The Experts below are selected from a list of 1224 Experts worldwide ranked by ideXlab platform

Leanna Vidya Yovita - One of the best experts on this subject based on the ideXlab platform.

  • implementasi voip sip dengan menggunakan datagram transport layer security dtls pada asterisk server
    eProceedings of Engineering, 2015
    Co-Authors: Emeraldo Faris Aufar, Rendy Munadi, Leanna Vidya Yovita
    Abstract:

    Internet protocol (IP) yang sangat mudah untuk dikembangkan menyebabkan peningkatan yang signifikan pada penggunanya. Sehingga tren perkembangan komunikasi masa depan akan mengarah kepada komunikasi melalui jaringan IP. Komunikasi suara pada jaringan data (internet) biasa disebut dengan istilah VoIP (Voice over IP). VoIP merupakan salah satu bentuk komunikasi pada jaringan IP yang mulai banyak digemari. Selain karena pertumbuhan pengguna jaringan IP yang masif, VoIP juga mudah dari segi penggunaan, dan lebih murah dari segi biaya dibandingkan dengan komunikasi pada jaringan legacy seperti PSTN. Namun dari segala kelebihannya, komunikasi VoIP juga memiliki kekurangan-kekurangan, salah satunya adalah masalah keamanan jaringan dan privasi pada saat berkomunikasi. Dalam tugas akhir yang berjudul “Implementasi VoIP SIP menggunakan Datagram Transport Layer Security (DTLS) pada Asterisk Server” telah diimplementasikan suatu pembangunan jaringan sistem komunikasi VoIP yang terproteksi dari usaha-usaha mengganggu atau perusakan komunikasi VoIP pada saat pengiriman data yang berupa suara. Penggunaan VoIP yang berbasis datagram ini membuatnya membutuhkan proteksi yang tepat dan memang dirancang untuk memproteksi aplikasi berbasis datagram. Dan dengan proteksi DTLS terbukti dapat melindungi sistem dari tool penguji (Penetration Tester) dan mempersempit peluang keberhasilan dalam usaha perusakan sistem ini. Dari hasil pengujian yang dilakukan dapat disimpulkan bahwa penambahan protokol keamanan DTLS-SRTP pada server Asterisk akan menambahkan aspek privacy, confidentiality dan integrity pada server dan kanal medianya, sedangkan dari hasil pengukuran kualitas komunikasi VoIP didapatkan delay sebesar 14 ms, jitter 0,2 ms, packet loss 0% dan throughput 0,094 MBps dengan menggunakan codec PCMU G.711 dan protokol keamanan tambahan DTLS-SRTP. Kata kunci : VoIP, SIP, DTLS, DTLS-SRTP, Asterisk

Emeraldo Faris - One of the best experts on this subject based on the ideXlab platform.

  • Implementasi VoIP SIP dengan Menggunakan Datagram Transport Layer Security (DTLS) pada Asterisk Server
    Universitas Telkom, 2015
    Co-Authors: Emeraldo Faris
    Abstract:

    Internet protocol (IP) yang sangat mudah untuk dikembangkan menyebabkan peningkatan yang signifikan pada penggunanya. Sehingga tren perkembangan komunikasi masa depan akan mengarah kepada komunikasi melalui jaringan IP. Komunikasi suara pada jaringan data (internet) biasa disebut dengan istilah VoIP (Voice over IP). VoIP merupakan salah satu bentuk komunikasi pada jaringan IP yang mulai banyak digemari. Selain karena pertumbuhan pengguna jaringan IP yang masif, VoIP juga mudah dari segi penggunaan, dan lebih murah dari segi biaya dibandingkan dengan komunikasi pada jaringan legacy seperti PSTN. Namun dari segala kelebihannya, komunikasi VoIP juga memiliki kekurangan-kekurangan, salah satunya adalah masalah keamanan jaringan dan privasi pada saat berkomunikasi. Dalam tugas akhir yang berjudul “Implementasi VoIP SIP menggunakan Datagram Transport Layer Security (DTLS) pada Asterisk Server” telah diimplementasikan suatu pembangunan jaringan sistem komunikasi VoIP yang terproteksi dari usaha-usaha mengganggu atau perusakan komunikasi VoIP pada saat pengiriman data yang berupa suara. Penggunaan VoIP yang berbasis datagram ini membuatnya membutuhkan proteksi yang tepat dan memang dirancang untuk memproteksi aplikasi berbasis datagram. Dan dengan proteksi DTLS terbukti dapat melindungi sistem dari tool penguji (Penetration Tester) dan mempersempit peluang keberhasilan dalam usaha perusakan sistem ini. Dari hasil pengujian yang dilakukan dapat disimpulkan bahwa penambahan protokol keamanan DTLS-SRTP pada server Asterisk akan menambahkan aspek privacy, integrity, communication security, dan data confidentiality pada server dan kanal medianya, sedangkan dari hasil pengukuran kualitas komunikasi VoIP didapatkan delay sebesar 14 ms, jitter 0,2 ms, packet loss 0% dan throughput 0,094 MBps dengan menggunakan codec PCMU G.711 dan protokol keamanan tambahan DTLS-SRTP. Kata kunci : VoIP, SIP, DTLS, Asteris

Pieter H Hartel - One of the best experts on this subject based on the ideXlab platform.

  • review of the basics of hacking and Penetration testing ethical hacking and Penetration testing made easy p engebretson syngress publishing waltham ma 2011
    Computing reviews, 2012
    Co-Authors: Pieter H Hartel
    Abstract:

    This is a book on the “dark side” of information technology, as it describes how the vulnerabilities of systems and networks can be exploited to gain unauthorized access. It is important that students and practitioners understand how advanced the state of the art in exploiting vulnerabilities is, since only a deep understanding of the problem will lead to good solutions. Engebretson presents an overview of the tools a Penetration Tester might use to test the vulnerability of a system or network. The tools are described in some detail, mainly focusing on the syntax of commands. The interpretation of the results is described only superficially. The reader is left wondering what exactly is going on and why. Let me give a few examples to illustrate this point. In several places, the book warns the Penetration Tester that stealth is important. However, there is no information on how stealthy the various tools are, nor is there a discussion on how to use the tools in the stealthiest manner. The book often suggests that the reader should learn about a particular topic--for example, Internet protocols (p. 53): “To truly master port scanning you will need to have a solid understanding of these protocols.” Another example is the discussion (p. 79) of the differences between bind and reverse payloads. The book provides some of the facts, but it does not explain the relevance or the underlying principles. There are no pointers to further studies, references, or even Web pages. What exactly do we have to learn? Why? Where can we find the relevant material? I have read books similar to this one, but on topics that are far from my area of expertise (for example, Nanotechnology for dummies [1]), which I found more readable because the relevance of the topic was clear, and links to further information were provided. In summary: if the reader knows little about networking and is looking for a book that will get him started on Penetration testing, then this book may be useful. But it won’t get the reader anywhere near successful Penetration tests, because a much better understanding of networking than the book provides will be needed. Unfortunately, the book does not even try to point readers in the right direction to becoming proficient Penetration Testers. 1) E. Boysen, Nanotechnology for dummiesDummies Series: Dummies Series. Wiley, Indianapolis, IN, 2011.

  • two methodologies for physical Penetration testing using social engineering
    Annual Computer Security Applications Conference, 2010
    Co-Authors: Trajce Dimkov, Andre Van Cleeff, Wolter Pieters, Pieter H Hartel
    Abstract:

    Penetration tests on IT systems are sometimes coupled with physical Penetration tests and social engineering. In physical Penetration tests where social engineering is allowed, the Penetration Tester directly interacts with the employees. These interactions are usually based on deception and if not done properly can upset the employees, violate their privacy or damage their trust toward the organization and might lead to law suits and loss of productivity. We propose two methodologies for performing a physical Penetration test where the goal is to gain an asset using social engineering. These methodologies aim to reduce the impact of the Penetration test on the employees. The methodologies have been validated by a set of Penetration tests performed over a period of two years.

Emeraldo Faris Aufar - One of the best experts on this subject based on the ideXlab platform.

  • implementasi voip sip dengan menggunakan datagram transport layer security dtls pada asterisk server
    eProceedings of Engineering, 2015
    Co-Authors: Emeraldo Faris Aufar, Rendy Munadi, Leanna Vidya Yovita
    Abstract:

    Internet protocol (IP) yang sangat mudah untuk dikembangkan menyebabkan peningkatan yang signifikan pada penggunanya. Sehingga tren perkembangan komunikasi masa depan akan mengarah kepada komunikasi melalui jaringan IP. Komunikasi suara pada jaringan data (internet) biasa disebut dengan istilah VoIP (Voice over IP). VoIP merupakan salah satu bentuk komunikasi pada jaringan IP yang mulai banyak digemari. Selain karena pertumbuhan pengguna jaringan IP yang masif, VoIP juga mudah dari segi penggunaan, dan lebih murah dari segi biaya dibandingkan dengan komunikasi pada jaringan legacy seperti PSTN. Namun dari segala kelebihannya, komunikasi VoIP juga memiliki kekurangan-kekurangan, salah satunya adalah masalah keamanan jaringan dan privasi pada saat berkomunikasi. Dalam tugas akhir yang berjudul “Implementasi VoIP SIP menggunakan Datagram Transport Layer Security (DTLS) pada Asterisk Server” telah diimplementasikan suatu pembangunan jaringan sistem komunikasi VoIP yang terproteksi dari usaha-usaha mengganggu atau perusakan komunikasi VoIP pada saat pengiriman data yang berupa suara. Penggunaan VoIP yang berbasis datagram ini membuatnya membutuhkan proteksi yang tepat dan memang dirancang untuk memproteksi aplikasi berbasis datagram. Dan dengan proteksi DTLS terbukti dapat melindungi sistem dari tool penguji (Penetration Tester) dan mempersempit peluang keberhasilan dalam usaha perusakan sistem ini. Dari hasil pengujian yang dilakukan dapat disimpulkan bahwa penambahan protokol keamanan DTLS-SRTP pada server Asterisk akan menambahkan aspek privacy, confidentiality dan integrity pada server dan kanal medianya, sedangkan dari hasil pengukuran kualitas komunikasi VoIP didapatkan delay sebesar 14 ms, jitter 0,2 ms, packet loss 0% dan throughput 0,094 MBps dengan menggunakan codec PCMU G.711 dan protokol keamanan tambahan DTLS-SRTP. Kata kunci : VoIP, SIP, DTLS, DTLS-SRTP, Asterisk

Sean Lowther - One of the best experts on this subject based on the ideXlab platform.

  • chapter 6 low tech hacking for the Penetration Tester
    Low Tech Hacking#R##N#Street Smarts for Security Professionals, 2012
    Co-Authors: Jack Wiles, Terry Gudaitis, Jennifer Jabbusch, Russ Rogers, Sean Lowther
    Abstract:

    Publisher Summary This chapter discusses the nuances of human nature and how to use traits such as selective attention to aide in distraction techniques, and how low tech hackers capitalize on the six basic tendencies of human behavior (reciprocation, consistency, social validation, liking, authority, and scarcity). The chapter hashes through all the considerations of a planned attack; selecting a target, designating an attack location, factoring corporate culture of the target, and picking the right technology and tools to increase the attack effectiveness. Humans tend to have physical, emotional, and mental limitations that impact how we process information. Our brains tend to take shortcuts, which makes reading a book more of an exercise of understanding the key concepts in the book versus one of reading every single word in the book. That same ability to generalize data from our surroundings makes us vulnerable to specially crafted attack methods. A great Penetration Tester can achieve high success rates by introducing slight variations in a target's environment without arousing suspicion. A case study showing how a possible low tech hack can be used to gain access to target computer systems is also presented in this chapter.

  • Low Tech Hacking: Street Smarts for Security Professionals
    2011
    Co-Authors: Jack Wiles, Terry Gudaitis, Jennifer Jabbusch, Russ Rogers, Sean Lowther
    Abstract:

    Criminals using hacking techniques can cost corporations, governments, and individuals millions of dollars each year. While the media focuses on the grand-scale attacks that have been planned for months and executed by teams and countries, there are thousands more that aren't broadcast. Low Tech Hacking focuses on the everyday hacks that, while simple in nature, actually add up to the most significant losses. Attackers are using common techniques like social engineering, wireless hacking, and targeting and surveillance to gain access to valuable data. This book contains detailed descriptions of potential threats and vulnerabilities, many of which the majority of the information systems world may be unaware. Author Jack Wiles spent many years as an inside Penetration testing team leader, proving these threats and vulnerabilities exist and their countermeasures work. His contributing authors are among the best in the world in their respective areas of expertise. Contains insider knowledge of what could be your most likely Low Tech threat Includes timely advice from some of the top security minds in the world Covers many detailed countermeasures that you can employ to improve your security posture Table of Contents Foreword by Paul A. Henry Introduction Chapter 1. Social Engineering-The Ultimate Low Tech Hacking Threat Chapter 2. Low Tech?Vulerabilities-Physical Security Chapter 3. More About Locks and Ways to Low Tech Hack Them Chapter 4. Low Tech Wireless Hacking Chapter 5. Low Tech Targeting and Surveillance-How Much Could They Find Out About You? Chapter 6. Low Tech Hacking for the Penetration Tester Chapter 7. Low Tech Hacking and the Law-Where Can You Go For Help? Chapter 8. Information Security Awareness Training: Your Most Valuable Countermeasure to Employee Risk