Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy,
2024
Dakota State University
Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang
Research & Publications
The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach …
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation,
2024
Dakota State University
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings
Research & Publications
This paper presents a multi-cloud networking architecture built on zero trust principles and micro-segmentation to provide secure connectivity with authentication, authorization, and encryption in transit. The proposed design includes the multi-cloud network to support a wide range of applications and workload use cases, compute resources including containers, virtual machines, and cloud-native services, including IaaS (Infrastructure as a Service), PaaS (Platform as a service). Furthermore, open-source tools provide flexibility, agility, and independence from locking to one vendor technology. The paper provides a secure architecture with micro-segmentation and follows zero trust principles to solve multi-fold security and operational challenges.
Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension,
2024
Air Force Institute of Technology
Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira
Theses and Dissertations
Embedded systems are vital in civilian and military applications, requiring high performance and security. The open RISC-V Instruction Set Architecture (ISA) offers significant advantages, including security through community review and strategic independence in microchip supplies. Brazil’s recent partnership with RISC-V highlights its potential for national technological sovereignty. However, RISC-V is not inherently resistant to code reuse attacks (CRAs), highlighting the need to integrate security measures early in development. The RISC-V Compressed extension, while beneficial for optimizing performance and code flexibility, introduces security trade-offs. As RISC-V adoption grows, particularly in critical systems, addressing these security challenges from the start is crucial …
Dynamic Key-Based Privacy-Preserving Authentication Scheme For Internet Of Drones,
2024
The University of Southern Mississippi
Dynamic Key-Based Privacy-Preserving Authentication Scheme For Internet Of Drones, Zain Chaudhary
Honors Theses
The Internet of Drones (IoD) proliferation has catalyzed transformative changes across various industries, from agriculture to urban management. However, expanding drone networks also presents significant security challenges concerning secure communication and authentication. This paper introduces a robust privacy-preserving key-based authentication scheme tailored explicitly for the IoD, utilizing a matrix key generated by Hierarchical Message Authentication Codes (HMAC) and the SHA-256 algorithm to address these vulnerabilities. Our system enhances security by ensuring each drone in the network can authenticate securely and reliably with a central unit, preventing unauthorized access and securing communications against common threats like eavesdropping and impersonation attacks. Our …
Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns,
2024
University of New Orleans
Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns, Jared Wise
LSU New Orleans Theses and Dissertations
In the digital age, text-based passwords remain a primary method for securing online accounts. Yet, users frequently face a dilemma between creating passwords that are easy to remember and sufficiently secure against cyberattacks. This research introduces an approach to password generation that bridges this gap by utilizing linguistic patterns, particularly song lyrics, to develop highly secure and naturally memorable passwords. Using large lyric datasets gained from web scrapes from popular song lyric websites (AZ Lyrics, Genius), features are extracted from a corpus of over 5 million lyrics using sentence structure and natural language processing in a novel way. In using …
A Web Application For Comparing Llm And Knowledge Graph Performance On Cybersecurity Queries,
2024
University of Tennessee at Chattanooga
A Web Application For Comparing Llm And Knowledge Graph Performance On Cybersecurity Queries, Major Schwartz
Honors Theses
The evolution of cybersecurity has led to a spike in digital threats, both in frequency and complexity, necessitating advanced, intelligent solutions to protect sensitive information. Traditional defense mechanisms are increasingly inadequate, pushing cybersecurity professionals to seek innovative approaches for threat detection, response, and data analysis. This thesis investigates the integration of Large Language Models (LLMs) and Knowledge Graphs into cybersecurity workflows to address these challenges. Specifically, it explores the development of a web application that enables real-time, interactive use of state-of-the-art LLMs, such as OpenAI’s GPT-4 and similar models, for improved threat response and workflow efficiency. Built with a React …
Phantom Jam Sybil Attack In Connected Vehicular Networks,
2024
University of Tennessee at Chattanooga
Phantom Jam Sybil Attack In Connected Vehicular Networks, Ahmed Ali Elamin Mohamed
Masters Theses and Doctoral Dissertations
Vehicular Ad-hoc Networks (VANETs) are vulnerable to Sybil attacks, mostly due to the lack of encryption in BSMs. In VANETs, multiple digital certificates (pseudonyms) are assigned to each vehicle to ensure their privacy. However, malicious nodes can exploit these pseudonyms to create ghost vehicles, inducing fake traffic jams and disturbance to other vehicles which may lead to accidents. In this work, we have developed the first sophisticated sybil attack, in which an attacker uses legitimate pseudonyms to create multiple ghost vehicles. These ghost vehicles transmit realistic kinematic data, using trajectory formulas and road maps. Additionally, the ghost vehicles randomly simulate …
A Comparative Study Of Patterns, Causes, And Impacts Of Data Breaches Across Geographical Regions And Time Frames,
2024
California State University – San Bernardino
A Comparative Study Of Patterns, Causes, And Impacts Of Data Breaches Across Geographical Regions And Time Frames, Bhavish Balsara
Electronic Theses, Projects, and Dissertations
The rise of digital technologies and interconnected systems has made data breaches a growing global concern. This culmination project explores the patterns, causes, and impacts of data breaches across various countries with varying levels of economic development and cybersecurity infrastructure from 2020 to 2023. This research aims to provide insights into the global landscape of data breaches and how they have evolved in recent years. The research questions are: (Q1) How do data breach patterns differ between countries with different levels of economic development and cybersecurity infrastructure? (Q2) What patterns and trends can be identified in data breaches when analyzing …
Container Runtime Vulnerability Mitigation Using User Namespace Isolation,
2024
California State University, San Bernardino
Container Runtime Vulnerability Mitigation Using User Namespace Isolation, Alexander Edsell
Electronic Theses, Projects, and Dissertations
Although containers have revolutionized application deployment by allowing for rapid and consistent deployment, their growing adoption has also raised significant security concerns. Each container is an isolated instance of an operating system that comes pre-packaged with the users desired applications. With multiple containers running on a host machine, an adversary can potentially break out of the container into the host machine. This project investigates the effectiveness of user namespace isolation as a security mechanism to mitigate container escape vulnerabilities that target the container’s runtime.
The research questions are: Question 1, does user namespace isolation mitigate container runtime vulnerabilities that target …
Hybrid Deep Learning-Based Model For Eclipse Attack Detection On Ethereum Network,
2024
University of South Alabama
Hybrid Deep Learning-Based Model For Eclipse Attack Detection On Ethereum Network, Dhanasak Bhumichai
Graduate Theses and Dissertations (2019 - present)
An eclipse attack is a significant cyber threat targeting the network layer of blockchain platforms. Detecting eclipse attacks is challenging for several reasons. First, there are no available datasets for training and testing models. Second, comprehensive studies identifying features to detect eclipse attacks are lacking. Additionally, the amount of eclipse network traffic is much smaller than that of normal network traffic, which leads to imbalanced samples. Moreover, the characteristics of eclipse network traffic closely resemble those of normal traffic, causing overlapping samples, which makes it challenging for traditional classifiers to learn how to identify eclipse attacks. To address these challenges, …
Real-Time Network Simulations For Ml/Dl Ddos Detection Using Docker,
2024
California Polytechnic State University, San Luis Obispo
Real-Time Network Simulations For Ml/Dl Ddos Detection Using Docker, Luis D. Garcia
Master's Theses
As the integration of artificial intelligence (AI) within cybersecurity continues to
grow, machine learning (ML) and deep learning (DL) models are increasingly used to
detect cyber attacks. However, these models are rarely evaluated in real-time attack
scenarios to see how subtle changes from the real networking environment can affect
their predictions. To address this issue, we propose a scalable, platform-independent
Docker testbed specifically designed for simulating real-time Distributed Denial of
Service (DDoS) attack scenarios that allows researchers to deploy and evaluate their
pre-trained, ML and DL detection models. Our framework is simple to configure
and can run across Intel and …
Exploring Secure Methods For Ensuring Data Integrity: A Theoretical Analysis Of Cryptographic And Detection Techniques,
2024
California State University, San Bernardino
Exploring Secure Methods For Ensuring Data Integrity: A Theoretical Analysis Of Cryptographic And Detection Techniques, Haryam Garcia Martinez
Electronic Theses, Projects, and Dissertations
This study investigates cryptographic methods to ensure data integrity within cloud environments, with a particular focus on comparing the security, performance, and efficiency of MD5 and SHA-256 hash algorithms. Data integrity is critical for protecting sensitive information, especially in sectors like healthcare, where cloud storage solutions are increasingly prevalent. Through a theoretical analysis, the study evaluates the advantages and limitations of MD5 and SHA-256, emphasizing SHA-256’s stronger security capabilities in preventing collision attacks compared to MD5, albeit with higher resource consumption.
The literature review draws from recent advancements in cryptography, blockchain, and artificial intelligence (AI) technologies, presenting a comprehensive view …
Fortifying Ai-Iot Food Supply Chains: Addressing Third-Party Cybersecurity Vulnerabilities,
2024
California State University, San Bernardino
Fortifying Ai-Iot Food Supply Chains: Addressing Third-Party Cybersecurity Vulnerabilities, Ashwin Chudasama
Electronic Theses, Projects, and Dissertations
The integration of Artificial Intelligence (AI) and the Internet of Things (IoT) technologies within food supply chains has led to significant operational efficiencies but has also introduced cybersecurity vulnerabilities, especially from third-party vendors supplying critical software and hardware. This study explores these vulnerabilities and evaluates multi-layered defense strategies to mitigate the cybersecurity risks they introduce. The research questions guiding this study are: (Q1) How do third-party vendors contribute to cybersecurity vulnerabilities within AI-IoT systems in the food industry? (Q2) How can multi-layered defense strategies effectively mitigate the cybersecurity risks introduced by these vendors?
Using a systematic literature review (SLR) approach …
The Effects Of Covid-19 Lockdowns On Cybersecurity,
2024
California State University, San Bernardino
The Effects Of Covid-19 Lockdowns On Cybersecurity, Natalie Sanders
Electronic Theses, Projects, and Dissertations
The COVID-19 pandemic and subsequent lockdowns forced many Americans to quickly adapt to working from home, many of which had never done so in the past. In addition, organizations were forced to modify security policies and protocols to allow for remote access to sensitive information. The rapid change in security policies as well as the sudden growth of remote access during the pandemic presented a broader landscape for cyber criminals to attack. In this report, we review the number and type of cyberattacks reported from two (2) years before the pandemic through two (2) years after (1998 through 2023), to …
Protocol Transformations Across Osi Network Stack Layers For Attack, Evasion, And Defense,
2024
Clemson University
Protocol Transformations Across Osi Network Stack Layers For Attack, Evasion, And Defense, Nathan Tusing
All Dissertations
Network endpoints frequently contend with errors and deviations within protocols. Many factors account for these deviations including noise, tampering, and algorithm implementations. Intermediate nodes are expected to modify instantiated protocols and not guarantee correctness. This ability to modify traffic enables all sides of network security to alter security and performance properties of protocols, and we define this intermediary modification of an instantiated protocol as a transformation. Protocol transformations traverse layers of the OSI reference model and changes a protocol's time series byte sequence. Within this thesis, we show that this framework applies to multiple domains and protocols. Common examples of …
Digital Humanities: Using Computational Methods On Literature To Understand Human-Water Relations,
2024
William & Mary
Digital Humanities: Using Computational Methods On Literature To Understand Human-Water Relations, Ariel Yang
Cybersecurity Undergraduate Research Showcase
By using computational techniques to analyze literature, deeper insights can be gained into human-water relationships across different historical and cultural contexts. Natural Language Processing (NLP) and other data science methods can explore applications of traditional ecological knowledge (TEK) and underlying emotions or beliefs in literature to help understand sustainability. Protecting this sensitive cultural data through ethical applications can further secure future implementations of policies, urban planning, and environmental relationships.
Security Vulnerabilities In Mobile Operating Systems Used In Iot Devices: An Examination Of Current Challenges And Countermeasures,
2024
Old Dominion University
Security Vulnerabilities In Mobile Operating Systems Used In Iot Devices: An Examination Of Current Challenges And Countermeasures, Isain Cortes Jr.
Cybersecurity Undergraduate Research Showcase
No abstract provided.
Drone Vs. Drone,
2024
Paul D. Camp Community College
Drone Vs. Drone, Mariah Smith
Cybersecurity Undergraduate Research Showcase
This paper focuses on the problems that drones pose to digital and physical infrastructure, as well as potential solutions to combat these issues. One solution is incorporating drone usage into ethical hacking. These drone-based attacks are affecting not only economic spaces but also seemingly high-security areas such as prison systems. It is only a matter of time before critical infrastructure is targeted. Conversely, by simulating drone attacks, drones equipped with complex hacking tools and sensors can detect unauthorized pathways and infiltrate networks for the greater good. Incorporating these new practices would enhance digital and physical protection. "Drone vs. Drone" highlights …
A Dynamical Systems Approach For Modeling Malware Propagating Through A Network And Potential Solutions Towards Mitigating Spread,
2024
William & Mary
A Dynamical Systems Approach For Modeling Malware Propagating Through A Network And Potential Solutions Towards Mitigating Spread, James Johnson
Cybersecurity Undergraduate Research Showcase
Many people draw close parallels between malware propagating through a network and an epidemic spreading through a population. Epidemics are often modeled by a Susceptible-Infected-Recovered (SIR) model, in which a similar system of equations can model the spread of a virus through a computer network, and can be simplified when making assumptions about the network itself and its fixed number of nodes and edges. In this instance, malware propagating in a network also should reflect the network it is propagating through, in which the dynamical system will factor in the nodes of the network and their properties. The system itself …
Enhancing 3d Knowledge-Based Authentication In Vr By Having Fun,
2024
Christopher Newport University
Enhancing 3d Knowledge-Based Authentication In Vr By Having Fun, William James Doyle V, Christopher Kreider
Cybersecurity Undergraduate Research Showcase
In the modern era of cyber attacks, and an ever-changing online world, safety and security must constantly evolve to fit the current standards. In virtual reality (VR) simple keyboard-typed passwords are a thing of the past. These passwords are complicated and frustrating to input. Along with the creation of VR, it also opened the door to a new era of password-based authentication. Using these systems' technology, password inputting can be a fun experience. These passwords are not only easier, and less frustrating to input, but as shown in previous studies, they can also be faster while still being secure. In …
