Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,670 Full-Text Articles 6,838 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,670 full-text articles. Page 33 of 201.

Customer Cybersecurity And Supplier Cost Management Strategy, Xu YANG, Peng LIANG, Nan HU, Fujing XUE 2023 Singapore Management University

Customer Cybersecurity And Supplier Cost Management Strategy, Xu Yang, Peng Liang, Nan Hu, Fujing Xue

Research Collection School Of Computing and Information Systems

In this paper, we explore the spillover effect of customer firms’ data breaches on their upstream supplier firms’ cost management strategies, proxied by cost stickiness. Our primary analyses suggest that data breaches suffered by customer firms are associated with a decrease in cost stickiness among supplier firms. Furthermore, the reductions in supplier cost stickiness are stronger if suppliers are managed by CEOs from national cultural groups with high uncertainty avoidance, low long-term orientations, and/or low individualism. In sum, the findings contribute to both Information Systems (IS) and Operations Management (OM) disciplines in terms of data breach, cost management strategy, and …


The Propagation And Execution Of Malware In Images, Piper Hall 2023 Christopher Newport University

The Propagation And Execution Of Malware In Images, Piper Hall

Cybersecurity Undergraduate Research Showcase

Malware has become increasingly prolific and severe in its consequences as information systems mature and users become more reliant on computing in their daily lives. As cybercrime becomes more complex in its strategies, an often-overlooked manner of propagation is through images. In recent years, several high-profile vulnerabilities in image libraries have opened the door for threat actors to steal money and information from unsuspecting users. This paper will explore the mechanisms by which these exploits function and how they can be avoided.


An Empirical Study On The Use Of Predictive Analytics For Improving Trade Forecasting In The Uae, Asma Salem Alneyadi 2023 United Arab Emirates University

An Empirical Study On The Use Of Predictive Analytics For Improving Trade Forecasting In The Uae, Asma Salem Alneyadi

Thesis/ Dissertation Defenses

Trade contributes to the United Arab Emirates' economic growth. This thesis focuses on trade dynamics in the UAE using Long Short-Term Memory (LSTM) neural networks. The study focuses on both import and export activities, providing understandings into the complex patterns and impacts of international trade on the UAE's economic growth. The research begins by constructing an LSTM model to forecast the UAE's Gross Domestic Product (GDP) through the utilization of historical trade data. We use time series data for imports and exports as key input features. This innovative approach highlights the relevance of trade statistics as a leading indicator of …


Assessing Open Source Tools For Enhanced Forensic Analysis Of Unmanned Aerial Vehicles (Uavs), Nura Shifa Hamed 2023 United Arab Emirates University

Assessing Open Source Tools For Enhanced Forensic Analysis Of Unmanned Aerial Vehicles (Uavs), Nura Shifa Hamed

Thesis/ Dissertation Defenses

The widespread applications of Unmanned Aerial Vehicles (UAVs), commonly referred to as drones, has given rise to significant national security threats due to their illicit activities. Consequently, the domain of UAV forensics is rapidly evolving, presenting a substantial knowledge deficit among forensic experts. Open-source tools provide accessible and affordable resources, making it easier for investigators to bridge this gap by gaining expertise in the use of these tools. This helps ensure that forensic professionals can keep up with the ever-changing UAV technology landscape. This thesis undertakes the mission of navigate the complex field of drone forensics and conducting a comprehensive …


Preparing Uk Students For The Workplace: The Acceptability Of A Gamified Cybersecurity Training, Oliver J. Mason, Siobhan Collman, Stella Kazamia, Ioana Boureanu 2023 University of Surrey

Preparing Uk Students For The Workplace: The Acceptability Of A Gamified Cybersecurity Training, Oliver J. Mason, Siobhan Collman, Stella Kazamia, Ioana Boureanu

Journal of Cybersecurity Education, Research and Practice

This pilot study aims to assess the acceptability of Open University’s training platform called Gamified Intelligent Cyber Aptitude and Skills Training course (GICAST), as a means of improving cybersecurity knowledge, attitudes, and behaviours in undergraduate students using both quantitative and qualitative methods. A mixed-methods, pre-post experimental design was employed. 43 self-selected participants were recruited via an online register and posters at the university (excluding IT related courses). Participants completed the Human Aspects of Information Security Questionnaire (HAIS-Q) and Fear of Missing Out (FoMO) Scale. They then completed all games and quizzes in the GICAST course before repeating the HAIS-Q and …


Closing The Gap: Leveraging Aes-Ni To Balance Adversarial Advantage And Honest User Performance In Argon2i, Nicholas Harrell, Nathaniel Krakauer 2023 Purdue University

Closing The Gap: Leveraging Aes-Ni To Balance Adversarial Advantage And Honest User Performance In Argon2i, Nicholas Harrell, Nathaniel Krakauer

CERIAS Technical Reports

The challenge of providing data privacy and integrity while maintaining efficient performance for honest users is a persistent concern in cryptography. Attackers exploit advances in parallel hardware and custom circuit hardware to gain an advantage over regular users. One such method is the use of Application-Specific Integrated Circuits (ASICs) to optimize key derivation function (KDF) algorithms, giving adversaries a significant advantage in password guessing and recovery attacks. Other examples include using graphical processing units (GPUs) and field programmable gate arrays (FPGAs). We propose a focused approach to close the gap between adversarial advantage and honest user performance by leveraging the …


Optimization Of Biomedical Imaging Filters For Use In Recaptured Identity Document Classification, John Magee, Stephen Sheridan PhD, Christina Thorpe PhD 2023 Technological University Dublin

Optimization Of Biomedical Imaging Filters For Use In Recaptured Identity Document Classification, John Magee, Stephen Sheridan Phd, Christina Thorpe Phd

Conference papers

As banks and online financial institutions move toward full remote onboarding services, the attack vectors for bad actors increases to include those of recaptured identity documents. This type of fraud opens banking customers to potential crimes of identity theft, as well as causing reputational damage to the institutions involved. In this paper we extend existing research focusing on the use of biomedical imaging filters and their usefulness when classifying recaptured identity documents. We perform a grid search and demonstrate that different filter configurations exist that dramatically reduce the classification error rates compared to those achieved using only the default filter …


Integrity, Confidentiality, And Equity: Using Inquiry-Based Labs To Help Students Understand Ai And Cybersecurity, Richard C. Alexander, Liran Ma, Ze-Li Dou, Zhipeng Cai, Yan Huang 2023 Texas Christian University

Integrity, Confidentiality, And Equity: Using Inquiry-Based Labs To Help Students Understand Ai And Cybersecurity, Richard C. Alexander, Liran Ma, Ze-Li Dou, Zhipeng Cai, Yan Huang

Journal of Cybersecurity Education, Research and Practice

Recent advances in Artificial Intelligence (AI) have brought society closer to the long-held dream of creating machines to help with both common and complex tasks and functions. From recommending movies to detecting disease in its earliest stages, AI has become an aspect of daily life many people accept without scrutiny. Despite its functionality and promise, AI has inherent security risks that users should understand and programmers must be trained to address. The ICE (integrity, confidentiality, and equity) cybersecurity labs developed by a team of cybersecurity researchers addresses these vulnerabilities to AI models through a series of hands-on, inquiry-based labs. Through …


A Novel Chatbot System For Digitizing Service Management To Improve Business Continuity, Asraa Mohammed Albeshr 2023 United Arab Emirates University

A Novel Chatbot System For Digitizing Service Management To Improve Business Continuity, Asraa Mohammed Albeshr

Thesis/ Dissertation Defenses

The COVID-19 pandemic underscored the importance of businesses transitioning to digital platforms to reduce human contact and maintain operations. Digital transformation is the act of leveraging digital technologies to enhance and update business operations, corporate culture, and customer interactions to address evolving market needs. IT service management (ITSM) stands to gain significantly from this shift, as many of its processes are currently manual and labor-intensive. In our research, we introduced a model designed to refine chatbot responses to user questions, making it an invaluable asset for our study. The model performed admirably, achieving an accuracy rate of 90%. Moreover, we …


Understanding The Non-Traditional Security Dimensions: Cyber Threat Landscape In Pakistan, Minhas Majeed Khan 2023 Research Scholar, University of Peshawar

Understanding The Non-Traditional Security Dimensions: Cyber Threat Landscape In Pakistan, Minhas Majeed Khan

CBER Conference

The research analyzes the vulnerabilities and consequences of cyber-attacks on essential infrastructure sectors such as energy, telecommunications, and finance, which are vital for the country’s stability and development. It also evaluates the economic, political, and social effects of cyber incidents on the country’s governance and society. Moreover, the research assesses the current cyber security measures and frameworks in Pakistan and identifies the gaps and opportunities for improvement.


Building A Diverse Cybersecurity Workforce: A Study On Attracting Learners With Varied Educational Backgrounds, Mubashrah Saddiqa, Kristian Helmer Kjær Larsen1 Helmer Kjær Larsen, Robert Nedergaard Nielsen, Jens Myrup Pedersen 2023 Aalborg University, Denmark

Building A Diverse Cybersecurity Workforce: A Study On Attracting Learners With Varied Educational Backgrounds, Mubashrah Saddiqa, Kristian Helmer Kjær Larsen1 Helmer Kjær Larsen, Robert Nedergaard Nielsen, Jens Myrup Pedersen

Journal of Cybersecurity Education, Research and Practice

Cybersecurity has traditionally been perceived as a highly technical field, centered around hacking, programming, and network defense. However, this article contends that the scope of cybersecurity must transcend its technical confines to embrace a more inclusive approach. By incorporating various concepts such as privacy, data sharing, and ethics, cybersecurity can foster diversity among audiences with varying educational backgrounds, thereby cultivating a richer and more resilient security landscape. A more diverse cybersecurity workforce can provide a broader range of perspectives, experiences, and skills to address the complex and ever-evolving threats of the digital age. The research focuses on enhancing cybersecurity education …


Evaluating Attack Surface Management In An Industrial Control System (Ics) Environment: Leveraging A Recon Ftw For Threat Classification And Incident Response, Nathalia de Sa Soares 2023 Louisiana State University at Baton Rouge

Evaluating Attack Surface Management In An Industrial Control System (Ics) Environment: Leveraging A Recon Ftw For Threat Classification And Incident Response, Nathalia De Sa Soares

LSU Master's Theses

Protecting Industrial Control Systems (ICS) from cyber threats is paramount to
ensure the reliability and security of critical infrastructure. Organizations must proactively identify vulnerabilities and strengthen their incident response capabilities as attack vectors evolve. This research explores implementing an Attack Surface Management (ASM) approach, utilizing Recon FTW, to assess an operating ICS environment’s security posture comprehensively.
The primary objective of this research is to develop a tool for performing recon-
naissance in an ICS environment with a non-intrusive approach, enabling the realistic simulation of potential threat scenarios and the identification of critical areas requiring immediate attention and remediation. We aim …


An Empirical Study On The Use Of Secure Predictive Analytics For Improving Trade Forecasting In The Uae, Asma Salem Alneyadi 2023 United Arab Emirates University

An Empirical Study On The Use Of Secure Predictive Analytics For Improving Trade Forecasting In The Uae, Asma Salem Alneyadi

Theses

Trade contributes to the United Arab Emirates' economic growth. This thesis focuses on trade dynamics in the UAE using Long Short-Term Memory (LSTM) neural networks. The study focuses on both import and export activities, providing understandings into the complex patterns and impacts of international trade on the UAE's economic growth. The research begins by constructing an LSTM model to forecast the UAE's Gross Domestic Product (GDP) through the utilization of historical trade data. We use time series data for imports and exports as key input features. This innovative approach highlights the relevance of trade statistics as a leading indicator of …


Designing Secure Mental Healthcare Chatbots For Older Adults, Aishwarya Surani 2023 University of Denver

Designing Secure Mental Healthcare Chatbots For Older Adults, Aishwarya Surani

Electronic Theses and Dissertations

The landscape of mental health support has evolved as a result of the rising demand for digital mental healthcare services. Users now have an opportunity to seek mental health support online due to the growth of digital platforms. For those looking for mental health treatments, chatbots have evolved as user-friendly, accessible platforms that provide remote access and convenience. However, for chatbots to be effective, users must divulge personal and sensitive information, such as demographics, insurance information, and a history of mental illness. While chatbots offer services to a variety of demographic users, older adults face unique challenges related to usability, …


A Smart Chatbot System For Digitizing Service Management To Improve Business Continuity, Asraa Mohammed Albeshr 2023 United Arab Emirates University

A Smart Chatbot System For Digitizing Service Management To Improve Business Continuity, Asraa Mohammed Albeshr

Theses

Chatbots, also called digital systems that require a natural language-based interface for user interaction, are increasingly being integrated into our daily lives. These chatbots respond intelligently to voice and text and function as sophisticated entities. Its functioning includes the recognition of multiple human languages through the application of Natural Language Processing (NLP) techniques. These chatbots find applications in various areas such as e-commerce services, medical assistance, recommendation systems, and educational purposes. This reflects the versatility and widespread adoption of this technology. AI chatbots play a crucial role in improving IT support in IT Service Management (ITSM) for better business continuity. …


Rethinking Conversational Agents In The Era Of Large Language Models: Proactivity, Non-Collaborativity, And Beyond, Yang DENG, Wenqiang LEI, Minlie HUANG, Tat-Seng CHUA 2023 Singapore Management University

Rethinking Conversational Agents In The Era Of Large Language Models: Proactivity, Non-Collaborativity, And Beyond, Yang Deng, Wenqiang Lei, Minlie Huang, Tat-Seng Chua

Research Collection School Of Computing and Information Systems

Conversational systems are designed to offer human users social support or functional services through natural language interactions. Typical conversation researches mainly focus on the response-ability of the system, such as dialogue context understanding and response generation. In the era of large language models (LLMs), LLM-augmented conversational systems showcase exceptional capabilities of responding to user queries for different language tasks. However, as LLMs are trained to follow users' instructions, LLM-augmented conversational systems typically overlook the design of an essential property in intelligent conversations, i.e., goal awareness. In this tutorial, we will introduce the recent advances on the design of agent's awareness …


Privacy-Preserving Bloom Filter-Based Keyword Search Over Large Encrypted Cloud Data, Yanrong LIANG, Jianfeng MA, Yinbin MIAO, Da KUANG, Xiangdong MENG, Robert H. DENG 2023 Singapore Management University

Privacy-Preserving Bloom Filter-Based Keyword Search Over Large Encrypted Cloud Data, Yanrong Liang, Jianfeng Ma, Yinbin Miao, Da Kuang, Xiangdong Meng, Robert H. Deng

Research Collection School Of Computing and Information Systems

To achieve the search over encrypted data in cloud server, Searchable Encryption (SE) has attracted extensive attention from both academic and industrial fields. The existing Bloom filter-based SE schemes can achieve similarity search, but will generally incur high false positive rates, and even leak the privacy of values in Bloom filters (BF). To solve the above problems, we first propose a basic Privacy-preserving Bloom filter-based Keyword Search scheme using the Circular Shift and Coalesce-Bloom Filter (CSC-BF) and Symmetric-key Hidden Vector Encryption (SHVE) technology (namely PBKS), which can achieve effective search while protecting the values in BFs. Then, we design a …


Krover: A Symbolic Execution Engine For Dynamic Kernel Analysis, Pansilu Madhura Bhashana Pitigalaarachchi PITIGALA ARACHCHILLAGE, Xuhua DING, Haiqing QIU, Haoxin TU, Jiaqi HONG, Lingxiao JIANG 2023 Singapore Management University

Krover: A Symbolic Execution Engine For Dynamic Kernel Analysis, Pansilu Madhura Bhashana Pitigalaarachchi Pitigala Arachchillage, Xuhua Ding, Haiqing Qiu, Haoxin Tu, Jiaqi Hong, Lingxiao Jiang

Research Collection School Of Computing and Information Systems

We present KRover, a novel kernel symbolic execution engine catered for dynamic kernel analysis such as vulnerability analysis and exploit generation. Different from existing symbolic execution engines, KRover operates directly upon a live kernel thread's virtual memory and weaves symbolic execution into the target's native executions. KRover is compact as it neither lifts the target binary to an intermediary representation nor uses QEMU or dynamic binary translation. Benchmarked against S2E, our performance experiments show that KRover is up to 50 times faster but with one tenth to one quarter of S2E memory cost. As shown in our four case studies, …


Verifytl: Secure And Verifiable Collaborative Transfer Learning, Zhuoran MA, Jianfeng MA, Yinbin MIAO, Ximeng LIU, Wei ZHENG, Kim-Kwang Raymond CHOO, Robert H. DENG 2023 Xidian University

Verifytl: Secure And Verifiable Collaborative Transfer Learning, Zhuoran Ma, Jianfeng Ma, Yinbin Miao, Ximeng Liu, Wei Zheng, Kim-Kwang Raymond Choo, Robert H. Deng

Research Collection School Of Computing and Information Systems

Getting access to labeled datasets in certain sensitive application domains can be challenging. Hence, one may resort to transfer learning to transfer knowledge learned from a source domain with sufficient labeled data to a target domain with limited labeled data. However, most existing transfer learning techniques only focus on one-way transfer which may not benefit the source domain. In addition, there is the risk of a malicious adversary corrupting a number of domains, which can consequently result in inaccurate prediction or privacy leakage. In this paper, we construct a secure and Verif iable collaborative T ransfer L earning scheme, VerifyTL, …


Ppdf: A Privacy-Preserving Cloud-Based Data Distribution System With Filtering, Yudi ZHANG, Willy SUSILO, Fuchun GUO, Guomin YANG 2023 Singapore Management University

Ppdf: A Privacy-Preserving Cloud-Based Data Distribution System With Filtering, Yudi Zhang, Willy Susilo, Fuchun Guo, Guomin Yang

Research Collection School Of Computing and Information Systems

Cloud computing has emerged as a popular choice for distributing data among both individuals and companies. Ciphertext-policy attribute-based encryption (CP-ABE) has been extensively used to provide data security and enable fine-grained access control. With this encryption technique, only users whose attributes satisfy the access policy can access the plaintext. In order to mitigate the computational overhead on users, particularly on lightweight devices, partial decryption has been introduced, where the cloud assists in performing the decryption computations without revealing sensitive information. However, in this process, the cloud obtains the user's attributes, thus infringing on the user's privacy. To address this issue, …


Digital Commons powered by bepress