Open Access. Powered by Scholars. Published by Universities.®
- Discipline
- Keyword
-
- Cybersecurity (3)
- Cryptography (2)
- HPC (2)
- Quantum key distribution (2)
- TLB (2)
-
- #ccr (1)
- #csra (1)
- CPU (1)
- Cascade error reconciliation protocol (1)
- Central Processing Unit (CPU) (1)
- Ciphers (1)
- Civil engineering (1)
- Code Reuse Attack (CRA) (1)
- Computer security (1)
- Control systems (1)
- Counterfeit Detection (1)
- Critical Infrastructure (1)
- Critical infrastructure (1)
- Data processing security (1)
- Digital badges (1)
- Functional verification (1)
- Hardware security (1)
- Image Classification (1)
- Information entropy (1)
- Intel Total Memory Encryption (1)
- JDMS (1)
- Jamming (1)
- Jump-Oriented Programming (JOP) (1)
- Malware (1)
- Memory Management Unit (MMU) (1)
- Publication Type
Articles 1 - 15 of 15
Full-Text Articles in Cybersecurity
Microarchitectural Malware Detection Via Translation Lookaside Buffer (Tlb) Events, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert Kabban, Jose R. Gutierrez Del Arroyo, Scott R. Graham
Microarchitectural Malware Detection Via Translation Lookaside Buffer (Tlb) Events, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert Kabban, Jose R. Gutierrez Del Arroyo, Scott R. Graham
Faculty Publications
Prior work has shown that Translation Lookaside Buffer (TLB) data contains valuable behavioral information. Many existing methodologies rely on timing features or focus solely on workload classification. In this study, we propose a novel approach to malware classification using only TLB-related Hardware Performance Counters (HPCs), explicitly excluding any dependence on timing features such as task execution duration or memory access timing. Our methodology evaluates whether TLB data alone, without any timing information, can effectively distinguish between malicious and benign programs. We test this across three classification scenarios: (1) A binary classification problem involving distinguishing malicious from benign tasks, (2) a …
Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez Del Arroyo, Tor J. Langehaug, Scott R. Graham
Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez Del Arroyo, Tor J. Langehaug, Scott R. Graham
Faculty Publications
The primary focus of modern Central Processing Unit (CPU) technologies is performance improvement, with security often considered a secondary concern. As a result, vulnerabilities within the system are overlooked. While significant research, both offensive and defensive, has been conducted on CPU caches, relatively little attention has been given to the Translation Lookaside Buffer (TLB) due to its perceived lack of data granularity. Prior studies have typically combined multiple Hardware Performance Counters (HPCs) or relied on timing analysis to extract meaningful insights. In contrast, this study introduces a novel methodology that leverages only TLB related HPCs for multi-task classification, without incorporating …
Evaluating Educational Benefits Of A Custom Cyber Game: ‘Hvac Attack!’, Jillian S. Valente
Evaluating Educational Benefits Of A Custom Cyber Game: ‘Hvac Attack!’, Jillian S. Valente
Theses and Dissertations
Cyber competition and conflict remain an enduring concern for the Department of Defense (DoD). Positive control of cyberspace is crucial across the vast diversity of military operations and supporting activities. Military members play an important role in cyber prevention, detection, and remediation, but most receive relatively little training outside of the annual Cyber Awareness Challenge. Particular career fields within the DoD may benefit from specialized training in cybersecurity, in particular the civil engineering (CE) community supporting critical infrastructure protection. Prior research has suggested that game-based learning (GBL) can be beneficial for teaching cyber concepts.
Evaluating A Military Digital Badging System Prototype, Benjamin T. Pederson
Evaluating A Military Digital Badging System Prototype, Benjamin T. Pederson
Theses and Dissertations
The Department of Defense is committed to developing and maintaining a highly skilled workforce capable of defending the United States and associated interests abroad. Digital badging systems, a form of micro-credentialing, offer a way to record service member competencies. By providing decision-makers with granular data, this technology could augment the military’s development of a highly skilled workforce, especially in technical career fields including cyber operations. Mixed-method data from thirty-six participants suggest that establishing a digital badging program could increase deterrence and operational effectiveness.
Jamming-Tolerant Low-Rate Wireless Personal Area Network For Detection Sensor Networks, Michael A. Eddy
Jamming-Tolerant Low-Rate Wireless Personal Area Network For Detection Sensor Networks, Michael A. Eddy
Theses and Dissertations
This research evaluates the impact of electronic warfare, particularly jamming, on an audio-based drone detection wireless sensor network (WSN) using Monte Carlo simulations. A six-node IEEE 802.15.4 network, with five edge nodes and a central sink, is tested against jamming probabilities ranging from 0-100% in 5% increments across 30 iterations per configuration. Results show that packet delivery ratio (PDR) degrades linearly at approximately 20% per jammed node, while detection performance often exceeds PDR. Even at 80% jamming, detection success rates remain above 57%, highlighting resilience despite network degradation. The study reveals that jamming effectiveness depends on node placement relative to …
Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira
Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira
Theses and Dissertations
Embedded systems are vital in civilian and military applications, requiring high performance and security. The open RISC-V Instruction Set Architecture (ISA) offers significant advantages, including security through community review and strategic independence in microchip supplies. Brazil’s recent partnership with RISC-V highlights its potential for national technological sovereignty. However, RISC-V is not inherently resistant to code reuse attacks (CRAs), highlighting the need to integrate security measures early in development. The RISC-V Compressed extension, while beneficial for optimizing performance and code flexibility, introduces security trade-offs. As RISC-V adoption grows, particularly in critical systems, addressing these security challenges from the start is crucial …
Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson
Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson
Theses and Dissertations
National level attention, resources, and priority regarding critical infrastructure have increased in recent years. This has led to adversaries and defenders exchanging positions between fortification and exploitation. One area that continues to be vulnerable is supply chain attacks like counterfeit insertion. This work investigates the application of converting collected signals into images from devices that may be considered for these critical networks. There are several aspects regarding the conversion of signals into images - specifically Red, Green, Blue (RGB) images. The methodology proposed here is potentially ideal fit for an initial security layer by achieving comparable classification results as more …
Intel Total Memory Encryption: Functional Verification And Performance Analysis, Tallas T. S. Goo
Intel Total Memory Encryption: Functional Verification And Performance Analysis, Tallas T. S. Goo
Theses and Dissertations
While more attention is generally focused on software security, computer hardware security remains an important effort. Should an attacker gain direct physical access, computers with little to no hardware security can quickly be compromised via a manner of methods. One such attacker method is to steal information directly from the active memory of a locked, powered-on computer. To counter this attack, a hardware security method was developed called memory encryption. Memory encryption, as the name suggests, protects against adversary methods like cold boot attacks by encrypting all of memory. This research evaluates the efficacy and performance specifically of Intel TME. …
Using Timing-Based Side Channels For Anomaly Detection In Industrial Control Systems, Stephen Dunlap, Jonathan W. Butts, Juan L. Lopez Jr., Mason J. Rice, Barry E. Mullins
Using Timing-Based Side Channels For Anomaly Detection In Industrial Control Systems, Stephen Dunlap, Jonathan W. Butts, Juan L. Lopez Jr., Mason J. Rice, Barry E. Mullins
Faculty Publications
The critical infrastructure, which includes the electric power grid, railroads and water treatment facilities, is dependent on the proper operation of industrial control systems. However, malware such as Stuxnet has demonstrated the ability to alter industrial control system parameters to create physical effects. Of particular concern is malware that targets embedded devices that monitor and control system functionality, while masking the actions from plant operators and security analysts. Indeed, system security relies on guarantees that the assurance of these devices can be maintained throughout their lifetimes. This paper presents a novel approach that uses timing-based side channel analysis to establish …
Pointing Analysis And Design Drivers For Low Earth Orbit Satellite Quantum Key Distribution, Jeremiah A. Specht
Pointing Analysis And Design Drivers For Low Earth Orbit Satellite Quantum Key Distribution, Jeremiah A. Specht
Theses and Dissertations
The world relies on encryption to perform critical and sensitive tasks every day. If quantum computing matures, the capability to decode keys and decrypt messages becomes possible. Quantum key distribution (QKD) is a method of distributing secure cryptographic keys which relies on the laws of quantum mechanics. Current implementations of QKD use fiber-based channels which limit the number of users and the distance between users. Satellite-based QKD using free-space channels is proposed as a feasible secure global communication solution. Since a free-space link does not use a waveguide, pointing a transmitter to receiver is required to ensure signal arrival. In …
Git As An Encrypted Distributed Version Control System, Russell G. Shirey
Git As An Encrypted Distributed Version Control System, Russell G. Shirey
Theses and Dissertations
This thesis develops and presents a secure Git implementation, Git Virtual Vault (GV2), for users of Git to work on sensitive projects with repositories located in unsecure distributed environments, such as in cloud computing. This scenario is common within the Department of Defense, as much work is of a sensitive nature. In order to provide security to Git, additional functionality is added for confidentiality and integrity protection. This thesis examines existing Git encryption implementations and baselines their performance compared to unencrypted Git. Real-world Git repositories are examined to characterize typical Git usage and determine if the existing Git encryption implementations …
Design And Analysis Of A Dynamically Configured Log-Based Distributed Security Event Detection Methodology, Michael R. Grimaila, Justin M. Myers, Robert F. Mills, Gilbert L. Peterson
Design And Analysis Of A Dynamically Configured Log-Based Distributed Security Event Detection Methodology, Michael R. Grimaila, Justin M. Myers, Robert F. Mills, Gilbert L. Peterson
Faculty Publications
Military and defense organizations rely upon the security of data stored in, and communicated through, their cyber infrastructure to fulfill their mission objectives. It is essential to identify threats to the cyber infrastructure in a timely manner, so that mission risks can be recognized and mitigated. Centralized event logging and correlation is a proven method for identifying threats to cyber resources. However, centralized event logging is inflexible and does not scale well, because it consumes excessive network bandwidth and imposes significant storage and processing requirements on the central event log server. In this paper, we present a flexible, distributed event …
An Empirical Analysis Of The Cascade Error Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver, Michael R. Grimaila, Jeffrey W. Humphries
An Empirical Analysis Of The Cascade Error Reconciliation Protocol For Quantum Key Distribution, Timothy I. Calver, Michael R. Grimaila, Jeffrey W. Humphries
Faculty Publications
Modern cryptography provides the means to securely communicate data between authorized entities by using mathematical transformations which require pre-shared cryptographic keys. The need to share key material with authorized entities in a secure, cost efficient and timely manner has driven efforts to develop new key distribution methods. A promising method is Quantum Key Distribution (QKD) which is considered to be “unconditionally secure” because it relies upon the immutable laws of quantum physics rather than computational complexity as the basis for its security. An important component of any QKD system is the error reconciliation protocol which is used to identify and …
A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube
A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube
Theses and Dissertations
The rapid transition of critical business processes to computer networks potentially exposes organizations to digital theft or corruption by advanced competitors. One tool used for these tasks is malware, because it circumvents legitimate authentication mechanisms. Malware is an epidemic problem for organizations of all types. This research proposes and evaluates a novel Malware Target Recognition (MaTR) architecture for malware detection and identification of propagation methods and payloads to enhance situation awareness in tactical scenarios using non-instruction-based, static heuristic features. MaTR achieves a 99.92% detection accuracy on known malware with false positive and false negative rates of 8.73e-4 and 8.03e-4 respectively. …
Detecting Software Attacks By Monitoring Electric Power Consumption Patterns, Grant A. Jacoby, Nathaniel J. Davis Iv, Randolph C. Marchany
Detecting Software Attacks By Monitoring Electric Power Consumption Patterns, Grant A. Jacoby, Nathaniel J. Davis Iv, Randolph C. Marchany
AFIT Patents
Software attacks such as worms and viruses are detected in an electronic device by monitoring power consumption patterns. In a first embodiment, software attacks are detected by an increase in power consumption. The increased power consumption can be caused by increased network traffic, or by increased activity in the microprocessor. Monitoring power consumption is particularly effective for detecting DOS/flooding attacks when the electronic device is in an idle state. In a second embodiment, a power consumption signal is converted to the frequency domain (e.g., by fast Fourier transform). The highest amplitude frequencies are identified. Specific software attacks produce characteristic frequencies …