Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

2025

Discipline
Institution
Keyword
Publication
Publication Type
File Type

Articles 181 - 205 of 205

Full-Text Articles in Information Security

A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective, Sujatha Alla, Sai Gireesh Komaragiri, Teresa Duvall, Satluk Karahan, Nagesh Bheesetty, Vijay Kumar Chattu Jan 2025

A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective, Sujatha Alla, Sai Gireesh Komaragiri, Teresa Duvall, Satluk Karahan, Nagesh Bheesetty, Vijay Kumar Chattu

Engineering Management & Systems Engineering Faculty Publications

Healthcare systems face unprecedented security and privacy challenges due to increasing digitization and interconnectedness. This paper provides a comprehensive analysis of these challenges by examining various cyberattacks, defensive mechanisms, and governance frameworks within modern healthcare infrastructure. The research systematically categorizes prevalent security threats, such as ransomware, insider threats, and data breaches, identifying vulnerabilities specific to healthcare systems. Furthermore, the study evaluates current defensive strategies, including encryption techniques, access control systems, and intrusion detection tools, assessing their effectiveness against complex cyber threats. A key focus is placed on governance structures and their role in cybersecurity resilience. The research explores how regulatory …


Potsdam: Pareto Optimization Targeting Security, Data, And Mediation, J Peter Brady Jan 2025

Potsdam: Pareto Optimization Targeting Security, Data, And Mediation, J Peter Brady

Dartmouth College Ph.D Dissertations

Given the growing amount and variety of data handled by modern systems, it is crucial to guarantee the accuracy and protection of input data without errors or malicious intentions. The need to improve security in software programs often conflicts with the assurance of maximum performance, making developers and maintainers hesitant to incorporate more testing.

LangSec (Language-Theoretic Security) is a security approach that treats input validation as a formal language recognition problem, ensuring that only well-defined, unambiguous inputs are processed to eliminate exploitable parsing flaws. This dissertation explores integrating LangSec principles with Pareto optimization to enhance safety and robustness in digital …


Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu Jan 2025

Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu

Engineering Management & Systems Engineering Faculty Publications

Port infrastructures are critical to global trade, handling over 80% of the world's cargo by volume. However, their increasing reliance on digital technologies has exposed them to a wide range of cyber threats. This paper provides a comprehensive analysis of cyberattacks targeting port infrastructures from 2011 to the present. We examine the types of attacks, geographical distribution, notable incidents, and underlying vulnerabilities. Additionally, we discuss mitigation strategies and future directions for enhancing cybersecurity in the maritime sector. Our findings highlight the urgent need for robust regulatory frameworks, advanced technological solutions, and collaborative efforts to safeguard critical port operations.


The Effectiveness Of Tech Support Fraud In Damaging Older Individual’S Financial Security, Vanessa Perera Jan 2025

The Effectiveness Of Tech Support Fraud In Damaging Older Individual’S Financial Security, Vanessa Perera

Theses : Honours

This study discovers the tactics employed to create detrimental effects upon older people impacted from fraudulent tech-support incidents. It examines social engineering, and financial confusion of older people. This is significant considering adaptations towards digital banking and payment management. This research looked at online and active over 65s. Using largely qualitative approaches over 65s were interviewed and responses validated against cyber-professionals’ responses. This identified three key findings: older adults feel confused and misunderstand tech support scams; threat actors build trust by pretending to offer technical help but use this to deceive their victims; and older adults face serious social and …


Building Cyber Resilience: Educational Programs In K-12 Education, Mildred Jones, Vukica Jovanovic, Petros Katsioloudis Jan 2025

Building Cyber Resilience: Educational Programs In K-12 Education, Mildred Jones, Vukica Jovanovic, Petros Katsioloudis

Engineering Technology Faculty Publications

The article discusses the challenges of teaching cybersecurity in K-12 education. Topics mentioned include the lack of access to resources and appropriate professional development, the career and technical education cybersecurity pathways, the fundamental pathways for cybersecurity and information technology and the results of program evaluation in several local community high schools from 2021 and 2022.


Attribute-Based Encryption With Searchable Encryption, Yang Yang Jan 2025

Attribute-Based Encryption With Searchable Encryption, Yang Yang

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) with searchable encryption is a notion that inherits the advantages of both ABE (Goyal et al., 2006) and searchable encryption (SE) (Boneh et al., 2004; Boneh and Waters, 2007) mechanisms to realize secure share and search for the outsourced data. ABE creates fine-grained access control system to prevent sensitive data from being accessed by unauthorized user or external attacker (Bethencourt et al., 2007). SE generates encrypted index for outsourced data such that it can be searched by a keyword trapdoor (or token) (Shi et al., 2007; Naveed et al., 2014), where the outsourced content and search keyword(s) …


Including Individuals' Sense Of Self In Digital Information Privacy, Peter N. Meso, Solomon Negash, Humayun Zafar, Gurpreet Dhillon Jan 2025

Including Individuals' Sense Of Self In Digital Information Privacy, Peter N. Meso, Solomon Negash, Humayun Zafar, Gurpreet Dhillon

Faculty Articles

The nature of contemporary digital ecosystems causes concerns that affect the person, the individual-self, an integral part of an individual’s information privacy calculus and hence a component of individuals’ Information Privacy Concerns (IPC). Yet, prior IPC models overlook self-focused concerns. This study articulates two constructs, termed “loss of autonomy” (i.e., autonomy) and “control over profiling” (i.e., profiling), that reflect individuals’ self-focused privacy concerns. Combining these new constructs with conventional IPC constructs that capture data-focused and device-focused concerns yields an IPC model made up of three dimensions: self-focused concerns, data-focused concerns, and device-focused concerns. The authors first develop instrument items for …


Navigating The Digital Frontier: New Perspectives On Cybercrime And Governance, Christopher S. Kayser, Thomas Dearden, Katalin Parti, Sinyong Choi Jan 2025

Navigating The Digital Frontier: New Perspectives On Cybercrime And Governance, Christopher S. Kayser, Thomas Dearden, Katalin Parti, Sinyong Choi

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


Modus Operandi And Blockchain Analysis Of Romance Scams: Cryptocurrency-Driven Victimization, Amy Lim, Kyung-Shick Choi Jan 2025

Modus Operandi And Blockchain Analysis Of Romance Scams: Cryptocurrency-Driven Victimization, Amy Lim, Kyung-Shick Choi

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


The Legal Response To The Intrusion Into Digital Identity In Social Media, Maria González-García Vinuela Jan 2025

The Legal Response To The Intrusion Into Digital Identity In Social Media, Maria González-García Vinuela

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


A Study Of Pattern Of Cybercrime Abuse Of Individual Internet Users In Umuahia North Lga, Abia State Of South-Eastern Nigeria, Ogochukwu Favour Nzeakor, Rita Ngozi Okafor, Chibuike Ndubuisi Nwoke Jan 2025

A Study Of Pattern Of Cybercrime Abuse Of Individual Internet Users In Umuahia North Lga, Abia State Of South-Eastern Nigeria, Ogochukwu Favour Nzeakor, Rita Ngozi Okafor, Chibuike Ndubuisi Nwoke

International Journal of Cybersecurity Intelligence & Cybercrime

Although a number of studies exist on cybercrime and its abuses, little is known about the pattern of cybercrime abuses individual Internet users experience in Nigeria, especially the south eastern region. Using data collected via various methods, this study examines the pattern of cybercrime abuses of individual Internet users in Umuahia, Abia State, of South Eastern Nigeria. The result of the analysis of 1,067 samples drawn from 223,134 Internet users in Umuahia North LGA of Abia Sate showed that: while most users are victims of stolen ICT-gadgets (19%), fraud related offences (17%), and hacking (15%); they rarely fall victims of …


Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen Jan 2025

Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The static nature of traditional military symbology, such as MIL-STD-2525D, hinders effective real-time threat detection and response in modern cybersecurity operations. This research introduces the Dynamic Adaptive Symbol System (DASS), a novel framework enhancing cyber situational awareness in military and enterprise environments. The DASS addresses static symbology limitations by employing a modular Python 3.10 architecture that uses machine learning-driven threat detection to dynamically adapt symbol visualization based on threat severity and context. Empirical testing assessed the DASS against a MIL-STD-2525D baseline using active cybersecurity professionals. Results show that the DASS significantly improves threat identification rates by 30% and reduces response …


Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu Jan 2025

Privshap: A Finer-Granularity Network Linearization Method For Private Inference, Xiangrui Xu, Zhenzhen Wang, Rui Ning, Chunsheng Xiu, Hongyi Wu

Computer Science Faculty Publications

Private inference applies cryptographic techniques like homomorphic encryption, garble circuit and secret sharing to keep both sides privacy in a client-server setting during inference. It is often hindered by the high communication overheads, especially at non-linear activation layers such as ReLU. Hence ReLU pruning has been widely recognized as an efficient way to accelerate private inference. Existing approaches to ReLU pruning typically rely on coarse hypothesis, which assume an inverse correlation between the importance of ReLU and linear layers or shallow activation layers have less importance for universal models, to assign the budgets according to the layer while preserving the …


Not Here, Go There: Analyzing Redirection Patterns On The Web, Kritika Garg, Sawood Alam, Dietrich Ayala, Michele C. Weigle, Michael L. Nelson Jan 2025

Not Here, Go There: Analyzing Redirection Patterns On The Web, Kritika Garg, Sawood Alam, Dietrich Ayala, Michele C. Weigle, Michael L. Nelson

Computer Science Faculty Publications

URI redirections are integral to web management, supporting structural changes, SEO optimization, and security. However, their complexities affect usability, SEO performance, and digital preservation. This study analyzed 11 million unique redirecting URIs, following redirections up to 10 hops per URI, to uncover patterns and implications of redirection practices. Our findings revealed that 50% of the URIs terminated successfully, while 50% resulted in errors, including 0.06% exceeding 10 hops. Canonical redirects, such as HTTP to HTTPS transitions, were prevalent, reflecting adherence to SEO best practices. Non-canonical redirects, often involving domain or path changes, highlighted significant web migrations, rebranding, and security risks. …


Position: Benchmarking Is Broken - Don't Let Ai Be Its Own Judge, Zerui Cheng, Stella Wohnig, Ruchika Gupta, Samiul Alam, Tassallah Abdullahi, João Alves Ribeiro, Christian Nielsen-Garcia, Saif Mir, Siran Li, Jason Orender, Seyed Ali Bahrainian, Daniel Kirste, Aaron Gokaslan, Carsten Eickhoff, Pramod Viswanath, Ruben Wolff Jan 2025

Position: Benchmarking Is Broken - Don't Let Ai Be Its Own Judge, Zerui Cheng, Stella Wohnig, Ruchika Gupta, Samiul Alam, Tassallah Abdullahi, João Alves Ribeiro, Christian Nielsen-Garcia, Saif Mir, Siran Li, Jason Orender, Seyed Ali Bahrainian, Daniel Kirste, Aaron Gokaslan, Carsten Eickhoff, Pramod Viswanath, Ruben Wolff

Computer Science Faculty Publications

The meteoric rise of Artificial Intelligence (AI), with its rapidly expanding market capitalization, presents both transformative opportunities and critical challenges. Chief among these is the urgent need for a new, unified paradigm for trustworthy evaluation, as current benchmarks increasingly reveal critical vulnerabilities. Issues like data contamination and selective reporting by model developers fuel hype, while inadequate data quality control can lead to biased evaluations that, even if unintentionally, may favor specific approaches. As a flood of participants enters the AI space, this "Wild West" of assessment makes distinguishing genuine progress from exaggerated claims exceptionally difficult. Such ambiguity blurs scientific signals …


Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh Jan 2025

Sting: A Stealthy Backdoor Attack On Gnn-Based Malicious Domain Detection Via Dns Perturbations, Muhammad Anan, Mahmoud Nazzal, Abdallah Khreishah, Issa Khalil, Nhathai Phan, Ahmad Sawalmeh

Computer Science Faculty Publications

Detecting malicious Internet domains is essential for safeguarding against various online threats. The current approach to detecting malicious domains (MDD) employs a graph neural network (GNN) method, which uses DNS logs to construct heterogeneous graphs for determining the maliciousness of unknown domains. Despite its success, this method is vulnerable to data poisoning attacks where an adversary can manipulate specific graph nodes to implant a backdoor into the model during training. To showcase the vulnerability, we propose a stealthy trigger injection attack on node features and graph structure in MDD, dubbed (STING). The attacker carefully manipulates selected features and edges of …


Adversarially Attacking Graph Properties And Sparsification In Graph Learning, Chunjiang Zhu, Blake Gaines, Jing Deng, Jinbo Bi Jan 2025

Adversarially Attacking Graph Properties And Sparsification In Graph Learning, Chunjiang Zhu, Blake Gaines, Jing Deng, Jinbo Bi

Computer Science Faculty Publications

Graph neural networks and graph transformers explicitly or implicitly rely on fundamental properties of the underlying graph, such as spectral properties and shortest-path distances. However, it is still not clear how these graph properties are vulnerable to adversarial attacks and what impacts this has on the downstream graph learning. Moreover, while graph sparsification has been used to improve computational cost of learning over graphs, its susceptibility to adversarial attacks has not been studied. In this paper, we study adversarial attacks on graph properties and graph sparsification and their impacts on downstream graph learning, paving the way for how to protect …


Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li Jan 2025

Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li

Computer Science Faculty Publications

Large Language Models (LLMs) exhibit strong natural language processing capabilities but also pose significant privacy risks, particularly regarding the leakage of Personally Identifiable Information (PII) embedded in their training data. Existing PII extraction methods suffer from the limitations of low success rates or impracticality for large-scale PII extraction. In this study, we propose a novel PII extraction approach based on enhanced few-shot learning techniques, which achieves efficient and cost-effective PII retrieval without relying on fine-tuning or jailbreaking. We evaluated our approach on both open-source and closed-source LLMs. The experimental results demonstrate that, for non-targeted PII extraction, the attack success rate …


Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang Jan 2025

Understanding Pii Leakage In Large Language Models: A Systematic Survey, Shuai Cheng, Zhao Li, Shu Meng, Mengxia Ren, Haitao Xu, Shuai Hao, Chuan Yue, Fang Zhang

Computer Science Faculty Publications

Large Language Models (LLMs) have demonstrated exceptional success across a variety of tasks, particularly in natural language processing, leading to their growing integration into numerous facets of daily life. However, this widespread deployment has raised substantial privacy concerns, especially regarding personally identifiable information (PII), which can be directly associated with specific individuals. The leakage of such information presents significant real-world privacy threats. In this paper, we conduct a systematic investigation into existing research on PII leakage in LLMs, encompassing commonly utilized PII datasets, evaluation metrics, and current studies on both PII leakage attacks and defensive strategies. Finally, we identify unresolved …


Machine Learning For Computer-Aided Diagnostics From Complex Medical Images, Afsah Saleem Jan 2025

Machine Learning For Computer-Aided Diagnostics From Complex Medical Images, Afsah Saleem

Theses: Doctorates and Masters

Machine learning has significantly transformed medical image analysis in the current age of artificial intelligence offering vast potential in improving disease diagnosis and management. Cardiovascular diseases (CVDs) are among the leading cause of global mortality, emphasizing the need for early detection for effective intervention and prevention. Abdominal Aortic Calcification (AAC) is an early indicator and contributor to Atherosclerotic Cardiovascular Diseases (ASCVDs) and is commonly assessed through imaging modalities such as computed tomography (CT), X-rays, and Dual-energy X-ray Absorptiometry (DXA). Among these, lateral spine DXA scans, commonly used for osteoporosis screening, offer a cost-effective and low-radiation opportunity for opportunistic CVD risk …


Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang Jan 2025

Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang

Electronic Theses & Dissertations (2024 - present)

The increasing frequency and severity of ransomware attacks pose significant challenges for organizational cybersecurity. Fragmentation across disciplines in cyber defense has created practical gaps in the development of the necessary capabilities needed to address rapidly evolving cyber threats. This study explores the impact of ransomware attacks and the evolving role of cyber insurance as a proactive cybersecurity partner. Bridging the gap between actuarial science and cyber risk management, it proposes an interdisciplinary framework that quantifies the impact of ransomware and integrates cyber insurance into cybersecurity strategies.

The primary contribution of this study is methodology. We present a framework that remains …


Zero Day Ransomware Detection With Pulse: Function Classification With Transformer Models And Assembly Language, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke Jan 2025

Zero Day Ransomware Detection With Pulse: Function Classification With Transformer Models And Assembly Language, Matthew Gaber, Mohiuddin Ahmed, Helge Janicke

Research outputs 2022 to 2026

Finding automated AI techniques to proactively defend against malware has become increasingly critical. The ability of an AI model to correctly classify novel malware is dependent on the quality of the features it is trained with and the authenticity of the features is dependent on the analysis tool. Peekaboo, a Dynamic Binary Instrumentation tool defeats evasive malware to capture its genuine behaviour. The ransomware Assembly instructions captured by Peekaboo, follow Zipf's law, a principle also observed in natural languages, indicating Transformer models are particularly well-suited to binary classification. We propose Pulse, a novel framework for zero day ransomware detection with …


Blockchain-Based Trust Model For Inter-Domain Routing, Qiong Yang, Li Ma, Sami Ullah, Shanshan Tu, Hisham Alasmary, Muhammad Waqas Jan 2025

Blockchain-Based Trust Model For Inter-Domain Routing, Qiong Yang, Li Ma, Sami Ullah, Shanshan Tu, Hisham Alasmary, Muhammad Waqas

Research outputs 2022 to 2026

Border Gateway Protocol (BGP), as the standard inter-domain routing protocol, is a distance-vector dynamic routing protocol used for exchanging routing information between distributed Autonomous Systems (AS). BGP nodes, communicating in a distributed dynamic environment, face several security challenges, with trust being one of the most important issues in inter-domain routing. Existing research, which performs trust evaluation when exchanging routing information to suppress malicious routing behavior, cannot meet the scalability requirements of BGP nodes. In this paper, we propose a blockchain-based trust model for inter-domain routing. Our model achieves scalability by allowing the master node of an AS alliance to transmit …


Joint 3d Beamforming-And-Trajectory Design For Uav-Satellite Uplink Covert Communication, Jihong Yu, Yuting Cai, Shihao Yan, Yun Li, Jingjing Wang, Jiahao Liu, Jianping An Jan 2025

Joint 3d Beamforming-And-Trajectory Design For Uav-Satellite Uplink Covert Communication, Jihong Yu, Yuting Cai, Shihao Yan, Yun Li, Jingjing Wang, Jiahao Liu, Jianping An

Research outputs 2022 to 2026

In this paper,we study uplink covert communication in a space-air system,where an unmanned aerial vehicle (UAV) transmits sensitive data to a Geosynchronous Earth Orbit (GEO) satellite while preventing the transmission action from being discovered by a warden. We derive the optimal decision threshold of the warden. We investigate the 3-dimensional (3D) beamformer and 3D trajectory design for the transmitter UAV against this optimum warden to maximize the covert transmission rate in the presence of imperfect channel state information and uncertain noise. Due to the non-convex structure and dependence between beamforming vectors and locations of the transmitter UAV,we develop a decoupling …


Enhancing Cybersecurity Through Autonomous Knowledge Graph Construction By Integrating Heterogeneous Data Sources, Hatoon Alharbi, Ali Hur, Hasan Alkahtani, Hafiz Farooq Ahmad Jan 2025

Enhancing Cybersecurity Through Autonomous Knowledge Graph Construction By Integrating Heterogeneous Data Sources, Hatoon Alharbi, Ali Hur, Hasan Alkahtani, Hafiz Farooq Ahmad

Research outputs 2022 to 2026

Cybersecurity plays a critical role in today’s modern human society, and leveraging knowledge graphs can enhance cybersecurity and privacy in the cyberspace. By harnessing the heterogeneous and vast amount of information on potential attacks, organizations can improve their ability to proactively detect and mitigate any threat or damage to their online valuable resources. Integrating critical cyberattack information into a knowledge graph offers a significant boost to cybersecurity, safeguarding cyberspace from malicious activities. This information can be obtained from structured and unstructured data, with a particular focus on extracting valuable insights from unstructured text through natural language processing (NLP). By storing …