A Comparison Of Personal Social Media Risk Perceptions Between Undergraduate Students And Human Resource Professionals,
2017
University of Alabama, Birmingham
A Comparison Of Personal Social Media Risk Perceptions Between Undergraduate Students And Human Resource Professionals, Julio C. Rivera, Jack Howard, Samuel Goh, James Worrell, Paul Di Gangi
KSU Proceedings on Cybersecurity Education, Research and Practice
This study contrasts the social media risk perceptions of undergraduate students, versus those of certified Human Resource professionals. Social media is widely used by most segments of the population, and particularly among the age group that includes most undergraduate students. Organizations hiring employees are increasingly examining job applicant's social media postings as part of the applicant screening process. In this study we examine how these groups differ in their perceptions of the risks inherent in using social media, and what these differences may mean for students seeking employment. Recommendations are made for raising undergraduate student awareness of these risks.
Experiments With Applying Artificial Immune System In Network Attack Detection,
2017
North Carolina A & T State University
Experiments With Applying Artificial Immune System In Network Attack Detection, Alexis Cooper
KSU Proceedings on Cybersecurity Education, Research and Practice
The assurance of security within a network is difficult due to the variations of attacks. This research conducts various experiments to implement an Artificial Immune System based Intrusion Detection System to identify intrusions using the Negative Selection Algorithm. This research explores the implementation of an Artificial Immune System opposed to the industry standard of machine learning. Various experiments were conducted to identify a method to separate data to avoid false-positive results. The use of an Artificial Immune System requires a self and nonself classification to determine if an intrusion is present within the network. The results of an Artificial Immune …
Reducing Human Error In Cyber Security Using The Human Factors Analysis Classification System (Hfacs).,
2017
Nova Southeastern University
Reducing Human Error In Cyber Security Using The Human Factors Analysis Classification System (Hfacs)., Tommy Pollock
KSU Proceedings on Cybersecurity Education, Research and Practice
For several decades, researchers have stated that human error is a significant cause of information security breaches, yet it still remains to be a major issue today. Quantifying the effects of security incidents is often a difficult task because studies often understate or overstate the costs involved. Human error has always been a cause of failure in many industries and professions that is overlooked or ignored as an inevitability. The problem with human error is further exacerbated by the fact that the systems that are set up to keep networks secure are managed by humans. There are several causes of …
A Developmental Study On Assessing The Cybersecurity Competency Of Organizational Information System Users,
2017
Nova Southeastern University
A Developmental Study On Assessing The Cybersecurity Competency Of Organizational Information System Users, Richard Nilsen, Yair Levy, Steven Terrell, Dawn Beyer
KSU Proceedings on Cybersecurity Education, Research and Practice
Organizational information system users (OISUs) that are open to cyber threats vectors are contributing to major financial and information losses for individuals, businesses, and governments. Moreover, technical cybersecurity controls may be rendered useless due to a lack of cybersecurity competency of OISUs. The main goal of this research study was to propose and validate, using subject matter experts (SMEs), a reliable hands-on assessment prototype tool for measuring the knowledge, skills, and abilities (KSAs) that comprise the cybersecurity competency of an OISU. Primarily using the Delphi methodology, this study implemented four phases of data collection using cybersecurity SMEs for proposing and …
Voice Hacking Proof Of Concept: Using Smartphones To Spread Ransomware To Traditional Pcs,
2017
University of North Georgia
Voice Hacking Proof Of Concept: Using Smartphones To Spread Ransomware To Traditional Pcs, Leonardo I. Mazuran, Bryson R. Payne, Tamirat T. Abegaz
KSU Proceedings on Cybersecurity Education, Research and Practice
This paper presents a working proof of concept that demonstrates the ability to deploy a sequence of hacks, triggered by speaking a smartphone command, to launch ransomware and other destructive attacks against vulnerable Windows computers on any wireless network the phone connects to after the voice command is issued. Specifically, a spoken, broadcast, or pre-recorded voice command directs vulnerable Android smartphones or tablets to a malicious download page that compromises the Android device and uses it as a proxy to run software designed to scan the Android device’s local area network for Windows computers vulnerable to the EternalBlue exploit, spreading …
Security Device Roles,
2017
Kennesaw State University
Security Device Roles, Vabrice Wilder
KSU Proceedings on Cybersecurity Education, Research and Practice
“An abstract of this article was published in the proceedings of the Conference on Cybersecurity Education, Research & Practice, 2017”. Communication has evolved since the beginning of mankind from smoke signals to drones to now the internet. In a world filled with technology the security of one’s device is not to be taken for granted. A series of research was done in order to gather details about network devices that can aid in the protection of one’s information while being transferred through the internet. The findings included but not limited to, switches, the seven layers of OSI, routers, firewalls, load …
"Think Before You Click. Post. Type." Lessons Learned From Our University Cyber Secuity Awareness Campaign,
2017
Eastern Michigan University
"Think Before You Click. Post. Type." Lessons Learned From Our University Cyber Secuity Awareness Campaign, Rachael Innocenzi, Kaylee Brown, Peggy Liggit, Samir Tout, Andrea Tanner, Theodore Coutilish, Rocky Jenkins
KSU Proceedings on Cybersecurity Education, Research and Practice
This article discusses the lessons learned after implementing a successful university-wide cyber security campaign. The Cyber Security Awareness Committee (CyberSAC), a group comprised of diverse units across campus, collaborated together on resources, talent, people, equipment, technology, and assessment practices to meet strategic goals for cyber safety and education. The project involves assessing student learning and behavior changes after participating in a Cyber Security Password Awareness event that was run as a year-long campaign targeting undergraduate students. The results have implications for planning and implementing university-wide initiatives in the field of cyber security, and more broadly, higher education at large.
Ssetgami: Secure Software Education Through Gamification,
2017
University of Tennessee at Chattanooga
Ssetgami: Secure Software Education Through Gamification, Hector Suarez, Hooper Kincannon, Li Yang
KSU Proceedings on Cybersecurity Education, Research and Practice
Since web browsers have become essential to accomplishing everyday tasks, developing secure web applications has become a priority in order to protect user data, corporate databases and critical infrastructure against cyber-crimes . This research presents a game-like (gamification) approach to teach key concepts and skills on how to develop secure web applications. Gamification draws on motivational models, one of psychological theories. Gamification design has great potential over traditional education where we often find students demotivated and lecturers failing to engage them in learning activities. This research created game-like learning modules to teach top vulnerabilities and countermeasures for these top vulnerabilities …
Jsforce: A Forced Execution Engine For Malicious Javascript Detection,
2017
Singapore Management University
Jsforce: A Forced Execution Engine For Malicious Javascript Detection, Xunchao Hu, Yao Cheng, Yue Duan, Andrew Henderson, Heng Yin
Research Collection School Of Computing and Information Systems
The drastic increase of JavaScript exploitation attacks has led to a strong interest in developing techniques to analyze malicious JavaScript. Existing analysis techniques fall into two general categories: static analysis and dynamic analysis. Static analysis tends to produce inaccurate results (both false positive and false negative) and is vulnerable to a wide series of obfuscation techniques. Thus, dynamic analysis is constantly gaining popularity for exposing the typical features of malicious JavaScript. However, existing dynamic analysis techniques possess limitations such as limited code coverage and incomplete environment setup, leaving a broad attack surface for evading the detection. To overcome these limitations, …
A Comparative Study On Machine Learning Algorithms For Network Defense,
2017
Norfolk State University
A Comparative Study On Machine Learning Algorithms For Network Defense, Abdinur Ali, Yen-Hung Hu, Chung-Chu (George) Hsieh, Mushtaq Khan
Virginia Journal of Science
Network security specialists use machine learning algorithms to detect computer network attacks and prevent unauthorized access to their networks. Traditionally, signature and anomaly detection techniques have been used for network defense. However, detection techniques must adapt to keep pace with continuously changing security attacks. Therefore, machine learning algorithms always learn from experience and are appropriate tools for this adaptation. In this paper, ten machine learning algorithms were trained with the KDD99 dataset with labels, then they were tested with a different dataset without labels. The researchers investigate the speed and the efficiency of these machine learning algorithms in terms of …
Every Step You Take, I’Ll Be Watching You: Practical Stepauth-Entication Of Rfid Paths,
2017
Singapore Management University
Every Step You Take, I’Ll Be Watching You: Practical Stepauth-Entication Of Rfid Paths, Kai Bu, Yingjiu Li
Research Collection School Of Computing and Information Systems
Path authentication thwarts counterfeits in RFID-based supply chains. Its motivation is that tagged products taking invalid paths are likely faked and injected by adversaries at certain supply chain partners/steps. Existing solutions are path-grained in that they simply regard a product as genuine if it takes any valid path. Furthermore, they enforce distributed authentication by offloading the sets of valid paths to some or all steps from a centralized issuer. This not only imposes network and storage overhead but also leaks transaction privacy. We present StepAuth, the first step-grained path authentication protocol that is practically efficient for authenticating products with strict …
Every Step You Take, I’Ll Be Watching You: Practical Stepauth-Entication Of Rfid Paths,
2017
Singapore Management University
Every Step You Take, I’Ll Be Watching You: Practical Stepauth-Entication Of Rfid Paths, Kai Bu, Yingjiu Li
Research Collection School Of Computing and Information Systems
Path authentication thwarts counterfeits in RFID-based supply chains. Its motivation is that tagged products taking invalid paths are likely faked and injected by adversaries at certain supply chain partners/steps. Existing solutions are path-grained in that they simply regard a product as genuine if it takes any valid path. Furthermore, they enforce distributed authentication by offloading the sets of valid paths to some or all steps from a centralized issuer. This not only imposes network and storage overhead but also leaks transaction privacy. We present StepAuth, the first step-grained path authentication protocol that is practically efficient for authenticating products with strict …
Strong Authenticated Key Exchange With Auxiliary Inputs,
2017
Singapore Management University
Strong Authenticated Key Exchange With Auxiliary Inputs, Rongmao Chen, Yi Mu, Guomin Yang, Willy Susilo, Fuchun Guo
Research Collection School Of Computing and Information Systems
Leakage attacks, including various kinds of side-channel attacks, allow an attacker to learn partial information about the internal secrets such as the secret key and the randomness of a cryptographic system. Designing a strong, meaningful, yet achievable security notion to capture practical leakage attacks is one of the primary goals of leakage-resilient cryptography. In this work, we revisit the modelling and design of authenticated key exchange (AKE) protocols with leakage resilience. We show that the prior works on this topic are inadequate in capturing realistic leakage attacks. To close this research gap, we propose a new security notion named leakage-resilient …
New Framework Of Password-Based Authenticated Key Exchange From Only-One Lossy Encryption,
2017
Singapore Management University
New Framework Of Password-Based Authenticated Key Exchange From Only-One Lossy Encryption, Haiyang Xue, Bao Li, Jingnan He
Research Collection School Of Computing and Information Systems
In this paper, we introduce a new framework of password-based key exchange (PAKE). Until now, most PAKEs are based on smooth projective hash function on secure encryption. Our PAKE does not rely on smooth projective hash function, and consists of a variate lossy encryption, called only-one lossy encryption, and indistinguishable plaintext checkable secure encryption. We also give construction of only-one lossy encryption based decisional Diffie Hellman (DDH) and learning with errors (LWE) assumptions. Although the instantiation based on DDH assumption does not improve efficiency of precious works, our framework provides more easier and elegant way to construct PAKE from LWE …
Analyzing Cyber Threats Affecting The Financial Industry,
2017
Embry-Riddle Aeronautical University
Analyzing Cyber Threats Affecting The Financial Industry, Anna Skelton
Student Works
As critical infrastructure, financial institutions must execute the highest level of cybersecurity as the threat of a crippling cyberattack continues to develop. Malicious actors, including disenfranchised employees, state sponsored actors, and traditional hackers, all have motivations to target the financial industry, and do so frequently. However, the threat changes slightly between resource rich large institutions and their smaller, community bank counterparts. The complex and multifaceted threat must be fully understood in order to properly address and analyze solution options to preserve the security of these institutions and the economy that they contribute to.
Simple Implementation Of An Elgamal Digital Signature And A Brute Force Attack On It,
2017
Embry-Riddle Aeronautical University
Simple Implementation Of An Elgamal Digital Signature And A Brute Force Attack On It, Valeriia Laryoshyna
Student Works
This study is an attempt to show a basic mathematical usage of the concepts behind digital signatures and to provide a simple approach and understanding to cracking basic digital signatures. The approach takes on simple C programming of the ElGamal digital signature to identify some limits that can be encountered and provide considerations for making more complex code. Additionally, there is a literature review of the ElGamal digital signature and the brute force attack.
The research component of this project provides a list of possible ways to crack the basic implementations and classifies the different approaches that could be taken …
Biologically Inspired Network (Bionet) Authentication Using Logical And Pathological Rf-Dna Credential Pairs,
2017
Air Force Institute of Technology
Biologically Inspired Network (Bionet) Authentication Using Logical And Pathological Rf-Dna Credential Pairs, Tyrone A.L. Lewis Sr.
Theses and Dissertations
The command and control (C2) of shared space resources are vulnerable to logical credential forgery and impersonation attacks among standardized and interoperable wireless radio frequency (RF) networks. Threats could come from trusted operators (insiders) or from external sources (outsiders). An attacker may gain unauthorized network access and illegally cross into C2 boundaries when conventional network authentication fails. This research proposes an integrated trust management system that uses both application-layer and physical-layer trust markers to authenticate users and their communication sources. In essence, the results from physical-layer RF-DNA fingerprinting techniques are used to improve application-level trust schemes based on command patterns, …
Security, Computation And Data Issues In Clouds,
2017
Arkansas State University
Security, Computation And Data Issues In Clouds, Lifeng Li
Student Theses and Dissertations
Recently, Cloud has become quite attractive due to its elasticity, availability, and scalability. However, the technologies such as virtualization build up Cloud appear like a double-edged sword because of the expansion on attacking surfaces to entire hardware-software stack. Moreover, homogeneous computing in Cloud severely limits the computational power it could potentially provide. As a result, it is strongly desired to have new and comprehensive solutions to take in all benefits from Cloud and suppress backsides. This thesis proposes three new solutions to address security, computation and data issues in Cloud. Firstly, a GPU MapReduce framework specifically aims at improving performance …
Front Matter,
2017
Embry-Riddle Aeronautical University
Back Matter,
2017
Embry-Riddle Aeronautical University
