The Experts below are selected from a list of 4101 Experts worldwide ranked by ideXlab platform
K. Minami - One of the best experts on this subject based on the ideXlab platform.
-
ACSAC - Securing Web servers against Insider Attack
Seventeenth Annual Computer Security Applications Conference, 2001Co-Authors: S. Jiang, Sean W. Smith, K. MinamiAbstract:Too often, "security of Web transactions" reduces to "encryption of the channel" - and neglects to address what happens at the server on the other end. This oversight forces clients to trust the good intentions and competence of the server operator - but gives clients no basis for that trust. In this paper, we apply secure coprocessing and cryptography to solve this real problem in Web technology. We present a vision: using secure coprocessors to establish trusted coservers at Web servers and moving sensitive computations inside these co-servers; we present a prototype implementation of this vision that scales to realistic workloads; and we validate this approach by building a simple E-voting application on top of our prototype. By showing the real potential of COTS secure coprocessing technology to establish trusted islands of computation in hostile environments - such as at Web servers with risk of Insider Attack - this work also helps demonstrate that "secure hardware" can be more than a synonym for "cryptographic accelerator".
-
Securing Web servers against Insider Attack
Seventeenth Annual Computer Security Applications Conference, 2001Co-Authors: S. Jiang, S. Smith, K. MinamiAbstract:Too often, "security of Web transactions" reduces to "encryption of the channel" - and neglects to address what happens at the server on the other end. This oversight forces clients to trust the good intentions and competence of the server operator - but gives clients no basis for that trust. In this paper, we apply secure coprocessing and cryptography to solve this real problem in Web technology. We present a vision: using secure coprocessors to establish trusted coservers at Web servers and moving sensitive computations inside these co-servers; we present a prototype implementation of this vision that scales to realistic workloads; and we validate this approach by building a simple E-voting application on top of our prototype. By showing the real potential of COTS secure coprocessing technology to establish trusted islands of computation in hostile environments - such as at Web servers with risk of Insider Attack - this work also helps demonstrate that "secure hardware" can be more than a synonym for "cryptographic accelerator".
E Venkatesan - One of the best experts on this subject based on the ideXlab platform.
-
an efficient intrusion detection and prevention system against Insider Attack by user behavior mining
Data mining and knowledge engineering, 2016Co-Authors: N Birla, M Jagadish, E VenkatesanAbstract:Intrusion Detection Systems (IDS) plays a significant role in computer security. In network surroundings IDS find the activities that have an effect on Confidentiality, Integrity and accessibility on network knowledge. Currently, most computer systems use user IDs and passwords because the login patterns to certify users. However, many of us share their login patterns with coworkers and request these coworkers to help co-tasks, thereby creating the pattern united of the weakest points of computer security. Insider Attackers, the valid users of a system who Attack the system internally, are exhausting to find since most intrusion detection systems and firewalls establish and isolate malicious behaviors launched from the external world of the system solely. Additionally, some studies claimed that analyzing system calls (SCs) generated by commands will establish these commands, with that to accurately find Attacks, with Attack patterns are the options of an Attack. Therefore, during this paper, a security system, named the interior Intrusion Detection and Protection System (IIDPS), is projected to find Insider Attacks at SC level by victimization data processing and rhetorical techniques. The IIDPS creates users’ personal profiles to stay track of users’ usage habits as their rhetorical options and determines whether or not a sound login user is that the account holder or not by scrutiny his/her current laptop usage behaviors with the patterns collected within the account holder’s personal profile.
Dipak Ghosal - One of the best experts on this subject based on the ideXlab platform.
-
SIDD: A Framework for Detecting Sensitive Data Exfiltration by an Insider Attack
2009 42nd Hawaii International Conference on System Sciences, 2009Co-Authors: Cherita Corbett, Ken Chiang, Rennie Archibald, Biswanath Mukherjee, Dipak GhosalAbstract:Detecting and mitigating Insider threat is a critical element in the overall information protection strategy. By successfully implementing tactics to detect this threat, organizations mitigate the loss of sensitive information and also potentially protect against future Attacks. Within the broader scope of mitigating Insider threat, we focus on detecting exfiltration of sensitive data through a protected network. We propose a multilevel framework called SIDD (Sensitive Information Dissemination Detection) system which is a high-speed transparent network bridge located at the edge of the protected network. SIDD consists of three main components: 1) network-level application identification, 2) content signature generation and detection, and 3) covert communication detection. Further, we introduce a model implementation of the key components, demonstrating how our system can be deployed. Our approach is based on the application of statistical and signal processing techniques on traffic flow to generate signatures and/or extract features for classification purposes. The proposed framework aims to address methods to detect, deter and prevent deliberate and unintended distribution of sensitive content outside the organization using the organization's system and network resources by a trusted Insider.
-
detecting sensitive data exfiltration by an Insider Attack
Cyber Security and Information Intelligence Research Workshop, 2008Co-Authors: Cherita Corbett, Ken Chiang, Rennie Archibald, Biswanath Mukherjee, Dipak GhosalAbstract:Detecting and mitigating Insider threat is a critical element in the overall information protection strategy. By successfully implementing tactics to detect this threat, organizations avoid the loss of sensitive information and also potentially protect against future Attacks. Within the broader scope of mitigating Insider threat, we focus on detecting exfiltration of sensitive data through the high speed network. We propose a multilevel approach that consists of three main components: 1) network level application identification, 2) content signature generation and detection, and 3) covert communication detection. The key scientific approach used for all the above components is applying statistical and signal processing techniques on network traffic to generate signatures and/or extract features for classification purposes. We provide a summary of the approaches used in network level application identification and content signature generation and detection and briefly describe our approach in detecting covert communications. This paper touches on these issues and outlines overall directions for our research.
S. Jiang - One of the best experts on this subject based on the ideXlab platform.
-
ACSAC - Securing Web servers against Insider Attack
Seventeenth Annual Computer Security Applications Conference, 2001Co-Authors: S. Jiang, Sean W. Smith, K. MinamiAbstract:Too often, "security of Web transactions" reduces to "encryption of the channel" - and neglects to address what happens at the server on the other end. This oversight forces clients to trust the good intentions and competence of the server operator - but gives clients no basis for that trust. In this paper, we apply secure coprocessing and cryptography to solve this real problem in Web technology. We present a vision: using secure coprocessors to establish trusted coservers at Web servers and moving sensitive computations inside these co-servers; we present a prototype implementation of this vision that scales to realistic workloads; and we validate this approach by building a simple E-voting application on top of our prototype. By showing the real potential of COTS secure coprocessing technology to establish trusted islands of computation in hostile environments - such as at Web servers with risk of Insider Attack - this work also helps demonstrate that "secure hardware" can be more than a synonym for "cryptographic accelerator".
-
Securing Web servers against Insider Attack
Seventeenth Annual Computer Security Applications Conference, 2001Co-Authors: S. Jiang, S. Smith, K. MinamiAbstract:Too often, "security of Web transactions" reduces to "encryption of the channel" - and neglects to address what happens at the server on the other end. This oversight forces clients to trust the good intentions and competence of the server operator - but gives clients no basis for that trust. In this paper, we apply secure coprocessing and cryptography to solve this real problem in Web technology. We present a vision: using secure coprocessors to establish trusted coservers at Web servers and moving sensitive computations inside these co-servers; we present a prototype implementation of this vision that scales to realistic workloads; and we validate this approach by building a simple E-voting application on top of our prototype. By showing the real potential of COTS secure coprocessing technology to establish trusted islands of computation in hostile environments - such as at Web servers with risk of Insider Attack - this work also helps demonstrate that "secure hardware" can be more than a synonym for "cryptographic accelerator".
Chandra Sekhar Vorugunti - One of the best experts on this subject based on the ideXlab platform.
-
Cryptanalysis of “a robust and effective smart card-based remote user authentication mechanism using hash function”
2014 International Conference on Computer and Communication Technology (ICCCT), 2014Co-Authors: Mrudula Sarvabhatla, Manoj Giri, Chandra Sekhar VoruguntiAbstract:To safeguard trustworthy remote user authentication services, various user authentication schemes for internet based E-Commerce, M-Commerce applications has been proposed. These schemes are proposed with an intention to legalize only authorized access to remote server resources, so that critical information can be protected from misuse. Very recently, A.K Das et al. proposed a user remote user authentication scheme using a hash function, which they claimed to provide enhanced privacy and their scheme is light weight due to usage of efficient one way hash function and bitwise XOR operations. In this paper we will cryptanalyze and show that A.K das et al scheme is susceptible to privileged Insider Attack, on success of the Attack, the Attacker can perform all major cryptographic Attacks.
-
Cryptanalysis of “a robust and effective smart card-based remote user authentication mechanism using hash function”
2014 International Conference on Computer and Communication Technology (ICCCT), 2014Co-Authors: Mrudula Sarvabhatla, Manoj Giri, Chandra Sekhar VoruguntiAbstract:To safeguard trustworthy remote user authentication services, various user authentication schemes for internet based E-Commerce, M-Commerce applications has been proposed. These schemes are proposed with an intention to legalize only authorized access to remote server resources, so that critical information can be protected from misuse. Very recently, A.K Das et al. proposed a user remote user authentication scheme using a hash function, which they claimed to provide enhanced privacy and their scheme is light weight due to usage of efficient one way hash function and bitwise XOR operations. In this paper we will cryptanalyze and show that A.K das et al scheme is susceptible to privileged Insider Attack, on success of the Attack, the Attacker can perform all major cryptographic Attacks.