| Forthcoming Papers > International Journal of Internet Technology and Secured Transactions (IJITST) Journal Homepage This page lists papers submitted for IJITST via the web that have been reviewed and accepted but not yet published. Please note that titles, authors, abstracts and keywords may change upon publication. Our TOC e-mail alerting service will notify you immediately when new issues of IJITST are published on-line. Click here to register for our TOC E-Mail Alerting. We also offer the convenience of RSS feeds which provide a means to view new content timely posted to your web site or desktop. Click here to start to use our free RSS news feeds. | International Journal of Internet Technology and Secured Transactions (3 papers in press)
- Optimizing Password Security through Key-Pattern Analysis
by Ravel Jabbour, Wes Masri, Ali El-Hajj Abstract: No security mechanism has been deemed secure enough. Thus, research into application security has ventured into alternative technologies that consider the user aspects of implementation. In this paper we present an enhanced approach to password security based on key-pattern analysis (KPA). Our approach relies on its two focal pillars, Inter and Intra timing, which are stretched along the lines of increasing password entropy, trouncing the habit factor, and finally trimming down the error margin under an appropriate user fitting technique. Other user optimization techniques include token authentication and character-sound recognition. By serving notice as to the immense power of Intra timing in reliable authentication, we amount to the development of beat-like passwords as a means of strengthening the overall KPA mechanism. Keywords: password security; key-pattern analysis; keystroke analysis; user authentication; biometrics. - Creating and Enforcing Access Control Policies using Description Logic Techniques
by Brian Shields, Owen Molloy Abstract: The quantity of generated information we store and need to access is colossal. Security of this information is becoming an issue of greater importance as the techniques and granularity with which it can be accessed become more advanced. Availability of information is a key component of any security system, although the information must be protected, it must also be available to the people who need it as and when they request it. However, increasing the methods by which it is accessible automatically increases the chance it maybe compromised. Security systems are now using advanced levels of encryption, digital signatures containing biometric data and highly complex access control policies. We are proposing an access control system which reduces the complexity involved in defining authorisation permissions, particularly in structured documents such as XML where the user may be granted restricted access. Our solution employs techniques usually reserved for intelligent systems and the semantic web. Keywords: Access Control; Description Logic; Rules - Trust Algorithms in P2P File Sharing Networks
by Sem Daskapan Abstract: Many peer to peer (p2p) networks are used to share different types of files between users who are usually anonymous. To prevent the distribution of files that have been intentionally damaged, filled with false content or infected with malware, users need to be able to distinguish between trustworthy and malicious peers. One way to help a user in separating the good peers from the bad peers, is to provide him/her with a sophisticated trust algorithm that calculates the trustworthiness of any peer involved in a file sharing transaction. In this paper the results of a comparative study are presented as a first contribution. This study is based on a taxonomy of seventeen trust algorithms as found in literature. The evaluation is done by means of both a literature study and a series of simulation tests. By using the evaluation results, the advantages of each of the current algorithms are singled out, and next combined to develop and implement a new and better trust algorithm for file sharing in p2p networks. This is the second contribution Keywords: Peer to Peer Networks, Trust management, Trust valuation, File sharing, Simulation
|
|