Open Access. Powered by Scholars. Published by Universities.®

Digital Commons Network™

Open Access. Powered by Scholars. Published by Universities.®

Information Security

Institution
Keyword
Publication Year
Publication
Publication Type

Articles 1 - 30 of 69

Full-Text Articles in Entire DC Network

Deep Learning Approaches For Anti-Money Laundering On Mobile Transactions: Review, Framework, And Directions, Jiani Fan, Lwin Khin Shar, Ruichen Zhang, Ziyao Liu, Wenzhuo Yang, Dusit Niyato, Kwok-Yan Lam Mar 2026

Deep Learning Approaches For Anti-Money Laundering On Mobile Transactions: Review, Framework, And Directions, Jiani Fan, Lwin Khin Shar, Ruichen Zhang, Ziyao Liu, Wenzhuo Yang, Dusit Niyato, Kwok-Yan Lam

Research Collection School Of Computing and Information Systems

Money laundering is a financial crime that obscures the origin of illicit funds, necessitating the development and enforcement of anti-money laundering (AML) policies by governments and organizations. The proliferation of mobile payment platforms and smart IoT devices has significantly complicated AML investigations. As payment networks become more interconnected, there is an increasing need for efficient real-time detection to process large volumes of transaction data on heterogeneous payment systems by different operators such as digital currencies, cryptocurrencies, and account-based payments. Most of these mobile payment networks are supported by connected devices, many of which are considered loT devices in the FinTech …


Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker Mar 2026

Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker

Research outputs 2022 to 2026

As networks expand in size and complexity, coupled with an exponential increase in intrusions on network and IoT systems, this leads to traditional models failing to capture increasingly intricate correlations among network components accurately. Graph Convolution Networks (GCNs) have recently acquired prominence for their capacity to represent nodes, edges, or entire graphs by aggregating information from adjacent nodes. However, the correlations between nodes and their neighbours, as well as related edges, differ. Assigning higher weights to nodes and edges with high similarity improves model accuracy and expressiveness. In this paper, we propose the GCN-DQN model, which integrates GCN with a …


Tackling The Societal And Regulatory Challenges Of Emerging Technologies: A Case Study Of Deepfake, Jingyao Li Jan 2026

Tackling The Societal And Regulatory Challenges Of Emerging Technologies: A Case Study Of Deepfake, Jingyao Li

2026

Governing emerging technologies such as Artificial Intelligence (AI) poses enduring challenges for policymakers, industries, and societies. Early-stage governance is often hindered by limited understanding of technological implications, rapid innovation cycles, and resistance from powerful industry actors who favor minimal oversight. Yet, timely and effective governance is essential, as new technologies are most malleable in their formative stages. This dissertation examines how emerging technologies can be governed effectively by using deepfakes technology as a focal case. This dissertation comprises three interrelated studies.

The first paper reviews the literature on deepfakes and emerging technology governance, identifying the distinct characteristics of deepfake technology …


Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu Apr 2025

Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu

Cybersecurity Undergraduate Research Showcase

Financial fraud, particularly credit card fraud, continues to pose substantial challenges to financial institutions due to its increasing frequency and impact on consumer trust. While traditional rule-based methods have provided foundational defenses, their limitations in scalability and adaptability have accelerated the adoption of machine learning (ML) techniques. Concurrently, Benford’s Law—a statistical principle often used in forensic accounting—has demonstrated efficacy in detecting anomalies within naturally occurring numerical datasets. This study explores a hybrid fraud detection approach that integrates Benford’s Law with supervised machine learning algorithms, including Logistic Regression, Random Forest, and k-Nearest Neighbors. Using the publicly available European credit card fraud …


Cybercrime As A Threat To The Banking Sector: A Perspective From Commercial Banks In Bangladesh, Hasibul Hossain, Rezaul Karim Shohag, Nikhil Chandra Nath, Sushmita Das Dalia Apr 2025

Cybercrime As A Threat To The Banking Sector: A Perspective From Commercial Banks In Bangladesh, Hasibul Hossain, Rezaul Karim Shohag, Nikhil Chandra Nath, Sushmita Das Dalia

International Journal of Cybersecurity Intelligence & Cybercrime

Cyber and technology related crimes are gradually increasing all over the world due to rapid transitions and transactions in the digital world and cyberspace. Cyber related threats are increasingly becoming universal, multi-faceted, sophisticated and transnational in this tech-driven age. Governments, law enforcement agencies, IT professionals, scholars, and researchers worldwide have been concerned about digital deviance and crime. The transition to this widespread cybercrime is particularly difficult for developing countries. Recently, the banking sectors in Bangladesh have seen the emerging threats to its system and reserves through cyberspace, e. g. cyber-attacks or taking illegal access. Cybercrime is becoming a threat to …


Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition, Rachel Bleiman, Hwanhee Park, Aunshul Rege Feb 2025

Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition, Rachel Bleiman, Hwanhee Park, Aunshul Rege

Journal of Cybersecurity Education, Research and Practice

The online dating industry generated 2.98 billion USD in 2023 and is estimated to reach 3.6 billion USD by 2025. Not surprisingly, online dating platforms are rife with romance scams that cause financial damages, with estimated losses of 1.3 billion USD in 2022 alone. Additionally, victims suffer emotional and psychological harms. This paper shares findings from a 2023 Romance Scam and Social Engineering Competition (RSSEC) that introduced students to the behavioral and psychological aspects of romance scams. Specifically, the competition aimed to expose students to (i) understanding how victims experience social engineering (SE) - the psychological manipulation of human behavior, …


Scalable Approaches Towards Characterizing And Mitigating Emerging Phishing Scams, Sayak Saha Roy Jan 2025

Scalable Approaches Towards Characterizing And Mitigating Emerging Phishing Scams, Sayak Saha Roy

Computer Science and Engineering Dissertations - Archive

Phishing scams are among the most dangerous and persistent forms of cybercrime, leveraging social engineering to exploit human behavior and obtain sensitive information, leading to widespread identity theft and data breaches. In the past year, these attacks have resulted in financial losses exceeding $10 billion in the United States alone. As phishing scams continue to evolve, they have not only expanded in scale but also grown in sophistication, spreading rapidly across social media and employing adversarial techniques to evade detection by anti-scam tools. The situation is further exacerbated by the availability of advanced phishing kits, and more recently, generative AI, …


Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu Jan 2025

Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu

Journal of Cybersecurity Education, Research and Practice

The profound impact of the Internet of Things (IoT) on various fronts, is driven by technological advancements, the ubiquitous spread of information, and the emergence of transformative events. IoT presents a diverse array of possibilities within university environments, fostering a more connected and enhanced educational experience. This research undertakes a comprehensive review of existing literature to provide context to the IoT and underscore its crucial significance in the realm of smart campuses. Additionally, the paper explores the intricate connections between IoT and key concepts such as cybersecurity and wireless sensor networks to present a holistic perspective. It delves into the …


Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh Jan 2025

Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh

Computer Science Faculty Publications

Detecting malicious Internet domains is essential for safeguarding against various online threats. The current approach to detecting malicious domains (MDD) employs a graph neural network (GNN) method, which uses DNS logs to construct heterogeneous graphs for determining the maliciousness of unknown domains. Despite its success, this method is vulnerable to data poisoning attacks where an adversary can manipulate specific graph nodes to implant a backdoor into the model during training. To showcase the vulnerability, we propose a stealthy trigger injection attack on node features and graph structure in MDD, dubbed (STING). The attacker carefully manipulates selected features and edges of …


Data Profits Vs. Privacy Rights: Ethical Concerns In Data Commerce, Amiah Armstrong Apr 2024

Data Profits Vs. Privacy Rights: Ethical Concerns In Data Commerce, Amiah Armstrong

Cybersecurity Undergraduate Research Showcase

In today’s digital age, the collection and sale of customer data for advertising is gaining a growing number of ethical concerns. The act of amassing extensive datasets encompassing customer preferences, behaviors, and personal information raises questions of its true purpose. It is widely acknowledged that companies track and store their customer’s digital activities under the pretext of benefiting the customer, but at what cost? Are users aware of how much of their data is being collected? Do they understand the trade-off between personalized services and the potential invasion of their privacy? This paper aims to show the advantages and disadvantages …


Privacy Principles And Harms: Balancing Protection And Innovation, Samuel Aiello Feb 2024

Privacy Principles And Harms: Balancing Protection And Innovation, Samuel Aiello

Journal of Cybersecurity Education, Research and Practice

In today's digitally connected world, privacy has transformed from a fundamental human right into a multifaceted challenge. As technology enables the seamless exchange of information, the need to protect personal data has grown exponentially. Privacy has emerged as a critical concern in the digital age, as technological advancements continue to reshape how personal information is collected, stored, and utilized. This paper delves into the fundamental principles of privacy and explores the potential harm that can arise from the mishandling of personal data. It emphasizes the delicate balance between safeguarding individuals' privacy rights and fostering innovation in a data-driven society. By …


A Comprehensive And Comparative Examination Of Healthcare Data Breaches: Assessing Security, Privacy, And Performance, Mohammed Al Kinoon Jan 2024

A Comprehensive And Comparative Examination Of Healthcare Data Breaches: Assessing Security, Privacy, And Performance, Mohammed Al Kinoon

Graduate Thesis and Dissertation 2023-2024

The healthcare sector is pivotal, offering life-saving services and enhancing well-being and community life quality, especially with the transition from paper-based to digital electronic health records (EHR). While improving efficiency and patient safety, this digital shift has also made healthcare a prime target for cybercriminals. The sector's sensitive data, including personal identification information, treatment records, and SSNs, are valuable for illegal financial gains. The resultant data breaches, increased by interconnected systems, cyber threats, and insider vulnerabilities, present ongoing and complex challenges. In this dissertation, we tackle a multi-faceted examination of these challenges. We conducted a detailed analysis of healthcare data …


Data Science In Finance: Challenges And Opportunities, Xianrong Zheng, Elizabeth Gildea, Sheng Chai, Tongxiao Zhang, Shuxi Wang Jan 2024

Data Science In Finance: Challenges And Opportunities, Xianrong Zheng, Elizabeth Gildea, Sheng Chai, Tongxiao Zhang, Shuxi Wang

Information Technology & Decision Sciences Faculty Publications

Data science has become increasingly popular due to emerging technologies, including generative AI, big data, deep learning, etc. It can provide insights from data that are hard to determine from a human perspective. Data science in finance helps to provide more personal and safer experiences for customers and develop cutting-edge solutions for a company. This paper surveys the challenges and opportunities in applying data science to finance. It provides a state-of-the-art review of financial technologies, algorithmic trading, and fraud detection. Also, the paper identifies two research topics. One is how to use generative AI in algorithmic trading. The other is …


Program Analysis For Android Security And Reliability, Sydur Rahaman Aug 2023

Program Analysis For Android Security And Reliability, Sydur Rahaman

Dissertations

The recent, widespread growth and adoption of mobile devices have revolutionized the way users interact with technology. As mobile apps have become increasingly prevalent, concerns regarding their security and reliability have gained significant attention. The ever-expanding mobile app ecosystem presents unique challenges in ensuring the protection of user data and maintaining app robustness. This dissertation expands the field of program analysis with techniques and abstractions tailored explicitly to enhancing Android security and reliability. This research introduces approaches for addressing critical issues related to sensitive information leakage, device and user fingerprinting, mobile medical score calculators, as well as termination-induced data loss. …


Victimization By Deepfake In The Metaverse: Building A Practical Management Framework, Julia Stavola, Kyung-Shick Choi Aug 2023

Victimization By Deepfake In The Metaverse: Building A Practical Management Framework, Julia Stavola, Kyung-Shick Choi

International Journal of Cybersecurity Intelligence & Cybercrime

Deepfake is digitally altered media aimed to deceive online users for political favor, monetary gain, extortion, and more. Deepfakes are the prevalent issues of impersonation, privacy, and fake news that cause substantial damage to individuals, groups, and organizations. The metaverse is an emerging 3-dimensional virtual platform led by AI and blockchain technology where users freely interact with each other. The purpose of this study is to identify the use of illicit deep fakes which can potentially contribute to cybercrime victimization in the metaverse. The data will be derived from expert interviews (n=8) and online open sources to design a framework …


Reinventing Cybersecurity Internships During The Covid-19 Pandemic, Lori L. Sussman Jan 2023

Reinventing Cybersecurity Internships During The Covid-19 Pandemic, Lori L. Sussman

Journal of Cybersecurity Education, Research and Practice

The Cybersecurity Ambassador Program provides professional skills training for emerging cybersecurity professionals remotely. The goal is to reach out to underrepresented populations who may use Federal Work-Study (FWS) or grant sponsored internships to participate. Cybersecurity Ambassadors (CAs) develop skills that will serve them well as cybersecurity workers prepared to do research, lead multidisciplinary, technical teams, and educate stakeholders and community members. CAP also reinforces leadership skills so that the next generation of cybersecurity professionals becomes a sustainable source of management talent for the program and profession. The remote curriculum innovatively builds non-technical professional skills (communications, teamwork, leadership) for cybersecurity research …


A Longitudinal Study Of Factors That Affect User Interactions With Social Media And Email Spam, Wojciech M. Mazurek Jan 2023

A Longitudinal Study Of Factors That Affect User Interactions With Social Media And Email Spam, Wojciech M. Mazurek

Graduate Theses, Dissertations, and Problem Reports (ETD)

Given the rapid growth of social media and the increasing prevalence of spam, it is crucial to understand users’ interactions with unsolicited content to develop effective countermeasures against spam. This thesis focuses on exploring the factors that influence users’ decisions to interact with spam on social media and email. It builds upon prior work, which serves as a foundation for further research and conducting a longitudinal analysis. Our results are based on the analysis of 221 responses collected through an online survey. The survey not only gathered demographic information such as age, gender, and race but also collected data on …


Post Pandemic Cyberbiosecurity Threats From Terrorist Groups, Haley D. Dodge Dec 2022

Post Pandemic Cyberbiosecurity Threats From Terrorist Groups, Haley D. Dodge

Master's Theses

The research in this thesis explored the research question: Are United States (US) health systems accessible to cyber-bio terrorist attacks post-pandemic, within the context of the emerging discipline of cyberbiosecurity? Key findings of the analysis demonstrated how US health systems are more accessible to cyber-bio terrorist attacks specifically from cyber hacking groups based on the increasing sophistication of their cyber capabilities and the lack of cyber protection for biological systems. The concept of cyberbiosecurity was first introduced in 2018 by researchers exploring the converging threat landscape of the cyber and biology domains. As biology is growing more dependent upon vulnerable …


Dynamics Of Dark Web Financial Marketplaces: An Exploratory Study Of Underground Fraud And Scam Business, Bo Ra Jung, Kyung-Shick Choi, Claire Seungeun Lee Aug 2022

Dynamics Of Dark Web Financial Marketplaces: An Exploratory Study Of Underground Fraud And Scam Business, Bo Ra Jung, Kyung-Shick Choi, Claire Seungeun Lee

International Journal of Cybersecurity Intelligence & Cybercrime

The number of Dark Web financial marketplaces where Dark Web users and sellers actively trade illegal goods and services anonymously has been growing exponentially in recent years. The Dark Web has expanded illegal activities via selling various illicit products, from hacked credit cards to stolen crypto accounts. This study aims to delineate the characteristics of the Dark Web financial market and its scams. Data were derived from leading Dark Web financial websites, including Hidden Wiki, Onion List, and Dark Web Wiki, using Dark Web search engines. The study combines statistical analysis with thematic analysis of Dark Web content. Offering promotions …


Camouflaged Poisoning Attack On Graph Neural Networks, Chao Jiang, Yi He, Richard Chapman, Hongyi Wu Jan 2022

Camouflaged Poisoning Attack On Graph Neural Networks, Chao Jiang, Yi He, Richard Chapman, Hongyi Wu

Computer Science Faculty Publications

Graph neural networks (GNNs) have enabled the automation of many web applications that entail node classification on graphs, such as scam detection in social media and event prediction in service networks. Nevertheless, recent studies revealed that the GNNs are vulnerable to adversarial attacks, where feeding GNNs with poisoned data at training time can lead them to yield catastrophically devastative test accuracy. This finding heats up the frontier of attacks and defenses against GNNs. However, the prior studies mainly posit that the adversaries can enjoy free access to manipulate the original graph, while obtaining such access could be too costly in …


Don't Bite The Bait: Phishing Attack For Internet Banking (E-Banking), Ilker Kara Nov 2021

Don't Bite The Bait: Phishing Attack For Internet Banking (E-Banking), Ilker Kara

Journal of Digital Forensics, Security and Law

Phishing attacks are based on obtaining desired information from users quickly and easily with the help of misdirecting, panicking, curiosity, or excitement. Most of the phishing web sites are designed on internet banking(e-banking) and the attackers can acquire financial information of misled users with the tactics and discourses they develop. Despite the increase of prevention techniques against phishing attacks day by day, an effective solution could not be found for this issue due to the human factor. Because of this reason, real phishing attack studies are essential to study and analyze the attackers’ attack techniques and strategies. This study focused …


Book Review: Computer Capers: Tales Of Electronic Thievery, Embezzlement, And Fraud. By Thomas Whiteside, Brian Nussbaum Nov 2020

Book Review: Computer Capers: Tales Of Electronic Thievery, Embezzlement, And Fraud. By Thomas Whiteside, Brian Nussbaum

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


A Survey Of Serious Games For Cybersecurity Education And Training, Winston Anthony Hill Jr., Mesafint Fanuel, Xiaohong Yuan, Jinghua Zhang, Sajad Sajad Oct 2020

A Survey Of Serious Games For Cybersecurity Education And Training, Winston Anthony Hill Jr., Mesafint Fanuel, Xiaohong Yuan, Jinghua Zhang, Sajad Sajad

KSU Proceedings on Cybersecurity Education, Research and Practice

Serious games can challenge users in competitive and entertaining ways. Educators have used serious games to increase student engagement in cybersecurity education. Serious games have been developed to teach students various cybersecurity topics such as safe online behavior, threats and attacks, malware, and more. They have been used in cybersecurity training and education at different levels. Serious games have targeted different audiences such as K-12 students, undergraduate and graduate students in academic institutions, and professionals in the cybersecurity workforce. In this paper, we provide a survey of serious games used in cybersecurity education and training. We categorize these games into …


Teaching About The Dark Web In Criminal Justice Or Related Programs At The Community College And University Levels., Scott H. Belshaw, Brooke Nodeland, Lorrin Underwood, Alexandrea Colaiuta Jan 2020

Teaching About The Dark Web In Criminal Justice Or Related Programs At The Community College And University Levels., Scott H. Belshaw, Brooke Nodeland, Lorrin Underwood, Alexandrea Colaiuta

Journal of Cybersecurity Education, Research and Practice

Increasingly, criminal justice practitioners have been called on to help solve breaches in cyber security. However, while the demand for criminal justice participation in cyber investigations increases daily, most universities are lagging in their educational and training opportunities for students entering the criminal justice fields. This article discusses the need to incorporate courses discussing the Dark Web in criminal justice. A review of existing cyber-criminal justice programs in Texas and nationally suggests that most community colleges and 4-year universities have yet to develop courses/programs in understanding and investigating the Dark Web on the internet. The Dark Web serves as the …


Df 2.0: An Automated, Privacy Preserving, And Efficient Digital Forensic Framework That Leverages Machine Learning For Evidence Prediction And Privacy Evaluation, Robin Verma, Jayaprakash Govindaraj Dr, Saheb Chhabra, Gaurav Gupta Jun 2019

Df 2.0: An Automated, Privacy Preserving, And Efficient Digital Forensic Framework That Leverages Machine Learning For Evidence Prediction And Privacy Evaluation, Robin Verma, Jayaprakash Govindaraj Dr, Saheb Chhabra, Gaurav Gupta

Journal of Digital Forensics, Security and Law

The current state of digital forensic investigation is continuously challenged by the rapid technological changes, the increase in the use of digital devices (both the heterogeneity and the count), and the sheer volume of data that these devices could contain. Although data privacy protection is not a performance measure, however, preventing privacy violations during the digital forensic investigation, is also a big challenge. With a perception that the completeness of investigation and the data privacy preservation are incompatible with each other, the researchers have provided solutions to address the above-stated challenges that either focus on the effectiveness of the investigation …


Multimodal Approach For Malware Detection, Jarilyn M. Hernandez Jimenez Jan 2019

Multimodal Approach For Malware Detection, Jarilyn M. Hernandez Jimenez

Graduate Theses, Dissertations, and Problem Reports (ETD)

Although malware detection is a very active area of research, few works were focused on using physical properties (e.g., power consumption) and multimodal features for malware detection. We designed an experimental testbed that allowed us to run samples of malware and non-malicious software applications and to collect power consumption, network traffic, and system logs data, and subsequently to extract dynamic behavioral-based features. We also extracted code-based static features of both malware and non-malicious software applications. These features were used for malware detection based on: feature level fusion using power consumption and network traffic data, feature level fusion using network traffic …


Managing Cyber Risks & Business Exposure In The Surface Transportation Ecosystem, Jacques R. Francoeur Jan 2019

Managing Cyber Risks & Business Exposure In The Surface Transportation Ecosystem, Jacques R. Francoeur

Mineta Transportation Institute

This report focuses on Surface Transportation (ST), both fixed and route-based, and the growing threats to their information technology (IT) infrastructures. As an industry, ST seeks to optimize the movement of people and goods, while ensuring safety and resiliency and minimizing environmental impact. Cyber threats are a powerful medium for those with the political, social, and economic motivations and wherewithal to disrupt and destroy existing ST systems. The ultimate objective is to develop a new paradigm to define, describe, design, and deploy the most effective protection, at the lowest cost, in the shortest time within the limits of available resources. …


Towards A Development Of Predictive Models For Healthcare Hipaa Security Rule Violation Fines, Jim Furstenberg, Yair Levy Oct 2018

Towards A Development Of Predictive Models For Healthcare Hipaa Security Rule Violation Fines, Jim Furstenberg, Yair Levy

KSU Proceedings on Cybersecurity Education, Research and Practice

The Health Insurance Portability and Accountability Act’s (HIPAA) Security Rule (SR) mandate provides a national standard for the protection of electronic protected health information (ePHI). The SR’s standards provide healthcare covered entities (CEs’) flexibility in how to meet the standards because the SR regulators realized that all health care organizations are not the same. However, the SR requires CEs’ to implement reasonable and appropriate safeguards, as well as security controls that protect the confidentiality, integrity, and availability (CIA) of their ePHI data. However, compliance with the HIPAA SR mandates are confusing, complicated, and can be costly to CEs’. Flexibility in …


Df 2.0: Designing An Automated, Privacy Preserving, And Efficient Digital Forensic Framework, Robin Verma, Jayaprakash Govindaraj, Gaurav Gupta May 2018

Df 2.0: Designing An Automated, Privacy Preserving, And Efficient Digital Forensic Framework, Robin Verma, Jayaprakash Govindaraj, Gaurav Gupta

Annual ADFSL Conference on Digital Forensics, Security and Law

The current state of digital forensic investigation is continuously challenged by the rapid technological changes, the increase in the use of digital devices (both the heterogeneity and the count), and the sheer volume of data that these devices could contain. Although it is not directly related to the performance of Digital Forensic Investigation process, preventing data privacy violations during the process is also a big challenge. The investigator gets full access to the forensic image including suspect's private data which may be sensitive at times as well as entirely unrelated to the given case under investigation. With a notion that …


Deceptive Security Based On Authentication Profiling, Andrew Nicholson, Helge Janicke, Andrew Jones, Adeeb Alnajaar Jan 2017

Deceptive Security Based On Authentication Profiling, Andrew Nicholson, Helge Janicke, Andrew Jones, Adeeb Alnajaar

Australian Information Security Management Conference

Passwords are broken. Multi-factor Authentication overcomes password insecurities, but its potentials are often not realised. This article presents InSight, a system to actively identify perpetrators by deceitful adaptation of the accessible system resources using Multi-factor Authentication profiles. This approach improves authentication reliability and attributes users by computing trust scores against profiles. Based on this score, certain functionality is locked, unlocked, buffered, or redirected to a deceptive honeypot, which is used for attribution. The novelty of this approach is twofold; a profile-based multi-factor authentication approach that is combined with a gradient, deceptive honeypot.