Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (443)
- Information Security (181)
- Artificial Intelligence and Robotics (137)
- Electrical and Computer Engineering (129)
- Software Engineering (124)
-
- Computer Engineering (114)
- Graphics and Human Computer Interfaces (98)
- Operations Research, Systems Engineering and Industrial Engineering (97)
- Theory and Algorithms (95)
- Databases and Information Systems (61)
- Aerospace Engineering (60)
- Signal Processing (58)
- Digital Communications and Networking (54)
- Operational Research (39)
- Business (35)
- Aviation (29)
- Physics (29)
- Electrical and Electronics (25)
- Navigation, Guidance, Control and Dynamics (25)
- Other Operations Research, Systems Engineering and Industrial Engineering (23)
- Social and Behavioral Sciences (23)
- OS and Networks (21)
- Cybersecurity (18)
- Systems Engineering (18)
- Systems Architecture (17)
- Applied Mathematics (16)
- Computer and Systems Architecture (16)
- Optics (16)
- Keyword
-
- #antcenter (75)
- Machine learning (70)
- Computer networks--Security measures (47)
- Computer security (45)
- Software engineering (44)
-
- Artificial intelligence (30)
- Object-oriented programming (Computer science) (27)
- Neural networks (Computer science) (24)
- Algorithms (23)
- Virtual reality (21)
- Genetic algorithms (20)
- Computer simulation (19)
- Deep learning (19)
- Expert systems (Computer science) (19)
- Intelligent agents (Computer software) (19)
- Cybersecurity (17)
- Ada (Computer program language) (16)
- Computer vision (16)
- Neural networks (16)
- Object-oriented databases (16)
- Center_CCR (15)
- Parallel processing (Electronic computers) (15)
- Wireless communication systems (15)
- Data protection (14)
- Image processing (14)
- Reverse engineering (14)
- Computer graphics (12)
- Computer network protocols (12)
- Computer viruses (12)
- Decision making (11)
- Publication Year
- Publication
- Publication Type
- File Type
Articles 511 - 540 of 1277
Full-Text Articles in Computer Sciences
Towards Quantifying Programmable Logic Controller Resilience Against Intentional Exploits, Henry W. Bushey
Towards Quantifying Programmable Logic Controller Resilience Against Intentional Exploits, Henry W. Bushey
Theses and Dissertations
Supervisory Control and Data Acquisition (SCADA) systems control and monitor services for the nation's critical infrastructure. Recent cyber induced events (e.g., Stuxnet) provide an example of a targeted, covert cyber attack against a SCADA system that resulted in physical effects. Of particular note is how Stuxnet exploited the trust relationship between the human machine interface (HMI) and programmable logic controllers (PLCs). Current methods for validating system operating parameters rely on message exchange and network communications protocols, generally observed at the HMI. Although sufficient at the macro level, this method does not provide detection of malware that exhibits physical effects via …
Binary Disassembly Block Coverage By Symbolic Execution Vs. Recursive Descent, Jonathan D. Miller
Binary Disassembly Block Coverage By Symbolic Execution Vs. Recursive Descent, Jonathan D. Miller
Theses and Dissertations
This research determines how appropriate symbolic execution is (given its current implementation) for binary analysis by measuring how much of an executable symbolic execution allows an analyst to reason about. Using the S2E Selective Symbolic Execution Engine with a built-in constraint solver (KLEE), this research measures the effectiveness of S2E on a sample of 27 Debian Linux binaries as compared to a traditional static disassembly tool, IDA Pro. Disassembly code coverage and path exploration is used as a metric for determining success. This research also explores the effectiveness of symbolic execution on packed or obfuscated samples of the same binaries …
Context Aware Routing Management Architecture For Airborne Networks, Joan A. Betances
Context Aware Routing Management Architecture For Airborne Networks, Joan A. Betances
Theses and Dissertations
This thesis advocates the use of Kalman filters in conjunction with network topology information derived from the Air Tasking Order (ATO) during the planning phase for military missions. This approach is the basis for an algorithm that implements network controls that optimize network performance for Mobile Ad hoc Networks (MANET). The trajectories of relevant nodes (airborne platforms) participating in the MANET can be forecasted by parsing key information contained in the ATO. This information is used to develop optimum network routes that can significantly improve MANET performance. Improved MANET performance in the battlefield enables decision makers to access information from …
3-D Scene Reconstruction From Aerial Imagery, Jared M. Ekholm
3-D Scene Reconstruction From Aerial Imagery, Jared M. Ekholm
Theses and Dissertations
3-D scene reconstructions derived from Structure from Motion (SfM) and Multi-View Stereo (MVS) techniques were analyzed to determine the optimal reconnaissance flight characteristics suitable for target reconstruction. In support of this goal, a preliminary study of a simple 3-D geometric object facilitated the analysis of convergence angles and number of camera frames within a controlled environment. Reconstruction accuracy measurements revealed at least 3 camera frames and a 6 convergence angle were required to achieve results reminiscent of the original structure. The central investigative effort sought the applicability of certain airborne reconnaissance flight profiles to reconstructing ground targets. The data sets …
Malware Target Recognition Via Static Heuristics, Thomas E. Dube, Richard A. Raines, Gilbert L. Peterson, Kenneth W. Bauer, Michael R. Grimaila, Steven K. Rogers
Malware Target Recognition Via Static Heuristics, Thomas E. Dube, Richard A. Raines, Gilbert L. Peterson, Kenneth W. Bauer, Michael R. Grimaila, Steven K. Rogers
Faculty Publications
Organizations increasingly rely on the confidentiality, integrity and availability of their information and communications technologies to conduct effective business operations while maintaining their competitive edge. Exploitation of these networks via the introduction of undetected malware ultimately degrades their competitive edge, while taking advantage of limited network visibility and the high cost of analyzing massive numbers of programs. This article introduces the novel Malware Target Recognition (MaTR) system which combines the decision tree machine learning algorithm with static heuristic features for malware detection. By focusing on contextually important static heuristic features, this research demonstrates superior detection results. Experimental results on large …
Stereoscopic Display System With Flexible Rendering Of Disparity Map According To The Stereoscopic Fusing Capability Of The Observer, Elaine W. Jin, Michael E. Miller, Serguei Endrikhovski, Cathleen D. Cerosaletti
Stereoscopic Display System With Flexible Rendering Of Disparity Map According To The Stereoscopic Fusing Capability Of The Observer, Elaine W. Jin, Michael E. Miller, Serguei Endrikhovski, Cathleen D. Cerosaletti
AFIT Patents
A method is provided for customizing scene content, according to a user or a cluster of users, for a given stereoscopic display, including obtaining customization information about the user; obtaining a scene disparity map for a pair of given stereo images and/or a three-dimensional (3D) computer graphic model; and determining an aim disparity range for the user. The method of the present invention also generates a customized disparity map and/or rendering conditions for a three-dimensional (3D) computer graphic model correlating with the user's fusing capability of the given stereoscopic display; and renders or re-renders the stereo images for subsequent display.
Acquiring Os X File Handles Through Forensic Memory Analysis, Andrew F. Hay, Gilbert L. Peterson
Acquiring Os X File Handles Through Forensic Memory Analysis, Andrew F. Hay, Gilbert L. Peterson
Faculty Publications
Memory analysis has become a critical capability in digital forensics because it provides insight into system state that cannot be fully represented through traditional media analysis. The volafox open source project has begun the work of structured memory analysis for OS X with support for a limited set of kernel structures. This paper addresses one memory analysis deficiency on OS X with the introduction of a new volafox module for parsing file handles associated with running processes. The developed module outputs information comparable to the UNIX lsof (list open files) command, which is used to validate the results.
Flexible Multitouch Electroluminescent Display, Michael E. Miller, John W. Harmer
Flexible Multitouch Electroluminescent Display, Michael E. Miller, John W. Harmer
AFIT Patents
A display device including a touch sensitive EL display having a flexible substrate; one or more power busses and one or more EL elements disposed over the flexible substrate; and a plurality of distributed chiplets arranged so that at least two chiplets are associated with each of a plurality of touch sensitive areas on the EL display and for sensing stress or strain associated with bending of the flexible substrate or the chiplet substrate to provide respective displacement signals corresponding to the touch sensitive areas; each chiplet connected to one or more of the power busses and one or more …
Windows Driver Memory Analysis: A Reverse Engineering Methodology, James S. Okolica, Gilbert L. Peterson
Windows Driver Memory Analysis: A Reverse Engineering Methodology, James S. Okolica, Gilbert L. Peterson
Faculty Publications
In a digital forensics examination, the capture and analysis of volatile data provides significant information on the state of the computer at the time of seizure. Memory analysis is a premier method of discovering volatile digital forensic information. While much work has been done in extracting forensic artifacts from Windows kernel structures, less focus has been paid to extracting information from Windows drivers. There are two reasons for this: (1) source code for one version of the Windows kernel (but not associated drivers) is available for educational use and (2) drivers are generally called asynchronously and contain no exported functions. …
An Empirical Analysis Of The Cascade Error Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver, Michael R. Grimaila, Jeffrey W. Humphries
An Empirical Analysis Of The Cascade Error Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver, Michael R. Grimaila, Jeffrey W. Humphries
Faculty Publications
Modern cryptography provides the means to securely communicate data between authorized entities by using mathematical transformations which require pre-shared cryptographic keys. The need to share key material with authorized entities in a secure, cost efficient and timely manner has driven efforts to develop new key distribution methods. A promising method is Quantum Key Distribution (QKD) which is considered to be “unconditionally secure” because it relies upon the immutable laws of quantum physics rather than computational complexity as the basis for its security. An important component of any QKD system is the error reconciliation protocol which is used to identify and …
A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube
A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube
Theses and Dissertations
The rapid transition of critical business processes to computer networks potentially exposes organizations to digital theft or corruption by advanced competitors. One tool used for these tasks is malware, because it circumvents legitimate authentication mechanisms. Malware is an epidemic problem for organizations of all types. This research proposes and evaluates a novel Malware Target Recognition (MaTR) architecture for malware detection and identification of propagation methods and payloads to enhance situation awareness in tactical scenarios using non-instruction-based, static heuristic features. MaTR achieves a 99.92% detection accuracy on known malware with false positive and false negative rates of 8.73e-4 and 8.03e-4 respectively. …
Detecting Man-In-The-Middle Attacks Against Transport Layer Security Connections With Timing Analysis, Lauren M. Wagoner
Detecting Man-In-The-Middle Attacks Against Transport Layer Security Connections With Timing Analysis, Lauren M. Wagoner
Theses and Dissertations
The Transport Layer Security (TLS) protocol is a vital component to the protection of data as it traverses across networks. From e-commerce websites to Virtual Private Networks (VPNs), TLS protects massive amounts of private information, and protecting this data from Man-in-the-Middle (MitM) attacks is imperative to keeping the information secure. This thesis illustrates how an attacker can successfully perform a MitM attack against a TLS connection without alerting the user to his activities. By deceiving the client machine into using a false certificate, an attacker takes away the only active defense mechanism a user has against a MitM. The goal …
An Empirical Analysis Of The Cascade Secret Key Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver
An Empirical Analysis Of The Cascade Secret Key Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver
Theses and Dissertations
The need to share key material with authorized entities in a secure, efficient and timely manner has driven efforts to develop new key distribution methods. The most promising method is Quantum Key Distribution (QKD) and is considered to be “unconditionally secure” because it relies upon the immutable laws of quantum physics rather than computational complexity. Unfortunately, the nonidealities present in actual implementations of QKD systems also result in errors manifested in the quantum data channel. As a consequence, an important component of any QKD system is the error reconciliation protocol which is used to identify and correct inconsistencies in the …
Improving Occupancy Grid Fastslam By Integrating Navigation Sensors, Christopher Weyers, Gilbert L. Peterson
Improving Occupancy Grid Fastslam By Integrating Navigation Sensors, Christopher Weyers, Gilbert L. Peterson
Faculty Publications
When an autonomous vehicle operates in an unknown environment, it must remember the locations of environmental objects and use those object to maintain an accurate location of itself. This vehicle is faced with Simultaneous Localization and Mapping (SLAM), a circularly defined robotics problem of map building with no prior knowledge. The SLAM problem is a difficult but critical component of autonomous vehicle exploration with applications to search and rescue missions. This paper presents the first SLAM solution combining stereo cameras, inertial measurements, and vehicle odometry into a Multiple Integrated Navigation Sensor (MINS) path. The FastSLAM algorithm, modified to make use …
Extracting Forensic Artifacts From Windows O/S Memory, James S. Okolica, Gilbert L. Peterson
Extracting Forensic Artifacts From Windows O/S Memory, James S. Okolica, Gilbert L. Peterson
AFIT Documents
Memory analysis is a rapidly growing area in both digital forensics and cyber situational awareness (SA). Memory provides the most accurate snapshot of what is occurring on a computer at a moment in time. By combining it with event and network logs as well as the files present on the filesystem, an analyst can re-create much of what has occurred and is occuring on a computer. The Compiled Memory Analysis Tool (CMAT) takes either a disk image of memory from a Windows operating system or an interface into a virtual machine running a Windows operating system and extracts forensic artifacts …
Extracting The Windows Clipboard From Physical Memory, James S. Okolica, Gilbert L. Peterson
Extracting The Windows Clipboard From Physical Memory, James S. Okolica, Gilbert L. Peterson
Faculty Publications
When attempting to reconstruct the events leading up to a cyber security incident, one potentially important piece of information is the clipboard (Prosise et al., 2003). The clipboard has been present in Windows since Windows 3.1 and is the mechanism for transferring information from one application to another through copy and pasting actions. Being able to retrieve the last file copied or the last password used may provide investigators with invaluable information during a forensic investigation. This paper describes the Windows clipboard structure and the process of retrieving copy/paste information from Windows XP, Vista, and Windows 7 (both 32 bit …
Combinational Circuit Obfuscation Through Power Signature Manipulation, Hyunchul Ko
Combinational Circuit Obfuscation Through Power Signature Manipulation, Hyunchul Ko
Theses and Dissertations
Today's military systems are composed of hardware and software systems, many of which are critical technologies, and must be protected to ensure our adversaries cannot gain any information from a various analysis attacks. Side Channel Analysis (SCA) attacks allow an attacker to gain the significant information from the measured signatures leaked by side-channels such as power consumption, and electro-magnetic emission. In this research the focus on detecting, characterizing, and manipulating the power signature by designing a power signature estimation and manipulation method. This research has determined that the proposed method capable of characterizing and altering the type of power signature …
Estimating Anthropometric Marker Locations From 3-D Ladar Point Clouds, Matthew J. Maier
Estimating Anthropometric Marker Locations From 3-D Ladar Point Clouds, Matthew J. Maier
Theses and Dissertations
An area of interest for improving the identification portion of the system is in extracting anthropometric markers from a Laser Detection and Ranging (LADAR) point cloud. Analyzing anthropometrics markers is a common means of studying how a human moves and has been shown to provide good results in determining certain demographic information about the subject. This research examines a marker extraction method utilizing principal component analysis (PCA), self-organizing maps (SOM), alpha hulls, and basic anthropometric knowledge. The performance of the extraction algorithm is tested by performing gender classification with the calculated markers.
Wolf Ant, Gilbert L. Peterson, Christopher M. Mayer, Kevin Cousin
Wolf Ant, Gilbert L. Peterson, Christopher M. Mayer, Kevin Cousin
Faculty Publications
Ant colony optimization (ACO) algorithms can generate quality solutions to combinatorial optimization problems. However, like many stochastic algorithms, the quality of solutions worsen as problem sizes grow. In an effort to increase performance, we added the variable step size off-policy hill-climbing algorithm called PDWoLF (Policy Dynamics Win or Learn Fast) to several ant colony algorithms: Ant System, Ant Colony System, Elitist-Ant System, Rank-based Ant System, and Max-Min Ant System. Easily integrated into each ACO algorithm, the PDWoLF component maintains a set of policies separate from the ant colony's pheromone. Similar to pheromone but with different update rules, the PDWoLF policies …
Passive Matrix Electro-Luminescent Display System, Michael E. Miller, John F. Hamilton Jr., Andrew D. Arnold
Passive Matrix Electro-Luminescent Display System, Michael E. Miller, John F. Hamilton Jr., Andrew D. Arnold
AFIT Patents
A passive matrix, electro-luminescent display system has a passive matrix, electro-luminescent display having an orthogonally oriented array of column and row electrodes and an electro-luminescent layer located between the electrodes at the intersection of each column and row electrode forming an individual light-emitting element. Drivers provide separate signals at different times to different groups of row electrodes within the array of row electrodes; wherein the row electrodes of each group simultaneously receive at least two different level signals. A display driver receives and processes the input image signal to provide a presharpened image control signal. Column drivers respond to the …
War Fighting In Cyberspace: Evolving Force Presentation And Command And Control, M. Bodine Birdwell, Robert F. Mills
War Fighting In Cyberspace: Evolving Force Presentation And Command And Control, M. Bodine Birdwell, Robert F. Mills
Faculty Publications
The Department of Defense (DOD) is endeavoring to define war fighting in the global cyberspace domain. Creation of US Cyber Command (USCYBERCOM), a subunified functional combatant command (FCC) under US Strategic Command (USSTRATCOM), is a huge step in integrating and coordinating the defense, protection, and operation of DOD networks; however, this step does not mean that USCYBERCOM will perform or manage all cyberspace functions. In fact the vast majority of cyberspace functions conducted by the services and combatant commands (COCOM), although vital for maintaining access to the domain in support of their operations, are not of an active war-fighting nature. …
Software And Critical Technology Protection Against Side Channel Analysis Through Dynamic Hardware Obfuscation, John R. Bochert
Software And Critical Technology Protection Against Side Channel Analysis Through Dynamic Hardware Obfuscation, John R. Bochert
Theses and Dissertations
Side Channel Analysis (SCA) is a method by which an adversary can gather information about a processor by examining the activity being done on a microchip though the environment surrounding the chip. Side Channel Analysis attacks use SCA to attack a microcontroller when it is processing cryptographic code, and can allow an attacker to gain secret information, like a crypto-algorithm's key. The purpose of this thesis is to test proposed dynamic hardware methods to increase the hardware security of a microprocessor such that the software code being run on the microprocessor can be made more secure without having to change …
A Multi Agent System For Flow-Based Intrusion Detection Using Reputation And Evolutionary Computation, David Hancock
A Multi Agent System For Flow-Based Intrusion Detection Using Reputation And Evolutionary Computation, David Hancock
Theses and Dissertations
The rising sophistication of cyber threats as well as the improvement of physical computer network properties present increasing challenges to contemporary Intrusion Detection (ID) techniques. To respond to these challenges, a multi agent system (MAS) coupled with flow-based ID techniques may effectively complement traditional ID systems. This paper develops: 1) a scalable software architecture for a new, self-organized, multi agent, flow-based ID system; and 2) a network simulation environment suitable for evaluating implementations of this MAS architecture and for other research purposes. Self-organization is achieved via 1) a reputation system that influences agent mobility in the search for effective vantage …
Malicious And Malfunctioning Node Detection Via Observed Physical Layer Data, Tyler J. Hardy
Malicious And Malfunctioning Node Detection Via Observed Physical Layer Data, Tyler J. Hardy
Theses and Dissertations
There are many mechanisms that can cause inadequate or unreliable information in sensor networks. A user of the network might be interested in detecting and classifying specific sensors nodes causing these problems. Several network layer based trust methods have been developed in previous research to assess these issues; in contrast this work develops a trust protocol based on observations of physical layer data collected by the sensors. Observations of physical layer data are used for decisions and calculations, and are based on just the measurements collected by the sensors. Although this information is packaged and distributed on the network layer, …
Holistic Network Defense: Fusing Host And Network Features For Attack Classification, Jenny W. Ji
Holistic Network Defense: Fusing Host And Network Features For Attack Classification, Jenny W. Ji
Theses and Dissertations
This work presents a hybrid network-host monitoring strategy, which fuses data from both the network and the host to recognize malware infections. This work focuses on three categories: Normal, Scanning, and Infected. The network-host sensor fusion is accomplished by extracting 248 features from network traffic using the Fullstats Network Feature generator and from the host using text mining, looking at the frequency of the 500 most common strings and analyzing them as word vectors. Improvements to detection performance are made by synergistically fusing network features obtained from IP packet flows and host features, obtained from text mining port, processor, logon …
An Architecture For Improving Timeliness And Relevance Of Cyber Incident Notifications, James L. Miller
An Architecture For Improving Timeliness And Relevance Of Cyber Incident Notifications, James L. Miller
Theses and Dissertations
This research proposes a communications architecture to deliver timely and relevant cyber incident notifications to dependent mission stakeholders. This architecture, modeled in Unified Modeling Language (UML), eschews the traditional method of pushing notifications via message as dictated in Air Force Instruction 33-138. It instead shifts to a pull or publish and subscribe method of making notifications. Shifting this paradigm improves the notification process by empowering mission owners to identify those resources on which they depend for mission accomplishment, provides a direct conduit between providing and dependent mission owners for notifications when an incident occurs, and provides a shared representation for …
Evaluating Information Assurance Control Effectiveness On An Air Force Supervisory Control And Data Acquisition (Scada) System, Jason R. Nielsen
Evaluating Information Assurance Control Effectiveness On An Air Force Supervisory Control And Data Acquisition (Scada) System, Jason R. Nielsen
Theses and Dissertations
Supervisory Control and Data Acquisition (SCADA) systems are increasingly being connected to corporate networks which has dramatically expanded their attack surface to remote cyber attack. Adversaries are targeting these systems with increasing frequency and sophistication. This thesis seeks to answer the research question addressing which Information Assurance (IA) controls are most significant for network defenders and SCADA system managers/operators to focus on in order to increase the security of critical infrastructure systems against a Stuxnet-like cyber attack. This research applies the National Institute of Science and Technology (NIST) IA controls to an attack tree modeled on a remote Stuxnet-like cyber …
Defensive Cyber Battle Damage Assessment Through Attack Methodology Modeling, Ryan T. Ostler
Defensive Cyber Battle Damage Assessment Through Attack Methodology Modeling, Ryan T. Ostler
Theses and Dissertations
Due to the growing sophisticated capabilities of advanced persistent cyber threats, it is necessary to understand and accurately assess cyber attack damage to digital assets. This thesis proposes a Defensive Cyber Battle Damage Assessment (DCBDA) process which utilizes the comprehensive understanding of all possible cyber attack methodologies captured in a Cyber Attack Methodology Exhaustive List (CAMEL). This research proposes CAMEL to provide detailed knowledge of cyber attack actions, methods, capabilities, forensic evidence and evidence collection methods. This product is modeled as an attack tree called the Cyber Attack Methodology Attack Tree (CAMAT). The proposed DCBDA process uses CAMAT to analyze …
Android Protection System: A Signed Code Security Mechanism For Smartphone Applications, Jonathan D. Stueckle
Android Protection System: A Signed Code Security Mechanism For Smartphone Applications, Jonathan D. Stueckle
Theses and Dissertations
This research develops the Android Protection System (APS), a hardware-implemented application security mechanism on Android smartphones. APS uses a hash-based white-list approach to protect mobile devices from unapproved application execution. Functional testing confirms this implementation allows approved content to execute on the mobile device while blocking unapproved content. Performance benchmarking shows system overhead during application installation increases linearly as the application package size increases. APS presents no noticeable performance degradation during application execution. The security mechanism degrades system performance only during application installation, when users expect delay. APS is implemented within the default Android application installation process. Applications are hashed …
Kernelized Locality-Sensitive Hashing For Fast Image Landmark Association, Mark A. Weems
Kernelized Locality-Sensitive Hashing For Fast Image Landmark Association, Mark A. Weems
Theses and Dissertations
As the concept of war has evolved, navigation in urban environments where GPS may be degraded is increasingly becoming more important. Two existing solutions are vision-aided navigation and vision-based Simultaneous Localization and Mapping (SLAM). The problem, however, is that vision-based navigation techniques can require excessive amounts of memory and increased computational complexity resulting in a decrease in speed. This research focuses on techniques to improve such issues by speeding up and optimizing the data association process in vision-based SLAM. Specifically, this work studies the current methods that algorithms use to associate a current robot pose to that of one previously …