24th IFIP TC 11 International Information Security Conference, SEC 2009 Pafos, Cyprus, May 18–20, 2009 Proceedings SEC 2009 was organized by the Technical Committee 11 (TC-11) of IFIP, and took place in Pafos, Cyprus, during May 18–20, 2009. It is an indication of good fortune for a Chair to serve a conference that takes place in a country with the natural beauty of Cyprus, an island where the hospitality and friend- liness of the people have been going together, hand-in-hand, with its long history. This volume contains the papers selected for presentation at SEC 2009. In response to the call for papers, 176 papers were submitted to the conference. All of them were evaluated on the basis of their novelty and technical quality, and reviewed by at least two members of the conference Program Committee. Of the papers submitted, 39 were selected for presentation at the conference; the acceptance rate was as low as 22%, thus making the conference a highly competitive forum. It is the commitment of several people that makes international conferences possi- ble. That also holds true for SEC 2009. The list of people who volunteered their time and energy to help is really long. We would like to express our sincere appreciation to the members of the Program Committee, to the external reviewers, and to the authors who trusted their work in our hands. Many thanks go, also, to all conference attendees. We thank our distinguished keynote speakers, namely, Bart Preneel (Katholieke Univer- siteit Leuven) and Christos Ellinides (European Commission/DIGIT) for accepting our invitation and for honoring the conference with their presence and their inspired talks. Last, but by no means least, we thank the local organizers and hosts, first among them being Philippos Peleties and Panikos Masouras, who took care of every detail, so that SEC 2009 would be a successful and memorable event. Finally, let us express a short personal note. We would like to thank all TC-11 mem- bers for giving us the opportunity to serve the SEC 2009 in a PC Chair’s capacity. It was the first time such an opportunity was given to Javier Lopez, the national representative of Spain. It was the third time (SEC 1996/Samos, SEC 2003/Athens, SEC 2009/Pafos) this opportunity was given to Dimitris Gritzalis, the national repre- sentative of Greece, who has, thus, already become a kind of …dinosaur in the long history of the SEC conferences. Sevasti Karatzouni, and Steven Furnell Combining Authentication, Reputation and Classification to Make Phishing Unprofitable ............................................ 13 Amir Herzberg Audio CAPTCHA for SIP-Based VoIP ............................. 25 Yannis Soupionis, George Tountas, and Dimitris Gritzalis Threats and Attacks Roving Bugnet: Distributed Surveillance Threat and Mitigation........ 39 Ryan Farley and Xinyuan Wang On Robust Covert Channels Inside DNS ............................ 51 Lucas Nussbaum, Pierre Neyron, and Olivier Richard Discovering Application-Level Insider Attacks Using Symbolic Execution....................................................... 63 Karthik Pattabiraman, Nithin Nakka, Zbigniew Kalbarczyk, and Ravishankar Iyer Identification and Authentication II Custom JPEG Quantization for Improved Iris Recognition Accuracy ... 76 Gerald Stefan Kostmajer, Herbert Sto¨gner, and Andreas Uhl On the IPP Properties of Reed-Solomon Codes ...................... 87 Marcel Fernandez, Josep Cotrina, Miguel Soriano, and Neus Domingo A Generic Authentication LoA Derivation Model..................... 98 Li Yao and Ning Zhang Applications of Cryptography and Information Hiding Media-Break Resistant eSignatures in eGovernment: An Austrian Experience ...................................................... 109 Herbert Leitold, Reinhard Posch, and Thomas R¨ossler XII Table of Contents How to Bootstrap Security for Ad-Hoc Network: Revisited ............ 119 Wook Shin, Carl A. Gunter, Shinsaku Kiyomoto, Kazuhide Fukushima, and Toshiaki Tanaka Steganalysis of Hydan ............................................ 132 Jorge Blasco, Julio C. Hernandez-Castro, Juan M.E. Tapiador, Arturo Ribagorda, and Miguel A. Orellana-Quiros Trusted Computing On the Impossibility of Detecting Virtual Machine Monitors........... 143 Shay Gueron and Jean-Pierre Seifert Implementation of a Trusted Ticket System ......................... 152 Andreas Leicher, Nicolai Kuntze, and Andreas U. Schmidt Security Policies A Policy Based Approach for the Management of Web Browser Resources to Prevent Anonymity Attacks in Tor ..................... 164 Guillermo Navarro-Arribas and Joaquin Garcia-Alfaro A Policy Language for Modelling Recommendations .................. 176 Anas Abou El Kalam and Philippe Balbiani Validation, Verification, Evaluation On the Security Validation of Integrated Security Solutions............ 190 Andreas Fuchs, Sigrid Gu¨rgens, and Carsten Rudolph Verification of Security Policy Enforcement in Enterprise Systems ...... 202 Puneet Gupta and Scott D. Stoller Optimization of the Controlled Evaluation of Closed Relational Queries ......................................................... 214 Joachim Biskup, Jan-Hendrik Lochner, and Sebastian Sonntag Privacy Protection - Security Assessment Collaborative Privacy – A Community-Based Privacy Infrastructure.... 226 Jan Kolter, Thomas Kernchen, and Gu¨nther Pernul Security and Privacy Improvements for the Belgian eID Technology .... 237 Pieter Verhaeghe, Jorn Lapon, Bart De Decker, Vincent Naessens, and Kristof Verslype