Open Access. Powered by Scholars. Published by Universities.®

Computer Engineering Commons

Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity

Discipline
Institution
Publication Year
Publication
Publication Type

Articles 31 - 60 of 152

Full-Text Articles in Computer Engineering

Detection Of Data Leakage And Disruption Of Covert Timing Channel In Secure Drone Communication Using Machine And Deep Learning, Jonathan Walatkiewicz Jan 2025

Detection Of Data Leakage And Disruption Of Covert Timing Channel In Secure Drone Communication Using Machine And Deep Learning, Jonathan Walatkiewicz

Master's Theses and Doctoral Dissertations

The utilization of recreational drones has experienced a substantial increase in both the United States and globally. However, it is noteworthy that most drones, classified as Internet of Things devices, are produced with a limited security lifecycle. This study's findings are of paramount importance, as traditional computing exploits can be applied to drones, designating them as high- value targets. This study examines the detectability and disruptability of covert timing channel traffic in secure drones. The investigation aims to ascertain the effects of multiple interarrival times, distances ranging from 1 to 330 feet, various detection algorithms, and stream sizes between 32-bit …


Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu Jan 2025

Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu

Journal of Cybersecurity Education, Research and Practice

The profound impact of the Internet of Things (IoT) on various fronts, is driven by technological advancements, the ubiquitous spread of information, and the emergence of transformative events. IoT presents a diverse array of possibilities within university environments, fostering a more connected and enhanced educational experience. This research undertakes a comprehensive review of existing literature to provide context to the IoT and underscore its crucial significance in the realm of smart campuses. Additionally, the paper explores the intricate connections between IoT and key concepts such as cybersecurity and wireless sensor networks to present a holistic perspective. It delves into the …


Machine Learning Based Network Traffic Classification With Cosine-Similarity Based Out-Of-Distribution Detection, Prabhat Edupuganti Jan 2025

Machine Learning Based Network Traffic Classification With Cosine-Similarity Based Out-Of-Distribution Detection, Prabhat Edupuganti

Master's Projects

The changes occurring in the amount of encrypted network traffic is growing at an alarming rate. This development has created intricate problems in traffic classification which is vital for effective cybersecurity. Moreover, most frameworks seem to ignore OOD detection, model calibration and novel pattern detection as cornerstone problem areas. The due analysis is presented as a machine learning approach aimed at resolving encrypted traffic classification issues and focuses on novel OOD detection and calibration issues. Primary contributions comprise detection of out-of-distribution states using softmax scaled cosine similarity, advanced variance-based feature elimination, and lowering ECE using stringent NNs. This work demonstrates …


Performance Evaluation Of Managed Switch Configurations For Secure And Efficient Plc-Based Industrial Automation Networks, Ahmed Salama Jan 2025

Performance Evaluation Of Managed Switch Configurations For Secure And Efficient Plc-Based Industrial Automation Networks, Ahmed Salama

All Graduate Theses, Dissertations, and Other Capstone Projects

This thesis explores how managed switches can improve network performance and security in PLC-based industrial systems. Using simulations in GNS3 and Cisco Packet Tracer, and packet analysis via Wireshark, the study compares unmanaged and managed switch configurations. Redundancy protocols, particularly STP and RSTP, are evaluated under failure scenarios. Results show that RSTP offers faster recovery times, making it more suitable for time-sensitive environments. Additionally, managed switch features like VLANs, port security, and MAC filtering significantly reduce vulnerabilities and improve network segmentation. The findings highlight the importance of incorporating both cybersecurity and redundancy in industrial network design as systems move toward …


Silent Sabotage: Identifying And Preventing Cyber Attacks From Inside Actors, Autumn Groen Jan 2025

Silent Sabotage: Identifying And Preventing Cyber Attacks From Inside Actors, Autumn Groen

Williams Honors College, Honors Research Projects

Cyber-attacks are becoming increasingly common and damaging as technology advances each year. Many businesses cannot afford the latest security technologies, and even with the highest security measures, there can still be room for employee error or insider threats that are not taken into account. It is crucial to keep these factors in mind when securing a business network of any size or financial standing.This project will aim to simulate a business environment by first building a small network with three routers and a switch, and implementing some of the common best practices for network hardening from credible organizations like NIST …


Application Of Advanced Convolutional Neural Network With Robust Hashing On Obfuscated Image Based Malware Dataset, Sanket Shekhar Kulkarni Jan 2025

Application Of Advanced Convolutional Neural Network With Robust Hashing On Obfuscated Image Based Malware Dataset, Sanket Shekhar Kulkarni

Master's Projects

This project report provides in-depth details on the creation of a malware classification system that makes use of Convolutional Neural Networks (CNNs) that have been strengthened by data set obfuscation and strong hashing. We test many CNN architectures, including MobileNet, ResNet, and DenseNet, using rigorous hashing and obfuscation techniques on datasets. The entire pipeline is described in this research, which ranges from the gathering and preprocessing of data sets to the application of novel hashing techniques that boost overall accuracy in classification and increase resilience against malicious attacks. Parallel to this, we show that dataset obfuscation adds an additional level …


Faux Capabilities: A Novel Approach For Code Analysis, Tanay Godse Jan 2025

Faux Capabilities: A Novel Approach For Code Analysis, Tanay Godse

Master's Projects

When using third-party packages or libraries, it is crucial to understand their behavior. Typically, this requires developers to either conduct code reviews or set up sandbox environments for testing or write unit tests with mocked values for every function used in their code. However, these approaches are often inefficient and time-consuming. A more effective solution would provide developers with a broad understanding of the functionality required by the code they plan to import. This can be done using object capabilities, where a particular functionality is the capability that an object must possess, in order to be able to perform the …


Pig Butchering In Cybersecurity: A Modern Social Engineering Threat, Sharon L. Burton, Pamela D. Moore Oct 2024

Pig Butchering In Cybersecurity: A Modern Social Engineering Threat, Sharon L. Burton, Pamela D. Moore

Publications

Pig butchering is an escalating cybersecurity threat that exploits social engineering to build trust and execute financial fraud. The relevance of this research problem lies in the growing incidence and sophistication of these scams, which have severe financial and psychological impacts on victims. The main purpose of this research is to uncover the methods used in pig butchering scams and their impact on individuals and businesses. The research focuses on digital platforms such as social media, dating apps, and professional networking sites, chosen for their wide user bases and the ease of establishing personal connections. The study period encompasses recent …


Crowdstrike Cyber Incident Vs. Past Major Cyber Incidents: Analysis And Solutions, Priyant Banerjee Aug 2024

Crowdstrike Cyber Incident Vs. Past Major Cyber Incidents: Analysis And Solutions, Priyant Banerjee

Himalayan Research Papers Archive

On July 19, 2024, a technical malfunction in CrowdStrike’s Falcon sensor software led to a global ITdisruption, affecting millions of devices across multiple sectors. This incident, although not a direct cyber-attack, caused significant operational upheavals reminiscent of major past cyber incidents. This paperexplores the CrowdStrike incident in detail, compares it with previous major cyber events, and proposescomprehensive solutions to mitigate such risks in the future.The faulty update from CrowdStrike resulted in widespread system crashes, notably the "Blue Screen ofDeath," paralyzing operations in critical sectors such as healthcare, finance, and transportation. The paperexamines the immediate and cascading effects of the incident, …


Emerging Cyber Risks & Threats In Healthcare Systems: A Case Study In Resilient Cybersecurity Solutions, Abdiaziz Abdi, Hajar Bennouri, Anthony Keane Jul 2024

Emerging Cyber Risks & Threats In Healthcare Systems: A Case Study In Resilient Cybersecurity Solutions, Abdiaziz Abdi, Hajar Bennouri, Anthony Keane

Conference Papers

The exponential growth of digitalisation in healthcare and the ongoing threat of cybersecurity breaches are significant and cast a shadow over the industry’s progress. As the cost of data breaches reaches unprecedented levels, reaching an average of US$10.93 million in 2023 alone, and the frequency of attacks escalates, evidenced by a staggering 60% increase in phishing incidents between 2022 and 2023 reported by Smarttech247, Healthcare infrastructure is at a critical intersection. In this paper, we address the complex relationship between harnessing the potential of digital systems to improve and combating the escalating risks posed by cyber threats. The cyberattack on …


Comprehensive Network Redundancy Implementation And Cybersecurity Hardening Project: Ensuring Resilience And Defending Against Dhcp Starvation, Stp Man-In-The-Middle, And Brute Force Attacks, Seth Shaheen Jun 2024

Comprehensive Network Redundancy Implementation And Cybersecurity Hardening Project: Ensuring Resilience And Defending Against Dhcp Starvation, Stp Man-In-The-Middle, And Brute Force Attacks, Seth Shaheen

Williams Honors College, Honors Research Projects

I have created a network topology that contains three Cisco routers, three Cisco switches, and three endpoints. The network has been built using the software GNS-3. The endpoints on the topology include one VPC, one Kali Linux VM, and one Ubuntu Server VM. The main purpose of this network topology is to show the skills I have learned during my tenure at The University of Akron. This will be done by hardening this network to ensure that the network is impervious to cyber-attacks. The Kali Linux VM will act as the attacker on the network and conduct three attacks: STP …


Improving Ethics Surrounding Collegiate-Level Hacking Education: Recommended Implementation Plan & Affiliation With Peer-Led Initiatives, Shannon Morgan, Dr. Sanjay Goel May 2024

Improving Ethics Surrounding Collegiate-Level Hacking Education: Recommended Implementation Plan & Affiliation With Peer-Led Initiatives, Shannon Morgan, Dr. Sanjay Goel

Military Cyber Affairs

Cybersecurity has become a pertinent concern, as novel technological innovations create opportunities for threat actors to exfiltrate sensitive data. To meet the demand for professionals in the workforce, universities have ramped up their academic offerings to provide a broad range of cyber-related programs (e.g., cybersecurity, informatics, information technology, digital forensics, computer science, & engineering). As the tactics, techniques, and procedures (TTPs) of hackers evolve, the knowledge and skillset required to be an effective cybersecurity professional have escalated accordingly. Therefore, it is critical to train cyber students both technically and theoretically to actively combat cyber criminals and protect the confidentiality, integrity, …


Generative Machine Learning For Cyber Security, James Halvorsen, Dr. Assefaw Gebremedhin May 2024

Generative Machine Learning For Cyber Security, James Halvorsen, Dr. Assefaw Gebremedhin

Military Cyber Affairs

Automated approaches to cyber security based on machine learning will be necessary to combat the next generation of cyber-attacks. Current machine learning tools, however, are difficult to develop and deploy due to issues such as data availability and high false positive rates. Generative models can help solve data-related issues by creating high quality synthetic data for training and testing. Furthermore, some generative architectures are multipurpose, and when used for tasks such as intrusion detection, can outperform existing classifier models. This paper demonstrates how the future of cyber security stands to benefit from continued research on generative models.


Securing The Void: Assessing The Dynamic Threat Landscape Of Space, Brianna Bace, Dr. Unal Tatar May 2024

Securing The Void: Assessing The Dynamic Threat Landscape Of Space, Brianna Bace, Dr. Unal Tatar

Military Cyber Affairs

Outer space is a strategic and multifaceted domain that is a crossroads for political, military, and economic interests. From a defense perspective, the U.S. military and intelligence community rely heavily on satellite networks to meet national security objectives and execute military operations and intelligence gathering. This paper examines the evolving threat landscape of the space sector, encompassing natural and man-made perils, emphasizing the rise of cyber threats and the complexity introduced by dual-use technology and commercialization. It also explores the implications for security and resilience, advocating for collaborative efforts among international organizations, governments, and industry to safeguard the space sector.


The Next Threat Landscape: Securing America’S Cyber-Physical Systems, Grayson Thomas Apr 2024

The Next Threat Landscape: Securing America’S Cyber-Physical Systems, Grayson Thomas

Honors College Theses

The goal of this research is to explore, identify, and enumerate the security threats that exist to industry current industrial controls systems (ICS) and supervisory control and data acquisition systems (SCADA). A scale lab similar to industry standard will be built and developed for research purposes. The Purdue Model for ICS and the Cyber Kill Chain will be referenced as frameworks for attack sequences, and the MITRE ATT&CK framework will be referenced for attack types. Attempts will be made to compromise the various pieces of our built SCADA system via configuration errors, software vulnerabilities, and deployment mistakes common with industrial …


Enhancing Cyber Resilience: Development, Challenges, And Strategic Insights In Cyber Security Report Websites Using Artificial Inteligence, Pooja Sharma Apr 2024

Enhancing Cyber Resilience: Development, Challenges, And Strategic Insights In Cyber Security Report Websites Using Artificial Inteligence, Pooja Sharma

Harrisburg University Dissertations and Theses

In an era marked by relentless cyber threats, the imperative of robust cyber security measures cannot be overstated. This thesis embarks on an in-depth exploration of the historical trajectory and contemporary relevance of penetration testing methodologies, elucidating their evolution from nascent origins to indispensable tools in the cyber security arsenal. Moreover, it undertakes the ambitious task of conceptualizing and implementing a cyber security report website, meticulously designed to fortify cyber resilience in the face of ever-evolving threats in the digital realm.

The research journey commences with an insightful examination of the historical antecedents of penetration testing, tracing its genesis in …


Cyber Attacks Against Industrial Control Systems, Adam Kardorff Apr 2024

Cyber Attacks Against Industrial Control Systems, Adam Kardorff

LSU Master's Theses

Industrial Control Systems (ICS) are the foundation of our critical infrastructure, and allow for the manufacturing of the products we need. These systems monitor and control power plants, water treatment plants, manufacturing plants, and much more. The security of these systems is crucial to our everyday lives and to the safety of those working with ICS. In this thesis we examined how an attacker can take control of these systems using a power plant simulator in the Applied Cybersecurity Lab at LSU. Running experiments on a live environment can be costly and dangerous, so using a simulated environment is the …


Longitudinal Attacks Against Iterative Data Collection With Local Differential Privacy, Mehmet Emre Gürsoy Feb 2024

Longitudinal Attacks Against Iterative Data Collection With Local Differential Privacy, Mehmet Emre Gürsoy

Turkish Journal of Electrical Engineering and Computer Sciences

Local differential privacy (LDP) has recently emerged as an accepted standard for privacy-preserving collection of users’ data from smartphones and IoT devices. In many practical scenarios, users’ data needs to be collected repeatedly across multiple iterations. In such cases, although each collection satisfies LDP individually by itself, a longitudinal collection of multiple responses from the same user degrades that user’s privacy. To demonstrate this claim, in this paper, we propose longitudinal attacks against iterative data collection with LDP. We formulate a general Bayesian adversary model, and then individually show the application of this adversary model on six popular LDP protocols: …


Media And Internet Censorship In India: A Study Of Its History And Political-Economy, Ramesh Subramanian Jan 2024

Media And Internet Censorship In India: A Study Of Its History And Political-Economy, Ramesh Subramanian

Journal of International Technology and Information Management

The Indian Constitution, which came into force on January 26, 1950, guarantees various fundamental rights, such as the freedom of speech and expression, freedom of religion, rights to form association, as well as rights to privacy. Yet, since the adoption of the Constitution, the Indian citizen has been subject to varying degrees of media censorship and surveillance. This paper seeks to delve into the historical evolution of media and Internet censorship and surveillance in India. It shows how media censorship of varying types have existed since the British colonists introduced restrictive laws in order to expand and control the native …


Ensemble Learning With Sleep Mode Management To Enhance Anomaly Detection In Iot Environment, Khawlah Harahsheh, Rami Al-Naimat, Malek Alzaqebah, Salam Shreem, Esraa Aldreabi, Chung-Hao Chen Jan 2024

Ensemble Learning With Sleep Mode Management To Enhance Anomaly Detection In Iot Environment, Khawlah Harahsheh, Rami Al-Naimat, Malek Alzaqebah, Salam Shreem, Esraa Aldreabi, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The rapid proliferation of Internet of Things (IoT) devices has underscored the critical need for energy-efficient cybersecurity measures. This presents the dual challenge of maintaining robust security while minimizing power consumption. Thus, this paper proposes enhancing the machine learning performance through Ensemble Techniques with Sleep Mode Management (ELSM) approach for IoT Intrusion Detection Systems (IDS). The main challenge lies in the high-power consumption attributed to continuous monitoring in traditional IDS setups. ELSM addresses this challenge by introducing a sophisticated sleep-awake mechanism, activating the IDS system only during anomaly detection events, effectively minimizing energy expenditure during periods of normal network operation. …


Cybersecurity In Critical Infrastructure Systems: Emulated Protection Relay, Mitchell Bylak Dec 2023

Cybersecurity In Critical Infrastructure Systems: Emulated Protection Relay, Mitchell Bylak

Computer Science and Computer Engineering Undergraduate Honors Theses

Cyber-attacks on Critical Systems Infrastructure have been steadily increasing across the world as the capabilities of and reliance on technology have grown throughout the 21st century, and despite the influx of new cybersecurity practices and technologies, the industry faces challenges in its cooperation between the government that regulates law practices and the private sector that owns and operates critical infrastructure and security, which has directly led to an absence of eas- ily accessible information and learning resources on cybersecurity for use in public environments and educational settings. This honors research thesis addresses these challenges by submitting the development of an …


Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim Oct 2023

Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim

Journal of Cybersecurity Education, Research and Practice

This paper reviews cybersecurity laws and regulations in Cameroon, focusing on cybersecurity and information security audits and risk assessments. The importance of cybersecurity risk assessment and the implementation of security controls to cure deficiencies noted during risk assessments or audits is a critical step in developing cybersecurity resilience. Cameroon's cybersecurity legal framework provides for audits but does not explicitly enumerate controls. Consequently, integrating relevant controls from the NIST frameworks and ISO Standards can improve the cybersecurity posture in Cameroon while waiting for a comprehensive revision of the legal framework. NIST and ISO are internationally recognized as best practices in information …


Sel4 On Risc-V - Developing High Assurance Platforms With Modular Open-Source Architectures, Michael A. Doran Jr Aug 2023

Sel4 On Risc-V - Developing High Assurance Platforms With Modular Open-Source Architectures, Michael A. Doran Jr

Masters Theses

Virtualization is now becoming an industry standard for modern embedded systems. Modern embedded systems can now support multiple applications on a single hardware platform while meeting power and cost requirements. Virtualization on an embedded system is achieved through the design of the hardware-software interface. Instruction set architecture, ISA, defines the hardware-software interface for an embedded system. At the hardware level the ISA, provides extensions to support virtualization.

In addition to an ISA that supports hypervisor extensions it is equally important to provide a hypervisor completely capable of exploiting the benefits of virtualization for securing modern embedded systems. Currently there does …


Unveiling The Digital Shadows: Cybersecurity And The Art Of Digital Forensics, Derek Beardall Jul 2023

Unveiling The Digital Shadows: Cybersecurity And The Art Of Digital Forensics, Derek Beardall

Cyber Operations and Resilience Program Graduate Projects

This paper navigates the symbiotic relationship between cybersecurity and digital forensics, exploring the profound role of digital forensic methodologies in addressing cyber incidents. Beginning with foundational definitions and historical evolution, this study delves into diverse types of methodologies and their applications across law enforcement and cybersecurity domains. The mechanics of cyber incident response illuminates the strategic orchestration of digital forensic methodologies. Amidst triumphs, challenges emerge from the shadows: swift threat evolution, digital ecosystem complexity, standardization gaps, resource limitations, and legal intricacies. Best practices guide experts through this intricate terrain, culminating in an enhanced understanding of the inseparable bond between cybersecurity …


Security-Enhanced Serial Communications, John White, Alexander Beall, Joseph Maurio, Dane Fichter, Dr. Matthew Davis, Dr. Zachary Birnbaum May 2023

Security-Enhanced Serial Communications, John White, Alexander Beall, Joseph Maurio, Dane Fichter, Dr. Matthew Davis, Dr. Zachary Birnbaum

Military Cyber Affairs

Industrial Control Systems (ICS) are widely used by critical infrastructure and are ubiquitous in numerous industries including telecommunications, petrochemical, and manufacturing. ICS are at a high risk of cyber attack given their internet accessibility, inherent lack of security, deployment timelines, and criticality. A unique challenge in ICS security is the prevalence of serial communication buses and other non-TCP/IP communications protocols. The communication protocols used within serial buses often lack authentication and integrity protections, leaving them vulnerable to spoofing and replay attacks. The bandwidth constraints and prevalence of legacy hardware in these systems prevent the use of modern message authentication and …


Detection Of Crypto-Ransomware Attack Using Deep Learning, Muna Jemal May 2023

Detection Of Crypto-Ransomware Attack Using Deep Learning, Muna Jemal

Master of Science in Computer Science Theses

The number one threat to the digital world is the exponential increase in ransomware attacks. Ransomware is malware that prevents victims from accessing their resources by locking or encrypting the data until a ransom is paid. With individuals and businesses growing dependencies on technology and the Internet, researchers in the cyber security field are looking for different measures to prevent malicious attackers from having a successful campaign. A new ransomware variant is being introduced daily, thus behavior-based analysis of detecting ransomware attacks is more effective than the traditional static analysis. This paper proposes a multi-variant classification to detect ransomware I/O …


What Senior U.S. Leaders Say We Should Know About Cyber, Dr. Joseph H. Schafer May 2023

What Senior U.S. Leaders Say We Should Know About Cyber, Dr. Joseph H. Schafer

Military Cyber Affairs

On April 6, 2023, the Atlantic Council’s Cyber Statecraft Initiative hosted a panel discussion on the new National Cybersecurity Strategy. The panel featured four senior officials from the Office of the National Cyber Director (ONCD), the Department of State (DoS), the Department of Justice (DoJ), and the Department of Homeland Security (DHS). The author attended and asked each official to identify the most important elements that policymakers and strategists must understand about cyber. This article highlights historical and recent struggles to express cyber policy, the responses from these officials, and the author’s ongoing research to improve national security cyber policy.


Protecting The Infrastructure Of Michigan: Analyzing And Understanding Internet Infrastructure, Samuel Blaser, Travis Munyer, Damian Ramirez, Lester Juarez, Jackson Servant May 2023

Protecting The Infrastructure Of Michigan: Analyzing And Understanding Internet Infrastructure, Samuel Blaser, Travis Munyer, Damian Ramirez, Lester Juarez, Jackson Servant

Theses/Capstones/Creative Projects

The Michigan Army National Guard DCOE is hoping to increase their understanding of the physical, electrical, protocol, and logical topography of internet service. In order to understand the infrastructure of the internet, information must be collected on its pieces. By studying, describing, and illustrating the infrastructure of the global internet we can develop hardening tactics, improve user training, and develop contingency plans in the case of an attack. The research is focused on where data lives, locating data centers in the region, identifying global infrastructure and who owns it, and potential for hardening. An interactive map has been created in …


The Rapid Increase Of Ransomware Attacks Over The 21st Century And Mitigation Strategies To Prevent Them From Arising, Sanjay Jacob May 2023

The Rapid Increase Of Ransomware Attacks Over The 21st Century And Mitigation Strategies To Prevent Them From Arising, Sanjay Jacob

Senior Honors Theses

Cyber-attacks have continued to become more common throughout the past century as more people are exposed to the Internet. Every year, various studies, reports, and scholarly research is done to emphasis the rapid increase of attacks. In this honors thesis, the student sought to gather further information about the rise of ransomware attacks, various cyber threats, discuss the psychological manipulation that exist, and provided the reader with an ethical complement of cyber-attacks. Additionally, case studies from previous research have been analyzed and mitigation strategies have been explained to provide the reader with practical application. This research emphasizes in on key …


Bridging The Gap Between Public Organizaions And Cybersecurity, Christopher Boutros May 2023

Bridging The Gap Between Public Organizaions And Cybersecurity, Christopher Boutros

Electronic Theses, Projects, and Dissertations

Cyberattacks are a major problem for public organizations across the nation, and unfortunately for them, the frequency of these attacks is constantly growing. This project used a case study approach to explore the types of cybersecurity public organization agencies face and how those crimes can be mitigated. The goal of this paper is to understand how public organization agencies have prepared for cyberattacks and discuss additional suggestions to improve their current systems with the current research available This research provides an analysis of current cyber security systems, new technologies that can be implemented, roadblocks public agencies face before and during …