The purpose of this article is to review what is known about the technologies that internet child sex offenders use to abuse or exploit children, offenders' attitudes towards online security and surveillance risk, and their use of identity protection tactics and technologies. The peer‐reviewed literature on internet sex offenders published between 2000 and 2011 was surveyed. Internet child sex offenders use a mixture of new and old technologies to abuse children. Offenders' awareness of internet‐related risk appears to exist along a continuum. A number of psychological and demographic factors may influence offenders' perceptions of online security risk and their willingness to take security precautions. A surprisingly large number of apprehended offenders in the time period examined by this review did not seem to use any technologies to disguise their identities. A major research programme into internet offenders' use of identity protection technologies, and their use of technologies in general, is needed. Copyright © 2014 John Wiley & Sons, Ltd. ‘Internet child sex offenders use a mixture of new and old technologies to abuse children.’ Key Practitioner Messages: Internet child sex offenders use a variety of commonly available technologies, such as social networking sites and peer‐to‐peer platforms, to abuse children. Offenders are a diverse group when it comes to how they perceive risk and act on those perceptions. The risk perceptions and risk management behaviours of individual offenders can be dynamic. In the period surveyed by this review (2000–11), some studies found that surprisingly few offenders used technological measures to protect their identities. ‘Surprisingly few offenders used technological measures to protect their identities.’
In this paper, we explore the ‘interface’ between identity-based public key cryptography (ID-PKC) and mobile ad hoc networks (MANETs). In particular, we examine the problem of naming and namespace design in an identity-based key infrastructure (IKI). We examine the potential impact that different types of identifiers may have on the utility of ad hoc networks where an IKI provides the underlying key infrastructure. We also highlight a number of open problems inherent in extending namespaces to allow inter-operability amongst heterogeneous trust domains. Copyright © 2009 John Wiley & Sons, Ltd.
This paper presents a novel algorithm for enhancing the efficiency and robustness of distributed trust authority protocols for mobile ad hoc networks (MANETs). Our algorithm determines a quorum of trust authority nodes required for a distributed protocol run based upon a set of quality metrics and establishes an efficient routing strategy to contact these nodes. An implementation and efficiency analysis illustrates the viability of our algorithm for small tactical networks consisting of 50 to 150 nodes and shows an approximate 32% reduction in communication overhead over traditional broadcast-based approaches to trust authority computations.
Key management is perhaps the most complex and most vulnerable part of any cryptographic implementation. To date key generation and activation have been extensively studie in the context of mobile ad hoc and wireless sensor networks. However, a dearth of research exists in designing techniques for key deactivation (revocation) and even less so for key reactiva tion. In this paper we study key-revocation schemes that are well-suited for the ad-hoc network environment. Specifically, we present a novel scheme with the following characteristics: • Distributed: Our scheme requires no permanently available central authority. • Active: A sufficient number of selfish honest nodes are incentivised to revoke malicious nodes. • Secure: The scheme is secure against a large number of malicious nodes (30% of the network for an IDS-error rate of 15%). • IDS-error tolerant: Revocation decisions are based on IDS. Our scheme is active for any meaningful IDS (IDS error rate < 0.5) and secure for an IDS error rate of up to 29%. Several schemes in the literature have 2 of the first 3 properties (property number 4 is typically not explored), but this work is the first to possess all four. This makes our revocation scheme well-suited for environments such as ad hoc networks, which are very dynamic, have significant bandwidth-constraints, and where many nodes are vulnerable to compromise.
In this paper, we examine issues of trust and reputation in mobile ad hoc networks (MANETs). We look at a number of the trust and reputation models that have been proposed, and we highlight open problems in this area. Copyright © 2009 John Wiley & Sons, Ltd.
In this paper we present a new key-revocation scheme for ad hoc network environments with the following characteristics: Distributed: Our scheme does not require a permanently available central authority. Active: Our scheme incentivizes rational (selfish but honest) nodes to revoke malicious nodes. Robust: Our scheme is resilient against large numbers of colluding malicious nodes (30% of the network for a detection error rate of 15%). Detection error tolerant: Revocation decisions fundamentally rely on intrusion detection systems (IDS). Our scheme is active for any meaningful IDS (IDS error rate 0.5) and robust for an IDS error rate of up to 29%. Several schemes in the literature have two of the above four characteristics (characteristic four is typically not explored). This work is the first to possess all four, making our revocation scheme well-suited for environments such as ad hoc networks, which are very dynamic, have significant bandwidth-constraints, and where many nodes must operate under the continual threat of compromise.
In both the commercial and defence sectors a compelling need is emerging for the rapid, yet secure, dissemination of information across traditional organisational boundaries. In this paper we present a novel trust management paradigm for securing pan-organisational information flows that aims to address the threat of information leakage. Our trust management system is built around an economic model and a trust-based encryption primitive wherein: (i) entities purchase a key from a Trust Authority (TA) which is bound to a voluntarily reported trust score r, (ii) information flows are encrypted such that a flow tagged with a recipient trust score R can be decrypted by the recipient only if it possesses the key corresponding to a voluntarily reported score r < = R, (iii) the economic model (the price of keys) is set such that a dishonest entity wishing to maximise information leakage is incentivised to report an honest trust score r to the TA. This paper makes two important contributions. First, we quantify fundamental tradeoffs on information flow rate, information leakage rate and error in estimating recipient trust score R. Second, we present a suite of encryption schemes that realise our trust-based encryption primitive and identify computation and communication tradeoffs between them.
We propose a novel scheme that uses Trusted Computing technology to secure Grid workflows. This scheme allows the selection of trustworthy resource providers based on their platform states. The integrity and confidentiality of workflow jobs are provided using cryptographic keys that can only be accessed when resource provider platforms are in trustworthy states. In addition, platform attestation is used to detect potential workflow execution problems, and the information collected can be used for process provenance.
We present a secure e-commerce architecture that is resistant to client compromise and man-in-the-middle attacks on SSL. To this end, we propose several security protocols that use attestation techniques offered by the Trusted Computing Group (TCG). Using these protocols, we can ensure that the client configuration remains untampered and trusted for the duration of the transaction. In addition, confidential data, such as authentication passwords, are only accessible by the electronic commerce server to which the users intend to transfer their data. Since we employ a trusted third party that is responsible for verifying a client's platform configuration, our approach does not depend on trusted computing at the server but instead only requires minor modification to server logic.
We demonstrate how Trusted Computing technology can be used to enhance the security of Internet-based Card Not Present (CNP) transactions. We focus on exploiting features of Trusted Computing as it is being deployed today, relying only on the presence of client-side Trusted Platform Modules. We discuss the threats to CNP transactions that remain even with our enhancements in place, focussing in particular on the threat of malware, and how it can be ameliorated.
Pervasive computing, as a concept, holds the promise of simplifying daily life by integrating mobile devices and digital infrastructures into our physical world. Computers would invisibly integrate themselves into background environments, providing useful services to users, as well as contextual information as to their surroundings. Devices would be able to establish dynamic ad hoc networks to provide ubiquitous services. However, the open and dynamic characteristics of pervasive computing environments necessitate the requirements for some form of trust assumptions to be made. Trusted Computing as a component of devices that themselves hold the promise of ubiquity may be used as a means of bootstrapping such trust assumptions. In this paper, we propose a trust enforced pervasive computing environment using the primitives provided by a TPM. We present an application scenario that shows how services and data of critical information infrastructure can be protected.
Traditional approaches to information sharing use a highly conservative approach to deduce the meta- data for an output object x derived from input ob- jects y1, y2, ···, yn (e.g.: maximum over the se- curity labels of all input objects). Such approaches does not account for functions that explicitly down- grade the value of an object. Consequently, the se- curity labels in traditional approaches tend to mono- tonically increase as newer objects are derived from existing ones. In this paper we present a novel meta- data calculus for securing information flows. The metadata calculus defines a metadata vector space that supports a time varying value function that is computed as a function of the object's metadata and operators + and · to compute the metadata of an output object that is derived by downgrad- ing, transforming or fusing other objects. We also describe a concrete realization of our metadata cal- culus wherein the tightness of our value estimates competes in an optimization problem. We present several tradeoffs with space and accuracy and ex- plore a spectrum of solutions ranging from conser- vative to risk-based value estimates.
Recently, risk-based information trading has emerged as a new paradigm for securely sharing information across traditional organizational boundaries. In this paradigm, the risk of sharing information between organizations is characterized using expected losses (due, for example, to (un)intended information disclosure) and billed to a recipient. However, within risk-based information trading systems, quantifying the risks associated with sharing information is a non-trivial task, particularly when risk calculations depend on a number of factors. In this paper we introduce a data-centric metadata framework that extends risk-based information trading approaches by allowing one or more domains to exchange sensitive information based on metadata evaluated against internal risk assessments of the domains. We present a use case of our metadata framework using a coalition military scenario, wherein information flows can be controlled and regulated by our framework whilst allowing sufficiently high-quality tactical information to be disseminated.
the date of receipt and acceptance should be inserted later Abstract In this paper, we demonstrate how Trusted Computing technology can be used to enhance the security of Internet-based Card Not Present (CNP) transactions. We take a pragmatic approach, focusing here on exploiting features of Trusted Computing as it is being deployed today. Thus we rely only on the presence of client-side Trusted Platform Modules, rather than upon the \idealised" deployment in which Trusted Computing functionality is fully integrated with OS and CPU, and which still seems to be a distant prospect. In essence, our approach uses features of the Public Key Infrastructure that is inherent in Trusted Computing to build lightweight client-side enrollment and certiflcation processes; public key certiflcates are then used to underpin authentication for CNP payments. Using this approach we demonstrate how Trusted Platform Module (TPM) enabled platforms can integrate with SSL and 3-D Secure. We discuss the threats to CNP transactions that remain even with our enhancements in place, focussing in particular on the threat of malware, and how it can be ameliorated.
This paper shows how the functionality associated with EMV-compliant payment cards can be securely emulated in software on platforms supporting Trusted Computing technology. We describe a detailed system architecture encompassing user enrolment, card deployment (in the form of software), card activation, and subsequent transaction processing. Our proposal is compatible with the existing EMV transaction processing architecture, and thus integrates fully and naturally with already deployed EMV infrastructure. We show that our proposal, which effectively makes available the full security of PoS transactions for Internet-based CNP transactions, has the potential to significantly reduce the opportunity for fraudulent CNP transactions.
Risk-based information trading systems have recently emerged as a new paradigm for enabling information sharing in dynamic environments. Such systems build an information trading market whose commodity is information (quantized into objects) and whose currency is monetized evaluated risk. In these trading systems, risk is calculated by the information seller (and consequently charged to the information buyer) as a function of the value of the object and an information buyerpsilas propensity to divulge shared information (based on observed past behavior). Whilst standard techniques exist for evaluating the value of an object, determining the propensity of a buyer to leak information is somewhat more problematic. Ostensibly, a seller could rely on static pre-assigned credentials of the buyer, however, such credentials only provide a clue as to the buyerpsilas ldquotrustworthinessrdquo at the time of credential issuance and gives no indication of post-issuance behavior. In this paper, we propose the use of a information leakage monitoring subsystem as part of a larger risk trading system to detect information leakage. We propose a framework for the design of such a subsystem and identify the fundamental tradeoffs between maximum information leakage rates, delays in leakage detection, buyer budgetary constraints and inherent errors in the monitoring subsystem.
Mobile Adhoc Networks (MANETs) are networks designed to operate in volatile and rapidly changing environments. Nodes within these networks are intended to be freeroaming, self-organising, self-discovering and operate where dedicated infrastructure is either not present or only ephemerally available. Within such environments, resource-limited nodes are expected to make complex risk-based decisions (either collaboratively or individually) to decide whether to deactivate the keys of nodes exhibiting undesirable behaviour in the network. In this work we provide a taxonomy for deactivation strategies that exist in the literature and highlight a number of possible weaknesses in their deployment. We also present a more complex form of key deactivation decision making in the form of judgement analysis whereby a node may choose a key deactivation strategy based on available contextual information.
Trust is a measure of the behaviour that is expected of another party in a transaction; there are many approaches to estimating trust, many of which are based on combining direct and indirect experience of transactions into a recommendation. This paper reviews the types of attack that are found in existing reputation-based systems, and their relevance to both human teams and to future military networks. Many of the attacks are forms of misuse or misrepresentation. For a reputation- based system to take account of such attacks it must include assessments of service quality based on the wider context of a transaction or the outcomes of a large number of transactions; these requirements are difficult to meet in fully automated networks, so reputation systems may be unsuitable as the primary source of trust in dynamic military networks. The results also highlight the difference between unmediated and mediated human interactions.
Trusted computing is proving to be one of the most controversial technologies in recent years. Rather than become embroiled in the debate over possible (mis)appropriations of its technologies, the authors highlight some of the technical obstacles that might hinder trusted computing's widespread adoption.
Stephen Wolthusen合作论文数Information Security Group, Department of Mathematics
Royal Holloway, University of London1