
In recent years, more and more applications based on bilinear pairing computation have been constructed. The very first issue is to pick up a pairingfriendly elliptic curve, which is efficient and secure. Many schemes have been published to generate secure curves. However, when it comes to implementation, the performance is a major concern. We estimate the cost of computing the reduced Tate pairing on the elliptic curves of short Weierstrass form with curve parameters, including the field size q, the subgroup order r, and the embedding degree k. From a large amount of curves, we can simply determine the curve on which the pairing computation is much efficient. We also generate some types of curves to perform pairing computation on SageMath and measure the real time cost. The result shows our estimation is accurate.
With the advance of IT technology, multimedia contents are widely used and distributed. Since novice uses them for illegal purpose, there are needs for protecting contents and blocking illegal usage through multimedia forensics. This paper presents a forensic technique for identifying digital camera using the sensor pattern noise. First, the way to acquire a sensor pattern noise which comes from the imperfection of photon detector against light is presented. Then, the way to identify the similarity of digital camera is explained after estimating the sensor pattern noises from the reference images and the unknown image. For the performance analysis of the proposed technique, 10 camera including DSLR and compact camera, smartphone, and camcorder are tested and analyzed quantitatively. Based on the results, the proposed technique can achieve the 99.6% identification accuracy.
The idea of “sending messages into the future” was first introduced in 1993 and brought up a new research track of timed-release encryption (TRE) scheme. However, most TRE schemes are constructed with a centralized and fullytrusted time server. This server should periodically generate and broadcast time-bound keys for legitimate users. Therefore, this setting is not scalable and suffers from single point failure. In addition, all of the time-bound keys are required to be stored at the server for all the possible time instances. In this paper, we proposed a timed-release encryption scheme with an efficient and privacy-preserving encoding in a decentralized/dealerless setting from the ciphertext-policy attribute-based encryption (CP-ABE) scheme. Our improved TRE scheme can be applied in the services where only semi-trusted servers are available.
In the context of Access provision, Identity access management holds the key to administering, monitoring and assurance of access to information within the Bank, both internal premises and application hosted on cloud. It is vital that the information is available when required providing both integrity and confidentiality. Failure to deliver information on time, lacking in integrity could results in compensation, loss of business, disclosure of company secrets and compliance issues. Identity management is widely herald as an opportunity for enhancing the operational process in information security, reducing cost, enhanced reporting capability and regulatory compliance. However in recent year this has proven to be the concept misunderstood, complex and costly. A case study within an investment Bank information system department is used to highlight issues around access management and the controls. Organisation is still reliant of manual provisioning of information access, user access addition, removal and update. This leave user under- privilege or over privilege access, high risk of human error and this could open up the organisation fraud risk. In this paper we extend the, issues within the previous unsuccessful implementation of Identity access management solution and highlight flaws within the access control provisioning requirements within investment banks by proposing a model framework to be used by the banks to enhance the process of access control and to be use by software vendors as a guideline in developing access provisioning identity access management software.
Digital evidence is becoming an integral part of most cases presented to court. From computers, to mobile phones, ATMs and surveillance cameras, our daily life is so inextricably entwined with technology that it is difficult to find court cases where technology plays no part. Thus the responsibility placed on a Digital Forensics (DF) practitioner to present usable evidence to a court is increasing fast. However, potential criminals have equally compelling reasons to prevent DF practitioners from getting their hands on information of probative value and use tools and methods known as Anti-Forensics (AF). The purpose of this study is to identify the abilities of DF practitioners to identify the impact that AF has on their active investigations. We created a research model that attempts to identify all the factors and constructs that impact the AF phenomenon. This model was then used to develop a survey instrument to gather empirical data from South African DFs. We found that whilst South African DF practitioners perceive DF as having an impact on their investigations, they also perceive electronic evidence as forming only part of the evidence presented to court, and that some usable evidence will generally remain. Unfortunately, we found also that most DF practitioners in South Africa are well versed only in the more commonly known AF techniques whilst not rating their abilities on more complex techniques well. Finally, most DF practitioners appear not to actively attempt to identify AF techniques as part of their investigations. This combined with a lack of understanding of more complex AF techniques could leave South African DF practitioners exposed by missing important evidence due to lack of technical proficiency. The research and its findings should be of benefit to academia and practicing DF investigators with a view to assisting them better prepare for the onslaught of AF.
The security accident is increasing in industrial infrastructure. The security of industrial control system is caused not only by deliberate acts of external attacker but also by sometimes inadvertent threats of legitimate inner operator. The latter can ultimately have more devastating consequences. Industrial control system works deterministic and restrictive operation. The anomaly communication patterns may be relevant to attack activities or misconfiguration of operator. To detect these threats in industrial control system, we propose security data objects that describe operation and state of system and security correlation analysis system that collects and analyzes these objects and detects intrusion or anomaly state of system. Our approach may provide complementary detection ability for protecting internal threat of industrial infrastructure.
Cyberspace has become the new frontier for countries to demonstrate power. Nations that have developed defense tools or those that can successfully launch attacks against adversaries will become the next global superpowers (1), (2). While cyber threats and attacks by government agencies are well documented, most widespread attacks are done by individuals or hacking groups for personal gains (3), (4). The UAE has become a major target for cyber conflicts due to increased economic activity, tourism, technology and rise of the oil and gas industry. Furthermore, the wide spread of internet in the region to the tune of 88% has exposed it to attackers (3). Recent attacks against Saudi Arabia's ARAMCO and Qatar RasGas and the Stuxnet attack on the Iranian nuclear plants are often cited as examples (3), (5). Previous reports show that the UAE Government is set to double expenditure on homeland security (6). Therefore, we need to assess whether available cyber- security defenses are effective and guarantee comprehensive cybersecurity strategies that would uphold the highest security standards in line with the vision 2030. In this paper, a critical review of the existing cyber security mechanisms has been done and a framework for effective management of cyber security threats proposed for the UAE government agencies.
The usage of the Tor network, has introduced a new malware paradigm that could also threaten mobile security and privacy. In the recent past months there have been only two cases of Tor-enabled malware spotted in the wild. In both cases, the malware used Tor for secondary operations and was not built around Tor from the ground up, limiting the potential impact. A more sophisticated malware that could use Tor as its core communication channel would have increased its impact and potentially the period of its illegal operations while making its detection significantly harder. At the same time, no commercially available mechanism has been found embedded in any anti-malware software that can detect Tor connection initiation at its source. This fact has identified this specific type of malware as a significant threat in both personal and business environments. This paper aims to set the principles and provide a proof of concept at design level of a new Tor-based Android malware, along with a related detection mechanism. This effort can prove that the risk can be significant and that such malware can be an actual threat, aiming to drive researchers and anti-malware vendors to include this type of malware in their research for antimalware techniques.
Mobile ad hoc networks (MANETS) are mobile nodes moving rapidly and they use wireless connections to connect to various networks or nodes. The dynamic nature of MANETs, make it vulnerable to attack by intruders. The sending and passing of nodes are based on several routing protocols. The packets do not reach the destination and some form of secure mechanism based on trust or friendship are deployed to protect the network integrity. Denial of service attacks is one of the typical attack type in mobile adhoc network. In this paper, we deployed Black hole and Grey hole attack. Black hole attack absord all data packets that are sent to its node whereas grey hole attack will drop some packet for a particular network destination based on packets type, time or randomly selected portion of packets. In this experiment we simulated several routing protocol to investigate the secure mechanism in protecting from the blackhole ad greyhole attack. The findings are presented and discussed. Index Terms—AODV; MANET; Trust
A large number of industries including: critical national infrastructure (electricity, gas, water, etc.) and manufacturing firms rely heavily on computer systems, networks, control systems, and embedded devices in order to provide safe and reliable operations. These networks can be very complex and are often bespoke to the types of product the industries may provide. In recent years we have seen a significant rise in malicious attacks against such systems, ranging from sophisticated intelligent attacks to simple tool based delivery mechanisms. With the rise in the reliance on industrial control networks and of course the increasing attacks, the lack of security monitoring and post forensic analysis of SCADA networks is becoming increasingly apparent. SCADA systems forensics is not like standard enterprise file-system forensics, the forensic specialist often has to be an expert in such systems/networks and SCADA related devices in order to identify where potential Forensic evidence could be located. This paper looks at the SCADA/industrial control systems, typical attacks and vulnerabilities, problems with forensic analysis and the development of a forensic methodology/toolkit for such systems.
During the last decade, smartphones have shown increased computational and networking capabilities. With the high bandwidth supported by Fourth Generation/ Long-Term Evolution (4G/LTE) technology, end-users will enjoy improved quality of communications, especially concerning data transfer services [1] in commercial and dedicated, Public Protection and Disaster Relief (PPDR) systems. PPDR infrastructures “are used by agencies and organizations dealing with the maintenance of law and order, the protection of life and property and with emergencies” [2]. With this transition, many research fields are developing, especially related to security issues. This work summarizes how the discipline of Mobile Forensics (MF), with various acquisition methods, complements traditional anti-malware and detection systems and contributes to malicious activity identification in PPDR systems. Additionally, a framework based on MF methods is proposed, alongside with its infrastructure and components. Estimations about the validation procedure and expected results are performed. Lastly, upcoming challenges and further research are discussed.
Most organizations have a tendency to focus on preventing threats from external attacks and almost overlooked on internal attacks. Biometrics, access control cards, keypad controls and door-locks are common types of physical security countermeasures. Failure of such design may endanger and post serious damage to major economics infrastructure, personal privacy and facilitate crime. Strong physical security applies the principle of Defense in Depth where multiple layers of protection are used in strengthening the security. This paper proposed an alternative security system design which uses audio as first layer of authentication to identify key-phrases generated randomly by the system with the integration of Random Number Generated (RNG) keypad as the second layer of authentication. Furthermore this system has the ability to resists man in the middle attack, and insider attacks because the system is connected in isolated and separated network, uses key-phrases identified from random audio and use software based keypad, with randomize number position. It is hoped that by having this system, common physical security countermeasure weaknesses can be minimized.
One important phase related to a cybercrime investigation is evidence collection. If the investigator lacks a standard, robust approach to properly conduct crime scene research, some important information can be lost, and judges can discard case evidence because the acquisition process was faulty. In this situation, a formal process could guarantee the evidence veracity and integrity. This paper presents processes, procedures, and tasks using a project structure that could be beneficial in the evidence collection phase. A detailed model that follows the project management process describes the steps a digital investigator should follow in the initiation, planning, execution, controlling, and closing phases of the evidence collection. All mechanisms can contribute to a best practices guide in the forensics field.
This paper focuses on identifying and evaluating the available security awareness tools, and later presents a study conducted to assess the level of security awareness among Libyan secondary school students covering social networks, passwords, and cyber-bullying. The quantitative methodology is applied via questionnaire in order to assess the students' awareness level. Moreover, qualitative methodology is used in order to observe secondary school students manner and behavior while they are participating in the training program. The targeted group of this study was Libyan secondary school students in Malaysia, and the sample is composed of ten students aged between 13-18 years old. The findings indicated that even the students show a slight level of awareness, but they still lack practicing the information security correctly. Therefore, a study on secondary school students' awareness level, as well as conducting security training program is crucial to avoid security risks.
Information security is traditionally understood to involve technical security measures, such as intrusion prevention systems, to establish a secure perimeter around an organization’s sensitive information. Threats, then, are any potential attack on that secure perimeter with the intent of either obtaining unauthorized access or damaging availability or information. With modern organizations using tools to allow every employee to access information, and even allowing employees to control access restrictions on sensitive information, information security managers must expand their information security program to educate personnel and establish a culture of security. The expanded information systems security program must address technical, policy, standards and norms, education and cultural initiatives.
The number of attacks based on advanced persistent threat (APT), which is a set of stealthy and continuous computer hacking processes, has been increasing around the world. To cope with such attacks, a management system that stores and analyses log information in order to identify unjust packet network communications has come to be used for threat detection in equipment equipped with functions such as security information and event management (SIEM). However, while it is possible to identify personal computers (PCs) engaging in unjust communication using this system, it is often very difficult to determine the process used by the malware to cause the PC to engage in unjust communication in the first place. To cope with that issue, the authors will propose a dedicated method for storing startup and closing log data and, reading modules. They will also report on communication trials conduct in a Windows operating system (OS) environment. In addition, they will report on a newly developed driver program called Onmitsu that can be used to implement the functions included in the proposed method, as well as its application to an example. Based on the results of the application evaluation, it was confirmed that the program could effectively achieve the desired objectives. In this paper, the proposed method, the developed program, applied results, and the evaluation performance results are described.
Money laundering is the legalization of capital and money obtained from crime and core activity of fraud management. This activity is carried out through financial transactions that obscure the original source of money or capital. Recurring modus operandi of money laundering is achieved through the falsification of documents and the manipulation of banking transactions. Money laundering is associated with various forms of threats to security as a source of financing terrorism, organized crime, trafficking of human and drugs. In the process of money laundering, exchange offices, casinos and insurance companies have important role, which are due to reduced regulatory oversight in relation to other institutions engaged in financial transactions. Global networking and interplay of many dimensions of globalization emphasis the necessity of solving the problem of money laundering on a global scale. Financing of political and economical processes obtained from money laundering is a serious security problem that has the impact even in the most economically developed countries in the world and requires special attention in creating mechanisms for the prevention of this type of criminal activity.
The phenomenal explosion of the information and communication technology (ICT) has brought great changes to our daily lives. And with the advent of numerous kinds of Internet communications such as electronic mails (e-mails), chat groups, online fora, web logs (blogs), social media platforms and many others, Internet users are able to easily publish and disseminate any kind of information to the public at large. Unfortunately, the ease of use of these online media has on several occasions been misused by unscrupulous individuals for publishing defamatory remarks in the cyber world. At present, reported cases of cyber defamation have been on the rise in Malaysia. In relation thereof, the paper embarks on a doctrinal study to examine the efficacy of the existing regulatory regime that governs such a crime. In so doing, the study will analyse the provisions of the Malaysian Defamation Act 1957 (the primary source of law for defamation) and relevant reported cases that have been decided by the Malaysian judiciary. Apart from that, a comparative analysis with the position in the United Kingdom after the enactment of the English Defamation Act 2013 will be made since the Malaysian statute was drafted far back in the 1950s and since then no significant amendment was made to reflect the advancement of the Information Age. Finally, this paper will attempt to highlight any loopholes or lacunae in the existing laws and possible suggestions and recommendation as part of its conclusion.