The Experts below are selected from a list of 42 Experts worldwide ranked by ideXlab platform

Keith S. Jones - One of the best experts on this subject based on the ideXlab platform.

  • abuse of the cloud as an Attack Platform
    Computer Software and Applications Conference, 2020
    Co-Authors: Moitrayee Chatterjee, Prerit Datta, Faranak Abri, Akbar Siami Namin, Keith S. Jones
    Abstract:

    We present an exploratory study of responses from 75 security professionals and ethical hackers in order to understand how they abuse cloud Platforms for Attack purposes. The participants were recruited at the Black Hat and DEF CON conferences. We presented the participants' with various Attack scenarios and asked them to explain the steps they would have carried out for launching the Attack in each scenario. Participants' responses were studied to understand Attackers' mental models, which would improve our understanding of necessary security controls and recommendations regarding precautionary actions to circumvent the exploitation of clouds for malicious activities. We observed that in 93.78% of the responses, participants are abusing cloud services to establish their Attack environment and launch Attacks.

  • Cloud as an Attack Platform
    arXiv: Cryptography and Security, 2020
    Co-Authors: Moitrayee Chatterjee, Prerit Datta, Faranak Abri, Akbar Siami Namin, Keith S. Jones
    Abstract:

    We present an exploratory study of responses from $75$ security professionals and ethical hackers in order to understand how they abuse cloud Platforms for Attack purposes. The participants were recruited at the Black Hat and DEF CON conferences. We presented the participants' with various Attack scenarios and asked them to explain the steps they would have carried out for launching the Attack in each scenario. Participants' responses were studied to understand Attackers' mental models, which would improve our understanding of necessary security controls and recommendations regarding precautionary actions to circumvent the exploitation of clouds for malicious activities. We observed that in 93.78% of the responses, participants are abusing cloud services to establish their Attack environment and launch Attacks.

Moitrayee Chatterjee - One of the best experts on this subject based on the ideXlab platform.

  • abuse of the cloud as an Attack Platform
    Computer Software and Applications Conference, 2020
    Co-Authors: Moitrayee Chatterjee, Prerit Datta, Faranak Abri, Akbar Siami Namin, Keith S. Jones
    Abstract:

    We present an exploratory study of responses from 75 security professionals and ethical hackers in order to understand how they abuse cloud Platforms for Attack purposes. The participants were recruited at the Black Hat and DEF CON conferences. We presented the participants' with various Attack scenarios and asked them to explain the steps they would have carried out for launching the Attack in each scenario. Participants' responses were studied to understand Attackers' mental models, which would improve our understanding of necessary security controls and recommendations regarding precautionary actions to circumvent the exploitation of clouds for malicious activities. We observed that in 93.78% of the responses, participants are abusing cloud services to establish their Attack environment and launch Attacks.

  • Cloud as an Attack Platform
    arXiv: Cryptography and Security, 2020
    Co-Authors: Moitrayee Chatterjee, Prerit Datta, Faranak Abri, Akbar Siami Namin, Keith S. Jones
    Abstract:

    We present an exploratory study of responses from $75$ security professionals and ethical hackers in order to understand how they abuse cloud Platforms for Attack purposes. The participants were recruited at the Black Hat and DEF CON conferences. We presented the participants' with various Attack scenarios and asked them to explain the steps they would have carried out for launching the Attack in each scenario. Participants' responses were studied to understand Attackers' mental models, which would improve our understanding of necessary security controls and recommendations regarding precautionary actions to circumvent the exploitation of clouds for malicious activities. We observed that in 93.78% of the responses, participants are abusing cloud services to establish their Attack environment and launch Attacks.

Jeffrey Carr - One of the best experts on this subject based on the ideXlab platform.

  • inside cyber warfare
    2011
    Co-Authors: Jeffrey Carr, Michael Chertoff
    Abstract:

    Inside Cyber Warfare provides fascinating and disturbing details on how nations, groups, and individuals throughout the world use the Internet as an Attack Platform to gain military, political, and economic advantages over their adversaries. You'll discover how sophisticated hackers working on behalf of states or organized crime patiently play a high-stakes game that could target anyone, regardless of affiliation or nationality. The second edition goes beyond the headlines of attention-grabbing DDoS Attacks and takes a deep look inside recent cyber-conflicts, including the use of Stuxnet. It also includes a Forward by Michael Chertoff (former Secretary of Homeland Security) and several guest essays, including one by Melissa Hathaway, former senior advisor to the Director of National Intelligence and Cyber Coordination Executive. Get an in-depth look at hot topics including: * The role of social networks in fomenting revolution in the Middle East and Northern Africa * The Kremlin's strategy to invest heavily in social networks (including Facebook) and how it benefits the Russian government * How the U.S. Cyber Command and equivalent commands are being stood up in other countries * The rise of Anonymous with analysis of its anti-structure and operational style or tempo * Stuxnet and its predecessors, and what they reveal about the inherent weaknesses in critical infrastructure * The Intellectual Property (IP) war, and how it has become the primary focus of state-sponsored cyber operations

  • inside cyber warfare mapping the cyber underworld
    2009
    Co-Authors: Jeffrey Carr
    Abstract:

    What people are saying about Inside Cyber Warfare "The necessary handbook for the 21st century." --Lewis Shepherd, Chief Tech Officer and Senior Fellow, Microsoft Institute for Advanced Technology in Governments "A must-read for policy makers and leaders who need to understand the big-picture landscape of cyber war." --Jim Stogdill, CTO, Mission Services Accenture You may have heard about "cyber warfare" in the news, but do you really know what it is? This book provides fascinating and disturbing details on how nations, groups, and individuals throughout the world are using the Internet as an Attack Platform to gain military, political, and economic advantages over their adversaries. You'll learn how sophisticated hackers working on behalf of states or organized crime patiently play a high-stakes game that could target anyone, regardless of affiliation or nationality. Inside Cyber Warfare goes beyond the headlines of attention-grabbing DDoS Attacks and takes a deep look inside multiple cyber-conflicts that occurred from 2002 through summer 2009. Learn how cyber Attacks are waged in open conflicts, including recent hostilities between Russia and Georgia, and Israel and Palestine Discover why Twitter, Facebook, LiveJournal, Vkontakte, and other sites on the social web are mined by the intelligence services of many nations Read about China's commitment to penetrate the networks of its technologically superior adversaries as a matter of national survival Find out why many Attacks originate from servers in the United States, and who's responsible Learn how hackers are "weaponizing" malware to Attack vulnerabilities at the application level

Ivan Seskar - One of the best experts on this subject based on the ideXlab platform.

  • security and privacy vulnerabilities of in car wireless networks a tire pressure monitoring system case study
    USENIX Security Symposium, 2010
    Co-Authors: Ishtiaq Rouf, Rob Miller, Hossen Mustafa, Travis Taylor, Sangho Oh, Wenyuan Xu, Marco Gruteser, Wade Trappe, Ivan Seskar
    Abstract:

    Wireless networks are being integrated into the modern automobile. The security and privacy implications of such in-car networks, however, have are not well understood as their transmissions propagate beyond the confines of a car's body. To understand the risks associated with these wireless systems, this paper presents a privacy and security evaluation of wireless Tire Pressure Monitoring Systems using both laboratory experiments with isolated tire pressure sensor modules and experiments with a complete vehicle system. We show that eavesdropping is easily possible at a distance of roughly 40m from a passing vehicle. Further, reverse-engineering of the underlying protocols revealed static 32 bit identifiers and that messages can be easily triggered remotely, which raises privacy concerns as vehicles can be tracked through these identifiers. Further, current protocols do not employ authentication and vehicle implementations do not perform basic input validation, thereby allowing for remote spoofing of sensor messages. We validated this experimentally by triggering tire pressure warning messages in a moving vehicle from a customized software radio Attack Platform located in a nearby vehicle. Finally, the paper concludes with a set of recommendations for improving the privacy and security of tire pressure monitoring systems and other forthcoming in-car wireless sensor networks.

Prerit Datta - One of the best experts on this subject based on the ideXlab platform.

  • abuse of the cloud as an Attack Platform
    Computer Software and Applications Conference, 2020
    Co-Authors: Moitrayee Chatterjee, Prerit Datta, Faranak Abri, Akbar Siami Namin, Keith S. Jones
    Abstract:

    We present an exploratory study of responses from 75 security professionals and ethical hackers in order to understand how they abuse cloud Platforms for Attack purposes. The participants were recruited at the Black Hat and DEF CON conferences. We presented the participants' with various Attack scenarios and asked them to explain the steps they would have carried out for launching the Attack in each scenario. Participants' responses were studied to understand Attackers' mental models, which would improve our understanding of necessary security controls and recommendations regarding precautionary actions to circumvent the exploitation of clouds for malicious activities. We observed that in 93.78% of the responses, participants are abusing cloud services to establish their Attack environment and launch Attacks.

  • Cloud as an Attack Platform
    arXiv: Cryptography and Security, 2020
    Co-Authors: Moitrayee Chatterjee, Prerit Datta, Faranak Abri, Akbar Siami Namin, Keith S. Jones
    Abstract:

    We present an exploratory study of responses from $75$ security professionals and ethical hackers in order to understand how they abuse cloud Platforms for Attack purposes. The participants were recruited at the Black Hat and DEF CON conferences. We presented the participants' with various Attack scenarios and asked them to explain the steps they would have carried out for launching the Attack in each scenario. Participants' responses were studied to understand Attackers' mental models, which would improve our understanding of necessary security controls and recommendations regarding precautionary actions to circumvent the exploitation of clouds for malicious activities. We observed that in 93.78% of the responses, participants are abusing cloud services to establish their Attack environment and launch Attacks.