Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (22)
- Social and Behavioral Sciences (21)
- Computer Engineering (20)
- Medicine and Health Sciences (19)
- Business (14)
-
- Health Information Technology (13)
- Public Affairs, Public Policy and Public Administration (6)
- Digital Communications and Networking (5)
- Legal Studies (5)
- Communication (4)
- Defense and Security Studies (4)
- Education (4)
- Health and Medical Administration (4)
- Criminology (3)
- Forensic Science and Technology (3)
- OS and Networks (3)
- Psychology (3)
- Sociology (3)
- Business Administration, Management, and Operations (2)
- Communication Technology and New Media (2)
- Criminology and Criminal Justice (2)
- E-Commerce (2)
- Electrical and Computer Engineering (2)
- Law (2)
- Organizational Behavior and Theory (2)
- Other Computer Sciences (2)
- Science and Technology Studies (2)
- Keyword
-
- Security (74)
- [RSTDPub] (54)
- Information security (30)
- Privacy (24)
- Cyber security (21)
-
- Computer security (18)
- Intrusion detection (17)
- Cybersecurity (16)
- Encryption (15)
- Network security (15)
- Authentication (14)
- Digital forensics (13)
- Blockchain (11)
- Risk management (11)
- Biometrics (10)
- Vulnerability (10)
- [aism] (10)
- Anomaly detection (9)
- Machine learning (9)
- Risk (9)
- Risk assessment (9)
- Android (8)
- Critical Infrastructure (8)
- Phishing (8)
- Wireless (8)
- Cloud computing (7)
- Data security (7)
- Healthcare (7)
- Information Security (7)
- Information security management (7)
- Publication Year
- Publication
-
- Australian Information Security Management Conference (224)
- Research outputs 2022 to 2026 (84)
- Australian Digital Forensics Conference (50)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
-
- International Cyber Resilience conference (19)
- Theses: Doctorates and Masters (16)
- Theses : Honours (15)
- Research outputs pre 2011 (14)
- Australian eHealth Informatics and Security Conference (10)
- Australian Security and Intelligence Conference (7)
- Research outputs 2011 (3)
- Research outputs 2012 (2)
- Research outputs 2013 (2)
- Research Datasets (1)
- Publication Type
- File Type
Articles 301 - 330 of 532
Full-Text Articles in Information Security
A Survey Of Computer And Network Security Support From Computer Retailers To Consumers In Australia, Patryk Szewczyk
A Survey Of Computer And Network Security Support From Computer Retailers To Consumers In Australia, Patryk Szewczyk
Australian Information Security Management Conference
Previously undertaken research suggests that novice end-users rely on computer retailers for security advice and support during and after a sale has occurred. This paper documents the survey results of computer and network security support provided to consumers by retailers in Perth, Western Australia between 2011 and 2012. The conducted survey shows that in the majority of cases, computers retailers were favourable in providing support and recommendations. However, these views were found to be flawed, confusing and do little to ensure that end-users are not victimized by cyber crime.
Corporate Security: Using Knowledge Construction To Define A Practising Body Of Knowledge, David Brooks
Corporate Security: Using Knowledge Construction To Define A Practising Body Of Knowledge, David Brooks
Research outputs 2012
Security is a multidimensional concept, with many meanings, practising domains, and heterogeneous occupations. Therefore, it is difficult to define security as a singular concept, although understanding may be achieved by its applied context in presenting a domicile body of knowledge. There have been studies that have presented a number of corporate security bodies of knowledge; however, there is still restricted consensus. From these past body of knowledge studies, and supported by multidimensional scaling knowledge mapping, a body of knowledge framework is put forward, integrating core and allied knowledge categories. The core knowledge categories include practise areas such as risk management, …
On The Effectiveness Of Intrusions Into Zigbee-Based Wireless Sensor Networks, Michael Johnstone, Jeremy Jarvis
On The Effectiveness Of Intrusions Into Zigbee-Based Wireless Sensor Networks, Michael Johnstone, Jeremy Jarvis
Research outputs 2012
Wireless Sensor Networks are becoming popular as a means of collecting data by military organisations, public utilities, motor vehicle manufacturers and security firms. Unfortunately, the devices on such networks are often insecure by default, which creates problems in terms of the confidentiality and integrity of data transmitted across such networks. This paper discusses attacks that were successful on a simple network consisting of nodes using the ZigBee protocol stack and proposes defences to thwart these attacks, thus leading to increased user confidence in the ability of organisations to provide secure and effective services. The outcomes were that it was possible …
A Phishing Model And Its Applications To Evaluating Phishing Attacks, Narasimha Shashidhar, Lei Chen
A Phishing Model And Its Applications To Evaluating Phishing Attacks, Narasimha Shashidhar, Lei Chen
International Cyber Resilience conference
Phishing is a growing threat to Internet users and causes billions of dollars in damage every year. In this paper, we present a theoretical yet practical model to study this threat in a formal manner. While it is folklore knowledge that a successful phishing attack entails creating messages that are indistinguishable from the natural, expected messages by the intended victim, this concept has not been formalized. Our model captures phishing in terms of this indistinguishability between the natural and phishing message distributions. To the best of our knowledge, this is the first study that places phishing on a concrete theoretical …
Gap Analysis Of Intrusion Detection In Smart Grids, Nishchal Kush, Ernest Foo, Ejaz Ahmed, Irfan Ahmed, Andrew Clark
Gap Analysis Of Intrusion Detection In Smart Grids, Nishchal Kush, Ernest Foo, Ejaz Ahmed, Irfan Ahmed, Andrew Clark
International Cyber Resilience conference
Given the recent emergence of the smart grid and smart grid related technologies, their security is a prime concern. Intrusion detection provides a second line of defence. However, conventional intrusion detection systems (IDSs) are unable to adequately address the unique requirements of the smart grid. This paper presents a gap analysis of contemporary IDSs from a smart grid perspective. This paper highlights the lack of adequate intrusion detection within the smart grid and discusses the limitations of current IDSs approaches. The gap analysis identifies current IDSs as being unsuited to smart grid application without significant changes to address smart grid …
A Threat To Cyber Resilience: A Malware Rebirthing Botnet, Murray Brand, Craig Valli, Andrew Woodward
A Threat To Cyber Resilience: A Malware Rebirthing Botnet, Murray Brand, Craig Valli, Andrew Woodward
International Cyber Resilience conference
This paper presents a threat to cyber resilience in the form of a conceptual model of a malware rebirthing botnet which can be used in a variety of scenarios. It can be used to collect existing malware and rebirth it with new functionality and signatures that will avoid detection by AV software and hinder analysis. The botnet can then use the customized malware to target an organization with an orchestrated attack from the member machines in the botnet for a variety of malicious purposes, including information warfare applications. Alternatively, it can also be used to inject known malware signatures into …
Why Australia's E-Health System Will Be A Vulnerable National Asset , Patricia A. Williams
Why Australia's E-Health System Will Be A Vulnerable National Asset , Patricia A. Williams
International Cyber Resilience conference
Connecting Australian health services and the e-health initiative is a major talking point currently. Many issues are presented as key to its success including solving issues with confidentiality and privacy. However the largest problem may not be these issues in sharing information but the fact that the point of origin and storage of such records is still relatively insecure. Australia aims to have a Personally Controlled Electronic Health Record in 2012 and this is underpinned by a national network for e-health. It is this very foundation that becomes the critical infrastructure, with general practice the cornerstone for its success. Yet, …
Securing The Elderly: A Developmental Approach To Hypermedia Based Online Information Security For Senior Novice Computer Users, David M. Cook, Patryk Szewczyk, Krishnun Sansurooah
Securing The Elderly: A Developmental Approach To Hypermedia Based Online Information Security For Senior Novice Computer Users, David M. Cook, Patryk Szewczyk, Krishnun Sansurooah
International Cyber Resilience conference
Whilst security threats to the general public continue to evolve, elderly computer users with limited skill and knowledge are left playing catch-up in an ever-widening gap in fundamental cyber-related comprehension. As a definable cohort, the elderly generally lack awareness of current security threats, and remain under-educated in terms of applying appropriate controls and safeguards to their computers and networking devices. This paper identifies that web-based computer security information sources do not adequately provide helpful information to senior citizen end-users in terms of both design and content. It subsequently demonstrates a solution designed with the elderly, yet novice, end-user in mind. …
On The Detection Of Hidden Terrorist Cells Immersed In Peer To Peer Networks, Belinda A. Chiera
On The Detection Of Hidden Terrorist Cells Immersed In Peer To Peer Networks, Belinda A. Chiera
International Cyber Resilience conference
Hidden terrorist cells in high dimensional communications networks arise when terrorists camouflage connectivity to appear randomly connected to the background network. We investigate hidden network detectability when the background network does not support terrorist activities. Using two September 11 terrorist networks as the test bed and a network measure called assortativity, we suggest hidden terrorist networks can behave as Peer-to-Peer networks. We compare the September 11 hidden networks with Peer-to-Peer networks containing embedded terrorist networks, as well as with generic Peer-to-Peer networks. Using Peer-to-Peer characteristics and social network group-based centralities, we show that for certain Peer-to-Peer networks it is possible …
K Anonymous Private Query Based On Blind Signature And Oblivious Transfer, Russell Paulet, Golam Kaosar, Xun Yi
K Anonymous Private Query Based On Blind Signature And Oblivious Transfer, Russell Paulet, Golam Kaosar, Xun Yi
International Cyber Resilience conference
In this paper, we consider a scenario where there are a group of clients and a database server, and a client wishes to query the database, but does not want to reveal her or his query to the server. Current solutions for this problem are based on oblivious transfer, which usually requires high communication overhead. To reduce the communication overhead, we propose three k-anonymous private query protocols. Our first protocol is based on blind signature, where the server cannot determine the identity of the querying client from the group. Our second protocol is based on k-anonymous oblivious transfer, where the …
A Comparative Analysis Of The Security Of Internet Banking In Australia:A Customer Perspective, Panida Subsorn, Sunsern Limwiriyakul
A Comparative Analysis Of The Security Of Internet Banking In Australia:A Customer Perspective, Panida Subsorn, Sunsern Limwiriyakul
International Cyber Resilience conference
Internet has its own inherent security issues in terms of confidentiality, integrity and privacy. The main impact of these kinds of issues is specifically on the banking industry as they have increased their Internet banking facilities in order to reduce costs and provide better services and banking convenience to their Internet banking customers. However, banking customers have not had a choice of Internet banking mainly due to the fact that they are already tied to whatever form of Internet banking that their current bank provides. This paper therefore examined Internet banking security systems in Australian banks by creating the proposed …
Novel Pseudo Random Number Generation Using Variant Logic Framework, Jeffrey Zheng
Novel Pseudo Random Number Generation Using Variant Logic Framework, Jeffrey Zheng
International Cyber Resilience conference
Cyber Security requires cryptology for the basic protection. Among different ECRYPT technologies, stream cipher plays a central role in advanced network security applications; in addition, pseudo-random number generators are placed in the core position of the mechanism. In this paper, a novel method of pseudo-random number generation is proposed to take advantage of the large functional space described using variant logic, a new framework for binary logic. Using permutation and complementary operations on classical truth table to form relevant variant table, numbers can be selected from table entries having pseudo-random properties. A simple generation mechanism is described and shown and …
An Agile It Security Model For Project Risk Assessment, Damien Hutchinson, Heath Maddern, Jason Wells
An Agile It Security Model For Project Risk Assessment, Damien Hutchinson, Heath Maddern, Jason Wells
Australian Information Security Management Conference
There are two fundamental challenges in effectively performing security risk assessment in today's IT projects. The first is the project manager's need to know what IT security risks face the project before the project begins. At this stage IT security staff are unable to answer this question without first knowing the system requirements for the project which are yet to be defined. Second organisations that deal with a large project throughput each year find the current IT security risk assessment process to be tedious and expensive, especially when the same process has to be repeated for each individual project. This …
Cloud Computing Concerns In Developing Economies, Mathias Mujinga, Baldreck Chipangura
Cloud Computing Concerns In Developing Economies, Mathias Mujinga, Baldreck Chipangura
Australian Information Security Management Conference
Cloud computing promises to bring substantial benefits to how organizations conduct their businesses and the way their services reach out to potential consumers. Cloud computing is a welcome initiative for small businesses that cannot afford to invest in ICT infrastructure but need to benefit from the rewards of conducting business online. In developing economies, there are challenges that face cloud services providers and their consumers. Broadband network access was identified as the main essential service for a successful cloud computing offering. The objective of this paper is to give background information on the security issues in cloud computing, and highlight …
Insecurity By Obscurity Continues: Are Adsl Router Manuals Putting End-Users At Risk, Kim Andersson, Patryk Szewczyk
Insecurity By Obscurity Continues: Are Adsl Router Manuals Putting End-Users At Risk, Kim Andersson, Patryk Szewczyk
Australian Information Security Management Conference
The quantity and sophistication of threats targeting ADSL routers is on a steady increase. There is a reliance on end-users to ensure that their ADSL router is secure by continually updating the firmware, using strong authentication credentials, and enabling the in-built firewall. However, to do this, the end-user must be presented with well written procedural instructions, and an explanation of why this is important. This paper examines the design quality and security content provided by vendors in ADSL router manuals. This paper reveals that the lack of security related content and poor overall design could impact on end-users’ interpretation and …
Penetration Of Zigbee-Based Wireless Sensor Networks, Michael N. Johnstone, Jeremy A. Jarvis
Penetration Of Zigbee-Based Wireless Sensor Networks, Michael N. Johnstone, Jeremy A. Jarvis
Australian Information Warfare and Security Conference
Wireless Sensor Networks are becoming popular as a simple means of collecting data by public utilities, motor vehicle manufacturers and other organisations. Unfortunately the devices on such networks are often insecure by default, which presents problems in terms of the integrity of the data provided across those networks. This paper explores a range of attacks that were successful on a network consisting of nodes using the ZigBee protocol stack and proposes defences that can be put in place to circumvent these attacks thus leading to more secure systems and increasing user confidence.
A Proposal For Utilising Active Jamming For The Defence Of Rfid Systems Against Attack, Christopher Bolan
A Proposal For Utilising Active Jamming For The Defence Of Rfid Systems Against Attack, Christopher Bolan
Australian Information Security Management Conference
With a range of documented attacks against RFID systems a majority of the current literature is focused on the encryption of the communication. This paper addresses such attacks by proposing alternative means of protection through utilising some of the same methods that may be used to attack these systems. The proposed methods would allow for increased security within a range of RFID applications whilst still allowing for normal operations compliant with the relevant standards.
User Perceptions Of End User License Agreements In The Smartphone Environment, Hamish Cotton, Christopher Bolan
User Perceptions Of End User License Agreements In The Smartphone Environment, Hamish Cotton, Christopher Bolan
Australian Information Security Management Conference
With the increasing usage of smartphones as a computing platform has come alongside the movement of End User License Agreements to such platforms. The smartphone platform brings new issues to these agreements especially with the advent of app stores, which allow access to a large consumer base to small or unknown developers. This survey conducted in Perth, Western Australia looked at user perceptions of EULAs on smartphone devices. The results show that a majority of users do not read such agreements citing issues of readability and length. Even amongst those that do read the agreements there is a majority feeling …
A Longitudinal Study Of Wi-Fi Access Point Security Inthe Perth Central Business District, Emil Jacobson, Andrew Woodward
A Longitudinal Study Of Wi-Fi Access Point Security Inthe Perth Central Business District, Emil Jacobson, Andrew Woodward
Australian Information Security Management Conference
This study collected data in 2008 and 2011 in relation to the level of apparent security of wireless network access points in the Perth CBD. It also compared this data to a comparable study conducted in 2004. The aim was to determine whether businesses were using an appropriate level of encryption to protect their wireless networks. A pre-determined route was followed which traced the Perth CBD and the open source wireless network auditing tool Kismet was used to survey the wireless networks. In 2008, approximately 1300 access points were discovered in the Perth CBD, this number climbing to approximately 3400 …
Modelling Misuse Cases As A Means Of Capturing Security Requirements, Michael N. Johnstone
Modelling Misuse Cases As A Means Of Capturing Security Requirements, Michael N. Johnstone
Australian Information Security Management Conference
Use cases as part of requirements engineering are often seen as an essential part of systems development in many methodologies. Given that modern, security-oriented software development methods such as SDL , SQUARE and CLASP place security at the forefront of product initiation, design and implementation, the focus of requirements elicitation must now move to capturing security requirements so as not to replicate past errors. Misuse cases can be an effective tool to model security requirements. This paper uses a case study to investigate the generation of successful misuse cases by employing the STRIDE framework as used in the SDL.
Australian Primary Care Health Check: Who Is Accountable For Information Security?, Rachel J. Mahncke, Patricia A H Williams
Australian Primary Care Health Check: Who Is Accountable For Information Security?, Rachel J. Mahncke, Patricia A H Williams
Australian Information Security Management Conference
Primary healthcare in Australia is vulnerable to a multitude of information security threats and insecure practices. This situation is increasingly important in the developing e-health environment. Information security is everyone’s responsibility and it is extensively documented in international standards and best practice frameworks, that this responsibility should be part of formal job descriptions. This necessitates incorporation of security at a functional level for all staff. These responsibilities are integral to demonstrable accountability, together with an authority to take action. Indeed, whilst senior management will ultimately be held accountable, staff need to be aware of the potential issues, given the responsibility …
An Exploratory Study Of Erm Perception In Oman And Proposing A Maturity Model For Risk Optimization, Arun N. Shivashankarappa, D Ramalingam, Leonid Smalov, N Anbazhagan
An Exploratory Study Of Erm Perception In Oman And Proposing A Maturity Model For Risk Optimization, Arun N. Shivashankarappa, D Ramalingam, Leonid Smalov, N Anbazhagan
Australian Information Security Management Conference
Enterprise Risk management is a process vital to enterprise governance which has gained tremendous momentum in modern business due to the dynamic nature of threats, vulnerability and stringent regulatory requirements. The business owners have realized that, risk creates opportunity which in turn creates value. Identifying and mitigating risk proactively across the enterprise is the purview of Enterprise Risk Management (ERM).However, key errors in the ERM process such as misinterpretation of statistical data, overlooking change management, inadequate attention to supply chain interdependencies, excessive trust of insiders and business partners, ambiguous grouping of risks and poor documentation has contributed significantly to the …
Efficient And Expressive Fully Secure Attribute-Based Signature In The Standard Model, Piyi Yang, Tanveer A. Zia, Zhenfu Cao, Xiaolei Dong
Efficient And Expressive Fully Secure Attribute-Based Signature In The Standard Model, Piyi Yang, Tanveer A. Zia, Zhenfu Cao, Xiaolei Dong
Australian Information Security Management Conference
Designing a fully secure (adaptive-predicate unforgeable and perfectly private) attribute-based signature (ABS), which allows a signer to choose a set of attributes in stead of a single string representing the signer‘s identity, under standard cryptographic assumption in the standard model is a challenging problem. Existing schemes are either too complicated or only proved in the generic group model. In this paper, we present an efficient fully secure ABS scheme in the standard model based on q-parallel BDHE assumption which is more practical than the generic group model used in the previous scheme. To the best of our knowledge, our scheme …
Designing A Knowledge Distribution Simulator, Martin Hill, Graham Fletcher
Designing A Knowledge Distribution Simulator, Martin Hill, Graham Fletcher
Australian Information Warfare and Security Conference
To make good decisions, we need to be suitably informed. 'Good' and 'Suitably' in this case depend on the informational needs of the decision and the mechanisms of getting the information to the decision maker in time. The trade-offs in qualities, quantities, timeliness, impacts on other activities, and so on are infamously wickedly complex, and usually buried in a clutter of special circumstances, personality characteristics, environments unsuitable for study, and so on. Decision-making systems can be explored using case studies and exercises, but these are limited by the expense and time of using real people. A virtual simulator for large …
Implementation Of Iso 27001 In Saudi Arabia – Obstacles, Motivations, Outcomes, And Lessons Learned, Belal Abusaad, Fahad A. Saeed, Khaled Alghathbar, Bilal Khan
Implementation Of Iso 27001 In Saudi Arabia – Obstacles, Motivations, Outcomes, And Lessons Learned, Belal Abusaad, Fahad A. Saeed, Khaled Alghathbar, Bilal Khan
Australian Information Security Management Conference
Protecting information assets is very vital to the core survival of an organization. With the increase in cyberattacks and viruses worldwide, it has become essential for organizations to adopt innovative and rigorous procedures to keep these vital assets out of the reach of exploiters. Although complying with an international information security standard such as ISO 27001 has been on the rise worldwide, with over 7000 registered certificates, few companies in Saudi Arabia are ISO 27001 certified. In this paper, we explore the motives, obstacles, challenges, and outcomes for a Saudi organization during their implementation of ISO 27001, with the goal …
An Investigation Into Darknets And The Content Available Via Anonymous Peer-To-Peer File Sharing, Symon Aked
An Investigation Into Darknets And The Content Available Via Anonymous Peer-To-Peer File Sharing, Symon Aked
Australian Information Security Management Conference
Media sites, both technical and non-technical, make references to Darknets as havens for clandestine file sharing. They are often given an aura of mystique; where content of any type is just a mouse click away. However, can Darknets really be easily accessed, and do they provide access to material that would otherwise be difficult to obtain? This paper investigates which Darknets are easily discovered, the technical designs and methods used to hide content on the networks, the tools needed to join, and ultimately what type and quantities of files can be found on anonymous peer-to-peer file sharing networks. This information …
Evaluation Of Users’ Perspective On Voip’S Security Vulnerabilities, Alireza Heravi, Sameera Mubarak
Evaluation Of Users’ Perspective On Voip’S Security Vulnerabilities, Alireza Heravi, Sameera Mubarak
Australian Information Security Management Conference
Voice over Internet protocol (VoIP) represents a major newish trend in telecommunications and an alternative to traditional phone systems. VoIP uses IP networks and therefore inherits their vulnerabilities. Adding voice traffic to IP networks complicates security issues and introduces a range of vulnerabilities. A VoIP system may face either an exclusive attack or an attack to the underlying IP network. The significance of security and privacy in VoIP communications are well known, and many studies mostly from the technical perspective have been published. However to date, no known research has been conducted to evaluate users’ perspectives on these issues. In …
Understanding The Management Of Information Security Controls In Practice, Daniel Bachlechner, Ronald Maier, Frank Innerhofer-Oberperfler, Lukas Demetz
Understanding The Management Of Information Security Controls In Practice, Daniel Bachlechner, Ronald Maier, Frank Innerhofer-Oberperfler, Lukas Demetz
Australian Information Security Management Conference
The ever greater reliance on complex information technology environments together with dynamically changing threat scenarios and increasing compliance requirements make an efficient and effective management of information security controls a key concern for most organizations. Good practice collections such as COBIT and ITIL as well as related standards such as the ones belonging to the ISO/IEC 27000 family provide useful starting points for control management. However, neither good practice collections and standards nor scholarly literature explain how the management of controls actually is performed in organizations or how the current state-of-practice can be improved. A series of interviews with information …
A Risk Index Model For Security Incident Prioritisation, Nor Badrul Anuar, Steven Furnell, Maria Papadaki, Nathan Clarke
A Risk Index Model For Security Incident Prioritisation, Nor Badrul Anuar, Steven Furnell, Maria Papadaki, Nathan Clarke
Australian Information Security Management Conference
With thousands of incidents identified by security appliances every day, the process of distinguishing which incidents are important and which are trivial is complicated. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the Analytic Hierarchy Process (AHP). The model uses indicators, such as criticality, maintainability, replaceability, and dependability as decision factors to calculate incidents’ risk index. The RIM was validated using the MIT DARPA LLDOS 1.0 dataset, and the results were compared against the combined priorities of the Common Vulnerability Scoring System (CVSS) v2 and Snort Priority. The experimental …
Seniors Language Paradigms: 21st Century Jargon And The Impact On Computer Security And Financial Transactions For Senior Citizens, David M. Cook, Patryk Szewczyk, Krishnun Sansurooah
Seniors Language Paradigms: 21st Century Jargon And The Impact On Computer Security And Financial Transactions For Senior Citizens, David M. Cook, Patryk Szewczyk, Krishnun Sansurooah
Australian Information Security Management Conference
Senior Citizens represent a unique cohort of computer users insomuch as they have come to the field of computer usage later in life, as novices compared to other users. As a group they exhibit a resentment, mistrust and ignorance towards cyber related technology that is born out of their educational and social experiences prior to widespread information technology. The shift from analogue to digital proficiency has been understated for a generation of citizens who were educated before computer usage and internet ubiquity. This paper examines the language difficulties encountered by senior citizens in attempting to engage in banking and communications …