Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,670 Full-Text Articles 6,838 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,670 full-text articles. Page 20 of 201.

Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham 2024 Air Force Institute of Technology

Inferring Tlb Configuration With Performance Tools, Cristian Agredo, Tor J. Langehaug, Scott R. Graham

Faculty Publications

Modern computing systems are primarily designed for maximum performance, which inadvertently introduces vulnerabilities at the micro-architecture level. While cache side-channel analysis has received significant attention, other Central Processing Units (CPUs) components like the Translation Lookaside Buffer (TLB) can also be exploited to leak sensitive information. This paper focuses on the TLB, a micro-architecture component that is vulnerable to side-channel attacks. Despite the coarse granularity at the page level, advancements in tools and techniques have made TLB information leakage feasible. The primary goal of this study is not to demonstrate the potential for information leakage from the TLB but to establish …


Developing A Framework For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan 2024 United Arab Emirates University

Developing A Framework For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan

Thesis/ Dissertation Defenses

This thesis is concerned with the data quality and security of the digital twin and how it is going to impact its adoption, trustworthiness, and potential for real-world applications. By addressing the potential vulnerabilities and ensuring the integrity of data, this research aims to contribute to the development of robust and trustworthy digital twin standards and policies that is going to complement the existing international standards across different domains. Moreover, it underscores the important need to establish robust standards to ensure the successful and secure deployment of digital twins across industries. Previous research, while valuable, may not have fully addressed …


Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous 2024 United Arab Emirates University

Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous

Thesis/ Dissertation Defenses

With the increase in popularity of online communities, such as social media platforms, online games, and chatroom servers, there is a need to improve chat and content moderation. Platforms have reported an increase in the prevalence of toxic behavior and hate speech. Meanwhile, moderators are reporting difficulties in keeping up with the amount of data to check as well and the type of content they are exposed to, which further harms their own mental health. The main objective of this work is to address the challenges that exist within online communities with the rising prevalence of hate speech. Additionally, some …


Developing Policies For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan 2024 United Arab Emirates University

Developing Policies For Digital Twin Data Quality And Security Controls, Ahmad Abdelbaset Hassan

Theses

This thesis is concerned with the data quality and security of the digital twin and how it is going to impact its adoption, trustworthiness, and potential for real-world applications. By addressing the potential vulnerabilities and ensuring the integrity of data, this research aims to contribute to the development of robust and trustworthy digital twin policies that to complement the existing international standards across different domains. Moreover, it underscores the important need to establish robust policies to ensure the successful and secure deployment of digital twins across industries. Previous research, while valuable, may not have fully addressed the critical interplay between …


A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed 2024 United Arab Emirates University

A Secure And Effective Framework For Key Concept Mining From Educational Content Using Large Language Models, Ashika Sameem Abdul Rasheed

Theses

This thesis examines the use of Large Language Models (LLMs) in education, with a focus on improving performance and implementing strong security measures. The research has two main goals, namely, the development of an effective lecture summarization technique using LLMs and identifying and addressing security vulnerabilities in LLM applications according to OWASP (Open Web Application Security Project) guidelines. For the former goal, we have proposed an effective framework for fine-tuning LLMs using real lecture datasets and compared the performance of different LLMs. For the latter goal, we conducted a thorough review of the application dataflow of the proposed framework and …


Efficient Multiplicative-To-Additive Function From Joye-Libert Cryptosystem And Its Application To Threshold Ecdsa, Haiyang XUE, Ho Man AU, Mengling LIU, Yin Kwan CHAN, Handong CUI, Xiang XIE, Hon Tsz YUEN, Chengru ZHANG 2024 Singapore Management University

Efficient Multiplicative-To-Additive Function From Joye-Libert Cryptosystem And Its Application To Threshold Ecdsa, Haiyang Xue, Ho Man Au, Mengling Liu, Yin Kwan Chan, Handong Cui, Xiang Xie, Hon Tsz Yuen, Chengru Zhang

Research Collection School Of Computing and Information Systems

Threshold ECDSA receives interest lately due to its widespread adoption in blockchain applications. A common building block of all leading constructions involves a secure conversion of multiplicative shares into additive ones, which is called the multiplicative-to-additive (MtA) function. MtA dominates the overall complexity of all existing threshold ECDSA constructions. Specifically, O(n2) invocations of MtA are required in the case of n active signers. Hence, improvement of MtA leads directly to significant improvements for all state-of-the-art threshold ECDSA schemes.In this paper, we design a novel MtA by revisiting the Joye-Libert (JL) cryptosystem. Specifically, we revisit JL encryption and propose a JL-based …


Adversarial Learning For Coordinate Regression Through K-Layer Penetrating Representation, Mengxi JIANG, Yulei SUI, Yunqi LEI, Xiaofei XIE, Cuihua LI, Yang LIU, Ivor W. TSANG 2024 Fuzhou University

Adversarial Learning For Coordinate Regression Through K-Layer Penetrating Representation, Mengxi Jiang, Yulei Sui, Yunqi Lei, Xiaofei Xie, Cuihua Li, Yang Liu, Ivor W. Tsang

Research Collection School Of Computing and Information Systems

Adversarial attack is a crucial step when evaluating the reliability and robustness of deep neural networks (DNNs) models. Most existing attack approaches apply an end-to-end gradient update strategy to generate adversarial examples for a classification or regression problem. However, few of them consider the non-differentiable DNN models (e.g., coordinate regression model) that prevent end-to-end backpropagation resulting in the failure of gradient calculation. In this paper, we present a new adversarial example generation approach for both untargeted and targeted attacks on coordinate regression models with non-differentiable operations. The novelty of our approach lies in a k-layer penetrating representation, on which we …


Badfl: Backdoor Attack Defense In Federated Learning From Local Model Perspective, Haiyan ZHANG, Xinghua LI, Mengfan XU, Ximeng LIU, Tong WU, Jian WENG, Robert H. DENG 2024 Singapore Management University

Badfl: Backdoor Attack Defense In Federated Learning From Local Model Perspective, Haiyan Zhang, Xinghua Li, Mengfan Xu, Ximeng Liu, Tong Wu, Jian Weng, Robert H. Deng

Research Collection School Of Computing and Information Systems

There is substantial attention to federated learning with its ability to train a powerful global model collaboratively while protecting data privacy. Despite its many advantages, federated learning is vulnerable to backdoor attacks, where an adversary injects malicious weights into the global model, making the global model's targeted predictions incorrect. Existing defenses based on identifying and eliminating malicious weights ignore the similarity variation of the local weights during iterations in the malicious model detection and the presence of benign weights in the malicious model during the malicious local weight elimination, resulting in a poor defense and a degradation of global model …


Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo HU, Xiao MA, Xinger HUANG, Yiran SHEN, Dong MA 2024 Singapore Management University

Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo Hu, Xiao Ma, Xinger Huang, Yiran Shen, Dong Ma

Research Collection School Of Computing and Information Systems

The increasing use of earbuds in applications like immersive entertainment and health monitoring necessitates effective implicit user authentication systems to preserve the privacy of sensitive data and provide personalized experiences. Existing approaches, which leverage physiological cues (e.g., jawbone structure) and behavioral cues (e.g., gait), face challenges such as limited usability, high delay and energy overhead, and significant computational demands, rendering them impractical for resource-constrained earbuds. To address these issues, we present LR-Auth, a lightweight, user-friendly implicit authentication system designed for various earbud usage scenarios. LR-Auth utilizes the modulation of sound frequencies by the user's unique occluded ear canal, generating user-specific …


Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous 2024 United Arab Emirates University

Tackling Toxicity And Harassment In Online Environments Through The Use Of Artificial Intelligence, Heba Saleous

Dissertations

With the increase in popularity of online communities, such as social media platforms, online games, and chatroom servers, there is a need to improve chat and content moderation. Platforms have reported an increase in the prevalence of toxic behavior and hate speech. Meanwhile, moderators are reporting difficulties in keeping up with the amount of data to check as well and the type of content they are exposed to, which further harms their own mental health. The main objective of this work is to address the challenges that exist within online communities with the rising prevalence of hate speech. Additionally, some …


An Efficient Pairing-Free Ciphertext-Policy Attribute-Based Encryption Scheme For Internet Of Things, Chong Guo, Bei Gong, Muhammad Waqas, Hisham Alasmary, Shanshan Tu, Sheng Chen 2024 Edith Cowan University

An Efficient Pairing-Free Ciphertext-Policy Attribute-Based Encryption Scheme For Internet Of Things, Chong Guo, Bei Gong, Muhammad Waqas, Hisham Alasmary, Shanshan Tu, Sheng Chen

Research outputs 2022 to 2026

The Internet of Things (IoT) is a heterogeneous network composed of numerous dynamically connected devices. While it brings convenience, the IoT also faces serious challenges in data security. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptography method that supports fine-grained access control, offering a solution to the IoT’s security issues. However, existing CP-ABE schemes are inefficient and unsuitable for IoT devices with limited computing resources. To address this problem, this paper proposes an efficient pairing-free CP-ABE scheme for the IoT. The scheme is based on lightweight elliptic curve scalar multiplication and supports multi-authority and verifiable outsourced decryption. The proposed scheme …


Maritime Behaviour Anomaly Detection With Seasonal Context, Travis Rybicki, Martin Masek, Chiou Peng Lam 2024 Edith Cowan University

Maritime Behaviour Anomaly Detection With Seasonal Context, Travis Rybicki, Martin Masek, Chiou Peng Lam

Research outputs 2022 to 2026

Monitoring maritime traffic has become an important task for ensuring the safety of vessels, as well as the goods, and persons that they may be transporting. An active area of research is the modelling of expected normal vessel behaviour so as to detect subsequent anomalies in new data. Anomalies indicate that a vessel is not behaving in an expected manner and their detection can be flagged for further investigation to identify whether the vessel needs assistance or intervention. An important factor for some vessels in determining normal behaviour is seasonal context. However, current approaches typically do not incorporate seasonality into …


Wormhole Attack Mitigation In Wireless Network Using Propagation Delay, Harry May, Travis Atkison 2024 Louisiana Tech University

Wormhole Attack Mitigation In Wireless Network Using Propagation Delay, Harry May, Travis Atkison

Journal of Cybersecurity Education, Research and Practice

This paper presents a novel approach for mitigating wormhole attacks on wireless networks using propagation delay timing. The wormhole attack is a persistent security threat that threatens the integrity of network communications, potentially leading to data theft or other malicious activities. While various methods exist for combating wormhole attacks, our approach offers advantages that set it apart. Our approach involves a combination of proactive and reactive measures, harnessing box plot analysis and weighting factor techniques to identify and isolate outlier node links effectively. Unlike traditional methods, our solution not only detects outlier links but also defines dynamic weighting factors, providing …


Happy Hours, Not Office Hours: Socially Engaging Cybersecurity Students In A Large Online Graduate Course, James T. McCafferty 2024 Kennesaw State University

Happy Hours, Not Office Hours: Socially Engaging Cybersecurity Students In A Large Online Graduate Course, James T. Mccafferty

Journal of Cybersecurity Education, Research and Practice

Engagement is a critical part of student learning and student success. This is especially true in online classes where students have less interaction with their classmates and instructors when compared to traditional face-to-face courses. Research on engagement has shown that when students are meaningfully engaged it can increase student satisfaction and it may also increase levels of academic achievement, including grades earned and degree progression (e.g. Wong et al., 2024). This paper focuses on social engagement in a graduate cybersecurity program that uses large, expandable online courses as described by Whitman and Mattord (2023). Large online graduate classes (i.e., more …


2024 Gateway Magazine, College of Computing, Michigan Technological University 2024 Michigan Technological University

2024 Gateway Magazine, College Of Computing, Michigan Technological University

College of Computing Annual Magazines

Table of Contents

  • 50 Years of Computer Science at Michigan Tech
  • Data Science for a Changing Planet
  • Healthcare Transformed
  • Mechatronics Matters
  • Powered by Michigan Tech Talent
  • Esports: Bringing Everything Great about Sports to More People
  • The Michigander Scholars Program: Electrifying Careers in Michigan
  • College of Computing News


A Survey Of Advanced Border Gateway Protocol Attack Detection Techniques, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk 2024 Edith Cowan University

A Survey Of Advanced Border Gateway Protocol Attack Detection Techniques, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk

Research outputs 2022 to 2026

The Internet's default inter-domain routing system, the Border Gateway Protocol (BGP), remains insecure. Detection techniques are dominated by approaches that involve large numbers of features, parameters, domain-specific tuning, and training, often contributing to an unacceptable computational cost. Efforts to detect anomalous activity in the BGP have been almost exclusively focused on single observable monitoring points and Autonomous Systems (ASs). BGP attacks can exploit and evade these limitations. In this paper, we review and evaluate categories of BGP attacks based on their complexity. Previously identified next-generation BGP detection techniques remain incapable of detecting advanced attacks that exploit single observable detection approaches …


Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings 2024 Dakota State University

Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings

Research & Publications

Digital engineering practices offer significant yet underutilized potential for improving information assurance and system lifecycle management. This paper examines how capabilities like model-based engineering, digital threads, and integrated product lifecycles can address gaps in prevailing frameworks. A reference model demonstrates applying digital engineering techniques to a reference information system, exhibiting enhanced traceability, risk visibility, accuracy, and integration. The model links strategic needs to requirements and architecture while reusing authoritative elements across views. Analysis of the model shows digital engineering closes gaps in compliance, monitoring, change management, and risk assessment. Findings indicate purposeful digital engineering adoption could transform cybersecurity, operations, service …


Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan 2024 Dakota State University

Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan

Research & Publications

As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …


Navigating Governance Paradigms: A Cross-Regional Comparative Study Of Generative Ai Governance Processes & Principle, Jose LUNA, Ivan TAN, Xiaofei XIE, Lingxiao JIANG 2024 Singapore Management University

Navigating Governance Paradigms: A Cross-Regional Comparative Study Of Generative Ai Governance Processes & Principle, Jose Luna, Ivan Tan, Xiaofei Xie, Lingxiao Jiang

Research Collection School Of Computing and Information Systems

As Generative Artificial Intelligence (GenAI) technologies evolve at an unprecedented rate, global governance approaches struggle to keep pace with the technology, highlighting a critical issue in the governance adaptation of significant challenges. Depicting the nuances of nascent and diverse governance approaches based on risks, rules, outcomes, principles, or a mix across different regions around the globe is fundamental to discern discrepancies and convergences and to shed light on specific limitations that need to be addressed, thereby facilitating the safe and trustworthy adoption of GenAI. In response to the need and the evolving nature of GenAI, this paper seeks to provide …


On The Lossiness Of 2k-Th Power And The Instantiability Of Rabin-Oaep, Haiyang XUE, Bao LI, Xianhui LU, Kunpeng WANG, Yamin LIU 2024 Singapore Management University

On The Lossiness Of 2k-Th Power And The Instantiability Of Rabin-Oaep, Haiyang Xue, Bao Li, Xianhui Lu, Kunpeng Wang, Yamin Liu

Research Collection School Of Computing and Information Systems

Seurin PKC 2014 proposed the 2-ï /4-hiding assumption which asserts the indistinguishability of Blum Numbers from pseudo Blum Numbers. In this paper, we investigate the lossiness of 2 k -th power based on the 2 k -ï /4-hiding assumption, which is an extension of the 2-ï /4-hiding assumption. And we prove that 2 k -th power function is a lossy trapdoor permutation over Quadratic Residuosity group. This new lossy trapdoor function has 2 k -bits lossiness for k -bits exponent, while the RSA lossy trapdoor function given by Kiltz et al. Crypto 2010 has k -bits lossiness for k -bits …


Digital Commons powered by bepress