Skip to main content

Home/ CSIA 459/ Group items tagged USED

Rss Feed Group items tagged

Phil Kemp

Massive casino scam pulled off via CCTV system compromise - 4 views

  •  
    While society is looking to use technology for it's benefits, there are many pitfalls, and adverse uses for this same technology. This article discusses how the use of CCTV systems for ensuring that players do not cheat was used against the same system, to do the very thing it was protecting against. We as technology professionals should be very congnizant of the security risks that the technology we recommend or put in place, may have alternate uses, which may be used against us, and thereby causing more damage than it helped to protect.
  • ...3 more comments...
  •  
    Good article and I like the site. Haven't been there before. Looks like a good site to find out current news articles for another class I'm taking. Thanks!
  •  
    I read about the scam shortly after it happened, but the article I read didn't provide nearly as many details. Thanks for the article and I think there might be more people unemployed than just the VIP services manager.
  •  
    Phil you are so right about an organization own security technology being used against them. This is a great example of that. It is important when implementing technology to fully analyze its impact, that includes vulnerabilities and threats. A good change managment policy can help reveal problems like this. I wonder if there was an insider involved or maybe the casino failed to properly protect the network.
  •  
    Phil, This is very interesting. You would have thought the casino would have better security than that on their system. It also suprises me that if you were in a game with that much money why did they not see the receiver the person had. A simple pat down could have reveiled it. It is scary what technology can do in the wrong hands. Lee
  •  
    Winning is one thing, but stacking the deck is another. I would have thought that a casino would have a better way of securing their systems. Ben
samuelrios

Homeland Security Drones Designed to Identify Civilians Carrying Guns - 4 views

  •  
    Recently uncovered government documents reveal that the U.S. Department of Homeland Security's (DHS) unmanned Predator B drone fleet has been custom designed to identify civilians carrying guns and track cell phone signals. "I am very concerned that this technology will be used against law-abiding American firearms owners," said founder and executive vice president of the Second Amendment Foundation, Alan Gottlieb.
  • ...2 more comments...
  •  
    Good read. After reading this and another related article (http://news.cnet.com/8301-13578_3-57572207-38/dhs-built-domestic-surveillance-tech-into-predator-drones/) There's a fine line which must be established before the full use of this technology, however it does raise concerns for the future in terms of privacy. It's primary purpose for homeland security is the survey the borders of the united states. There are certainlly risks involved in its use. Ensuring that this technology is effectively secured from attacks to its onboard weapons and communications systems is equally important to the issues raised in the articles.
  •  
    Good post I've heard chatter about drones being flown over the USA before. I could see the benefits of using drones for recon and counter terrorism, but this opens the door for much larger issues. Where will line be drawn in the sand as far as citizen privacy and avoiding the "big brother" hysteria?
  •  
    The power these drones represent is incredible. I can easily see how the can (and will be) abused. As Jammes pointed out, the Primary purpose of DHS is securing our nations borders, yet I have read of DHS rading peoples homes because of an "improperly" imported car! Not to sound like I am about to put a tinfoil hat on, but I do see the distinct possibility of the banning of firearms in this country as happened in England in 1997. These tools will be in place well before that day.
  •  
    The use of Drones in the field as a tool to fight the fight on the borders is one thing, using them as a tool to fight terrorism is still another, but using them as tool to spy on the people of the United States is another. I think this is one that the United States Supreme Court will be deciding soon.
Gilbert Rivera

Data Migration from Grid to Cloud Computing - 0 views

  •  
    Cloud Data Storage: Annotated Bibliography In this document the authors shows us the migration that business are taking from handling data from their grid to using cloud data storage services. This document focuses on how to use database libraries with data stored in the cloud. It provides guidance in using tools like SQL, Hadoop and HBase mapping. This item can be useful for business to access their databases from information stored in the cloud and can be very helpful.
Funsho Aiyedogbon

5 Emerging Technologies Every Office Will Have In 2020 - 1 views

  •  
    This article explores five emerging technologies that will be commonly used in business offices in the next seven years.
  • ...1 more comment...
  •  
    Now this is scary and yet so amazing. The fact that they are already predicting that typing a password into a device is something that is going to be in the past, is unreal. A device is going to recognize your face and allow you to have access to it. The scary part is the phone aspect in how the devices will pick up your phone conversation and automatically send a calendar invite to your device. New technologies are definitely amazing but still, there is little to no talk on how they are going to secure the environments that they are creating.
  •  
    Very interesting article. Basically, all human existence will be completely gone by 2020. I can't believe these technologies even exist and are currently in the prototype stage. You never know, this technology can take over sooner that what this article expect. The most interesting technology to me the use of sensors. If things come out to be in full effect, with the use of these sensors can provide very accurate data and help avoid the use of any fraudulent it identity threats. Thanks!
  •  
    I read this article and loved it. After reading it a while back I became very interested in Gesture Control. This is the emerging technology that I chose for this class. I know that this article talks about the use of this technology in the office but we have already seen it in Smartphones (the new Galaxy) who knows where it will pop up next!
Amy Harding

The Security Content Automation Protocol (SCAP) - NIST - 5 views

shared by Amy Harding on 06 Mar 13 - Cached
  •  
    Using the links to the left of the screen, click around the SCAP website and think about how this protocol could help organizations manage their security vulnerabilities. Does your organization use SCAP?
Vickye F

http://www.us-cert.gov/sites/default/files/publications/cyber_threats-to_mobile_phones.pdf - 0 views

  •  
    This website gives information about Cyber Threats to Mobile Phones. The US-CERT provides valuable information on this site concerning recent threats.
Gilbert Rivera

EBSCOhost: Storing Information in the Cloud - A Research Project - 0 views

  •  
    Cloud Data Storage: Annotated Bibliography In this research document, the authors provide us with a study of data storage in the cloud. It focuses on the management, operation and security of data stored for long periods of time in the cloud. This item is useful for the fact that it can present several demographics to business regarding cloud computing security, data storage functionality and also cites several business surveys that can assist in organizations to make the decision to migrate to cloud computing services and data storage.
Percy Kendrick

US-CERT | United States Computer Emergency Readiness Team - 3 views

  •  
    US-CERT's mission is to improve the nation's cybersecurity posture, coordinate cyber information sharing, and proactively manage cyber risks to the nation.
  •  
    The "Alerts And Tips" page of this site provides excellent up to date alerts. (http://www.us-cert.gov/ncas). Subheadings include: Current Activity, Alerts, Bulletins, and Tips. The Bulletins page provides weekly vulnerability summaries. It's worth a look for anyone who hasn't seen this already.
Amy Harding

Scope Of APTs More Widespread Than Thought - Dark Reading - 3 views

  •  
    Researcher uncovers hundreds of different custom malware families used by cyberspies -- and discovers an Asian security company conducting cyberespionage
  •  
    This article raises some serious questions in my opinion. As we move more into an environment where cyber warfare is to be used against different countries, where are the lines drawn between declaring war. As this article discusses, it is not as easy to see who actually was behind the attack, and an attack coming from Chinese, or some other countries IP space, is not neccessarily a state sponsored attack, nor is it neccessarily coming from someone inside the country. In a hack back scenario, it could be determined after the fact that whatever country was thought to initiate the first move, was actually a victim of a "zombie/bot" type of controlled attack that was actually initiated in another country. Can you say, Wargames? Edited 3222013: as I spoke yesterday, today guess what? http://news.yahoo.com/skorea-misidentifies-china-cyberattack-origin-071350510.html
Amy Harding

Security Requirements for Cryptographic Modules - 4 views

  •  
    This standards publication (FIPS 140-2) is a key standard's document. Skim through it and see if you can find some ideas for emerging threats against the standard(s).
  • ...1 more comment...
  •  
    FIPS 140-3 is on its way and is needed as 140-2 is quite old now. Interestingly however, crypto is one of the slower moving changes in information security. Many of our algorithms have been around for many years; we have moved forward by increasing key size rather than changing the algorithms. AES and 3DES are still FIPS approved, whereas RC4 is not (which is used by many internet giants such as google and facebook).
  •  
    Any time you are allowed to introduce code into a program, you have a chance for error. By allowing cryptographic software and firmware to be updated, I think you will always have the chance for emerging threats to be introduced in the form of malware. Recently, the U.S. has stopped allowing the use of Chinese built hardware for certain DOD/ Federal agencies. if we allow the enemy to build the devices we use to form our security foundations, we have already lost the war.
  •  
    I believe the frequency of review of this policy is untimely to the speed technology advances in. If they could move the review from 5 years to 2 years will suffice. At times, once the policy is published folks are already working on the revision to keep up with technology growth. "Since a standard of this nature must be flexible enough to adapt to advancements and innovations in science and technology, this standard will be reviewed every five years in order to consider new or revised requirements that may be needed to meet technological and economic changes."
samuelrios

Court Says C.I.A. Must Yield Some Data on Drones - NYTimes.com - 3 views

  •  
    Article supports drones as being an emerging technology. ASSignment1, Part1 Support
  •  
    Interesting article, It seems to me that this is just another one of those cases about flexing the "muscle" of the Freedom of Information Act. In my opinion it is pretty common knowledge that targeted drone strikes are being used to eliminate enemies; so why is it so important here that the C.I.A. has to acknowledge these attacks? What would that accomplish? The media outlets already report on successful drone strikes and now there are even military medals to recognize drone pilots. http://www.fsunews.com/article/20130318/FSVIEW0303/130317001/New-military-medal-stirs-controversy-?odyssey=mod|newswell|text|frontpage|s
  •  
    I just wonder how long it's going to take before something comes out of these attacks. Using these drones to fly into other countries like Pakistan, and "take out" suspected enemies is pretty borderline in my opinion. If this were to happen in America, we would certainly not stand for it, and would declare war on the country that carried out the action. Pushing the button from California on a drone missle is alot like conducting cyber warfare from one country to another. The damage that can be done is becoming greater and greater every day as technology is starting to tie together national infrastructures. In my opinion, drones are the some of the first of the cyber warfare machines.
Shondre Fort

Researchers Share Useful Lessons Learned in Evaluating Emerging Technologies - 0 views

  • Schlenoff and his colleagues used their SCORE approach to evaluate technologies as they progressed under two DARPA programs: ASSIST and TRANSTAC. In ASSIST, DARPA is funding efforts to instrument soldiers with wearable sensors—video cameras, microphones, global positioning devices and more—to continuously record activities while they are on a mission. TRANSTAC is driving the development of two-way speech-translation systems that enable speakers of different languages to communicate with each other in real-world situations, without an interpreter. By providing constructive feedback on system capabilities, the SCORE evaluative framework helps to drive innovation and performance improvements.
  •  
    SCORE (System, Component and Operationally Relevant Evaluations) is a unified set of criteria and software tools for defining a performance evaluation approach for complex intelligent systems. It provides a comprehensive evaluation blueprint that assesses the technical performance of a system and its components through isolating and changing variables as well as capturing end-user utility of the system in realistic use-case environments. The SCORE framework has proven to be widely-applicable in nature and equally relevant to technologies ranging from manufacturing to military systems. It has been applied to the evaluation of technologies in DARPA programs that range from soldier-worn sensor on patrol to speech-to-speech translation systems. It is also currently being applied to the assessing the control of autonomous vehicles on a shop floor.
  •  
    From NIST Tech Beat: June 21, 2011 Most industry executives, military planners, research managers or venture capitalists charged with assessing the potential of an R&D project probably are familiar with the wry twist on Arthur C. Clarke's third law*: "Any sufficiently advanced technology is indistinguishable from a rigged demo."
samuelrios

Unmanned drones making U.S. a Predator nation - 3 views

  •  
    (TomDispatch) Here's the essence of it: you can trust America's creme de la creme, the most elevated, responsible people, no matter what weapons, what powers, you put in their hands. No need to constantly look over their shoulders.
  • ...1 more comment...
  •  
    Samuel, A god article, even though the writer seems very passionate about the topic. Like everything else there are good and bad sides it. I can understand the view point, but have also talked to people who use some of these and people who have been supported by these and yes in the hands of "good" they are a valuable asset. I have even heard of the police using them as they are quiter than choppers. Very good article. Lee
  •  
    Great article Samuel, I had wondered about this topic for a while but did not have the chance to actual research the in's and out's. This article has definitely informed me of the issue. Great find!
  •  
    Sam, Great article. Sometimes people don't always think about the negative side of things. I know about unmanned drones I had not. Thank you for informing us of this.
paksingtham

Growing Data Security Concerns to Drive Global Market for Keystroke and Typing Dynamics... - 4 views

  •  
    I can't see this being used much for single factor authentication, but I could certainly see it being used on top of a username/password setup to bolster the security of that password. Another useful application for this would be to augment an anomaly based IDS running on the user's system. If keystroke patterns/dynamics exceed standard deviation, an alert could be sent to the help desk or security, who could then verify the identity of the user.
  •  
    I could see some companies implementing keystroke and typing dynamics depending on their sector and security posture. However, depending on the sensitivity of the software, they could receive a lot of false positives. I've personally noticed my typing speed fluctuates drastically depending on the time of day. Nevertheless, I could see more companies deploying the software depending of their budget.
  •  
    It seems that there are way to many variables for this technology to really take off. I agree with trevor that there is potential for a high volume of false positives. I also see potential for a high volume of false negatives. This technology seems as though it could end up being extremely frustrating for the end user.
Amy Harding

U.S. business groups worried by cybersecurity law aimed at China | Reuters - 0 views

  •  
    This article talks about buying technology products from China and whether the US should. The supply chain is an important part of emerging technologies. As you worked on your bibliography - did you question where the technology comes from?
Shondre Fort

Gestures are taking control - 0 views

  •  
    The author of this article presents the anticipated growth of gesture control technology. It is already used in Smart phones; however, the author presented information about the expansion of this technology to laptop and personal computers. The author presented how this technology has developed presenting that the beginning formation of this technology has been seen in gaming systems that allow the user to use their body movements to control their avatar. Australian researchers are developing similar technology to be used to control the television.
Justin Ohm

Cognitive biometrics: A very personal login - 2 views

  •  
    Retina and iris scans, fingerprint and palm logins rely on possession of unique anatomical characteristics that you cannot forget as you might a password. But, Kenneth Revett of the British University in Egypt, in El-Sherouk City, reviews the state of the art in an alternative approach to user authentication in the inaugural issue of the International Journal of Cognitive Biometrics.
  •  
    Very interesting article Justin. I like the idea of using biometrics as an authentication layer, vs. relying on a CA to issue digital certificates. In my opinion, biometrics should only use functions that can be read or measured when the person is alive.
  •  
    Biometrics is great for a multi factored authentication. It is a very expensive approach to authenticating as well. I doubt there will be a market for it until the price for implementation drops drastically. I would not use it as a stand alone authentication approach.
Jessica Riedel

Mozilla: Ad Networks Have No 'Constitutional Right' To Set Cookies - 2 views

  •  
    With all of the privacy issues running rampant today, it looks like Mozilla is taking a stand against third-party cookies. Essentially they want to stop the third-party cookies from collecting data about the user's browsing habits and create the Internet people expect. Even though it isn't mentioned I think its an excellent marketing strategy against other browsers, cough cough Google, that rely on these cookies to track user habits and provide/tailor their product. This is a short description of the article: Mozilla recently drew the ire of the online ad industry by announcing plans to move forward with a project to block third-party cookies in the Firefox browser. Randall Rothenberg, President and CEO of the Interactive Advertising Bureau, publicly called on the company to retreat, arguing that it shouldn't try to implement "economic and cultural policies."
  •  
    It's bad enough that retailers are looking into or actually using camera footage to capture our spending and shopping habits without posting any warning. Thanks for the artical posting.
  •  
    I give Monzilla credit for being the first to step up about this issue. If they could stop the third party cookies I am sure a lot of users would jump over to their browser. The problem is that data is used for advertising which is used by companies like Monzilla to sell advertising space
Amy Harding

Biometrics and Cyber Security - 8 views

  •  
    Review the presentation.
  • ...3 more comments...
  •  
    This article does mention balancing some weaknesses of biometrics. The one weakness that is common right now among these systems is the use of usernames and passwords to form a secondary means of accessing the system once the biometrics no longer work. With the implementation of multi-modal systems, this could be resolved. The article also discusses international based systems, which could be difficult, personal information is a source of contention between many countries. Where is the information stored, and what laws become enforceable depending on the users point of presence?
  •  
    Interesting article thank you for posting it. As Phil and the article mentioned where is this information stored. The security of this information is deeply concenring. Not that I am a conspiracy theorist but I really do not want my biometric information to be stored on some database. I remember when my daughter was young there was a push to have your child's DNA sample taken and stored in case it was ever needed in the event the child was kidnapped or lost. After thinking about it back then I just did not see how the government having her DNA sample was a good thing. Of course if she ever comitted a crime I would like to think that I would want her punished for the crime but being a parent I also know that I would do anything to protect her, so why would I give the government a readily available DNA sample for them to identify her with. In the event a sample was needed because of some terrible event happening to her one could be provided through other methods. Just my thoughts.
  •  
    I just posted up an article on fooling biometric fingerprint scanners, Facial scanners can be fooled with photos http://thehackernews.com/2011/11/android-facial-recognition-based.html The Danger is that while one can get a new password or smart card if the old is compromised, You only have one face, two eyes and 10 fingers to use for ID and can't get new ones when someone figures out how to comprimise them.
  •  
    Thanks for the posting especially since my project deals with Ambient Intelligence wherein biometrics can be an integral part of its implementation. One of the most common and frequent incidents in Service Management is authentication. Whether it is with entering secure facilities or logging into computer systems both in the office and remotely, people tend to forget their credentials. Consequently, this causes a loss in productivity as someone tries to regain their access to systems or for system administrators to provide them with temporary access. Ambient intelligence and biometrics may seem as a viable solution since the physical characteristics is intrinsic in each individual. This presentation presents me with the cybersecurity flaws and weaknesses that should be mitigated.
  •  
    Biometrics is always something I have found to be fascinating. Because like this article stated no one knows who you are on the other end of that computer so being able to authenticate that in some sort of method is a great thing
Amy Harding

Blueprint for a Secure Cyber Future - 30 views

  •  
    This document is used for your Week 1 discussion questions.
1 - 20 of 108 Next › Last »
Showing 20 items per page