Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

2024

Discipline
Institution
Keyword
Publication
Publication Type

Articles 31 - 60 of 65

Full-Text Articles in Cybersecurity

Bi-Directional Transformers Vs. Word2vec: Discovering Vulnerabilities In Lifted Compiled Code, Gary Mccully, John Hastings, Shengjie Xu, Adam Fortier Oct 2024

Bi-Directional Transformers Vs. Word2vec: Discovering Vulnerabilities In Lifted Compiled Code, Gary Mccully, John Hastings, Shengjie Xu, Adam Fortier

Research & Publications

Detecting vulnerabilities within compiled binaries is challenging due to lost high-level code structures and other factors such as architectural dependencies, compilers, and optimization options. To address these obstacles, this research explores vulnerability detection using natural language processing (NLP) embedding techniques with word2vec, BERT, and RoBERTa to learn semantics from intermediate representation (LLVM IR) code. Long short-term memory (LSTM) neural networks were trained on embeddings from encoders created using approximately 48k LLVM functions from the Juliet dataset. This study is pioneering in its comparison of word2vec models with multiple bidirectional transformers (BERT, RoBERTa) embeddings built using LLVM code to train neural …


The Psychological Impacts Of Algorithmic And Ai-Driven Social Media On Teenagers: A Call To Action, Sunil Arora, Sahil Arora, John Hastings Oct 2024

The Psychological Impacts Of Algorithmic And Ai-Driven Social Media On Teenagers: A Call To Action, Sunil Arora, Sahil Arora, John Hastings

Research & Publications

This study investigates the meta-issues surrounding social media, which, while theoretically designed to enhance social interactions and improve our social lives by facilitating the sharing of personal experiences and life events, often results in adverse psychological impacts. Our investigation reveals a paradoxical outcome: rather than fostering closer relationships and improving social lives, the algorithms and structures that underlie social media platforms inadvertently contribute to a profound psychological impact on individuals, influencing them in unforeseen ways. This phenomenon is particularly pronounced among teenagers, who are disproportionately affected by curated online personas, peer pressure to present a perfect digital image, and the …


Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings Oct 2024

Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings

Research & Publications

Digital engineering practices offer significant yet underutilized potential for improving information assurance and system lifecycle management. This paper examines how capabilities like model-based engineering, digital threads, and integrated product lifecycles can address gaps in prevailing frameworks. A reference model demonstrates applying digital engineering techniques to a reference information system, exhibiting enhanced traceability, risk visibility, accuracy, and integration. The model links strategic needs to requirements and architecture while reusing authoritative elements across views. Analysis of the model shows digital engineering closes gaps in compliance, monitoring, change management, and risk assessment. Findings indicate purposeful digital engineering adoption could transform cybersecurity, operations, service …


Confronting The Reproducibility Crisis: A Case Study Of Challenges In Cybersecurity Ai, Richard H. Moulton, Gary A. Mccully, John D. Hastings Oct 2024

Confronting The Reproducibility Crisis: A Case Study Of Challenges In Cybersecurity Ai, Richard H. Moulton, Gary A. Mccully, John D. Hastings

Research & Publications

In the rapidly evolving field of cybersecurity, ensuring the reproducibility of AI-driven research is critical to maintaining the reliability and integrity of security systems. This paper addresses the reproducibility crisis within the domain of adversarial robustness—a key area in AI-based cybersecurity that focuses on defending deep neural networks against malicious perturbations. Through a detailed case study, we attempt to validate results from prior work on certified robustness using the VeriGauge toolkit, revealing significant challenges due to software and hardware incompatibilities, version conflicts, and obsolescence. Our findings underscore the urgent need for standardized methodologies, containerization, and comprehensive documentation to ensure the …


Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan Oct 2024

Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan

Research & Publications

As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …


A Survey Of Unikernel Security: Insights And Trends From A Quantitative Analysis, Alex Wollman, John Hastings Oct 2024

A Survey Of Unikernel Security: Insights And Trends From A Quantitative Analysis, Alex Wollman, John Hastings

Research & Publications

Unikernels, an evolution of LibOSs, are emerging as a virtualization technology to rival those currently used by cloud providers. Unikernels combine the user and kernel space into one ``uni''fied memory space and omit functionality that is not necessary for its application to run, thus drastically reducing the required resources. The removed functionality is significant however, and includes components that have become common security technologies such as Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), and Non-executable bits (NX bits). This raises questions about the security of unikernels. This research presents a quantitative methodology using TF-IDF to analyze the focus …


A Quantitative Study Assessing The Impact Of Financial Sector Safeguards Rules On Us Publicly Traded Companies' Cybersecurity Breach Frequency And Severity, Alan Dinerman Oct 2024

A Quantitative Study Assessing The Impact Of Financial Sector Safeguards Rules On Us Publicly Traded Companies' Cybersecurity Breach Frequency And Severity, Alan Dinerman

School of Public Service Theses & Dissertations

Cybersecurity failure in the private sector is a growing federal policy priority. Nevertheless, US policy makers struggle with policy instrumentation in this domain. Behavioral public policy theory asserts that a linkage exists between policy target behavioral & cultural attributes and effective policy tool instrumentation. The federal government is now embracing a regulation heavy approach, but little empirical study exists at the nexus of behavioral public policy theory and use of regulatory tools in the cybersecurity policy domain. Since the early 2000s, the financial sector has employed a regulation heavy approach using the Safeguards regulations to facilitate cybersecurity in financial private …


Real Time Pii Scanning, John David Aug 2024

Real Time Pii Scanning, John David

Electronic Theses and Dissertations

The increased amount of web applications and internet software solutions utilizing cloud frameworks has contributed to large data sets of system log messages being generated constantly. These messages may contain sensitive data, creating an additional security risk for the systems and contributing to the need for analysis of such large volumes of data in real time. Large commercial data monitoring systems can solve for these analysis requirements, but they can be costly. We present a solution to analyzing web application log data which ingests it, processes it and visualizes sensitive data found within in real time. Our solution utilizes an …


Assessment Of Web Security Vulnerabilities For Common Open Source Virtualization Software, Said Ally Aug 2024

Assessment Of Web Security Vulnerabilities For Common Open Source Virtualization Software, Said Ally

Tanzania Journal of Engineering and Technology (TJET)

Open-source hypervisors have emerged as an integral technology for virtualizing server resources in cloud and data center computing. Hypervisor security efficiency is determined by virtual machine isolation, which is a de facto adoption factor in the selection process, as well as its ability to respond to web attacks. This paper assesses the security performance of Proxmox VE and XenServer for type 1 hypervisors, and Kernel Virtual Machine and Oracle Virtual Box for type 2 hypervisors. Security analysis was conducted using common exposures extracted from vulnerability databases and mapped against the OWASP 2013 and 2017 projects. For clarity, experiments were carried …


Investigations Of Cell Tower Antennas Parameters On Reduction Of Radio Frequency Radiation Levels From Radio Base Stations, Florence U. Rashidi Aug 2024

Investigations Of Cell Tower Antennas Parameters On Reduction Of Radio Frequency Radiation Levels From Radio Base Stations, Florence U. Rashidi

Tanzania Journal of Engineering and Technology (TJET)

The widespread deployment of mobile cellular base stations in populated areas has raised public health concerns due to increased exposure to radio frequency (RF) radiation emissions. Exposure to high levels of RF radiation can have potential thermal and non-thermal biological effects. Optimizing the configuration of cell tower antenna parameters is crucial for mitigating these radiation levels. This study therefore aims at systematically investigating the influence of different cell tower antenna parameters on reducing the RF radiation levels from mobile base stations. Field measurements were conducted at two cell sites shared by multiple mobile operators. Electric field strengths were measured at …


Concept And Development Trend Of Novel E-Infrastructure Platform, Jing Xu, Chuan Tang, Kuangjunyu Yang, Juan Zhang, Ru Huang Aug 2024

Concept And Development Trend Of Novel E-Infrastructure Platform, Jing Xu, Chuan Tang, Kuangjunyu Yang, Juan Zhang, Ru Huang

Bulletin of Chinese Academy of Sciences (Chinese Version)

E-infrastructure platform has become a critical strategic asset for driving national scientific and technological innovation, and is the focus of strategic deployment by technologically advanced countries globally. This study, through the analysis of relevant strategy documents in the United States, European Union, and the United Kingdom, the relevant concepts and development changes of the novel E-infrastructure platform have been clarified. It also summarizes the planning process and development stages of e-infrastructure platform in the United States, Europe, and the United Kingdom, and analyzes that e-infrastructure platform will develop towards a new type of ecological, intelligent, diversified, and full process novel …


Evaluation Of Business-Driven Reference Architecture For Big Data Analytics Implementation By Public Sector Organizations In Resource-Constrained Setting: A Case Study Of Uganda, Matendo Didas Aug 2024

Evaluation Of Business-Driven Reference Architecture For Big Data Analytics Implementation By Public Sector Organizations In Resource-Constrained Setting: A Case Study Of Uganda, Matendo Didas

Tanzania Journal of Engineering and Technology (TJET)

Big Data Analytics (BDA) is a new area at the nexus of agenda, public sector organizations, and government business. It may satisfy the growing need for trustworthy, cost-effective services in the public sector for better, more informed decision-making processes. BDA has been proposed on the planning schedules of several public sector organizations and the government. Therefore, from the previous work, using Uganda as a case study, specifically the Uganda Bureau of Statistics (UBOS), Ministry of Health (MoH), and Ministry of Education and Sports (MoES), this study aims to evaluate a designed Business-Driven Reference Architecture for Big Data Analytics Implementation (BRABDAI) …


Data Communication Over Power-Lines: A Review On Technical, And Applications Challenges, Abdi Abdalla Aug 2024

Data Communication Over Power-Lines: A Review On Technical, And Applications Challenges, Abdi Abdalla

Tanzania Journal of Engineering and Technology (TJET)

This paper presents a review study on the data communication over power-lines, commonly referred to as power-line carrier, power-line communication (PLC), mains communications, or power-line digital subscriber line (PDSL). This study examines the technical and application advantages and challenges associated with adopting PLC as a preferred alternative technology for wideband or broadband data communication. The broader coverage area of the PLC network gives it a distinct advantage over other communication network technologies. Additionally, implementing a communication system using the existing power-line network is more cost-effective and less time-consuming compared to constructing a new network from scratch. However, the primary challenge …


Cybersecurity In Education, Rahima Shelim Aug 2024

Cybersecurity In Education, Rahima Shelim

Theses, Dissertations and Culminating Projects

Cybersecurity is becoming increasingly important as we rely more on digital devices and programs to conduct our daily lives, including the transfer and storage of personal information. According to research, one of the most critical stages in improving cybersecurity is to implement an effective security awareness program. In this work, we seek to understand the existing level of security knowledge among college students, industry professionals and create a module to help raise the awareness. Our module's primary elements are interaction and the display of alarming effects of reckless cyber behaviors among common Internet/technology users. This report presents a simple systematic …


A Privacy-Preserving Federated Learning Framework For Blockchain Networks, Youssif Abuzied, Mohamed Ghanem, Fadi Dawoud, Habiba Gamal, Eslam Soliman, Hossam Sharara, Tamer Elbatt Jul 2024

A Privacy-Preserving Federated Learning Framework For Blockchain Networks, Youssif Abuzied, Mohamed Ghanem, Fadi Dawoud, Habiba Gamal, Eslam Soliman, Hossam Sharara, Tamer Elbatt

Faculty Journal Articles

In this paper we introduce a scalable, privacy-preserving, federated learning framework, coined FLoBC, based on the concept of distributed ledgers underlying blockchains. This is motivated by the rapid growth of data worldwide, especially decentralized data which calls for scalable, decenteralized machine learning models which is capable of preserving the privacy of the data of the participating users. Towards this objective, we first motivate and define the problem scope. We then introduce the proposed FLoBC system architecture hinging on a number of key pillars, namely parallelism, decentralization and node update synchronization. In particular, we examine a number of known node update …


A Framework For Evaluating The Security And Privacy Of Smart-Home Devices, And Its Application To Common Platforms, Ravindra Mangar, Timothy Pierson, David Kotz Jul 2024

A Framework For Evaluating The Security And Privacy Of Smart-Home Devices, And Its Application To Common Platforms, Ravindra Mangar, Timothy Pierson, David Kotz

Dartmouth Scholarship

In this article, we outline the challenges associated with the widespread adoption of smart devices in homes. These challenges are primarily driven by scale and device heterogeneity: a home may soon include dozens or hundreds of devices, across many device types, and may include multiple residents and other stakeholders. We develop a framework for reasoning about these challenges based on the deployment, operation, and decommissioning life cycle stages of smart devices within a smart home. We evaluate the challenges in each stage using the well-known CIA triad—Confidentiality, Integrity, and Availability. In addition, we highlight open research questions at each stage. …


Development Of An Algorithm To Identify And Calculate The Amount Of File Slack On An Image Of A Given Drive, Nicholas Flynn Jul 2024

Development Of An Algorithm To Identify And Calculate The Amount Of File Slack On An Image Of A Given Drive, Nicholas Flynn

Honors Theses

As society increasingly relies on technology, the rates of cyber crime have been increasing at exponential rates. Cyber criminals are also discovering new ways to hide evidence of their crimes. This study develops a forensic analysis algorithm to evaluate the amount of file slack on an image of a drive. Slack space, leftover drive space on a disk sector after a file has been written, can be exploited to hide data. The algorithm aims to detect and calculate this slack space to help direct forensic investigations. The algorithm was evaluated on a population dataset of 100,000 files with random data …


How Do Preservice Teachers Learn To Teach Integrated Computational Thinking?: Evidence From Planning, Enactment, And Reflection, Rachael Dektor, Samuel Severance, Kip Téllez Jun 2024

How Do Preservice Teachers Learn To Teach Integrated Computational Thinking?: Evidence From Planning, Enactment, And Reflection, Rachael Dektor, Samuel Severance, Kip Téllez

Journal of Computer Science Integration

This study examines pre-service teachers’ (PSTs) beliefs and understandings about computational thinking (CT) integration and lesson implementation over time. Utilizing a design-based research approach, 3 PSTs led the co-design of integrated CT lessons with support from researchers and enacted these CT integrated lessons with K-5 students. All PSTs participated in a whole-group CT workshop and engaged in one-on-one lesson design sessions with a researcher. We utilized a grounded theory approach to qualitatively analyze pre-surveys, semi-structured interviews, and video data of three PSTs enacting their lessons. We found that PSTs’ initial beliefs about CT instruction – including the importance of it …


Securing Tomorrow: Synergizing Change Management And Cybersecurity In The Digital Era, Sharon L. Burton Jun 2024

Securing Tomorrow: Synergizing Change Management And Cybersecurity In The Digital Era, Sharon L. Burton

Publications

In the rapidly evolving business environment of 2024, organizational change management (OCM) leaders face unprecedented challenges driven by technological advancements, digital transformation, the integration of remote work, and a heightened focus on sustainability. This study examines the efficacy of traditional OCM models in addressing these modern complexities. Through a qualitative methodology employing an extensive literature review, the research identifies vital issues such as resistance to change, digital transformation imperatives, the shift to remote and hybrid work models, and the imperative for sustainable and ethical business practices. The study posits that while classical OCM frameworks offer foundational insights, there is a …


Evaluation Of Cybersecurity In Remote Working Settings For Mobile Network Operators, Victoria Mahabi Apr 2024

Evaluation Of Cybersecurity In Remote Working Settings For Mobile Network Operators, Victoria Mahabi

Tanzania Journal of Engineering and Technology (TJET)

Cybersecurity has increasingly been a primary concern to people as technology advances and allows them to work remotely. This study thus evaluated the cybersecurity posture for organisations that have opted for remote working culture, whereas emerging cyber threats, practices to combat them, and appropriate guidelines for managing cyber threats were discussed. The study used a descriptive design with a quantitative approach from 118 information technology personnel working for Tanzania's three major mobile network operators (MNOs). SPSS analysed the collected data. The study revealed that predominant cyber-threats affecting MNOs in remote working include human errors, phishing attacks, malicious domains, denial of …


Towards The Design And Evaluation Of Clickbait Education Content: Leveraging User Mental Models And Learning Science Principles, A. Shrestha, A. Flood, B. Hackler, Arezou Behfar, M. N. Al-Ameen Mar 2024

Towards The Design And Evaluation Of Clickbait Education Content: Leveraging User Mental Models And Learning Science Principles, A. Shrestha, A. Flood, B. Hackler, Arezou Behfar, M. N. Al-Ameen

Computer Science Student Research

Clickbait refers to sensationalized or misleading post on social networking sites (e.g., Facebook) that can trick users into clicking on malicious links. Clickbait is often used in cyberattacks, especially to conduct 'social engineering attacks' that direct users to malicious websites, resulting in disclosure of users' personal information or installing malicious software (i.e., malware). Thus, clickbait has become a major security concern with the recent boom in social media use. Therefore, security education has become necessary more than ever for the safe and secure use of social media, where there is dearth in security education literature to explore how we could …


Remote Controlled Cyber: Toward Engaging And Educating A Diverse Cybersecurityworkforce, Curtice Gough, Carl Mann, Cherrise Ficke, Maureen Namukasa, Meredith Carroll, Tj Oconnor Mar 2024

Remote Controlled Cyber: Toward Engaging And Educating A Diverse Cybersecurityworkforce, Curtice Gough, Carl Mann, Cherrise Ficke, Maureen Namukasa, Meredith Carroll, Tj Oconnor

Aeronautics Faculty Publications

Cybersecurity education has grown exponentially to support the need for a skilled cybersecurity workforce. Further, capture-the-flag competitions have popularized cybersecurity by engaging and recruiting students while exposing them to cybersecurity workforce competencies. However, the heavy reliance on competition-based educational approaches may contribute to the lack of diversity in cybersecurity programs. Cybersecurity competitions are the primary catalyst to expose and recruit students from both high school and collegiate cybersecurity education programs. In response, we propose a collaborative, experiential learning approach that leverages hackable Internet of Things (IoT) toys as a pedagogical tool for cybersecurity education. We share our detailed design, activities, …


Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson Mar 2024

Signal-To-Image Method For Counterfeit Detection In Layered Security Paradigm, Jordan Williamson

Theses and Dissertations

National level attention, resources, and priority regarding critical infrastructure have increased in recent years. This has led to adversaries and defenders exchanging positions between fortification and exploitation. One area that continues to be vulnerable is supply chain attacks like counterfeit insertion. This work investigates the application of converting collected signals into images from devices that may be considered for these critical networks. There are several aspects regarding the conversion of signals into images - specifically Red, Green, Blue (RGB) images. The methodology proposed here is potentially ideal fit for an initial security layer by achieving comparable classification results as more …


Broadening Participation Of Teachers In Computing: Examining Postsecondary Educational Experiences And Prospective Educators’ Cs Teaching Interests, Robert Schwarzhaupt, Alexsandra Galanis, Joanna Goode, Kate Blanchard, Jill Bowdon, Joseph P. Wilson Feb 2024

Broadening Participation Of Teachers In Computing: Examining Postsecondary Educational Experiences And Prospective Educators’ Cs Teaching Interests, Robert Schwarzhaupt, Alexsandra Galanis, Joanna Goode, Kate Blanchard, Jill Bowdon, Joseph P. Wilson

Journal of Computer Science Integration

Teacher shortages in K–12 computer science (CS) education negatively impact students’ access to CS courses, exposure to CS concepts, and interest in CS-related careers. To address CS teacher shortages, this study seeks to understand factors related to expressing a preference to teach CS among prospective teachers. The study team analyzed data from 27,700 prospective teacher applications accepted into the 2016–2020 Teach For America (TFA) corps (cohorts). The TFA corps is an alternative teacher development program that recruits and prepares participants to obtain their teaching certification while they work for at least two years in underserved communities on a temporary teaching …


Data Driven Trade-Off Analysis For Cybersecurity, Goskel Kucukkaya, Murat Ozer, Murat Balci, Emrah Ugurlu Jan 2024

Data Driven Trade-Off Analysis For Cybersecurity, Goskel Kucukkaya, Murat Ozer, Murat Balci, Emrah Ugurlu

Engineering Management & Systems Engineering Faculty Publications

Trade-off analysis, a specialization of systems engineering, addresses design criteria like security, cost, performance, and compliance. Monte Carlo simulations are commonly employed to generate impact scenarios for trade-off analysis combined with solution alternatives that accommodate industry-specific considerations and uncertainties. In the cyber domain, this paper proposes a methodology for data-driven trade-off analysis in cybersecurity, leveraging industry reports as primary data sources using confidentiality, integrity, and availability as trade-off analysis objectives. Distribution functions are derived to manage and model uncertainties for various industries. The approach given in this study aims to facilitate informed choices and to enhance cybersecurity decision making and …


Tapped In: The Rise Of Mobile Malware, Chrystofuer Davenport Jan 2024

Tapped In: The Rise Of Mobile Malware, Chrystofuer Davenport

Cybersecurity Undergraduate Research Showcase

As the world of technology continues to evolve and become more advanced with our life, so do the dangers and threats that are determined to hinder that development. Malware continues to be a danger to internet surfers or people with access to technology. At first it was an issue that existed only with computers but since the evolution of smartphones in the early twenty-first century, mobile devices have been a target for multiple malware viruses. It’s important to be aware of what different viruses are capable of doing and how to avoid them when they are encountered. Even though computers …


A Prototype Application For The Measurement Of Data Breach Event Intensity, James Palazzolo Jan 2024

A Prototype Application For The Measurement Of Data Breach Event Intensity, James Palazzolo

Master's Theses and Doctoral Dissertations

The data breach phenomenon is not new. People have valued information, its protection, and its security for centuries. A data breach is the loss of control over one’s information. In contemporary society (circa 2024), a data breach can occur in several ways: through accidental disclosure, negligence, or malicious action. Likewise, the study of the data breach phenomenon is not new. As with other studies, this research effort seeks to expand the current body of knowledge concerning data breaches. However, unlike previous research, we adopt a novel approach to further our understanding of the phenomenon. By employing topological and phenomenological thinking, …


Towards Trust And Reputation As A Service In Society 5.0, Stephan Olariu, Ravi Mukkamala, Meshari Aljohani Jan 2024

Towards Trust And Reputation As A Service In Society 5.0, Stephan Olariu, Ravi Mukkamala, Meshari Aljohani

Computer Science Faculty Publications

Our paper was inspired by the recent Society 5.0 initiative of the Japanese Government which seeks to create a sustainable human-centric society by putting to work recent advances in technology. One of the key challenges in implementing Society 5.0 is providing trusted and secure services for everyone to use. Motivated by this challenge, this paper makes three contributions that we summarize as follows: Our first main contribution is to propose a novel blockchain and smart contract-based trust and reputation service design to reduce the uncertainty associated with buyer feedback in marketplaces that we expect to see in Society 5.0. Our …


Qctaas (Quality Cloud Teaching As A Service): An Immersive Framework For Teaching Cloud Computing For Cybersecurity Majors, Mahmoud K. Quweider, Liyu Zhang, Alexis Aaron De La Cruz Jan 2024

Qctaas (Quality Cloud Teaching As A Service): An Immersive Framework For Teaching Cloud Computing For Cybersecurity Majors, Mahmoud K. Quweider, Liyu Zhang, Alexis Aaron De La Cruz

Informatics and Engineering Systems Faculty Publications

Abstract Cloud Computing and Cybersecurity are at the heart of our recently created new bachelor-level degree in cybersecurity that addresses the national need for cybersecurity specialists. Cloud Computing involves many service models, including IaaS, PaaS, and SaaS, and many deployment models including Public, Private, and Hybrid clouds. Within the services and deployment models lies many concepts and practical implementations that a Cyber-analyst needs to master. We have adopted an immersive approach to teaching Cloud Computing services that introduces standard concepts based on clearly defined objectives from national certification authorities such as CompTIA Cloud+, covering all major services offered by the …


Machine Learning Based Intrusion Detection Framework For Can Bus Vulnerabilities In Modern Vehicles, Obinna C. Agbo Jan 2024

Machine Learning Based Intrusion Detection Framework For Can Bus Vulnerabilities In Modern Vehicles, Obinna C. Agbo

Graduate Theses, Dissertations, and Problem Reports (ETD)

The Controller Area Network (CAN) bus is a crucial communication backbone in modern vehicles, connecting various Electronic Control Units (ECUs). However, inherent design weaknesses such as the lack of encryption and authentication make CAN networks vulnerable to cyber-attacks, including spoofing, Denial of Service (DoS), and fuzzing attacks. This thesis thoroughly evaluates these vulnerabilities and the limitations of existing security frameworks like Message Authentication Codes (MACs) and encryption, advocating for the adoption of Intrusion Detection Systems (IDS) as a more practical solution for CAN bus security. The proposed IDS leverages advanced machine learning techniques to accurately detect intrusions, even under complex …