Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Computer Law (40)
- Law (40)
- Engineering (32)
- Electrical and Computer Engineering (30)
- Computer Engineering (29)
-
- Social and Behavioral Sciences (28)
- Forensic Science and Technology (27)
- Legal Studies (27)
- Business (3)
- Digital Communications and Networking (2)
- Electrical and Electronics (2)
- Software Engineering (2)
- Business Administration, Management, and Operations (1)
- Business Law, Public Responsibility, and Ethics (1)
- Communication (1)
- Databases and Information Systems (1)
- Education (1)
- Educational Administration and Supervision (1)
- Graphics and Human Computer Interfaces (1)
- Health and Medical Administration (1)
- Higher Education Administration (1)
- Journalism Studies (1)
- Mass Communication (1)
- Mathematics (1)
- Medicine and Health Sciences (1)
- OS and Networks (1)
- Organizational Behavior and Theory (1)
- Institution
-
- Embry-Riddle Aeronautical University (43)
- Edith Cowan University (23)
- Air Force Institute of Technology (18)
- Singapore Management University (15)
- California State University, San Bernardino (1)
-
- Central Washington University (1)
- Munster Technological University (1)
- Portland State University (1)
- Technological University Dublin (1)
- University of Arkansas Little Rock (1)
- University of Arkansas, Fayetteville (1)
- University of New Mexico (1)
- University of Tennessee at Chattanooga (1)
- Western Kentucky University (1)
- Keyword
-
- Computer security (13)
- Computer networks--Security measures (8)
- Cyberterrorism (4)
- Digital forensics (4)
- Network security (4)
-
- Security (4)
- Computer forensics (3)
- Privacy (3)
- Access control (2)
- Computer Forensics (2)
- Critical Infrastructure (2)
- Data disposal (2)
- Data protection (2)
- Data recovery (2)
- Digital Forensics (2)
- Electronic data destruction (2)
- Information warfare--United States (2)
- Intrusion detection (2)
- Public key infrastructure (2)
- Remote attestation (2)
- Trusted computing (2)
- Vulnerability (2)
- #antcenter (1)
- Active attack (1)
- Agency theory (1)
- Agile security (1)
- Algorithms (1)
- Analysis (1)
- Anomaly detection (1)
- Anomaly detection (Computer science) (1)
- Publication
-
- Journal of Digital Forensics, Security and Law (34)
- Theses and Dissertations (19)
- Australian Information Security Management Conference (16)
- Research Collection School Of Computing and Information Systems (15)
- Annual ADFSL Conference on Digital Forensics, Security and Law (6)
-
- Australian Information Warfare and Security Conference (6)
- Publications (3)
- All Faculty Scholarship for the College of Business (1)
- Branch Mathematics and Statistics Faculty and Staff Publications (1)
- Computer Science Faculty Publications and Presentations (1)
- Computer Science and Computer Engineering Undergraduate Honors Theses (1)
- Conference papers (1)
- Masters Theses and Doctoral Dissertations (1)
- Theses (1)
- Theses : Honours (1)
- Theses Digitization Project (1)
- WKU Administration Documents (1)
- Publication Type
Articles 61 - 90 of 109
Full-Text Articles in Information Security
Evaluating The Usability Impacts Of Security Interface Adjustments In Word 2007, M Helala, S M. Furnell, M Papadaki
Evaluating The Usability Impacts Of Security Interface Adjustments In Word 2007, M Helala, S M. Furnell, M Papadaki
Australian Information Security Management Conference
Prior research has suggested that integrating security features with user goals and increasing their visibility would improve the usability of the associated functionalities. This paper investigates how these approaches affect the efficiency of use and the level of user satisfaction. The user interface of Word 2007 was modified according to these principles, with usability tests being conducted with both the original and the modified user interfaces. The results suggest that integrating security features with user goals improves the efficiency of use, but the impacts upon user satisfaction cannot be clearly identified based on the collected data. No indications of any …
Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver
Organisational Security Requirements:An Agile Approach To Ubiquitous Information Security, A B. Ruighaver
Australian Information Security Management Conference
This paper proposes to address the need for more innovation in organisational information security by adding a security requirement engineering focus. Based on the belief that any heavyweight security requirements process in organisational security will be doomed to fail, we developed a security requirement approach with three dimensions. The use of a simple security requirements process in the first dimension has been augmented by an agile security approach. However, introducing this second dimension of agile security does provide support for, but does not necessarily stimulate, innovation. A third dimension is, therefore, needed to ensure there is a proper focus in …
Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce
Enhanced Security For Preventing Man-In-The-Middle Attacks In Authentication, Dataentry And Transaction Verification, Jason Wells, Damien Hutchinson, Justin Pierce
Australian Information Security Management Conference
There is increasing coverage in the literature highlighting threats to online financial systems. Attacks range from the prevalent reverse social engineering technique known as phishing; where spam emails are sent to customers with links to fake websites, to Trojans that monitor a customer’s account log on process that captures authentication details that are later replayed for financial gain. This ultimately results in loss of monetary funds for affected victims. As technological advances continue to influence the way society makes payment for goods and services, the requirement for more advanced security approaches for transaction verification in the online environment increases. This …
Rfid Communications - Who Is Listening?, Christopher Bolan
Rfid Communications - Who Is Listening?, Christopher Bolan
Australian Information Security Management Conference
Radio Frequency Identification (RFID) is seeing a surge in awareness across a range of industries as a successor to barcoding. The nature of this technology promises a wide range of benefits but it appears to be at the expense of security. This paper investigates an eavesdropping attack against an EPC RFID system and shows how a simple device may be used to record interactions between both Tag and Readers. The device is used to record and decode signals within range and its output is analysed to verify that the attack was indeed successful. The findings verify previous assertions by other …
Secure Portable Execution Environments: A Review Of Available Technologies, Peter James
Secure Portable Execution Environments: A Review Of Available Technologies, Peter James
Australian Information Security Management Conference
Live operating systems and virtualisation allow a known, defined, safe and secure execution environment to be loaded in to a PC’s memory and executed with either minimal or possibly no reliance on the PC’s internal hard disk drive. The ability to boot a live operating system or load a virtual environment (containing an operating system) from a USB storage device allows a secure portable execution environment to be created. Portable execution environments have typically been used by technologists, for example to recover data from a failing PC internal hard disk drive or to perform forensic analysis. However, with the commercial …
Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew
Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew
Australian Information Security Management Conference
In an environment where technical solutions for securing networked systems are commonplace, there still exist problems in implementation of such solutions for home and small business users. One component of this protection is the use of intrusion detection systems. Intrusion detection monitors network traffic for suspicious activity, performs access blocking and alerts the system administrator or user of potential attacks. This paper reviews the basic function of intrusion detection systems and maps them to an existing end-user capability framework. Using this framework, implementation guidance and systematic improvement in implementation of this security measure are defined.
Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong
Assessing And Mitigating Vip Vulnerabilities In The Corporate Environment, Hoi Z. Wong
Australian Information Security Management Conference
Video over IP (VIP) is becoming a tool of communication in corporate environments to reduce the time spent conducting meetings face-to-face. This has been driven by efficiencies of time saving, management’s monitoring of staff and to communicate with flexibilities - without placing additional disadvantages on employees who must regularly attend personal meetings amongst hectic business schedules. With technology excelling beyond the old telegraphy of analogy video over hard copper wire to dark fibre technology, VIP is a technology that is starting to receive more attention in the corporate world as more organisations have the equipment to support this additional plug-in. …
Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke
Deployment Of Keystroke Analysis On A Smartphone, A Buchoux, N L. Clarke
Australian Information Security Management Conference
The current security on mobile devices is often limited to the Personal Identification Number (PIN), a secretknowledge based technique that has historically demonstrated to provide ineffective protection from misuse. Unfortunately, with the increasing capabilities of mobile devices, such as online banking and shopping, the need for more effective protection is imperative. This study proposes the use of two-factor authentication as an enhanced technique for authentication on a Smartphone. Through utilising secret-knowledge and keystroke analysis, it is proposed a stronger more robust mechanism will exist. Whilst keystroke analysis using mobile devices have been proven effective in experimental studies, these studies have …
Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari
Information Security Governance And Boards Of Directors: Are They Compatible?, Endre Bihari
Australian Information Security Management Conference
This paper presents a critique of emergent views on the roles of the boards of directors in relation to information security. The analysis highlights several concerns about the separation and validation of proper theory and business assertions of information security at board level. New requirements articulated by industry bodies – represented by a selected group of experts and evident in literature – are compared to the underlying theory of corporate governance to identify possible discrepancies. The discussion shows in particular the importance of staying within the theoretical underpinnings of corporate governance when discussing the topic of governance in general and …
Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones
Framework For Anomaly Detection In Okl4-Linux Based Smartphones, Geh W. Chow, Andy Jones
Australian Information Security Management Conference
Smartphones face the same threats as traditional computers. As long as a device has the capabilities to perform logic processing, the threat of running malicious logic exists. The only difference between security threats on traditional computers versus security threats on smartphones is the challenge to understand the inner workings of the operating system on different hardware processor architectures. To improve upon the security of smartphones, anomaly detection capabilities can be implemented at different functional layers of a smartphone in a coherent manner; instead of just looking at individual functional layers. This paper will focus on identifying conceptual points for measuring …
Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao
Risk Mitigation Strategies For The Prepaid Card Issuer In Australia, M A. Khairuddin, P Zhang, A Rao
Australian Information Security Management Conference
The prepaid card market in Australia is growing rapidly. Its features not only attract customers from all sorts of backgrounds but also expose it to numerous risks. Using the methodology of the Australian Risk Management Standard AS/NZS4360, this paper looks at the risks inherent in prepaid cards. Concentrating on two major risks, the paper details the regulations governing the industry in the USA as well the technical controls employed by the credit/debit card industry. We suggest risk mitigation strategies from these two view-points, aiming to become an important reference both for industry as it adopts better risk mitigation techniques, and …
Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong
Identifying Dos Attacks Using Data Pattern Analysis, Mohammed Salem, Helen Armstrong
Australian Information Security Management Conference
During a denial of service attack, it is difficult for a firewall to differentiate legitimate packets from rogue packets, particularly in large networks carrying substantial levels of traffic. Large networks commonly use network intrusion detection systems to identify such attacks, however new viruses and worms can escape detection until their signatures are known and classified as an attack. Commonly used IDS are rule based and static, and produce a high number of false positive alerts. The aim of this research was to determine if it is possible for a firewall to analyse its own traffic patterns to identify attempted denial …
Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward
Securing A Wireless Network With Eap-Tls: Perception And Realities Of Its Implementation, Brett Turner, Andrew Woodward
Australian Information Security Management Conference
In the arena of wireless security, EAP-TLS is considered one of the most secure protocols. However since its inception the uptake has been poor and the investigation into the reasons for this are sparse. There is an industry perception that EAP-TLS is complex as well as difficult to configure and manage. One of the major barriers is in the use of public key infrastructure and the perceived difficulties in its application. The paper discusses why it is seemingly difficult to implement and how this may differ from the reality of its implementation. This premise is investigated using Windows Server 2003 …
Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward
Network Security Isn’T All Fun And Games: An Analysis Of Information Transmitted While Playing Team Fortress 2, Brett Turner, Andrew Woodward
Australian Information Security Management Conference
In the world of online gaming, information is exchanged as a matter of course. What information is exchanged behind the scenes is something that is not obvious to the casual user. People who play these games trust that the applications they are using are securely written and in this case, communicate securely. This paper looks at the traffic that is transmitted by the game Team Fortress 2 and incidentally the supporting authentication traffic of the Steam network. It was discovered through packet analysis that there is quite a lot of information which should be kept private being broadcast in the …
Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli
Trust Me. I Am A Doctor. Your Records Are Safe…, Patricia A. Williams, Craig Valli
Australian Information Security Management Conference
Primary care medical practices in Australia have been identified as a profession in need of assistance with information security practices. Whilst guidelines exist, there is little assistance in an accessible and easily implemented form for medical practices. This research presents the preliminary findings of a study which advocates that information security practices can be improved using a capability operational framework which is contextualised to its target environment.
The Development Of A Framework For Enterprise Security Architecture And Its Application In Organizations, Yi-Ting Shen
The Development Of A Framework For Enterprise Security Architecture And Its Application In Organizations, Yi-Ting Shen
Theses Digitization Project
The main purpose of this study is to develop an enterprise security framework that is based on a comprehensive following the Zachman EA architecture. The enterprise architecture (EA) is a long-term view or blueprint for an organization. It is a very important blueprint for balancing business and IT technology and for adding value to an organization. Security is also an essential dimension for enterprises nowadays. This paper will incorporate the security dimension with the Zachman EA framework, which intends to serve as an enterprise security framework in assisting an organization to successfully and effectively implement security.
Ua1f Wku Archives Vertical File - Wku Information Technology, Wku Archives
Ua1f Wku Archives Vertical File - Wku Information Technology, Wku Archives
WKU Administration Documents
Digitized vertical file materials regarding WKU Information Technology.
Traffic Analysis Of Udp-Based Flows In Ourmon, Jim Binkley, Divya Parekh
Traffic Analysis Of Udp-Based Flows In Ourmon, Jim Binkley, Divya Parekh
Computer Science Faculty Publications and Presentations
We present a custom UDP flow tuple with an IP address key and a set of simple related statistical attributes. Attributes are used to calculate a per host metric called the UDP work weight which roughly measures the amount of network noise caused by a host. The work weight is used to produce a near real-time sorted top N report for UDP host tuples. We also present a derived attribute based on an algorithm called the UDP guesstimator. The UDP guesstimator roughly classifies port report hosts into various traffic categories including security threats (DOS/scanning) or P2P hosts based on high …
Analysis Of Information Remaining On Hand Held Devices Offered For Sale On The Second Hand, Andy Jones, Craig Valli, Iain Sutherland
Analysis Of Information Remaining On Hand Held Devices Offered For Sale On The Second Hand, Andy Jones, Craig Valli, Iain Sutherland
Journal of Digital Forensics, Security and Law
The ownership and use of mobile phones, Personal Digital Assistants and other hand held devices is now ubiquitous both for home and business use. The majority of these devices have a high initial cost, a relatively short period before they become obsolescent and a relatively low second hand value. As a result of this, when the devices are replaced, there are indications that they tend to be discarded. As technology has continued to develop, it has led to an increasing diversity in the number and type of devices that are available, and the processing power and the storage capacity of …
Case Analysis Of Information Security Risk Perceptions, Alexis Guillot
Case Analysis Of Information Security Risk Perceptions, Alexis Guillot
Theses : Honours
The scientific rationality used by experts towards risk evaluation is expressed as the product of its likelihood of occurrence with its consequences or impacts (ENISA, 2006a). This directly opposes the subjective nature of risk perception, often appearing as inconsistent if not completely irrational (Byrne, 2003). Risk perception theories are a pathway to explain the subjective nature of risk and a deeper insight into the human's cognitive system. Those theories may help to explain why people see, act and plan for risks in the way that they do, the weaknesses that exist in the human decision mechanisms and their impact on …
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
Who Is Reading The Data On Your Old Computer?, Vivienne Mee
Who Is Reading The Data On Your Old Computer?, Vivienne Mee
Journal of Digital Forensics, Security and Law
Researchers at Rits Information Security performed a study in how the Irish population disposes of their old computers. How would you dispose of your old computer, or how would the company you work for dispose of their old computers?
The majority of Irish homeowners, would bring their old computers to local civic amenity centres, give it away to a relative or sell it on to another party.
Some organisations would give their old equipment to a staff member, as a gift gesture, others may simply discard in the local civic amenity site.
What is wrong with the methods currently being …
Trends In Virtualized User Environments, Diane Barrett
Trends In Virtualized User Environments, Diane Barrett
Journal of Digital Forensics, Security and Law
Virtualized environments can make forensics investigation more difficult. Technological advances in virtualization tools essentially make removable media a PC that can be carried around in a pocket or around a neck. Running operating systems and applications this way leaves very little trace on the host system. This paper will explore all the newest methods for virtualized environments and the implications they have on the world of forensics. It will begin by describing and differentiating between software and hardware virtualization. It will then move on to explain the various methods used for server and desktop virtualization. Next, it will explain how …
Data Recovery From Palmmsgv001, Satheesaan Pasupatheeswaran
Data Recovery From Palmmsgv001, Satheesaan Pasupatheeswaran
Journal of Digital Forensics, Security and Law
Both SMS and MMS data analysis is an important factor in mobile forensic analysis. Author did not find any mobile forensic tool that is capable of extracting short messages (SMS) and multimedia messages (MMS) from Palm Treo 750. SMS file of Palm Treo 750 is called PalmMgeV001 and it is a proprietary file system. A research work done to find a method to recover SMS data from PalmMsgV001 file. This paper is going to describe the research work and its findings. This paper also discusses a methodology that will help recover SMS data from PalmMsgV001. The PalmMsgV001 file is analysed …
Extraction And Categorisation Of User Activity From Windows Restore Points, Damir Kahvedžić, Tahar Kechadi
Extraction And Categorisation Of User Activity From Windows Restore Points, Damir Kahvedžić, Tahar Kechadi
Journal of Digital Forensics, Security and Law
The extraction of the user activity is one of the main goals in the analysis of digital evidence. In this paper we present a methodology for extracting this activity by comparing multiple Restore Points found in the Windows XP operating system. The registry copies represent a snapshot of the state of the system at a certain point in time. Differences between them can reveal user activity from one instant to another. The algorithms for comparing the hives and interpreting the results are of high complexity. We develop an approach that takes into account the nature of the investigation and the …
Steganography: Forensic, Security, And Legal Issues, Merrill Warkentin, Ernst Bekkering, Mark B. Schmidt
Steganography: Forensic, Security, And Legal Issues, Merrill Warkentin, Ernst Bekkering, Mark B. Schmidt
Journal of Digital Forensics, Security and Law
Steganography has long been regarded as a tool used for illicit and destructive purposes such as crime and warfare. Currently, digital tools are widely available to ordinary computer users also. Steganography software allows both illicit and legitimate users to hide messages so that they will not be detected in transit. This article provides a brief history of steganography, discusses the current status in the computer age, and relates this to forensic, security, and legal issues. The paper concludes with recommendations for digital forensics investigators, IT staff, individual users, and other stakeholders.
Elliptic Curve Cryptography Security On Restricted Mobile Devices, Debbie Mccann
Elliptic Curve Cryptography Security On Restricted Mobile Devices, Debbie Mccann
Theses
Mobile technologies with limited resources, such as smart phones or PDAs, have increased dramatically in popularity. However, the level of security provided for these technologies has not kept pace with the value of the data that they contain or transmit.
Wireless networks usually provide some security, in the form of encryption. GSM and GPRS use different forms of the A5 algorithm, and Wi-Fi uses WEP or WPA. These encryption algorithms have proven weaknesses and in some cases have been efficiently cracked. To improve the security of wireless networks, stronger encryption algorithms need to be developed. One of the most attractive …
Set Linear Algebra And Set Fuzzy Linear Algebra, Florentin Smarandache, W.B. Vasantha Kandasamy, K. Ilanthenral
Set Linear Algebra And Set Fuzzy Linear Algebra, Florentin Smarandache, W.B. Vasantha Kandasamy, K. Ilanthenral
Branch Mathematics and Statistics Faculty and Staff Publications
In this book, the authors define the new notion of set vector spaces which is the most generalized form of vector spaces. Set vector spaces make use of the least number of algebraic operations, therefore, even a non-mathematician is comfortable working with it. It is with the passage of time, that we can think of set linear algebras as a paradigm shift from linear algebras. Here, the authors have also given the fuzzy parallels of these new classes of set linear algebras. This book abounds with examples to enable the reader to understand these new concepts easily. Laborious theorems and …
Network Security In Two-Year Colleges, Tamya Jean Stallings
Network Security In Two-Year Colleges, Tamya Jean Stallings
Theses and Dissertations
Network security has become a growing challenge in industry and education. With the increase of viruses, spam, hackers, and identity theft, organizations are beginning to look at areas to improve the protection of their Information Technology structure. Higher Education has the highest vulnerability to network security threats especially the two-year institutions. Two-year institutions are known for open access admission. Open labs, limited staff and resources hinder security measures for these institutions. This thesis focuses on the two-year institution delving into the Information Technology Departments and how security is handled. What challenges have these institutions faced trying to protect data and …
Remote Forensics May Bring The Next Sea Change In E-Discovery: Are All Networked Computers Now Readily Accessible Under The Revised Federal Rules Of Civil Procedure?, Joseph J. Schwerha, Scott Inch
Remote Forensics May Bring The Next Sea Change In E-Discovery: Are All Networked Computers Now Readily Accessible Under The Revised Federal Rules Of Civil Procedure?, Joseph J. Schwerha, Scott Inch
Journal of Digital Forensics, Security and Law
The recent amendments to Rule 26 of the Federal Rules of Civil Procedure created a two-tiered approach to discovery of electronically stored information (“ESI”). Responding parties must produce ESI that is relevant, not subject to privilege, and reasonably accessible. However, because some methods of storing ESI, such as on magnetic backup tapes and within enormous databases, require substantial cost to access and search their contents, the rules permit parties to designate those repositories as “not reasonably accessible” because of undue burden or cost. But even despite the difficulty in searching for ESI, the party’s duty to preserve potentially responsive evidence …