
Security and Management is a compendium of articles and papers that were presented at SAM '13, an international conference that serves researchers, scholars, professionals, students, and academicians. Selected topics include: * Security Management, Security Education, and Hardware Security* Biometric And Forensics* Computer Security* Information Assurance* Cryptographic Technologies* Systems Engineering and Security* Computer and Network Security* Network Security* Cybersecurity Education* Cryptography + Malware and Spam Detection + Network Security and Cyber Security Education
Mobile and Wireless systems offer new services for public administration that cannot be served by customary wired systems. The wireless mobile system is a solution for some problems that exist in traditional wired systems but they also initiate new security issues. Although the security concerns of wireless mobile systems cannot be completely eliminated with today’s available standards and techniques, it can be moderate some of the problems by a proper integration of standards, technologies, management, policies and service environments. This paper will address the wireless and mobile security issues and challenges faced in the development and implementation of mGovernment Systems and we will also discuss the cases and lessons learned, and future of security solutions, as they relate to mGovernment.
Traditional attacks against anonymous routing systems aim to uncover the identities of those involved, however, a more likely goal of attackers is to block or degrade the network itself, discouraging participation and forcing vulnerable users to communicate using less secure means. Since these anonymous networks operate on known protocols and employ strong encryption it is difficult to distinguish them from regular traffic. This paper proposes a method for identifying traffic belonging to anonymous networks by examining their communication patterns. If successful the method would enable the identification of Tor usage and thus allow for more directed attacks and possible user identification.
- The paper presents a new ontology-based approach to the development of the Business Continuity Management System (BCMS) compliant with the BS 25999 standard. BCMS encompasses management processes allowing to identify threats for an organization and their impacts to its business operations. If these threats occur, BCMS supports organizational resilience, capability for effective response and recovery. The contribution of the paper is the Business Continuity Management Ontology (BCMO) and related knowledge base, constituting the prototype of the management framework and tool developed to support business continuity managers in their activities. The paper presents the state-of-the-art in the security-related ontologies applications, the developed BCMO ontology and its usage in business continuity management, conclusions and future plans. Keywords: Business continuity management, knowledge engineering, modelling, ontology, BS 25999.
A network firewall is a widespread means to enforce a security policy, however it remains a network device. Such a duality has caused a somewhat independent way of firewall development from other security management methods. Following the way firewall vendors are focused on performance problems while management issues don’t receive enough attention. Firewalls have grown to complicated computer systems, but there is no general highlevel programming language for them. This problem becomes more and more urgent due to the increasing complexity of modern security policies, which must be enforced by firewalls. In this paper we 1) propose the basic idea of firewall configuration based on specifications of an access policy and a network environment; 2) describe Organization Based Access Control (ORBAC) model, which is used to specify an access policy; 3) propose a model to specify a network environment, and 4) the method of integration of an access policy with a network environment.