Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Theses and Dissertations

Discipline
Institution
Keyword
Publication Year

Articles 1 - 23 of 23

Full-Text Articles in Cybersecurity

Data Defines Success: Algorithm For Dataset Quality Assessment In Deep Learning For Malware Detection, Matei Ionescu Jan 2026

Data Defines Success: Algorithm For Dataset Quality Assessment In Deep Learning For Malware Detection, Matei Ionescu

Theses and Dissertations

The field of artificial intelligence is based upon the premise of constructing architectures through which to propagate training data. However, the majority of existing research literature is focused on architecture. While necessary, the attention devoted to the architecture should not so precipitously exceed that of the data. It should be noted that this disparity is not without reasonable cause. Data quality is often exceedingly difficult to verify due to particularities of the field or subfield; LLM repositories of text are distinct from image recognition pictures of dog breeds which are distinct from EEG waveforms of human brains which are distinct …


Advancing Cybersecurity Through Userland Memory Forensics: From Runtime Analysis To Security Applications, Hala Ali Jan 2026

Advancing Cybersecurity Through Userland Memory Forensics: From Runtime Analysis To Security Applications, Hala Ali

Theses and Dissertations

Memory forensics has become a crucial component of digital investigations, particularly for detecting malware operating solely in system memory. As operating system vendors implemented kernel access restrictions, malware authors shifted to userland malware. However, existing memory forensics techniques have largely focused on kernel-level analysis, leaving userland runtimes insufficiently covered. This dissertation addresses this gap by expanding memory analysis capabilities across two distinct paradigms: interpreted and compiled runtimes. The first phase targets the Python runtime, developing automated recovery techniques that enable several security applications. For malware detection, these techniques extract critical forensic artifacts such as encryption keys and command-and-control configurations. For …


Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems, Gustaf Barkstrom Jan 2026

Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems, Gustaf Barkstrom

Theses and Dissertations

Businesses lose millions of dollars every year when they can’t restore data from backups. Research shows that Disaster Recovery Plan (DRP) testing is not conducted frequently enough, nor are records maintained that demonstrate full data recovery from backups. This work introduces a design science artifact called PRTOK that aims to increase DRP testing. The design science artifact is a software solution that integrates with Data Management Systems (DMS)

such as iRODS and DSpace, and can work with formats such as HDF5 and BagIt. Proof-of- recovery records, or tokens, are recorded in a replicated, resilient, and indelible proof-of- authority blockchain data …


An Analysis Of Face Morphing Presentation Attacks Against Facial Recognition Systems, Joshua Breininger May 2025

An Analysis Of Face Morphing Presentation Attacks Against Facial Recognition Systems, Joshua Breininger

Theses and Dissertations

Security has been a problem for human society for as long as history has been recorded. The identification of people is an ongoing, ancient battle, with a variety of methods that only become more complex with time. The Romans performed censuses, ciphers have been used for thousands of years in the pursuit of security, and in modern day we own identifications and governments keep track of who lives in their country with citizenship and licenses. The question of ”Who are you?” is vital for society to function, which opens up a massive field of potential for how to ask that …


Evaluating Educational Benefits Of A Custom Cyber Game: ‘Hvac Attack!’, Jillian S. Valente Mar 2025

Evaluating Educational Benefits Of A Custom Cyber Game: ‘Hvac Attack!’, Jillian S. Valente

Theses and Dissertations

Cyber competition and conflict remain an enduring concern for the Department of Defense (DoD). Positive control of cyberspace is crucial across the vast diversity of military operations and supporting activities. Military members play an important role in cyber prevention, detection, and remediation, but most receive relatively little training outside of the annual Cyber Awareness Challenge. Particular career fields within the DoD may benefit from specialized training in cybersecurity, in particular the civil engineering (CE) community supporting critical infrastructure protection. Prior research has suggested that game-based learning (GBL) can be beneficial for teaching cyber concepts.


Evaluating A Military Digital Badging System Prototype, Benjamin T. Pederson Mar 2025

Evaluating A Military Digital Badging System Prototype, Benjamin T. Pederson

Theses and Dissertations

The Department of Defense is committed to developing and maintaining a highly skilled workforce capable of defending the United States and associated interests abroad. Digital badging systems, a form of micro-credentialing, offer a way to record service member competencies. By providing decision-makers with granular data, this technology could augment the military’s development of a highly skilled workforce, especially in technical career fields including cyber operations. Mixed-method data from thirty-six participants suggest that establishing a digital badging program could increase deterrence and operational effectiveness.


Jamming-Tolerant Low-Rate Wireless Personal Area Network For Detection Sensor Networks, Michael A. Eddy Mar 2025

Jamming-Tolerant Low-Rate Wireless Personal Area Network For Detection Sensor Networks, Michael A. Eddy

Theses and Dissertations

This research evaluates the impact of electronic warfare, particularly jamming, on an audio-based drone detection wireless sensor network (WSN) using Monte Carlo simulations. A six-node IEEE 802.15.4 network, with five edge nodes and a central sink, is tested against jamming probabilities ranging from 0-100% in 5% increments across 30 iterations per configuration. Results show that packet delivery ratio (PDR) degrades linearly at approximately 20% per jammed node, while detection performance often exceeds PDR. Even at 80% jamming, detection success rates remain above 57%, highlighting resilience despite network degradation. The study reveals that jamming effectiveness depends on node placement relative to …


Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira Dec 2024

Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira

Theses and Dissertations

Embedded systems are vital in civilian and military applications, requiring high performance and security. The open RISC-V Instruction Set Architecture (ISA) offers significant advantages, including security through community review and strategic independence in microchip supplies. Brazil’s recent partnership with RISC-V highlights its potential for national technological sovereignty. However, RISC-V is not inherently resistant to code reuse attacks (CRAs), highlighting the need to integrate security measures early in development. The RISC-V Compressed extension, while beneficial for optimizing performance and code flexibility, introduces security trade-offs. As RISC-V adoption grows, particularly in critical systems, addressing these security challenges from the start is crucial …


Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson Mar 2024

Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson

Theses and Dissertations

National level attention, resources, and priority regarding critical infrastructure have increased in recent years. This has led to adversaries and defenders exchanging positions between fortification and exploitation. One area that continues to be vulnerable is supply chain attacks like counterfeit insertion. This work investigates the application of converting collected signals into images from devices that may be considered for these critical networks. There are several aspects regarding the conversion of signals into images - specifically Red, Green, Blue (RGB) images. The methodology proposed here is potentially ideal fit for an initial security layer by achieving comparable classification results as more …


Smart Homes And You: Iot Device Data Risks In An Ever-Changing World, Autumn Person Oct 2023

Smart Homes And You: Iot Device Data Risks In An Ever-Changing World, Autumn Person

Theses and Dissertations

Social media applications are increasingly seen as a national security threat and a cause for concern because they can be used to create user profiles on government personnel and on US citizens. These profiles could be used for big data and artificial intelligence purposes of interest to foreign governments. With the rise of big data and AI being used, foreign governments could use this data for a variety of purposes that can affect normal everyday citizens, not just high value personnel. IoT (Internet of Things) devices that the population uses everyday can also pose the same threat. These devices can …


Docker Technology For Small Scenario-Based Excercises In Cybersecurity, Zeinab Ahmed Oct 2023

Docker Technology For Small Scenario-Based Excercises In Cybersecurity, Zeinab Ahmed

Theses and Dissertations

This study aims to better prepare students for cybersecurity roles by providing practical tools that bridge the gap between theory and real-world applications. We investigate the role of small scenario-based exercises for students’ understanding of cybersecurity concepts. In particular, we assess the use of Docker technology to deliver training that includes a simple small scenario on html code injection. The effectiveness of scenario-based learning has long been defined and by using SBL, we are going to create hands-on activity that involves the fundamental topics in cybersecurity using Docker technology, allowing students to see the exploitation of the vulnerabilities and defense …


Intel Total Memory Encryption: Functional Verification And Performance Analysis, Tallas T. S. Goo Mar 2023

Intel Total Memory Encryption: Functional Verification And Performance Analysis, Tallas T. S. Goo

Theses and Dissertations

While more attention is generally focused on software security, computer hardware security remains an important effort. Should an attacker gain direct physical access, computers with little to no hardware security can quickly be compromised via a manner of methods. One such attacker method is to steal information directly from the active memory of a locked, powered-on computer. To counter this attack, a hardware security method was developed called memory encryption. Memory encryption, as the name suggests, protects against adversary methods like cold boot attacks by encrypting all of memory. This research evaluates the efficacy and performance specifically of Intel TME. …


Exploring Misinformation Campaigns And How To Defend Against Them, Michelle S. Kuralt Nov 2022

Exploring Misinformation Campaigns And How To Defend Against Them, Michelle S. Kuralt

Theses and Dissertations

Misinformation campaigns can have very real and lasting effects. Misinformation has been known to impact elections, create vaccine hesitancy, and increase polarization within societies. This paper reviewed existing literature regarding misinformation research, collected information from research participants to discern factors which may contribute to an increased susceptibility to misinformation, and examined Rule Based Training and a training program which utilized both rules and mindfulness to ascertain if these training programs might be effective in reducing participant susceptibility to misinformation.


The Applications Of The Internet Of Things In The Medical Field, Cody Repass May 2022

The Applications Of The Internet Of Things In The Medical Field, Cody Repass

Theses and Dissertations

The Internet of Things (IoT) paradigm promises to make “things” include a more generic set of entities such as smart devices, sensors, human beings, and any other IoT objects to be accessible at anytime and anywhere. IoT varies widely in its applications, and one of its most beneficial uses is in the medical field. However, the large attack surface and vulnerabilities of IoT systems needs to be secured and protected. Security is a requirement for IoT systems in the medical field where the Health Insurance Portability and Accountability Act (HIPAA) applies.

This work investigates various applications of IoT in healthcare …


In-Depth Analysis Of College Students’ Data Privacy Awareness, Vernon D. Andrews Dec 2020

In-Depth Analysis Of College Students’ Data Privacy Awareness, Vernon D. Andrews

Theses and Dissertations

While attending university, college students need to be aware of issues related to data privacy. Regardless of the age, gender, race, or education level of college students, every student can relate to the advancement of the internet within the last decades. The internet has completely transformed the way the world receives and stores messages. Positively, the internet allows messages to be sent across the globe within the fraction of a second and provides students with access to potentially unlimited information on a variety of subjects. On the downside, there are issues on the internet that can cause more harm than …


Proactive Management In Academic Libraries: Promoting Improved Communication And Inclusion Of Academic Librarians And Archivists In Cybersecurity Policy Creation, Paul J. Luft Dec 2020

Proactive Management In Academic Libraries: Promoting Improved Communication And Inclusion Of Academic Librarians And Archivists In Cybersecurity Policy Creation, Paul J. Luft

Theses and Dissertations

Although increasing cybersecurity threats continue in libraries, not many studies are available which examine surrounding cybersecurity policies. Even less has been done on specific types of libraries such as academic and archives. When it comes to academic libraries, cybersecurity policies take a top-down approach to managing and creating policies. The problem is that both academic libraries and archives are unique areas within a university setting. Some of the general policies do not always handle specific issues dealt with in an academic library or archives. This paper investigates if an actual gap or void in policy exists which could create issues …


Cybersecurity Framework And Algorithms For Prioritized Vulnerability Mitigation (Cyfer): An Adoption To Blockchain Systems, Sri Nikhil Gupta Gourisetti Oct 2019

Cybersecurity Framework And Algorithms For Prioritized Vulnerability Mitigation (Cyfer): An Adoption To Blockchain Systems, Sri Nikhil Gupta Gourisetti

Theses and Dissertations

Cybersecurity vulnerability assessment tools, frameworks, methodologies, and processes are commonly used to understand the cybersecurity maturity and posture of a system or a facility. Those tools are strictly developed based on standards defined by organizations such as the National Institute of Standards and Technology (NIST) and the U.S. Department of Energy, and the majority of these tools and frameworks do not provide a platform to prioritize the requirements to reach a desired cybersecurity maturity. To address that challenge, we used multi-criteria decision analysis (MCDA) techniques to develop a framework and a software application family called the Cybersecurity Framework and Algorithms …


Adapting Financial Technology Standards To Blockchain Platforms, Gabriel Bello Jan 2019

Adapting Financial Technology Standards To Blockchain Platforms, Gabriel Bello

Theses and Dissertations

Traditional payment systems have standards designed to keep transaction data secure, but blockchain systems are not in scope for such security standards. We compare the Payment Application Data Security Standard’s (PA-DSS) applicability towards transaction-supported blockchain platforms to test the standard’s applicability. By highlighting the differences in implementation on traditional and decentralized transaction platforms, we critique and adapt the standards to fit the decentralized model. In two case studies, we analyze the QTUM and Ethereum blockchain platforms’ industry compliance, as their payment platforms support transactions equivalent to that of applications governed by the PA-DSS. We determine QTUM’s and Ethereum’s capabilities to …


Using Self-Organizing Maps For Computer Network Intrusion Detection, Manuel R. Parrachavez Jan 2017

Using Self-Organizing Maps For Computer Network Intrusion Detection, Manuel R. Parrachavez

Theses and Dissertations

Anomaly detection in user access patterns using artificial neural networks is a novel way of combating the ever-present concern of computer network intrusion detection for many entities around the world. Anomaly detection is a technique in network security in which a profile is built around a user's normal daily actions. The data collected for these profiles can be as following: file access attempts; failed login attempts; file creations; file access failures; and countless others. This data is collected and used as training data for a neural network.

There are many types of neural networks, such as multi-layer feed-forward network; recurrent …


Pointing Analysis And Design Drivers For Low Earth Orbit Satellite Quantum Key Distribution, Jeremiah A. Specht Mar 2016

Pointing Analysis And Design Drivers For Low Earth Orbit Satellite Quantum Key Distribution, Jeremiah A. Specht

Theses and Dissertations

The world relies on encryption to perform critical and sensitive tasks every day. If quantum computing matures, the capability to decode keys and decrypt messages becomes possible. Quantum key distribution (QKD) is a method of distributing secure cryptographic keys which relies on the laws of quantum mechanics. Current implementations of QKD use fiber-based channels which limit the number of users and the distance between users. Satellite-based QKD using free-space channels is proposed as a feasible secure global communication solution. Since a free-space link does not use a waveguide, pointing a transmitter to receiver is required to ensure signal arrival. In …


Git As An Encrypted Distributed Version Control System, Russell G. Shirey Mar 2015

Git As An Encrypted Distributed Version Control System, Russell G. Shirey

Theses and Dissertations

This thesis develops and presents a secure Git implementation, Git Virtual Vault (GV2), for users of Git to work on sensitive projects with repositories located in unsecure distributed environments, such as in cloud computing. This scenario is common within the Department of Defense, as much work is of a sensitive nature. In order to provide security to Git, additional functionality is added for confidentiality and integrity protection. This thesis examines existing Git encryption implementations and baselines their performance compared to unencrypted Git. Real-world Git repositories are examined to characterize typical Git usage and determine if the existing Git encryption implementations …


A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube Sep 2011

A Novel Malware Target Recognition Architecture For Enhanced Cyberspace Situation Awareness, Thomas E. Dube

Theses and Dissertations

The rapid transition of critical business processes to computer networks potentially exposes organizations to digital theft or corruption by advanced competitors. One tool used for these tasks is malware, because it circumvents legitimate authentication mechanisms. Malware is an epidemic problem for organizations of all types. This research proposes and evaluates a novel Malware Target Recognition (MaTR) architecture for malware detection and identification of propagation methods and payloads to enhance situation awareness in tactical scenarios using non-instruction-based, static heuristic features. MaTR achieves a 99.92% detection accuracy on known malware with false positive and false negative rates of 8.73e-4 and 8.03e-4 respectively. …


Statistical Tools For Linking Engine-Generated Malware To Its Engine, Edna Chelangat Milgo Dec 2009

Statistical Tools For Linking Engine-Generated Malware To Its Engine, Edna Chelangat Milgo

Theses and Dissertations

Malware-generating engines challenge typical malware analysts by requiring them to quickly extract and upload to their customers' machines, a signature for each of a possibly vast number of never-before-seen malware instances that an engine can generate in a short amount of time In this thesis we propose and evaluate two methods for linking variants of engine-generated malware to its engine. The proposed methods use the w-gram frequency vector (NFV) of the opcode mnemonics of an engine-generated malware in- stance as a feature vector for the instance. An NFV is a tuple that maps «-grams with their frequencies. The in-formation contained …