Automated Tool Support For Security Bug Repair In Mobile Applications,
2019
University of Nebraska at Omaha
Automated Tool Support For Security Bug Repair In Mobile Applications, Larry Singleton
Computer Science Graduate Research Workshop
No abstract provided.
Cyber Security- A New Secured Password Generation Algorithm With Graphical Authentication And Alphanumeric Passwords Along With Encryption,
2019
Old Dominion University
Cyber Security- A New Secured Password Generation Algorithm With Graphical Authentication And Alphanumeric Passwords Along With Encryption, Akash Rao
Electrical & Computer Engineering Theses & Dissertations
Graphical passwords are always considered as an alternative of alphanumeric passwords for their better memorability and usability [1]. Alphanumeric passwords provide an adequate amount of satisfaction, but they do not offer better memorability compared to graphical passwords [1].
On the other hand, graphical passwords are considered less secured and provide better memorability [1]. Therefore many researchers have researched on graphical passwords to overcome the vulnerability. One of the most significant weaknesses of the graphical passwords is "Shoulder Surfing Attack," which means, sneaking into a victim's computer to learn the whole password or part of password or some confidential information. Such …
Quantifying Impact Of Cyber Actions On Missions Or Business Processes: A Multilayer Propagative Approach,
2019
Old Dominion University
Quantifying Impact Of Cyber Actions On Missions Or Business Processes: A Multilayer Propagative Approach, Unal Tatar
Engineering Management & Systems Engineering Theses & Dissertations
Ensuring the security of cyberspace is one of the most significant challenges of the modern world because of its complexity. As the cyber environment is getting more integrated with the real world, the direct impact of cybersecurity problems on actual business frequently occur. Therefore, operational and strategic decision makers in particular need to understand the cyber environment and its potential impact on business. Cyber risk has become a top agenda item for businesses all over the world and is listed as one of the most serious global risks with significant financial implications for businesses.
Risk analysis is one of the …
Machine Learning For Real-Time Data-Driven Security Practices,
2019
Department of Computing, Institute of Technology, Tralee, Kerry, Ireland
Machine Learning For Real-Time Data-Driven Security Practices, Shane Coleman
Theses
The risk of cyber-attacks exploiting vulnerable organisations has increased significantly over the past several years. Cyber-attacks can be described as any type of aggressive strategy which targets computer information systems, computer networks, personal computer systems or other organisational infrastructures which may originate internally or externally. These attacks may combine to exploit a vulnerability breach within a system’s protection strategy which has the potential for loss, damage or destruction of assets. Consequently, every vulnerability has an accompanying risk which is defined as the “intersection of assets, threats, and vulnerabilities”.
This research project uses various types of recommender system techniques, employed for …
On Efficiency Of Artifact Lookup Strategies In Digital Forensics,
2019
CRISP, Center for Research in Security and Privacy
On Efficiency Of Artifact Lookup Strategies In Digital Forensics, Lorenz Liebler, Patrick Schmitt, Harald Baier, Frank Breitinger
Electrical & Computer Engineering and Computer Science Faculty Publications
In recent years different strategies have been proposed to handle the problem of ever-growing digital forensic databases. One concept to deal with this data overload is data reduction, which essentially means to separate the wheat from the chaff, e.g., to filter in forensically relevant data. A prominent technique in the context of data reduction are hash-based solutions. Data reduction is achieved because hash values (of possibly large data input) are much smaller than the original input. Today's approaches of storing hash-based data fragments reach from large scale multithreaded databases to simple Bloom filter representations. One main focus was put on …
A Dendritic Cell Algorithm Based Approach For Malicious Tcp Port Scanning Detection,
2019
United Arab Emirates University
A Dendritic Cell Algorithm Based Approach For Malicious Tcp Port Scanning Detection, Nuha Yousef Al Masalmeh
Information Security Theses
The proliferation of cyber-attacks is accompanied by an urgent need to develop sophisticated detection tools. Some of these tools are based on algorithms inspired by the Human Immune System (HIS). The Dendritic Cell Algorithm (DCA) is one of such HIS inspired methods, which is based on the Danger theory model. In this thesis, two types of DCA algorithms are identified, namely the deterministic a classical DCA in order to improve the algorithm's applicability and performance to detect TCP port scanning. This algorithm consists of components based on the behavior of Human dendritic cells, which involves four categories of the input …
Fair And Dynamic Data Sharing Framework In Cloud-Assisted Internet Of Everything,
2019
Xidian University
Fair And Dynamic Data Sharing Framework In Cloud-Assisted Internet Of Everything, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng, Hongjun Wu, Hongwei Li
Research Collection School Of Computing and Information Systems
Cloud-assisted Internet of Things (IoT) is increasingly prevalent in our society, for example in home and office environment; hence, it is also known as cloud-assisted Internet of Everything (IoE). While in such a setup, data can be easily shared and disseminated (e.g., between a device, such as Amazon Echo and the cloud, such as Amazon AWS), there are potential security considerations that need to be addressed. Thus, a number of security solutions have been proposed. For example, searchable encryption (SE) has been extensively studied due to its capability to facilitate searching of encrypted data. However, threat models in most existing …
Cinema: Efficient And Privacy-Preserving Online Medical Primary Diagnosis With Skyline Query,
2019
Singapore Management University
Cinema: Efficient And Privacy-Preserving Online Medical Primary Diagnosis With Skyline Query, Jianfeng Hua, Hui Zhu, Fengwei Wang, Ximeng Liu, Rongxing Lu, Hao Li, Yeping Zhang
Research Collection School Of Computing and Information Systems
Online medical primary diagnosis system, which can provide convenient medical decision support through applying mobile communication and data analysis technology, has been considered as a promising approach to improve the quality of healthcare service. However, it still faces many severe challenges on the privacy of users' health information and the accuracy of diagnosis result, which deter the wide adoption of online medical primary diagnosis system. In this paper, we propose an efficient and privacy-preserving online medical primary diagnosis (CINEMA) framework. Within CINEMA framework, users can access online medical primary diagnosing service accurately without divulging their medical data. Specifically, based on …
Cybersecurity In The Maritime Domain,
2019
Embry-Riddle Aeronautical University
Cybersecurity In The Maritime Domain, Gary C. Kessler
Publications
In 2017 and 2018, the maritime industry saw a record number of attempted—and many successful—frauds via email, phishing, or other means. Demonstrated and actual attacks on vessel networks, communication systems, and navigation systems have become practically routine. Port and shipping line networks are increasingly vulnerable to what appears to be increasingly targeted attacks against maritime systems.
A Framework To Reveal Clandestine Organ Trafficking In The Dark Web And Beyond,
2019
Department of Computer Science, Volgenau School of Engineering, George Mason University
A Framework To Reveal Clandestine Organ Trafficking In The Dark Web And Beyond, Michael P. Heinl, Bo Yu, Duminda Wijesekera
Journal of Digital Forensics, Security and Law
Due to the scarcity of transplantable organs, patients have to wait on long lists for many years to get a matching kidney. This scarcity has created an illicit market place for wealthy recipients to avoid long waiting times. Brokers arrange such organ transplants and collect most of the payment that is sometimes channeled to fund other illicit activities. In order to collect and disburse payments, they often resort to money laundering-like schemes of money transfers. As the low-cost Internet arrives in some of the affected countries, social media and the dark web are used to illegally trade human organs. This …
Digital Forensics, A Need For Credentials And Standards,
2019
University of Baltimore
Digital Forensics, A Need For Credentials And Standards, Nima Zahadat
Journal of Digital Forensics, Security and Law
The purpose of the conducted study was to explore the credentialing of digital forensic investigators, drawing from applicable literature. A qualitative, descriptive research design was adopted which entailed searching across Google Scholar and ProQuest databases for peer reviewed articles on the subject matter. The resulting scholarship was vetted for timeliness and relevance prior to identification of key ideas on credentialing. The findings of the study indicated that though credentialing was a major issue in digital forensics with an attentive audience of stakeholders, it had been largely overshadowed by the fundamental curricula problems in the discipline. A large portion of research …
Front Matter,
2019
Embry-Riddle Aeronautical University
Immersive Virtual Reality Attacks And The Human Joystick,
2019
University of New Haven
Immersive Virtual Reality Attacks And The Human Joystick, Peter Casey, Ibrahim Baggili, Ananya Yarramreddy
Electrical & Computer Engineering and Computer Science Faculty Publications
This is one of the first accounts for the security analysis of consumer immersive Virtual Reality (VR) systems. This work breaks new ground, coins new terms, and constructs proof of concept implementations of attacks related to immersive VR. Our work used the two most widely adopted immersive VR systems, the HTC Vive, and the Oculus Rift. More specifically, we were able to create attacks that can potentially disorient users, turn their Head Mounted Display (HMD) camera on without their knowledge, overlay images in their field of vision, and modify VR environmental factors that force them into hitting physical objects and …
Unguided Cyber Education Techniques Of The Non-Expert,
2019
Air Force Institute of Technology
Unguided Cyber Education Techniques Of The Non-Expert, Seth A. Martin
Theses and Dissertations
The United States Air Force and Department of Defense continues to rely on its total workforce to provide the first layer of protection against cyber intrusion. Prior research has shown that the workforce is not adequately educated to perform this task. As a result, DoD cybersecurity strategy now includes attempting to improve education and training on cyber-related concepts and technical skills to all users of DoD networks. This paper describes an experiment designed to understand the broad methods that non-expert users may use to educate themselves on how to perform technical tasks. Preliminary results informed subsequent experiments that directly compared …
A Blockchain-Based Anomalous Detection System For Internet Of Things Devices,
2019
Air Force Institute of Technology
A Blockchain-Based Anomalous Detection System For Internet Of Things Devices, Joshua K. Mosby
Theses and Dissertations
Internet of Things devices are highly susceptible to attack, and owners often fail to realize they have been compromised. This thesis describes an anomalous-based intrusion detection system that operates directly on Internet of Things devices utilizing a custom-built Blockchain. In this approach, an agent on each node compares the node's behavior to that of its peers, generating an alert if they are behaving differently. An experiment is conducted to determine the effectiveness at detecting malware. Three different code samples simulating common malware are deployed against a testbed of 12 Raspberry Pi devices. Increasing numbers are infected until two-thirds of the …
Testing The Fault Tolerance Of A Wide Area Backup Protection System Using Spin,
2019
Air Force Institute of Technology
Testing The Fault Tolerance Of A Wide Area Backup Protection System Using Spin, Kenneth James
Theses and Dissertations
Cyber-physical systems are increasingly prevalent in daily life. Smart grids in particular are becoming more interconnected and autonomously operated. Despite the advantages, new challenges arise in the form of defending these assets. Recent studies reveal that small-scale, coordinated cyber-attacks on only a few substations across the U.S. could result in cascading failures affecting the entire nation. In support of defending critical infrastructure, this thesis tests the fault tolerance of a backup protection system. Each transmission line in the system incorporates autonomous agents which monitor the status of the line and make decisions regarding the safety of the grid. Various malfunctions …
Evaluating Machine Learning Techniques For Smart Home Device Classification,
2019
Air Force Institute of Technology
Evaluating Machine Learning Techniques For Smart Home Device Classification, Angelito E. Aragon Jr.
Theses and Dissertations
Smart devices in the Internet of Things (IoT) have transformed the management of personal and industrial spaces. Leveraging inexpensive computing, smart devices enable remote sensing and automated control over a diverse range of processes. Even as IoT devices provide numerous benefits, it is vital that their emerging security implications are studied. IoT device design typically focuses on cost efficiency and time to market, leading to limited built-in encryption, questionable supply chains, and poor data security. In a 2017 report, the United States Government Accountability Office recommended that the Department of Defense investigate the risks IoT devices pose to operations security, …
Cyber-Attack Drone Payload Development And Geolocation Via Directional Antennae,
2019
Air Force Institute of Technology
Cyber-Attack Drone Payload Development And Geolocation Via Directional Antennae, Clint M. Bramlette
Theses and Dissertations
The increasing capabilities of commercial drones have led to blossoming drone usage in private sector industries ranging from agriculture to mining to cinema. Commercial drones have made amazing improvements in flight time, flight distance, and payload weight. These same features also offer a unique and unprecedented commodity for wireless hackers -- the ability to gain ‘physical’ proximity to a target without personally having to be anywhere near it. This capability is called Remote Physical Proximity (RPP). By their nature, wireless devices are largely susceptible to sniffing and injection attacks, but only if the attacker can interact with the device via …
Confidence Inference In Defensive Cyber Operator Decision Making,
2019
Air Force Institute of Technology
Confidence Inference In Defensive Cyber Operator Decision Making, Graig S. Ganitano
Theses and Dissertations
Cyber defense analysts face the challenge of validating machine generated alerts regarding network-based security threats. Operations tempo and systematic manpower issues have increased the importance of these individual analyst decisions, since they typically are not reviewed or changed. Analysts may not always be confident in their decisions. If confidence can be accurately assessed, then analyst decisions made under low confidence can be independently reviewed and analysts can be offered decision assistance or additional training. This work investigates the utility of using neurophysiological and behavioral correlates of decision confidence to train machine learning models to infer confidence in analyst decisions. Electroencephalography …
Preserving Privacy In Automotive Tire Pressure Monitoring Systems,
2019
Air Force Institute of Technology
Preserving Privacy In Automotive Tire Pressure Monitoring Systems, Kenneth L. Hacker
Theses and Dissertations
The automotive industry is moving towards a more connected ecosystem, with connectivity achieved through multiple wireless systems. However, in the pursuit of these technological advances and to quickly satisfy requirements imposed on manufacturers, the security of these systems is often an afterthought. It has been shown that systems in a standard new automobile that one would not expect to be vulnerable can be exploited for a variety of harmful effects. This thesis considers a seemingly benign, but government mandated, safety feature of modern vehicles; the Tire Pressure Monitoring System (TPMS). Typical implementations have no security-oriented features, leaking data that can …
