Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (45)
- Social and Behavioral Sciences (42)
- Business (29)
- Computer Engineering (26)
- Artificial Intelligence and Robotics (24)
-
- Databases and Information Systems (22)
- Management Information Systems (21)
- Technology and Innovation (21)
- Law (20)
- Legal Studies (20)
- Sociology (20)
- Forensic Science and Technology (17)
- Other Computer Sciences (15)
- Communication (14)
- Software Engineering (14)
- Electrical and Computer Engineering (13)
- Computer Law (12)
- Public Affairs, Public Policy and Public Administration (12)
- Social Media (12)
- Criminology (11)
- OS and Networks (11)
- Systems Architecture (11)
- Medicine and Health Sciences (10)
- Criminology and Criminal Justice (9)
- Risk Analysis (8)
- Theory and Algorithms (8)
- Arts and Humanities (7)
- Institution
-
- Singapore Management University (64)
- San Jose State University (20)
- Kennesaw State University (19)
- Embry-Riddle Aeronautical University (18)
- Old Dominion University (17)
-
- Air Force Institute of Technology (10)
- Bridgewater State University (9)
- University of New Haven (9)
- Dakota State University (8)
- Clark University (6)
- Edith Cowan University (5)
- West Virginia University (5)
- Boise State University (4)
- Florida Institute of Technology (4)
- Technological University Dublin (4)
- University for Business and Technology in Kosovo (4)
- City University of New York (CUNY) (3)
- California Polytechnic State University, San Luis Obispo (2)
- Franklin University (2)
- Maurer School of Law: Indiana University (2)
- Montclair State University (2)
- Munster Technological University (2)
- Southern Methodist University (2)
- United Arab Emirates University (2)
- University of Arkansas, Fayetteville (2)
- University of Central Florida (2)
- University of Nebraska at Omaha (2)
- Bemidji State University (1)
- Brigham Young University (1)
- Columbia Law School (1)
- Keyword
-
- Cybersecurity (19)
- Blockchain (13)
- Privacy (12)
- Security (12)
- Center_CCR (7)
-
- Computer security (7)
- Cybercrime (7)
- Machine learning (7)
- Authentication (6)
- Internet of Things (6)
- Encryption (5)
- Access control (4)
- Attribute-based encryption (4)
- Cryptocurrency (4)
- Cryptography (4)
- Data privacy (4)
- Digital forensics (4)
- GDPR (4)
- Information security (4)
- MPA (4)
- Machine Learning (4)
- Privacy-preserving (4)
- Cloud computing (3)
- Cyberbullying (3)
- Data protection (3)
- Deep learning (3)
- Efficiency (3)
- Forensics (3)
- Internet of Things (IoT) (3)
- Malware detection (3)
- Publication
-
- Research Collection School Of Computing and Information Systems (58)
- Master's Projects (18)
- Theses and Dissertations (16)
- Journal of Digital Forensics, Security and Law (13)
- KSU Proceedings on Cybersecurity Education, Research and Practice (10)
-
- Computer Ethics - Philosophical Enquiry (CEPE) Proceedings (9)
- Electrical & Computer Engineering and Computer Science Faculty Publications (8)
- International Journal of Cybersecurity Intelligence & Cybercrime (8)
- Journal of Cybersecurity Education, Research and Practice (8)
- Masters Theses & Doctoral Dissertations (8)
- School of Professional Studies (6)
- Graduate Theses, Dissertations, and Problem Reports (ETD) (5)
- Boise State University Theses and Dissertations (4)
- Electronic Theses and Dissertations (4)
- International Journal of Business and Technology (4)
- Research outputs 2014 to 2021 (4)
- Publications (3)
- All Faculty and Staff Scholarship (2)
- Articles by Maurer Faculty (2)
- Conference Papers (2)
- Dissertations and Theses Collection (Open Access) (2)
- Graduate Theses and Dissertations (2)
- Information Security Theses (2)
- Master's Theses (2)
- Perspectives@SMU (2)
- SMU Data Science Review (2)
- Theses, Dissertations and Culminating Projects (2)
- VMASC Publications (2)
- Annual ADFSL Conference on Digital Forensics, Security and Law (1)
- Articles (1)
- Publication Type
Articles 31 - 60 of 258
Full-Text Articles in Information Security
Effectiveness Of Tools In Identifying Rogue Access Points On A Wireless Network, Ryan Vansickle, Tamirat Abegaz, Bryson Payne
Effectiveness Of Tools In Identifying Rogue Access Points On A Wireless Network, Ryan Vansickle, Tamirat Abegaz, Bryson Payne
KSU Proceedings on Cybersecurity Education, Research and Practice
Wireless access points have greatly improved users' ability to connect to the Internet. However, they often lack the security mechanisms needed to protect users. Malicious actors could create a rogue access point (RAP), using a device such as the WiFi Pineapple Nano, that could trick users into connecting to an illegitimate access point (AP). To make them look legitimate, adversaries tend to setup RAPs to include a captive portal. This is very effective, since most public networks use captive portals as a means to provide genuine access. The objective of this study is to examine the effectiveness of RAP identification …
Automatic Security Bug Detection With Findsecuritybugs Plugin, Hossain Shahriar, Kmarul Riad, Arabin Talukder, Hao Zhang, Zhuolin Li
Automatic Security Bug Detection With Findsecuritybugs Plugin, Hossain Shahriar, Kmarul Riad, Arabin Talukder, Hao Zhang, Zhuolin Li
KSU Proceedings on Cybersecurity Education, Research and Practice
The security threats to mobile application are growing explosively. Mobile app flaws and security defects could open doors for hackers to easily attack mobile apps. Secure software development must be addressed earlier in the development lifecycle rather than fixing the security holes after attacking. Early eliminating against possible security vulnerability will help us increase the security of software and mitigate the consequence of damages of data loss caused by potential malicious attacking. In this paper, we present a static security analysis approach with open source FindSecurityBugs plugin for Android StThe security threats to mobile application are growing explosively. Mobile app …
Automated Reverse Engineering Of Automotive Can Bus Controls, Charles Barron Kirby, Bryson Payne
Automated Reverse Engineering Of Automotive Can Bus Controls, Charles Barron Kirby, Bryson Payne
KSU Proceedings on Cybersecurity Education, Research and Practice
This research provides a means of automating the process to reverse engineer an automobile’s CAN Bus to quickly recover CAN IDs and message values to control the various systems in a modern automobile. This approach involved the development of a Python script that uses several open-source tools to interact with the CAN Bus, and it takes advantage of several vulnerabilities associated with the CAN protocol. These vulnerabilities allow the script to conduct replay attacks against the CAN Bus and affect various systems in an automobile without the operator’s knowledge or interaction.
These replay attacks can be accomplished by capturing recorded …
A World Of Cyber Attacks (A Survey), Mubarak Banisakher, Marwan Omar
A World Of Cyber Attacks (A Survey), Mubarak Banisakher, Marwan Omar
KSU Proceedings on Cybersecurity Education, Research and Practice
The massive global network that connects billions of humans and millions of devices and allow them to communicate with each other is known as the internet. Over the last couple of decades, the internet has grown expeditiously and became easier to use and became a great educational tool. Now it can used as a weapon that can steal someone’s identity, expose someone’s financial information, or can destroy your networking devices. Even in the last decade, there have been more cyber attacks and threats destroying major companies by breaching the databases that have millions of personal information that can be sold …
An Exploratory Analysis Of Mobile Security Tools, Hossain Shahriar, Md Arabin Talukder, Md Saiful Islam
An Exploratory Analysis Of Mobile Security Tools, Hossain Shahriar, Md Arabin Talukder, Md Saiful Islam
KSU Proceedings on Cybersecurity Education, Research and Practice
The growing market of the mobile application is overtaking the web application. Mobile application development environment is open source, which attracts new inexperienced developers to gain hands on experience with applicationn development. However, the security of data and vulnerable coding practice is an issue. Among all mobile Operating systems such as, iOS (by Apple), Android (by Google) and Blackberry (RIM), Android dominates the market. The majority of malicious mobile attacks take advantage of vulnerabilities in mobile applications, such as sensitive data leakage via the inadvertent or side channel, unsecured sensitive data storage, data transition and many others. Most of these …
Iot: Challenges In Information Security Training, Lech J. Janczewski, Gerard Ward
Iot: Challenges In Information Security Training, Lech J. Janczewski, Gerard Ward
KSU Proceedings on Cybersecurity Education, Research and Practice
Both consumers and businesses are rapidly adopting IoT premised on convenience and control. Industry and academic literature talk about billions of embedded IoT devices being implemented with use-cases ranging from smart speakers in the home, to autonomous trucks, and trains operating in remote industrial sites. Historically information systems supporting these disparate use-cases have been categorised as Information Technology (IT) or Operational Technology (OT), but IoT represents a fusion between these traditionally distinct information security models.
This paper presents a review of IEEE and Elsevier peer reviewed papers that identifies the direction in IoT education and training around information security. It …
Proposal For A Joint Cybersecurity And Information Technology Management Program, Christopher Simpson, Debra Bowen, William Reid, James Juarez
Proposal For A Joint Cybersecurity And Information Technology Management Program, Christopher Simpson, Debra Bowen, William Reid, James Juarez
KSU Proceedings on Cybersecurity Education, Research and Practice
Cybersecurity and Information Technology Management programs have many similarities and many similar knowledge, skills, and abilities are taught across both programs. The skill mappings for the NICE Framework and the knowledge units required to become a National Security Agency and Department of Homeland Security Center of Academic Excellence in Cyber Defense Education contain many information technology management functions. This paper explores one university’s perception on how a joint Cybersecurity and Information Technology Management program could be developed to upskill students to be work force ready.
Adversarial Thinking: Teaching Students To Think Like A Hacker, Frank Katz
Adversarial Thinking: Teaching Students To Think Like A Hacker, Frank Katz
KSU Proceedings on Cybersecurity Education, Research and Practice
Today’s college and university cybersecurity programs often contain multiple laboratory activities on various different hardware and software-based cybersecurity tools. These include preventive tools such as firewalls, virtual private networks, and intrusion detection systems. Some of these are tools used in attacking a network, such as packet sniffers and learning how to craft cross-site scripting attacks or man-in-the-middle attacks. All of these are important in learning cybersecurity. However, there is another important component of cybersecurity education – teaching students how to protect a system or network from attackers by learning their motivations, and how they think, developing the students’ “abilities to …
Internet Core Functions: Security Today And Future State, Jeffrey Jones
Internet Core Functions: Security Today And Future State, Jeffrey Jones
KSU Proceedings on Cybersecurity Education, Research and Practice
Never in the history of the world has so much trust been given to something that so few understand. Jeff reviews three core functions of the Internet along with recent and upcoming changes that will impact security and the world.
Preparing For Tomorrow By Looking At Yesterday, Peter Dooley
Preparing For Tomorrow By Looking At Yesterday, Peter Dooley
KSU Proceedings on Cybersecurity Education, Research and Practice
Why do we learn? Why do we study history? Why do we research the work of others? The answer is that there is value today in what was already learned and experienced, successes and failures. Mr. Dooley, a 25-year security professional and 20-year hospitality executive, will share his experiences and how our history in security will help us in thinking about our future.
Concolic Testing Heap-Manipulating Programs, Long H. Pham, Quang Loc Le, Quoc-Sang Phan, Jun Sun
Concolic Testing Heap-Manipulating Programs, Long H. Pham, Quang Loc Le, Quoc-Sang Phan, Jun Sun
Research Collection School Of Computing and Information Systems
Concolic testing is a test generation technique which works effectively by integrating random testing generation and symbolic execution. Existing concolic testing engines focus on numeric programs. Heap-manipulating programs make extensive use of complex heap objects like trees and lists. Testing such programs is challenging due to multiple reasons. Firstly, test inputs for such program are required to satisfy non-trivial constraints which must be specified precisely. Secondly, precisely encoding and solving path conditions in such programs are challenging and often expensive. In this work, we propose the first concolic testing engine called CSF for heap-manipulating programs based on separation logic. CSF …
Privacidad Digital En Ecuador: El Papel De La Vigilancia, La Jurisprudencia Y Los Derechos Humanos, Giselle Valdez
Privacidad Digital En Ecuador: El Papel De La Vigilancia, La Jurisprudencia Y Los Derechos Humanos, Giselle Valdez
Independent Study Project (ISP) Collection
Este documento es un estudio de caso sobre la privacidad digital en Ecuador, cómo se protege y cómo se debe mejorar las protecciones. Comienzo presentando la falta de privacidad de la persona en Ecuador, a través de la reciente violación de datos y las tecnologías de vigilancia en todo el país desde China. Luego, para analizar la jurisprudencia y la falta de protección de la privacidad en la ley, hago la transición a un análisis legal de la privacidad de datos en Ecuador a través de la Constitución de 2008. Cuando establezco que falta privacidad digital en Ecuador, demuestro una …
A Study Of Existing Cross-Site Scripting Detection And Prevention Techniques Using Xampp And Virtualbox, Jalen Mack, Yen-Hung (Frank) Hu, Mary Ann Hoppa
A Study Of Existing Cross-Site Scripting Detection And Prevention Techniques Using Xampp And Virtualbox, Jalen Mack, Yen-Hung (Frank) Hu, Mary Ann Hoppa
Virginia Journal of Science
Most operating websites experience a cyber-attack at some point. Cross-site Scripting (XSS) attacks are cited as the top website risk. More than 60 percent of web applications are vulnerable to them, and they ultimately are responsible for over 30 percent of all web application attacks. XSS attacks are complicated, and they often are used in conjunction with social engineering techniques to cause even more damage. Although prevention techniques exist, hackers still find points of vulnerability to launch their attacks. This project explored what XSS attacks are, examples of popular attacks, and ways to detect and prevent them. Using knowledge gained …
Enhancing Symbolic Execution Of Heap-Based Programs With Separation Logic For Test Input Generation, Long H. Pham, Quang Loc Le, Quoc-Sang Phan, Jun Sun, Shengchao Qin
Enhancing Symbolic Execution Of Heap-Based Programs With Separation Logic For Test Input Generation, Long H. Pham, Quang Loc Le, Quoc-Sang Phan, Jun Sun, Shengchao Qin
Research Collection School Of Computing and Information Systems
Symbolic execution is a well established method for test input generation. Despite of having achieved tremendous success over numerical domains, existing symbolic execution techniques for heap-based programs are limited due to the lack of a succinct and precise description for symbolic values over unbounded heaps. In this work, we present a new symbolic execution method for heap-based programs based on separation logic. The essence of our proposal is context-sensitive lazy initialization, a novel approach for efficient test input generation. Our approach differs from existing approaches in two ways. Firstly, our approach is based on separation logic, which allows us to …
Esdra: An Efficient And Secure Distributed Remote Attestation Scheme For Iot Swarms, Boyu Kuang, Anmin Fu, Shui Yu, Guomin Yang, Mang Su, Yuqing Zhang
Esdra: An Efficient And Secure Distributed Remote Attestation Scheme For Iot Swarms, Boyu Kuang, Anmin Fu, Shui Yu, Guomin Yang, Mang Su, Yuqing Zhang
Research Collection School Of Computing and Information Systems
An Internet of Things (IoT) system generally contains thousands of heterogeneous devices which often operate in swarms-large, dynamic, and self-organizing networks. Remote attestation is an important cornerstone for the security of these IoT swarms, as it ensures the software integrity of swarm devices and protects them from attacks. However, current attestation schemes suffer from single point of failure verifier. In this paper, we propose an Efficient and Secure Distributed Remote Attestation (ESDRA) scheme for IoT swarms. We present the first many-to-one attestation scheme for device swarms, which reduces the possibility of single point of failure verifier. Moreover, we utilize distributed …
Tighter Security Proofs For Post-Quantum Key Encapsulation Mechanism In The Multi-Challenge Setting, Zhengyu Zhang, Puwen Wei, Haiyang Xue
Tighter Security Proofs For Post-Quantum Key Encapsulation Mechanism In The Multi-Challenge Setting, Zhengyu Zhang, Puwen Wei, Haiyang Xue
Research Collection School Of Computing and Information Systems
Due to the threat posed by quantum computers, a series of works investigate the security of cryptographic schemes in the quantum-accessible random oracle model (QROM) where the adversary can query the random oracle in superposition. In this paper, we present tighter security proofs of a generic transformations for key encapsulation mechanism (KEM) in the QROM in the multi-challenge setting, where the reduction loss is independent of the number of challenge ciphertexts. In particular, we introduce the notion of multi-challenge OW-CPA (mOW-CPA) security, which captures the one-wayness of the underlying public key encryption (PKE) under chosen plaintext attack in the multi-challenge …
Phishing: Message Appraisal And The Exploration Of Fear And Self-Confidence, Deanna House, M. K. Raja
Phishing: Message Appraisal And The Exploration Of Fear And Self-Confidence, Deanna House, M. K. Raja
Information Systems and Quantitative Analysis Faculty Publications
Phishing attacks have threatened the security of both home users and organizations in recent years. Phishing uses social engineering to fraudulently obtain information that is confidential or sensitive. Individuals are targeted to take action by clicking on a link and providing information. This research explores fear arousal and self-confidence in subjects confronted by phishing attacks. The study collected data from multiple sources (including an attempted phishing attack). The survey results indicated that when individuals had a high level of fear arousal related to providing login credentials they had a decreased intention to respond to a phishing attack. Self-confidence did not …
The Future Of Cybercrime Prevention Strategies: Human Factors And A Holistic Approach To Cyber Intelligence, Sinchul Back, Jennifer Laprade
The Future Of Cybercrime Prevention Strategies: Human Factors And A Holistic Approach To Cyber Intelligence, Sinchul Back, Jennifer Laprade
International Journal of Cybersecurity Intelligence & Cybercrime
New technology is rapidly emerging to fight increasing cybercrime threats, however, there is one important component of a cybercrime that technology cannot always impact and that is human behavior. Unfortunately, humans can be vulnerable and easily deceived making technological advances alone inadequate in the cybercrime fight. Instead, we must take a more holistic approach by using technology and better understanding the human factors that make cybercrime possible. In this issue of the International Journal of Cybersecurity Intelligence and Cybercrime, three studies contribute to our knowledge of human factors and emerging cybercrime technology so that more effective comprehensive cybercrime prevention strategies …
A Test Of Structural Model For Fear Of Crime In Social Networking Sites, Seong-Sik Lee, Kyung-Shick Choi, Sinyong Choi, Elizabeth Englander
A Test Of Structural Model For Fear Of Crime In Social Networking Sites, Seong-Sik Lee, Kyung-Shick Choi, Sinyong Choi, Elizabeth Englander
International Journal of Cybersecurity Intelligence & Cybercrime
This study constructed a structural model which consists of social demographic factors, experience of victimization, opportunity factors, and social context factors to explain the public’s fear of crime on social networking sites (SNS). The model is based on the risk interpretation model, which predicts that these factors influence users’ fear of crime victimization. Using data from 486 university students in South Korea, an empirically-tested model suggests that sex and age have direct and significant effects on fear of victimization, supporting the vulnerability hypothesis. Among opportunity factors, the level of personal information and the number of offending peers have significant effects …
An Exploratory Perception Analysis Of Consensual And Nonconsensual Image Sharing, Jin Ree Lee, Steven Downing
An Exploratory Perception Analysis Of Consensual And Nonconsensual Image Sharing, Jin Ree Lee, Steven Downing
International Journal of Cybersecurity Intelligence & Cybercrime
Limited research has considered individual perceptions of moral distinctions between consensual and nonconsensual intimate image sharing, as well as decision making parameters around why others might engage in such behavior. The current study conducted a perception analysis using mixed-methods online surveys administered to 63 participants, inquiring into their perceptions of why individuals engage in certain behaviors surrounding the sending of intimate images from friends and partners. The study found that respondents favored the concepts of (1) sharing images with romantic partners over peers; (2) sharing non-intimate images over intimate images; and (3) sharing images with consent rather than without it. …
Blockchain Security: Situational Crime Prevention Theory And Distributed Cyber Systems, Nicholas J. Blasco, Nicholas A. Fett
Blockchain Security: Situational Crime Prevention Theory And Distributed Cyber Systems, Nicholas J. Blasco, Nicholas A. Fett
International Journal of Cybersecurity Intelligence & Cybercrime
The authors laid the groundwork for analyzing the crypto-economic incentives of interconnected blockchain networks and utilize situational crime prevention theory to explain how more secure systems can be developed. Blockchain networks utilize smaller blockchains (often called sidechains) to increase throughput in larger networks. Identified are several disadvantages to using sidechains that create critical exposures to the assets locked on them. Without security being provided by the mainchain in the form of validated exits, sidechains or statechannels which have a bridge or mainchain asset representations are at significant risk of attack. The inability to have a sufficiently high cost to attack …
Memoryranger Prevents Highjacking File_Object Structures In Windows Kernel, Igor Korkin
Memoryranger Prevents Highjacking File_Object Structures In Windows Kernel, Igor Korkin
Journal of Digital Forensics, Security and Law
Windows OS kernel memory is one of the main targets of cyber-attacks. By launching such attacks, hackers are succeeding in process privilege escalation and tampering users’ data by accessing kernel-mode memory. This paper considers a new example of such an attack, which results in access to the files opened in an exclusive mode. Windows built-in security features prevent such a legal access, but attackers can circumvent them by patching dynamically allocated objects. The research shows that the newest Windows 10 x64 is vulnerable to this attack. The paper provides an example of using MemoryRanger, a hypervisor- based solution to prevent …
Be Sensitive And Collaborative: Analyzing Impact Of Coverage Metrics In Greybox Fuzzing, Jinghan Wang, Yue Duan, Wei Song, Heng Yin, Chengyu Song
Be Sensitive And Collaborative: Analyzing Impact Of Coverage Metrics In Greybox Fuzzing, Jinghan Wang, Yue Duan, Wei Song, Heng Yin, Chengyu Song
Research Collection School Of Computing and Information Systems
Coverage-guided greybox fuzzing has become one of the most common techniques for finding software bugs. Coverage metric, which decides how a fuzzer selects new seeds, is an essential parameter of fuzzing and can significantly affect the results. While there are many existing works on the effectiveness of different coverage metrics on software testing, little is known about how different coverage metrics could actually affect the fuzzing results in practice. More importantly, it is unclear whether there exists one coverage metric that is superior to all the other metrics. In this paper, we report the first systematic study on the impact …
Fast Forensic Triage Using Centralised Thumbnail Caches On Windows Operating Systems, Sean Mckeown, Gordon Russell, Petra Leimich
Fast Forensic Triage Using Centralised Thumbnail Caches On Windows Operating Systems, Sean Mckeown, Gordon Russell, Petra Leimich
Journal of Digital Forensics, Security and Law
A common investigative task is to identify known contraband images on a device, which typically involves calculating cryptographic hashes for all the files on a disk and checking these against a database of known contraband. However, modern drives are now so large that it can take several hours just to read this data from the disk, and can contribute to the large investigative backlogs suffered by many law enforcement bodies. Digital forensic triage techniques may thus be used to prioritise evidence and effect faster investigation turnarounds. This paper proposes a new forensic triage method for investigating disk evidence relating to …
Improved Decay Tolerant Inference Of Previously Uninstalled Computer Applications, Oluwaseun Adegbehingbe, James Jones
Improved Decay Tolerant Inference Of Previously Uninstalled Computer Applications, Oluwaseun Adegbehingbe, James Jones
Journal of Digital Forensics, Security and Law
When an application is uninstalled from a computer system, the application’s deleted file contents are overwritten over time, depending on factors such as operating system, available unallocated disk space, user activity, etc. As this content decays, the ability to infer the application’s prior presence, based on the remaining digital artifacts, becomes more difficult. Prior research inferring previously installed applications by matching sectors from a hard disk of interest to a previously constructed catalog of labeled sector hashes showed promising results. This prior work used a white list approach to identify relevant artifacts, resulting in no irrelevant artifacts but incurring the …
Lightweight Fine-Grained Search Over Encrypted Data In Fog Computing, Yinbin Miao, Jianfeng Ma, Ximeng Liu, Jian Weng, Hongwei Li, Hui Li
Lightweight Fine-Grained Search Over Encrypted Data In Fog Computing, Yinbin Miao, Jianfeng Ma, Ximeng Liu, Jian Weng, Hongwei Li, Hui Li
Research Collection School Of Computing and Information Systems
Fog computing, as an extension of cloud computing, outsources the encrypted sensitive data to multiple fog nodes on the edge of Internet of Things (IoT) to decrease latency and network congestion. However, the existing ciphertext retrieval schemes rarely focus on the fog computing environment and most of them still impose high computational and storage overhead on resource-limited end users. In this paper, we first present a Lightweight Fine-Grained ciphertexts Search (LFGS) system in fog computing by extending Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and Searchable Encryption (SE) technologies, which can achieve fine-grained access control and keyword search simultaneously. The LFGS can shift …
Finding Flaws From Password Authentication Code In Android Apps, Siqi Ma, Elisa Bertino, Surya Nepal, Jianru Li, Ostry Diethelm, Robert H. Deng, Sanjay Jha
Finding Flaws From Password Authentication Code In Android Apps, Siqi Ma, Elisa Bertino, Surya Nepal, Jianru Li, Ostry Diethelm, Robert H. Deng, Sanjay Jha
Research Collection School Of Computing and Information Systems
Password authentication is widely used to validate users’ identities because it is convenient to use, easy for users to remember, and simple to implement. The password authentication protocol transmits passwords in plaintext, which makes the authentication vulnerable to eavesdropping and replay attacks, and several protocols have been proposed to protect against this. However, we find that secure password authentication protocols are often implemented incorrectly in Android applications (apps). To detect the implementation flaws in password authentication code, we propose GLACIATE, a fully automated tool combining machine learning and program analysis. Instead of creating detection templates/rules manually, GLACIATE automatically and accurately …
Efficient Oblivious Transfer With Membership Verification, Weiwei Liu, Dazhi Sun, Yangguang Tian
Efficient Oblivious Transfer With Membership Verification, Weiwei Liu, Dazhi Sun, Yangguang Tian
Research Collection School Of Computing and Information Systems
In this article, we introduce a new concept of oblivious transfer with membership verification that allows any legitimate group users to obtain services from a service provider in an oblivious manner. We present two oblivious transfer with membership verification schemes, differing in design. In the first scheme, a trusted group manager issues credentials for a pre-determined group of users so that the group of users with a valid group credential can obtain services from the service provider, while the choices made by group users remain oblivious to the service provider. The second scheme avoids the trusted group manager, which allows …
Automatic Generation Of Non-Intrusive Updates For Third-Party Libraries In Android Applications, Yue Duan, Lian Gao, Jie Hu, Heng Yin
Automatic Generation Of Non-Intrusive Updates For Third-Party Libraries In Android Applications, Yue Duan, Lian Gao, Jie Hu, Heng Yin
Research Collection School Of Computing and Information Systems
Third-Party libraries, which are ubiquitous in Android apps,have exposed great security threats to end users as they rarelyget timely updates from the app developers, leaving manysecurity vulnerabilities unpatched. This issue is due to thefact that manually updating libraries can be technically nontrivialand time-consuming for app developers. In this paper,we propose a technique that performs automatic generationof non-intrusive updates for third-party libraries in Androidapps. Given an Android app with an outdated library and anewer version of the library, we automatically update the oldlibrary in a way that is guaranteed to be fully backward compatibleand imposes zero impact to the library’s interactionswith …
Puncturable Proxy Re-Encryption Supporting To Group Messaging Service, Tran Viet Xuan Phuong, Willy Susilo, Jongkil Kim, Guomin Yang, Dongxi Liu
Puncturable Proxy Re-Encryption Supporting To Group Messaging Service, Tran Viet Xuan Phuong, Willy Susilo, Jongkil Kim, Guomin Yang, Dongxi Liu
Research Collection School Of Computing and Information Systems
This work envisions a new encryption primitive for many-to-many paradigms such as group messaging systems. Previously, puncturable encryption (PE) was introduced to provide forward security for asynchronous messaging services. However, existing PE schemes were proposed only for one-to-one communication, and causes a significant overhead for a group messaging system. In fact, the group communication over PE can only be achieved by encrypting a message multiple times for each receiver by the sender’s device, which is usually suitable to restricted resources such as mobile phones or sensor devices. Our new suggested scheme enables to re-encrypt ciphertexts of puncturable encryption by a …