Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Law (54)
- Computer Law (51)
- Engineering (45)
- Computer Engineering (43)
- Social and Behavioral Sciences (39)
-
- Electrical and Computer Engineering (38)
- Forensic Science and Technology (36)
- Legal Studies (36)
- Digital Communications and Networking (5)
- Privacy Law (5)
- Software Engineering (5)
- Business (4)
- Databases and Information Systems (4)
- Management Information Systems (3)
- Education (2)
- Graphics and Human Computer Interfaces (2)
- International Law (2)
- Numerical Analysis and Scientific Computing (2)
- OS and Networks (2)
- Other Computer Engineering (2)
- Other Computer Sciences (2)
- Programming Languages and Compilers (2)
- Systems Architecture (2)
- Theory and Algorithms (2)
- Archival Science (1)
- Artificial Intelligence and Robotics (1)
- Computer and Systems Architecture (1)
- Institution
-
- Embry-Riddle Aeronautical University (48)
- Singapore Management University (43)
- Edith Cowan University (13)
- Maurer School of Law: Indiana University (5)
- Air Force Institute of Technology (4)
-
- California State University, San Bernardino (4)
- Rochester Institute of Technology (4)
- University of Nevada, Las Vegas (3)
- Bridgewater College (2)
- Old Dominion University (2)
- University of Arkansas, Fayetteville (2)
- Central Washington University (1)
- Eastern Michigan University (1)
- LSU New Orleans (1)
- Technological University Dublin (1)
- University of Dayton (1)
- University of Kentucky (1)
- University of New Haven (1)
- University of South Carolina (1)
- University of Texas Rio Grande Valley (1)
- Utah State University (1)
- Western Kentucky University (1)
- Keyword
-
- Security (9)
- Privacy (6)
- Computer security (5)
- Data protection (5)
- Authentication (4)
-
- Data privacy (4)
- Digital forensics (4)
- Threat (4)
- Cloud computing (3)
- Computer networks Security measures (3)
- Cryptography (3)
- Data encryption (Computer science) (3)
- Encryption (3)
- Network security (3)
- Android (2)
- Automated Psychological assessment (2)
- Computer Graphics (2)
- Computer Security (2)
- Computer crimes (2)
- Computer forensics (2)
- Content Analysis (2)
- Cybersecurity (2)
- Cyberterrorism Prevention (2)
- Denial of service attacks (2)
- Detecting (2)
- Digital Communication (2)
- Digital Forensics (2)
- Disgruntlement (2)
- Economic incentive (2)
- Employee Anger (2)
- Publication
-
- Research Collection School Of Computing and Information Systems (39)
- Journal of Digital Forensics, Security and Law (35)
- Annual ADFSL Conference on Digital Forensics, Security and Law (13)
- Australian Information Security Management Conference (11)
- Articles by Maurer Faculty (5)
-
- Theses (4)
- Theses Digitization Project (4)
- Dissertations and Theses Collection (Open Access) (3)
- Theses and Dissertations (3)
- UNLV Theses, Dissertations, Professional Papers, and Capstones (3)
- Computer Science Faculty Publications (2)
- Research outputs 2013 (2)
- Senior Seminars (2)
- AFIT Patents (1)
- All Faculty Scholarship for the College of the Sciences (1)
- All Graduate Theses and Dissertations, Spring 1920 to Summer 2023 (1)
- Distance Learning Faculty & Staff Publications (1)
- Doctoral (1)
- Electrical & Computer Engineering and Computer Science Faculty Publications (1)
- Electrical Engineering Undergraduate Honors Theses (1)
- Faculty Publications (1)
- Faculty Senate (1)
- Geography Faculty Publications (1)
- Graduate Theses and Dissertations (1)
- LSU New Orleans Theses and Dissertations (1)
- Master's Theses and Doctoral Dissertations (1)
- Perspectives@SMU (1)
- Theses and Dissertations - UTB/UTPA (1)
- Publication Type
- File Type
Articles 61 - 90 of 141
Full-Text Articles in Information Security
Money Laundering Detection Framework To Link The Disparate And Evolving Schemes, Murad Mehmet, Duminda Wijesekera, Miguel F. Buchholtz
Money Laundering Detection Framework To Link The Disparate And Evolving Schemes, Murad Mehmet, Duminda Wijesekera, Miguel F. Buchholtz
Annual ADFSL Conference on Digital Forensics, Security and Law
Money launderers hide traces of their transactions with the involvement of entities that participate in sophisticated schemes. Money laundering detection requires unraveling concealed connections among multiple but seemingly unrelated human money laundering networks, ties among actors of those schemes, and amounts of funds transferred among those entities. The link among small networks, either financial or social, is the primary factor that facilitates money laundering. Hence, the analysis of relations among money laundering networks is required to present the full structure of complex schemes. We propose a framework that uses sequence matching, case-based analysis, social network analysis, and complex event processing …
Identifying Peer-To-Peer Traffic On Shared Wireless Networks, Simon Piel, Ej Jung
Identifying Peer-To-Peer Traffic On Shared Wireless Networks, Simon Piel, Ej Jung
Annual ADFSL Conference on Digital Forensics, Security and Law
Tracing contraband downloads leads investigators to an IP address, and in turn Internet Service Providers (ISP) can provide a physical location using this IP address. However, most homes and offices share this IP address among many computers using wireless networks. In other words, there needs to be another investigation to find out which computer was responsible for contraband downloads. To make matters worse, these shared wireless networks often have vulnerabilities in access control such as using WEP or using weak passwords. In such cases, any computer in range, not necessarily at the given physical address, could be responsible. We use …
On Resolving The Cloud Forensics Conundrum, John Bagby
On Resolving The Cloud Forensics Conundrum, John Bagby
Annual ADFSL Conference on Digital Forensics, Security and Law
The “cloud” is idiom for an ill-defined set of online services. The cloud simultaneously offers IT savings and promises advances in functionality (e.g., ubiquity). However, the cloud also imposes poorly understood burdens on security and it may provoke injustice. Thus, the cloud presents a durable and seemingly irreconcilable conundrum for the digital forensics communit(ies). First, cloud proponents make efficiency promises for cloud services (SaaS, IaaS, PaaS). These translate well into the digital forensics domain. Indeed, the cloud may enable crowd sourcing of investigatory data vastly lowering costs of dispute resolution. For example, cloud-based litigation war rooms may reduce electronic discovery …
Cybercrime And Punishment: An Analysis Of The Deontological And Utilitarian Functions Of Punishment In The Information Age, Karim Jetha
Annual ADFSL Conference on Digital Forensics, Security and Law
This conceptual piece analyzes the role of criminal punishment and the nature of cyber crime to investigate whether the current punishment schemes are appropriate given the deontological and utilitarian goals of punishment: retribution, deterrence, incapacitation, and rehabilitation. The research has implications for policymaking in cybercriminal law.
Keywords: cybercrime, criminal law, punishment, retribution, deterrence, information economics
The Development Of Computer Forensic Legal System In China, Yonghao Mai, K. P. Chow, Rongsheng Xu, Gang Zhou, Fei Xu, Jun Zhang
The Development Of Computer Forensic Legal System In China, Yonghao Mai, K. P. Chow, Rongsheng Xu, Gang Zhou, Fei Xu, Jun Zhang
Annual ADFSL Conference on Digital Forensics, Security and Law
The computer forensic discipline was established around 2000 in China, which was further developed along with Chinese judicial appraisal system in 2005. The new criminal and civil procedure laws of the People’s Republic of China was enacted on 1 Jan 2013. The new laws specified electronic data is legal evidence and has great impact on the current practice on handling electronic evidence. This paper introduces the electronic data and electronic evidence examination procedure in mainland China, the general concept of computer forensic legal system, the management of computer judicial experts, the management of computer judicial expertise institutions.
Keywords: China legal …
A New Unpredictability-Based Rfid Privacy Model, Anjia Yang, Yunhui Zhuang, Duncan S. Wong, Guomin Yang
A New Unpredictability-Based Rfid Privacy Model, Anjia Yang, Yunhui Zhuang, Duncan S. Wong, Guomin Yang
Research Collection School Of Computing and Information Systems
Ind-privacy and unp-privacy, later refined to unp∗-privacy, are two different classes of privacy models for RFID authentication protocols. These models have captured the major anonymity and untraceability related attacks regarding RFID authentication protocols with privacy, and existing work indicates that unp∗-privacy seems to be a stronger notion when compared with ind-privacy. In this paper, we continue studying the RFID privacy models, and there are two folds regarding our results. First of all, we describe a new traceability attack and show that schemes proven secure in unp∗-privacy may not be secure against this new and practical type of traceability attacks. We …
Attribute-Based Access To Scalable Media In Cloud-Assisted Content Sharing, Yongdong Wu, Zhuo Wei, Robert H. Deng
Attribute-Based Access To Scalable Media In Cloud-Assisted Content Sharing, Yongdong Wu, Zhuo Wei, Robert H. Deng
Research Collection School Of Computing and Information Systems
This paper presents a novel Multi-message Ciphertext Policy Attribute-Based Encryption (MCP-ABE) technique, and employs the MCP-ABE to design an access control scheme for sharing scalable media based on data consumers’ attributes (e.g., age, nationality, gender) rather than an explicit list of the consumers’ names. The scheme is efficient and flexible because MCP-ABE allows a content provider to specify an access policy and encrypt multiple messages within one ciphertext such that only the users whose attributes satisfy the access policy can decrypt the ciphertext. Moreover, the paper shows how to support resource-limited mobile devices by offloading computational intensive perations to cloud …
A Modified Anonymisation Algorithm Towards Reducing Information Loss., Rose Tinabo
A Modified Anonymisation Algorithm Towards Reducing Information Loss., Rose Tinabo
Doctoral
The growth of various technologies in the modern digital world results in the col- lection and storage of huge amounts of individual's data. In addition of providing direct services delivery, this data can be used for other non-direct activities known as secondary use. This includes activities such as doing research, analysis, quality and safety measurement, public health, and marketing.
Think Twice Before You Share: Analyzing Privacy Leakage Under Privacy Control In Online Social Networks, Yan Li, Yingjiu Li, Qiang Yan, Robert H. Deng
Think Twice Before You Share: Analyzing Privacy Leakage Under Privacy Control In Online Social Networks, Yan Li, Yingjiu Li, Qiang Yan, Robert H. Deng
Research Collection School Of Computing and Information Systems
Online Social Networks (OSNs) have become one of the major platforms for social interactions. Privacy control is deployed in popular OSNs to protect user’s data. However, user’s sensitive information could still be leaked even when privacy rules are properly configured. We investigate the effectiveness of privacy control against privacy leakage from the perspective of information flow. Our analysis reveals that the existing privacy control mechanisms do not protect the flow of personal information effectively. By examining typical OSNs including Facebook, Google+, and Twitter, we discover a series of privacy exploits which are caused by the conflicts between privacy control and …
Launching Generic Attacks On Ios With Approved Third-Party Applications, Jin Han, Mon Kywe Su, Qiang Yan, Feng Bao, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou
Launching Generic Attacks On Ios With Approved Third-Party Applications, Jin Han, Mon Kywe Su, Qiang Yan, Feng Bao, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou
Research Collection School Of Computing and Information Systems
iOS is Apple’s mobile operating system, which is used on iPhone, iPad and iPod touch. Any third-party applications developed for iOS devices are required to go through Apple’s application vetting process and appear on the official iTunes App Store upon approval.When an application is downloaded from the store and installed on an iOS device, it is given a limited set of privileges, which are enforced by iOS application sandbox. Although details of the vetting process and the sandbox are kept as black box by Apple, it was generally believed that these iOS security mechanisms are effective in defending against malwares. …
Mitigating Access-Driven Timing Channels In Clouds Using Stopwatch, Peng Li, Debin Gao, Michael K. Reiter
Mitigating Access-Driven Timing Channels In Clouds Using Stopwatch, Peng Li, Debin Gao, Michael K. Reiter
Research Collection School Of Computing and Information Systems
This paper presents StopWatch , a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatchtriplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses thetiming of I/O events at a VM's replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VM. We detail the design and implementation …
Improving Internet Security Through Social Information And Social Comparison: A Field Quasi-Experiment, Qian Tang, Leigh L. Linden, John S. Quarterman, Andrew B. Whinston
Improving Internet Security Through Social Information And Social Comparison: A Field Quasi-Experiment, Qian Tang, Leigh L. Linden, John S. Quarterman, Andrew B. Whinston
Research Collection School Of Computing and Information Systems
Cybersecurity is a national priority in this big data era. Because of negative externalities and the resulting lack of economic incentives, companies often underinvest in security controls, despite government and industry recommendations. Although many existing studies on security have explored technical solutions, only a few have looked at the economic motivations. To fill the gap, we propose an approach to increase the incentives of organizations to address security problems. Specifically, we utilize and process existing security vulnerability data, derive explicit security performance information, and disclose the information as feedback to organizations and the public. We regularly release information on the …
Distortion Tolerant Source Code Using Viterbi Algorithm, Christopher Hankins
Distortion Tolerant Source Code Using Viterbi Algorithm, Christopher Hankins
Electrical Engineering Undergraduate Honors Theses
Convolutional codes are used in digital communication systems in order to protect information from distortion and increase system reliability. One of the most efficient methods for decoding convolutional codes is based on the Viterbi Algorithm. Considering the fundamental similarities between these channel codes and source codes, it is logical to postulate that the Viterbi Algorithm may also provide a basis for the implementation of an efficient lossy source code. In this thesis, the Viterbi Algorithm is used to used to compress digital data from a symmetric Bernoulli source. The Viterbi source code is simulated and shown to produce results which …
Onespace: Shared Depth-Corrected Video Interaction, David Ledo, Bon Adriel Aseniero, Sebastian Boring, Anthony Tang
Onespace: Shared Depth-Corrected Video Interaction, David Ledo, Bon Adriel Aseniero, Sebastian Boring, Anthony Tang
Research Collection School Of Computing and Information Systems
Video conferencing commonly employs a video portal metaphor to connect individuals from remote spaces. In this work, we explore an alternate metaphor, a shared depth mirror, where video images of two spaces are merged into a single shared, depth-corrected video. Just as seeing one’s mirror image causes reflective interaction, the shared video space changes the nature of interaction in the video space. We realize this metaphor in OneSpace, where the space respects virtual spatial relationships between people and objects, and in so doing, encourages cross-site, full-body interactions. We report preliminary observations of OneSpace in use, describing the role of depth …
A Secure And Fair Resource Sharing Model For Community Clouds, Santhosh S. Anand
A Secure And Fair Resource Sharing Model For Community Clouds, Santhosh S. Anand
Graduate Theses and Dissertations
Cloud computing has gained a lot of importance and has been one of the most discussed segment of today's IT industry. As enterprises explore the idea of using clouds, concerns have emerged related to cloud security and standardization. This thesis explores whether the Community Cloud Deployment Model can provide solutions to some of the concerns associated with cloud computing. A secure framework based on trust negotiations for resource sharing within the community is developed as a means to provide standardization and security while building trust during resource sharing within the community. Additionally, a model for fair sharing of resources is …
Simulation And Analysis Of Insider Attacks, Christopher Blake Clark
Simulation And Analysis Of Insider Attacks, Christopher Blake Clark
UNLV Theses, Dissertations, Professional Papers, and Capstones
An insider is an individual (usually an employee, contractor, or business partner) that has been trusted with access to an organization's systems and sensitive data for legitimate purposes. A malicious insider abuses this access in a way that negatively impacts the company, such as exposing, modifying, or defacing software and data.
Many algorithms, strategies, and analyses have been developed with the intent of detecting and/or preventing insider attacks. In an academic setting, these tools and approaches show great promise. To be sure of their effectiveness, however, these analyses need to be tested. While real data is available on insider attacks …
The Chain-Link Fence Model: A Framework For Creating Security Procedures, Robert F. Houghton
The Chain-Link Fence Model: A Framework For Creating Security Procedures, Robert F. Houghton
All Graduate Theses and Dissertations, Spring 1920 to Summer 2023
Information technology security professionals are facing an ever growing threat to the networks that they defend. The process for creating procedures to help stem this threat is very difficult for security professionals. The Chain-Link Fence Model helps security professionals by guiding them through the process of creating and implementing new security procedures.
Designing Leakage-Resilient Password Entry On Touchscreen Mobile Devices, Qiang Yan, Jin Han, Yingjiu Li, Jianying Zhou, Robert H. Deng
Designing Leakage-Resilient Password Entry On Touchscreen Mobile Devices, Qiang Yan, Jin Han, Yingjiu Li, Jianying Zhou, Robert H. Deng
Research Collection School Of Computing and Information Systems
Touchscreen mobile devices are becoming commodities as the wide adoption of pervasive computing. These devices allow users to access various services at anytime and anywhere. In order to prevent unauthorized access to these services, passwords have been pervasively used in user authentication. However, password-based authentication has intrinsic weakness in password leakage. This threat could be more serious on mobile devices, as mobile devices are widely used in public places. Most prior research on improving leakage resilience of password entry focuses on desktop computers, where specific restrictions on mobile devices such as small screen size are usually not addressed. Meanwhile, additional …
Expressive Search On Encrypted Data, Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen
Expressive Search On Encrypted Data, Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen
Research Collection School Of Computing and Information Systems
Different from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user’s public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Searchable pubic key encryption has many promising applications. Unfortunately, existing schemes either only support simple query predicates, such as equality queries and conjunctive queries, or have a superpolynomial blowup in ciphertext size …
Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks, Divyan Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen Fienberg
Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks, Divyan Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen Fienberg
Research Collection School Of Computing and Information Systems
In this paper we focus on authentication and privacy aspects of an application scenario that utilizes mobile crowd sensing for the benefit of amusement park operators and their visitors. The scenario involves a mobile app that gathers visitors’ demographic details, preferences, and current location coordinates, and sends them to the park’s sever for various analyses. These analyses assist the park operators to efficiently deploy their resources, estimate waiting times and queue lengths, and understand the behavior of individual visitors and groups. The app server also offers visitors optimal recommendations on routes and attractions for an improved dynamic experience and minimized …
Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model, Guomin Yang, Yi Mu, Willy Susilo, Duncan S. Wong
Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model, Guomin Yang, Yi Mu, Willy Susilo, Duncan S. Wong
Research Collection School Of Computing and Information Systems
Authenticated key exchange (AKE) protocols allow two parties communicating over an insecure network to establish a common secret key. They are among the most widely used cryptographic protocols in practice. In order to resist key-leakage attacks, several leakage resilient AKE protocols have been proposed recently in the bounded leakage model. In this paper, we initiate the study on leakage resilient AKE in the auxiliary input model. A promising way to construct such a protocol is to use a digital signature scheme that is entropically-unforgeable under chosen message and auxiliary input attacks. However, to date we are not aware of any …
Information Security As A Credence Good, Ping Fan Ke, Kai-Lung Hui, Wei Thoo Yue
Information Security As A Credence Good, Ping Fan Ke, Kai-Lung Hui, Wei Thoo Yue
Research Collection School Of Computing and Information Systems
With increasing use of information systems, many organizations are outsourcing information security protection to a managed security service provider (MSSP). However, diagnosing the risk of an information system requires special expertise, which could be costly and difficult to acquire. The MSSP may exploit their professional advantage and provide fraudulent diagnosis of clients’ vulnerabilities. Such an incentive to mis-represent clients’ risks is often called the credence goods problem in the economics literature[3]. Although different mechanisms have been introduced to tackle the credence goods problem, in the information security outsourcing context, such mechanisms may not work well with the presence of system …
Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang
Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang
Research Collection School Of Computing and Information Systems
We revisit the problem of secure cross-domain communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a generic framework for designing four-party password-based authenticated key exchange (4PAKE) protocols. Our framework takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with …
Rootkit Detection Using A Cross-View Clean Boot Method, Bridget N. Flatley
Rootkit Detection Using A Cross-View Clean Boot Method, Bridget N. Flatley
Theses and Dissertations
In cyberspace, attackers commonly infect computer systems with malware to gain capabilities such as remote access, keylogging, and stealth. Many malware samples include rootkit functionality to hide attacker activities on the target system. After detection, users can remove the rootkit and associated malware from the system with commercial tools. This research describes, implements, and evaluates a clean boot method using two partitions to detect rootkits on a system. One partition is potentially infected with a rootkit while the other is clean. The method obtains directory listings of the potentially infected operating system from each partition and compares the lists to …
Mobile Network Defense Interface For Cyber Defense And Situational Awareness, James C. Hannan
Mobile Network Defense Interface For Cyber Defense And Situational Awareness, James C. Hannan
Theses and Dissertations
Today's computer networks are under constant attack. In order to deal with this constant threat, network administrators rely on intrusion detection and prevention services (IDS) (IPS). Most IDS and IPS implement static rule sets to automatically alert administrators and resolve intrusions. Network administrators face a difficult challenge, identifying attacks against a vast number of benign network transactions. Also after a threat is identified making even the smallest policy change to the security software potentially has far-reaching and unanticipated consequences. Finally, because the administrator is primarily responding to alerts they may lose situational awareness of the network. During this research a …
Accountable Authority Identity-Based Encryption With Public Traceability, Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng
Accountable Authority Identity-Based Encryption With Public Traceability, Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng
Research Collection School Of Computing and Information Systems
At Crypto’07, Goyal introduced the notion of accountable authority identity-based encryption (A-IBE) in order to mitigate the inherent key escrow problem in identity-based encryption, and proposed two concrete constructions. In an A-IBE system, if the private key generator (PKG) distributes a decryption key or produces an unauthorized decryption box for a user maliciously, it runs the risk of being caught and sued in the court of law with the help of a tracing algorithm. Subsequent efforts focused on constructions of A-IBE schemes with enhanced security. In these A-IBE constructions, the tracing algorithm needs to take a user’s decryption key as …
Almost Touching: Parent-Child Remote Communication Using The Sharetable System, Svetlana Yarosh, Anthony Tang, Sanika Mokashi, Gregory D. Abowd
Almost Touching: Parent-Child Remote Communication Using The Sharetable System, Svetlana Yarosh, Anthony Tang, Sanika Mokashi, Gregory D. Abowd
Research Collection School Of Computing and Information Systems
We deployed the ShareTable - a system that provides easy-to-initiate videochat and a shared tabletop task space - in four divorced households. Throughout the month of its use, the families employed the ShareTable to participate in shared activities, share emotional moments, and communicate closeness through metaphorical touch. The ShareTable provided a number of advantages over the phone and was easier to use than standard videoconferencing. However, it did also introduce concerns over privacy and new sources of conflict about appropriate calling practices. We relate our findings to the larger research landscape and present implications for future work.