Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Singapore Management University (1107)
- Embry-Riddle Aeronautical University (768)
- Edith Cowan University (532)
- Kennesaw State University (300)
- Old Dominion University (256)
-
- Air Force Institute of Technology (181)
- San Jose State University (117)
- Bridgewater State University (73)
- Clark University (71)
- University of New Haven (65)
- United Arab Emirates University (64)
- University of Arkansas, Fayetteville (59)
- City University of New York (CUNY) (55)
- Dakota State University (49)
- California State University, San Bernardino (34)
- Nova Southeastern University (33)
- Maurer School of Law: Indiana University (32)
- University for Business and Technology in Kosovo (30)
- University of Central Florida (24)
- University of South Alabama (23)
- University of Dayton (22)
- Franklin University (21)
- LSU New Orleans (21)
- University of Nebraska at Omaha (20)
- Wayne State University (20)
- California Polytechnic State University, San Luis Obispo (18)
- University of Kentucky (18)
- Florida Institute of Technology (17)
- Louisiana State University (16)
- Portland State University (16)
- Keyword
-
- Cybersecurity (317)
- Security (246)
- Privacy (163)
- Computer security (101)
- Digital forensics (89)
-
- Information security (89)
- Blockchain (88)
- Machine learning (82)
- Authentication (71)
- Cryptography (71)
- Cloud computing (68)
- Encryption (65)
- Data privacy (62)
- [RSTDPub] (54)
- Cyber security (53)
- Access control (50)
- Data protection (47)
- Network security (45)
- Malware (41)
- Machine Learning (39)
- Android (38)
- Artificial intelligence (38)
- Computer networks--Security measures (38)
- Cybercrime (38)
- Internet of Things (36)
- Deep learning (34)
- Digital Forensics (34)
- Intrusion detection (33)
- MPA (33)
- Forensics (31)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (1056)
- Journal of Digital Forensics, Security and Law (536)
- Australian Information Security Management Conference (224)
- Theses and Dissertations (212)
- Annual ADFSL Conference on Digital Forensics, Security and Law (186)
-
- Journal of Cybersecurity Education, Research and Practice (171)
- Master's Projects (107)
- KSU Proceedings on Cybersecurity Education, Research and Practice (97)
- Cybersecurity Undergraduate Research Showcase (90)
- Research outputs 2022 to 2026 (84)
- International Journal of Cybersecurity Intelligence & Cybercrime (72)
- School of Professional Studies (71)
- Electrical & Computer Engineering and Computer Science Faculty Publications (58)
- Australian Digital Forensics Conference (50)
- Theses (45)
- Australian Information Warfare and Security Conference (44)
- Research outputs 2014 to 2021 (41)
- Computer Science Faculty Publications (40)
- Masters Theses & Doctoral Dissertations (34)
- CCAC Theses and Dissertations (33)
- Graduate Theses and Dissertations (33)
- Articles by Maurer Faculty (31)
- Publications (29)
- Electronic Theses and Dissertations (25)
- UBT International Conference (24)
- VMASC Publications (24)
- Electrical & Computer Engineering Faculty Publications (23)
- Open Educational Resources (23)
- Faculty Publications (22)
- LSU New Orleans Theses and Dissertations (21)
- Publication Type
Articles 1351 - 1380 of 4675
Full-Text Articles in Computer Sciences
An Exploratory Study Of Mode Efficacy In Cybersecurity Training, Michael D. Workman
An Exploratory Study Of Mode Efficacy In Cybersecurity Training, Michael D. Workman
Journal of Cybersecurity Education, Research and Practice
Cybersecurity capabilities in organizations and governmental agencies continue to lag behind the threats. Given the current environment, these entities have placed renewed emphasis on cybersecurity education. However, education appears to lack its full potential in most settings. Few empirical studies have systematically tested the efficacy of various training methods and modes, and those that have been conducted have yielded inconsistent findings. Recent literature on the use of gamified simulations have suggested that they may improve cybersecurity behaviors. Similarly, live activities such as hackathons and capture the flag events have been surmised to augment learning and capabilities. We conducted an exploratory …
An Economical Method For Securely Disintegrating Solid-State Drives Using Blenders, Brandon J. Hopkins Phd, Kevin A. Riggle
An Economical Method For Securely Disintegrating Solid-State Drives Using Blenders, Brandon J. Hopkins Phd, Kevin A. Riggle
Journal of Digital Forensics, Security and Law
Pulverizing solid-state drives (SSDs) down to particles no larger than 2 mm is required by the United States National Security Agency (NSA) to ensure the highest level of data security, but commercial disintegrators that achieve this standard are large, heavy, costly, and often difficult to access globally. Here, we present a portable, inexpensive, and accessible method of pulverizing SSDs using a household blender and other readily available materials. We verify this approach by pulverizing SSDs with a variety of household blenders for fixed periods of time and sieve the resulting powder to ensure appropriate particle size. Among the 6 household …
Certis: Digital Transformation Of A Physical Security Company, Singapore Management University
Certis: Digital Transformation Of A Physical Security Company, Singapore Management University
Perspectives@SMU
How a company synonymous with auxiliary police injected sensors and artificial intelligence into its 21st century operations
A Mean-Field Markov Decision Process Model For Spatial-Temporal Subsidies In Ride-Sourcing Markets, Zheng Zhu, Jintao Ke, Hai Wang
A Mean-Field Markov Decision Process Model For Spatial-Temporal Subsidies In Ride-Sourcing Markets, Zheng Zhu, Jintao Ke, Hai Wang
Research Collection School Of Computing and Information Systems
Ride-sourcing services are increasingly popular because of their ability to accommodate on-demand travel needs. A critical issue faced by ride-sourcing platforms is the supply-demand imbalance, as a result of which drivers may spend substantial time on idle cruising and picking up remote passengers. Some platforms attempt to mitigate the imbalance by providing relocation guidance for idle drivers who may have their own self-relocation strategies and decline to follow the suggestions. Platforms then seek to induce drivers to system-desirable locations by offering them subsidies. This paper proposes a mean-field Markov decision process (MF-MDP) model to depict the dynamics in ride-sourcing markets …
Effect Of Team Cohesion Nn Flow: An Empirical Study Of Team-Based Gamification For Enterprise Resource Planning Systems In Online Classes, Yu Zhao, Mark Srite, Sumin Kim, Jinwoong Lee
Effect Of Team Cohesion Nn Flow: An Empirical Study Of Team-Based Gamification For Enterprise Resource Planning Systems In Online Classes, Yu Zhao, Mark Srite, Sumin Kim, Jinwoong Lee
Business and Information Technology Faculty Research & Creative Works
Pedagogy using gamification has recently received much attention as a way of enhancing student learning and retention. Additionally, academic institutions are making extensive use of online resources to expand teaching beyond the traditional classroom setting. Both academic institutions and companies utilize virtual teams to accomplish remote teamwork, particularly in a post-COVID environment. Despite the growing interest in incorporating gamification into teaching for business school courses, prior researchers have paid little attention to team-based gamification in the online learning environment. The purpose of this study is to examine if team members' perceived team cohesion influences their perceptions of flow. Also, we …
Privacy-Preserving Proof Of Storage For The Pay-As-You-Go Business Model, Tong Wu, Guomin Yang, Yi Mu, Fuchun Guo, Robert H. Deng
Privacy-Preserving Proof Of Storage For The Pay-As-You-Go Business Model, Tong Wu, Guomin Yang, Yi Mu, Fuchun Guo, Robert H. Deng
Research Collection School Of Computing and Information Systems
Proof of Storage (PoS) enables a cloud storage provider to prove that a client's data is intact. However, existing PoS protocols are not designed for the pay-as-you-go business model in which payment is made based on both storage volume and duration. In this paper, we propose two PoS protocols suitable for the pay-as-you-go storage business model. The first is a time encapsulated Proof of Retrievability (PoR) protocol that ensures retrievability of the original file upon successful auditing by a client. Considering the large size of outsourced data, we then extend the protocol to a privacy-preserving public auditing protocol which allows …
A Look Into Increasing The Number Of Veterans And Former Government Employees Converting To Career And Technical Cybersecurity Teachers, Vukica M. Jovanovic, Michael Anthony Crespo, Drew E. Brown, Deborah Marshall, Otilia Popescu, Murat Kuzlu, Petros J. Katsioloudis, Linda Vahala
A Look Into Increasing The Number Of Veterans And Former Government Employees Converting To Career And Technical Cybersecurity Teachers, Vukica M. Jovanovic, Michael Anthony Crespo, Drew E. Brown, Deborah Marshall, Otilia Popescu, Murat Kuzlu, Petros J. Katsioloudis, Linda Vahala
Engineering Technology Faculty Publications
The current state of technology with recent explosions in the digital processing of paperwork, computer networking use, and online and virtual approaches to areas, which until very recently had traditional and non-computerized ways of operating, led to a steady increase in the demand for jobs in the area of computer science and cybersecurity. The education system, the pipeline for the incoming workforce, needs to keep up with this tremendous pace in technology and the job market. The current K-12 school system has been extensively challenged to fill out necessary positions in order to address the increasing need for programs that …
Automated Privacy Protection For Mobile Device Users And Bystanders In Public Spaces, David Darling
Automated Privacy Protection For Mobile Device Users And Bystanders In Public Spaces, David Darling
Graduate Theses and Dissertations
As smartphones have gained popularity over recent years, they have provided usersconvenient access to services and integrated sensors that were previously only available through larger, stationary computing devices. This trend of ubiquitous, mobile devices provides unparalleled convenience and productivity for users who wish to perform everyday actions such as taking photos, participating in social media, reading emails, or checking online banking transactions. However, the increasing use of mobile devices in public spaces by users has negative implications for their own privacy and, in some cases, that of bystanders around them.
Specifically, digital photography trends in public have negative implications for …
A Coprocessor-Based Introspection Framework Via Intel Management Engine, Lei Zhou, Fengwei Zhang, Jidong Xiao, Kevin Leach, Westley Weimer, Xuhua Ding, Guojun Wang
A Coprocessor-Based Introspection Framework Via Intel Management Engine, Lei Zhou, Fengwei Zhang, Jidong Xiao, Kevin Leach, Westley Weimer, Xuhua Ding, Guojun Wang
Research Collection School Of Computing and Information Systems
During the past decade, virtualization-based (e.g., virtual machine introspection) and hardware-assisted approaches (e.g., x86 SMM and ARM TrustZone) have been used to defend against low-level malware such as rootkits. However, these approaches either require a large Trusted Computing Base (TCB) or they must share CPU time with the operating system, disrupting normal execution. In this article, we propose an introspection framework called NIGHTHAWK that transparently checks system integrity and monitor the runtime state of target system. NIGHTHAWK leverages the Intel Management Engine (IME), a co-processor that runs in isolation from the main CPU. By using the IME, our approach has …
Measuring The Relationship Of Gender Misclassification And Automated Face Recognition Match Accuracy Relative To Skin Tone, Afi Edem-Edi Gbekevi
Measuring The Relationship Of Gender Misclassification And Automated Face Recognition Match Accuracy Relative To Skin Tone, Afi Edem-Edi Gbekevi
Theses and Dissertations
The gap of accuracy observed in some commercial face analytic systems based on race and gender raised questions about the equity and fairness of those systems. Since these systems are part of several applications today, some more critical than others, it urges designers to detect and mitigate any sources of bias. In this thesis, we begin by clarifying the confusion between face analytic, face recognition, and face processing systems. Then, we analyze gender classification accuracy using two datasets and three classifiers. The Pilot Parliaments Benchmark dataset is examined with an open-source algorithm to corroborate the gender shade. Secondly, the Morph …
Privacy-Preserving Cloud-Assisted Data Analytics, Wei Bao
Privacy-Preserving Cloud-Assisted Data Analytics, Wei Bao
Graduate Theses and Dissertations
Nowadays industries are collecting a massive and exponentially growing amount of data that can be utilized to extract useful insights for improving various aspects of our life. Data analytics (e.g., via the use of machine learning) has been extensively applied to make important decisions in various real world applications. However, it is challenging for resource-limited clients to analyze their data in an efficient way when its scale is large. Additionally, the data resources are increasingly distributed among different owners. Nonetheless, users' data may contain private information that needs to be protected.
Cloud computing has become more and more popular in …
Rnnrepair: Automatic Rnn Repair Via Model-Based Analysis, Xiaofei Xie, Wenbo Guo, Lei Ma, Wei Le, Jian Wang, Lingjun Zhou, Yang Liu, Xinyu Xing
Rnnrepair: Automatic Rnn Repair Via Model-Based Analysis, Xiaofei Xie, Wenbo Guo, Lei Ma, Wei Le, Jian Wang, Lingjun Zhou, Yang Liu, Xinyu Xing
Research Collection School Of Computing and Information Systems
Deep neural networks are vulnerable to adversarial attacks. Due to their black-box nature, it is rather challenging to interpret and properly repair these incorrect behaviors. This paper focuses on interpreting and repairing the incorrect behaviors of Recurrent Neural Networks (RNNs). We propose a lightweight model-based approach (RNNRepair) to help understand and repair incorrect behaviors of an RNN. Specifically, we build an influence model to characterize the stateful and statistical behaviors of an RNN over all the training data and to perform the influence analysis for the errors. Compared with the existing techniques on influence function, our method can efficiently estimate …
Design And Development Of Techniques To Ensure Integrity In Fog Computing Based Databases, Abdulwahab Fahad S. Alazeb
Design And Development Of Techniques To Ensure Integrity In Fog Computing Based Databases, Abdulwahab Fahad S. Alazeb
Graduate Theses and Dissertations
The advancement of information technology in coming years will bring significant changes to the way sensitive data is processed. But the volume of generated data is rapidly growing worldwide. Technologies such as cloud computing, fog computing, and the Internet of things (IoT) will offer business service providers and consumers opportunities to obtain effective and efficient services as well as enhance their experiences and services; increased availability and higher-quality services via real-time data processing augment the potential for technology to add value to everyday experiences. This improves human life quality and easiness. As promising as these technological innovations, they are prone …
Development Of A Reference Design For Intrusion Detection Using Neural Networks For A Smart Inverter, Ammar Mohammad Khan
Development Of A Reference Design For Intrusion Detection Using Neural Networks For A Smart Inverter, Ammar Mohammad Khan
Graduate Theses and Dissertations
The purpose of this thesis is to develop a reference design for a base level implementation of an intrusion detection module using artificial neural networks that is deployed onto an inverter and runs on live data for cybersecurity purposes, leveraging the latest deep learning algorithms and tools. Cybersecurity in the smart grid industry focuses on maintaining optimal standards of security in the system and a key component of this is being able to detect cyberattacks. Although researchers and engineers aim to design such devices with embedded security, attacks can and do still occur. The foundation for eventually mitigating these attacks …
Quantifying Cyber Risk By Integrating Attack Graph And Impact Graph, Omer F. Keskin
Quantifying Cyber Risk By Integrating Attack Graph And Impact Graph, Omer F. Keskin
Engineering Management & Systems Engineering Theses & Dissertations
Being a relatively new risk source, models to quantify cyber risks are not well developed; therefore, cyber risk management in most businesses depends on qualitative assessments. With the increase in the economic consequences of cyber incidents, the importance of quantifying cyber risks has increased. Cyber risk quantification is also needed to establish communication among decision-makers of different levels of an enterprise, from technical personnel to top management.
The goal of this research is to build a probabilistic cybersecurity risk analysis model that relates attack propagation with impact propagation through internal dependencies and allows temporal analysis.
The contributions of the developed …
Strengthening Criteria Independence Through Optimization Of Alternative Value Ratio Comparisons, Joseph P. Kristbaum, Frank W. Ciarallo
Strengthening Criteria Independence Through Optimization Of Alternative Value Ratio Comparisons, Joseph P. Kristbaum, Frank W. Ciarallo
Faculty Publications
Every decision maker’s internal scale is different based on a myriad of possible factors unique to that decision maker. Conflicting criteria within and between alternatives in multicriteria decision making can create negative effects within the weighting schemes and amplify preference biases and scale disparities between decision makers in a group decision context. Additionally, the weighting of group decision-making frameworks can intensify the already skewed criteria values. When making judgments against requirements, it may be preferable to reduce scale trend distortions between decision makers as much as possible. Previous research supports that certain information presentation modes can significantly reduce preference bias …
Understanding Ransomware Trajectory To Create An Informed Prediction, J. D. Klusnick
Understanding Ransomware Trajectory To Create An Informed Prediction, J. D. Klusnick
University Honors Theses
Ransomware is a form of extortion in which digital files are rendered inaccessible until a ransom payment is made. Modern ransomware emerged in 2006 and its destructive influence has been expanding ever since. In recent years cybercriminals have evolved who they target, what computer systems they target, and how they infect those systems. Meanwhile, cybersecurity experts have modelled ransomware methods allowing them to innovate their defense techniques across three paradigms: recovery, detection, and prevention. Ultimately either ransomware attackers or ransomware defenders will dominate this ongoing conflict. A review of the literature indicates that the ransomware crime wave will likely be …
Windows Kernel Hijacking Is Not An Option: Memoryranger Comes To The Rescue Again, Igor Korkin
Windows Kernel Hijacking Is Not An Option: Memoryranger Comes To The Rescue Again, Igor Korkin
Journal of Digital Forensics, Security and Law
The security of a computer system depends on OS kernel protection. It is crucial to reveal and inspect new attacks on kernel data, as these are used by hackers. The purpose of this paper is to continue research into attacks on dynamically allocated data in the Windows OS kernel and demonstrate the capacity of MemoryRanger to prevent these attacks. This paper discusses three new hijacking attacks on kernel data, which are based on bypassing OS security mechanisms. The first two hijacking attacks result in illegal access to files open in exclusive access. The third attack escalates process privileges, without applying …
A Method For Comparative Analysis Of Trusted Execution Environments, Stephano Cetola
A Method For Comparative Analysis Of Trusted Execution Environments, Stephano Cetola
Dissertations and Theses
The problem of secure remote computation has become a serious concern of hardware manufacturers and software developers alike. Trusted Execution Environments (TEEs) are a solution to the problem of secure remote computation in applications ranging from "chip and pin" financial transactions to intellectual property protection in modern gaming systems. While extensive literature has been published about many of these technologies, there exists no current model for comparing TEEs. This thesis provides hardware architects and designers with a set of tools for comparing TEEs. I do so by examining several properties of a TEE and comparing their implementations in several technologies. …
Deterring Intellectual Property Thieves: Algorithmic Generation Of Adversary-Aware Fake Knowledge Graphs, Snow Kang
Dartmouth College Undergraduate Theses
Publicly available estimates suggest that in the U.S. alone, IP theft costs our economy between $225 billion and $600 billion each year. In our paper, we propose combating IP theft by generating fake versions of technical documents. If an enterprise system has n fake documents for each real document, any IP thief must sift through an array of documents in an attempt to separate the original from a sea of fakes. This costs the attacker time and money - and inflicts pain and frustration on the part of its technical staff.
Leveraging a graph-theoretic approach, we created the Clique-FakeKG algorithm …
Capstone Case Study Guide Mapfre, Apoorva Arbooj, Ahamad Waqas, K C Prabhat, Manju Jayam, Rashmi Sakleshpur Rajashekar
Capstone Case Study Guide Mapfre, Apoorva Arbooj, Ahamad Waqas, K C Prabhat, Manju Jayam, Rashmi Sakleshpur Rajashekar
School of Professional Studies
Mapfre is a Top-Notch insurer and a competitive and fast-evolving insurance company. Clark team will help Mapfre to organize to secure systems availability and resilience to support the business process. Assist and recommend the IT team for further analysis and identify data, trends, and patterns and come up with to improve the services
How Social Media And Embedded Recommender Algorithm Fostered Political Issues, Yan Shi
How Social Media And Embedded Recommender Algorithm Fostered Political Issues, Yan Shi
School of Professional Studies
Social media plays a significant role in social communication and interaction, connecting people from different continents and facilitating information flaws worldwide. Meanwhile, along with the evolution of embedded recommender algorithms that clustering people with similar demographic features, social media has become the most important means of communication for modern society. However, the prosper of interconnecting platforms also have potential flows alongside. One of the major issues is the unexpected political consequence. This paper delivers the first comprehensive analysis of the political impacts posed by social media and embedded recommending algorithms. The article identifies three major political concerns through literature review, …
Efficient Attribute-Based Encryption With Repeated Attributes Optimization, Fawad Khan, Hui Li, Yinghui Zhang, Haider Abbas, Tahreem Yaqoob
Efficient Attribute-Based Encryption With Repeated Attributes Optimization, Fawad Khan, Hui Li, Yinghui Zhang, Haider Abbas, Tahreem Yaqoob
Research Collection School Of Computing and Information Systems
Internet of Things (IoT) is an integration of various technologies to provide technological enhancements. To enforce access control on low power operated battery constrained devices is a challenging issue in IoT scenarios. Attribute-based encryption (ABE) has emerged as an access control mechanism to allow users to encrypt and decrypt data based on an attributes policy. However, to accommodate the expressiveness of policy for practical application scenarios, attributes may be repeated in a policy. For certain policies, the attributes repetition cannot be avoided even after applying the boolean optimization techniques to attain an equivalent smaller length boolean formula. For such policies, …
Ultrapin: Inferring Pin Entries Via Ultrasound, Liu, Ximing, Robert H. Deng, Robert H. Deng
Ultrapin: Inferring Pin Entries Via Ultrasound, Liu, Ximing, Robert H. Deng, Robert H. Deng
Research Collection School Of Computing and Information Systems
While PIN-based user authentication systems such as ATM have long been considered to be secure enough, they are facing new attacks, named UltraPIN, which can be launched from commodity smartphones. As a target user enters a PIN on a PIN-based user authentication system, an attacker may use UltraPIN to infer the PIN from a short distance (50 cm to 100 cm). In this process, UltraPIN leverages smartphone speakers to issue human-inaudible ultrasound signals and uses smartphone microphones to keep recording acoustic signals. It applies a series of signal processing techniques to extract high-quality feature vectors from low-energy and high-noise signals …
Non-Equivocation In Blockchain: Double-Authentication-Preventing Signatures Gone Contractual, Yannan Li, Willy Susilo, Guomin Yang, Yong Yu, Tran Viet Xuan Phuong, Dongxi Liu
Non-Equivocation In Blockchain: Double-Authentication-Preventing Signatures Gone Contractual, Yannan Li, Willy Susilo, Guomin Yang, Yong Yu, Tran Viet Xuan Phuong, Dongxi Liu
Research Collection School Of Computing and Information Systems
Equivocation is one of the most fundamental problems that need to be solved when designing distributed protocols. Traditional methods to defeat equivocation rely on trusted hardware or particular assumptions, which may hinder their adoption in practice. The advent of blockchain and decentralized cryptocurrencies provides an auspicious breakthrough paradigm to resolve the problem above. In this paper, we propose a blockchain-based solution to address contractual equivocation, which supports user-defined fine-grained policybased equivocation. Specifically, users will be de-incentive if the statements they made breach the predefined access rules. The core of our solution is a newly introduced primitive named Policy-Authentication-Preventing Signature (PoAPS), …
Lattice-Based Remote User Authentication From Reusable Fuzzy Signature, Yangguang Tian, Yingjiu Li, Robert H. Deng, Binanda Sengupta, Guomin Yang
Lattice-Based Remote User Authentication From Reusable Fuzzy Signature, Yangguang Tian, Yingjiu Li, Robert H. Deng, Binanda Sengupta, Guomin Yang
Research Collection School Of Computing and Information Systems
In this paper, we introduce a new construction of reusable fuzzy signature based remote user authentication that is secure against quantum computers. We investigate the reusability of fuzzy signature, and we prove that the fuzzy signature schemes provide biometrics reusability (aka. reusable fuzzy signature). We define formal security models for the proposed construction, and we prove that it achieves user authenticity and user privacy. The proposed construction ensures: 1) a user’s biometrics can be securely reused in remote user authentication; 2) a third party having access to the communication channel between a user and the authentication server cannot identify the …
Secure Repackage-Proofing Framework For Android Apps Using Collatz Conjecture, Haoyu Ma, Shijia Li, Debin Gao, Chunfu Jia
Secure Repackage-Proofing Framework For Android Apps Using Collatz Conjecture, Haoyu Ma, Shijia Li, Debin Gao, Chunfu Jia
Research Collection School Of Computing and Information Systems
App repackaging has been raising serious concerns about the health of the Android ecosystem, and repackage-proofing is an important mitigation against threat of such attacks. However, existing app repackage-proofing schemes were only evaluated against trivial adversaries simulated using analyzers for other purposes (e.g., disclosing privacy leakage vulnerabilities), hence were shown “effective” mainly because their key programming features were not even supported by those toolkits. Furthermore, existing works have also neglected dynamic adversaries capable of manipulating victim apps at runtime, making them vulnerable against such stronger opponents. In this paper, we propose a novel repackage-proofing framework, which deploys distributed detection and …
Catch You With Cache: Out-Of-Vm Introspection To Trace Malicious Executions, Chao Su, Xuhua Ding, Qinghai Zeng
Catch You With Cache: Out-Of-Vm Introspection To Trace Malicious Executions, Chao Su, Xuhua Ding, Qinghai Zeng
Research Collection School Of Computing and Information Systems
Out-of-VM introspection is an imperative part of security analysis. The legacy methods either modify the system, introducing enormous overhead, or rely heavily on hardware features, which are neither available nor practical in most cloud environments. In this paper, we propose a novel analysis method, named as Catcher, that utilizes CPU cache to perform out-of-VM introspection. Catcher does not make any modifications to the target program and its running environment, nor demands special hardware support. Implemented upon Linux KVM, it natively introspects the target's virtual memory. More importantly, it uses the cache-based side channel to infer the target control flow. To …
Expressive Bilateral Access Control For Internet-Of-Things In Cloud-Fog Computing, Shengmin Xu, Jianting Ning, Jinhua Ma, Xinyi Huang, Hwee Hwa Pang, Robert H. Deng
Expressive Bilateral Access Control For Internet-Of-Things In Cloud-Fog Computing, Shengmin Xu, Jianting Ning, Jinhua Ma, Xinyi Huang, Hwee Hwa Pang, Robert H. Deng
Research Collection School Of Computing and Information Systems
As a versatile system architecture, cloud-fog Internet-of-Things (IoT) enables multiple resource-constrained devices to communicate and collaborate with each other. By outsourcing local data and immigrating expensive workloads to cloud service providers and fog nodes (FNs), resource-constrained devices can enjoy data services with low latency and minimal cost. To protect data security and privacy in the untrusted cloud-fog environment, many cryptographic mechanisms have been invented. Unfortunately, most of them are impractical when directly applied to cloud-fog IoT computing, mainly due to the large number of resource-constrained end-devices (EDs). In this paper, we present a secure cloud-fog IoT data sharing system with …
When Program Analysis Meets Bytecode Search: Targeted And Efficient Inter-Procedural Analysis Of Modern Android Apps In Backdroid, Daoyuan Wu, Debin Gao, Robert H. Deng, Rocky Chang
When Program Analysis Meets Bytecode Search: Targeted And Efficient Inter-Procedural Analysis Of Modern Android Apps In Backdroid, Daoyuan Wu, Debin Gao, Robert H. Deng, Rocky Chang
Research Collection School Of Computing and Information Systems
Widely-used Android static program analysis tools,e.g., Amandroid and FlowDroid, perform the whole-app interprocedural analysis that is comprehensive but fundamentallydifficult to handle modern (large) apps. The average app size hasincreased three to four times over five years. In this paper, weexplore a new paradigm of targeted inter-procedural analysis thatcan skip irrelevant code and focus only on the flows of securitysensitive sink APIs. To this end, we propose a technique calledon-the-fly bytecode search, which searches the disassembled appbytecode text just in time when a caller needs to be located. In thisway, it guides targeted (and backward) inter-procedural analysisstep by step until reaching …