Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 13 of 201.

5g Network Slice Vulnerabilities And Exploit Chaining Through Enablers, John Breeden 2025 East Tennessee State University

5g Network Slice Vulnerabilities And Exploit Chaining Through Enablers, John Breeden

Electronic Theses and Dissertations

Network slicing provides fundamental support for the enhanced features of 5G. Network slicing enablers, such as software-defined networking and network function virtualization facilitate the separation of the physical distributed infrastructures and the functions that create isolated slices. With this framework, the network slice is no longer under the control of a single entity. Multiple infrastructure providers share responsibility for the slice. The 5G architecture derives from multiple services, distributed over great distances, and managed by multiple parties. Each enabler and provider adds vulnerability to network slicing. We examine the interweaving of these enablers to identify vulnerabilities, discuss potential mitigation, and …


Acccred: Improved Accountable Anonymous Credentials With Dynamic Triple-Hiding Committees, Sijiang XIE, Rui SHI, Yang YANG, Huiqin XIE, Yingjiu LI, Robert H. DENG 2025 University of Science and Technology of China

Acccred: Improved Accountable Anonymous Credentials With Dynamic Triple-Hiding Committees, Sijiang Xie, Rui Shi, Yang Yang, Huiqin Xie, Yingjiu Li, Robert H. Deng

Research Collection School Of Computing and Information Systems

Accountable anonymous credentials protect user privacy while holding the accountability of ill-intentioned individuals, which is a critical feature for applications such as online payments and other financial services. Existing accountable anonymous credentials rely on a public committee of trustworthy members who are assumed not to collude and are well protected to perform privacy revocation. However, this assumption is unsound in blockchain-based cryptocurrency systems because the selected committees may involve nodes with significant stakes, and public nodes serving as committee members are vulnerable against targeted attacks from high-computing power adversaries. In this paper, we propose an improved accountable anonymous credential called …


Sigscope: Detecting And Understanding Off‑Chain Message Signing‑Related Vulnerabilities In Decentralized Applications, Sajad MEISAMI, Hugo DABADIE, Song LI, Yuzhe TANG, Yue DUAN 2025 Singapore Management University

Sigscope: Detecting And Understanding Off‑Chain Message Signing‑Related Vulnerabilities In Decentralized Applications, Sajad Meisami, Hugo Dabadie, Song Li, Yuzhe Tang, Yue Duan

Research Collection School Of Computing and Information Systems

In Web 3.0, an emerging paradigm of building decentralized applications or DApps is off-chain message signing, which has advantages in performance, cost efficiency, and usability compared to conventional transaction-signing schemes. However, message signing burdens DApp developers with extra coding complexity and message designing, leading to new security risks.This paper presents the first systematic study to uncover and characterize the security issues in off-chain message signing schemes and the DApps built atop them. We present a holistic static-analysis framework, SigScope, that uniquely combines the insights extracted from DApp front-end code (HTML and Javascript) off-chain and back-end smart contracts on-chain. We evaluate …


Robust Threshold Ecdsa With Online-Friendly Design In Three Rounds, Guofeng TANG, Haiyang XUE 2025 Singapore Management University

Robust Threshold Ecdsa With Online-Friendly Design In Three Rounds, Guofeng Tang, Haiyang Xue

Research Collection School Of Computing and Information Systems

Threshold signatures, especially ECDSA, enhance key protection by addressing the single-point-of-failure issue. Threshold signing can be divided into offline and online phases, based on whether the message is required. Schemes with low-cost online phases are referred to as “online-friendly”. Another critical aspect of threshold ECDSA for real-world applications is robustness, which guarantees the successful completion of each signing execution whenever a threshold number t of semi-honest participants is met, even in the presence of misbehaving signatories. The state-of-the-art online-friendly threshold ECDSA with-out robustness was developed by Doerner et al. in S&P'24, requiring only three rounds. Recent work by Wong et …


Augsso: Secure Threshold Single-Sign-On Authentication With Popular Password Collection, Changsong JIANG, Chunxiang XU, Guomin YANG 2025 Singapore Management University

Augsso: Secure Threshold Single-Sign-On Authentication With Popular Password Collection, Changsong Jiang, Chunxiang Xu, Guomin Yang

Research Collection School Of Computing and Information Systems

Single-sign-on authentication is widely deployed in mobile systems, which allows an identity server to authenticate a mobile user and issue her/him with a token, such that the user can access diverse mobile services. To address the single-point-offailure problem, threshold single-sign-on authentication (PbTA) is a feasible solution, where multiple identity servers perform user authentication and token issuance in a threshold way. However, existing PbTA schemes confront critical drawbacks. Specifically, these schemes are vulnerable to perpetual secret leakage attacks (PSLA): an adversary perpetually compromises secrets of identity servers (e.g., secret key shares or credentials) to break security. Besides, they fail to achieve …


Hdwsa2: A Secure Hierarchical Deterministic Wallet Supporting Stealth Address And Signature Aggregation, Xin YIN, Zhen LIU, Guomin YANG, Guoxing CHEN, Haojin ZHU 2025 Shanghai Jiaotong University

Hdwsa2: A Secure Hierarchical Deterministic Wallet Supporting Stealth Address And Signature Aggregation, Xin Yin, Zhen Liu, Guomin Yang, Guoxing Chen, Haojin Zhu

Research Collection School Of Computing and Information Systems

Hierarchical Deterministic Wallet (HDW) and Stealth Address (SA) are widely used in cryptocurrency communities due to their functionality and security. In the preliminary version of this work (ESORICS 2022), we formally define the syntax and security models of Hierarchical Deterministic Wallet supporting Stealth Address (HDWSA), capturing the functionality and security requirements imposed by the practice in cryptocurrency. We propose a concrete HDWSA construction and prove its security in the random oracle model. Note that when applied in blockchain, in practice, signature aggregation could reduce the cost of computation, storage, and communication dramatically. In this full version, we develop HDWSA definition …


Empirically Exploring The Physical Realizability Of Adversarial Examples, Ruoyao Wen 2025 Washington University in St. Louis

Empirically Exploring The Physical Realizability Of Adversarial Examples, Ruoyao Wen

McKelvey School of Engineering Graduate Student Theses & Dissertations

The development of autonomous vehicles (AVs) has been accelerated by advancements in deep neural networks (DNNs), which power the complex perception systems necessary for safe and efficient real-world navigation. However, as AVs increasingly integrate into public transportation networks, the robustness of their perception systems against potential vulnerabilities is critical. Among these threats, adversarial attacks—particularly through the use of adversarial patches—pose significant risks. These patches are carefully crafted perturbations designed to mislead DNNs, potentially compromising AV safety by causing incorrect object recognition or misclassification.

While extensive research has demonstrated high attack success rates for adversarial patches in controlled digital environments, their …


Using Machine Learning To Detect Vault (Anti-Forensic) Apps, Michael N. Johnstone, Wencheng Yang, Mohiuddin Ahmed 2025 Edith Cowan University

Using Machine Learning To Detect Vault (Anti-Forensic) Apps, Michael N. Johnstone, Wencheng Yang, Mohiuddin Ahmed

Research outputs 2022 to 2026

Content hiding, or vault applications (apps), are designed with a secondary, often concealed purpose, such as encrypting and storing files. While these apps may serve legitimate functions, they unequivocally present significant challenges for law enforcement. Conventional methods for tackling this issue, whether static or dynamic, prove inadequate when devices—typically smartphones—cannot be modified. Additionally, these methods frequently require prior knowledge of which apps are classified as vault apps. This research decisively demonstrates that a non-invasive method of app analysis, combined with machine learning, can effectively identify vault apps. Our findings reveal that it is entirely possible to detect an Android vault …


Infusing Aboriginal Perspectives In Cyber Education, John Shannahan, Mohiuddin Ahmed 2025 Edith Cowan University

Infusing Aboriginal Perspectives In Cyber Education, John Shannahan, Mohiuddin Ahmed

Research outputs 2022 to 2026

While human factors are important in cyber security, the discipline has largely not explored incorporating indigenous perspectives—or, more specifically, in an Australian context, Aboriginal perspectives—in its curricula. In this paper, we introduce a promising approach for aligning Aboriginal perspectives with the needs of cyber security graduates and incorporating diverse perspectives into cyber degrees. The approach advocates for the centrality of good curriculum design fundamentals: backward design, constructive alignment, and student outcomes. The paper ends by reflecting on challenges and lessons from the first implementation and review of the material. It provides recommendations for other cyber practitioners exploring ways of incorporating …


Cascading Effects: Analyzing Project Failure Impact In The Maven Central Ecosystem, Mina Shehata 2025 Belmont University

Cascading Effects: Analyzing Project Failure Impact In The Maven Central Ecosystem, Mina Shehata

SPARK Symposium Presentations

Abstract—This study examines failure propagation patterns within the Maven Central ecosystem, a critical software de- pendency repository, through comprehensive analysis of dependency networks using the Goblin framework. Our dual-sampling methodology, investigating both top dependencies and random libraries, revealed two distinct failure propagation patterns that pose significant risks to ecosystem stability. Core infrastructure failures, particularly evident in cases like the AWS SDK family with 429,800 total dependencies, create immediate and widespread disruption, affecting an average of 20,402 dependent projects and propagating through dependency chains averaging 90.80 levels deep.

Our analysis of peripheral projects reveals their significant cascading effects, with higher average …


Systemization Of Knowledge (Sok): Goals, Coverage, And Evaluation In Cybersecurity And Privacy Games, Yue Huang, Marthie Grobler, Lauren S. Ferro, Georgia Psaroulis, Sanchari Das, Jing Wei, Helge Janicke 2025 Edith Cowan University

Systemization Of Knowledge (Sok): Goals, Coverage, And Evaluation In Cybersecurity And Privacy Games, Yue Huang, Marthie Grobler, Lauren S. Ferro, Georgia Psaroulis, Sanchari Das, Jing Wei, Helge Janicke

Research outputs 2022 to 2026

This paper systematized existing knowledge on cybersecurity and privacy game-based approaches, exploring their goals, scope, and evaluation methods. Our review of 93 academic papers revealed that these approaches serve multiple purposes and target diverse player types. We identified 11 key aspects of cybersecurity and privacy that these approaches addressed, such as threats, defensive strategies, and data privacy. Additionally, we analyzed the effectiveness evaluation methods of these approaches, emphasizing the connections between evaluation techniques, types of data used, and their alignment with the approaches' goals. We also summarized the aspects of user experience evaluated in the literature and the types of …


"Exploring The Training Data Landscape For Ai Based Threathunting For Protecting Intellectual Property", Manzi Siibo, Christopher Kreider 2025 Christopher Newport University

"Exploring The Training Data Landscape For Ai Based Threathunting For Protecting Intellectual Property", Manzi Siibo, Christopher Kreider

Cybersecurity Undergraduate Research Showcase

This study provides a comprehensive evaluation of the effectiveness that would result in the integration of AI into traditional threat hunting systems. To do so, 10-15 scholarly articles and data sets were evaluated to see the results of AI and machine learning threat hunting versus traditional systems. With so many proven benefits of this integration, this paper also explores how it impacts the protection of Intellectual property which is some of the most important forms of information that threat hunting systems aim to protect.


Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr. 2025 Old Dominion University

Elder Fraud Metrics And Preventative Measures Of Chesapeake, Virginia, Joey J. Whitmore Jr.

Cybersecurity Undergraduate Research Showcase

Geriatric crime continues to escalate in the digital era, where older individuals are disproportionately being targeted because of their low digital literacy and high susceptibility to online frauds. In this paper, we examine the breadth of elder fraud in Chesapeake, Virginia using FBI Internet Crime Complaint Center (IC3) data and state-level cybersecurity initiatives and survey responses. Older adults aged 60 and up have reported losses of over $3.4 billion in 2023 alone, underscoring the importance of proactive measures. It assesses the public awareness from traditional and AI-based perspectives revealing significant gaps in digital safety literacy and fraud reporting mechanism among …


Analysis Of Cybersecurity Threats And Mitigation Strategies: Theory In To Practice, Project Proposal, Fransly Dutervil 2025 Minnesota State University Moorhead

Analysis Of Cybersecurity Threats And Mitigation Strategies: Theory In To Practice, Project Proposal, Fransly Dutervil

Student Academic Conference

Cybersecurity threats pose significant risks to individuals and organizations, leading to data breaches, financial losses, and operational disruptions. This presentation explores key threats such as malware, phishing, DDoS attacks, insider threats, and zero-day exploits. It also discusses mitigation strategies, including network security measures, multi-factor authentication, encryption, and incident response planning. Through case studies of real-world cyber incidents, we highlight lessons learned and best practices to strengthen security defenses. The goal is to enhance awareness and promote proactive cybersecurity measures in an increasingly digital world.


Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu 2025 William & Mary

Leveraging Benford’S Law And Machine Learning For Financial Fraud Detection, Benjamin R. Fu

Cybersecurity Undergraduate Research Showcase

Financial fraud, particularly credit card fraud, continues to pose substantial challenges to financial institutions due to its increasing frequency and impact on consumer trust. While traditional rule-based methods have provided foundational defenses, their limitations in scalability and adaptability have accelerated the adoption of machine learning (ML) techniques. Concurrently, Benford’s Law—a statistical principle often used in forensic accounting—has demonstrated efficacy in detecting anomalies within naturally occurring numerical datasets. This study explores a hybrid fraud detection approach that integrates Benford’s Law with supervised machine learning algorithms, including Logistic Regression, Random Forest, and k-Nearest Neighbors. Using the publicly available European credit card fraud …


A Data-Driven Recommendation System For Selecting The Appropriate Mode Of Learning And Instructional Tools Based On Course Characteristics, Ayisha Manzoor 2025 United Arab Emirates University

A Data-Driven Recommendation System For Selecting The Appropriate Mode Of Learning And Instructional Tools Based On Course Characteristics, Ayisha Manzoor

Thesis/ Dissertation Defenses

The rapid transformation of educational delivery methods during the COVID-19 pandemic required institutions to transition between online, hybrid, and offline learning approaches, creating both challenges and opportunities for educators and students. While online and hybrid learning modes ensured continuity, their effectiveness across different course types remained uncertain. This thesis addresses this gap by developing a data-driven recommendation framework that predicts Course Learning Outcome (CLO) achievement and recommends the most appropriate learning mode (online, hybrid, or offline) along with instructional tools based on course characteristics.

This study analyzed 100 undergraduate and postgraduate courses from the College of Information Technology (CIT) at …


The National Cybersecurity Teaching Coalition: Expanding Cybersecurity Education Opportunities, Paul Wagner, Melissa Dark, Robert Honomichl, Filipo Sharevski, Sandra Leiterman 2025 University of Arizona

The National Cybersecurity Teaching Coalition: Expanding Cybersecurity Education Opportunities, Paul Wagner, Melissa Dark, Robert Honomichl, Filipo Sharevski, Sandra Leiterman

Journal of Cybersecurity Education, Research and Practice

The increasing prevalence of cybersecurity threats and the shortage of qualified professionals necessitate innovative solutions for cybersecurity education at all levels. Despite the expansion of post-secondary cybersecurity programs, employer dissatisfaction with graduates and a lack of standardized introductory curricula highlights the need for structured secondary education pathways. The National Cybersecurity Teaching Coalition (NCTC) and its National Cybersecurity Teaching Academy (NCTA) address this gap by equipping high school educators with the necessary knowledge and credentials to teach cybersecurity effectively. NCTA offers an 18-credit cybersecurity graduate certificate program to ensure teachers are competent and confident to develop and teach cybersecurity curriculum with …


The Impact Of Ai Use In Programming Courses On Critical Thinking Skills, Christian Jay St Francis Clarke, Abdullah Konak 2025 Penn State Berks

The Impact Of Ai Use In Programming Courses On Critical Thinking Skills, Christian Jay St Francis Clarke, Abdullah Konak

Journal of Cybersecurity Education, Research and Practice

Proficiency in computer programming extends far beyond memorizing syntax; it depends on the cultivation of critical thinking. Computer programming requires multiple interconnected competencies, including systematic problem analysis, algorithmic reasoning, mastery of programming languages, debugging capabilities, a comprehensive understanding of software development methodologies, rigorous testing practices, and systematic troubleshooting approaches. These skills are also essential for cybersecurity experts; cybersecurity programs require several programming courses to enhance students’ technical and critical thinking skills. Generative AI (GenAI) technologies have fundamentally changed the process of developing applications and approaches to teaching coding. The growing use of GenAI technologies by students in writing computer code …


Assessing Readiness For Transformation From Rule-Based To Ai-Based Chatbot In Uae Healthcare: A Case Study Of A Rehabilitation Hospital In Abu Dhabi, Mubarak Alketbi 2025 United Arab Emirates University

Assessing Readiness For Transformation From Rule-Based To Ai-Based Chatbot In Uae Healthcare: A Case Study Of A Rehabilitation Hospital In Abu Dhabi, Mubarak Alketbi

Thesis/ Dissertation Defenses

This research investigates the readiness of UAE healthcare institutions to transition from rule-based chatbot systems to AI-powered alternatives, focusing on a rehabilitation hospital in Abu Dhabi. Through a structured quantitative study involving 96 healthcare professionals, the research explores technology acceptance, service quality, usability, and implementation readiness. Findings highlight strong correlations between perceived usefulness and behavioral intention to adopt AI, emphasizing the importance of integration, staff training, and service reliability. The study proposes a practical implementation framework for healthcare transformation, offering insights for institutions seeking to improve operational efficiency through AI integration.


Phishing Attacks And Prevention, Ruth Johnson 2025 Old Dominion University

Phishing Attacks And Prevention, Ruth Johnson

Cybersecurity Undergraduate Research Showcase

Phishing attacks have been the number one leading cause of identity theft and financial theft since 1990. The internet is one of the leading places where individuals’ identity is stolen. Many businesses and government agencies have been at risk of cyber phishing attacks from foreign countries. Attacks on Several U.S. federal government agencies have been hit in a global cyberattack by Russian cybercriminals that exploit a vulnerability in widely used software, according to a top us cybersecurity agency (Lyngaas, Government hit cyber-attacks, 2023).

Phishing attacks are cybercrimes where one or many individuals steal sensitive information like passwords, credit card information, …


Digital Commons powered by bepress