Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Singapore Management University (105)
- University of Dayton (14)
- Dakota State University (11)
- Embry-Riddle Aeronautical University (7)
- Kennesaw State University (6)
-
- University of Arkansas, Fayetteville (6)
- Purdue University (5)
- Air Force Institute of Technology (4)
- City University of New York (CUNY) (4)
- University of Malaya (4)
- Montclair State University (3)
- Old Dominion University (3)
- Southern Methodist University (3)
- Syracuse University (3)
- University of Nebraska at Omaha (3)
- Boise State University (2)
- Liberty University (2)
- New Jersey Institute of Technology (2)
- San Jose State University (2)
- University of Denver (2)
- University of Nebraska - Lincoln (2)
- Western Kentucky University (2)
- Western University (2)
- Arkansas Tech University (1)
- Belmont University (1)
- Brigham Young University (1)
- California State University, San Bernardino (1)
- DePaul University (1)
- East Tennessee State University (1)
- Edith Cowan University (1)
- Keyword
-
- Security (13)
- Cybersecurity (12)
- Android (7)
- Machine learning (7)
- Privacy (7)
-
- Vulnerability detection (7)
- Blockchain (6)
- Computer Science (5)
- Machine Learning (5)
- Static analysis (5)
- Classification (4)
- Android Security (3)
- Android malware (3)
- Anomaly detection (3)
- Computer security (3)
- Cyber security (3)
- Deep learning (3)
- Empirical study (3)
- Encryption (3)
- Ethereum (3)
- Formal verification (3)
- Framework (3)
- Internet (3)
- Obfuscation (3)
- Software security (3)
- Verification (3)
- Android Malware Detection (2)
- Android security (2)
- Application (2)
- Artificial Intelligence (AI) (2)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (99)
- Computer Science Faculty Publications (14)
- Masters Theses & Doctoral Dissertations (9)
- Electronic Theses and Dissertations (5)
- Department of Electrical and Computer Engineering Faculty Publications (4)
-
- Graduate Theses and Dissertations (4)
- Theses and Dissertations (4)
- Department of Computer Science Faculty Scholarship and Creative Works (3)
- Dissertations and Theses Collection (Open Access) (3)
- Electrical Engineering and Computer Science - Technical Reports (3)
- Journal of Digital Forensics, Security and Law (3)
- Boise State University Theses and Dissertations (2)
- Computer Science and Computer Engineering Undergraduate Honors Theses (2)
- Computer Science and Engineering Theses and Dissertations (2)
- Dissertations (2)
- Doctoral Dissertations and Master's Theses (2)
- Electrical and Computer Engineering Publications (2)
- Masters Theses & Specialist Projects (2)
- Publications and Research (2)
- Research & Publications (2)
- School of Computing: Dissertations, Theses, and Student Research (2)
- Senior Honors Theses (2)
- Student Works (2000-2009) (2)
- Student Works (2020-2029) (2)
- Symposium of Student Scholars (2)
- VMASC Publications (2)
- AFIT Patents (1)
- ATU Scholars Symposium (1)
- Articles (1)
- College of Computing Annual Magazines (1)
- Publication Type
- File Type
Articles 91 - 120 of 223
Full-Text Articles in Information Security
Analysis Of Theoretical And Applied Machine Learning Models For Network Intrusion Detection, Jonah Baron
Analysis Of Theoretical And Applied Machine Learning Models For Network Intrusion Detection, Jonah Baron
Masters Theses & Doctoral Dissertations
Network Intrusion Detection System (IDS) devices play a crucial role in the realm of network security. These systems generate alerts for security analysts by performing signature-based and anomaly-based detection on malicious network traffic. However, there are several challenges when configuring and fine-tuning these IDS devices for high accuracy and precision. Machine learning utilizes a variety of algorithms and unique dataset input to generate models for effective classification. These machine learning techniques can be applied to IDS devices to classify and filter anomalous network traffic. This combination of machine learning and network security provides improved automated network defense by developing highly-optimized …
Shedding Light On Dark Patterns: A Case Study On Digital Harms, Noreen Y. Whysel
Shedding Light On Dark Patterns: A Case Study On Digital Harms, Noreen Y. Whysel
Publications and Research
You’ve been there before. You thought you could trust someone with a secret. You thought it would be safe, but found out later that they blabbed to everyone. Or maybe they didn’t share it, but the way they used it felt manipulative. You gave more than you got and it didn’t feel fair. But now that it’s out there, do you even have control anymore?
Ok. Now imagine that person was your supermarket. Or your bank. Or your boss.
As designers of digital spaces for consumer products and services, how often do we consider the relationship we have with our …
Machine Learning Based Approaches Towards Robust Android Malware Detection, Jiayun Xu
Machine Learning Based Approaches Towards Robust Android Malware Detection, Jiayun Xu
Dissertations and Theses Collection (Open Access)
The Android platform is becoming increasingly popular and numerous applications (apps) have been developed by organizations to meet the ever increasing market demand over years. Naturally, security and privacy concerns on Android apps have grabbed considerable attention from both academic and industrial
communities. Many approaches have been proposed to detect Android malware in different ways so far, and most of them produce satisfactory performance under the given Android environment settings and labelled samples. However, existing approaches suffer the following robustness problems:
In many Android malware detection approaches, specific API calls are used to build the feature sets, and their feature …
Looking Back! Using Early Versions Of Android Apps As Attack Vectors, Yue Zhang, Jian Weng, Jia-Si Wneg, Lin Hou, Anjia Yang, Ming Li, Yang Xiang, Deng, Robert H.
Looking Back! Using Early Versions Of Android Apps As Attack Vectors, Yue Zhang, Jian Weng, Jia-Si Wneg, Lin Hou, Anjia Yang, Ming Li, Yang Xiang, Deng, Robert H.
Research Collection School Of Computing and Information Systems
Android platform is gaining explosive popularity. This leads developers to invest resources to maintain the upward trajectory of the demand. Unfortunately, as the profit potential grows higher, the chances of these Apps getting attacked also get higher. Therefore, developers improved the security of their Apps, which limits attackers ability to compromise upgraded versions of the Apps. However, developers cannot enhance the security of earlier versions that have been released on the Play Store. The earlier versions of the App can be subject to reverse engineering and other attacks. In this paper, we find that attackers can use these earlier versions …
Understanding Adversarial Robustness Via Critical Attacking Route, Tianlin Li, Aishan Liu, Xianglong Liu, Yitao Xu, Chongzhi Zhang, Xiaofei Xie
Understanding Adversarial Robustness Via Critical Attacking Route, Tianlin Li, Aishan Liu, Xianglong Liu, Yitao Xu, Chongzhi Zhang, Xiaofei Xie
Research Collection School Of Computing and Information Systems
Deep neural networks (DNNs) are vulnerable to adversarial examples which are generated by inputs with imperceptible perturbations. Understanding adversarial robustness of DNNs has become an important issue, which would for certain result in better practical deep learning applications. To address this issue, we try to explain adversarial robustness for deep models from a new perspective of critical attacking route, which is computed by a gradient-based influence propagation strategy. Similar to rumor spreading in social net-works, we believe that adversarial noises are amplified and propagated through the critical attacking route. By exploiting neurons' influences layer by layer, we compose the critical …
Privattnet: Predicting Privacy Risks In Images Using Visual Attention, Zhang Chen, Thivya Kandappu, Vigneshwaran Subbaraju
Privattnet: Predicting Privacy Risks In Images Using Visual Attention, Zhang Chen, Thivya Kandappu, Vigneshwaran Subbaraju
Research Collection School Of Computing and Information Systems
Visual privacy concerns associated with image sharing is a critical issue that need to be addressed to enable safe and lawful use of online social platforms. Users of social media platforms often suffer from no guidance in sharing sensitive images in public, and often face with social and legal consequences. Given the recent success of visual attention based deep learning methods in measuring abstract phenomena like image memorability, we are motivated to investigate whether visual attention based methods could be useful in measuring psychophysical phenomena like “privacy sensitivity”. In this paper we propose PrivAttNet – a visual attention based approach, …
Can We Trust Your Explanations? Sanity Checks For Interpreters In Android Malware Analysis, Min Fan, Wenying Wei, Xiaofei Xie, Yang Liu, Xiaohong Guan, Ting Liu
Can We Trust Your Explanations? Sanity Checks For Interpreters In Android Malware Analysis, Min Fan, Wenying Wei, Xiaofei Xie, Yang Liu, Xiaohong Guan, Ting Liu
Research Collection School Of Computing and Information Systems
With the rapid growth of Android malware, many machine learning-based malware analysis approaches are proposed to mitigate the severe phenomenon. However, such classifiers are opaque, non-intuitive, and difficult for analysts to understand the inner decision reason. For this reason, a variety of explanation approaches are proposed to interpret predictions by providing important features. Unfortunately, the explanation results obtained in the malware analysis domain cannot achieve a consensus in general, which makes the analysts confused about whether they can trust such results. In this work, we propose principled guidelines to assess the quality of five explanation approaches by designing three critical …
Coinwatch: A Clone-Based Approach For Detecting Vulnerabilities In Cryptocurrencies, Qingze Hum, Wei Jin Tan, Shi Ying Tey, Latasha Lenus, Ivan Homoliak, Yun Lin, Jun Sun
Coinwatch: A Clone-Based Approach For Detecting Vulnerabilities In Cryptocurrencies, Qingze Hum, Wei Jin Tan, Shi Ying Tey, Latasha Lenus, Ivan Homoliak, Yun Lin, Jun Sun
Research Collection School Of Computing and Information Systems
Cryptocurrencies have become very popular in recent years. Thousands of new cryptocurrencies have emerged, proposing new and novel techniques that improve on Bitcoin's core innovation of the blockchain data structure and consensus mechanism. However, cryptocurrencies are a major target for cyber-attacks, as they can be sold on exchanges anonymously and most cryptocurrencies have their codebases publicly available. One particular issue is the prevalence of code clones in cryptocurrencies, which may amplify security threats. If a vulnerability is found in one cryptocurrency, it might be propagated into other cloned cryptocurrencies. In this work, we propose a systematic remedy to this problem, …
Sfuzz: An Efficient Adaptive Fuzzer For Solidity Smart Contracts, Tai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin, Minh Quang Tran
Sfuzz: An Efficient Adaptive Fuzzer For Solidity Smart Contracts, Tai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin, Minh Quang Tran
Research Collection School Of Computing and Information Systems
Smart contracts are Turing-complete programs that execute on the infrastructure of the blockchain, which often manage valuable digital assets. Solidity is one of the most popular programming languages for writing smart contracts on the Ethereum platform. Like traditional programs, smart contracts may contain vulnerabilities. Unlike traditional programs, smart contracts cannot be easily patched once they are deployed. It is thus important that smart contracts are tested thoroughly before deployment. In this work, we present an adaptive fuzzer for smart contracts on the Ethereum platform called sFuzz. Compared to existing Solidity fuzzers, sFuzz combines the strategy in the AFL fuzzer and …
Espade: An Efficient And Semantically Secure Shortest Path Discovery For Outsourced Location-Based Services, Bharath K. Samanthula, Divyadharshini Karthikeyan, Boxiang Dong, K. Anitha Kumari
Espade: An Efficient And Semantically Secure Shortest Path Discovery For Outsourced Location-Based Services, Bharath K. Samanthula, Divyadharshini Karthikeyan, Boxiang Dong, K. Anitha Kumari
Department of Computer Science Faculty Scholarship and Creative Works
With the rapid growth of smart devices and technological advancements in tracking geospatial data, the demand for Location-Based Services (LBS) is facing a constant rise in several domains, including military, healthcare and transportation. It is a natural step to migrate LBS to a cloud environment to achieve on-demand scalability and increased resiliency. Nonetheless, outsourcing sensitive location data to a third-party cloud provider raises a host of privacy concerns as the data owners have reduced visibility and control over the outsourced data. In this paper, we consider outsourced LBS where users want to retrieve map directions without disclosing their location information. …
Enhancing A Cluster-Based Tdma Mac Protocol For Vehicle-To-Vehicle Communications, Abubakar Bello Tambawal
Enhancing A Cluster-Based Tdma Mac Protocol For Vehicle-To-Vehicle Communications, Abubakar Bello Tambawal
Student Works (2020-2029)
Vehicular Ad hoc Network technology (VANET) is one of the emerging and promising wireless technology, providing support for vehicles to communicate and share resources, (such as safety messages) through vehicle-to-vehicle (V2V) communications. Sequel to that the Time Division Multiple Access (TDMA) MAC protocol using a cluster-based topology has been proposed by the research community. Most of the existing research works focused on the cluster head (CH) election with very few addressing other critical issues, including cluster formation, efficient time slot allocation, and cluster maintenance. These challenges result in an unstable cluster, which could affect the timely delivery of safety applications. …
White-Box Fairness Testing Through Adversarial Sampling, Peixin Zhang, Jingyi Wang, Jun Sun, Guoliang Dong, Xinyu Wang, Xingen Wang, Jin Song Dong, Dai Ting
White-Box Fairness Testing Through Adversarial Sampling, Peixin Zhang, Jingyi Wang, Jun Sun, Guoliang Dong, Xinyu Wang, Xingen Wang, Jin Song Dong, Dai Ting
Research Collection School Of Computing and Information Systems
Although deep neural networks (DNNs) have demonstrated astonishing performance in many applications, there are still concerns on their dependability. One desirable property of DNN for applications with societal impact is fairness (i.e., non-discrimination). In this work, we propose a scalable approach for searching individual discriminatory instances of DNN. Compared with state-of-the-art methods, our approach only employs lightweight procedures like gradient computation and clustering, which makes it significantly more scalable than existing methods. Experimental results show that our approach explores the search space more effectively (9 times) and generates much more individual discriminatory instances (25 times) using much less time (half …
Efficient Ciphertext-Policy Attribute-Based Encryption With Blackbox Traceability, Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang, Zuobin Yang
Efficient Ciphertext-Policy Attribute-Based Encryption With Blackbox Traceability, Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang, Zuobin Yang
Research Collection School Of Computing and Information Systems
Traitor tracing scheme is a paradigm to classify the users who illegal use of their decryption keys in cryptosystems. In the ciphertext-policy attribute-based cryptosystem, the decryption key usually contains the users’ attributes, while the real identities are hidden. The decryption key with hidden identities enables malicious users to intentionally leak decryption keys or embed the decryption keys in the decryption device to gain illegal profits with a little risk of being discovered. To mitigate this problem, the concept of blackbox traceability in the ciphertext-policy attribute-based scheme was proposed to identify the malicious user via observing the I/O streams of the …
Towards Systematically Deriving Defence Mechanisms From Functional Requirements Of Cyber-Physical Systems, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt
Towards Systematically Deriving Defence Mechanisms From Functional Requirements Of Cyber-Physical Systems, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt
Research Collection School Of Computing and Information Systems
The threats faced by cyber-physical systems (CPSs) in critical infrastructure have motivated the development of different attack detection mechanisms, such as those that monitor for violations of invariants, i.e. properties that always hold in normal operation. Given the complexity of CPSs, several existing approaches focus on deriving invariants automatically from data logs, but these can miss possible system behaviours if they are not represented in that data. Furthermore, resolving any design flaws identified in this process is costly, as the CPS is already built. In this position paper, we propose a systematic method for deriving invariants before a CPS is …
An Enhancement Of Age And Gender Classification Accuracy With Hybrid Handcrafted And Deep Features Using Hierarchical Extreme Learning Machine, Mohammad Javidan Darugar
An Enhancement Of Age And Gender Classification Accuracy With Hybrid Handcrafted And Deep Features Using Hierarchical Extreme Learning Machine, Mohammad Javidan Darugar
Student Works (2020-2029)
Age and gender classification are some of the essential algorithms that have many use cases in our everyday life. For example, in robotics, field robots can interact with a human base on their gender in data analysis, to have statistics about age and gender of audiences in social events, YouTube video analysis, and many other applications. In this research, we have addressed limitations in deep neural networks, which by overcoming this limitation, we can gain better accuracy and performance. Our study has several other possible applications which are not limited only to age and gender classification. This dissertation is about …
Privacy-Enhanced Remote Data Integrity Checking With Updatable Timestamp, Tong Wu, Guomin Yang, Yi Mu, Rongmao Chen, Shengmin Xu
Privacy-Enhanced Remote Data Integrity Checking With Updatable Timestamp, Tong Wu, Guomin Yang, Yi Mu, Rongmao Chen, Shengmin Xu
Research Collection School Of Computing and Information Systems
Remote data integrity checking (RDIC) enables clients to verify whether the outsourced data is intact without keeping a copy locally or downloading it. Nevertheless, the existing RDIC schemes do not support the pay-as-you-go (PAYG) payment model, where the payment is decided by the volume and duration of the outsourced data. Specifically, none of the existing works have considered the client’s control over changes in storage duration. In this paper, we propose an RDIC scheme to simultaneously check the data content and storage duration represented by an updatable timestamp via the third-party auditor (TPA). Also, our proposed scheme achieves indistinguishable privacy …
Spring 2020
In The Loop
Letter from the Dean: Advancing Past Adversity; Look Who's Talking: Expert Talk Series; Seen and Heard; Keeping It Real: Client Web Projects for Students; OMG, It's DIBS, LOL!; X-ray Vision: Brian Andrews bones up on anthropomorphic entities and virtual realty in an audacious Project Bluelight film; Nothing But Net: Shannon Linares scores a win for female and first-generation college students in network engineering and cybersecurity careers; Mix Master: Claire Rosas blends disciplines and social synergy in her designs, from egg-ceptional typography to adaptive ergs
The Prom Problem: Fair And Privacy-Enhanced Matchmaking With Identity Linked Wishes, Dwight Horne
The Prom Problem: Fair And Privacy-Enhanced Matchmaking With Identity Linked Wishes, Dwight Horne
Computer Science and Engineering Theses and Dissertations
In the Prom Problem (TPP), Alice wishes to attend a school dance with Bob and needs a risk-free, privacy preserving way to find out whether Bob shares that same wish. If not, no one should know that she inquired about it, not even Bob. TPP represents a special class of matchmaking challenges, augmenting the properties of privacy-enhanced matchmaking, further requiring fairness and support for identity linked wishes (ILW) – wishes involving specific identities that are only valid if all involved parties have those same wishes.
The Horne-Nair (HN) protocol was proposed as a solution to TPP along with a …
Storage Management Strategy In Mobile Phones For Photo Crowdsensing, En Wang, Zhengdao Qu, Xinyao Liang, Xiangyu Meng, Yongjian Yang, Dawei Li, Weibin Meng
Storage Management Strategy In Mobile Phones For Photo Crowdsensing, En Wang, Zhengdao Qu, Xinyao Liang, Xiangyu Meng, Yongjian Yang, Dawei Li, Weibin Meng
Department of Computer Science Faculty Scholarship and Creative Works
In mobile crowdsensing, some users jointly finish a sensing task through the sensors equipped in their intelligent terminals. In particular, the photo crowdsensing based on Mobile Edge Computing (MEC) collects pictures for some specific targets or events and uploads them to nearby edge servers, which leads to richer data content and more efficient data storage compared with the common mobile crowdsensing; hence, it has attracted an important amount of attention recently. However, the mobile users prefer uploading the photos through Wifi APs (PoIs) rather than cellular networks. Therefore, photos stored in mobile phones are exchanged among users, in order to …
Byod-Insure: A Security Assessment Model For Enterprise Byod, Melva Ratchford
Byod-Insure: A Security Assessment Model For Enterprise Byod, Melva Ratchford
Masters Theses & Doctoral Dissertations
As organizations continue allowing employees to use their personal mobile devices to access the organizations’ networks and the corporate data, a phenomenon called ‘Bring Your Own Device’ or BYOD, proper security controls need to be adopted not only to secure the corporate data but also to protect the organizations against possible litigation problems. Until recently, current literature and research have been focused on specific areas or solutions regarding BYOD. The information associated with BYOD security issues in the areas of Management, IT, Users and Mobile Device Solutions is fragmented. This research is based on a need to provide a holistic …
Automated Tool Support - Repairing Security Bugs In Mobile Applications, Larry Singleton
Automated Tool Support - Repairing Security Bugs In Mobile Applications, Larry Singleton
UNO Student Research and Creative Activity Fair
Cryptography is often a critical component in secure software systems. Cryptographic primitive misuses often cause several vulnerability issues. To secure data and communications in applications, developers often rely on cryptographic algorithms and APIs which provide confidentiality, integrity, and authentication based on solid mathematical foundations. While many advanced crypto algorithms are available to developers, the correct usage of these APIs is challenging. Turning mathematical equations in crypto algorithms into an application is a difficult task. A mistake in cryptographic implementations can subvert the security of the entire system. In this research, we present an automated approach for Finding and Repairing Bugs …
A Virtual Machine Introspection Based Multi-Service, Multi-Architecture, High-Interaction Honeypot For Iot Devices, Cory A. Nance
A Virtual Machine Introspection Based Multi-Service, Multi-Architecture, High-Interaction Honeypot For Iot Devices, Cory A. Nance
Masters Theses & Doctoral Dissertations
Internet of Things (IoT) devices are quickly growing in adoption. The use case for IoT devices runs the gamut from household applications (such as toasters, lighting, and thermostats) to medical, battlefield, or Industrial Control System (ICS) applications used in life or death situations. A disturbing trend is that for IoT devices is that they are not developed with security in mind. This lack of security has led to the creation of massive botnets that conduct nefarious acts. A clear understanding of the threat landscape IoT devices face is needed to address these security issues. One technique used to understand threats …
Iot-Hass: A Framework For Protecting Smart Home Environment, Tarig Mudawi
Iot-Hass: A Framework For Protecting Smart Home Environment, Tarig Mudawi
Masters Theses & Doctoral Dissertations
While many solutions have been proposed for smart home security, the problem that no single solution fully protects the smart home environment still exists. In this research we propose a security framework to protect the smart home environment. The proposed framework includes three engines that complement each other to protect the smart home IoT devices. The first engine is an IDS/IPS module that monitors all traffic in the home network and then detects, alerts users, and/or blocks packets using anomaly-based detection. The second engine works as a device management module that scans and verifies IoT devices in the home network, …
Network Traffic Analysis Framework For Cyber Threat Detection, Meshesha K. Cherie
Network Traffic Analysis Framework For Cyber Threat Detection, Meshesha K. Cherie
Masters Theses & Doctoral Dissertations
The growing sophistication of attacks and newly emerging cyber threats requires advanced cyber threat detection systems. Although there are several cyber threat detection tools in use, cyber threats and data breaches continue to rise. This research is intended to improve the cyber threat detection approach by developing a cyber threat detection framework using two complementary technologies, search engine and machine learning, combining artificial intelligence and classical technologies.
In this design science research, several artifacts such as a custom search engine library, a machine learning-based engine and different algorithms have been developed to build a new cyber threat detection framework based …
Saga: Efficient And Large-Scale Detection Of Near-Miss Clones With Gpu Acceleration, Guanhua Li, Yijian Wu, Chanchal K. Roy, Jun Sun, Xin Peng, Nanjie Zhan, Bin Hu, Jingyi Ma
Saga: Efficient And Large-Scale Detection Of Near-Miss Clones With Gpu Acceleration, Guanhua Li, Yijian Wu, Chanchal K. Roy, Jun Sun, Xin Peng, Nanjie Zhan, Bin Hu, Jingyi Ma
Research Collection School Of Computing and Information Systems
Clone detection on large code repository is necessary for many big code analysis tasks. The goal is to provide rich information on identical and similar code across projects. Detecting near-miss code clones on big code is challenging since it requires intensive computing and memory resources as the scale of the source code increases. In this work, we propose SAGA, an efficient suffix-array based code clone detection tool designed with sophisticated GPU optimization. SAGA not only detects Type-l and Type-2 clones but also does so for cross-project large repositories and for the most computationally expensive Type-3 clones. Meanwhile, it also works …
Advanced Security Analysis For Emergent Software Platforms, Mohannad Alhanahnah
Advanced Security Analysis For Emergent Software Platforms, Mohannad Alhanahnah
School of Computing: Dissertations, Theses, and Student Research
Emergent software ecosystems, boomed by the advent of smartphones and the Internet of Things (IoT) platforms, are perpetually sophisticated, deployed into highly dynamic environments, and facilitating interactions across heterogeneous domains. Accordingly, assessing the security thereof is a pressing need, yet requires high levels of scalability and reliability to handle the dynamism involved in such volatile ecosystems.
This dissertation seeks to enhance conventional security detection methods to cope with the emergent features of contemporary software ecosystems. In particular, it analyzes the security of Android and IoT ecosystems by developing rigorous vulnerability detection methods. A critical aspect of this work is the …
Countering Cybersecurity Vulnerabilities In The Power System, Fengli Zhang
Countering Cybersecurity Vulnerabilities In The Power System, Fengli Zhang
Graduate Theses and Dissertations
Security vulnerabilities in software pose an important threat to power grid security, which can be exploited by attackers if not properly addressed. Every month, many vulnerabilities are discovered and all the vulnerabilities must be remediated in a timely manner to reduce the chance of being exploited by attackers. In current practice, security operators have to manually analyze each vulnerability present in their assets and determine the remediation actions in a short time period, which involves a tremendous amount of human resources for electric utilities. To solve this problem, we propose a machine learning-based automation framework to automate vulnerability analysis and …
Compositional Verification Of Heap-Manipulating Programs Through Property-Guided Learning, Long H. Pham, Jun Sun, Quang Loc Le
Compositional Verification Of Heap-Manipulating Programs Through Property-Guided Learning, Long H. Pham, Jun Sun, Quang Loc Le
Research Collection School Of Computing and Information Systems
Analyzing and verifying heap-manipulating programs automatically is challenging. A key for fighting the complexity is to develop compositional methods. For instance, many existing verifiers for heap-manipulating programs require user-provided specification for each function in the program in order to decompose the verification problem. The requirement, however, often hinders the users from applying such tools. To overcome the issue, we propose to automatically learn heap-related program invariants in a property-guided way for each function call. The invariants are learned based on the memory graphs observed during test execution and improved through memory graph mutation. We implemented a prototype of our approach …
Learning-Guided Network Fuzzing For Testing Cyber-Physical System Defences, Yuqi Chen, Chris Poskitt, Jun Sun, Sridhar Adepu, Fan Zhang
Learning-Guided Network Fuzzing For Testing Cyber-Physical System Defences, Yuqi Chen, Chris Poskitt, Jun Sun, Sridhar Adepu, Fan Zhang
Research Collection School Of Computing and Information Systems
The threat of attack faced by cyber-physical systems (CPSs), especially when they play a critical role in automating public infrastructure, has motivated research into a wide variety of attack defence mechanisms. Assessing their effectiveness is challenging, however, as realistic sets of attacks to test them against are not always available. In this paper, we propose smart fuzzing, an automated, machine learning guided technique for systematically finding 'test suites' of CPS network attacks, without requiring any knowledge of the system's control programs or physical processes. Our approach uses predictive machine learning models and metaheuristic search algorithms to guide the fuzzing of …
Blocks' Network: Redesign Architecture Based On Blockchain Technology, Moataz Hanif
Blocks' Network: Redesign Architecture Based On Blockchain Technology, Moataz Hanif
Doctoral Dissertations and Master's Theses
The Internet is a global network that uses communication protocols. It is considered the most important system reached by humanity, which no one can abandon. However, this technology has become a weapon that threatens the privacy of users, especially in the client-server model, where data is stored and managed privately. Additionally, users have no power over their data that store in a private server, which means users’ data may interrupt by government or might be sold via service provider for-profit purposes. Furthermore, blockchain is a technology that we can rely on to solve issues related to client-server model if appropriately …