The Experts below are selected from a list of 30 Experts worldwide ranked by ideXlab platform

Shambhu Upadhyaya - One of the best experts on this subject based on the ideXlab platform.

  • continuous authentication using behavioral biometrics
    International Workshop on Security, 2017
    Co-Authors: Shambhu Upadhyaya
    Abstract:

    Currently, the standard methods to authenticate a computer/network user typically occur once at the initial log-in. These authentication methods involve user proxies, especially passwords and smart cards such as common access cards (CACs) and service ID cards. Passwords suffer from a variety of vulnerabilities including brute-force and dictionary based attacks, while smart cards and other physical tokens used for authentication can be lost or stolen. As a result, the computer systems are extremely vulnerable to "masquerading attacks", which refers to illegitimate activity on a computer system when an unauthorized human or software impersonates a user on a computer system or network. These attacks can be challenging to detect as they are mostly carried out by insiders or people or software familiar with the authorized user. By actively and continually authenticating a user, intruders can be identified before they hijack the user session of an authorized individual who may have momentarily stepped away from his/her console. In this talk, we will present our results on continuous authentication using keystroke dynamics as the behavioral biometric. The methods we developed can also be readily extended to protecting wired and wireless networks, mobile devices, etc.

  • IWSPA@CODASPY - Continuous Authentication Using Behavioral Biometrics
    Proceedings of the 3rd ACM on International Workshop on Security And PrivacyAnalytics - IWSPA '17, 2017
    Co-Authors: Shambhu Upadhyaya
    Abstract:

    Currently, the standard methods to authenticate a computer/network user typically occur once at the initial log-in. These authentication methods involve user proxies, especially passwords and smart cards such as common access cards (CACs) and service ID cards. Passwords suffer from a variety of vulnerabilities including brute-force and dictionary based attacks, while smart cards and other physical tokens used for authentication can be lost or stolen. As a result, the computer systems are extremely vulnerable to "masquerading attacks", which refers to illegitimate activity on a computer system when an unauthorized human or software impersonates a user on a computer system or network. These attacks can be challenging to detect as they are mostly carried out by insiders or people or software familiar with the authorized user. By actively and continually authenticating a user, intruders can be identified before they hijack the user session of an authorized individual who may have momentarily stepped away from his/her console. In this talk, we will present our results on continuous authentication using keystroke dynamics as the behavioral biometric. The methods we developed can also be readily extended to protecting wired and wireless networks, mobile devices, etc.

Elizabeth A. Mann-salinas - One of the best experts on this subject based on the ideXlab platform.

  • Bacterial Contamination of Burn Unit Employee Identity cards.
    Journal of burn care & research : official publication of the American Burn Association, 2016
    Co-Authors: Nicole W. Caldwell, Charles H. Guymon, James K. Aden, Kevin S. Akers, Elizabeth A. Mann-salinas
    Abstract:

    The purpose of this study was to identify the presence or absence of pathogenic bacteria on burn intensive care unit employees' common access cards (CACs) and identity badges (IDs) and to identify possible variables that may increase risk for the presence of those bacteria. A prospective, cross-sectional study was conducted in our regional Burn Center in which bacterial swab specimens were collected from both the CAC and ID of 10 burn intensive care unit employees in each of five cohorts (nurses, respiratory therapists, physical therapists, physicians, and ancillary staff). Ten additional paired samples, collected from direct care staff in the outpatient burn clinic, served as control. Additional information described how the cards were worn and if/how they had been cleaned in the previous week. Fifty-eight CACs and 60 IDs were swabbed from participants. The overall contamination rate was 75%, with no trends identified based on how cards were worn. Bacteria were recovered from 86% (50/58) of CACs and 65% (39/60) of IDs, with CACs being significantly more contaminated overall than IDs (P < .01). In terms of potentially pathogenic bacteria, the overall rate was 3%, with 100% of those isolates coming from the outpatient clinic staff cohort (P < .001). When cleaned in the last week (n = 16), the contamination rate dropped to 50% overall (P = .003), indicating that even periodic cleaning appears to have a positive effect on bacterial contamination rates. The simple practice of routine identity card decontamination may reduce potential threats to patient safety as a result of nosocomial bacterial transmission.

Paul J. Granetto - One of the best experts on this subject based on the ideXlab platform.

  • Controls Over the Contractor common access Card Life Cycle
    2008
    Co-Authors: Paul J. Granetto, Donald A Bloomer, Carol N Gorman, Melinda M Oleksa, Dewayne J Mcosker, Michael D Durda, Hanh T Nguyen, Thomas T Nguyen, David M Staley, Anthony M Torres
    Abstract:

    Abstract : The overall objective of this audit was to determine whether controls over common access cards (CACs) provided to contractors were in place and worked as intended. Specifically, we determined whether DoD officials issued CACs to contractors, verified the continued need for contractors to possess CACs, and revoked and recovered CACs from contractors in accordance with DoD policies and procedures.

  • Accountability for Defense Security Service Assets With Personally Identifiable Information
    2008
    Co-Authors: Paul J. Granetto, Robert F Prinzbach, Kimberley A. Caprio, Patricia A Papas, Rhonda L. Ragsdale, Robert P Goldberg, Andrew R Macattram, David A Palmer, Antwan Jackson, Bridgette A Seebacher
    Abstract:

    Abstract : The management at the Defense Security Service (DSS) and personnel concerned with property accountability should read this report because it discusses accountability for assets that contain personally identifiable information (PII) and the requirements for reporting unauthorized disclosure of PII. DSS provides the Secretary of Defense, DoD Components, and Defense contractors security support services. In February 2005, DSS transferred responsibility for the personnel security investigation function to the Office of Personnel Management (OPM), along with 1,567 DSS employees. The former Director of DSS also transferred common access cards (CACs), safes, laptops, and auxiliary hard drives to OPM. DSS management in place during the transfer of the personnel security investigation function to OPM created a lack of accountability for assets, posing an undue risk of compromising PII for military, civilian, and contractor employees who were investigated for personnel security clearances between 1997 and 2005. Through substantial efforts of its current management, DSS located and confirmed by unique identifier 308 of an estimated 501 initially unaccounted-for laptops. DSS obtained additional information demonstrating reasonable assurance that the remaining 193 laptops did not leave control of Government personnel; therefore, PII contained on the laptops is not at risk. Although DSS has accounted for the 501 initially unaccounted-for laptops, the initial listing of 501 laptops was not accurate. Additional laptops may still need to be accounted for. DSS demonstrated to the Defense Privacy Office that there was no indication the unaccounted-for laptops had left the control of Government personnel. Based on the information provided by Defense Security Service, the Defense Privacy Office concluded that the risk of unauthorized disclosure of PII was not high enough to warrant public notification. Consequently, DSS did not issue a public notification. Although the Defense Privacy O

Anthony M Torres - One of the best experts on this subject based on the ideXlab platform.

  • Controls Over the Contractor common access Card Life Cycle
    2008
    Co-Authors: Paul J. Granetto, Donald A Bloomer, Carol N Gorman, Melinda M Oleksa, Dewayne J Mcosker, Michael D Durda, Hanh T Nguyen, Thomas T Nguyen, David M Staley, Anthony M Torres
    Abstract:

    Abstract : The overall objective of this audit was to determine whether controls over common access cards (CACs) provided to contractors were in place and worked as intended. Specifically, we determined whether DoD officials issued CACs to contractors, verified the continued need for contractors to possess CACs, and revoked and recovered CACs from contractors in accordance with DoD policies and procedures.

Nicole W. Caldwell - One of the best experts on this subject based on the ideXlab platform.

  • Bacterial Contamination of Burn Unit Employee Identity cards.
    Journal of burn care & research : official publication of the American Burn Association, 2016
    Co-Authors: Nicole W. Caldwell, Charles H. Guymon, James K. Aden, Kevin S. Akers, Elizabeth A. Mann-salinas
    Abstract:

    The purpose of this study was to identify the presence or absence of pathogenic bacteria on burn intensive care unit employees' common access cards (CACs) and identity badges (IDs) and to identify possible variables that may increase risk for the presence of those bacteria. A prospective, cross-sectional study was conducted in our regional Burn Center in which bacterial swab specimens were collected from both the CAC and ID of 10 burn intensive care unit employees in each of five cohorts (nurses, respiratory therapists, physical therapists, physicians, and ancillary staff). Ten additional paired samples, collected from direct care staff in the outpatient burn clinic, served as control. Additional information described how the cards were worn and if/how they had been cleaned in the previous week. Fifty-eight CACs and 60 IDs were swabbed from participants. The overall contamination rate was 75%, with no trends identified based on how cards were worn. Bacteria were recovered from 86% (50/58) of CACs and 65% (39/60) of IDs, with CACs being significantly more contaminated overall than IDs (P < .01). In terms of potentially pathogenic bacteria, the overall rate was 3%, with 100% of those isolates coming from the outpatient clinic staff cohort (P < .001). When cleaned in the last week (n = 16), the contamination rate dropped to 50% overall (P = .003), indicating that even periodic cleaning appears to have a positive effect on bacterial contamination rates. The simple practice of routine identity card decontamination may reduce potential threats to patient safety as a result of nosocomial bacterial transmission.