Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Discipline
Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 2581 - 2610 of 4670

Full-Text Articles in Information Security

An Accidental Discovery Of Iot Botnets And A Method For Investigating Them With A Custom Lua Dissector, Max Gannon, Gary Warner, Arsh Arora May 2017

An Accidental Discovery Of Iot Botnets And A Method For Investigating Them With A Custom Lua Dissector, Max Gannon, Gary Warner, Arsh Arora

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper presents a case study that occurred while observing peer-to-peer network communications on a botnet monitoring station and shares how tools were developed to discover what ultimately was identified as Mirai and many related IoT DDOS Botnets. The paper explains how researchers developed a customized protocol dissector in Wireshark using the Lua coding language, and how this enabled them to quickly identify new DDOS variants over a five month period of study.


Kelihos Botnet: A Never-Ending Saga, Arsh Arora, Max Gannon, Gary Warner May 2017

Kelihos Botnet: A Never-Ending Saga, Arsh Arora, Max Gannon, Gary Warner

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper investigates the recent behavior of the Kelihos botnet, a spam-sending botnet that accounts for many millions of emails sent each day. The paper demonstrates how a team of students are able to perform a longitudinal malware study, making significant observations and contributions to the understanding of a major botnet using tools and techniques taught in the classroom. From this perspective the paper has two objectives: encouragement and observation. First, by providing insight into the methodology and tools used by student researchers to document and understand a botnet, the paper strives to embolden other academic programs to follow a …


Lightweight Data Aggregation Scheme Against Internal Attackers In Smart Grid Using Elliptic Curve Cryptography, Debiao He, Sherali Zeadally, Huaqun Wang, Qin Liu May 2017

Lightweight Data Aggregation Scheme Against Internal Attackers In Smart Grid Using Elliptic Curve Cryptography, Debiao He, Sherali Zeadally, Huaqun Wang, Qin Liu

Information Science Faculty Publications

Recent advances of Internet and microelectronics technologies have led to the concept of smart grid which has been a widespread concern for industry, governments, and academia. The openness of communications in the smart grid environment makes the system vulnerable to different types of attacks. The implementation of secure communication and the protection of consumers’ privacy have become challenging issues. The data aggregation scheme is an important technique for preserving consumers’ privacy because it can stop the leakage of a specific consumer’s data. To satisfy the security requirements of practical applications, a lot of data aggregation schemes were presented over the …


Ispy: Threats To Individual And Institutional Privacy In The Digital World, Lori Andrews May 2017

Ispy: Threats To Individual And Institutional Privacy In The Digital World, Lori Andrews

All Faculty Scholarship

What type of information is collected, who is viewing it, and what law librarians can do to protect their patrons and institutions.


Mining Software Repositories For Automatic Software Bug Management From Bug Triaging To Patch Backporting, Yuan Tian May 2017

Mining Software Repositories For Automatic Software Bug Management From Bug Triaging To Patch Backporting, Yuan Tian

Dissertations and Theses Collection

Software systems are often released with bugs due to system complexity and inadequate testing. Bug resolving process plays an important role in development and evolution of software systems because developers could collect a considerable number of bugs from users and testers daily. For instance, during September 2015, the Eclipse project received approximately 2,500 bug reports, averaging 80 new reports each day. To help developers effectively address and manage bugs, bug tracking systems such as Bugzilla and JIRA are adopted to manage the life cycle of a bug through bug report. Since most of the information related to bugs are stored …


Umass Memorial Healthcare Information System Job Ladder, Matthew Simoncini, Vamsi Kavuru, Antariksh Nanda, Tahaseen Mahaboob Basha, Vikram Patil May 2017

Umass Memorial Healthcare Information System Job Ladder, Matthew Simoncini, Vamsi Kavuru, Antariksh Nanda, Tahaseen Mahaboob Basha, Vikram Patil

School of Professional Studies

The capstone project report emphasizes the importance of a job ladder and the need of an hour to implement it at UMASS Memorial health care. The scope of this project is to create a well-established job ladder at UMASS with pre-defined standards on job levels related to Information Technology department that would facilitate in hiring, developing and promoting employees at various stages.


A Learning Framework For The Ywca Central Massachusetts, Dayna Ankermann, Manjushree Burdekar, Priyanka Joshi, Ying Song, Yumeng Chen, Xing Xie May 2017

A Learning Framework For The Ywca Central Massachusetts, Dayna Ankermann, Manjushree Burdekar, Priyanka Joshi, Ying Song, Yumeng Chen, Xing Xie

School of Professional Studies

After meeting with the Director of Wellness and Health Equity at the YWCA Central Massachusetts (which will be referred to as the YWCA from here on out), we learned that as a non-profit gym and health center, it is heavily underfunded. The main focus of the project was to determine how to upkeep the facility while bringing in new customers with limited resources and budget. Due to the needs of the YWCA, our group focused on six aspects: revenue stream, donor retention, increasing membership, customer experience, social media marketing, and membership fee structure. After completing extensive research, we were able …


Human Services Management (Hsm) Certificate Program Expansion To Western Massachusetts Feasibility Study, Paul Campbell, Patrick Deschenes, Maria Pacheco, Bradley Paul, Elizabeth Vittum, Jing Zhang May 2017

Human Services Management (Hsm) Certificate Program Expansion To Western Massachusetts Feasibility Study, Paul Campbell, Patrick Deschenes, Maria Pacheco, Bradley Paul, Elizabeth Vittum, Jing Zhang

School of Professional Studies

One of the most popular cost-savings programs that the Providers’ Council currently offers its members is a Certificate in Nonprofit Human Service Management (HSM) provided in partnership with Clark University and Suffolk University. As human services providers are struggling to hire and retain qualified staff, the need to provide professional development opportunities to help grow and expand a skilled health and human services workforce is a critical issue facing nonprofit organizations and communities in Massachusetts. This feasibility study examines the viability of Providers’ Council and Clark University expanding its HSM Certificate Program to organizations and staff located in western Massachusetts. …


Somali National University, Sharmarke Abdulla, Nikala Pieroni, Jenna Caskie, Sergii Odnodvorets, Tanyue Gong, Lahari Dasari May 2017

Somali National University, Sharmarke Abdulla, Nikala Pieroni, Jenna Caskie, Sergii Odnodvorets, Tanyue Gong, Lahari Dasari

School of Professional Studies

The executive summary presents an overview of the principal conclusions and recommendations for Somali National University Faculty of Education (FoEd) regarding the following concerns: Difficulty with recruiting high quality prospects to the FoEd; Ineffective and counterintuitive use of social media as a tool to improve brand equity, as well as as a tool to attract and communicate with prospective and current students; Unbalanced gender ratio of current student body; Absence of student services and student supports; Low student retention rate; Limited resources for academic advising; This document is the result of a Clark University School of Professional Studies Capstone Project.


The Economics Of The Right To Be Forgotten, Byung-Cheol Kim, Jin Yeub Kim May 2017

The Economics Of The Right To Be Forgotten, Byung-Cheol Kim, Jin Yeub Kim

Department of Economics: Faculty Publications

Scholars and practitioners debate whether to expand the scope of the right to be forgotten—the right to have certain links removed from search results—to encompass global search results. The debate centers on the assumption that the expansion will increase the incidence of link removal, which reinforces privacy while hampering free speech. We develop a game-theoretic model to show that the expansion of the right to be forgotten can reduce the incidence of link removal. We also show that the expansion does not necessarily enhance the welfare of individuals who request removal and that it can either improve or reduce societal …


The Impact Of Monetary Value Gains And Losses On Cybersecurity Behavior, Samuel Noah Smith, Fiona Fui-Hoon Nah, Maggie Cheng, Santosh Kuma Ravindran May 2017

The Impact Of Monetary Value Gains And Losses On Cybersecurity Behavior, Samuel Noah Smith, Fiona Fui-Hoon Nah, Maggie Cheng, Santosh Kuma Ravindran

Research Collection School Of Computing and Information Systems

This research examines if users take more risky cybersecurity actions when presented with the possibility of losing monetary value rather than gaining monetary value. Prospect theory provides the theoretical foundation for the research. An experimental design is proposed to test the hypothesis for the research.


Cryptography And Data Security In Cloud Computing, Zheng Yan, Robert H. Deng, Vijay Varadharajan May 2017

Cryptography And Data Security In Cloud Computing, Zheng Yan, Robert H. Deng, Vijay Varadharajan

Research Collection School Of Computing and Information Systems

Cloud computing offers a new way of services by re-arranging various resources and providing them to users based on their demands. It also plays an important role in the next generation mobile networks and services (5G) and Cyber-Physical and Social Computing (CPSC). Storing data in the cloud greatly reduces storage burden of users and brings them access convenience, thus it has become one of the most important cloud services. However, cloud data security, privacy and trust become a crucial issue that impacts the success of cloud computing and may impede the development of 5G and CPSC. First, storing data at …


Encrypted Data Processing With Homomorphic Re-Encryption, Wenxiu Ding, Zheng Yan, Robert H. Deng May 2017

Encrypted Data Processing With Homomorphic Re-Encryption, Wenxiu Ding, Zheng Yan, Robert H. Deng

Research Collection School Of Computing and Information Systems

Cloud computing offers various services to users by re-arranging storage and computing resources. In order to preserve data privacy, cloud users may choose to upload encrypted data rather than raw data to the cloud. However, processing and analyzing encrypted data are challenging problems, which have received increasing attention in recent years. Homomorphic Encryption (HE) was proposed to support computation on encrypted data and ensure data confidentiality simultaneously. However, a limitation of HE is it is a single user system, which means it only allows the party that owns a homomorphic decryption key to decrypt processed ciphertexts. Original HE cannot support …


Online/Offline Provable Data Possession, Yujue Wang, Qianhong Wu, Bo Qin, Shaohua Tang, Willy Susilo May 2017

Online/Offline Provable Data Possession, Yujue Wang, Qianhong Wu, Bo Qin, Shaohua Tang, Willy Susilo

Research Collection School Of Computing and Information Systems

Provable data possession (PDP) allows a user to outsource data with a guarantee that the integrity can be efficiently verified. Existing publicly verifiable PDP schemes require the user to perform expensive computations, such as modular exponentiations for processing data before outsourcing to the storage server, which is not desirable for weak users with limited computation resources. In this paper, we introduce and formalize an online/offline PDP (OOPDP) model, which divides the data processing procedure into offline and online phases. In OOPDP, most of the expensive computations for processing data are performed in the offline phase, and the online phase requires …


Dpweka: Achieving Differential Privacy In Weka, Srinidhi Katla May 2017

Dpweka: Achieving Differential Privacy In Weka, Srinidhi Katla

Graduate Theses and Dissertations

Organizations belonging to the government, commercial, and non-profit industries collect and store large amounts of sensitive data, which include medical, financial, and personal information. They use data mining methods to formulate business strategies that yield high long-term and short-term financial benefits. While analyzing such data, the private information of the individuals present in the data must be protected for moral and legal reasons. Current practices such as redacting sensitive attributes, releasing only the aggregate values, and query auditing do not provide sufficient protection against an adversary armed with auxiliary information. In the presence of additional background information, the privacy protection …


Binary Analysis Framework, Josh Stroschein May 2017

Binary Analysis Framework, Josh Stroschein

Masters Theses & Doctoral Dissertations

The binary analysis of software has become an integral activity for security researchers and attackers alike. As the value of being able to exploit a vulnerability has increased, the need to discover, fix and prevent such vulnerabilities has never been greater. This paper proposes the Binary Analysis Framework, which is intended to be used by security researchers to query and analyze information about system and third party libraries. Researchers can use the tool to evaluate and discover unknown vulnerabilities in these libraries. Furthermore, the framework can be utilized to analyze mitigation techniques implemented by operating system and thirdparty vendors. The …


High Fidelity Adaptive Cyber Emulation, Samir Mammadov May 2017

High Fidelity Adaptive Cyber Emulation, Samir Mammadov

Theses and Dissertations

While looking for a high-level adaptive traffic generation tool, we came to realize that no such tool exists that can be used for rapid development while being platform agnostic. Having reviewed a wide array of tools to either implement user models or simulate traffic, we were unable to find a tool with the right capabilities while maintaining complexity, portability and extensibility. To overcome these issues, we introduce a new adaptive user-modelling framework for the specific use case of cyber activity emulation. Our framework supports the creation of high-level user models that can react to changes in their environments and vary …


Provably Secure Attribute Based Signcryption With Delegated Computation And Efficient Key Updating, Hanshu Hong, Yunhao Xia, Zhixin Sun, Ximeng Liu May 2017

Provably Secure Attribute Based Signcryption With Delegated Computation And Efficient Key Updating, Hanshu Hong, Yunhao Xia, Zhixin Sun, Ximeng Liu

Research Collection School Of Computing and Information Systems

Equipped with the advantages of flexible access control and fine-grained authentication, attribute based signcryption is diffusely designed for security preservation in many scenarios. However, realizing efficient key evolution and reducing the calculation costs are two challenges which should be given full consideration in attribute based cryptosystem. In this paper, we present a key-policy attribute based signcryption scheme (KP-ABSC) with delegated computation and efficient key updating. In our scheme, an access structure is embedded into user’s private key, while ciphertexts corresponds a target attribute set. Only the two are matched can a user decrypt and verify the ciphertexts. When the access …


Monitoring The Dark Web And Securing Onion Services, John Schriner Apr 2017

Monitoring The Dark Web And Securing Onion Services, John Schriner

Publications and Research

This paper focuses on how researchers monitor the Dark Web. After defining what onion services and Tor are, we discuss tools for monitoring and securing onion services. As Tor Project itself is research-driven, we find that the development and use of these tools help us to project where use of the Dark Web is headed.


Cybersecurity In The 21st Century, Singapore Management University Apr 2017

Cybersecurity In The 21st Century, Singapore Management University

Perspectives@SMU

Increased awareness is necessary in fending off data theft and cyber attacks, and it is not just the CIO’s job to do so


Smu’S Professor Robert Deng Conferred Axa Chair Professorship Of Cybersecurity, Singapore Management University Apr 2017

Smu’S Professor Robert Deng Conferred Axa Chair Professorship Of Cybersecurity, Singapore Management University

SMU Press Releases and News

Singapore Management University’s Professor Robert Deng, a leading global authority and award winning researcher in cybersecurity, has today been conferred the prestigious AXA Chair Professorship of Cybersecurity.

€800,000 funding from AXA Research Fund over a period of eight years will support Professor Deng’s research in the development of new ways of protecting data security and privacy.


Security And Privacy In Cloud Computing, Ramakrishnan Krishnan Apr 2017

Security And Privacy In Cloud Computing, Ramakrishnan Krishnan

Masters Theses

Cloud computing (CC) gained a widespread acceptance as a paradigm of computing. The main aim of CC is to reduce the need for customers' investment in new hardware or software by offering flexible cloud services, with a user reaping the benefits of the pay per use approach. CC demands addressing many security and privacy issues: both problems (vulnerabilities, threats, and attacks) and solutions (controls). The thesis discusses all these classes of problems and solutions, categorizing them as either security-related issues, privacy-related issues, or intertwined security and privacy issues. The main contributions of the thesis are twofold: first, using the …


Mobile Big Data Analytics In Healthcare, Alramzana Nujum Navaz Apr 2017

Mobile Big Data Analytics In Healthcare, Alramzana Nujum Navaz

Theses

Mobile and ubiquitous devices are everywhere around us generating considerable amount of data. The concept of mobile computing and analytics is expanding due to the fact that we are using mobile devices day in and out without even realizing it. These mobile devices use Wi-Fi, Bluetooth or mobile data to be intermittently connected to the world, generating, sending and receiving data on the move. Latest mobile applications incorporating graphics, video and audio are main causes of loading the mobile devices by consuming battery, memory and processing power. Mobile Big data analytics includes for instance, big health data, big location data, …


On The Effectiveness Of Virtualization Based Memory Isolation On Multicore Platforms, Siqi Zhao, Xuhua Ding Apr 2017

On The Effectiveness Of Virtualization Based Memory Isolation On Multicore Platforms, Siqi Zhao, Xuhua Ding

Research Collection School Of Computing and Information Systems

Virtualization based memory isolation has beenwidely used as a security primitive in many security systems.This paper firstly provides an in-depth analysis of itseffectiveness in the multicore setting; a first in the literature.Our study reveals that memory isolation by itself is inadequatefor security. Due to the fundamental design choices inhardware, it faces several challenging issues including pagetable maintenance, address mapping validation and threadidentification. As demonstrated by our attacks implementedon XMHF and BitVisor, these issues undermine the security ofmemory isolation. Next, we propose a new isolation approachthat is immune to the aforementioned problems. In our design,the hypervisor constructs a fully isolated micro …


What You See Is Not What You Get: Leakage-Resilient Password Entry Schemes For Smart Glasses, Yan Li, Yao Cheng, Yingjiu Li, Robert H. Deng Apr 2017

What You See Is Not What You Get: Leakage-Resilient Password Entry Schemes For Smart Glasses, Yan Li, Yao Cheng, Yingjiu Li, Robert H. Deng

Research Collection School Of Computing and Information Systems

Smart glasses are becoming popular for users to access various services such as email. To protect these services, password-based user authentication is widely used. Unfortunately, the password based user authentication has inherent vulnerability against password leakage. Many efforts have been put on designing leakage resilient password entry schemes on PCs and mobile phones with traditional input equipment including keyboards and touch screens. However, such traditional input equipment is not available on smart glasses. Existing password entry on smart glasses relies on additional PCs or mobile devices. Such solutions force users to switch between different systems, which causes interrupted experience and …


Vulnerabilities, Attacks, And Countermeasures In Balise-Based Train Control Systems, Yongdong Wu, Jian Weng, Zhe Tang, Xin Li, Robert H. Deng Apr 2017

Vulnerabilities, Attacks, And Countermeasures In Balise-Based Train Control Systems, Yongdong Wu, Jian Weng, Zhe Tang, Xin Li, Robert H. Deng

Research Collection School Of Computing and Information Systems

In modern rail transport systems, balises are widely used to exchange track-train information via air-gap interface. In this paper, we first present the vulnerabilities on the standard balise air-gap interface, and then conduct vulnerability simulations using the system parameters that were specified in the European Train Control System. The simulation results show that the vulnerabilities can be exploited to launch effective and practical attacks, which could lead to catastrophic consequences, such as train derailment or collision. To mitigate the vulnerabilities and attacks, we propose to implement a challenge-response authentication process in the air-gap interface in the existing transport infrastructure.


A Secure And Efficient Id-Based Aggregate Signature Scheme For Wireless Sensor Networks, Limin Shen, Jianfeng Ma, Ximeng Liu, Fushan Wei, Meixia Miao Apr 2017

A Secure And Efficient Id-Based Aggregate Signature Scheme For Wireless Sensor Networks, Limin Shen, Jianfeng Ma, Ximeng Liu, Fushan Wei, Meixia Miao

Research Collection School Of Computing and Information Systems

Affording secure and efficient big data aggregation methods is very attractive in the field of wireless sensor networks (WSNs) research. In real settings, the WSNs have been broadly applied, such as target tracking and environment remote monitoring. However, data can be easily compromised by a vast of attacks, such as data interception and data tampering, etc. In this paper, we mainly focus on data integrity protection, give an identity-based aggregate signature (IBAS) scheme with a designated verifier for WSNs. According to the advantage of aggregate signatures, our scheme not only can keep data integrity, but also can reduce bandwidth and …


Identity-Based Data Outsourcing With Comprehensive Auditing In Clouds, Yujue Wang, Qianhong Wu, Bo Qin, Wenchang Shi, Robert H. Deng, Jiankun Hu Apr 2017

Identity-Based Data Outsourcing With Comprehensive Auditing In Clouds, Yujue Wang, Qianhong Wu, Bo Qin, Wenchang Shi, Robert H. Deng, Jiankun Hu

Research Collection School Of Computing and Information Systems

Cloud storage system provides facilitative file storage and sharing services for distributed clients. To address integrity, controllable outsourcing, and origin auditing concerns on outsourced files, we propose an identity-based data outsourcing (IBDO) scheme equipped with desirable features advantageous over existing proposals in securing outsourced data. First, our IBDO scheme allows a user to authorize dedicated proxies to upload data to the cloud storage server on her behalf, e.g., a company may authorize some employees to upload files to the company's cloud account in a controlled way. The proxies are identified and authorized with their recognizable identities, which eliminates complicated certificate …


Characterizing Malicious Android Apps By Mining Topic-Specific Data Flow Signatures, Xinli Yang, David Lo, Li Li, Xin Xia, Tegawendé F. Bissyande, Jacques Klein Apr 2017

Characterizing Malicious Android Apps By Mining Topic-Specific Data Flow Signatures, Xinli Yang, David Lo, Li Li, Xin Xia, Tegawendé F. Bissyande, Jacques Klein

Research Collection School Of Computing and Information Systems

Context: State-of-the-art works on automated detection of Android malware have leveraged app descriptions to spot anomalies w.r.t the functionality implemented, or have used data flow information as a feature to discriminate malicious from benign apps. Although these works have yielded promising performance,we hypothesize that these performances can be improved by a better understanding of malicious behavior. Objective: To characterize malicious apps, we take into account both information on app descriptions,which are indicative of apps’ topics, and information on sensitive data flow, which can be relevant todiscriminate malware from benign apps. Method: In this paper, we propose a topic-specific approach to …


Special Issue Of Best Papers From The 11th International Conference On Systematic Approaches To Digital Forensic Engineering (Sadfe 2016) Mar 2017

Special Issue Of Best Papers From The 11th International Conference On Systematic Approaches To Digital Forensic Engineering (Sadfe 2016)

Journal of Digital Forensics, Security and Law

The SADFE series feature the different editions of the International Conference on Systematic Approaches to Digital Forensics Engineering. Now in its eleventh edition, SADFE has established itself as the premier conference for researchers and practitioners working in Systematic Approaches to Digital Forensics Engineering.

SADFE 2016, the eleventh international conference on Systematic Approaches to Digital Forensic Engineering was held in Kyoto, Japan, September 20 - 22, 2016.

Digital forensics engineering and the curation of digital collections in cultural institutions face pressing and overlapping challenges related to provenance, chain of custody, authenticity, integrity, and identity. The generation, analysis and sustainability of digital …