
The present paper suggests separating the real structure of information systems and information about the system which subjects of the system have. The paper gives an example of such division using mathematical models of information security. The paper describes interaction processes between objects and the system that may result in changing their awareness structure. Based on the mathematical models described herein it is possible to establish which subjective images of the system are stable and define conditions that enable us to confirm that our own subjective image is objective. Problem setting for hiding some processes by modification of information stream structure in the system is provided.
Twitter is one of the many social media accessible to users in Indonesia. The official account in one of these organizations is very dangerous if the official account is used by many users that do tweet and the data is not store who, what time doing it. Moreover, if the official account is already too much to millions. This paper propose a framework can work on recording data i.e. who, what time all tweets. Desktop pc and smartphone to u. s. clients do not directly access the official twitter account of its organization, so the official twitter account of security can be maintained secret username and password. This paper shows a user indirect access to official accounts of the organization, i.e. username password email user using LDAP access organization, can record the user be who and what time at the time of tweet, and for the community is that followers will trust the accuracy of the information which is posted on the official accounts of the organization, because only someone who just registered on social media management system for post and chosen by the manager level before it is posted.
The significant growth of information and communication technology (ICT) has the potential to promote economic growth. On the other hand, it also cause an increase in cyber threat and hence must be handled properly. Comprehensive and collective approach in handling cyber threat should be considered as importance. One of the most important aspect that should be considered is organizational structures. It plays a significant role in organizing responsibility among cyber related agencies. This paper provides a comparison study about a delegation scheme of responsibilities in cyber related role among different agencies among three different countries Malaysia, Australia and Indonesia. This study has shown that Indonesia has a more complex partition scheme of delegating responsibilities.
Printed documents are vulnerable to forgery through the latest technology development and it becomes extremely important. Most of the forgeries can be resulting loss of personal identity or ownership of a certain valuable object. This paper proposes novel authentication technique and schema for printed document authentication using watermarked QR (Quick Response) code. The technique is based Watermarked QR code generated with embedding logo belongs to the owner of the document which contain validation link, and the schema is checking the validation link of the printed document which linked to the web server and database server through internet connection by scanning it over camera phone and QR code reader, the result from this technique and schema is the validation can be done in real-time using smart phone such as smart phone based Android, Black Berry, and iOS. To get a good performance in extracting and validating printed document, it can be done by preparing in advance the validation link via internet connection to get the authentication of information hidden. Finally, this paper provide experimental results to demonstrate the authenticated of printed documents using watermarked QR code.
LSB steganography and Vigenere chiper methods are integrated in used for data security validation in this study. This approach used Arithmetic Coding method for data compression and data decompression. To maintain the authenticity of the data file, a hash function (SHA 256) technique was added. This paper presents a prototype called Ste-Chy as a proof of concept of the combination of these techniques. This approach helps the user in terms of the exchange of confidential data through an online share in Android-based media. For the confidential authentication purpose, the confidential message is hidden togetherwith the target image. The quality of the original image and stego images in this work produce an image picture in an acceptable level for the user. The bigger the secret of the message, the compression will produce higher compression ratio. With this approach, security process of exchange of confidential message shared through the online share smartphone is considerably secured especially in an android environment.
Recently, Wireless Sensor Networks (WSNs) and its applications have obtained considerable momentum due to its growing usage in different applications. However, security and power limits of WSNs are still important matters especially during routing since the early beginning of this research due to few of previous studies take into consideration security threats and energy consumption at the same time. Many existing approaches at most concentrate on cryptography to improve data security but this addresses only a part of the security problem without consideration for high energy consumption. This article presents a hybrid solution that depends on combination between network nodes trustworthiness and energy aware routing mechanism. This solution provides security and minimizes power consumption during routing. Performance and efficiency are measured through simulation results, analysis and comparison with well-known mechanisms.
Several methods have been suggested to address the identification of security requirements for information systems (IS) from risk analysis or not. To the best of our knowledge, there is no methodology that enables the derivation in a formal way of security requirements starting from risk analysis. The aim of this paper is to provide a guiding method allowing us to determine security requirements based on risk analysis. To achieve this objective, we propose to align the concepts of assets, risks to those of security requirements through the use of three ontologies: assets, risks and security requirements. The alignment of the three ontologies is based on best practices in the security domain. In addition to the description of guiding method, we detail, in this paper, the approaches used for the construction and alignment of the three ontologies.
A physical security is best described as securing the perimeter of an area. Most organisation tends to focus on securing their data over the wires and overlooked threats coming from inside their premises. Servers are protected with maximum security configurations and firewall, however the server room are accessible by unauthorized personnel, access card often left behind, broken or missing main door entrance although secured with access card system, vendors, consultants and visitors were not accompanied by staff during visitation, piggy-backing, tailgating, shoulder surfing and keylogging cases are common scenario that can be seen inside an organization. To minimize or/and to overcome the mentioned problems, an enhanced type of physical security method is proposed which is authentication using Random Number Generated (RNG) Keypad based on One Time Pad Concept. It is a computational physical device designed to generate a sequence of numbers or symbols that will appear randomly using Pseudo-random numbers algorithm each time One Time Password (OTP) is keyed in. It is typically generated by a token possessed by the user and it is the input to the authentication system. The input OTP is compared to an OTP generated by the system. If it matches, the user is allowed to access the system. It is hoped that by having this prototype system, common physical security countermeasure weaknesses can be minimized while assuring confidentiality, integrity and availability of the data stays protected with minimum cost and minimal configurations.
With the rapid growth of the Internet, there are an increasing number of computer threats and attacks. The prevalence of zero-day attack activities has given rise to the need to prevent these attack activities from spreading and damaging the computer system. As such, intrusion detection system (IDS) should satisfy complex requirements and must be durable, manageable and reliable. In this paper, we developed an anomaly-based detection model using a statistical method combined with a binary logistic regression approach. The model, Layer based Anomaly Detection (LbAD) is designed to detect remote to user (R2L) and user to root (U2R) attacks by statistically examining the degree of normal field values within three layer (data link, network, transport) of OSI Seven Layer. The results of the new method outperform the leading existing methods.
We propose a method for managing online accounts from the point of view of risk management. The proposed method reduces the risk of a personal information leakage, while permitting users to reuse passwords. We further propose a way to measure the risk of personal information leakage in order to estimate the risk impact. This proposed risk value is an index of the quantitative influence of leaked personal information. We evaluated the ability of the proposed method to minimize the risk of personal information leakage and the number of passwords that users can remember. In this evaluation, the α-group contained five passwords, and the β-group contains seven passwords. Thus, we conclude that the proposed method is useful as a whole.
Wearable devices are computationally rich, portable and wearable to suit users in various needs and situations. Still, users of wearable devices suffer from lack of efficient input methods and proper feedback modality. In this paper, we design and implement a novel input method exploiting readily available ambient light sensor on wearable devices. We present concepts and implementation results of re-purposing the light sensor for user input and processing UI events. Furthermore, a PIN entry application based on the proposed input method is implemented to demonstrate a device authentication scenario for wearables.
Recently, the number of targeted attacks to specific organizations, such as companies or governments, has been increasing. Although such organizations are required to conduct to protect against the attack or mitigate the effect of the targeted attack, it is very difficult to perform the proper operation without the assistance of a support system. Therefore, the authors developed the Live and Intelligent Network Forensic Technologies (LIFT) system to guide the proper operation and/or conduct an automatic operation using artificial intelligence. The LIFT system collects the logs from servers, PCs, and communication equipment such as routers and detects abnormal signs from the collected logs. Next, the LIFT system calculates the certainty factor of an event occurrence by using the knowledge of the relation between the detected signs and the estimated event. If the certainty factor is large enough, the event is assumed to occur, or else the LIFT system requires collecting additional logs or results of a memory dump. Moreover, the LIFT system guides the proper operation and/or conducts an automatic operation with the knowledge of the relation between the event and proposed action, which would be a guide or automatic operation. If the knowledge described is given to the LIFT system, a total simulation can be performed in the LIFT system based on rule-based technology, which is one of the artificial intelligence technologies. This paper describes the objective to develop the LIFT system, the overview of the system, the developed prototype of the LIFT system and the experimental results of applying the LIFT system prototype. From the experimental results, we confirm that the LIFT system can be a useful tool to perform the proper operation against a targeted attack.
A targeted attack affects all terminals in a network. Therefore, in order to properly deal with such an attack, it is necessary to analyze the event information for each terminal in the network as well as all event information within the terminal. We have been studying a dynamic diagnostic method based on malware behavior in a network. We herein propose a malware detection method that works by dynamically converting collected process logs into CybOX and analyzing the converted data. In the present paper, we focus on the observables of the penetration/exploration phase of targeted attacks. We propose a method for identifying the route of infection by analyzing the process and a communication attempt associated with the process of the detected malware. We confirmed the ability to find the source of the infection process in the initially infected terminal by analyzing the behavior of the malware in a secondarily infected terminal.
In recent years, zero-day attacks that exploit software vulnerabilities before they can be covered by hotfix deployments have become increasingly serious. And it has become very dangerous to leave such vulnerabilities uncovered because they may permit unauthorized access or malware infection. Additionally, hotfixes of software that manufacturers have stopped support will not be distributed. Because of these and other issues, vulnerability mitigation software packages such as the Enhanced Mitigation Experience Toolkit (EMET), Malawarebyte Anti Exploit (MBAE), and HitmanPro. Alert have attracted attention nowadays. It is possible to take countermeasures against vulnerability attacks in real-time by introducing them without the definition files or sandboxes used in common anti-virus software packages. However, it has been reported that some malware types that execute vulnerability attacks are capable of circumventing vulnerability mitigation software packages such as EMET. Therefore, in this study, we perform detection experiments using vulnerability mitigation software in a personal computer equipped with an old version of the Windows 7 operating system. From the result, we found that basically HitmanPro. Alert was most effective against vulnerability attack and attacks of malware described via macro language such as VBA.
When a security incident is reported, identifying the point-of-breach is critical to figure out what an attacker might do next. Besides, the information related to the resources and levels of privilege acquired as a result of the breach, is essential to re-create the process. Such information is also crucial to planning a defense in real-time. To this end, we need to determine the following parameters associated with the system under attack, viz., a breach probability determined from the success of past cyber-attacks, the attack matrix which is dependent on the system design that decides the types of attacks and the associated modalities that the system may be susceptible to under standard conditions, and the access matrix which is determined by the access privileges that get granted when an attack succeeds. In this paper, we introduce the breach-point detection problem and present a model based on Bayes' conditional probability to identify the point-of-breach on a system impacted by a cyber-attack. We evaluate the probability associated with likely points-of-breach in the rest of the system based on the knowledge of its design and estimate the posterior probabilities associated with the points so identified based on the system parameters outlined earlier. We also determine the most probable point-of-breach and its posterior probability using our model. We demonstrate the use of our model by way of a numerical example. Finally, we illustrate the generalization of this approach to an arbitrary system and outline a method to compute its system parameters, viz., the breach probability, the attack matrix and the access matrix.
Lock folder is one of method that used to ensure nobody intentionally gets access to your private and confidential information. Presently used password based systems have a number of associated inconveniences and problems such as user needs to remember passwords, passwords can be guessed or broken down via brute force and also there is problem of non-repudiation. Besides, password authentication method as a keyword permission to access something is breakable. Hence, it can be leaked out and cracked by using any methods such as dictionary attack, or social engineering. Due to the drawback, this method is lack of universality of some characteristics and the recognition performance of the systems is upper limit and it is unacceptable error rates for the single modal authentication system. Multimodal biometric can be at least combination of two types of any physical or behavioral biometric as it applies in the system that has been developed. Therefore, a system is proposed to overcome the aforementioned problems by adding multimodal biometric authentication will provide another layer of security. Those problems encountered have being overcome and it is proven that by adding another layer of security as the authentication is more secure. It has been proved and has been tested that using combination of two biometric methods, fingerprint and signature as an authentication method is more secure and reliable.
Advanced Persistent Threat (APT) attacks, which have become prevalent in recent years, are classified into four phases. These are initial compromise phase, attacking infrastructure building phase, penetration and exploration phase, and mission execution phase. The malware on infected terminals attempts various communications on and after the attacking infrastructure building phase. In this research, using OpenFlow technology for virtual networks, we developed a system of identifying infected terminals by detecting communication events of malware communications in APT attacks. In addition, we prevent information fraud by using OpenFlow, which works as real-time path control. To evaluate our system, we executed malware infection experiments with a simulation tool for APT attacks and malware samples. In these experiments, an existing network using only entry control measures was prepared. As a result, we confirm the developed system is effective.
For an organization, the guarantee of the integrity of business processes in the event of an incident, which may cause paralysis of information technology infrastructure, including resources in it is a strategic necessity. Though considered difficult, at least for the organization's management are able to minimize the impact of the incident on their business processes. One of the vital assets that will be the impact of an incident is the loss or damage to the digital evidence. This study was motivated by the importance of a process model that is concise and effective in the domain of Digital Forensics Readiness (DFR), considering that several sources have published earlier DFR models that broadly has the similar four entities, namely people, process, policy, and technology. This paper produces a model of a process called Digital Forensics Readiness Schema (DFRS), which is the result of the normalization of the process model published by Caroline Crime Report by incorporating some key elements of the 10 stages to 5 stages, without reducing the quality and capability of the existing business processes.
The current growth of the smartphone with Android operating system-based has increased rapidly. This rapid growth has given access for certain parties to make it as a crime target through malware spreading. Various efforts are needed to be taken to minimize the number of Android users, which are victimized by these malware activities. The encountered problem is that there is increasing the ability of malware that causes difficulties in the malware detection process. In general, the usual solution taken to handle this issue is by doing the malware detection using a signature-based method. However, this method can be easily avoided by polymorphic-ability kind of malware. Therefore, it is necessary to develop a dynamic behavioral-based malware detection through observing the use of System Call. Considering the large number of malware that have to be detected and the system call that should be observed, the help of machine learning is needed for the classification process purpose, one of which is Support Vector Machine (SVM) method. This study shows that the observation towards system call with its classification using SVM yields 90% accuracy for polynomial kernel and 86% for the RBF kernel. This proves that the system call can be used to make polymorphic malware detection. In this research, however, the use of the system call is not able to distinctly distinguish between malware and nonmalware. This has something to do with the use of the same accustomed data with the experimental data. The classification result could reach a quite high level of accuracy because the experimental data used are the observation result from the same application with the accustomed data. This is considered a weakness since this method is unable to identify new applications in which its system call frequency has never been observed and trained with SVM.
Smart grid infrastructure is one of the critical infrastructure that combines the energy and telecommunications infrastructure and Internet networks. Thus, the smart grid must operate safely and meet the information security aspects. This research is a case study in smart electricity grid as critical infrastructure. The research objective is for improvement on critical infrastructure security policies based on case studies conducted. This research was conducted with the combined quantitative and qualitative method that combines the results of the risk assessment on the research object to the opinion of experts / practitioners. Results of this research is input to policy frameworks and securing of critical infrastructure.