Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Singapore Management University

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 811 - 840 of 1102

Full-Text Articles in Information Security

Onespace: Shared Depth-Corrected Video Interaction, David Ledo, Bon Adriel Aseniero, Sebastian Boring, Anthony Tang May 2013

Onespace: Shared Depth-Corrected Video Interaction, David Ledo, Bon Adriel Aseniero, Sebastian Boring, Anthony Tang

Research Collection School Of Computing and Information Systems

Video conferencing commonly employs a video portal metaphor to connect individuals from remote spaces. In this work, we explore an alternate metaphor, a shared depth mirror, where video images of two spaces are merged into a single shared, depth-corrected video. Just as seeing one’s mirror image causes reflective interaction, the shared video space changes the nature of interaction in the video space. We realize this metaphor in OneSpace, where the space respects virtual spatial relationships between people and objects, and in so doing, encourages cross-site, full-body interactions. We report preliminary observations of OneSpace in use, describing the role of depth …


Designing Leakage-Resilient Password Entry On Touchscreen Mobile Devices, Qiang Yan, Jin Han, Yingjiu Li, Jianying Zhou, Robert H. Deng May 2013

Designing Leakage-Resilient Password Entry On Touchscreen Mobile Devices, Qiang Yan, Jin Han, Yingjiu Li, Jianying Zhou, Robert H. Deng

Research Collection School Of Computing and Information Systems

Touchscreen mobile devices are becoming commodities as the wide adoption of pervasive computing. These devices allow users to access various services at anytime and anywhere. In order to prevent unauthorized access to these services, passwords have been pervasively used in user authentication. However, password-based authentication has intrinsic weakness in password leakage. This threat could be more serious on mobile devices, as mobile devices are widely used in public places. Most prior research on improving leakage resilience of password entry focuses on desktop computers, where specific restrictions on mobile devices such as small screen size are usually not addressed. Meanwhile, additional …


Expressive Search On Encrypted Data, Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen May 2013

Expressive Search On Encrypted Data, Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen

Research Collection School Of Computing and Information Systems

Different from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user’s public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Searchable pubic key encryption has many promising applications. Unfortunately, existing schemes either only support simple query predicates, such as equality queries and conjunctive queries, or have a superpolynomial blowup in ciphertext size …


Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks, Divyan Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen Fienberg May 2013

Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks, Divyan Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen Fienberg

Research Collection School Of Computing and Information Systems

In this paper we focus on authentication and privacy aspects of an application scenario that utilizes mobile crowd sensing for the benefit of amusement park operators and their visitors. The scenario involves a mobile app that gathers visitors’ demographic details, preferences, and current location coordinates, and sends them to the park’s sever for various analyses. These analyses assist the park operators to efficiently deploy their resources, estimate waiting times and queue lengths, and understand the behavior of individual visitors and groups. The app server also offers visitors optimal recommendations on routes and attractions for an improved dynamic experience and minimized …


Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model, Guomin Yang, Yi Mu, Willy Susilo, Duncan S. Wong May 2013

Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model, Guomin Yang, Yi Mu, Willy Susilo, Duncan S. Wong

Research Collection School Of Computing and Information Systems

Authenticated key exchange (AKE) protocols allow two parties communicating over an insecure network to establish a common secret key. They are among the most widely used cryptographic protocols in practice. In order to resist key-leakage attacks, several leakage resilient AKE protocols have been proposed recently in the bounded leakage model. In this paper, we initiate the study on leakage resilient AKE in the auxiliary input model. A promising way to construct such a protocol is to use a digital signature scheme that is entropically-unforgeable under chosen message and auxiliary input attacks. However, to date we are not aware of any …


Information Security As A Credence Good, Ping Fan Ke, Kai-Lung Hui, Wei Thoo Yue Apr 2013

Information Security As A Credence Good, Ping Fan Ke, Kai-Lung Hui, Wei Thoo Yue

Research Collection School Of Computing and Information Systems

With increasing use of information systems, many organizations are outsourcing information security protection to a managed security service provider (MSSP). However, diagnosing the risk of an information system requires special expertise, which could be costly and difficult to acquire. The MSSP may exploit their professional advantage and provide fraudulent diagnosis of clients’ vulnerabilities. Such an incentive to mis-represent clients’ risks is often called the credence goods problem in the economics literature[3]. Although different mechanisms have been introduced to tackle the credence goods problem, in the information security outsourcing context, such mechanisms may not work well with the presence of system …


Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang Apr 2013

Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang

Research Collection School Of Computing and Information Systems

We revisit the problem of secure cross-domain communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a generic framework for designing four-party password-based authenticated key exchange (4PAKE) protocols. Our framework takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with …


Accountable Authority Identity-Based Encryption With Public Traceability, Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng Mar 2013

Accountable Authority Identity-Based Encryption With Public Traceability, Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng

Research Collection School Of Computing and Information Systems

At Crypto’07, Goyal introduced the notion of accountable authority identity-based encryption (A-IBE) in order to mitigate the inherent key escrow problem in identity-based encryption, and proposed two concrete constructions. In an A-IBE system, if the private key generator (PKG) distributes a decryption key or produces an unauthorized decryption box for a user maliciously, it runs the risk of being caught and sued in the court of law with the help of a tracing algorithm. Subsequent efforts focused on constructions of A-IBE schemes with enhanced security. In these A-IBE constructions, the tracing algorithm needs to take a user’s decryption key as …


Almost Touching: Parent-Child Remote Communication Using The Sharetable System, Svetlana Yarosh, Anthony Tang, Sanika Mokashi, Gregory D. Abowd Mar 2013

Almost Touching: Parent-Child Remote Communication Using The Sharetable System, Svetlana Yarosh, Anthony Tang, Sanika Mokashi, Gregory D. Abowd

Research Collection School Of Computing and Information Systems

We deployed the ShareTable - a system that provides easy-to-initiate videochat and a shared tabletop task space - in four divorced households. Throughout the month of its use, the families employed the ShareTable to participate in shared activities, share emotional moments, and communicate closeness through metaphorical touch. The ShareTable provided a number of advantages over the phone and was easier to use than standard videoconferencing. However, it did also introduce concerns over privacy and new sources of conflict about appropriate calling practices. We relate our findings to the larger research landscape and present implications for future work.


Simple Identity-Based Encryption With Mediated Rsa, Xuhua Ding, Gene Tsudik Feb 2013

Simple Identity-Based Encryption With Mediated Rsa, Xuhua Ding, Gene Tsudik

Research Collection School Of Computing and Information Systems

Identity-based encryption (IBE) [5] and digital signatures are important tools in modern secure communication. In general, identity-based cryptographic methods facilitate easy introduction of public key cryptography by allowing an entity’s public key to be derived from some arbitrary identification value such as an email address or a phone number. Identity-based cryptography greatly reduces the need for, and reliance on, public key certificates. Mediated RSA (mRSA) [4] is a simple and practical method of splitting RSA private keys between the user and the Security Mediator (SEM). Neither the user nor the SEM can cheat one another since each signature or decryption …


Comparing Mobile Privacy Protection Through Cross-Platform Applications, Jin Han, Qiang Yan, Debin Gao, Jianying Zhou, Robert H. Deng Feb 2013

Comparing Mobile Privacy Protection Through Cross-Platform Applications, Jin Han, Qiang Yan, Debin Gao, Jianying Zhou, Robert H. Deng

Research Collection School Of Computing and Information Systems

With the rapid growth of the mobile market, security of mobile platforms is receiving increasing attention from both research community as well as the public. In this paper, we make the first attempt to establish a baseline for security comparison between the two most popular mobile platforms. We investigate applications that run on both Android and iOS and examine the difference in the usage of their security sensitive APIs (SS-APIs). Our analysis over 2,600 applications shows that iOS applications consistently access more SS-APIs than their counterparts on Android. The additional privileges gained on iOS are often associated with accessing private …


I Can Be You: Questioning The Use Of Keystroke Dynamics As Biometrics, Chee Meng Tey, Payas Gupta, Debin Gao Feb 2013

I Can Be You: Questioning The Use Of Keystroke Dynamics As Biometrics, Chee Meng Tey, Payas Gupta, Debin Gao

Research Collection School Of Computing and Information Systems

Keystroke dynamics refer to information about the typing patterns of individuals, such as the relative timing when the individual presses and releases each key. Prior studies suggest that such patterns are unique and cannot be easily imitated. This lays the foundation for the use of keystroke biometrics in authentication systems. The research effort in this area has thus far focused on novel detection techniques to differentiate between legitimate users and imposters. In this paper, we demonstrate a novel feedback and training interface named Mimesis. Mimesis provides both positive and negative feedback on the differences between a submitted pattern vs. a …


Raising The Game: Applying Theory And Analytics To Real-World Threats, Singapore Management University Jan 2013

Raising The Game: Applying Theory And Analytics To Real-World Threats, Singapore Management University

Perspectives@SMU

Safety and security are, on many levels, essential priorities for governments, businesses and individuals. While an increase of defence and security budgets may bring some assurance of peaceful times to come, it seems the world has no lack of insane perpetrators who can still somehow evade, breach, ambush, assail and attack as they please. Enter the “Bayesian Stackelberg Game”, a game theory model that can, and has been applied rather successfully to the allocation of security resources in the United States by Prof Milind Tambe, University of Southern California.


Guardian: Hypervisor As Security Foothold For Personal Computers, Yueqiang Cheng, Xuhua Ding Jan 2013

Guardian: Hypervisor As Security Foothold For Personal Computers, Yueqiang Cheng, Xuhua Ding

Research Collection School Of Computing and Information Systems

Personal computers lack of a security foothold to allow the end-users to protect their systems or to mitigate the damage. Existing candidates either rely on a large Trusted Computing Base (TCB) or are too costly to widely deploy for commodity use. To fill this gap, we propose a hypervisor-based security foothold, named as Guardian, for commodity personal computers. We innovate a bootup and shutdown mechanism to achieve both integrity and availability of Guardian. We also propose two security utilities based on Guardian. One is a device monitor which detects malicious manipulation on camera and network adaptors. The other is hyper-firewall …


Accountable Trapdoor Sanitizable Signatures, Junzuo Lai, Xuhua Ding, Yongdong Wu Jan 2013

Accountable Trapdoor Sanitizable Signatures, Junzuo Lai, Xuhua Ding, Yongdong Wu

Research Collection School Of Computing and Information Systems

Sanitizable signature (SS) allows a signer to partly delegate signing rights to a predetermined party, called sanitizer, who can later modify certain designated parts of a message originally signed by the signer and generate a new signature on the sanitized message without interacting with the signer. One of the important security requirements of sanitizable signatures is accountability, which allows the signer to prove, in case of dispute, to a third party that a message was modified by the sanitizer. Trapdoor sanitizable signature (TSS) enables a signer of a message to delegate the power of sanitization to any parties at anytime …


A Study Of The Imitation, Collection And Usability Issues Of Keystroke Biometrics, Chee Meng Tey Jan 2013

A Study Of The Imitation, Collection And Usability Issues Of Keystroke Biometrics, Chee Meng Tey

Dissertations and Theses Collection (Open Access)

The majority of authentication systems used today involves passwords, where a user is required to remember and key in the correct password to login. Keystroke biometrics is an alternative approach whereby users are identified by one or more features such as (a) the timing between keystrokes, (b) how long users hold each key and (c) how hard users press each key. It is being assumed in prior research that the way one user types a password/word is different from the way another user types the same password and this characteristic remains stable over time. Existing literature however left open three …


Exploiting Human Factors In User Authentication, Payas Gupta Jan 2013

Exploiting Human Factors In User Authentication, Payas Gupta

Dissertations and Theses Collection (Open Access)

Our overarching issue in security is the human factor – and dealing with it is perhaps one of the biggest challenges we face today. Human factor is often described as the weakest part of a security system and users are often described as the weakest link in the security chain. In this thesis, we focus on two problems which are caused by human factors in user authentication and propose respective solutions. a) Secrecy information inference attack – publicly available information can be used to infer some secrecy information about the user. b) Coercion attack – where an attacker forces a …


Towards Secure And Usable Leakage-Resilient Password Entry, Qiang Yan Jan 2013

Towards Secure And Usable Leakage-Resilient Password Entry, Qiang Yan

Dissertations and Theses Collection (Open Access)

Password leakage is one of the most common security threats for pervasive password based user authentication. The design of a secure and usable password entry against password leakage remains a challenge since twenty year ago when the first academic proposal attempted to address it. This dissertation focuses on investigating the difficulty in designing leakage-resilient password entry (LRPE) schemes and exploring the feasibility of constructing secure and usable LRPE schemes with the assistance of state-of-the-art technology. The first work in this dissertation reveals the infeasibility of designing practical LRPE schemes in the absence of trusted devices by investigating the inherent tradeoff …


Verifiable And Private Top-K Monitoring, Xuhua Ding, Hwee Hwa Pang Jan 2013

Verifiable And Private Top-K Monitoring, Xuhua Ding, Hwee Hwa Pang

Research Collection School Of Computing and Information Systems

In a data streaming model, records or documents are pushed from a data owner, via untrusted third-party servers, to a large number of users with matching interests. The match in interest is calculated from the correlation between each pair of document and user query. For scalability and availability reasons, this calculation is delegated to the servers, which gives rise to the need to protect the privacy of the documents and user queries. In addition, the users need to guard against the eventuality of a server distorting the correlation score of the documents to manipulate which documents are highlighted to certain …


Improving Internet Security Through Information Disclosure: A Field Quasi-Experiment, Qian Tang, Leigh L. Linden, John S. Quarterman, Andrew B. Whinston Jan 2013

Improving Internet Security Through Information Disclosure: A Field Quasi-Experiment, Qian Tang, Leigh L. Linden, John S. Quarterman, Andrew B. Whinston

Research Collection School Of Computing and Information Systems

Cybersecurity is a national priority in this big data era. Because of negative externalities and the resulting lack of economic incentives, companies often underinvest in security controls, despite government and industry recommendations. Although many existing studies on security have explored technical solutions, only a few have looked at the economic motivations. To fill the gap, we propose an approach to increase the incentives of organizations to address security problems. Specifically, we utilize and process existing security vulnerability data, derive explicit security performance information, and disclose the information as feedback to organizations and the public. We regularly release information on the …


A Secure Platform For Information Sharing In Epcglobal Network, Jie Shi, Yingjiu Li, Robert H. Deng, Wei He, Eng Wah Lee Jan 2013

A Secure Platform For Information Sharing In Epcglobal Network, Jie Shi, Yingjiu Li, Robert H. Deng, Wei He, Eng Wah Lee

Research Collection School Of Computing and Information Systems

With the rapid development of RFID technology, the EPCglobal network has drawn considerable attention from both research and industry communities, which enables supply chain partners to automatically share information and improve the visibility of supply chains. As the information shared in the EPCglobal network is usually sensitive and valuable, security mechanisms should be provided. In this paper, we aim at designing and implementing a secure information sharing platform in the EPCglobal network with a focus on authorization mechanism. We also design and implement a track and trace application based on the proposed secure platform so as to demonstrate its feasibility …


Semi-Automated Verification Of Defense Against Sql Injection In Web Applications, Kaiping Liu, Hee Beng Kuan Tan, Lwin Khin Shar Dec 2012

Semi-Automated Verification Of Defense Against Sql Injection In Web Applications, Kaiping Liu, Hee Beng Kuan Tan, Lwin Khin Shar

Research Collection School Of Computing and Information Systems

Recent reports reveal that majority of the attacks to Web applications are input manipulation attacks. Among these attacks, SQL injection attack malicious input is submitted to manipulate the database in a way that was unintended by the applications' developers is one such attack. This paper proposes an approach for assisting to code verification process on the defense against SQL injection. The approach extracts all such defenses implemented in code. With the use of the proposed approach, developers, testers or auditors can then check the defenses extracted from code to verify their adequacy. We have evaluated the feasibility, effectiveness, and usefulness …


Investigating Intelligent Agents In A 3d Virtual World, Yilin Kang, Fiona Fui-Hoon Nah, Ah-Hwee Tan Dec 2012

Investigating Intelligent Agents In A 3d Virtual World, Yilin Kang, Fiona Fui-Hoon Nah, Ah-Hwee Tan

Research Collection School Of Computing and Information Systems

Web 3.0 involves " intelligent " web applications that utilize natural language processing, machine-based learning and reasoning, and intelligent techniques to analyze and understand user behavior. In this research, we empirically assess a specific form of Web 3.0 application in the form of intelligent agents that offer assistance to users in the virtual world. Using media naturalness theory, we hypothesize that the use of intelligent agents in the virtual world can enhance user experience by offering a more natural way of communication and assistance to users. We are interested to test if media naturalness theory holds in the context of …


Ibinhunt: Binary Hunting With Inter-Procedural Control Flow, Jiang Ming, Meng Pan, Debin Gao Dec 2012

Ibinhunt: Binary Hunting With Inter-Procedural Control Flow, Jiang Ming, Meng Pan, Debin Gao

Research Collection School Of Computing and Information Systems

Techniques have been proposed to find the semantic differences between two binary programs when the source code is not available. Analyzing control flow, and in particular, intra-procedural control flow, has become an attractive technique in the latest binary diffing tools since it is more resistant to syntactic, but non-semantic, differences. However, this makes such techniques vulnerable to simple function obfuscation techniques (e.g., function inlining) attackers any malware writers could use. In this paper, we first show function obfuscation as an attack to such binary diffing techniques, and then propose iBinHunt which uses deep taint and automatic input generation to find …


Scalable Malware Clustering Through Coarse-Grained Behavior Modeling, Mahinthan Chandramohan, Hee Beng Kuan Tan, Lwin Khin Shar Nov 2012

Scalable Malware Clustering Through Coarse-Grained Behavior Modeling, Mahinthan Chandramohan, Hee Beng Kuan Tan, Lwin Khin Shar

Research Collection School Of Computing and Information Systems

Anti-malware vendors receive several thousand new malware (malicious software) variants per day. Due to large volume of malware samples, it has become extremely important to group them based on their malicious characteristics. Grouping of malware variants that exhibit similar behavior helps to generate malware signatures more efficiently. Unfortunately, exponential growth of new malware variants and huge-dimensional feature space, as used in existing approaches, make the clustering task very challenging and difficult to scale. Furthermore, malware behavior modeling techniques proposed in the literature do not scale well, where malware feature space grows in proportion with the number of samples under examination. …


Audit Mechanisms For Provable Risk Management And Accountable Data Governance, Jeremiah Blocki, Nicolas Christin, Anupam Datta, Arunesh Sinha Nov 2012

Audit Mechanisms For Provable Risk Management And Accountable Data Governance, Jeremiah Blocki, Nicolas Christin, Anupam Datta, Arunesh Sinha

Research Collection School Of Computing and Information Systems

Organizations that collect and use large volumes of personal information are expected under the principle of accountable data governance to take measures to protect data subjects from risks that arise from inapproriate uses of this information. In this paper, we focus on a specific class of mechanisms—audits to identify policy violators coupled with punishments—that organizations such as hospitals, financial institutions, and Web services companies may adopt to protect data subjects from privacy and security risks stemming from inappropriate information use by insiders. We model the interaction between the organization (defender) and an insider (adversary) during the audit process as a …


(Strong) Multidesignated Verifiers Signatures Secure Against Rogue Key Attack, Yunmei Zhang, Man Ho Au, Guomin Yang, Willy Susilo Nov 2012

(Strong) Multidesignated Verifiers Signatures Secure Against Rogue Key Attack, Yunmei Zhang, Man Ho Au, Guomin Yang, Willy Susilo

Research Collection School Of Computing and Information Systems

Designated verifier signatures (DVS) allow a signer to create a signature whose validity can only be verified by a specific entity chosen by the signer. In addition, the chosen entity, known as the designated verifier, cannot convince any body that the signature is created by the signer. Multi-designated verifiers signatures (MDVS) are a natural extension of DVS in which the signer can choose multiple designated verifiers. DVS and MDVS are useful primitives in electronic voting and contract signing. In this paper, we investigate various aspects of MDVS and make two contributions. Firstly, we revisit the notion of unforgeability under rogue …


An Improved Authentication Scheme For H.264/Svc And Its Performance Evaluation Over Non-Stationary Wireless Mobile Networks, Yifan Zhao, Swee-Won Lo, Robert H. Deng, Xuhua Ding Nov 2012

An Improved Authentication Scheme For H.264/Svc And Its Performance Evaluation Over Non-Stationary Wireless Mobile Networks, Yifan Zhao, Swee-Won Lo, Robert H. Deng, Xuhua Ding

Research Collection School Of Computing and Information Systems

In this paper, a bit stream-based authentication scheme for H.264/Scalable Video Coding (SVC) is proposed. The proposed scheme seamlessly integrates cryptographic algorithms and erasure correction codes (ECCs) to SVC video streams such that the authenticated streams are format compliant with the SVC specifications and preserve the three dimensional scalability (i. e., spatial, quality and temporal) of the original streams. We implement our scheme on a smart phone and study its performance over a realistic bursty packet-lossy wireless mobile network. Our analysis and experimental results show that the scheme achieves very high verification rates with lower communication overhead and much smaller …


Oto: Online Trust Oracle For User-Centric Trust Establishment, Tiffany Hyun-Jin Kim, Payas Gupta, Jun Han, Emmanuel Owusu, Jason Hong, Adrian Perrig, Debin Gao Oct 2012

Oto: Online Trust Oracle For User-Centric Trust Establishment, Tiffany Hyun-Jin Kim, Payas Gupta, Jun Han, Emmanuel Owusu, Jason Hong, Adrian Perrig, Debin Gao

Research Collection School Of Computing and Information Systems

Malware continues to thrive on the Internet. Besides automated mechanisms for detecting malware, we provide users with trust evidence information to enable them to make informed trust decisions. To scope the problem, we study the challenge of assisting users with judging the trustworthiness of software downloaded from the Internet. Through expert elicitation, we deduce indicators for trust evidence, then analyze these indicators with respect to scalability and robustness. We design OTO, a system for communicating these trust evidence indicators to users, and we demonstrate through a user study the effectiveness of OTO, even with respect to IE’s SmartScreen Filter (SSF). …


Predicting Common Web Application Vulnerabilities From Input Validation And Sanitization Code Patterns, Lwin Khin Shar, Hee Beng Kuan Tan Sep 2012

Predicting Common Web Application Vulnerabilities From Input Validation And Sanitization Code Patterns, Lwin Khin Shar, Hee Beng Kuan Tan

Research Collection School Of Computing and Information Systems

Software defect prediction studies have shown that defect predictors built from static code attributes are useful and effective. On the other hand, to mitigate the threats posed by common web application vulnerabilities, many vulnerability detection approaches have been proposed. However, finding alternative solutions to address these risks remains an important research problem. As web applications generally adopt input validation and sanitization routines to prevent web security risks, in this paper, we propose a set of static code attributes that represent the characteristics of these routines for predicting the two most common web application vulnerabilities—SQL injection and cross site scripting. In …