
Many real-world scenarios such as protecting DRM, online payments and usage in NEC payments in embedded devices require a trustworthy "trusted execution environment" (TEE) platform. The TEE should run on the ARM architecture. That is popular in embedded devices. Furthermore, past experience has proved that such TEE platform should be available in source code form. Without the source code 3rd parties and user cannot be conducted code review audit. Lack of review put doubt on the system as a trustworthy environment. The popular Android OS supports various TEE implementations. Each TEL OS implementation has its own unique way of deploying trusted applications(trustlets) and its own distinct features. Choosing a proper TEE operating system can be a problem for trust applications developers. When choosing TEE applications developers has many conflicting goals. The developers attempt to ensure that their apps work on as many different Android devices as possible. Furthermore, developers relay on the TEE for certain features and must ensure the suggested TEE provides all the features that they need. We survey multiple ARM TrustZone TEE operating systems that are commonly available and in use today. We wish to provide all the information for IoT vendors and SoC manufacturer to select a suitable TEE.
Microsoft windows is a family of client and server operating systems that needs no introduction. Microsoft windows operating system family has a feature to handle exceptions by storing in the stack the address of an exception handler. This feature of Microsoft Windows operating system family is called SEH (Structured exception handlers). When using SEH the exception handler address is specifically located on the stack like the function return address. When an exception occurs the address acts as a trampoline and the EIP jumps to the SEH address. By overwriting the stack one can create a unique type of return oriented programming (ROP) exploit that force the instruction pointer to jump to a random memory address. This memory address may contain random malicious code. Multiple Microsoft Windows applications are particularly vulnerable to this type of exploit. Attacks on Microsoft Window application that exploit these mechanisms are found in many common windows applications (including Microsoft Office, Adobe Acrobat, Flash and other popular software). These attacks are well documented in CVE database in numerous exploits. We previously described how hypervisors can be used to white list an end point and provide application control fora workstation and servers and protect against malware and viruses that may run on the end point computer. In this work we extend the protection mechanism for end points and servers that uses the hypervisor to white list the machine. The hypervisor detects permission elevation from user space to kernel space (system calls invocation) and detects anomalies in the software execution. The hypervisor based mechanism allows for detection and prevention of SEH return oriented exploits execution. Our hypervisor based SEH-exploit prevention mechanism was tested on multiple well documented CVE vulnerabilities. Our hypervisor was found to prevent a large collection of different types of SEH exploits in multiple applications and multiple flavours and versions of Windows OS in both 32 and 64 bit environments
There are currently many research projects underway concerning the intelligent transport system (ITS), with the intent to develop a variety of communication solutions between vehicles, roadside stations and services. In the near future, the roll-out of 5G networks will improve short-range vehicle-to-vehicle traffic and vehicle-to-infrastructure communications. More extensive services can be introduced due to almost non-delayed response time. Cyber security is central for the usability of the services and, most importantly, for car safety. The Controller Area Network (CAN) is an automation bus that was originally designed for real-time data transfer of distributed control systems to cars. Later, the CAN bus was developed as a universal automation system for many automation solutions. One of its characteristics is that bus traffic is not supervised in any way due to the lack of timing of control. In other words there are no authentication mechanism. This article highlights different approaches and their usability to reveal the car's CAN bus malfunctions. The study complements earlier studies on the safety of vehicles in the CAN bus. Based on the test results, practical methods can be evaluated to detect changes in CAN bus traffic, such as targeted cyber-attacks. The article is based on the results of a study on the cybersecurity of cars conducted at the University of Jyvaskyla (AaTi study). Initially, the AaTi study attempted to identify the message content of the bus and to detect interferences via the Neural network solution. However, the problem with the neural network was the computational performance required and the lack of prediction accuracy. After that the study was focused on experiments that were based on the arrival times of control messages, that is, their timing-based intrusion detection. In this sense the research did concentrate on kernel density estimation, one-class support vector machine solution, absolute deviation method and categorization. Due to methodological challenges, a method for detecting intrusions based on statistical processing of message traffic was ultimately developed as an outcome of the study.
The Internet is used increasingly as a platform both for free expression and e-commerce. Internet users have a variety of attitudes towards the security and privacy risks involved with using the Internet; and distinct concerns and behaviors with regard to expressing themselves online. Users may have controversial viewpoints that they may express online in various ways. Controversial viewpoints or artwork by their nature may not be as well received as positive or polite expressions. In the online environment, users with controversial viewpoints may be reluctant to express the viewpoints due to concern about possible consequences resulting from the expressions. Consequences may be imposed by individuals, groups, organizations, businesses, or nation-states. Examples of such consequences include firings, removal of forum posting privileges ("banning"), violent attacks, online stalking, and doxing. Users may also have different attitudes towards personal spending of money for cybersecurity products and services. Factors such as concern about the risks associated with free expression online may impact their attitudes towards spending for personal cybersecurity. We perform a factor analysis on survey data. Our goal is to establish variables for expression reluctance, and attitude towards personal cybersecurity purchasing. The positive attitude toward spending on personal cybersecurity, as a factor, includes reported activity of purchasing cybersecurity products or services, and an overall generally positive attitude toward the purchasing of such products or services. We propose a research model that enables an analysis of the relationship between the reluctance to make controversial expressions online and a positive attitude toward spending money on personal cybersecurity products and services. We perform a correlation analysis between the factors. Results indicate that there is a correlation between users' reluctance to express controversial messages online, and a positive attitude towards spending money on personal cybersecurity. Future work will include additional analyses, including the effects of various demographic factors.
There is fundamental need in EU-level to develop common alarm procedures and emergency response models with preventive functions which work well from local to national level and from national to international level. European Public Protection and Disaster Relief (PPDR) services such as law enforcement, firefighting, emergency medical and disaster recovery services have recognized that lack of interoperability of technical systems limits cooperation between the PPDR authorities. Also, the military (MIL) and critical infrastructure protection (CIP) faces similar challenges. Recent major accidents have indicated that lack of human resources affects to disaster recovery. PPDR-actors cannot start operations, if there is a human factor preventing the flow of information. Preventing a domino effect after a disaster may be delayed. There is a need to understand how public safety authorities can act in a preventive manner so that a potential accident or offense can be prevented in advance. This paper's goal is to find out main factors which affect to implementing of the next generation hybrid emergency response system for critical infrastructure protection. Early detection of any threat and rapid response to neutralize the threat may help to save human lives and vital functions before any disaster occurs. By comparing present emergency response processes to the next generation Smart hybrid emergency process model, it can be found effects and factors which prevent to implement this architecture. For example, legislation, organizational changes, lack of using cyber dimension and emergency procedures effects to combine different kind of PPDR-functions. Cyber dimension as a part of situational awareness raises its value for the continuity management. For traditional purposes, PPDR services are being seen as separate physical operational functions. This study proposes to solve the problems of development needs through technical, organizational and structural alternatives. The main issue regarding dividing reliable decision support information to decision-makers is related to at which point in chain-reaction a human action is more harmful than useful. It has been seen in earlier empirical studies that human activities may prevent to manage functions of essential emergency response procedures during a disaster. It's necessary to create emergency response model, that will be functionally capable and modern combining cyber and physical elements in a right proportion.
Information security is concerned with the protection of information, which can be stored, processed or transmitted within the critical information systems from organizations, against loss of confidentiality, integrity or availability. Protection measures to prevent these problems result through the implementation of controls at several dimensions: technical, administrative or physical. A vital objective for military organizations is to ensure superiority in contexts of information warfare and competitive intelligence. Therefore, the problem of information security in military organizations has been a topic of intensive work at both national and transnational levels, and extensive conceptual and standardization work is being produced. A current effort is to develop automated decision support systems to assist military decision makers, at different levels in the command chain, to provide suitable control measures that can effectively deal with potential attacks and, at the same time, prevent, detect and contain vulnerabilities targeted at their information systems. The concept and processes of the Case-Based Reasoning (CBR) methodology outstandingly resembles classical military processes and doctrine, in particular the analysis of "lessons learned" and definition of "modes of action". Therefore, the present paper addresses the modeling and design of a CBR system with two key objectives: to support an effective response in context of information security for military organizations; to allow for scenario planning and analysis for training and auditing processes.
In 2007 Estonia was faced with a new type of international violence that was difficult to conceptualise. Characterisations of the cyber attacks by Estonian officials at the time ranged from war, crime to terrorism. The technological makeup of cyberspace led to a range of problems for the traditional distinctions between these categories and hence international law was uncertain in its application to this new form of violence. These issues are among those generally discussed in literature on cyber attacks and international law. This literature also tends to follow a typical pattern of writing about law and technology, and arguably this does not result in a developed understanding of the relationship between law and technology. However, another body of literature exists which seeks to understand the intersection of law and technology better by looking at past events where technology created problems for the law, the socio-technical context of the law and the values that law seeks to protect. By adopting the insights from this body of literature, the uncertainties that cyber attacks (technology) creates for law will be explored. Accordingly, it will be shown that cyber attacks create a number of uncertainties for international law. On one level, this new type of violence has created uncertainties in the application of existing law and thus led to legal issues. These are centred around doctrinal issues on state responsibility (particularly attribution) and what constitutes an illegitimate use of force. On another level, they raise uncertainties about the compatibility of law premised upon a technological environment in which state sovereignty is central to regulate behaviour in an environment in which states lack a monopoly of violence and distinctions between the actors inflicting this violence is less clear. Exploring these uncertainties will lead to a more developed appreciation of how technology can shape the way we understand violence in international law.
Hybrid threats use conventional and unconventional means to achieve their goals. In this paper we explore the cyber threats as one possible aspect of hybrid threats. We describe three ways of appro ...
Anomaly detection techniques are used to find the presence of anomalous activities in a network by comparing traffic data activities against a baseline. Although it has several advantages which include detection of zero-day attacks, the question surrounding absolute definition of systems deviations from its behaviour is important to reduce the number of false positives in the system. This study proposes a novel multi-agent network-based framework known as Statistical model for Correlation and Detection (SCoDe), an anomaly detection framework that looks for timecorrelated anomalies by leveraging statistical properties of a large network, monitoring the rate of events occurrence based on their intensity. SCoDe is an instantaneous learning-based anomaly detector, practically shifting away from the conventional technique of having a training phase prior to detection. It does acquire its training using the improved extension of Exponential Weighted Moving Average (EWMA) which is proposed in this study. SCoDe does not require any previous knowledge of the network traffic, or network administrators chosen reference window as normal but effectively builds upon the statistical properties from different attributes of the network traffic, to correlate undesirable deviations in order to identify abnormal patterns. The approach is generic as it can be easily modified to fit particular types of problems, with a predefined attribute, and it is highly robust because of the proposed statistical approach. The proposed framework was targeted to detect attacks that increase the number of activities on the network server, examples which include Distributed Denial of Service (DDoS) and, flood and flash-crowd events. This paper provides a mathematical foundation for SCoDe, describing the specific implementation and testing of the approach based on a network log file generated from the cyber range simulation experiment of the industrial partner of this project.
In 2011 cyberspace came under highly visible military threat. This threat was not cyber-attack by governments or terrorists, but the threat of a militaristic approach to cyber-security. The US and UK military establishments (among others) made strong arguments about the need to expand their online presence from use of the Internet for their own information transmission and into cyber-attack capabilities. Responding to claims of the Russian and Chinese governments sponsoring cracking attacks against Estonia, Georgia and Google, cyberspace in 2011 became the fifth arena of warfare (land, (under)sea, air, space and now cyberspace). Although development of the basic concept and protocols of the Internet was funded by DARPA, a military research agency, the military and civilian uses of Internet systems rapidly diverged in the early days. This separation allowed the development of a free, generative and borderless Internet whose base flexibility and civilian orientation made it one of the core technologies of modern life by 2011. Just as it has become an essential platform for legitimate activity, illegitimate activity has also flourished online. The very automation which makes computers and the Internet so valuable can also be utilised for negative purposes such as Denial of Service Attacks, malware distribution and fraud. There are claims that some governments are sponsoring attacks and cyber-espionage against their enemies (other states or large corporations), and claims about the rise and dangers of cyber-terrorism. Military forces, faced with a diminishing role in preparations for large scale physical conflicts, have begun claiming that civilian cyberspace needs to be (re-)militarised and that the armed forces should be given both the technical tools and the legal rights to conduct not just cyber-defence activities, but offensive cyber-attacks. In this paper we argue from both philosophical and practical standpoints that a pacifist approach to cyber-security is more appropriate. Based on the constitutional pacifism of Germany and Japan, we argue that investment in cyber-defence would be better targetted at improving the physical and electronic infrastructure of the Internet in general (for example, by funding the free distribution of malware signatures to all users or research and development of better technological security tools). This would provide better cyber-security for the citizens of the world than an arms race to develop military cyber-attack capabilities. The borderless and non-geographic topology of the Internet provide little capacity for avoiding collateral damage which, we argue, is likely to prove more costly than the original dangers identified or forecast. Technological measures used within the parameter of laws protecting the privacy, civil rights and civil liberties of citizens and utilized for defensive purposes, along with further research on thwarting cyber-attacks on critical information infrastructures, would be more beneficial and are evaluated in this pacifist context.
In recent years computing has shown an increasing shift towards mobile devices. Smartphones and similar devices such as tablets are becoming more powerful and less expensive every day and as such are becoming more widespread not only in developed, but also in developing countries. Alongside the development of the mobile devices, the internet offers an increasing amount of services for these devices. This evolution of mobile devices from simple telephones to portable computers as well as their increased interconnectivity however also made them more prone to security issues. As such secret services around the world are given more possibilities and opportunities to use these mobile devices for espionage and widespread surveillance. The recent leak of cables sent by US embassies around the world also known as the 'cablegate' gives us an opportunity to get a better understanding of this issue. In the light of these events we tried to measure to which extent US have spied on European companies, especially one of the leading manufacturers of mobile devices around the world, Nokia. We set up a database and preprocessed the embassy messages to allow us to search through the huge amount of data in short time. We then investigated Nokia's fields of business to find possible contact points to special agencies. Additionally we looked for other reasons why special agencies might have a specific interest in Nokia. With this information we analyzed the data. The analysis clarifies two major key points: Firstly it validated the assumption that mobile devices, even civil ones, play an important role in modern warfare. They are used not only by US special agents, but also by guerrilla forces to coordinate military operations. Secondly Nokia is a main competitor to American companies in the fastest growing markets worldwide, such as India and China. This paper intends to present the results and the main conclusion of our analysis.
Linguistics is not a traditional method used in the security studies. However, today's world, and the information society are ever more based on texts and images. Also, both the sense of security and a threat are produced with language at the first place. For this reason, the study of a discourse used in a conflict is of vital importance. The present paper will deal with the political debate in favour of Italy's participation in the Iraq war in the spring of 2003, as it is represented in one of Italy's most important newspapers, Il Corriere della Sera. In using the term 'representation' I mean the interpretation of a given phenomenon with language. According to the method of critical linguistics elaborated by Roger Fowler, Robert Hodge and Gunther Kress, and based on the functional grammar of M. A. K. Halliday, I shall analyse the vocabulary and naming of different elements related to warfare, and transitivity; I will examine the choice of agents and affected participants and types of predicates to which they are related, as well as the argumentation strategies. In conclusion, I shall show how the representation of the Iraq war contributes to the creation of and/or emphasis on a specific national Italian identity.
This paper explores the issue of public engagement with cyber security issues and positions it as a key factor in ensuring cyber security. Reported incidents of vigilante hacking are given as examples of the role of the public in cyber security. The case is made that in order to ensure public engagement and to manage the potential threat from vigilante hackers we need more inter-disciplinary academic research and better quality journalism. The role of the public and the link between the state and the public as mediated through cyberspace is used as a case study to set the context. To explore the issue of inter-disciplinary research a brief review of current academic literature is outlined. The topic of better quality journalism is examined using content analysis of newspaper reports focusing on the Stuxnet worm. The paper concludes that at a very basic level without increased academic debate or better quality journalism we will have little to inform our public engagement programme. One area to be addressed that emerges strongly through the research is the need for a lexicon and framework for discussing cyber security. This is necessary, at least at a high level, in order to conceptualise the problems and to support work that crosses academic disciplines. A suggested high level lexicon is presented together with a simple framework to facilitate engagement and debate.
The concept of virtualization is not new but leveraging virtualization in different modes and at different layers has revolutionized its usage scenarios. Virtualization can be applied at application layer to create sandbox environment, operating system layer to virtualize shared system resources (e. g. memory, CPU), at platform level or in any other useful possible hybrid scheme. When virtualization is applied at platform level, the resulting virtualized platform can run multiple virtual machines as if they were physically separated real machines. Provisioning virtualized platforms in this way is often also referred to as Infrastructure-as-a-Service or Platform-as-a-Service when full hosting and application support is also offered. Different business models, like datacenters or telecommunication providers and operators, can get business benefits by using platform virtualization due to the possibility of increased resource utilization and reduced upfront infrastructure setup expenditures. This opportunity comes together with new security issues. An organization that runs services in form of virtual machine images on an offered platform needs security guarantees. In short, it wants evidence that the platforms it utilizes are trustworthy and that sensitive information is protected. Even if this sounds natural and straight forward, few attempts have been made to analyze in details what these expectations means from a security technology perspective in a realistic deployment scenario. In this paper we present a telecommunication virtualized platform provisioning scenario with two major stakeholders, the operator who utilizes virtualized telecommunication platform resources and the service provider, who offers such resources to operators. We make threats analysis for this scenario and derive major security requirements from the different stakeholders' perspectives. Through investigating a particular virtual machine provisioning use case, we take the first steps towards a better understanding of the major security obstacles with respect to platform service offerings. The last couple of years we have seen increased activities around security for clouds regarding different usage and business models. We contribute to this important area through a thorough security analysis of a concrete deployment scenario. Finally, we use the security requirements derived through the analysis to make a comparison with contemporary related research and to identify future research challenges in the area.
Australia has developed sophisticated national security policies and physical security agencies to protect against current and future security threats associated with critical infrastructure protection and cyber warfare protection. This paper will discuss some of the common security risks that face Australia and how their government policies and strategies have been developed and changed over time, for example, the proposed Australian Homeland Security department. This paper will discuss the different steps that Australia has undertaken in relation to developing national policies to deal with critical infrastructure protection.
Over the last decade, the mobile device has become a ubiquitous tool within everyday life. Unfortunately, whilst the popularity of mobile devices has increased, a corresponding increase can also be identified in the threats being targeted towards these devices. Security countermeasures such as AV and firewalls are being deployed, however, the increasing sophistication of the attacks requires additional measures to be taken. This paper proposes a novel behaviour-based profiling technique that is able to build upon the weaknesses of current systems by developing a comprehensive multilevel approach to profiling. In support of this model, a series of experiments have been designed to look at profiling calling, device usage and Bluetooth network scanning. Using neural networks, experimental results for the aforementioned activities’ are able to achieve an EER (Equal Error Rate) of: 13.5%, 35.1% and 35.7%.
In the last few years we have witnessed a strong interest in the protection of Critical Infrastructures (CIs) such as power distribution networks, power plants, refineries, water distribution, transportation systems, hospitals and telecommunication networks. Despite their relevance for public safety and security, these infrastructures are highly exposed to a large number of threats, including natural hazards, component failures, criminal actions and terrorism. Several research projects address this topic. Many of them focus on building CI simulators for preventive analysis of system vulnerabilities, while others try to proactively strengthen partial sections of the CIs (such as fault tolerant components or secure control networks). Nevertheless, despite their positive results, those projects seldom provide mechanisms to assess, in real time, the risk level associated with each of the services provided by the addressed CI. Moreover, they do not take into account the high level of interdependency between heterogeneous CIs (power distribution failures, for instance, have a direct impact on telecommunication networks, which also affect other critical infrastructures and so on) or, when they do, they have to make compromises at the level of scalability, performance, or privacy of sensitive information. In this paper we present a CI alerting system that takes a step further, when compared to those approaches, by estimating in real time the risk level associated with each service provided by the CI (i.e. the current likelihood of service degradation or service shutdown induced on a given CI by "undesired" events occurred in that CI and/or in other interdependent CIs).
This paper illustrates the activities under development within the FP7 EU MICIE project. The project is devoted to design and implement an on-line alerting system, able to evaluate, in real time, the level of risk of interdependent Critical Infrastructures (CIs). Such a risk is generated by undesired events and by the high level of interconnection of the different infrastructures. Heterogeneous models are under development to perform short term predictions of the Quality of Service (QoS) of each CI according to the QoS of the others, to the level of interdependency among the Infrastructures, and according to the undesired events identified in the reference scenario.