simple compiler technique that virtually eliminates buffer overflow vulnerabilities with only modest performance penalties. Privileged programs that are recompiled with the StackGuard …
Analyzing And Improving Stochastic Network Security: A Multicriteria Prescriptive Risk Analysis Model, David L. Lyle
Analyzing And Improving Stochastic Network Security: A Multicriteria Prescriptive Risk Analysis Model, David L. Lyle
Theses and Dissertations
This research optimized two measures of network security by hardening components and improving their reliability. A common measure of effectiveness (MOE) for networks is statistical reliability, which ignores the effects of hostile actions. A new MOE which includes hostile actions was developed. Both measures require component reliability functions, derived using fault trees. Fuzzy Logic and Monte Carlo simulation were used to quantify uncertainty. Results from the model are compared to traditional Risk Assessment results.
A Specialization Toolkit To Increase The Diversity Of Operating Systems, Calton Pu, Andrew P. Black, Crispin Cowan, Jonathan Walpole, Charles Consel
A Specialization Toolkit To Increase The Diversity Of Operating Systems, Calton Pu, Andrew P. Black, Crispin Cowan, Jonathan Walpole, Charles Consel
Computer Science Faculty Publications and Presentations
Virus and worm attacks that exploit system implementation details can be countered with a diversified set of implementations. Furthermore, immune systems show that attacks from previously unknown organisms require effective dynamic response. In the Synthetix project, we have been developing a specialization toolkit to improve the performance of operating system kernels. The toolkit helps programmers generate and manage diverse specialized implementations of software modules. The Tempo-C specializer tool generates different versions for both compile-time and run-time specialization. We are now adapting the toolkit to improve operating system survivability against implementations attacks.