Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (80)
- Social and Behavioral Sciences (75)
- Law (71)
- Computer Law (67)
- Forensic Science and Technology (64)
-
- Legal Studies (64)
- Computer Engineering (60)
- Electrical and Computer Engineering (47)
- Sociology (23)
- OS and Networks (21)
- Other Computer Sciences (20)
- Aviation (18)
- Defense and Security Studies (18)
- Public Affairs, Public Policy and Public Administration (18)
- Aviation Safety and Security (17)
- National Security Law (17)
- Social Control, Law, Crime, and Deviance (17)
- Databases and Information Systems (15)
- Medicine and Health Sciences (11)
- Health Information Technology (8)
- Software Engineering (7)
- Systems Architecture (7)
- Communication (5)
- Theory and Algorithms (5)
- Business (4)
- Programming Languages and Compilers (4)
- Criminology (3)
- Institution
-
- Embry-Riddle Aeronautical University (70)
- Edith Cowan University (44)
- Singapore Management University (37)
- University of New Haven (8)
- Nova Southeastern University (7)
-
- The University of San Francisco (6)
- Maurer School of Law: Indiana University (3)
- San Jose State University (3)
- DePauw University (2)
- Franklin University (2)
- Kennesaw State University (2)
- Rose-Hulman Institute of Technology (2)
- University of Dayton (2)
- Air Force Institute of Technology (1)
- Boise State University (1)
- California Polytechnic State University, San Luis Obispo (1)
- East Tennessee State University (1)
- Eastern Michigan University (1)
- Governors State University (1)
- LSU New Orleans (1)
- Marquette University (1)
- Northern Michigan University (1)
- Parkland College (1)
- Portland State University (1)
- Sacred Heart University (1)
- Syracuse University (1)
- University of Arkansas, Fayetteville (1)
- University of Central Florida (1)
- University of Richmond (1)
- Western University (1)
- Keyword
-
- Digital forensics (18)
- Security (15)
- Big data (8)
- Privacy (7)
- Approximate matching (6)
-
- Mrsh-v2 (6)
- Android (5)
- Authentication (5)
- Computer security (5)
- Cyber security (5)
- Digital evidence (5)
- Forensics (5)
- Bloom filter (4)
- Data privacy (4)
- Encryption (4)
- Information security (4)
- Mobile device forensics (4)
- Network forensics (4)
- Sdhash (4)
- Smartphone (4)
- Social media (4)
- [RSTDPub] (4)
- Analytics (3)
- Cloud forensics (3)
- Communications (3)
- Cybersecurity (3)
- Data protection (3)
- Discrete logarithm (3)
- Hashing (3)
- Healthcare (3)
- Publication
-
- Journal of Digital Forensics, Security and Law (50)
- Research Collection School Of Computing and Information Systems (36)
- Annual ADFSL Conference on Digital Forensics, Security and Law (17)
- Australian Information Security Management Conference (13)
- Australian Digital Forensics Conference (12)
-
- Australian eHealth Informatics and Security Conference (8)
- Electrical & Computer Engineering and Computer Science Faculty Publications (8)
- CCAC Theses and Dissertations (7)
- Media Studies (6)
- Australian Information Warfare and Security Conference (4)
- Research outputs 2014 to 2021 (4)
- Articles by Maurer Faculty (3)
- Australian Security and Intelligence Conference (3)
- Master's Projects (3)
- All Faculty and Staff Scholarship (2)
- Computer Science Faculty Publications (2)
- Publications (2)
- A with Honors Projects (1)
- All Capstone Projects (1)
- Annual Student Research Poster Session (1)
- Bookshelf (1)
- College of Arts and Sciences Presentations (1)
- Conference Papers in Published Proceedings (1)
- Department of Electrical Engineering and Computer Science - Daytona Beach (1)
- Dissertations (1934 -) (1)
- Dissertations and Theses (1)
- Dissertations and Theses Collection (Open Access) (1)
- Dissertations, Theses and Capstone Projects (1)
- Electrical Engineering and Computer Science - All Scholarship (1)
- Electrical and Computer Engineering Publications (1)
- Publication Type
Articles 1 - 30 of 205
Full-Text Articles in Information Security
A Hash-Cash Based Music Streaming Payment System, Timothy Chen
A Hash-Cash Based Music Streaming Payment System, Timothy Chen
Master's Projects
This project develops a hash-cash based, streaming music payment system. In our system, musicians are paid based on how long their works are listened to. Artists can upload their works to our proof-of-concept service so that people can discover and listen to them. While their works are being listened to, a mining process is run in parallel. The mining process discovers a “listening coin” based on the hash-cash algorithm. Users of our service would pay a monthly fee to access the music library. The monthly fees are then distributed to all artists proportionate to the number of virtual coins they …
Masquerade Detection Using Singular Value Decomposition, Sweta Vikram Shah
Masquerade Detection Using Singular Value Decomposition, Sweta Vikram Shah
Master's Projects
Information systems and networks are highly susceptible to attacks in the form of intrusions. One such attack is by the masqueraders who impersonate legitimate users. Masqueraders can be detected in anomaly based intrusion detection by identifying the abnormalities in user behavior. This user behavior is logged in log files of different types. In our research we use the score based technique of Singular Value Decomposition to address the problem of masquerade detection on a unix based system. We have data collected in the form of sequential unix commands ran by 50 users. SVD is a linear algebraic technique, which has …
Spartan Web Application Firewall, Brian C. Lee
Spartan Web Application Firewall, Brian C. Lee
Master's Projects
Computer security is an ongoing issue and attacks are growing more sophisit- cated. One category of attack utilizes cross-site scripting (XSS) to extract confiden- tial data such as a user’s login credential’s without the knowledge of either the user nor the web server by utilizing vulnerabilities on web pages and internet browsers. Many people develop their own web applications without learning about or having good coding practices or security in mind. Web application firewalls are able to help but can be enhanced to be more effective than they currently are at detecting re- flected XSS attacks by analyzing the request …
Customising Doctor-Nurse Communications, Brian Cusack, Dave Parry
Customising Doctor-Nurse Communications, Brian Cusack, Dave Parry
Australian eHealth Informatics and Security Conference
Doctor-Nurse communications are critical for patient safety and workflow effectiveness. Our research question was: What further improvements can be made to current communication systems? A variety of mobile and land based communication systems have been used and experimented with. In the study, the pager was found to be most common and more recent attempts to provide broadband capability with systems such as the iBeep. We built an alternative information system using Android phones and a software application that was customised by feedback from the medical professionals. The trial in five wards with 22 doctors and 170 nurses over one month …
Security Of Electronic Health Records In A Resource Limited Setting: The Case Of Smart-Care Electronic Health Record In Zambia, Keith Mweebo
Security Of Electronic Health Records In A Resource Limited Setting: The Case Of Smart-Care Electronic Health Record In Zambia, Keith Mweebo
Australian eHealth Informatics and Security Conference
This paper presents a case study of security issues related to the operationalization of smart-care, an electronic medical record (EMR) used to manage Human Immunodeficiency Virus (HIV) health information in Zambia. The aim of the smart-care program is to link up services and improve access to health information, by providing a reliable way to collect, store, retrieve and analyse health data in a secure way. As health professionals gain improved access to patient health information electronically, there is need to ensure this information is secured, and that patient privacy and confidentiality is maintained. During the initial stages of the program …
The Potentials And Challenges Of Big Data In Public Health, Rena N. Vithiatharan
The Potentials And Challenges Of Big Data In Public Health, Rena N. Vithiatharan
Australian eHealth Informatics and Security Conference
The potential to use big data sources for public health increases with the broadening availability of data and improved methods of analysis. Whilst there are some well-known examples of the opportunistic use of big data, such as GoogleFlu, public health has not yet realised the full potential of such data sources. A literature review was undertaken to identify the potential of such data collections to impact public health, and to identify what challenges are currently limiting this potential. The potential include improved real-time analysis, research and development and genome studies. However, challenges listed are poor universal standardisation and classification, privacy …
Byod In Ehealth: Herding Cats And Stable Doors, Or A Catastrophe Waiting To Happen?, Krishnun Sansurooh, Patricia A H Williams
Byod In Ehealth: Herding Cats And Stable Doors, Or A Catastrophe Waiting To Happen?, Krishnun Sansurooh, Patricia A H Williams
Australian eHealth Informatics and Security Conference
The use of personal devices in the work environment has crossed the boundaries of work and socially related tasks. With cyber criminals seriously targeting healthcare for medical identity theft, the lack of control of new technologies within healthcare networks becomes an increasing vulnerability. The prolific adoption of personal mobile devices in the healthcare environment requires a proactive approach to the management of Bring Your Own Device (BYOD). This paper analysed the current state of the problem and the challenges that this creates in an environment that has stringent privacy and security requirements. The discourse demonstrates that the issue is not …
3rd Australian Ehealth Informatics And Security Conference, 2014, Edith Cowan University: Conference Details, Security Research Institute, Edith Cowan University
3rd Australian Ehealth Informatics And Security Conference, 2014, Edith Cowan University: Conference Details, Security Research Institute, Edith Cowan University
Australian eHealth Informatics and Security Conference
No abstract provided.
Big Data In Healthcare: What Is It Used For?, Rebecca Hermon, Patricia A H Williams
Big Data In Healthcare: What Is It Used For?, Rebecca Hermon, Patricia A H Williams
Australian eHealth Informatics and Security Conference
Big data analytics is a growth area with the potential to provide useful insight in healthcare. Whilst many dimensions of big data still present issues in its use and adoption, such as managing the volume, variety, velocity, veracity, and value, the accuracy, integrity, and semantic interpretation are of greater concern in clinical application. However, such challenges have not deterred the use and exploration of big data as an evidence source in healthcare. This drives the need to investigate healthcare information to control and reduce the burgeoning cost of healthcare, as well as to seek evidence to improve patient outcomes. Whilst …
Avoiding Epic Fails: Software And Standards Directions To Increase Clinical Safety, Patricia A H Williams, Vincent B. Mccauley
Avoiding Epic Fails: Software And Standards Directions To Increase Clinical Safety, Patricia A H Williams, Vincent B. Mccauley
Australian eHealth Informatics and Security Conference
No abstract provided.
Managing Wireless Security Risks In Medical Services, Brian Cusack, Akar Kyaw
Managing Wireless Security Risks In Medical Services, Brian Cusack, Akar Kyaw
Australian eHealth Informatics and Security Conference
Medical systems are designed for a range of end users from different professional skill groups and people who carry the devices in and on their bodies. Open, accurate, and efficient communication is the priority for medical systems and consequently strong protection costs are traded against the utility benefits for open systems. In this paper we assess the vulnerabilities created by the professional and end user expectations, and theorise ways to mitigate wireless security vulnerabilities. The benefits of wireless medical services are great in terms of efficiencies, mobility, and information management. These benefits may be realised by treating the vulnerabilities and …
Detecting Camouflaged Applications On Mobile Application Markets, Mon Kywe Su, Yingjiu Li, Huijie Robert Deng, Jason Hong
Detecting Camouflaged Applications On Mobile Application Markets, Mon Kywe Su, Yingjiu Li, Huijie Robert Deng, Jason Hong
Research Collection School Of Computing and Information Systems
Application plagiarism or application cloning is an emerging threat in mobile application markets. It reduces profits of original developers and sometimes even harms the security and privacy of users. In this paper, we introduce a new concept, called camouflaged applications, where external features of mobile applications, such as icons, screenshots, application names or descriptions, are copied. We then propose a scalable detection framework, which can find these suspiciously similar camouflaged applications. To accomplish this, we apply text-based retrieval methods and content-based image retrieval methods in our framework. Our framework is implemented and tested with 30,625 Android applications from the official …
Android Or Ios For Better Privacy Protection?, Jin Han, Qiang Yan, Debin Gao, Jianying Zhou, Huijie Robert Deng
Android Or Ios For Better Privacy Protection?, Jin Han, Qiang Yan, Debin Gao, Jianying Zhou, Huijie Robert Deng
Research Collection School Of Computing and Information Systems
With the rapid growth of the mobile market, security of mobile platforms is receiving increasing attention from both research community as well as the public. In this paper, we make the first attempt to establish a baseline for security comparison between the two most popular mobile platforms. We investigate applications that run on both Android and iOS and examine the difference in the usage of their security sensitive APIs (SS-APIs). Our analysis over 2,600 applications shows that iOS applications consistently access more SS-APIs than their counterparts on Android. The additional privileges gained on iOS are often associated with accessing private …
Factors Impacting Information Security Noncompliance When Completing Job Tasks, Martha Nanette Harrell
Factors Impacting Information Security Noncompliance When Completing Job Tasks, Martha Nanette Harrell
CCAC Theses and Dissertations
Work systems are comprised of the technical and social systems that should harmoniously work together to ensure a successful attainment of organizational goals and objectives. Information security controls are often designed to protect the information system and seldom consider the work system design. Using a positivist case study, this research examines the user's perception of having to choose between completing job tasks or remaining compliant with information security controls. An understanding of this phenomenon can help mitigate the risk associated with an information system security user's choice. Most previous research fails to consider the work system perspective on this issue. …
Information System Security Commitment: A Study Of External Influences On Senior Management, Kevin Andrew Barton
Information System Security Commitment: A Study Of External Influences On Senior Management, Kevin Andrew Barton
CCAC Theses and Dissertations
This dissertation investigated how senior management is motivated to commit to information system security (ISS). Research shows senior management participation is critical to successful ISS, but has not explained how senior managers are motivated to participate in ISS. Information systems research shows pressures external to the organization have greater influence on senior managers than internal pressures. However, research has not fully examined how external pressures motivate senior management participation in ISS. This study addressed that gap by examining how external pressures motivate senior management participation in ISS through the lens of neo-institutional theory. The research design was survey research. Data …
Unsupervised Learning Trojan, Arturo Geigel
Unsupervised Learning Trojan, Arturo Geigel
CCAC Theses and Dissertations
This work presents a proof of concept of an Unsupervised Learning Trojan. The Unsupervised Learning Trojan presents new challenges over previous work on the Neural network Trojan, since the attacker does not control most of the environment. The current work will presented an analysis of how the attack can be successful by proposing new assumptions under which the attack can become a viable one. A general analysis of how the compromise can be theoretically supported is presented, providing enough background for practical implementation development. The analysis was carried out using 3 selected algorithms that can cover a wide variety of …
Ironfox: Securing The Web, Stephen Mcmurtry, William Johnson, Khadija Stewart (Advisor)
Ironfox: Securing The Web, Stephen Mcmurtry, William Johnson, Khadija Stewart (Advisor)
Annual Student Research Poster Session
No abstract provided.
Semantics-Aware Android Malware Classification Using Weighted Contextual Api Dependency Graphs, Mu Zhang, Yue Duan, Heng Yin, Zhiruo Zhao
Semantics-Aware Android Malware Classification Using Weighted Contextual Api Dependency Graphs, Mu Zhang, Yue Duan, Heng Yin, Zhiruo Zhao
Research Collection School Of Computing and Information Systems
The drastic increase of Android malware has led to a strong interest in developing methods to automate the malware analysis process. Existing automated Android malware detection and classification methods fall into two general categories: 1) signature-based and 2) machine learning-based. Signature-based approaches can be easily evaded by bytecode-level transformation attacks. Prior learning-based works extract features from application syntax, rather than program semantics, and are also subject to evasion. In this paper, we propose a novel semantic-based approach that classifies Android malware via dependency graphs. To battle transformation attacks, we extract a weighted contextual API dependency graph as program semantics to …
Stopwatch: A Cloud Architecture For Timing Channel Mitigation, Peng Li, Debin Gao, Michael K Reiter
Stopwatch: A Cloud Architecture For Timing Channel Mitigation, Peng Li, Debin Gao, Michael K Reiter
Research Collection School Of Computing and Information Systems
This article presents StopWatch, a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatch triplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses the timing of I/O events at a VM’s replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VMs. We detail the design and …
Web Application Vulnerability Prediction Using Hybrid Program Analysis And Machine Learning, Lwin Khin Shar, Lionel Briand, Hee Beng Kuan Tan
Web Application Vulnerability Prediction Using Hybrid Program Analysis And Machine Learning, Lwin Khin Shar, Lionel Briand, Hee Beng Kuan Tan
Research Collection School Of Computing and Information Systems
Due to limited time and resources, web software engineers need support in identifying vulnerable code. A practical approach to predicting vulnerable code would enable them to prioritize security auditing efforts. In this paper, we propose using a set of hybrid (staticþdynamic) code attributes that characterize input validation and input sanitization code patterns and are expected to be significant indicators of web application vulnerabilities. Because static and dynamic program analyses complement each other, both techniques are used to extract the proposed attributes in an accurate and scalable way. Current vulnerability prediction techniques rely on the availability of data labeled with vulnerability …
Workplace Surveillance, Tamara Kneese
Workplace Surveillance, Tamara Kneese
Media Studies
Employers have long devised techniques and used new technologies to surveil employees in order to increase efficiency, decrease theft, and otherwise assert power and control over subordinates. New and cheaper networked technologies make surveillance easier to implement, but what are the ramifications of widespread workplace surveillance?
Security Policies That Make Sense For Complex Systems: Comprehensible Formalism For The System Consumer, Rhonda R. Henning
Security Policies That Make Sense For Complex Systems: Comprehensible Formalism For The System Consumer, Rhonda R. Henning
CCAC Theses and Dissertations
Information Systems today rarely are contained within a single user workstation, server, or networked environment. Data can be transparently accessed from any location, and maintained across various network infrastructures. Cloud computing paradigms commoditize the hardware and software environments and allow an enterprise to lease computing resources by the hour, minute, or number of instances required to complete a processing task. An access control policy mediates access requests between authorized users of an information system and the system's resources. Access control policies are defined at any given level of abstraction, such as the file, directory, system, or network, and can be …
Ios Device Forensics, Lauren Drish
Ios Device Forensics, Lauren Drish
All Capstone Projects
Many people today have an iPhone, iPad or iPod. Not many would realize that valuable information is stored on these devices. When a crime occurs, an iOS Device could hold key information to help solve said crime that criminals are not aware are present on the device. This can include GPS information as well as application history on the device itself.
The project I wish to do and complete is to create a class where students can learn the about iOS Forensics. Student will be able to learn the basics of an iDevice, as well as how to work with …
Attribute-Based Signing Right Delegation, Weiwei Liu, Yi Mu, Guomin Yang
Attribute-Based Signing Right Delegation, Weiwei Liu, Yi Mu, Guomin Yang
Research Collection School Of Computing and Information Systems
Attribute-based signature and proxy signature are both very useful in many real-world applications. In this paper, we combine the special features of both signatures and propose an attribute-based proxy signature scheme, where the original signer, who possesses a set of attributes, can delegate his/her signing right to a designated proxy signer. By verifying the signature, a verifier can be convinced that the signature is generated by the proxy signer who has obtained the delegation from a legitimate signer whose attributes satisfy a predicate. However, the verifier cannot tell from the signature who is the original signer. We provide the formal …
Analyzing The Dangers Posed By Chrome Extensions, Lujo Bauer, Shaoying Cai, Limin Jia, Timothy Passaro, Yuan Tian
Analyzing The Dangers Posed By Chrome Extensions, Lujo Bauer, Shaoying Cai, Limin Jia, Timothy Passaro, Yuan Tian
Research Collection School Of Computing and Information Systems
A common characteristic of modern web browsers is that their functionality can be extended via third-party addons. In this paper we focus on Chrome extensions, to which the Chrome browser exports a rich API: extensions can potentially make network requests, access the local file system, get low-level information about running processes, etc. To guard against misuse, Chrome uses a permission system to curtail an extension's privileges. We demonstrate a series of attacks by which extensions can steal data, track user behavior, and collude to elevate their privileges. Although some attacks have previously been reported, we show that subtler versions can …
Lossy Trapdoor Relation And Its Applications To Lossy Encryption And Adaptive Trapdoor Relation, Haiyang Xue, Xianhui Lu, Bao Li, Yamin Liu
Lossy Trapdoor Relation And Its Applications To Lossy Encryption And Adaptive Trapdoor Relation, Haiyang Xue, Xianhui Lu, Bao Li, Yamin Liu
Research Collection School Of Computing and Information Systems
Peikert and Waters proposed the notion of lossy trapdoor function in STOC 2008. In this paper, we propose a relaxation of lossy trapdoor function, called lossy trapdoor relation. Unlike the lossy trapdoor function, lossy trapdoor relation does not require completely recovering the input but a public computable injective map of it. Interestingly, the lossy trapdoor relation maintains the application of lossy trapdoor function on the lossy encryption. Moreover, motivated by the construction of adaptive trapdoor relation proposed by Wee (Crypto 2010), we introduce all-but-one verifiable lossy trapdoor relation which is in fact a relaxation of all-but-one lossy trapdoor function. – …