RIT professor recommends tougher computer security measures to beat hackers

December 3rd, 2008

Hackers beware. A Rochester Institute of Technology professor knows how to thwart sophisticated and determined intruders from stealing personal and corporate information. His secret? Anchor your online activities to the physical world.

RIT scientist and entrepreneur Roger Dube takes a close look at user authentication and computer security in his recently published book "Hardware-Based Computer Security Techniques to Defeat Hackers: From Biometrics to Quantum Cryptography" (Wiley).

Intended for information technology professionals and others responsible for implementing computer security, "Hardware-Based Computer Security Techniques to Defeat Hackers" is a complete review of different types of hardware technology that can protect computer systems.

"There are steps you can take to protect your computer so you can be certain an application you bring up is authentic and hasn't been replaced with something, for instance, that contains a Trojan horse—a virus that masquerades as a normal program," says Dube, research professor in RIT's Chester F. Carlson Center for Imaging Science, and president and chief scientist of Digital Authentication Technologies Inc.

"The protection that is available today is largely based on algorithms and secrets," Dube adds. "And the problem with secrets is that they have to be shared before they can be used. Poorly constructed secrets can be guessed, making systems vulnerable to attack. And poorly protected secrets can be stolen outright."

A recent example of this weakness made the news when a hacker gained access to Gov. Sarah Palin's Yahoo! account, weeks before the election, by pretending to be the Republican vice presidential candidate. The hacker used Palin's personal information reported in the news to answer the security question protecting her e-mail account.

Software approaches to computer security provide limited protection, Dube says. The problem is that encrypted keystrokes hiding the password/secret are transmitted over the Internet, and these passwords can be intercepted and broken.

Pseudo random number generators, algorithms that are often used to create passwords or disguise a password as a jumble of symbols and numbers, are inherently predictable and can be cracked. The commonly used two-factor form of authentication— username plus password, PIN number or pass phrase—is fragile. Today, more robust security systems require users to present their name and password, and something unique to themselves. The nation protects its top secrets with software and hardware security technologies considered to be astronomically difficult to break, Dube notes.

"You cannot use an algorithm to generate a true random number," Dube says. "It's going to be predictable because it's a calculation. It will create a number that looks random, but if a hacker commandeers the 'seed' condition, they've broken the code completely."

According to Dube, only hardware-based security applications can provide the strongest security systems possible—pattern-free and unpredictable. These methods connect a system or a person to the physical world, ensuring confidentiality and authenticity of communication in ways software applications cannot.

"We needed to tie our security system to something that has its roots in the physical world, rather than to make it purely algorithmic. The advantage is that you can find all kinds of random sources in the physical world that are completely pattern free, but the disadvantage is that they typically involved a piece of hardware. Until recently people have been reluctant to add another piece of hardware or to carry something around. But when the loss becomes too much, hardware-based protection becomes the answer."

In his book, Dube details security systems that generate "passwords" from the physical world such as advanced biometrics (fingerprint scanning and iris and retinal scans) and tokens, such as smart cards embedded with a secure electronic chip. He also discusses location technologies that determine if remote servers are legitimate or carefully constructed fakes commonly used in phishing attacks, as well as geolocation technologies, such as global positioning system technology. The book also discusses the potential vulnerabilities of each of these technologies.

Dube's own computer-security research focuses on location technologies and satellite timing signals. Contractors for the U.S. Department of Defense tested the security system Dube developed for Digital Authentication Technologies Inc. and found it robust.

"The technology gives us location awareness, but doesn't tell us where on the surface of the Earth we are," Dube says. "It's double safe in that way."

Source: Rochester Institute of Technology


print this article email this article download pdf blog this article bookmark this article     Digg this Stumble it share on Facebook share on Reddit add to delicious save to Yahoo! bookmarks
4/5 after 5 votes


December 3rd, 2008 all stories
Technology / Hi Tech

Comments: 0
Rank: 4/5 after 5 votes

  • Stumble this up

  • Digg this

  • Share it:
  • share on Facebook
  • share on MySpace
  • share on Slashdot
  • rss-newsfeed
  • share on Google
  • share on Reddit
  • add to delicious
  • save to Yahoo! bookmarks
  • share on Windows Live
  • Add to Mixx!
Rating: 4/5 after 5 votes

  • Related Stories

  • US government Internet traffic to be screened: report (Update)
    created Jul 03, 2009 | popularity not rated yet | comments 0
  • US wants privacy in new cyber security system
    created Jul 03, 2009 | popularity not rated yet | comments 0
  • All in sight: Scientists test infrared system for the protection of whales
    created Jul 02, 2009 | popularity not rated yet | comments 0
  • PC makers voluntarily supply Web filter in China
    created Jul 02, 2009 | popularity not rated yet | comments 0
  • China Web controversy highlights public role
    created Jul 01, 2009 | popularity not rated yet | comments 0


  • Physicists Demonstrate Quantum Memory with Matter Qubits
    Physicists Demonstrate Quantum Memory with Matter Qubits
    Physics / General Physics
    created Jul 03, 2009 | popularity 4.4 / 5 (17) | comments 1
  • 'Holey' Nanosheets for Wastewater Dye Removal
    Nanotechnology / Nanomaterials
    created Jul 01, 2009 | popularity 5 / 5 (5) | comments 1
  • Jellyfish Robot Swims Like its Biological Counterpart
    Jellyfish Robot Swims Like its Biological Counterpart
    Electronics / Robotics
    created Jun 26, 2009 | popularity 4.4 / 5 (8) | comments 1
  • Could Maxwell's Demon Exist in Nanoscale Systems?
    Could Maxwell's Demon Exist in Nanoscale Systems?
    Physics / General Physics
    created Jun 24, 2009 | popularity 4.4 / 5 (18) | comments 29
  • Living Safely with Robots, Beyond Asimov's Laws
    Living Safely with Robots, Beyond Asimov's Laws
    Electronics / Robotics
    created Jun 22, 2009 | popularity 4.6 / 5 (52) | comments 40
  • Other News

    Japan demands 119 million dlrs in tax from Amazon: report

    Technology / Business

    created 16 hours ago | popularity 3.6 / 5 (5) | comments 1

    Japanese authorities told a sales affiliate of US retail giant Amazon.com to pay about 119 million dollars in tax for unreported income over a three-year period, a newspaper said Sunday.


    Iconic skyscrapers find new luster by going green (AP)

    Iconic skyscrapers find new luster by going green

    Technology / Energy

    created 17 hours ago | popularity 1 / 5 (1) | comments 0

    (AP) -- When owners of the Empire State Building decided to blanket its towering facade this year with thousands of insulating windows, they were only partly interested in saving energy. They also needed ...


    Geeks double as scourges and sages at media summit

    Technology / Business

    created 12 hours ago | popularity not rated yet | comments 0

    (AP) -- The media moguls attending an annual powwow staged by investment bank Allen & Co. used to be able to rest comfortably in the Idaho mountains as they mulled their next moves.


    Downturn dating: Hearts flutter as markets stutter (AP)

    Downturn dating: Hearts flutter as markets stutter

    Technology / Internet

    created 17 hours ago | popularity not rated yet | comments 0

    (AP) -- Credit the recession for "staycations" and bringing us more game-night parties at home. But also give it a shout for spurring more first dates.


    UK spy chief's family details posted on Facebook

    Technology / Internet

    created 17 hours ago | popularity not rated yet | comments 0

    (AP) -- He's the spy who came in from the beach.