Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Discipline
Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 1951 - 1980 of 4669

Full-Text Articles in Information Security

Cybersecurity For Critical Infrastructure: Addressing Threats And Vulnerabilities In Canada, Samuel A. Cohen May 2019

Cybersecurity For Critical Infrastructure: Addressing Threats And Vulnerabilities In Canada, Samuel A. Cohen

Graduate Theses/Dissertations

The aim of this thesis is to assess the unique technical and policy-based cybersecurity challenges facing Canada’s critical infrastructure environment and to analyze how current government and industry practices are not equipped to remediate or offset associated strategic risks to the country. Further, the thesis also provides cases and evidence demonstrating that Canada’s critical infrastructure has been specifically targeted by foreign and domestic cyber threat actors to pressure the country’s economic, safety and national security interests. Essential services that Canadians and Canadian businesses rely on daily are intricately linked to the availability and integrity of vital infrastructure sectors, such as …


Forensic Analysis Of Spy Applications In Android Devices, Shinelle Hutchinson, Umit Karabiyik May 2019

Forensic Analysis Of Spy Applications In Android Devices, Shinelle Hutchinson, Umit Karabiyik

Annual ADFSL Conference on Digital Forensics, Security and Law

Smartphones with Google's Android operating system are becoming more and more popular each year, and with this increased user base, comes increased opportunities to collect more of these users' private data. There have been several instances of malware being made available via the Google Play Store, which is one of the predominant means for users to download applications. One effective way of collecting users' private data is by using Android Spyware. In this paper, we conduct a forensic analysis of a malicious Android spyware application and present our findings. We also highlight what information the application accesses and what it …


Assessing Code Obfuscation Of Metamorphic Javascript, Kaushik Murli May 2019

Assessing Code Obfuscation Of Metamorphic Javascript, Kaushik Murli

Master's Projects

Metamorphic malware is one of the biggest and most ubiquitous threats in the digital world. It can be used to morph the structure of the target code without changing the underlying functionality of the code, thus making it very difficult to detect using signature-based detection and heuristic analysis. The focus of this project is to analyze Metamorphic JavaScript malware and techniques that can be used to mutate the code in JavaScript. To assess the capabilities of the metamorphic engine, we performed experiments to visualize the degree of code morphing. Further, this project discusses potential methods that have been used to …


Cptc - A Security Competition Unlike Any Other, Bill Stackpole, Daryl Johnson May 2019

Cptc - A Security Competition Unlike Any Other, Bill Stackpole, Daryl Johnson

Presentations and other scholarship

Participating in cybersecurity competitions has become increasing popular for students in higher education programs that have a focus on computing or cyber security. The Collegiate Penetration Testing Competition was developed to address the industry skills gap and assist in identifying ethically minded security personnel with experience identifying, exercising, and mitigating vulnerabilities.


Analysis Of Computer Audit Data To Create Indicators Of Compromise For Intrusion Detection, Steven Millett, Michael Toolin, Justin Bates May 2019

Analysis Of Computer Audit Data To Create Indicators Of Compromise For Intrusion Detection, Steven Millett, Michael Toolin, Justin Bates

SMU Data Science Review

Network security systems are designed to identify and, if possible, prevent unauthorized access to computer and network resources. Today most network security systems consist of hardware and software components that work in conjunction with one another to present a layered line of defense against unauthorized intrusions. Software provides user interactive layers such as password authentication, and system level layers for monitoring network activity. This paper examines an application monitoring network traffic that attempts to identify Indicators of Compromise (IOC) by extracting patterns in the network traffic which likely corresponds to unauthorized access. Typical network log data and construct indicators are …


Intrusion-Tolerant Order-Preserving Encryption, John Huson May 2019

Intrusion-Tolerant Order-Preserving Encryption, John Huson

Masters Theses, 2010-2019

Traditional encryption schemes such as AES and RSA aim to achieve the highest level of security, often indistinguishable security under the adaptive chosen-ciphertext attack. Ciphertexts generated by such encryption schemes do not leak useful information. As a result, such ciphertexts do not support efficient searchability nor range queries.

Order-preserving encryption is a relatively new encryption paradigm that allows for efficient queries on ciphertexts. In order-preserving encryption, the data-encrypting key is a long-term symmetric key that needs to stay online for insertion, query and deletion operations, making it an attractive target for attacks.

In this thesis, an intrusion-tolerant order-preserving encryption system …


Managing The Power And Pitfalls Of Data In Ai, Singapore Management University May 2019

Managing The Power And Pitfalls Of Data In Ai, Singapore Management University

Perspectives@SMU

Ethics and education are crucial in maintaining data privacy and augmenting human ability

“It’s difficult to imagine the power that you’re going to have when so many different sorts of data are available.” – Tim Berners-Lee, father of the Internet

“Before Google, and long before Facebook, Bezos had realised that the greatest value of an online company lay in the consumer data it collected.” – George Packer, author for the New Yorker


“Greening” Worcester: Municipal Best Practices For Sustainability, Erin Mckeon, Charline Kirongozi, Jared Duval, Antannia Greene, Qianshu Sun, Zewei Yao May 2019

“Greening” Worcester: Municipal Best Practices For Sustainability, Erin Mckeon, Charline Kirongozi, Jared Duval, Antannia Greene, Qianshu Sun, Zewei Yao

School of Professional Studies

In response to the urgent threat posed by climate change, more and more cities, including Worcester, are attempting to become more environmentally responsible and sustainable. Worcester is attempting to develop ways to become more sustainable; both to strengthen their communities and to protect the planet. The Green Worcester Working Group (GWWG) tasked the Clark Capstone Team with researching best practices for municipal sustainability. The GWWG has set the following priorities: climate change mitigation, resilience, open spaces, sustainable resource management, education and awareness. Taking these into account, the Clark Capstone Team researched the sustainability practices of cities in New England, across …


Worcester Chamber Of Commerce: Recruiting Minority Business Owners, Ryan Dimaria, Alexander Hull, Xikun Lu, Haopeng Wang, Jiacheng Hou, Danning Zhao May 2019

Worcester Chamber Of Commerce: Recruiting Minority Business Owners, Ryan Dimaria, Alexander Hull, Xikun Lu, Haopeng Wang, Jiacheng Hou, Danning Zhao

School of Professional Studies

Our capstone project was to help the Worcester Regional Chamber of Commerce identify how to re-frame their marketing so it would be appealing to immigrant and minority owned businesses. Based on interviews and external research, our group was able to create a tangible and resourceful data set that provided justified recommendations and ideas on how the Chamber could make adjustments to their marketing plan to attract more businesses of this particular demographic in the city of Worcester. By implementing these recommendations, we believe the Chamber has the opportunity to create a more diverse group of Chamber members, add value to …


Service Now: Cmdb Research, Monika Patel, Smita Patil, Katerina Tzanavara, Manish Chauhan, Yuhao Wang, Houmin Xie, Lei Shi May 2019

Service Now: Cmdb Research, Monika Patel, Smita Patil, Katerina Tzanavara, Manish Chauhan, Yuhao Wang, Houmin Xie, Lei Shi

School of Professional Studies

The MAPFRE Capstone team has been tasked with reviewing and recommending roadmap on the existing CMDB configuration. Paper discusses the team’s overall research on ServiceNow CMDB, Client’s deliverables and introduction to the latest technological innovations. Based on given objectives and team’s analysis we have recommended key solutions for the client to better understand the IT environment areas of business service impact, asset management, compliance, and configuration management. In addition, our research has covered all the majority of the technical and functional areas to provide greater visibility and insight into existing CMDB and IT environment.


For One Child, Zion Bereket, Xin Huang, Yitong Lin, Ruobing Pei, Rachel White, Ziyuan Li May 2019

For One Child, Zion Bereket, Xin Huang, Yitong Lin, Ruobing Pei, Rachel White, Ziyuan Li

School of Professional Studies

The entirety of this project was completed on the foundation of the three focus areas, which were identified by our client as areas of high need. The client wanted to prioritize these three areas as they believed that these three areas were the most integral to the successful achievement of their mission, as well as to the overall health and longevity of the organization.


Hiv/Aids In The Latino Community Of San Francisco: Past And Present, Jessica Da Silva May 2019

Hiv/Aids In The Latino Community Of San Francisco: Past And Present, Jessica Da Silva

School of Professional Studies

There are approximately 122,000 people of Latino origin in San Francisco, which account for 15% of the total population (Census, 2010). Historically, Latinos have and still face several barriers to access healthcare and improvements in health (Aguirre-Molina, Molina & Zambrana, 2001). When the world was exposed to the spread of a new and unknown virus, the broader population suffered from the epidemic. The Latino community in San Francisco was and still is one of the hardest hit by the virus.


Changing The Current Perception Of Affordable Housing In Worcester, Simone Mcguinness, William Roberts, Vaske Gjino, Tong Zhou, Mengxin Ma, Sarawadee Sonpuak May 2019

Changing The Current Perception Of Affordable Housing In Worcester, Simone Mcguinness, William Roberts, Vaske Gjino, Tong Zhou, Mengxin Ma, Sarawadee Sonpuak

School of Professional Studies

One of Worcester Interfaith’s goals is to eradicate the stigma of affordable housing in Worcester. Currently, the perception of affordable housing is of an image of unkept and old residences filled with destitute citizens who cannot afford basic needs to live in a city, let alone housing. This image is perpetuated by media, stigma, and a lack of education of the true reality of affordable housing and who its recipients are. Affordable housing-qualified citizens represent a range of educations, professions, age, race, and income levels. Affordable housing units, too, represent a variety of homes, many of which are extremely well-kept …


A Privacy-Preserving Framework For Collaborative Association Rule Mining In Cloud, Salha Albehairi May 2019

A Privacy-Preserving Framework For Collaborative Association Rule Mining In Cloud, Salha Albehairi

Theses, Dissertations and Culminating Projects

Collaborative Data Mining facilitates multiple organizations to integrate their datasets and extract useful knowledge from their joint datasets for mutual benefits. The knowledge extracted in this manner is found to be superior to the knowledge extracted locally from a single organization’s dataset. With the rapid development of outsourcing, there is a growing interest for organizations to outsource their data mining tasks to a cloud environment to effectively address their economic and performance demands. However, due to privacy concerns and stringent compliance regulations, organizations do not want to share their private datasets neither with the cloud nor with other participating organizations. …


A Privacy-Aware Framework For Friend Recommendations In Online Social Networks, Mona Fahad Alkanhal May 2019

A Privacy-Aware Framework For Friend Recommendations In Online Social Networks, Mona Fahad Alkanhal

Theses, Dissertations and Culminating Projects

Online social networks (OSN), such as Facebook, Twitter, and LinkedIn, have revolutionized the way how people share information and stay connected with family and friends. Along this direction, user’s privacy has been a significant concern to all users in the social networks. In this thesis, we propose a privacyaware framework that allows users to outsource their encrypted profile data to a cloud environment. In order to achieve better security and efficiency, our framework utilizes a hybrid approach that consists of Paillier’s encryption scheme and AES. Furthermore, we develop a privacy-aware friend recommendation protocol that recommends new friends to social network …


The Golden Ticket: How Blockchain Technology Can Be Implemented Into Event Ticketing, Jack Singer May 2019

The Golden Ticket: How Blockchain Technology Can Be Implemented Into Event Ticketing, Jack Singer

Renée Crown University Honors Thesis Projects - All

When the group/individual named Satoshi Nakamoto first conceptualized blockchain in 2008, it served as the underlying foundation to the cryptocurrency Bitcoin. In the years following, cryptocurrencies alike experiences massive gains in profitability; however, after the bubble had burst organizations began to look at the technology from a more academic standpoint. It was quickly found out that there is a massive application for blockchain in almost all sectors of industry from bulk stores (Walmart) to banking (IBM). This paper will explore how blockchain technology can be implemented into event ticketing, more specifically concerts. The current landscape of the industry is under …


Federal, State And Local Law Enforcement Agency Interoperability Capabilities And Cyber Vulnerabilities, Tyrone Trapnell May 2019

Federal, State And Local Law Enforcement Agency Interoperability Capabilities And Cyber Vulnerabilities, Tyrone Trapnell

Electronic Theses and Dissertations

The National Data Exchange (N-DEx) System is the central informational hub located at the Federal Bureau of Investigation (FBI). Its purpose is to provide network subscriptions to all Federal, state and local level law enforcement agencies while increasing information collaboration across all domains. The National Data Exchange users must satisfy the Advanced Permission Requirements, confirming the terms of N-DEx information use, and the Verification Requirement (verifying the completeness, timeliness, accuracy, and relevancy of N-DEx information) through coordination with the record-owning agency (Management, 2018). A network infection model is proposed to simulate the spread impact of various cyber-attacks within Federal, state …


Applying Machine Learning To Anomaly-Based Intrusion Detection Systems, Fekadu Yihunie, Eman Abdelfattah, Amish Regmi May 2019

Applying Machine Learning To Anomaly-Based Intrusion Detection Systems, Fekadu Yihunie, Eman Abdelfattah, Amish Regmi

School of Computer Science & Engineering Faculty Publications

The enormous growth of Internet-based traffic exposes corporate networks with a wide variety of vulnerabilities. Intrusive traffics are affecting the normal functionality of network's operation by consuming corporate resources and time. Efficient ways of identifying, protecting, and mitigating from intrusive incidents enhance productivity. As Intrusion Detection System (IDS) is hosted in the network and at the user machine level to oversee the malicious traffic in the network and at the individual computer, it is one of the critical components of a network and host security. Unsupervised anomaly traffic detection techniques are improving over time. This research aims to find an …


Increasing User Confidence In Privacy-Sensitive Robots, Raniah Abdullah Bamagain May 2019

Increasing User Confidence In Privacy-Sensitive Robots, Raniah Abdullah Bamagain

Theses and Dissertations

As the deployment and availability of robots grow rapidly, and spreads everywhere to reach places where they can communicate with humans, and they can constantly sense, watch, hear, process, and record all the environment around them, numerous new benefits and services can be provided, but at the same time, various types of privacy issues appear. Indeed, the use of robots that process data remotely causes privacy concerns. There are some main factors that could increase the capability of violating the users’ privacy, such as the robots’ appearance, perception, or navigation capability, as well as the lack of authentication, the lack …


Hardware Ip Classification Through Weighted Characteristics, Brendan Mcgeehan May 2019

Hardware Ip Classification Through Weighted Characteristics, Brendan Mcgeehan

Graduate Theses and Dissertations

Today’s business model for hardware designs frequently incorporates third-party Intellectual Property (IP) due to the many benefits it can bring to a company. For instance, outsourcing certain components of an overall design can reduce time-to-market by allowing each party to specialize and perfect a specific part of the overall design. However, allowing third-party involvement also increases the possibility of malicious attacks, such as hardware Trojan insertion. Trojan insertion is a particularly dangerous security threat because testing the functionality of an IP can often leave the Trojan undetected. Therefore, this thesis work provides an improvement on a Trojan detection method known …


Analysis Of A Group Of Automorphisms Of A Free Group As A Platform For Conjugacy-Based Group Cryptography, Pavel Shostak May 2019

Analysis Of A Group Of Automorphisms Of A Free Group As A Platform For Conjugacy-Based Group Cryptography, Pavel Shostak

Dissertations, Theses, and Capstone Projects

Let F be a finitely generated free group and Aut(F) its group of automorphisms.

In this monograph we discuss potential uses of Aut(F) in group-based cryptography.

Our main focus is on using Aut(F) as a platform group for the Anshel-Anshel-Goldfeld protocol, Ko-Lee protocol, and other protocols based on different versions of the conjugacy search problem or decomposition problem, such as Shpilrain-Ushakov protocol.

We attack the Anshel-Anshel-Goldfeld and Ko-Lee protocols by adapting the existing types of the length-based attack to the specifics of Aut(F). We also present our own version of the length-based attack that significantly increases the attack' success …


On-The-Fly Android Static Analysis With Applications In Vulnerability Discovery, Daoyuan Wu May 2019

On-The-Fly Android Static Analysis With Applications In Vulnerability Discovery, Daoyuan Wu

Dissertations and Theses Collection (Open Access)

Static analysis is a common program analysis technique extensively used in the software security field. Widely-used static analysis tools for Android, e.g., Amandroid and FlowDroid, perform the whole-app analysis which is comprehensive yet at the cost of huge overheads. In this dissertation, we make a first attempt to explore a novel on-demand analysis that creatively leverages bytecode search to guide inter-procedural analysis on the fly or just in time, and develop such on-the-fly analysis into a tool, called BackDroid, for Android apps. We further explore how the core technique of on-the-fly static analysis in BackDroid can enable different vulnerability studies …


Querying Over Encrypted Databases In A Cloud Environment, Jake Douglas May 2019

Querying Over Encrypted Databases In A Cloud Environment, Jake Douglas

Boise State University Theses and Dissertations

The adoption of cloud computing has created a huge shift in where data is processed and stored. Increasingly, organizations opt to store their data outside of their own network to gain the benefits offered by shared cloud resources. With these benefits also come risks; namely, another organization has access to all of the data. A malicious insider at the cloud services provider could steal any personal information contained on the cloud or could use the data for the cloud service provider's business advantage. By encrypting the data, some of these risks can be mitigated. Unfortunately, encrypting the data also means …


Designated-Server Identity-Based Authenticated Encryption With Keyword Search For Encrypted Emails, Hongbo Li, Qiong Huang, Jian Shen, Guomin Yang, Willy Susilo May 2019

Designated-Server Identity-Based Authenticated Encryption With Keyword Search For Encrypted Emails, Hongbo Li, Qiong Huang, Jian Shen, Guomin Yang, Willy Susilo

Research Collection School Of Computing and Information Systems

In encrypted email system, how to search over encrypted cloud emails without decryption is an important and practical problem. Public key encryption with keyword search (PEKS) is an efficient solution to it. However, PEKS suffers from the complex key management problem in the public key infrastructure. Its variant in the identity-based setting addresses the drawback, however, almost all the schemes does not resist against offline keyword guessing attacks (KGA) by inside adversaries. In this work we introduce the notion of designated-server identity-based authenticated encryption with keyword search (dIBAEKS), in which the email sender authenticates the message while encrypting so that …


Pptds: A Privacy-Preserving Truth Discovery Scheme In Crowd Sensing Systems, Chuan Zhang, Liehuang Zhu, Chang Xu, Kashif Sharif, Ximeng Liu May 2019

Pptds: A Privacy-Preserving Truth Discovery Scheme In Crowd Sensing Systems, Chuan Zhang, Liehuang Zhu, Chang Xu, Kashif Sharif, Ximeng Liu

Research Collection School Of Computing and Information Systems

Benefiting from the fast development of human-carried mobile devices, crowd sensing has become an emerging paradigm to sense and collect data. However, reliability of sensory data provided by participating users is still a major concern. To address this reliability challenge, truth discovery is an effective technology to improve data accuracy, and has garnered significant attention. Nevertheless, many of state of art works in truth discovery, either failed to address the protection of participants' privacy or incurred tremendous overhead on the user side. In this paper, we first propose a privacy-preserving truth discovery scheme, named PPTDS-I, which is implemented on two …


A Blockchain-Based Location Privacy-Preserving Crowdsensing System, Mengmeng Yang, Tianqing Zhu, Kaitai Liang, Wanlei Zhou, Robert H. Deng May 2019

A Blockchain-Based Location Privacy-Preserving Crowdsensing System, Mengmeng Yang, Tianqing Zhu, Kaitai Liang, Wanlei Zhou, Robert H. Deng

Research Collection School Of Computing and Information Systems

With the support of portable electronic devices and crowdsensing, a new class of mobile applications based on the Internet of Things (IoT) application is emerging. Crowdsensing enables workers with mobile devices to travel to specified locations and collect data, then send it back to the requester for rewards. However, the majority of the existing crowdsensing systems are based on centralized servers, which are prone to a high chance of attack, intrusion, and manipulation. Further, during the process of transmitting information to and from the service server, the worker's location is usually exposed. This raises the potential risk of a privacy …


Bilateral Liability-Based Contracts In Information Security Outsourcing, Kai-Lung Hui, Ping Fan Ke, Yuxi Yao, Wei Thoo Yue May 2019

Bilateral Liability-Based Contracts In Information Security Outsourcing, Kai-Lung Hui, Ping Fan Ke, Yuxi Yao, Wei Thoo Yue

Research Collection School Of Computing and Information Systems

We study the efficiency of bilateral liability-based contracts in managed security services (MSSs). We model MSS as a collaborative service with the protection quality shaped by the contribution of both the service provider and the client. We adopt the negligence concept from the legal profession to design two novel contracts: threshold-based liability contract and variable liability contract. We find that they can achieve the first best outcome when postbreach effort verification is feasible. More importantly, they are more efficient than a multilateral contract when the MSS provider assumes limited liability. Our results show that bilateral liability-based contracts can work in …


Adversarial Sample Detection For Deep Neural Network Through Model Mutation Testing, Jingyi Wang, Guoliang Dong, Jun Sun, Xinyu Wang, Zhang Peixin May 2019

Adversarial Sample Detection For Deep Neural Network Through Model Mutation Testing, Jingyi Wang, Guoliang Dong, Jun Sun, Xinyu Wang, Zhang Peixin

Research Collection School Of Computing and Information Systems

No abstract provided.


Analyzing And Estimating Cyberattack Trends By Performing Data Mining On A Cybersecurity Data Set, Chan Young Koh Apr 2019

Analyzing And Estimating Cyberattack Trends By Performing Data Mining On A Cybersecurity Data Set, Chan Young Koh

Honors Program Theses and Projects

More than five billion personal information has been compromised over the past eight years through data breaches from notable companies, and the damage related to cybercrime is expected to reach six trillion USD annually by the year of 2021. Interestingly, recent cyberattacks were aimed specifically at credit agencies and companies that hold credit information of their customers and employees. The question is: “Why is it difficult to protect against or evade cyberattacks even for these prestigious companies?”. The purpose of this research is to bring the notion of notorious, rapidly-multiplying cyberthreats. Hence, the research focuses on analyzing cyberattack techniques and …


Securing Our Future Homes: Smart Home Security Issues And Solutions, Nicholas Romano Apr 2019

Securing Our Future Homes: Smart Home Security Issues And Solutions, Nicholas Romano

Senior Honors Theses

The Internet of Things, commonly known as IoT, is a new technology transforming businesses, individuals’ daily lives and the operation of entire countries. With more and more devices becoming equipped with IoT technology, smart homes are becoming increasingly popular. The components that make up a smart home are at risk for different types of attacks; therefore, security engineers are developing solutions to current problems and are predicting future types of attacks. This paper will analyze IoT smart home components, explain current security risks, and suggest possible solutions. According to “What is a Smart Home” (n.d.), a smart home is a …