Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (22)
- Social and Behavioral Sciences (21)
- Computer Engineering (20)
- Medicine and Health Sciences (19)
- Business (14)
-
- Health Information Technology (13)
- Public Affairs, Public Policy and Public Administration (6)
- Digital Communications and Networking (5)
- Legal Studies (5)
- Communication (4)
- Defense and Security Studies (4)
- Education (4)
- Health and Medical Administration (4)
- Criminology (3)
- Forensic Science and Technology (3)
- OS and Networks (3)
- Psychology (3)
- Sociology (3)
- Business Administration, Management, and Operations (2)
- Communication Technology and New Media (2)
- Criminology and Criminal Justice (2)
- E-Commerce (2)
- Electrical and Computer Engineering (2)
- Law (2)
- Organizational Behavior and Theory (2)
- Other Computer Sciences (2)
- Science and Technology Studies (2)
- Keyword
-
- Security (74)
- [RSTDPub] (54)
- Information security (30)
- Privacy (24)
- Cyber security (21)
-
- Computer security (18)
- Intrusion detection (17)
- Cybersecurity (16)
- Encryption (15)
- Network security (15)
- Authentication (14)
- Digital forensics (13)
- Blockchain (11)
- Risk management (11)
- Biometrics (10)
- Vulnerability (10)
- [aism] (10)
- Anomaly detection (9)
- Machine learning (9)
- Risk (9)
- Risk assessment (9)
- Android (8)
- Critical Infrastructure (8)
- Phishing (8)
- Wireless (8)
- Cloud computing (7)
- Data security (7)
- Healthcare (7)
- Information Security (7)
- Information security management (7)
- Publication Year
- Publication
-
- Australian Information Security Management Conference (224)
- Research outputs 2022 to 2026 (84)
- Australian Digital Forensics Conference (50)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
-
- International Cyber Resilience conference (19)
- Theses: Doctorates and Masters (16)
- Theses : Honours (15)
- Research outputs pre 2011 (14)
- Australian eHealth Informatics and Security Conference (10)
- Australian Security and Intelligence Conference (7)
- Research outputs 2011 (3)
- Research outputs 2012 (2)
- Research outputs 2013 (2)
- Research Datasets (1)
- Publication Type
- File Type
Articles 391 - 420 of 532
Full-Text Articles in Information Security
Ascent Of Asymmetric Risk In Information Security: An Initial Evaluation., Tobias Ruighaver, Matthew Warren, Atif Ahmad
Ascent Of Asymmetric Risk In Information Security: An Initial Evaluation., Tobias Ruighaver, Matthew Warren, Atif Ahmad
Australian Information Warfare and Security Conference
Dramatic changes in the information security risk landscape over several decades have not yet been matched by similar changes in organizational information security, which is still mainly based on a mindset that security is achieved through extensive preventive controls. As a result, maintenance cost of information security is increasing rapidly, but this increased expenditure has not really made an attack more difficult. The opposite seems to be true, information security attacks have become easier to perpetrate and appear more like information warfare tactics. At the same time, the damage caused by a successful attack has increased significantly and may sometimes …
Information Security Disclosure: A Case Study, I Rosewall, M J. Warren
Information Security Disclosure: A Case Study, I Rosewall, M J. Warren
Australian Information Security Management Conference
New social networking systems such as Facebook are an ever evolving and developing means of social interaction, which is not only being used to disseminate information to family, friends and colleagues but as a way of meeting and interacting with "strangers" through the advent of a large number of social applications. This paper will focus upon the impact of Generation F - the Facebook Generation and their attitudes to security. The paper will be based around discussing the findings of a major UK case study and the implications that this has. The case study identifies 51 recommendations to improve the …
Strong Authentication For Web Services Using Smartcards, D S. Stienne, Nathan Clarke, Paul Reynolds
Strong Authentication For Web Services Using Smartcards, D S. Stienne, Nathan Clarke, Paul Reynolds
Australian Information Security Management Conference
The popularity of the Internet and the variety of services it provides has been immense. Unfortunately, many of these services require the user to register and subsequently login to the system in order to access them. This has resulted in the user having to remember a multitude of username and password combinations in order to use the service securely. However, literature has clearly demonstrated this is not an effective approach, as users will frequently choose simple passwords, write them down, share them or use the same password for multiple systems. This paper proposes a novel concept where Internet users authenticate …
Security Issues Challenging Facebook, S Leitch, M Warren
Security Issues Challenging Facebook, S Leitch, M Warren
Australian Information Security Management Conference
The advancement in Internet and bandwidth capability has resulted in a number of new applications to be developed; many of these newer applications are described as being Web 2. A Web 2 application such as Facebook has allowed people around the world to interact together. One of the interesting aspects of Facebook is the use of third parties applications and the interactions that this allows.Not surprisingly, the problems that exist in the real world such as theft, fraud, vandalism also exist in online Web 2 environments. This paper explores and categorises several security issues within the Facebook environment. It contributes …
Improving An Organisations Existing Information Technology Policy To Increase Security, Shane Talbot, Andrew Woodward
Improving An Organisations Existing Information Technology Policy To Increase Security, Shane Talbot, Andrew Woodward
Australian Information Security Management Conference
A security policy which includes the appropriate phases of implementation, enforcement, auditing and review is vital to protecting an organisations information security. This paper examined the information security policy of a government organisation in response to a number of perceived shortcomings. The specific issues identified relating to the organisations security policy as a result of this investigation were as follows: a culture of ignoring policies, minimal awareness of policies, minimal policy enforcement, policy updating and review ad hoc at best, policy framework, lengthy policy development and approval process, no compliance program, no formal non-compliance reporting and an apparent inconsistent enforcement …
Review Of Browser Extensions, A Man-In-The-Browser Phishing Techniques Targeting Bank Customers, Nattakant Utakrit
Review Of Browser Extensions, A Man-In-The-Browser Phishing Techniques Targeting Bank Customers, Nattakant Utakrit
Australian Information Security Management Conference
Initially, online scammers (phishers) used social engineering techniques to send emails to solicit personal information from customer in order to steal money from their Internet banking account. Data, such as passwords or bank account details, could be further used for other criminal activities. For instance, the scammers may intend to leave the victim’s information behind after they have successfully committed the crime so that the police can suspect the visible evidence as a suspicious criminal. Many customers are now aware of the need to protect their banking details from the phishers by not providing any sensitive information. Recently, phishing attacks …
Assessment Of Internationalised Domain Name Homograph Attack Mitigation, Peter Hannay, Christopher Bolan
Assessment Of Internationalised Domain Name Homograph Attack Mitigation, Peter Hannay, Christopher Bolan
Australian Information Security Management Conference
With the advent of internationalised domains the threat posed by non-english character sets has eventuated. Whilst this phenomenon remains well known in the development and internet industry the actual implementations of popular applications have been tested to determine their resilience to homograph based attack. The research found that most provided features that overcome such attacks, but there remain a few notable exceptions. Should an attacker take advantage of such oversights a victim would likely not be able to spot a fraudulent site or email and thus provide a perfect platform for subsequent attack.
The 2009 Personal Firewall Robustness Evaluation, Ken Pydayya, Peter Hannay, Patryk Szewczyk
The 2009 Personal Firewall Robustness Evaluation, Ken Pydayya, Peter Hannay, Patryk Szewczyk
Australian Information Security Management Conference
The evolution of the internet as a platform for commerce, banking, general information and personal communications has resulted in a situation where many individuals who may not have previously required internet access now require this connectivity as part of their everyday lives. In addition to this the widespread adoption of mobile broadband has lead to an increasing number of individuals having public facing IP addresses with no firewall appliances present. This situation has dramatically increased reliance on personal firewalls as the first and often last defence against intruders (human and malware alike). The evaluation performed demonstrates the capabilities of current …
Exploring The Relationship Between Organizational Culture And Information Security Culture, Joo S. Lim, Shanton Chang, Sean Maynard, Atif Ahmad
Exploring The Relationship Between Organizational Culture And Information Security Culture, Joo S. Lim, Shanton Chang, Sean Maynard, Atif Ahmad
Australian Information Security Management Conference
Managing Information Security is becoming more challenging in today’s business because people are both a cause of information security incidents as well as a key part of the protection from them. As the impact of organizational culture (OC) on employees is significant, many researchers have called for the creation of information security culture (ISC) in organizations to influence the actions and behaviour of employees towards better organizational information security. Although researchers have called for the creation of ISC to be embedded in organizations, nonetheless, literature suggests that little past research examining the relationship between the nature of OC and ISC. …
A Spoofing Attack Against An Epc Class One Rfid System, Christopher Bolan
A Spoofing Attack Against An Epc Class One Rfid System, Christopher Bolan
Australian Information Security Management Conference
In computing the term spoofing historically referred to the creation of TCP/IP packets using another device’s valid IP address to gain an advantage. The Electronic Product Code (EPC) RFID system was investigated to test the efficacy of spoofing a valid tag response to basic requests. A radio frequency transmission device was constructed to determine whether a valid reader could distinguish between the response of an actual tag and a spoofed response. The results show that the device was able to successfully deceive the EPC reader and further, to replace actual tag responses with a spoofed response. The potential for such …
When You Can't See The Forest For The Domains: Why A Two Forest Model Should Be Used To Achieve Logical Segregation Between Scada And Corporate Networks, Andrew Woodward, Brett Turner
When You Can't See The Forest For The Domains: Why A Two Forest Model Should Be Used To Achieve Logical Segregation Between Scada And Corporate Networks, Andrew Woodward, Brett Turner
Australian Information Warfare and Security Conference
The increasing convergence of corporate and control systems networks creates new challenges for the security of critical infrastructure. There is no argument that whilst this connection of what was traditionally an isolated network, to a usually internet enabled corporate network, is unavoidable, segregation must be maintained. One such challenge presented is how to properly and appropriately configure an active directory environment to allow for exchange of required data, but still maintain the security goal of separation of the two networks. This paper argues that while separate domains may seem to achieve this goal, the reality is that a domain is …
Challenges In Improving Information Security Practice In Australian General Practice, Donald C. Mcdermid, Rachel J. Mahncke, Patricia A. Williams
Challenges In Improving Information Security Practice In Australian General Practice, Donald C. Mcdermid, Rachel J. Mahncke, Patricia A. Williams
Australian Information Security Management Conference
The status of information security in Australian medical general practice is discussed together with a review of the challenges facing small practices that often lack the technical knowledge and skill to secure patient information by themselves. It is proposed that an information security governance framework is required to assist practices in identifying weaknesses and gaps and then to plan and implement how to overcome their shortcomings through policies, training and changes to processes and management structure.
Security Requirements Engineering-The Reluctant Oxymoron, Michael N. Johnstone
Security Requirements Engineering-The Reluctant Oxymoron, Michael N. Johnstone
Australian Information Security Management Conference
Security is a focus in many systems that are developed today, yet this aspect of systems development is often relegated when the shipping date for a software product looms. This leads to problems post-implementation in terms of patches required to fix security defects or vulnerabilities. A simplistic answer is that if the code was correct in the first instance, then vulnerabilities would not exist. The reality of a complex software artefact is however, driven by other concerns. Rather than probing programs for coding errors that lead to vulnerabilities, it is perhaps more beneficial to look at the root causes of …
Measuring Information Security Governance Within General Medical Practice, Rachel J. Mahncke, Donald C. Mcdermid, Patricia A. Williams
Measuring Information Security Governance Within General Medical Practice, Rachel J. Mahncke, Donald C. Mcdermid, Patricia A. Williams
Australian Information Security Management Conference
Information security is becoming increasingly important within the Australian general medical practice environment as legal and accreditation compliance is being enforced. Using a literature review, approaches to measuring information security governance were analysed for their potential suitability and use within General Practice for the effective protection of confidential information. The models, frameworks and guidelines selected were analysed to evaluate if they were Key Performance Indicator (KPI), or process driven; whether the approach taken was strategic, tactical or operational; and if governance or management assessment tools were presented. To measure information security governance, and be both effective and practical, the approach …
Case Study On An Investigation Of Information Security Management Among Law Firms, Sameera Mubarak, Elena Sitnikova
Case Study On An Investigation Of Information Security Management Among Law Firms, Sameera Mubarak, Elena Sitnikova
Australian Information Security Management Conference
The integrity of lawyers trust accounts as come under scrutiny in the last few years. There have been many incidents of trust account fraud reported internationally, including a case in Australia, where an employee of a law firm stole $4,500,000 from the trust funds of forty-two clients. Our study involved interviewing principles of ten law companies to find out solicitors’ attitudes to computer security and the possibility of breaches of their trust accounts. An overall finding highlights that law firms were not current with technology to combat computer crime, and inadequate access control was a major concern in safeguarding account …
Development Of A Critical Factors Model For The Knowledge Economy In Saudi Arabia, Fahad A. Alothman, Peter Busch
Development Of A Critical Factors Model For The Knowledge Economy In Saudi Arabia, Fahad A. Alothman, Peter Busch
Australian Information Security Management Conference
If knowledge-based economic systems are to be adopted, succeed and be disseminated, many significant barriers must be overcome regardless of how advanced a country is in terms of its infrastructure and domestic production. This paper describes an investigation of the critical factors associated with the adoption and dissemination of a knowledge economy initiative. The focus of the research is on knowledge management, national culture and other country-specific factors and how they are influencing Saudi Arabia’s efforts to develop a knowledge economy.
Method For Securing Online Community Service: A Study Of Selected Western Australian Councils, Sunsern Limwiriyakul
Method For Securing Online Community Service: A Study Of Selected Western Australian Councils, Sunsern Limwiriyakul
Australian Information Security Management Conference
Since the Internet was publicly made available, it has become popular and widely used in a range of services such as Email, News, IRC, World Wide Web around the globe. Progressively other services such as telephony, video conferencing, video on demand, interactive TV, Geospatial Information System (GIS), have emerged and become available on the Internet. Nowadays, Internet broadband communication infrastructure, both wired and wireless, make the concept of a Digital Community possible. The Digital Community has been growing and expanding rapidly around the world. This changes the way we live, work and play. Creating a Digital Community can empower local …
Security Decay: An Entropic Approach To Definition And Understanding, Michael Coole, David J. Brooks
Security Decay: An Entropic Approach To Definition And Understanding, Michael Coole, David J. Brooks
Australian Security and Intelligence Conference
This article discusses the affect decay has within a systems approach used when implementing security strategies, in particular, the theory of defence in depth. Defence in depth is implemented within a risk management framework to reduce an organisation’s identified risks, which could lead to undesirable and unacceptable consequences. Defence in depth aims to link layered security elements into a system to ensure a holistic and functional security system, underpinned by the functions of; deter, detect, delay, response and recovery. For such a system to be commissioned and maintain its commissioning effectiveness, these functions must be performed in their sequential order …
Information Overload: Cctv, Your Networks, Communities And Crime, Vandra Harris, Crispin Harris
Information Overload: Cctv, Your Networks, Communities And Crime, Vandra Harris, Crispin Harris
Australian Security and Intelligence Conference
Electronic surveillance continues to play a central but often unobserved role in contemporary Western societies and attempts to police them. This paper focuses on closed circuit television (CCTV) footage and its technological implications, particularly relating infrastructure and data storage and integrity. While CCTV might appear attractive in augmenting law enforcement systems, the authors argue that the debate on use of CCTV in crime prevention remains incomplete without an effective understanding of the diverse costs. This discussion reveals startling ICT resource needs and associated costs, together with very specific technological capacity. These contribute significantly to the costs of such systems, reinforcing …
A Holistic Scada Security Standard For The Australian Context, Christopher Beggs
A Holistic Scada Security Standard For The Australian Context, Christopher Beggs
Australian Information Warfare and Security Conference
Supervisory Control and Data Acquisition (SCADA) systems which control Australia’s critical infrastructure are currently demonstrating signs of vulnerabilities as they are being interconnected to corporate networks, essentially exposing them to malicious threats. This paper discusses the vulnerabilities associated with SCADA systems, as well as discussing various SCADA standards and initiatives that have been developed in recent years to mitigate such threats. The paper presents the requirement for a holistic SCADA security standard that is practical and feasible for each SCADA industry sector.
Visualisation Of Critical Infrastructure Failure, W D. Wilde, M J. Warren
Visualisation Of Critical Infrastructure Failure, W D. Wilde, M J. Warren
Australian Information Warfare and Security Conference
The paper explores the complexity of critical infrastructure and critical infrastructure failure (CIF), real life examples are used to discuss the complexity involved. The paper then discusses what Visualisation is and how Visualisation can be applied to a security situation, in particular critical infrastructure. The paper concludes by discussing the future direction of the research.
Media, Government And Manipulation: The Cases Of The Two Gulf Wars, William Hutchinson
Media, Government And Manipulation: The Cases Of The Two Gulf Wars, William Hutchinson
Australian Information Warfare and Security Conference
This paper explores the bias and manipulation of the Western mass media during the Gulf wars of 1991 and 2003. The tactics of compliance and the ethics of the press and journalists are examined. The need for a pluralist press is extolled.
Protecting Critical Infrastructure With Games Technology, Adrian Boeing, Martin Masek, Bill Bailey
Protecting Critical Infrastructure With Games Technology, Adrian Boeing, Martin Masek, Bill Bailey
Australian Information Warfare and Security Conference
It is widely recognised that there is a considerable gap in the protection of the national infrastructure. Trying to identify what is in fact ‘critical’ is proving to be very difficult as threats constantly evolve. An interactive prototyping tool is useful in playing out scenarios and simulating the effect of change, however existing simulators in the critical infrastructure area are typically limited in the visual representation and interactivity. To remedy this we propose the use of games technology. Through its use, critical infrastructure scenarios can be rapidly constructed, tested, and refined. In this paper, we highlight the features of games …
Information Sharing: Hackers Vs Law Enforcement, David P. Biros, Mark Weiser, Jim Burkman, Jason Nichols
Information Sharing: Hackers Vs Law Enforcement, David P. Biros, Mark Weiser, Jim Burkman, Jason Nichols
Australian Information Warfare and Security Conference
The fields of information assurance and digital forensics continue to grow in both importance and complexity, spurred on by rapid advancement in digital crime. Contemporary law enforcement professionals facing such issues quickly discover that they cannot be successful while operating in a vacuum and turn to colleagues for assistance. However, there is a clear need for greater IT-based knowledge sharing capabilities amongst law enforcement organizations; an environment historically typified by a silo mentality. A number of efforts have attempted to provide such capabilities, only to be met with limited enthusiasm and difficulties in sustaining continued use. Conversely, the hacker community …
Security Metrics - A Critical Analysis Of Current Methods, Manwinder Kaur, Andy Jones
Security Metrics - A Critical Analysis Of Current Methods, Manwinder Kaur, Andy Jones
Australian Information Warfare and Security Conference
This paper documents and analyses a number of security metrics currently in popular use. These will include government standards and commercial methods of measuring security on networks. It will conclude with a critical look at some of the problems and challenges faced when using the metrics available today, and also with the development of new metrics.
Dealing With The Malicious Insider, Andy Jones, Carl Colwill
Dealing With The Malicious Insider, Andy Jones, Carl Colwill
Australian Information Security Management Conference
This paper looks at a number of issues relating to the malicious insider and the nature of motivation, loyalty and the type of attacks that occur. The paper also examines the changing environmental, social, cultural and business issues that have resulted in an increased exposure to the insider threat. The paper then discusses a range of measures that can be taken to reduce both the likelihood of an attack and the impact that such an attack may have. These measures should be driven by focused and effective risk management processes.
Evaluating The Usability Impacts Of Security Interface Adjustments In Word 2007, M Helala, S M. Furnell, M Papadaki
Evaluating The Usability Impacts Of Security Interface Adjustments In Word 2007, M Helala, S M. Furnell, M Papadaki
Australian Information Security Management Conference
Prior research has suggested that integrating security features with user goals and increasing their visibility would improve the usability of the associated functionalities. This paper investigates how these approaches affect the efficiency of use and the level of user satisfaction. The user interface of Word 2007 was modified according to these principles, with usability tests being conducted with both the original and the modified user interfaces. The results suggest that integrating security features with user goals improves the efficiency of use, but the impacts upon user satisfaction cannot be clearly identified based on the collected data. No indications of any …
Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver
Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver
Australian Information Security Management Conference
This paper proposes to address the need for more innovation in organisational information security by adding a security requirement engineering focus. Based on the belief that any heavyweight security requirements process in organisational security will be doomed to fail, we developed a security requirement approach with three dimensions. The use of a simple security requirements process in the first dimension has been augmented by an agile security approach. However, introducing this second dimension of agile security does provide support for, but does not necessarily stimulate, innovation. A third dimension is, therefore, needed to ensure there is a proper focus in …
Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce
Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce
Australian Information Security Management Conference
There is increasing coverage in the literature highlighting threats to online financial systems. Attacks range from the prevalent reverse social engineering technique known as phishing; where spam emails are sent to customers with links to fake websites, to Trojans that monitor a customer’s account log on process that captures authentication details that are later replayed for financial gain. This ultimately results in loss of monetary funds for affected victims. As technological advances continue to influence the way society makes payment for goods and services, the requirement for more advanced security approaches for transaction verification in the online environment increases. This …
Rfid Communications - Who Is Listening?, Christopher Bolan
Rfid Communications - Who Is Listening?, Christopher Bolan
Australian Information Security Management Conference
Radio Frequency Identification (RFID) is seeing a surge in awareness across a range of industries as a successor to barcoding. The nature of this technology promises a wide range of benefits but it appears to be at the expense of security. This paper investigates an eavesdropping attack against an EPC RFID system and shows how a simple device may be used to record interactions between both Tag and Readers. The device is used to record and decode signals within range and its output is analysed to verify that the attack was indeed successful. The findings verify previous assertions by other …