
Recently, RFID technology has become one of essential technologies, which applies to a wide area of applications such as logistic, manufacture and pharmacy. Testing of RFID middleware is a critical process to increase stability of RFID system. As it requires much money to use a real RFID reader, a virtual reader to emulate an RFID reader is necessary. To emulate a physical reader, it is necessary to consider the reader’s operational characteristics as well as protocol-level emulation. In this paper, we propose a mechanism for a virtual RFID reader which closely emulates an RFID reader by considering communicational characteristics between the reader and RFID tags. To do this, we analyze characteristics of RF communications and parameterize them. Based on the parameters, we present a mechanism for the virtual reader. The experimental results show that our approach can emulate more similar to RFID physical reader using set parameters.
Journaling file systems are widely used file systems to guarantee data integrity. However, the system performance is degraded due to data request fragmentations. We propose a technique that efficiently handles fragmented data workloads in journaling file system, which we call De-Fragmented Writeback(DFW). The first method of the DFW sorts write orders of the atomic data set in accordance with their disk block numbers before issuing into write requests. The second method of the DFW searches for data fragments in the sorted data set and tries to fill up holes between adjacent data fragments using dirty blocks in main memory. The filling of holes between data fragments converts fragmented data blocks into sequential ones so that this method lowers the number of write requests and reduces unnecessary disk-head movements to write the blocks.
Steganography provides secure communications over the Internet with a cover image. However, it is difficult to transfer many messages with small-sized images. We have improved EMD (Exploiting Modification Direction), proposed by Zhang and Wang, to solve this problem. In this paper, we have developed a (2 n + 2-1)-ary scheme. Our scheme shows a higher embedding rate, R=log2(2 n + 2-1)/n, which is greater than that of the EMD scheme, because the EMD scheme embedding rate is R=log2(2n+1)/n, for n>=2. The experimental results show that our scheme is able to embed twice as many secret bits in multimedia communications compared to the existing EMD embedding method. Our method has low complexity and achieves higher embedding performance with good perceptual quality against the earlier arts. An experiment verified our proposed data hiding method in multimedia communications.
As the recent growth of RFID technologies, a goal of productivity has been achieved in various industry areas where the technologies are used. With this change, a number of RFID logistics systems have been studied, and various standard systems also have been proposed. However, in the storage stage as a part of logistics process, the environmental characteristics on goods, i.e. the sensor technology is not studied to put together with. A system in which status information is processed with the existing sensor nodes has been developed a lot. But in the sensor node system, the nodes are put on specific locations, and the sensor sends sensing information on a large space. Thus, the system is inappropriate for that environment that a temperature-sensitive product has to be checked thoroughly down to a tiny section. To solve this problem, as a part of the smart logistics system, the smart storage modeling technology with sensor tags used is suggested in this paper. With the suggested technology, the space limit problem of sensor node based storage will be solved.
Data sharing agreements are a common mechanism by which enterprises can legalise and express acceptable circumstances for the sharing of information and digital assets across their administrative boundaries. Such agreements, often written in some natural language, are expected to form the basis for the low-level policies that control the access to and usage of such digital assets. This paper contributes to the problem of expressing data sharing requirements in security policy languages such that the resulting policies can enforce the terms of a data sharing agreement. We extend one such language, SecPAL, with constructs for expressing permissions, obligations, penalties and risk, which often occur as clauses in a data sharing agreement.
The spatial co-location pattern represents the relationships between spatial features that are frequently located close together, and is one of the most important concepts in spatial data mining. The spatial co-location pattern mining approach, which is based on association analysis and uses maximal cliques as input data, is general and useful. However, there are no algorithms that can generate all maximal cliques from large dense spatial data sets in polynomial execution time. We propose a polynomial algorithm called AGSMC to generate all maximal cliques from general spatial data sets; including an enhanced existing materializing method to extract neighborhood relationships between spatial objects, and a tree-type data structure to express maximal cliques. AGSMC constructs the tree-type data structures using the materializing method, and generates maximal cliques by scanning the constructed trees. AGSMC can support the spatial co-location pattern mining efficiently, and is also useful for listing maximal cliques of graph whose vertexes are a geometric object.
Multimedia applications have made their way to the wireless/mobile world and this is not likely to change. However, people have not stopped using multimedia services through wired networks and this is also something that is not foreseen to change. What really is changing in the coming networks is the separation of network and service providers; this separation is creating new security challenges since the end user does not have the same trust relationships with all these providers. This paper proposes an architecture for protecting end users from untrusted and unreliable multimedia service providers in Next Generation Networks (NGNs) that utilize the IP Multimedia Subsystem (IMS) for multimedia delivery. Our proposal is based on the Usage Control (UCON) model for monitoring continuously the multimedia content delivered to the end user and ensure that it is the proper content requested by the user.
When a forensic investigation is carried out in the enterprise environment, most of the important data is stored in database servers, and data stored in them are very important elements for a forensic investigation. As for database servers with such data stored, there are over 10 various kinds, such as SQL Server, Mysql and Oracle. All the methods of investigating a database system are important, but this study suggests a single methodology likely to investigate all the database systems while considering the common characteristics of database system. A method of detecting a server, data acquiring and investigating data in the server can be usefully used for such an investigation in the enterprise environment. Therefore, such a methodology will be explained through a way of carrying out a forensic investigation on SQL Server Database of Microsoft Corporation.
As a diverse range of smartphones has been recently developed, the use of smartphones is being dramatically increased. The use of smartphones allowed many tasks to be done at smartphones, which used to require the use of computers. Especially, along with the increase in smartphone use, the users of SNS (Social Network Service) also have been sharply increased. The SNS saves a variety of information such as exchanged pictures and videos, voice mails or location sharing, chat history, etc. as well as simple user data, so that the acquisition of data that are useful in the aspect of digital forensic is achievable. This thesis reviews the types of SNS that are available for the iPhone, a recent example of highly used smartphones, and studies the data to be collected by client and the analysis methods accordingly.
Network data sets are often used for evaluating the performance of intrusion detection systems and intrusion prevention systems[1]. The KDD CUP 99’ data set, which was modeled after MIT Lincoln laboratory network data has been a popular network data set used for evaluation network intrusion detection algorithm and system. However, many points at issues have been discovered concerning the modeling method of the KDD CUP 99’ data. This paper proposed both a measure to compare the similarities between two data groups and an optimization method to efficiently modeled data sets with the proposed measure. Then, both similarities between KDD CUP 99’ and MIT Lincoln laboratory data that between our composed data set from the MIT Lincoln laboratory data and MIT Lincoln laboratory are compared quantitatively.
The distributed software paradigms of grid and cloud computing offer massive computational power at commodity prices. Unfortunately, a number of security risks exist. In this paper we propose a software architecture which leverages the Trusted Computing principle of Remote Attestation to assess the trustworthiness of nodes in computing clouds. We combine hardware-security based on the Trusted Platform Module and Intel Trusted Execution Technology with an integrity-guaranteeing virtualization platform. Cloud services are offered by an easy-to-use Java middleware that performs role based access control and trust decisions hidden from the developer.
Malformed messages in different protocols pose a serious threat because they are used to remotely launch malicious activity. Furthermore, they are capable of crashing servers and end points, sometimes with a single message. Recently, it was shown that a malformed SMS can crash a mobile phone or gain unfettered access to it. In spite of this, little research has been done to protect mobile phones against malformed SMS messages. In this paper, we propose an SMS malformed message detection framework that extracts novel syntactical features from SMS messages at the access layer of a smart phone. Our framework operates in four steps: (1) it analyzes the syntax of the SMS protocol, (2) extracts syntactical features from SMS messages and represents them in a suffix tree, (3) uses well-known feature selection schemes to remove the redundancy in the features’ set, and (4) uses standard distance measures to raise the final alarm. The benefit of our framework is that it is lightweight-requiring less processing and memory resources-and provides a high detection rate and small false alarm rate. We evaluated our system on a real-world SMS dataset consisting of more than 5000 benign and malformed SMS messages. The results of our experiments demonstrated that our framework achieves a detection rate of more than 99% with a false alarm rate of less than 0.005%. Last, but not least, its processing and memory requirements are relatively small; as a result, it can be easily deployed on resource-constrained smart phones or mobile devices.
In this paper we survey existing work on automatically processing legal, regulatory and other policy texts for the extraction and representation of privacy knowledge and rules. Our objective is to link and apply some of these techniques to policy enforcement and compliance, to provide a core means of achieving and maintaining customer privacy in an enterprise context, particularly where data is stored and processed in cloud data centres. We sketch our thoughts on how this might be done given the many different, but so far strictly distinct from one another, approaches to natural-language analysis of legal and other prescriptive texts, approaches to knowledge extraction, semantic representation, and automated enforcement of privacy rules.
Today, computer users have trouble in separating malicious and legitimate software. Traditional countermeasures such as anti-virus tools mainly protect against truly malicious programs, but the situation is complicated due to a ”grey-zone” of questionable programs that are difficult to classify. We therefore suggest a software reputation system (SRS) to help computer users in separating legitimate software from its counterparts. In this paper we simulate the usage of a SRS to investigate the effects that malicious users have on the system. Our results show that malicious users will have little impact on the overall system, if kept within 10% of the population. However, a coordinated attack against a selected subset of the applications may distort the reputation of these applications. The results also show that there are ways to detect attack attempts in an early stage. Our conclusion is that a SRS could be used as a decision support system to protect against questionable software.
Vehicular Ad hoc NETworks (VANETs) were proposed to improve driving safety. In VANETs vehicles communicate with other vehicles and with the infrastructure’s Road Side Units (RSUs) to achieve this safety. 5.9 GHz band was assigned by FCC for the use of VANETs in Dedicated Short Range Communications (DSRC) [1]. VANETs’ security has been a hot topic since the very first day of its announcement. While IEEE 1609.2 is setting security standards for VANETS, many researches around the world are working hard to provide an ideal system. IEEE 1609.2 chose Public Key Infrastructure (PKI) to be used in VANETs [2]. PKI comes with its inherent issues such as key management and Certificate revocation lists (CRLs) in addition to issues related to wireless networks such privacy and linkability. In this paper we propose Exclusion-Based Vanet (EBV), a novel framework based on a combination of PKI and Exclusion Based Systems (EBS) [3] to address the above issues. EBV eliminates the need for CRLs, guarantees privacy and scalability.
We present a strong authentication mechanism intended for embedded systems based on standard but weak processors, without support for cryptographic operations. So far the main effort was to provide methods based on relatively short keys and complex computations. we make advantage of availability of non-volatile memory of larger size and confine ourselves to basic bit operations available on each processor.
Evaluation of RFID middleware is a complex process due to its cost for constructing a test bed involving RFID readers and tags. An input dataset of the RFID middleware is a tag event stream from connected readers. A randomly generated dataset can be considered for stress testing, but this cannot guarantee whether the middleware can provide correct answers on given dataset. To enable this, the dataset should be meaningful to represent tags' activities based on business rules. This paper presents an RSN Tool which generates semantic datasets based on tags' behavior. The basic idea is to virtualize RFID environments in a point of business processes. To do this, the RSN Tool provides a modeling of real world RFID environments using graph representations, and execution mechanisms of tags' movements under several business rules. The experimental result shows that the RSN Tool can create a semantic valid dataset which reflects tags' behavior.
Data-sharing agreements across organisations are often used to derive security policies to enforce the access, usage and routing or data across different trust and administrative domains. The data exchanged is usually annotated with metadata to describe its meaning in different applications and contexts, which may be used by the enforcement points of such data-sharing policies. In this paper, we present a metadata model for describing data-centric security, i.e. any security information that may be used to annotate data. Such metadata may be used to describe attributes of the data as well as their security requirements. We demonstrate an applicability scenario of our model in the context of organisations sharing scientific data.
In this paper, we study the problem of finding the top-k most frequent itemsets in data streams. To only mine top-k restricted to the sub-domains of the workspace or the result of some query. Most previous algorithms are clearly not suitable for this problem with limited memory, such as for instance, an allocated for each stream summary. Therefore, we propose that in order to solve memory efficiency for mining frequent itemsets from massively and speedy a data stream. Our algorithm is used to a bloom filter structure, named MineTop-k, which permit the efficient computation and maintenance of the results. We show that our approach is memory-efficient method for the top-k problem.
RFID technology is being applied to the wide field of distributions and logistics for item-level tracking of tagged goods. Recently, spoilage and abnormalities of product in Blood Supply Chain (BSC), Cold Chain Management (CCM) and Hazardous Materials (HAZMAT) Management become issues. To monitor item's health status is as a crucial issue as to keep track of the item. By augmenting passive RFID tags with sensor nodes, we can easily extend existing RFID systems and reduce operational cost. However, this approach will suffer from high overhead for joining two streaming data in real time. To address this problem, we propose a scheme for continuous query processing to monitor sensing information of tagged items in real-time. It makes integrated stream data from each stream data. And we summarize integrated stream data using MBR, and we make summarized data. It requires comparing the summarized data with registered queries. Finally, we do query processing between integrated stream data and matched query. Experimental results show that our method can handle both RFID tag data and sensing information efficiently.