Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Other Computer Sciences (19)
- Information Security (10)
- Systems Architecture (7)
- OS and Networks (5)
- Programming Languages and Compilers (4)
-
- Databases and Information Systems (3)
- Data Science (2)
- Engineering (2)
- Environmental Sciences (2)
- Law (2)
- Theory and Algorithms (2)
- Water Resource Management (2)
- Artificial Intelligence and Robotics (1)
- COVID-19 (1)
- Civil and Environmental Engineering (1)
- Computer Engineering (1)
- Digital Circuits (1)
- Hardware Systems (1)
- Health Information Technology (1)
- Health Services Research (1)
- Medicine and Health Sciences (1)
- Other Civil and Environmental Engineering (1)
- Other Environmental Sciences (1)
- Other Medicine and Health Sciences (1)
- Other Public Health (1)
- Public Health (1)
- Water Resources Engineering (1)
- Publication
- Publication Type
Articles 1 - 21 of 21
Full-Text Articles in Cybersecurity
Using Siamese Neural Networks To Effectively Detect Trojans In Fpgas When Trojans Manipulate Encryption Operations At The Bitstream Level, Kylie Arnett
Graduate Theses and Dissertations (2019 - present)
This research investigates security vulnerabilities in Field-Programmable Gate Arrays (FPGAs) at the bitstream level, focusing on hardware trojans (HTs) that manipulate encryption operations. This study addresses two critical questions: (1) The feasibility of exploiting FPGA bitstreams to selectively bypass encryption operations when a predefined input pattern is observed (all ones), thereby exposing sensitive data, and (2) the efficacy of Siamese Neural Networks (SNNs) in detecting such trojans with high accuracy. FPGAs are vulnerable to malicious modifications during manufacturing or deployment, posing risks to data integrity and system functionality. In this work, a trojan is inserted into a Xilinx series-7 FPGA …
Polyglot File Detection For Forensic Investigations, Chase Stevens
Polyglot File Detection For Forensic Investigations, Chase Stevens
Graduate Theses and Dissertations (2019 - present)
As technology has become far more ubiquitous over the years, so too has the amount of digital evidence that can and needs to be collected and processed. Forensic tools are developed in response to the growing need, but are limited to what they are programmed to do. One such forensic tool is Autopsy, one of the most widely used open-source tools. Autopsy uses known file-type signatures (e.g., headers, trailers) to identify and recover files from forensic images. Polyglot files introduce a unique problem to both these forensic tools and investigators alike. In the context of the research conducted, polyglot files …
Detecting Sophisticated Cyberattacks On Public Water Infrastructure, Ayrton Purdy
Detecting Sophisticated Cyberattacks On Public Water Infrastructure, Ayrton Purdy
Graduate Theses and Dissertations (2019 - present)
In recent years there has been an increasing number of cyberattacks on public water generation and distribution systems. Advanced persistent attackers could usurp sensors and control systems to contaminate public drinking water. In order to conceal their malicious activity, they can manipulate sensor data flows to give the appearance of normal activity. The compromised sensors would report normal chemical levels even though unsafe water is entering the distribution system. In response, this research proposes a multi-sensor, cross-comparison approach to anomaly detection. The proposed approach is designed to detect sophisticated cyberattacks which are not easily detectable using traditional cyber tools. The …
Developing A Framework For Microchip Design Recovery, Eric Diep
Developing A Framework For Microchip Design Recovery, Eric Diep
Graduate Theses and Dissertations (2019 - present)
Due to the increase in diverse chip production over the past decade, reverse engineering has become a difficult and daunting task. This research develops a methodology for microchip design recovery, seeking to validate and reproduce prior approaches to physical reverse engineering using low-cost tools and techniques. We used mechanical hardware abrasion tools and techniques to delayer and capture silicon integrated chip (IC) layout. We focused on the Mifare Classic EVl microchip, commonly implemented in public transit/transportation cards, to extract information for design recovery. The research explores limitations and advantages of mechanical abrasion and optical microscopy in context to modem chip …
Evaluating The Effects Of Anti-Forensic Activities In Additive Manufacturing Devices, Daniel B. Miller
Evaluating The Effects Of Anti-Forensic Activities In Additive Manufacturing Devices, Daniel B. Miller
Shelby Hall Graduate Research Forum Posters
Additive Manufacturing (AM) is a newer famlily of production tecchologies that constructs objects by fusing layers of material into the desired shape. Methods for achieving this as described in Gibson et al. [1] are varied and include Fused Filament Deposition, Selective Laser Sintering, Stereolithography (SLA), and Powder Bed Fusion. Computers are integral to the processes being responsible for creating and decoding design instructions, collecting and processing sensor data, and, ultimately, directing the activity of the machines which implement the process. Additionally, the AM industry is rapidly expanding, worth an estimated $23 billion in 2023 and projected to reach $88 billion …
Cellebrite Reliability In Digital Forensics, Christina Huynh
Cellebrite Reliability In Digital Forensics, Christina Huynh
Shelby Hall Graduate Research Forum Posters
Forensic tools like Cellebrite are commonly used in court to gather and interpret raw data for evidence. Cellebrite does not only collect data but creates and interprets the artifacts of data to create a scene of the process it has been through. With this, evidence can be influenced by software designs and not just the data on the mobile device. Courts and police use Cellebrite to gather evidence and reconstruct it to create an easily readable dataset. These tools lack reproducibility, transparency, integrity, and chain of evidence command. Cellebrite is often used in court and by police without further vetting …
Detecting Sophisticated Cyberattacks On Public Water Infrastructure, Ayrton Purdy
Detecting Sophisticated Cyberattacks On Public Water Infrastructure, Ayrton Purdy
Shelby Hall Graduate Research Forum Posters
From around the globe, malicious actors continually probe critical infrastructure assets for weaknesses. Their backgrounds, goals, and motives may vary, but the purpose of their attacks is the same: to damage, undermine, or exploit the functionality of these assets [2]. At a fundamental level, critical infrastructure is any essential system and asset vital to national security. Critical infrastructure includes assets such as power, transportation, telecommunications, water and wastewater systems (WWS), and many more [3].
Nonlinear Phase Space Analysis For Anomaly Detection In Ros 2 Communications: Detecting Man-In-The-Middle Attacks In Simulated Environments, William L. Locklier
Nonlinear Phase Space Analysis For Anomaly Detection In Ros 2 Communications: Detecting Man-In-The-Middle Attacks In Simulated Environments, William L. Locklier
Graduate Theses and Dissertations (2019 - present)
Robot Operating System 2 (ROS 2) marks a significant advancement over its predecessor through the transition from a centralized to a decentralized architecture, integrating the Data Distribution Service (DDS) to support real-time, scalable communications. Despite these improvements, inherent vulnerabilities in the ROS 2 communication stack continue to leave these systems exposed to sophisticated network-based attacks. This study leveraged nonlinear phase space analysis (NLPSA) as an intrusion detection system (IDS) to detect man-in-the-middle (MitM) attack anomalies in ROS 2 traffic. Grounded in Takens’ embedding theorem, NLPSA reconstructs the phase space of communication features and compares the resulting structure against a baseline …
Application Of Graph Neural Networks On Phase Space Graphs For Cybersecurity, Parker H. Cole
Application Of Graph Neural Networks On Phase Space Graphs For Cybersecurity, Parker H. Cole
Graduate Theses and Dissertations (2019 - present)
Non-linear phase space analysis may be used to represent time-series data as graph data with transitions between states in the time domain. By studying these transitions, we can predict anomalies within the system. Previous research has demonstrated success in learning from phase graphs for malware and seizure detection. These solutions either require extracting global features or converting the graph into an image for convolutional neural networks (CNNs), which adds a layer of complexity and limits the size and potential expressiveness of a graph. To sidestep current limitations, this study proposed Graph Neural Networks (GNNs) for analyzing phase graphs. GNNs do …
Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeffrey K. Holifield
Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeffrey K. Holifield
Graduate Theses and Dissertations (2019 - present)
Real Time Operating Systems (RTOS) are increasing present throughout the industrial, business, defense, and healthcare spaces. These lightweight and efficient operating systems are designed to run on embedded, resource constrained devices, often within cyber-physical systems (CPS). A defining characteristic ofRTOSs is that they are deterministic. Tasks are scheduled to run on fixed timelines within guaranteed execution windows. In Industry 4.0 applications for example, sensors must receive and process inputs within a fixed schedule to ensure products are properly manufactured. This requires guaranteed service at fixed time periods. To accomplish this, RTOSs must conform to worst case execution times (WCETs) as …
Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeff K. Holifield
Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeff K. Holifield
Shelby Hall Graduate Research Forum Posters
Real Time Operating Systems (RTOS) are increasing present throughout the industrial, business, defense, and healthcare spaces. These lightweight and efficient operating systems are designed to run on embedded, resource constrained devices, often within cyber-physical systems (CFS). A defining characteristic of RTOSs is that they are deterministic. Tasks are scheduled to run on fixed timelines within guaranteed execution windows. To accomplish tasks on time, real time software must conform to worst case execution times (WCETs) as design parameters. WCET is the maximum time a particular task can take to complete. Exceeding the WCET could cause system failure and lead to damage, …
Analysis Of Forensic Techniques For Additive Manufacturing Devices, Daniel B. Miller, Brad Glisson, Mark Yampolskiy, J Todd Mcdonald
Analysis Of Forensic Techniques For Additive Manufacturing Devices, Daniel B. Miller, Brad Glisson, Mark Yampolskiy, J Todd Mcdonald
Shelby Hall Graduate Research Forum Posters
Additive Manufacturing (AM) is a set of newer computer-dependent production technologies that is seeing rapid adoption across a wide variety of industries, including defense, aerospace, automotive, and healthcare. With increased adoption comes an increased opportunity for misuse and abuse of such systems, which will lead to an increased need for Digital Forensic investigations into these platforms. This research forensically analyzes a number of AM devices to explore the options available for data acquisition as well as the impacts of hardware and software design choices on the analysis and investigation results. Hardware is investigated using Open-Source Intelligence (OSINT) sources to determine …
Using Image-Based Representation For Network Intrusion Detection, Chakriya Suon, J. Todd Mcdonald
Using Image-Based Representation For Network Intrusion Detection, Chakriya Suon, J. Todd Mcdonald
Shelby Hall Graduate Research Forum Posters
The primary focus of our research is to evaluate the effectiveness of converting network traffic data, PCAPs, into image-based representations for anomaly-based network intrusion detection. We aim to analyze PCAPs to detect malware, or malicious software in hopes of creating a useful approach for anomaly detection against cyber threats including Advanced Persistent Threats (APTs). With the rise of cyber threats, cybersecurity continues to play a critical role in the ever-changing landscape of technology, by protecting and defending against threat agents. Our research will apply novel machine learning (ML) techniques to detect potential malware transmitted over a network effectively. The overall …
Security Vulnerabilities Of A Field Programmable Gate Array, Kylie Arnett
Security Vulnerabilities Of A Field Programmable Gate Array, Kylie Arnett
Shelby Hall Graduate Research Forum Posters
The primary goal of this research is to understand and exploit the security vulnerabilities of a Field Programmable Gate Array (FPGA), at the bitstream level. This paper is working to successfully show that an FPGA can be altered via the bitstream file, and a Trojan can be inserted into the device. Once a Trojan is successfully inserted into the FPGA and activated through a certain input value, a Siamese Neural Network (SNN) will be used to test the effectiveness of Trojan detection. Followed by recording the successful flag rate to detect Trojans, which will be averaged to determine the accuracy …
Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems, Krista Stacey, Todd R. Andel
Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems, Krista Stacey, Todd R. Andel
Shelby Hall Graduate Research Forum Posters
The rapid evolution of computational ecosystems—ranging from embedded systems and cloud platforms to hybrid and quantum architectures—has introduced new challenges in deploying machine learning (ML) applications. While cloud computing offers scalability, it comes with increased latency and security risks, whereas edge computing, such as FPGA-based systems, provides real-time processing with constrained resources. Hybrid and quantum ecosystems further complicate decision-making, requiring careful trade-offs between performance and security. This research seeks to establish a framework for evaluating ML performance and security risks across these ecosystems, forming the foundation of the Computational Performance And Security System (COMPASS) decision-support tool. The study will systematically …
Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive, Nicholas Flynn, Michael Black
Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive, Nicholas Flynn, Michael Black
Shelby Hall Graduate Research Forum Posters
Current forensic tools struggle to effectively detect encrypted storage media. In recent years, there have been significant advancements, but a noticeable gap remains when it comes to identifying encrypted volumes from metadata alone. The goal of this research is to develop a novel algorithm that will identify the presence of volumes on a disk image which have been encrypted with the Linux Unified Key Setup (LUKS) encryption algorithm, in an effort to aid digital forensics investigations. Bad actors often use encryption as an anti-forensics tool to pose significant challenges to forensic investigators, especially when it is done within sections of …
False Narratives, Real Consequences, Russell W. Cantrell, Matt Campbell
False Narratives, Real Consequences, Russell W. Cantrell, Matt Campbell
Shelby Hall Graduate Research Forum Posters
Social media is an increasingly significant tool in modern cyber warfare, capable of rapidly shaping public opinion. The swift dissemination of information complicates efforts to distinguish fact from fiction [1]. During public health crises, healthcare professionals use these platforms to share updates, yet their credible content must contend with false or deliberately misleading narratives [2]. This environment creates an opportunity for cyberattacks through social media influence campaigns [3]. While disinformation's role in political interference has been widely studied, its potential to destabilize healthcare remains largely unexplored. Prior research primarily focuses on how vaccine misinformation affects the general public [4]. This …
Detecting Sensor Data Manipulation, Ricky Green, Michael Black
Detecting Sensor Data Manipulation, Ricky Green, Michael Black
Shelby Hall Graduate Research Forum Posters
The integration of Information Technology (IT) and Operational Technology (OT) have made OT devices vulnerable to threats that have been successfully exploited with devastating results. Many modern techniques for hardening and securing enterprise IT systems are either incompatible with OT components in an Industrial Control System (ICS), reduce the efficiency of processes, or are prohibitively expensive to implement. Research in the area of ICS security focuses on a top-down approach, such as intrusion prevention by securing the perimeter of the network and hardening computer systems. This approach is useful in business IT systems, but full compatibility with OT components in …
Using Machine Learning Models To Improve The Cyber Physical Security Of Drones, Sean Lee, Aviv Segev
Using Machine Learning Models To Improve The Cyber Physical Security Of Drones, Sean Lee, Aviv Segev
Shelby Hall Graduate Research Forum Posters
This research proposes a new manner of implementing machine learning models such that, when applied on a drone, it will be able to accurately identify and maintain the authenticity of the entity sending the control data to the drone. To begin with, the drone will, for a pre-determined amount of signals received per unit time, determine the average signal strength (RSSI) of them and use that average to determine the approximate distance between the drone and the source of those signals. This single data point will be fed into a custom implementation of the SCluStream algorithm (a real-time clustering machine …
Hybrid Deep Learning-Based Model For Eclipse Attack Detection On Ethereum Network, Dhanasak Bhumichai
Hybrid Deep Learning-Based Model For Eclipse Attack Detection On Ethereum Network, Dhanasak Bhumichai
Graduate Theses and Dissertations (2019 - present)
An eclipse attack is a significant cyber threat targeting the network layer of blockchain platforms. Detecting eclipse attacks is challenging for several reasons. First, there are no available datasets for training and testing models. Second, comprehensive studies identifying features to detect eclipse attacks are lacking. Additionally, the amount of eclipse network traffic is much smaller than that of normal network traffic, which leads to imbalanced samples. Moreover, the characteristics of eclipse network traffic closely resemble those of normal traffic, causing overlapping samples, which makes it challenging for traditional classifiers to learn how to identify eclipse attacks. To address these challenges, …
Development Of An Algorithm To Identify And Calculate The Amount Of File Slack On An Image Of A Given Drive, Nicholas Flynn
Development Of An Algorithm To Identify And Calculate The Amount Of File Slack On An Image Of A Given Drive, Nicholas Flynn
Honors Theses
As society increasingly relies on technology, the rates of cyber crime have been increasing at exponential rates. Cyber criminals are also discovering new ways to hide evidence of their crimes. This study develops a forensic analysis algorithm to evaluate the amount of file slack on an image of a drive. Slack space, leftover drive space on a disk sector after a file has been written, can be exploited to hide data. The algorithm aims to detect and calculate this slack space to help direct forensic investigations. The algorithm was evaluated on a population dataset of 100,000 files with random data …