Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Discipline
Institution
Keyword
Publication Year
Publication
Publication Type
File Type

Articles 451 - 480 of 4669

Full-Text Articles in Information Security

Esem: To Harden Process Synchronization For Servers, Zhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang, Ning Hu Jul 2024

Esem: To Harden Process Synchronization For Servers, Zhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang, Ning Hu

Research Collection School Of Computing and Information Systems

Process synchronization primitives lubricate server computing involving a group of processes as they ensure those processes to properly coordinate their executions for a common purpose such as provisioning a web service. A malfunctioned synchronization due to attacks causes friction among processes and leads to unexpected, and often hard-to-detect, application transaction errors. Unfortunately, synchronization primitives are not naturally protected by existing hardware-assisted isolation techniques e.g., SGX, because their process-oriented isolation conflicts with the primitive's demand for cross-process operations.This paper introduces the Enclave-Semaphore service (ESem) which shelters application semaphores and their operations against kernel-privileged attacks. ESem encapsulates all semaphores in the platform …


Privacy-Preserving Arbitrary Geometric Range Query In Mobile Internet Of Vehicles, Yinbin Miao, Lin Song, Xinghua Li, Hongwei Li, Kim-Kwang Raymond Choo, Robert H. Deng Jul 2024

Privacy-Preserving Arbitrary Geometric Range Query In Mobile Internet Of Vehicles, Yinbin Miao, Lin Song, Xinghua Li, Hongwei Li, Kim-Kwang Raymond Choo, Robert H. Deng

Research Collection School Of Computing and Information Systems

The mobile Internet of Vehicles (IoVs) has great potential for intelligent transportation, and creates spatial data query demands to realize the value of data. Outsourcing spatial data to a cloud server eliminates the need for local computation and storage, but it leads to data security and privacy threats caused by untrusted third-parties. Existing privacy-preserving spatial range query solutions based on Homomorphic Encryption (HE) have been developed to increase security. However, in the single server model, the private key is held by the query user, which incurs high computation and communication burdens on query users due to multiple rounds of interactions. …


Key Cooperative Attribute-Based Encryption, Luqi Huang, Willy Susilo, Guomin Yang, Fuchun Guo Jul 2024

Key Cooperative Attribute-Based Encryption, Luqi Huang, Willy Susilo, Guomin Yang, Fuchun Guo

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) is an important technology in building access control systems with precise control and scalability. In an ABE system, there exists a private key generator (PKG) that issues all private keys. The PKG has a significant drawback referred to as the huge key management burden in large-scale user systems. To overcome this limitation, we propose a more flexible system that offers users the choice to utilize decryption keys either from the PKG or from trusted users to decrypt the ciphertext, reducing the workload of the PKG. Unfortunately, users are restricted to only receiving private keys from the PKG …


Development Of Cyber Security Platform For Experiential Learning, Abhishek Vaish, Ravindra Kumar, Samo Bobek, Simona Sternad Jun 2024

Development Of Cyber Security Platform For Experiential Learning, Abhishek Vaish, Ravindra Kumar, Samo Bobek, Simona Sternad

Journal of Cybersecurity Education, Research and Practice

The cyber security education market has grown-up exponentially, with a CAGR of 13.9 % as reported by Data Intelo. The report published by the World Economic Fo- rum 2023 indicates a shortfall of 2.27 million cyber security experts in 2021 across different roles and hence manifest that Skill-based cyber security education is the need of the hour. Cybersecurity as a field has evolved as a multi-discipline, multi-stakeholder and multi-role discipline. Therefore, the need to address formal education with an outcome-based philosophy is imperative to address for a wider audience with varied past training in their formal education. With the Internet …


Trust, Transparency, And Transport: The Impact Of Privacy Protection On The Acceptance Of Last-Mile Drone Delivery, Jurgen Heinz Famula Jun 2024

Trust, Transparency, And Transport: The Impact Of Privacy Protection On The Acceptance Of Last-Mile Drone Delivery, Jurgen Heinz Famula

Electronic Theses and Dissertations

A common set of problems commercial delivery companies face is finding ways to increase the efficiency and reliability of the “last mile” of a package’s journey, all while reducing operating costs. This need for efficiency has driven many companies to explore using unmanned aerial vehicles (UAVs), or drones, to get packages to their final destination. Although UAVs have great potential to help increase efficiency in commercial package delivery, this comes at a potential cost to the privacy of people who intersect the flight paths of these unmanned vehicles. This thesis explores the effect of a mobile phone application for commercial …


Federated Learning Based Autoencoder Ensemble System For Malware Detection On Internet Of Things Devices, Steven Edward Arroyo Jun 2024

Federated Learning Based Autoencoder Ensemble System For Malware Detection On Internet Of Things Devices, Steven Edward Arroyo

Theses and Dissertations

New technologies are being introduced at a rate faster than ever before and smaller in size. Due to the size of these devices, security is often difficult to implement. The existing solution is a firewall-segmented “IoT Network” that only limits the effect of these infected devices on other parts of the network. We propose a lightweight unsupervised hybrid-cloud ensemble anomaly detection system for malware detection. We perform transfer learning using a generalized model trained on multiple IoT device sources to learn network traffic on new devices with minimal computational resources. We further extend our proposed system to utilize federated learning …


Securing The Inbox: Advancing Cyber Resilience With Fine-Tuned Bert, Fatima Rashed Al Saedi Jun 2024

Securing The Inbox: Advancing Cyber Resilience With Fine-Tuned Bert, Fatima Rashed Al Saedi

Thesis/ Dissertation Defenses

In recent years, phishing attacks have persisted as a widespread threat in the contemporary digital environment, presenting substantial risks to individuals and organizations. Cybercriminals are devising increasingly sophisticated strategies to deceive users through malicious emails. In response to this challenge, this research focuses on developing a new tool for detecting phishing emails utilizing the BERT algorithm. The tool aims to enhance email security by accurately identifying deceptive emails and protecting users from potential cyber threats. The primary objective of this study is to investigate how leveraging the BERT algorithm can improve the detection of phishing emails compared to traditional methods. …


An Alternative Approach To Data Carving Portable Document Format (Pdf) Files, Kevin Hughes, Michael Black Jun 2024

An Alternative Approach To Data Carving Portable Document Format (Pdf) Files, Kevin Hughes, Michael Black

Journal of Cybersecurity Education, Research and Practice

Traditional data carving relies on the successful identification of headers and trailers, unique hexadecimal signatures which are exclusive to specific file types. This can present a challenge for digital forensics examiners when pitted against modern anti-forensics techniques. The interest of this study is file signature obfuscation, a technique which alters headers and trailers. This research will focus on the development of a new, proof-of-concept algorithm that analyzes content in segments based on unique elements found within the body of a file. The file type being targeted is the Portable Document Format (PDF) and this research is built upon previously successful …


Securing The Inbox: Advancing Phishing Email Detection With Fine-Tuned Bert, Fatima Rashed Al Saedi Jun 2024

Securing The Inbox: Advancing Phishing Email Detection With Fine-Tuned Bert, Fatima Rashed Al Saedi

Theses

In recent years, phishing attacks have persisted as a widespread threat in the contemporary digital environment, presenting substantial risks to individuals and organizations. Cybercriminals are devising increasingly sophisticated strategies to deceive users through malicious emails. In response to this challenge, this research focuses on developing a new tool for detecting phishing emails utilizing the BERT algorithm. The tool aims to enhance email security by accurately identifying deceptive emails and protecting users from potential cyber threats. The primary objective of this study is to investigate how leveraging the BERT algorithm can improve the detection of phishing emails compared to traditional methods. …


Automated Sensor Node Malicious Activity Detection With Explainability Analysis, Md Zubair, Helge Janicke, Ahmad Mohsin, Leandros Maglaras, Iqbal H. Sarker Jun 2024

Automated Sensor Node Malicious Activity Detection With Explainability Analysis, Md Zubair, Helge Janicke, Ahmad Mohsin, Leandros Maglaras, Iqbal H. Sarker

Research outputs 2022 to 2026

Cybersecurity has become a major concern in the modern world due to our heavy reliance on cyber systems. Advanced automated systems utilize many sensors for intelligent decision-making, and any malicious activity of these sensors could potentially lead to a system-wide collapse. To ensure safety and security, it is essential to have a reliable system that can automatically detect and prevent any malicious activity, and modern detection systems are created based on machine learning (ML) models. Most often, the dataset generated from the sensor node for detecting malicious activity is highly imbalanced because the Malicious class is significantly fewer than the …


Visualizing Privately Protected Data: Exploring The Privacy-Utility Trade-Offs, Sarah Hayi Alkaabi Jun 2024

Visualizing Privately Protected Data: Exploring The Privacy-Utility Trade-Offs, Sarah Hayi Alkaabi

Theses

In a data-driven era, achieving a balance between privacy and utility is crucial. Organizations often utilize data for research, analysis, and enhancement of services, which emphasizes the significance of effective privacy-preserving techniques to protect individuals' privacy and comply with regulations. This equilibrium is vital in data visualization to derive insightful decisions from data representations. The goal is to evaluate the trade-off between privacy preservation and data utility, understanding how differentially private parameters impact effective visualizations. Valuable insights will guide strategies for achieving optimal privacy-preserving visualization techniques. The study aims to investigate the effects on privacy and data utility in different …


Pkt-Sin: A Secure Communication Protocol For Space Information Networks With Periodic K-Time Anonymous Authentication, Yang Yang, Wenyi Xue, Jianfei Sun, Guomin Yang, Yingjiu Li, Hwee Hwa Pang, Robert H. Deng Jun 2024

Pkt-Sin: A Secure Communication Protocol For Space Information Networks With Periodic K-Time Anonymous Authentication, Yang Yang, Wenyi Xue, Jianfei Sun, Guomin Yang, Yingjiu Li, Hwee Hwa Pang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Space Information Network (SIN) enables universal Internet connectivity for any object, even in remote and extreme environments where deploying a cellular network is difficult. Access authentication is crucial for ensuring user access control in SIN and preventing unauthorized entities from gaining access to network services. However, due to the complex communication environment in SIN, including exposed links and higher signal delay, designing a secure and efficient authentication scheme presents a significant challenge. In this paper, we propose a secure communication protocol for SIN with periodic k-time anonymous authentication (named PkT-SIN) that allows satellite users to anonymously authenticate to ground stations …


Unmasking The Lurking: Malicious Behavior Detection For Iot Malware With Multi-Label Classification, Ruitao Feng, Sen Li, Sen Chen, Mengmeng Ge, Xuewei Li, Xiaohong Li Jun 2024

Unmasking The Lurking: Malicious Behavior Detection For Iot Malware With Multi-Label Classification, Ruitao Feng, Sen Li, Sen Chen, Mengmeng Ge, Xuewei Li, Xiaohong Li

Research Collection School Of Computing and Information Systems

Current methods for classifying IoT malware predominantly utilize binary and family classifications. However, these outcomes lack the detailed granularity to describe malicious behavior comprehensively. This limitation poses challenges for security analysts, failing to support further analysis and timely preventive actions. To achieve fine-grained malicious behavior identification in the lurking stage of IoT malware, we propose MaGraMal. This approach, leveraging masked graph representation, supplements traditional classification methodology, empowering analysts with critical insights for rapid responses. Through the empirical study, which took three person-months, we identify and summarize four fine-grained malicious behaviors during the lurking stage, constructing an annotated dataset. Our evaluation …


Enhancing Code Vulnerability Detection Via Vulnerability-Preserving Data Augmentation, Shangqing Liu, Wei Ma, Jian Wang, Xiaofei Xie, Ruitao Feng, Yang Liu Jun 2024

Enhancing Code Vulnerability Detection Via Vulnerability-Preserving Data Augmentation, Shangqing Liu, Wei Ma, Jian Wang, Xiaofei Xie, Ruitao Feng, Yang Liu

Research Collection School Of Computing and Information Systems

Source code vulnerability detection aims to identify inherent vulnerabilities to safeguard software systems from potential attacks. Many prior studies overlook diverse vulnerability characteristics, simplifying the problem into a binary (0-1) classification task for example determining whether it is vulnerable or not. This poses a challenge for a single deep-learning based model to effectively learn the wide array of vulnerability characteristics. Furthermore, due to the challenges associated with collecting large-scale vulnerability data, these detectors often overfit limited training datasets, resulting in lower model generalization performance. To address the aforementioned challenges, in this work, we introduce a fine-grained vulnerability detector namely FGVulDet. …


Measuring Confidentiality With Multiple Observables, John J. Utley May 2024

Measuring Confidentiality With Multiple Observables, John J. Utley

Computer Science Senior Theses

Measuring the confidentiality of programs that need to interact with the outside world can prevent leakages and is important to protect against dangerous attacks. However, information propagation is difficult to follow through a large program with implicit information flow, tricky loops, and complicated instructions. Previous works have tackled this problem in several ways but often measure leakage a program has on average rather than the leakage produced by a set of particularly compromising interactions. We introduce new methods that target a specific set of observables revealed throughout execution to cut down on the resources needed for analysis. Our implementation examines …


Singleadv: Single-Class Target-Specific Attack Against Interpretable Deep Learning Systems, Eldor Abdukhamidov, Mohammed Abuhamad, George K. Thiruvathukal, Hyoungshick Kim, Tamer Abuhmed May 2024

Singleadv: Single-Class Target-Specific Attack Against Interpretable Deep Learning Systems, Eldor Abdukhamidov, Mohammed Abuhamad, George K. Thiruvathukal, Hyoungshick Kim, Tamer Abuhmed

Computer Science: Faculty Publications and Other Works

In this paper, we present a novel Single-class target-specific Adversarial attack called SingleADV. The goal of SingleADV is to generate a universal perturbation that deceives the target model into confusing a specific category of objects with a target category while ensuring highly relevant and accurate interpretations. The universal perturbation is stochastically and iteratively optimized by minimizing the adversarial loss that is designed to consider both the classifier and interpreter costs in targeted and non-targeted categories. In this optimization framework, ruled by the first- and second-moment estimations, the desired loss surface promotes high confidence and interpretation score of adversarial samples. By …


Whisper: Proximity-Based Authentication For Securely Sharing Secrets, Charles A. Vogel May 2024

Whisper: Proximity-Based Authentication For Securely Sharing Secrets, Charles A. Vogel

Computer Science Senior Theses

Cryptography offers a wide arsenal of encryption methods to enable secure communication between two
devices that have already exchanged a shared secret. Existing techniques for exchanging a shared secret,
however, are often vulnerable to man-in-the-middle attacks, require special hardware for out-of-band com-
munications, or require a pre-existing Internet connection. With the constantly increasing prevalence of
Internet of Things (IoT) devices sharing sensitive information via wireless networks, the need for a method
to establish secure communication is more pressing than ever.
With this context, we present Whisper, a novel technique that combines elements of digital commu-
nication theory, cryptography, and probability …


Supporting South Korea’S Aging Population: How Ai And Iot Acceptance Connects The Young And Old, Bobby Im May 2024

Supporting South Korea’S Aging Population: How Ai And Iot Acceptance Connects The Young And Old, Bobby Im

Master's Projects and Capstones

In 2024, South Korea surpassed every other nation by becoming the country with the lowest fertility rate (below 0.7%). Population decline will hinder future ability to care for their aging population and although the government and private corporations are investing millions of dollars on developing Artificial Intelligence-Internet of Things (AI-IoT) devices to support the aging, the acceptance levels and the amount of family support required is undervalued. By examining AI-IoT’s current use and role in South Korea’s public health system this paper shows how intergenerational support helps optimize existing procedures and equipment, increases the level of acceptance and use, and …


Improving Tattle-Tale K-Deniability, Nicholas G.E. Morales May 2024

Improving Tattle-Tale K-Deniability, Nicholas G.E. Morales

Student Research Symposium

Ensuring privacy for databases is an ongoing struggle. While the majority of work has focused on using access control lists to protect sensitive data these methods are vulnerable to inference attacks. A set of algorithms, referred to as Tattle-Tale, was developed that could protect sensitive data from being inferred however its runtime performance wasn’t suitable for production code. This set of algorithms contained two main subsets, Full Deniability and K-Deniability. My research focused on improving the runtime or utility of the K-Deniability algorithms. I investigated the runtime of the K-Deniability algorithms to identify what was slowing the process down. Aside …


A Novel Caching Algorithm For Efficient Fine-Grained Access Control In Database Management Systems, Anadi Shakya May 2024

A Novel Caching Algorithm For Efficient Fine-Grained Access Control In Database Management Systems, Anadi Shakya

Student Research Symposium

Fine-grained access Control (FGAC) in DBMS is vital for restricting user access to authorized data and enhancing security. FGAC policies govern how users are granted access to specific resources based on detailed criteria, ensuring security and privacy measures. Traditional methods struggle with scaling policies to thousands, causing delays in query responses. This paper introduces a novel caching algorithm designed to address this challenge by accelerating query processing and ensuring compliance with FGAC policies. In our approach, we create a circular hashmap and employ different replacement techniques to efficiently manage the cache, prioritizing entries that are visited more frequently. To evaluate …


Securing The Internet Of Things At Scale, Steven L. Willoughby May 2024

Securing The Internet Of Things At Scale, Steven L. Willoughby

Student Research Symposium

The world of the connected “Internet of Things” (IoT), including the "Industrial Internet of Things" (IIoT) is expanding to include more devices which observe and influence our daily lives, routines, locations, and even our state of health. But have the underlying protocols by which they communicate this data kept pace with the need to protect our privacy and security?

My talk will introduce my research into an approach to better secure this information flow using appropriate access controls without sacrificing performance. I will assess the historical challenges and simple access controls applied to IoT networking protocols and how they can …


Generative Machine Learning For Cyber Security, James Halvorsen, Dr. Assefaw Gebremedhin May 2024

Generative Machine Learning For Cyber Security, James Halvorsen, Dr. Assefaw Gebremedhin

Military Cyber Affairs

Automated approaches to cyber security based on machine learning will be necessary to combat the next generation of cyber-attacks. Current machine learning tools, however, are difficult to develop and deploy due to issues such as data availability and high false positive rates. Generative models can help solve data-related issues by creating high quality synthetic data for training and testing. Furthermore, some generative architectures are multipurpose, and when used for tasks such as intrusion detection, can outperform existing classifier models. This paper demonstrates how the future of cyber security stands to benefit from continued research on generative models.


Privacy Protection In Mobile Photography With Face Cloaking, Rithyka Heng May 2024

Privacy Protection In Mobile Photography With Face Cloaking, Rithyka Heng

Computer Science and Computer Engineering Undergraduate Honors Theses

In a world of increasing connectivity, privacy is becoming ever-more difficult to maintain. People have little control over the capture of their image while in public and have even less control over the online sharing or posting of their image. This leaves many people vulnerable to being tracked or profiled via their image’s presence in other people’s photos. This thesis implements and evaluates an approach to privacy protection that involves the photographers protecting the privacy of bystanders. Because most photographs are now being taken by smartphones, a mobile application is decidedly the technology that would best achieve widespread adoption and …


Side Channel Detection Of Pc Rootkits Using Nonlinear Phase Space, Rebecca Clark May 2024

Side Channel Detection Of Pc Rootkits Using Nonlinear Phase Space, Rebecca Clark

Poster Presentations

Cyberattacks are increasing in size and scope yearly, and the most effective and common means of attack is through malicious software executed on target devices of interest. Malware threats vary widely in terms of behavior and impact and, thus, effective methods of detection are constantly being sought from the academic research community to offset both volume and complexity. Rootkits are malware that represent a highly feared threat because they can change operating system integrity and alter otherwise normally functioning software. Although normal methods of detection that are based on signatures of known malware code are the standard line of defense, …


Exploring Decentralized Computing Using Solid And Ipfs For Social Media Applications, Pranav Balasubramanian Natarajan May 2024

Exploring Decentralized Computing Using Solid And Ipfs For Social Media Applications, Pranav Balasubramanian Natarajan

Computer Science and Computer Engineering Undergraduate Honors Theses

As traditional centralized social media platforms face growing concerns over data privacy, censorship, and lack of user control, there has been an increasing interest in decentralized alternatives. This thesis explores the design and implementation of a decentralized social media application by integrating two key technologies: Solid and the InterPlanetary File System (IPFS). Solid, led by Sir Tim Berners-Lee, enables users to store and manage their personal data in decentralized "Pods," giving them ownership over their digital identities. IPFS, a peer-to-peer hypermedia protocol, facilitates decentralized file storage and sharing, ensuring content availability and resilience against censorship. By leveraging these technologies, the …


Detection Of Jamming Attacks In Vanets, Thomas Justice May 2024

Detection Of Jamming Attacks In Vanets, Thomas Justice

Undergraduate Honors Theses

A vehicular network is a type of communication network that enables vehicles to communicate with each other and the roadside infrastructure. The roadside infrastructure consists of fixed nodes such as roadside units (RSUs), traffic lights, road signs, toll booths, and so on. RSUs are devices equipped with communication capabilities that allow vehicles to obtain and share real-time information about traffic conditions, weather, road hazards, and other relevant information. These infrastructures assist in traffic management, emergency response, smart parking, autonomous driving, and public transportation to improve roadside safety, reduce traffic congestion, and enhance the overall driving experience. However, communication between the …


An In-Network Approach For Pmu Missing Data Recovery With Data Plane Programmability, Jack Norris May 2024

An In-Network Approach For Pmu Missing Data Recovery With Data Plane Programmability, Jack Norris

Computer Science and Computer Engineering Undergraduate Honors Theses

Phasor measurement unit (PMU) systems often experience unavoidable missing and erroneous measurements, which undermine power system observability and operational effectiveness. Traditional solutions for recovering missing PMU data employ a centralized approach at the control center, resulting in lengthy recovery times due to data transmission and aggregation. In this work, we leverage P4-based programmable networks to expedite missing data recovery. Our approach utilizes the data plane programmability offered by P4 to present an in-network solution for PMU data recovery. We establish a data-plane pipeline on P4 switches, featuring a customized PMU protocol parser, a missing data detection module, and an auto-regressive …


Monero: Powering Anonymous Digital Currency Transactions, Jake Braddy May 2024

Monero: Powering Anonymous Digital Currency Transactions, Jake Braddy

Theses/Capstones/Creative Projects

Cryptocurrencies rely on a distributed public ledger (record of transactions) in order to perform their intended functions. However, the public’s ability to audit the network is both its greatest strength and greatest weakness: Anyone can see what address sent currency, and to whom the currency was sent. If cryptocurrency is ever going to take some of the responsibility of fiat currency, then there needs to be a certain level of confidentiality. Thus far, Monero has come out on top as the preferred currency for embodying the ideas of privacy and confidentiality. Through numerous cryptographic procedures, Monero is able to obfuscate …


A Study Of Cybersecurity Landscape In The United States: Trend, Regional Variations, And Socioeconomic Factors, Trang Thi Thu Horn May 2024

A Study Of Cybersecurity Landscape In The United States: Trend, Regional Variations, And Socioeconomic Factors, Trang Thi Thu Horn

All-Inclusive List of Electronic Theses and Dissertations

The Internet has become an essential part of our daily lives. Cyberspace has emerged significantly with an enormous number of users, creating a lucrative hunting field for cybercriminals. The exponential growth of internet users and online activities, along with the increased sophistication of cybercrimes, is raising significant global concerns for individuals, organizations, and governments. This research aims to explore the cybersecurity landscape in the United States, investigate regional variations, and the potential impact of the COVID-19 pandemic on the number of cybercrimes. The study utilizes a mixed research method approach, including historical analysis and a Delphi study. Historical analysis studied …


Formalization Of A Security Framework Design For A Health Prescription Assistant In An Internet Of Things System, Thomas Rolando Mellema May 2024

Formalization Of A Security Framework Design For A Health Prescription Assistant In An Internet Of Things System, Thomas Rolando Mellema

Electronic Theses and Dissertations

Security system design flaws will create greater risks and repercussions as the systems being secured further integrate into our daily life. One such application example is incorporating the powerful potential of the concept of the Internet of Things (IoT) into software services engineered for improving the practices of monitoring and prescribing effective healthcare to patients. A study was performed in this application area in order to specify a security system design for a Health Prescription Assistant (HPA) that operated with medical IoT (mIoT) devices in a healthcare environment. Although the efficiency of this system was measured, little was presented to …