Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,670 Full-Text Articles 6,838 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,670 full-text articles. Page 21 of 201.

Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming ZHAO, Zhaoxuan LI, Xiaofei XIE, Jiongchi YU, Fan ZHANG, Rui ZHANG, Binbin CHEN, Xiangyang LUO, Ming HU, Wenrui MA 2024 Zhejiang University

Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang, Rui Zhang, Binbin Chen, Xiangyang Luo, Ming Hu, Wenrui Ma

Research Collection School Of Computing and Information Systems

Anomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. …


Direct Range Proofs For Paillier Cryptosystem And Their Applications, Zhikang XIE, Mengling LIU, Haiyang XUE, Man Ho AU, Robert H. DENG, Siu-Ming YIU 2024 Singapore Management University

Direct Range Proofs For Paillier Cryptosystem And Their Applications, Zhikang Xie, Mengling Liu, Haiyang Xue, Man Ho Au, Robert H. Deng, Siu-Ming Yiu

Research Collection School Of Computing and Information Systems

The Paillier cryptosystem is renowned for its applications in electronic voting, threshold ECDSA, multi-party computation, and more, largely due to its additive homomorphism. In these applications, range proofs for the Paillier cryptosystem are crucial for maintaining security, because of the mismatch between the message space in the Paillier system and the operation space in application scenarios. In this paper, we present novel range proofs for the Paillier cryptosystem, specifically aimed at optimizing those for both Paillier plaintext and affine operation. We interpret encryptions and affine operations as commitments over integers, as opposed to solely over ZN. Consequently, we propose direct …


A Survey Of Protocol Fuzzing, Xiaohan ZHANG, Cen ZHANG, Xinghua LI, Zhengjie DU, Bing MAO, Yeting LI, Pan LI 2024 Singapore Management University

A Survey Of Protocol Fuzzing, Xiaohan Zhang, Cen Zhang, Xinghua Li, Zhengjie Du, Bing Mao, Yeting Li, Pan Li

Research Collection School Of Computing and Information Systems

Communication protocols form the bedrock of our interconnected world, yet vulnerabilities within their implementations pose significant security threats. Recent developments have seen a surge in fuzzing-based research dedicated to uncovering these vulnerabilities within protocol implementations. However, there still lacks a systematic overview of protocol fuzzing for answering the essential questions such as what the unique challenges are, how existing works solve them, and so on. To bridge this gap, we conducted a comprehensive investigation of related works from both academia and industry. Our study includes a detailed summary of the specific challenges in protocol fuzzing and provides a systematic categorization …


Resilient Tcp Variant Enabling Smooth Network Updates For Software-Defined Data Center Networks, Abdul Basit Dogar, Sami Ullah, Yiran Zhang, Hisham Alasmary, Muhammad Waqas, Sheng Chen 2024 Edith Cowan University

Resilient Tcp Variant Enabling Smooth Network Updates For Software-Defined Data Center Networks, Abdul Basit Dogar, Sami Ullah, Yiran Zhang, Hisham Alasmary, Muhammad Waqas, Sheng Chen

Research outputs 2022 to 2026

Network updates have become increasingly prevalent since the broad adoption of software-defined networks (SDNs) in data centers. Modern TCP designs, including cutting-edge TCP variants DCTCP, CUBIC, and BBR, however, are not resilient to network updates that provoke flow rerouting. In this paper, we first demonstrate that popular TCP implementations perform inadequately in the presence of frequent and inconsistent network updates, because inconsistent and frequent network updates result in out-of-order packets and packet drops induced via transitory congestion and lead to serious performance deterioration. We look into the causes and propose a network update-friendly TCP (NUFTCP), which is an extension of …


Leveraging Propagation Delay For Wormhole Detection In Wireless Networks, Harry May, Travis Atkison 2024 Louisiana Tech University

Leveraging Propagation Delay For Wormhole Detection In Wireless Networks, Harry May, Travis Atkison

Journal of Cybersecurity Education, Research and Practice

Detecting and mitigating wormhole attacks in wireless networks remains a critical challenge due to their deceptive nature and potential to compromise network integrity. This paper proposes a novel approach to wormhole detection by leveraging propagation delay analysis between network nodes. Unlike traditional methods that rely on signature-based detection or specialized hardware, our method focuses on analyzing propagation delay timings to identify anomalous behavior indicative of wormhole attacks. The proposed methodology involves collecting propagation delay data in both normal network scenarios and scenarios with inserted malicious wormhole nodes. By comparing these delay timings, our approach aims to differentiate between legitimate network …


How State Universities Are Addressing The Shortage Of Cybersecurity Professionals In The United States, Gary Harris 2024 University of Arkansas at Little Rock

How State Universities Are Addressing The Shortage Of Cybersecurity Professionals In The United States, Gary Harris

Journal of Cybersecurity Education, Research and Practice

Cybersecurity threats have been a serious and growing problem for decades. In addition, a severe shortage of cybersecurity professionals has been proliferating for nearly as long. These problems exist in the United States and globally and are well documented in literature. This study examined what state universities are doing to help address the shortage of cybersecurity professionals since higher education institutions are a primary source to the workforce pipeline. It is suggested that the number of cybersecurity professionals entering the workforce is related to the number of available programs. Thus increasing the number of programs will increase the number of …


Cyber Victimization In The Healthcare Industry: Analyzing Offender Motivations And Target Characteristics Through Routine Activities Theory (Rat) And Cyber-Routine Activities Theory (Cyber-Rat), Yashna Praveen, Mijin Kim, Kyung-Shick Choi 2024 Bridgewater State University

Cyber Victimization In The Healthcare Industry: Analyzing Offender Motivations And Target Characteristics Through Routine Activities Theory (Rat) And Cyber-Routine Activities Theory (Cyber-Rat), Yashna Praveen, Mijin Kim, Kyung-Shick Choi

International Journal of Cybersecurity Intelligence & Cybercrime

The integration of computer technology in healthcare has revolutionized patient care but has also introduced significant cyber risks. Despite the healthcare sector being a primary target for cyber-attacks, research on the dynamics of these threats and practical solutions remains limited. Understanding the complexities of cyberattacks in this sector is critical, as the impact extends beyond financial losses to directly affect patient care and the protection of sensitive information. This paper applies Routine Activities Theory (RAT) and Cyber Routine Activities Theory (C-RAT) to analyze high-tech cyber victimization case studies in healthcare. The analysis explores the motivations behind these attacks and identifies …


Understanding The Use Of Artificial Intelligence In Cybercrime, Sinyong Choi, Thomas Dearden, Katalin Parti 2024 Bridgewater State University

Understanding The Use Of Artificial Intelligence In Cybercrime, Sinyong Choi, Thomas Dearden, Katalin Parti

International Journal of Cybersecurity Intelligence & Cybercrime

Artificial intelligence is one of the newest innovations that offenders also exploit to satisfy their criminal desires. Although understanding cybercrimes associated with this relatively new technology is essential in developing proper preventive measures, little has been done to examine this area. Therefore, this paper provides an overview of the articles featured in the special issue of the International Journal of Cybersecurity Intelligence and Cybercrime, ranging from deepfake in the metaverse to social engineering attacks. This issue includes articles that were presented by the winners of the student paper competition at the 2024 International White Hat Conference.


Investigating The Intersection Of Ai And Cybercrime: Risks, Trends, And Countermeasures, Sanaika Shetty, Kyung-Shick Choi, Insun Park 2024 Bridgewater State University

Investigating The Intersection Of Ai And Cybercrime: Risks, Trends, And Countermeasures, Sanaika Shetty, Kyung-Shick Choi, Insun Park

International Journal of Cybersecurity Intelligence & Cybercrime

No abstract provided.


Integrated Model Of Cybercrime Dynamics: A Comprehensive Framework For Understanding Offending And Victimization In The Digital Realm, Troy Smith PhD 2024 Targeted Evidence-based Research Solutions, Trinidad and Tobago

Integrated Model Of Cybercrime Dynamics: A Comprehensive Framework For Understanding Offending And Victimization In The Digital Realm, Troy Smith Phd

International Journal of Cybersecurity Intelligence & Cybercrime

This article introduces the Integrated Model of Cybercrime Dynamics (IMCD), a novel theoretical framework for examining the complex interplay between individual characteristics, online behavior, environmental factors, and outcomes related to cybercrime offending and victimization. The model incorporates key concepts from existing theories, empirical evidence, and interdisciplinary perspectives to provide a comprehensive framework. In contrast to traditional criminological theories, the proposed model integrates concepts from multiple disciplines to offer a holistic framework that captures the complexity of cybercrime and specifically caters for the uniqueness of cyberspace. The article will provide a detailed overview of the conceptual model, its theoretical underpinnings drawing …


Use Your Own Device (Uyod): Framework For Building A Human Firewall, Tapiwa Gundu, Kevin Kativu 2024 Nelson Mandela University

Use Your Own Device (Uyod): Framework For Building A Human Firewall, Tapiwa Gundu, Kevin Kativu

African Conference on Information Systems and Technology

The Use Your Own Device (UYOD) paradigm is increasingly common in modern digital workplaces, offering benefits like flexibility and cost savings but also introducing significant cybersecurity risks. This study develops a comprehensive framework for constructing a robust human firewall aimed at mitigating these risks. The research employs a systematic literature review (SLR) methodology, starting with a corpus of 198 articles, from which 17 high-quality studies were selected for in-depth analysis. Key components identified include cybersecurity awareness training, regular simulated attacks, clear policies and procedures, technology competence training, and fostering a security-first culture. Findings reveal that integrating these components into an …


Data Breach Mitigation In Hospital Database Management Systems – The Case Of A Hospital In South-South Nigeria, Leton Rebecca Nsereka, Irene Govender 2024 University of KwaZulu-Natal, Durban, South Africa

Data Breach Mitigation In Hospital Database Management Systems – The Case Of A Hospital In South-South Nigeria, Leton Rebecca Nsereka, Irene Govender

African Conference on Information Systems and Technology

The damaging effects of data breaches result in the loss of sensitive data, operational downtime, financial losses, and, in extreme cases, legal action. This study investigates the Hospital Database Management systems (HDMS) in a selected hospital in South-South Nigeria for the mitigation of data breaches. The deployment of an Incident Response Framework for data breach mitigation on HDMS has yet to be fully researched, creating a gap literature. The research objectives were accomplished through mixed methods and design science research (DSR). About 180 participants including forty employees from the medical records unit and 140 patients/patient relatives, who interact with the …


Designing Cybersecurity Escape Rooms: A Gamified Approach To Undergraduate Learning, Thitima Srivatanakul 2024 York College, City University of New York

Designing Cybersecurity Escape Rooms: A Gamified Approach To Undergraduate Learning, Thitima Srivatanakul

Journal of Cybersecurity Education, Research and Practice

Gamification, including game-based learning (GBL), is a widely recognized pedagogical approach used for imparting and reinforcing cybersecurity knowledge and skills to learners. One innovative form of GBL gaining popularity across various educational levels, from secondary schools to professional development, is escape room-style education. This study is centered on the development and design of escape room activities tailored for teaching cybersecurity concepts, with a particular focus on web and software security, to undergraduate students at York College. The primary objectives of this research are twofold: firstly, to evaluate the effectiveness of educational escape room activities in reinforcing cybersecurity concepts taught in …


Cyberattack Detection And Handling For Neural Network-Approximated Economic Model Predictive Control, Jihan Abou Halloun, Helen E. Durand 2024 Wayne State University

Cyberattack Detection And Handling For Neural Network-Approximated Economic Model Predictive Control, Jihan Abou Halloun, Helen E. Durand

Chemical Engineering and Materials Science Faculty Research Publications

Cyberattacks on control systems can create unprofitable and unsafe operating conditions. To enhance safety and attack resiliency of control systems, cyberattack detection strategies can be developed. Prior work in our group has sought to develop cyberattack detection strategies that are integrated with an advanced control formulation known as Lyapunov-based economic model predictive control (LEMPC), in the sense that the controller properties can be used to analyze closed-loop stability in the presence or absence of undetected attacks. In this work, we consider neural network-approximated control laws, concepts for mitigating cyberattacks on such control laws, and how these ideas elucidate concepts in …


Lyapunov-Based Cyberattack Detection For Distinguishing Between Sensor And Actuator Attacks, Dominic Messina, Helen E. Durand 2024 Wayne State University

Lyapunov-Based Cyberattack Detection For Distinguishing Between Sensor And Actuator Attacks, Dominic Messina, Helen E. Durand

Chemical Engineering and Materials Science Faculty Research Publications

Control-theoretic cyberattack detection strategies are control strategies where control theory can be used in the design of the detection policies and analysis of stability properties with and without cyberattacks. This work provides a step toward understanding how to diagnose cyberattacks using control-theoretic cyberattack detection mechanisms. Specifically, we analyze the conditions under which a control-theoretic cyberattack detection strategy developed in our prior work to handle detection of simultaneous actuator and sensor attacks can be extended to distinguish between whether attacks are occurring on sensors or actuators. We present and evaluate heuristic concepts for attempting to diagnose sensor attacks; these again demonstrate …


Profit Considerations For Nonlinear Control-Integrated Cyberattack Detection On Process Actuators, Keshav Kasturi Rangan, Helen E. Durand 2024 Wayne State University

Profit Considerations For Nonlinear Control-Integrated Cyberattack Detection On Process Actuators, Keshav Kasturi Rangan, Helen E. Durand

Chemical Engineering and Materials Science Faculty Research Publications

Prior research from our group developed a control-integrated active actuator cyberattack detection strategy. This strategy continuously probed for cyberattacks by updating target steady-states at every sampling time and then moving the process state toward these over the subsequent sampling period. Attacks were fagged if a Lyapunov function around the target steady-state did not decrease over a sampling period. This strategy had the benefit of ensuring safety of the process until an attack was detected. However, the continuous probing for attacks could decrease profit from the process compared to not probing for the attacks, which could limit the attractiveness of the …


Pias: Privacy-Preserving Incentive Announcement System Based On Blockchain For Internet Of Vehicles, Yonghua ZHAN, Yang YANG, Hongju CHENG, Xiangyang LUO, Zhuangshuang GUAN, Robert H. DENG 2024 Fuzhou University

Pias: Privacy-Preserving Incentive Announcement System Based On Blockchain For Internet Of Vehicles, Yonghua Zhan, Yang Yang, Hongju Cheng, Xiangyang Luo, Zhuangshuang Guan, Robert H. Deng

Research Collection School Of Computing and Information Systems

More vehicles are connecting to the Internet of Things (IoT), transforming Vehicle Ad hoc Networks (VANETs) into the Internet of Vehicles (IoV), providing a more environmentally friendly and safer driving experience. Vehicular announcement networks show promise in vehicular communication applications. However, two major issues arise when establishing such a system. Firstly, user privacy cannot be guaranteed when messages are forwarded anonymously, thus the reliability of these messages is in question. Secondly, users often lack interest in responding to announcements. To address these problems, we introduce a Blockchain-based incentive announcement system called PIAS. This system enables anonymous message commitment in a …


Fdi : Attack Neural Code Generation Systems Through User Feedback Channel, Zhensu SUN, Xiaoning DU, Xiapu LUO, Fu SONG, David LO, Li LI 2024 Singapore Management University

Fdi : Attack Neural Code Generation Systems Through User Feedback Channel, Zhensu Sun, Xiaoning Du, Xiapu Luo, Fu Song, David Lo, Li Li

Research Collection School Of Computing and Information Systems

Neural code generation systems have recently attracted increasing attention to improve developer productivity and speed up software development. Typically, these systems maintain a pre-trained neural model and make it available to general users as a service (e.g., through remote APIs) and incorporate a feedback mechanism to extensively collect and utilize the users' reaction to the generated code, i.e., user feedback. However, the security implications of such feedback have not yet been explored. With a systematic study of current feedback mechanisms, we find that feedback makes these systems vulnerable to feedback data injection (FDI) attacks. We discuss the methodology of FDI …


The Impact Of Managerial Myopia On Cybersecurity: Evidence From Data Breaches, Wen CHEN, Xing LI, Haibin WU, Liandong ZHANG 2024 Singapore Management University

The Impact Of Managerial Myopia On Cybersecurity: Evidence From Data Breaches, Wen Chen, Xing Li, Haibin Wu, Liandong Zhang

Research Collection School Of Accountancy

Using a sample of U.S. firms for the period 2005–2017, we provide evidence that managerial myopic actions contribute to corporate cybersecurity risk. Specifically, we show that abnormal cuts in discretionary expenditures, our proxy for managerial myopia, are positively associated with the likelihood of data breaches. The association is largely driven by firms that appear to cut discretionary expenditures to meet short-term earnings targets. In addition, the association is stronger for firms with greater short-term equity incentives, higher earnings response coefficients, low levels of institutional block ownership, or large market shares. Finally, firms appear to increase discretionary expenditures upon the announcement …


Efficient And Secure Federated Learning Against Backdoor Attacks, Yinbin MIAO, Rongpeng XIE, Xinghua LI, Zhiquan LIU, Kim-Kwang Raymond CHOO, Robert H. DENG 2024 Singapore Management University

Efficient And Secure Federated Learning Against Backdoor Attacks, Yinbin Miao, Rongpeng Xie, Xinghua Li, Zhiquan Liu, Kim-Kwang Raymond Choo, Robert H. Deng

Research Collection School Of Computing and Information Systems

Due to the powerful representation ability and superior performance of Deep Neural Networks (DNN), Federated Learning (FL) based on DNN has attracted much attention from both academic and industrial fields. However, its transmitted plaintext data causes privacy disclosure. FL based on Local Differential Privacy (LDP) solutions can provide privacy protection to a certain extent, but these solutions still cannot achieve adaptive perturbation in DNN model. In addition, this kind of schemes cause high communication overheads due to the curse of dimensionality of DNN, and are naturally vulnerable to backdoor attacks due to the inherent distributed characteristic. To solve these issues, …


Digital Commons powered by bepress