My experience on my daily works... helping others ease each other

Tuesday, December 17, 2013

Top Crypto and Security Conferences Ranking 2013 by Jianying Zhou


Conference
CIF [2013]
AR
PR
CR [2013]
1.      IEEE S&P
4.26
11.4%  (29.4 / 257.3)   [2004-2013]
9.1%    (29.4 / 322.8)  [2004-2013]
3%
2.      Usenix Sec
3.95
15.5%  (31.3 / 201.9)   [2006-2013]
6.9%    (31.3 / 452.1)  [2006-2013]
2.9%
3.      Eurocrypt
3.23
19.2%  (34.5 / 179.6)   [2006-2013]
8.9%    (34.5 / 387.3)  [2006-2013]
2.9%
4.      Crypto
3.02
19.4%  (40.9 / 211)     [2006-2013]
10.4%  (40.9 / 393.8)  [2006-2013]
3.3%
5.      ACM CCS
2.77
17.9%  (66.3 / 371.3)  [2007-2013]
13.2%  (66.3 / 500.9)  [2007-2013]
5%
6.      Asiacrypt
2.58
15.2%  (38.6 / 253.3)  [2006-2013]
16.7%  (38.6 / 231.1)  [2006-2013]
6.8%
7.      NDSS
2.51
16.7%  (29.1 / 173.9)  [2007-2013]
20.8%  (29.1 / 140.1)  [2007-2013]
2.3%
8.      CHES
2.45
25.3%  (31.1 / 122.8)  [2004-2013]
10.3%  (31.1 / 302.9)  [2004-2013]
5.3%
9.      RAID
2.19
22.2%  (19.4 / 87.5)    [2006-2013]
17.5%  (19.4 / 110.9)  [2006-2013]
6%
10.    PETS
2.15
24.2%  (15.9 / 65.8)    [2006-2013]
14.4%  (15.9 / 110.1)  [2006-2013]
8%
11.    ACSAC
2.08
21%     (39.7 / 189.5)  [2004-2013]
17.8%  (39.7 / 223.5)  [2004-2013]
9.4%
12.    FSE
1.87
29.1%  (26 / 89.3)       [2006-2013]
16.4%  (26 / 158.9)     [2006-2013]
8.1%
13.    IEEE CSF
1.81
24.2%  (22.6 / 93.4)    [2006-2013]
24.7%  (22.6 / 91.4)    [2006-2013]
6.3%
14.    DSN
1.79
22.5%  (63.1 / 281)     [2004-2013]
23.3%  (63.1 / 270.9)  [2004-2013]
10%
15.    DIMVA
1.689
30.3%  (13.1 / 43.3)    [2004-2013]
16.6%  (13.1 / 78.9)    [2004-2013]
12.3%
16.    CT-RSA
1.686
28.7%  (25.5 / 88.9)    [2006-2013]
22.8%  (25.5 / 112.1)  [2006-2013]
7.8%
17.    PKC
1.59
25.8%  (30.7 / 118.9)   [2004-2013]
30.1%  (30.7 / 102)     [2004-2013]
6.9%
18.    ACNS
1.56
17.2%  (32.8 / 190.6)   [2004-2013]
33.8%  (32.8 / 97)       [2004-2013] 
19.    TCC
1.54
32.1%  (33.5 / 104.5)   [2006-2013]
26%    (33.5 / 129.1)   [2006-2013]
6.8%
20.    ESORICS
1.50
20.6%  (40.1 / 194.8)   [2006-2013]
35.1% (40.1 / 114.4)   [2006-2013]
11.1%
21.    ACM WiSec
1.40
25.7%  (22.8 / 88.7)    [2008-2013]
31.1%  (22.8 / 73.3)    [2008-2013]
14.6%
22.    FC
1.399
28.5%  (26.1 / 91.6)    [2006-2013]
31.3%  (26.1 / 83.5)    [2006-2013]
11.7%
23.    SAC
1.28
27.7%  (25.5 / 92)       [2008-2013]
37.3%  (25.5 / 68.3)    [2008-2013]
12.9%
24.    ISC
1.25
24.7%  (32.1 / 129.8)  [2005-2013]
41%     (32.1 / 78.3)    [2005-2013]
14.1%
25.    ACISP
1.03
31.4%  (30.5 / 97.3)    [2008-2013]
46.2%  (30.5 / 66)       [2008-2013]
14.5%
•            ACM AsiaCCS

27%     (48.9 / 181)     [2007-2013]
56.3%  (48.9 / 86.9)    [2007-2013]
?




Share:

Monday, November 25, 2013

Writing Thesis - What You Need To Know?

I've been writing my thesis since last year and had to extend my studies due to this. I failed to understand the gist and only know about this few months ago. Yet, I still have difficulties and putting the right things/word/sentence in my thesis. The most difficult part will be findings and discussion. It is not the result, but how to put and explain the result and ensure that anyone reads the thesis understand what we have done without necessity to ask us. So how do we do that?


I found few sites sharing about it. The best was published in Monash University website. As such, I would like to share it and hopefully, anyone interested to do research in Master or Phd, will get something before the begin their journey. :)

Have fun reading :)

Writing

  1. What you need to know before writing thesis - http://www.monash.edu.au/lls/hdr/write/
  2. Writing your thesis - http://www.phrasebank.manchester.ac.uk/introductions.htm
  3. Getting your discussion and findings right - http://www.heacademy.ac.uk/assets/hlst/documents/research_gateway/research_gateway_section7_discussion_of_findings.pdf
Share:

Thursday, October 31, 2013

Building Security in Maturity Model (BSIMM)

BSIMM-V does a number on secure software development
by Gary McGraw, Contributor
The fifth iteration of the Building Security In Maturity Model project is a tool enterprises can use as a measuring stick for their software security initiatives. Gary McGraw offers this exclusive first look... [read more]
(SearchSecurity.com)


What is BSIMM-V?
The Building Security In Maturity Model (BSIMM, pronounced "bee simm") is an observation-based scientific model describing the collective software security activities of 51 software security initiatives. Thirty-six of the 51 firms we studied have graciously allowed us to use their names -- they are listed under "BSIMM member organizations" in the sidebar.
BSIMM4 is used as a measuring stick for software security. As such, it is useful for comparing software security activities observed in a target firm to those activities observed among the 51 firms (or various subsets of the 51 firms). A direct comparison using the BSIMM is an excellent tool for devising a software security strategy... [read more]
Share:

Wednesday, October 30, 2013

Challenge - Develop awesome mobile games with a free state-of-the-art game engine

New challenge

Develop awesome mobile games with a free state-of-the-art game engine

Admit it, you've had an amazing game brewing in your imagination ever since you played that last mobile game and thought "I could have made this!".

Now's your chance to develop YOUR dream game, ship it for FREE on iOS or Android, and show it to the world. Download Project Anarchy, Havok's complete end to end game engine for mobile, and get started developing today.

In addition to $100,000 in prizes, up to ten Early Submission Finalists will be chosen to showcase and promote their games at Havok's booth during the 2014 Game Developers Conference in San Francisco.

Enter your game by February 1, 2014 to get feedback from Havok's world-class dev team who helped perfect everything from Assassin's Creed IV, Destiny, Halo 4, Uncharted 3, and Skyrim. They can help push the limits of what your game can do with the power of Project Anarchy!
$100,000 IN PRIZES
May 31, 2014 
SUBMISSION DEADLINE
Open to most developers age 18+ around the world
See official rules for details
Facebook   Twitter   Email


Share:

Saturday, October 5, 2013

Glorious Future of BlackBerry Z10

The BlackBerry Z10 is supposed to be the start of a new era for BlackBerry. If that is to happen, consumers will need to be convinced of its innovation and potential. Therefore, they will need to know two things: how does it differ from previous BlackBerry models? And, why should they be interested? BlackBerry will be hoping that the answer to the first question will also answer the second.

Z10 versus early Blackberry

In terms of differences to previous BlackBerry models the Z10 has many. The most notable of these is the absence of the quintessential qwerty keyboard with the 4.2 inch, high resolution touch screen of the Z10 leaving no room for it. This may please those who prefer a touch screen keyboard but may also put off the hardcore faithful who enjoyed the old keyboards. However, for both parties, BlackBerry has designed a spacious and easy to use touch screen keyboard with a predictive text feature which means the predicted word appears over the next letter, meaning the user only needs to swipe it upwards to enter.

Price does matters

Alongside previous model differences, you also need to consider how it fares against the main rivals. Often cheaper than competitors, the BlackBerry Z10 price comes in at RM 1,799.00 for the handset.

Superb Features of Z10

Another new feature on the Z10 is the BlackBerry Hub, which houses all messages, e-mails and notifications. It has been designed with the object of allowing an experience which is flowing and easy for the user. The user may be in the middle of something on an app when their phone beeps but there is no need to close that app and search through texts, social media and e-mail to discover the source of the notification. All they need do is swipe upwards and right with their thumb and peek into the hub, this will allow them to see their texts, e-mails and anything else they have told the Hub to store. From there they can choose whether to reply immediately or later allowing them to not be completely disturbed by every single notification.

In pursuit of further flow there is no need to close apps if the user chooses to reply to the message. The user just has to simply swipe the app down where it will stay exactly as they left it ready to be picked up later when the user is ready. It is important to note that with the Z10s ability to run eight apps simultaneously, there is no need to worry about lag when doing this.

Not everything is totally new on the Z10, some of it has just been updated and modernised such as the new BlackBerry Messenger (BBM). This has always been popular with BlackBerry users as it allows you to exchange messages and pictures instantly with your contact list for free. BBM has been expanded, with the Z10s front facing camera in mind, to allow video calls to any contact anywhere in the world thus making it perfect for catching up with friends and conducting international business alike.

A second new feature to BBM is Screen Share. At the press of a button during a video call Screen Share allows users to literally share their screen with the contact they are calling. This again has great potential for social and business use alike by allowing people to show their friend a funny Youtube clip or to show their colleague an important document with the valuable ability to talk it over at the same time.


Z10 - Simply the best

Older BlackBerry models put many consumers off with the lack of apps that could be downloaded onto them, but with the Z10 BlackBerry launched its new BlackBerry 10 World which contains 70,000 apps including big names, such as Skype, that were missing before. This is a valuable asset in a world where apps are king and BlackBerry World looks only set to grow. However, whether the BlackBerry Z10s future is glorious remains in the hands, or the wallets, of the consumers.


Writer: Lenny Marlina (Nina Lia) - (http://mightytechnews.wordpress.com/)
Share:

Wednesday, September 25, 2013

SWOT analysis (strengths, weaknesses, opportunities and threats analysis)

SWOT analysis (strengths, weaknesses, opportunities, and threats analysis) is a framework for identifying and analyzing the internal and external factors that can have an impact on the viability of a project, product, place or person. 
The framework is credited to Albert Humphrey, who tested the approach in 1960s and 1970s at the Stanford Research Institute (SRI). Developed for business and based on data from Fortune 500 companies, the SWOT analysis has been adopted by organizations of all types as an aid to making decisions.
As its name states, a SWOT analysis examines four elements:
  • Strengths - internal attributes and resources that support a successful outcome.
  • Weaknesses - internal attributes resources that work against a successful outcome.
  • Opportunities - external factors the project can capitalize on or use to its advantage.
  • Threats - external factors that could jeopardize the project.
Share:

Tuesday, September 10, 2013

Internet Society Responds to Reports of the U.S. Government’s Circumvention of Encryption Technology

Internet Society Responds to Reports of the U.S. Government’s Circumvention of Encryption Technology

The Internet Society is alarmed by continuing reports alleging systematic United States government efforts to circumvent Internet security mechanisms.  The Internet Society President and CEO, Lynn St. Amour, said,  “If true, these reports describe government programmes that undermine the technical foundations of the Internet and are a fundamental threat to the Internet’s economic, innovative, and social potential. Any systematic, state-level attack on Internet security and privacy is a rejection of the global, collaborative fabric that has enabled the Internet's growth to extend beyond the interests of any one country.”

The Internet Society believes that global interoperability and openness of the Internet are pre-requisites for confidence in online interaction, they unlock the Internet as a forum for economic and social progress, and they are founded on basic assumptions of trust. We are deeply concerned that these principles are being eroded and that users' legitimate expectations of online security are being treated with contempt.
As the institutional home of the Internet Engineering Task Force (IETF), we believe that open and transparent processes are essential for security standardization, and result in better outcomes than any alternative approach.  For example, protocols developed by the IETF are open for all to see, inspect, and verify, as are the open and inclusive processes by which they are specified. 

IETF Chairman Jari Arkko has strongly reiterated the IETF’s commitment to improving security in the Internet, and to seeking ways of improving security protocols in light of these new revelations and security threats.  “The IETF has a long-standing commitment to openness and transparency in developing security protocols for the Internet, and sees this as critical to confidence in their use and implementation.”  To read more, visit:  http://www.ietf.org/blog/2013/09/security-and-pervasive-monitoring/.

However, the open development of robust technical specifications is just one link in the chain. Security standards must be properly implemented and used. This is a wake-up call for technology developers and adopters alike, to reexamine what we can do to ensure that all links in the chain are equally strong. This is key to helping restore public trust and confidence in the Internet.

The Internet has tremendous potential for economic and social good, but unless all stakeholders trust the Internet as a safe place for business, social interaction, academic enquiry, and self-expression, those economic and social benefits are put at risk. To fulfill its potential, the Internet must be underpinned by the right combination of technology, operational processes, legislation, policy, and governance. The recent reports suggest that U.S. Government programmes have systematically undermined some or all of those measures, and that is why we view the revelations with such grave concern.

With this mind, we issue these calls to action for the global community:

• To every citizen of the Internet: let your government representatives know that, even in matters of national security, you expect privacy, rule of law, and due process in any handling of your data.

Security is a collective responsibility that involves multiple stakeholders.  In this regard, we call on:

• Those involved in technology research and development: use the openness of standards processes like the IETF to challenge assumptions about security specifications.

• Those who implement the technology and standards for Internet security: uphold that responsibility in your work, and be mindful of the damage caused by loss of trust.

• Those who develop products and services that depend on a trusted Internet: secure your own services, and be intolerant of insecurity in the infrastructure on which you depend.

• To every Internet user: ensure you are well informed about good practice in online security, and act on that information. Take responsibility for your own security.

At the Internet Society, we remain committed to advancing work in areas such as browser security, privacy settings, and digital footprint awareness in order to help users understand and manage their privacy and security.  The citizens of the Internet deserve a global and open platform for communication built on solid foundations of security and privacy.

As email by ISOC
Share:

Tuesday, September 3, 2013

VULNERABILITIES AND EXPLOITATION IN COMPUTER SYSTEM – PAST, PRESENT, AND FUTURE


Software vulnerabilities are regard as the most critical vulnerabilities due to its impact and availability as compared to hardware and network vulnerabilities. Throughout the years from the first appearance of software vulnerabilities in late 80s until today, there are many identified and classified software vulnerabilities such as the well-known buffer overflow, scripting and SQL command. We studied on those known software vulnerabilities, compared the criticality, impact and significant of the vulnerabilities, and further predicted the trend of the vulnerabilities and proposed the focus area based on the comparative studies. The result shows that C overflow vulnerabilities will continue to persist despite losing its dominance in terms of numbers of availability and exploitation. However, the impact of exploiting the C overflow vulnerabilities is still regard as the most critical as compare to others. Therefore, C overflow vulnerabilities will prevail again and continues its domination as it did for the past two decades.

The complete paper can be retrieve here (coming soon).

The presentation slide is available here (click the image below)

or can be view at slideshare as shown below



Share:

Sunday, September 1, 2013

Tuesday, August 13, 2013

Photos taken might pose security threat to you

How serious it is?


However, I found out that this can only affects the user IF:
1. You combine your photos with few other data such as Foursquare, Picasa, blogs, etc.
2. You did mention something that can be used to indicates your location or surrounding.
3. You used current photos capture capability (with sound and GPS setting)
4. And few others combination setting.
Share:

Monday, August 5, 2013

Thursday, August 1, 2013

Big Problem needs Simple Solutions :)

This shows how big problem can be solved by simple and small solutions.. (TRIZ)

https://www.youtube.com/watch?feature=player_embedded&v=nw9g9OVHdJI

Moral: Sometimes we don't need extravaganza solutions to solve our problem :)

Thanks to my TRIZ LinkedIn Group for the sharing.
Share:

About Me

Somewhere, Selangor, Malaysia
An IT by profession, a beginner in photography

Labels

Blog Archive

Blogger templates