Smart Cities have become a global strategy. However, massive data generated by various smart devices need to be uploaded and stored to the cloud servers. It is critical to ensure the integrity and privacy of the stored data. Quite a few public cloud auditing schemes have been proposed recently. However, most of them use bilinear pairing operations in the audit phase, requiring a significant time cost. Meanwhile, users (may be resource constrained mobile devices or sensor nodes) still need to perform significant computations, like computing meta data for each data block, which bring a huge burden of calculation for these users. Moreover, those schemes cannot effectively protect users' data privacy. Thus, we propose a lightweight and privacy-preserving public cloud auditing scheme for smart cities that does not require bilinear pairings. First, the proposed scheme is pairing-free, and allowing a third party auditor to generate authentication meta set on behalf of users. Furthermore, it also protects data privacy against the third party auditor and the cloud service providers. In addition, this new scheme can be easily and naturally extended to batch auditing in a multi-user scenario. Detailed security and performance analyses show that the proposed scheme is more secure and efficient compared to the existing public cloud auditing schemes.
We live in a world where we attempt to keep credit card numbers as a secret. However we have seen large scale hacking into companies such as Target, Equifax, Home Depot, PayPal, Sak's, Lord & Taylors, and many others. Financial credit card companies spend millions of dollars each year replacing consumers' cards because of risk of fraudulent charges. Businesses are spending millions of dollars ensuring these numbers are protected within their IT infrastructure. Businesses are losing millions of dollars in stolen merchandise due to fraudulent use of credit cards. The Blockchain technology can be used to prevent these losses from being incurred. This paper analyzes how the Blockchain technology could be used, how it can be secure, and how it can alleviate the risk to credit card data. In addition, this paper identifies and defines a system that can be developed using existing technologies, such as, two factor identification, SMS text messaging, and biometrics to prevent credit card breaches.
Real "black hat" hackers use their skills to provide malicious attacks against government, institutions and other organizations for either financial benefits, methods of protest or publicity. Although it is true that most hackers prefer Linux operating systems, many advanced attacks occur in Microsoft Windows in plain sight. Linux is an easy target for hackers because it is an open-source system. This means that millions of lines of code can viewed publicly and can easily be modified. The system is very flexible, and the hacker can easily check for vulnerabilities through penetration testing, while also having the capabilities to hide their tracks. Windows is a required, but dreaded target for most hackers because it requires them to work in Windows-only environments. It is much more restrictive than Linux, yet is still vulnerable because most exploits are directed at targets running on Windows operating systems. These types of attacks can only be approached in a Windows based environment. This research paper will compare different operating systems used to hack, with a focus of Linux and Windows. It will explain the methodology behind why Hackers choose Linux, as their system of choice to and include key preferences such as source code and interface types. This paper will also cover some of the most popular operating systems besides Linux and Windows for 2017, including: Parrot Security OS, Samurai, Pentoo and Bugtraq.
Due to the rapid developments of cloud technologies, mobile devices, especially smartphones, have become much more powerful, bringing people great convenience. People can do many things on their smartphones: checking email, updating Facebook/Snapchat/Instagram, or shopping via different apps. With all these applications, people tend to access their smartphones frequently and instantly, i.e., they want to use the phone right away. On the other hand, more and more sensitive information is now stored or accessible on smartphones such as Visa Signature or Paypal apps. Smartphones need to be protected more than ever before.
Vehicles currently on the market are more like computers on wheels than most consumers would even begin to consider. Instead, they research and debate about the latest safety features and whether or not the vehicle is able to connect to the internet, or how big the LED screen is in the center consol. Rarely do they consider if their new vehicle could be hacked in a fashion similar to their home PC. Thanks to white hat hackers, attacks on vehicles are being brought into the spotlight, which is making vehicle cybersecurity a priority with both vehicle manufacturers and politicians, through both design and US Senate bills. This paper explores the means by which a vehicle could potentially be hacked, what ramifications come from a hacking attack, and how a vehicle could be protected against attacks.
Aggregate signature algorithms combine n signatures on n different messages from n distinct users into one aggregated signature. The aggregated signature allows the verifier to authenticate the n signatures simultaneously. Because the total signature length and authentication costs are significantly reduced, aggregate signature algorithms are attractive to applications with resource constraints and applications requiring efficient batch authentications. In this paper, we propose a novel aggregate signature scheme based on certificateless-PKC. Under this novel scheme, the length of the aggregated signature and the pairing computation cost in the aggregate signature verification process are independent of the number of signatures being aggregated. We also prove that the proposed scheme is existentially unforgeable against adaptive chosen-message and chosen-identity attacks, based on the hardness assumption of the computational Diffie-Hellman problem. The new scheme will be suitable for resource-constrained applications. Copyright (C) 2016 John Wiley & Sons, Ltd.
With the rapid progresses in ICT (Information Communication Technology), multidisciplinary research fields such as Internet of Things (IoT), Cyber-Physical System (CPS), and Social Computing have been widely explored in recent years. These research and application have speeded up the formation of cyberspace, which will further lead to a subversive change for information science development as well as human production and living (Ma and Yang, 2015). Cyberspace is being linked to versatile individuals in physical space and social space — Cyber-Physical Society (CPSoc) (Zhuge, 2014). This special issue on new technologies and research trends for cyber physical systems technologies and application provides high quality contributions addressing related theoretical and practical aspects of CPS technologies and their applications. We have selected five research papers whose topics are strongly related to this special issue.
Due to the flexibility of wireless mesh networks (WMNs) to form the backhaul subnetworks, future generation networks may have to integrate various kinds of WMNs under possibly various administrative domains. Aiming at establishing secure access and communications among the communication entities in a multi-domain WMN environment, in this paper, we intend to address the cross-domain authentication and key agreement problem. We present a light-weight cross-domain authentication and key agreement protocol, namely CAKA , under certificateless-based public key cryptosystem. CAKA has a few attractive features. First, mutual authentication and key agreement between any pair of users from different WMN domains can be easily achieved with two-round interactions. Second, no central domain authentication server is required and fast authentication for various roaming scenarios is supported by using a repeated cross-domain algorithm. Third, no revocation and renewal of certificates and key escrow are needed. Finally, it provides relatively more security features without increasing too much overhead of computation and storage. Our analysis shows that the proposed CAKA protocol is highly efficient in terms of communication overhead and resilient to various kinds of attacks.
Denial of service (DoS) attacks have been around for a significant period of time and is exponentially growing in popularity. This paper discusses various DoS attacks and the evolution towards distributed denial of service (DDoS) attacks. An analysis of high profile attacks will be conducted to evaluate the methods used by the attackers. We will also describe the roles of enterprise, consumers, and ISPs in reducing the damage and frequency of the attacks.
1Department of Industrial Security, College of Business and Economics, Chung-Ang University, Seoul 156-756, Republic of Korea 2Department of Computer Science and Information Technology, La Trobe University, Melbourne, VIC 3086, Australia 3Department of Multimedia, Sungkyul University, Anyang, Gyeonggi-do 430-742, Republic of Korea 4XLIM Laboratory, University of Limoges, 87060 Limoges Cedex, France 5Department of Math, Computer Science and Computer Information Systems, California University of Pennsylvania, California, PA 15419, USA 6Division of Convergence Computer & Media, Mokwon University, Daejeon 302-729, Republic of Korea
Mobile devices have become so prevalent in human's life. Mobile operating systems (MOS) will be the next big thing in operating systems to provide security protection to mobile devices. Compared to desktop operating systems, MOS are so new in their life cycle. In this paper, we present the future directions to develop MOS to protect devices and data. We also discuss approaches that could be used to secure phones and information before secure MOS become available.
With the flood and popularity of various multimedia contents on the Internet, intelligent interactive multimedia services such as personalization and adaptability have become essential in recent multimedia systems. For this reason, they need to be interactive not only through classical modes of interactionwhere a user inputs information through a keyboard ormouse, but also through advanced interaction modes which are more attractive, more user friendly, more human-like and more informative [9]. We have received 18 manuscripts. Each manuscript was blindly reviewed by at least three reviewers consisting of guest editors and external reviewers. After the first and second review processes, eight manuscripts were finally selected to be included in this special issue. In Section 2 and 3, we present a brief description about the signal processing and HCI (Human Computer Interaction) issues for interactive multimedia services, respectively. In the last section, we conclude the paper with some observations and future work.
Land monitoring is a critical task to ensure the quality of agricultural production. Traditional precision agriculture techniques require intensive computation and expensive hardware devices. This paper explores the techniques of deploying sensor networks in the field for practical land monitoring. As an example, we accurately measure the dark-area/light-area ratios in agriculture fields based on the Monte Carlo theory. We formulate the minimum sensor deployment problem, whose aim is to minimize the number of sensor nodes needed to achieve measurement precision requirements while satisfying size limitation requirements. Size limitation requirements are specified so that manual treatments can be carried on sub-regions that have an extraordinary dark/light ratio. We propose an incremental deployment solution - INCOME - to solve the problem, which does not require any prior knowledge of the dark/light distribution of the field. A split/merge algorithm is designed in INCOME to divide the monitored field into sub-regions satisfying both requirements. We formally prove that the sensor number needed in INCOME is less than that of regular division, and analyze the sensors needed in the ideal case and worst case. Comprehensive simulation studies demonstrate that the performance of INCOME is close to the optimal solution.
Recent advances in pervasive computers, networks, telecommunication, and information technology, along with the proliferation of multimedia-capable mobile devices, such as laptops, portable media players, personal digital assistants, and cellular telephones, have stimulated the development of intelligent and pervasive multimedia applications in a ubiquitous environment.The new multimedia standards (for example, MPEG-21) facilitate the seamless integration of multiple modalities into interoperable multimedia frameworks, transforming the way people work and interact with multimedia data.These key technologies and multimedia solutions interact and collaborate with each other in increasingly effective ways, contributing to the multimedia revolution and having a significant impact across a wide spectrum of consumer, business, healthcare, education, and governmental domains.This conference provides an opportunity for academic and industry professionals to discuss recent progress in the area of multimedia and ubiquitous environment including models and systems, new directions, novel applications associated with the utilization and acceptance of ubiquitous computing devices and systems.We have received 41 manuscripts.After the pre-review process, 28 manuscripts were selected for the first review.
In wireless sensor networks, clustering is an effective technique to extend the network lifetime. However, in the multi-hop clustering model, if the nodes are uniformly distributed and the clusters are of equal size, the cluster heads closer to the sink have to relay much heavier traffic, leading to the “energy hole” problem. Unequal clustering structures have been proposed to mitigate the “energy hole” problem; but, how to quantify the cluster sizes for the aim of scalability and energy hole avoidance remains as a challenging problem. In this paper, we first investigate the theoretical issues of the unequal clustering strategy in uniformly distributed sensor networks. We then propose a method to construct optimal clustering architecture to minimize the total energy consumption of all sensor nodes. Furthermore, we design simple but effective and distributed protocols for energy-aware cluster-head rotation and routing that achieve even energy consumption among all nodes. Extensive simulations show that the performance of our approach extends the network lifetime in two to three times of the one achieved in the best-so-far unequal clustering-based routing.
During the last decades, many researchers in image processing and AI community have been focused on developing image and video analysis and understanding. However, despite their extensive efforts on these, there are still several significant challenges such as robust object segmentation and tracking, motion feature extraction, context modeling, and machine learning algorithms. Therefore, more advanced related issues should be taken into account. We have selected nine research papers whose topics are strongly related to the intelligent surveillance system in smart home environment.
The recently proposed TCP-targeted Low-rate Distributed Denial-of-Service (LDDoS) attacks send fewer packets to attack legitimate flows by exploiting the vulnerability in TCP’s congestion control mechanism. They are difficult to detect while causing severe damage to TCP-based applications. Existing approaches can only detect the presence of an LDDoS attack, but fail to identify LDDoS flows. In this paper, we propose a novel metric – Congestion Participation Rate (CPR) – and a CPR-based approach to detect and filter LDDoS attacks by their intention to congest the network. The major innovation of the CPR-base approach is its ability to identify LDDoS flows. A flow with a CPR higher than a predefined threshold is classified as an LDDoS flow, and consequently all of its packets will be dropped. We analyze the effectiveness of CPR theoretically by quantifying the average CPR difference between normal TCP flows and LDDoS flows and showing that CPR can differentiate them. We conduct ns-2 simulations, test-bed experiments, and Internet traffic trace analysis to validate our analytical results and evaluate the performance of the proposed approach. Experimental results demonstrate that the proposed CPR-based approach is substantially more effective compared to an existing Discrete Fourier Transform (DFT)-based approach – one of the most efficient approaches in detecting LDDoS attacks. We also provide experimental guidance to choose the CPR threshold in practice.
Wireless access points (APs) divide a plane into small areas where their coverage ranges overlap. A mobile device can be located within a particular small overlapped area based on the unique set of APs covering the device. We formally define an optimal AP deployment problem for both coverage and area localization. Our objective is to deploy a minimum number of APs that provide full communication coverage while achieving the ability to locate a mobile device within a certain area no larger than a given accuracy parameter. We propose a set of optimal solutions and approximations to this problem under the diamond pattern, a deployment pattern that has been shown to achieve optimal coverage in most cases. We conduct extensive numerical evaluation as well as real experiments to validate our proposed solutions.
Peer-to-peer (P2P) networks and applications represent an efficient method of distributing various network contents across the Internet. Foremost among these networks is the BitTorrent protocol. While BitTorrent has become one of the most popular P2P applications, attacking BitTorrent applications recently began to arise. Although sources of the attacks may be different, their main goal is to slow down the distribution of files via BitTorrent networks. This paper provides an experimental study on peer attacks in the BitTorrent applications. Real BitTorrent network traffic was collected and analyzed, based on which, attacks were identified and classified. This study aims to better understand the current situation of attacks on BitTorrent applications and provide supports for developing possible approaches in the future to prevent such attacks.
Zihui Ge合作论文数Network Management and Engineering Department
AT&T Labs - Research2