Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

Theses and Dissertations

Discipline
Institution
Keyword
Publication Year

Articles 1 - 30 of 212

Full-Text Articles in Information Security

Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs, Brittni Hardie Apr 2026

Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs, Brittni Hardie

Theses and Dissertations

This study examines the intersection of cybersecurity education, open educational resources (OER), and rural higher education through a systematic review of current literature and an exploratory survey of rural community college faculty. The purpose of this research, consistent with the approved Institutional Review Board (IRB) protocol, was to understand how OER can be leveraged to design and deliver an affordable, high-quality System Security course within a rural higher-education environment. As cybersecurity workforce shortages continue to grow across the United States, rural institutions face persistent challenges in sustaining high-quality programs due to financial constraints, limited faculty capacity, and rapidly evolving curriculum …


Creating An Iot User Centric Security And Privacy Label, Luke Joseph Gleba Nov 2025

Creating An Iot User Centric Security And Privacy Label, Luke Joseph Gleba

Theses and Dissertations

Concerns for cybersecurity awareness and training in the public have been rising at astronomical rates over the past few years. People globally have entered a critical intersection with computers. Computers are being used in everyday life, and users do not have an easy way to understand their own cyber risk. Consumers deserve to know how secure their new Internet of Things (IoT) system is in a quick, efficient way before they purchase the device and while they own it. The following research looks to improve on ideas for the criteria and the development of a security label. Few prototypes currently …


Enhancing Cybersecurity Strategies Through Automated Cti Extraction, Risk Prioritization, And Privacy-Conscious Information Sharing, Spencer Rian Massengale Dec 2024

Enhancing Cybersecurity Strategies Through Automated Cti Extraction, Risk Prioritization, And Privacy-Conscious Information Sharing, Spencer Rian Massengale

Theses and Dissertations

Cybersecurity operations require the ability to collect and analyze large amounts of cyber threat intelligence (CTI) to assess risks and formulate defensive strategies against emerging threats. This task has become increasingly complex due to the rapid evolution of cyber threats and the growing volume of unstructured, natural-language CTI sources. The scale of data and analysis needed to utilize CTI effectively far exceeds humans' manual capacity, especially for organizations with limited resources. This research focuses on leveraging Large Language Models (LLMs) and machine learning techniques to enhance CTI extraction, risk assessment, and data sharing. We utilized LLMs to automate the extraction …


Increasing The Robustness Of Machine Learning By Adversarial Attacks, Gourab Mukhopadhyay Jul 2024

Increasing The Robustness Of Machine Learning By Adversarial Attacks, Gourab Mukhopadhyay

Theses and Dissertations

By perturbation or physical attacks any machine can be fooled into predicting something else other than the intended output. There are training data based on which the model is trained to predict unknown things. The objective was to create noises and shades of different levels on the images and do experiments for measuring accuracy and making the model classify the traffic signs. When it comes to adding shades to the pictures, pixels were modified for three different layers of the pictures. The experiment also shows that with the shadows getting deeper, the accuracies drop significantly. Here, some changes in pixels …


Federated Learning Based Autoencoder Ensemble System For Malware Detection On Internet Of Things Devices, Steven Edward Arroyo Jun 2024

Federated Learning Based Autoencoder Ensemble System For Malware Detection On Internet Of Things Devices, Steven Edward Arroyo

Theses and Dissertations

New technologies are being introduced at a rate faster than ever before and smaller in size. Due to the size of these devices, security is often difficult to implement. The existing solution is a firewall-segmented “IoT Network” that only limits the effect of these infected devices on other parts of the network. We propose a lightweight unsupervised hybrid-cloud ensemble anomaly detection system for malware detection. We perform transfer learning using a generalized model trained on multiple IoT device sources to learn network traffic on new devices with minimal computational resources. We further extend our proposed system to utilize federated learning …


Cloud Ecosystem In A Box Security Services, Chirone Gamble Jr Feb 2024

Cloud Ecosystem In A Box Security Services, Chirone Gamble Jr

Theses and Dissertations

The recent years have witnessed a remarkable surge in the use of large-scale data analytics, significantly advancing research in data-driven fields [1, 2]. While these innovative technologies offer the promise of accelerated research, they concurrently introduce new security and privacy challenges, complicating collaborative efforts among researchers. These challenges are ubiquitous across various research domains, particularly in the realms of data collection, analysis, and collaboration [3, 4]. Predominantly, existing data collection and analytics platforms prioritize performance over security. This prioritization compels users to rely heavily on their collaborators for adhering to all relevant security and privacy protocols. Often, researchers find themselves …


A Conceptual Decentralized Identity Solution For State Government, Martin Duclos Dec 2023

A Conceptual Decentralized Identity Solution For State Government, Martin Duclos

Theses and Dissertations

In recent years, state governments, exemplified by Mississippi, have significantly expanded their online service offerings to reduce costs and improve efficiency. However, this shift has led to challenges in managing digital identities effectively, with multiple fragmented solutions in use. This paper proposes a Self-Sovereign Identity (SSI) framework based on distributed ledger technology. SSI grants individuals control over their digital identities, enhancing privacy and security without relying on a centralized authority. The contributions of this research include increased efficiency, improved privacy and security, enhanced user satisfaction, and reduced costs in state government digital identity management. The paper provides background on digital …


Designing An Artificial Immune Inspired Intrusion Detection System, William Hosier Anderson Dec 2023

Designing An Artificial Immune Inspired Intrusion Detection System, William Hosier Anderson

Theses and Dissertations

The domain of Intrusion Detection Systems (IDS) has witnessed growing interest in recent years due to the escalating threats posed by cyberattacks. As Internet of Things (IoT) becomes increasingly integrated into our every day lives, we widen our attack surface and expose more of our personal lives to risk. In the same way the Human Immune System (HIS) safeguards our physical self, a similar solution is needed to safeguard our digital self. This thesis presents the Artificial Immune inspired Intrusion Detection System (AIS-IDS), an IDS modeled after the HIS. This thesis proposes an architecture for AIS-IDS, instantiates an AIS-IDS model …


Security Analysis Of Holystone Drones: Examining Attack Vectors And Data Extraction Techniques, Sandesh Ambadas More Dec 2023

Security Analysis Of Holystone Drones: Examining Attack Vectors And Data Extraction Techniques, Sandesh Ambadas More

Theses and Dissertations

In recent years, the surge in popularity of small-scale Unmanned Aerial Vehicles (UAVs), especially Holy Stone models, has raised significant security concerns. This study examines specific Holy Stone drone models, including the HS 175D, HS 430, HS 360S, and HS720, focusing on sub-250g drones exempt from FAA registration and those requiring registration and Remote ID. Despite advancements in drone technology, our research reveals persistent vulnerabilities that could be exploited by malicious actors for illicit purposes, posing a substantial security risk. Our comprehensive analysis involved simulated attacks in identifying and exploiting these vulnerabilities, leading to the successful acquisition of flight logs, …


Identity Management Pki System Using Blockchain, Mohamed Abdel Fattah Abdel Baki Awad Sep 2023

Identity Management Pki System Using Blockchain, Mohamed Abdel Fattah Abdel Baki Awad

Theses and Dissertations

Identity management is one of the most important topics in the security field. Public Key Infrastructure (PKI) is the most commonly used approach in legally identity management systems. PKI systems have many centralized services that might affect the availability and trustworthiness of the system. Issues related to certificate verification methods such as Certificate Revocation List (CRL) and Online Certificate Status Protocol (OCSP) can be avoided if blockchain is used. Blockchain is a decentralized trusted system where data can only be appended to a public ledger. Edits are not allowed in blockchain. Blockchain consists of several nodes all of them have …


A Multimodal Immune System Inspired Defense Architecture For Detecting And Deterring Digital Pathogens In Container Hosted Web Services, Islam Khalil Jun 2023

A Multimodal Immune System Inspired Defense Architecture For Detecting And Deterring Digital Pathogens In Container Hosted Web Services, Islam Khalil

Theses and Dissertations

With the increased use of web technologies, microservices, and Application Programming Interface (API) for integration between systems, and with the development of containerization of services on operating system level as a method of isolating system execution and for easing the deployment and scaling of systems, there is a growing need as well as opportunities for providing platforms that improve the security of such services. In our work, we propose an architecture for a containerization platform that utilizes various concepts derived from the human immune system. The goal of the proposed containerization platform is to introduce the concept of slowing down …


An Analysis Of Text-Based Machine Learning Models For Vulnerability Detection, Kollin Ryne Napier May 2023

An Analysis Of Text-Based Machine Learning Models For Vulnerability Detection, Kollin Ryne Napier

Theses and Dissertations

With an increase in complexity of software, developers rely more on reuse and dependencies in their source code via code snippets. As a result, it is becoming harder to identify and mitigate vulnerabilities. Although traditional analysis tools are still utilized, machine learning models are being adopted to expand efforts and combat such threats. Given the possibilities towards usage of such models, research in this area has introduced various approaches which vary in usability and prediction. In generalizing models to a more natural language approach, researchers have opted to train models on source code to identify existing and potential vulnerabilities. Exploratory …


Towards Privacy-Preserving Social Media Networks: Protecting The Facial Privacy Of Images Uploaded On Social Media, Ahsi Lo May 2023

Towards Privacy-Preserving Social Media Networks: Protecting The Facial Privacy Of Images Uploaded On Social Media, Ahsi Lo

Theses and Dissertations

Since the 2000s, social media has allowed individuals the ability to communicate online. As the popularity of social media increased, the sharing of information such as pictures increased as well. Recently, there have been privacy concerns about the information shared online such as cases where third parties were able to gain access to users’ information without being given explicit access through scraping or other means. When user images are scraped from social media, there is a risk that these individuals can be identified o✏ine. Bystanders, who may be captured in images also run this risk of identification. This research investigates …


The Effect Of Cybersecurity Training On Government Employee’S Knowledge Of Cybersecurity Issues And Practices, Juan Jaime Saldana Ii May 2023

The Effect Of Cybersecurity Training On Government Employee’S Knowledge Of Cybersecurity Issues And Practices, Juan Jaime Saldana Ii

Theses and Dissertations

There is an ever-pressing need for cybersecurity awareness and implementation of learning strategies in the workplace to mitigate the increased threat posed by cyber-attacks and exacerbated by an untrained workforce. The lack of cybersecurity knowledge amongst government employees has increased to critical levels due to the amount of sensitive information their agencies are responsible for. The digital compromise of a government entity often leads to a compromise of constituent data along with the disruption of public services (Axelrod, 2019; Yazdanpanahi, 2021). The need for awareness is further complicated by agencies looking to cater to a digital culture looking for a …


Jtag-Based Extraction Of Processor And Memory Data For Anomaly Detection In Cyber-Physical Systems, Jonathan D. Price Mar 2023

Jtag-Based Extraction Of Processor And Memory Data For Anomaly Detection In Cyber-Physical Systems, Jonathan D. Price

Theses and Dissertations

This document is a compilation of two scholarly articles that together compose a graduate thesis. The first article assesses the viability of commercially available JTAG debuggers to access runtime memory and register data, finding that commercial JTAG debuggers are not suitable for runtime data extraction for anomaly detection in cyber-physical systems due to slow memory and register access times. Because of this gap in technology, the second article designs, implements, and tests a novel, custom-built architecture named JTAG Data Extraction Tool (J-DET) for program counter-sampling. J-DET is the first device purpose-built to extract processor information in runtime for attack detection; …


Air Force Digital Badges, Jacob Chan Mar 2023

Air Force Digital Badges, Jacob Chan

Theses and Dissertations

The Air Force talent management and force development systems are antiquated. Airmen records are often stored on different Air Force information systems. Existing records sometimes lack granularity and context to recognize Airmen skills. Digital badges are a newer technology utilized by academia and industry to recognize member skills. However, military badging research is sparse and existing studies do not provide sufficient evidence on the value of digital badging to the Air Force. The studies: (1) lack background research on badging; (2) do not provide quantitative data on the effects of badging; and (3) issued badges through commercial entities which may …


Material Extrusion-Based Additive Manufacturing: G-Code And Firmware Attacks And Defense Frameworks, Haris Rais Jan 2023

Material Extrusion-Based Additive Manufacturing: G-Code And Firmware Attacks And Defense Frameworks, Haris Rais

Theses and Dissertations

Additive Manufacturing (AM) refers to a group of manufacturing processes that create physical objects by sequentially depositing thin layers. AM enables highly customized production with minimal material wastage, rapid and inexpensive prototyping, and the production of complex assemblies as single parts in smaller production facilities. These features make AM an essential component of Industry 4.0 or Smart Manufacturing. It is now used to print functional components for aircraft, rocket engines, automobiles, medical implants, and more. However, the increased popularity of AM also raises concerns about cybersecurity. Researchers have demonstrated strength degradation attacks on printed objects by injecting cavities in the …


Formal Verification Applications For The Treekem Continuous Group Key Agreement Protocol, Alexander J. Washburn Jul 2022

Formal Verification Applications For The Treekem Continuous Group Key Agreement Protocol, Alexander J. Washburn

Theses and Dissertations

The features of Secure Group Messaging, the security guarantees of Message Layer Security, and the TreeKEM protocol designed to satisfy these guarantees and features are explored. A motivation and methodology for verification via explicit model checking is presented. Subsequently, a translation of the TreeKEM protocol into a Promela reference model is described, examining the nuances explicit model checking brings. Finally the results of the formal verification methods are discussed.


Asynchronous Messaging In A P2p System: Defending Against A Storage Exhaustion Attack On Kademlia Dht, Maxim Biro Jul 2022

Asynchronous Messaging In A P2p System: Defending Against A Storage Exhaustion Attack On Kademlia Dht, Maxim Biro

Theses and Dissertations

An instant messaging service designed using a peer to peer distributed network architecture has many appealing properties it gets for free: high scalability, cheap operational cost and no reliance on a third party to provide the service. However, the nature of the distributed network architecture makes implementing some of the instant messaging features rather challenging, asynchronous messaging being one of them. The asynchronous messaging requires that peers store arbitrary data on behalf of other peers for prolonged periods of time, often measured in days, which, if not kept in check, can be easily abused by malicious actors by spamming the …


Malware Detection Using Electromagnetic Side-Channel Analysis, Matthew A. Bergstedt Mar 2022

Malware Detection Using Electromagnetic Side-Channel Analysis, Matthew A. Bergstedt

Theses and Dissertations

Many physical systems control or monitor important applications without the capacity to monitor for malware using on-device resources. Thus, it becomes valuable to explore malware detection methods for these systems utilizing external or off-device resources. This research investigates the viability of employing EM SCA to determine whether a performed operation is normal or malicious. A Raspberry Pi 3 was set up as a simulated motor controller with code paths for a normal or malicious operation. While the normal path only calculated the motor speed before updating the motor, the malicious path added a line of code to modify the calculated …


Securing Infiniband Networks With End-Point Encryption, Noah B. Diamond Mar 2022

Securing Infiniband Networks With End-Point Encryption, Noah B. Diamond

Theses and Dissertations

The NVIDIA-Mellanox Bluefield-2 is a 100 Gbps high-performance network interface which offers hardware offload and acceleration features that can operate directly on network traffic without routine involvement from the ARM CPU. This allows the ARM multi-core CPU to orchestrate the hardware to perform operations on both Ethernet and RDMA traffic at high rates rather than processing all the traffic directly. A testbed called TNAP was created for performance testing and a MiTM verification process called MiTMVMP is used to ensure proper network configuration. The hardware accelerators of the Bluefield-2 support a throughput of nearly 86 Gbps when using IPsec to …


Dds-Cerberus: Improving Security In Dds Middleware Using Kerberos Tickets, Andrew T. Park Mar 2022

Dds-Cerberus: Improving Security In Dds Middleware Using Kerberos Tickets, Andrew T. Park

Theses and Dissertations

The military deploys many IoT in battlefield operations to provide information on terrain and enemy combatants. It also deploys automated robots or UAVs where securing and trusting collected data is essential. Choosing the middleware that handles this message transfer is crucial for real-time operations. Networks with multiple entities, including IoT devices, UAVs, and small computers, require robust middleware facilitating message sending in real-time. Ideally, the middleware would provide QoS to handle lost packets and retransmissions in lossy environments, especially between low-power machines. DDS is a middleware that implements real-time and QoS capabilities by sending messages, not based on endpoints but …


Evaluating Secure Enclave Firmware Development For Contemporary Risc-V Workstations, Samuel D. Chadwick Mar 2022

Evaluating Secure Enclave Firmware Development For Contemporary Risc-V Workstations, Samuel D. Chadwick

Theses and Dissertations

The emergence of the open-source RISC-V ISA empowers developers and engineers, device manufactures, industry leaders, nation-states, adversaries and allies alike with the unique opportunity to re-evaluate existing Trusted Computing paradigms. Emerging open-source security mechanisms facilitate the proliferation of Confidential Computing principles. These technology standards aim to provide secure enclave computing as a fundamental computing attribute, inherent within the RISC-V ISA specification. Security enforcement within these enclaves are handled by performing computation in memory-isolated, hardware-based, software-defined TEEs. This research evaluates the firmware development procedures required to implement Keystone Enclave on new unsupported hardware. Expressly, this effort extends Keystone SM firmware components …


An Assessment Of Image-Cloaking Techniques Against Automated Face Recognition For Biometric Privacy, Brandon Scott Ledford Dec 2021

An Assessment Of Image-Cloaking Techniques Against Automated Face Recognition For Biometric Privacy, Brandon Scott Ledford

Theses and Dissertations

Over the past two decades, Americans have aggressively increased the amount of facial data uploaded to the internet primarily via social media. This data is largely unprotected due to the dire lack of existing regulations protecting users from large scale face recognition in the United States, where the value of data trade is in the tens of billions. In its current state, facial privacy in the United States depends on American corporations opting not to collect the public data, an option rarely chosen. Much research has been done in the area of suppressing recognition abilities, giving users the ability to …


A Comparative Study On Feature Extraction And Classification/Clustering Of Fake News And Conspiracy Theories From Twitter Data, Deb Shana Oct 2021

A Comparative Study On Feature Extraction And Classification/Clustering Of Fake News And Conspiracy Theories From Twitter Data, Deb Shana

Theses and Dissertations

Fake news and conspiracy theories have become largely abundant in the expanding world of social media. They predominantly affect the beliefs and thoughts of the public, resulting in chaos. They have always existed throughout the last few decades. They have been linked to prejudice, revolutions and genocide across history. They have also been known to have propelled people to reject mainstream medicines to an extent where some diseases are recurring in some parts of the world. They impose a serious impact since they are capable of spreading very fast Thus, it is very important to find suitable ways to detect …


Determining Physical Characteristics Through Information Leakage In 802.11ac Beamforming, Albert D. Taglieri Sep 2021

Determining Physical Characteristics Through Information Leakage In 802.11ac Beamforming, Albert D. Taglieri

Theses and Dissertations

The risk of information leakage in 802.11ac allows an eavesdropper to monitor wireless traffic and correlate physical locations between devices, as well as environment changes such as the motion of a person. Previous pattern-analysis mitigation methods, which used nonexistent devices to fool an eavesdropper, are not effective in an 802.11ac network, because devices on the network can be correlated to their physical location, which a nonexistent device does not have. Further, additional information about motion in the target environment can be observed and analyzed, providing a new potential for pattern analysis and sensing. 802.11ac makes it possible to plug in …


Enterprise Resource Allocation For Intruder Detection And Interception, Adam B. Haywood Sep 2021

Enterprise Resource Allocation For Intruder Detection And Interception, Adam B. Haywood

Theses and Dissertations

This research considers the problem of an intruder attempting to traverse a defender's territory in which the defender locates and employs disparate sets of resources to lower the probability of a successful intrusion. The research is conducted in the form of three related research components. The first component examines the problem in which the defender subdivides their territory into spatial stages and knows the plan of intrusion. Alternative resource-probability modeling techniques as well as variable bounding techniques are examined to improve the convergence of global solvers for this nonlinear, nonconvex optimization problem. The second component studies a similar problem but …


Measuring The Relationship Of Gender Misclassification And Automated Face Recognition Match Accuracy Relative To Skin Tone, Afi Edem-Edi Gbekevi Jul 2021

Measuring The Relationship Of Gender Misclassification And Automated Face Recognition Match Accuracy Relative To Skin Tone, Afi Edem-Edi Gbekevi

Theses and Dissertations

The gap of accuracy observed in some commercial face analytic systems based on race and gender raised questions about the equity and fairness of those systems. Since these systems are part of several applications today, some more critical than others, it urges designers to detect and mitigate any sources of bias. In this thesis, we begin by clarifying the confusion between face analytic, face recognition, and face processing systems. Then, we analyze gender classification accuracy using two datasets and three classifiers. The Pilot Parliaments Benchmark dataset is examined with an open-source algorithm to corroborate the gender shade. Secondly, the Morph …


Remote Monitoring Of Memory Data Structures For Malware Detection In A Talos Ii Architecture, Robert A. Willburn Mar 2021

Remote Monitoring Of Memory Data Structures For Malware Detection In A Talos Ii Architecture, Robert A. Willburn

Theses and Dissertations

New forms of malware, namely xC;leless malware and rootkits, pose a threat to traditional anti-malware. In particular, Rootkits have the capacity to obscure the present state of memory from the user space of a target machine. If thishappens, anti-malware running in the user space of an axB;ected machine cannot be trusted to operate properly. To combat this threat, this research proposes the remote monitoring of memory from a second, secure processor runningOpenBMC, serving as a baseboard management controller for a POWER9 processor, which is assumed vulnerable to exploitation. The baseboard management controller includes an application called pdbg, used for debugging …


Infiniband Network Monitoring: Challenges And Possibilities, Kyle D. Hintze Mar 2021

Infiniband Network Monitoring: Challenges And Possibilities, Kyle D. Hintze

Theses and Dissertations

Within the realm of High Performance Computing, the InfiniBand Architecture is among the leading interconnects used today. Capable of providing high bandwidth and low latency, InfiniBand is finding applications outside the High Performance Computing domain. One of these is critical infrastructure, encompassing almost all essential sectors as the work force becomes more connected. InfiniBand is not immune to security risks, as prior research has shown that common traffic analyzing tools cannot effectively monitor InfiniBand traffic transmitted between hosts, due to the kernel bypass nature of the IBA in conjunction with Remote Direct Memory Access operations. If Remote Direct Memory Access …