Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Discipline
Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 4621 - 4650 of 4677

Full-Text Articles in Information Security

Electronic Questionnaire, Lip Yee Por Jan 2001

Electronic Questionnaire, Lip Yee Por

Student Works (2000-2009)

This project aims to develop an E-Questionnaire for users through the web. Besides that, it will create awareness among users on the proper way of using password and more. E-Questionnaire System provides users information for example information about password usage. Moreover, this system provides an example for users as a guideline to answer questionnaire on web. Those questions inside EQuestionnaire's questionnaire are in both open ended and dosed format. Users can answer in Malay and English languages. E-Questionnaire does provide online submitting facility. After accumulating, reports can be generated by users. This application will be developed using the prototype model. …


Legal Deposit Of Electronic Publications : Perpustakaan Negara Malaysia's Experience, Shahrozat Ibrahim Jan 2001

Legal Deposit Of Electronic Publications : Perpustakaan Negara Malaysia's Experience, Shahrozat Ibrahim

Student Works (2000-2009)

The main purpose of this study is to analyse the statistical data of non-print/ electronic publications received and registered by the National Depository Centre, Perpustakaan Negara Malaysia since the enforcement of the Deposit of Library Material Act, 1986. Statistical data of non-print/electronic publications received from the years 1988-2000 were obtained from the National Depository Centre, Perpustakaan Negara Malaysia. The study revealed that out of the 7,926 titles of non-print publications received and registered from the year 1988-2000, only 165 titles (2.08%) are electronic publications, of which CD-ROMs constitute 1.87%, while diskettes and computer software constitute 0.19% and 0.03% respectively. The …


E-Mail Filter With Attachment Scanning Prototype, Losini Goval Hema Jan 2001

E-Mail Filter With Attachment Scanning Prototype, Losini Goval Hema

Student Works (2000-2009)

The E-mail Filter is a mail client that retrieves mails from the Ms Outlook Express, which retrieves mails from POP3 server and categorizes them into different a category that has different level of priorities. Attachments in the incoming mails are scanned and sent to respective folders. These attachments will be stored in the personal computer for easy reference. Meanwhile, the automatic response system automatically replies the mails classified in the Appointments category using automatic response, which runs even when the e-mails are closed. The E-mail Filter with Attachment Scanning Prototype is a stand-alone system. It has a user-friendly concept and …


Working For Excellence In The E-Conomy: 2nd International We-B Conference, Sue Stoney (Ed.) Jan 2001

Working For Excellence In The E-Conomy: 2nd International We-B Conference, Sue Stoney (Ed.)

Research outputs pre 2011

Welcome to Perth, Western Australia, and to the 2nd International We-B Conference 2001 "working for excellence in the e-conomy" hosted by the We-B Centre, School of Management Information Systems at Edith Cowan University.

This is an international conference for academics and industry specialists in e-business, e-government and related fields. The conference has drawn participants from national and international organisations.

All submitted papers were subjected to an anonymous peer review process managed by the Conference Committee.


Mpls Vpn Simulation Using Mp-Ibgp, Tan Fong Ang Jan 2001

Mpls Vpn Simulation Using Mp-Ibgp, Tan Fong Ang

Student Works (2000-2009)

As Internet traffic continues to increase, companies are demanding greater speeds and better services to disseminate information to their customers, partners and employees. In order to provide reliable services and to support a variety of secure communications among a wide range of locations, Multiprotocol Label Switching Virtual Private Network (MPLS VPN) has been introduced. MPLS is an emerging technology that aims to address many of the existing issues associated with packet forwarding in today's internetworking environment. Whereas, VPN provides secure private connections through public infrastructure amongst multiple locations. MPLS­ based VPN provides isolation. security, simplified routing, easier provisioning as well …


An Efficient And Practical Scheme For Privacy Protection In E-Commerce Of Digital Goods, Feng Bao, Robert H. Deng, Peirong Feng Dec 2000

An Efficient And Practical Scheme For Privacy Protection In E-Commerce Of Digital Goods, Feng Bao, Robert H. Deng, Peirong Feng

Research Collection School Of Computing and Information Systems

It is commonly acknowledged that customers’ privacy in electronic commerce should be well protected. The solutions may come not only from the ethics education and legislation, but also from cryptographic technologies. In this paper we propose and analyze a privacy protection scheme for e-commerce of digital goods. The scheme takes cryptography as its technical means to realize privacy protection for online customers. It is efficient in both computational cost and communication cost. It is very practical for real e-commerce systems compared with previous solutions. The cryptographic technique presented in this paper is rather simple. But the scheme has great application …


The Cracker Patch Choice: An Analysis Of Post Hoc Security Techniques, Crispin Cowan, Heather Hinton, Calton Pu, Jonathan Walpole Oct 2000

The Cracker Patch Choice: An Analysis Of Post Hoc Security Techniques, Crispin Cowan, Heather Hinton, Calton Pu, Jonathan Walpole

Computer Science Faculty Publications and Presentations

It has long been known that security is easiest to achieve when it is designed in from the start. Unfortunately, it has also become evident that systems built with security as a priority are rarely selected for wide spread deployment, because most consumers choose features, convenience, and performance over security. Thus security officers are often denied the option of choosing a truly secure solution, and instead must choose among a variety of post hoc security adaptations. We classify security enhancing methods, and compare and contrast these methods in terms of their effectiveness vs. cost of deployment. Our analysis provides practitioners …


Cryptanalysis Of The M-Permutation Protection Schemes, Hongjun Wu, Feng Bao, Dingfeng Ye, Robert H. Deng Jul 2000

Cryptanalysis Of The M-Permutation Protection Schemes, Hongjun Wu, Feng Bao, Dingfeng Ye, Robert H. Deng

Research Collection School Of Computing and Information Systems

Anderson and Kuhn have proposed the EEPROM modification attack to recover the secret key stored in the EEPROM. At ACISP ’98, Fung and Gray proposed an m-permutation protection scheme against the EEPROM modification attack. At ACISP ’99, Fung and Gray pointed out that in their original scheme, a secret key with too small or too large Hamming weight could be recovered easily. Then they proposed a revised m- permutation protection scheme and claimed that their revised scheme does not leak any information of the secret key. In this paper, we break completely both the original and the revised …


Multicast Internet Protocol, X. K. Wang, Robert H. Deng, Feng Bao Jun 2000

Multicast Internet Protocol, X. K. Wang, Robert H. Deng, Feng Bao

Research Collection School Of Computing and Information Systems

In this paper, we first review the existing IPv4 based multicast protocols and identify their shortcomings. We then proposed a new multicast protocol, called Multicast Internet Protocol (MIP), which is both scalable and flexible. The design principle of MIP is fundamentally different from the existing IPv4 based multicast protocols. The issues related to MIP routing and implementations are also studied in this paper.


On The Validity Of Digital Signatures, Jianying Zhou, Robert H. Deng Apr 2000

On The Validity Of Digital Signatures, Jianying Zhou, Robert H. Deng

Research Collection School Of Computing and Information Systems

An important feature of digital signatures is to serve as non-repudiation evidence. To be eligible as non-repudiation evidence, a digital signature on an electronic document should remain valid until its expiry date which is specified by some non-repudiation policy. As signature keys may be compromised and the validity of signatures may become questionable, additional security mechanisms need to be imposed on digital signatures. This paper examines the mechanisms for maintaining the validity of digital signatures, and provides a guideline on the use of these mechanisms in various context of applications.


A Distributed Agent Architecture For A Computer Virus Immune System, Paul K. Harmer Mar 2000

A Distributed Agent Architecture For A Computer Virus Immune System, Paul K. Harmer

Theses and Dissertations

Information superiority is identified as an Air Force core competency and is recognized as a key enabler for the success of future missions. Information protection and information assurance are vital components required for achieving superiority in the Infosphere, but these goals are threatened by the exponential birth rate of new computer viruses. The increased global interconnectivity that is empowering advanced information systems is also increasing the spread of malicious code and current anti-virus solutions are quickly becoming overwhelmed by the burden of capturing and classifying new viral stains. To overcome this problem, a distributed computer virus immune system (CVIS) based …


Human Fallacies And Personnel Security: James Deutch And Wen Ho Lee, Ibpp Editor Feb 2000

Human Fallacies And Personnel Security: James Deutch And Wen Ho Lee, Ibpp Editor

International Bulletin of Political Psychology

This article describes psychological phenomena that can easily subvert personnel security standards in government, the military, and business.


System Login Authentication Using Voice Recognition And Other Ai Methods, Azizul Hasan Zati Hakim Jan 2000

System Login Authentication Using Voice Recognition And Other Ai Methods, Azizul Hasan Zati Hakim

Student Works (2000-2009)

As computer becomes a commodity in work places and households appliances used by all - be it male or female young or old - the issue of security and privacy are increasing from day to day. Today, every user wishes for a better way to protect sensitive data. For all the talk about beefing up system security, the most effective way to breach a user's personal files and applications is to guess his or her password. That's because in the interest of easy recall, familiar terms are most preferred by users in general when it come too remembering a password. …


Packet Sniffer & Analyzer, Khoon Kok Ong Jan 2000

Packet Sniffer & Analyzer, Khoon Kok Ong

Student Works (2000-2009)

The communication of network is a complex process which cannot be seen by human beings. Even a computer that sit on a network can only knows the conversation within itself and others computer it talk to but not others computers· conversation that it didn't take part. Furthermore, the communication in network can be viewed as traffic which always triggers a lot of unsolved problems for computers to "talk. Therefore, to solve the problems we need to exactly know what really happened inside the network traffic. A variety of sniffing tools are invented for these purpose. All of these tools have …


Security In Distributed Systems - A Framework For Different Application Types, Ingo Stengel Jan 2000

Security In Distributed Systems - A Framework For Different Application Types, Ingo Stengel

Theses

Security is a factor which decides upon the applicability of distributed applications. Therefore this thesis deals with security in distributed systems. The complexity of the existing distributed technologies makes it necessary to reduce the number of distributed technologies considered in this thesis, i.e. concentrating on: Java, Mobile Agents and CORBA, where only Java-based mobile agents will be considered.

After a short review of basic security principles including firewalls, existing security problems in the above mentioned distributed technologies are analysed. Additional generic problems in distributed systems are outlined.

Solutions are referring to two different areas: those regarding security problems with firewalls …


Some Remarks On Fair Exchange Protocol, Jianying Zhou, Robert H. Deng, Feng Bao Jan 2000

Some Remarks On Fair Exchange Protocol, Jianying Zhou, Robert H. Deng, Feng Bao

Research Collection School Of Computing and Information Systems

Fair exchange turns out to be an increasingly important topic due to the rapid growth of electronic commerce. An exchange is deemed to be fair if at the end of exchange, either each party receives the expected item or neither party receives any useful information about the other’s item. Several protocols for fair exchange have been proposed in recent years. In this paper, we first examine a newly published fair exchange protocol and point out its flaws and weaknesses. We then put forward a more efficient and secure protocol and give an informal analysis.


Enhanced Password-Based Authentication Protocol, Chee Kiam Lee Jan 2000

Enhanced Password-Based Authentication Protocol, Chee Kiam Lee

Student Works (2000-2009)

This dissertation introduces Enhanced Password-Based Authentication Protocol (E­PAP) System. E-PAP System combines asymmetric (public-key) and symmetric (secret-key) cryptography that allow two parties sharing a small shared secret to provide authentication service, exchange confidential and authenticated information over an insecure network like lntemet. E-PAP System also provides authentication service by using somelhing you know concept. It has some advantages over biometric which uses something you are concept and smancard that uses something you have concept, as it is free of equipment's physical limitations, accuracy and cost problem as well as other constraints. The core for E-PAP System is FreeSPEKE SDK, a …


Disaster Recovery Planning : Local And Remote Data Backup System, Chin Seng Low Jan 2000

Disaster Recovery Planning : Local And Remote Data Backup System, Chin Seng Low

Student Works (2000-2009)

This dissertation studies about the disaster recovery planning focusing on data backup and which there is a data recovery capability in the event of a sudden, severe and unplanned disruption in an organization with network computing environment. The planning must ensure continuity of all the critical data and functions with minimum disruption and recover quickly during such calamity. The elements of a comprehensive and complete disaster recovery planning must include risk analysis, business impact analysis in order to recommend a suitable disaster recovery strategy. Hence, Local and Remote Data Backup System is the designed strategy based on the literature review …


Network Security Versus Network Connectivity: A Framework For Addressing The Issues Facing The Air Force Medical Community, Franklin E. Cunningham Jr. Dec 1999

Network Security Versus Network Connectivity: A Framework For Addressing The Issues Facing The Air Force Medical Community, Franklin E. Cunningham Jr.

Theses and Dissertations

The Air Force has instituted Barrier Reef to protect its networks. The Air Force medical community operates network connections that are incompatible with Barrier Reef. To overcome this problem, OASD(HA) directed the Tri-Service Management Program Office (TIMPO) to develop an architecture that protects all military health systems and allows them to link with all three services and outside partners. This research studied the underlying networking issues and formed a framework based on data from network experts from the Air Force's medical centers and their base network organizations. The findings were compared TIMPO and a composite framework was developed that more …


Information System Incidents: The Development Of A Damage Assessment Model, Mark D. Horony Dec 1999

Information System Incidents: The Development Of A Damage Assessment Model, Mark D. Horony

Theses and Dissertations

Information system (IS) incidents are on the rise. With low manning and undertrained information security specialists it is difficult for organizations to stop IS incidents from occurring. Once an incident has occurred it is the IS manager's responsibility to ensure that a full and accurate damage assessment has been accomplished. However, most IS managers lack the necessary tools to assess the damage from an incident. This exploratory thesis developed an IS incident damage assessment model (DAM) that can be part of the IS manager's tool kit. During the development of the model, it became apparent that the model was supported …


An Interview With David Brin, Switch Staffs Apr 1999

An Interview With David Brin, Switch Staffs

SWITCH

This is an interview with David Brin, a science fiction author, and the Switch staff. They discuss some topics of Brin’s book, "The Transparent Society". The main hypothesis of this book is reciprocal surveillance for accountability and decentralization of power. Brin discusses his thoughts on privacy, such as real privacy, illusory privacy, and a third kind of privacy. He goes on to connect surveillance with power and the government. He continues with how people react to the advances of technology and how they learn from past generations.


Trends. An Encryption Paradox: Cracking The Groupe Speciale Mobile Standard (Gsm), Ibpp Editor Apr 1998

Trends. An Encryption Paradox: Cracking The Groupe Speciale Mobile Standard (Gsm), Ibpp Editor

International Bulletin of Political Psychology

The author discusses the vulnerability of encryption methods used with today's modern technology.


Trends. Injustice Through Justice Within The Ins And The Fbi: Fertile Territory For Information, Ibpp Editor Mar 1998

Trends. Injustice Through Justice Within The Ins And The Fbi: Fertile Territory For Information, Ibpp Editor

International Bulletin of Political Psychology

The author discusses the quest for justice, in which policymakers, legislators, and those who seek to influence them sometimes seek to effect mandatory sequences of adjudicative procedure upon allegations of misbehavior.


A Signcryption Scheme With Signature Directly Verifiable By Public Key, Feng Bao, Robert H. Deng Feb 1998

A Signcryption Scheme With Signature Directly Verifiable By Public Key, Feng Bao, Robert H. Deng

Research Collection School Of Computing and Information Systems

Signcryption, first proposed by Zheng, is a cryptographic primitive which combines both the functions of digital signature and public key encryption in a logical single step, and with a computational cost significantly lower than that needed by the traditional signature-then-encryption approach. In Zheng's scheme, the signature verification can be done either by the recipient directly (using his private key) or by engaging a zero-knowledge interative protocol with a third party, without disclosing recipient's private key. In this note, we modify Zheng's scheme so that the recipient's private key is no longer needed in signature verification. The computational cost of the …


Stackguard: Automatic Adaptive Detection And Prevention Of Buffer-Overflow Attacks, Crispin Cowan, Calton Pu, David Maier, Heather Hinton, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, Qian Zhang Jan 1998

Stackguard: Automatic Adaptive Detection And Prevention Of Buffer-Overflow Attacks, Crispin Cowan, Calton Pu, David Maier, Heather Hinton, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, Qian Zhang

Computer Science Faculty Publications and Presentations

This paper presents a systematic solution to the persistent problem of buffer overflow attacks. Buffer overflow attacks gained notoriety in 1988 as part of the Morris Worm incident on the Internet. While it is fairly simple to fix individual buffer overflow vulnerabilities, buffer overflow attacks continue to this day. Hundreds of attacks have been discovered, and while most of the obvious vulnerabilities have now been patched, more sophisticated buffer overflow attacks continue to emerge.

We describe StackGuard: a simple compiler technique that virtually eliminates buffer overflow vulnerabilities with only modest performance penalties. Privileged programs that are recompiled with the StackGuard …


Network Security: An Evaluation Of Security Policies And Firewall Implementations, Melanie L. Abbas Jan 1998

Network Security: An Evaluation Of Security Policies And Firewall Implementations, Melanie L. Abbas

Dissertations and Theses @ UNI

This paper begins focusing on network security issues. The areas of physical security, access security, and connection security are explored. Connection security provides the biggest need for improvement in the entire security field. This type of security is managed best with firewall implementations. Various firewall models are discussed.

Software evaluations were performed on three different commercial Internet security tools. The software was compared on the basis of ease of installation, functionality, level of security provided, and output available. In summary, the value of the firewall is dependent on the need to implement a firewall in an organization.

However, a security …


A Model For Determining Information To Be Captured Regarding Unauthorized Computer Entry Of An Air Force Computer System, Leslie F. Himebrook Dec 1997

A Model For Determining Information To Be Captured Regarding Unauthorized Computer Entry Of An Air Force Computer System, Leslie F. Himebrook

Theses and Dissertations

This thesis presents a model of information to capture regarding unauthorized computer systems access attempts. This model takes a management focus, and incorporates the technical focus, intelligence focus, and legal focus as inputs. The author used an exploratory, qualitative methodology consisting of an extensive literature review and interviews with experts in the field. These efforts produced the proposed model, which was reviewed by experts in the field using a delphi technique. The model consists of information that is divided into the following areas: 1. What information was compromised. 2. What type of intrusion occurred. 3. How the intrusion was attempted. …


A New On-Line Cash Check Scheme, Robert H. Deng, Yongfei Han, Albert B. Jeng, Teow-Hin Ngair Apr 1997

A New On-Line Cash Check Scheme, Robert H. Deng, Yongfei Han, Albert B. Jeng, Teow-Hin Ngair

Research Collection School Of Computing and Information Systems

This paper presents a new on-line cash check scheme which guarantees payor anonymity and improves upon existing similar schemes in efficiency and security.


Analyzing And Improving Stochastic Network Security: A Multicriteria Prescriptive Risk Analysis Model, David L. Lyle Mar 1997

Analyzing And Improving Stochastic Network Security: A Multicriteria Prescriptive Risk Analysis Model, David L. Lyle

Theses and Dissertations

This research optimized two measures of network security by hardening components and improving their reliability. A common measure of effectiveness (MOE) for networks is statistical reliability, which ignores the effects of hostile actions. A new MOE which includes hostile actions was developed. Both measures require component reliability functions, derived using fault trees. Fuzzy Logic and Monte Carlo simulation were used to quantify uncertainty. Results from the model are compared to traditional Risk Assessment results.


The "Hoover" Project: Home Occupants Vehicular Electronic Reconnaissance, Kelvin Chan Jan 1997

The "Hoover" Project: Home Occupants Vehicular Electronic Reconnaissance, Kelvin Chan

SWITCH

The article explains telepresence, as well as its potential in safety and security, along with its traditional usage of traversing dangerous situations. This article describes a dystopian plan to place drones equipped with cameras and microphones in all homes in the Silicon Valley as a vehicle for telepresence. The data achieved through this method would also be stored into a public domain browser on the internet, free for anyone in the public to view, including larger corporations and the government. The idea behind this is the assimilation of data behind all cultures for understanding and to assist law enforcement in …