The Experts below are selected from a list of 114 Experts worldwide ranked by ideXlab platform

Cormac Herley - One of the best experts on this subject based on the ideXlab platform.

  • klassp entering passwords on a spyware Infected Machine using a shared secret proxy
    Annual Computer Security Applications Conference, 2006
    Co-Authors: Dinei Florencio, Cormac Herley
    Abstract:

    In this paper we examine the problem of entering sensitive data, such as passwords, from an untrusted Machine. By untrusted we mean that it is suspected to be Infected with spyware which snoops on the user?s activity. Using such a Machine is obviously undesirable, and yet roaming users often have no choice. They are in no position to judge the security status of internet cafe, airport lounge or business center Machines. Either malice or negligence on the part of an administrator means that any such Machine can easily be running a keylogger. The roaming user has no reliable way of determining whether it is safe, and has no alternative to typing the password. We consider whether it is possible to enter data to confound spyware assumed to be running on the Machine in question. The difficulty of mounting a collusion attack on a single user?s password makes the problem more tractable than it might appear. We explore several approaches. In the first, we show how the user can embed a password in random keystrokes to confuse spyware, while leaving the actual login unaffected. In the second we employ a proxy server to strip random keys. In the third we again employ a proxy that inverts a key mapping performed by the user. We examine also several potential attacks.

  • KLASSP: Enterring Passwords from a Spyware Infected Machine
    2006
    Co-Authors: Dinei Florencio, Cormac Herley
    Abstract:

    In this paper we examine the problem of entering sensitive data, such as passwords, from an untrusted Machine. By untrusted we mean that it is suspected to be Infected with spyware which snoops on the user’s activity. Using such a Machine is obviously undesirable, and yet roaming users often have no choice. They are in no position to judge the security status of internet cafe, airport lounge or business center Machines. Either malice or negligence on the part of an administrator means that any such Machine can easily be running a keylogger. The roaming user has no reliable way of determining whether it is safe, and has no alternative to typing the password. We consider whether it is possible to enter data to confound spyware assumed to be running on the Machine in question. The difficulty of mounting a collusion attack on a single user’s password makes the problem more tractable than it might appear. We explore several approaches. In the first, we show how the user can embed a password in random keystrokes to confuse spyware, while leaving the actual login unaffected. In the second we employ a proxy server to strip random keys. In the third we again employ a proxy that inverts a key mapping performed by the user. We examine also several potential attacks.

  • ACSAC - KLASSP: Entering Passwords on a Spyware Infected Machine Using a Shared-Secret Proxy
    2006 22nd Annual Computer Security Applications Conference (ACSAC'06), 2006
    Co-Authors: Dinei Florencio, Cormac Herley
    Abstract:

    In this paper we examine the problem of entering sensitive data, such as passwords, from an untrusted Machine. By untrusted we mean that it is suspected to be Infected with spyware which snoops on the user?s activity. Using such a Machine is obviously undesirable, and yet roaming users often have no choice. They are in no position to judge the security status of internet cafe, airport lounge or business center Machines. Either malice or negligence on the part of an administrator means that any such Machine can easily be running a keylogger. The roaming user has no reliable way of determining whether it is safe, and has no alternative to typing the password. We consider whether it is possible to enter data to confound spyware assumed to be running on the Machine in question. The difficulty of mounting a collusion attack on a single user?s password makes the problem more tractable than it might appear. We explore several approaches. In the first, we show how the user can embed a password in random keystrokes to confuse spyware, while leaving the actual login unaffected. In the second we employ a proxy server to strip random keys. In the third we again employ a proxy that inverts a key mapping performed by the user. We examine also several potential attacks.

Dinei Florencio - One of the best experts on this subject based on the ideXlab platform.

  • klassp entering passwords on a spyware Infected Machine using a shared secret proxy
    Annual Computer Security Applications Conference, 2006
    Co-Authors: Dinei Florencio, Cormac Herley
    Abstract:

    In this paper we examine the problem of entering sensitive data, such as passwords, from an untrusted Machine. By untrusted we mean that it is suspected to be Infected with spyware which snoops on the user?s activity. Using such a Machine is obviously undesirable, and yet roaming users often have no choice. They are in no position to judge the security status of internet cafe, airport lounge or business center Machines. Either malice or negligence on the part of an administrator means that any such Machine can easily be running a keylogger. The roaming user has no reliable way of determining whether it is safe, and has no alternative to typing the password. We consider whether it is possible to enter data to confound spyware assumed to be running on the Machine in question. The difficulty of mounting a collusion attack on a single user?s password makes the problem more tractable than it might appear. We explore several approaches. In the first, we show how the user can embed a password in random keystrokes to confuse spyware, while leaving the actual login unaffected. In the second we employ a proxy server to strip random keys. In the third we again employ a proxy that inverts a key mapping performed by the user. We examine also several potential attacks.

  • KLASSP: Enterring Passwords from a Spyware Infected Machine
    2006
    Co-Authors: Dinei Florencio, Cormac Herley
    Abstract:

    In this paper we examine the problem of entering sensitive data, such as passwords, from an untrusted Machine. By untrusted we mean that it is suspected to be Infected with spyware which snoops on the user’s activity. Using such a Machine is obviously undesirable, and yet roaming users often have no choice. They are in no position to judge the security status of internet cafe, airport lounge or business center Machines. Either malice or negligence on the part of an administrator means that any such Machine can easily be running a keylogger. The roaming user has no reliable way of determining whether it is safe, and has no alternative to typing the password. We consider whether it is possible to enter data to confound spyware assumed to be running on the Machine in question. The difficulty of mounting a collusion attack on a single user’s password makes the problem more tractable than it might appear. We explore several approaches. In the first, we show how the user can embed a password in random keystrokes to confuse spyware, while leaving the actual login unaffected. In the second we employ a proxy server to strip random keys. In the third we again employ a proxy that inverts a key mapping performed by the user. We examine also several potential attacks.

  • ACSAC - KLASSP: Entering Passwords on a Spyware Infected Machine Using a Shared-Secret Proxy
    2006 22nd Annual Computer Security Applications Conference (ACSAC'06), 2006
    Co-Authors: Dinei Florencio, Cormac Herley
    Abstract:

    In this paper we examine the problem of entering sensitive data, such as passwords, from an untrusted Machine. By untrusted we mean that it is suspected to be Infected with spyware which snoops on the user?s activity. Using such a Machine is obviously undesirable, and yet roaming users often have no choice. They are in no position to judge the security status of internet cafe, airport lounge or business center Machines. Either malice or negligence on the part of an administrator means that any such Machine can easily be running a keylogger. The roaming user has no reliable way of determining whether it is safe, and has no alternative to typing the password. We consider whether it is possible to enter data to confound spyware assumed to be running on the Machine in question. The difficulty of mounting a collusion attack on a single user?s password makes the problem more tractable than it might appear. We explore several approaches. In the first, we show how the user can embed a password in random keystrokes to confuse spyware, while leaving the actual login unaffected. In the second we employ a proxy server to strip random keys. In the third we again employ a proxy that inverts a key mapping performed by the user. We examine also several potential attacks.

M.m. Williamson - One of the best experts on this subject based on the ideXlab platform.

  • ACSAC - Design, implementation and test of an email virus throttle
    19th Annual Computer Security Applications Conference 2003. Proceedings., 2003
    Co-Authors: M.m. Williamson
    Abstract:

    We present an approach to preventing the damage caused by viruses that travel via email. The approach prevents an Infected Machine spreading the virus further. This directly addresses the two ways that viruses cause damage: less Machines spreading the virus will reduce the number of Machines Infected and reduce the traffic generated by the virus. The approach relies on the observation that normal entailing behaviour is quite different from the behaviour of a spreading virus, with the virus sending messages at a much higher rate, to different addresses. To limit propagation a rate-limiter or virus throttle is described that does not affect normal traffic, but quickly slows and stops viral traffic. We include an analysis of normal emailing behaviour, and details of the throttle design. In addition an implementation is described and tested with real viruses, showing that the approach is practical.

  • ACSAC - Throttling viruses: restricting propagation to defeat malicious mobile code
    18th Annual Computer Security Applications Conference 2002. Proceedings., 1
    Co-Authors: M.m. Williamson
    Abstract:

    Modern computer viruses spread incredibly quickly, far faster than human-mediated responses. This greatly increases the damage that they cause. This paper presents an approach to restricting this high speed propagation automatically. The approach is based on the observation that during virus propagation, an Infected Machine will connect to as many different Machines as fast as possible. An unInfected Machine has a different behaviour: connections are made at a lower rate, and are locally correlated (repeat connections to recently accessed Machines are likely). This paper describes a simple technique to limit the rate of connections to "new" Machines that is remarkably effective at both slowing and halting virus propagation without affecting normal traffic. Results of applying the filter to Web browsing data are included. The paper concludes by suggesting an implementation and discussing the potential and limitations of this approach.

Hein S. Venter - One of the best experts on this subject based on the ideXlab platform.

  • Digital Forensic Readiness Framework for Ransomware Investigation
    Digital Forensics and Cyber Crime, 2019
    Co-Authors: Avinash Singh, Adeyemi Richard Ikuesan, Hein S. Venter
    Abstract:

    Over the years there has been a significant increase in the exploitation of the security vulnerabilities of Windows operating systems, the most severe threat being malicious software (malware). Ransomware, a variant of malware which encrypts files and retains the decryption key for ransom, has recently proven to become a global digital epidemic. The current method of mitigation and propagation of malware and its variants, such as anti-viruses, have proven ineffective against most Ransomware attacks. Theoretically, Ransomware retains footprints of the attack process in the Windows Registry and the volatile memory of the Infected Machine. Digital Forensic Readiness (DFR) processes provide mechanisms for the pro-active collection of digital footprints. This study proposed the integration of DFR mechanisms as a process to mitigate Ransomware attacks. A detailed process model of the proposed DFR mechanism was evaluated in compliance with the ISO/IEC 27043 standard. The evaluation revealed that the proposed mechanism has the potential to harness system information prior to, and during a Ransomware attack. This information can then be used to potentially decrypt the encrypted Machine. The implementation of the proposed mechanism can potentially be a major breakthrough in mitigating this global digital endemic that has plagued various organizations. Furthermore, the implementation of the DFR mechanism implies that useful decryption processes can be performed to prevent ransom payment.

  • ICDF2C - Digital Forensic Readiness Framework for Ransomware Investigation
    Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2018
    Co-Authors: Avinash Singh, Adeyemi Richard Ikuesan, Hein S. Venter
    Abstract:

    Over the years there has been a significant increase in the exploitation of the security vulnerabilities of Windows operating systems, the most severe threat being malicious software (malware). Ransomware, a variant of malware which encrypts files and retains the decryption key for ransom, has recently proven to become a global digital epidemic. The current method of mitigation and propagation of malware and its variants, such as anti-viruses, have proven ineffective against most Ransomware attacks. Theoretically, Ransomware retains footprints of the attack process in the Windows Registry and the volatile memory of the Infected Machine. Digital Forensic Readiness (DFR) processes provide mechanisms for the pro-active collection of digital footprints. This study proposed the integration of DFR mechanisms as a process to mitigate Ransomware attacks. A detailed process model of the proposed DFR mechanism was evaluated in compliance with the ISO/IEC 27043 standard. The evaluation revealed that the proposed mechanism has the potential to harness system information prior to, and during a Ransomware attack. This information can then be used to potentially decrypt the encrypted Machine. The implementation of the proposed mechanism can potentially be a major breakthrough in mitigating this global digital endemic that has plagued various organizations. Furthermore, the implementation of the DFR mechanism implies that useful decryption processes can be performed to prevent ransom payment.

Stefan Dziembowski - One of the best experts on this subject based on the ideXlab platform.

  • TCC - Intrusion-Resilience via the bounded-storage model
    Theory of Cryptography, 2006
    Co-Authors: Stefan Dziembowski
    Abstract:

    We introduce a new method of achieving intrusion-resilience in the cryptographic protocols. More precisely we show how to preserve security of such protocols, even if a malicious program (e.g. a virus) was installed on a computer of an honest user (and it was later removed). The security of our protocols relies on the assumption that the amount of data that the adversary can transfer from the Infected Machine is limited (however, we allow the adversary to perform any efficient computation on user's private data, before deciding on what to transfer). We focus on two cryptographic tasks, namely: session-key generation and entity authentication. Our method is based on the results from the Bounded-Storage Model.

  • Intrusion-Resilience via the Bounded-Storage Model.
    IACR Cryptology ePrint Archive, 2005
    Co-Authors: Stefan Dziembowski
    Abstract:

    We introduce a new method of achieving intrusion-resilience in the cryptographic protocols. More precisely we show how to preserve security of such protocols, even if a malicious program (e.g. a virus) was installed on a computer of an honest user (and it was later removed). The security of our protocols relies on the assumption that the amount of data that the adversary can transfer from the Infected Machine is limited (however, we allow the adversary to perform any efficient computation on user’s private data, before deciding on what to transfer). We focus on two cryptographic tasks, namely: session-key generation and entity authentication. Our method is based on the results from the BoundedStorage Model.