Html5 Zero Configuration Covert Channels: Security Risks And Challenges,
2015
School of Computer Science & Informatics, University College Dublin, Ireland
Html5 Zero Configuration Covert Channels: Security Risks And Challenges, Jason Farina, Mark Scanlon, Stephen Kohlmann, Nhien-An Le-Khac, Tahar Kechadi
Annual ADFSL Conference on Digital Forensics, Security and Law
In recent months there has been an increase in the popularity and public awareness of secure, cloudless file transfer systems. The aim of these services is to facilitate the secure transfer of files in a peer-to-peer (P2P) fashion over the Internet without the need for centralized authentication or storage. These services can take the form of client installed applications or entirely web browser based interfaces. Due to the P2P nature, there is generally no limit to the file sizes involved or to the volume of data transmitted - and where these limitations do exist they will be purely reliant on …
Measuring Hacking Ability Using A Conceptual Expertise Task,
2015
School of Business, University at Albany
Measuring Hacking Ability Using A Conceptual Expertise Task, Justin S. Giboney, Jeffrey G. Proudfoot, Sanjay Goel, Joseph S. Valacich
Annual ADFSL Conference on Digital Forensics, Security and Law
Hackers pose a continuous and unrelenting threat to organizations. Industry and academic researchers alike can benefit from a greater understanding of how hackers engage in criminal behavior. A limiting factor of hacker research is the inability to verify that self-proclaimed hackers participating in research actually possess their purported knowledge and skills. This paper presents current work in developing and validating a conceptual-expertise based tool that can be used to discriminate between novice and expert hackers. The implications of this work are promising since behavioral information systems researchers operating in the information security space will directly benefit from the validation of …
Invited Paper - A Profile Of Prolonged, Persistent Ssh Attack On A Kippo Based Honeynet,
2015
Security Research Institute, Edith Cowan University
Invited Paper - A Profile Of Prolonged, Persistent Ssh Attack On A Kippo Based Honeynet, Craig Valli, Priya Rabadia, Andrew Woodard
Annual ADFSL Conference on Digital Forensics, Security and Law
This paper is an investigation focusing on activities detected by SSH honeypots that utilised kippo honeypot software. The honeypots were located across a variety of geographical locations and operational platforms. The honeynet has suffered prolonged, persistent and attack from a /24 network which appears to be of Chinese geographical origin. In addition to these attacks, other attackers have been successful in compromising real hosts in a wide range of other countries that were subsequently involved in attacking the honeypot machines in the honeynet.
Keywords: Cyber Security, SSH, Secure Shell, Honeypots, Kippo
Inivited Paper - Potential Changes To Ediscovery Rules In Federal Court: A Discussion Of The Process, Substantive Changes And Their Applicability And Impact On Virginia Practice,
2015
California U of Pennsylvania, United States
Inivited Paper - Potential Changes To Ediscovery Rules In Federal Court: A Discussion Of The Process, Substantive Changes And Their Applicability And Impact On Virginia Practice, Joseph J. Schwerha, Susan L. Mitchell, John W. Bagby
Annual ADFSL Conference on Digital Forensics, Security and Law
The Federal Rules of Civil Procedure (FRCP) are subject to a unique process also once used in revising the Federal Rules of Evidence (FRE). Today, this process is followed in revisions of the FRCP, the Federal Rules of Criminal Procedure and the Federal Bankruptcy Rules. This unique rulemaking process differs significantly from traditional notice and comment rulemaking required for a majority of federal regulatory agencies under the Administrative Procedure Act (APA).1 Most notably, rule-making for the federal courts’ procedural matters remain unaffected by the invalidation of legislative veto. It is still widely, but wrongly believed, that the legislative veto was …
On The Network Performance Of Digital Evidence Acquisition Of Small Scale Devices Over Public Networks,
2015
Department of Computer and Systems Sciences, Stockholm University
On The Network Performance Of Digital Evidence Acquisition Of Small Scale Devices Over Public Networks, Irvin Homem, Spyridon Dosis
Annual ADFSL Conference on Digital Forensics, Security and Law
While cybercrime proliferates – becoming more complex and surreptitious on the Internet – the tools and techniques used in performing digital investigations are still largely lagging behind, effectively slowing down law enforcement agencies at large. Real-time remote acquisition of digital evidence over the Internet is still an elusive ideal in the combat against cybercrime. In this paper we briefly describe the architecture of a comprehensive proactive digital investigation system that is termed as the Live Evidence Information Aggregator (LEIA). This system aims at collecting digital evidence from potentially any device in real time over the Internet. Particular focus is made …
A Review Of Recent Case Law Related To Digital Forensics: The Current Issues,
2015
Department of Computer and Information Technology, Purdue University
A Review Of Recent Case Law Related To Digital Forensics: The Current Issues, Kelly A. Cole, Shruti Gupta, Dheeraj Gurugubelli, Marcus K. Rogers
Annual ADFSL Conference on Digital Forensics, Security and Law
Digital forensics is a new field without established models of investigation. This study uses thematic analysis to explore the different issues seen in the prosecution of digital forensic investigations. The study looks at 100 cases from different federal appellate courts to analyze the cause of the appeal. The issues are categorized into one of four categories, ‘search and seizure’, ‘data analysis’, ‘presentation’ and ‘legal issues’. The majority of the cases reviewed related to the search and seizure activity.
Keywords: Computer Investigation, Case Law, Digital Forensics, Legal Issues, and Courts
A New Cyber Forensic Philosophy For Digital Watermarks In The Context Of Copyright Laws,
2015
Cyber Forensic Consultant, GJ Software Forensics
A New Cyber Forensic Philosophy For Digital Watermarks In The Context Of Copyright Laws, Vinod P. Bhattathiripad, Sneha Sudhakaran, Roshna K. Thalayaniyil
Annual ADFSL Conference on Digital Forensics, Security and Law
The objective of this paper is to propose a new cyber forensic philosophy for watermark in the context of copyright laws for the benefit of the forensic community and the judiciary worldwide. The paper first briefly introduces various types of watermarks, and then situates watermarks in the context of the ideaexpression dichotomy and the copyright laws. It then explains the forensic importance of watermarks and proposes a forensic philosophy for them in the context of copyright laws. Finally, the paper stresses the vital need to incorporate watermarks in the forensic tests to establish software copyright infringement and also urges the …
A Survey Of Software-Based String Matching Algorithms For Forensic Analysis,
2015
Norwegian Information Security Laboratory, Gjøvik University College
A Survey Of Software-Based String Matching Algorithms For Forensic Analysis, Yi-Ching Liao
Annual ADFSL Conference on Digital Forensics, Security and Law
Employing a fast string matching algorithm is essential for minimizing the overhead of extracting structured files from a raw disk image. In this paper, we summarize the concept, implementation, and main features of ten software-based string matching algorithms, and evaluate their applicability for forensic analysis. We provide comparisons between the selected software-based string matching algorithms from the perspective of forensic analysis by conducting their performance evaluation for file carving. According to the experimental results, the Shift-Or algorithm (R. Baeza-Yates & Gonnet, 1992) and the Karp-Rabin algorithm (Karp & Rabin, 1987) have the minimized search time for identifying the locations of …
Investigating Forensics Values Of Windows Jump Lists Data,
2015
University of North Georgia, Department of Computer Science and Information Systems
Investigating Forensics Values Of Windows Jump Lists Data, Ahmad Ghafarian
Annual ADFSL Conference on Digital Forensics, Security and Law
Starting with Windows 7, Microsoft introduced a new feature to the Windows Operating Systems called Jump Lists. Jump Lists stores information about user activities on the host machine. These activities may include links to the recently visited web pages, applications executed, or files processed. Computer forensics investigators may find traces of misuse in Jump Lists auto saved files. In this research, we investigate the forensics values of Jump Lists data. Specifically, we use several tools to view Jump Lists data on a virtual machine. We show that each tool reveal certain types of information about user’s activity on the host …
An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?,
2015
Cyber Forensics Research and Education Group (UNHcFREG), Tagliatela College of Engineering, ECECS Department, University of New Haven
An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?, Satyendra Gurjar, Ibrahim Baggili, Frank Breitinger, Alice Fischer
Annual ADFSL Conference on Digital Forensics, Security and Law
Hash functions are widespread in computer sciences and have a wide range of applications such as ensuring integrity in cryptographic protocols, structuring database entries (hash tables) or identifying known files in forensic investigations. Besides their cryptographic requirements, a fundamental property of hash functions is efficient and easy computation which is especially important in digital forensics due to the large amount of data that needs to be processed when working on cases. In this paper, we correlate the runtime efficiency of common hashing algorithms (MD5, SHA-family) and their implementation. Our empirical comparison focuses on C-OpenSSL, Python, Ruby, Java on Windows and …
Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations,
2015
National Research Nuclear University Moscow Engineering & Physics Institute (NRNU MEPhI), Department of Cryptology and Discrete Mathematics, Russia
Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations, Igor Korkin
Annual ADFSL Conference on Digital Forensics, Security and Law
Hardware virtualization technologies play a significant role in cyber security. On the one hand these technologies enhance security levels, by designing a trusted operating system. On the other hand these technologies can be taken up into modern malware which is rather hard to detect. None of the existing methods is able to efficiently detect a hypervisor in the face of countermeasures such as time cheating, temporary self-uninstalling, memory hiding etc. New hypervisor detection methods which will be described in this paper can detect a hypervisor under these countermeasures and even count several nested ones. These novel approaches rely on the …
Swords Into Stethoscopes: How The U.S. Military Could Conduct Medical Diplomacy,
2015
Macalester College
Swords Into Stethoscopes: How The U.S. Military Could Conduct Medical Diplomacy, Oliver Kendall
Political Science Honors Projects
Since the early 1960’s, Cuba and China have won international appreciation by sending doctors abroad to help where they are needed. While there was surprise in some quarters when U.S. military personnel were deployed to combat Ebola in the last months of 2014, the Department of Defense actually has a long history of medical activity. In its current form, DoD medical outreach cannot likely garner soft power in the way that the Chinese and Cuban programs can, but with a few modifications, the U.S. military could be a serious conductor of medical diplomacy that would save countless lives and benefit …
Community Safety, Livelihoods And Socio-Economic Development: Karamoja, Uganda,
2015
Geneva International Centre for Humanitarian Demining (GICHD)
Community Safety, Livelihoods And Socio-Economic Development: Karamoja, Uganda, Gichd
Global CWD Repository
Development survey in collaboration with DRC/DDG in the Karamoja region of north-eastern Uganda in December 2014.
This survey:
- identifies which activities appear to have the most positive impact on safety, livelihoods and socio-economic well-being, and why
- identifies any negative impacts on any intended beneficiaries and the reasons for them
- provides recommendations to help DDG improve their activities and impact.
The survey was an excellent opportunity to explore how the GICHD’s landmines and livelihoods surveys can be used for the broader human security sector. The findings and recommendations provide DDG with a better understanding of how linkages between security and livelihoods …
Unisdr Scientific And Technical Advisory Group Case Studies 2015 | The Use Of Geographic Information Systems For Environmental Impact Assessments In Mine Action, Gianluca Maspoli, Angela Desantis
Global CWD Repository
The 'do no harm' approach to mine action requires that mine action organisations consider the possible negative impacts of mine clearance operations. They must ensure they do not lead to longer-term vulnerability or threaten livelihoods and food security and, by mitigating environmental damage, they should contribute to disaster risk reduction. The combined use of remotely sensed data and Geographic Information Systems (GIS) can be a sound solution to assess pre-contamination conditions, monitor both the environmental impact and the effects of mitigation activities, analyse consequences of natural disasters on contamination, and, finally, support an evidence-based decision making process.
The Snowden Effect: The Conflict In A Free Society, Who Values Privacy Versus Who Values Security?,
2015
Bemidji State University
The Snowden Effect: The Conflict In A Free Society, Who Values Privacy Versus Who Values Security?, Matthew C. Blake
Political Science Theses and Capstones
The Obama Administration has come under scrutiny by both the public and Congress, since former National Security Agency (NSA) contractor Edward Snowden made known the scope of government surveillance programs being utilized by the U.S. government to gather intelligence on domestic citizens. Snowden’s disclosures about the government’s surveillance practices to the mainstream media began in June 2013. I focus on how public opinion towards the government’s surveillance practices and an individual’s reasonable right to privacy has shifted after revelations made by Edward Snowden on the practices of the NSA. Individuals may show support for more government surveillance in the name …
Falkland Islands Malvinas Exploitation Report 2015,
2015
James Madison University
Falkland Islands Malvinas Exploitation Report 2015, Fenix- Insight Ltd.
Global CWD Repository
A series of three reports were published by the Demining Programme Office in the Falkland Islands (Malvinas). This report explains that the need for exploitation was recognised early during the planning for mine clearance operations in the Falkland Islands (Malvinas). Little was known about the state of the mines some 30 years after the conflict, and it was considered important to understand the effects of ageing, along with the implications for issues such as appearance/recognition, functionality and detectability. Exploitation was previously carried out during clearance Phases 1 and 3.
This report outlines the work conducted during Phase 4a, where a …
The Cold War: Over, Renewed, Or Never Ended?,
2015
Bemidji State University
The Cold War: Over, Renewed, Or Never Ended?, Matt Phipps
Political Science Theses and Capstones
The Cold War has been studied repeatedly since the war supposedly ended in 1991. However recent events are starting to cause some concern and make many question whether or not the Cold War actually ended, if it took a different shape or perhaps has just been on pause. I argue that the Cold War has been a conflict that has been going on since 1947 and although the conflict has looked differently in recent decades the conflict was never properly put to an end. The research analyzes US decision making with respect to Russian and Asian relations over the last …
National Capacities And Residual Contamination | Mali,
2015
Geneva International Centre for Humanitarian Demining (GICHD)
National Capacities And Residual Contamination | Mali, Gichd
Global CWD Repository
This case study forms part of a broader GICHD study on national capacities and residual contamination and is based on both desk-top research and findings from a GICHD mission to Mali in March 2014. The purpose of the report is to document Mali’s experience of developing national clearance capacities to address residual contamination and to identify and present good practices and lessons learnt.
Kittens And Nutella: Why Women Join Isis,
2015
Gettysburg College
Kittens And Nutella: Why Women Join Isis, Samantha K. Smith
What All Americans Should Know About Women in the Muslim World
On February 18, 2015 CNN published a reported stating that Western women were leaving their homes to join ISIS because of a social media campaign featuring pictures of kittens and Nutella. This reported propagated the notion that women who join jihadist organizations are brainwashed or feeble minded. The reality is not so simple. This paper explores the motives women may have for joining ISIS through comparison to the motivations that drove women to partake in other violent jihadist organizations' activities.
The F-35: Putting Rma Theory To The Test,
2015
University of Kentucky
The F-35: Putting Rma Theory To The Test, Alexander Melynkovych
Ex-Patt Magazine
Will history judge the F-35 as a success or failure? Putting RMA Theory to the test.
