From individual universities around the country to a consortium of research institutions stretching the length of the west coast, networking teams are deploying an infrastructure architecture known as the Science DMZ to help researchers make productive use of ever-increasing data flows. The Science DMZ traces its name to an element of network security architecture. In…
Automated Voice Imitation fools Humans and Machines
Researchers have found that automated and human verification for voice-based user authentication systems are vulnerable to voice impersonation attacks. Using an off-the-shelf voice-morphing tool, the researchers developed a voice impersonation attack to attempt to penetrate automated and human verification systems. This new research was presented at the European Symposium on Research in Computer Security, or ESORICS,…
Scientists Stop and Search Malware hidden in Super Bowl Tweets
Cyber criminals are taking advantage of real-world events with high volumes of traffic on Twitter in order to post links to Web sites that contain malware. To combat the threat, computer scientists have created an intelligent system to identify malicious links disguised in shortened URLs on Twitter. In the recent study, the Cardiff University team…
Millions More Government Fingerprints Deemed Stolen
WASHINGTON (AP) — The number of people applying for or receiving security clearances whose fingerprint images were stolen in one of the worst government data breaches is now believed to be 5.6 million, not 1.1 million as first thought, the Office of Personnel Management announced September 23, 2015. The agency was the victim of what…
Pursuing Effective Security Tools for Software Developers
For software programmers, security tools are analytic software that can scan or run their code to expose vulnerabilities long before the software goes to market. But these tools can have shortcomings, and programmers don’t always use them. New research from National Science Foundation-funded computer science researcher Emerson Murphy-Hill and his colleagues tackles three different aspects…
Quantum-proof: Cryptographers Develop New Protocol to Secure Data from Tomorrow’s Supercomputers
For the powerful quantum computers that will be developed in the future, cracking online bank account details and credit card numbers will be a cinch. But a team of cryptographers is already working at future-proofing the privacy of today’s Internet communications from tomorrow’s powerful computers. Queensland University of Technology’s Dr. Douglas Stebila, along with researchers…
JSM 2015 Roundup: 10 Stories You Don’t Want to Miss
JSM, the Joint Statistical Meetings, the largest gathering of statisticians held in North America, took place this year from August 8 to 13, 2015, in Seattle WA. Attended by more than 6,000 people, it was held jointly with the American Statistical Association, International Biometric Society (ENAR and WNAR), Institute of Mathematical Statistics, Statistical Society of…
New Analysis Method Finds 11 Security Flaws in Popular Internet Browsers
WASHINGTON, DC — Researchers from the Georgia Institute of Technology College of Computing developed a new cyber security analysis method that discovered 11 previously unknown Internet browser security flaws, and were honored with the Internet Defense Prize, an award offered by Facebook in partnership with USENIX at the 24th USENIX Security Symposium. Ph.D. students Byoungyoung…
Powerful New Security Tool Detects Malware Uploading to Cloud Servers
A powerful new computer security tool called XDet that can detect malicious files being uploaded to a cloud computing service is reported this month in the International Journal of Space-Based and Situated Computing by researchers from Manchester Metropolitan University and Nottingham Trent University, UK. Rob Hegarty (MMU) and John Haggerty (NTU) explain how cloud computing…
U.S. seeks Extradition of Man Charged with Hacking into U.S. Government Networks
NEWARK, N.J. (AP) — A British man accused of hacking into U.S. government computer networks and stealing sensitive and confidential information was arrested in England, and U.S. prosecutors said they will attempt to have him transferred to New Jersey. Lauri Love, of Stradishall, England, has been charged with hacking into agencies including the U.S. Army,…
LLNL Licenses Tool to Improve Government Computer Network Security
Government agencies, along with state and local governments, could receive a helping hand from a computer network security tool developed by Lawrence Livermore National Laboratory (LLNL) computer scientists and engineers. The LLNL software-based technology, known as the Network Mapping System (NeMS), has been licensed to Cambridge Global Advisors, a Washington, D.C.-area strategic advisory firm. “We…
Stories You Shouldn’t Miss — July 3-9
Here they are — the top most visited stories from the past week. A spyware peddler suffers a major hack; experimental artificial heart is a success; 8-minute video of Rover Opportunity’s Epic Mars Marathon; astounding new mosaic image of our Sun’s surface, and a series of intriguing spots along Pluto’s’ equator are all among the…
Milan-based Hacking Team appears to get Hacked
LONDON (AP) — An Italian surveillance company known for selling malicious software used by police bodies and spy agencies appears to have succumbed to a damaging cyberattack that sent documents and invoices ricocheting across the Internet. Hacking Team’s Twitter account appears to have been hijacked late on July 5, 2015, posting screenshots of what were…
NIST 2015 – 6th Annual Conference & Expo
NIST 2015 – 6th Annual Conference & Expo November 3-4, 2015 Paradise Point San Diego, California Attendee Registration Call For Papers (Presentations) will be released in mid-July The 6th Annual Conference & Expo will take place from November 3 to 4, 2015, in San Diego, CA. It is sponsored by the National Initiative for…
RAID: Alive or Dead?
Is RAID dead or alive? Are erasure codes replacing RAID for data protection? We present these questions, because some storage vendors promote RAID, while others promote erasure codes. Looking at how vendors are marketing data protection in their products, it almost appears that there is a battle between RAID and erasure code technology and that…
Extremely Sophisticated Criminals access Tremendous Amount of IRS Data
WASHINGTON (AP) — More than 100,000 taxpayers have had their personal tax information stolen from an IRS Web site as part of an elaborate scheme to claim fraudulent tax refunds. The information was stolen from an online system called “Get Transcript,” where taxpayers can get tax returns and other tax filings from previous years. In…
With One False Tweet, Computer-based Hack Crash Led to Real Panic
BUFFALO, NY — A false tweet from a hacked account owned by the Associated Press (AP) in 2013 sent financial markets into a tailspin. The Dow Jones Industrial Average dropped 143.5 points and the Standard & Poor’s 500 Index lost more than $136 billion of its value in the seconds that immediately followed the post.…
Advancing Security and Trust in Reconfigurable Devices
A research team at the Georgia Tech Research Institute (GTRI) is studying a range of security challenges involving programmable logic devices — in particular, field programmable gate arrays (FPGAs). FPGAs are integrated circuits whose hardware can be reconfigured — even partially during run-time — enabling users to create their own customized, evolving microelectronic designs. They…
Bringing Cyber Threat Predictive Analytics to The Cloud
ARMONK, NY — IBM is bringing its Security Intelligence technology, IBM QRadar, to the cloud, giving companies the ability to quickly prioritize real threats and free up critical resources to fight cyberattacks. The new services are available through a cloud-based software as a service (SaaS) model, with optional IBM Security Managed Services to provide deeper…
New Pentagon Strategy Warns of Cyberwar Capabilities
PALO ALTO, CA (AP) — A new Pentagon cybersecurity strategy lays out for the first time publicly that the U.S. military plans to use cyberwarfare as an option in conflicts with enemies. The 33-page strategy says the Defense Department “should be able to use cyber operations to disrupt an adversary’s command and control networks, military-related…
Cloud Security Reaches Silicon: Defending against Memory-access Attacks
In the last 10 years, computer security researchers have shown that malicious hackers don’t need to see your data in order to steal your data. From the pattern in which your computer accesses its memory banks, adversaries can infer a shocking amount about what’s stored there. The risk of such attacks is particularly acute in…
Restoring Lost Data: 3-D Digital Laser Microscopy Creates Visual Roadmap
It can be disheartening to learn that something precious, such as a one-of-a-kind family photo, has disappeared from a scratched or broken CD or DVD. It also can become serious, dangerous and potentially costly if it happens to a disc containing criminal forensic evidence, corporate records or scientific data. But there may be a way…
MOVIA Big Data Analytics Platform
MOVIA Big Data Analytics Platform is designed to help organizations watch for important patterns in their data and generate instant alerts to users or other systems. The software enables improved prediction of trends through advanced data modeling that captures situational context, so decisions are not ‘made in a vacuum.’ It employs semantics and logical reasoning…
Mathematicians adapt Knapsack Code to take on Quantum-level Cyber Attacks
PULLMAN, WA — Mathematicians have designed an encryption code capable of fending off the phenomenal hacking power of a quantum computer. Using high-level number theory and cryptography, the researchers reworked an infamous old cipher called the knapsack code to create an online security system better prepared for future demands. The findings were recently published in…
Better Debugger: Algorithm Automatically Finds Integer-overflow Bugs
Integer overflows are one of the most common bugs in computer programs — not only causing programs to crash but, even worse, potentially offering points of attack for malicious hackers. Computer scientists have devised a battery of techniques to identify them, but all have drawbacks. Researchers from MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL)…






















