Bi-Directional Transformers Vs. Word2vec: Discovering Vulnerabilities In Lifted Compiled Code,
2024
Dakota State University
Bi-Directional Transformers Vs. Word2vec: Discovering Vulnerabilities In Lifted Compiled Code, Gary Mccully, John Hastings, Shengjie Xu, Adam Fortier
Research & Publications
Detecting vulnerabilities within compiled binaries is challenging due to lost high-level code structures and other factors such as architectural dependencies, compilers, and optimization options. To address these obstacles, this research explores vulnerability detection using natural language processing (NLP) embedding techniques with word2vec, BERT, and RoBERTa to learn semantics from intermediate representation (LLVM IR) code. Long short-term memory (LSTM) neural networks were trained on embeddings from encoders created using approximately 48k LLVM functions from the Juliet dataset. This study is pioneering in its comparison of word2vec models with multiple bidirectional transformers (BERT, RoBERTa) embeddings built using LLVM code to train neural …
The Psychological Impacts Of Algorithmic And Ai-Driven Social Media On Teenagers: A Call To Action,
2024
Dakota State University
The Psychological Impacts Of Algorithmic And Ai-Driven Social Media On Teenagers: A Call To Action, Sunil Arora, Sahil Arora, John Hastings
Research & Publications
This study investigates the meta-issues surrounding social media, which, while theoretically designed to enhance social interactions and improve our social lives by facilitating the sharing of personal experiences and life events, often results in adverse psychological impacts. Our investigation reveals a paradoxical outcome: rather than fostering closer relationships and improving social lives, the algorithms and structures that underlie social media platforms inadvertently contribute to a profound psychological impact on individuals, influencing them in unforeseen ways. This phenomenon is particularly pronounced among teenagers, who are disproportionately affected by curated online personas, peer pressure to present a perfect digital image, and the …
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration,
2024
Dakota State University
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings
Research & Publications
Digital engineering practices offer significant yet underutilized potential for improving information assurance and system lifecycle management. This paper examines how capabilities like model-based engineering, digital threads, and integrated product lifecycles can address gaps in prevailing frameworks. A reference model demonstrates applying digital engineering techniques to a reference information system, exhibiting enhanced traceability, risk visibility, accuracy, and integration. The model links strategic needs to requirements and architecture while reusing authoritative elements across views. Analysis of the model shows digital engineering closes gaps in compliance, monitoring, change management, and risk assessment. Findings indicate purposeful digital engineering adoption could transform cybersecurity, operations, service …
Confronting The Reproducibility Crisis: A Case Study Of Challenges In Cybersecurity Ai,
2024
Dakota State University
Confronting The Reproducibility Crisis: A Case Study Of Challenges In Cybersecurity Ai, Richard H. Moulton, Gary A. Mccully, John D. Hastings
Research & Publications
In the rapidly evolving field of cybersecurity, ensuring the reproducibility of AI-driven research is critical to maintaining the reliability and integrity of security systems. This paper addresses the reproducibility crisis within the domain of adversarial robustness—a key area in AI-based cybersecurity that focuses on defending deep neural networks against malicious perturbations. Through a detailed case study, we attempt to validate results from prior work on certified robustness using the VeriGauge toolkit, revealing significant challenges due to software and hardware incompatibilities, version conflicts, and obsolescence. Our findings underscore the urgent need for standardized methodologies, containerization, and comprehensive documentation to ensure the …
Setc: A Vulnerability Telemetry Collection Framework,
2024
Dakota State University
Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan
Research & Publications
As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …
A Survey Of Unikernel Security: Insights And Trends From A Quantitative Analysis,
2024
Dakota State University
A Survey Of Unikernel Security: Insights And Trends From A Quantitative Analysis, Alex Wollman, John Hastings
Research & Publications
Unikernels, an evolution of LibOSs, are emerging as a virtualization technology to rival those currently used by cloud providers. Unikernels combine the user and kernel space into one ``uni''fied memory space and omit functionality that is not necessary for its application to run, thus drastically reducing the required resources. The removed functionality is significant however, and includes components that have become common security technologies such as Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), and Non-executable bits (NX bits). This raises questions about the security of unikernels. This research presents a quantitative methodology using TF-IDF to analyze the focus …
A Quantitative Study Assessing The Impact Of Financial Sector Safeguards Rules On Us Publicly Traded Companies' Cybersecurity Breach Frequency And Severity,
2024
Old Dominion University
A Quantitative Study Assessing The Impact Of Financial Sector Safeguards Rules On Us Publicly Traded Companies' Cybersecurity Breach Frequency And Severity, Alan Dinerman
School of Public Service Theses & Dissertations
Cybersecurity failure in the private sector is a growing federal policy priority. Nevertheless, US policy makers struggle with policy instrumentation in this domain. Behavioral public policy theory asserts that a linkage exists between policy target behavioral & cultural attributes and effective policy tool instrumentation. The federal government is now embracing a regulation heavy approach, but little empirical study exists at the nexus of behavioral public policy theory and use of regulatory tools in the cybersecurity policy domain. Since the early 2000s, the financial sector has employed a regulation heavy approach using the Safeguards regulations to facilitate cybersecurity in financial private …
Real Time Pii Scanning,
2024
University of Denver
Real Time Pii Scanning, John David
Electronic Theses and Dissertations
The increased amount of web applications and internet software solutions utilizing cloud frameworks has contributed to large data sets of system log messages being generated constantly. These messages may contain sensitive data, creating an additional security risk for the systems and contributing to the need for analysis of such large volumes of data in real time. Large commercial data monitoring systems can solve for these analysis requirements, but they can be costly. We present a solution to analyzing web application log data which ingests it, processes it and visualizes sensitive data found within in real time. Our solution utilizes an …
Assessment Of Web Security Vulnerabilities For Common Open Source Virtualization Software,
2024
The Open University of Tanzania
Assessment Of Web Security Vulnerabilities For Common Open Source Virtualization Software, Said Ally
Tanzania Journal of Engineering and Technology (TJET)
Open-source hypervisors have emerged as an integral technology for virtualizing server resources in cloud and data center computing. Hypervisor security efficiency is determined by virtual machine isolation, which is a de facto adoption factor in the selection process, as well as its ability to respond to web attacks. This paper assesses the security performance of Proxmox VE and XenServer for type 1 hypervisors, and Kernel Virtual Machine and Oracle Virtual Box for type 2 hypervisors. Security analysis was conducted using common exposures extracted from vulnerability databases and mapped against the OWASP 2013 and 2017 projects. For clarity, experiments were carried …
Investigations Of Cell Tower Antennas Parameters On Reduction Of Radio Frequency Radiation Levels From Radio Base Stations,
2024
Department of Electronics and Telecommunication Engineering, College of Informatics and Virtual Education, The University of Dodoma, Dodoma, Tanzania,
Investigations Of Cell Tower Antennas Parameters On Reduction Of Radio Frequency Radiation Levels From Radio Base Stations, Florence U. Rashidi
Tanzania Journal of Engineering and Technology (TJET)
The widespread deployment of mobile cellular base stations in populated areas has raised public health concerns due to increased exposure to radio frequency (RF) radiation emissions. Exposure to high levels of RF radiation can have potential thermal and non-thermal biological effects. Optimizing the configuration of cell tower antenna parameters is crucial for mitigating these radiation levels. This study therefore aims at systematically investigating the influence of different cell tower antenna parameters on reducing the RF radiation levels from mobile base stations. Field measurements were conducted at two cell sites shared by multiple mobile operators. Electric field strengths were measured at …
Concept And Development Trend Of Novel E-Infrastructure Platform,
2024
National Science Library (Chengdu), Chinese Academy of Sciences, Chengdu 610299, China; Department of Information Resources Management, School of Economics and Management, University of Chinese Academy of Sciences, Beijing 100049, China
Concept And Development Trend Of Novel E-Infrastructure Platform, Jing Xu, Chuan Tang, Kuangjunyu Yang, Juan Zhang, Ru Huang
Bulletin of Chinese Academy of Sciences (Chinese Version)
E-infrastructure platform has become a critical strategic asset for driving national scientific and technological innovation, and is the focus of strategic deployment by technologically advanced countries globally. This study, through the analysis of relevant strategy documents in the United States, European Union, and the United Kingdom, the relevant concepts and development changes of the novel E-infrastructure platform have been clarified. It also summarizes the planning process and development stages of e-infrastructure platform in the United States, Europe, and the United Kingdom, and analyzes that e-infrastructure platform will develop towards a new type of ecological, intelligent, diversified, and full process novel …
Evaluation Of Business-Driven Reference Architecture For Big Data Analytics Implementation By Public Sector Organizations In Resource-Constrained Setting: A Case Study Of Uganda,
2024
Department of Information Systems and Technology, The University of Dodoma, Tanzania
Evaluation Of Business-Driven Reference Architecture For Big Data Analytics Implementation By Public Sector Organizations In Resource-Constrained Setting: A Case Study Of Uganda, Matendo Didas
Tanzania Journal of Engineering and Technology (TJET)
Big Data Analytics (BDA) is a new area at the nexus of agenda, public sector organizations, and government business. It may satisfy the growing need for trustworthy, cost-effective services in the public sector for better, more informed decision-making processes. BDA has been proposed on the planning schedules of several public sector organizations and the government. Therefore, from the previous work, using Uganda as a case study, specifically the Uganda Bureau of Statistics (UBOS), Ministry of Health (MoH), and Ministry of Education and Sports (MoES), this study aims to evaluate a designed Business-Driven Reference Architecture for Big Data Analytics Implementation (BRABDAI) …
Data Communication Over Power-Lines: A Review On Technical, And Applications Challenges,
2024
University of Dar es salaam
Data Communication Over Power-Lines: A Review On Technical, And Applications Challenges, Abdi Abdalla
Tanzania Journal of Engineering and Technology (TJET)
This paper presents a review study on the data communication over power-lines, commonly referred to as power-line carrier, power-line communication (PLC), mains communications, or power-line digital subscriber line (PDSL). This study examines the technical and application advantages and challenges associated with adopting PLC as a preferred alternative technology for wideband or broadband data communication. The broader coverage area of the PLC network gives it a distinct advantage over other communication network technologies. Additionally, implementing a communication system using the existing power-line network is more cost-effective and less time-consuming compared to constructing a new network from scratch. However, the primary challenge …
Cybersecurity In Education,
2024
Montclair State University
Cybersecurity In Education, Rahima Shelim
Theses, Dissertations and Culminating Projects
Cybersecurity is becoming increasingly important as we rely more on digital devices and programs to conduct our daily lives, including the transfer and storage of personal information. According to research, one of the most critical stages in improving cybersecurity is to implement an effective security awareness program. In this work, we seek to understand the existing level of security knowledge among college students, industry professionals and create a module to help raise the awareness. Our module's primary elements are interaction and the display of alarming effects of reckless cyber behaviors among common Internet/technology users. This report presents a simple systematic …
A Privacy-Preserving Federated Learning Framework For Blockchain Networks,
2024
The American University in Cairo
A Privacy-Preserving Federated Learning Framework For Blockchain Networks, Youssif Abuzied, Mohamed Ghanem, Fadi Dawoud, Habiba Gamal, Eslam Soliman, Hossam Sharara, Tamer Elbatt
Faculty Journal Articles
In this paper we introduce a scalable, privacy-preserving, federated learning framework, coined FLoBC, based on the concept of distributed ledgers underlying blockchains. This is motivated by the rapid growth of data worldwide, especially decentralized data which calls for scalable, decenteralized machine learning models which is capable of preserving the privacy of the data of the participating users. Towards this objective, we first motivate and define the problem scope. We then introduce the proposed FLoBC system architecture hinging on a number of key pillars, namely parallelism, decentralization and node update synchronization. In particular, we examine a number of known node update …
A Framework For Evaluating The Security And Privacy Of Smart-Home Devices, And Its Application To Common Platforms,
2024
Dartmouth College
A Framework For Evaluating The Security And Privacy Of Smart-Home Devices, And Its Application To Common Platforms, Ravindra Mangar, Timothy Pierson, David Kotz
Dartmouth Scholarship
In this article, we outline the challenges associated with the widespread adoption of smart devices in homes. These challenges are primarily driven by scale and device heterogeneity: a home may soon include dozens or hundreds of devices, across many device types, and may include multiple residents and other stakeholders. We develop a framework for reasoning about these challenges based on the deployment, operation, and decommissioning life cycle stages of smart devices within a smart home. We evaluate the challenges in each stage using the well-known CIA triad—Confidentiality, Integrity, and Availability. In addition, we highlight open research questions at each stage. …
Development Of An Algorithm To Identify And Calculate The Amount Of File Slack On An Image Of A Given Drive,
2024
University of South Alabama
Development Of An Algorithm To Identify And Calculate The Amount Of File Slack On An Image Of A Given Drive, Nicholas Flynn
Honors Theses
As society increasingly relies on technology, the rates of cyber crime have been increasing at exponential rates. Cyber criminals are also discovering new ways to hide evidence of their crimes. This study develops a forensic analysis algorithm to evaluate the amount of file slack on an image of a drive. Slack space, leftover drive space on a disk sector after a file has been written, can be exploited to hide data. The algorithm aims to detect and calculate this slack space to help direct forensic investigations. The algorithm was evaluated on a population dataset of 100,000 files with random data …
How Do Preservice Teachers Learn To Teach Integrated Computational Thinking?: Evidence From Planning, Enactment, And Reflection,
2024
University of California, Santa Cruz
How Do Preservice Teachers Learn To Teach Integrated Computational Thinking?: Evidence From Planning, Enactment, And Reflection, Rachael Dektor, Samuel Severance, Kip Téllez
Journal of Computer Science Integration
This study examines pre-service teachers’ (PSTs) beliefs and understandings about computational thinking (CT) integration and lesson implementation over time. Utilizing a design-based research approach, 3 PSTs led the co-design of integrated CT lessons with support from researchers and enacted these CT integrated lessons with K-5 students. All PSTs participated in a whole-group CT workshop and engaged in one-on-one lesson design sessions with a researcher. We utilized a grounded theory approach to qualitatively analyze pre-surveys, semi-structured interviews, and video data of three PSTs enacting their lessons. We found that PSTs’ initial beliefs about CT instruction – including the importance of it …
Securing Tomorrow: Synergizing Change Management And Cybersecurity In The Digital Era,
2024
Embry-Riddle Aeronautical University
Securing Tomorrow: Synergizing Change Management And Cybersecurity In The Digital Era, Sharon L. Burton
Publications
In the rapidly evolving business environment of 2024, organizational change management (OCM) leaders face unprecedented challenges driven by technological advancements, digital transformation, the integration of remote work, and a heightened focus on sustainability. This study examines the efficacy of traditional OCM models in addressing these modern complexities. Through a qualitative methodology employing an extensive literature review, the research identifies vital issues such as resistance to change, digital transformation imperatives, the shift to remote and hybrid work models, and the imperative for sustainable and ethical business practices. The study posits that while classical OCM frameworks offer foundational insights, there is a …
Evaluation Of Cybersecurity In Remote Working Settings For Mobile Network Operators,
2024
Mechanical and Industrial Engineering Department, College of Engineering and Technology, University of Dar es Salaam, P.O. Box 35131, Dar es Salaam, Tanzania.
Evaluation Of Cybersecurity In Remote Working Settings For Mobile Network Operators, Victoria Mahabi
Tanzania Journal of Engineering and Technology (TJET)
Cybersecurity has increasingly been a primary concern to people as technology advances and allows them to work remotely. This study thus evaluated the cybersecurity posture for organisations that have opted for remote working culture, whereas emerging cyber threats, practices to combat them, and appropriate guidelines for managing cyber threats were discussed. The study used a descriptive design with a quantitative approach from 118 information technology personnel working for Tanzania's three major mobile network operators (MNOs). SPSS analysed the collected data. The study revealed that predominant cyber-threats affecting MNOs in remote working include human errors, phishing attacks, malicious domains, denial of …
