id abstract abstract packet_id category_id flag_id protocol_id dummy_id order packet_flags_des abstract_id packet category_id category category sub_flag_id flag_bridge flag_id subflag_id sub_flag flag_id flags flag ACK SYN RST NULL FIN PSH URG XMAS portscan TCP/IP optional?
This experimental study suggests an alternative method of data deletion which can be considered secure up to an acceptable level for most purposes while maintaining anti-forensics characteristics. It is a quick and “dirty” solution to remove data from a storage medium while achieving to confuse the investigator about the contents of the i.e. the hard disk. More specifically, working upon the file system of the storage medium it fills all the empty space leaving no slack space available. Consequently, this approach could provide an insight today, as in how it could be used as an anti-forensics method tomorrow.
In this paper we present the findings of an analysis of approximately 260 second hand disks that was conducted in 2006. A third party organisation bought the disks from the second hand market providing a degree of anonymity. This paper will demonstrate the quantitative outcomes of the analysis and the overall experiences. It will look at how analysts can expand their tools and techniques in order to achieve faster results, how one can organise the analysis based on the way information is found and finally a holistic picture of the case should be generated following the proposed methodology.
Despite the existence of a number of advanced authentication mechanisms such as twofactor tokens, biometrics etc., the use of passwords is still the most popular means of authenticating users in a computing system. Consequently, we need to generate and remember a large number of passwords, and these passwords need to be as strong as the assets they protect. During the course of a forensic examination a computer forensics analyst may come across a number of situations where the recovery of passwords is required, either in order to access a particular user account, or to unlock encrypted or otherwise obfuscated digital content. In this paper we create a cognitive model to describe the creation of end-user generated passwords that may be applied particularly during an attempt to forensically recover such passwords. We propose that it may be feasible to recover a password by reversing the logic of its creation, taking into account contextual and other parameters, instead of applying computationally expensive brute force.
Universities have been targets of exploitation ever since the first university networks were created. Although security was not a prime objective, over the years different security systems where put in place to keep unauthorised users out. As the years pass these systems have implemented, in some cases, some intelligence. Unfortunately all, intelligent or not, have a common weakness. This weakness is the password a user is required to provide initially and then uses to login to the computer infrastructure.
The hypothesis of this project is based on the idea that it is possible to take unified intrusion related information stored in a predefined single database schema and perform a real-time threat assessment. Consequently, it is believed that the proposed architecture will provide an efficient way to detect a potential attack while it is in progress, identify the knowledge level of the attacker, prevent the attack and finally be able to suggest a series of countermeasures for this particular type of attack.
Throughout the several modern ways existing today for authenticating ourselves in a computerised environment, the use of alphanumeric pass-words still is the primary concept. If any other type of authentication fails (e.g. biometric scan of a fingertip) the use of a password entered the old fashioned way will provide access to the user. Consequently, the need of remembering as many passwords as possible and these passwords to be as strong as the assets they are protecting leads to the need of having a way to remember them whenever are needed. This paper tries to suggest an alternative way of 'remembering' passwords by simply trying to introduce a different way of thinking when a password is generated for the first time. Instead of trying to remember a forgotten password, it can be possible to ask the human brain to regenerate.
Vast amount of network traffic generated by distributed and heterogeneous Intrusion Detection System's could be unified and put together to form the source of a very detailed network event repository. However, this repository inevitably expands constantly making it difficult to query and build a holistic picture of the network activity stored within a reasonable time window. Consequently, there is a need for a more interactive approach that identifies and builds up an understanding of the network events as the data collection is progressing. The need to achieve this understanding efficiently brought forth the idea of creating a dynamic, interactive and flexible way to build attack signatures called digital footprints. Describing footprints by making use of the dynamic representation capabilities of eXtensible Markup Language (XML), feeds the threat assessment process with a notional understanding of what it should be looking for. This distinguishes the tasks that should be performed by each key element. Consequently, the engine that performs the threat assessment is based on a specific logic and the intelligence resides on the human factor that creates each digital footprint.
Despite the advantages by the Intrusion Detection community and Computer Network Defense, network infrastructures still suffers from the danger of targeted and untargeted network attacks. Most of the ongoing research is focused on protecting a single network or even a larger infrastructure without providing the bigger picture of how to protect a number of large homogeneous and heterogeneous network infrastructures. This can be achieved by combining their existing capabilities and by making them to work together in order to develop a holistic picture of how to perform network defense. Also, the need for more dynamic solution in the area of threat assessment by following the path of real-time analysis is presented. Finally, this work tries to explain, in realistic terms, up to what level security can be considered achievable and how existing intelligent technologies could be used in order to reach this point.