Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

2017

Discipline
Institution
Keyword
Publication
Publication Type

Articles 151 - 180 of 271

Full-Text Articles in Information Security

Development Of Peer Instruction Material For A Cybersecurity Curriculum, William Johnson May 2017

Development Of Peer Instruction Material For A Cybersecurity Curriculum, William Johnson

LSU New Orleans Theses and Dissertations

Cybersecurity classes focus on building practical skills alongside the development of the open mindset that is essential to tackle the dynamic cybersecurity landscape. Unfortunately, traditional lecture-style teaching is insufficient for this task. Peer instruction is a non-traditional, active learning approach that has proven to be effective in computer science courses. The challenge in adopting peer instruction is the development of conceptual questions. This thesis presents a methodology for developing peer instruction questions for cybersecurity courses, consisting of four stages: concept identification, concept trigger, question presentation, and development. The thesis analyzes 279 questions developed over two years for three cybersecurity courses: …


Downstream Competence Challenges And Legal/Ethical Risks In Digital Forensics, Michael M. Losavio, Antonio Losavio May 2017

Downstream Competence Challenges And Legal/Ethical Risks In Digital Forensics, Michael M. Losavio, Antonio Losavio

Annual ADFSL Conference on Digital Forensics, Security and Law

Forensic practice is an inherently human-mediated system, from processing and collection of evidence to presentation and judgment. This requires attention to human factors and risks which can lead to incorrect judgments and unjust punishments.

For digital forensics, such challenges are magnified by the relative newness of the discipline and the use of electronic evidence in forensic proceedings. Traditional legal protections, rules of procedure and ethics rules mitigate these challenges. Application of those traditions better ensures forensic findings are reliable. This has significant consequences where findings may impact a person's liberty or property, a person's life or even the political direction …


Detecting Deception In Asynchronous Text, Fletcher Glancy May 2017

Detecting Deception In Asynchronous Text, Fletcher Glancy

Annual ADFSL Conference on Digital Forensics, Security and Law

Glancy and Yadav (2010) developed a computational fraud detection model (CFDM) that successfully detected financial reporting fraud in the text of the management’s discussion and analysis (MDA) portion of annual filings with the United States Securities and Exchange Commission (SEC). This work extends the use of the CFDM to additional genres, demonstrates the generalizability of the CFDM and the use of text mining for quantitatively detecting deception in asynchronous text. It also demonstrates that writers committing fraud use words differently from truth tellers.


Understanding Deleted File Decay On Removable Media Using Differential Analysis, James H. Jones Jr, Anurag Srivastava, Josh Mosier, Connor Anderson, Seth Buenafe May 2017

Understanding Deleted File Decay On Removable Media Using Differential Analysis, James H. Jones Jr, Anurag Srivastava, Josh Mosier, Connor Anderson, Seth Buenafe

Annual ADFSL Conference on Digital Forensics, Security and Law

Digital content created by picture recording devices is often stored internally on the source device, on either embedded or removable media. Such storage media is typically limited in capacity and meant primarily for interim storage of the most recent image files, and these devices are frequently configured to delete older files as necessary to make room for new files. When investigations involve such devices and media, it is sometimes these older deleted files that would be of interest. It is an established fact that deleted file content may persist in part or in its entirety after deletion, and identifying the …


Development Of A Professional Code Of Ethics In Digital Forensics, Kathryn C. Seigfried-Spellar, Marcus Rogers, Danielle M. Crimmins 2184089 May 2017

Development Of A Professional Code Of Ethics In Digital Forensics, Kathryn C. Seigfried-Spellar, Marcus Rogers, Danielle M. Crimmins 2184089

Annual ADFSL Conference on Digital Forensics, Security and Law

Academics, government officials, and practitioners suggest the field of digital forensics is in need of a professional code of ethics. In response to this need, the authors developed and proposed a professional code of ethics in digital forensics. The current paper will discuss the process of developing the professional code of ethics, which included four sets of revisions based on feedback and suggestions provided by members of the digital forensic community. The final version of the Professional Code of Ethics in Digital Forensics includes eight statements, and we hope this is a step toward unifying the field of digital forensics …


Fast Filtering Of Known Png Files Using Early File Features, Sean Mckeown, Gordon Russell, Petra Leimich May 2017

Fast Filtering Of Known Png Files Using Early File Features, Sean Mckeown, Gordon Russell, Petra Leimich

Annual ADFSL Conference on Digital Forensics, Security and Law

A common task in digital forensics investigations is to identify known contraband images. This is typically achieved by calculating a cryptographic digest, using hashing algorithms such as SHA256, for each image on a given media, comparing individual digests with a database of known contraband. However, the large capacities of modern storage media, and increased time pressure on forensics examiners, necessitates that more efficient processing mechanisms be developed. This work describes a technique for creating signatures for images of the PNG format which only requires a tiny fraction of the file to effectively distinguish between a large number of images. Highly …


Detect Kernel-Mode Rootkits Via Real Time Logging & Controlling Memory Access, Satoshi Tanda, Irvin Homem, Igor Korkin May 2017

Detect Kernel-Mode Rootkits Via Real Time Logging & Controlling Memory Access, Satoshi Tanda, Irvin Homem, Igor Korkin

Annual ADFSL Conference on Digital Forensics, Security and Law

Modern malware and spyware platforms attack existing antivirus solutions and even Microsoft PatchGuard. To protect users and business systems new technologies developed by Intel and AMD CPUs may be applied. To deal with the new malware we propose monitoring and controlling access to the memory in real time using Intel VT-x with EPT. We have checked this concept by developing MemoryMonRWX, which is a bare-metal hypervisor. MemoryMonRWX is able to track and trap all types of memory access: read, write, and execute. MemoryMonRWX also has the following competitive advantages: fine-grained analysis, support of multi-core CPUs and 64-bit Windows 10. MemoryMonRWX …


Harnessing Predictive Models For Assisting Network Forensic Investigations Of Dns Tunnels, Irvin Homem, Panagiotis Papapetrou May 2017

Harnessing Predictive Models For Assisting Network Forensic Investigations Of Dns Tunnels, Irvin Homem, Panagiotis Papapetrou

Annual ADFSL Conference on Digital Forensics, Security and Law

In recent times, DNS tunneling techniques have been used for malicious purposes, however network security mechanisms struggle to detect them. Network forensic analysis has been proven effective, but is slow and effort intensive as Network Forensics Analysis Tools struggle to deal with undocumented or new network tunneling techniques. In this paper, we present a machine learning approach, based on feature subsets of network traffic evidence, to aid forensic analysis through automating the inference of protocols carried within DNS tunneling techniques. We explore four network protocols, namely, HTTP, HTTPS, FTP, and POP3. Three features are extracted from the DNS tunneled traffic: …


An Accidental Discovery Of Iot Botnets And A Method For Investigating Them With A Custom Lua Dissector, Max Gannon, Gary Warner, Arsh Arora May 2017

An Accidental Discovery Of Iot Botnets And A Method For Investigating Them With A Custom Lua Dissector, Max Gannon, Gary Warner, Arsh Arora

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper presents a case study that occurred while observing peer-to-peer network communications on a botnet monitoring station and shares how tools were developed to discover what ultimately was identified as Mirai and many related IoT DDOS Botnets. The paper explains how researchers developed a customized protocol dissector in Wireshark using the Lua coding language, and how this enabled them to quickly identify new DDOS variants over a five month period of study.


Kelihos Botnet: A Never-Ending Saga, Arsh Arora, Max Gannon, Gary Warner May 2017

Kelihos Botnet: A Never-Ending Saga, Arsh Arora, Max Gannon, Gary Warner

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper investigates the recent behavior of the Kelihos botnet, a spam-sending botnet that accounts for many millions of emails sent each day. The paper demonstrates how a team of students are able to perform a longitudinal malware study, making significant observations and contributions to the understanding of a major botnet using tools and techniques taught in the classroom. From this perspective the paper has two objectives: encouragement and observation. First, by providing insight into the methodology and tools used by student researchers to document and understand a botnet, the paper strives to embolden other academic programs to follow a …


Lightweight Data Aggregation Scheme Against Internal Attackers In Smart Grid Using Elliptic Curve Cryptography, Debiao He, Sherali Zeadally, Huaqun Wang, Qin Liu May 2017

Lightweight Data Aggregation Scheme Against Internal Attackers In Smart Grid Using Elliptic Curve Cryptography, Debiao He, Sherali Zeadally, Huaqun Wang, Qin Liu

Information Science Faculty Publications

Recent advances of Internet and microelectronics technologies have led to the concept of smart grid which has been a widespread concern for industry, governments, and academia. The openness of communications in the smart grid environment makes the system vulnerable to different types of attacks. The implementation of secure communication and the protection of consumers’ privacy have become challenging issues. The data aggregation scheme is an important technique for preserving consumers’ privacy because it can stop the leakage of a specific consumer’s data. To satisfy the security requirements of practical applications, a lot of data aggregation schemes were presented over the …


Ispy: Threats To Individual And Institutional Privacy In The Digital World, Lori Andrews May 2017

Ispy: Threats To Individual And Institutional Privacy In The Digital World, Lori Andrews

All Faculty Scholarship

What type of information is collected, who is viewing it, and what law librarians can do to protect their patrons and institutions.


Mining Software Repositories For Automatic Software Bug Management From Bug Triaging To Patch Backporting, Yuan Tian May 2017

Mining Software Repositories For Automatic Software Bug Management From Bug Triaging To Patch Backporting, Yuan Tian

Dissertations and Theses Collection

Software systems are often released with bugs due to system complexity and inadequate testing. Bug resolving process plays an important role in development and evolution of software systems because developers could collect a considerable number of bugs from users and testers daily. For instance, during September 2015, the Eclipse project received approximately 2,500 bug reports, averaging 80 new reports each day. To help developers effectively address and manage bugs, bug tracking systems such as Bugzilla and JIRA are adopted to manage the life cycle of a bug through bug report. Since most of the information related to bugs are stored …


Umass Memorial Healthcare Information System Job Ladder, Matthew Simoncini, Vamsi Kavuru, Antariksh Nanda, Tahaseen Mahaboob Basha, Vikram Patil May 2017

Umass Memorial Healthcare Information System Job Ladder, Matthew Simoncini, Vamsi Kavuru, Antariksh Nanda, Tahaseen Mahaboob Basha, Vikram Patil

School of Professional Studies

The capstone project report emphasizes the importance of a job ladder and the need of an hour to implement it at UMASS Memorial health care. The scope of this project is to create a well-established job ladder at UMASS with pre-defined standards on job levels related to Information Technology department that would facilitate in hiring, developing and promoting employees at various stages.


A Learning Framework For The Ywca Central Massachusetts, Dayna Ankermann, Manjushree Burdekar, Priyanka Joshi, Ying Song, Yumeng Chen, Xing Xie May 2017

A Learning Framework For The Ywca Central Massachusetts, Dayna Ankermann, Manjushree Burdekar, Priyanka Joshi, Ying Song, Yumeng Chen, Xing Xie

School of Professional Studies

After meeting with the Director of Wellness and Health Equity at the YWCA Central Massachusetts (which will be referred to as the YWCA from here on out), we learned that as a non-profit gym and health center, it is heavily underfunded. The main focus of the project was to determine how to upkeep the facility while bringing in new customers with limited resources and budget. Due to the needs of the YWCA, our group focused on six aspects: revenue stream, donor retention, increasing membership, customer experience, social media marketing, and membership fee structure. After completing extensive research, we were able …


Human Services Management (Hsm) Certificate Program Expansion To Western Massachusetts Feasibility Study, Paul Campbell, Patrick Deschenes, Maria Pacheco, Bradley Paul, Elizabeth Vittum, Jing Zhang May 2017

Human Services Management (Hsm) Certificate Program Expansion To Western Massachusetts Feasibility Study, Paul Campbell, Patrick Deschenes, Maria Pacheco, Bradley Paul, Elizabeth Vittum, Jing Zhang

School of Professional Studies

One of the most popular cost-savings programs that the Providers’ Council currently offers its members is a Certificate in Nonprofit Human Service Management (HSM) provided in partnership with Clark University and Suffolk University. As human services providers are struggling to hire and retain qualified staff, the need to provide professional development opportunities to help grow and expand a skilled health and human services workforce is a critical issue facing nonprofit organizations and communities in Massachusetts. This feasibility study examines the viability of Providers’ Council and Clark University expanding its HSM Certificate Program to organizations and staff located in western Massachusetts. …


Somali National University, Sharmarke Abdulla, Nikala Pieroni, Jenna Caskie, Sergii Odnodvorets, Tanyue Gong, Lahari Dasari May 2017

Somali National University, Sharmarke Abdulla, Nikala Pieroni, Jenna Caskie, Sergii Odnodvorets, Tanyue Gong, Lahari Dasari

School of Professional Studies

The executive summary presents an overview of the principal conclusions and recommendations for Somali National University Faculty of Education (FoEd) regarding the following concerns: Difficulty with recruiting high quality prospects to the FoEd; Ineffective and counterintuitive use of social media as a tool to improve brand equity, as well as as a tool to attract and communicate with prospective and current students; Unbalanced gender ratio of current student body; Absence of student services and student supports; Low student retention rate; Limited resources for academic advising; This document is the result of a Clark University School of Professional Studies Capstone Project.


The Economics Of The Right To Be Forgotten, Byung-Cheol Kim, Jin Yeub Kim May 2017

The Economics Of The Right To Be Forgotten, Byung-Cheol Kim, Jin Yeub Kim

Department of Economics: Faculty Publications

Scholars and practitioners debate whether to expand the scope of the right to be forgotten—the right to have certain links removed from search results—to encompass global search results. The debate centers on the assumption that the expansion will increase the incidence of link removal, which reinforces privacy while hampering free speech. We develop a game-theoretic model to show that the expansion of the right to be forgotten can reduce the incidence of link removal. We also show that the expansion does not necessarily enhance the welfare of individuals who request removal and that it can either improve or reduce societal …


The Impact Of Monetary Value Gains And Losses On Cybersecurity Behavior, Samuel Noah Smith, Fiona Fui-Hoon Nah, Maggie Cheng, Santosh Kuma Ravindran May 2017

The Impact Of Monetary Value Gains And Losses On Cybersecurity Behavior, Samuel Noah Smith, Fiona Fui-Hoon Nah, Maggie Cheng, Santosh Kuma Ravindran

Research Collection School Of Computing and Information Systems

This research examines if users take more risky cybersecurity actions when presented with the possibility of losing monetary value rather than gaining monetary value. Prospect theory provides the theoretical foundation for the research. An experimental design is proposed to test the hypothesis for the research.


Cryptography And Data Security In Cloud Computing, Zheng Yan, Robert H. Deng, Vijay Varadharajan May 2017

Cryptography And Data Security In Cloud Computing, Zheng Yan, Robert H. Deng, Vijay Varadharajan

Research Collection School Of Computing and Information Systems

Cloud computing offers a new way of services by re-arranging various resources and providing them to users based on their demands. It also plays an important role in the next generation mobile networks and services (5G) and Cyber-Physical and Social Computing (CPSC). Storing data in the cloud greatly reduces storage burden of users and brings them access convenience, thus it has become one of the most important cloud services. However, cloud data security, privacy and trust become a crucial issue that impacts the success of cloud computing and may impede the development of 5G and CPSC. First, storing data at …


Encrypted Data Processing With Homomorphic Re-Encryption, Wenxiu Ding, Zheng Yan, Robert H. Deng May 2017

Encrypted Data Processing With Homomorphic Re-Encryption, Wenxiu Ding, Zheng Yan, Robert H. Deng

Research Collection School Of Computing and Information Systems

Cloud computing offers various services to users by re-arranging storage and computing resources. In order to preserve data privacy, cloud users may choose to upload encrypted data rather than raw data to the cloud. However, processing and analyzing encrypted data are challenging problems, which have received increasing attention in recent years. Homomorphic Encryption (HE) was proposed to support computation on encrypted data and ensure data confidentiality simultaneously. However, a limitation of HE is it is a single user system, which means it only allows the party that owns a homomorphic decryption key to decrypt processed ciphertexts. Original HE cannot support …


Online/Offline Provable Data Possession, Yujue Wang, Qianhong Wu, Bo Qin, Shaohua Tang, Willy Susilo May 2017

Online/Offline Provable Data Possession, Yujue Wang, Qianhong Wu, Bo Qin, Shaohua Tang, Willy Susilo

Research Collection School Of Computing and Information Systems

Provable data possession (PDP) allows a user to outsource data with a guarantee that the integrity can be efficiently verified. Existing publicly verifiable PDP schemes require the user to perform expensive computations, such as modular exponentiations for processing data before outsourcing to the storage server, which is not desirable for weak users with limited computation resources. In this paper, we introduce and formalize an online/offline PDP (OOPDP) model, which divides the data processing procedure into offline and online phases. In OOPDP, most of the expensive computations for processing data are performed in the offline phase, and the online phase requires …


Dpweka: Achieving Differential Privacy In Weka, Srinidhi Katla May 2017

Dpweka: Achieving Differential Privacy In Weka, Srinidhi Katla

Graduate Theses and Dissertations

Organizations belonging to the government, commercial, and non-profit industries collect and store large amounts of sensitive data, which include medical, financial, and personal information. They use data mining methods to formulate business strategies that yield high long-term and short-term financial benefits. While analyzing such data, the private information of the individuals present in the data must be protected for moral and legal reasons. Current practices such as redacting sensitive attributes, releasing only the aggregate values, and query auditing do not provide sufficient protection against an adversary armed with auxiliary information. In the presence of additional background information, the privacy protection …


Binary Analysis Framework, Josh Stroschein May 2017

Binary Analysis Framework, Josh Stroschein

Masters Theses & Doctoral Dissertations

The binary analysis of software has become an integral activity for security researchers and attackers alike. As the value of being able to exploit a vulnerability has increased, the need to discover, fix and prevent such vulnerabilities has never been greater. This paper proposes the Binary Analysis Framework, which is intended to be used by security researchers to query and analyze information about system and third party libraries. Researchers can use the tool to evaluate and discover unknown vulnerabilities in these libraries. Furthermore, the framework can be utilized to analyze mitigation techniques implemented by operating system and thirdparty vendors. The …


High Fidelity Adaptive Cyber Emulation, Samir Mammadov May 2017

High Fidelity Adaptive Cyber Emulation, Samir Mammadov

Theses and Dissertations

While looking for a high-level adaptive traffic generation tool, we came to realize that no such tool exists that can be used for rapid development while being platform agnostic. Having reviewed a wide array of tools to either implement user models or simulate traffic, we were unable to find a tool with the right capabilities while maintaining complexity, portability and extensibility. To overcome these issues, we introduce a new adaptive user-modelling framework for the specific use case of cyber activity emulation. Our framework supports the creation of high-level user models that can react to changes in their environments and vary …


Provably Secure Attribute Based Signcryption With Delegated Computation And Efficient Key Updating, Hanshu Hong, Yunhao Xia, Zhixin Sun, Ximeng Liu May 2017

Provably Secure Attribute Based Signcryption With Delegated Computation And Efficient Key Updating, Hanshu Hong, Yunhao Xia, Zhixin Sun, Ximeng Liu

Research Collection School Of Computing and Information Systems

Equipped with the advantages of flexible access control and fine-grained authentication, attribute based signcryption is diffusely designed for security preservation in many scenarios. However, realizing efficient key evolution and reducing the calculation costs are two challenges which should be given full consideration in attribute based cryptosystem. In this paper, we present a key-policy attribute based signcryption scheme (KP-ABSC) with delegated computation and efficient key updating. In our scheme, an access structure is embedded into user’s private key, while ciphertexts corresponds a target attribute set. Only the two are matched can a user decrypt and verify the ciphertexts. When the access …


Monitoring The Dark Web And Securing Onion Services, John Schriner Apr 2017

Monitoring The Dark Web And Securing Onion Services, John Schriner

Publications and Research

This paper focuses on how researchers monitor the Dark Web. After defining what onion services and Tor are, we discuss tools for monitoring and securing onion services. As Tor Project itself is research-driven, we find that the development and use of these tools help us to project where use of the Dark Web is headed.


Cybersecurity In The 21st Century, Singapore Management University Apr 2017

Cybersecurity In The 21st Century, Singapore Management University

Perspectives@SMU

Increased awareness is necessary in fending off data theft and cyber attacks, and it is not just the CIO’s job to do so


Smu’S Professor Robert Deng Conferred Axa Chair Professorship Of Cybersecurity, Singapore Management University Apr 2017

Smu’S Professor Robert Deng Conferred Axa Chair Professorship Of Cybersecurity, Singapore Management University

SMU Press Releases and News

Singapore Management University’s Professor Robert Deng, a leading global authority and award winning researcher in cybersecurity, has today been conferred the prestigious AXA Chair Professorship of Cybersecurity.

€800,000 funding from AXA Research Fund over a period of eight years will support Professor Deng’s research in the development of new ways of protecting data security and privacy.


Security And Privacy In Cloud Computing, Ramakrishnan Krishnan Apr 2017

Security And Privacy In Cloud Computing, Ramakrishnan Krishnan

Masters Theses

Cloud computing (CC) gained a widespread acceptance as a paradigm of computing. The main aim of CC is to reduce the need for customers' investment in new hardware or software by offering flexible cloud services, with a user reaping the benefits of the pay per use approach. CC demands addressing many security and privacy issues: both problems (vulnerabilities, threats, and attacks) and solutions (controls). The thesis discusses all these classes of problems and solutions, categorizing them as either security-related issues, privacy-related issues, or intertwined security and privacy issues. The main contributions of the thesis are twofold: first, using the …