Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 12 of 201.

Leakage-Resilient Easily Deployable And Efficiently Searchable Encryption (Edese), Jiaming YUAN, Yingjiu LI, Jun LI, Daoyuan WU, Jianting NING, Yangguang TIAN, Robert H. DENG 2025 University of Oregon

Leakage-Resilient Easily Deployable And Efficiently Searchable Encryption (Edese), Jiaming Yuan, Yingjiu Li, Jun Li, Daoyuan Wu, Jianting Ning, Yangguang Tian, Robert H. Deng

Research Collection School Of Computing and Information Systems

Easily Deployable and Efficiently Searchable Encryption (EDESE) is a cryptographic primitive designed for practical searchable applications, offering efficient search and easy deployment. However, it remains vulnerable to Leakage-Abuse attacks, allowing adversaries to exploit keyword-matching processes to extract sensitive information. To address these vulnerabilities, we introduce Leakage-Resilient EDESE (LR-EDESE) with k-indistinguishability and controlled leakage functions. We then propose Volume Leakage-Resilient EDESE (VLR-EDESE), a new scheme to protect against both query and document volume leakage. Our experimental results demonstrate that at k = 5000 (maximum security setting), VLR-EDESE incurs an overhead of 63× compared to the baseline EDESE without leakage protection, outperforming …


Enhancing Proof-Of-Learning Security Against Spoofing Attacks Using Model Watermarking, Ozgur Ural 2025 Embry-Riddle Aeronautical University

Enhancing Proof-Of-Learning Security Against Spoofing Attacks Using Model Watermarking, Ozgur Ural

Doctoral Dissertations and Master's Theses

With the rapid expansion of machine learning (ML) technologies across diverse domains such as healthcare, finance, and autonomous systems, ensuring secure and trustworthy training methodologies has become more critical than ever. Proof-of-Learning (PoL) has recently emerged as a foundational mechanism for verifying the computational effort invested in training ML models, thereby certifying the authenticity and reproducibility of the training process. Yet PoL, when deployed in isolation, remains vulnerable to sophisticated spoofing attacks that manipulate its subset-verification pathways and tolerance parameters. In parallel, model watermarking has become indispensable for safeguarding intellectual property and detecting unauthorized model usage. Motivated by these complementary …


Sanitizable Cross-Domain Access Control With Policy-Driven Dynamic Authorization, Jianfei SUN, Guowen XU, Hongwei LI, Tianwei ZHANG, Cong WU, Xuehuan YANG, Robert H. DENG 2025 University of Electronic Science and Technology of China

Sanitizable Cross-Domain Access Control With Policy-Driven Dynamic Authorization, Jianfei Sun, Guowen Xu, Hongwei Li, Tianwei Zhang, Cong Wu, Xuehuan Yang, Robert H. Deng

Research Collection School Of Computing and Information Systems

The increasing demand for secure and efficient data sharing has underscored the importance of developing robust cryptographic schemes. However, many existing endeavors have overlooked the following critical issues: (1) unauthorized access resulting from malicious information leakage by senders; (2) absence of constraints on write and read permissions for participants; (3) and inflexibility of strategies to dynamically designate ciphertexts to multiple recipients. In this paper, we present SCPA, a cross-domain access control scheme imbued with sanitization features and propelled by policy-driven dynamic authorization, tailored for cloud-based data sharing. This scheme not only facilitates access controls, including regulations for no-read and no-write …


Understanding The Bad Development Practices Of Android Custom Permissions In The Wild, Xiaohan ZHANG, Zhiyuan YU, Xinghua LI, Cen ZHANG, Cong SUN, Ning ZHANG, Robert H. DENG 2025 Xidian University

Understanding The Bad Development Practices Of Android Custom Permissions In The Wild, Xiaohan Zhang, Zhiyuan Yu, Xinghua Li, Cen Zhang, Cong Sun, Ning Zhang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Android system provides application developers with the ability to define custom permissions, which serve to moderate the sharing of resources and interactions with other applications. However, poor development practices of developers can render the permission mechanism ineffective, weakening the system protection. This paper presents a comprehensive examination of the problematic practices surrounding custom permissions employed by developers, referred to as Bad Practices of Custom Permissions (BPCP issues). To accomplish this, we conducted an empirical study and identified nine common BPCP issue patterns that can lead to various adverse consequences, such as installation failures, crashes, or even component hijacking. To automatically …


Real-World Continuous Smartwatch-Based User Authentication, N. Al-Naffakh, N. Clarke, F. Li, P. Haskell-Dowland 2025 Edith Cowan University

Real-World Continuous Smartwatch-Based User Authentication, N. Al-Naffakh, N. Clarke, F. Li, P. Haskell-Dowland

Research outputs 2022 to 2026

User authentication is often regarded as the "gatekeeper"of cyber security. It has, however, long suffered from significant usability issues that have resulted in research focussing upon frictionless and transparent biometric approaches. Activity-based user authentication - a technique that authenticates a user by what they are physically doing at a specific point in time has attracted significant attention, particularly due to the increasing popularity of smartwatches. This research aims to overcome limitations in prior work by exploring the viability of the approach in real-world conditions. The study presents two principal experiments, one focused upon a constrained environment to provide a control …


Integrating Iota Tangle And Artificial Intelligence (Ai) In Iot Network For Network Anomaly Detection, Saida Hafsa Rafique 2025 United Arab Emirates University

Integrating Iota Tangle And Artificial Intelligence (Ai) In Iot Network For Network Anomaly Detection, Saida Hafsa Rafique

Thesis/ Dissertation Defenses

The Internet of Things (IoT) ecosystem has advanced with the advent of Distributed Ledger Technology (DLT) and Artificial Intelligence (AI). Individually, DLT and AI have been explored for enhancement of data management, security, integrity and efficiency of IoT systems. In this thesis, the combined use to apply DLT and AI for network anomaly detection in IoT systems is considered. A framework is proposed to integrate IOTA Tangle, a DLT architecture with Machine Learning (ML)- Random Forest, Decision Trees, and LightGBM, to detect network anomalies in IoT systems. The proposed framework processes network traffic data from UNSW-NB15 dataset and categorizes it …


Advancing Academic Advising With Knowledge Graphs: Integrating Machine Learning And Llms For Personalized Course Planning, Sara Alshamsi 2025 United Arab Emirates University

Advancing Academic Advising With Knowledge Graphs: Integrating Machine Learning And Llms For Personalized Course Planning, Sara Alshamsi

Theses

Academic advising plays a critical role in helping students make informed decisions, improve academic performance, and successfully navigate their university journey. However, with increasing university enrollment, traditional advising methods often struggle to scale, leading to student frustration and overburdened advisors. Additionally, designing course offerings that match student demand is a complex and error-prone process involving multiple stakeholders. To address these challenges, this thesis proposes an automated, data-driven system for generating personalized academic plans for students. The primary aim of this thesis is to develop a system that reduces students’ dependency on advisors while simultaneously providing accurate estimates of course demand …


Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath Routing, Ziming Zhao, Zhaoxuan Li, Xiaofei XIE, Zhipeng Liu, Tingting Li, Jiongchi YU, Fan Zhang, Binbin Chen 2025 Singapore Management University

Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath Routing, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Zhipeng Liu, Tingting Li, Jiongchi Yu, Fan Zhang, Binbin Chen

Research Collection School Of Computing and Information Systems

With the popularity of encryption protocols, machine learning (ML)-based traffic analysis technologies have attracted widespread attention. To adapt to modern high-speed bandwidth, recent research is dedicated to advancing zero-trust intrusion detection by offloading feature extraction and model inference into the network dataplane. Especially, with the rise of programmable switches, achieving line-speed ML inference becomes promising. However, existing research only considers a single switch node as a relay to conduct evaluation. This is far from real-world deployments involving multiple switches (given that zero-trust security assumes that threats can originate from anywhere, including within the network), particularly the multipath routing phenomenon that …


Spos: An Attestation Solution For The Detection And Mitigation Of Point Of Sale Malware, Damian Singh Dhesi 2025 California Polytechnic State University, San Luis Obispo

Spos: An Attestation Solution For The Detection And Mitigation Of Point Of Sale Malware, Damian Singh Dhesi

Master's Theses

Securing 95% of card present transactions, accounting for billions of transactions a year, has made EMV the premier protocol for card-based payment. Created by and named after Europay, Mastercard, and Visa, the EMV protocol provides multiple solutions to resolve security concerns with the outdated, swipe-based, magnetic stripe payment. Such solutions are Chip and PIN which provides a more secure transaction at a significant time cost and EMV contactless which provides improved security to Chip and PIN at greater ease of use with its quick, tap-to-pay based payment. However, regardless of how secure the EMV protocol makes the card side of …


Efficient Gan-Based Adversarial Example Generation Against Ml-Based Network Intrusion Detection Systems, Darren D. Hartono 2025 Cal Poly

Efficient Gan-Based Adversarial Example Generation Against Ml-Based Network Intrusion Detection Systems, Darren D. Hartono

Master's Theses

In the realm of network security, Network Intrusion Detection Systems (NIDS) are essential for identifying and mitigating malicious activities targeting networked devices. Traditionally, these systems have relied on signature-based and anomaly-based detection techniques. However, the increasing complexity and adapt- ability of cyber threats have driven the adoption of Machine Learning (ML) ap- proaches in modern NIDS, significantly improving their ability to detect a wider range of attack vectors. Despite these advancements, ML-based NIDS remain vulnerable to adversarial examples—deliberately crafted inputs designed to mislead models and trigger incorrect classifications. Originally identified in the field of computer vision, adversarial examples now pose …


Some Studies On Information Set Decoding Algorithms And Universal Hash Functions, Sreyosi Bhattacharyya 2025 Indian Statistical Institute

Some Studies On Information Set Decoding Algorithms And Universal Hash Functions, Sreyosi Bhattacharyya

Doctoral Theses

This thesis presents some studies on Information Set Decoding algorithms and Universal Hash Functions. In the context of Information Set Decoding (ISD) the thesis studies time/memory trade-off of ISD algorithms and in the context of universal hash functions, the thesis studies design and efficient implementations of polynomial hash functions defined over prime order fields. A cornerstone of ISD algorithms is the algorithm proposed by Stern and it introduced the meet-in-the-middle collision search approach to ISD algorithms. Though this algorithm is more efficient in terms of asymptotic time complex- ity than the preceding algorithms proposed by Prange, Lee and Brickell and …


Selected Artificial Intelligence Provisions In U.S. Fiscal Year 2025 National Defense Authorization Act, Bert Chapman 2025 Purdue University

Selected Artificial Intelligence Provisions In U.S. Fiscal Year 2025 National Defense Authorization Act, Bert Chapman

Libraries Faculty and Staff Presentations

The 2025 Fiscal Year National Defense Authorization Act contains multiple provisions relating to artificial intelligence (AI). These congressionally mandated provisions direct various sections of the Department of Defense (DOD) and individual U.S. armed service branches to execute congressional intent for AI policymaking. Examples of such intent include identifying and planning DOD's AI workforce, demonstrating AI biotechnology applications for national security, improving the human usability of AI systems, and establishing an AI security center. This presentation will note that reports on these initiatives must be prepared for relevant congressional oversight committees, and, in many cases, are in many cases, publicly released …


Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory 2025 University of Mississippi

Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory

Honors Theses

Phishing attacks are a widespread, malicious phenomenon. These attacks steal people’s personal information, causing them ruin and lining the pockets of criminals. What makes them so dangerous is that they come in a variety of forms, including emails, websites, phone calls, and social media can be vectors for attackers. Fortunately, these attacks can be stopped by informing potential victims of common signs to look out for. Training is one of the best methods people use to teach web-users how to protect themselves. To train them, however, users must be taken through many examples of phishing attacks to learn the characteristics …


Optimizing Information Security In Cloud Environments: A Risk Management Approach And Guide For Enterprise Cloud Security, Joshua Olusegun Oyeniyi, Oluwashina Akinloye Oyeniran 2025 Osun State University

Optimizing Information Security In Cloud Environments: A Risk Management Approach And Guide For Enterprise Cloud Security, Joshua Olusegun Oyeniyi, Oluwashina Akinloye Oyeniran

Journal of Cybersecurity Education, Research and Practice

In recent years, cloud computing has become increasingly integral to organizational operations due to its scalability, accessibility and cost effectiveness in managing data and resources. However, the rise in security threats and attacks on cloud environments necessitates having robust measures in place to protect data confidentiality, integrity and availability. This paper presents an optimized approach to cloud information security management by reviewing the current threat landscape, evaluating key risk management frameworks, and provided practical solutions for enhancing enterprise cloud security. The study examined three leading cloud security frameworks: the Cloud Controls Matrix (CCM) known for its cloud-specific controls, the NIST …


Leveraging P4 Programmable Switches For Resilient Operation And Design Of Phasor Measurement Unit Networks, Eva Casto 2025 University of Arkansas, Fayetteville

Leveraging P4 Programmable Switches For Resilient Operation And Design Of Phasor Measurement Unit Networks, Eva Casto

Electrical Engineering and Computer Science Undergraduate Honors Theses

The power grid utilizes a device called the phasor measurement unit (PMU), allowing power system administrators to remotely monitor and manage the state of the grid in Wide Area Monitoring Systems (WAMS). The advantages of PMUs – such as fine-grained, time-synchronized measurements and efficient, decentralized monitoring – are what make them key devices in the power grid. However, PMU technology also comes with new threats of the digital age, like malfunctions and cyberattacks, which can result in missing and faulty measurements that compromise power grid observability. P4 programmable networks can be used to detect faulty PMU data in a decentralized, …


Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green 2025 Journal of Intelligent Informatics, Networking, and Cybersecurity

Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green

Honors College Theses

As deepfake technology advances, cybercriminals are increasingly using AI-generated videos and audios to impersonate executives and carry out sophisticated CEO fraud schemes. These synthetic forgeries target human trust and corporate communication systems, creating an urgent need for forensic tools capable of authenticating digital evidence with legal accuracy. This thesis presents a forensic-grade AI deepfake detection pipeline designed for this purpose, emphasizing courtroom admissibility, reproducibility, and evidentiary integrity. Built entirely with free, opensource tools, the framework combines metadata analysis, AI-powered spectrogram analysis, neural artifact detection, and facial manipulation recognition into a transparent workflow that accurately identifies synthetic media. It was trained …


Managing Software Dependency Risks In Web Applications, Christopher Alan Scott 2025 Stephen F. Austin State University

Managing Software Dependency Risks In Web Applications, Christopher Alan Scott

Electronic Theses and Dissertations

Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security …


How Do Simulated Phishing Attacks Impact Cybersecurity Awareness And The Enhancement Of Security Protocols Among Faculty Members In A University Environment?, Navnoor Sandhu 2025 Northeastern Illinois University

How Do Simulated Phishing Attacks Impact Cybersecurity Awareness And The Enhancement Of Security Protocols Among Faculty Members In A University Environment?, Navnoor Sandhu

University Honors Program Senior Projects

Phishing attacks are cyber threats where attackers deceive users into performing actions that compromise the user’s security and benefit the attacker. In 2024 alone, phishing attacks have resulted in estimated damages of around 800 million dollars [1]. In response, many institutions have implemented internal simulated phishing attacks to enhance their employees' cybersecurity awareness. This training exercise has been proven beneficial in improving cybersecurity awareness on an enterprise scale[4]. This study aims to evaluate the potential effectiveness of a simulated phishing attack within a university setting, which is a relatively unseen practice thus far. Universities, like other secure organizations, store sensitive …


Capturing The Digital Scene: Applying Routine Activity Theory To Iot Smart Frames, Jordan Bakar 2025 University of Nebraska at Omaha

Capturing The Digital Scene: Applying Routine Activity Theory To Iot Smart Frames, Jordan Bakar

Theses/Capstones/Creative Projects

This project investigates the forensic risks and investigative challenges posed by smart frames, which are WiFi-enabled Internet of Things (IoT) devices used to store, display, and share digital media. These devices often collect and synchronize sensitive media, metadata, and behavioral logs across cloud ecosystems that lack adequate transparency and privacy safeguards. Routine Activity Theory (RAT) provides a criminological framework for examining how the convergence of a motivated offender, a suitable target, and the absence of capable guardianship creates opportunities for misuse and forensic exploitation. Smart frames represent ideal targets because of weak default security configurations, passive data synchronization, and limited …


Cybersecurity's Pr Problem: The Education Gap Fueling Mfa Aversion, Tyler M. Stafford, Catherine Dwyer 2025 Pace University - New York

Cybersecurity's Pr Problem: The Education Gap Fueling Mfa Aversion, Tyler M. Stafford, Catherine Dwyer

Honors College Theses

Through surveying individuals with no professional experience in cybersecurity, this study examines the relationship between awareness and education surrounding security controls and end users’ willingness to adopt them. The findings reveal a strong link between understanding the effectiveness of these controls and user comfort, indicating that as end users’ understanding increases, so does their willingness to use the controls. Working in both identity and access management (IAM) and human risk management, I observed what appeared to be a connection between security education and positive attitudes toward security more broadly, but found limited research statistically linking the two. This study’s findings …


Digital Commons powered by bepress