Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

Law

Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 1 - 30 of 809

Full-Text Articles in Information Security

From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance, Shelby C. Snyder Sep 2026

From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance, Shelby C. Snyder

Military Cyber Affairs

Federal agencies face a fiscal year 2027 target for enterprise-wide Zero Trust deployment, but NIST SP 800-207A defines logical components without identifying the Kubernetes technologies that implement them. This paper proposes a three-tier mapping of the Policy Engine, Policy Administrator, and Policy Enforcement Point to service mesh, microsegmentation, and perimeter tooling, stating the criteria by which each component is classified. It then applies a defined rubric to six Zero Trust vendors across component alignment, Kubernetes capability, federal authorization posture, and evidence quality, finding that no single vendor covers all three tiers. The mapping is a testable architectural proposition; a Stage …


Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck Sep 2026

Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck

Military Cyber Affairs

Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public safety consequences. However, attributing ransomware incidents to specific threat actors remains challenging due to ransomware-as-a-service ecosystems, actor rebranding, and the obfuscation of traditional indicators of compromise. This paper presents Semantic Shields, an NLP-driven attribution framework that leverages BERT-generated semantic embeddings and DBSCAN clustering to profile ransomware actors through the linguistic characteristics of ransom notes. Using a dataset of 295 ransom notes from 189 distinct threat groups, the framework achieved an 87.2% true positive clustering rate and …


Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap Jul 2026

Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap

Journal of Cybersecurity Education, Research and Practice

 Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking.  The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from …


The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds Apr 2026

The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds

School of Cybersecurity Master's Level Projects and Papers

Cybercrime has evolved significantly with the integration of artificial intelligence (AI), transforming traditional phishing and social engineering attacks into highly sophisticated and personalized threats. While early phishing attempts relied on generic messaging and low success rates, modern AI-driven attacks leverage advanced data analytics, natural language processing, and behavioral prediction to manipulate victims more effectively.

This research examines how cybercriminals utilize AI to enhance psychological manipulation techniques in phishing and social engineering attacks, increasing victim susceptibility. Drawing from interdisciplinary literature in cybersecurity and psychology, this study explores key psychological mechanisms, including cognitive biases, emotional triggers, and decision-making processes that influence victim …


A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad Jan 2026

A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad

American University Business Law Review

[INTRODUCTION] The term “cloud computing” means the remote storage of software applications, tools, and data accessed through the internet. Cloud customers enter into subscription agreements with providers who give 24/7, on-demand, as-needed access to software, storage, and networking services owned and managed by providers through a web browser. “Many businesses are transitioning to the cloud for data storage, remote work, and collaboration.” Cloud providers operate their software as a software-as-a-service (“SaaS”) model, under which customers pay a subscription fee to access the software. Netflix and Amazon Prime Video are examples of subscription services that deliver television programs and videos through …


Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi Oct 2025

Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi

Faculty Publications

Contract law is supposed to enable people to reach genuine agreements and cooperate. If this ideal was ever a reality, the rise of mass market contracts and boil­erplate rendered it pure fiction. Modern consumer contracts are incomprehensible to most people. No one reads them anyway.

Digital contracting involves design features that amplify traditional boilerplate harms and create others. For example, digital contracting is too cheap; low marginal costs lead to overexpansion in scale and scope. To make matters worse, the loss of autonomy from repeat engagement with digital contracting systems is pernicious. People become increasingly predictable and programmable as digital …


Selected Artificial Intelligence Provisions In U.S. Fiscal Year 2025 National Defense Authorization Act, Bert Chapman May 2025

Selected Artificial Intelligence Provisions In U.S. Fiscal Year 2025 National Defense Authorization Act, Bert Chapman

Libraries Faculty and Staff Presentations

The 2025 Fiscal Year National Defense Authorization Act contains multiple provisions relating to artificial intelligence (AI). These congressionally mandated provisions direct various sections of the Department of Defense (DOD) and individual U.S. armed service branches to execute congressional intent for AI policymaking. Examples of such intent include identifying and planning DOD's AI workforce, demonstrating AI biotechnology applications for national security, improving the human usability of AI systems, and establishing an AI security center. This presentation will note that reports on these initiatives must be prepared for relevant congressional oversight committees, and, in many cases, are in many cases, publicly released …


Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green May 2025

Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green

Honors College Theses

As deepfake technology advances, cybercriminals are increasingly using AI-generated videos and audios to impersonate executives and carry out sophisticated CEO fraud schemes. These synthetic forgeries target human trust and corporate communication systems, creating an urgent need for forensic tools capable of authenticating digital evidence with legal accuracy. This thesis presents a forensic-grade AI deepfake detection pipeline designed for this purpose, emphasizing courtroom admissibility, reproducibility, and evidentiary integrity. Built entirely with free, opensource tools, the framework combines metadata analysis, AI-powered spectrogram analysis, neural artifact detection, and facial manipulation recognition into a transparent workflow that accurately identifies synthetic media. It was trained …


Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr. Apr 2025

Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr.

Cybersecurity Undergraduate Research Showcase

Geriatric crime continues to escalate in the digital era, where older individuals are disproportionately being targeted because of their low digital literacy and high susceptibility to online frauds. In this paper, we examine the breadth of elder fraud in Chesapeake, Virginia using FBI Internet Crime Complaint Center (IC3) data and state-level cybersecurity initiatives and survey responses. Older adults aged 60 and up have reported losses of over $3.4 billion in 2023 alone, underscoring the importance of proactive measures. It assesses the public awareness from traditional and AI-based perspectives revealing significant gaps in digital safety literacy and fraud reporting mechanism among …


Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu Apr 2025

Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu

Cybersecurity Undergraduate Research Showcase

Financial fraud, particularly credit card fraud, continues to pose substantial challenges to financial institutions due to its increasing frequency and impact on consumer trust. While traditional rule-based methods have provided foundational defenses, their limitations in scalability and adaptability have accelerated the adoption of machine learning (ML) techniques. Concurrently, Benford’s Law—a statistical principle often used in forensic accounting—has demonstrated efficacy in detecting anomalies within naturally occurring numerical datasets. This study explores a hybrid fraud detection approach that integrates Benford’s Law with supervised machine learning algorithms, including Logistic Regression, Random Forest, and k-Nearest Neighbors. Using the publicly available European credit card fraud …


Securing Biometric Data, Alyssa F. Carroll Apr 2025

Securing Biometric Data, Alyssa F. Carroll

Cybersecurity Undergraduate Research Showcase

Biometric data has been widely adopted across various sectors, including digital identity, artificial intelligence (AI), border control, digital wallets, and national identification systems. While biometric identifiers—such as fingerprints, retina scans, and facial recognition—offer reliable and convenient authentication, they also raise significant concerns regarding privacy and security. This paper examines how biometric data is stored, the vulnerabilities it faces, and the most effective methods for safeguarding it. By highlighting the critical importance of biometric data protection, this study reviews current research on approaches, strategies, and policies that enhance security while preserving the functionality and efficiency of biometric systems.


Integrating Humanities Into Cybersecurity Education: Enhancing Ethical, Historical, And Sociopolitical Understanding In Technical Training, Joseph Frusci Nov 2024

Integrating Humanities Into Cybersecurity Education: Enhancing Ethical, Historical, And Sociopolitical Understanding In Technical Training, Joseph Frusci

Journal of Cybersecurity Education, Research and Practice

The increasing complexity of cybersecurity challenges necessitates a holistic educational approach that integrates both technical skills and humanistic perspectives. This article examines the importance of infusing humanities disciplines such as history, ethics, political science, sociology, law, and anthropology—into cybersecurity education. Through a pilot course developed for Staten Island Technical High School, aligned with the New York State K-12 Computer Science and Digital Fluency Standards, students were introduced to an interdisciplinary curriculum that combined technical cybersecurity training with historical analysis, ethical reasoning, and sociopolitical context. The results of pre- and post-course assessments demonstrated significant improvements in critical thinking, ethical decision-making, and …


Quantitative Evaluation Of Security Intelligence Policy Texts In China: Text Analysis Based On Pmc Model, Bin Zhang Jul 2024

Quantitative Evaluation Of Security Intelligence Policy Texts In China: Text Analysis Based On Pmc Model, Bin Zhang

Journal of Scientific Information Research

[Purpose/significance]Analyzing the laws, regulations and policies related to security intelligence in China can not only provide reference for decision-making, but also effectively enrich the connotation of China's overall national security concept. [Method/process]Using the LDA topic model, text mining was conducted on laws, regulations and policies related to security intelligence in China, and theme words were extracted from them. At the same time, based on the selection of policy indicators by existing scholars, scientifically select and design evaluation indicators for China's security intelligence laws, regulations, and policies. Referring to the overall national security concept, several representative policy contents were selected for …


Content Moderation On Social Media: Social And Computational Standards And Implications, Mohit Singhal Jan 2024

Content Moderation On Social Media: Social And Computational Standards And Implications, Mohit Singhal

Computer Science and Engineering Dissertations - Archive

Social media has become a powerful tool that reflects human communication's best and worst aspects. They allow individuals to freely express opinions, communicate with others, and learn about new stories. On the other hand, they have become fertile grounds for several forms of abuse, harassment, and the dissemination of misinformation. Social media platforms have established and employed content moderation to counteract the spread of abuse and misinformation.

Some critical challenges hinder the understanding of the social media content moderation ecosystem. This dissertation investigates various aspects of content moderation, including their coverage, fairness, and effectiveness. Firstly, it investigates how, in practice, …


Reducing Food Scarcity: The Benefits Of Urban Farming, S.A. Claudell, Emilio Mejia Dec 2023

Reducing Food Scarcity: The Benefits Of Urban Farming, S.A. Claudell, Emilio Mejia

Journal of Nonprofit Innovation

Urban farming can enhance the lives of communities and help reduce food scarcity. This paper presents a conceptual prototype of an efficient urban farming community that can be scaled for a single apartment building or an entire community across all global geoeconomics regions, including densely populated cities and rural, developing towns and communities. When deployed in coordination with smart crop choices, local farm support, and efficient transportation then the result isn’t just sustainability, but also increasing fresh produce accessibility, optimizing nutritional value, eliminating the use of ‘forever chemicals’, reducing transportation costs, and fostering global environmental benefits.

Imagine Doris, who is …


Rising Threat - Deepfakes And National Security In The Age Of Digital Deception, Dougo Kone-Sow Dec 2023

Rising Threat - Deepfakes And National Security In The Age Of Digital Deception, Dougo Kone-Sow

Cybersecurity Undergraduate Research Showcase

This paper delves into the intricate landscape of deepfakes, exploring their genesis, capabilities, and far-reaching implications. The rise of deepfake technology presents an unprecedented threat to American national security, propagating disinformation and manipulation across various media formats. Notably, deepfakes have evolved from a historical backdrop of disinformation campaigns, merging with the advancements of artificial intelligence (AI) and machine learning to craft convincing but false multimedia content.

Examining the capabilities of deepfakes reveals their potential for misuse, evidenced by instances targeting individuals, companies, and even influencing political events like the 2020 U.S. elections. The paper highlights the direct threats posed by …


Link Tank Oct 2023

Link Tank

DePaul Magazine

A new JD certificate program in information technology, cybersecurity and data privacy provides DePaul University students with proficiency in both law and tech.


Executive Order On The Safe, Secure, And Trustworthy Development And Use Of Artificial Intelligence, Joseph R. Biden Oct 2023

Executive Order On The Safe, Secure, And Trustworthy Development And Use Of Artificial Intelligence, Joseph R. Biden

Copyright, Fair Use, Scholarly Communication, etc.

Section 1. Purpose. Artificial intelligence (AI) holds extraordinary potential for both promise and peril. Responsible AI use has the potential to help solve urgent challenges while making our world more prosperous, productive, innovative, and secure. At the same time, irresponsible use could exacerbate societal harms such as fraud, discrimination, bias, and disinformation; displace and disempower workers; stifle competition; and pose risks to national security. Harnessing AI for good and realizing its myriad benefits requires mitigating its substantial risks. This endeavor demands a society-wide effort that includes government, the private sector, academia, and civil society.

My Administration places the highest urgency …


Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim Oct 2023

Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim

Journal of Cybersecurity Education, Research and Practice

This paper reviews cybersecurity laws and regulations in Cameroon, focusing on cybersecurity and information security audits and risk assessments. The importance of cybersecurity risk assessment and the implementation of security controls to cure deficiencies noted during risk assessments or audits is a critical step in developing cybersecurity resilience. Cameroon's cybersecurity legal framework provides for audits but does not explicitly enumerate controls. Consequently, integrating relevant controls from the NIST frameworks and ISO Standards can improve the cybersecurity posture in Cameroon while waiting for a comprehensive revision of the legal framework. NIST and ISO are internationally recognized as best practices in information …


Privacy Harm And Non-Compliance From A Legal Perspective, Suvineetha Herath, Haywood Gelman, Lisa Mckee Oct 2023

Privacy Harm And Non-Compliance From A Legal Perspective, Suvineetha Herath, Haywood Gelman, Lisa Mckee

Journal of Cybersecurity Education, Research and Practice

In today's data-sharing paradigm, personal data has become a valuable resource that intensifies the risk of unauthorized access and data breach. Increased data mining techniques used to analyze big data have posed significant risks to data security and privacy. Consequently, data breaches are a significant threat to individual privacy. Privacy is a multifaceted concept covering many areas, including the right to access, erasure, and rectify personal data. This paper explores the legal aspects of privacy harm and how they transform into legal action. Privacy harm is the negative impact to an individual as a result of the unauthorized release, gathering, …


An Ml Based Digital Forensics Software For Triage Analysis Through Face Recognition, Gaurav Gogia, Parag H. Rughani Jul 2023

An Ml Based Digital Forensics Software For Triage Analysis Through Face Recognition, Gaurav Gogia, Parag H. Rughani

Journal of Digital Forensics, Security and Law

Since the past few years, the complexity and heterogeneity of digital crimes has increased exponentially, which has made the digital evidence & digital forensics paramount for both criminal investigation and civil litigation cases. Some of the routine digital forensic analysis tasks are cumbersome and can increase the number of pending cases especially when there is a shortage of domain experts. While the work is not very complex, the sheer scale can be taxing. With the current scenarios and future predictions, crimes are only going to become more complex and the precedent of collecting and examining digital evidence is only going …


What Senior U.S. Leaders Say We Should Know About Cyber, Dr. Joseph H. Schafer May 2023

What Senior U.S. Leaders Say We Should Know About Cyber, Dr. Joseph H. Schafer

Military Cyber Affairs

On April 6, 2023, the Atlantic Council’s Cyber Statecraft Initiative hosted a panel discussion on the new National Cybersecurity Strategy. The panel featured four senior officials from the Office of the National Cyber Director (ONCD), the Department of State (DoS), the Department of Justice (DoJ), and the Department of Homeland Security (DHS). The author attended and asked each official to identify the most important elements that policymakers and strategists must understand about cyber. This article highlights historical and recent struggles to express cyber policy, the responses from these officials, and the author’s ongoing research to improve national security cyber policy.


Some Legal And Practical Challenges In The Investigation Of Cybercrime, Ritz Carr Apr 2023

Some Legal And Practical Challenges In The Investigation Of Cybercrime, Ritz Carr

Cybersecurity Undergraduate Research Showcase

According to the Internet Crime Complaint Center (IC3), in 2021, the United States lost around $6.9 billion to cybercrime. In 2022, that number grew to over $10.2 billion (IC3, 2022). In one of many efforts to combat cybercrimes, at least 40 states “introduced or considered more than 250 bills or resolutions that deal significantly with cybersecurity” with 24 states officially enacting a total of 41 bills (National Conference on State Legislatures, 2022).

The world of cybercrime evolves each day. Nevertheless, challenges arise when we investigate and prosecute cybercrime, which will be examined in the following collection of essays that highlight …


An Evaluation Framework For Digital Image Forensics Tools, Zainab Khalid, Sana Qadir Oct 2022

An Evaluation Framework For Digital Image Forensics Tools, Zainab Khalid, Sana Qadir

Journal of Digital Forensics, Security and Law

The boom of digital cameras, photography, and social media has drastically changed how humans live their day-to-day, but this normalization is accompanied by malicious agents finding new ways to forge and tamper with images for unlawful monetary (or other) gains. Disinformation in the photographic media realm is an urgent threat. The availability of a myriad of image editing tools renders it almost impossible to differentiate between photo-realistic and original images. The tools available for image forensics require a standard framework against which they can be evaluated. Such a standard framework can aid in evaluating the suitability of an image forensics …


A Study Of The Data Remaining On Second-Hand Mobile Devices In The Uk, Olga Angelopoulou, Andy Jones, Graeme Horsman, Seyedali Pourmoafi Oct 2022

A Study Of The Data Remaining On Second-Hand Mobile Devices In The Uk, Olga Angelopoulou, Andy Jones, Graeme Horsman, Seyedali Pourmoafi

Journal of Digital Forensics, Security and Law

This study was carried out intending to identify the level and type of information that remained on portable devices that were purchased from the second-hand market in the UK over the last few years. The sample for this study consisted of 100 second hand mobile phones and tablets. The aim of the study was to determine the proportion of devices that still contained data and the type of data that they contained. Where data was identified, the study attempted to determine the level of personal identifiable information that is associated with the previous owner. The research showed that when sensitive …


Data Vu: Why Breaches Involve The Same Stories Again And Again, Woodrow Hartzog, Daniel Solove Jul 2022

Data Vu: Why Breaches Involve The Same Stories Again And Again, Woodrow Hartzog, Daniel Solove

Shorter Faculty Works

In the classic comedy Groundhog Day, protagonist Phil, played by Bill Murray, asks “What would you do if you were stuck in one place and every day was exactly the same, and nothing that you did mattered?” In this movie, Phil is stuck reliving the same day over and over, where the events repeat in a continual loop, and nothing he does can stop them. Phil’s predicament sounds a lot like our cruel cycle with data breaches.

Every year, organizations suffer more data spills and attacks, with personal information being exposed and abused at alarming rates. While Phil …


To License Or Not To License Reexamined: An Updated Report On Licensing Of Digital Examiners Under State Private Investigator Statutes, Thomas Lonardo, Alan Rea, Doug White Jul 2022

To License Or Not To License Reexamined: An Updated Report On Licensing Of Digital Examiners Under State Private Investigator Statutes, Thomas Lonardo, Alan Rea, Doug White

Journal of Digital Forensics, Security and Law

In this update to the 2015 study, the authors examine US state statutes and regulations relating to licensing and enforcement of Digital Examiner functions under each state’s private investigator/detective statute. As with the prior studies, the authors find that very few state statutes explicitly distinguish between Private Investigators (PI) and Digital Examiners (DE), and when they do, they either explicitly require a license or exempt them from the licensing statute. As noted in the previous 2015 study there is a minor trend in which some states are moving to exempt DE from PI licensing requirements. We examine this trend as …


Gauging The Acceptance Of Contact Tracing Technology: An Empirical Study Of Singapore Residents’ Concerns With Sharing Their Information And Willingness To Trust, Ee-Ing Ong, Wee Ling Loo Jun 2022

Gauging The Acceptance Of Contact Tracing Technology: An Empirical Study Of Singapore Residents’ Concerns With Sharing Their Information And Willingness To Trust, Ee-Ing Ong, Wee Ling Loo

Research Collection Yong Pung How School Of Law

In response to the COVID-19 pandemic, governments began implementing various forms of contact tracing technology. Singapore’s implementation of its contact tracing technology, TraceTogether, however, was met with significant concern by its population, with regard to privacy and data security. This concern did not fit with the general perception that Singaporeans have a high level of trust in its government. We explore this disconnect, using responses to our survey (conducted pre-COVID-19) in which we asked participants about their level of concern with the government and business collecting certain categories of personal data. The results show that respondents had less concern with …


Regulating Personal Data Usage In Covid-19 Control Conditions, Mark Findlay, Nydia Remolina Jun 2022

Regulating Personal Data Usage In Covid-19 Control Conditions, Mark Findlay, Nydia Remolina

Research Collection Yong Pung How School Of Law

Concern has been widely expressed about the potential for COVID-19 control technologies and resultant data sharing negatively impacting on civil rights, invading personal privacy, undermining citizen dignity through expansive data matching and ultimately providing opportunities for data use well beyond the brief of virus mitigation. This chapter offers suggestions regarding effective and inclusive regulatory responses when faced with extended surveillance, tracking/tracing, public/private provider data sharing and any breakdown in personal data firewalls, or otherwise conventional aggregated data deviations and distortion. In doing so, the chapter explores personal data usage in the context of COVID-19 as a regulatory enterprise. It addresses …


Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa May 2022

Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa

The Scholar: St. Mary's Law Review on Race and Social Justice

Small businesses and small minority owned businesses are vital to our nation’s economy; therefore legislation, regulation, and policy has been created in order to assist them in overcoming their economic stability issues and ensure they continue to serve the communities that rely on them. However, there is not a focus on regulating nor assisting small businesses to ensure their cybersecurity standards are up to par despite them increasingly becoming a victim of cyberattacks that yield high consequences. The external oversight and assistance is necessary for small businesses due to their lack of knowledge in implementing effective cybersecurity policies, the fiscal …