Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

University of Central Florida

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 1 - 24 of 24

Full-Text Articles in Information Security

A Systematic Review And Characterization Of Privacy Noncompliance In Real-World Applications, Alexander E. Charkiewicz Jan 2026

A Systematic Review And Characterization Of Privacy Noncompliance In Real-World Applications, Alexander E. Charkiewicz

Graduate Studies Theses and Dissertations 2026

Software applications increasingly rely on user data to provide their functionality, but improper handling of such data can lead to serious privacy noncompliance with applicable regulations and policies. A prominent example is the Facebook–Cambridge Analytica scandal, in which a third-party application collected the personal data of approximately 87 million Facebook users without users' consent. Despite growing attention to privacy compliance, two key challenges hinder the systematic understanding and analysis of privacy noncompliance. First, unlike security vulnerabilities, which have been systematically categorized through taxonomies such as the Common Weakness Enumeration (CWE), privacy noncompliance lacks a technical taxonomy describing how it manifests …


Making Unsafe Sequences Unexecutable: Formal Protocol Enforcement For Cyber-Physical Systems, Arthur Amorim Jan 2026

Making Unsafe Sequences Unexecutable: Formal Protocol Enforcement For Cyber-Physical Systems, Arthur Amorim

Graduate Studies Theses and Dissertations 2026

Cyber-physical systems execute physical actions in response to software commands, making their communication protocols a primary attack surface. A stealthy attack is a sequence of individually valid messages that violates a required ordering, driving the system into an unsafe state without malware or protocol violation. Existing defenses examine messages or physical state in isolation, not protocol level sequences, and cannot prevent them. Preventing them requires enforcement that makes unsafe sequences unexecutable at the communication boundary.

Formal methods offer a principled path to enforcement, but no tool spans specification to safe deployed hardware. Model checking automates proofs but has no certified …


A Comprehensive And Comparative Examination Of Healthcare Data Breaches: Assessing Security, Privacy, And Performance, Mohammed Al Kinoon Jan 2024

A Comprehensive And Comparative Examination Of Healthcare Data Breaches: Assessing Security, Privacy, And Performance, Mohammed Al Kinoon

Graduate Thesis and Dissertation 2023-2024

The healthcare sector is pivotal, offering life-saving services and enhancing well-being and community life quality, especially with the transition from paper-based to digital electronic health records (EHR). While improving efficiency and patient safety, this digital shift has also made healthcare a prime target for cybercriminals. The sector's sensitive data, including personal identification information, treatment records, and SSNs, are valuable for illegal financial gains. The resultant data breaches, increased by interconnected systems, cyber threats, and insider vulnerabilities, present ongoing and complex challenges. In this dissertation, we tackle a multi-faceted examination of these challenges. We conducted a detailed analysis of healthcare data …


Privacy And Security Of The Windows Registry, Edward L. Amoruso Jan 2024

Privacy And Security Of The Windows Registry, Edward L. Amoruso

Graduate Thesis and Dissertation 2023-2024

The Windows registry serves as a valuable resource for both digital forensics experts and security researchers. This information is invaluable for reconstructing a user's activity timeline, aiding forensic investigations, and revealing other sensitive information. Furthermore, this data abundance in the Windows registry can be effortlessly tapped into and compiled to form a comprehensive digital profile of the user. Within this dissertation, we've developed specialized applications to streamline the retrieval and presentation of user activities, culminating in the creation of their digital profile. The first application, named "SeeShells," using the Windows registry shellbags, offers investigators an accessible tool for scrutinizing and …


Demystifying The Hosting Infrastructure Of The Free Content Web: A Security Perspective, Mohammed Alqadhi Jan 2024

Demystifying The Hosting Infrastructure Of The Free Content Web: A Security Perspective, Mohammed Alqadhi

Graduate Thesis and Dissertation 2023-2024

This dissertation delves into the security of free content websites, a crucial internet component that presents significant security challenges due to their susceptibility to exploitation by malicious actors. While prior research has highlighted the security disparities between free and premium content websites, it has not delved into the underlying causes. This study aims to address this gap by examining the security infrastructure of free content websites. The research commences with an analysis of the content management systems (CMSs) employed by these websites and their role. Data from 1,562 websites encompassing free and premium categories is collected to identify CMS usage …


A Systematic Review Of Cryptocurrencies Use In Cybercrimes, Kieran B D Human Jan 2023

A Systematic Review Of Cryptocurrencies Use In Cybercrimes, Kieran B D Human

Graduate Thesis and Dissertation 2023-2024

Cryptocurrencies are one of the most prominent applications of blockchain systems. While cryptocurrencies promise many features and advantages, such as decentralization, anonymity, and ease of access, those very features can be abused. For instance, as documented in various recent works, cryptocurrencies have been frequently abused in many different forms of cybercrime. Despite the plethora of works on measuring and understanding the abuse of cryptocurrencies in the digital space, there has been no work on systemizing this knowledge by comprehensively understanding those contributions, contrasting them based on their merit, and understanding the gap in this research space.

This thesis initiates the …


Towards A Holistic And Comparative Analysis Of The Free Content Web: Security, Privacy, And Performance, Abdulrahman Alabduljabbar Jan 2023

Towards A Holistic And Comparative Analysis Of The Free Content Web: Security, Privacy, And Performance, Abdulrahman Alabduljabbar

Electronic Theses and Dissertations, 2020-2023

Free content websites that provide free books, music, games, movies, etc., have existed on the Internet for many years. While it is a common belief that such websites might be different from premium websites providing the same content types in terms of their security, a rigorous analysis that supports this belief is lacking from the literature. In particular, it is unclear if those websites are as safe as their premium counterparts. In this dissertation, we set out to investigate the similarities and differences between free content and premium websites, including their risk profiles. Moreover, we analyze and quantify through measurements …


Discovering Vulnerabilities And Designing Trustworthy Defenses In Iot Systems And Devices, Bryan Pearson Jan 2023

Discovering Vulnerabilities And Designing Trustworthy Defenses In Iot Systems And Devices, Bryan Pearson

Electronic Theses and Dissertations, 2020-2023

Internet of Things (IoT) dominates many functions in the modern world, from sensing and reporting temperature, humidity, and air quality, to controlling and automating homes, commercial buildings, and equipment. However, IoT systems have received scrutiny in recent years due to countless security incidents, which can have physical and even deadly consequences. This research provides a comprehensive assessment of the security of IoT systems and devices, including low-cost microcontroller (MCU) based sensors, cloud services, and Building Automation Systems (BAS). We begin by exploring the current landscape of vulnerabilities and defenses in modern IoT applications. We show that many security needs can …


Examining Cooperative System Responses Against Grid Integrity Attacks, Alexander D. Parady Jan 2022

Examining Cooperative System Responses Against Grid Integrity Attacks, Alexander D. Parady

Honors Undergraduate Theses

Smart grid technologies are integral to society’s transition to sustainable energy sources, but they do not come without a cost. As the energy sector shifts away from a century’s reliance on fossil fuels and centralized generation, technology that actively monitors and controls every aspect of the power infrastructure has been widely adopted, resulting in a plethora of new vulnerabilities that have already wreaked havoc on critical infrastructure. Integrity attacks that feedback false data through industrial control systems, which result in possible catastrophic overcorrections and ensuing failures, have plagued grid infrastructure over the past several years. This threat is now at …


Towards Secure And Trustworthy Iot Systems, Lan Luo Jan 2022

Towards Secure And Trustworthy Iot Systems, Lan Luo

Electronic Theses and Dissertations, 2020-2023

The boom of the Internet of Things (IoT) brings great convenience to the society by connecting the physical world to the cyber world, but it also attracts mischievous hackers for benefits. Therefore, understanding potential attacks aiming at IoT systems and devising new protection mechanisms are of great significance to maintain the security and privacy of the IoT ecosystem. In this dissertation, we first demonstrate potential threats against IoT networks and their severe consequences via analyzing a real-world air quality monitoring system. By exploiting the discovered flaws, we can impersonate any victim sensor device and polluting its data with fabricated data. …


Exploring The Privacy Dimension Of Wearables Through Machine Learning-Enabled Inference, Ulku Meteriz Yildiran Jan 2022

Exploring The Privacy Dimension Of Wearables Through Machine Learning-Enabled Inference, Ulku Meteriz Yildiran

Electronic Theses and Dissertations, 2020-2023

Today's hyper-connected consumers demand convenient ways to tune into information without switching between devices, which led the industry leaders to the wearables. Wearables such as smartwatches, fitness trackers, and augmented reality (AR) glasses can be comfortably worn on the body. In addition, they offer limitless features, including activity tracking, authentication, navigation, and entertainment. Wearables that provide digestible information stimulate even higher consumer demand. However, to keep up with the ever-growing user expectations, developers keep adding new features and interaction methods to augment the use cases without considering their privacy impacts. In this dissertation, we explore the privacy dimension of wearables …


Fpga-Augmented Secure Crash-Consistent Non-Volatile Memory, Yu Zou Jan 2021

Fpga-Augmented Secure Crash-Consistent Non-Volatile Memory, Yu Zou

Electronic Theses and Dissertations, 2020-2023

Emerging byte-addressable Non-Volatile Memory (NVM) technology, although promising superior memory density and ultra-low energy consumption, poses unique challenges to achieving persistent data privacy and computing security, both of which are critically important to the embedded and IoT applications. Specifically, to successfully restore NVMs to their working states after unexpected system crashes or power failure, maintaining and recovering all the necessary security-related metadata can severely increase memory traffic, degrade runtime performance, exacerbate write endurance problem, and demand costly hardware changes to off-the-shelf processors. In this thesis, we summarize and expand upon two of our innovative works, ARES and HERMES, to design …


Family Communication: Examining The Differing Perceptions Of Parents And Teens Regarding Online Safety Communication, Tara Rutkowski Jan 2021

Family Communication: Examining The Differing Perceptions Of Parents And Teens Regarding Online Safety Communication, Tara Rutkowski

Honors Undergraduate Theses

The opportunity for online engagement increases possible exposure to potentially risky behaviors for teens, which may have significant negative consequences (Hair et al., 2009). Effective family communication about online safety can help reduce the risky adolescent behavior and limit the consequences after it occurs. This paper contributes a theory of communication factors that positively influence teen and parent perception of communication about online safety and provides design implications based on those findings. Previous work identified gaps in family communication, however, this study seeks to empirically identify factors that would close the communication gap from the perspective of both teens and …


Mind The Gap: Understanding Stakeholder Reactions To Different Types Of Data Security, Audra Diers-Lawson, Amelia Symons Jan 2020

Mind The Gap: Understanding Stakeholder Reactions To Different Types Of Data Security, Audra Diers-Lawson, Amelia Symons

International Crisis and Risk Communication Conference

Data security breaches are an increasingly common problem for organizations, yet there are critical gaps in our understanding of how different stakeholders understand and evaluate organizations that have experienced these kinds of security breaches. While organizations have developed relatively standard approaches to responding to security breaches that: (1) acknowledge the situation; (2) highlight how much they value their stakeholders’ privacy and private information; and (3) focus on correcting and preventing the problem in the future, the effectiveness of this response strategy and factors influencing it have not been adequately explored. This experiment focuses on a 2 (type of organization) x …


Improving The Security Of Critical Infrastructure: Metrics, Measurements, And Analysis, Jeman Park Jan 2020

Improving The Security Of Critical Infrastructure: Metrics, Measurements, And Analysis, Jeman Park

Electronic Theses and Dissertations, 2020-2023

In this work, we propose three important contributions needed in the process of improving the security of the critical infrastructure: metrics, measurement, and analysis. To improve security, metrics are key to ensuring the accuracy of the assessment and evaluation. Measurements are the core of the process of identifying the causality and effectiveness of various behaviors, and accurate measurement with the right assumptions is a cornerstone for accurate analysis. Finally, contextualized analysis essential for understanding measurements. Different results can be derived for the same data according to the analysis method, and it can serve as a basis for understanding and improving …


Interdisciplinary Cybersecurity For Resilient Cyberdefense, Rachid Ait Maalem Lahcen Jan 2020

Interdisciplinary Cybersecurity For Resilient Cyberdefense, Rachid Ait Maalem Lahcen

Electronic Theses and Dissertations, 2020-2023

Cybersecurity's role is to protect confidentiality, integrity, and availability of enterprise assets. Confidentiality secures data from theft, integrity mitigates modification of data in a malicious way, and availability assures continuation of systems' access and services. However, achieving these goals is difficult due to the mushrooming of various cyber attackers that come from individuals or state actors with motives ranging from ideological, financial, state-sponsored espionage, revenge, or simple curiosity and boredom. The difficulty also lies in the complexity of the cyber layers that are not well studied. Layers that interconnect and require effective communication and collaboration. This effectiveness is still lacking …


Understanding The Challenges Child Welfare Workers Encounter Related To Promoting The Online Safety Of Foster Youth, Denielle Kirk L. Abaquita Jan 2020

Understanding The Challenges Child Welfare Workers Encounter Related To Promoting The Online Safety Of Foster Youth, Denielle Kirk L. Abaquita

Honors Undergraduate Theses

Foster care case managers are responsible for the wellbeing of foster youth in the foster care system. Teens (ages 13-17) in foster care are most vulnerable to serious risks, such as sex trafficking. Such risks have been heightened by the advent of internet-based technologies that connect foster youth with unsafe others at unprecedented frequency and speed. This thesis examines how case managers tackle the challenge of online safety as it relates to adolescents in the foster care system in the United States. I conducted 32 semi-structured interviews with case managers who worked with foster teens (ages 13-17) within the past …


Co-Designing "Teenovate": An Intergenerational Online Safety Design Team, Arianna J. Davis Jan 2020

Co-Designing "Teenovate": An Intergenerational Online Safety Design Team, Arianna J. Davis

Honors Undergraduate Theses

The Socio-Technical Interaction Research (STIR) Lab at UCF intends to create a new participatory design program, called "Teenovate," where teenagers and adults work together to design technologies that keep teens safe online. Previous participatory design projects, however, commonly focus on younger children under the age of 13. Teens differ significantly from young children in how they develop, socialize, and perceive the world. To inform the design of Teenovate, so that their unique needs are appropriately met, we conducted a participatory design study with 21 teens using polls, open-ended response questions, and subsequent group discussions. The teens were intrigued by the …


High Performance And Secure Execution Environments For Emerging Architectures, Mazen Alwadi Jan 2020

High Performance And Secure Execution Environments For Emerging Architectures, Mazen Alwadi

Electronic Theses and Dissertations, 2020-2023

Energy-efficiency and performance have been the driving forces of system architectures and designers in the last century. Given the diversity of workloads and the significant performance and power improvements when running workloads on customized processing elements, system vendors are drifting towards new system architectures (e.g., FAM or HMM). Such architectures are being developed with the purpose of improving the system's performance, allow easier data sharing, and reduce the overall power consumption. Additionally, current computing systems suffer from a very wide attack surface, mainly due to the fact that such systems comprise of tens to hundreds of sub-systems that could be …


Federal, State And Local Law Enforcement Agency Interoperability Capabilities And Cyber Vulnerabilities, Tyrone Trapnell May 2019

Federal, State And Local Law Enforcement Agency Interoperability Capabilities And Cyber Vulnerabilities, Tyrone Trapnell

Electronic Theses and Dissertations

The National Data Exchange (N-DEx) System is the central informational hub located at the Federal Bureau of Investigation (FBI). Its purpose is to provide network subscriptions to all Federal, state and local level law enforcement agencies while increasing information collaboration across all domains. The National Data Exchange users must satisfy the Advanced Permission Requirements, confirming the terms of N-DEx information use, and the Verification Requirement (verifying the completeness, timeliness, accuracy, and relevancy of N-DEx information) through coordination with the record-owning agency (Management, 2018). A network infection model is proposed to simulate the spread impact of various cyber-attacks within Federal, state …


A Study Of Perceptions On Incident Response Exercises, Information Sharing, Situational Awareness, And Incident Response Planning In Power Grid Utilities, Joseph Garmon Jan 2019

A Study Of Perceptions On Incident Response Exercises, Information Sharing, Situational Awareness, And Incident Response Planning In Power Grid Utilities, Joseph Garmon

Electronic Theses and Dissertations

The power grid is facing increasing risks from a cybersecurity attack. Attacks that shut off electricity in Ukraine have already occurred, and successful compromises of the power grid that did not shut off electricity to customers have been privately disclosed in North America. The objective of this study is to identify how perceptions of various factors emphasized in the electric sector affect incident response planning. Methods used include a survey of 229 power grid personnel and the use of partial least squares structural equation modeling to identify causal relationships. This study reveals the relationships between perceptions by personnel responsible for …


Assessment Of Information Security Culture In Higher Education, Henry Glaspie Jan 2018

Assessment Of Information Security Culture In Higher Education, Henry Glaspie

Electronic Theses and Dissertations

Information security programs are instituted by organizations to provide guidance to their users who handle their data and systems. The main goal of these programs is to protect the organization's information assets through the creation and cultivation of a positive information security culture within the organization. As the collection and use of data expands in all economic sectors, the threat of data breach due to human error increases. Employee's behavior towards information security is influenced by the organizations information security programs and the overall information security culture. This study examines the human factors of an information security program and their …


A Value Sensitive Design Approach To Adolescent Mobile Online Safety, Arup Kumar Ghosh Jan 2018

A Value Sensitive Design Approach To Adolescent Mobile Online Safety, Arup Kumar Ghosh

Electronic Theses and Dissertations

With the rise of adolescent smartphone use, concerns about teen online safety are also on the rise. A number of parental control apps are available for mobile devices, but adoption of these apps has been markedly low. To better understand these apps, their users, and design opportunities in the space of mobile online safety for adolescents, we have conducted four studies informed by the principles of Value Sensitive Design (VSD). In Study 1 (Chapter 2), we conducted a web-based survey of 215 parents and their teens (ages 13-17) using two separate logistic regression models (parent and teen) to examine the …


How Many Credit Card Frauds Must We Endure Before Security Improves?, Maritza Martinez Mar 2014

How Many Credit Card Frauds Must We Endure Before Security Improves?, Maritza Martinez

UCF Forum

Yes, it can happen to you…