Open Access. Powered by Scholars. Published by Universities.®

Business Commons™

Open Access. Powered by Scholars. Published by Universities.®

Kennesaw State University

Discipline
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 1141 - 1170 of 1815

Full-Text Articles in Business

Individuals' Concern About Information Privacy In Ar Mobile Games, Dapeng Liu Oct 2016

Individuals' Concern About Information Privacy In Ar Mobile Games, Dapeng Liu

KSU Proceedings on Cybersecurity Education, Research and Practice

Augmented Reality (AR) proves to be an attractive technology in mobile games. While AR techniques energize mobile games, the privacy issue is raised to be discussed. Employing social media analytics (SMA) techniques, this research makes efforts to examines Twitter postings of “PokemonGo” case and explores individuals’ attitudes toward privacy in AR games. In this research, we examine what are the privacy concerns of individuals in AR games and what are the individuals’ sentiments toward privacy. In the interesting case of PokemonGo, this paper suggests that individuals’ concerns about privacy are emphasized on six dimensions - collection, improper access, unauthorized secondary …


Semi-Supervised Deep Neural Network For Network Intrusion Detection, Mutahir Nadeem, Ochaun Marshall, Sarbjit Singh, Xing Fang, Xiaohong Yuan Oct 2016

Semi-Supervised Deep Neural Network For Network Intrusion Detection, Mutahir Nadeem, Ochaun Marshall, Sarbjit Singh, Xing Fang, Xiaohong Yuan

KSU Proceedings on Cybersecurity Education, Research and Practice

Network security is of vital importance for corporations and institutions. In order to protect valuable computer systems, network data needs to be analyzed so that possible network intrusions can be detected. Supervised machine learning methods achieve high accuracy at classifying network data as normal or malicious, but they require the availability of fully labeled data. The recently developed ladder network, which combines neural networks with unsupervised learning, shows promise in achieving a high accuracy while only requiring a small number of labeled examples. We applied the ladder network to classifying network data using the Third International Knowledge Discovery and Data …


Planning And Implementing A Successful Nsa-Nsf Gencyber Summer Cyber Academy, Bryson R. Payne, Tamirat Abegaz, Keith Antonia Oct 2016

Planning And Implementing A Successful Nsa-Nsf Gencyber Summer Cyber Academy, Bryson R. Payne, Tamirat Abegaz, Keith Antonia

KSU Proceedings on Cybersecurity Education, Research and Practice

The GenCyber program is jointly sponsored by the National Security Agency (NSA) and the National Science Foundation (NSF) to help faculty and cybersecurity experts provide summer cybersecurity camp experiences for K-12 students and teachers. The main objective of the program is to attract, educate, and motivate a new generation of young men and women to help address the nationwide shortage of trained cybersecurity professionals. The curriculum is flexible and centers on ten cybersecurity first principles. Currently, GenCyber provides cyber camp options for three types of audiences: students, teachers, and a combination of both teachers and students. In 2016, over 120 …


User Privacy Suffers At The Hands Of Access Controls, Chad N. Hoye Oct 2016

User Privacy Suffers At The Hands Of Access Controls, Chad N. Hoye

KSU Proceedings on Cybersecurity Education, Research and Practice

With advancements in personal hand held devices, smaller more mobile computers, tablets, and the world’s population connected with social media the threat to the user’s privacy has been diminished. I will look at how access control policies have opened the proverbial door to user’s privacy being attacked and threatened. You will see examples of how users have to divulge personal information to get better service and even be monitored while at work to prevent intrusions in to the company.


Brain Betrayal: A Neuropsychological Categorization Of Insider Attacks, Rachel L. Whitman Oct 2016

Brain Betrayal: A Neuropsychological Categorization Of Insider Attacks, Rachel L. Whitman

KSU Proceedings on Cybersecurity Education, Research and Practice

Thanks to an abundance of highly publicized data breaches, Information Security (InfoSec) is taking a larger place in organizational priorities. Despite the increased attention, the threat posed to employers by their own employees remains a frightening prospect studied mostly in a technical light. This paper presents a categorization of insider deviant behavior and misbehavior based off of the neuropsychological foundations of three main types of insiders posing a threat to an organization: accidental attackers; neurologically “hot” malcontents, and neurologically “cold” opportunists.


Training Decrement In Security Awareness Training, Tianjian Zhang Oct 2016

Training Decrement In Security Awareness Training, Tianjian Zhang

KSU Proceedings on Cybersecurity Education, Research and Practice

This study determines if there is a decremental effect following IT security awareness training. In most security policy compliance literature, the main focus has been on policy design. Studies that address security awareness training are seldom theory driven and even fewer are empirically based. To fill this gap, we draw from the theory of vigilance decrement as well as forgetting curves in psychology, and propose a classroom experiment showing that participants' IT security awareness decreases over a 45-day period since the training at day one. The result adds to the security policy compliance literature and suggests that some policy violations …


Investigating The Influence Of Perceived Uncertainty On Protection Motivation: An Experimental Study, Ali Vedadi Oct 2016

Investigating The Influence Of Perceived Uncertainty On Protection Motivation: An Experimental Study, Ali Vedadi

KSU Proceedings on Cybersecurity Education, Research and Practice

IS users and organizations must take necessary measures to adequately cope with security threats. Considering the importance and prevalence of these issues and challenges, IS security research has extensively investigated a variety of factors that influence IS users’ security intentions/behaviors. In this regard, protection-motivated behaviors are primarily based on individuals’ personal cognitive evaluations and vigilance. In reality, however, many users reach security hygiene decisions through various non-rational and non-protection-motivated processes. Such users may not necessarily rely on their own cognitive appraisals and information processing, but proceed to make decisions without careful cognitive assessments of security threats and coping responses. One …


Towards A Development Of A Mobile Application Security Invasiveness Index, Sam Espana Oct 2016

Towards A Development Of A Mobile Application Security Invasiveness Index, Sam Espana

KSU Proceedings on Cybersecurity Education, Research and Practice

The economic impact of Mobile IP, the standard that allows IP sessions to be maintained even when switching between different cellular towers or networks, has been staggering in terms of both scale and acceleration (Doherty, 2016). As voice communications transition to all-digital, all-IP networks such as 4G, there will be an increase in risk due to vulnerabilities, malware, and hacks that exist for PC-based systems and applications (Harwood, 2011). According to Gostev (2006), in June, 2004, a well-known Spanish virus collector known as VirusBuster, emailed the first known mobile phone virus to Kaspersky Lab, Moscow. Targeting the Symbian OS, the …


Teaching Security Of Internet Of Things In Using Raspberrypi, Oliver Nichols, Li Yang, Xiaohong Yuan Oct 2016

Teaching Security Of Internet Of Things In Using Raspberrypi, Oliver Nichols, Li Yang, Xiaohong Yuan

KSU Proceedings on Cybersecurity Education, Research and Practice

The Internet of Things (IoTs) is becoming a reality in today’s society. The IoTs can find its application in multiple domains including healthcare, critical infrastructure, transportation, and home and personal use. It is important to teach students importance and techniques that are essential in protecting IoTs. We design a series of hands-on labs in a smart home setting, which can exercise attack and protection of IoTs. Our hands-on labs use a Raspberry Pi and several diverse smart things that communicate through Z-Wave technology. Using this environment, students can operate a home automation system and learn security concepts by performing these …


Is Security Research Development: Implications For Future Researchers, Kane Smith, Chris Merritt Oct 2016

Is Security Research Development: Implications For Future Researchers, Kane Smith, Chris Merritt

KSU Proceedings on Cybersecurity Education, Research and Practice

Security within the context of Information Systems has long been a concern for both academics and practitioners. For this reason an extensive body of research has been built around the need for protecting vital technical systems and the information contained within them. This stream of research, termed Information Systems Security (ISS), has evolved with technology over the last several decades in numerous different ways. This evolution can create a great deal of difficulty for researchers to identify under-represented areas of ISS research as well as ensure all relevant areas of concern are addressed. The purpose of this paper is threefold: …


Pedagogical Resources For Industrial Control Systems Security: Design, Implementation, Conveyance, And Evaluation, Guillermo A. Francia Iii, Greg Randall Oct 2016

Pedagogical Resources For Industrial Control Systems Security: Design, Implementation, Conveyance, And Evaluation, Guillermo A. Francia Iii, Greg Randall

KSU Proceedings on Cybersecurity Education, Research and Practice

Industrial Control Systems (ICS), which are pervasive in our nation’s critical infrastructures, are becoming increasingly at risk and vulnerable to internal and external threats. It is imperative that the future workforce be educated and trained on the security of such systems. However, it is equally important that careful and deliberate considerations must be exercised in designing and implementing the educational and training activities that pertain to ICS. To that end, we designed and implemented pedagogical materials and tools to facilitate the teaching and learning processes in the area of ICS security. In this paper, we describe those resources, the professional …


Towards An In-Depth Understanding Of Deep Packet Inspection Using A Suite Of Industrial Control Systems Protocol Packets, Guillermo A. Francia Iii Oct 2016

Towards An In-Depth Understanding Of Deep Packet Inspection Using A Suite Of Industrial Control Systems Protocol Packets, Guillermo A. Francia Iii

KSU Proceedings on Cybersecurity Education, Research and Practice

Industrial control systems (ICS) are increasingly at risk and vulnerable to internal and external threats. These systems are integral part of our nation’s critical infrastructures. Consequently, a successful cyberattack on one of these could present disastrous consequences to human life and property as well. It is imperative that cybersecurity professionals gain a good understanding of these systems particularly in the area of communication protocols. Traditional Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) are made to encapsulate some of these ICS protocols which may enable malicious payload to get through the network firewall and thus, gain entry into the …


Investigating Cyberbullying In Social Media: The Case Of Twitter, Xin Tian Oct 2016

Investigating Cyberbullying In Social Media: The Case Of Twitter, Xin Tian

KSU Proceedings on Cybersecurity Education, Research and Practice

Social media has profoundly changed how we interact with one another and the world around us. Recent research indicates that more and more people are using social media sites such as Facebook and Twitter for a significant portion of their day for various reasons such as making new friends, socializing with old friends, receiving information, and entertaining themselves. However, social media has also caused some problems. One of the problems is called social media cyberbullying which has developed over time as new social media technologies have developed over time. Social media cyberbullying has received increasing attention in recent years as …


Towards A Model Of Senior Citizens’ Motivation To Pursue Cybersecurity Awareness Training: Lecture-Based Vs. Video-Cases Training, Carlene G. Blackwood-Brown Oct 2016

Towards A Model Of Senior Citizens’ Motivation To Pursue Cybersecurity Awareness Training: Lecture-Based Vs. Video-Cases Training, Carlene G. Blackwood-Brown

KSU Proceedings on Cybersecurity Education, Research and Practice

Cyber-attacks on Internet users, and in particular senior citizens, who have limited awareness of cybersecurity, have caused billions of dollars in losses annually. To mitigate the effects of cyber-attacks, several researchers have recommended that the cybersecurity awareness levels of Internet users be increased. Cybersecurity awareness training programs are most effective when they involve training that focus on making users more aware so that they can identify cyber-attacks as well as mitigate the effects of the cyber-attacks when they use the Internet. However, it is unclear about what motivates Internet users to pursue cybersecurity awareness training so that they can identify …


Towards A Comparison Of Training Methodologies On Employee’S Cybersecurity Countermeasures Awareness And Skills In Traditional Vs. Socio-Technical Programs, Jodi Goode Oct 2016

Towards A Comparison Of Training Methodologies On Employee’S Cybersecurity Countermeasures Awareness And Skills In Traditional Vs. Socio-Technical Programs, Jodi Goode

KSU Proceedings on Cybersecurity Education, Research and Practice

Organizations, which have established an effective technical layer of security, continue to experience difficulties triggered by cyber threats. Ultimately, the cybersecurity posture of an organization depends on appropriate actions taken by employees whose naive cybersecurity practices have been found to represent 72% to 95% of cybersecurity threats and vulnerabilities. However, employees cannot be held responsible for cybersecurity practices if they are not provided the education and training to acquire skills which allow for identification of security threats along with the proper course of action. This work-in-progress study addresses the first phase of a larger project to empirically assess if there …


Code Metrics For Predicting Risk Levels Of Android Applications, Akond A. Rahman Oct 2016

Code Metrics For Predicting Risk Levels Of Android Applications, Akond A. Rahman

KSU Proceedings on Cybersecurity Education, Research and Practice

Android applications pose security and privacy risks for end-users. Early prediction of risk levels that are associated with Android applications can help Android developers is releasing less risky applications to end-users. Researchers have showed how code metrics can be used as early predictors of failure prone software components. Whether or not code metrics can be used to predict risk levels of Android applications requires systematic exploration. The goal of this paper is to aid Android application developers in assessing the risk associated with developed Android applications by identifying code metrics that can be used as predictors to predict two levels …


Training Wheels: A New Approach To Teaching Mobile Device Security, Philip Menard, Jordan Shropshire Oct 2016

Training Wheels: A New Approach To Teaching Mobile Device Security, Philip Menard, Jordan Shropshire

KSU Proceedings on Cybersecurity Education, Research and Practice

Despite massive investments in cyber security education, training, and awareness programs, most people retain unsafe mobile computing habits. They not only jeopardize their own data, but also risk the security of their associated organizations. It appears that conventional training programs are not ingraining sound security practices on trainees. This research questions the efficacy of legacy SETA frameworks and proposes a new cyber training tool for mobile devices. The tool is called Training Wheels. Training Wheels stands a number of cyber security training practices on their heads: instead of using punitive methods of reinforcement it provides rewards to encourage good behavior, …


Teaching Static Call Analysis To Detect Anomalous Software Behavior, Jordan Shropshire, Philip Menard Oct 2016

Teaching Static Call Analysis To Detect Anomalous Software Behavior, Jordan Shropshire, Philip Menard

KSU Proceedings on Cybersecurity Education, Research and Practice

Malicious code detection is a critical part of any cyber security operation. Typically, the behavior of normal applications is modeled so that deviations from normal behavior can be identified. There are multiple approach to modeling good behavior but the most common approach is to observe applications’ system call activity. System calls are messages passed between user space applications and their underlying operating systems. The detection of irregular system call activity signals the presence of malicious software behavior. This method of malware-detection has been used successfully for almost two decades. Unfortunately, it can be difficult to cover this concept at the …


Research Insights About Risk Governance: Implications From A Review Of Erm Research, Therese R. Viscelli, Mark S. Beasley, Dana R. Hermanson Oct 2016

Research Insights About Risk Governance: Implications From A Review Of Erm Research, Therese R. Viscelli, Mark S. Beasley, Dana R. Hermanson

Faculty Articles

In recent years, expectations for increased risk governance have been placed explicitly on boards of directors. In response, boards are being held responsible for not only understanding and approving management’s risk management processes, but they are also being held responsible for assessing the risks identified by those processes as part of overseeing management’s pursuit of value. These increasing responsibilities have led a number of organizations to adopt enterprise risk management (ERM) as a holistic approach to risk management that extends beyond traditional silo-based risk management techniques. As boards, often through their audit committee, consider management’s implementation of ERM as part …


An Investigation Of Factors Leading To The Reluctance Of Saas Erp Adoption In Namibian Smes, Victoria T. Hasheela Miss, Kari Smolander Professor, Tulimevava K. Mufeti Dr Oct 2016

An Investigation Of Factors Leading To The Reluctance Of Saas Erp Adoption In Namibian Smes, Victoria T. Hasheela Miss, Kari Smolander Professor, Tulimevava K. Mufeti Dr

The African Journal of Information Systems

This paper aims to contribute to the growing study of Cloud ERP in small and medium enterprises (SMEs). A qualitative study was done in Namibian SMEs to investigate factors that lead to the reluctance of Cloud ERP in SMEs in developing countries. Data was collected from fourteen different SMEs. A Diffusion of Innovation (DoI) framework was chosen to understand how this relatively new technology is being adopted. The study has found attitude towards change, satisfaction with the existing system, lack of knowledge, compatibility issues, unreliable internet connectivity and data security concerns as the main factors that lead to this reluctance. …


Holistic Approach: Paradigm Shift In The Research Agenda For Digitalisation Of Healthcare In Sub-Saharan Africa, Tadeusz K. Bara-Slupski Oct 2016

Holistic Approach: Paradigm Shift In The Research Agenda For Digitalisation Of Healthcare In Sub-Saharan Africa, Tadeusz K. Bara-Slupski

The African Journal of Information Systems

Despite significant resources employed in the digitalisation agenda in the healthcare sector in Sub-Saharan Africa, the transformative impact of information and communication technologies has not been realised. This article makes two contributions towards developing an understanding of this failure. First, it provides a review of a rich body of academic literature and practitioner accounts regarding barriers to digitalisation and organises them using an established framework. Second, recognising the continuing struggle that digitalisation presents, it proposes a paradigmatic shift in thinking about barriers to digitalisation and suggests the existence of a more fundamental barrier related to inappropriate incentives within the international …


Enterprise Risk Management: The Transformation Of Board-Level Engagement As Evidenced By Disclosure, Timothy L. Baker Sep 2016

Enterprise Risk Management: The Transformation Of Board-Level Engagement As Evidenced By Disclosure, Timothy L. Baker

Doctor of Business Administration Dissertations

Utilizing available information about ERM practices within organizations disclosed by boards of directors in annual proxy statements filed with the U.S. Securities and Exchange Commission (SEC), this study expands the understanding of the value of disclosure of board-level ERM oversight information in proxy statements. The study first creates a board-level ERM engagement index (BODERMX) to identify aspects of board engagement in the ERM efforts disclosed by companies. Development of this index will present opportunities to future researchers to conduct empirical ERM-related research as information about firms’ ERM is costly to obtain. The study next examines associations between the extent of …


From Offshoring To Reshoring: A Conceptual Framework For Manufacturing Location Decisions In A Slow-Steam World, Jeffrey J. Risher Jul 2016

From Offshoring To Reshoring: A Conceptual Framework For Manufacturing Location Decisions In A Slow-Steam World, Jeffrey J. Risher

Doctor of Business Administration Dissertations

Reshoring, the act of moving manufacturing operations from an offshore location to the nation of the parent company, is rapidly becoming one of the most researched topics in business. Reshoring describes the reversal of a previous offshoring decision, whereby a firm either relocated its own manufacturing operations overseas or outsourced a significant portion of production to offshore suppliers. With looming uncertainty in global consumer demand and diminishing returns in offshore markets, reshoring is gaining exposure as a viable strategy for firms experiencing a diluted competitive advantage as grounded costs approach market equilibrium.

With academic literature on reshoring only beginning to …


Enterprise Resource Planning Systems In Family Firms, James Nathan Smith Jul 2016

Enterprise Resource Planning Systems In Family Firms, James Nathan Smith

Doctor of Business Administration Dissertations

For organizations that have them, an enterprise resource planning (ERP) system is an organization’s most wide-reaching information system, sitting at the heart of its accounting and operational structure. Thus, successful implementation of an ERP is critical to an organization’s success. Organizations have long struggled with achieving successful implementations of large-scale information systems, and family influenced firms are no exception. In light of unique considerations for family influenced firms as compared with non-family influenced firms, this research examines the relation between the influence of family ownership in family business and success in implementing an ERP system. This research presents a quantitative …


Management And Organizational Influences On The Compliance Behavior Of Employees To Reduce Non-Malicious It Misuse Intention, Randy G. Colvin Jul 2016

Management And Organizational Influences On The Compliance Behavior Of Employees To Reduce Non-Malicious It Misuse Intention, Randy G. Colvin

Doctor of Business Administration Dissertations

The widespread use of information technology and information systems (IT) throughout corporations, too often includes employees who choose not to follow the stated policies and procedures in performing their job tasks. In many cases, this encompasses employees who mean no harm, but choose not to comply with IT policies and procedures. The present study frames such compliance behavior as non-malicious IT misuse. Non-malicious IT misuse by an employee occurs when the employee improvises, takes short cuts, or works around IT procedures and guidelines in order to perform their assigned tasks. As expressed, they do not intend to cause internal control …


Is Success Model For Evaluating Cloud Computing For Small Business Benefit: A Quantitative Study, Charles Kenneth Flack Jul 2016

Is Success Model For Evaluating Cloud Computing For Small Business Benefit: A Quantitative Study, Charles Kenneth Flack

Doctor of Business Administration Dissertations

Information system (IS) success has been extensively researched to frame key attributes of an information system or technology to understand its benefit to business. One definition of IS success is the adoption and extensive use of an information system (Robey & Zeller, 1978). In the present era of cloud computing, as in former IS eras, successful implementation is critical for achieving business success in all enterprise types. IS success is also described as a lagging multifaceted measure of technology effectiveness for a business. Early adopters of a new technology are a rich resource to determine benefits for later adopters, and …


The Impact Of Rural Pensions In China On Labor Migration, Karen Eggleson, Ang Sun, Zhaoguo Zhan Jul 2016

The Impact Of Rural Pensions In China On Labor Migration, Karen Eggleson, Ang Sun, Zhaoguo Zhan

Faculty Articles

We study the impact of China’s new rural pension program on promoting migration of labor by applying a regression discontinuity analysis to this new pension program. The results reveal a perceptible difference in labor migration among adult children whose parents are just above and below the age of pension eligibility: The adult children with a parent just attaining the pension-eligible age are more likely to be labor migrants compared with those with a parent just below the pension-eligible age. We also find that with a pension-eligible parent, the adult children are more likely to have off-farm jobs. These abrupt changes …


Reflecting On Performance Feedback: The Effect Of Counterfactual Thinking On Subsequent Leader Performance, Kelly R. Hall Jul 2016

Reflecting On Performance Feedback: The Effect Of Counterfactual Thinking On Subsequent Leader Performance, Kelly R. Hall

Doctor of Business Administration Dissertations

Performance feedback is an integral aspect of facilitating employee learning. Despite its importance, research suggests that when that feedback conveys a performance discrepancy, subsequent performance does not improve. Researchers have advanced reflection as a strategy for increasing feedback effectiveness and have established its value for learning and performance improvement. However, these studies have not accounted for the effects of specific types of reflection on performance. To this point, the current research examines the role of one form of reflection, counterfactual thinking, for learning after performance discrepancies. I explored boundary conditions that might influence self-focused upward counterfactual thinking—a form of reflection …


Audit Firm Rotation, Audit Firm Tenure, And Audit Committee Support In Accounting Disputes, Janice E. Rummell Jun 2016

Audit Firm Rotation, Audit Firm Tenure, And Audit Committee Support In Accounting Disputes, Janice E. Rummell

Doctor of Business Administration Dissertations

Since the late 1990s, U.S. regulators have sought to increase auditors’ independence from management and to reduce the presumed detrimental effects of economic bonding on public company financial reporting. Implementation of mandatory audit firm rotation that limits auditor tenure to reduce potential independence impairment has been discussed in the U.S. and other jurisdictions, and adopted in some non-U.S. jurisdictions. While audit firm rotation is expected to increase auditor independence, the opponents of mandatory rotation cite decreasing auditor expertise as a significant counter-argument. This independence/expertise trade-off is integral to much of the academic discussion of mandatory audit firm rotation. The audit …


From The Editors, Michael E. Whitman, Herbert J. Mattord Jun 2016

From The Editors, Michael E. Whitman, Herbert J. Mattord

Journal of Cybersecurity Education, Research and Practice

Welcome to the inaugural issue of the Journal of Cybersecurity Education, Research and Practice (JCERP).