Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Computer Law (37)
- Law (37)
- Engineering (28)
- Computer Engineering (26)
- Social and Behavioral Sciences (26)
-
- Electrical and Computer Engineering (25)
- Forensic Science and Technology (25)
- Legal Studies (25)
- Databases and Information Systems (6)
- Numerical Analysis and Scientific Computing (3)
- OS and Networks (3)
- Theory and Algorithms (3)
- Business (2)
- Graphics and Human Computer Interfaces (2)
- Management Information Systems (2)
- Other Computer Sciences (2)
- Risk Analysis (2)
- Systems Architecture (2)
- Applied Behavior Analysis (1)
- Applied Mathematics (1)
- Medicine and Health Sciences (1)
- Programming Languages and Compilers (1)
- Psychology (1)
- Software Engineering (1)
- Institution
- Keyword
-
- [RSTDPub] (9)
- Security (7)
- Computer networks--Security measures (6)
- Privacy (5)
- Data protection (4)
-
- Hackers (4)
- Wireless communication systems (4)
- Computer forensics (3)
- Deception (3)
- Information Warfare (3)
- Information security (3)
- Risk (3)
- Risk assessment (3)
- Risk management (3)
- Terrorism (3)
- Authentication (2)
- Compliance (2)
- Computer networks (2)
- Computer security (2)
- Cyber crime (2)
- Cybercrime (2)
- Data integrity (2)
- Forensic computing (2)
- Fraud (2)
- ICQ (2)
- ISO 27001 (2)
- Information Security (2)
- Information Terrorism (2)
- Internet (2)
- Logfile (2)
- Publication
-
- Journal of Digital Forensics, Security and Law (31)
- Australian Information Security Management Conference (23)
- Research Collection School Of Computing and Information Systems (17)
- Australian Information Warfare and Security Conference (14)
- Theses and Dissertations (13)
-
- Annual ADFSL Conference on Digital Forensics, Security and Law (6)
- All Faculty and Staff Scholarship (2)
- Australian Digital Forensics Conference (2)
- Computer Science Faculty Publications (2)
- Computer Science Theses & Dissertations (1)
- Faculty Publications (1)
- Honors Theses (1)
- Inquiry: The University of Arkansas Undergraduate Research Journal (1)
- Publications (1)
- Theses : Honours (1)
- Theses Digitization Project (1)
- Publication Type
Articles 61 - 90 of 117
Full-Text Articles in Information Security
Enhancing The Forensic Icq Logfile Extraction Tool, Kim Morfitt
Enhancing The Forensic Icq Logfile Extraction Tool, Kim Morfitt
Australian Digital Forensics Conference
Programmers of forensic tools need to ensure that their tools are of suitable use, robustness and correctness for their output to be used as evidence. One tool for logfile extraction that is currently under development and is intended for forensic use extracts information from ICQ clients has several limitations that need to be overcome before it is of significant value to forensic investigators. This paper covers the process and research involved in further developing the tool, and overcoming a subset of the limitations of the tool. It also documents what was learnt in the process about the logfiles and the …
Mediated Identification, D T. Shaw
Mediated Identification, D T. Shaw
Australian Information Warfare and Security Conference
Identity and identification are linked by variable meanings and applications and are essential in many remote transactions. Identification relying on mediation or third party intervention may be modified or withdrawn at will. Creating or reestablishing identity may require time and resources including artefacts such as the identity card usually sourced from a third party. The characteristics of the identification process and artefacts are discussed and the requirements of usermediated identification artefacts are explored. The implicit link between user identity and artefact identity may be broken under certain circumstances.
Deception On The Network: Thinking Differently About Covert Channels, Maarten Van Horenbeeck
Deception On The Network: Thinking Differently About Covert Channels, Maarten Van Horenbeeck
Australian Information Warfare and Security Conference
The concept of covert channels has been visited frequently by academia in a quest to analyse their occurrence and prevention in trusted systems. This has lead to a wide variety of approaches being developed to prevent and identify such channels and implement applicable countermeasures. However, little of this research has actually trickled down into the field of operational security management and risk analysis. Quite recently a number of covert channels and enabling tools have appeared that did have a significant impact on the operational security of organizations. This paper identifies a number of those channels and shows the relative ease …
An Information Operation Model And Classification Scheme, D T. Shaw, S Cikara
An Information Operation Model And Classification Scheme, D T. Shaw, S Cikara
Australian Information Warfare and Security Conference
Information systems are used in overt and covert conflict and information operations target an opponent’s ability to manage information in support of operations for political, commercial and military advantage. System level attacks are complicated by logistic problems that require resources, command and control. Node level attacks are practical but of limited value. Collocated equipment comprises a temporary node that may be feasibly attacked. Estimation of IW operation merits may founder on the difficulty of predicting the net benefit for the costs. Starting from with Shannon’s model, a simple costbenefit model is discussed. Existing models are extended by an IW attack …
Security Risk Assessment: Group Approach To A Consensual Outcome, Ben Beard, David J. Brooks
Security Risk Assessment: Group Approach To A Consensual Outcome, Ben Beard, David J. Brooks
Australian Information Warfare and Security Conference
AS/NZS4360:2004 suggests that the risk assessment process should not be conducted or information gathered in isolation. This insular method of data collection may lead to inaccurate risk assessment, as stakeholders with vested interests may emphasise their own risks or game the risk assessment process. The study demonstrated how a consensual risk assessment approach may result in a more acceptable risk assessment outcome when compared to individual assessments. The participants were senior managers at a West Australian motel located on the West Coast Highway, Scarborough. The motel consists of four three storey blocks of units, resulting in a total of 75 …
Terrorism As Opiniotainment: Perceptions Warriors And The Public Battlefield, Luke Howie
Terrorism As Opiniotainment: Perceptions Warriors And The Public Battlefield, Luke Howie
Australian Information Warfare and Security Conference
Terrorism continues to have a significant impact on the lives of Australians. Whilst Australian cities remain untargeted during this present wave of terrorism, many Australians perceive the threat to be significant. Terrorism is offered for consumption daily in the news media and many Australians have seen the images of terrorism. In addition to television images, media consumers have been inundated with terrorism reporting on talkback radio, in feature films, and in newspapers. What impact does the perceptions wars on terrorism have on Australian society? Are the public more or less knowledgeable because of public debate? These are questions that need …
Information Terrorism: Networked Influence, W Hutchinson
Information Terrorism: Networked Influence, W Hutchinson
Australian Information Warfare and Security Conference
The advent of digital information technology heralded the concept of information warfare. This ‘preliminary’ stage in the 1990s really consisted of technology warfare where the networks, upon which combat relied, were seen as weapons to gain ‘information superiority’. This was the inception of the technological aspect of Information Warfare. The realisation of the effectiveness of electronic networks to optimize organisational communication was taken up by industry, the military and terrorist groups alike. As society quickly became more reliant on digital networks to run its critical functions, it became apparent that this infrastructure was vulnerable and needed protection (as well as …
The Awareness And Perception Of Spyware Amongst Home Pc Computer Users, M Jaeger, N L. Clarke
The Awareness And Perception Of Spyware Amongst Home Pc Computer Users, M Jaeger, N L. Clarke
Australian Information Warfare and Security Conference
Spyware is a major threat to personal computer based data confidentiality, with criminal elements utilising it as a positive moneymaking device by theft of personal data from security unconscious home internet users. This paper examines the level of understanding and awareness of home computer users to Spyware. An anonymous survey was distributed via email invitation with 205 completed surveys. From an analysis of the survey it was found that the majority of respondents do understand what Spyware is, however, there was found to be a lack of understanding of computer security in defending against Spyware, with 20% of survey respondents …
Assessing End-User Awareness Of Social Engineering And Phishing, A Karakasiliotis,, S M. Furnell, M Papadaki
Assessing End-User Awareness Of Social Engineering And Phishing, A Karakasiliotis,, S M. Furnell, M Papadaki
Australian Information Warfare and Security Conference
Social engineering is a significant problem involving technical and nontechnical ploys in order to acquire information from unsuspecting users. This paper presents an assessment of user awareness of such methods in the form of email phishing attacks. Our experiment used a webbased survey, which presented a mix of 20 legitimate and illegitimate emails, and asked participants to classify them and explain the rationale for their decisions. This assessment shows that the 179 participants were 36% successful in identifying legitimate emails, versus 45% successful in spotting illegitimate ones. Additionally, in many cases, the participants who identified illegitimate emails correctly could not …
Global Reach: Terrorists And The Internet, Simon O'Rourke
Global Reach: Terrorists And The Internet, Simon O'Rourke
Australian Information Warfare and Security Conference
The use of the Internet by terrorists appears to diverge into two distinct modes neither of which is mutually exclusive. The first aligns to the view that terrorists will use the Internet as a platform to launch cyber attacks against critical infrastructure nodes as well as key government and private sector networks. This paper discusses the alternate mode that being the primary use of the Internet by terrorists will be to recruit, train, communicate and gain information about potential targets by conducting virtual reconnaissance. It will examine the nexus between the virtual world and the physical threat that is manifested …
Conceptual Modelling: Choosing A Critical Infrastructure Modelling Methodology, Graeme Pye, Matthew J. Warren
Conceptual Modelling: Choosing A Critical Infrastructure Modelling Methodology, Graeme Pye, Matthew J. Warren
Australian Information Warfare and Security Conference
This paper reports on further research undertaken regarding systems modelling as applied to critical infrastructure systems and networks and builds upon the initial modelling research of Pye and Warren (2006a). We discuss system characteristics, inter-relationships, dynamics and modelling of similar systems and why modelling of a critical infrastructure is important. In overview we compare four modelling methods and techniques previously used to model similar systems and discuss their potential transference to model critical infrastructure systems, before selecting the most promising and suitable for modelling critical infrastructure systems for further research.
Tags At War: A Review Of The United States Department Of Defence Rfid Tag Data Standard, Uros Urosevic, Christopher Bolan
Tags At War: A Review Of The United States Department Of Defence Rfid Tag Data Standard, Uros Urosevic, Christopher Bolan
Australian Information Warfare and Security Conference
The U.S. Department of Defence have mandated the use of RFID technology in their procurement and supply systems. To enable compatibility across civilian contractors and suppliers and military systems the US DOD RFTag Data Format 2.0 specification has been implemented. This paper outlines the features of this standard and the possible security implications of its adoption.
An Interactive Relaxation Approach For Anomaly Detection And Preventive Measures In Computer Networks, Garrick A. Bell
An Interactive Relaxation Approach For Anomaly Detection And Preventive Measures In Computer Networks, Garrick A. Bell
Theses and Dissertations
It is proposed to develop a framework of detecting and analyzing small and widespread changes in specific dynamic characteristics of several nodes. The characteristics are locally measured at each node in a large network of computers and analyzed using a computational paradigm known as the Relaxation technique. The goal is to be able to detect the onset of a worm or virus as it originates, spreads-out, attacks and disables the entire network. Currently, selective disabling of one or more features across an entire subnet, e.g. firewalls, provides limited security and keeps us from designing high performance net-centric systems. The most …
Anonymous Signature Schemes, Guomin Yang, Duncan S. Wong, Xiaotie Deng, Huaxiong Wang
Anonymous Signature Schemes, Guomin Yang, Duncan S. Wong, Xiaotie Deng, Huaxiong Wang
Research Collection School Of Computing and Information Systems
Digital signature is one of the most important primitives in public key cryptography. It provides authenticity, integrity and non-repudiation to many kinds of applications. On signer privacy however, it is generally unclear or suspicious of whether a signature scheme itself can guarantee the anonymity of the signer. In this paper, we give some affirmative answers to it. We formally define the signer anonymity for digital signature and propose some schemes of this type. We show that a signer anonymous signature scheme can be very useful by proposing a new anonymous key exchange protocol which allows a client Alice to establish …
A Practical Password-Based Two-Server Authentication And Key Exchange System, Yanjiang Yang, Robert H. Deng, Feng Bao
A Practical Password-Based Two-Server Authentication And Key Exchange System, Yanjiang Yang, Robert H. Deng, Feng Bao
Research Collection School Of Computing and Information Systems
Most password-based user authentication systems place total trust on the authentication server where cleartext passwords or easily derived password verification data are stored in a central database. Such systems are, thus, by no means resilient against offline dictionary attacks initiated at the server side. Compromise of the authentication server by either outsiders or insiders subjects all user passwords to exposure and may have serious legal and financial repercussions to an organization. Recently, several multiserver password systems were proposed to circumvent the single point of vulnerability inherent in the single-server architecture. However, these multiserver systems are difficult to deploy and operate …
Determining The Level Of Network Security Awareness Of Utc Students Living On Campus, Alma Cemerlic
Determining The Level Of Network Security Awareness Of Utc Students Living On Campus, Alma Cemerlic
Honors Theses
While information technology divisions in various schools often conduct surveys on general computer use, almost no studies have been done that directly targeted the level of Internet security awareness among college students. The National Cyber Security Alliance (NCSA), a not-for-profit, public-private partnership focused on increasing online security awareness, in collaboration with the Government and the Internet industry, organized a number of different projects designed to promote "safe online practices" among college students. However, since research has not been done to investigate the relationship between students' demographics and their Internet security awareness, it is not possible to tell how effective these …
Factors Impacting Key Management Effectiveness In Secured Wireless Networks, Yongjoo Shin
Factors Impacting Key Management Effectiveness In Secured Wireless Networks, Yongjoo Shin
Theses and Dissertations
The use of a Public Key Infrastructure (PKI) offers a cryptographic solution that can overcome many, but not all, of the MANET security problems. One of the most critical aspects of a PKI system is how well it implements Key Management. Key Management deals with key generation, key storage, key distribution, key updating, key revocation, and certificate service in accordance with security policies over the lifecycle of the cryptography. The approach supported by traditional PKI works well in fixed wired networks, but it may not appropriate for MANET due to the lack of fixed infrastructure to support the PKI. This …
Formal Mitigation Strategies For The Insider Threat: A Security Model And Risk Analysis Framework, Jonathan W. Butts
Formal Mitigation Strategies For The Insider Threat: A Security Model And Risk Analysis Framework, Jonathan W. Butts
Theses and Dissertations
The advancement of technology and reliance on information systems have fostered an environment of sharing and trust. The rapid growth and dependence on these systems, however, creates an increased risk associated with the insider threat. The insider threat is one of the most challenging problems facing the security of information systems because the insider already has capabilities within the system. Despite research efforts to prevent and detect insiders, organizations remain susceptible to this threat because of inadequate security policies and a willingness of some individuals to betray their organization. To investigate these issues, a formal security model and risk analysis …
An Adaptable Energy-Efficient Medium Access Control Protocol For Wireless Sensor Networks, Justin T. Kautz
An Adaptable Energy-Efficient Medium Access Control Protocol For Wireless Sensor Networks, Justin T. Kautz
Theses and Dissertations
Wireless networks have become ubiquitous recently and therefore their usefulness has also become more extensive. Wireless sensor networks (WSN) detect environmental information with sensors in remote settings. One problem facing WSNs is the inability to resupply power to these energy-constrained devices due to their remoteness. Therefore to extend a WSN's effectiveness, the lifetime of the network must be increased by making them as energy efficient as possible. An energy efficient medium access control (MAC) can boost a WSN's lifetime. This research creates a MAC protocol called Adaptive sensor Medium Access Control (AMAC) which is based on Sensor Medium Access Control …
Mitigating Distributed Denial Of Service Attacks In An Anonymous Routing Environment: Client Puzzles And Tor, Nicholas A. Fraser
Mitigating Distributed Denial Of Service Attacks In An Anonymous Routing Environment: Client Puzzles And Tor, Nicholas A. Fraser
Theses and Dissertations
Online intelligence operations use the Internet to gather information on the activities of U.S. adversaries. The security of these operations is paramount, and one way to avoid being linked to the Department of Defense (DoD) is to use anonymous communication systems. One such system, Tor, makes interactive TCP services anonymous. Tor uses the Transport Layer Security (TLS) protocol and is thus vulnerable to a distributed denial-of-service (DDoS) attack that can significantly delay data traversing the Tor network. This research uses client puzzles to mitigate TLS DDoS attacks. A novel puzzle protocol, the Memoryless Puzzle Protocol (MPP), is conceived, implemented, and …
A Real-Time Wireless Sensor Media Access Control (Mac) Protocol, Barry W. Park
A Real-Time Wireless Sensor Media Access Control (Mac) Protocol, Barry W. Park
Theses and Dissertations
Wireless sensor networks are rapidly becoming a platform for applications such as battlefield monitoring, intelligence gathering, environmental monitoring, and emergency response. Inherent in these applications is a priority and urgency of the information or messages. This means the messages must be delivered in a timely manner for them to be useful. This research assigns a message priority level and provides high-priority messages quicker access to the channel. Using MICA2 sensors and a modified Media Access Control (MAC) layer, real-time message End-to-End (ETE) delay was reduced by 50 percent. Coupled with this decrease in delay, these same real-time messages also had …
Fortifying Password Authentication In Integrated Healthcare Delivery Systems, Yanjiang Yang, Robert H. Deng, Feng Bao
Fortifying Password Authentication In Integrated Healthcare Delivery Systems, Yanjiang Yang, Robert H. Deng, Feng Bao
Research Collection School Of Computing and Information Systems
Integrated Delivery Systems (IDSs) now become a primary means of care provision in healthcare domain. However, existing password systems (under either the single-server model or the multi-server model) do not provide adequate security when applied to IDSs. We are thus motivated to present a practical password authentication system built upon a novel two-server model. We generalize the two-server model to an architecture of a single control server supporting multiple service servers, tailored to the organizational structure of IDSs. The underlying user authentication and key exchange protocols we propose are password-only, neat, efficient, and robust against off-line dictionary attacks mounted by …
Cryptanalysis Of Pseudorandom Number Generators In Wireless Sensor Networks, Kevin M. Finnigin
Cryptanalysis Of Pseudorandom Number Generators In Wireless Sensor Networks, Kevin M. Finnigin
Theses and Dissertations
This work presents a brute-force attack on an elliptic curve cryptosystem implemented on UC Berkley's TinyOS operating system for wireless sensor networks. The attack exploits the short period of the pseudorandom number generator (PRNG) used by the cryptosystem to generate private keys. The attack assumes a laptop is listening promiscuously to network traffic for key messages and requires only the sensor node?s public key and network address to discover the private key. Experimental results show that roughly 50% of the address space leads to a private key compromise in 25 minutes on average. Furthermore, approximately 32% of the address space …
Detecting Potential Insider Threats Through Email Datamining, James S. Okolica
Detecting Potential Insider Threats Through Email Datamining, James S. Okolica
Theses and Dissertations
No abstract provided.
Publicly Verifiable Ownership Protection For Relational Databases, Yingjiu Li, Robert H. Deng
Publicly Verifiable Ownership Protection For Relational Databases, Yingjiu Li, Robert H. Deng
Research Collection School Of Computing and Information Systems
Today, watermarking techniques have been extended from the multimedia context to relational databases so as to protect the ownership of data even after the data are published or distributed. However, all existing watermarking schemes for relational databases are secret key based, thus require a secret key to be presented in proof of ownership. This means that the ownership can only be proven once to the public (e.g., to the court). After that, the secret key is known to the public and the embedded watermark can be easily destroyed by malicious users. Moreover, most of the existing techniques introduce distortions to …
Scalable Authentication Of Mpeg-4 Streams, Yongdong Wu, Robert H. Deng
Scalable Authentication Of Mpeg-4 Streams, Yongdong Wu, Robert H. Deng
Research Collection School Of Computing and Information Systems
This paper presents three scalable and efficient schemes for authenticating MPEG-4 streams: the Flat Authentication Scheme, the Progressive Authentication Scheme, and the Hierarchical Authentication Scheme. All the schemes allow authentication of MPEG-4 streams over lossy networks by integrating seamlessly digital signatures and erasure correction coding with MPEG-4's fine granular scalability. A prominent feature of our schemes is their "sign once, verify many ways" property, i.e., they generate only one digital signature per compressed MPEG-4 object group, but allow clients to verify the authenticity of any down-scaled version of the original signed object group.
Webisms: (Web-Based Information Security Management System): A Prevention Information Security Tool, Nam Kim
Webisms: (Web-Based Information Security Management System): A Prevention Information Security Tool, Nam Kim
Theses Digitization Project
The impetus for this project came from five years of experience working as a system and network administrator in the California State University, San Bernardino's (CSUSB's) College of Natural Sciences. The college and campus in general are under continual cyber attack, usually by direct-penetration methods and all kinds of viruses, worms, and spywares. This project developed WebISMS as a prevention approach in information security. WebISMS is now deployed in the CSUSB Institute of Applied Supercomputing lab, where it is working efficiently as an information security assessment / audit tool.