Rfid Ownership Transfer With Positive Secrecy Capacity Channels,
2017
Singapore Management University
Rfid Ownership Transfer With Positive Secrecy Capacity Channels, Jorge Munilla, Mike Burmester, Alberto Peinado, Guomin Yang, Willy Susilo
Research Collection School Of Computing and Information Systems
RFID ownership transfer protocols (OTPs) transfer tag ownership rights. Recently, there has been considerable interest in such protocols; however, guaranteeing privacy for symmetric-key settings without trusted third parties (TTPs) is a challenge still unresolved. In this paper, we address this issue and show that it can be solved by using channels with positive secrecy capacity. We implement these channels with noisy tags and provide practical values, thus proving that perfect secrecy is theoretically possible. We then define a communication model that captures spatiotemporal events and describe a first example of symmetric-key based OTP that: (i) is formally secure in the …
Financial Fraud Risk Management And Corporate Governance,
2017
Auckland University of Technology
Financial Fraud Risk Management And Corporate Governance, Raymond Lutui, Tau'aho 'Ahokovi
Australian Information Security Management Conference
Risk management is important so that risk is assessed, understood and appropriately managed. This is important both for conformance and performance. It is essential that strategic planning and management decisions are made appropriately in the context of the risk appetite of the corporation and its various stakeholders – especially its shareholders. If a company does not have a good understanding of risk, the likelihood of conformance and performance failure is high, this implies good internal and external corporate intelligence. Large global corporations have a significant impact on economies around the world. These entities are subject to intense competition and require …
Evaluating Ip Surveillance Camera Vulnerabilities,
2017
Auckland University of Technology
Evaluating Ip Surveillance Camera Vulnerabilities, Brian Cusack, Zhuang Tian
Australian Information Security Management Conference
Hacking of IP surveillance camera systems came to public attention in 2016 when the high bandwidth and resources were exploited for a massive DDoS attack that affected one third of all US Internet services. A review of previous studies show that a vast number of IP cameras have been hacked because the default usernames and passwords have not been changed from the factory defaults. In this research we asked, What are the vulnerabilities of an IP surveillance camera? The purpose of the study was to provide identification of vulnerabilities and guidance for the protection of surveillance camera systems. The research …
A Sri Lankan Hacking Case Study,
2017
Deakin University
A Sri Lankan Hacking Case Study, Ishan Senarathna, Matthew Warren
Australian Information Security Management Conference
The aim of the paper is to consider how hacking could impact a country that had historically experienced major cyber-attacks. The aim of the paper is to explore a cyber incident that occurred against the Sri Lankan president and how Sri Lankan authorities reacted to the incident. The paper will focus upon the motivations of the attack, the impact of the attack and how Sri Lankan authorities reacted to the situation.
Neurosecurity For Brainware Devices,
2017
Auckland University of Technology
Neurosecurity For Brainware Devices, Brian Cusack, Kaushik Sundararajan, Reza Khaleghparast
Australian Information Security Management Conference
Brainware has a long history of development down into the present day where very simple and usable devices are available to train for the control of games and services. One of the big areas of application has been in the health sciences to provide compensatory control to humans who may lack the usual capabilities. Our concern has been the protection of information in brainware so that a human intention may have confidentiality, integrity, and accessibility to the required implementation mechanisms for services. The research question was: What are the consequences of security failure in brainware? Our research tested a brainware …
Assessment Of Security Vulnerabilities In Wearable Devices,
2017
Auckland University of Technology
Assessment Of Security Vulnerabilities In Wearable Devices, Brian Cusack, Bryce Antony, Gerard Ward, Shaunak Mody
Australian Information Security Management Conference
Wearable devices have proliferated in usage and human experience, and they provide convenience for personal information requirements. These devices are both sensory and immersive for the diverse global network that is generally termed the Internet of things (IoT). The immediacy of the two-way communication created in the IoT has made vulnerable human behaviour and raised debate around information ownership and privacy expectations. The legitimacy of ownership of information and its reuse are prevalent problems. In this research, we tested four wearable devices that share 44% of the current market, for security vulnerabilities. We found serious weaknesses that could result in …
Literature-Based Analysis Of The Influences Of The New Forces On Isms: A Conceptual Framework,
2017
RMIT University
Literature-Based Analysis Of The Influences Of The New Forces On Isms: A Conceptual Framework, Zahir Al-Rashdi, Martin Dick, Ian Storey
Australian Information Security Management Conference
This paper presents an analysis that arose from a comprehensive review of the academic and professional literature of two areas – information security management systems (ISMS) and information resources – and their relationship with information security. It analyzes the role of ISMS in protecting an organization’s information environment and infrastructure. It has identified four key areas that strongly influence the safety of information resources: cloud computing; social media/networking; mobility; and information management/big data. Commonly referred to as ‘new forces’, these four aspects are all growing exponentially and are not easily controlled by IT. Another key finding of the paper is …
Core Elements In Information Security Accountability In The Cloud,
2017
RMIT University
Core Elements In Information Security Accountability In The Cloud, Zahir Al-Rashdi, Martin Dick, Ian Storey
Australian Information Security Management Conference
This paper proposes 9 core elements of information security accountability in the area of cloud computing. The core elements were determined via a series of 18 case studies with Omani government organisations that were actively using and/or providing cloud computing. 36 interviews were conducted and then analysed using a grounded theory methodology As a result of the analysis, responsibility, transparency, assurance, remediation, accountability support environment, flexible change process, collaboration, mechanisms and commitment to external criteria. The research also found that the emphasis on specific core elements is context-dependent and that there was considerable variation in emphasis amongst the case study …
The Proceedings Of 15th Australian Information Security Management Conference, 5-6 December, 2017, Edith Cowan University, Perth, Australia,
2017
Edith Cowan University
The Proceedings Of 15th Australian Information Security Management Conference, 5-6 December, 2017, Edith Cowan University, Perth, Australia, Craig Valli (Ed.)
Australian Information Security Management Conference
Conference Foreword
The annual Security Congress, run by the Security Research Institute at Edith Cowan University, includes the Australian Information Security and Management Conference. Now in its fifteenth year, the conference remains popular for its diverse content and mixture of technical research and discussion papers. The area of information security and management continues to be varied, as is reflected by the wide variety of subject matter covered by the papers this year. The papers cover topics from vulnerabilities in “Internet of Things” protocols through to improvements in biometric identification algorithms and surveillance camera weaknesses. The conference has drawn interest and …
Availability Of Datasets For Digital Forensics–And What Is Missing,
2017
University of New Haven
Availability Of Datasets For Digital Forensics–And What Is Missing, Cinthya Grajeda, Frank Breitinger, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
This paper targets two main goals. First, we want to provide an overview of available datasets that can be used by researchers and where to find them. Second, we want to stress the importance of sharing datasets to allow researchers to replicate results and improve the state of the art. To answer the first goal, we analyzed 715 peer-reviewed research articles from 2010 to 2015 with focus and relevance to digital forensics to see what datasets are available and focused on three major aspects: (1) the origin of the dataset (e.g., real world vs. synthetic), (2) if datasets were released …
Online Hacker Forum Censorship: Would Banning The Bad Guys Attract Good Guys?,
2017
Singapore Management University
Online Hacker Forum Censorship: Would Banning The Bad Guys Attract Good Guys?, Qiu-Hong Wang, Le-Ting Zhang, Meng-Ke Qiao
Research Collection School Of Computing and Information Systems
To tackle the ubiquitous cybersecurity threats, a few countries have enacted legislation to criminalize the production, distribution and possession of computer misuse tools. Consequently, online hacker forums, which enable the provision and dissemination of malicious cyber-attack techniques among potential hackers or technology-savvy users, are subject to censorship. This project examines the mixed impacts of online hacker forum censorship on users’ contribution to protection discussion through a natural experiment with large-scale content analysis. We find that while the enforcement indeed reduced the discussion on malicious cyber-attacks, the discussion on cybersecurity protection could increase or decrease in different scenarios. The rationale is …
On The Effectiveness Of Code-Reuse-Based Android Application Obfuscation,
2017
Singapore Management University
On The Effectiveness Of Code-Reuse-Based Android Application Obfuscation, Xiaoxiao Tang, Yu Liang, Xinjie Ma, Yan Lin, Debin Gao
Research Collection School Of Computing and Information Systems
Attackers use reverse engineering techniques to gain detailed understanding of executable for malicious purposes, such as re-packaging an Android app to inject malicious code or advertising components. To make reverse engineering more difficult, researchers have proposed various code obfuscation techniques to conceal purposes or logic of code segments. One interesting idea of code obfuscation is to apply codereuse techniques (e.g., Return-Oriented Programming) to (re-)distribute essential code segments before they are reconstructed at runtime. Such techniques are well understood on x86 platform, but relatively less explored on Android. In this paper, we present an evaluation on the extent to which code-reuse-based …
High Impact Bug Report Identification With Imbalanced Learning Strategies,
2017
Zhejiang University
High Impact Bug Report Identification With Imbalanced Learning Strategies, Xinli Yang, David Lo, Xin Xia, Qiao Huang, Jianling Sun
Research Collection School Of Computing and Information Systems
In practice, some bugs have more impact than others and thus deserve more immediate attention. Due to tight schedule and limited human resources, developers may not have enough time to inspect all bugs. Thus, they often concentrate on bugs that are highly impactful. In the literature, high-impact bugs are used to refer to the bugs which appear at unexpected time or locations and bring more unexpected effects (i.e., surprise bugs), or break pre-existing functionalities and destroy the user experience (i.e., breakage bugs). Unfortunately, identifying high-impact bugs from thousands of bug reports in a bug tracking system is not an easy …
Attribute-Based Storage Supporting Secure Deduplication Of Encrypted Data In Cloud,
2017
Singapore Management University
Attribute-Based Storage Supporting Secure Deduplication Of Encrypted Data In Cloud, Hui Cui, Robert H. Deng, Yingjiu Li, Guowei Wu
Research Collection School Of Computing and Information Systems
Attribute-based encryption (ABE) has been widely used in cloud computing where a data provider outsources his/herencrypted data to a cloud service provider, and can share the data with users possessing specific credentials (or attributes). However,the standard ABE system does not support secure deduplication, which is crucial for eliminating duplicate copies of identical data inorder to save storage space and network bandwidth. In this paper, we present an attribute-based storage system with securededuplication in a hybrid cloud setting, where a private cloud is responsible for duplicate detection and a public cloud manages thestorage. Compared with the prior data deduplication systems, our …
Assessing Patient And Caregiver Intent To Use Mobile Device Videoconferencing For Remote Mechanically-Ventilated Patient Management,
2017
Eastern Michigan University
Assessing Patient And Caregiver Intent To Use Mobile Device Videoconferencing For Remote Mechanically-Ventilated Patient Management, Brian R. Smith
Master's Theses and Doctoral Dissertations
The Michigan Medicine adult Assisted Ventilation Clinic (AVC) supports patients with neuromuscular disorders and spinal cord injuries and their caregivers at home, helping them avoid expensive emergency department visits, hospitalization, and unnecessary or excessive treatments. Mobile device videoconferencing provides an effective capability for remote mechanically-ventilated patient management but must rely upon an unknown infrastructure comprising patient and caregiver mobile device ownership, connectivity, and experience—and intent to use the service if provided. The purpose of this study was to measure the extent of this infrastructure and the perceived ease of use, perceived usefulness, and intent to use this mobile device …
Anomaly Detection In Rfid Networks,
2017
University of North Florida
Anomaly Detection In Rfid Networks, Alaa Alkadi
UNF Graduate Theses and Dissertations
Available security standards for RFID networks (e.g. ISO/IEC 29167) are designed to secure individual tag-reader sessions and do not protect against active attacks that could also compromise the system as a whole (e.g. tag cloning or replay attacks). Proper traffic characterization models of the communication within an RFID network can lead to better understanding of operation under “normal” system state conditions and can consequently help identify security breaches not addressed by current standards. This study of RFID traffic characterization considers two piecewise-constant data smoothing techniques, namely Bayesian blocks and Knuth’s algorithms, over time-tagged events and compares them in the context …
Examining And Exposing The Darknet,
2017
Georgia Southern University
Examining And Exposing The Darknet, Ton H. Don
College of Graduate Studies: Theses & Dissertations
This thesis consists of two studies; the first study is “Diving into the Darknet” and the second is “Exposing the Darknet on Mobile Devices”. The Darknet is a network of hidden sites and services which are built based on anonymity. In “Diving into the Darknet”, we applied different data science methods to establish the relationships between the data in the data set. This data set has information related to seller, drug types, and transactions. Additionally, we used Tableau to visualize the data set. For the second study, we took a digital forensics perspective of the Darknet. Orfox and Orbot, a …
Human-Centered Authentication Guidelines,
2017
San Jose State University
Human-Centered Authentication Guidelines, Jeremiah Still, Ashley Cain, David Schuster
Faculty Publications
PurposeDespite the widespread use of authentication schemes and the rapid emergence of novel authentication schemes, a general set of domain-specific guidelines has not yet been developed. This paper aims to present and explain a list of human-centered guidelines for developing usable authentication schemes.Design/methodology/approachThe guidelines stem from research findings within the fields of psychology, human–computer interaction and information/computer science.FindingsInstead of viewing users as the inevitable weak point in the authentication process, this study proposes that authentication interfaces be designed to take advantage of users’ natural abilities. This approach requires that one understands how interactions with authentication interfaces can be improved and …
Teaching Hands-On Cyber Defense Labs To Middle School And High School Students: Our Experience From Gencyber Camps,
2017
Old Dominion University
Teaching Hands-On Cyber Defense Labs To Middle School And High School Students: Our Experience From Gencyber Camps, Peng Jiang, Xin Tian, Chunsheng Xin, Wu He
Electrical & Computer Engineering Faculty Publications
With the high demand of the nation for next generation cybersecurity experts, it is important to design and provide hands-on labs for students at the K-12 level in order to increase their interest in cybersecurity and enhance their confidence in learning cybersecurity skills at the young age. This poster reports some preliminary analysis results from the 2016 GenCyber summer camp held at Old Dominion University (ODU), which is part of a nationwide grant program funded by the National Security Agency (NSA) and the National Science Foundation (NSF). This poster also demonstrates the design of three hands-on labs which have been …
Leveraging The Srtp Protocol For Over-The-Network Memory Acquisition Of A Ge Fanuc Series 90-30,
2017
University of New Haven
Leveraging The Srtp Protocol For Over-The-Network Memory Acquisition Of A Ge Fanuc Series 90-30, George Denton, Filip Karpisek, Frank Breitinger, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
Programmable Logic Controllers (PLCs) are common components implemented across many industries such as manufacturing, water management, travel, aerospace and hospitals to name a few. Given their broad deployment in critical systems, they became and still are a common target for cyber attacks; the most prominent one being Stuxnet. Often PLCs (especially older ones) are only protected by an outer line of defense (e.g., a firewall) but once an attacker gains access to the system or the network, there might not be any other defense layers. In this scenario, a forensic investigator should not rely on the existing software as it …
