Immunology Inspired Detection Of Data Theft From Autonomous Network Activity,
2015
Nova Southeastern University
Immunology Inspired Detection Of Data Theft From Autonomous Network Activity, Theodore O. Cochran
CCAC Theses and Dissertations
The threat of data theft posed by self-propagating, remotely controlled bot malware is increasing. Cyber criminals are motivated to steal sensitive data, such as user names, passwords, account numbers, and credit card numbers, because these items can be parlayed into cash. For anonymity and economy of scale, bot networks have become the cyber criminal’s weapon of choice. In 2010 a single botnet included over one million compromised host computers, and one of the largest botnets in 2011 was specifically designed to harvest financial data from its victims. Unfortunately, current intrusion detection methods are unable to effectively detect data extraction techniques …
Usable Security Using Goms: A Study To Evaluate And Compare The Usability Of User Accounts On E-Government Websites,
2015
Nova Southeastern University
Usable Security Using Goms: A Study To Evaluate And Compare The Usability Of User Accounts On E-Government Websites, Amran Din
CCAC Theses and Dissertations
The term e-Government refers to providing citizens a series of services that can be conveniently conducted over the Internet. However, the potential to redefine and transform e-Government increasingly relies on citizens successfully establishing and managing a user account profile online. E-Government has not adequately addressed user-centric designs for social inclusion of all citizens on e-Government websites. There is a lack of research on the usability of user account management, and a clear lack of innovation in incorporating user-friendly authentication interfaces to accommodate a diverse user population given the wealth of existing research in web authentication techniques within Identity Management. The …
Software Watermarking Using Return-Oriented Programming,
2015
Singapore Management University
Software Watermarking Using Return-Oriented Programming, Haoyu Ma, Kangjie Lu, Xinjie Ma, Haining Zhang, Chunfu Jia, Debin Gao
Research Collection School Of Computing and Information Systems
We propose a novel dynamic software watermarking design based on Return-Oriented Programming (ROP). Our design formats watermarking code into well-crafted data arrangements that look like normal data but could be triggered to execute. Once triggered, the pre-constructed ROP execution will recover the hidden watermark message. The proposed ROP-based watermarking technique is more stealthy and resilient over existing techniques since the watermarking code is allocated dynamically into data region and therefore out of reach of attacks based on code analysis. Evaluations show that our design not only achieves satisfying stealth and resilience, but also causes significantly lower overhead to the watermarked …
Masthead,
2015
Embry-Riddle Aeronautical University
Back Matter,
2015
Embry-Riddle Aeronautical University
Front Matter,
2015
Embry-Riddle Aeronautical University
Constructing Cost-Effective And Targetable Ics Honeypots Suited For Production Networks,
2015
Air Force Institute of Technology
Constructing Cost-Effective And Targetable Ics Honeypots Suited For Production Networks, Michael M. Winn
Theses and Dissertations
Honeypots are a technique that can mitigate the risk of cyber threats. Effective honeypots are authentic and targetable, and their design and implementation must accommodate risk tolerance and financial constraints. The proprietary, and often expensive, hardware and software used by Industrial Control System (ICS) devices creates the challenging problem of building a flexible, economical, and scalable honeypot. This research extends Honeyd into Honeyd+, making it possible to use the proxy feature to create multiple high interaction honeypots with a single Programmable Logic Controller (PLC). Honeyd+ is tested with a network of 75 decoy PLCs, and the interactions with the decoys …
Evaluating Machine Learning Classifiers For Hybrid Network Intrusion Detection Systems,
2015
Air Force Institute of Technology
Evaluating Machine Learning Classifiers For Hybrid Network Intrusion Detection Systems, Michael D. Rich
Theses and Dissertations
Existing classifier evaluation methods do not fully capture the intended use of classifiers in hybrid intrusion detection systems (IDS), systems that employ machine learning alongside a signature-based IDS. This research challenges traditional classifier evaluation methods in favor of a value-focused evaluation method that incorporates evaluator-specific weights for classifier and prediction threshold selection. By allowing the evaluator to weight known and unknown threat detection by alert classification, classifier selection is optimized to evaluator values for this application. The proposed evaluation methods are applied to a Cyber Defense Exercise (CDX) dataset. Network data is processed to produce connection-level features, then labeled using …
The Impact Of Image Synonyms In Graphical-Based Authentication Systems,
2015
Nova Southeastern University
The Impact Of Image Synonyms In Graphical-Based Authentication Systems, Jonathan William Sparks
CCAC Theses and Dissertations
Traditional text-based passwords used for authentication in information systems have several known issues in the areas of usability and security. Research has shown that when users generate passwords for systems, they tend to create passwords that are subject to compromise more so than those created randomly by the computer. Research has also shown that users have difficulty remembering highly secure, randomly created, text-based passwords.
Graphical-based passwords have been shown to be highly memorable for users when applied to system authentication. However, graphical-based authentication systems require additional cognitive load to recognize and enter a password compared to traditional text-based authentication that …
Privacy Leakage Analysis In Online Social Networks,
2015
Singapore Management University
Privacy Leakage Analysis In Online Social Networks, Yan Li, Yingjiu Li, Qiang Yan, Deng, Robert H.
Research Collection School Of Computing and Information Systems
Online Social Networks (OSNs) have become one of the major platforms for social interactions, such as building up relationship, sharing personal experiences, and providing other services. The wide adoption of OSNs raises privacy concerns due to personal data shared online. Privacy control mechanisms have been deployed in popular OSNs for users to determine who can view their personal information. However, user's sensitive information could still be leaked even when privacy rules are properly configured. We investigate the effectiveness of privacy control mechanisms against privacy leakage from the perspective of information flow. Our analysis reveals that the existing privacy control mechanisms …
Leading Undergraduate Students To Big Data Generation,
2015
University of North Georgia
Leading Undergraduate Students To Big Data Generation, Jianjun Yang, Ju Shen
Computer Science Faculty Publications
People are facing a flood of data today. Data are being collected at unprecedented scale in many areas, such as networking, image processing, virtualization, scientific computation, and algorithms. The huge data nowadays are called Big Data. Big data is an all encompassing term for any collection of data sets so large and complex that it becomes difficult to process them using traditional data processing applications. In this article, the authors present a unique way which uses network simulator and tools of image processing to train students abilities to learn, analyze, manipulate, and apply Big Data. Thus they develop students hands-on …
Reconstruction Privacy: Enabling Statistical Learning,
2015
Singapore Management University
Reconstruction Privacy: Enabling Statistical Learning, Ke Wang, Chao Han, Ada Waichee Fu, Raymond C. Wong, Philip S. Yu
Research Collection School Of Computing and Information Systems
Non-independent reasoning (NIR) allows the information about one record in the data to be learnt from the information of other records in the data. Most posterior/prior based privacy criteria consider NIR as a privacy violation and require to smooth the distribution of published data to avoid sensitive NIR. The drawback of this approach is that it limits the utility of learning statistical relationships. The differential privacy criterion considers NIR as a non-privacy violation, therefore, enables learning statistical relationships, but at the cost of potential disclosures through NIR. A question is whether it is possible to (1) allow learning statistical relationships, …
Understanding Natural Disasters As Risks In Supply Chain Management Through Web Data Analysis,
2015
Singapore Management University
Understanding Natural Disasters As Risks In Supply Chain Management Through Web Data Analysis, Jimmy Ong, Zhaoxia Wang, Rick Siow Mong Goh, Xiao Feng Yin, Xin Xin, Xiuju Fu
Research Collection School Of Computing and Information Systems
With the increasing trend of global outsourcing, companies are now facing ever more complexsupply chains. When a company operates over a large geographical area, the likelihood of disruptions ispotentially increased due to such unforeseen events as natural disasters, union strikes or social unrest. Inthis paper, we consider natural disasters as a form of risks in supply chains and propose to aid itsmanagement by analyzing Web data collected in real-time. Using Twitter "tweets" as our primary source ofWeb data, a real-time data crawler is developed to collect and analyze tweets that are identified as relevant tonatural disasters. In addition, a visualization …
A Web-Based Temperature Monitoring System For The College Of Arts And Letters,
2015
California State University - San Bernardino
A Web-Based Temperature Monitoring System For The College Of Arts And Letters, Rigoberto Solorio
Electronic Theses, Projects, and Dissertations
In general, server rooms have restricted access requiring that staff possess access codes, keys, etc. Normally, only administrators are provided access to protect the physical hardware and the data stored in the servers. Servers also have firewalls to restrict outsiders from accessing them via the Internet. Servers also cost a lot of money. For this reason, server rooms also need to be protected against overheating. This will prolong the lifecycle of the units and can prevent data loss from hardware failure.
The California State University San Bernardino (CSUSB), Specifically the College of Arts and Letters server room has faced power …
Analysis And Improvement On A Biometric-Based Remote User Authentication Scheme Using Smart Cards,
2015
Singapore Management University
Analysis And Improvement On A Biometric-Based Remote User Authentication Scheme Using Smart Cards, Fengtong Wen, Willy Susilo, Guomin Yang
Research Collection School Of Computing and Information Systems
In a recent paper (BioMed Research International, 2013/491289), Khan et al. proposed an improved biometrics-based remote user authentication scheme with user anonymity. The scheme is believed to be secure against password guessing attack, user impersonation attack, server masquerading attack, and provide user anonymity, even if the secret information stored in the smart card is compromised. In this paper, we analyze the security of Khan et al.’s scheme, and demonstrate that their scheme doesn’t provide user anonymity. This also renders that their scheme is insecure against other attacks, such as off-line password guessing attack, user impersonation attacks. Subsequently, we propose a …
Hole Detection And Shape-Free Representation And Double Landmarks Based Geographic Routing In Wireless Sensor Networks,
2015
University of North Georgia
Hole Detection And Shape-Free Representation And Double Landmarks Based Geographic Routing In Wireless Sensor Networks, Jianjun Yang, Zongming Fei, Ju Shen
Computer Science Faculty Publications
In wireless sensor networks, an important issue of geographic routing is “local minimum” problem, which is caused by a “hole” that blocks the greedy forwarding process. Existing geographic routing algorithms use perimeter routing strategies to find a long detour path when such a situation occurs. To avoid the long detour path, recent research focuses on detecting the hole in advance, then the nodes located on the boundary of the hole advertise the hole information to the nodes near the hole. Hence the long detour path can be avoided in future routing. We propose a heuristic hole detecting algorithm which identifies …
Role-Based Access Control Administration Of Security Policies And Policy Conflict Resolution In Distributed Systems,
2015
Nova Southeastern University
Role-Based Access Control Administration Of Security Policies And Policy Conflict Resolution In Distributed Systems, Stephen Sakawa Kibwage
CCAC Theses and Dissertations
Security models using access control policies have over the years improved from Role-based access control (RBAC) to newer models which have added some features like support for distributed systems and solving problems in older security policy models such as identifying policy conflicts. Access control policies based on hierarchical roles provide more flexibility in controlling system resources for users. The policies allow for granularity when extended to have both allow and deny permissions as well as weighted priority attribute for the rules in the policies. Such flexibility allows administrators to succinctly specify access for their system resources but also prone to …
Leakage-Resilient Password Entry: Challenges, Design, And Evaluation,
2015
Singapore Management University
Leakage-Resilient Password Entry: Challenges, Design, And Evaluation, Qiang Yan, Jin Han, Yingjiu Li, Jianying Zhou, Robert H. Deng
Research Collection School Of Computing and Information Systems
Password leakage is one of the most serious threats for password-based user authentication. Although this problem has been extensively investigated over the last two decades, there is still no widely adopted solution. In this paper, we attempt to systematically understand the challenges behind this problem and investigate the feasibility of solving it. Since password leakage usually happens when a password is input during authentication, we focus on designing leakage-resilient password entry (LRPE) schemes in this study. We develop a broad set of design criteria and use them to construct a practical LRPE scheme named CoverPad, which not only improves leakage …
Biometric Authentication On Iphone And Android: Usability, Perceptions, And Influences On Adoption,
2015
Carnegie Mellon University
Biometric Authentication On Iphone And Android: Usability, Perceptions, And Influences On Adoption, Rasekhar Bhagavatula, Blase Ur, Kevin Iacovino, Su Mon Kywe, Lorrie Faith Cranor, Marios Savvides
Research Collection School Of Computing and Information Systems
While biometrics have long been promoted as the future of authentication, the recent introduction of Android face unlock and iPhone fingerprint unlock are among the first large-scale deployments of biometrics for consumers. In a 10-participant, within-subjects lab study and a 198-participant online survey, we investigated the usability of these schemes, along with users ’ experiences, attitudes, and adoption decisions. Participants in our lab study found both face unlock and fingerprint unlock easy to use in typical scenarios. The notable exception was that face unlock was completely unusable in a dark room. Most participants preferred fingerprint unlock over face unlock or …
An Overview Of Steganography For The Computer Forensics Examiner (Updated Version, February 2015),
2015
Embry-Riddle Aeronautical University
An Overview Of Steganography For The Computer Forensics Examiner (Updated Version, February 2015), Gary C. Kessler
Publications
"Steganography is the art of covered or hidden writing. The purpose of steganography is covert communication-to hide the existence of a message from a third party. This paper is intended as a high-level technical introduction to steganography for those unfamiliar with the field. It is directed at forensic computer examiners who need a practical understanding of steganography without delving into the mathematics, although references are provided to some of the ongoing research for the person who needs or wants additional detail. Although this paper provides a historical context for steganography, the emphasis is on digital applications, focusing on hiding information …
