Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (988)
- Social and Behavioral Sciences (930)
- Law (808)
- Computer Engineering (742)
- Computer Law (728)
-
- Legal Studies (638)
- Forensic Science and Technology (617)
- Electrical and Computer Engineering (552)
- Business (485)
- Databases and Information Systems (395)
- Management Information Systems (332)
- Artificial Intelligence and Robotics (289)
- Technology and Innovation (279)
- OS and Networks (257)
- Sociology (251)
- Other Computer Sciences (237)
- Public Affairs, Public Policy and Public Administration (227)
- Software Engineering (223)
- Medicine and Health Sciences (159)
- Cybersecurity (143)
- Systems Architecture (139)
- Theory and Algorithms (135)
- Digital Communications and Networking (134)
- Education (125)
- Communication (119)
- Defense and Security Studies (119)
- Social Media (89)
- Institution
-
- Singapore Management University (1102)
- Embry-Riddle Aeronautical University (768)
- Edith Cowan University (532)
- Kennesaw State University (300)
- Old Dominion University (256)
-
- Air Force Institute of Technology (181)
- San Jose State University (117)
- Bridgewater State University (73)
- Clark University (71)
- University of New Haven (65)
- United Arab Emirates University (64)
- University of Arkansas, Fayetteville (59)
- City University of New York (CUNY) (55)
- Dakota State University (49)
- California State University, San Bernardino (34)
- Nova Southeastern University (33)
- Maurer School of Law: Indiana University (32)
- University for Business and Technology in Kosovo (30)
- University of Central Florida (24)
- University of South Alabama (23)
- University of Dayton (22)
- Franklin University (21)
- LSU New Orleans (21)
- University of Nebraska at Omaha (20)
- Wayne State University (20)
- California Polytechnic State University, San Luis Obispo (18)
- University of Kentucky (18)
- Florida Institute of Technology (17)
- Louisiana State University (16)
- Portland State University (16)
- Keyword
-
- Cybersecurity (317)
- Security (246)
- Privacy (163)
- Computer security (101)
- Digital forensics (89)
-
- Information security (89)
- Blockchain (88)
- Machine learning (82)
- Authentication (71)
- Cryptography (71)
- Cloud computing (68)
- Encryption (65)
- Data privacy (62)
- [RSTDPub] (54)
- Cyber security (53)
- Access control (50)
- Data protection (47)
- Network security (45)
- Malware (41)
- Machine Learning (39)
- Android (38)
- Artificial intelligence (38)
- Computer networks--Security measures (38)
- Cybercrime (38)
- Internet of Things (36)
- Deep learning (34)
- Digital Forensics (34)
- Intrusion detection (33)
- MPA (33)
- Forensics (31)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (1051)
- Journal of Digital Forensics, Security and Law (536)
- Australian Information Security Management Conference (224)
- Theses and Dissertations (212)
- Annual ADFSL Conference on Digital Forensics, Security and Law (186)
-
- Journal of Cybersecurity Education, Research and Practice (171)
- Master's Projects (107)
- KSU Proceedings on Cybersecurity Education, Research and Practice (97)
- Cybersecurity Undergraduate Research Showcase (90)
- Research outputs 2022 to 2026 (84)
- International Journal of Cybersecurity Intelligence & Cybercrime (72)
- School of Professional Studies (71)
- Electrical & Computer Engineering and Computer Science Faculty Publications (58)
- Australian Digital Forensics Conference (50)
- Theses (45)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
- Computer Science Faculty Publications (40)
- Masters Theses & Doctoral Dissertations (34)
- CCAC Theses and Dissertations (33)
- Graduate Theses and Dissertations (33)
- Articles by Maurer Faculty (31)
- Publications (29)
- Electronic Theses and Dissertations (25)
- UBT International Conference (24)
- VMASC Publications (24)
- Electrical & Computer Engineering Faculty Publications (23)
- Open Educational Resources (23)
- Faculty Publications (22)
- LSU New Orleans Theses and Dissertations (21)
- Publication Type
Articles 2551 - 2580 of 4670
Full-Text Articles in Information Security
Stay Safe Online!, Jenny Blaine
Stay Safe Online!, Jenny Blaine
Innovate! Teaching with Technology Conference
Inform audience of potential online threats to their online security and reasons for that; empower audience to employ best practices to protect themselves during online activities.
Multiple Audiences
Encryption Backdoors: A Discussion Of Feasibility, Ethics, And The Future Of Cryptography, Jennifer A. Martin
Encryption Backdoors: A Discussion Of Feasibility, Ethics, And The Future Of Cryptography, Jennifer A. Martin
Honors Projects
In the age of technological advancement and the digitization of information, privacy seems to be all but an illusion. Encryption is supposed to be the white knight that keeps our information and communications safe from unwanted eyes, but how secure are the encryption algorithms that we use? Do we put too much trust in those that are charged with implementing our everyday encryption systems? This paper addresses the concept of backdoors in encryption: ways that encryption systems can be implemented so that the security can be bypassed by those that know about its existence. Many governments around the world are …
Efficient Large-Universe Multi-Authority Ciphertext-Policy Attribute-Based Encryption With White-Box Traceability, Kai Zhang, Hui Li, Jianfeng Ma, Ximeng Liu
Efficient Large-Universe Multi-Authority Ciphertext-Policy Attribute-Based Encryption With White-Box Traceability, Kai Zhang, Hui Li, Jianfeng Ma, Ximeng Liu
Research Collection School of Computing and Information Systems
Traceable multi-authority ciphertext-policy attribute-based encryption (CP-ABE) is a practical encryption method that can achieve user traceability and fine-grained access control simultaneously. However, existing traceable multi-authority CP-ABE schemes have two main limitations that prevent them from practical applications. First, these schemes only support small universe: the attributes must be fixed at system setup and the attribute space is restricted to polynomial size. Second, the schemes are either less expressive (the access policy is limited to “AND gates with wildcard”) or inefficient (the system is constructed in composite order bilinear groups). To address these limitations, we present a traceable large universe multi-authority …
Message-Layer Encryption In Ricochet, Liam B. Kirsh
Message-Layer Encryption In Ricochet, Liam B. Kirsh
Computer Science and Software Engineering
My intention for this project was to implement encryption and authentication on Ricochet's message layer. This provides two major benefits. The first is a higher level of encryption in the event that a flaw is found in the existing channel-layer encryption, or if increases in computing power make attacks on that encryption feasible. Tor is used by the military, journalists, law enforcement, researchers, and activists, whose communications may be interesting to state-level adversaries and criminal organizations with access to great amount of computing resources. Additionally, message-layer encryption would allow users to specify relay nodes that can temporarily store messages and …
Cca Secure Encryption Supporting Authorized Equality Test On Ciphertexts In Standard Model And Its Applications, Yujue Wang, Hwee Hwa Pang, Ngoc Hieu Tran, Robert H. Deng
Cca Secure Encryption Supporting Authorized Equality Test On Ciphertexts In Standard Model And Its Applications, Yujue Wang, Hwee Hwa Pang, Ngoc Hieu Tran, Robert H. Deng
Research Collection School Of Computing and Information Systems
We present an encryption scheme for authorized equality test on ciphertexts (SEET), which allows the data owner to authorize a tester to compare her ciphertexts without decrypting their values. The security of SEET is formally proved against three types of adversary, two of them for ciphertext confidentiality in the phases before and after authorization respectively, and the third for token privacy. To the best of our knowledge, our SEET construction is the first encryption scheme supporting equality test on ciphertexts that is proven secure against the three types of adversary in the standard model. Our SEET construction outperforms existing schemes …
Breathprint: Breathing Acoustics-Based User Authentication, Jagmohan Chauhan, Yining Hu, Suranga Sereviratne, Archan Misra, Aruna Sereviratne, Youngki Lee
Breathprint: Breathing Acoustics-Based User Authentication, Jagmohan Chauhan, Yining Hu, Suranga Sereviratne, Archan Misra, Aruna Sereviratne, Youngki Lee
Research Collection School Of Computing and Information Systems
We propose BreathPrint, a new behavioural biometric signature based on audio features derived from an individual's commonplace breathing gestures. Specifically, BreathPrint uses the audio signatures associated with the three individual gestures: sniff, normal, and deep breathing, which are sufficiently different across individuals. Using these three breathing gestures, we develop the processing pipeline that identifies users via the microphone sensor on smartphones and wearable devices. In BreathPrint, a user performs breathing gestures while holding the device very close to their nose. Using off-the-shelf hardware, we experimentally evaluate the BreathPrint prototype with 10 users, observed over seven days. We show that users …
Flexible Wildcard Searchable Encryption System, Yang Yang, Ximeng Liu, Robert H. Deng, Jian Weng
Flexible Wildcard Searchable Encryption System, Yang Yang, Ximeng Liu, Robert H. Deng, Jian Weng
Research Collection School Of Computing and Information Systems
Searchable encryption is an important technique for public cloud storage service to provide user data confidentiality protection and at the same time allow users performing keyword search over their encrypted data. Previous schemes only deal with exact or fuzzy keyword search to correct some spelling errors. In this paper, we propose a new wildcard searchable encryption system to support wildcard keyword queries which has several highly desirable features. First, our system allows multiple keywords search in which any queried keyword may contain zero, one or two wildcards, and a wildcard may appear in any position of a keyword and represent …
Cybercrime Deterrence And International Legislation: Evidence From Distributed Denial Of Service Attacks, Kai-Lung Hui, Seung Hyun Kim, Qiu-Hong Wang
Cybercrime Deterrence And International Legislation: Evidence From Distributed Denial Of Service Attacks, Kai-Lung Hui, Seung Hyun Kim, Qiu-Hong Wang
Research Collection School Of Computing and Information Systems
In this paper, we estimate the impact of enforcing the Convention on Cybercrime (COC) on deterring distributed denial of service (DDOS) attacks. Our data set comprises a sample of real, random spoof-source DDOS attacks recorded in 106 countries in 177 days in the period 2004-2008. We find that enforcing the COC decreases DDOS attacks by at least 11.8 percent, but a similar deterrence effect does not exist if the enforcing countries make a reservation on international cooperation. We also find evidence of network and displacement effects in COC enforcement. Our findings imply attackers in cyberspace are rational, motivated by economic …
Understanding Android App Piggybacking: A Systematic Study Of Malicious Code Grafting, Li Li, Daoyuan Li, Tegawende F. Bissyande, Jacques Klein, Yves Le Traon, David Lo, Lorenzo Cavallaro
Understanding Android App Piggybacking: A Systematic Study Of Malicious Code Grafting, Li Li, Daoyuan Li, Tegawende F. Bissyande, Jacques Klein, Yves Le Traon, David Lo, Lorenzo Cavallaro
Research Collection School Of Computing and Information Systems
The Android packaging model offers ample opportunities for malware writers to piggyback malicious code in popular apps, which can then be easily spread to a large user base. Although recent research has produced approaches and tools to identify piggybacked apps, the literature lacks a comprehensive investigation into such phenomenon. We fill this gap by: 1) systematically building a large set of piggybacked and benign apps pairs, which we release to the community; 2) empirically studying the characteristics of malicious piggybacked apps in comparison with their benign counterparts; and 3) providing insights on piggybacking processes. Among several findings providing insights analysis …
Employing Smartwatch For Enhanced Password Authentication, Bing Chang, Ximing Liu, Yingjiu Li, Pingjian Wang, Wen-Tao Zhu, Zhan Wang
Employing Smartwatch For Enhanced Password Authentication, Bing Chang, Ximing Liu, Yingjiu Li, Pingjian Wang, Wen-Tao Zhu, Zhan Wang
Research Collection School Of Computing and Information Systems
This paper presents an enhanced password authentication scheme by systematically exploiting the motion sensors in a smartwatch. We extract unique features from the sensor data when a smartwatch bearer types his/her password (or PIN), and train certain machine learning classifiers using these features. We then implement smartwatch-aided password authentication using the classifiers. Our scheme is user-friendly since it does not require users to perform any additional actions when typing passwords or PINs other than wearing smartwatches. We conduct a user study involving 51 participants on the developed prototype so as to evaluate its feasibility and performance. Experimental results show that …
Adding Differential Privacy In An Open Board Discussion Board System, Pragya Rana
Adding Differential Privacy In An Open Board Discussion Board System, Pragya Rana
Master's Projects
This project implements a privacy system for statistics generated by the Yioop search and discussion board system. Statistical data for such a system consists of various counts, sums, and averages that might be displayed for groups, threads, etc. When statistical data is made publicly available, there is no guarantee of preserving the privacy of an individual. Ideally, any data extracted should not reveal any sensitive information about an individual. In order to help achieve this, we implemented a Differential Privacy mechanism for Yioop. Differential privacy preserves privacy up to some controllable parameters of the number of items or individuals being …
Dynamic Information Flow Analysis In Ruby, Vigneshwari Chandrasekaran
Dynamic Information Flow Analysis In Ruby, Vigneshwari Chandrasekaran
Master's Projects
With the rapid increase in usage of the internet and online applications, there is a huge demand for applications to handle data privacy and integrity. Applications are already complex with business logic; adding the data safety logic would make them more complicated. The more complex the code becomes, the more possibilities it opens for security-critical bugs. To solve this conundrum, we can push this data safety handling feature to the language level rather than the application level. With a secure language, developers can write their application without having to worry about data security.
This project introduces dynamic information flow analysis …
Black Box Analysis Of Android Malware Detectors, Guruswamy Nellaivadivelu
Black Box Analysis Of Android Malware Detectors, Guruswamy Nellaivadivelu
Master's Projects
Code obfuscation can make it challenging to detect malware in Android devices. Malware writers obfuscate the code of their programs by employing various techniques that attempt to hide the true purpose of the program. Malware detectors can use a number of features to classify a program as a malware. If the malware detector uses a feature that is obfuscated, then the malware detector will likely fail to classify the malware as malicious software. In this research, we obfuscate selected features of known malware and determine whether the malware can still be detected by a given detector. Using this approach, we …
Malware Scores Based On Image Processing, Vikash Raja Samuel Selvin
Malware Scores Based On Image Processing, Vikash Raja Samuel Selvin
Master's Projects
Malware analysis can be based on static or dynamic analysis. Static analysis includes signature-based detection and other forms of analysis rely only on features that can be extracted without code execution or emulation. In contrast, dynamic analysis depends on features extracted at runtime (or via emulation) such as API calls, patterns of memory access, and so on. Dynamic analysis can be more informative and is generally more robust, but static analysis is typically more efficient. In this research, we implement, test, and analyze malware scores based on image processing. Previous work has shown that useful malware scores can be obtained …
Masquerade Detection On Mobile Devices, Swathi Nambiar Kadala Manikoth
Masquerade Detection On Mobile Devices, Swathi Nambiar Kadala Manikoth
Master's Projects
A masquerade is an attack where the attacker avoids detection by impersonating an authorized user of a system. In this research we consider the problem of masquerade detection on mobile devices. Our goal is to improve on previous work by considering more features and a wide variety of machine learning techniques. Our approach consists of verifying the authenticity of users based on individual features and combinations of features for all users to determine which features contribute the most to masquerade detection. Also, we determine which of the two approaches - the combination of features or using individual features has performed …
Transcriptase–Light: A Polymorphic Virus Construction Kit, Saurabh Borwankar
Transcriptase–Light: A Polymorphic Virus Construction Kit, Saurabh Borwankar
Master's Projects
Many websites use JavaScript to display dynamic and interactive content. Hence, attackers are developing JavaScript–based malware. In this paper, we focus on Transcriptase JavaScript malware.
The high–level and dynamic nature of the JavaScript language helps malware writers to create polymorphic and metamorphic malware using obfuscation techniques. These types of malware change their internal structure on each infection, making them difficult to detect with traditional methods. These types of malware can be detected using machine learning methods.
This project creates Transcriptase–Light, a new polymorphic construction kit. We perform an experiment with the Transcriptase–Light against a hidden Markov model. Our experiment shows …
Policy-Agnostic Programming On The Client-Side, Kushal Palesha
Policy-Agnostic Programming On The Client-Side, Kushal Palesha
Master's Projects
Browser security has become a major concern especially due to web pages becoming more complex. These web applications handle a lot of information, including sensitive data that may be vulnerable to attacks like data exfiltration, cross-site scripting (XSS), etc. Most modern browsers have security mechanisms in place to prevent such attacks but they still fall short in preventing more advanced attacks like evolved variants of data exfiltration. Moreover, there is no standard that is followed to implement security into the browser.
A lot of research has been done in the field of information flow security that could prove to be …
Implementing Dynamic Coarse & Fine Grained Taint Analysis For Rhino Javascript, Tejas Saoji
Implementing Dynamic Coarse & Fine Grained Taint Analysis For Rhino Javascript, Tejas Saoji
Master's Projects
Web application systems today are at great risk from attackers. They use methods like cross-site scripting, SQL injection, and format string attacks to exploit vulnerabilities in an application. Standard techniques like static analysis, code audits seem to be inadequate in successfully combating attacks like these. Both the techniques point out the vulnerabilities before an application is run. However, static analysis may result in a higher rate of false positives, and code audits are time-consuming and costly. Hence, there is a need for reliable detection mechanisms.
Dynamic taint analysis offers an alternate solution — it marks the incoming data from the …
Image Spam Detection, Aneri Chavda
Image Spam Detection, Aneri Chavda
Master's Projects
Email is one of the most common forms of digital communication. Spam can be de ned as unsolicited bulk email, while image spam includes spam text embedded inside images. Image spam is used by spammers so as to evade text-based spam lters and hence it poses a threat to email based communication. In this research, we analyze image spam detection methods based on various combinations of image processing and machine learning techniques.
Analysis Of Periodicity In Botnets, Prathiba Nagarajan
Analysis Of Periodicity In Botnets, Prathiba Nagarajan
Master's Projects
A botnet consists of a network of infected computers which are controlled re- motely via a command and control (C&C) server. A typical botnet requires frequent communication between the C&C server and the infected nodes. Previous approaches to detecting botnets have employed various machine learning techniques, based on features extracted from network tra c. In this research, we carefully analyze the pe- riodicity of tra c as a means for detecting a variety of botnets by applying machine learning to publicly available datasets.
Malware Analysis And Privacy Policy Enforcement Techniques For Android Applications, Aisha Ibrahim Ali-Gombe
Malware Analysis And Privacy Policy Enforcement Techniques For Android Applications, Aisha Ibrahim Ali-Gombe
LSU New Orleans Theses and Dissertations
The rapid increase in mobile malware and deployment of over-privileged applications over the years has been of great concern to the security community. Encroaching on user’s privacy, mobile applications (apps) increasingly exploit various sensitive data on mobile devices. The information gathered by these applications is sufficient to uniquely and accurately profile users and can cause tremendous personal and financial damage.
On Android specifically, the security and privacy holes in the operating system and framework code has created a whole new dynamic for malware and privacy exploitation. This research work seeks to develop novel analysis techniques that monitor Android applications for …
Towards Real-Time Volatile Memory Forensics: Frameworks, Methods, And Analysis, Joseph T. Sylve
Towards Real-Time Volatile Memory Forensics: Frameworks, Methods, And Analysis, Joseph T. Sylve
LSU New Orleans Theses and Dissertations
Memory forensics (or memory analysis) is a relatively new approach to digital forensics that deals exclusively with the acquisition and analysis of volatile system memory. Because each function performed by an operating system must utilize system memory, analysis of this memory can often lead to a treasure trove of useful information for forensic analysts and incident responders. Today’s forensic investigators are often subject to large case backlogs, and incident responders must be able to quickly identify the source and cause of security breaches. In both these cases time is a critical factor. Unfortunately, today’s memory analysis tools can take many …
Development Of Peer Instruction Material For A Cybersecurity Curriculum, William Johnson
Development Of Peer Instruction Material For A Cybersecurity Curriculum, William Johnson
LSU New Orleans Theses and Dissertations
Cybersecurity classes focus on building practical skills alongside the development of the open mindset that is essential to tackle the dynamic cybersecurity landscape. Unfortunately, traditional lecture-style teaching is insufficient for this task. Peer instruction is a non-traditional, active learning approach that has proven to be effective in computer science courses. The challenge in adopting peer instruction is the development of conceptual questions. This thesis presents a methodology for developing peer instruction questions for cybersecurity courses, consisting of four stages: concept identification, concept trigger, question presentation, and development. The thesis analyzes 279 questions developed over two years for three cybersecurity courses: …
Downstream Competence Challenges And Legal/Ethical Risks In Digital Forensics, Michael M. Losavio, Antonio Losavio
Downstream Competence Challenges And Legal/Ethical Risks In Digital Forensics, Michael M. Losavio, Antonio Losavio
Annual ADFSL Conference on Digital Forensics, Security and Law
Forensic practice is an inherently human-mediated system, from processing and collection of evidence to presentation and judgment. This requires attention to human factors and risks which can lead to incorrect judgments and unjust punishments.
For digital forensics, such challenges are magnified by the relative newness of the discipline and the use of electronic evidence in forensic proceedings. Traditional legal protections, rules of procedure and ethics rules mitigate these challenges. Application of those traditions better ensures forensic findings are reliable. This has significant consequences where findings may impact a person's liberty or property, a person's life or even the political direction …
Detecting Deception In Asynchronous Text, Fletcher Glancy
Detecting Deception In Asynchronous Text, Fletcher Glancy
Annual ADFSL Conference on Digital Forensics, Security and Law
Glancy and Yadav (2010) developed a computational fraud detection model (CFDM) that successfully detected financial reporting fraud in the text of the management’s discussion and analysis (MDA) portion of annual filings with the United States Securities and Exchange Commission (SEC). This work extends the use of the CFDM to additional genres, demonstrates the generalizability of the CFDM and the use of text mining for quantitatively detecting deception in asynchronous text. It also demonstrates that writers committing fraud use words differently from truth tellers.
Understanding Deleted File Decay On Removable Media Using Differential Analysis, James H. Jones Jr, Anurag Srivastava, Josh Mosier, Connor Anderson, Seth Buenafe
Understanding Deleted File Decay On Removable Media Using Differential Analysis, James H. Jones Jr, Anurag Srivastava, Josh Mosier, Connor Anderson, Seth Buenafe
Annual ADFSL Conference on Digital Forensics, Security and Law
Digital content created by picture recording devices is often stored internally on the source device, on either embedded or removable media. Such storage media is typically limited in capacity and meant primarily for interim storage of the most recent image files, and these devices are frequently configured to delete older files as necessary to make room for new files. When investigations involve such devices and media, it is sometimes these older deleted files that would be of interest. It is an established fact that deleted file content may persist in part or in its entirety after deletion, and identifying the …
Development Of A Professional Code Of Ethics In Digital Forensics, Kathryn C. Seigfried-Spellar, Marcus Rogers, Danielle M. Crimmins 2184089
Development Of A Professional Code Of Ethics In Digital Forensics, Kathryn C. Seigfried-Spellar, Marcus Rogers, Danielle M. Crimmins 2184089
Annual ADFSL Conference on Digital Forensics, Security and Law
Academics, government officials, and practitioners suggest the field of digital forensics is in need of a professional code of ethics. In response to this need, the authors developed and proposed a professional code of ethics in digital forensics. The current paper will discuss the process of developing the professional code of ethics, which included four sets of revisions based on feedback and suggestions provided by members of the digital forensic community. The final version of the Professional Code of Ethics in Digital Forensics includes eight statements, and we hope this is a step toward unifying the field of digital forensics …
Fast Filtering Of Known Png Files Using Early File Features, Sean Mckeown, Gordon Russell, Petra Leimich
Fast Filtering Of Known Png Files Using Early File Features, Sean Mckeown, Gordon Russell, Petra Leimich
Annual ADFSL Conference on Digital Forensics, Security and Law
A common task in digital forensics investigations is to identify known contraband images. This is typically achieved by calculating a cryptographic digest, using hashing algorithms such as SHA256, for each image on a given media, comparing individual digests with a database of known contraband. However, the large capacities of modern storage media, and increased time pressure on forensics examiners, necessitates that more efficient processing mechanisms be developed. This work describes a technique for creating signatures for images of the PNG format which only requires a tiny fraction of the file to effectively distinguish between a large number of images. Highly …
Detect Kernel-Mode Rootkits Via Real Time Logging & Controlling Memory Access, Satoshi Tanda, Irvin Homem, Igor Korkin
Detect Kernel-Mode Rootkits Via Real Time Logging & Controlling Memory Access, Satoshi Tanda, Irvin Homem, Igor Korkin
Annual ADFSL Conference on Digital Forensics, Security and Law
Modern malware and spyware platforms attack existing antivirus solutions and even Microsoft PatchGuard. To protect users and business systems new technologies developed by Intel and AMD CPUs may be applied. To deal with the new malware we propose monitoring and controlling access to the memory in real time using Intel VT-x with EPT. We have checked this concept by developing MemoryMonRWX, which is a bare-metal hypervisor. MemoryMonRWX is able to track and trap all types of memory access: read, write, and execute. MemoryMonRWX also has the following competitive advantages: fine-grained analysis, support of multi-core CPUs and 64-bit Windows 10. MemoryMonRWX …
Harnessing Predictive Models For Assisting Network Forensic Investigations Of Dns Tunnels, Irvin Homem, Panagiotis Papapetrou
Harnessing Predictive Models For Assisting Network Forensic Investigations Of Dns Tunnels, Irvin Homem, Panagiotis Papapetrou
Annual ADFSL Conference on Digital Forensics, Security and Law
In recent times, DNS tunneling techniques have been used for malicious purposes, however network security mechanisms struggle to detect them. Network forensic analysis has been proven effective, but is slow and effort intensive as Network Forensics Analysis Tools struggle to deal with undocumented or new network tunneling techniques. In this paper, we present a machine learning approach, based on feature subsets of network traffic evidence, to aid forensic analysis through automating the inference of protocols carried within DNS tunneling techniques. We explore four network protocols, namely, HTTP, HTTPS, FTP, and POP3. Three features are extracted from the DNS tunneled traffic: …