System-Generated Digital Forensic Evidence In Graphic Design Applications,
2013
University of Pretoria, South Africa
System-Generated Digital Forensic Evidence In Graphic Design Applications, Enos Mabuto, Hein Venter
Journal of Digital Forensics, Security and Law
Graphic design applications are often used for the editing and design of digital art. The same applications can be used for creating counterfeit documents such as identity documents (IDs), driver’s licences, passports, etc. However, the use of any graphic design application leaves behind traces of digital information that can be used during a digital forensic investigation. Current digital forensic tools examine a system to find digital evidence, but they do not examine a system specifically for the creating of counterfeit documents created through the use of graphic design applications. The paper in hand reviews the system-generated digital forensic evidence gathered …
The Extraterritoriality Of Data Privacy Laws -- An Explosive Issue Yet To Detonate,
2013
Indiana University Maurer School of Law
The Extraterritoriality Of Data Privacy Laws -- An Explosive Issue Yet To Detonate, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
The Business Of Privacy,
2013
Indiana University Maurer School of Law
The Business Of Privacy, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Face-To-Data -- Another Developing Privacy Threat?,
2013
Indiana University Maurer School of Law
Face-To-Data -- Another Developing Privacy Threat?, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Automated Detection Of Vehicles With Machine Learning,
2013
Edith Cowan University
Automated Detection Of Vehicles With Machine Learning, Michael N. Johnstone, Andrew Woodward
Australian Information Security Management Conference
Considering the significant volume of data generated by sensor systems and network hardware which is required to be analysed and intepreted by security analysts, the potential for human error is significant. This error can lead to consequent harm for some systems in the event of an adverse event not being detected. In this paper we compare two machine learning algorithms that can assist in supporting the security function effectively and present results that can be used to select the best algorithm for a specific domain. It is suggested that a naive Bayesian classiifer (NBC) and an artificial neural network (ANN) …
Guardian: Hypervisor As Security Foothold For Personal Computers,
2013
Singapore Management University
Guardian: Hypervisor As Security Foothold For Personal Computers, Yueqiang Cheng, Xuhua Ding
Research Collection School Of Computing and Information Systems
Personal computers lack of a security foothold to allow the end-users to protect their systems or to mitigate the damage. Existing candidates either rely on a large Trusted Computing Base (TCB) or are too costly to widely deploy for commodity use. To fill this gap, we propose a hypervisor-based security foothold, named as Guardian, for commodity personal computers. We innovate a bootup and shutdown mechanism to achieve both integrity and availability of Guardian. We also propose two security utilities based on Guardian. One is a device monitor which detects malicious manipulation on camera and network adaptors. The other is hyper-firewall …
Accountable Trapdoor Sanitizable Signatures,
2013
Singapore Management University
Accountable Trapdoor Sanitizable Signatures, Junzuo Lai, Xuhua Ding, Yongdong Wu
Research Collection School Of Computing and Information Systems
Sanitizable signature (SS) allows a signer to partly delegate signing rights to a predetermined party, called sanitizer, who can later modify certain designated parts of a message originally signed by the signer and generate a new signature on the sanitized message without interacting with the signer. One of the important security requirements of sanitizable signatures is accountability, which allows the signer to prove, in case of dispute, to a third party that a message was modified by the sanitizer. Trapdoor sanitizable signature (TSS) enables a signer of a message to delegate the power of sanitization to any parties at anytime …
A Study Of The Imitation, Collection And Usability Issues Of Keystroke Biometrics,
2013
Singapore Management University
A Study Of The Imitation, Collection And Usability Issues Of Keystroke Biometrics, Chee Meng Tey
Dissertations and Theses Collection (Open Access)
The majority of authentication systems used today involves passwords, where a user is required to remember and key in the correct password to login. Keystroke biometrics is an alternative approach whereby users are identified by one or more features such as (a) the timing between keystrokes, (b) how long users hold each key and (c) how hard users press each key. It is being assumed in prior research that the way one user types a password/word is different from the way another user types the same password and this characteristic remains stable over time. Existing literature however left open three …
Exploiting Human Factors In User Authentication,
2013
Singapore Management University
Exploiting Human Factors In User Authentication, Payas Gupta
Dissertations and Theses Collection (Open Access)
Our overarching issue in security is the human factor – and dealing with it is perhaps one of the biggest challenges we face today. Human factor is often described as the weakest part of a security system and users are often described as the weakest link in the security chain. In this thesis, we focus on two problems which are caused by human factors in user authentication and propose respective solutions. a) Secrecy information inference attack – publicly available information can be used to infer some secrecy information about the user. b) Coercion attack – where an attacker forces a …
Towards Secure And Usable Leakage-Resilient Password Entry,
2013
Singapore Management University
Towards Secure And Usable Leakage-Resilient Password Entry, Qiang Yan
Dissertations and Theses Collection (Open Access)
Password leakage is one of the most common security threats for pervasive password based user authentication. The design of a secure and usable password entry against password leakage remains a challenge since twenty year ago when the first academic proposal attempted to address it. This dissertation focuses on investigating the difficulty in designing leakage-resilient password entry (LRPE) schemes and exploring the feasibility of constructing secure and usable LRPE schemes with the assistance of state-of-the-art technology. The first work in this dissertation reveals the infeasibility of designing practical LRPE schemes in the absence of trusted devices by investigating the inherent tradeoff …
Verifiable And Private Top-K Monitoring,
2013
Singapore Management University
Verifiable And Private Top-K Monitoring, Xuhua Ding, Hwee Hwa Pang
Research Collection School Of Computing and Information Systems
In a data streaming model, records or documents are pushed from a data owner, via untrusted third-party servers, to a large number of users with matching interests. The match in interest is calculated from the correlation between each pair of document and user query. For scalability and availability reasons, this calculation is delegated to the servers, which gives rise to the need to protect the privacy of the documents and user queries. In addition, the users need to guard against the eventuality of a server distorting the correlation score of the documents to manipulate which documents are highlighted to certain …
Improving Internet Security Through Information Disclosure: A Field Quasi-Experiment,
2013
Singapore Management University
Improving Internet Security Through Information Disclosure: A Field Quasi-Experiment, Qian Tang, Leigh L. Linden, John S. Quarterman, Andrew B. Whinston
Research Collection School Of Computing and Information Systems
Cybersecurity is a national priority in this big data era. Because of negative externalities and the resulting lack of economic incentives, companies often underinvest in security controls, despite government and industry recommendations. Although many existing studies on security have explored technical solutions, only a few have looked at the economic motivations. To fill the gap, we propose an approach to increase the incentives of organizations to address security problems. Specifically, we utilize and process existing security vulnerability data, derive explicit security performance information, and disclose the information as feedback to organizations and the public. We regularly release information on the …
Book Review: Placing The Suspect Behind The Keyboard: Using Digital Forensics And Investigative Techniques To Identify Cybercrime Suspects,
2013
Internet Crime against Children Task Force
Book Review: Placing The Suspect Behind The Keyboard: Using Digital Forensics And Investigative Techniques To Identify Cybercrime Suspects, Thomas Nash
Journal of Digital Forensics, Security and Law
In this must read for any aspiring novice cybercrime investigator as well as the seasoned professional computer guru alike, Brett Shaver takes the reader into the ever changing and dynamic world of Cybercrime investigation. Shaver, an experienced criminal investigator, lays out the details and intricacies of a computer related crime investigation in a clear and concise manner in his new easy to read publication, Placing the Suspect behind the Keyboard. Using Digital Forensics and Investigative techniques to Identify Cybercrime Suspects. Shaver takes the reader from start to finish through each step of the investigative process in well organized …
Automating Vendor Fraud Detection In Enterprise Systems,
2013
Griffith University, Australia
Automating Vendor Fraud Detection In Enterprise Systems, Kishore Singh, Peter Best, Joseph Mula
Journal of Digital Forensics, Security and Law
Fraud is a multi-billion dollar industry that continues to grow annually. Many organizations are poorly prepared to prevent and detect fraud. Fraud detection strategies are intended to quickly and efficiently identify fraudulent activities that circumvent preventative measures. In this paper, we adopt a DesignScience methodological framework to develop a model for detection of vendor fraud based on analysis of patterns or signatures identified in enterprise system audit trails. The concept is demonstrated by developing prototype software. Verification of the prototype is achieved by performing a series of experiments. Validation is achieved by independent reviews from auditing practitioners. Key findings of …
Book Review: Professional Penetration Testing: Creating And Learning In A Hacking Lab 2e,
2013
CISSP, CEECS, CFCE, DFCP, CRISC, CSM
Book Review: Professional Penetration Testing: Creating And Learning In A Hacking Lab 2e, Joshua Bartolomie
Journal of Digital Forensics, Security and Law
Organizations often strive for proactive information security programs in an effort to limit occurrence and impact of security breaches. However, traditional security programs run the risk of being unable to provide adequate insight and proactive awareness into real attack vectors that may exist within their organizations. With attack methods and efforts becoming increasingly aggressive, and effective, organizations must take equally assertive measures to protect their critical information and assets. Penetration testing is one of those tools that is often misunderstood, overlooked, and undervalued. A true adversary would not hesitate to exploit every potential to gain entry or cause a disruption …
Technology Corner: Calculating The Number Of Android Lock Patterns: An Unfinished Study In Number Theory,
2013
Embry-Riddle Aeronautical University
Technology Corner: Calculating The Number Of Android Lock Patterns: An Unfinished Study In Number Theory, Gary C. Kessler
Journal of Digital Forensics, Security and Law
Although one is unlikely to ever want to brute-force an Android lock pattern, many do wonder about the relative strength of the lock pattern versus a multidigit personal identification number (PIN). It becomes obvious pretty quickly that there are many more lock patterns than the 10,000 possible four-digit PINs.
Science Column: Reconstruction: The Experimental Side Of Digital Forensics,
2013
California Sciences Institute
Science Column: Reconstruction: The Experimental Side Of Digital Forensics, Fred Cohen
Journal of Digital Forensics, Security and Law
Many in digital forensics seem to forget that the science part of digital forensics means experimentation and that implies a whole lot of things that most practitioners never learned.
Book Review: Iphone And Ios Forensic: Investigation, Analysis And Mobile Security For Apple Iphone, Ipad And Ios Devices,
2013
Simson Garfinkel
Book Review: Iphone And Ios Forensic: Investigation, Analysis And Mobile Security For Apple Iphone, Ipad And Ios Devices, Simson Garfinkel
Journal of Digital Forensics, Security and Law
In April 2011 news outlets around the world revealed shocking news about Apple’s iPhone: for reasons that were not apparently clear, every iPhone contained a small SQLite database that logged where and when the user had been whenever the phone was turned on, and those records went back for pretty much as long as the user had owned their phone. Apple eventually declared that the data cache was the result of a bug and issued a software update to prune the database (it had previously grown without limit). Privacy activists rejoiced that their beloved iPhones were once again trustworthy. But …
Table Of Contents,
2013
Embry-Riddle Aeronautical University
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
Testing A Distributed Denial Of Service Defence Mechanism Using Red Teaming,
2013
Edith Cowan University
Testing A Distributed Denial Of Service Defence Mechanism Using Red Teaming, Samaneh Rastegari, Philip Hingston, Chiou-Peng Lam, Murray Brand
Research outputs 2013
The increased number of security threats against the Internet has made communications more vulnerable to attacks. Despite much research and improvement in network security, the number of denial of service (DoS) attacks has rapidly grown in frequency, severity, and sophistication in recent years. Thus, serious attention needs to be paid to network security. However, to create a secure network that can stay ahead of all threats, detection and response features are real challenges. In this paper, we look at the the interaction between the attacker and the defender in a Red Team/Blue Team exercise. We also propose a quantitative decision …
