Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

City University of New York (CUNY)

Discipline
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 1 - 30 of 55

Full-Text Articles in Information Security

The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala Jun 2026

The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala

Student Theses

The rapid adoption of Large Language Models (LLMs) in software development has transformed coding practices by enabling automated code generation, completion, and optimization. Despite these advantages, concerns persist regarding the security and reliability of LLM-generated code. This study presents a comprehensive evaluation of both the functional correctness and security of code produced by three prominent LLMs as of early 2026. A total of 4,800 code snippets were generated using 100 security-focused programming prompts derived from the OWASP Top 10:2025, translated across eight natural languages and two phrasing styles (literal and natural developer-oriented prompts). To assess performance, a multi-stage experimental framework …


Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy Jun 2026

Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy

Student Theses

Social network platforms, child safety organizations, and image provenance systems use perceptual hashing to identify known child sexual abuse material (CSAM), support content moderation and reverse image search, and verify image integrity. Perceptual hashing works by producing similar fingerprints for visually similar images, even after common transformations such as compression, resizing, or minor brightness changes. This useful similarity-preserving property also creates an adversarial attack surface, as attackers can use AI-assisted or conventional image manipulation techniques to move a hash across a matching threshold while maintaining visual similarity, often without access to specialized hardware.

The security failures produced by adversarial attacks …


Exploring Adversarial Threats To Neuralhash: A Perceptual Hashing Algorithm, Gurleen Kaur Jul 2025

Exploring Adversarial Threats To Neuralhash: A Perceptual Hashing Algorithm, Gurleen Kaur

Student Theses

Perceptual hashing algorithms are algorithms that generate content-based image hashes by extracting perceptual features from the images. Unlike cryptographic hashes, which exhibit significant changes with even slight input alterations, perceptual hashes do not change when modifications like compression, color correction and brightness are applied to the images. These hashes are designed to remain similar for inputs that are visually or perceptually alike, which has led to their widespread application in detecting duplicate images, finding similar images for reverse image search and to detecting inappropriate content of Child sexual abuse (CSAM) images by comparing image hashes with dataset of known perceptual …


Full-Stack Web Applications: Infrastructure, Development Pipelines & Devsecops, Yassine Chahid, Patrick Slattery Jul 2025

Full-Stack Web Applications: Infrastructure, Development Pipelines & Devsecops, Yassine Chahid, Patrick Slattery

Publications and Research

This research explores emerging development methodologies and technologies which facilitate the deployment and maintenance of software applications. It evaluates architectural styles for the development of software such as monolithic (legacy) and microservice models, with a focus on their key differences such as scalability or project structure through to the development of an application. By examining methodologies such as Agile and continuous integration/continuous development pipelines along with the deployment tools Docker and Git for version/release control, the study analyzes how these innovations speed up development, improve existing practices, and serve as the foundation for development operations. Cloud solutions for tasks such …


Attribute-Based Fine-Grained Access Control Using Verifiable Credentials, Srinivasa Dumpa Jul 2024

Attribute-Based Fine-Grained Access Control Using Verifiable Credentials, Srinivasa Dumpa

Student Theses

In the era of digital transformation, ensuring secure and privacy-preserving access control mechanisms is of paramount importance. Traditional identity-based access control systems often fall short in providing granular control and user autonomy over digital identities. This thesis presents a novel approach to access control by leveraging the power of verifiable credentials and attribute-based access control. The proposed system introduces a decentralized and user-centric framework that enables fine-grained access control based on specific attributes encapsulated within verifiable credentials. These tamper-evident digital credentials, stored in a user's digital wallet, contain a rich set of attributes that can be selectively disclosed to grant …


Performance Modeling For Network Anomaly Detection And Sensor Networks, Jie Chu Jun 2023

Performance Modeling For Network Anomaly Detection And Sensor Networks, Jie Chu

Dissertations, Theses, and Capstone Projects

Computer networks have become one of the fundamental communication infrastructures of the modern world. Data collection and data analysis over computer networks is a broad area of research and is getting more and more complicated as the ever-increasing complexity of the computer networks. In this dissertation, I will conduct performance modeling work for a few network scenarios and applications. In the first part of this dissertation, I will focus on two vital perspectives of the Internet, one from network administrators and the other from network users. Network administrators are key to manage and protect a computer network. I will study …


Transformation And Abstraction To Aid Comparison Of Binary Executables Across Compilation Environments, Jeremy D. Seideman Jun 2023

Transformation And Abstraction To Aid Comparison Of Binary Executables Across Compilation Environments, Jeremy D. Seideman

Dissertations, Theses, and Capstone Projects

Binary analysis allows researchers to examine how programs are constructed and how they will impact an underlying system. The various analysis techniques allow the determination of code authorship, reuse, and similarity. Detecting code reuse is significant because code reuse can be a method for vulnerabilities and security issues to spread among software projects. In this work, we examine techniques that can aid in binary analysis, especially those that abstract and transform binaries, so that they can be compared across compilation environments, including possible changes in compiler version, hardware architecture, and compilation options. Historically, this has been difficult to accomplish since …


Structural Anomaly Detection, Shoufu Luo Jun 2023

Structural Anomaly Detection, Shoufu Luo

Dissertations, Theses, and Capstone Projects

As computer systems become more complex and powerful, the threat of sophisticated and persistent computer attacks increases dramatically. Traditional intrusion detection systems that rely on log analysis struggle to keep pace with these evolving threats, as the attacking trails are often buried in high-volume and high-velocity legitimate activities in the system. Despite tremendous progress in applying machine learning techniques to anomaly-based intrusion detection, such methods continue to suffer from a high false positive rate due to the diversity and variability of individual behavior.To address this problem, this thesis proposes a new framework for detecting structural anomalies in computer systems. The …


Anomaly Based Intrusion Detection System Through Remote Virtual Machine Introspection, Huseyn Huseynov Jan 2023

Anomaly Based Intrusion Detection System Through Remote Virtual Machine Introspection, Huseyn Huseynov

Dissertations and Theses

Research on identifying malicious applications is an important direction in information security, especially when it comes to detection of evasive malware such as keyloggers, trojans, rootkits and their derivatives. Inspired by a biological immune system and based on negative selection algorithm approach to detect various types of malwares is proposed in this paper.

By deeply studying Linux kernel, understanding links behind different internal system processes, examining, and experimenting with hundreds of various keyloggers we propose a single Artificial Intelligence based solution as a comprehensive protection against wide range of malwares. Developed Intrusion Detection System (IDS) can be deployed in the …


Witness-Authenticated Key Exchange, Kelsey G. Melissaris Sep 2022

Witness-Authenticated Key Exchange, Kelsey G. Melissaris

Dissertations, Theses, and Capstone Projects

In this dissertation we investigate Witness-Authenticated Key Exchange (WAKE), a key agreement protocol in which each party is authenticated through knowledge of a witness to an arbitrary NP statement. We provide both game-based and universally composable definitions. Thereby, this thesis presents solutions for the most flexible and general method of authentication for group key exchange, providing simple constructions from (succinct) signatures of knowledge (SOK) and a two round UC-secure protocol.

After a discussion of flaws in previous definitions for WAKE we supply a new and improved game-based definition along with the first definition for witness-authenticated key exchange between groups of …


On The Cryptographic Deniability Of The Signal Protocol, Nihal Vatandas Sep 2022

On The Cryptographic Deniability Of The Signal Protocol, Nihal Vatandas

Dissertations, Theses, and Capstone Projects

Offline deniability is the ability to a posteriori deny having participated in a particular communication session. This property has been widely assumed for the Signal messaging application, yet no formal proof has appeared in the literature. In this work, we present the first formal study of the offline deniability of the Signal protocol. Our analysis shows that building a deniability proof for Signal is non-trivial and requires strong assumptions on the underlying mathematical groups where the protocol is run.

To do so, we study various implicitly authenticated key exchange protocols, including MQV, HMQV, and 3DH/X3DH, the latter being the core …


Code Cyber: A Curated Collection Of Cybersecurity Career Learning And Preparation Resources, Kazi Tasin, Ethan Pruzhansky, Jason Lin, Tanvir Rahman, Patrick J. Slattery Jul 2022

Code Cyber: A Curated Collection Of Cybersecurity Career Learning And Preparation Resources, Kazi Tasin, Ethan Pruzhansky, Jason Lin, Tanvir Rahman, Patrick J. Slattery

Publications and Research

Since we are living in a digital age, the need to protect ourselves and those who are vulnerable to cyber-attacks is paramount to prevent cyber attacks that steal information such as banking accounts and important sensitive information.

Our research team extensively investigated the five aspects of cybersecurity such as identity, protection, detection, and response. By conducting various interviews with cybersecurity professionals, we gathered information about these five aspects for example security intelligence or security operations and response, (thread hunting, response orchestration) identity access management, (identity management, and data protection), and risks (risk perspective). Our main goal is to look into …


Formal Verification Applications For The Treekem Continuous Group Key Agreement Protocol, Alexander J. Washburn Jul 2022

Formal Verification Applications For The Treekem Continuous Group Key Agreement Protocol, Alexander J. Washburn

Theses and Dissertations

The features of Secure Group Messaging, the security guarantees of Message Layer Security, and the TreeKEM protocol designed to satisfy these guarantees and features are explored. A motivation and methodology for verification via explicit model checking is presented. Subsequently, a translation of the TreeKEM protocol into a Promela reference model is described, examining the nuances explicit model checking brings. Finally the results of the formal verification methods are discussed.


An Adaptive Cryptosystem On A Finite Field, Awnon Bhowmik, Unnikrishnan Menon Aug 2021

An Adaptive Cryptosystem On A Finite Field, Awnon Bhowmik, Unnikrishnan Menon

Publications and Research

Owing to mathematical theory and computational power evolution, modern cryptosystems demand ingenious trapdoor functions as their foundation to extend the gap between an enthusiastic interceptor and sensitive information. This paper introduces an adaptive block encryption scheme. This system is based on product, exponent, and modulo operation on a finite field. At the heart of this algorithm lies an innovative and robust trapdoor function that operates in the Galois Field and is responsible for the superior speed and security offered by it. Prime number theorem plays a fundamental role in this system, to keep unwelcome adversaries at bay. This is a …


Shedding Light On Dark Patterns: A Case Study On Digital Harms, Noreen Y. Whysel Apr 2021

Shedding Light On Dark Patterns: A Case Study On Digital Harms, Noreen Y. Whysel

Publications and Research

You’ve been there before. You thought you could trust someone with a secret. You thought it would be safe, but found out later that they blabbed to everyone. Or maybe they didn’t share it, but the way they used it felt manipulative. You gave more than you got and it didn’t feel fair. But now that it’s out there, do you even have control anymore?

Ok. Now imagine that person was your supermarket. Or your bank. Or your boss.

As designers of digital spaces for consumer products and services, how often do we consider the relationship we have with our …


The Internet Never Forgets: Image-Based Sexual Abuse And The Workplace, John Schriner, Melody Lee Rood Oct 2020

The Internet Never Forgets: Image-Based Sexual Abuse And The Workplace, John Schriner, Melody Lee Rood

Publications and Research

Image-based sexual abuse (IBSA), commonly known as revenge pornography, is a type of cyberharassment that often results in detrimental effects to an individual's career and livelihood. Although there exists valuable research concerning cyberharassment in the workplace generally, there is little written about specifically IBSA and the workplace. This chapter examines current academic research on IBSA, the issues with defining this type of abuse, victim blaming, workplace policy, and challenges to victim-survivors' redress. The authors explore monetary motivation for websites that host revenge pornography and unpack how the dark web presents new challenges to seeking justice. Additionally, this chapter presents recommendations …


Lecture - Csci 275: Linux Systems Administration And Security, Moe Hassan, Nyc Tech-In-Residence Corps Oct 2020

Lecture - Csci 275: Linux Systems Administration And Security, Moe Hassan, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for CSCI 275: Linux Systems Administration and Security


Cybersecurity (Cs 3550): Lecture 11: Identity & Access Management, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 11: Identity & Access Management, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "11: Identity & Access Management" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 1: Introduction & State Of Cybersecurity, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 1: Introduction & State Of Cybersecurity, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "1: Introduction & State of Cybersecurity" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 2: Cybersecurity Fundamentals, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 2: Cybersecurity Fundamentals, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "2: Cybersecurity Fundamentals" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 5: Intro To Web Applications I, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 5: Intro To Web Applications I, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "5: Intro to Web Applications I" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 9-10: Data Protection & Cryptography, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 9-10: Data Protection & Cryptography, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "9-10: Data Protection & Cryptography" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 15: Application Security, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 15: Application Security, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "15: Application Security" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 14: Business Continuity & Disaster Recovery, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 14: Business Continuity & Disaster Recovery, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "14: Business Continuity & Disaster Recovery" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 12: Network & Endpoint Security, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 12: Network & Endpoint Security, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "12: Network & Endpoint Security" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 7-8: Risk Management, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 7-8: Risk Management, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "7-8: Risk Management" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 3-4: Networking Fundamentals, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 3-4: Networking Fundamentals, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "3-4: Networking Fundamentals" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 21: Hacking Democracy: Election Security, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 21: Hacking Democracy: Election Security, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "21: Hacking Democracy: Election Security" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 18-19: Anatomy Of A Breach, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 18-19: Anatomy Of A Breach, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "18-19: Anatomy of a Breach" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.


Cybersecurity (Cs 3550): Lecture 13: Patching & Vulnerability Management, Michael Whiteman, Nyc Tech-In-Residence Corps Apr 2020

Cybersecurity (Cs 3550): Lecture 13: Patching & Vulnerability Management, Michael Whiteman, Nyc Tech-In-Residence Corps

Open Educational Resources

Lecture for the course: CIS 3550: Cybersecurity - "13: Patching & Vulnerability Management" delivered at Baruch College in Spring 2020 by Michael Whiteman as part of the Tech-in-Residence Corps program.