Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Social and Behavioral Sciences (58)
- Law (57)
- Engineering (55)
- Business (53)
- Computer Law (48)
-
- Management Information Systems (41)
- Sociology (38)
- Public Affairs, Public Policy and Public Administration (34)
- Technology and Innovation (31)
- Legal Studies (30)
- Computer Engineering (29)
- Forensic Science and Technology (27)
- Databases and Information Systems (25)
- Medicine and Health Sciences (25)
- OS and Networks (22)
- Software Engineering (22)
- Electrical and Computer Engineering (21)
- Other Computer Sciences (19)
- Communication (18)
- Public Administration (18)
- Social Media (18)
- Business and Corporate Communications (17)
- Family, Life Course, and Society (17)
- Health Policy (17)
- Human Resources Management (17)
- Marketing (17)
- Nonprofit Administration and Management (17)
- Institution
-
- Singapore Management University (89)
- Embry-Riddle Aeronautical University (54)
- Kennesaw State University (34)
- Edith Cowan University (19)
- Clark University (17)
-
- Air Force Institute of Technology (13)
- Old Dominion University (10)
- University of New Haven (7)
- Bridgewater State University (6)
- Maurer School of Law: Indiana University (6)
- GALILEO, University System of Georgia (5)
- Southern Methodist University (5)
- University of Arkansas, Fayetteville (5)
- City University of New York (CUNY) (4)
- LSU New Orleans (4)
- Brigham Young University (3)
- Dakota State University (3)
- Florida Institute of Technology (3)
- Syracuse University (3)
- United Arab Emirates University (3)
- University for Business and Technology in Kosovo (3)
- University of Kentucky (3)
- Virginia Commonwealth University (3)
- Boise State University (2)
- California Polytechnic State University, San Luis Obispo (2)
- Chicago-Kent College of Law (2)
- Eastern Michigan University (2)
- Eastern Washington University (2)
- Louisiana State University (2)
- Purdue University (2)
- Keyword
-
- Cybersecurity (27)
- Security (21)
- Cloud computing (15)
- Privacy (12)
- Access control (9)
-
- Blockchain (8)
- Cryptography (8)
- Machine learning (8)
- Digital forensics (6)
- MPA (6)
- MSPC (6)
- Android (5)
- Cloud storage (5)
- IoT (5)
- MSIT (5)
- Searchable encryption (5)
- Virtualization (5)
- [RSTDPub] (5)
- Anonymity (4)
- Bitcoin (4)
- Cyber security (4)
- Data privacy (4)
- Information security (4)
- Malware (4)
- Mobile security (4)
- Plausibly deniable encryption (4)
- Privacy-preserving (4)
- Traceability (4)
- Wireless networks (4)
- Authentication (3)
- Publication
-
- Research Collection School Of Computing and Information Systems (88)
- Journal of Digital Forensics, Security and Law (35)
- KSU Proceedings on Cybersecurity Education, Research and Practice (19)
- Theses and Dissertations (19)
- Annual ADFSL Conference on Digital Forensics, Security and Law (17)
-
- School of Professional Studies (17)
- Australian Information Security Management Conference (10)
- Journal of Cybersecurity Education, Research and Practice (10)
- Electrical & Computer Engineering and Computer Science Faculty Publications (7)
- International Journal of Cybersecurity Intelligence & Cybercrime (6)
- Articles by Maurer Faculty (5)
- Computer Science and Information Technology Grants Collections (5)
- Research outputs 2014 to 2021 (5)
- Graduate Theses and Dissertations (4)
- LSU New Orleans Theses and Dissertations (4)
- Australian Digital Forensics Conference (3)
- Electrical Engineering and Computer Science - Technical Reports (3)
- Information Security Theses (3)
- Master of Science in Computer Science Theses (3)
- SMU Data Science Review (3)
- VMASC Publications (3)
- All Faculty Scholarship (2)
- Boise State University Theses and Dissertations (2)
- Chemical Engineering and Materials Science Faculty Research Publications (2)
- Computer Science and Engineering Theses and Dissertations (2)
- EWU Masters Thesis Collection (2)
- Electronic Theses and Dissertations (2)
- Engineering Management & Systems Engineering Faculty Publications (2)
- Information Science Faculty Publications (2)
- International Journal of Business and Technology (2)
- Publication Type
- File Type
Articles 271 - 300 of 348
Full-Text Articles in Information Security
Secure Fine-Grained Access Control And Data Sharing For Dynamic Groups In The Cloud, Shengmin Xu, Guomin Yang, Yi Mu, Robert H. Deng
Secure Fine-Grained Access Control And Data Sharing For Dynamic Groups In The Cloud, Shengmin Xu, Guomin Yang, Yi Mu, Robert H. Deng
Research Collection School Of Computing and Information Systems
Cloud computing is an emerging computing paradigm that enables users to store their data in a cloud server to enjoy scalable and on-demand services. Nevertheless, it also brings many security issues, since cloud service providers (CSPs) are not in the same trusted domain as users. To protect data privacy against untrusted CSPs, existing solutions apply cryptographic methods (e.g., encryption mechanisms) and provide decryption keys only to authorized users. However, sharing cloud data among authorized users at a fine-grained level is still a challenging issue, especially when dealing with dynamic user groups. In this paper, we propose a secure and efficient …
An Overview Of The Usage Of Default Passwords, Brandon Knierem, Xiaolu Zhang, Philip Levine, Frank Breitinger, Ibrahim Baggili
An Overview Of The Usage Of Default Passwords, Brandon Knierem, Xiaolu Zhang, Philip Levine, Frank Breitinger, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
The recent Mirai botnet attack demonstrated the danger of using default passwords and showed it is still a major problem. In this study we investigated several common applications and their password policies. Specifically, we analyzed if these applications: (1) have default passwords or (2) allow the user to set a weak password (i.e., they do not properly enforce a password policy). Our study shows that default passwords are still a significant problem: 61% of applications inspected initially used a default or blank password. When changing the password, 58% allowed a blank password, 35% allowed a weak password of 1 character.
Tactful Inattention: Erving Goffman, Privacy In The Digital Age, And The Virtue Of Averting One's Eyes, Elizabeth De Armond
Tactful Inattention: Erving Goffman, Privacy In The Digital Age, And The Virtue Of Averting One's Eyes, Elizabeth De Armond
All Faculty Scholarship
No abstract provided.
How Much Should We Spend To Protect Privacy?: Data Breaches And The Need For Information We Do Not Have, Richard Warner, Robert Sloan
How Much Should We Spend To Protect Privacy?: Data Breaches And The Need For Information We Do Not Have, Richard Warner, Robert Sloan
All Faculty Scholarship
A cost/benefit approach to privacy confronts two tradeoff issues. One is making appropriate tradeoffs between privacy and many goals served by the collection, distribution, and use of information. The other is making tradeoffs between investments in preventing unauthorized access to information and the variety of other goals that also make money, time, and effort demands. Much has been written about the first tradeoff. We focus on the second. The issue is critical. Data breaches occur at the rate of over three a day, and the aggregate social cost is extremely high. The puzzle is that security experts have long explained …
Introduction - Syllabus, C. Ariel Pinto
Introduction - Syllabus, C. Ariel Pinto
Module 1: Fundamentals of Cybersecurity Risk Management
Cybersecurity risk management is a necessary tool for decision making for all management levels from tactical to strategic and creating a common understanding between people from diverse domains or having different priorities. This course adopts a multidisciplinary perspective. It creates a common understanding of risk for a diverse set of students which are coming from different disciplines such as technical, social, economics, law, and politics to remove communication barriers between strategic, operational, and tactical level decision makers.
The course covers related government and industry regulations and standards along with best practices frequently used to assess, analyze and manage cyber risks, …
A Malware Analysis And Artifact Capture Tool, Dallas Wright, Josh Stroschein
A Malware Analysis And Artifact Capture Tool, Dallas Wright, Josh Stroschein
Research & Publications
Malware authors attempt to obfuscate and hide their code in its static and dynamic states. This paper provides a novel approach to aid analysis by intercepting and capturing malware artifacts and providing dynamic control of process flow. Capturing malware artifacts allows an analyst to more quickly and comprehensively understand malware behavior and obfuscation techniques and doing so interactively allows multiple code paths to be explored. The faster that malware can be analyzed the quicker the systems and data compromised by it can be determined and its infection stopped. This research proposes an instantiation of an interactive malware analysis and artifact …
Preparing Millennials As Digital Citizens And Socially And Environmentally Responsible Business Professionals In A Socially Irresponsible Climate, Barbara Burgess-Wilkerson, Clovia Hamilton, Chlotia Garrison, Keith Robbins
Preparing Millennials As Digital Citizens And Socially And Environmentally Responsible Business Professionals In A Socially Irresponsible Climate, Barbara Burgess-Wilkerson, Clovia Hamilton, Chlotia Garrison, Keith Robbins
Winthrop Faculty and Staff Publications
No abstract provided.
Examining The Influence Of Technology Acceptance, Self-Efficacy, And Locus Of Control On Information Security Behavior Of Social Media Users, Abdullah Almuqrin
Examining The Influence Of Technology Acceptance, Self-Efficacy, And Locus Of Control On Information Security Behavior Of Social Media Users, Abdullah Almuqrin
Master's Theses and Doctoral Dissertations
Due to recent advances in online communication technology, social networks have become a vital avenue for human interaction. At the same time, they have been exploited as a target for viruses, attacks, and security threats. The first line of defense against such attacks and threats— as well as their primary cause—are social media users themselves. This study investigated the relationship between certain personality factors among social media users—i.e., technology acceptance of security protection technologies, self-efficacy of information security, and locus of control—and their information security behavior. Quantitative methods were used to examine this relationship. The population consisted of all students …
Graduate Admissions Recruitment Project, Kevin Anderson, Chiemela Dike, Yixin Du, Arvinder Kaur, Amanda Popp, Huizhong Yang
Graduate Admissions Recruitment Project, Kevin Anderson, Chiemela Dike, Yixin Du, Arvinder Kaur, Amanda Popp, Huizhong Yang
School of Professional Studies
In this project, several comparison schools were interviewed and disclosed to have used search lists to find candidates. The organizations that have valuable search lists which may be of good use for the School of Professional Studies include Educational Testing Service (ETS) and the Graduate Management Admission Council (GMAC). By choosing criteria such as demographics, location, academic performance, educational history provided by search lists, we believe there are many quality candidates for SPS programs. However, as we further investigated the functionality and cost-efficiency or return of investment of GRE search list, we spotted many uncertainties and few solid and successful …
Worcester Center For Crafts: A Transition To Online Sales, Monica Gow, Carly Branconnier, Srilatha Prodduturi, Ekaterina Shusharina, Alberta Yamoah
Worcester Center For Crafts: A Transition To Online Sales, Monica Gow, Carly Branconnier, Srilatha Prodduturi, Ekaterina Shusharina, Alberta Yamoah
School of Professional Studies
The Clark University School of Professional Studies created a capstone team consisting of Monica Gow, Carly Branconnier, Iana Matkovskaia, Srilatha Prodduturi, Ekaterina Shusharina, and Alberta Yamoah to assist Worcester Center for Crafts (WCC) with the launch of their new online store. Worcester Center for Crafts wanted to showcase their beautiful American handmade crafts on an online platform, Shopify, in order to increase their sales and expand their market reach. The capstone team created a charter that outlined the scope of the project and what the team would deliver to WCC by the end of the project. The team agreed to …
Audubon Data Project Final Report, Askhat Beygenov, Valinur Kutlambetov, Shrikant Patel, Phoebe Roberts, Ulfat Sayyed, Shriram Sivaraman
Audubon Data Project Final Report, Askhat Beygenov, Valinur Kutlambetov, Shrikant Patel, Phoebe Roberts, Ulfat Sayyed, Shriram Sivaraman
School of Professional Studies
The Audubon Data Project was initiated as a Clark University Capstone project. The project’s client, Mass Audubon’s Shaping the Future of Your Community program, had identified a need to improve their data management methods and make better use of their data. The Capstone team, composed of Clark University graduate students, met with the client regularly to review the current state of the data and potential improvements to be made. The process began with a data review. During the review we worked with the client to explicitly define the purposes and requirements of the data, the current process for updating and …
Assessment Of Information Security Culture In Higher Education, Henry Glaspie
Assessment Of Information Security Culture In Higher Education, Henry Glaspie
Electronic Theses and Dissertations
Information security programs are instituted by organizations to provide guidance to their users who handle their data and systems. The main goal of these programs is to protect the organization's information assets through the creation and cultivation of a positive information security culture within the organization. As the collection and use of data expands in all economic sectors, the threat of data breach due to human error increases. Employee's behavior towards information security is influenced by the organizations information security programs and the overall information security culture. This study examines the human factors of an information security program and their …
A Formally Verified Heap Allocator, Arash Sahebolamri, Scott D. Constable, Steve J. Chapin
A Formally Verified Heap Allocator, Arash Sahebolamri, Scott D. Constable, Steve J. Chapin
Electrical Engineering and Computer Science - Technical Reports
We present the formal verification of a heap allocator written in C. We use the Isabelle/HOL proof assistant to formally verify the correctness of the heap allocator at the source code level. The C source code of the heap allocator is imported into Isabelle/HOL using CParser and AutoCorres. In addition to providing the guarantee that the heap allocator is free of bugs and therefore is suitable for use in security critical projects, our work facilitates verification of other projects written in C that utilize Isabelle and AutoCorres.
The Legacy Of Multics And Secure Operating Systems Today, John Schriner
The Legacy Of Multics And Secure Operating Systems Today, John Schriner
Publications and Research
This paper looks to the legacy of Multics from 1963 and its influence on computer security. It discusses kernel-based and virtualization-based containment in projects like SELinux and Qubes, respectively. The paper notes the importance of collaborative and research-driven projects like Qubes and Tor Project.
Construction Of A Custom Network Security Appliance, Jacob Rickerd
Construction Of A Custom Network Security Appliance, Jacob Rickerd
Senior Honors Theses and Projects
Over the last three semesters, I worked toward my final goal to develop a custom network security appliance. I first began by completing a comparison analysis of network intrusion detection systems which are devices that read traffic from the network and determine if network packets should go through or be dropped. Second, I conducted a feasibility study of a custom framework to profile attackers in a network; this yielded positive results. Finally, I worked on creating a custom network security appliance; it uses the profiles I created in my framework to more efficiently block malicious attackers in comparison to other …
Economics-Based Risk Management Of Distributed Denial Of Service Attacks: A Distance Learning Case Study, Omer Keskin, Unal Tatar, Omer Poyraz, Ariel Pinto, Adrian Gheorghe
Economics-Based Risk Management Of Distributed Denial Of Service Attacks: A Distance Learning Case Study, Omer Keskin, Unal Tatar, Omer Poyraz, Ariel Pinto, Adrian Gheorghe
Engineering Management & Systems Engineering Faculty Publications
Managing risk of cyber systems is still on the top of the agendas of Chief Information Security Officers (CISO). Investment in cybersecurity is continuously rising. Efficiency and effectiveness of cybersecurity investments are under scrutiny by boards of the companies. The primary method of decision making on cybersecurity adopts a risk-informed approach. Qualitative methods bring a notion of risk. However, particularly for strategic level decisions, more quantitative methods that can calculate the risk and impact in monetary values are required. In this study, a model is built to calculate the economic value of business interruption during a Distributed Denial-of-Service (DDoS) attack …
Isolated Mobile Malware Observation, Augustine Paul
Isolated Mobile Malware Observation, Augustine Paul
College of Graduate Studies: Theses & Dissertations
The idea behind Bring Your Own Device (BYOD) it that personal mobile devices can be used in the workplace to enhance convenience and flexibility. This development encourages organizations to allow access of personal mobile devices to business information and systems for businesses operation. However, BYOD opens a firm to various security risks such as data contamination and the exposure of user interest to criminal activities. Mobile devices were not designed to handle intense data security and advanced security features are frequently turned off. Using personal mobile devices can also expose a system to various forms of security threats like malware. …
Is Working With What We Have Enough?, Brian Cusack, Bryce Antony
Is Working With What We Have Enough?, Brian Cusack, Bryce Antony
Australian Digital Forensics Conference
Augmented reality (AR) digital environments have introduced a new complexity to digital investigation where augmented overlays of real objects may be momentary, changed, distorted and evade the usual methods for evidence collection. It is possible an investigator applying standard investigation methods factually reports a real situation and its digital context but has none of the relevant evidence. In this situation the potential for a fair hearing is low and the chance of retrial high. Such situations are unacceptably dangerous and require redress. In this paper the AR condition is considered in terms of its complexity and management during an investigation. …
Digital Forensics Investigative Framework For Control Rooms In Critical Infrastructure, Brian Cusack, Amr Mahmoud
Digital Forensics Investigative Framework For Control Rooms In Critical Infrastructure, Brian Cusack, Amr Mahmoud
Australian Digital Forensics Conference
In this paper a cyber-forensic framework with a detailed guideline for protecting control systems is developed to improve the forensic capability for big data in critical infrastructures. The main objective of creating a cyber-forensic plan is to cover the essentials of monitoring, troubleshooting, data reconstruction, recovery, and the safety of classified information. The problem to be addressed in control rooms is the diversity and quantity of data, and for investigators, bringing together the different skill groups for managing data and device diversity. This research embraces establishing of a new digital forensic model for critical infrastructures that supports digital forensic investigators …
Consortium Blockchain-Based Sift: Outsourcing Encrypted Feature Extraction In The D2d Network, Xiaoqin Feng, Jianfeng Ma, Tao Feng, Yinbin Miao, Ximeng Liu
Consortium Blockchain-Based Sift: Outsourcing Encrypted Feature Extraction In The D2d Network, Xiaoqin Feng, Jianfeng Ma, Tao Feng, Yinbin Miao, Ximeng Liu
Research Collection School Of Computing and Information Systems
Privacy-preserving outsourcing algorithms for feature extraction not only reduce users' storage and computation overhead but also preserve the image privacy. However, the existing schemes still suffer from deficiencies induced by security, applications, efficiency and storage. To solve the problems, we implement a consortium chain-based outsourcing feature extraction scheme over encrypted images by using the smart contract, distributed autonomous corporation (DAC), sharding technique, and device to device (D2D) communication, which is secure, widely applied, highly efficient, and has less storage overhead. First, the effectiveness, security, and performance of our scheme are analyzed. Then, the efficiency and storage overhead of our scheme …
Can Ego Defense Mechanism Help Explain Is Security Dysfunctional Behavior, Abhijit Chaudhury, Debasish Mallick
Can Ego Defense Mechanism Help Explain Is Security Dysfunctional Behavior, Abhijit Chaudhury, Debasish Mallick
Information Systems and Analytics Department Faculty Conference Proceedings
IS security behavior studies are becoming popular. To date, much of the research has been based on theories such as the Theory of Planned Behavior, Technology Adoption Model, Rational Choice theory and Theory of Reasoned Action. They view users as rational individuals making conscious utilitarian decisions when there is increasing evidence that security breaches are the result of human behavior such as carelessness, malicious intent, bad habits, and hostility. We propose the ego defense mechanism model, taken from the psychoanalytical world. This model makes no assumption of rationality and has been developed to help understand the roots of dysfunctional behavior …
Developing A Cyberterrorism Policy: Incorporating Individual Values, Osama Bassam J. Rabie
Developing A Cyberterrorism Policy: Incorporating Individual Values, Osama Bassam J. Rabie
Theses and Dissertations
Preventing cyberterrorism is becoming a necessity for individuals, organizations, and governments. However, current policies focus on technical and managerial aspects without asking for experts and non-experts values and preferences for preventing cyberterrorism. This study employs value focused thinking and public value forum to bare strategic measures and alternatives for complex policy decisions for preventing cyberterrorism. The strategic measures and alternatives are per socio-technical process.
Security Vulnerabilities In Android Applications, Crischell Montealegre, Charles Rubia Njuguna, Muhammad Imran Malik, Peter Hannay, Ian Noel Mcateer
Security Vulnerabilities In Android Applications, Crischell Montealegre, Charles Rubia Njuguna, Muhammad Imran Malik, Peter Hannay, Ian Noel Mcateer
Australian Information Security Management Conference
Privacy-related vulnerabilities and risks are often embedded into applications during their development, with this action being either performed out of malice or out of negligence. Moreover, the majority of the mobile applications initiate connections to websites, other apps, or services outside of its scope causing significant compromise to the oblivious user. Therefore, mobile data encryption or related data-protection controls should be taken into account during the application development phase. This paper evaluates some standard apps and their associated threats using publicly available tools and demonstrates how an ignorant user or an organisation can fall prey to such apps.
Xmpp Architecture And Security Challenges In An Iot Ecosystem, Muhammad Imran Malik, Ian Noel Mcateer, Peter Hannay, Syed Naeem Firdous, Zubair Baig
Xmpp Architecture And Security Challenges In An Iot Ecosystem, Muhammad Imran Malik, Ian Noel Mcateer, Peter Hannay, Syed Naeem Firdous, Zubair Baig
Australian Information Security Management Conference
The elusive quest for technological advancements with the aim to make human life easier has led to the development of the Internet of Things (IoT). IoT technology holds the potential to revolutionise our daily life, but not before overcoming barriers of security and data protection. IoTs’ steered a new era of free information that transformed life in ways that one could not imagine a decade ago. Hence, humans have started considering IoTs as a pervasive technology. This digital transformation does not stop here as the new wave of IoT is not about people, rather it is about intelligent connected devices. …
Securing The Internet Of Healthcare, Michael Mattioli, Scott J. Shackelford, Steve Myers, Austin Brady, Yvette Wang, Stephanie Wong
Securing The Internet Of Healthcare, Michael Mattioli, Scott J. Shackelford, Steve Myers, Austin Brady, Yvette Wang, Stephanie Wong
Articles by Maurer Faculty
Cybersecurity, including the security of information technology (IT), is a critical requirement in ensuring society trusts, and therefore can benefit from, modern technology. Problematically, though, rarely a day goes by without a news story related to how critical data has been exposed, exfiltrated, or otherwise inappropriately used or accessed as a result of supply chain vulnerabilities. From the Russian government's campaign to influence the 2016 U.S. presidential election to the September 2017 Equifax breach of more than 140-million Americans' credit reports, mitigating cyber risk has become a topic of conversation in boardrooms and the White House, on Wall Street and …
The New Writs Of Assistance, Ian Samuel
The New Writs Of Assistance, Ian Samuel
Articles by Maurer Faculty
The providers of network services (and the makers of network devices) know an enormous amount about our lives. Because they do, these network intermediaries are being asked with increasing frequency to assist the government in solving crimes or gathering intelligence. Given how much they know about us, if the government can secure the assistance of these intermediaries, it will enjoy a huge increase in its theoretical capacity for surveillance—the ability to learn, in principle, almost anything about anyone. That has the potential to create serious social harm, even assuming that the government continues to adhere to ordinary democratic norms and …
An Unstoppable Force And An Immoveable Object? Eu Data Protection Law And National Security, Fred H. Cate, Christopher Kuner, Orla Lynskey, Christopher Millard, Nora Ni Loideain, Dan Jerker B. Svantesson
An Unstoppable Force And An Immoveable Object? Eu Data Protection Law And National Security, Fred H. Cate, Christopher Kuner, Orla Lynskey, Christopher Millard, Nora Ni Loideain, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Expanding The Artificial Intelligence-Data Protection Debate, Fred H. Cate, Christopher Kuner, Orla Lynskey, Christopher Millard, Nora Ni Loideain, Dan Jerker B. Svantesson
Expanding The Artificial Intelligence-Data Protection Debate, Fred H. Cate, Christopher Kuner, Orla Lynskey, Christopher Millard, Nora Ni Loideain, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
A Value Sensitive Design Approach To Adolescent Mobile Online Safety, Arup Kumar Ghosh
A Value Sensitive Design Approach To Adolescent Mobile Online Safety, Arup Kumar Ghosh
Electronic Theses and Dissertations
With the rise of adolescent smartphone use, concerns about teen online safety are also on the rise. A number of parental control apps are available for mobile devices, but adoption of these apps has been markedly low. To better understand these apps, their users, and design opportunities in the space of mobile online safety for adolescents, we have conducted four studies informed by the principles of Value Sensitive Design (VSD). In Study 1 (Chapter 2), we conducted a web-based survey of 215 parents and their teens (ages 13-17) using two separate logistic regression models (parent and teen) to examine the …
Determining Vulnerability Using Attach Graphs: An Expansion Of The Current Fair Model, Beth M. Anderson
Determining Vulnerability Using Attach Graphs: An Expansion Of The Current Fair Model, Beth M. Anderson
EWU Masters Thesis Collection
Factor Analysis of Information Risk (FAIR) provides a framework for measuring and understanding factors that contribute to information risk. One such factor is FAIR Vulnerability; the probability that an event involving a threat will result in a loss. An asset is vulnerable if a threat actor’s Threat Capability is higher than the Resistance Strength of the asset. In FAIR scenarios, Resistance Strength is currently estimated for entire assets, oversimplifying assets containing individual systems and the surrounding environment. This research explores enhancing estimations of FAIR Vulnerability by modeling interactions between threat actors and assets through attack graphs. By breaking down the …