The Experts below are selected from a list of 1236 Experts worldwide ranked by ideXlab platform

Kenneth Van Surksum - One of the best experts on this subject based on the ideXlab platform.

Michael Fabian - One of the best experts on this subject based on the ideXlab platform.

  • Endpoint Security managing usb based removable devices with the advent of portable applications
    Information Security Curriculum Development, 2007
    Co-Authors: Michael Fabian
    Abstract:

    Endpoint Security is a major concern of IT management staff as the cost of data loss is high in monetary value and consumer confidence. Sensitive data, traditionally, has been threatened by physical theft of hardcopy or a device containing sensitive data. Recently, with the advent of USB-based applications, the threats presented towards sensitive data have increased dramatically. IT managers should employ a layered defense-in-depth strategy to mitigate the risks posed by these devices. The strategy should include hardware and software based mitigation techniques, an acceptable use policy, and a Security education program to maintain vigilance in Security practices.

  • InfoSecCD - Endpoint Security: managing USB-based removable devices with the advent of portable applications
    Proceedings of the 4th annual conference on Information security curriculum development - InfoSecCD '07, 2007
    Co-Authors: Michael Fabian
    Abstract:

    Endpoint Security is a major concern of IT management staff as the cost of data loss is high in monetary value and consumer confidence. Sensitive data, traditionally, has been threatened by physical theft of hardcopy or a device containing sensitive data. Recently, with the advent of USB-based applications, the threats presented towards sensitive data have increased dramatically. IT managers should employ a layered defense-in-depth strategy to mitigate the risks posed by these devices. The strategy should include hardware and software based mitigation techniques, an acceptable use policy, and a Security education program to maintain vigilance in Security practices.

Xavier Titi - One of the best experts on this subject based on the ideXlab platform.

  • On the Road to Privacy- and Data Protection-Friendly Security Technologies in the Workplace – A Case-Study of the MUSES Risk and Trust Analysis Engine
    Law Governance and Technology Series, 2017
    Co-Authors: Yung Shin Van Der Sype, Jonathan Guislain, Jean-marc Seigneur, Xavier Titi
    Abstract:

    It seems generally accepted that the major threat for company Security occurs from within the organisation itself. Given the potential threats for the value attached to information resources, companies are increasing their efforts to counteract these risks, introduced by employees. Many company Security technologies are strongly focused on analysing employee behaviour. An example of such a monitoring tool is MUSES (Multiplatform Usable Endpoint Security). MUSES is a user-centric Security system that aims to enhance company Security by reducing Security risks introduced by user behaviour. However, even though the monitoring of employees may be beneficial to secure company data assets, the monitoring of employees is restricted by privacy and data protection regulation. In this paper, we use one MUSES component, namely the Real-Time Risk and Trust Analysis Engine (MUSES RT2AE), as a use case to study in which way privacy and data protection legislation limits the monitoring of employees through company Security technologies.

  • on the road to privacy and data protection friendly Security technologies in the workplace a case study of the muses risk and trust analysis engine
    2017
    Co-Authors: Yung Shin Van Der Sype, Jonathan Guislain, Jean-marc Seigneur, Xavier Titi
    Abstract:

    It seems generally accepted that the major threat for company Security occurs from within the organisation itself. Given the potential threats for the value attached to information resources, companies are increasing their efforts to counteract these risks, introduced by employees. Many company Security technologies are strongly focused on analysing employee behaviour. An example of such a monitoring tool is MUSES (Multiplatform Usable Endpoint Security). MUSES is a user-centric Security system that aims to enhance company Security by reducing Security risks introduced by user behaviour. However, even though the monitoring of employees may be beneficial to secure company data assets, the monitoring of employees is restricted by privacy and data protection regulation. In this paper, we use one MUSES component, namely the Real-Time Risk and Trust Analysis Engine (MUSES RT2AE), as a use case to study in which way privacy and data protection legislation limits the monitoring of employees through company Security technologies.

Yuting Shang - One of the best experts on this subject based on the ideXlab platform.

  • Security Design and Implementation of the Cloud-based Online System
    DEStech Transactions on Computer Science and Engineering, 2016
    Co-Authors: Wei Chen, Yuting Shang
    Abstract:

    This paper discusses safety analysis and design based on the online system of the cloud computing, to enhance system Security from the deployment of HTTP Endpoint Security, database key and certificate, server Security strategy. According to the performance of the system, the results were satisfactory, the evaluation from the user is high, also served as an example of the similar online system designed to promote safety.

Anthony Arrott - One of the best experts on this subject based on the ideXlab platform.

  • CyberSA - Cluster analysis for deobfuscation of malware variants during ransomware attacks
    2018 International Conference On Cyber Situational Awareness Data Analytics And Assessment (Cyber SA), 2018
    Co-Authors: Anthony Arrott, Ferenc Leitold, Arun Lakhotia, Charles Ledoux
    Abstract:

    Risk managers attempting to reduce cyber-Security vulnerability in enterprise IT networks rely on the "malware detection rate" as a primary measure at each layer of protection (e.g., network firewalls, breach detection systems, secure mail-servers, Endpoint Security suites). However, to be directly usable in risk assessments, separate malware detection rates are required for different malware categories that are quantitatively related to specific impacts of infection. A three-tier hierarchy of malware classification is formulated to assist cyber-risk decision-making. Malware is first categorized by victim impact (e.g., adware, data exfiltration, ransomware); second by malware technique (e.g., malware families), and third by evasion and obfuscation variants within individual malware families (e.g., polymorphs, metamorphs). The three-tier hierarchy is applied to a specific vertical: ransomware (impact); ransomware family (technique); and malware binary variants within one family, WannaCry (obfuscation and evasion).

  • MALWARE - Protection against remote code execution exploits of popular applications in Windows
    2014 9th International Conference on Malicious and Unwanted Software: The Americas (MALWARE), 2014
    Co-Authors: Jeffrey Wu, Anthony Arrott, Fernando C. Colon Osorio
    Abstract:

    The objective of Malicious Remote Code Execution Exploits is to remotely execute code transparently to the user, and without relying on user interaction, in order to infect targeted machines. This comparative study examines the effectiveness of different proactive exploit mitigation technologies included in popular Endpoint Security products and specialized anti-exploit tools. The study focuses on exploits of popular applications running on Windows XP SP3 with Internet Explorer (IE8). As such, the Microsoft Enhanced Mitigation Experience Toolkit (MS-EMET) is used as a reference standard for all exploit mitigation solutions. The study compares the effectiveness of Endpoint Security products and anti-exploit tools by separating measurements of protections in common with MS-EMET from measures of protections supplemental to MS-EMET. This is done in order to understand not just the relative competitive effectiveness of the individual products and tools but also to understand the overall capabilities of the Windows Endpoint Security solutions to combat the remote code execution exploit capabilities of the overall Windows malware ecosystem.

  • MALWARE - Use-case-specific metrics for comparative testing of Endpoint Security products
    2013 8th International Conference on Malicious and Unwanted Software: "The Americas" (MALWARE), 2013
    Co-Authors: Jeffrey Wu, Anthony Arrott
    Abstract:

    A battery of protection and resource performance tests were conducted using commercial internet Security suites designed for general purpose usage with a Windows 8 personal computer (PC). Six classes of PC users were identified: Internet addict; network businessman; socializer; basic user; gamer; self-presenter; infrequent user. Recognizing that practical Internet Security is different for each of these user groups, the importance of each component protection and resource performance test was assessed independently for each PC user group. By weighting component results to match relative importance for each user group, separate overall comparative assessments of the tested internet Security suite products were obtained separately for each user group. From this, a more effective assessment of the value of commercial anti-malware protection is obtained specific to a customer's PC usage. When third party commercial anti-malware products were compared to the protection application provided by Microsoft, the average improvement ranged from 5% to 10% when measured separately for each PC user group.

  • Use-case-specific metrics for comparative testing of Endpoint Security products
    2013 8th International Conference on Malicious and Unwanted Software: "The Americas" (MALWARE), 2013
    Co-Authors: Jeffrey Wu, Anthony Arrott
    Abstract:

    A battery of protection and resource performance tests were conducted using commercial internet Security suites designed for general purpose usage with a Windows 8 personal computer (PC). Six classes of PC users were identified: Internet addict; network businessman; socializer; basic user; gamer; self-presenter; infrequent user. Recognizing that practical Internet Security is different for each of these user groups, the importance of each component protection and resource performance test was assessed independently for each PC user group. By weighting component results to match relative importance for each user group, separate overall comparative assessments of the tested internet Security suite products were obtained separately for each user group. From this, a more effective assessment of the value of commercial anti-malware protection is obtained specific to a customer's PC usage. When third party commercial anti-malware products were compared to the protection application provided by Microsoft, the average improvement ranged from 5% to 10% when measured separately for each PC user group.

  • MALWARE - Component protection metrics for Security product development: I. AV-TEST Full Product Tests
    2012 7th International Conference on Malicious and Unwanted Software, 2012
    Co-Authors: Andreas Marx, Alice Decker, Anthony Arrott
    Abstract:

    The AV-TEST Full Product Tests were used to perform iterative private tests on pre-release builds of version 6 of the Trend Micro Titanium Maximum Security Windows Endpoint product. The Full Product Tests include separate measurements of the protection provided by the consumer Endpoint Security product including measurements of blocking “real world” attacks; detecting and removing rootkits; cleaning malware infections; blocking malware execution; and detecting and removing stored malware files. All tests were conducted as a private “piggyback” on regularly scheduled public tests of the new version's predecessor and currently released versions of competitor peer products.