• AccountabilityFS: A File System Monitor for Forensic Readiness 

      Nordvik, Rune; Liao, Yi-Ching; Langweg, Hanno (Chapter, 2014)
      We present a file system monitor, AccountabilityFS, which prepares an organization for forensic analysis and incident investigation in advance by ensuring file system operation traces readily available. We demonstrate the ...
    • Cyberwindow 

      Spataru, David; Nes, Peter Behncke; Lindskog, Herman; Wallden, Gustav Isaksen (Bachelor thesis, 2022)
      Denne oppgaven omhandler utviklingen av en webapplikasjon med formål om å hente informasjon fra de forskjellige fagapplikasjonene til NTNU SOC sine APIer, for å så fremstille de grafisk på en oversiktlig måte. Oppgaven kom ...
    • Difficult SQLi Code Patterns for Static Code Analysis Tools 

      Schuckert, Felix; Katt, Basel; Langweg, Hanno (Peer reviewed; Journal article, 2020)
      We compared vulnerable and xed versions of the source code of 50 dierent PHP open source projects based on CVE reports for SQL injection vulnerabilities. We scanned the source code with commercial and open source tools for ...
    • Evidential Reasoning for Forensic Readiness 

      Liao, Yi-Ching; Langweg, Hanno (Peer reviewed; Journal article, 2016)
      To learn from the past, we analyse 1,088 "computer as a target" judgements for evidential reasoning by extracting four case elements: decision, intent, fact, and evidence. Analysing the decision element is essential for ...
    • One click privacy for online social networks 

      Hehnle, Philipp; Keilbach, Pascal; Lee, Hyun-Jin; Lejn, Sabrina; Steidinger, Daniel; Weinbrenner, Marina; Langweg, Hanno (Journal article; Peer reviewed, 2017)
      We present an approach to reduce the complexity of adjusting privacy preferences for multiple online social networks. To achieve this, we quantify the effect on privacy for choices that users make, and simplify configuration ...
    • Opportunities of Insecurity Refactoring for Training and Software Development 

      Schuckert, Felix (Doctoral theses at NTNU;2024:106, Doctoral thesis, 2024)
      Teaching software security is complex and should involve practical exercises. Practical exercises require software artifacts and projects that contain vulnerabilities. The vulnerabilities can be exploited to understand ...
    • Process Tracking for Forensic Readiness 

      Liao, Yi-Ching (Doctoral theses at NTNU;2016:339, Doctoral thesis, 2016)
      This thesis contributes to the tangible methods to prepare an enterprise for upcoming digital investigation with complete, pertinent, reliable, and privacy preserving evidence. Regarding an information security incident ...
    • Source Code Patterns of Buffer Overflow Vulnerabilities in Firefox 

      Schuckert, Felix; Hildner, Max; Katt, Basel; Langweg, Hanno (Chapter, 2018)
      We investigated 50 randomly selected buffer overflow vulnerabilities in Firefox. The source code of these vulnerabilities and the corresponding patches were manually reviewed and patterns were identified. Our main contribution ...
    • Source Code Patterns of Cross Site Scripting in PHP Open Source Projects 

      Schuckert, Felix; Hildner, Max; Katt, Basel; Langweg, Hanno (Journal article; Peer reviewed, 2018)
      To get a better understanding of Cross Site Scripting vulnerabilities, we investigated 50 randomly selected CVE reports which are related to open source projects. The vulnerable and patched source code was manually reviewed ...