Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

2024

Discipline
Institution
Keyword
Publication
Publication Type

Articles 31 - 60 of 265

Full-Text Articles in Information Security

Beyond Human-Centric Models In Cybersecurity Education: A Pilot Posthuman Analysis Of The Nice Workforce Framework For Cybersecurity, Ryan Straight Nov 2024

Beyond Human-Centric Models In Cybersecurity Education: A Pilot Posthuman Analysis Of The Nice Workforce Framework For Cybersecurity, Ryan Straight

Journal of Cybersecurity Education, Research and Practice

This study applies a posthuman lens to the National Initiative for Cybersecurity Education (NICE) Workforce Framework, examining two key Work Roles in cybersecurity education. Employing a novel posthuman coding scheme, the associated Tasks, Knowledge, and Skills (TKS) statements were analyzed. Findings reveal significant posthuman elements within the framework while identifying opportunities for further integration. The analysis demonstrates a strong presence of human-technology entanglement and adaptive learning concepts, yet highlights areas where the framework could emphasize system complexity and interconnectedness. This research contributes to ongoing discussions on cybersecurity education in complex technological landscapes, proposing a theoretical framework for integrating posthuman concepts …


Phishing Emails: An Evolving Cyberattack, Brooke Waltz Nov 2024

Phishing Emails: An Evolving Cyberattack, Brooke Waltz

Cybersecurity Undergraduate Research Showcase

This paper describes the history of phishing attacks and how they turned into cyberattacks, focusing on companies. Over the course of 34 years, phishing has been evolving at an alarming rate, especially with AI now coming into play. As phishing attacks have become more prominent towards companies, there has been an increase in financial loss and data breaches, resulting in a loss of trust in companies. With this loss, companies are trying to find solutions to this problem. Some notable attacks were the RSA breach in 2011, the Texas Energy Company in 2014, and the ILOVEYOU virus in 2000. They …


A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed Nov 2024

A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed

Thesis/ Dissertation Defenses

This thesis examines the use of Large Language Models (LLMs) in education, with a focus on improving performance and implementing strong security measures. The research has two main goals, namely, the development of an effective lecture summarization technique using LLMs and identifying and addressing security vulnerabilities in LLM applications according to OWASP (Open Web Application Security Project) guidelines. For the former goal, we have proposed an effective framework for fine-tuning LLMs using real lecture datasets and compared the performance of different LLMs. For the latter goal, we conducted a thorough review of the application dataflow of the proposed framework and …


Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham Nov 2024

Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham

Faculty Publications

Modern computing systems are primarily designed for maximum performance, which inadvertently introduces vulnerabilities at the micro-architecture level. While cache side-channel analysis has received significant attention, other Central Processing Units (CPUs) components like the Translation Lookaside Buffer (TLB) can also be exploited to leak sensitive information. This paper focuses on the TLB, a micro-architecture component that is vulnerable to side-channel attacks. Despite the coarse granularity at the page level, advancements in tools and techniques have made TLB information leakage feasible. The primary goal of this study is not to demonstrate the potential for information leakage from the TLB but to establish …


Developing A Framework For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan Nov 2024

Developing A Framework For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan

Thesis/ Dissertation Defenses

This thesis is concerned with the data quality and security of the digital twin and how it is going to impact its adoption, trustworthiness, and potential for real-world applications. By addressing the potential vulnerabilities and ensuring the integrity of data, this research aims to contribute to the development of robust and trustworthy digital twin standards and policies that is going to complement the existing international standards across different domains. Moreover, it underscores the important need to establish robust standards to ensure the successful and secure deployment of digital twins across industries. Previous research, while valuable, may not have fully addressed …


Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous Nov 2024

Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous

Thesis/ Dissertation Defenses

With the increase in popularity of online communities, such as social media platforms, online games, and chatroom servers, there is a need to improve chat and content moderation. Platforms have reported an increase in the prevalence of toxic behavior and hate speech. Meanwhile, moderators are reporting difficulties in keeping up with the amount of data to check as well and the type of content they are exposed to, which further harms their own mental health. The main objective of this work is to address the challenges that exist within online communities with the rising prevalence of hate speech. Additionally, some …


Developing Policies For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan Nov 2024

Developing Policies For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan

Theses

This thesis is concerned with the data quality and security of the digital twin and how it is going to impact its adoption, trustworthiness, and potential for real-world applications. By addressing the potential vulnerabilities and ensuring the integrity of data, this research aims to contribute to the development of robust and trustworthy digital twin policies that to complement the existing international standards across different domains. Moreover, it underscores the important need to establish robust policies to ensure the successful and secure deployment of digital twins across industries. Previous research, while valuable, may not have fully addressed the critical interplay between …


An Efficient Pairing-Free Ciphertext-Policy Attribute-Based Encryption Scheme For Internet Of Things, Chong Guo, Bei Gong, Muhammad Waqas, Hisham Alasmary, Shanshan Tu, Sheng Chen Nov 2024

An Efficient Pairing-Free Ciphertext-Policy Attribute-Based Encryption Scheme For Internet Of Things, Chong Guo, Bei Gong, Muhammad Waqas, Hisham Alasmary, Shanshan Tu, Sheng Chen

Research outputs 2022 to 2026

The Internet of Things (IoT) is a heterogeneous network composed of numerous dynamically connected devices. While it brings convenience, the IoT also faces serious challenges in data security. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptography method that supports fine-grained access control, offering a solution to the IoT’s security issues. However, existing CP-ABE schemes are inefficient and unsuitable for IoT devices with limited computing resources. To address this problem, this paper proposes an efficient pairing-free CP-ABE scheme for the IoT. The scheme is based on lightweight elliptic curve scalar multiplication and supports multi-authority and verifiable outsourced decryption. The proposed scheme …


A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed Nov 2024

A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed

Theses

This thesis examines the use of Large Language Models (LLMs) in education, with a focus on improving performance and implementing strong security measures. The research has two main goals, namely, the development of an effective lecture summarization technique using LLMs and identifying and addressing security vulnerabilities in LLM applications according to OWASP (Open Web Application Security Project) guidelines. For the former goal, we have proposed an effective framework for fine-tuning LLMs using real lecture datasets and compared the performance of different LLMs. For the latter goal, we conducted a thorough review of the application dataflow of the proposed framework and …


Efficient Multiplicative-To-Additive Function From Joye-Libert Cryptosystem And Its Application To Threshold Ecdsa, Haiyang Xue, Ho Man Au, Mengling Liu, Yin Kwan Chan, Handong Cui, Xiang Xie, Hon Tsz Yuen, Chengru Zhang Nov 2024

Efficient Multiplicative-To-Additive Function From Joye-Libert Cryptosystem And Its Application To Threshold Ecdsa, Haiyang Xue, Ho Man Au, Mengling Liu, Yin Kwan Chan, Handong Cui, Xiang Xie, Hon Tsz Yuen, Chengru Zhang

Research Collection School Of Computing and Information Systems

Threshold ECDSA receives interest lately due to its widespread adoption in blockchain applications. A common building block of all leading constructions involves a secure conversion of multiplicative shares into additive ones, which is called the multiplicative-to-additive (MtA) function. MtA dominates the overall complexity of all existing threshold ECDSA constructions. Specifically, O(n2) invocations of MtA are required in the case of n active signers. Hence, improvement of MtA leads directly to significant improvements for all state-of-the-art threshold ECDSA schemes.In this paper, we design a novel MtA by revisiting the Joye-Libert (JL) cryptosystem. Specifically, we revisit JL encryption and propose a JL-based …


Adversarial Learning For Coordinate Regression Through K-Layer Penetrating Representation, Mengxi Jiang, Yulei Sui, Yunqi Lei, Xiaofei Xie, Cuihua Li, Yang Liu, Ivor W. Tsang Nov 2024

Adversarial Learning For Coordinate Regression Through K-Layer Penetrating Representation, Mengxi Jiang, Yulei Sui, Yunqi Lei, Xiaofei Xie, Cuihua Li, Yang Liu, Ivor W. Tsang

Research Collection School Of Computing and Information Systems

Adversarial attack is a crucial step when evaluating the reliability and robustness of deep neural networks (DNNs) models. Most existing attack approaches apply an end-to-end gradient update strategy to generate adversarial examples for a classification or regression problem. However, few of them consider the non-differentiable DNN models (e.g., coordinate regression model) that prevent end-to-end backpropagation resulting in the failure of gradient calculation. In this paper, we present a new adversarial example generation approach for both untargeted and targeted attacks on coordinate regression models with non-differentiable operations. The novelty of our approach lies in a k-layer penetrating representation, on which we …


Badfl: Backdoor Attack Defense In Federated Learning From Local Model Perspective, Haiyan Zhang, Xinghua Li, Mengfan Xu, Ximeng Liu, Tong Wu, Jian Weng, Robert H. Deng Nov 2024

Badfl: Backdoor Attack Defense In Federated Learning From Local Model Perspective, Haiyan Zhang, Xinghua Li, Mengfan Xu, Ximeng Liu, Tong Wu, Jian Weng, Robert H. Deng

Research Collection School Of Computing and Information Systems

There is substantial attention to federated learning with its ability to train a powerful global model collaboratively while protecting data privacy. Despite its many advantages, federated learning is vulnerable to backdoor attacks, where an adversary injects malicious weights into the global model, making the global model's targeted predictions incorrect. Existing defenses based on identifying and eliminating malicious weights ignore the similarity variation of the local weights during iterations in the malicious model detection and the presence of benign weights in the malicious model during the malicious local weight elimination, resulting in a poor defense and a degradation of global model …


Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo Hu, Xiao Ma, Xinger Huang, Yiran Shen, Dong Ma Nov 2024

Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo Hu, Xiao Ma, Xinger Huang, Yiran Shen, Dong Ma

Research Collection School Of Computing and Information Systems

The increasing use of earbuds in applications like immersive entertainment and health monitoring necessitates effective implicit user authentication systems to preserve the privacy of sensitive data and provide personalized experiences. Existing approaches, which leverage physiological cues (e.g., jawbone structure) and behavioral cues (e.g., gait), face challenges such as limited usability, high delay and energy overhead, and significant computational demands, rendering them impractical for resource-constrained earbuds. To address these issues, we present LR-Auth, a lightweight, user-friendly implicit authentication system designed for various earbud usage scenarios. LR-Auth utilizes the modulation of sound frequencies by the user's unique occluded ear canal, generating user-specific …


Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous Nov 2024

Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous

Dissertations

With the increase in popularity of online communities, such as social media platforms, online games, and chatroom servers, there is a need to improve chat and content moderation. Platforms have reported an increase in the prevalence of toxic behavior and hate speech. Meanwhile, moderators are reporting difficulties in keeping up with the amount of data to check as well and the type of content they are exposed to, which further harms their own mental health. The main objective of this work is to address the challenges that exist within online communities with the rising prevalence of hate speech. Additionally, some …


Maritime Behaviour Anomaly Detection With Seasonal Context, Travis Rybicki, Martin Masek, Chiou Peng Lam Oct 2024

Maritime Behaviour Anomaly Detection With Seasonal Context, Travis Rybicki, Martin Masek, Chiou Peng Lam

Research outputs 2022 to 2026

Monitoring maritime traffic has become an important task for ensuring the safety of vessels, as well as the goods, and persons that they may be transporting. An active area of research is the modelling of expected normal vessel behaviour so as to detect subsequent anomalies in new data. Anomalies indicate that a vessel is not behaving in an expected manner and their detection can be flagged for further investigation to identify whether the vessel needs assistance or intervention. An important factor for some vessels in determining normal behaviour is seasonal context. However, current approaches typically do not incorporate seasonality into …


Wormhole Attack Mitigation In Wireless Network Using Propagation Delay, Harry May, Travis Atkison Oct 2024

Wormhole Attack Mitigation In Wireless Network Using Propagation Delay, Harry May, Travis Atkison

Journal of Cybersecurity Education, Research and Practice

This paper presents a novel approach for mitigating wormhole attacks on wireless networks using propagation delay timing. The wormhole attack is a persistent security threat that threatens the integrity of network communications, potentially leading to data theft or other malicious activities. While various methods exist for combating wormhole attacks, our approach offers advantages that set it apart. Our approach involves a combination of proactive and reactive measures, harnessing box plot analysis and weighting factor techniques to identify and isolate outlier node links effectively. Unlike traditional methods, our solution not only detects outlier links but also defines dynamic weighting factors, providing …


Happy Hours, Not Office Hours: Socially Engaging Cybersecurity Students In A Large Online Graduate Course, James T. Mccafferty Oct 2024

Happy Hours, Not Office Hours: Socially Engaging Cybersecurity Students In A Large Online Graduate Course, James T. Mccafferty

Journal of Cybersecurity Education, Research and Practice

Engagement is a critical part of student learning and student success. This is especially true in online classes where students have less interaction with their classmates and instructors when compared to traditional face-to-face courses. Research on engagement has shown that when students are meaningfully engaged it can increase student satisfaction and it may also increase levels of academic achievement, including grades earned and degree progression (e.g. Wong et al., 2024). This paper focuses on social engagement in a graduate cybersecurity program that uses large, expandable online courses as described by Whitman and Mattord (2023). Large online graduate classes (i.e., more …


2024 Gateway Magazine, College Of Computing, Michigan Technological University Oct 2024

2024 Gateway Magazine, College Of Computing, Michigan Technological University

College of Computing Annual Magazines

Table of Contents

  • 50 Years of Computer Science at Michigan Tech
  • Data Science for a Changing Planet
  • Healthcare Transformed
  • Mechatronics Matters
  • Powered by Michigan Tech Talent
  • Esports: Bringing Everything Great about Sports to More People
  • The Michigander Scholars Program: Electrifying Careers in Michigan
  • College of Computing News


A Survey Of Advanced Border Gateway Protocol Attack Detection Techniques, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk Oct 2024

A Survey Of Advanced Border Gateway Protocol Attack Detection Techniques, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk

Research outputs 2022 to 2026

The Internet's default inter-domain routing system, the Border Gateway Protocol (BGP), remains insecure. Detection techniques are dominated by approaches that involve large numbers of features, parameters, domain-specific tuning, and training, often contributing to an unacceptable computational cost. Efforts to detect anomalous activity in the BGP have been almost exclusively focused on single observable monitoring points and Autonomous Systems (ASs). BGP attacks can exploit and evade these limitations. In this paper, we review and evaluate categories of BGP attacks based on their complexity. Previously identified next-generation BGP detection techniques remain incapable of detecting advanced attacks that exploit single observable detection approaches …


Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings Oct 2024

Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings

Research & Publications

Digital engineering practices offer significant yet underutilized potential for improving information assurance and system lifecycle management. This paper examines how capabilities like model-based engineering, digital threads, and integrated product lifecycles can address gaps in prevailing frameworks. A reference model demonstrates applying digital engineering techniques to a reference information system, exhibiting enhanced traceability, risk visibility, accuracy, and integration. The model links strategic needs to requirements and architecture while reusing authoritative elements across views. Analysis of the model shows digital engineering closes gaps in compliance, monitoring, change management, and risk assessment. Findings indicate purposeful digital engineering adoption could transform cybersecurity, operations, service …


Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan Oct 2024

Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan

Research & Publications

As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …


Resilient Tcp Variant Enabling Smooth Network Updates For Software-Defined Data Center Networks, Abdul Basit Dogar, Sami Ullah, Yiran Zhang, Hisham Alasmary, Muhammad Waqas, Sheng Chen Oct 2024

Resilient Tcp Variant Enabling Smooth Network Updates For Software-Defined Data Center Networks, Abdul Basit Dogar, Sami Ullah, Yiran Zhang, Hisham Alasmary, Muhammad Waqas, Sheng Chen

Research outputs 2022 to 2026

Network updates have become increasingly prevalent since the broad adoption of software-defined networks (SDNs) in data centers. Modern TCP designs, including cutting-edge TCP variants DCTCP, CUBIC, and BBR, however, are not resilient to network updates that provoke flow rerouting. In this paper, we first demonstrate that popular TCP implementations perform inadequately in the presence of frequent and inconsistent network updates, because inconsistent and frequent network updates result in out-of-order packets and packet drops induced via transitory congestion and lead to serious performance deterioration. We look into the causes and propose a network update-friendly TCP (NUFTCP), which is an extension of …


Navigating Governance Paradigms: A Cross-Regional Comparative Study Of Generative Ai Governance Processes & Principle, Jose Luna, Ivan Tan, Xiaofei Xie, Lingxiao Jiang Oct 2024

Navigating Governance Paradigms: A Cross-Regional Comparative Study Of Generative Ai Governance Processes & Principle, Jose Luna, Ivan Tan, Xiaofei Xie, Lingxiao Jiang

Research Collection School Of Computing and Information Systems

As Generative Artificial Intelligence (GenAI) technologies evolve at an unprecedented rate, global governance approaches struggle to keep pace with the technology, highlighting a critical issue in the governance adaptation of significant challenges. Depicting the nuances of nascent and diverse governance approaches based on risks, rules, outcomes, principles, or a mix across different regions around the globe is fundamental to discern discrepancies and convergences and to shed light on specific limitations that need to be addressed, thereby facilitating the safe and trustworthy adoption of GenAI. In response to the need and the evolving nature of GenAI, this paper seeks to provide …


On The Lossiness Of 2k-Th Power And The Instantiability Of Rabin-Oaep, Haiyang Xue, Bao Li, Xianhui Lu, Kunpeng Wang, Yamin Liu Oct 2024

On The Lossiness Of 2k-Th Power And The Instantiability Of Rabin-Oaep, Haiyang Xue, Bao Li, Xianhui Lu, Kunpeng Wang, Yamin Liu

Research Collection School Of Computing and Information Systems

Seurin PKC 2014 proposed the 2-ï /4-hiding assumption which asserts the indistinguishability of Blum Numbers from pseudo Blum Numbers. In this paper, we investigate the lossiness of 2 k -th power based on the 2 k -ï /4-hiding assumption, which is an extension of the 2-ï /4-hiding assumption. And we prove that 2 k -th power function is a lossy trapdoor permutation over Quadratic Residuosity group. This new lossy trapdoor function has 2 k -bits lossiness for k -bits exponent, while the RSA lossy trapdoor function given by Kiltz et al. Crypto 2010 has k -bits lossiness for k -bits …


Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang, Rui Zhang, Binbin Chen, Xiangyang Luo, Ming Hu, Wenrui Ma Oct 2024

Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang, Rui Zhang, Binbin Chen, Xiangyang Luo, Ming Hu, Wenrui Ma

Research Collection School Of Computing and Information Systems

Anomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. …


Direct Range Proofs For Paillier Cryptosystem And Their Applications, Zhikang Xie, Mengling Liu, Haiyang Xue, Man Ho Au, Robert H. Deng, Siu-Ming Yiu Oct 2024

Direct Range Proofs For Paillier Cryptosystem And Their Applications, Zhikang Xie, Mengling Liu, Haiyang Xue, Man Ho Au, Robert H. Deng, Siu-Ming Yiu

Research Collection School Of Computing and Information Systems

The Paillier cryptosystem is renowned for its applications in electronic voting, threshold ECDSA, multi-party computation, and more, largely due to its additive homomorphism. In these applications, range proofs for the Paillier cryptosystem are crucial for maintaining security, because of the mismatch between the message space in the Paillier system and the operation space in application scenarios. In this paper, we present novel range proofs for the Paillier cryptosystem, specifically aimed at optimizing those for both Paillier plaintext and affine operation. We interpret encryptions and affine operations as commitments over integers, as opposed to solely over ZN. Consequently, we propose direct …


A Survey Of Protocol Fuzzing, Xiaohan Zhang, Cen Zhang, Xinghua Li, Zhengjie Du, Bing Mao, Yeting Li, Pan Li Oct 2024

A Survey Of Protocol Fuzzing, Xiaohan Zhang, Cen Zhang, Xinghua Li, Zhengjie Du, Bing Mao, Yeting Li, Pan Li

Research Collection School Of Computing and Information Systems

Communication protocols form the bedrock of our interconnected world, yet vulnerabilities within their implementations pose significant security threats. Recent developments have seen a surge in fuzzing-based research dedicated to uncovering these vulnerabilities within protocol implementations. However, there still lacks a systematic overview of protocol fuzzing for answering the essential questions such as what the unique challenges are, how existing works solve them, and so on. To bridge this gap, we conducted a comprehensive investigation of related works from both academia and industry. Our study includes a detailed summary of the specific challenges in protocol fuzzing and provides a systematic categorization …


Leveraging Propagation Delay For Wormhole Detection In Wireless Networks, Harry May, Travis Atkison Sep 2024

Leveraging Propagation Delay For Wormhole Detection In Wireless Networks, Harry May, Travis Atkison

Journal of Cybersecurity Education, Research and Practice

Detecting and mitigating wormhole attacks in wireless networks remains a critical challenge due to their deceptive nature and potential to compromise network integrity. This paper proposes a novel approach to wormhole detection by leveraging propagation delay analysis between network nodes. Unlike traditional methods that rely on signature-based detection or specialized hardware, our method focuses on analyzing propagation delay timings to identify anomalous behavior indicative of wormhole attacks. The proposed methodology involves collecting propagation delay data in both normal network scenarios and scenarios with inserted malicious wormhole nodes. By comparing these delay timings, our approach aims to differentiate between legitimate network …


How State Universities Are Addressing The Shortage Of Cybersecurity Professionals In The United States, Gary Harris Sep 2024

How State Universities Are Addressing The Shortage Of Cybersecurity Professionals In The United States, Gary Harris

Journal of Cybersecurity Education, Research and Practice

Cybersecurity threats have been a serious and growing problem for decades. In addition, a severe shortage of cybersecurity professionals has been proliferating for nearly as long. These problems exist in the United States and globally and are well documented in literature. This study examined what state universities are doing to help address the shortage of cybersecurity professionals since higher education institutions are a primary source to the workforce pipeline. It is suggested that the number of cybersecurity professionals entering the workforce is related to the number of available programs. Thus increasing the number of programs will increase the number of …


Cyber Victimization In The Healthcare Industry: Analyzing Offender Motivations And Target Characteristics Through Routine Activities Theory (Rat) And Cyber-Routine Activities Theory (Cyber-Rat), Yashna Praveen, Mijin Kim, Kyung-Shick Choi Sep 2024

Cyber Victimization In The Healthcare Industry: Analyzing Offender Motivations And Target Characteristics Through Routine Activities Theory (Rat) And Cyber-Routine Activities Theory (Cyber-Rat), Yashna Praveen, Mijin Kim, Kyung-Shick Choi

International Journal of Cybersecurity Intelligence & Cybercrime

The integration of computer technology in healthcare has revolutionized patient care but has also introduced significant cyber risks. Despite the healthcare sector being a primary target for cyber-attacks, research on the dynamics of these threats and practical solutions remains limited. Understanding the complexities of cyberattacks in this sector is critical, as the impact extends beyond financial losses to directly affect patient care and the protection of sensitive information. This paper applies Routine Activities Theory (RAT) and Cyber Routine Activities Theory (C-RAT) to analyze high-tech cyber victimization case studies in healthcare. The analysis explores the motivations behind these attacks and identifies …