Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Artificial Intelligence and Robotics (34)
- Business (33)
- Social and Behavioral Sciences (33)
- Engineering (29)
- Databases and Information Systems (26)
-
- Technology and Innovation (24)
- Management Information Systems (23)
- Cybersecurity (22)
- Software Engineering (18)
- Education (17)
- Public Affairs, Public Policy and Public Administration (16)
- Computer Engineering (15)
- Other Computer Sciences (15)
- OS and Networks (14)
- Theory and Algorithms (14)
- Data Science (13)
- Sociology (12)
- Systems Architecture (12)
- Defense and Security Studies (9)
- Electrical and Computer Engineering (9)
- Science and Technology Policy (9)
- Criminology (8)
- Criminology and Criminal Justice (7)
- Legal Studies (7)
- Medicine and Health Sciences (7)
- Forensic Science and Technology (6)
- Graphics and Human Computer Interfaces (6)
- Institution
-
- Singapore Management University (66)
- Old Dominion University (34)
- Kennesaw State University (25)
- Edith Cowan University (24)
- United Arab Emirates University (18)
-
- Chinese Academy of Sciences (9)
- Bridgewater State University (7)
- California State University, San Bernardino (6)
- Dakota State University (6)
- University of South Alabama (5)
- Dartmouth College (3)
- Portland State University (3)
- University at Albany, State University of New York (3)
- University of Arkansas, Fayetteville (3)
- University of Central Florida (3)
- Wayne State University (3)
- Arkansas Tech University (2)
- Clemson University (2)
- Indiana State University (2)
- Louisiana State University (2)
- Loyola University Chicago (2)
- Michigan Technological University (2)
- University of Arkansas Little Rock (2)
- University of Denver (2)
- University of Texas Rio Grande Valley (2)
- University of Texas at Arlington (2)
- Air Force Institute of Technology (1)
- American University in Cairo (1)
- Association of Arab Universities (1)
- California Polytechnic State University, San Luis Obispo (1)
- Keyword
-
- Cybersecurity (34)
- Security (18)
- Privacy (14)
- Blockchain (13)
- Machine learning (11)
-
- Artificial intelligence (8)
- Internet of Things (6)
- Protocols (6)
- Cybercrime (5)
- Data privacy (5)
- Data security (5)
- Federated learning (5)
- Internet of things (5)
- Servers (5)
- Training (5)
- Anomaly detection (4)
- Computer security (4)
- Cryptography (4)
- Deep Learning (4)
- Education (4)
- Encryption (4)
- Homomorphic encryption (4)
- Intrusion detection (4)
- Intrusion detection system (4)
- IoT (4)
- Natural language processing (4)
- Adaptation models (3)
- Bitcoin (3)
- Classification (3)
- Cyber security (3)
- Publication
-
- Research Collection School Of Computing and Information Systems (62)
- Research outputs 2022 to 2026 (23)
- Journal of Cybersecurity Education, Research and Practice (18)
- Cybersecurity Undergraduate Research Showcase (10)
- Bulletin of Chinese Academy of Sciences (Chinese Version) (9)
-
- Theses (8)
- International Journal of Cybersecurity Intelligence & Cybercrime (7)
- Thesis/ Dissertation Defenses (7)
- Electronic Theses, Projects, and Dissertations (6)
- Research & Publications (6)
- KSU Proceedings on Cybersecurity Education, Research and Practice (5)
- School of Cybersecurity Faculty Publications (5)
- VMASC Publications (5)
- Dissertations (4)
- Electrical & Computer Engineering Faculty Publications (4)
- Theses and Dissertations (4)
- Chemical Engineering and Materials Science Faculty Research Publications (3)
- Computer Science and Computer Engineering Undergraduate Honors Theses (3)
- Electronic Theses and Dissertations (3)
- Graduate Theses and Dissertations (2019 - present) (3)
- Graduate Thesis and Dissertation 2023-2024 (3)
- Information Technology & Decision Sciences Faculty Publications (3)
- Student Research Symposium (3)
- ALL - Honors Theses (2)
- ATU Scholars Symposium (2)
- African Conference on Information Systems and Technology (2)
- Computer Science Senior Theses (2)
- Computer Science and Engineering Dissertations - Archive (2)
- Computer Science: Faculty Publications and Other Works (2)
- Dissertations and Theses Collection (Open Access) (2)
- Publication Type
Articles 31 - 60 of 265
Full-Text Articles in Information Security
Beyond Human-Centric Models In Cybersecurity Education: A Pilot Posthuman Analysis Of The Nice Workforce Framework For Cybersecurity, Ryan Straight
Beyond Human-Centric Models In Cybersecurity Education: A Pilot Posthuman Analysis Of The Nice Workforce Framework For Cybersecurity, Ryan Straight
Journal of Cybersecurity Education, Research and Practice
This study applies a posthuman lens to the National Initiative for Cybersecurity Education (NICE) Workforce Framework, examining two key Work Roles in cybersecurity education. Employing a novel posthuman coding scheme, the associated Tasks, Knowledge, and Skills (TKS) statements were analyzed. Findings reveal significant posthuman elements within the framework while identifying opportunities for further integration. The analysis demonstrates a strong presence of human-technology entanglement and adaptive learning concepts, yet highlights areas where the framework could emphasize system complexity and interconnectedness. This research contributes to ongoing discussions on cybersecurity education in complex technological landscapes, proposing a theoretical framework for integrating posthuman concepts …
Phishing Emails: An Evolving Cyberattack, Brooke Waltz
Phishing Emails: An Evolving Cyberattack, Brooke Waltz
Cybersecurity Undergraduate Research Showcase
This paper describes the history of phishing attacks and how they turned into cyberattacks, focusing on companies. Over the course of 34 years, phishing has been evolving at an alarming rate, especially with AI now coming into play. As phishing attacks have become more prominent towards companies, there has been an increase in financial loss and data breaches, resulting in a loss of trust in companies. With this loss, companies are trying to find solutions to this problem. Some notable attacks were the RSA breach in 2011, the Texas Energy Company in 2014, and the ILOVEYOU virus in 2000. They …
A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed
A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed
Thesis/ Dissertation Defenses
This thesis examines the use of Large Language Models (LLMs) in education, with a focus on improving performance and implementing strong security measures. The research has two main goals, namely, the development of an effective lecture summarization technique using LLMs and identifying and addressing security vulnerabilities in LLM applications according to OWASP (Open Web Application Security Project) guidelines. For the former goal, we have proposed an effective framework for fine-tuning LLMs using real lecture datasets and compared the performance of different LLMs. For the latter goal, we conducted a thorough review of the application dataflow of the proposed framework and …
Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham
Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham
Faculty Publications
Modern computing systems are primarily designed for maximum performance, which inadvertently introduces vulnerabilities at the micro-architecture level. While cache side-channel analysis has received significant attention, other Central Processing Units (CPUs) components like the Translation Lookaside Buffer (TLB) can also be exploited to leak sensitive information. This paper focuses on the TLB, a micro-architecture component that is vulnerable to side-channel attacks. Despite the coarse granularity at the page level, advancements in tools and techniques have made TLB information leakage feasible. The primary goal of this study is not to demonstrate the potential for information leakage from the TLB but to establish …
Developing A Framework For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan
Developing A Framework For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan
Thesis/ Dissertation Defenses
This thesis is concerned with the data quality and security of the digital twin and how it is going to impact its adoption, trustworthiness, and potential for real-world applications. By addressing the potential vulnerabilities and ensuring the integrity of data, this research aims to contribute to the development of robust and trustworthy digital twin standards and policies that is going to complement the existing international standards across different domains. Moreover, it underscores the important need to establish robust standards to ensure the successful and secure deployment of digital twins across industries. Previous research, while valuable, may not have fully addressed …
Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous
Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous
Thesis/ Dissertation Defenses
With the increase in popularity of online communities, such as social media platforms, online games, and chatroom servers, there is a need to improve chat and content moderation. Platforms have reported an increase in the prevalence of toxic behavior and hate speech. Meanwhile, moderators are reporting difficulties in keeping up with the amount of data to check as well and the type of content they are exposed to, which further harms their own mental health. The main objective of this work is to address the challenges that exist within online communities with the rising prevalence of hate speech. Additionally, some …
Developing Policies For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan
Developing Policies For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan
Theses
This thesis is concerned with the data quality and security of the digital twin and how it is going to impact its adoption, trustworthiness, and potential for real-world applications. By addressing the potential vulnerabilities and ensuring the integrity of data, this research aims to contribute to the development of robust and trustworthy digital twin policies that to complement the existing international standards across different domains. Moreover, it underscores the important need to establish robust policies to ensure the successful and secure deployment of digital twins across industries. Previous research, while valuable, may not have fully addressed the critical interplay between …
An Efficient Pairing-Free Ciphertext-Policy Attribute-Based Encryption Scheme For Internet Of Things, Chong Guo, Bei Gong, Muhammad Waqas, Hisham Alasmary, Shanshan Tu, Sheng Chen
An Efficient Pairing-Free Ciphertext-Policy Attribute-Based Encryption Scheme For Internet Of Things, Chong Guo, Bei Gong, Muhammad Waqas, Hisham Alasmary, Shanshan Tu, Sheng Chen
Research outputs 2022 to 2026
The Internet of Things (IoT) is a heterogeneous network composed of numerous dynamically connected devices. While it brings convenience, the IoT also faces serious challenges in data security. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptography method that supports fine-grained access control, offering a solution to the IoT’s security issues. However, existing CP-ABE schemes are inefficient and unsuitable for IoT devices with limited computing resources. To address this problem, this paper proposes an efficient pairing-free CP-ABE scheme for the IoT. The scheme is based on lightweight elliptic curve scalar multiplication and supports multi-authority and verifiable outsourced decryption. The proposed scheme …
A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed
A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed
Theses
This thesis examines the use of Large Language Models (LLMs) in education, with a focus on improving performance and implementing strong security measures. The research has two main goals, namely, the development of an effective lecture summarization technique using LLMs and identifying and addressing security vulnerabilities in LLM applications according to OWASP (Open Web Application Security Project) guidelines. For the former goal, we have proposed an effective framework for fine-tuning LLMs using real lecture datasets and compared the performance of different LLMs. For the latter goal, we conducted a thorough review of the application dataflow of the proposed framework and …
Efficient Multiplicative-To-Additive Function From Joye-Libert Cryptosystem And Its Application To Threshold Ecdsa, Haiyang Xue, Ho Man Au, Mengling Liu, Yin Kwan Chan, Handong Cui, Xiang Xie, Hon Tsz Yuen, Chengru Zhang
Efficient Multiplicative-To-Additive Function From Joye-Libert Cryptosystem And Its Application To Threshold Ecdsa, Haiyang Xue, Ho Man Au, Mengling Liu, Yin Kwan Chan, Handong Cui, Xiang Xie, Hon Tsz Yuen, Chengru Zhang
Research Collection School Of Computing and Information Systems
Threshold ECDSA receives interest lately due to its widespread adoption in blockchain applications. A common building block of all leading constructions involves a secure conversion of multiplicative shares into additive ones, which is called the multiplicative-to-additive (MtA) function. MtA dominates the overall complexity of all existing threshold ECDSA constructions. Specifically, O(n2) invocations of MtA are required in the case of n active signers. Hence, improvement of MtA leads directly to significant improvements for all state-of-the-art threshold ECDSA schemes.In this paper, we design a novel MtA by revisiting the Joye-Libert (JL) cryptosystem. Specifically, we revisit JL encryption and propose a JL-based …
Adversarial Learning For Coordinate Regression Through K-Layer Penetrating Representation, Mengxi Jiang, Yulei Sui, Yunqi Lei, Xiaofei Xie, Cuihua Li, Yang Liu, Ivor W. Tsang
Adversarial Learning For Coordinate Regression Through K-Layer Penetrating Representation, Mengxi Jiang, Yulei Sui, Yunqi Lei, Xiaofei Xie, Cuihua Li, Yang Liu, Ivor W. Tsang
Research Collection School Of Computing and Information Systems
Adversarial attack is a crucial step when evaluating the reliability and robustness of deep neural networks (DNNs) models. Most existing attack approaches apply an end-to-end gradient update strategy to generate adversarial examples for a classification or regression problem. However, few of them consider the non-differentiable DNN models (e.g., coordinate regression model) that prevent end-to-end backpropagation resulting in the failure of gradient calculation. In this paper, we present a new adversarial example generation approach for both untargeted and targeted attacks on coordinate regression models with non-differentiable operations. The novelty of our approach lies in a k-layer penetrating representation, on which we …
Badfl: Backdoor Attack Defense In Federated Learning From Local Model Perspective, Haiyan Zhang, Xinghua Li, Mengfan Xu, Ximeng Liu, Tong Wu, Jian Weng, Robert H. Deng
Badfl: Backdoor Attack Defense In Federated Learning From Local Model Perspective, Haiyan Zhang, Xinghua Li, Mengfan Xu, Ximeng Liu, Tong Wu, Jian Weng, Robert H. Deng
Research Collection School Of Computing and Information Systems
There is substantial attention to federated learning with its ability to train a powerful global model collaboratively while protecting data privacy. Despite its many advantages, federated learning is vulnerable to backdoor attacks, where an adversary injects malicious weights into the global model, making the global model's targeted predictions incorrect. Existing defenses based on identifying and eliminating malicious weights ignore the similarity variation of the local weights during iterations in the malicious model detection and the presence of benign weights in the malicious model during the malicious local weight elimination, resulting in a poor defense and a degradation of global model …
Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo Hu, Xiao Ma, Xinger Huang, Yiran Shen, Dong Ma
Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo Hu, Xiao Ma, Xinger Huang, Yiran Shen, Dong Ma
Research Collection School Of Computing and Information Systems
The increasing use of earbuds in applications like immersive entertainment and health monitoring necessitates effective implicit user authentication systems to preserve the privacy of sensitive data and provide personalized experiences. Existing approaches, which leverage physiological cues (e.g., jawbone structure) and behavioral cues (e.g., gait), face challenges such as limited usability, high delay and energy overhead, and significant computational demands, rendering them impractical for resource-constrained earbuds. To address these issues, we present LR-Auth, a lightweight, user-friendly implicit authentication system designed for various earbud usage scenarios. LR-Auth utilizes the modulation of sound frequencies by the user's unique occluded ear canal, generating user-specific …
Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous
Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous
Dissertations
With the increase in popularity of online communities, such as social media platforms, online games, and chatroom servers, there is a need to improve chat and content moderation. Platforms have reported an increase in the prevalence of toxic behavior and hate speech. Meanwhile, moderators are reporting difficulties in keeping up with the amount of data to check as well and the type of content they are exposed to, which further harms their own mental health. The main objective of this work is to address the challenges that exist within online communities with the rising prevalence of hate speech. Additionally, some …
Maritime Behaviour Anomaly Detection With Seasonal Context, Travis Rybicki, Martin Masek, Chiou Peng Lam
Maritime Behaviour Anomaly Detection With Seasonal Context, Travis Rybicki, Martin Masek, Chiou Peng Lam
Research outputs 2022 to 2026
Monitoring maritime traffic has become an important task for ensuring the safety of vessels, as well as the goods, and persons that they may be transporting. An active area of research is the modelling of expected normal vessel behaviour so as to detect subsequent anomalies in new data. Anomalies indicate that a vessel is not behaving in an expected manner and their detection can be flagged for further investigation to identify whether the vessel needs assistance or intervention. An important factor for some vessels in determining normal behaviour is seasonal context. However, current approaches typically do not incorporate seasonality into …
Wormhole Attack Mitigation In Wireless Network Using Propagation Delay, Harry May, Travis Atkison
Wormhole Attack Mitigation In Wireless Network Using Propagation Delay, Harry May, Travis Atkison
Journal of Cybersecurity Education, Research and Practice
This paper presents a novel approach for mitigating wormhole attacks on wireless networks using propagation delay timing. The wormhole attack is a persistent security threat that threatens the integrity of network communications, potentially leading to data theft or other malicious activities. While various methods exist for combating wormhole attacks, our approach offers advantages that set it apart. Our approach involves a combination of proactive and reactive measures, harnessing box plot analysis and weighting factor techniques to identify and isolate outlier node links effectively. Unlike traditional methods, our solution not only detects outlier links but also defines dynamic weighting factors, providing …
Happy Hours, Not Office Hours: Socially Engaging Cybersecurity Students In A Large Online Graduate Course, James T. Mccafferty
Happy Hours, Not Office Hours: Socially Engaging Cybersecurity Students In A Large Online Graduate Course, James T. Mccafferty
Journal of Cybersecurity Education, Research and Practice
Engagement is a critical part of student learning and student success. This is especially true in online classes where students have less interaction with their classmates and instructors when compared to traditional face-to-face courses. Research on engagement has shown that when students are meaningfully engaged it can increase student satisfaction and it may also increase levels of academic achievement, including grades earned and degree progression (e.g. Wong et al., 2024). This paper focuses on social engagement in a graduate cybersecurity program that uses large, expandable online courses as described by Whitman and Mattord (2023). Large online graduate classes (i.e., more …
2024 Gateway Magazine, College Of Computing, Michigan Technological University
2024 Gateway Magazine, College Of Computing, Michigan Technological University
College of Computing Annual Magazines
Table of Contents
- 50 Years of Computer Science at Michigan Tech
- Data Science for a Changing Planet
- Healthcare Transformed
- Mechatronics Matters
- Powered by Michigan Tech Talent
- Esports: Bringing Everything Great about Sports to More People
- The Michigander Scholars Program: Electrifying Careers in Michigan
- College of Computing News
A Survey Of Advanced Border Gateway Protocol Attack Detection Techniques, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk
A Survey Of Advanced Border Gateway Protocol Attack Detection Techniques, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk
Research outputs 2022 to 2026
The Internet's default inter-domain routing system, the Border Gateway Protocol (BGP), remains insecure. Detection techniques are dominated by approaches that involve large numbers of features, parameters, domain-specific tuning, and training, often contributing to an unacceptable computational cost. Efforts to detect anomalous activity in the BGP have been almost exclusively focused on single observable monitoring points and Autonomous Systems (ASs). BGP attacks can exploit and evade these limitations. In this paper, we review and evaluate categories of BGP attacks based on their complexity. Previously identified next-generation BGP detection techniques remain incapable of detecting advanced attacks that exploit single observable detection approaches …
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings
Research & Publications
Digital engineering practices offer significant yet underutilized potential for improving information assurance and system lifecycle management. This paper examines how capabilities like model-based engineering, digital threads, and integrated product lifecycles can address gaps in prevailing frameworks. A reference model demonstrates applying digital engineering techniques to a reference information system, exhibiting enhanced traceability, risk visibility, accuracy, and integration. The model links strategic needs to requirements and architecture while reusing authoritative elements across views. Analysis of the model shows digital engineering closes gaps in compliance, monitoring, change management, and risk assessment. Findings indicate purposeful digital engineering adoption could transform cybersecurity, operations, service …
Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan
Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan
Research & Publications
As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …
Resilient Tcp Variant Enabling Smooth Network Updates For Software-Defined Data Center Networks, Abdul Basit Dogar, Sami Ullah, Yiran Zhang, Hisham Alasmary, Muhammad Waqas, Sheng Chen
Resilient Tcp Variant Enabling Smooth Network Updates For Software-Defined Data Center Networks, Abdul Basit Dogar, Sami Ullah, Yiran Zhang, Hisham Alasmary, Muhammad Waqas, Sheng Chen
Research outputs 2022 to 2026
Network updates have become increasingly prevalent since the broad adoption of software-defined networks (SDNs) in data centers. Modern TCP designs, including cutting-edge TCP variants DCTCP, CUBIC, and BBR, however, are not resilient to network updates that provoke flow rerouting. In this paper, we first demonstrate that popular TCP implementations perform inadequately in the presence of frequent and inconsistent network updates, because inconsistent and frequent network updates result in out-of-order packets and packet drops induced via transitory congestion and lead to serious performance deterioration. We look into the causes and propose a network update-friendly TCP (NUFTCP), which is an extension of …
Navigating Governance Paradigms: A Cross-Regional Comparative Study Of Generative Ai Governance Processes & Principle, Jose Luna, Ivan Tan, Xiaofei Xie, Lingxiao Jiang
Navigating Governance Paradigms: A Cross-Regional Comparative Study Of Generative Ai Governance Processes & Principle, Jose Luna, Ivan Tan, Xiaofei Xie, Lingxiao Jiang
Research Collection School Of Computing and Information Systems
As Generative Artificial Intelligence (GenAI) technologies evolve at an unprecedented rate, global governance approaches struggle to keep pace with the technology, highlighting a critical issue in the governance adaptation of significant challenges. Depicting the nuances of nascent and diverse governance approaches based on risks, rules, outcomes, principles, or a mix across different regions around the globe is fundamental to discern discrepancies and convergences and to shed light on specific limitations that need to be addressed, thereby facilitating the safe and trustworthy adoption of GenAI. In response to the need and the evolving nature of GenAI, this paper seeks to provide …
On The Lossiness Of 2k-Th Power And The Instantiability Of Rabin-Oaep, Haiyang Xue, Bao Li, Xianhui Lu, Kunpeng Wang, Yamin Liu
On The Lossiness Of 2k-Th Power And The Instantiability Of Rabin-Oaep, Haiyang Xue, Bao Li, Xianhui Lu, Kunpeng Wang, Yamin Liu
Research Collection School Of Computing and Information Systems
Seurin PKC 2014 proposed the 2-ï /4-hiding assumption which asserts the indistinguishability of Blum Numbers from pseudo Blum Numbers. In this paper, we investigate the lossiness of 2 k -th power based on the 2 k -ï /4-hiding assumption, which is an extension of the 2-ï /4-hiding assumption. And we prove that 2 k -th power function is a lossy trapdoor permutation over Quadratic Residuosity group. This new lossy trapdoor function has 2 k -bits lossiness for k -bits exponent, while the RSA lossy trapdoor function given by Kiltz et al. Crypto 2010 has k -bits lossiness for k -bits …
Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang, Rui Zhang, Binbin Chen, Xiangyang Luo, Ming Hu, Wenrui Ma
Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang, Rui Zhang, Binbin Chen, Xiangyang Luo, Ming Hu, Wenrui Ma
Research Collection School Of Computing and Information Systems
Anomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. …
Direct Range Proofs For Paillier Cryptosystem And Their Applications, Zhikang Xie, Mengling Liu, Haiyang Xue, Man Ho Au, Robert H. Deng, Siu-Ming Yiu
Direct Range Proofs For Paillier Cryptosystem And Their Applications, Zhikang Xie, Mengling Liu, Haiyang Xue, Man Ho Au, Robert H. Deng, Siu-Ming Yiu
Research Collection School Of Computing and Information Systems
The Paillier cryptosystem is renowned for its applications in electronic voting, threshold ECDSA, multi-party computation, and more, largely due to its additive homomorphism. In these applications, range proofs for the Paillier cryptosystem are crucial for maintaining security, because of the mismatch between the message space in the Paillier system and the operation space in application scenarios. In this paper, we present novel range proofs for the Paillier cryptosystem, specifically aimed at optimizing those for both Paillier plaintext and affine operation. We interpret encryptions and affine operations as commitments over integers, as opposed to solely over ZN. Consequently, we propose direct …
A Survey Of Protocol Fuzzing, Xiaohan Zhang, Cen Zhang, Xinghua Li, Zhengjie Du, Bing Mao, Yeting Li, Pan Li
A Survey Of Protocol Fuzzing, Xiaohan Zhang, Cen Zhang, Xinghua Li, Zhengjie Du, Bing Mao, Yeting Li, Pan Li
Research Collection School Of Computing and Information Systems
Communication protocols form the bedrock of our interconnected world, yet vulnerabilities within their implementations pose significant security threats. Recent developments have seen a surge in fuzzing-based research dedicated to uncovering these vulnerabilities within protocol implementations. However, there still lacks a systematic overview of protocol fuzzing for answering the essential questions such as what the unique challenges are, how existing works solve them, and so on. To bridge this gap, we conducted a comprehensive investigation of related works from both academia and industry. Our study includes a detailed summary of the specific challenges in protocol fuzzing and provides a systematic categorization …
Leveraging Propagation Delay For Wormhole Detection In Wireless Networks, Harry May, Travis Atkison
Leveraging Propagation Delay For Wormhole Detection In Wireless Networks, Harry May, Travis Atkison
Journal of Cybersecurity Education, Research and Practice
Detecting and mitigating wormhole attacks in wireless networks remains a critical challenge due to their deceptive nature and potential to compromise network integrity. This paper proposes a novel approach to wormhole detection by leveraging propagation delay analysis between network nodes. Unlike traditional methods that rely on signature-based detection or specialized hardware, our method focuses on analyzing propagation delay timings to identify anomalous behavior indicative of wormhole attacks. The proposed methodology involves collecting propagation delay data in both normal network scenarios and scenarios with inserted malicious wormhole nodes. By comparing these delay timings, our approach aims to differentiate between legitimate network …
How State Universities Are Addressing The Shortage Of Cybersecurity Professionals In The United States, Gary Harris
How State Universities Are Addressing The Shortage Of Cybersecurity Professionals In The United States, Gary Harris
Journal of Cybersecurity Education, Research and Practice
Cybersecurity threats have been a serious and growing problem for decades. In addition, a severe shortage of cybersecurity professionals has been proliferating for nearly as long. These problems exist in the United States and globally and are well documented in literature. This study examined what state universities are doing to help address the shortage of cybersecurity professionals since higher education institutions are a primary source to the workforce pipeline. It is suggested that the number of cybersecurity professionals entering the workforce is related to the number of available programs. Thus increasing the number of programs will increase the number of …
Cyber Victimization In The Healthcare Industry: Analyzing Offender Motivations And Target Characteristics Through Routine Activities Theory (Rat) And Cyber-Routine Activities Theory (Cyber-Rat), Yashna Praveen, Mijin Kim, Kyung-Shick Choi
Cyber Victimization In The Healthcare Industry: Analyzing Offender Motivations And Target Characteristics Through Routine Activities Theory (Rat) And Cyber-Routine Activities Theory (Cyber-Rat), Yashna Praveen, Mijin Kim, Kyung-Shick Choi
International Journal of Cybersecurity Intelligence & Cybercrime
The integration of computer technology in healthcare has revolutionized patient care but has also introduced significant cyber risks. Despite the healthcare sector being a primary target for cyber-attacks, research on the dynamics of these threats and practical solutions remains limited. Understanding the complexities of cyberattacks in this sector is critical, as the impact extends beyond financial losses to directly affect patient care and the protection of sensitive information. This paper applies Routine Activities Theory (RAT) and Cyber Routine Activities Theory (C-RAT) to analyze high-tech cyber victimization case studies in healthcare. The analysis explores the motivations behind these attacks and identifies …