Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity

Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 61 - 90 of 143

Full-Text Articles in Information Security

Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory May 2025

Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory

Honors Theses

Phishing attacks are a widespread, malicious phenomenon. These attacks steal people’s personal information, causing them ruin and lining the pockets of criminals. What makes them so dangerous is that they come in a variety of forms, including emails, websites, phone calls, and social media can be vectors for attackers. Fortunately, these attacks can be stopped by informing potential victims of common signs to look out for. Training is one of the best methods people use to teach web-users how to protect themselves. To train them, however, users must be taken through many examples of phishing attacks to learn the characteristics …


Leveraging P4 Programmable Switches For Resilient Operation And Design Of Phasor Measurement Unit Networks, Eva Casto May 2025

Leveraging P4 Programmable Switches For Resilient Operation And Design Of Phasor Measurement Unit Networks, Eva Casto

Electrical Engineering and Computer Science Undergraduate Honors Theses

The power grid utilizes a device called the phasor measurement unit (PMU), allowing power system administrators to remotely monitor and manage the state of the grid in Wide Area Monitoring Systems (WAMS). The advantages of PMUs – such as fine-grained, time-synchronized measurements and efficient, decentralized monitoring – are what make them key devices in the power grid. However, PMU technology also comes with new threats of the digital age, like malfunctions and cyberattacks, which can result in missing and faulty measurements that compromise power grid observability. P4 programmable networks can be used to detect faulty PMU data in a decentralized, …


Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green May 2025

Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green

Honors College Theses

As deepfake technology advances, cybercriminals are increasingly using AI-generated videos and audios to impersonate executives and carry out sophisticated CEO fraud schemes. These synthetic forgeries target human trust and corporate communication systems, creating an urgent need for forensic tools capable of authenticating digital evidence with legal accuracy. This thesis presents a forensic-grade AI deepfake detection pipeline designed for this purpose, emphasizing courtroom admissibility, reproducibility, and evidentiary integrity. Built entirely with free, opensource tools, the framework combines metadata analysis, AI-powered spectrogram analysis, neural artifact detection, and facial manipulation recognition into a transparent workflow that accurately identifies synthetic media. It was trained …


Managing Software Dependency Risks In Web Applications, Christopher Alan Scott May 2025

Managing Software Dependency Risks In Web Applications, Christopher Alan Scott

Electronic Theses and Dissertations

Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security …


Capturing The Digital Scene: Applying Routine Activity Theory To Iot Smart Frames, Jordan Bakar May 2025

Capturing The Digital Scene: Applying Routine Activity Theory To Iot Smart Frames, Jordan Bakar

Theses/Capstones/Creative Projects

This project investigates the forensic risks and investigative challenges posed by smart frames, which are WiFi-enabled Internet of Things (IoT) devices used to store, display, and share digital media. These devices often collect and synchronize sensitive media, metadata, and behavioral logs across cloud ecosystems that lack adequate transparency and privacy safeguards. Routine Activity Theory (RAT) provides a criminological framework for examining how the convergence of a motivated offender, a suitable target, and the absence of capable guardianship creates opportunities for misuse and forensic exploitation. Smart frames represent ideal targets because of weak default security configurations, passive data synchronization, and limited …


Cybersecurity's Pr Problem: The Education Gap Fueling Mfa Aversion, Tyler M. Stafford, Catherine Dwyer May 2025

Cybersecurity's Pr Problem: The Education Gap Fueling Mfa Aversion, Tyler M. Stafford, Catherine Dwyer

Honors College Theses

Through surveying individuals with no professional experience in cybersecurity, this study examines the relationship between awareness and education surrounding security controls and end users’ willingness to adopt them. The findings reveal a strong link between understanding the effectiveness of these controls and user comfort, indicating that as end users’ understanding increases, so does their willingness to use the controls. Working in both identity and access management (IAM) and human risk management, I observed what appeared to be a connection between security education and positive attitudes toward security more broadly, but found limited research statistically linking the two. This study’s findings …


5g Network Slice Vulnerabilities And Exploit Chaining Through Enablers, John Breeden May 2025

5g Network Slice Vulnerabilities And Exploit Chaining Through Enablers, John Breeden

Electronic Theses and Dissertations

Network slicing provides fundamental support for the enhanced features of 5G. Network slicing enablers, such as software-defined networking and network function virtualization facilitate the separation of the physical distributed infrastructures and the functions that create isolated slices. With this framework, the network slice is no longer under the control of a single entity. Multiple infrastructure providers share responsibility for the slice. The 5G architecture derives from multiple services, distributed over great distances, and managed by multiple parties. Each enabler and provider adds vulnerability to network slicing. We examine the interweaving of these enablers to identify vulnerabilities, discuss potential mitigation, and …


"Exploring The Training Data Landscape For Ai Based Threathunting For Protecting Intellectual Property", Manzi Siibo, Christopher Kreider Apr 2025

"Exploring The Training Data Landscape For Ai Based Threathunting For Protecting Intellectual Property", Manzi Siibo, Christopher Kreider

Cybersecurity Undergraduate Research Showcase

This study provides a comprehensive evaluation of the effectiveness that would result in the integration of AI into traditional threat hunting systems. To do so, 10-15 scholarly articles and data sets were evaluated to see the results of AI and machine learning threat hunting versus traditional systems. With so many proven benefits of this integration, this paper also explores how it impacts the protection of Intellectual property which is some of the most important forms of information that threat hunting systems aim to protect.


Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr. Apr 2025

Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr.

Cybersecurity Undergraduate Research Showcase

Geriatric crime continues to escalate in the digital era, where older individuals are disproportionately being targeted because of their low digital literacy and high susceptibility to online frauds. In this paper, we examine the breadth of elder fraud in Chesapeake, Virginia using FBI Internet Crime Complaint Center (IC3) data and state-level cybersecurity initiatives and survey responses. Older adults aged 60 and up have reported losses of over $3.4 billion in 2023 alone, underscoring the importance of proactive measures. It assesses the public awareness from traditional and AI-based perspectives revealing significant gaps in digital safety literacy and fraud reporting mechanism among …


Analysis Of Cybersecurity Threats And Mitigation Strategies: Theory In To Practice, Project Proposal, Fransly Dutervil Apr 2025

Analysis Of Cybersecurity Threats And Mitigation Strategies: Theory In To Practice, Project Proposal, Fransly Dutervil

Student Academic Conference

Cybersecurity threats pose significant risks to individuals and organizations, leading to data breaches, financial losses, and operational disruptions. This presentation explores key threats such as malware, phishing, DDoS attacks, insider threats, and zero-day exploits. It also discusses mitigation strategies, including network security measures, multi-factor authentication, encryption, and incident response planning. Through case studies of real-world cyber incidents, we highlight lessons learned and best practices to strengthen security defenses. The goal is to enhance awareness and promote proactive cybersecurity measures in an increasingly digital world.


Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu Apr 2025

Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu

Cybersecurity Undergraduate Research Showcase

Financial fraud, particularly credit card fraud, continues to pose substantial challenges to financial institutions due to its increasing frequency and impact on consumer trust. While traditional rule-based methods have provided foundational defenses, their limitations in scalability and adaptability have accelerated the adoption of machine learning (ML) techniques. Concurrently, Benford’s Law—a statistical principle often used in forensic accounting—has demonstrated efficacy in detecting anomalies within naturally occurring numerical datasets. This study explores a hybrid fraud detection approach that integrates Benford’s Law with supervised machine learning algorithms, including Logistic Regression, Random Forest, and k-Nearest Neighbors. Using the publicly available European credit card fraud …


Phishing Attacks And Prevention, Ruth Johnson Apr 2025

Phishing Attacks And Prevention, Ruth Johnson

Cybersecurity Undergraduate Research Showcase

Phishing attacks have been the number one leading cause of identity theft and financial theft since 1990. The internet is one of the leading places where individuals’ identity is stolen. Many businesses and government agencies have been at risk of cyber phishing attacks from foreign countries. Attacks on Several U.S. federal government agencies have been hit in a global cyberattack by Russian cybercriminals that exploit a vulnerability in widely used software, according to a top us cybersecurity agency (Lyngaas, Government hit cyber-attacks, 2023).

Phishing attacks are cybercrimes where one or many individuals steal sensitive information like passwords, credit card information, …


Securing Biometric Data, Alyssa F. Carroll Apr 2025

Securing Biometric Data, Alyssa F. Carroll

Cybersecurity Undergraduate Research Showcase

Biometric data has been widely adopted across various sectors, including digital identity, artificial intelligence (AI), border control, digital wallets, and national identification systems. While biometric identifiers—such as fingerprints, retina scans, and facial recognition—offer reliable and convenient authentication, they also raise significant concerns regarding privacy and security. This paper examines how biometric data is stored, the vulnerabilities it faces, and the most effective methods for safeguarding it. By highlighting the critical importance of biometric data protection, this study reviews current research on approaches, strategies, and policies that enhance security while preserving the functionality and efficiency of biometric systems.


Advanced Techniques In Symmetric Key Cryptanalysis, Debasmita Chakraborty Mar 2025

Advanced Techniques In Symmetric Key Cryptanalysis, Debasmita Chakraborty

Doctoral Theses

Symmetric key cryptographic primitives are essential tools used extensively in daily digital interactions. These primitives are mainly designed to provide three key services: ensuring data confidentiality, maintaining data integrity, and verifying the authenticity of data sources. The primary types of symmetric key primitives that deliver these services include block ciphers, stream ciphers, hash functions, message authentication codes, and authenticated encryption with associated data. This thesis mainly explores the security analysis of hash functions, several block ciphers, and stream ciphers using some advanced cryptanalytic techniques. We begin by examining the collision security of a hash function, specifically under the assumption that …


Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeff K. Holifield Mar 2025

Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeff K. Holifield

Shelby Hall Graduate Research Forum Posters

Real Time Operating Systems (RTOS) are increasing present throughout the industrial, business, defense, and healthcare spaces. These lightweight and efficient operating systems are designed to run on embedded, resource constrained devices, often within cyber-physical systems (CFS). A defining characteristic of RTOSs is that they are deterministic. Tasks are scheduled to run on fixed timelines within guaranteed execution windows. To accomplish tasks on time, real time software must conform to worst case execution times (WCETs) as design parameters. WCET is the maximum time a particular task can take to complete. Exceeding the WCET could cause system failure and lead to damage, …


Analysis Of Forensic Techniques For Additive Manufacturing Devices, Daniel B. Miller, Brad Glisson, Mark Yampolskiy, J Todd Mcdonald Mar 2025

Analysis Of Forensic Techniques For Additive Manufacturing Devices, Daniel B. Miller, Brad Glisson, Mark Yampolskiy, J Todd Mcdonald

Shelby Hall Graduate Research Forum Posters

Additive Manufacturing (AM) is a set of newer computer-dependent production technologies that is seeing rapid adoption across a wide variety of industries, including defense, aerospace, automotive, and healthcare. With increased adoption comes an increased opportunity for misuse and abuse of such systems, which will lead to an increased need for Digital Forensic investigations into these platforms. This research forensically analyzes a number of AM devices to explore the options available for data acquisition as well as the impacts of hardware and software design choices on the analysis and investigation results. Hardware is investigated using Open-Source Intelligence (OSINT) sources to determine …


Using Image-Based Representation For Network Intrusion Detection, Chakriya Suon, J. Todd Mcdonald Mar 2025

Using Image-Based Representation For Network Intrusion Detection, Chakriya Suon, J. Todd Mcdonald

Shelby Hall Graduate Research Forum Posters

The primary focus of our research is to evaluate the effectiveness of converting network traffic data, PCAPs, into image-based representations for anomaly-based network intrusion detection. We aim to analyze PCAPs to detect malware, or malicious software in hopes of creating a useful approach for anomaly detection against cyber threats including Advanced Persistent Threats (APTs). With the rise of cyber threats, cybersecurity continues to play a critical role in the ever-changing landscape of technology, by protecting and defending against threat agents. Our research will apply novel machine learning (ML) techniques to detect potential malware transmitted over a network effectively. The overall …


Security Vulnerabilities Of A Field Programmable Gate Array, Kylie Arnett Mar 2025

Security Vulnerabilities Of A Field Programmable Gate Array, Kylie Arnett

Shelby Hall Graduate Research Forum Posters

The primary goal of this research is to understand and exploit the security vulnerabilities of a Field Programmable Gate Array (FPGA), at the bitstream level. This paper is working to successfully show that an FPGA can be altered via the bitstream file, and a Trojan can be inserted into the device. Once a Trojan is successfully inserted into the FPGA and activated through a certain input value, a Siamese Neural Network (SNN) will be used to test the effectiveness of Trojan detection. Followed by recording the successful flag rate to detect Trojans, which will be averaged to determine the accuracy …


Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems, Krista Stacey, Todd R. Andel Mar 2025

Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems, Krista Stacey, Todd R. Andel

Shelby Hall Graduate Research Forum Posters

The rapid evolution of computational ecosystems—ranging from embedded systems and cloud platforms to hybrid and quantum architectures—has introduced new challenges in deploying machine learning (ML) applications. While cloud computing offers scalability, it comes with increased latency and security risks, whereas edge computing, such as FPGA-based systems, provides real-time processing with constrained resources. Hybrid and quantum ecosystems further complicate decision-making, requiring careful trade-offs between performance and security. This research seeks to establish a framework for evaluating ML performance and security risks across these ecosystems, forming the foundation of the Computational Performance And Security System (COMPASS) decision-support tool. The study will systematically …


Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive, Nicholas Flynn, Michael Black Mar 2025

Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive, Nicholas Flynn, Michael Black

Shelby Hall Graduate Research Forum Posters

Current forensic tools struggle to effectively detect encrypted storage media. In recent years, there have been significant advancements, but a noticeable gap remains when it comes to identifying encrypted volumes from metadata alone. The goal of this research is to develop a novel algorithm that will identify the presence of volumes on a disk image which have been encrypted with the Linux Unified Key Setup (LUKS) encryption algorithm, in an effort to aid digital forensics investigations. Bad actors often use encryption as an anti-forensics tool to pose significant challenges to forensic investigators, especially when it is done within sections of …


False Narratives, Real Consequences, Russell W. Cantrell, Matt Campbell Mar 2025

False Narratives, Real Consequences, Russell W. Cantrell, Matt Campbell

Shelby Hall Graduate Research Forum Posters

Social media is an increasingly significant tool in modern cyber warfare, capable of rapidly shaping public opinion. The swift dissemination of information complicates efforts to distinguish fact from fiction [1]. During public health crises, healthcare professionals use these platforms to share updates, yet their credible content must contend with false or deliberately misleading narratives [2]. This environment creates an opportunity for cyberattacks through social media influence campaigns [3]. While disinformation's role in political interference has been widely studied, its potential to destabilize healthcare remains largely unexplored. Prior research primarily focuses on how vaccine misinformation affects the general public [4]. This …


Detecting Sensor Data Manipulation, Ricky Green, Michael Black Mar 2025

Detecting Sensor Data Manipulation, Ricky Green, Michael Black

Shelby Hall Graduate Research Forum Posters

The integration of Information Technology (IT) and Operational Technology (OT) have made OT devices vulnerable to threats that have been successfully exploited with devastating results. Many modern techniques for hardening and securing enterprise IT systems are either incompatible with OT components in an Industrial Control System (ICS), reduce the efficiency of processes, or are prohibitively expensive to implement. Research in the area of ICS security focuses on a top-down approach, such as intrusion prevention by securing the perimeter of the network and hardening computer systems. This approach is useful in business IT systems, but full compatibility with OT components in …


Provable Security In Idealised Models, Chandranan Dhar Feb 2025

Provable Security In Idealised Models, Chandranan Dhar

Doctoral Theses

This thesis is a compilation of provable security analyses of various cryptographic constructions in idealised models. The first construction examined is the ABR hash. We revisit the existing proof of the ABR hash in the random oracle model and identify significant errors in the proof. Although we are unable to correct the original proof, we establish the security of the ABR tree of height 3 from scratch, addressing the first non-trivial case. As our second contribution, we conduct a tight and comprehensive security analysis of the Ascon AEAD mode in the random permutation model. We show that the efficiency of …


"It's Definitely New And Different...It's Really Engaging": Understanding The Power Of Storytelling Towards Secure Password Creation, Rizu Paudel, Mahdi Nasrullah Al-Ameen Jan 2025

"It's Definitely New And Different...It's Really Engaging": Understanding The Power Of Storytelling Towards Secure Password Creation, Rizu Paudel, Mahdi Nasrullah Al-Ameen

Computer Science Student Research

There is a dearth in existing literature to attain systematic understanding of leveraging digital storytelling in security designs. As we begin to address this gap, we focused on user authentication where the existing password composition policies and password meters often fail to help users around creating a strong and memorable password. To this end, we conducted a lab study with 19 participants, where we updated our initial designs in an iterative manner based on their feedback. We then conducted a between-subject online study with 104 participants over Amazon Mechanical Turk to evaluate our designs. We found that all of our …


Computing In The Commonwealth: Specialized Education In Computer Science And Information Technology For High School Students In Virginia – An Environmental Scan, Amy Corning, Jonathan D. Becker, Jon Graham, James Carrigan, Keisha Tennessee Jan 2025

Computing In The Commonwealth: Specialized Education In Computer Science And Information Technology For High School Students In Virginia – An Environmental Scan, Amy Corning, Jonathan D. Becker, Jon Graham, James Carrigan, Keisha Tennessee

ICRE Publications

Over the past two decades, Virginia has invested substantially in STEM education, in part through specialized programs focused on computer science and information technology (CS/IT). This study represents the first effort to identify Virginia’s specialized secondary CS/IT programs and examine them collectively. Findings from the statewide environmental scan indicate that the programs are delivered through a wide variety of institutional structures, including Governor’s STEM Academies, Governor’s Schools, specialty centers, and academies, but most often through Career and Technical Education (CTE) centers. Programs tend to be concentrated in metropolitan areas, and some rural divisions may not be served. The programs provide …


A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings Jan 2025

A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings

Research & Publications

This study investigates the prevalence and underlying causes of work-related stress and burnout among cybersecurity professionals using a quantitative survey approach guided by the Job Demands-Resources model. Analysis of responses from 50 cybersecurity practitioners reveals an alarming reality: 44% report experiencing severe work-related stress and burnout, while an additional 28% are uncertain about their condition. The demanding nature of cybersecurity roles, unrealistic expectations, and unsupportive organizational cultures emerge as primary factors fueling this crisis. Notably, 66% of respondents perceive cybersecurity jobs as more stressful than other IT positions, with 84% facing additional challenges due to the pandemic and recent high-profile …


Technology-Facilitated Abuse (Tfa): Analyzing Trends, Tactics, And Victim Responses On Reddit, Solomon G. Dandekar Jan 2025

Technology-Facilitated Abuse (Tfa): Analyzing Trends, Tactics, And Victim Responses On Reddit, Solomon G. Dandekar

Computer Science and Engineering Theses - Archive

The increasing integration of technology into daily life has provided numerous benefits but also significant risks, particularly when exploited by malicious actors in cases of technology facilitated abuse (TFA). Per- petrators can misuse technology to monitor, control, and intimidate their partners, random strangers, etc. exacerbating cycles of abuse. From location tracking and cellphone surveillance to smart device manipula- tion, spyware, and doxing, digital tools have become powerful instruments for coercion and control. This research project investigates the role of technology in stalking and harassment by analyzing discussions on a relevant subreddit where victims share their experiences, strategies for coping, and …


Scalable Approaches Towards Characterizing And Mitigating Emerging Phishing Scams, Sayak Saha Roy Jan 2025

Scalable Approaches Towards Characterizing And Mitigating Emerging Phishing Scams, Sayak Saha Roy

Computer Science and Engineering Dissertations - Archive

Phishing scams are among the most dangerous and persistent forms of cybercrime, leveraging social engineering to exploit human behavior and obtain sensitive information, leading to widespread identity theft and data breaches. In the past year, these attacks have resulted in financial losses exceeding $10 billion in the United States alone. As phishing scams continue to evolve, they have not only expanded in scale but also grown in sophistication, spreading rapidly across social media and employing adversarial techniques to evade detection by anti-scam tools. The situation is further exacerbated by the availability of advanced phishing kits, and more recently, generative AI, …


Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu Jan 2025

Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu

Research & Publications

Ransomware and other malware inflict devastating financial and operational damage on organizations worldwide by exploiting deeply embedded, hard-to-detect vulnerabilities in their systems. Detecting these vulnerabilities in compiled code before malicious actors exploit them remains a critical challenge in cybersecurity. This research introduces TEDVIL (Transformer-based Embeddings for Discovering Vulnerabilities in Lifted Code), a novel framework which uses transformer-based embeddings to train neural networks to detect vulnerabilities in lifted code. The framework was implemented using bidirectional (BERT and RoBERTa) and unidirectional (GPT-1 and GPT-2) transformer-based models to generate embeddings for training Long Short-Term Memory (LSTM) neural networks to detect stack-based buffer overflows …


Signal-Based Error Handling: Case Study Using The Bathymetric Attributed Grid Library, Anthony R. Papetti Jan 2025

Signal-Based Error Handling: Case Study Using The Bathymetric Attributed Grid Library, Anthony R. Papetti

Honors Theses and Capstones

No abstract provided.