Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (22)
- Social and Behavioral Sciences (21)
- Computer Engineering (20)
- Medicine and Health Sciences (19)
- Business (14)
-
- Health Information Technology (13)
- Public Affairs, Public Policy and Public Administration (6)
- Digital Communications and Networking (5)
- Legal Studies (5)
- Communication (4)
- Defense and Security Studies (4)
- Education (4)
- Health and Medical Administration (4)
- Criminology (3)
- Forensic Science and Technology (3)
- OS and Networks (3)
- Psychology (3)
- Sociology (3)
- Business Administration, Management, and Operations (2)
- Communication Technology and New Media (2)
- Criminology and Criminal Justice (2)
- E-Commerce (2)
- Electrical and Computer Engineering (2)
- Law (2)
- Organizational Behavior and Theory (2)
- Other Computer Sciences (2)
- Science and Technology Studies (2)
- Keyword
-
- Security (74)
- [RSTDPub] (54)
- Information security (30)
- Privacy (24)
- Cyber security (21)
-
- Computer security (18)
- Intrusion detection (17)
- Cybersecurity (16)
- Encryption (15)
- Network security (15)
- Authentication (14)
- Digital forensics (13)
- Blockchain (11)
- Risk management (11)
- Biometrics (10)
- Vulnerability (10)
- [aism] (10)
- Anomaly detection (9)
- Machine learning (9)
- Risk (9)
- Risk assessment (9)
- Android (8)
- Critical Infrastructure (8)
- Phishing (8)
- Wireless (8)
- Cloud computing (7)
- Data security (7)
- Healthcare (7)
- Information Security (7)
- Information security management (7)
- Publication Year
- Publication
-
- Australian Information Security Management Conference (224)
- Research outputs 2022 to 2026 (84)
- Australian Digital Forensics Conference (50)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
-
- International Cyber Resilience conference (19)
- Theses: Doctorates and Masters (16)
- Theses : Honours (15)
- Research outputs pre 2011 (14)
- Australian eHealth Informatics and Security Conference (10)
- Australian Security and Intelligence Conference (7)
- Research outputs 2011 (3)
- Research outputs 2012 (2)
- Research outputs 2013 (2)
- Research Datasets (1)
- Publication Type
- File Type
Articles 421 - 450 of 532
Full-Text Articles in Information Security
Secure Portable Execution Environments: A Review Of Available Technologies, Peter James
Secure Portable Execution Environments: A Review Of Available Technologies, Peter James
Australian Information Security Management Conference
Live operating systems and virtualisation allow a known, defined, safe and secure execution environment to be loaded in to a PC’s memory and executed with either minimal or possibly no reliance on the PC’s internal hard disk drive. The ability to boot a live operating system or load a virtual environment (containing an operating system) from a USB storage device allows a secure portable execution environment to be created. Portable execution environments have typically been used by technologists, for example to recover data from a failing PC internal hard disk drive or to perform forensic analysis. However, with the commercial …
Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew
Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew
Australian Information Security Management Conference
In an environment where technical solutions for securing networked systems are commonplace, there still exist problems in implementation of such solutions for home and small business users. One component of this protection is the use of intrusion detection systems. Intrusion detection monitors network traffic for suspicious activity, performs access blocking and alerts the system administrator or user of potential attacks. This paper reviews the basic function of intrusion detection systems and maps them to an existing end-user capability framework. Using this framework, implementation guidance and systematic improvement in implementation of this security measure are defined.
Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong
Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong
Australian Information Security Management Conference
Video over IP (VIP) is becoming a tool of communication in corporate environments to reduce the time spent conducting meetings face-to-face. This has been driven by efficiencies of time saving, management’s monitoring of staff and to communicate with flexibilities - without placing additional disadvantages on employees who must regularly attend personal meetings amongst hectic business schedules. With technology excelling beyond the old telegraphy of analogy video over hard copper wire to dark fibre technology, VIP is a technology that is starting to receive more attention in the corporate world as more organisations have the equipment to support this additional plug-in. …
Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke
Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke
Australian Information Security Management Conference
The current security on mobile devices is often limited to the Personal Identification Number (PIN), a secretknowledge based technique that has historically demonstrated to provide ineffective protection from misuse. Unfortunately, with the increasing capabilities of mobile devices, such as online banking and shopping, the need for more effective protection is imperative. This study proposes the use of two-factor authentication as an enhanced technique for authentication on a Smartphone. Through utilising secret-knowledge and keystroke analysis, it is proposed a stronger more robust mechanism will exist. Whilst keystroke analysis using mobile devices have been proven effective in experimental studies, these studies have …
Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari
Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari
Australian Information Security Management Conference
This paper presents a critique of emergent views on the roles of the boards of directors in relation to information security. The analysis highlights several concerns about the separation and validation of proper theory and business assertions of information security at board level. New requirements articulated by industry bodies – represented by a selected group of experts and evident in literature – are compared to the underlying theory of corporate governance to identify possible discrepancies. The discussion shows in particular the importance of staying within the theoretical underpinnings of corporate governance when discussing the topic of governance in general and …
Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones
Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones
Australian Information Security Management Conference
Smartphones face the same threats as traditional computers. As long as a device has the capabilities to perform logic processing, the threat of running malicious logic exists. The only difference between security threats on traditional computers versus security threats on smartphones is the challenge to understand the inner workings of the operating system on different hardware processor architectures. To improve upon the security of smartphones, anomaly detection capabilities can be implemented at different functional layers of a smartphone in a coherent manner; instead of just looking at individual functional layers. This paper will focus on identifying conceptual points for measuring …
Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao
Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao
Australian Information Security Management Conference
The prepaid card market in Australia is growing rapidly. Its features not only attract customers from all sorts of backgrounds but also expose it to numerous risks. Using the methodology of the Australian Risk Management Standard AS/NZS4360, this paper looks at the risks inherent in prepaid cards. Concentrating on two major risks, the paper details the regulations governing the industry in the USA as well the technical controls employed by the credit/debit card industry. We suggest risk mitigation strategies from these two view-points, aiming to become an important reference both for industry as it adopts better risk mitigation techniques, and …
Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong
Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong
Australian Information Security Management Conference
During a denial of service attack, it is difficult for a firewall to differentiate legitimate packets from rogue packets, particularly in large networks carrying substantial levels of traffic. Large networks commonly use network intrusion detection systems to identify such attacks, however new viruses and worms can escape detection until their signatures are known and classified as an attack. Commonly used IDS are rule based and static, and produce a high number of false positive alerts. The aim of this research was to determine if it is possible for a firewall to analyse its own traffic patterns to identify attempted denial …
Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward
Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward
Australian Information Security Management Conference
In the arena of wireless security, EAP-TLS is considered one of the most secure protocols. However since its inception the uptake has been poor and the investigation into the reasons for this are sparse. There is an industry perception that EAP-TLS is complex as well as difficult to configure and manage. One of the major barriers is in the use of public key infrastructure and the perceived difficulties in its application. The paper discusses why it is seemingly difficult to implement and how this may differ from the reality of its implementation. This premise is investigated using Windows Server 2003 …
Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward
Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward
Australian Information Security Management Conference
In the world of online gaming, information is exchanged as a matter of course. What information is exchanged behind the scenes is something that is not obvious to the casual user. People who play these games trust that the applications they are using are securely written and in this case, communicate securely. This paper looks at the traffic that is transmitted by the game Team Fortress 2 and incidentally the supporting authentication traffic of the Steam network. It was discovered through packet analysis that there is quite a lot of information which should be kept private being broadcast in the …
Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli
Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli
Australian Information Security Management Conference
Primary care medical practices in Australia have been identified as a profession in need of assistance with information security practices. Whilst guidelines exist, there is little assistance in an accessible and easily implemented form for medical practices. This research presents the preliminary findings of a study which advocates that information security practices can be improved using a capability operational framework which is contextualised to its target environment.
Case Analysis Of Information Security Risk Perceptions, Alexis Guillot
Case Analysis Of Information Security Risk Perceptions, Alexis Guillot
Theses : Honours
The scientific rationality used by experts towards risk evaluation is expressed as the product of its likelihood of occurrence with its consequences or impacts (ENISA, 2006a). This directly opposes the subjective nature of risk perception, often appearing as inconsistent if not completely irrational (Byrne, 2003). Risk perception theories are a pathway to explain the subjective nature of risk and a deeper insight into the human's cognitive system. Those theories may help to explain why people see, act and plan for risks in the way that they do, the weaknesses that exist in the human decision mechanisms and their impact on …
Improving Information Security Management In Nonprofit Organisations With Action, Mark Carey-Smith, Karen Nelson, Lauren May
Improving Information Security Management In Nonprofit Organisations With Action, Mark Carey-Smith, Karen Nelson, Lauren May
Australian Information Security Management Conference
Information security is vital for protecting important assets of organisations, including the information resources and the organisation’s reputation. In Australia, the nonprofit sector makes a significant contribution to society but is under represented in the information security literature. This paper describes research in progress that is investigating and improving information security management in some nonprofit organisations (NPOs), which incorporates a participatory action research methodology. This approach will enhance the skill set likely to be present in Australian nonprofit organisations, producing a more sustainable solution, as well as contributing to the open literature. The Technology Acceptance Model will be utilised as …
Evolution Of A Database Security Course: Using Non-Enterprise Teaching Tools, Justin Brown
Evolution Of A Database Security Course: Using Non-Enterprise Teaching Tools, Justin Brown
Australian Information Security Management Conference
This paper examines the issues in delivering a university unit of teaching in database security, examining problems in database environment selection and the ability to provide hands on training for students via oncampus and online modes. Initial problems with Linux and then Windows based enterprise database environments prompted the adoption of Microsoft Access as a database tool that was easier to deliver in-class and online. Though Access is file based and has fundamental flaws in its security implementation (within the enterprise context) it can be tweaked to emulate RDBMS level security, allowing students to see how a properly designed security …
Information Security Surveys: A Review Of The Methodologies, The Critics And A Pragmatic Approach To Their Purposes And Usage, Alexis Guillot, Sue Kennedy
Information Security Surveys: A Review Of The Methodologies, The Critics And A Pragmatic Approach To Their Purposes And Usage, Alexis Guillot, Sue Kennedy
Australian Information Security Management Conference
Each year the latest information security surveys are released to the computing and business communities. Often their findings and their methodologies are subject to criticism from the information security community, professional bodies and others in the profession. This paper looks at the viewpoints of both the producers and the critics of the surveys. The criticisms cover such issues as the methodologies, the response rates, the experience of the respondents, the design of the questions and the interpretation of the results. This paper looks at these issues and discusses the validity of these criticisms, the impact of the surveys and their …
Network Security – Is Ip Telephony Helping The Cause?, Paul Hansen, Andrew Woodward
Network Security – Is Ip Telephony Helping The Cause?, Paul Hansen, Andrew Woodward
Australian Information Security Management Conference
The major players in the Public Branch Exchange (PBX) market are moving rapidly towards the implementation of IP Telephony. What will be the effect on network security overall? Will the push to IP Telephony damage the good work already devoted to security networks? As more doorways open up on our networks there is an increased chance we have opened another unseen vector for hackers and other malicious organisation or individuals to access the data stored on server and users workstations, corrupting that data or destroying it. Is it better from a security perspective to have IP telephony only between PBX …
Taxonomy Of Iphone Activation And Sim Unlocking Methods, Marwan Al-Zarouni, Haitham Al-Hajri
Taxonomy Of Iphone Activation And Sim Unlocking Methods, Marwan Al-Zarouni, Haitham Al-Hajri
Australian Information Security Management Conference
This paper will discuss the different methods of SIM unlocking and activation for the Apple iPhone. Early iPhone activation and SIM card fabrication methods as well as the latest software only methods will be discussed. The paper will examine the benefits and drawbacks of each method. It will provide a step-by-step guide to creating a specially crafted SIM card for an iPhone by using Super SIM and Turbo SIM methods. The paper will also include a section on recovering (unbricking) the iPhone and other advanced hacks
Network Security Devices And Protocols Using State Model Diagrams, C. Nuangjamnong, D. Veal, S. P. Maj
Network Security Devices And Protocols Using State Model Diagrams, C. Nuangjamnong, D. Veal, S. P. Maj
Australian Information Security Management Conference
Network security is concerned with protecting sensitive information, limiting unauthorised access, and reinforcing network performance. An important factor in network security is encryption. Internet Security Protocol (IPSec) is the de facto open standard for encryption and replaces the older Cisco Encryption Technology (CET). Both encryption protocols are typically implemented and managed using the text based Command Line Interface (CLI). A graphical user interface (GUI) is available; however, it is not routinely used. Regardless of whether the CLI or GUI is used, both encryption suites are complex to implement and manage. State Model Diagrams (SMDs) were developed and successfully used as …
Device- Versus Network-Centric Authentication Paradigms For Mobile Devices: Operational And Perceptual Trade-Offs, S. Karatzouni, N. L. Clarke, S. M. Furnell
Device- Versus Network-Centric Authentication Paradigms For Mobile Devices: Operational And Perceptual Trade-Offs, S. Karatzouni, N. L. Clarke, S. M. Furnell
Australian Information Security Management Conference
The increasing capability and functionality of mobile devices is leading to a corresponding increase in the need for security to prevent unauthorised access. Indeed, as the data and services accessed via mobile devices become more sensitive, the existing method of user authentication (predominately based upon Personal Identification Numbers) appears increasingly insufficient. An alternative basis for authentication is offered by biometric approaches; which have the potential to be implemented in a non-intrusive manner and also enable authentication to be applied in an ongoing manner, beyond initial point-of-entry. However, the implementation of any authentication mechanism, particularly biometric approaches, introduces considerations of where …
Importance Of Verification And Validation Of Data Sources In Attaining Information Superiority, Gautham Kasinath, Leisa Armstrong
Importance Of Verification And Validation Of Data Sources In Attaining Information Superiority, Gautham Kasinath, Leisa Armstrong
Australian Information Security Management Conference
Information superiority has been defined as a state that is achieved when a competitive advantage is derived from the ability to exploit a superior information position. To achieve such a superior information position enterprises and nations, alike, must not only collect and record correct, accurate, timely and useful information but also ensure that information recorded is not lost to competitors due to lack of comprehensive security and leaks. Further, enterprises that aim to attain information superiority must also ensure mechanisms of validating and verifying information to reduce the chances of mis-information. Although, research has been carried out into ways to …
Analysis Of Pki As A Means Of Securing Odf Documents, Gautham Kasinath, Leisa Armstrong
Analysis Of Pki As A Means Of Securing Odf Documents, Gautham Kasinath, Leisa Armstrong
Australian Information Security Management Conference
Public Key Infrastructure (PKI) has for the last two decades been a means of securing systems and communication. With the adoption of Open Document Format (ODF) as an ISO standard, the question remains if the unpopular, expensive, complex and unmaintainable PKI can prove to be a viable means of securing ODF documents. This paper analyses the drawbacks of PKI and evaluates the usefulness of PKI in provisioning robust, cheap and maintainable XML security to XML based ODF. This paper also evaluates the existing research on XML security, more specifically fine grained access control.
A Conceptual Model For Security Outsourcing, K. Samarasinghe, M. Warren, G. Pye
A Conceptual Model For Security Outsourcing, K. Samarasinghe, M. Warren, G. Pye
Australian Information Security Management Conference
This research analyses the current literature on IT security outsourcing and the organisational attitudes towards this approach to determine the applicability of outsourcing IT security in a commercial environment. A conceptual model is developed as the main goal of research which provides guidance in the process of outsourcing IT security functions to a third-party security service provider. The research conducted has established a complete process for outsourcing IT security.
Security Issues Within Virtual Worlds Such As Second Life, Chia Yao Lee, Matthew Warren
Security Issues Within Virtual Worlds Such As Second Life, Chia Yao Lee, Matthew Warren
Australian Information Security Management Conference
The advancement in Internet and bandwidth has resulted in a number of new applications to be developed. An area of advancement has been in the development of virtual worlds, where people can interact together via virtual characters. Virtual World systems have been so complex that virtual lives can be lived, including all aspect of life such as education, commerce, social activities etc. Not surprisingly, the problems that exist in the real world such as theft, fraud, vandalism and terrorism, also exist in the virtual worlds. The more developed these virtual worlds become the greater the breaches of security will be …
The Phantasm Of Atm Withdrawal, Nattakant Utakrit
The Phantasm Of Atm Withdrawal, Nattakant Utakrit
Australian Information Security Management Conference
Despite the stringent legislation and increased enforcement aimed at combating financial crime, fraud using cash machines remains a public concern. The problem of ATM fraud is happening on a global scale and the ramifications have been felt in Australia. This paper highlights the stratagems of financial crime, in particular of ATM fraud. The abuse of ATMs with intelligent methods used by perpetrators will be discussed. At the same time, the paper will present some global cases of ATM fraud. Finally this paper will illustrate countermeasures and security methods, such as biometrics and premises protections of banks, financial institutions and customers, …
Medical Insecurity: When One Size Does Not Fit All, Patricia A. Williams
Medical Insecurity: When One Size Does Not Fit All, Patricia A. Williams
Australian Information Security Management Conference
Security is most commonly seen as a business concept. This is one reason for the poor uptake and implementation of standard security processes in non-business environments such as general medical practice. It is clear that protection of sensitive patient information is imperative yet the overarching conceptual business processes required to ensure this protection are not well suited to this context. The issue of sensitivity of information, together with the expectation that security can be effectively implemented by non-security trained professionals creates an insecure environment. The general security processes used by business, including those for risk assessment, are difficult to operationally …
A Single Channel Attack On 915mhz Radio Frequency Identification Systems, Christopher Bolan
A Single Channel Attack On 915mhz Radio Frequency Identification Systems, Christopher Bolan
Australian Information Security Management Conference
There has been some speculation as to the protection offered by the Frequency Hopping Spread Spectrum utilised by RFID technology. This paper explores the construction of an attack based on the broadcast of an attack signal in a single channel. The study details an experiment on two groups of tags where the experimental group are exposed to an attack signal broadcast on a single channel. With consistent findings across both control and experimental groups the experiment clearly demonstrates that FHSS offers no protection against such an attack.
Teaching Php With Security In Mind, Greg Baatard
Teaching Php With Security In Mind, Greg Baatard
Australian Information Security Management Conference
The PHP server-side scripting language has found significant popularity due to its accessibility, simplicity and affordability. With the deployment of PHP-inclusive web development environments becoming easier, universities have begun to offer units of study in the language. However, students coming from a background of HTML-based web development will often not be adequately prepared to consider the security implications associated with a powerful scripting language. It is important that students are taught to recognise and respond to the security implications of their code from an early stage, as a matter of good programming practice. This paper demonstrates how security teachings can …
A Comprehensive Firewall Testing Methodology, Murray Brand
A Comprehensive Firewall Testing Methodology, Murray Brand
Australian Information Security Management Conference
This paper proposes an all encompassing test methodology for firewalls. It extends the life cycle model to revisit the major phases of the life cycle after a firewall is in service as foundations for the tests. The focus of the tests is to show that the firewall is, or isn’t, still fit for purpose. It also focuses on the traceability between business requirements through to policy, rule sets, physical design, implementation, egress and ingress testing, monitoring and auditing. The guidelines are provided by a Test and Evaluation Master Plan (TEMP). The methodology is very much process driven and in keeping …
Increasing Security In The Physical Layer Of Wireless Communication, Luke Golygowski
Increasing Security In The Physical Layer Of Wireless Communication, Luke Golygowski
Australian Information Security Management Conference
This paper introduces a concept of increasing securing in the Physical layer (PHY) of wireless communication. It gives a short description of current status of wireless standards and their security. Despite the existence of advanced security protocols such as IEEE 802.11i or WLAN VPNs, wireless networks still remain vulnerable to denial-of-service (DoS) attacks aiming at PHY and Data Link Layers. The new solution challenges the problems with the currently defined PHY and Data Link layers. The concept introduced here, holds a promise of descending with some of the security measures to the lower layers of the TCP/IP and in this …
The Importance Of Human Factors When Assessing Outsourcing Security Risks, Carl Colwill, Andy Jones
The Importance Of Human Factors When Assessing Outsourcing Security Risks, Carl Colwill, Andy Jones
Australian Information Security Management Conference
The word is becoming increasingly interconnected and ways of doing business are evolving rapidly. Communications technology is ubiquitous and reliable and businesses are continuously seeking ways in which systems can be exploited to improve resilience, become more efficient and reduce costs. One way in which organisations seek to achieve this is by concentrating their efforts on core business processes and outsourcing non-core functions. However, outsourcing - and particularly offshoring - presents many security issues that must be considered throughout the lifetime of contracts. The scale of outsourcing and increasing technological and security complexity is making this task more difficult. Often …