
Konflik Laut China Selatan telah berlangsung sejak lama. Sejarah awalnya adalah penetrasi yang dilakukan oleh Tiongkok atas klaim sepihak mereka terhadap kepemilikan mayoritas wilayah Laut China Selatan. Beberapa tahun terakhir ini eskalasi konflik di Laut China Selatan mengalami peningkatan. Hal ini tentunya berpengaruh pada wilayah Indonesia yang berada atau berbatasan langsung dengan Laut China Selatan. Wilayah yang paling dekat dengan Kawasan Laut China Selatan adalah Kawasan Laut Natuna Utara dan Kepulauan Natuna. Tujuan penelitian ini adalah menganalisis ancaman dari konflik Laut China Selatan dan kesiapan Kogabwilhan I untuk mengantisipasinya. Metode penelitian ini adalah kualitatif desain deskriptif. Teori yang digunakan pertahanan negara, kesiapan, peranan, ancaman, kekuatan udara dan konsep operasi udara. Hasil dari penelitian ini adalah Potensi ancaman yang terjadi baik berupa ancaman militer dan non-militer terhadap wilayah kedaulatan udara Negara Republik Indonesia cukup besar terdampak dari konflik Laut China Selatan. Kesiapan Kogabwilhan I dalam mengantisipasi ancaman udara di Laut China Selatan meliputi kesiapan operasional dan tempur yang didukung oleh kesiapan pengembangan organisasi, latihan dan pergeseran kekuatan atau alutsista. Kesimpulan terdapat potensi ancaman dan kesiapan Kogabwilhan I membutuhkan dukungan sarana prasarana dan alutsista
Konflik Papua diawali pada tahun 1961 ketika Belanda berkeinginan membentuk negara Papua Barat. Adanya pemutarbalikan fakta dari sebagian tokoh Papua terhadap perjanjian New York tahun 1963, menjadikan tonggak lahirnya ide-ide separatis untuk memisahkan diri dari NKRI. Kasus pelanggaran HAM yang tidak kunjung terselesaikan, rasa termarginalisasi serta rasa terdiskriminasi orang Papua menambah deretan panjang permasalahan di Papua sampai dengan saat ini. Permasalahan kesejahteraan dan stabilitas keamanan di Papua sampai belum dapat diselesaikan dengan cukup baik, walaupun pemerintah telah melakukan berbagai upaya dengan melibatkan seluruh stakeholder terkait. Terlebih ketika pemerintah mengganti label KKB Papua menjadi Kelompok Separatis Separatis Papua (KSTP), membuat stabilitas keamanan di Papua menjadi lebih dinamis. Di satu sisi masyarakat Papua belum terbentuk dan terbina untuk membentuk suatu pertahanan wilayah yang mengakibatkan kendala bagi satuan-satuan TNI/Polri dalam menangani kasus-kasus KSTP ini, sehingga diperlukannya operasi teritorial terpadu yang dapat melibatkan seluruh stakeholder terkait di Papua. Tujuan dari penelitian ini adalah untuk mengetahui pelibatan tokoh-tokoh Papua, strategi pembinaan teritorial dan adanya indikator keberhasilan operasi teritorial dalam rangka meningkatkan kesejahteraan dan stabilitas keamanan di Papua. Metode yang digunakan dalam penelitian ini menggunakan metode penelitian kualitatif fenomenologi untuk mengungkap suatu fenomena yang didasarkan oleh kesadaran dari beberapa individu. Hasil dari penelitian ini dapat disimpulkan perlu adanya suatu kebijakan untuk mengangkat seluruh tokoh Papua sebagai duta/kader yang dapat berkolaborasi dengan pemerintah dalam meningkatkan kesejahteraan dan menjaga stabilitas keamanan di Papua. Sehingga operasi teritorial yang dilaksanakan oleh TNI akan terus berpijak terhadap kultur atau kearifan lokal di papua itu sendiri
Konflik wilayah maritim di Laut China Selatan (LCS) berlatar belakang pada sebuah klaim sepihak Tiongkok yang menganggap sebagian besar kawasan itu sebagai bagian teritorialnya berdasar peta negara Tiongkok tahun 1947. Berbagai upaya dilakukan untuk menunjukkan eksistensi kepemilikannya dengan mengambil sikap ofensif dan agresif. Selain melakukan patroli wilayah menggunakan unsur Coast guard, Tiongkok juga membangun pangkalan militer dan secara aktif melakukan berbagai latihan menggunakan armadanya di LCS. Terhadap Indonesia, klaim ini bersinggungan dengan Zona Ekonomi Eksklusif Indonesia (ZEEI) di wilayah Natuna. Terkait persinggungan itu, kapal-kapal patroli Tiongkok, secara aktif senantiasa melakukan penjagaan hingga pengawalan pada kapal berbendera mereka yang melakukan pelanggaran wilayah ZEEI dan kerap bersikap represif terhadap unsur patroli milik Bakamla dan TNI AL. Menghadapi kondisi ini, perlu disusun sebuah langkah strategis untuk menghadapi kemungkinan meluasnya konflik yang selama ini terjadi apabila berkembang menjadi konflik militer. Pulau Natuna Besar, adalah pulau terdekat terluas dari kawasan ZEEI yang bersinggungan dengan klaim Tiongkok. Pulau ini memiliki infrastruktur untuk menjadi garda kekuatan terdepan Indonesia dalam mengantisipasi kemungkinan di atas. Untuk itu, peneliti melakukan sebuah penelitian bersifat kualitatif terhadap Pulau Natuna Besar terkait kapasitasnya untuk menjadi sebuah Kapal Induk Statis yang memiliki kemampuan surveillance mumpuni, kekuatan penyerang dan pelindung, serta kekuatan pertahanan pantai strategis demi menjaga keutuhan wilayah Negara Kesatuan Republik Indonesia (NKRI)
Luasnya wilayah perairan yang dimiliki oleh negara Indonesia memiliki potensi ancaman pertahanan dan keamanan yang luas pula. Pertahanan maritim tidak dapat dijalankan oleh kekuatan militer matra laut semata, namun harus diselenggarakan secara terintegrasi bersama kekuatan militer matra lainnya, serta melibatkan segenap unsur kekuatan pertahanan non militer dalam suatu sistem pertahanan semesta pada ranah maritim. Selain itu, tidak sebandingnya jumlah personel penegak hukum dibandingkan dengan luas wilayah tanggung jawabnya mendorong perlunya pembangunan kebijakan pertahanan rakyat semesta di laut. Penelitian ini bertujuan untuk menganalisis penguatan sistem pertahanan rakyat semesta di laut guna meningkatkan pertahanan laut Indonesia khususnya pada industri jasa maritime armada kapal niaga. Penelitian dilakukan dengan metode kualitatif, dan pengumpulan data melalui wawancara dan studi dokumentasi. Hasil penelitian adalah aspek perencanaan belum didukung dengan peraturan perundangan untuk pertahanan rakyat semesta di laut; aspek pengorganisasian masih belum menyeluruh dimana belum meliputi industri jasa maritim dan kapal niaga; aspek kesiapan belum dilaksanakan modifikasi dan transformasi kapal niaga untuk mendukung tugas kemiliteran TNI AL; serta aspek pembinaan baru pada tahap rekayasa armada kapal niaga dan menggerakkan komponen industri jasa maritim tersebut untuk kepentingan pertahanan di laut. Ditemukan pula permasalahan terkait dengan armada kapal niaga adalah Belum adanya konsep modifikasi terhadap sarana prasarana armada kapal niaga untuk mendukung sistem pertahanan rakyat semesta di laut. Kesimpulan penelitian bahwa sistem pertahanan rakyat semesta di laut yang ada saat ini masih belum optimal dan masih jauh dalam implementasi di lapangan. Sehingga perlu diimplementasikan rumusan strategi yang telah dibuat guna mencapai penguatan sistem pertahanan rakyat semesta di laut yang optimal
Pendekatan kesejahteraan sebagai langkah yang diambil dalam upaya pembangunan kesetaraan keadilan sosial wilayah Indonesia. Belum tercapainya kesejahteraan masyarakat Papua, dan belum optimalnya pelaksanaan pembangunan di Papua, serta belum efektifnya keterlibatan TNI pada program pembangunan nasional dalam mewujudkan welfare state di Papua, merupakan akar permasalahan munculnya Konflik GSTP. Penelitian ini menggunakan metode penelitian kualitatif,dengan desain penelitian deskriptif kualitatif. Hasil penelitian ini menunjukkan; pertama, penyelesaian konflik GSTP melalui welfare state diperlukan kebijakan pemerintah yang mengatur pendekatan kesejahteraan di bidang pendidikan, kesehatan, mendapatkan pekerjaan dan penghidupan yang layak, serta persamaan di dalam hukum bagi masyarakat Papua. Kedua, pelaksanaan program pembangunan untuk meningkatkan kesejahteraan masyarakat Papua harus memprioritaskan pengembangan SDM dan meningkatkan sarana prasarana potensi wilayah,baik fasilitas umum dan sosial yang dapat diakses oleh masyarakat. Ketiga, keterlibatan TNI dalam Proses Pembangunan Nasional mewujudkan welfare state di Papua yang fokus pada peningkatan kesejahteraan di bidang pendidikan dan kesehatan serta mewujudkan keadilan sosial dalam hal perlakuan yang sama di mata hukum dan pemberdayaan masyarakat untuk mendorong terwujudnya kesetaraan dan keadilan
Pada pelaksanaan penanggulangan bencana pada tahap darurat, Satuan TNI yang telah dilibatkan menjadi unsur pengarah tetapi juga sebagai unsur pelaksana teknis dilapangan. Hal ini menyebabkan terjadinya ketidakjelasan peran dan tugas serta kesulitan dalam berkoordinasi di lapangan. Penelitian ini bertujuan untuk menganalisis manajemen penanggulangan terpadu akibat bencana alam guna meningkatkan kesiapan tahap tanggap darurat dalam rangka mendukung tugas pokok TNI. Penelitian dilakukan dengan metode kualitatif, dan pengumpulan data melalui wawancara dan studi pustaka. Pengalaman empiris penulis sebagai pelaku pada penanggulangan bencana alam di Lombok juga mendukung hasil penelitian yang komprehensif. Hasil penelitian Ditinjau Aspek regulasi, dalam upaya penanggulangan akibat bencana alam terpadu perlu dukungan regulasi yang kuat secara kualitas maupun kuantitas; Dari tingkat intensitas perencanaan tanggap darurat, maka pihak bertugas selaku koordinator pelaksana belum mengimplementasikan paradigma baru penanggulangan bencana; Bentuk nyata konsep penanggulangan bencana alam masih belum terwujud, dimana penggunaan dan gelar yang terintegrasi secara terpadu belum ada. Kesimpulan penelitian bahwa Pelibatan TNI dalam tanggap darurat penanggulangan bencana masih belum optimal dan membutuhkan implementasi strategi dalam mencapai kondisi manajemen penanggulangan bencana yang diharapkan. Strategi yang dirumuskan adalah Terwujudnya implementasi manajemen penanggulangan bencana alam secara terpadu dengan menata ulang regulasi tentang pelibatan TNI dalam penanggulangan bencana alam, upaya aktualisasi rencana yang terintegrasi pada kondisi darurat bencana, dan perwujudan penggunaan dan penggelaran yang terintegrasi dalam rangka mendukung tugas pokok TNI. Saran penelitian adalah perlu tinjauan ulang terhadap Perpres penanggulangan akibat bencana skala nasional kepada TNI. Mengingat pada tugas tentang penanggulangan akibat bencana skala nasional seharusnya ditujukan kepada BNPB
Abstract-The threat of pandemics and epidemics of dangerous and deadly diseases is very likely to occur in Indonesia. The spread of Covid-19 that is out of control and exceeds the capacity of the epidemic, and has made the status of the spread of Covid- 19 a pandemic outbreak. Pusziad CBRNE Company is a central-level implementing agency in the field of CBRNE. Biological threats increase and spread, such as in handling the Covid-19 pandemic, Pusziad CBRNE Company has limitations. Pusziad CBRNE Company's capability is not sufficient from the aspect of the organization, personnel resources, and equipment. This study analyzes how the strategy of Pusziad CBRNE Company in dealing with the Covid-19 pandemic with qualitative research and data collection through observation, interviews, and documentation. The occurrence of the Covid-19 pandemic that hit the world, including Indonesia with a fairly high death rate, is clear evidence of a biological threat. Biological threats in Indonesia are increasing evident with the development of bio-science and its supporting facilities in Indonesia as well as the opening up of bioterrorism actions. With increasing biological threats such as the Covid-19 pandemic, the role of Pusziad CBRNE Company becomes very important. Faced with the limitations of Pusziad CBRNE Company, the strategies that need to be suggested are reviewing the Pusziad CBRNE Company organization to be upgraded to a detachment or battalion, proposing optimal budget support, equipping special equipment for CBRNE, and increasing the human capacity resources of Pusziad CBRNE Company personnel. Therefore, against the backdrop of increasing perceptions of biological threats in Indonesia, Pusziad CBRNE Company needs to improve its organization, personnel capabilities, and equipment, so that Pusziad CBRNE Company has reliable capabilities supported by a proportional organization with professional personnel and sophisticated equipment.Keywords: Nuclear biology and chemistry (CBRNE), Biological Threats, Covid-19 Pandemic, Capabilities and Strategies
Abstract - This research is motivated by the phenomenon of threatening national defense in West Java. The objectives of this study are (1) To analyze the threat of national defense in West Java; (2) To analyze the performance intelligence detachment of the 3rd military regional command (KODAM III)/Siliwangi in overcoming the threat of national defense in West Java; and (3) To analyze the strategy intelligence detachment of 3rd military regional command (KODAM III)/Siliwangi in improving performance to overcome the threat of national defense in West Java. The research method used is qualitative. The results showed that; (1) State defense threats in West Java are related to ideological, political, economic, socio-cultural, and security threats; (2) The performance intelligence detachment of the 3rd military regional command (KODAM III)/Siliwangi in overcoming the threat of national defense in West Java is related to collection, analysis, counterintelligence, and covert operations. As for the implementation, Kodam III Siliwangi did some support such as data collection, deepening, raising, coordination, and social communication; and (3) Strategy intelligence detachment of 3rd military regional command (KODAM III)/Siliwangi in improving performance in order to overcome the threat of national defense in West Java through improving the capability of soldiers, increasing the number of soldiers, increasing the responsiveness of information and situations, and improving facilities and infrastructure through procurement based on priorities. The conclusion of the research shows that the performance intelligence detachment of the 3rd military regional command (KODAM III)/Siliwangi is quite good but it needs strengthening based on a priority scale.Keywords: Threats, Intelligence, Performance
Abstract-The government's plan to relocate the nation's capital city (IKN) is a hot topic of discussion at this time. After the announcement of the results of the direct election of the president and vice president (Pilpres) of the Republic of Indonesia, at the end of April 2019, the National Development Planning Agency (Bappenas) submitted the results of a study on the relocation of the nation's capital through a limited cabinet meeting. The Bappenas announcement received a pro and contra response from several parties related to the IKN relocation plan. In this study, the method used is descriptive qualitative. The discourse on relocating the nation's capital city (IKN) from Jakarta to East Kalimantan is not only related to geographical and environmental issues, but also to reasons for state security. The relocation of the capital will certainly have positive and negative impacts, one of which is the shifting of the "center of gravity". This is a term for the center of strength as well as the center of vulnerability that determines the victory or defeat of a country in war. Defense strategy analysis shows that the shift is strategically and tactically beneficial. But the benefits are not free. The state defense posture needs to be adjusted, especially the level of strength in Kalimantan must be strengthened. This requires a high commitment from all stakeholders, especially from the budget side.Keywords: State Capital (IKN), East Kalimantan, Defense Strategy.
Abstract - The COVID-19 pandemic has prompted all education providers in Indonesia to make changes, including Army Staff and Command College as an educational institution in the Indonesian Army. The problem being researched is the problem of organizing general development education or Army Staff and Command College Regular Education during the COVID-19 pandemic. This study analyzes the strategy of the Army Command and Staff College in carrying out available development education activities optimally during the COVID-19 pandemic. According to Sugiyono's theory (2015), this study uses qualitative research methods on the Case Study of Learning and general development education at the Army Staff and Command College in 2020 and 2021. The first result obtained is that Learning Methods used by Army Staff and Command College during the COVID-19 Pandemic are online learning methods and face-to-face learning methods carried out both in phase I and Phase II in combination. The second result about how to implement a general development education during the COVID-19 pandemic is to revise the education curriculum, increase the ability of lecturers and officers at the Army Staff and Command College, upgrade educational facilities at the Army Staff and Command College based on information technology for online learning, expanding the capacity of the Army Staff and Command College's website for Lecturer and Officers activities, US well the US increasing the abilities of lecturers in the teaching and learning process. This study concludes that the program can still be carried out by complying with strict health protocols, making internal breakthroughs at Army Staff and Command College, including the education curriculum, educators, students, and an independent online learning support media at Army Staff and Command College has a level of security verified by the Army Information and Data Processing Service units and the Army Cyber and Crypto Center.Keywords: Army Command and Staff College, COVID-19 Pandemic, General Development Education, offline learning, online learning
Abstract - Bais TNI is the implementing agency at the level of TNI Headquarters directly under the commander in charge of organizing activities and strategic intelligence operations as well as the construction of strategic strength and intelligence in order to support the Duty of TNI. Intelligence operations based on its functions there are 3 (three) namely research intelligence operations, security intelligence operations/counter-intelligence, and intelligence-raising operations. The fundraising operation by Bais TNI in the country was carried out in conflict areas/former conflicts as in Aceh by issuing a task force raising to the operating area. The implementation of the raising operations in the former conflict area in Aceh can be executed optimally task. But in fact, the ability of the task force to raise the Bais TNI in Aceh in 2018 is considered not optimal and has not been in accordance with expectations, so it is necessary to analyze an ability that is expected to be the optimal achievement of the task. The research aims to analyze the ability of the task force to raise the Bais TNI in Aceh in 2018 and efforts to improve the ability of the task force to raise the Bais TNI. The qualitative research method of descriptive analysis is based on the philosophy of Postpositivism, used to examine the condition of natural objects where the researcher is a critical instrument, sampling data sources Conducted following the achievement of research objectives. The results showed that the ability of the task force to raise the Bais TNI in Aceh in 2018 is not optimal in some indicators and experienced many shortcomings, such as in terms of personnel skills, education, and several personnel and support facilities Infrastructure. Efforts that can be implemented to improve the force's ability are to improve the quality and quantity of personnel. The intelligence education, skills in tactics and techniques of raising, the recruitment of Taskforce personnel who are Qualified and modern infrastructures in the implementation of tasks so that the achievement of tasks can be optimal.Keywords: intelligence operations raising, ability
Abstract-The State Capital is the center of gravity of a nation where its domicile is the center of government of a country, as well as the place where administrative elements, namely the executive, legislative, and judiciary are gathered. The conduciveness and stability of the National Capital need to be a concern because various vital state objects are contained in it. Indonesia, with its five pillars of the World Maritime Axis (PMD), is still struggling with issues of maritime threats that often arise in the form of encroachment on territorial boundaries, theft of marine products, and other illegal activities. As an archipelagic country with a wide border gate in the form of the sea, the violations that occur are often difficult to control. Indonesia has enormous marine potential that requires the attention of the state in order to create protection from threats to sovereignty in the maritime territory of the archipelago. Moreover, the National Capital of the Archipelago is adjacent to the Makassar Strait, which is an international shipping lane, namely the Indonesian Archipelago Sea Route (ALKI) II. ALKI II passes through the Sulawesi Sea, Makassar Strait, Flores Sea, and Lombok Strait connecting the Pacific Ocean and the Indian Ocean. The development of the maritime defense of the National Capital City is urgent that really need to be the attention of all stakeholders in the defense of the State of Indonesia.Keywords: Maritime Security, Nusantara's Capital City, Threat, Makassar Strait, Global Maritime Fulcrum
Social media fuels fake news’ spread across the world. English news has dominated existing fake news research, and how fake news in different languages compares remains severely under studied. To address this scarcity of literature, this research examines the content and linguistic behaviors of fake news in relation to COVID-19. The comparisons reveal both differences and similarities between English and Spanish fake news. The findings have implications for global collaboration in combating fake news.
The cybersecurity threat landscape has lately become overly complex. Threat actors leverage weaknesses in the network and endpoint security in a very coordinated manner to perpetuate sophisticated attacks that could bring down the entire network and many critical hosts in the network. To defend against such attacks, cybersecurity solutions are upgrading from the traditional to advanced deep and machine learning defense mechanisms for threat detection and protection. The application of these techniques has been reviewed well in the scientific literature. Deep Reinforcement Learning has shown great promise in developing AI solutions for areas that had earlier required advanced human cognizance. Different techniques and algorithms under deep reinforcement learning have shown great promise in applications ranging from games to industrial processes, where it is claimed to augment systems with general AI capabilities. These algorithms have recently also been used in cybersecurity, especially in threat detection and protection, where these are showing state-of-the-art results. Unlike supervised machine learning and deep learning, deep reinforcement learning is used in more diverse ways and is empowering many innovative applications in the threat defense landscape. However, there does not exist any comprehensive review of deep reinforcement learning applications in advanced cybersecurity threat detection and protection. Therefore, in this paper, we intend to fill this gap and provide a comprehensive review of the different applications of deep reinforcement learning in this field.
The last five years have shown a tremendous increase in the number of Android smartphone users. So has been the case with malicious Android applications that aim to jeopardize user data, security, and privacy. Most existing Android malware detection engines find it challenging to keep up with the pace of incoming malware and their sophistication of evasion techniques against the detection engines. This has prompted researchers to delve into using machine learning and deep learning algorithms to construct state-of-the-art malware detection models. However, research indicates that these detection models might be vulnerable to adversarial attacks prompting a thorough investigation. Therefore, we first propose a image based malware detection pipeline that uses an embedding layer-based hybrid CNN named E-CNN that uses Android permissions and intents as features for malware detection. The permission and intent based E-CNN detection models achieved baseline accuracy of 93.48% and 76.7% respectively. We then act as an adversary and propose the ECO-FGSM adversarial evasion attack against the above detection models. The ECO-FGSM attack converts malware samples into adversarial malware samples so that they are forcefully misclassified as benign by the detection models. The proposed attack achieved a high fooling rate of 55.72% and 99.97% against permission and intent based E-CNN detection models, respectively. We also identified a list of most vulnerable permissions and intents to generate adversarial samples. We then use adversarial retraining as a defense strategy to counter the ECO-FGSM attack against the detection models. The adversarial defense helped improve the baseline accuracies of permission and intent based E-CNN detection models by 3.41% and 11.4%, respectively. We reattack the adversarially retrained models using the ECO-FGSM attack to validate their adversarial robustness. We found a reduction in the fooling rate by 23.28% and 97.55% against permission and intent-based E-CNN detection models, respectively. Finally, we conclude that investigating the adversarial robustness of the malware detection models is an essential step that helps improve their performance and robustness before real-world deployment.
With digitization, critical infrastructures face a higher risk of security incidents and attacks on cyber-physical systems (CPS). In the past 50 years, research and practice have developed various approaches to monitor and detect attacks such as with anomaly detection. While many approaches focuses on artificial neural networks, bio-inspired approaches utilize nature as reference. For example, artificial immune systems (AIS) refer to principles of the natural immune system. In this paper, we investigate the Negative Selection Algorithm (NSA), an algorithm from the domain of AIS for anomaly detection in CPS. Particularly in CPS, datasets can become quite complex and can require a number of detectors for the analysis. Therefore, we will investigate how AIS can be extended to handle and manage complex datasets of CPS. We propose two models that use Principal Component Analysis (PCA) and Autoencoder (AE) to enable dimensionality reduction. Using these models, we are able to show that it is possible to apply the NSA approach to such datasets. Our results indicate that the use of PCA and AE is beneficial for both a better representation of the data and therefore significantly relevant for an improvement of the detection rate, and provides in addition the possibility to add further features to support the identification of anomalies. As the NSA approach allows for distributed computation, it might be possible to allow faster or distributed detection; the extent to which this is possible remains to be investigated and therefore represents future work.
Android applications are extremely popular, as they are widely used for banking, social media, e-commerce, etc. Such applications typically leverage a series of Permissions, which serve as a convenient abstraction for mediating access to security-sensitive functionality, e.g., sending data over the Internet, within the Android Ecosystem. However, several malicious applications have recently deployed attacks such as data leaks and spurious credit card charges by abusing the Permissions granted initially to them by unaware users in good faith. To alleviate this pressing concern, we present DyPolDroid, a dynamic and semi-automated security framework that builds upon Android Enterprise, a device-management framework for organizations, to allow for users and administrators to design and enforce so-called Counter-Policies, a convenient user-friendly abstraction to restrict the sets of Permissions granted to potential malicious applications, thus effectively protecting against serious attacks without requiring advanced security and technical expertise. Additionally, as a part of our experimental procedures, we introduce Laverna, a fully operational application that uses permissions to provide benign functionality at the same time it also abuses them for malicious purposes. To fully support the reproducibility of our results, and to encourage future work, the source code of both DyPolDroid and Laverna is publicly available as open-source.
Metacognition plays important roles in human judgments. In this study, we study two types of metacognitive skills, namely calibration and resolution, in individuals’ judgments of phishing emails. Drawing upon the Probabilistic Mental Model (PMM) and past research on phishing detection, we examine individual- and task-related factors and their impacts on both skills. Results from an online survey experiment show that task-related factors (i.e., email familiarity, judgment time, variability of judgment time, and task easiness) influence calibration while both task- and individual-related factors (i.e., online transaction experience, victimization experience, email entity familiarity, and variability of judgment time) influence resolution. Interventions to improve individuals’ metacognition in phishing email detection are discussed.
The majority of online services continue their reliance on text-based passwords as the primary means of user authentication. With a growing number of these services and the limited creativity and memory to come up with new memorable passwords, users tend to reuse their passwords across multiple platforms. These factors, combined with the increasing amount of leaked passwords, make passwords vulnerable to cross-site guessing attacks. Over the years, several popular methods have been proposed to predict subsequently used passwords, such as dictionary attacks, rule-based approaches, neural networks, and combinations of the above. In this paper, we work with a dataset of 28 8 million users and their 61.5 million passwords, where there is at least one pair of passwords available for each user. We exploit the correlation between the similarity and predictability of these subsequent passwords. We build on the idea of a rule-based approach but delegate rule derivation, classification, and prediction to a Recurrent Neural Network (RNN). We limit the number of guessing attempts to ten yet get an astonishingly high prediction accuracy of up to 83% in under five attempts in several categories, which is twice as much as any other known models or algorithms. It makes our model an effective solution for real-time password guessing against online services without getting spotted or locked out. To the best of our knowledge, this study is the first attempt of its kind using RNN.