Secure And Efficient Outsourcing Of Large-Scale Overdetermined Systems Of Linear Equations,
2018
Singapore Management University
Secure And Efficient Outsourcing Of Large-Scale Overdetermined Systems Of Linear Equations, Shiran Pan, Wen-Tao Zhu, Qiongxiao Wang, Bing Chang
Research Collection School Of Computing and Information Systems
We address overdetermined systems of linear equations, where the number of unknowns is smaller than the number of equations so that only approximate solutions exist instead of exact solutions. Such systems are prevalent in many areas of science and engineering, and finding the optimal solutions is mathematically known as the linear least squares (LLS) problem. Real-world overdetermined systems are often large-scale and computationally expensive to solve. Consequently, we are interested in connecting the LLS problem with cloud computing, where a resource-constrained client outsources the problem to a powerful but untrusted cloud. Among several security considerations is that the input of …
Regular Lossy Functions And Their Applications In Leakage-Resilient Cryptography,
2018
Singapore Management University
Regular Lossy Functions And Their Applications In Leakage-Resilient Cryptography, Yu Chen, Baodong Qin, Haiyang Xue
Research Collection School Of Computing and Information Systems
In STOC 2008, Peikert and Waters introduced a powerful primitive called lossy trapdoor functions (LTFs). In a nutshell, LTFs are functions that behave in one of two modes. In the normal mode, functions are injective and invertible with a trapdoor. In the lossy mode, functions statistically lose information about their inputs. Moreover, the two modes are computationally indistinguishable. In this work, we put forward a relaxation of LTFs, namely, regular lossy functions (RLFs). Compared to LTFs, the functions in the normal mode are not required to be efficiently invertible or even unnecessary to be injective. Instead, they could also be …
An Exploratory Study Of Organizational Security Risk Management For Improved Effectiveness,
2018
Kennesaw State University
An Exploratory Study Of Organizational Security Risk Management For Improved Effectiveness, Angela Jackson-Summers
Doctor of Business Administration Dissertations
Information technology executives continue to have concerns about information security (Kappelman, McLean, Johnson, & Torres, 2016) and the increasing rate of information security threats facing organizations (Ponemon Institute, 2017). This exploratory study aimed to take a closer look at the organizational security risk management process for improved effectiveness, and its integral role among other organizational processes. Two research questions were addressed by identifying organizational drivers to security risk management effectiveness, and by determining challenges to achieving organizational security risk management effectiveness. Using the resource-based view theory (RBV), and Carnegie Mellon University’s Software Engineering Institute Capability Maturity Model Integration …
Data Center Application Security: Lateral Movement Detection Of Malware Using Behavioral Models,
2018
Southen Methodist University, Dallas, Texas
Data Center Application Security: Lateral Movement Detection Of Malware Using Behavioral Models, Harinder Pal Singh Bhasin, Elizabeth Ramsdell, Albert Alva, Rajiv Sreedhar, Medha Bhadkamkar
SMU Data Science Review
Data center security traditionally is implemented at the external network access points, i.e., the perimeter of the data center network, and focuses on preventing malicious software from entering the data center. However, these defenses do not cover all possible entry points for malicious software, and they are not 100% effective at preventing infiltration through the connection points. Therefore, security is required within the data center to detect malicious software activity including its lateral movement within the data center. In this paper, we present a machine learning-based network traffic analysis approach to detect the lateral movement of malicious software within the …
Social Engineering In Non-Linear Warfare,
2018
Marshall University
Social Engineering In Non-Linear Warfare, Bill Gardner
Journal of Applied Digital Evidence
This paper explores the use of hacking, leaking, and trolling by Russia to influence the 2016 United States Presidential Elections. These tactics have been called “the weapons of the geek” by some researchers. By using proxy hackers and Russian malware to break into the email of the Democratic National Committee and then giving that email to Wikileaks to publish on the Internet, the Russian government attempted to swing the election in the favor of their preferred candidate.
The source of the malware used in the DNC hack was determined to be of Russian in nature and has been used on …
Experiential Learning Builds Cybersecurity Self-Efficacy In K-12 Students,
2018
Penn State Berks
Experiential Learning Builds Cybersecurity Self-Efficacy In K-12 Students, Abdullah Konak
Journal of Cybersecurity Education, Research and Practice
In recent years, there have been increased efforts to recruit talented K-12 students into cybersecurity fields. These efforts led to many K-12 extracurricular programs organized by higher education institutions. In this paper, we first introduce a weeklong K-12 program focusing on critical thinking, problem-solving, and igniting interest in information security through hands-on activities performed in a state-of-the-art virtual computer laboratory. Then, we present an inquiry-based approach to design hands-on activities to achieve these goals. We claim that hands-on activities designed based on this inquiry-based framework improve K-12 students’ self-efficacy in cybersecurity as well as their problem-solving skills. The evaluation of …
Student Misconceptions About Cybersecurity Concepts: Analysis Of Think-Aloud Interviews,
2018
San Jose State University
Student Misconceptions About Cybersecurity Concepts: Analysis Of Think-Aloud Interviews, Julia D. Thompson, Geoffrey L. Herman, Travis Scheponik, Linda Oliva, Alan Sherman, Ennis Golaszewski, Dhananjay Phatak, Kostantinos Patsourakos
Journal of Cybersecurity Education, Research and Practice
We conducted an observational study to document student misconceptions about cybersecurity using thematic analysis of 25 think-aloud interviews. By understanding patterns in student misconceptions, we provide a basis for developing rigorous evidence-based recommendations for improving teaching and assessment methods in cybersecurity and inform future research. This study is the first to explore student cognition and reasoning about cybersecurity. We interviewed students from three diverse institutions. During these interviews, students grappled with security scenarios designed to probe their understanding of cybersecurity, especially adversarial thinking. We analyzed student statements using a structured qualitative method, novice-led paired thematic analysis, to document patterns in …
"Think Before You Click. Post. Type." Lessons Learned From Our University Cyber Security Awareness Campaign,
2018
Eastern Michigan University
"Think Before You Click. Post. Type." Lessons Learned From Our University Cyber Security Awareness Campaign, Rachael L. Innocenzi, Kaylee Brown, Peggy Liggit, Samir Tout, Andrea Tanner, Theodore Coutilish, Rocky J. Jenkins
Journal of Cybersecurity Education, Research and Practice
This article discusses the lessons learned after implementing a successful university-wide cyber security campaign. The Cyber Security Awareness Committee (CyberSAC), a group comprised of diverse units across campus, collaborated together on resources, talent, people, equipment, technology, and assessment practices to meet strategic goals for cyber safety and education. The project involves assessing student learning and behavior changes after participating in a Cyber Security Password Awareness event that was run as a year-long campaign targeting undergraduate students. The results have implications for planning and implementing university-wide initiatives in the field of cyber security, and more broadly, higher education at large.
Voice Hacking: Using Smartphones To Spread Ransomware To Traditional Pcs,
2018
University of North Georgia
Voice Hacking: Using Smartphones To Spread Ransomware To Traditional Pcs, Bryson R. Payne, Leonardo I. Mazuran, Tamirat Abegaz
Journal of Cybersecurity Education, Research and Practice
This paper presents a voice hacking proof of concept that demonstrates the ability to deploy a sequence of hacks, triggered by speaking a smartphone command, to launch ransomware and other destructive attacks against vulnerable Windows computers on any wireless network the phone connects to after the voice command is issued. Specifically, a spoken, broadcast, or pre-recorded voice command directs vulnerable Android smartphones or tablets to a malicious download page that compromises the Android device and uses it as a proxy to run software designed to scan the Android device’s local area network for Windows computers vulnerable to the EternalBlue exploit, …
A Case Study In The Implementation Of A Human-Centric Higher Education Cybersecurity Program,
2018
The University of West Florida
A Case Study In The Implementation Of A Human-Centric Higher Education Cybersecurity Program, John W. Coffey, Melanie Haveard, Geissler Golding
Journal of Cybersecurity Education, Research and Practice
This article contains a description of the implementation of a comprehensive cyber security program at a regional comprehensive university. The program was designed to create an effective cyber security management infrastructure and to train end users and other categories of security management personnel in data protection and cyber security. This work addresses the impetus for the program, the rather extensive planning and development that went into the program, its implementation, and insights gleaned from the experience. The paper concludes with a summary of the strengths and weaknesses of the initiative.
From The Editors,
2018
Kennesaw State University
From The Editors, Michael E. Whitman, Herbert J. Mattord, Carole L. Hollingsworth
Journal of Cybersecurity Education, Research and Practice
Welcome to the Spring 2018 issue of the Journal of Cybersecurity Education, Research, and Practice (JCERP). On behalf of the editorial team, we thank you for taking the time to read this issue and strongly encourage you to submit an article for consideration in an upcoming edition.
Compact Hardware Implementation Of A Sha-3 Core For Wireless Body Sensor Networks,
2018
Wuhan University, China
Compact Hardware Implementation Of A Sha-3 Core For Wireless Body Sensor Networks, Yi Yang, Debiao He, Neeraj Kumar, Sherali Zeadally
Information Science Faculty Publications
One of the most important Internet of Things applications is the wireless body sensor network (WBSN), which can provide universal health care, disease prevention, and control. Due to large deployments of small scale smart sensors in WBSNs, security, and privacy guarantees (e.g., security and safety-critical data, sensitive private information) are becoming a challenging issue because these sensor nodes communicate using an open channel, i.e., Internet. We implement data integrity (to resist against malicious tampering) using the secure hash algorithm 3 (SHA-3) when smart sensors in WBSNs communicate with each other using the Internet. Due to the limited resources (i.e., storage, …
Survey Results On Adults And Cybersecurity Education,
2018
University of New Haven
Survey Results On Adults And Cybersecurity Education, Frank Breitinger, Joseph Ricci, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
Cyberattacks and identity theft are common problems nowadays where researchers often say that humans are the weakest link in the security chain. Therefore, this survey focused on analyzing the interest for adults for ‘cyber threat education seminars’, e.g., how to project themselves and their loved ones. Specifically, we asked questions to understand a possible audience, willingness for paying / time commitment, or fields of interest as well as background and previous training experience. The survey was conducted in late 2016 and taken by 233 participants. The results show that many are worried about cyber threats and about their children exploring …
Is Information Systems Misuse Always Bad? A New Perspective On Is Misuse In Hospitals Under The Context Of Disasters,
2018
Dakota State University
Is Information Systems Misuse Always Bad? A New Perspective On Is Misuse In Hospitals Under The Context Of Disasters, Dheyaaldin Alsalman
Masters Theses & Doctoral Dissertations
Although the extant literature has investigated how individuals engage in inappropriate behaviors based on the rational choice theory (RCT) (e.g., computer misconduct), the neutralization theory (e.g., IS security policies violation), and workarounds under normal situations, it has given little consideration to how individuals are involved in misuse of information systems with a good intention under the context of disasters. To fill this research gap, we propose a selfless misuse model, which offers a theoretical explanation for the concept of individuals’ selfless misuse intention under uncertainty caused by disasters. In this study, we show why employees make decisions to misuse the …
Lattice-Based Dual Receiver Encryption And More,
2018
Singapore Management University
Lattice-Based Dual Receiver Encryption And More, Daode Zhang, Kai Zhang, Bao Li, Xianhui Lu, Haiyang Xue, Jie Li
Research Collection School Of Computing and Information Systems
Dual receiver encryption (DRE), proposed by Diament et al. at ACM CCS 2004, is a special extension notion of public-key encryption, which enables two independent receivers to decrypt a ciphertext into a same plaintext. This primitive is quite useful in designing combined public key cryptosystems and denial of service attack-resilient protocols. Up till now, a series of DRE schemes are constructed with bilinear pairing groups. In this work, we introduce the first construction of lattice-based DRE. Our scheme is secure against chosen-ciphertext attacks from the standard Learning with Errors (LWE) assumption with a public key of bit-size about 2nmlogq, where …
An Assessment Of Users’ Cyber Security Risk Tolerance In Reward-Based Exchange,
2018
Singapore Management University
An Assessment Of Users’ Cyber Security Risk Tolerance In Reward-Based Exchange, Xinhui Zhan, Fiona Fui-Hoon Nah, Maggie X. Cheng
Research Collection School Of Computing and Information Systems
This study examines users’ risk-taking behavior in software downloads. We are interested in quantifying the degree of risks that users are willing to take in the cyber security context. We propose conducting an experiment using Amazon’s Mechanical Turk to assess the degree of risks that people are willing to take for monetary gains when they download software from uncertified sources.
Experience Constructing The Artifact Genome Project (Agp): Managing The Domain's Knowledge One Artifact At A Time,
2018
University of New Haven
Experience Constructing The Artifact Genome Project (Agp): Managing The Domain's Knowledge One Artifact At A Time, Cinthya Grajeda, Laura Sanchez, Ibrahim Baggili, Devon R. Clark, Frank Breitinger
Electrical & Computer Engineering and Computer Science Faculty Publications
While various tools have been created to assist the digital forensics community with acquiring, processing, and organizing evidence and indicating the existence of artifacts, very few attempts have been made to establish a centralized system for archiving artifacts. The Artifact Genome Project (AGP) has aimed to create the largest vetted and freely available digital forensics repository for Curated Forensic Artifacts (CuFAs). This paper details the experience of building, implementing, and maintaining such a system by sharing design decisions, lessons learned, and future work. We also discuss the impact of AGP in both the professional and academic realms of digital forensics. …
Privacy-Preserving Mining Of Association Rule On Outsourced Cloud Data From Multiple Parties,
2018
Singapore Management University
Privacy-Preserving Mining Of Association Rule On Outsourced Cloud Data From Multiple Parties, Lin Liu, Jinshu Su, Rongmao Chen, Ximeng Liu, Xiaofeng Wang, Shuhui Chen, Ho-Fung Fung Leung
Research Collection School Of Computing and Information Systems
It has been widely recognized as a challenge to carry out data analysis and meanwhile preserve its privacy in the cloud. In this work, we mainly focus on a well-known data analysis approach namely association rule mining. We found that the data privacy in this mining approach have not been well considered so far. To address this problem, we propose a scheme for privacy-preserving association rule mining on outsourced cloud data which are uploaded from multiple parties in a twin-cloud architecture. In particular, we mainly consider the scenario where the data owners and miners have different encryption keys that are …
Situation-Aware Authenticated Video Broadcasting Over Train-Trackside Wifi Networks,
2018
Jinan University - China
Situation-Aware Authenticated Video Broadcasting Over Train-Trackside Wifi Networks, Yongdong Wu, Dengpan Ye, Zhuo Wei, Qian Wang, William Tan, Robert H. Deng
Research Collection School Of Computing and Information Systems
Live video programmes can bring in better travel experience for subway passengers and earn abundant advertisement revenue for subway operators. However, because the train-trackside channels for video dissemination are easily accessible to anyone, the video traffic are vulnerable to attacks which may cause deadly tragedies. This paper presents a situation-aware authenticated video broadcasting scheme in the railway network which consists of train, on-board sensor, trackside GSM-R (Global System for Mobile Communications-Railway) device, WiFi AP (Access Point), and train control center. Specifically, the scheme has four modules: (1) a train uses its on-board sensors to obtain its speed, location, and RSSI …
Security Risk Tolerance In Mobile Payment: A Trade-Off Framework,
2018
Old Dominion University
Security Risk Tolerance In Mobile Payment: A Trade-Off Framework, Yong Chen
Information Technology & Decision Sciences Theses & Dissertations
Security is identified as a major barrier for consumers in adopting mobile payment. Although existing literature has incorporated security into the Technology Acceptance Model (TAM), the Unified Theory of Acceptance, and the Use of Technology (UTAUT) and it has investigated the way in which security affects consumers’ acceptance of mobile payment, security is a factor only in diverse research models. Studies of mobile payment that focus on security are not available. Additionally, previous studies of mobile payment are based on Direct Carrier Billing- (DCB)-based mobile payment or Near Field Communication- (NFC)-based mobile payment. The results regarding security might not be …
