The Experts below are selected from a list of 1059 Experts worldwide ranked by ideXlab platform

Guschlbauer Fabian - One of the best experts on this subject based on the ideXlab platform.

  • Effiziente automatisierte Erst-Analyse von Android-Anwendungen in Bezug auf IT-Sicherheit basierend auf Open-Source-Werkzeugen
    2019
    Co-Authors: Guschlbauer Fabian
    Abstract:

    Das Betriebssystem Android liegt mit knapp 85% Marktanteil weltweit an führender Position, und der Android eigene Google Play Store verzeichnet rund 2.8 Millionen mobile Anwendungen, die vielen Menschen den Mehrwert ihrer tragbaren Geräte aufzeigen. Gefahren, die diese Anwendungen mit sich bringen, bleiben allerdings oftmals im Verborgenen. In den vergangenen Jahren wurden im Bereich der mobilen Anwendungssicherheit zahlreiche Publikationen und Werkzeuge veröffentlicht. Dabei wurden die unterschiedlichsten Sicherheitsbereiche wie etwa Kommunikation, Kryptografie oder Datenzugriff und Speicherung fokussiert und Sicherheitslücken aufgezeigt. Um die Analysefunktionalität von unterschiedlichen Werkzeugen zu bündeln und eine automatisierte Sicherheitseinstufung in Bezug auf IT-Sicherheit von Android-Anwendungen durchzuführen, wurde innerhalb dieser Arbeit ein webbasiertes Testing as a Service (TaaS) Framework entwickelt. Dieses integriert unterschiedliche existierende Sicherheitsanalyse-Werkzeuge und führt basierend auf deren Ergebnissen eine Sicherheitseinstufung der Anwendung in Bezug auf die Empfehlungen des Open Web Application Security Project (OWASP) Top 10 sowie der CERT-Abteilung des Software-Engineering Institut der Carnegie Mellon Universität (CMU) durch. Um die am häufigsten auftretenden Sicherheitsprobleme, die sichersten sowie gefährdetsten Google Play Store-Kategorien und Veränderungen der Sicherheit im Bereich Kryptografie in den vergangenen sechs Jahren aufzuzeigen, wurde im Rahmen einer durchgeführten Evaluierung automatisiert die Sicherheit von jeweils 100 Android-Anwendungen aus den 58 unterschiedlichen Google Play Store-Kategorien (e.g. Android Wear, Business oder Finance) bestimmt. Bei der Analyse der 5.800 Google Play Store-Anwendungen durch die angebundenen Werkzeuge sowie die Sicherheitseinstufung, der in der Arbeit definierten Kategorien mangelnder Angriffsschutz, Sicherheitsinvalidierung, anwendungsübergreifende Zugriffskontrolle, Datenlecks und Eingabevalidierung, wurde bei rund 76% der untersuchten Anwendungen mindestens ein schwerwiegender Sicherheitsverstoß festgestellt. Das Ergebnis der sicherheitskritisch eingestuften Anwendungen variiert dabei in den unterschiedlichen Google Play Store-Kategorien. In sicherheitskritischen Kategorien wie Business, Family Education, Finance und Medical konnten geringere Häufigkeiten kritischer Anwendungen festgestellt werden. Die meisten Probleme zeichneten sich im Bereich der Sicherheitsinvalidierung beziehungsweise genauer in den Bereichen der Zertifikatvalidierung sowie Kryptografie ab. Im Gebiet der Kryptografie wurden Regeln zur Verwendung des electronic code book Mode (ECB), Cipher Block Chaining Mode (CBC) mit konstant definierten Initialisierungsvektor (IV) sowie statischen Seeds evaluiert. Dabei konnte insgesamt ein Rückgang der Sicherheitsprobleme in diesem Bereich in den letzten sechs Jahren manifestiert werden.The operating system Android is with almost 85% market share worldwide in a leading position and the Android Google Play Store counts around 2.8 million mobile applications. However, the threats these applications involve remain often untold. In the last few years publications and tools with a focus on security areas such as communication, cryptography and data access or data storage have been published. To compose the functionality of different analysis tools and to accomplish an automated security classification of Android applications with a focus on IT-Security, a web-based Testing as a Service (TaaS) framework has been implemented, which integrates various existing security analysis tools. Based on the analysis results of the integrated tools and the recommendations of the Open Web Application Security Project (OWASP) Top 10 as well as the rules of the CERT Department of the Software Engineering Institute of Carnegie Mellon University (CMU) the framework identifies the security class of the analyzed applications. In order to identify the most common security threats and issues, the most secure and vulnerable Google Play Store categories as well as the changes in the security field of cryptography in the last six years, an evaluation was conducted as part of the thesis to automatically determine the security of 100 android applications from 58 different Google Play Store categories that include categories such as Android Wear, Business or Finance. Analyzing the 5.800 Google Play Store applications using the framework attached tools, as well as the security classification of the defined categories Insufficient Attack Protection, Security Invalidation, Access Control, Sensitive Data Leakage and Input Validation resulted in at least one security issue in about 76% of the evaluated applications. The result of critical or insecure classified applications varied in different Google Play Store categories, with lower rates of critical applications found in security-critical categories such as Business, Family Education, Finance and Medical. Most of the issues were located in the Security Invalidation category or more precisely in the areas of Certificate Validation and Cryptography. In the field of Cryptography rules concerning the usage of electronic code book Mode (ECB), Cipher Block Chaining Mode (CBC) with non-random Initialization Vector (IV) as well as static seeds have been evaluated and resulted overall in a decline of problems in the past six years.von Fabian GuschlbauerZusammenfassung in englischer SpracheTechnische Universität Wien, Diplomarbeit, 2019(VLID)455742

  • Effiziente automatisierte Erst-Analyse von Android-Anwendungen in Bezug auf IT-Sicherheit basierend auf Open-Source-Werkzeugen
    'Universidad Norbert Wiener', 2019
    Co-Authors: Guschlbauer Fabian
    Abstract:

    Das Betriebssystem Android liegt mit knapp 85% Marktanteil weltweit an führender Position, und der Android eigene Google Play Store verzeichnet rund 2.8 Millionen mobile Anwendungen, die vielen Menschen den Mehrwert ihrer tragbaren Geräte aufzeigen. Gefahren, die diese Anwendungen mit sich bringen, bleiben allerdings oftmals im Verborgenen. In den vergangenen Jahren wurden im Bereich der mobilen Anwendungssicherheit zahlreiche Publikationen und Werkzeuge veröffentlicht. Dabei wurden die unterschiedlichsten Sicherheitsbereiche wie etwa Kommunikation, Kryptografie oder Datenzugriff und Speicherung fokussiert und Sicherheitslücken aufgezeigt. Um die Analysefunktionalität von unterschiedlichen Werkzeugen zu bündeln und eine automatisierte Sicherheitseinstufung in Bezug auf IT-Sicherheit von Android-Anwendungen durchzuführen, wurde innerhalb dieser Arbeit ein webbasiertes Testing as a Service (TaaS) Framework entwickelt. Dieses integriert unterschiedliche existierende Sicherheitsanalyse-Werkzeuge und führt basierend auf deren Ergebnissen eine Sicherheitseinstufung der Anwendung in Bezug auf die Empfehlungen des Open Web Application Security Project (OWASP) Top 10 sowie der CERT-Abteilung des Software-Engineering Institut der Carnegie Mellon Universität (CMU) durch. Um die am häufigsten auftretenden Sicherheitsprobleme, die sichersten sowie gefährdetsten Google Play Store-Kategorien und Veränderungen der Sicherheit im Bereich Kryptografie in den vergangenen sechs Jahren aufzuzeigen, wurde im Rahmen einer durchgeführten Evaluierung automatisiert die Sicherheit von jeweils 100 Android-Anwendungen aus den 58 unterschiedlichen Google Play Store-Kategorien (e.g. Android Wear, Business oder Finance) bestimmt. Bei der Analyse der 5.800 Google Play Store-Anwendungen durch die angebundenen Werkzeuge sowie die Sicherheitseinstufung, der in der Arbeit definierten Kategorien mangelnder Angriffsschutz, Sicherheitsinvalidierung, anwendungsübergreifende Zugriffskontrolle, Datenlecks und Eingabevalidierung, wurde bei rund 76% der untersuchten Anwendungen mindestens ein schwerwiegender Sicherheitsverstoß festgestellt. Das Ergebnis der sicherheitskritisch eingestuften Anwendungen variiert dabei in den unterschiedlichen Google Play Store-Kategorien. In sicherheitskritischen Kategorien wie Business, Family Education, Finance und Medical konnten geringere Häufigkeiten kritischer Anwendungen festgestellt werden. Die meisten Probleme zeichneten sich im Bereich der Sicherheitsinvalidierung beziehungsweise genauer in den Bereichen der Zertifikatvalidierung sowie Kryptografie ab. Im Gebiet der Kryptografie wurden Regeln zur Verwendung des electronic code book Mode (ECB), Cipher Block Chaining Mode (CBC) mit konstant definierten Initialisierungsvektor (IV) sowie statischen Seeds evaluiert. Dabei konnte insgesamt ein Rückgang der Sicherheitsprobleme in diesem Bereich in den letzten sechs Jahren manifestiert werden.The operating system Android is with almost 85% market share worldwide in a leading position and the Android Google Play Store counts around 2.8 million mobile applications. However, the threats these applications involve remain often untold. In the last few years publications and tools with a focus on security areas such as communication, cryptography and data access or data storage have been published. To compose the functionality of different analysis tools and to accomplish an automated security classification of Android applications with a focus on IT-Security, a web-based Testing as a Service (TaaS) framework has been implemented, which integrates various existing security analysis tools. Based on the analysis results of the integrated tools and the recommendations of the Open Web Application Security Project (OWASP) Top 10 as well as the rules of the CERT Department of the Software Engineering Institute of Carnegie Mellon University (CMU) the framework identifies the security class of the analyzed applications. In order to identify the most common security threats and issues, the most secure and vulnerable Google Play Store categories as well as the changes in the security field of cryptography in the last six years, an evaluation was conducted as part of the thesis to automatically determine the security of 100 android applications from 58 different Google Play Store categories that include categories such as Android Wear, Business or Finance. Analyzing the 5.800 Google Play Store applications using the framework attached tools, as well as the security classification of the defined categories Insufficient Attack Protection, Security Invalidation, Access Control, Sensitive Data Leakage and Input Validation resulted in at least one security issue in about 76% of the evaluated applications. The result of critical or insecure classified applications varied in different Google Play Store categories, with lower rates of critical applications found in security-critical categories such as Business, Family Education, Finance and Medical. Most of the issues were located in the Security Invalidation category or more precisely in the areas of Certificate Validation and Cryptography. In the field of Cryptography rules concerning the usage of electronic code book Mode (ECB), Cipher Block Chaining Mode (CBC) with non-random Initialization Vector (IV) as well as static seeds have been evaluated and resulted overall in a decline of problems in the past six years.13

Faisal - Sidik - One of the best experts on this subject based on the ideXlab platform.

  • IMPLEMENTASI ALGORITMA LOW BIT CODING(LBC) DANBLOCK CIPHER DENGAN MODE electronic code book (ECB) UNTUK LEGALITAS DATA PADA STREAMING AUDIO STEGANOGRAFI
    2018
    Co-Authors: Faisal - Sidik
    Abstract:

    Popularitas penggunaan berkas mp3 sebagai format media musik dan lagu digital membuatnya rentan terhadap permasalahan hak cipta. Salah satu cara untuk melindungi hak cipta pada berkas mp3 adalah dengan menggunakan teknik audio steganografi. Metode yang digunakan untuk audio steganografi ini adalah metode Low Bit Encoding bersamaan dengan algoritma electronic code book. Metode Low Bit Encoding menyisipkan pesan kedalam berkas mp3 pada setiap bit yang paling tidak berpengaruh atau Least Significant Bit. Algoritma electronic code book digunakan sebagai pengamanan agar pesan yang disisipkan kedalam berkas mp3 aman dari manipulasi pihak-pihak yang tidak bertanggung-jawab untuk kepentingan tertentu. Hasil penelitian menunjukkan bahwa penggunaan audio steganografi menggunakan metode Low Bit Encoding dan Algoritma electronic code book sukses menyisipkan informasi hak cipta kedalam berkas audio berformat mp3. Meskipun memiliki tingkat ketahanan (robustness) yang rendah karena tidak tahan terhadap manipulasi konversi dan manipulasi amplitudo, namun hasil penelitian menunjukkan berkas mp3 stego yang dihasilkan memiliki tingkat imperceptibility, fidelity dan recovery yang baik. Pengujian menggunakan MOS (Mean Opinion Score) menghasilkan nilai rata-rata 5 untuk semua genre dan nilai rata-rata SNR (Signal to Noise Ratio) sebesar 35 dB. ;---The popularity of the use of mp3 files as a format of music media and digital songs makes it vulnerable to copyright issues. One way to protect copyright on mp3 files is to use steganographic audio techniques. The method used for this steganographic audio is the Low Bit Encoding method along with the electronic code book algorithm. The Low Bit Encoding method inserts messages into mp3 files on each least significant bit or Least Significant Bit. The electronic code book algorithm is used as a safeguard so that messages inserted into mp3 files are safe from the manipulation of irresponsible parties for a particular interest. The results showed that the use of steganographic audio using Low Bit Encoding method and electronic code book Algorithm successfully insert copyright information into mp3 format audio files. Although it has a low robustness because it can not withstand conversion manipulation and amplitude manipulation, but the results show that the resulting mp3 stego file has good imperceptibility, fidelity and recovery rates. Testing using MOS (Mean Opinion Score) yields a mean value of 5 for all genres and a mean value of SNR (Signal to Noise Ratio) of 35 d

  • IMPLEMENTASI ALGORITMA LOW BIT CODING (LBC) DAN BLOCK CIPHER DENGAN MODE electronic code book (ECB) UNTUK LEGALITAS DATA PADA STREAMING AUDIO STEGANOGRAFI
    2018
    Co-Authors: Faisal - Sidik
    Abstract:

    Popularitas penggunaan berkas mp3 sebagai format media musik dan lagu digital membuatnya rentan terhadap permasalahan hak cipta. Salah satu cara untuk melindungi hak cipta pada berkas mp3 adalah dengan menggunakan teknik audio steganografi. Metode yang digunakan untuk audio steganografi ini adalah metode Low Bit Encoding bersamaan dengan algoritma electronic code book. Metode Low Bit Encoding menyisipkan pesan kedalam berkas mp3 pada setiap bit yang paling tidak berpengaruh atau Least Significant Bit. Algoritma electronic code book digunakan sebagai pengamanan agar pesan yang disisipkan kedalam berkas mp3 aman dari manipulasi pihak-pihak yang tidak bertanggung-jawab untuk kepentingan tertentu. Hasil penelitian menunjukkan bahwa penggunaan audio steganografi menggunakan metode Low Bit Encoding dan Algoritma electronic code book sukses menyisipkan informasi hak cipta kedalam berkas audio berformat mp3. Meskipun memiliki tingkat ketahanan (robustness) yang rendah karena tidak tahan terhadap manipulasi konversi dan manipulasi amplitudo, namun hasil penelitian menunjukkan berkas mp3 stego yang dihasilkan memiliki tingkat imperceptibility, fidelity dan recovery yang baik. Pengujian menggunakan MOS (Mean Opinion Score) menghasilkan nilai rata-rata 5 untuk semua genre dan nilai rata-rata SNR (Signal to Noise Ratio) sebesar 35 dB;--- The popularity of the use of mp3 files as a format of music media and digital songs makes it vulnerable to copyright issues. One way to protect copyright on mp3 files is to use steganographic audio techniques. The method used for this steganographic audio is the Low Bit Encoding method along with the electronic code book algorithm. The Low Bit Encoding method inserts messages into mp3 files on each least significant bit or Least Significant Bit. The electronic code book algorithm is used as a safeguard so that messages inserted into mp3 files are safe from the manipulation of irresponsible parties for a particular interest. The results showed that the use of steganographic audio using Low Bit Encoding method and electronic code book Algorithm successfully insert copyright information into mp3 format audio files. Although it has a low robustness because it can not withstand conversion manipulation and amplitude manipulation, but the results show that the resulting mp3 stego file has good imperceptibility, fidelity and recovery rates. Testing using MOS (Mean Opinion Score) yields a mean value of 5 for all genres and a mean value of SNR (Signal to Noise Ratio) of 35 dB

Ervyn, Indra Yoga - One of the best experts on this subject based on the ideXlab platform.

  • PENERAPAN TEORI CHAOS PADA KRIPTOGRAFI MENGGUNAKAN ALGORITMA STREAM CIPHER DAN electronic code book (ECB) UNTUK KEAMANAN PESAN TEKS
    2014
    Co-Authors: Ervyn, Indra Yoga
    Abstract:

    Masalah keamanan merupakan salah satu aspek terpenting dalam sistem informasi. Dalam komunikasi pasti akan ada pengiriman pesan kepada orang lain, maka tentunya pesan tersebut harus sampai dengan aman. Sebuah informasi umumnya hanya ditunjukan bagi golongan tertentu, sangatlah penting untuk mencegah agar keamanan pesan tidak sampai jatuh kepada pihak-pihak lain yang tidak berkepentingan. Untuk mengurangi tindak kejahatan dalam keamanan data, maka kriptografi bisa dijadikan solusi yang tepat. Dalam penelitian ini, teori Chaos dengan Logistic Map akan digunakan untuk membangkitkan kunci secara acak dan panjang. Kemudian kunci tersebut diterapkan pada algoritma Stream Cipher dan electronic code book (ECB). Dengan teori Chaos tersebut, akan dihasilkan kunci yang acak dan panjang kunci sama dengan panjang plainteks pada Stream Cipher. Sedangkan pada ECB akan menambah jumlah panjang kunci yang acak sehingga dapat menutup kelemahan. Dari hasil penelitian ini, teori Chaos dengan Logistic Map dapat mempermudah dalam mengingat kunci yang acak dan sekaligus panjang. Selain itu penelitian ini juga mengembangkan pada nomor iterasi tertentu yang dihasilkan oleh Logistic Map dapat dipilih menjadi nomor iterasi pertama kunci sehingga dalam pembangkitan kunci akan menambah variasi dan kemungkinan dalam penebakan kunci

Kurniawan, Ervyn Yoga Indra - One of the best experts on this subject based on the ideXlab platform.

  • PENERAPAN TEORI CHAOS PADA KRIPTOGRAFI MENGGUNAKAN ALGORITMA STREAM CIPHER DAN electronic code book (ECB) UNTUK KEAMANAN PESAN TEKS
    2014
    Co-Authors: Kurniawan, Ervyn Yoga Indra
    Abstract:

    Security problem is one of many important aspect in information system. In communications will be messagesending to another people. So, definitely those message must arrive safely. An information generally should only be shown for certain people, it is very important to prevent message’s security to fall to the wrong hands. To lessen criminal activity within data security, so cryptography can be use as the right solution.In this research, Chaos theory with logistic Map will be use to generate keys randomly and long. Then those keys implemented to Stream Cipher algorithm and electronic code book (ECB). With these Chaos theory, random keys will be generated and key’s length will be same with the plaintext in Stream Cipher. While in ECB, a random key’s length will be added so weakness can be covered. From this research’s result, Chaos theory with Logistic Map can make remembering random and long keys easier. Other than that, this research also developing in some certain iteration number which was generated by Logistic Map can be chosen as key’s first iteration number, so in keys generation, variation and possibility in keys guessing will be increased

Muljono M. - One of the best experts on this subject based on the ideXlab platform.

  • Keamanan Pesan Teks Menggunakan Teori Chaos dan electronic code book
    Sekolah Tinggi Manajemen Informatika dan Komputer Dipanegara, 2015
    Co-Authors: Indra E. Y., Muljono M.
    Abstract:

    Masalah keamanan merupakan salah satu aspek penting dalam system informasi. Dalam komunikasi pasti akan ada pengiriman pesan kepada orang lain, maka tentunya pesan tersebut harus sampai dengan aman. Sebuah informasi umumnya hanya ditunjukan bagi golongan tertentu, sangatlah pentinguntuk mencegah agar keamanan pesan tidak sampai jatuh kepada pihak-pihak lain yang tidak berkepentingan.Untuk mengurangi tindak kejahatan dalam keamanan data, maka kriptografi bias dijadikan solusi yang tepat. Dalam penelitian ini, teori Chaos dengan Logistic Map akan digunakan untuk membangkitkan kunci secara acak dan panjang. Kemudian kunci tersebut diterapkan pada algoritma Stream Cipher dan electronic code book (ECB).Dengan teori Chaos tersebut akan dihasilkan kunci yang acak dan panjang kunci sama dengan panjang plainteks pada Stream Cipher. Sedangkan pada ECB akan menambah jumlah panjang kunci yang acak sehingga dapat menutup kelemahan. Dari hasil penelitian ini, teori Chaos dengan Logistic Map dapat mempermudah dalam mengingat kunci yang acak dan sekaligus panjang. Selain itu penelitian ini juga mengembangkan pada nomor iterasi tertentu yang dihasilkan oleh Logistic Map dapat dipilih menjadi nomor iterasi pertama kunci sehingga dalam pembangkitan kunci akan menambah variasi dan kemungkinan dalam penebakan kunci