An Hierarchical Asset Valuation Method For Information Security Risk Analysis,
2012
Franklin University
An Hierarchical Asset Valuation Method For Information Security Risk Analysis, Bilge Karabacak, Unal Tatar
All Faculty and Staff Scholarship
The widespread use of information technology transforms businesses continuously and rapidly. Information technology introduces new threats to organizations as well. Risk analysis is an important tool in order to make correct decisions and to deal with cyber threats. Identification and valuation of assets is a crucial process that must be performed in risk analyses. Without properly identified and valued assets, the results of risk analyses lead to wrong decisions. Wrong decisions on information security may directly affect corresponding business processes. There are some finished and applied methods in literature for asset identification and valuation; however these methods are complicated and …
The Intricacies Of Independence,
2012
Indiana University Maurer School of Law
The Intricacies Of Independence, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantession
Articles by Maurer Faculty
No abstract provided.
The Challenge Of "Big Data" For Data Protection,
2012
Indiana University Maurer School of Law
The Challenge Of "Big Data" For Data Protection, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Cloud Storage,
2012
Bridgewater College
Cloud Storage, Matthew G. Chaulklin
Senior Seminars
Technology is forever changing in our world today. The way in which we receive information must match the convenience of our current technology. As of now most information that is stored is often restricted to the site of the server when one wants to access it. Cloud storage can change this process by allowing users anywhere to access the information they need. This technology is a solution to our storage problems as it is convenient for any user to obtain information. Unfortunately this technology has various large problems, like security, but hopefully in the future these can be solved. Overall, …
Calm Before The Storm: The Challenges Of Cloud Computing In Digital Forensics,
2012
University of Nebraska at Omaha
Calm Before The Storm: The Challenges Of Cloud Computing In Digital Forensics, George Grispos, Tim Storer, William Bradley Glisson
Interdisciplinary Informatics Faculty Publications
Cloud computing is a rapidly evolving information technology (IT) phenomenon. Rather than procure, deploy and manage a physical IT infrastructure to host their software applications, organizations are increasingly deploying their infrastructure into remote, virtualized environments, often hosted and managed by third parties. This development has significant implications for digital forensic investigators, equipment vendors, law enforcement, as well as corporate compliance and audit departments (among others). Much of digital forensic practice assumes careful control and management of IT assets (particularly data storage) during the conduct of an investigation. This paper summarises the key aspects of cloud computing and analyses how established …
Column: The Physics Of Digital Information-Part 2,
2012
CEO, Fred Cohen & Associates President, California Sciences Institute
Column: The Physics Of Digital Information-Part 2, Fred Cohen
Journal of Digital Forensics, Security and Law
In part 1 of this series (Cohen, 2011a), we discussed some of the basics of building a physics of digital information. Assuming, as we have, that science is about causality and that a scientific theory should require that cause(C) produces effect (E) via mechanism M (written C→ME), we explore that general theory of digital systems from the perspective of attributing effects (i.e., traces of activities in digital systems) to their causes. Full details of the current version of this physics are available online2 , and in this article, we explore a few more of them.
Technology Corner: Dating Of Electronic Hardware For Prior Art Investigations,
2012
VintageTech
Technology Corner: Dating Of Electronic Hardware For Prior Art Investigations, Sellam Ismail
Journal of Digital Forensics, Security and Law
In many legal matters, specifically patent litigation, determining and authenticating the date of computer hardware or other electronic products or components is often key to establishing the item as legitimate evidence of prior art. Such evidence can be used to buttress claims of technologies available or of events transpiring by or at a particular date.
Applying The Acpo Principles In Public Cloud Forensic Investigations,
2012
University of Warwick, Coventry
Applying The Acpo Principles In Public Cloud Forensic Investigations, Harjinder S. Lallie, Lee Pimlott
Journal of Digital Forensics, Security and Law
The numerous advantages offered by cloud computing has fuelled its growth and has made it one of the most significant of current computing trends. The same advantages have created complex issues for those conducting digital forensic investigations. Digital forensic investigators rely on the ACPO (Association of Chief Police Officers) or similar guidelines when conducting an investigation, however the guidelines make no reference to some of the issues presented by cloud investigations. This study investigates the impact of cloud computing on ACPO’s core principles and asks whether these principles can still be applied in a cloud investigation and the challenges presented …
An Overview Of The Jumplist Configuration File In Windows 7,
2012
University of Warwick, Coventry
An Overview Of The Jumplist Configuration File In Windows 7, Harjinder S. Lallie, Parmjit S. Bains
Journal of Digital Forensics, Security and Law
The introduction of Jumplists in Windows 7 was an important feature from a forensic examiners viewpoint. Jumplist configuration files can provide the examiner with a wealth of information relating to file access and in particular: dates/times, Volume GUIDs and unique file object IDs relating to those files. Some of the information in the Jumplist could be used to build a more precise timeline relating to system and file usage. In this article, we analyse the structure of a Jumplist configuration file and in particular a record from a Jumplist configuration file and highlight some of the important entries therein.
Pandora’S Email Box? An Exploratory Study Of Web-Based Email Forgery Detection And Validation.,
2012
Murdoch University
Pandora’S Email Box? An Exploratory Study Of Web-Based Email Forgery Detection And Validation., Richard Boddington, Grant Boxall, Jeremy Ardley
Journal of Digital Forensics, Security and Law
Web based email systems may be a source of pristine digital evidence because of the perceived difficulty of client tampering with messages stored inside the email account. We demonstrate that such assumption is wrong in the case of Windows Live Hotmail®1 . Windows Live Mail®1 synchronises message on client-side computers with the Hotmail® server, benefiting users wishing to synchronise their email accounts and personal devices. However, this synchronisation opens an exploit for wrongdoers to tamper with existing email messages and attachments as well as facilitating the insertion of fabricated messages. The exploit process enables persistent storage of tampered and fabricated …
Toward Alignment Between Communities Of Practice And Knowledge-Based Decision Support,
2012
Oklahoma State University
Toward Alignment Between Communities Of Practice And Knowledge-Based Decision Support, Jason Nichols, David Biros, Mark Weiser
Journal of Digital Forensics, Security and Law
The National Repository of Digital Forensics Information (NRDFI) is a knowledge repository for law enforcement digital forensics investigators (LEDFI). Over six years, the NRDFI has undertaken significant design revisions in order to more closely align the architecture of the system with theory addressing motivation to share knowledge and communication within ego-centric groups and communities of practice. These revisions have been met with minimal change in usage patterns by LEDFI community members, calling into question the applicability of relevant theory when the domain for knowledge sharing activities expands beyond the confines of an individual organization to a community of practice. When …
Implementing The Automated Phases Of The Partially-Automated Digital Triage Process Model,
2012
Dixie State College of Utah
Implementing The Automated Phases Of The Partially-Automated Digital Triage Process Model, Gary Cantrell, David A. Dampier
Journal of Digital Forensics, Security and Law
Digital triage is a pre-digital-forensic phase that sometimes takes place as a way of gathering quick intelligence. Although effort has been undertaken to model the digital forensics process, little has been done to-date to model digital triage. This work discusses the further development of a model that attempts to address digital triage, the Partially-automated Crime Specific Digital Triage Process model. The model itself will be presented along with a description of how its automated functionality was implemented to facilitate model testing.
Table Of Contents,
2012
Embry-Riddle Aeronautical University
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
Digital Evidence Education In Schools Of Law,
2012
University of Washington
Digital Evidence Education In Schools Of Law, Aaron Alva, Barbara Endicott-Popovsky
Journal of Digital Forensics, Security and Law
An examination of State of Connecticut v. Julie Amero provides insight into how a general lack of understanding of digital evidence can cause an innocent defendant to be wrongfully convicted. By contrast, the 101-page opinion in Lorraine v. Markel American Insurance Co. provides legal precedence and a detailed consideration for the admission of digital evidence. An analysis of both cases leads the authors to recommend additions to Law School curricula designed to raise the awareness of the legal community to ensure such travesties of justice, as in the Amero case, don’t occur in the future. Work underway at the University …
Crisis Response Information Networks,
2012
Singapore Management University
Crisis Response Information Networks, Shan L. Pan, Gary Pan, Dorothy Leidner
Research Collection School Of Accountancy
In the past two decades, organizational scholars have focused significant attention on how organizations manage crises. While most of these studies concentrate on crisis prevention, there is a growing emphasis on crisis response. Because information that is critical to crisis response may become outdated as crisis conditions change, crisis response research recognizes that the management of information flows and networks is critical to crisis response. Yet despite its importance, little is known about the various types of crisis information networks and the role of IT in enabling these information networks. Employing concepts from information flow and social network theories, this …
Systematic Government Access To Private-Sector Data,
2012
Indiana University Maurer School of Law
Systematic Government Access To Private-Sector Data, Fred H. Cate, James X. Dempsey, Ira S. Rubenstein
Articles by Maurer Faculty
No abstract provided.
The End Of The Beginning,
2012
Indiana University Maurer School of Law
The End Of The Beginning, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
A Survey Of Computer And Network Security Support From Computer Retailers To Consumers In Australia,
2012
Edith Cowan University
A Survey Of Computer And Network Security Support From Computer Retailers To Consumers In Australia, Patryk Szewczyk
Australian Information Security Management Conference
Previously undertaken research suggests that novice end-users rely on computer retailers for security advice and support during and after a sale has occurred. This paper documents the survey results of computer and network security support provided to consumers by retailers in Perth, Western Australia between 2011 and 2012. The conducted survey shows that in the majority of cases, computers retailers were favourable in providing support and recommendations. However, these views were found to be flawed, confusing and do little to ensure that end-users are not victimized by cyber crime.
A Survey And Analysis Of Solutions To The Oblivious Memory Access Problem,
2012
Portland State University
A Survey And Analysis Of Solutions To The Oblivious Memory Access Problem, Erin Elizabeth Chapman
Dissertations and Theses
Despite the use of strong encryption schemes, one can still learn information about encrypted data using side channel attacks [2]. Watching what physical memory is being accessed can be such a side channel. One can hide this information by using oblivious simulation - hiding the true access pattern of a program. In this paper we will review the model behind oblivious simulation, attempt to formalize the problem and define a security game. We will review the major solutions pro- posed so far, the square root and hierarchical solutions, as well as propose a new variation on the square root solution. …
Novel Techniques Of Using Diversity In Software Security And Information Hiding,
2012
Singapore Management University
Novel Techniques Of Using Diversity In Software Security And Information Hiding, Jin Han
Dissertations and Theses Collection (Open Access)
Diversity is an important and valuable concept that has been adopted in many fields to reduce correlated risks and to increase survivability. In information security, diversity also helps to increase both defense capability and fault tolerance for information systems and communication networks, where diversity can be adopted from many different perspectives. This dissertation, in particular, focuses mainly on two aspects of diversity – the application software diversity and the diversity in data interpretation. Software diversity has many advantages over mono-culture in improving system security. A number of previous researches focused on utilizing existing off-theshelf diverse software for network protection and …
