Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Singapore Management University

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 781 - 810 of 1102

Full-Text Articles in Information Security

Identity Based Identification From Algebraic Coding Theory, Guomin Yang, Chik How Tan, Yi Mu, Willy Susilo, Duncan S. Wong Feb 2014

Identity Based Identification From Algebraic Coding Theory, Guomin Yang, Chik How Tan, Yi Mu, Willy Susilo, Duncan S. Wong

Research Collection School Of Computing and Information Systems

Cryptographic identification schemes allow a remote user to prove his/her identity to a verifier who holds some public information of the user, such as the user public key or identity. Most of the existing cryptographic identification schemes are based on numbertheoretic hard problems such as Discrete Log and Factorization. This paper focuses on the design and analysis of identity based identification (IBI) schemes based on algebraic coding theory. We first revisit an existing code-based IBI scheme which is derived by combining the Courtois–Finiasz–Sendrier signature scheme and the Stern zero-knowledge identification scheme. Previous results have shown that this IBI scheme is …


Virtualization-Based System Hardening Against Untrusted Kernels, Yueqiang Cheng Jan 2014

Virtualization-Based System Hardening Against Untrusted Kernels, Yueqiang Cheng

Dissertations and Theses Collection (Open Access)

Applications are integral to our daily lives to help us processing sensitive I/O data, such as individual passwords and camera streams, and private application data, such as financial information and medical reports. However, applications and sensitive data all surfer from the attacks from kernel rootkits in the traditional architecture, where the commodity OS that is supposed to be the secure foothold of the system is routinely compromised due to the large code base and the broad attack surface. Fortunately, the virtualization technology has significantly reshaped the landscape of the modern computer system, and provides a variety of new opportunities for …


On The Security Of Auditing Mechanisms For Secure Cloud Storage, Yong Yu, Lei Niu, Guomin Yang, Yi Mu, Willy Susilo Jan 2014

On The Security Of Auditing Mechanisms For Secure Cloud Storage, Yong Yu, Lei Niu, Guomin Yang, Yi Mu, Willy Susilo

Research Collection School Of Computing and Information Systems

Cloud computing is a novel computing model that enables convenient and on-demand access to a shared pool of configurable computing resources. Auditing services are highly essential to make sure that the data is correctly hosted in the cloud. In this paper, we investigate the active adversary attacks in three auditing mechanisms for shared data in the cloud, including two identity privacy-preserving auditing mechanisms called Oruta and Knox, and a distributed storage integrity auditing mechanism.We show that these schemes become insecure when active adversaries are involved in the cloud storage. Specifically, an active adversary can arbitrarily alter the cloud data without …


Detecting Click Fraud In Online Advertising: A Data Mining Approach, Richard Oentaryo, Ee Peng Lim, Michael Finegold, David Lo, Feida Zhu, Clifton Phua, Eng-Yeow Cheu, Ghim-Eng Yap, Kelvin Sim, Kasun Perera, Bijay Neupane, Mustafa Faisal, Zeyar Aung, Wei Lee Woon, Wei Chen, Dhaval Patel, Daniel Berrar Jan 2014

Detecting Click Fraud In Online Advertising: A Data Mining Approach, Richard Oentaryo, Ee Peng Lim, Michael Finegold, David Lo, Feida Zhu, Clifton Phua, Eng-Yeow Cheu, Ghim-Eng Yap, Kelvin Sim, Kasun Perera, Bijay Neupane, Mustafa Faisal, Zeyar Aung, Wei Lee Woon, Wei Chen, Dhaval Patel, Daniel Berrar

Research Collection School Of Computing and Information Systems

Click fraud - the deliberate clicking on advertisements with no real interest on the product or service offered - is one of the most daunting problems in online advertising. Building an elective fraud detection method is thus pivotal for online advertising businesses. We organized a Fraud Detection in Mobile Advertising (FDMA) 2012 Competition, opening the opportunity for participants to work on real-world fraud data from BuzzCity Pte. Ltd., a global mobile advertising company based in Singapore. In particular, the task is to identify fraudulent publishers who generate illegitimate clicks, and distinguish them from normal publishers. The competition was held from …


Privacy-Preserving Ad-Hoc Equi-Join On Outsourced Data, Hwee Hwa Pang, Xuhua Ding Jan 2014

Privacy-Preserving Ad-Hoc Equi-Join On Outsourced Data, Hwee Hwa Pang, Xuhua Ding

Research Collection School Of Computing and Information Systems

In IT outsourcing, a user may delegate the data storage and query processing functions to a third-party server that is not completely trusted. This gives rise to the need to safeguard the privacy of the database as well as the user queries over it. In this article, we address the problem of running ad hoc equi-join queries directly on encrypted data in such a setting. Our contribution is the first solution that achieves constant complexity per pair of records that are evaluated for the join. After formalizing the privacy requirements pertaining to the database and user queries, we introduce a …


Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang Jan 2014

Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang

Research Collection School Of Computing and Information Systems

We revisit the problem of secure cross-domain communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this article, we propose a generic framework for designing four-party password-based authenticated key exchange (4PAKE) protocols. Our framework takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords, which they share …


Innovative Applications And Security Of Internet Of Things, Yingjiu Li, Yingjiu Li, Nai-Wei Lo Jan 2014

Innovative Applications And Security Of Internet Of Things, Yingjiu Li, Yingjiu Li, Nai-Wei Lo

Research Collection School Of Computing and Information Systems

With the advances and falling cost of intelligent things like RFID/USN, sensor networks, NFC, ZigBee, smart phones, and other relevant technologies, the potential applications and implementations of Internet of things have been intensively studied by both the academia and the industry. One potential application is integrating social networks with IoT, which results in the social Internet of things (SIoT). This vision not only provides potential opportunities but also new challenges. Innovative application and security are two main issues toward this paradigm


A Robust Smart Card-Based Anonymous User Authentication Protocol For Wireless Communications, Fengton Wen, Willy Susilo, Guomin Yang Jan 2014

A Robust Smart Card-Based Anonymous User Authentication Protocol For Wireless Communications, Fengton Wen, Willy Susilo, Guomin Yang

Research Collection School Of Computing and Information Systems

Anonymous user authentication is an important but challenging task for wireless communications. In a recent paper, Das proposed a smart cardï based anonymous user authentication protocol for wireless communications. The scheme can protect user privacy and is believed to be secure against a range of network attacks even if the secret information stored in the smart card is compromised. In this paper, we reanalyze the security of Das' scheme, and show that the scheme is in fact insecure against impersonation attacks. We then propose a new smart cardï based anonymous user authentication protocol for wireless communications. Compared with the existing …


A Secure And Effective Anonymous User Authentication Scheme For Roaming Service In Global Mobility Networks, Fengtong Wen, Willy Susilo, Guomin Yang Dec 2013

A Secure And Effective Anonymous User Authentication Scheme For Roaming Service In Global Mobility Networks, Fengtong Wen, Willy Susilo, Guomin Yang

Research Collection School Of Computing and Information Systems

In global mobility networks, anonymous user authentication is an essential task for enabling roaming service. In a recent paper, Jiang et al. proposed a smart card based anonymous user authentication scheme for roaming service in global mobility networks. This scheme can protect user privacy and is believed to have many abilities to resist a range of network attacks, even if the secret information stored in the smart card is compromised. In this paper, we analyze the security of Jiang et al.’s scheme, and show that the scheme is in fact insecure against the stolen-verifier attack and replay attack. Then, we …


Towards A Hybrid Framework For Detecting Input Manipulation Vulnerabilities, Sun Ding, Hee Beng Kuan Tan, Lwin Khin Shar, Bindu Madhavi Padmanabhuni Dec 2013

Towards A Hybrid Framework For Detecting Input Manipulation Vulnerabilities, Sun Ding, Hee Beng Kuan Tan, Lwin Khin Shar, Bindu Madhavi Padmanabhuni

Research Collection School Of Computing and Information Systems

Input manipulation vulnerabilities such as SQL Injection, Cross-site scripting, Buffer Overflow vulnerabilities are highly prevalent and pose critical security risks. As a result, many methods have been proposed to apply static analysis, dynamic analysis or a combination of them, to detect such security vulnerabilities. Most of the existing methods classify vulnerabilities into safe and unsafe. They have both false-positive and false-negative cases. In general, security vulnerability can be classified into three cases: (1) provable safe, (2) provable unsafe, (3) unsure. In this paper, we propose a hybrid framework-Detecting Input Manipulation Vulnerabilities (DIMV), to verify the adequacy of security vulnerability defenses …


Defending Against Heap Overflow By Using Randomization In Nested Virtual Clusters, Chee Meng Tey, Debin Gao Nov 2013

Defending Against Heap Overflow By Using Randomization In Nested Virtual Clusters, Chee Meng Tey, Debin Gao

Research Collection School Of Computing and Information Systems

Heap based buffer overflows are a dangerous class of vulnerability. One countermeasure is randomizing the location of heap memory blocks. Existing techniques segregate the address space into clusters, each of which is used exclusively for one block size. This approach requires a large amount of address space reservation, and results in lower location randomization for larger blocks.


Self-Blindable Credential: Towards Anonymous Entity Authentication Upon Resource-Constrained Devices, Yanjiang Yang, Xuhua Ding, Haibing Lu, Jian Weng, Jianying Zhou Nov 2013

Self-Blindable Credential: Towards Anonymous Entity Authentication Upon Resource-Constrained Devices, Yanjiang Yang, Xuhua Ding, Haibing Lu, Jian Weng, Jianying Zhou

Research Collection School Of Computing and Information Systems

We are witnessing the rapid expansion of smart devices in our daily life. The need for individual privacy protection calls for anonymous entity authentication techniques with affordable efficiency upon the resource-constrained smart devices. Towards this objective, in this paper we propose self-blindable credential, a lightweight anonymous entity authentication primitive.We provide a formulation of the primitive and present two concrete instantiations. The first scheme implements verifier-local revocation and the second scheme enhances the former with forward security. Our analytical performance results show that our schemes outperform relevant existing schemes.


Adaptable Ciphertext-Policy Attribute-Based Encryption, Junzuo Lai, Robert H. Deng, Yanjiang Yang, Jian Weng Nov 2013

Adaptable Ciphertext-Policy Attribute-Based Encryption, Junzuo Lai, Robert H. Deng, Yanjiang Yang, Jian Weng

Research Collection School Of Computing and Information Systems

In this paper, we introduce a new cryptographic primitive, called adaptable ciphertext-policy attribute-based encryption (CP-ABE). Adaptable CP-ABE extends the traditional CP-ABE by allowing a semi-trusted proxy to modify a ciphertext under one access policy into ciphertexts of the same plaintext under any other access policies; the proxy, however, learns nothing about the underlying plaintext. With such “adaptability” possessed by the proxy, adaptable CP-ABE has many real world applications, such as handling policy changes in CP-ABE encryption of cloud data and outsourcing of CP-ABE encryption. Specifically, we first specify a formal model of adaptable CP-ABE; then, based on the CP-ABE scheme …


Achieving Revocable Fine-Grained Cryptographic Access Control Over Cloud Data, Yanjiang Yang, Xuhua Ding, Haibing Lu, Zhiguo Wan, Jianying Zhou Nov 2013

Achieving Revocable Fine-Grained Cryptographic Access Control Over Cloud Data, Yanjiang Yang, Xuhua Ding, Haibing Lu, Zhiguo Wan, Jianying Zhou

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) is well suited for finegrained access control for data residing on a cloud server. However, existing approaches for user revocation are not satisfactory. In this work, we propose a new approach which works by splitting an authorized user’s decryption capability between the cloud and the user herself. User revocation is attained by simply nullifying the decryption ability at the cloud, requiring neither key update nor re-generation of cloud data. We propose a concrete scheme instantiating the approach, which features lightweight computation at the user side. This makes it possible for users to use resource-constrained devices such as …


Efficient Lossy Trapdoor Functions Based On Subgroup Membership Assumptions, Haiyang Xue, Bao Li, Xianhui Lu, Dingding Jia, Yamin Liu Nov 2013

Efficient Lossy Trapdoor Functions Based On Subgroup Membership Assumptions, Haiyang Xue, Bao Li, Xianhui Lu, Dingding Jia, Yamin Liu

Research Collection School Of Computing and Information Systems

We propose a generic construction of lossy trapdoor function from the subgroup membership assumption. We present three concrete constructions based on the k-DCR assumption over Z∗ N2 , the extended psubgroup assumption over Z∗ N2 , and the decisional RSA subgroup membership assumption over Z∗ N . Our constructions are more efficient than the previous construction from the DCR assumption over Z∗ Ns (s ≥ 3).


A Collusion-Resistant Conditional Access System For Flexible-Pay-Per-Channel Pay-Tv Broadcasting, Zhiguo Wan, June Liu, Rui Zhang, Robert H. Deng Oct 2013

A Collusion-Resistant Conditional Access System For Flexible-Pay-Per-Channel Pay-Tv Broadcasting, Zhiguo Wan, June Liu, Rui Zhang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Pay-TV Broadcasting system, an extensively de- ployed application, charges its subscribers when receiving the broadcasted video. A conditional access system (CAS) ensures security for the Pay-TV broadcasting system, which is designed to control TV channel/program access to only authorized subscribers. There are mainly three CAS models: pay-per-channel (PPC), pay-per-view (PPV), and flexible-pay-per-channel (F- PPC). F-PPC is a novel model which combines the properties and advantages of both PPC and PPV. Several key management schemes with four-level hierarchical key structure have been proposed for this model. In this paper, we point out a severe security weakness of these schemes against collusion …


K-Time Proxy Signature: Formal Definition And Efficient Construction, Weiwei Liu, Guomin Yang, Yi Mu, Jiannan Wei Oct 2013

K-Time Proxy Signature: Formal Definition And Efficient Construction, Weiwei Liu, Guomin Yang, Yi Mu, Jiannan Wei

Research Collection School Of Computing and Information Systems

Proxy signature, which allows an original signer to delegate his/her signing right to another party (or proxy signer), is very useful in many applications. Conventional proxy signature only allows the original signer to specify in the warrant the validity time period of the delegation but not the number of proxy signatures the proxy signer can generate. To address this problem, in this paper, we provide a formal treatment for k-time proxy signature. Such a scheme allows a designated proxy signer to produce only a fixed number of proxy signatures on behalf of the original signer. We provide the formal definitions …


A Highly Efficient Rfid Distance Bounding Protocol Without Real-Time Prf Evaluation, Yunhui Zhuang, Anjia Yang, Duncan S. Wong, Guomin Yang, Qi Xie Sep 2013

A Highly Efficient Rfid Distance Bounding Protocol Without Real-Time Prf Evaluation, Yunhui Zhuang, Anjia Yang, Duncan S. Wong, Guomin Yang, Qi Xie

Research Collection School Of Computing and Information Systems

There is a common situation among current distance bounding protocols in the literature: they set the fast bit exchange phase after a slow phase in which the nonces for both the reader and a tag are exchanged. The output computed in the slow phase is acting as the responses in the subsequent fast phase. Due to the calculation constrained RFID environment of being lightweight and efficient, it is the important objective of building the protocol which can have fewer number of message flows and less number of cryptographic operations in real time performed by the tag. In this paper, we …


Driverguard: Virtualization Based Fine-Grained Protection On I/O Flows, Yueqiang Cheng, Xuhua Ding, Robert H. Deng Sep 2013

Driverguard: Virtualization Based Fine-Grained Protection On I/O Flows, Yueqiang Cheng, Xuhua Ding, Robert H. Deng

Research Collection School Of Computing and Information Systems

Most commodity peripheral devices and their drivers are geared to achieve high performance with security functions being opted out. The absence of strong security measures invites attacks on the I/O data and consequently posts threats to those services feeding on them, such as fingerprint-based biometric authentication. In this article, we present a generic solution called DriverGuard, which dynamically protects the secrecy of I/O flows such that the I/O data are not exposed to the malicious kernel. Our design leverages a composite of cryptographic and virtualization techniques to achieve fine-grained protection without using any extra devices and modifications on user applications. …


Cost-Sensitive Online Active Learning With Application To Malicious Url Detection, Peilin Zhao, Steven C. H. Hoi Aug 2013

Cost-Sensitive Online Active Learning With Application To Malicious Url Detection, Peilin Zhao, Steven C. H. Hoi

Research Collection School Of Computing and Information Systems

Malicious Uniform Resource Locator (URL) detection is an important problem in web search and mining, which plays a critical role in internet security. In literature, many existing studies have attempted to formulate the problem as a regular supervised binary classification task, which typically aims to optimize the prediction accuracy. However, in a real-world malicious URL detection task, the ratio between the number of malicious URLs and legitimate URLs is highly imbalanced, making it very inappropriate for simply optimizing the prediction accuracy. Besides, another key limitation of the existing work is to assume a large amount of training data is available, …


Attribute-Based Encryption With Verifiable Outsourced Decryption, Junzuo Lai, Robert H. Deng, Chaowen Guan, Jian Weng Aug 2013

Attribute-Based Encryption With Verifiable Outsourced Decryption, Junzuo Lai, Robert H. Deng, Chaowen Guan, Jian Weng

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) is a public-keybased one-to-many encryption that allows users to encrypt and decrypt data based on user attributes. A promising application of ABE is flexible access control of encrypted data stored in the cloud, using access polices and ascribed attributes associated with private keys and ciphertexts.One of themain efficiency drawbacks of the existing ABE schemes is that decryption involves expensive pairing operations and the number of such operations grows with the complexity of the access policy. Recently, Green et al. proposed an ABE system with outsourced decryption that largely eliminates the decryption overhead for users. In such a …


Technique For Authenticating H.264/Svc Streams In Surveillance Applications, Wei Zhuo, Robert H. Deng, Jialie Shen, Yongdong Wu, Xuhua Ding, Swee Won Lo Jul 2013

Technique For Authenticating H.264/Svc Streams In Surveillance Applications, Wei Zhuo, Robert H. Deng, Jialie Shen, Yongdong Wu, Xuhua Ding, Swee Won Lo

Research Collection School Of Computing and Information Systems

Surveillance codestreams coded by H.264/SVC (scalable video coding), which consists of one base layer and one or more enhancement layers, supply flexible and various quality, resolution, and temporal (sub)codestreams such that clients with different network bandwidth and terminal devices can seamlessly access them. In this paper, we present a robust authentication scheme for them in order to insure the integrity of SVC surveillance codestreams, named AUSSC (Authenticating SVC Surveillance Codestreams). AUSSC exploits cryptographic-based authentication for base layer and content-based authentication for enhancement layers. For content-based authentication, AUSSC extracts full features from the first frame of each GOP (group of picture) …


The Case For Mobile Forensics Of Private Data Leaks: Towards Large-Scale User-Oriented Privacy Protection, Joseph Joo Keng Chan, Kiat Wee Tan, Lingxiao Jiang, Rajesh Krishna Balan Jul 2013

The Case For Mobile Forensics Of Private Data Leaks: Towards Large-Scale User-Oriented Privacy Protection, Joseph Joo Keng Chan, Kiat Wee Tan, Lingxiao Jiang, Rajesh Krishna Balan

Research Collection School Of Computing and Information Systems

Privacy protection against mobile applications on mobile devices is becoming a serious concern as user sensitive data may be leaked without proper justification. Most current leak detection tools only report leaked private data, but provide inadequate information about the causes of the leaks for end users to take preventive measures. Hence, users often cannot reconcile the way they have used an application to a reported leak — i.e., they are unable to comprehend the (il)legitimacy of the leak or make a decision on whether to allow the leak. This paper aims to demonstrate the feasibility and benefits of identifying the …


Keystroke Timing Analysis Of On-The-Fly Web Apps, Chee Meng Tey, Payas Gupta, Debin Gao, Yan Zhang Jun 2013

Keystroke Timing Analysis Of On-The-Fly Web Apps, Chee Meng Tey, Payas Gupta, Debin Gao, Yan Zhang

Research Collection School Of Computing and Information Systems

The Google Suggestions service used in Google Search is one example of an interactivity rich Javascript application. In this paper, we analyse the timing side channel of Google Suggestions by reverse engineering the communication model from obfuscated Javascript code. We consider an attacker who attempts to infer the typing pattern of a victim. From our experiments involving 11 participants, we found that for each keypair with at least 20 samples, the mean of the inter-keystroke timing can be determined with an error of less than 20%.


A New Unpredictability-Based Rfid Privacy Model, Anjia Yang, Yunhui Zhuang, Duncan S. Wong, Guomin Yang Jun 2013

A New Unpredictability-Based Rfid Privacy Model, Anjia Yang, Yunhui Zhuang, Duncan S. Wong, Guomin Yang

Research Collection School Of Computing and Information Systems

Ind-privacy and unp-privacy, later refined to unp∗-privacy, are two different classes of privacy models for RFID authentication protocols. These models have captured the major anonymity and untraceability related attacks regarding RFID authentication protocols with privacy, and existing work indicates that unp∗-privacy seems to be a stronger notion when compared with ind-privacy. In this paper, we continue studying the RFID privacy models, and there are two folds regarding our results. First of all, we describe a new traceability attack and show that schemes proven secure in unp∗-privacy may not be secure against this new and practical type of traceability attacks. We …


Attribute-Based Access To Scalable Media In Cloud-Assisted Content Sharing, Yongdong Wu, Zhuo Wei, Robert H. Deng Jun 2013

Attribute-Based Access To Scalable Media In Cloud-Assisted Content Sharing, Yongdong Wu, Zhuo Wei, Robert H. Deng

Research Collection School Of Computing and Information Systems

This paper presents a novel Multi-message Ciphertext Policy Attribute-Based Encryption (MCP-ABE) technique, and employs the MCP-ABE to design an access control scheme for sharing scalable media based on data consumers’ attributes (e.g., age, nationality, gender) rather than an explicit list of the consumers’ names. The scheme is efficient and flexible because MCP-ABE allows a content provider to specify an access policy and encrypt multiple messages within one ciphertext such that only the users whose attributes satisfy the access policy can decrypt the ciphertext. Moreover, the paper shows how to support resource-limited mobile devices by offloading computational intensive perations to cloud …


Think Twice Before You Share: Analyzing Privacy Leakage Under Privacy Control In Online Social Networks, Yan Li, Yingjiu Li, Qiang Yan, Robert H. Deng Jun 2013

Think Twice Before You Share: Analyzing Privacy Leakage Under Privacy Control In Online Social Networks, Yan Li, Yingjiu Li, Qiang Yan, Robert H. Deng

Research Collection School Of Computing and Information Systems

Online Social Networks (OSNs) have become one of the major platforms for social interactions. Privacy control is deployed in popular OSNs to protect user’s data. However, user’s sensitive information could still be leaked even when privacy rules are properly configured. We investigate the effectiveness of privacy control against privacy leakage from the perspective of information flow. Our analysis reveals that the existing privacy control mechanisms do not protect the flow of personal information effectively. By examining typical OSNs including Facebook, Google+, and Twitter, we discover a series of privacy exploits which are caused by the conflicts between privacy control and …


Launching Generic Attacks On Ios With Approved Third-Party Applications, Jin Han, Mon Kywe Su, Qiang Yan, Feng Bao, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou Jun 2013

Launching Generic Attacks On Ios With Approved Third-Party Applications, Jin Han, Mon Kywe Su, Qiang Yan, Feng Bao, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou

Research Collection School Of Computing and Information Systems

iOS is Apple’s mobile operating system, which is used on iPhone, iPad and iPod touch. Any third-party applications developed for iOS devices are required to go through Apple’s application vetting process and appear on the official iTunes App Store upon approval.When an application is downloaded from the store and installed on an iOS device, it is given a limited set of privileges, which are enforced by iOS application sandbox. Although details of the vetting process and the sandbox are kept as black box by Apple, it was generally believed that these iOS security mechanisms are effective in defending against malwares. …


Mitigating Access-Driven Timing Channels In Clouds Using Stopwatch, Peng Li, Debin Gao, Michael K. Reiter Jun 2013

Mitigating Access-Driven Timing Channels In Clouds Using Stopwatch, Peng Li, Debin Gao, Michael K. Reiter

Research Collection School Of Computing and Information Systems

This paper presents StopWatch , a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatchtriplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses thetiming of I/O events at a VM's replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VM. We detail the design and implementation …


Improving Internet Security Through Social Information And Social Comparison: A Field Quasi-Experiment, Qian Tang, Leigh L. Linden, John S. Quarterman, Andrew B. Whinston Jun 2013

Improving Internet Security Through Social Information And Social Comparison: A Field Quasi-Experiment, Qian Tang, Leigh L. Linden, John S. Quarterman, Andrew B. Whinston

Research Collection School Of Computing and Information Systems

Cybersecurity is a national priority in this big data era. Because of negative externalities and the resulting lack of economic incentives, companies often underinvest in security controls, despite government and industry recommendations. Although many existing studies on security have explored technical solutions, only a few have looked at the economic motivations. To fill the gap, we propose an approach to increase the incentives of organizations to address security problems. Specifically, we utilize and process existing security vulnerability data, derive explicit security performance information, and disclose the information as feedback to organizations and the public. We regularly release information on the …