Long Term Key Management Architecture For Scada Systems,
2018
Singapore Management University
Long Term Key Management Architecture For Scada Systems, Hendra Saputra, Zhigang Zhao
Research Collection School Of Computing and Information Systems
A SCADA key management is required to provide a key management protocol that will be used to secure the communication channel of the SCADA entities. The SCADA key management scheme often uses symmetric cryptography due to resource constraints of the SCADA entities. Normally the use of symmetric cryptography mechanism is in the form of pre-shared keys, which are installed manually and are fixed. Then, these pre-shared keys or long term keys are used to generate session keys. However, it is important that these long term keys can be updated and refreshed dynamically. With the nature of SCADA systems which may …
Attribute-Based Cloud Storage With Secure Provenance Over Encrypted Data,
2018
Royal Melbourne Institute of Technology
Attribute-Based Cloud Storage With Secure Provenance Over Encrypted Data, Hui Cui, Robert H. Deng, Yingjiu Li
Research Collection School Of Computing and Information Systems
To securely and conveniently enjoy the benefits of cloud storage, it is desirable to design a cloud data storage system which protects data privacy from storage servers through encryption, allows fine-grained access control such that data providers can expressively specify who are eligible to access the encrypted data, enables dynamic user management such that the total number of data users is unbounded and user revocation can be carried out conveniently, supports data provider anonymity and traceability such that a data provider’s identity is not disclosed to data users in normal circumstances but can be traced by a trusted authority if …
Secure Fine-Grained Access Control And Data Sharing For Dynamic Groups In The Cloud,
2018
University of Wollongong
Secure Fine-Grained Access Control And Data Sharing For Dynamic Groups In The Cloud, Shengmin Xu, Guomin Yang, Yi Mu, Robert H. Deng
Research Collection School Of Computing and Information Systems
Cloud computing is an emerging computing paradigm that enables users to store their data in a cloud server to enjoy scalable and on-demand services. Nevertheless, it also brings many security issues, since cloud service providers (CSPs) are not in the same trusted domain as users. To protect data privacy against untrusted CSPs, existing solutions apply cryptographic methods (e.g., encryption mechanisms) and provide decryption keys only to authorized users. However, sharing cloud data among authorized users at a fine-grained level is still a challenging issue, especially when dealing with dynamic user groups. In this paper, we propose a secure and efficient …
An Overview Of The Usage Of Default Passwords,
2018
University of New Haven
An Overview Of The Usage Of Default Passwords, Brandon Knierem, Xiaolu Zhang, Philip Levine, Frank Breitinger, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
The recent Mirai botnet attack demonstrated the danger of using default passwords and showed it is still a major problem. In this study we investigated several common applications and their password policies. Specifically, we analyzed if these applications: (1) have default passwords or (2) allow the user to set a weak password (i.e., they do not properly enforce a password policy). Our study shows that default passwords are still a significant problem: 61% of applications inspected initially used a default or blank password. When changing the password, 58% allowed a blank password, 35% allowed a weak password of 1 character.
Tactful Inattention: Erving Goffman, Privacy In The Digital Age, And The Virtue Of Averting One's Eyes,
2018
Chicago-Kent College of Law
Tactful Inattention: Erving Goffman, Privacy In The Digital Age, And The Virtue Of Averting One's Eyes, Elizabeth De Armond
All Faculty Scholarship
No abstract provided.
How Much Should We Spend To Protect Privacy?: Data Breaches And The Need For Information We Do Not Have,
2018
University of Illinois at Chicago
How Much Should We Spend To Protect Privacy?: Data Breaches And The Need For Information We Do Not Have, Richard Warner, Robert Sloan
All Faculty Scholarship
A cost/benefit approach to privacy confronts two tradeoff issues. One is making appropriate tradeoffs between privacy and many goals served by the collection, distribution, and use of information. The other is making tradeoffs between investments in preventing unauthorized access to information and the variety of other goals that also make money, time, and effort demands. Much has been written about the first tradeoff. We focus on the second. The issue is critical. Data breaches occur at the rate of over three a day, and the aggregate social cost is extremely high. The puzzle is that security experts have long explained …
Introduction - Syllabus,
2018
Old Dominion University
Introduction - Syllabus, C. Ariel Pinto
Module 1: Fundamentals of Cybersecurity Risk Management
Cybersecurity risk management is a necessary tool for decision making for all management levels from tactical to strategic and creating a common understanding between people from diverse domains or having different priorities. This course adopts a multidisciplinary perspective. It creates a common understanding of risk for a diverse set of students which are coming from different disciplines such as technical, social, economics, law, and politics to remove communication barriers between strategic, operational, and tactical level decision makers.
The course covers related government and industry regulations and standards along with best practices frequently used to assess, analyze and manage cyber risks, …
A Malware Analysis And Artifact Capture Tool,
2018
Dakota State University
A Malware Analysis And Artifact Capture Tool, Dallas Wright, Josh Stroschein
Research & Publications
Malware authors attempt to obfuscate and hide their code in its static and dynamic states. This paper provides a novel approach to aid analysis by intercepting and capturing malware artifacts and providing dynamic control of process flow. Capturing malware artifacts allows an analyst to more quickly and comprehensively understand malware behavior and obfuscation techniques and doing so interactively allows multiple code paths to be explored. The faster that malware can be analyzed the quicker the systems and data compromised by it can be determined and its infection stopped. This research proposes an instantiation of an interactive malware analysis and artifact …
Preparing Millennials As Digital Citizens And Socially And Environmentally Responsible Business Professionals In A Socially Irresponsible Climate,
2018
Winthrop University
Preparing Millennials As Digital Citizens And Socially And Environmentally Responsible Business Professionals In A Socially Irresponsible Climate, Barbara Burgess-Wilkerson, Clovia Hamilton, Chlotia Garrison, Keith Robbins
Winthrop Faculty and Staff Publications
No abstract provided.
Examining The Influence Of Technology Acceptance, Self-Efficacy, And Locus Of Control On Information Security Behavior Of Social Media Users,
2018
Eastern Michigan University
Examining The Influence Of Technology Acceptance, Self-Efficacy, And Locus Of Control On Information Security Behavior Of Social Media Users, Abdullah Almuqrin
Master's Theses and Doctoral Dissertations
Due to recent advances in online communication technology, social networks have become a vital avenue for human interaction. At the same time, they have been exploited as a target for viruses, attacks, and security threats. The first line of defense against such attacks and threats— as well as their primary cause—are social media users themselves. This study investigated the relationship between certain personality factors among social media users—i.e., technology acceptance of security protection technologies, self-efficacy of information security, and locus of control—and their information security behavior. Quantitative methods were used to examine this relationship. The population consisted of all students …
Graduate Admissions Recruitment Project,
2018
Clark University
Graduate Admissions Recruitment Project, Kevin Anderson, Chiemela Dike, Yixin Du, Arvinder Kaur, Amanda Popp, Huizhong Yang
School of Professional Studies
In this project, several comparison schools were interviewed and disclosed to have used search lists to find candidates. The organizations that have valuable search lists which may be of good use for the School of Professional Studies include Educational Testing Service (ETS) and the Graduate Management Admission Council (GMAC). By choosing criteria such as demographics, location, academic performance, educational history provided by search lists, we believe there are many quality candidates for SPS programs. However, as we further investigated the functionality and cost-efficiency or return of investment of GRE search list, we spotted many uncertainties and few solid and successful …
Worcester Center For Crafts: A Transition To Online Sales,
2018
Clark University
Worcester Center For Crafts: A Transition To Online Sales, Monica Gow, Carly Branconnier, Srilatha Prodduturi, Ekaterina Shusharina, Alberta Yamoah
School of Professional Studies
The Clark University School of Professional Studies created a capstone team consisting of Monica Gow, Carly Branconnier, Iana Matkovskaia, Srilatha Prodduturi, Ekaterina Shusharina, and Alberta Yamoah to assist Worcester Center for Crafts (WCC) with the launch of their new online store. Worcester Center for Crafts wanted to showcase their beautiful American handmade crafts on an online platform, Shopify, in order to increase their sales and expand their market reach. The capstone team created a charter that outlined the scope of the project and what the team would deliver to WCC by the end of the project. The team agreed to …
Audubon Data Project Final Report,
2018
Clark University
Audubon Data Project Final Report, Askhat Beygenov, Valinur Kutlambetov, Shrikant Patel, Phoebe Roberts, Ulfat Sayyed, Shriram Sivaraman
School of Professional Studies
The Audubon Data Project was initiated as a Clark University Capstone project. The project’s client, Mass Audubon’s Shaping the Future of Your Community program, had identified a need to improve their data management methods and make better use of their data. The Capstone team, composed of Clark University graduate students, met with the client regularly to review the current state of the data and potential improvements to be made. The process began with a data review. During the review we worked with the client to explicitly define the purposes and requirements of the data, the current process for updating and …
Assessment Of Information Security Culture In Higher Education,
2018
University of Central Florida
Assessment Of Information Security Culture In Higher Education, Henry Glaspie
Electronic Theses and Dissertations
Information security programs are instituted by organizations to provide guidance to their users who handle their data and systems. The main goal of these programs is to protect the organization's information assets through the creation and cultivation of a positive information security culture within the organization. As the collection and use of data expands in all economic sectors, the threat of data breach due to human error increases. Employee's behavior towards information security is influenced by the organizations information security programs and the overall information security culture. This study examines the human factors of an information security program and their …
A Formally Verified Heap Allocator,
2018
Syracuse University
A Formally Verified Heap Allocator, Arash Sahebolamri, Scott D. Constable, Steve J. Chapin
Electrical Engineering and Computer Science - Technical Reports
We present the formal verification of a heap allocator written in C. We use the Isabelle/HOL proof assistant to formally verify the correctness of the heap allocator at the source code level. The C source code of the heap allocator is imported into Isabelle/HOL using CParser and AutoCorres. In addition to providing the guarantee that the heap allocator is free of bugs and therefore is suitable for use in security critical projects, our work facilitates verification of other projects written in C that utilize Isabelle and AutoCorres.
The Legacy Of Multics And Secure Operating Systems Today,
2018
CUNY Queensborough Community College
The Legacy Of Multics And Secure Operating Systems Today, John Schriner
Publications and Research
This paper looks to the legacy of Multics from 1963 and its influence on computer security. It discusses kernel-based and virtualization-based containment in projects like SELinux and Qubes, respectively. The paper notes the importance of collaborative and research-driven projects like Qubes and Tor Project.
Construction Of A Custom Network Security Appliance,
2018
Eastern Michigan University
Construction Of A Custom Network Security Appliance, Jacob Rickerd
Senior Honors Theses and Projects
Over the last three semesters, I worked toward my final goal to develop a custom network security appliance. I first began by completing a comparison analysis of network intrusion detection systems which are devices that read traffic from the network and determine if network packets should go through or be dropped. Second, I conducted a feasibility study of a custom framework to profile attackers in a network; this yielded positive results. Finally, I worked on creating a custom network security appliance; it uses the profiles I created in my framework to more efficiently block malicious attackers in comparison to other …
Economics-Based Risk Management Of Distributed Denial Of Service Attacks: A Distance Learning Case Study,
2018
Old Dominion University
Economics-Based Risk Management Of Distributed Denial Of Service Attacks: A Distance Learning Case Study, Omer Keskin, Unal Tatar, Omer Poyraz, Ariel Pinto, Adrian Gheorghe
Engineering Management & Systems Engineering Faculty Publications
Managing risk of cyber systems is still on the top of the agendas of Chief Information Security Officers (CISO). Investment in cybersecurity is continuously rising. Efficiency and effectiveness of cybersecurity investments are under scrutiny by boards of the companies. The primary method of decision making on cybersecurity adopts a risk-informed approach. Qualitative methods bring a notion of risk. However, particularly for strategic level decisions, more quantitative methods that can calculate the risk and impact in monetary values are required. In this study, a model is built to calculate the economic value of business interruption during a Distributed Denial-of-Service (DDoS) attack …
Isolated Mobile Malware Observation,
2018
Georgia Southern University
Isolated Mobile Malware Observation, Augustine Paul
College of Graduate Studies: Theses & Dissertations
The idea behind Bring Your Own Device (BYOD) it that personal mobile devices can be used in the workplace to enhance convenience and flexibility. This development encourages organizations to allow access of personal mobile devices to business information and systems for businesses operation. However, BYOD opens a firm to various security risks such as data contamination and the exposure of user interest to criminal activities. Mobile devices were not designed to handle intense data security and advanced security features are frequently turned off. Using personal mobile devices can also expose a system to various forms of security threats like malware. …
Is Working With What We Have Enough?,
2018
Edith Cowan University
Is Working With What We Have Enough?, Brian Cusack, Bryce Antony
Australian Digital Forensics Conference
Augmented reality (AR) digital environments have introduced a new complexity to digital investigation where augmented overlays of real objects may be momentary, changed, distorted and evade the usual methods for evidence collection. It is possible an investigator applying standard investigation methods factually reports a real situation and its digital context but has none of the relevant evidence. In this situation the potential for a fair hearing is low and the chance of retrial high. Such situations are unacceptably dangerous and require redress. In this paper the AR condition is considered in terms of its complexity and management during an investigation. …
