Technology Corner: Analysing E-Mail Headers For Forensic Investigation,
2011
Banday University of Kashmir India
Technology Corner: Analysing E-Mail Headers For Forensic Investigation, M. T. Banday
Journal of Digital Forensics, Security and Law
Electronic Mail (E-Mail), which is one of the most widely used applications of Internet, has become a global communication infrastructure service. However, security loopholes in it enable cybercriminals to misuse it by forging its headers or by sending it anonymously for illegitimate purposes, leading to e-mail forgeries. E-mail messages include transit handling envelope and trace information in the form of structured fields which are not stripped after messages are delivered, leaving a detailed record of e-mail transactions. A detailed header analysis can be used to map the networks traversed by messages, including information on the messaging software and patching policies …
Survey On Cloud Forensics And Critical Criteria For Cloud Forensic Capability: A Preliminary Analysis,
2011
University College Dublin
Survey On Cloud Forensics And Critical Criteria For Cloud Forensic Capability: A Preliminary Analysis, Keyun Ruan, Ibrahim Baggili, Joe Carthy, Tahar Kechadi
Electrical & Computer Engineering and Computer Science Faculty Publications
In this paper we present the current results and analysis of the survey “Cloud forensics and critical criteria for cloud forensic capability” carried out towards digital forensic experts and practitioners. This survey was created in order to gain a better understanding on some of the key questions of the new field - cloud forensics - before further research and development. We aim to understand concepts such as its definition, the most challenging issues, most valuable research directions, and the critical criteria for cloud forensic capability.
Cat Detect (Computer Activity Timeline Detection): A Tool For Detecting Inconsistency In Computer Activity Timelines,
2011
Zayed University
Cat Detect (Computer Activity Timeline Detection): A Tool For Detecting Inconsistency In Computer Activity Timelines, Andrew Marrington, Ibrahim Baggili, George Mohay, Andrew Clark
Electrical & Computer Engineering and Computer Science Faculty Publications
The construction of timelines of computer activity is a part of many digital investigations. These timelines of events are composed of traces of historical activity drawn from system logs and potentially from evidence of events found in the computer file system. A potential problem with the use of such information is that some of it may be inconsistent and contradictory thus compromising its value. This work introduces a software tool (CAT Detect) for the detection of inconsistency within timelines of computer activity. We examine the impact of deliberate tampering through experiments conducted with our prototype software tool. Based on the …
Penetration Of Zigbee-Based Wireless Sensor Networks,
2011
Edith Cowan University
Penetration Of Zigbee-Based Wireless Sensor Networks, Michael N. Johnstone, Jeremy A. Jarvis
Australian Information Warfare and Security Conference
Wireless Sensor Networks are becoming popular as a simple means of collecting data by public utilities, motor vehicle manufacturers and other organisations. Unfortunately the devices on such networks are often insecure by default, which presents problems in terms of the integrity of the data provided across those networks. This paper explores a range of attacks that were successful on a network consisting of nodes using the ZigBee protocol stack and proposes defences that can be put in place to circumvent these attacks thus leading to more secure systems and increasing user confidence.
A Proposal For Utilising Active Jamming For The Defence Of Rfid Systems Against Attack,
2011
Edith Cowan University
A Proposal For Utilising Active Jamming For The Defence Of Rfid Systems Against Attack, Christopher Bolan
Australian Information Security Management Conference
With a range of documented attacks against RFID systems a majority of the current literature is focused on the encryption of the communication. This paper addresses such attacks by proposing alternative means of protection through utilising some of the same methods that may be used to attack these systems. The proposed methods would allow for increased security within a range of RFID applications whilst still allowing for normal operations compliant with the relevant standards.
User Perceptions Of End User License Agreements In The Smartphone Environment,
2011
Edith Cowan University
User Perceptions Of End User License Agreements In The Smartphone Environment, Hamish Cotton, Christopher Bolan
Australian Information Security Management Conference
With the increasing usage of smartphones as a computing platform has come alongside the movement of End User License Agreements to such platforms. The smartphone platform brings new issues to these agreements especially with the advent of app stores, which allow access to a large consumer base to small or unknown developers. This survey conducted in Perth, Western Australia looked at user perceptions of EULAs on smartphone devices. The results show that a majority of users do not read such agreements citing issues of readability and length. Even amongst those that do read the agreements there is a majority feeling …
A Longitudinal Study Of Wi-Fi Access Point Security Inthe Perth Central Business District,
2011
Edith Cowan University
A Longitudinal Study Of Wi-Fi Access Point Security Inthe Perth Central Business District, Emil Jacobson, Andrew Woodward
Australian Information Security Management Conference
This study collected data in 2008 and 2011 in relation to the level of apparent security of wireless network access points in the Perth CBD. It also compared this data to a comparable study conducted in 2004. The aim was to determine whether businesses were using an appropriate level of encryption to protect their wireless networks. A pre-determined route was followed which traced the Perth CBD and the open source wireless network auditing tool Kismet was used to survey the wireless networks. In 2008, approximately 1300 access points were discovered in the Perth CBD, this number climbing to approximately 3400 …
Modelling Misuse Cases As A Means Of Capturing Security Requirements,
2011
Edith Cowan University
Modelling Misuse Cases As A Means Of Capturing Security Requirements, Michael N. Johnstone
Australian Information Security Management Conference
Use cases as part of requirements engineering are often seen as an essential part of systems development in many methodologies. Given that modern, security-oriented software development methods such as SDL , SQUARE and CLASP place security at the forefront of product initiation, design and implementation, the focus of requirements elicitation must now move to capturing security requirements so as not to replicate past errors. Misuse cases can be an effective tool to model security requirements. This paper uses a case study to investigate the generation of successful misuse cases by employing the STRIDE framework as used in the SDL.
Australian Primary Care Health Check: Who Is Accountable For Information Security?,
2011
Edith Cowan University
Australian Primary Care Health Check: Who Is Accountable For Information Security?, Rachel J. Mahncke, Patricia A H Williams
Australian Information Security Management Conference
Primary healthcare in Australia is vulnerable to a multitude of information security threats and insecure practices. This situation is increasingly important in the developing e-health environment. Information security is everyone’s responsibility and it is extensively documented in international standards and best practice frameworks, that this responsibility should be part of formal job descriptions. This necessitates incorporation of security at a functional level for all staff. These responsibilities are integral to demonstrable accountability, together with an authority to take action. Indeed, whilst senior management will ultimately be held accountable, staff need to be aware of the potential issues, given the responsibility …
An Exploratory Study Of Erm Perception In Oman And Proposing A Maturity Model For Risk Optimization,
2011
Coventry University, United Kingdom
An Exploratory Study Of Erm Perception In Oman And Proposing A Maturity Model For Risk Optimization, Arun N. Shivashankarappa, D Ramalingam, Leonid Smalov, N Anbazhagan
Australian Information Security Management Conference
Enterprise Risk management is a process vital to enterprise governance which has gained tremendous momentum in modern business due to the dynamic nature of threats, vulnerability and stringent regulatory requirements. The business owners have realized that, risk creates opportunity which in turn creates value. Identifying and mitigating risk proactively across the enterprise is the purview of Enterprise Risk Management (ERM).However, key errors in the ERM process such as misinterpretation of statistical data, overlooking change management, inadequate attention to supply chain interdependencies, excessive trust of insiders and business partners, ambiguous grouping of risks and poor documentation has contributed significantly to the …
Efficient And Expressive Fully Secure Attribute-Based Signature In The Standard Model,
2011
University of Shanghai for Science and Technology
Efficient And Expressive Fully Secure Attribute-Based Signature In The Standard Model, Piyi Yang, Tanveer A. Zia, Zhenfu Cao, Xiaolei Dong
Australian Information Security Management Conference
Designing a fully secure (adaptive-predicate unforgeable and perfectly private) attribute-based signature (ABS), which allows a signer to choose a set of attributes in stead of a single string representing the signer‘s identity, under standard cryptographic assumption in the standard model is a challenging problem. Existing schemes are either too complicated or only proved in the generic group model. In this paper, we present an efficient fully secure ABS scheme in the standard model based on q-parallel BDHE assumption which is more practical than the generic group model used in the previous scheme. To the best of our knowledge, our scheme …
Let's Not Kill All The Privacy Laws (And Lawyers),
2011
Indiana University Maurer School of Law
Let's Not Kill All The Privacy Laws (And Lawyers), Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Privacy -- An Elusive Concept,
2011
Indiana University Maurer School of Law
Privacy -- An Elusive Concept, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Editorial,
2011
Indiana University Maurer School of Law
Editorial, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
A Comparison Of Forensic Evidence Recovery: Techniques For A Windows Mobile Smart Phone,
2011
University of Nebraska at Omaha
A Comparison Of Forensic Evidence Recovery: Techniques For A Windows Mobile Smart Phone, George Grispos, Tim Storer, William Bradley Glisson
Interdisciplinary Informatics Faculty Publications
Acquisition, decoding and presentation of information from mobile devices is complex and challenging. Device memory is usually integrated into the device, making isolation prior to recovery difficult. In addition, manufacturers have adopted a variety of file systems and formats complicating decoding and presentation.
A variety of tools and methods have been developed (both commercially and in the open source community) to assist mobile forensics investigators. However, it is unclear to what extent these tools can present a complete view of the information held on a mobile device, or the extent the results produced by different tools are consistent.
This paper …
Forensic Analysis Of Plug Computers,
2011
University of Central Florida
Forensic Analysis Of Plug Computers, Scott Conrad, Greg Dorn, Philip Craiger
Publications
A plug computer is essentially a cross between an embedded computer and a traditional computer, and with many of the same capabilities. However, the architecture of a plug computer makes it difficult to apply commonly used digital forensic methods. This paper describes methods for extracting and analyzing digital evidence from plug computers. Two popular plug computer models are examined, the SheevaPlug and the Pogoplug.
Moving Forward Together,
2011
Indiana University Maurer School of Law
Moving Forward Together, Fred H. Cate, Christopher Kuner, Christopher Millard, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Column: File Cabinet Forensics,
2011
Naval Postgraduate School, California
Column: File Cabinet Forensics, Simson Garfinkel
Journal of Digital Forensics, Security and Law
Researchers can spend their time reverse engineering, performing reverse analysis, or making substantive contributions to digital forensics science. Although work in all of these areas is important, it is the scientific breakthroughs that are the most critical for addressing the challenges that we face. Reverse Engineering is the traditional bread-and-butter of digital forensics research. Companies like Microsoft and Apple deliver computational artifacts (operating systems, applications and phones) to the commercial market. These artifacts are bought and used by billions. Some have evil intent, and (if society is lucky), the computers end up in the hands of law enforcement. Unfortunately the …
Column: Putting The Science In Digital Forensics,
2011
California Sciences Institute, Fred Cohen & Associates
Column: Putting The Science In Digital Forensics, Fred Cohen
Journal of Digital Forensics, Security and Law
In a recent study, digital forensics was found to lack a consensus around even the most basis notions and terminology of the field. To quote: “These two preliminary studies individually suggest that (1) scientific consensus in the area of digital forensic evidence examination is lacking in the broad sense, but that different groups within that overall community may have limited consensus around areas in which they have special expertise, and (2) that the current peerreviewed publication process is not acting to bring about the sorts of elements typically found in the advancement of a science toward such a consensus. ... …
Technology Corner: Internet Packet Sniffers,
2011
University of New Mexico
Technology Corner: Internet Packet Sniffers, Nick V. Flor, Kenneth Guillory
Journal of Digital Forensics, Security and Law
The best way to understand an internet packet sniffer, hereafter “packet sniffer”, is by analogy with a wiretap. A wiretap is a piece of hardware that allows a person to eavesdrop on phone conversations over a telephone network. Similarly, a packet sniffer is a piece of software that allows a person to eavesdrop on computer communications over the internet. A packet sniffer can be used as a diagnostic tool by network administrators or as a spying tool by hackers who can use it to steal passwords and other private information from computer users. Whether you are a network administrator or …
