Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,670 Full-Text Articles 6,838 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,670 full-text articles. Page 24 of 201.

Unmasking The Lurking: Malicious Behavior Detection For Iot Malware With Multi-Label Classification, Ruitao FENG, Sen LI, Sen CHEN, Mengmeng GE, Xuewei LI, Xiaohong LI 2024 Singapore Management University

Unmasking The Lurking: Malicious Behavior Detection For Iot Malware With Multi-Label Classification, Ruitao Feng, Sen Li, Sen Chen, Mengmeng Ge, Xuewei Li, Xiaohong Li

Research Collection School Of Computing and Information Systems

Current methods for classifying IoT malware predominantly utilize binary and family classifications. However, these outcomes lack the detailed granularity to describe malicious behavior comprehensively. This limitation poses challenges for security analysts, failing to support further analysis and timely preventive actions. To achieve fine-grained malicious behavior identification in the lurking stage of IoT malware, we propose MaGraMal. This approach, leveraging masked graph representation, supplements traditional classification methodology, empowering analysts with critical insights for rapid responses. Through the empirical study, which took three person-months, we identify and summarize four fine-grained malicious behaviors during the lurking stage, constructing an annotated dataset. Our evaluation …


Enhancing Code Vulnerability Detection Via Vulnerability-Preserving Data Augmentation, Shangqing LIU, Wei MA, Jian WANG, Xiaofei XIE, Ruitao FENG, Yang LIU 2024 Singapore Management University

Enhancing Code Vulnerability Detection Via Vulnerability-Preserving Data Augmentation, Shangqing Liu, Wei Ma, Jian Wang, Xiaofei Xie, Ruitao Feng, Yang Liu

Research Collection School Of Computing and Information Systems

Source code vulnerability detection aims to identify inherent vulnerabilities to safeguard software systems from potential attacks. Many prior studies overlook diverse vulnerability characteristics, simplifying the problem into a binary (0-1) classification task for example determining whether it is vulnerable or not. This poses a challenge for a single deep-learning based model to effectively learn the wide array of vulnerability characteristics. Furthermore, due to the challenges associated with collecting large-scale vulnerability data, these detectors often overfit limited training datasets, resulting in lower model generalization performance. To address the aforementioned challenges, in this work, we introduce a fine-grained vulnerability detector namely FGVulDet. …


Automated Sensor Node Malicious Activity Detection With Explainability Analysis, Md Zubair, Helge Janicke, Ahmad Mohsin, Leandros Maglaras, Iqbal H. Sarker 2024 Edith Cowan University

Automated Sensor Node Malicious Activity Detection With Explainability Analysis, Md Zubair, Helge Janicke, Ahmad Mohsin, Leandros Maglaras, Iqbal H. Sarker

Research outputs 2022 to 2026

Cybersecurity has become a major concern in the modern world due to our heavy reliance on cyber systems. Advanced automated systems utilize many sensors for intelligent decision-making, and any malicious activity of these sensors could potentially lead to a system-wide collapse. To ensure safety and security, it is essential to have a reliable system that can automatically detect and prevent any malicious activity, and modern detection systems are created based on machine learning (ML) models. Most often, the dataset generated from the sensor node for detecting malicious activity is highly imbalanced because the Malicious class is significantly fewer than the …


Measuring Confidentiality With Multiple Observables, John J. Utley 2024 Dartmouth College

Measuring Confidentiality With Multiple Observables, John J. Utley

Computer Science Senior Theses

Measuring the confidentiality of programs that need to interact with the outside world can prevent leakages and is important to protect against dangerous attacks. However, information propagation is difficult to follow through a large program with implicit information flow, tricky loops, and complicated instructions. Previous works have tackled this problem in several ways but often measure leakage a program has on average rather than the leakage produced by a set of particularly compromising interactions. We introduce new methods that target a specific set of observables revealed throughout execution to cut down on the resources needed for analysis. Our implementation examines …


Singleadv: Single-Class Target-Specific Attack Against Interpretable Deep Learning Systems, Eldor Abdukhamidov, Mohammed Abuhamad, George K. Thiruvathukal, Hyoungshick Kim, Tamer Abuhmed 2024 Sung Kyun Kwan University

Singleadv: Single-Class Target-Specific Attack Against Interpretable Deep Learning Systems, Eldor Abdukhamidov, Mohammed Abuhamad, George K. Thiruvathukal, Hyoungshick Kim, Tamer Abuhmed

Computer Science: Faculty Publications and Other Works

In this paper, we present a novel Single-class target-specific Adversarial attack called SingleADV. The goal of SingleADV is to generate a universal perturbation that deceives the target model into confusing a specific category of objects with a target category while ensuring highly relevant and accurate interpretations. The universal perturbation is stochastically and iteratively optimized by minimizing the adversarial loss that is designed to consider both the classifier and interpreter costs in targeted and non-targeted categories. In this optimization framework, ruled by the first- and second-moment estimations, the desired loss surface promotes high confidence and interpretation score of adversarial samples. By …


Whisper: Proximity-Based Authentication For Securely Sharing Secrets, Charles A. Vogel 2024 Dartmouth College

Whisper: Proximity-Based Authentication For Securely Sharing Secrets, Charles A. Vogel

Computer Science Senior Theses

Cryptography offers a wide arsenal of encryption methods to enable secure communication between two
devices that have already exchanged a shared secret. Existing techniques for exchanging a shared secret,
however, are often vulnerable to man-in-the-middle attacks, require special hardware for out-of-band com-
munications, or require a pre-existing Internet connection. With the constantly increasing prevalence of
Internet of Things (IoT) devices sharing sensitive information via wireless networks, the need for a method
to establish secure communication is more pressing than ever.
With this context, we present Whisper, a novel technique that combines elements of digital commu-
nication theory, cryptography, and probability …


Supporting South Korea’S Aging Population: How Ai And Iot Acceptance Connects The Young And Old, Bobby Im 2024 USF

Supporting South Korea’S Aging Population: How Ai And Iot Acceptance Connects The Young And Old, Bobby Im

Master's Projects and Capstones

In 2024, South Korea surpassed every other nation by becoming the country with the lowest fertility rate (below 0.7%). Population decline will hinder future ability to care for their aging population and although the government and private corporations are investing millions of dollars on developing Artificial Intelligence-Internet of Things (AI-IoT) devices to support the aging, the acceptance levels and the amount of family support required is undervalued. By examining AI-IoT’s current use and role in South Korea’s public health system this paper shows how intergenerational support helps optimize existing procedures and equipment, increases the level of acceptance and use, and …


Improving Tattle-Tale K-Deniability, Nicholas G.E. Morales 2024 Portland State University

Improving Tattle-Tale K-Deniability, Nicholas G.E. Morales

Student Research Symposium

Ensuring privacy for databases is an ongoing struggle. While the majority of work has focused on using access control lists to protect sensitive data these methods are vulnerable to inference attacks. A set of algorithms, referred to as Tattle-Tale, was developed that could protect sensitive data from being inferred however its runtime performance wasn’t suitable for production code. This set of algorithms contained two main subsets, Full Deniability and K-Deniability. My research focused on improving the runtime or utility of the K-Deniability algorithms. I investigated the runtime of the K-Deniability algorithms to identify what was slowing the process down. Aside …


A Novel Caching Algorithm For Efficient Fine-Grained Access Control In Database Management Systems, Anadi Shakya 2024 Portland State University

A Novel Caching Algorithm For Efficient Fine-Grained Access Control In Database Management Systems, Anadi Shakya

Student Research Symposium

Fine-grained access Control (FGAC) in DBMS is vital for restricting user access to authorized data and enhancing security. FGAC policies govern how users are granted access to specific resources based on detailed criteria, ensuring security and privacy measures. Traditional methods struggle with scaling policies to thousands, causing delays in query responses. This paper introduces a novel caching algorithm designed to address this challenge by accelerating query processing and ensuring compliance with FGAC policies. In our approach, we create a circular hashmap and employ different replacement techniques to efficiently manage the cache, prioritizing entries that are visited more frequently. To evaluate …


Securing The Internet Of Things At Scale, Steven L. Willoughby 2024 Portland State University

Securing The Internet Of Things At Scale, Steven L. Willoughby

Student Research Symposium

The world of the connected “Internet of Things” (IoT), including the "Industrial Internet of Things" (IIoT) is expanding to include more devices which observe and influence our daily lives, routines, locations, and even our state of health. But have the underlying protocols by which they communicate this data kept pace with the need to protect our privacy and security?

My talk will introduce my research into an approach to better secure this information flow using appropriate access controls without sacrificing performance. I will assess the historical challenges and simple access controls applied to IoT networking protocols and how they can …


Generative Machine Learning For Cyber Security, James Halvorsen, Dr. Assefaw Gebremedhin 2024 Washington State University

Generative Machine Learning For Cyber Security, James Halvorsen, Dr. Assefaw Gebremedhin

Military Cyber Affairs

Automated approaches to cyber security based on machine learning will be necessary to combat the next generation of cyber-attacks. Current machine learning tools, however, are difficult to develop and deploy due to issues such as data availability and high false positive rates. Generative models can help solve data-related issues by creating high quality synthetic data for training and testing. Furthermore, some generative architectures are multipurpose, and when used for tasks such as intrusion detection, can outperform existing classifier models. This paper demonstrates how the future of cyber security stands to benefit from continued research on generative models.


Privacy Protection In Mobile Photography With Face Cloaking, Rithyka Heng 2024 University of Arkansas, Fayetteville

Privacy Protection In Mobile Photography With Face Cloaking, Rithyka Heng

Computer Science and Computer Engineering Undergraduate Honors Theses

In a world of increasing connectivity, privacy is becoming ever-more difficult to maintain. People have little control over the capture of their image while in public and have even less control over the online sharing or posting of their image. This leaves many people vulnerable to being tracked or profiled via their image’s presence in other people’s photos. This thesis implements and evaluates an approach to privacy protection that involves the photographers protecting the privacy of bystanders. Because most photographs are now being taken by smartphones, a mobile application is decidedly the technology that would best achieve widespread adoption and …


Side Channel Detection Of Pc Rootkits Using Nonlinear Phase Space, Rebecca Clark 2024 University of South Alabama

Side Channel Detection Of Pc Rootkits Using Nonlinear Phase Space, Rebecca Clark

Poster Presentations

Cyberattacks are increasing in size and scope yearly, and the most effective and common means of attack is through malicious software executed on target devices of interest. Malware threats vary widely in terms of behavior and impact and, thus, effective methods of detection are constantly being sought from the academic research community to offset both volume and complexity. Rootkits are malware that represent a highly feared threat because they can change operating system integrity and alter otherwise normally functioning software. Although normal methods of detection that are based on signatures of known malware code are the standard line of defense, …


Exploring Decentralized Computing Using Solid And Ipfs For Social Media Applications, Pranav Balasubramanian Natarajan 2024 University of Arkansas, Fayetteville

Exploring Decentralized Computing Using Solid And Ipfs For Social Media Applications, Pranav Balasubramanian Natarajan

Computer Science and Computer Engineering Undergraduate Honors Theses

As traditional centralized social media platforms face growing concerns over data privacy, censorship, and lack of user control, there has been an increasing interest in decentralized alternatives. This thesis explores the design and implementation of a decentralized social media application by integrating two key technologies: Solid and the InterPlanetary File System (IPFS). Solid, led by Sir Tim Berners-Lee, enables users to store and manage their personal data in decentralized "Pods," giving them ownership over their digital identities. IPFS, a peer-to-peer hypermedia protocol, facilitates decentralized file storage and sharing, ensuring content availability and resilience against censorship. By leveraging these technologies, the …


Detection Of Jamming Attacks In Vanets, Thomas Justice 2024 East Tennessee State University

Detection Of Jamming Attacks In Vanets, Thomas Justice

Undergraduate Honors Theses

A vehicular network is a type of communication network that enables vehicles to communicate with each other and the roadside infrastructure. The roadside infrastructure consists of fixed nodes such as roadside units (RSUs), traffic lights, road signs, toll booths, and so on. RSUs are devices equipped with communication capabilities that allow vehicles to obtain and share real-time information about traffic conditions, weather, road hazards, and other relevant information. These infrastructures assist in traffic management, emergency response, smart parking, autonomous driving, and public transportation to improve roadside safety, reduce traffic congestion, and enhance the overall driving experience. However, communication between the …


An In-Network Approach For Pmu Missing Data Recovery With Data Plane Programmability, Jack Norris 2024 University of Arkansas, Fayetteville

An In-Network Approach For Pmu Missing Data Recovery With Data Plane Programmability, Jack Norris

Computer Science and Computer Engineering Undergraduate Honors Theses

Phasor measurement unit (PMU) systems often experience unavoidable missing and erroneous measurements, which undermine power system observability and operational effectiveness. Traditional solutions for recovering missing PMU data employ a centralized approach at the control center, resulting in lengthy recovery times due to data transmission and aggregation. In this work, we leverage P4-based programmable networks to expedite missing data recovery. Our approach utilizes the data plane programmability offered by P4 to present an in-network solution for PMU data recovery. We establish a data-plane pipeline on P4 switches, featuring a customized PMU protocol parser, a missing data detection module, and an auto-regressive …


Monero: Powering Anonymous Digital Currency Transactions, Jake Braddy 2024 University of Nebraska at Omaha

Monero: Powering Anonymous Digital Currency Transactions, Jake Braddy

Theses/Capstones/Creative Projects

Cryptocurrencies rely on a distributed public ledger (record of transactions) in order to perform their intended functions. However, the public’s ability to audit the network is both its greatest strength and greatest weakness: Anyone can see what address sent currency, and to whom the currency was sent. If cryptocurrency is ever going to take some of the responsibility of fiat currency, then there needs to be a certain level of confidentiality. Thus far, Monero has come out on top as the preferred currency for embodying the ideas of privacy and confidentiality. Through numerous cryptographic procedures, Monero is able to obfuscate …


A Study Of Cybersecurity Landscape In The United States: Trend, Regional Variations, And Socioeconomic Factors, Trang Thi Thu Horn 2024 Indiana State University

A Study Of Cybersecurity Landscape In The United States: Trend, Regional Variations, And Socioeconomic Factors, Trang Thi Thu Horn

All-Inclusive List of Electronic Theses and Dissertations

The Internet has become an essential part of our daily lives. Cyberspace has emerged significantly with an enormous number of users, creating a lucrative hunting field for cybercriminals. The exponential growth of internet users and online activities, along with the increased sophistication of cybercrimes, is raising significant global concerns for individuals, organizations, and governments. This research aims to explore the cybersecurity landscape in the United States, investigate regional variations, and the potential impact of the COVID-19 pandemic on the number of cybercrimes. The study utilizes a mixed research method approach, including historical analysis and a Delphi study. Historical analysis studied …


Formalization Of A Security Framework Design For A Health Prescription Assistant In An Internet Of Things System, Thomas Rolando Mellema 2024 Stephen F Austin State University

Formalization Of A Security Framework Design For A Health Prescription Assistant In An Internet Of Things System, Thomas Rolando Mellema

Electronic Theses and Dissertations

Security system design flaws will create greater risks and repercussions as the systems being secured further integrate into our daily life. One such application example is incorporating the powerful potential of the concept of the Internet of Things (IoT) into software services engineered for improving the practices of monitoring and prescribing effective healthcare to patients. A study was performed in this application area in order to specify a security system design for a Health Prescription Assistant (HPA) that operated with medical IoT (mIoT) devices in a healthcare environment. Although the efficiency of this system was measured, little was presented to …


Data Recovery Beyond The Obvious Using Digital Forensic Techniques, Smit Chandrakant Nayak 2024 Montclair State University

Data Recovery Beyond The Obvious Using Digital Forensic Techniques, Smit Chandrakant Nayak

Theses, Dissertations and Culminating Projects

Advancement in drone technology, particularly for smaller drones, are creating new research fields and potential applications, particularly with regard to smaller drones. On the other hand, these enhancements bring forth additional hurdles in terms of adaptability, homogeneity, and safety. The purpose of this study is to investigate the science and technology behind drones, as well as their applications, the many ways in which citizens implement them, and the risks, precautions, and privacy problems that are associated with their utilization. This article discusses the existing literature, as well as the available solutions for drone cybersecurity, the security challenges related with drones …


Digital Commons powered by bepress