Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Old Dominion University (32)
- Dakota State University (10)
- University of South Alabama (10)
- Kennesaw State University (6)
- University of Malaya (6)
-
- California State University, San Bernardino (4)
- Indian Statistical Institute (4)
- University of South Florida (4)
- City University of New York (CUNY) (3)
- Dartmouth College (3)
- Embry-Riddle Aeronautical University (3)
- Georgia Southern University (3)
- The University of Akron (3)
- University of Nebraska at Omaha (3)
- University of Texas at Arlington (3)
- Bridgewater College (2)
- California Polytechnic State University, San Luis Obispo (2)
- Liberty University (2)
- Marshall University (2)
- Minnesota State University Moorhead (2)
- University of North Florida (2)
- Western Kentucky University (2)
- American University in Cairo (1)
- Bemidji State University (1)
- Chinese Academy of Sciences (1)
- Columbus State University (1)
- East Tennessee State University (1)
- Eastern Michigan University (1)
- Grand Valley State University (1)
- LSU New Orleans (1)
- Keyword
-
- Cybersecurity (21)
- Artificial intelligence (6)
- Machine learning (6)
- Security (6)
- Privacy (5)
-
- Machine Learning (4)
- Phishing (4)
- Blockchain (3)
- Cryptography (3)
- Data privacy (3)
- Information security (3)
- Network security (3)
- Ransomware (3)
- Training (3)
- Vulnerability (3)
- AI Security (2)
- Adversarial Attacks (2)
- Anonymity (2)
- COVID-19 (2)
- Cybersecurity education (2)
- Cyberterrorism (2)
- Data models (2)
- Digital Forensics (2)
- Digital forensics (2)
- Dissertations, Academic -- UNF -- Computing (2)
- Dissertations, Academic -- UNF -- Master of Science in Computer and Information Sciences (2)
- Experiential learning (2)
- Extraction (2)
- Feature extraction (2)
- Generative AI (2)
- Publication Year
- Publication
-
- Cybersecurity Undergraduate Research Showcase (15)
- Research & Publications (10)
- Shelby Hall Graduate Research Forum Posters (8)
- Computer Science Faculty Publications (6)
- Journal of Cybersecurity Education, Research and Practice (5)
-
- Military Cyber Affairs (4)
- Student Works (2000-2009) (4)
- College of Graduate Studies: Theses & Dissertations (3)
- Doctoral Theses (3)
- Electronic Theses and Dissertations (3)
- Electronic Theses, Projects, and Dissertations (3)
- Engineering Management & Systems Engineering Faculty Publications (3)
- Student Theses (3)
- Theses/Capstones/Creative Projects (3)
- Williams Honors College, Honors Research Projects (3)
- Doctoral Dissertations and Master's Theses (2)
- Electrical & Computer Engineering Faculty Publications (2)
- Graduate Theses and Dissertations (2019 - present) (2)
- Honors College Theses (2)
- Honors Theses (2)
- Master's Theses (2)
- School of Cybersecurity Faculty Publications (2)
- Senior Honors Theses (2)
- Senior Seminars (2)
- Student Works (2020-2029) (2)
- Theses, Dissertations and Capstones (2)
- UNF Graduate Theses and Dissertations (2)
- African Conference on Information Systems and Technology (1)
- All Graduate Theses, Dissertations, and Other Capstone Projects (1)
- Bulletin of Chinese Academy of Sciences (Chinese Version) (1)
- Publication Type
- File Type
Articles 91 - 120 of 143
Full-Text Articles in Information Security
A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty
A Trust-By-Learning Framework For Secure 6g Wireless Networks Under Native Generative Ai Attacks, Md Shirajum Munir, Sravanthi Proddatoori, Manjushree Muralidhara, Trinidad Mario Dena, Walid Saad, Zhu Han, Sachin Shetty
Center for Secure and Intelligent Critical Systems (CSICS) Publications
Sixth-generation (6G) wireless networks will become vulnerable due to native generative AI (GenAI)-driven intelligent poisoning attacks in both the radio unit and the core network. In particular, network parameters and metrics in cross-layer design pose fundamentally uncertain conditions and can be compromised through the native GenAI mechanism, which leverages data augmentation and reconstruction capabilities. This work investigates the capabilities of native GenAI to create novel poisoning attacks in wireless networks, while investigating their impact through uncertainty-informed root analysis. Then, detected attacks are mitigated by developing a trustworthy service aggregation in the wireless network. First, a joint decision problem is formulated …
A Systematic Review And Taxonomy For Privacy Breach Classification: Trends, Gaps, And Future Directions, Clint Fuchs, John Hastings
A Systematic Review And Taxonomy For Privacy Breach Classification: Trends, Gaps, And Future Directions, Clint Fuchs, John Hastings
Research & Publications
In response to the rising frequency and complexity of data breaches and evolving global privacy regulations, this study presents a comprehensive examination of academic literature on the classification of privacy breaches and violations between 2010-2024. Through a systematic literature review, a corpus of screened studies was assembled and analyzed to identify primary research themes, emerging trends, and gaps in the field. A novel taxonomy is introduced to guide efforts by categorizing research efforts into seven domains: breach classification, report classification, breach detection, threat detection, breach prediction, risk analysis, and threat classification. An analysis reveals that breach classification and detection dominate …
Dynamic Analysis Of Malware Detection Using Customized Payloads: Examining The Effectiveness Of Manual And Automated Approaches In Web Applications, Jiban Krisna Das
Dynamic Analysis Of Malware Detection Using Customized Payloads: Examining The Effectiveness Of Manual And Automated Approaches In Web Applications, Jiban Krisna Das
College of Graduate Studies: Theses & Dissertations
Web applications are becoming the prime targets for cyber-attacks, where SQL injection (SQLi) and Cross Site Scripting (XSS) are the most exploited vulnerabilities. The study explores a novel approach using customized payloads to examine the effectiveness of manual and automated techniques of malware detection. This dynamic approach can effectively generate attack payloads and identify the vulnerabilities in a website thereby strengthening website security measures. This research focuses on dynamic analysis in a controlled environment while testing and analyzing SQL and XSS payloads under varying security conditions. This quantitative analysis involves crafting targeted payloads to bypass Web Application Firewall (WAF) filters …
Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi
Exploring Research And Tools In Ai Security: A Systematic Mapping Study, Sidhant Narula, Mohammad Ghasemigol, Javier Carnerero-Cano, Amanda Minnich, Emil Lupu, Daniel Takabi
School of Cybersecurity Faculty Publications
With the pervasive integration of artificial intelligence (AI) in various facets of modern technology, the importance of AI security has been thrust into the spotlight. The field is rapidly evolving, with new challenges and solutions emerging at a swift pace. However, the breadth and depth of AI security research have not been comprehensively mapped in recent times, presenting a crucial need for an extensive review and synthesis of existing literature. Given the increasing reliance on AI in critical domains such as healthcare, finance, and national security, ensuring the resilience and trustworthiness of these systems is imperative. This survey fulfills the …
Privacy-Preserved And Incentivized Knowledge Sharing For Reinforced-Learning Based Iot Platform Security, Weichao Wang, Md Morshed Alam, Yu Wang
Privacy-Preserved And Incentivized Knowledge Sharing For Reinforced-Learning Based Iot Platform Security, Weichao Wang, Md Morshed Alam, Yu Wang
School of Cybersecurity Faculty Publications
With the fast development and deep penetration of IoT devices and smart environments, using localized machine learning models to detect malicious activities has also been developed and deployed. However, these isolated learning models and results cannot be effectively federated together because of privacy concerns and lack of incentivization. This paper proposed several mechanisms to solve the problem. A verification method was designed for phased learning results to protect user privacy and prevent individual parties from manipulating the verification selection. The paper also presented an incentive method based on delay of distribution of the latest federated learning results. Extensive simulations were …
Zero Trust Architecture As A Risk Countermeasure In Small-Medium Enterprises And Advanced Technology Systems, Ahmed M. Abdelmagid, Rafael Diaz
Zero Trust Architecture As A Risk Countermeasure In Small-Medium Enterprises And Advanced Technology Systems, Ahmed M. Abdelmagid, Rafael Diaz
Engineering Management & Systems Engineering Faculty Publications
The growing sophistication of cyberattacks exposes small- and medium-sized businesses (SMBs) to a widening range of security risks. As these threats evolve in complexity, the need for advanced security measures becomes increasingly pressing. This necessitates a proactive approach to defending against potential cyber intrusions. Emerging technologies, such as blockchain, artificial intelligence, and Zero Trust security framework, offer crucial tools for strengthening the digital infrastructure of SMBs. The Zero Trust architecture (ZTA) holds significant promise as a critical strategy for protecting SMBs. While existing literature explores the implementation of ZTA in various business settings, discussions specifically addressing the financial, human resource, …
A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective, Sujatha Alla, Sai Gireesh Komaragiri, Teresa Duvall, Satluk Karahan, Nagesh Bheesetty, Vijay Kumar Chattu
A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective, Sujatha Alla, Sai Gireesh Komaragiri, Teresa Duvall, Satluk Karahan, Nagesh Bheesetty, Vijay Kumar Chattu
Engineering Management & Systems Engineering Faculty Publications
Healthcare systems face unprecedented security and privacy challenges due to increasing digitization and interconnectedness. This paper provides a comprehensive analysis of these challenges by examining various cyberattacks, defensive mechanisms, and governance frameworks within modern healthcare infrastructure. The research systematically categorizes prevalent security threats, such as ransomware, insider threats, and data breaches, identifying vulnerabilities specific to healthcare systems. Furthermore, the study evaluates current defensive strategies, including encryption techniques, access control systems, and intrusion detection tools, assessing their effectiveness against complex cyber threats. A key focus is placed on governance structures and their role in cybersecurity resilience. The research explores how regulatory …
Potsdam: Pareto Optimization Targeting Security, Data, And Mediation, J Peter Brady
Potsdam: Pareto Optimization Targeting Security, Data, And Mediation, J Peter Brady
Dartmouth College Ph.D Dissertations
Given the growing amount and variety of data handled by modern systems, it is crucial to guarantee the accuracy and protection of input data without errors or malicious intentions. The need to improve security in software programs often conflicts with the assurance of maximum performance, making developers and maintainers hesitant to incorporate more testing.
LangSec (Language-Theoretic Security) is a security approach that treats input validation as a formal language recognition problem, ensuring that only well-defined, unambiguous inputs are processed to eliminate exploitable parsing flaws. This dissertation explores integrating LangSec principles with Pareto optimization to enhance safety and robustness in digital …
Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu
Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu
Engineering Management & Systems Engineering Faculty Publications
Port infrastructures are critical to global trade, handling over 80% of the world's cargo by volume. However, their increasing reliance on digital technologies has exposed them to a wide range of cyber threats. This paper provides a comprehensive analysis of cyberattacks targeting port infrastructures from 2011 to the present. We examine the types of attacks, geographical distribution, notable incidents, and underlying vulnerabilities. Additionally, we discuss mitigation strategies and future directions for enhancing cybersecurity in the maritime sector. Our findings highlight the urgent need for robust regulatory frameworks, advanced technological solutions, and collaborative efforts to safeguard critical port operations.
Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen
Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen
Electrical & Computer Engineering Faculty Publications
The static nature of traditional military symbology, such as MIL-STD-2525D, hinders effective real-time threat detection and response in modern cybersecurity operations. This research introduces the Dynamic Adaptive Symbol System (DASS), a novel framework enhancing cyber situational awareness in military and enterprise environments. The DASS addresses static symbology limitations by employing a modular Python 3.10 architecture that uses machine learning-driven threat detection to dynamically adapt symbol visualization based on threat severity and context. Empirical testing assessed the DASS against a MIL-STD-2525D baseline using active cybersecurity professionals. Results show that the DASS significantly improves threat identification rates by 30% and reduces response …
Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu
Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu
Computer Science Faculty Publications
Private inference applies cryptographic techniques like homomorphic encryption, garble circuit and secret sharing to keep both sides privacy in a client-server setting during inference. It is often hindered by the high communication overheads, especially at non-linear activation layers such as ReLU. Hence ReLU pruning has been widely recognized as an efficient way to accelerate private inference. Existing approaches to ReLU pruning typically rely on coarse hypothesis, which assume an inverse correlation between the importance of ReLU and linear layers or shallow activation layers have less importance for universal models, to assign the budgets according to the layer while preserving the …
Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh
Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh
Computer Science Faculty Publications
Detecting malicious Internet domains is essential for safeguarding against various online threats. The current approach to detecting malicious domains (MDD) employs a graph neural network (GNN) method, which uses DNS logs to construct heterogeneous graphs for determining the maliciousness of unknown domains. Despite its success, this method is vulnerable to data poisoning attacks where an adversary can manipulate specific graph nodes to implant a backdoor into the model during training. To showcase the vulnerability, we propose a stealthy trigger injection attack on node features and graph structure in MDD, dubbed (STING). The attacker carefully manipulates selected features and edges of …
Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li
Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li
Computer Science Faculty Publications
Large Language Models (LLMs) exhibit strong natural language processing capabilities but also pose significant privacy risks, particularly regarding the leakage of Personally Identifiable Information (PII) embedded in their training data. Existing PII extraction methods suffer from the limitations of low success rates or impracticality for large-scale PII extraction. In this study, we propose a novel PII extraction approach based on enhanced few-shot learning techniques, which achieves efficient and cost-effective PII retrieval without relying on fine-tuning or jailbreaking. We evaluated our approach on both open-source and closed-source LLMs. The experimental results demonstrate that, for non-targeted PII extraction, the attack success rate …
Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang
Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang
Computer Science Faculty Publications
Large Language Models (LLMs) have demonstrated exceptional success across a variety of tasks, particularly in natural language processing, leading to their growing integration into numerous facets of daily life. However, this widespread deployment has raised substantial privacy concerns, especially regarding personally identifiable information (PII), which can be directly associated with specific individuals. The leakage of such information presents significant real-world privacy threats. In this paper, we conduct a systematic investigation into existing research on PII leakage in LLMs, encompassing commonly utilized PII datasets, evaluation metrics, and current studies on both PII leakage attacks and defensive strategies. Finally, we identify unresolved …
Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang
Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang
Electronic Theses & Dissertations (2024 - present)
The increasing frequency and severity of ransomware attacks pose significant challenges for organizational cybersecurity. Fragmentation across disciplines in cyber defense has created practical gaps in the development of the necessary capabilities needed to address rapidly evolving cyber threats. This study explores the impact of ransomware attacks and the evolving role of cyber insurance as a proactive cybersecurity partner. Bridging the gap between actuarial science and cyber risk management, it proposes an interdisciplinary framework that quantifies the impact of ransomware and integrates cyber insurance into cybersecurity strategies.
The primary contribution of this study is methodology. We present a framework that remains …
Toward An Insider Threat Education Platform: A Theoretical Literature Review, Haywood Gelman, John D. Hastings, David Kenley, Eleanor Loiacono
Toward An Insider Threat Education Platform: A Theoretical Literature Review, Haywood Gelman, John D. Hastings, David Kenley, Eleanor Loiacono
Research & Publications
Insider threats (InTs) within organizations are small in number but have a disproportionate ability to damage systems, information, and infrastructure. Existing InT research studies the problem from psychological, technical, and educational perspectives. Proposed theories include research on psychological indicators, machine learning, user behavioral log analysis, and educational methods to teach employees recognition and mitigation techniques. Because InTs are a human problem, training methods that address InT detection from a behavioral perspective are critical. While numerous technological and psychological theories exist on detection, prevention, and mitigation, few training methods prioritize psychological indicators. This literature review studied peer-reviewed, InT research organized by …
Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang
Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang
Research & Publications
The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach …
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings
Research & Publications
This paper presents a multi-cloud networking architecture built on zero trust principles and micro-segmentation to provide secure connectivity with authentication, authorization, and encryption in transit. The proposed design includes the multi-cloud network to support a wide range of applications and workload use cases, compute resources including containers, virtual machines, and cloud-native services, including IaaS (Infrastructure as a Service), PaaS (Platform as a service). Furthermore, open-source tools provide flexibility, agility, and independence from locking to one vendor technology. The paper provides a secure architecture with micro-segmentation and follows zero trust principles to solve multi-fold security and operational challenges.
Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns, Jared Wise
Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns, Jared Wise
LSU New Orleans Theses and Dissertations
In the digital age, text-based passwords remain a primary method for securing online accounts. Yet, users frequently face a dilemma between creating passwords that are easy to remember and sufficiently secure against cyberattacks. This research introduces an approach to password generation that bridges this gap by utilizing linguistic patterns, particularly song lyrics, to develop highly secure and naturally memorable passwords. Using large lyric datasets gained from web scrapes from popular song lyric websites (AZ Lyrics, Genius), features are extracted from a corpus of over 5 million lyrics using sentence structure and natural language processing in a novel way. In using …
Container Runtime Vulnerability Mitigation Using User Namespace Isolation, Alexander Edsell
Container Runtime Vulnerability Mitigation Using User Namespace Isolation, Alexander Edsell
Electronic Theses, Projects, and Dissertations
Although containers have revolutionized application deployment by allowing for rapid and consistent deployment, their growing adoption has also raised significant security concerns. Each container is an isolated instance of an operating system that comes pre-packaged with the users desired applications. With multiple containers running on a host machine, an adversary can potentially break out of the container into the host machine. This project investigates the effectiveness of user namespace isolation as a security mechanism to mitigate container escape vulnerabilities that target the container’s runtime.
The research questions are: Question 1, does user namespace isolation mitigate container runtime vulnerabilities that target …
Hybrid Deep Learning-Based Model For Eclipse Attack Detection On Ethereum Network, Dhanasak Bhumichai
Hybrid Deep Learning-Based Model For Eclipse Attack Detection On Ethereum Network, Dhanasak Bhumichai
Graduate Theses and Dissertations (2019 - present)
An eclipse attack is a significant cyber threat targeting the network layer of blockchain platforms. Detecting eclipse attacks is challenging for several reasons. First, there are no available datasets for training and testing models. Second, comprehensive studies identifying features to detect eclipse attacks are lacking. Additionally, the amount of eclipse network traffic is much smaller than that of normal network traffic, which leads to imbalanced samples. Moreover, the characteristics of eclipse network traffic closely resemble those of normal traffic, causing overlapping samples, which makes it challenging for traditional classifiers to learn how to identify eclipse attacks. To address these challenges, …
Exploring Secure Methods For Ensuring Data Integrity: A Theoretical Analysis Of Cryptographic And Detection Techniques, Haryam Garcia Martinez
Exploring Secure Methods For Ensuring Data Integrity: A Theoretical Analysis Of Cryptographic And Detection Techniques, Haryam Garcia Martinez
Electronic Theses, Projects, and Dissertations
This study investigates cryptographic methods to ensure data integrity within cloud environments, with a particular focus on comparing the security, performance, and efficiency of MD5 and SHA-256 hash algorithms. Data integrity is critical for protecting sensitive information, especially in sectors like healthcare, where cloud storage solutions are increasingly prevalent. Through a theoretical analysis, the study evaluates the advantages and limitations of MD5 and SHA-256, emphasizing SHA-256’s stronger security capabilities in preventing collision attacks compared to MD5, albeit with higher resource consumption.
The literature review draws from recent advancements in cryptography, blockchain, and artificial intelligence (AI) technologies, presenting a comprehensive view …
The Effects Of Covid-19 Lockdowns On Cybersecurity, Natalie Sanders
The Effects Of Covid-19 Lockdowns On Cybersecurity, Natalie Sanders
Electronic Theses, Projects, and Dissertations
The COVID-19 pandemic and subsequent lockdowns forced many Americans to quickly adapt to working from home, many of which had never done so in the past. In addition, organizations were forced to modify security policies and protocols to allow for remote access to sensitive information. The rapid change in security policies as well as the sudden growth of remote access during the pandemic presented a broader landscape for cyber criminals to attack. In this report, we review the number and type of cyberattacks reported from two (2) years before the pandemic through two (2) years after (1998 through 2023), to …
Digital Humanities: Using Computational Methods On Literature To Understand Human-Water Relations, Ariel Yang
Digital Humanities: Using Computational Methods On Literature To Understand Human-Water Relations, Ariel Yang
Cybersecurity Undergraduate Research Showcase
By using computational techniques to analyze literature, deeper insights can be gained into human-water relationships across different historical and cultural contexts. Natural Language Processing (NLP) and other data science methods can explore applications of traditional ecological knowledge (TEK) and underlying emotions or beliefs in literature to help understand sustainability. Protecting this sensitive cultural data through ethical applications can further secure future implementations of policies, urban planning, and environmental relationships.
Security Vulnerabilities In Mobile Operating Systems Used In Iot Devices: An Examination Of Current Challenges And Countermeasures, Isain Cortes Jr.
Security Vulnerabilities In Mobile Operating Systems Used In Iot Devices: An Examination Of Current Challenges And Countermeasures, Isain Cortes Jr.
Cybersecurity Undergraduate Research Showcase
No abstract provided.
A Dynamical Systems Approach For Modeling Malware Propagating Through A Network And Potential Solutions Towards Mitigating Spread, James Johnson
A Dynamical Systems Approach For Modeling Malware Propagating Through A Network And Potential Solutions Towards Mitigating Spread, James Johnson
Cybersecurity Undergraduate Research Showcase
Many people draw close parallels between malware propagating through a network and an epidemic spreading through a population. Epidemics are often modeled by a Susceptible-Infected-Recovered (SIR) model, in which a similar system of equations can model the spread of a virus through a computer network, and can be simplified when making assumptions about the network itself and its fixed number of nodes and edges. In this instance, malware propagating in a network also should reflect the network it is propagating through, in which the dynamical system will factor in the nodes of the network and their properties. The system itself …
Phishing Emails: An Evolving Cyberattack, Brooke Waltz
Phishing Emails: An Evolving Cyberattack, Brooke Waltz
Cybersecurity Undergraduate Research Showcase
This paper describes the history of phishing attacks and how they turned into cyberattacks, focusing on companies. Over the course of 34 years, phishing has been evolving at an alarming rate, especially with AI now coming into play. As phishing attacks have become more prominent towards companies, there has been an increase in financial loss and data breaches, resulting in a loss of trust in companies. With this loss, companies are trying to find solutions to this problem. Some notable attacks were the RSA breach in 2011, the Texas Energy Company in 2014, and the ILOVEYOU virus in 2000. They …
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings
Research & Publications
Digital engineering practices offer significant yet underutilized potential for improving information assurance and system lifecycle management. This paper examines how capabilities like model-based engineering, digital threads, and integrated product lifecycles can address gaps in prevailing frameworks. A reference model demonstrates applying digital engineering techniques to a reference information system, exhibiting enhanced traceability, risk visibility, accuracy, and integration. The model links strategic needs to requirements and architecture while reusing authoritative elements across views. Analysis of the model shows digital engineering closes gaps in compliance, monitoring, change management, and risk assessment. Findings indicate purposeful digital engineering adoption could transform cybersecurity, operations, service …
Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan
Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan
Research & Publications
As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …
Real Time Pii Scanning, John David
Real Time Pii Scanning, John David
Electronic Theses and Dissertations
The increased amount of web applications and internet software solutions utilizing cloud frameworks has contributed to large data sets of system log messages being generated constantly. These messages may contain sensitive data, creating an additional security risk for the systems and contributing to the need for analysis of such large volumes of data in real time. Large commercial data monitoring systems can solve for these analysis requirements, but they can be costly. We present a solution to analyzing web application log data which ingests it, processes it and visualizes sensitive data found within in real time. Our solution utilizes an …