Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Articles 1 - 15 of 15

Full-Text Articles in Cybersecurity

Microarchitectural Malware Detection Via Translation Lookaside Buffer (Tlb) Events, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert Kabban, Jose R. Gutierrez Del Arroyo, Scott R. Graham Sep 2025

Microarchitectural Malware Detection Via Translation Lookaside Buffer (Tlb) Events, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert Kabban, Jose R. Gutierrez Del Arroyo, Scott R. Graham

Faculty Publications

Prior work has shown that Translation Lookaside Buffer (TLB) data contains valuable behavioral information. Many existing methodologies rely on timing features or focus solely on workload classification. In this study, we propose a novel approach to malware classification using only TLB-related Hardware Performance Counters (HPCs), explicitly excluding any dependence on timing features such as task execution duration or memory access timing. Our methodology evaluates whether TLB data alone, without any timing information, can effectively distinguish between malicious and benign programs. We test this across three classification scenarios: (1) A binary classification problem involving distinguishing malicious from benign tasks, (2) a …


Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez Del Arroyo, Tor J. Langehaug, Scott R. Graham Jun 2025

Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez Del Arroyo, Tor J. Langehaug, Scott R. Graham

Faculty Publications

The primary focus of modern Central Processing Unit (CPU) technologies is performance improvement, with security often considered a secondary concern. As a result, vulnerabilities within the system are overlooked. While significant research, both offensive and defensive, has been conducted on CPU caches, relatively little attention has been given to the Translation Lookaside Buffer (TLB) due to its perceived lack of data granularity. Prior studies have typically combined multiple Hardware Performance Counters (HPCs) or relied on timing analysis to extract meaningful insights. In contrast, this study introduces a novel methodology that leverages only TLB related HPCs for multi-task classification, without incorporating …


Evaluating Educational Benefits Of A Custom Cyber Game: ‘Hvac Attack!’, Jillian S. Valente Mar 2025

Evaluating Educational Benefits Of A Custom Cyber Game: ‘Hvac Attack!’, Jillian S. Valente

Theses and Dissertations

Cyber competition and conflict remain an enduring concern for the Department of Defense (DoD). Positive control of cyberspace is crucial across the vast diversity of military operations and supporting activities. Military members play an important role in cyber prevention, detection, and remediation, but most receive relatively little training outside of the annual Cyber Awareness Challenge. Particular career fields within the DoD may benefit from specialized training in cybersecurity, in particular the civil engineering (CE) community supporting critical infrastructure protection. Prior research has suggested that game-based learning (GBL) can be beneficial for teaching cyber concepts.


Evaluating A Military Digital Badging System Prototype, Benjamin T. Pederson Mar 2025

Evaluating A Military Digital Badging System Prototype, Benjamin T. Pederson

Theses and Dissertations

The Department of Defense is committed to developing and maintaining a highly skilled workforce capable of defending the United States and associated interests abroad. Digital badging systems, a form of micro-credentialing, offer a way to record service member competencies. By providing decision-makers with granular data, this technology could augment the military’s development of a highly skilled workforce, especially in technical career fields including cyber operations. Mixed-method data from thirty-six participants suggest that establishing a digital badging program could increase deterrence and operational effectiveness.


Jamming-Tolerant Low-Rate Wireless Personal Area Network For Detection Sensor Networks, Michael A. Eddy Mar 2025

Jamming-Tolerant Low-Rate Wireless Personal Area Network For Detection Sensor Networks, Michael A. Eddy

Theses and Dissertations

This research evaluates the impact of electronic warfare, particularly jamming, on an audio-based drone detection wireless sensor network (WSN) using Monte Carlo simulations. A six-node IEEE 802.15.4 network, with five edge nodes and a central sink, is tested against jamming probabilities ranging from 0-100% in 5% increments across 30 iterations per configuration. Results show that packet delivery ratio (PDR) degrades linearly at approximately 20% per jammed node, while detection performance often exceeds PDR. Even at 80% jamming, detection success rates remain above 57%, highlighting resilience despite network degradation. The study reveals that jamming effectiveness depends on node placement relative to …


Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira Dec 2024

Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira

Theses and Dissertations

Embedded systems are vital in civilian and military applications, requiring high performance and security. The open RISC-V Instruction Set Architecture (ISA) offers significant advantages, including security through community review and strategic independence in microchip supplies. Brazil’s recent partnership with RISC-V highlights its potential for national technological sovereignty. However, RISC-V is not inherently resistant to code reuse attacks (CRAs), highlighting the need to integrate security measures early in development. The RISC-V Compressed extension, while beneficial for optimizing performance and code flexibility, introduces security trade-offs. As RISC-V adoption grows, particularly in critical systems, addressing these security challenges from the start is crucial …


Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson Mar 2024

Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson

Theses and Dissertations

National level attention, resources, and priority regarding critical infrastructure have increased in recent years. This has led to adversaries and defenders exchanging positions between fortification and exploitation. One area that continues to be vulnerable is supply chain attacks like counterfeit insertion. This work investigates the application of converting collected signals into images from devices that may be considered for these critical networks. There are several aspects regarding the conversion of signals into images - specifically Red, Green, Blue (RGB) images. The methodology proposed here is potentially ideal fit for an initial security layer by achieving comparable classification results as more …


Intel Total Memory Encryption: Functional Verification And Performance Analysis, Tallas T. S. Goo Mar 2023

Intel Total Memory Encryption: Functional Verification And Performance Analysis, Tallas T. S. Goo

Theses and Dissertations

While more attention is generally focused on software security, computer hardware security remains an important effort. Should an attacker gain direct physical access, computers with little to no hardware security can quickly be compromised via a manner of methods. One such attacker method is to steal information directly from the active memory of a locked, powered-on computer. To counter this attack, a hardware security method was developed called memory encryption. Memory encryption, as the name suggests, protects against adversary methods like cold boot attacks by encrypting all of memory. This research evaluates the efficacy and performance specifically of Intel TME. …


Using Timing-Based Side Channels For Anomaly Detection In Industrial Control Systems, Stephen Dunlap, Jonathan W. Butts, Juan L. Lopez Jr., Mason J. Rice, Barry E. Mullins Nov 2016

Using Timing-Based Side Channels For Anomaly Detection In Industrial Control Systems, Stephen Dunlap, Jonathan W. Butts, Juan L. Lopez Jr., Mason J. Rice, Barry E. Mullins

Faculty Publications

The critical infrastructure, which includes the electric power grid, railroads and water treatment facilities, is dependent on the proper operation of industrial control systems. However, malware such as Stuxnet has demonstrated the ability to alter industrial control system parameters to create physical effects. Of particular concern is malware that targets embedded devices that monitor and control system functionality, while masking the actions from plant operators and security analysts. Indeed, system security relies on guarantees that the assurance of these devices can be maintained throughout their lifetimes. This paper presents a novel approach that uses timing-based side channel analysis to establish …


Pointing Analysis And Design Drivers For Low Earth Orbit Satellite Quantum Key Distribution, Jeremiah A. Specht Mar 2016

Pointing Analysis And Design Drivers For Low Earth Orbit Satellite Quantum Key Distribution, Jeremiah A. Specht

Theses and Dissertations

The world relies on encryption to perform critical and sensitive tasks every day. If quantum computing matures, the capability to decode keys and decrypt messages becomes possible. Quantum key distribution (QKD) is a method of distributing secure cryptographic keys which relies on the laws of quantum mechanics. Current implementations of QKD use fiber-based channels which limit the number of users and the distance between users. Satellite-based QKD using free-space channels is proposed as a feasible secure global communication solution. Since a free-space link does not use a waveguide, pointing a transmitter to receiver is required to ensure signal arrival. In …


Git As An Encrypted Distributed Version Control System, Russell G. Shirey Mar 2015

Git As An Encrypted Distributed Version Control System, Russell G. Shirey

Theses and Dissertations

This thesis develops and presents a secure Git implementation, Git Virtual Vault (GV2), for users of Git to work on sensitive projects with repositories located in unsecure distributed environments, such as in cloud computing. This scenario is common within the Department of Defense, as much work is of a sensitive nature. In order to provide security to Git, additional functionality is added for confidentiality and integrity protection. This thesis examines existing Git encryption implementations and baselines their performance compared to unencrypted Git. Real-world Git repositories are examined to characterize typical Git usage and determine if the existing Git encryption implementations …


Design And Analysis Of A Dynamically Configured Log-Based Distributed Security Event Detection Methodology, Michael R. Grimaila, Justin M. Myers, Robert F. Mills, Gilbert L. Peterson Jul 2012

Design And Analysis Of A Dynamically Configured Log-Based Distributed Security Event Detection Methodology, Michael R. Grimaila, Justin M. Myers, Robert F. Mills, Gilbert L. Peterson

Faculty Publications

Military and defense organizations rely upon the security of data stored in, and communicated through, their cyber infrastructure to fulfill their mission objectives. It is essential to identify threats to the cyber infrastructure in a timely manner, so that mission risks can be recognized and mitigated. Centralized event logging and correlation is a proven method for identifying threats to cyber resources. However, centralized event logging is inflexible and does not scale well, because it consumes excessive network bandwidth and imposes significant storage and processing requirements on the central event log server. In this paper, we present a flexible, distributed event …


An Empirical Analysis Of The Cascade Error Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver, Michael R. Grimaila, Jeffrey W. Humphries Oct 2011

An Empirical Analysis Of The Cascade Error Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver, Michael R. Grimaila, Jeffrey W. Humphries

Faculty Publications

Modern cryptography provides the means to securely communicate data between authorized entities by using mathematical transformations which require pre-shared cryptographic keys. The need to share key material with authorized entities in a secure, cost efficient and timely manner has driven efforts to develop new key distribution methods. A promising method is Quantum Key Distribution (QKD) which is considered to be “unconditionally secure” because it relies upon the immutable laws of quantum physics rather than computational complexity as the basis for its security. An important component of any QKD system is the error reconciliation protocol which is used to identify and …


A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube Sep 2011

A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube

Theses and Dissertations

The rapid transition of critical business processes to computer networks potentially exposes organizations to digital theft or corruption by advanced competitors. One tool used for these tasks is malware, because it circumvents legitimate authentication mechanisms. Malware is an epidemic problem for organizations of all types. This research proposes and evaluates a novel Malware Target Recognition (MaTR) architecture for malware detection and identification of propagation methods and payloads to enhance situation awareness in tactical scenarios using non-instruction-based, static heuristic features. MaTR achieves a 99.92% detection accuracy on known malware with false positive and false negative rates of 8.73e-4 and 8.03e-4 respectively. …


Detecting Software Attacks By Monitoring Electric Power Consumption Patterns, Grant A. Jacoby, Nathaniel J. Davis Iv, Randolph C. Marchany Jan 2011

Detecting Software Attacks By Monitoring Electric Power Consumption Patterns, Grant A. Jacoby, Nathaniel J. Davis Iv, Randolph C. Marchany

AFIT Patents

Software attacks such as worms and viruses are detected in an electronic device by monitoring power consumption patterns. In a first embodiment, software attacks are detected by an increase in power consumption. The increased power consumption can be caused by increased network traffic, or by increased activity in the microprocessor. Monitoring power consumption is particularly effective for detecting DOS/flooding attacks when the electronic device is in an idle state. In a second embodiment, a power consumption signal is converted to the frequency domain (e.g., by fast Fourier transform). The highest amplitude frequencies are identified. Specific software attacks produce characteristic frequencies …