Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Databases and Information Systems (6)
- Engineering (6)
- Artificial Intelligence and Robotics (5)
- Computer Engineering (5)
- Other Computer Sciences (5)
-
- Software Engineering (5)
- Cybersecurity (3)
- Public Affairs, Public Policy and Public Administration (3)
- Social and Behavioral Sciences (3)
- Systems Architecture (3)
- Computer and Systems Architecture (2)
- Data Storage Systems (2)
- Defense and Security Studies (2)
- OS and Networks (2)
- Other Computer Engineering (2)
- Theory and Algorithms (2)
- Controls and Control Theory (1)
- Digital Communications and Networking (1)
- Disability and Equity in Education (1)
- Education (1)
- Education Policy (1)
- Educational Leadership (1)
- Educational Technology (1)
- Electrical and Computer Engineering (1)
- Graphics and Human Computer Interfaces (1)
- Industrial Engineering (1)
- Logic and Foundations (1)
- Institution
- Keyword
-
- Daniel Felix Ritchie School of Engineering and Computer Science (6)
- Computer Science (4)
- Information security (3)
- Cyber security (2)
- Internet of Things (2)
-
- Intrusion Detection (2)
- Machine Learning (2)
- Privacy (2)
- Security (2)
- TLA+ (2)
- 51% Attack (1)
- 5G (1)
- Adversarial learning (1)
- Amazon Web Services (AWS) (1)
- Anomaly detection (1)
- Artificial intelligence (AI) (1)
- Attacks (1)
- Authentication (1)
- Autonomous aerial vehicles (1)
- Blockchain (1)
- Bull Extractor (1)
- Bystanders (1)
- CAmkES (1)
- Case study (1)
- Chatbot (1)
- Classification. (1)
- Cloud platform (1)
- Concept drift (1)
- Cryptocurrency (1)
- Cyber kill chain (1)
Articles 1 - 25 of 25
Full-Text Articles in Information Security
Data Governance Maturity, Ai Integration, And Equity In Colorado K-12 Public Schools, John R. Curtin
Data Governance Maturity, Ai Integration, And Equity In Colorado K-12 Public Schools, John R. Curtin
Electronic Theses and Dissertations
Colorado's 179 K-12 public school districts operate as autonomous governance units, each responsible for securing and managing student data assets that span health, financial, residential, and academic records. The accelerating integration of artificial intelligence (AI) and machine learning (ML) tools into administrative workflows, productivity software, and instructional platforms has fundamentally altered the risk landscape for student data, yet governance frameworks at the state, district, and school levels have not kept pace. This dissertation investigates whether Colorado's decentralized educational governance structure is institutionally capable of producing equitable, secure, and sustainable data governance outcomes in the AI era.
Drawing on Institutional Theory …
Post-Vote Tampering In Nigerian Elections And The Role Of Blockchain-Enabled Electoral Systems, Ransome Chukwubuikem Enechukwu
Post-Vote Tampering In Nigerian Elections And The Role Of Blockchain-Enabled Electoral Systems, Ransome Chukwubuikem Enechukwu
Electronic Theses and Dissertations
Post-vote tampering during the collation and transmission of election results remains a persistent challenge in Nigerian elections, enabling manipulation of already-cast votes and weakening public trust in electoral outcomes. Existing technological interventions, including biometric voter accreditation and digital result transmission systems, improve voter authentication but do not adequately secure the post-vote result collation process. This thesis proposes a blockchain-enabled framework designed to protect the integrity of election results during the collation and transmission stages. Using a Design Science Research methodology, the study develops a permissioned blockchain framework based on Hyperledger Fabric that records polling-unit results as immutable ledger entries and …
Managing Software Dependency Risks In Web Applications, Christopher Alan Scott
Managing Software Dependency Risks In Web Applications, Christopher Alan Scott
Electronic Theses and Dissertations
Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security …
5g Network Slice Vulnerabilities And Exploit Chaining Through Enablers, John Breeden
5g Network Slice Vulnerabilities And Exploit Chaining Through Enablers, John Breeden
Electronic Theses and Dissertations
Network slicing provides fundamental support for the enhanced features of 5G. Network slicing enablers, such as software-defined networking and network function virtualization facilitate the separation of the physical distributed infrastructures and the functions that create isolated slices. With this framework, the network slice is no longer under the control of a single entity. Multiple infrastructure providers share responsibility for the slice. The 5G architecture derives from multiple services, distributed over great distances, and managed by multiple parties. Each enabler and provider adds vulnerability to network slicing. We examine the interweaving of these enablers to identify vulnerabilities, discuss potential mitigation, and …
Real Time Pii Scanning, John David
Real Time Pii Scanning, John David
Electronic Theses and Dissertations
The increased amount of web applications and internet software solutions utilizing cloud frameworks has contributed to large data sets of system log messages being generated constantly. These messages may contain sensitive data, creating an additional security risk for the systems and contributing to the need for analysis of such large volumes of data in real time. Large commercial data monitoring systems can solve for these analysis requirements, but they can be costly. We present a solution to analyzing web application log data which ingests it, processes it and visualizes sensitive data found within in real time. Our solution utilizes an …
Trust, Transparency, And Transport: The Impact Of Privacy Protection On The Acceptance Of Last-Mile Drone Delivery, Jurgen Heinz Famula
Trust, Transparency, And Transport: The Impact Of Privacy Protection On The Acceptance Of Last-Mile Drone Delivery, Jurgen Heinz Famula
Electronic Theses and Dissertations
A common set of problems commercial delivery companies face is finding ways to increase the efficiency and reliability of the “last mile” of a package’s journey, all while reducing operating costs. This need for efficiency has driven many companies to explore using unmanned aerial vehicles (UAVs), or drones, to get packages to their final destination. Although UAVs have great potential to help increase efficiency in commercial package delivery, this comes at a potential cost to the privacy of people who intersect the flight paths of these unmanned vehicles. This thesis explores the effect of a mobile phone application for commercial …
Formalization Of A Security Framework Design For A Health Prescription Assistant In An Internet Of Things System, Thomas Rolando Mellema
Formalization Of A Security Framework Design For A Health Prescription Assistant In An Internet Of Things System, Thomas Rolando Mellema
Electronic Theses and Dissertations
Security system design flaws will create greater risks and repercussions as the systems being secured further integrate into our daily life. One such application example is incorporating the powerful potential of the concept of the Internet of Things (IoT) into software services engineered for improving the practices of monitoring and prescribing effective healthcare to patients. A study was performed in this application area in order to specify a security system design for a Health Prescription Assistant (HPA) that operated with medical IoT (mIoT) devices in a healthcare environment. Although the efficiency of this system was measured, little was presented to …
Enhanced Content-Based Fake News Detection Methods With Context-Labeled News Sources, Duncan Arnfield
Enhanced Content-Based Fake News Detection Methods With Context-Labeled News Sources, Duncan Arnfield
Electronic Theses and Dissertations
This work examined the relative effectiveness of multilayer perceptron, random forest, and multinomial naïve Bayes classifiers, trained using bag of words and term frequency-inverse dense frequency transformations of documents in the Fake News Corpus and Fake and Real News Dataset. The goal of this work was to help meet the formidable challenges posed by proliferation of fake news to society, including the erosion of public trust, disruption of social harmony, and endangerment of lives. This training included the use of context-categorized fake news in an effort to enhance the tools’ effectiveness. It was found that term frequency-inverse dense frequency provided …
Designing Secure Mental Healthcare Chatbots For Older Adults, Aishwarya Surani
Designing Secure Mental Healthcare Chatbots For Older Adults, Aishwarya Surani
Electronic Theses and Dissertations
The landscape of mental health support has evolved as a result of the rising demand for digital mental healthcare services. Users now have an opportunity to seek mental health support online due to the growth of digital platforms. For those looking for mental health treatments, chatbots have evolved as user-friendly, accessible platforms that provide remote access and convenience. However, for chatbots to be effective, users must divulge personal and sensitive information, such as demographics, insurance information, and a history of mental illness. While chatbots offer services to a variety of demographic users, older adults face unique challenges related to usability, …
Blockchain Security: Double-Spending Attack And Prevention, William Henry Scott Iii
Blockchain Security: Double-Spending Attack And Prevention, William Henry Scott Iii
Electronic Theses and Dissertations
This thesis shows that distributed consensus systems based on proof of work are vulnerable to hashrate-based double-spending attacks due to abuse of majority rule. Through building a private fork of Litecoin and executing a double-spending attack this thesis examines the mechanics and principles behind the attack. This thesis also conducts a survey of preventative measures used to deter double-spending attacks, concluding that a decentralized peer-to-peer network using proof of work is best protected by the addition of an observer system whether internal or external.
Differentiate Metasploit Framework Attacks From Others, Gina Liu Ajero
Differentiate Metasploit Framework Attacks From Others, Gina Liu Ajero
Electronic Theses and Dissertations
Metasploit Framework is a very popular collection of penetration testing tools. From auxiliaries such as network scanners and mappers to exploits and payloads, Metasploit Framework offers a plethera of apparatuses to implement all the stages of a penetration test. There are two versions: both a free open-source community version and a commercial professional version called Metasploit Pro. The free version, Metasploit Framework, is heavily used by cyber crimininals to carry out illegal activities to gain unauthorized access to targets.
In this paper, I conduct experiments in a virtual environment to discover whether attacks originated from Metasploit Framework are marked with …
A Machine Learning Approach For Reconnaissance Detection To Enhance Network Security, Rachel Bakaletz
A Machine Learning Approach For Reconnaissance Detection To Enhance Network Security, Rachel Bakaletz
Electronic Theses and Dissertations
Before cyber-crime can happen, attackers must research the targeted organization to collect vital information about the target and pave the way for the subsequent attack phases. This cyber-attack phase is called reconnaissance or enumeration. This malicious phase allows attackers to discover information about a target to be leveraged and used in an exploit. Information such as the version of the operating system and installed applications, open ports can be detected using various tools during the reconnaissance phase. By knowing such information cyber attackers can exploit vulnerabilities that are often unique to a specific version.
In this work, we develop an …
Lightweight Mutual Authentication And Privacy Preservation Schemes For Iot Systems., Samah Mansour
Lightweight Mutual Authentication And Privacy Preservation Schemes For Iot Systems., Samah Mansour
Electronic Theses and Dissertations
Internet of Things (IoT) presents a holistic and transformative approach for providing services in different domains. IoT creates an atmosphere of interaction between humans and the surrounding physical world through various technologies such as sensors, actuators, and the cloud. Theoretically, when everything is connected, everything is at risk. The rapid growth of IoT with the heterogeneous devices that are connected to the Internet generates new challenges in protecting and preserving user’s privacy and ensuring the security of our lives. IoT systems face considerable challenges in deploying robust authentication protocols because some of the IoT devices are resource-constrained with limited computation …
Knot Flow Classification And Its Applications In Vehicular Ad-Hoc Networks (Vanet), David Schmidt
Knot Flow Classification And Its Applications In Vehicular Ad-Hoc Networks (Vanet), David Schmidt
Electronic Theses and Dissertations
Intrusion detection systems (IDSs) play a crucial role in the identification and mitigation for attacks on host systems. Of these systems, vehicular ad hoc networks (VANETs) are difficult to protect due to the dynamic nature of their clients and their necessity for constant interaction with their respective cyber-physical systems. Currently, there is a need for a VANET-specific IDS that meets this criterion. To this end, a spline-based intrusion detection system has been pioneered as a solution. By combining clustering with spline-based general linear model classification, this knot flow classification method (KFC) allows for robust intrusion detection to occur. Due its …
Formally Designing And Implementing Cyber Security Mechanisms In Industrial Control Networks., Mehdi Sabraoui
Formally Designing And Implementing Cyber Security Mechanisms In Industrial Control Networks., Mehdi Sabraoui
Electronic Theses and Dissertations
This dissertation describes progress in the state-of-the-art for developing and deploying formally verified cyber security devices in industrial control networks. It begins by detailing the unique struggles that are faced in industrial control networks and why concepts and technologies developed for securing traditional networks might not be appropriate. It uses these unique struggles and examples of contemporary cyber-attacks targeting control systems to argue that progress in securing control systems is best met with formal verification of systems, their specifications, and their security properties. This dissertation then presents a development process and identifies two technologies, TLA+ and seL4, that can be …
Federal, State And Local Law Enforcement Agency Interoperability Capabilities And Cyber Vulnerabilities, Tyrone Trapnell
Federal, State And Local Law Enforcement Agency Interoperability Capabilities And Cyber Vulnerabilities, Tyrone Trapnell
Electronic Theses and Dissertations
The National Data Exchange (N-DEx) System is the central informational hub located at the Federal Bureau of Investigation (FBI). Its purpose is to provide network subscriptions to all Federal, state and local level law enforcement agencies while increasing information collaboration across all domains. The National Data Exchange users must satisfy the Advanced Permission Requirements, confirming the terms of N-DEx information use, and the Verification Requirement (verifying the completeness, timeliness, accuracy, and relevancy of N-DEx information) through coordination with the record-owning agency (Management, 2018). A network infection model is proposed to simulate the spread impact of various cyber-attacks within Federal, state …
Probabilistic Record Linkage With Elliptic Curve Operations, Shreya Dhiren Patel
Probabilistic Record Linkage With Elliptic Curve Operations, Shreya Dhiren Patel
Electronic Theses and Dissertations
Federated query processing for an electronic health record infrastructure enables large epidemiology studies using data integrated from geographically dispersed medical institutions. However, government imposed privacy regulations prohibit disclosure of patient's health record outside the context of clinical care, thereby making it difficult to determine which records correspond to the same entity in the process of query aggregation.
Privacy-preserving record linkage is an actively pursued research area to facilitate the linkage of database records under the constraints of regulations that do not allow the linkage agents to learn sensitive identities of record owners. In earlier works, scalability has been shown to …
A Study Of Perceptions On Incident Response Exercises, Information Sharing, Situational Awareness, And Incident Response Planning In Power Grid Utilities, Joseph Garmon
Electronic Theses and Dissertations
The power grid is facing increasing risks from a cybersecurity attack. Attacks that shut off electricity in Ukraine have already occurred, and successful compromises of the power grid that did not shut off electricity to customers have been privately disclosed in North America. The objective of this study is to identify how perceptions of various factors emphasized in the electric sector affect incident response planning. Methods used include a survey of 229 power grid personnel and the use of partial least squares structural equation modeling to identify causal relationships. This study reveals the relationships between perceptions by personnel responsible for …
Assessment Of Information Security Culture In Higher Education, Henry Glaspie
Assessment Of Information Security Culture In Higher Education, Henry Glaspie
Electronic Theses and Dissertations
Information security programs are instituted by organizations to provide guidance to their users who handle their data and systems. The main goal of these programs is to protect the organization's information assets through the creation and cultivation of a positive information security culture within the organization. As the collection and use of data expands in all economic sectors, the threat of data breach due to human error increases. Employee's behavior towards information security is influenced by the organizations information security programs and the overall information security culture. This study examines the human factors of an information security program and their …
A Value Sensitive Design Approach To Adolescent Mobile Online Safety, Arup Kumar Ghosh
A Value Sensitive Design Approach To Adolescent Mobile Online Safety, Arup Kumar Ghosh
Electronic Theses and Dissertations
With the rise of adolescent smartphone use, concerns about teen online safety are also on the rise. A number of parental control apps are available for mobile devices, but adoption of these apps has been markedly low. To better understand these apps, their users, and design opportunities in the space of mobile online safety for adolescents, we have conducted four studies informed by the principles of Value Sensitive Design (VSD). In Study 1 (Chapter 2), we conducted a web-based survey of 215 parents and their teens (ages 13-17) using two separate logistic regression models (parent and teen) to examine the …
Authorship Identification Of Translation Algorithms., Keishin Nishiyama
Authorship Identification Of Translation Algorithms., Keishin Nishiyama
Electronic Theses and Dissertations
Authorship analysis is a process of identifying a true writer of a given document and has been studied for decades. However, only a handful of studies of authorship analysis of translators are available despite the fact that online translations are widely available and also popularly employed in automatic translations of posts in social networking services. The identification of translation algorithms has potential to contribute to the investigation of cybercrimes, involving translation of scam messages by algorithmic translations to reach speakers of foreign languages. This study tested bag of words (BOW) approach in authorship attribution and the existing approaches to translator …
Dynamic Adversarial Mining - Effectively Applying Machine Learning In Adversarial Non-Stationary Environments., Tegjyot Singh Sethi
Dynamic Adversarial Mining - Effectively Applying Machine Learning In Adversarial Non-Stationary Environments., Tegjyot Singh Sethi
Electronic Theses and Dissertations
While understanding of machine learning and data mining is still in its budding stages, the engineering applications of the same has found immense acceptance and success. Cybersecurity applications such as intrusion detection systems, spam filtering, and CAPTCHA authentication, have all begun adopting machine learning as a viable technique to deal with large scale adversarial activity. However, the naive usage of machine learning in an adversarial setting is prone to reverse engineering and evasion attacks, as most of these techniques were designed primarily for a static setting. The security domain is a dynamic landscape, with an ongoing never ending arms race …
Leveraging Client Processing For Location Privacy In Mobile Local Search, Wisam Mohamed Eltarjaman
Leveraging Client Processing For Location Privacy In Mobile Local Search, Wisam Mohamed Eltarjaman
Electronic Theses and Dissertations
Usage of mobile services is growing rapidly. Most Internet-based services targeted for PC based browsers now have mobile counterparts. These mobile counterparts often are enhanced when they use user's location as one of the inputs. Even some PC-based services such as point of interest Search, Mapping, Airline tickets, and software download mirrors now use user's location in order to enhance their services. Location-based services are exactly these, that take the user's location as an input and enhance the experience based on that. With increased use of these services comes the increased risk to location privacy. The location is considered an …
Assessing The Physical Security Of Idfs With Psatool: A Case Study, Sulabh Bista
Assessing The Physical Security Of Idfs With Psatool: A Case Study, Sulabh Bista
Electronic Theses and Dissertations
PSATool is a checklist-based, web-based application for assessing the physical security of Intermediate Distribution Frameworks. IDFs, or wiring closets, are an integral if often neglected component of information security. Earlier work by Timbs (2013) identified 52 IDF-related security requirements based on federal and international standards for physical security. PSATool refines Timbs’ prototype application for IDF assessment, extending it with support for mobile-device-based data entry.
PSATool was used to assess 25 IDFs at a regional university, a college and a manufacturing corporation, with an average of 9 minutes per assessment. Network managers and assessors involved in the assessments characterized PSATool as …
Heuristics For Improved Enterprise Intrusion Detection, James J. Treinen
Heuristics For Improved Enterprise Intrusion Detection, James J. Treinen
Electronic Theses and Dissertations
One of the greatest challenges facing network operators today is the identification of malicious activity on their networks. The current approach is to deploy a set of intrusion detection sensors (IDSs) in various locations throughout the network and on strategic hosts. Unfortunately, the available intrusion detection technologies generate an overwhelming volume of false alarms, making the task of identifying genuine attacks nearly impossible. This problem is very difficult to solve even in networks of nominal size. The task of uncovering attacks in enterprise class networks quickly becomes unmanageable.
Research on improving intrusion detection sensors is ongoing, but given the nature …