Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (4)
- Computer Engineering (3)
- Social and Behavioral Sciences (3)
- Psychology (2)
- Aerospace Engineering (1)
-
- Applied Behavior Analysis (1)
- Artificial Intelligence and Robotics (1)
- Business (1)
- Computer Law (1)
- Contracts (1)
- Cybersecurity (1)
- Defense and Security Studies (1)
- Digital Communications and Networking (1)
- Electrical and Computer Engineering (1)
- Internet Law (1)
- Law (1)
- Management Sciences and Quantitative Methods (1)
- Multi-Vehicle Systems and Air Traffic Control (1)
- OS and Networks (1)
- Power and Energy (1)
- Public Affairs, Public Policy and Public Administration (1)
- Software Engineering (1)
- Statistics and Probability (1)
- Theory and Algorithms (1)
- Institution
- Keyword
-
- Communication model (2)
- Confidentiality (2)
- Cybersecurity (2)
- Malware detection (2)
- Anomaly detection (1)
-
- Api call (1)
- Awareness (1)
- Biometric authentication (1)
- Budgeting (1)
- Certificate-based signature (1)
- Clustering (1)
- Computational Diffie–Hellman assumption (1)
- Computer simulation (1)
- Con-resistant trust (1)
- Contactless fingerprint recognition (1)
- Contracts (1)
- Counter espionage (1)
- Critical infrastructure (1)
- Cyber security (1)
- Cyber security user behavior (1)
- Data breaches (1)
- Decision trees (1)
- Deep learning (1)
- Digital Forensics (1)
- Dynamic analysis (1)
- Engineering, Computer Engineering, Computer Sciences, Digital Communications and Networking, Information Security (1)
- Evaluation research (1)
- FPGA (1)
- False injection (1)
- Firewall (1)
Articles 1 - 22 of 22
Full-Text Articles in Information Security
Deep Learning Based Contactless Fingerprint Identification, Mohammad Alsmirat, M. Moneb Khaled, Aghyad A.L. Sayadi
Deep Learning Based Contactless Fingerprint Identification, Mohammad Alsmirat, M. Moneb Khaled, Aghyad A.L. Sayadi
Faculty Publications
Biometric authentication systems, particularly contactless fingerprint methods, offer enhanced security and convenience across various domains like access control, law enforcement, and finance. Despite these advantages, contactless systems face significant challenges related to image quality, finger orientation, and environmental factors. To address this, our paper presents the first extensive deep learning-based study on contactless fingerprint recognition using a large dataset of 2,143 images from 175 individuals. Our proposed approach integrates state-of-the-art preprocessing techniques with deep learning models to boost identification performance. After studying various transfer learning models, we achieved a high accuracy of 93.5%. We also conducted two further studies on …
Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi
Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi
Faculty Publications
Contract law is supposed to enable people to reach genuine agreements and cooperate. If this ideal was ever a reality, the rise of mass market contracts and boilerplate rendered it pure fiction. Modern consumer contracts are incomprehensible to most people. No one reads them anyway.
Digital contracting involves design features that amplify traditional boilerplate harms and create others. For example, digital contracting is too cheap; low marginal costs lead to overexpansion in scale and scope. To make matters worse, the loss of autonomy from repeat engagement with digital contracting systems is pernicious. People become increasingly predictable and programmable as digital …
Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham
Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham
Faculty Publications
Modern computing systems are primarily designed for maximum performance, which inadvertently introduces vulnerabilities at the micro-architecture level. While cache side-channel analysis has received significant attention, other Central Processing Units (CPUs) components like the Translation Lookaside Buffer (TLB) can also be exploited to leak sensitive information. This paper focuses on the TLB, a micro-architecture component that is vulnerable to side-channel attacks. Despite the coarse granularity at the page level, advancements in tools and techniques have made TLB information leakage feasible. The primary goal of this study is not to demonstrate the potential for information leakage from the TLB but to establish …
Optimizing Cybersecurity Budgets With Attacksimulation, Alexander Master, George Hamilton, J. Eric Dietz
Optimizing Cybersecurity Budgets With Attacksimulation, Alexander Master, George Hamilton, J. Eric Dietz
Faculty Publications
Modern organizations need effective ways to assess cybersecurity risk. Successful cyber attacks can result in data breaches, which may inflict significant loss of money, time, and public trust. Small businesses and non-profit organizations have limited resources to invest in cybersecurity controls and often do not have the in-house expertise to assess their risk. Cyber threat actors also vary in sophistication, motivation, and effectiveness. This paper builds on the previous work of Lerums et al., who presented an AnyLogic model for simulating aspects of a cyber attack and the efficacy of controls in a generic enterprise network. This paper argues that …
Extending The Quality Of Secure Service Model To Multi-Hop Networks, Paul M. Simon, Scott R. Graham
Extending The Quality Of Secure Service Model To Multi-Hop Networks, Paul M. Simon, Scott R. Graham
Faculty Publications
Rarely are communications networks point-to-point. In most cases, transceiver relay stations exist between transmitter and receiver end-points. These relay stations, while essential for controlling cost and adding flexibility to network architectures, reduce the overall security of the respective network. In an effort to quantify that reduction, we extend the Quality of Secure Service (QoSS) model to these complex networks, specifically multi-hop networks. In this approach, the quantification of security is based upon probabilities that adversarial listeners and disruptors gain access to or manipulate transmitted data on one or more of these multi-hop channels. Message fragmentation and duplication across available channels …
Traffic Collision Avoidance System: False Injection Viability, John Hannah, Robert F. Mills, Richard Dill, Douglas D. Hodson
Traffic Collision Avoidance System: False Injection Viability, John Hannah, Robert F. Mills, Richard Dill, Douglas D. Hodson
Faculty Publications
Safety is a simple concept but an abstract task, specifically with aircraft. One critical safety system, the Traffic Collision Avoidance System II (TCAS), protects against mid-air collisions by predicting the course of other aircraft, determining the possibility of collision, and issuing a resolution advisory for avoidance. Previous research to identify vulnerabilities associated with TCAS’s communication processes discovered that a false injection attack presents the most comprehensive risk to veritable trust in TCAS, allowing for a mid-air collision. This research explores the viability of successfully executing a false injection attack against a target aircraft, triggering a resolution advisory. Monetary constraints precluded …
Strengthening Criteria Independence Through Optimization Of Alternative Value Ratio Comparisons, Joseph P. Kristbaum, Frank W. Ciarallo
Strengthening Criteria Independence Through Optimization Of Alternative Value Ratio Comparisons, Joseph P. Kristbaum, Frank W. Ciarallo
Faculty Publications
Every decision maker’s internal scale is different based on a myriad of possible factors unique to that decision maker. Conflicting criteria within and between alternatives in multicriteria decision making can create negative effects within the weighting schemes and amplify preference biases and scale disparities between decision makers in a group decision context. Additionally, the weighting of group decision-making frameworks can intensify the already skewed criteria values. When making judgments against requirements, it may be preferable to reduce scale trend distortions between decision makers as much as possible. Previous research supports that certain information presentation modes can significantly reduce preference bias …
Model For Quantifying The Quality Of Secure Service, Paul M. Simon, Scott R. Graham, Christopher Talbot, Micah J. Hayden
Model For Quantifying The Quality Of Secure Service, Paul M. Simon, Scott R. Graham, Christopher Talbot, Micah J. Hayden
Faculty Publications
Although not common today, communications networks could adjust security postures based on changing mission security requirements, environmental conditions, or adversarial capability, through the coordinated use of multiple channels. This will require the ability to measure the security of communications networks in a meaningful way. To address this need, in this paper, we introduce the Quality of Secure Service (QoSS) model, a methodology to evaluate how well a system meets its security requirements. This construct enables a repeatable and quantifiable measure of security in a single- or multi-channel network under static configurations. In this approach, the quantification of security is based …
Zynq System-On-Chip Dma Messaging For Processor Monitoring, Daniel F. Koranek, Douglas D. Hodson, Scott R. Graham
Zynq System-On-Chip Dma Messaging For Processor Monitoring, Daniel F. Koranek, Douglas D. Hodson, Scott R. Graham
Faculty Publications
Xilinx Zynq-7000 System-on-Chip architectures combine an ARM Cortex-A9 core with an FPGA fabric. One benefit of this hybrid architecture is that it allows fast prototyping of designs where the security of either the processing system (PS) is monitored by the programmable logic (PL) or vice versa. The choice of implementing a design in the PS or PL is driven by cost-to-benefit analysis across many factors. This effort examines the design process required to construct security monitoring designs that use both the PS and PL. For background, this effort reviews similar security monitoring projects. For the effort, a PL peripheral was …
Interpretability Of Api Call Topic Models: An Exploratory Study, Puntitra Glendowne, Dae Glendowne
Interpretability Of Api Call Topic Models: An Exploratory Study, Puntitra Glendowne, Dae Glendowne
Faculty Publications
Topic modeling is an unsupervised method for discovering semantically coherent combinations of words, called topics, in unstructured text. However, the human interpretability of topics discovered from non-natural language corpora, specifically Windows API call logs, is unknown. Our objective is to explore the coherence of topics and their ability to represent the themes of API calls from malware analysts’ perspective. Three Latent Dirichlet Allocation (LDA) models were fit to a collection of dynamic API call logs. Topics, or behavioral themes, were manually evaluated by malware analysts. The results were compared to existing automated quality measures. Participants were able to accurately determine …
Cyber Security Awareness Among College Students, Abbas Moallem
Cyber Security Awareness Among College Students, Abbas Moallem
Faculty Publications
This study reports the early results of a study aimed to investigate student awareness and attitudes toward cyber security and the resulting risks in the most advanced technology environment: the Silicon Valley in California, USA. The composition of students in Silicon Valley is very ethnically diverse. The objective was to see how much the students in such a tech-savvy environment are aware of cyber-attacks and how they protect themselves against them. The early statistical analysis suggested that college students, despite their belief that they are observed when using the Internet and that their data is not secure even on university …
Sequence Pattern Mining With Variables, James S. Okolica, Gilbert L. Peterson, Robert F. Mills, Michael R. Grimaila
Sequence Pattern Mining With Variables, James S. Okolica, Gilbert L. Peterson, Robert F. Mills, Michael R. Grimaila
Faculty Publications
Sequence pattern mining (SPM) seeks to find multiple items that commonly occur together in a specific order. One common assumption is that all of the relevant differences between items are captured through creating distinct items, e.g., if color matters then the same item in two different colors would have two items created, one for each color. In some domains, that is unrealistic. This paper makes two contributions. The first extends SPM algorithms to allow item differentiation through attribute variables for domains with large numbers of items, e.g, by having one item with a variable with a color attribute rather than …
Anomalydetection: Implementation Of Augmented Network Log Anomaly Detection Procedures, Robert J. Gutierrez, Bradley C. Boehmke, Kenneth W. Bauer, Cade M. Saie, Trevor J. Bihl
Anomalydetection: Implementation Of Augmented Network Log Anomaly Detection Procedures, Robert J. Gutierrez, Bradley C. Boehmke, Kenneth W. Bauer, Cade M. Saie, Trevor J. Bihl
Faculty Publications
As the number of cyber-attacks continues to grow on a daily basis, so does the delay in threat detection. For instance, in 2015, the Office of Personnel Management discovered that approximately 21.5 million individual records of Federal employees and contractors had been stolen. On average, the time between an attack and its discovery is more than 200 days. In the case of the OPM breach, the attack had been going on for almost a year. Currently, cyber analysts inspect numerous potential incidents on a daily basis, but have neither the time nor the resources available to perform such a task. …
Human-Centered Authentication Guidelines, Jeremiah Still, Ashley Cain, David Schuster
Human-Centered Authentication Guidelines, Jeremiah Still, Ashley Cain, David Schuster
Faculty Publications
PurposeDespite the widespread use of authentication schemes and the rapid emergence of novel authentication schemes, a general set of domain-specific guidelines has not yet been developed. This paper aims to present and explain a list of human-centered guidelines for developing usable authentication schemes.Design/methodology/approachThe guidelines stem from research findings within the fields of psychology, human–computer interaction and information/computer science.FindingsInstead of viewing users as the inevitable weak point in the authentication process, this study proposes that authentication interfaces be designed to take advantage of users’ natural abilities. This approach requires that one understands how interactions with authentication interfaces can be improved and …
A Method For Revealing And Addressing Security Vulnerabilities In Cyber-Physical Systems By Modeling Malicious Agent Interactions With Formal Verification, Dean C. Wardell, Robert F. Mills, Gilbert L. Peterson, Mark E. Oxley
A Method For Revealing And Addressing Security Vulnerabilities In Cyber-Physical Systems By Modeling Malicious Agent Interactions With Formal Verification, Dean C. Wardell, Robert F. Mills, Gilbert L. Peterson, Mark E. Oxley
Faculty Publications
Several cyber-attacks on the cyber-physical systems (CPS) that monitor and control critical infrastructure were publically announced over the last few years. Almost without exception, the proposed security solutions focus on preventing unauthorized access to the industrial control systems (ICS) at various levels – the defense in depth approach. While useful, it does not address the problem of making the systems more capable of responding to the malicious actions of an attacker once they have gained access to the system. The first step in making an ICS more resilient to an attacker is identifying the cyber security vulnerabilities the attacker can …
Understanding Firewalld In Multi-Zone Configurations, Nathan R. Vance, William F. Polik
Understanding Firewalld In Multi-Zone Configurations, Nathan R. Vance, William F. Polik
Faculty Publications
Stories of compromised servers and data theft fill today's news. It isn't difficult for someone who has read an informative blog post to access a system via a misconfigured service, take advantage of a recently exposed vulnerability, or gain control using a stolen password. Any of the many internet services found on a typical Linux server could harbor a vulnerability that grants unauthorized access to the system.
Since it's an impossible task to harden a system at the application level against every possible threat, firewalls provide security by limiting access to a system. Firewalls filter incoming packets based on their …
Quantum Key Distribution: Boon Or Bust, Logan O. Mailloux, Douglas D. Hodson, Michael R. Grimaila, Colin V. Mclaughlin, Gerald B. Baumgartner
Quantum Key Distribution: Boon Or Bust, Logan O. Mailloux, Douglas D. Hodson, Michael R. Grimaila, Colin V. Mclaughlin, Gerald B. Baumgartner
Faculty Publications
Quantum Key Distribution (QKD) is an emerging cybersecurity technology which provides the means for two geographically separated parties to grow “unconditionally secure” symmetric cryptographic keying material. Unlike traditional key distribution techniques, the security of QKD rests on the laws of quantum mechanics and not computational complexity. This unique aspect of QKD is due to the fact that any unauthorized eavesdropping on the key distribution channel necessarily introduces detectable errors (Gisin, Ribordy, Tittel, & Zbinden, 2002). This attribute makes QKD desirable for high-security environments such as banking, government, and military applications. However, QKD is a nascent technology where implementation non-idealities can …
Con-Resistant Trust For Improved Reliability In A Smart Grid Special Protection System, Crystal M. Shipman, Kenneth M. Hopkinson, Juan L. Lopez Jr.
Con-Resistant Trust For Improved Reliability In A Smart Grid Special Protection System, Crystal M. Shipman, Kenneth M. Hopkinson, Juan L. Lopez Jr.
Faculty Publications
This paper applies a con-resistant trust mechanism to improve the performance of a communications-based special protection system to enhance its effectiveness and resiliency. Smart grids incorporate modern information technologies to increase reliability and efficiency through better situational awareness. However, with the benefits of this new technology come the added risks associated with threats and vulnerabilities to the technology and to the critical infrastructure it supports. The research in this paper uses con-resistant trust to quickly identify malicious or malfunctioning (untrustworthy) protection system nodes to mitigate instabilities. The con-resistant trust mechanism allows protection system nodes to make trust assessments based on …
A Forward-Secure Certificate-Based Signature Scheme, Jiguo Li, Huiyun Teng, Xinyu Huang, Yichen Zhang, Jianying Zhou
A Forward-Secure Certificate-Based Signature Scheme, Jiguo Li, Huiyun Teng, Xinyu Huang, Yichen Zhang, Jianying Zhou
Faculty Publications
Cryptographic computations are often carried out on insecure devices for which the threat of key exposure raises a serious concern. In an effort to address the key exposure problem, the notion of forward security was first presented by Günther in 1990. In a forward-secure scheme, secret keys are updated at regular periods of time; exposure of the secret key corresponding to a given time period does not enable an adversary to ‘break’ the scheme for any prior time period. In this paper, we first introduce forward security into certificate-based cryptography and define the security model of forward-secure certificate-based signatures (CBSs). …
Malware Target Recognition Via Static Heuristics, Thomas E. Dube, Richard A. Raines, Gilbert L. Peterson, Kenneth W. Bauer, Michael R. Grimaila, Steven K. Rogers
Malware Target Recognition Via Static Heuristics, Thomas E. Dube, Richard A. Raines, Gilbert L. Peterson, Kenneth W. Bauer, Michael R. Grimaila, Steven K. Rogers
Faculty Publications
Organizations increasingly rely on the confidentiality, integrity and availability of their information and communications technologies to conduct effective business operations while maintaining their competitive edge. Exploitation of these networks via the introduction of undetected malware ultimately degrades their competitive edge, while taking advantage of limited network visibility and the high cost of analyzing massive numbers of programs. This article introduces the novel Malware Target Recognition (MaTR) system which combines the decision tree machine learning algorithm with static heuristic features for malware detection. By focusing on contextually important static heuristic features, this research demonstrates superior detection results. Experimental results on large …
A Multidiscipline Approach To Mitigating The Insider Threat, Jonathan W. Butts, Robert F. Mills, Gilbert L. Peterson
A Multidiscipline Approach To Mitigating The Insider Threat, Jonathan W. Butts, Robert F. Mills, Gilbert L. Peterson
Faculty Publications
Preventing and detecting the malicious insider is an inherently difficult problem that expands across many areas of expertise such as social, behavioral and technical disciplines. Unfortunately, current methodologies to combat the insider threat have had limited success primarily because techniques have focused on these areas in isolation. The technology community is searching for technical solutions such as anomaly detection systems, data mining and honeypots. The law enforcement and counterintelligence communities, however, have tended to focus on human behavioral characteristics to identify suspicious activities. These independent methods have limited effectiveness because of the unique dynamics associated with the insider threat. The …
A Comparison Of Generalizability For Anomaly Detection, Gilbert L. Peterson, Robert F. Mills, Brent T. Mcbride, Wesley T. Allred
A Comparison Of Generalizability For Anomaly Detection, Gilbert L. Peterson, Robert F. Mills, Brent T. Mcbride, Wesley T. Allred
Faculty Publications
In security-related areas there is concern over the novel “zeroday” attack that penetrates system defenses and wreaks havoc. The best methods for countering these threats are recognizing “non-self” as in an Artificial Immune System or recognizing “self” through clustering. For either case, the concern remains that something that looks similar to self could be missed. Given this situation one could logically assume that a tighter fit to self rather than generalizability is important for false positive reduction in this type of learning problem. This article shows that a tight fit, although important, does not supersede having some model generality. This …