Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 176 of 201.

Expressive Search On Encrypted Data, Junzuo LAI, Xuhua ZHOU, Robert H. DENG, Yingjiu LI, Kefei CHEN 2013 Singapore Management University

Expressive Search On Encrypted Data, Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen

Research Collection School Of Computing and Information Systems

Different from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user’s public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Searchable pubic key encryption has many promising applications. Unfortunately, existing schemes either only support simple query predicates, such as equality queries and conjunctive queries, or have a superpolynomial blowup in ciphertext size …


Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks, Divyan KONIDALA, Robert H. DENG, Yingjiu LI, Hoong Chuin LAU, Stephen FIENBERG 2013 Singapore Management University

Anonymous Authentication Of Visitors For Mobile Crowd Sensing At Amusement Parks, Divyan Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen Fienberg

Research Collection School Of Computing and Information Systems

In this paper we focus on authentication and privacy aspects of an application scenario that utilizes mobile crowd sensing for the benefit of amusement park operators and their visitors. The scenario involves a mobile app that gathers visitors’ demographic details, preferences, and current location coordinates, and sends them to the park’s sever for various analyses. These analyses assist the park operators to efficiently deploy their resources, estimate waiting times and queue lengths, and understand the behavior of individual visitors and groups. The app server also offers visitors optimal recommendations on routes and attractions for an improved dynamic experience and minimized …


Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model, Guomin YANG, Yi MU, Willy SUSILO, Duncan S. WONG 2013 Singapore Management University

Leakage Resilient Authenticated Key Exchange Secure In The Auxiliary Input Model, Guomin Yang, Yi Mu, Willy Susilo, Duncan S. Wong

Research Collection School Of Computing and Information Systems

Authenticated key exchange (AKE) protocols allow two parties communicating over an insecure network to establish a common secret key. They are among the most widely used cryptographic protocols in practice. In order to resist key-leakage attacks, several leakage resilient AKE protocols have been proposed recently in the bounded leakage model. In this paper, we initiate the study on leakage resilient AKE in the auxiliary input model. A promising way to construct such a protocol is to use a digital signature scheme that is entropically-unforgeable under chosen message and auxiliary input attacks. However, to date we are not aware of any …


Information Security As A Credence Good, Ping Fan KE, Kai-Lung HUI, Wei Thoo YUE 2013 Singapore Management University

Information Security As A Credence Good, Ping Fan Ke, Kai-Lung Hui, Wei Thoo Yue

Research Collection School Of Computing and Information Systems

With increasing use of information systems, many organizations are outsourcing information security protection to a managed security service provider (MSSP). However, diagnosing the risk of an information system requires special expertise, which could be costly and difficult to acquire. The MSSP may exploit their professional advantage and provide fraudulent diagnosis of clients’ vulnerabilities. Such an incentive to mis-represent clients’ risks is often called the credence goods problem in the economics literature[3]. Although different mechanisms have been introduced to tackle the credence goods problem, in the information security outsourcing context, such mechanisms may not work well with the presence of system …


Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun CHEN, Hoon Wei LIM, Guomin YANG 2013 Singapore Management University

Cross-Domain Password-Based Authenticated Key Exchange Revisited, Liqun Chen, Hoon Wei Lim, Guomin Yang

Research Collection School Of Computing and Information Systems

We revisit the problem of secure cross-domain communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a generic framework for designing four-party password-based authenticated key exchange (4PAKE) protocols. Our framework takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with …


Front Matter, 2013 Embry-Riddle Aeronautical University

Front Matter

Journal of Digital Forensics, Security and Law

No abstract provided.


Masthead, 2013 Embry-Riddle Aeronautical University

Masthead

Journal of Digital Forensics, Security and Law

No abstract provided.


Back Matter, 2013 Embry-Riddle Aeronautical University

Back Matter

Journal of Digital Forensics, Security and Law

No abstract provided.


Rootkit Detection Using A Cross-View Clean Boot Method, Bridget N. Flatley 2013 Air Force Institute of Technology

Rootkit Detection Using A Cross-View Clean Boot Method, Bridget N. Flatley

Theses and Dissertations

In cyberspace, attackers commonly infect computer systems with malware to gain capabilities such as remote access, keylogging, and stealth. Many malware samples include rootkit functionality to hide attacker activities on the target system. After detection, users can remove the rootkit and associated malware from the system with commercial tools. This research describes, implements, and evaluates a clean boot method using two partitions to detect rootkits on a system. One partition is potentially infected with a rootkit while the other is clean. The method obtains directory listings of the potentially infected operating system from each partition and compares the lists to …


Mobile Network Defense Interface For Cyber Defense And Situational Awareness, James C. Hannan 2013 Air Force Institute of Technology

Mobile Network Defense Interface For Cyber Defense And Situational Awareness, James C. Hannan

Theses and Dissertations

Today's computer networks are under constant attack. In order to deal with this constant threat, network administrators rely on intrusion detection and prevention services (IDS) (IPS). Most IDS and IPS implement static rule sets to automatically alert administrators and resolve intrusions. Network administrators face a difficult challenge, identifying attacks against a vast number of benign network transactions. Also after a threat is identified making even the smallest policy change to the security software potentially has far-reaching and unanticipated consequences. Finally, because the administrator is primarily responding to alerts they may lose situational awareness of the network. During this research a …


Accountable Authority Identity-Based Encryption With Public Traceability, Junzuo LAI, Robert H. DENG, Yunlei ZHAO, Jian Weng 2013 Singapore Management University

Accountable Authority Identity-Based Encryption With Public Traceability, Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng

Research Collection School Of Computing and Information Systems

At Crypto’07, Goyal introduced the notion of accountable authority identity-based encryption (A-IBE) in order to mitigate the inherent key escrow problem in identity-based encryption, and proposed two concrete constructions. In an A-IBE system, if the private key generator (PKG) distributes a decryption key or produces an unauthorized decryption box for a user maliciously, it runs the risk of being caught and sued in the court of law with the help of a tracing algorithm. Subsequent efforts focused on constructions of A-IBE schemes with enhanced security. In these A-IBE constructions, the tracing algorithm needs to take a user’s decryption key as …


Almost Touching: Parent-Child Remote Communication Using The Sharetable System, Svetlana YAROSH, Anthony TANG, Sanika MOKASHI, Gregory D. ABOWD 2013 Singapore Management University

Almost Touching: Parent-Child Remote Communication Using The Sharetable System, Svetlana Yarosh, Anthony Tang, Sanika Mokashi, Gregory D. Abowd

Research Collection School Of Computing and Information Systems

We deployed the ShareTable - a system that provides easy-to-initiate videochat and a shared tabletop task space - in four divorced households. Throughout the month of its use, the families employed the ShareTable to participate in shared activities, share emotional moments, and communicate closeness through metaphorical touch. The ShareTable provided a number of advantages over the phone and was easier to use than standard videoconferencing. However, it did also introduce concerns over privacy and new sources of conflict about appropriate calling practices. We relate our findings to the larger research landscape and present implications for future work.


Simple Identity-Based Encryption With Mediated Rsa, Xuhua DING, Gene Tsudik 2013 Singapore Management University

Simple Identity-Based Encryption With Mediated Rsa, Xuhua Ding, Gene Tsudik

Research Collection School Of Computing and Information Systems

Identity-based encryption (IBE) [5] and digital signatures are important tools in modern secure communication. In general, identity-based cryptographic methods facilitate easy introduction of public key cryptography by allowing an entity’s public key to be derived from some arbitrary identification value such as an email address or a phone number. Identity-based cryptography greatly reduces the need for, and reliance on, public key certificates. Mediated RSA (mRSA) [4] is a simple and practical method of splitting RSA private keys between the user and the Security Mediator (SEM). Neither the user nor the SEM can cheat one another since each signature or decryption …


Comparing Mobile Privacy Protection Through Cross-Platform Applications, Jin HAN, Qiang YAN, Debin GAO, Jianying ZHOU, Robert H. DENG 2013 Singapore Management University

Comparing Mobile Privacy Protection Through Cross-Platform Applications, Jin Han, Qiang Yan, Debin Gao, Jianying Zhou, Robert H. Deng

Research Collection School Of Computing and Information Systems

With the rapid growth of the mobile market, security of mobile platforms is receiving increasing attention from both research community as well as the public. In this paper, we make the first attempt to establish a baseline for security comparison between the two most popular mobile platforms. We investigate applications that run on both Android and iOS and examine the difference in the usage of their security sensitive APIs (SS-APIs). Our analysis over 2,600 applications shows that iOS applications consistently access more SS-APIs than their counterparts on Android. The additional privileges gained on iOS are often associated with accessing private …


I Can Be You: Questioning The Use Of Keystroke Dynamics As Biometrics, Chee Meng TEY, Payas GUPTA, Debin GAO 2013 Singapore Management University

I Can Be You: Questioning The Use Of Keystroke Dynamics As Biometrics, Chee Meng Tey, Payas Gupta, Debin Gao

Research Collection School Of Computing and Information Systems

Keystroke dynamics refer to information about the typing patterns of individuals, such as the relative timing when the individual presses and releases each key. Prior studies suggest that such patterns are unique and cannot be easily imitated. This lays the foundation for the use of keystroke biometrics in authentication systems. The research effort in this area has thus far focused on novel detection techniques to differentiate between legitimate users and imposters. In this paper, we demonstrate a novel feedback and training interface named Mimesis. Mimesis provides both positive and negative feedback on the differences between a submitted pattern vs. a …


Raising The Game: Applying Theory And Analytics To Real-World Threats, Singapore Management University 2013 Singapore Management University

Raising The Game: Applying Theory And Analytics To Real-World Threats, Singapore Management University

Perspectives@SMU

Safety and security are, on many levels, essential priorities for governments, businesses and individuals. While an increase of defence and security budgets may bring some assurance of peaceful times to come, it seems the world has no lack of insane perpetrators who can still somehow evade, breach, ambush, assail and attack as they please. Enter the “Bayesian Stackelberg Game”, a game theory model that can, and has been applied rather successfully to the allocation of security resources in the United States by Prof Milind Tambe, University of Southern California.


Developing Focused Auditing Tools: A Practical Framework For Creating Formalized Multi-Level Security Policy Specifications, Barbara Ann Brough 2013 California State University, San Bernardino

Developing Focused Auditing Tools: A Practical Framework For Creating Formalized Multi-Level Security Policy Specifications, Barbara Ann Brough

Theses Digitization Project

The purpose of this study is that formalized policy specifications and focused penetration testing are needed to effectively audit any information system. Designing and maintaining the security system information is the primary duty of the cyber security professional. In today's world, nearly all government agencies manage some form of financial, defense, national security, and/or privacy information security policies. It is also necessary in this environment that agencies are accountable for auditing the security systems that protect this information.


The Implementation Of A Thin Client In The Department Of Defense Network System, Sung Ju In 2013 California State University, San Bernardino

The Implementation Of A Thin Client In The Department Of Defense Network System, Sung Ju In

Theses Digitization Project

The purpose of this project is to introduce and analyze a thin client solution that could enhance the overall Department of Defense (DoD) network system as well as its IT security posture, minimize risk from external threats, and ease of network operations.


Quantum Cryptography, Razvan Augustin Dinu 2013 California State University, San Bernardino

Quantum Cryptography, Razvan Augustin Dinu

Theses Digitization Project

This study builds a case for using a quantum computer for solving cryptographic problems. It looks at the quantum turing machine concept, explores why use quantum computers and presents Deutsch's problem which allows one to select from amongst the parallel paths a quantum computer calculates.


Security Risks And Protection In Online Learning: A Survey, Yong Chen, Wu He 2013 Old Dominion University

Security Risks And Protection In Online Learning: A Survey, Yong Chen, Wu He

Distance Learning Faculty & Staff Publications

This paper describes a survey of online learning which attempts to determine online learning providers' awareness of potential security risks and the protection measures that will diminish them. The authors use a combination of two methods: blog mining and a traditional literature search. The findings indicate that, while scholars have identified diverse security risks and have proposed solutions to mitigate the security threats in online learning, bloggers have not discussed security in online learning with great frequency. The differences shown in the survey results generated by the two different methods confirm that online learning providers and practitioners have not considered …


Digital Commons powered by bepress