Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,670 Full-Text Articles 6,838 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,670 full-text articles. Page 40 of 201.

Fine-Grained Commit-Level Vulnerability Type Prediction By Cwe Tree Structure, Shengyi PAN, Lingfeng BAO, Xin XIA, David LO, Shanping LI 2023 Singapore Management University

Fine-Grained Commit-Level Vulnerability Type Prediction By Cwe Tree Structure, Shengyi Pan, Lingfeng Bao, Xin Xia, David Lo, Shanping Li

Research Collection School Of Computing and Information Systems

Identifying security patches via code commits to allow early warnings and timely fixes for Open Source Software (OSS) has received increasing attention. However, the existing detection methods can only identify the presence of a patch (i.e., a binary classification) but fail to pinpoint the vulnerability type. In this work, we take the first step to categorize the security patches into fine-grained vulnerability types. Specifically, we use the Common Weakness Enumeration (CWE) as the label and perform fine-grained classification using categories at the third level of the CWE tree. We first formulate the task as a Hierarchical Multi-label Classification (HMC) problem, …


Colefunda: Explainable Silent Vulnerability Fix Identification, Jiayuan ZHOU, Michael PACHECO, Jinfu CHEN, Xing HU, Xin XIA, David LO, Ahmed E. HASSAN 2023 Singapore Management University

Colefunda: Explainable Silent Vulnerability Fix Identification, Jiayuan Zhou, Michael Pacheco, Jinfu Chen, Xing Hu, Xin Xia, David Lo, Ahmed E. Hassan

Research Collection School Of Computing and Information Systems

It is common practice for OSS users to leverage and monitor security advisories to discover newly disclosed OSS vulnerabilities and their corresponding patches for vulnerability remediation. It is common for vulnerability fixes to be publicly available one week earlier than their disclosure. This gap in time provides an opportunity for attackers to exploit the vulnerability. Hence, OSS users need to sense the fix as early as possible so that the vulnerability can be remediated before it is exploited. However, it is common for OSS to adopt a vulnerability disclosure policy which causes the majority of vulnerabilities to be fixed silently, …


Low-Complexity Three-Dimensional Aoa-Cross Geometric Center Localization Methods Via Multi-Uav Network, Baihua Shi, Yifan Li, Guilu Wu, Riqing Chen, Shihao Yan, Feng Shu 2023 Edith Cowan University

Low-Complexity Three-Dimensional Aoa-Cross Geometric Center Localization Methods Via Multi-Uav Network, Baihua Shi, Yifan Li, Guilu Wu, Riqing Chen, Shihao Yan, Feng Shu

Research outputs 2022 to 2026

The angle of arrival (AOA) is widely used to locate a wireless signal emitter in unmanned aerial vehicle (UAV) localization. Compared with received signal strength (RSS) and time of arrival (TOA), AOA has higher accuracy and is not sensitive to the time synchronization of the distributed sensors. However, there are few works focusing on three-dimensional (3-D) scenarios. Furthermore, although the maximum likelihood estimator (MLE) has a relatively high performance, its computational complexity is ultra-high. Therefore, it is hard to employ it in practical applications. This paper proposed two center of inscribed sphere-based methods for 3-D AOA positioning via multiple UAVs. …


Premium Wireless, Dakota Burkhart, Andrew Clark, Garrett Kenney, Brandon Monroe 2023 Arkansas Tech University

Premium Wireless, Dakota Burkhart, Andrew Clark, Garrett Kenney, Brandon Monroe

ATU Scholars Symposium

Our work implements an inventory system and appointment system for the Premium Wireless phone company. It includes separate views for employees to manage inventory and view appointments for the day and the near future and allows customers to view all current inventory and set an appointment.


Analysis Of Honeypots In Detecting Tactics, Techniques, And Procedure (Ttp) Changes In Threat Actors Based On Source Ip Address, Carson Reynolds, Andy Green 2023 Kennesaw State University

Analysis Of Honeypots In Detecting Tactics, Techniques, And Procedure (Ttp) Changes In Threat Actors Based On Source Ip Address, Carson Reynolds, Andy Green

Symposium of Student Scholars

The financial and national security impacts of cybercrime globally are well documented. According to the 2020 FBI Internet Crime Report, financially motivated threat actors committed 86% of reported breaches, resulting in a total loss of approximately $4.1 billion in the United States alone. In order to combat this, our research seeks to determine if threat actors change their tactics, techniques, and procedures (TTPs) based on the geolocation of their target’s IP address. We will construct a honeypot network distributed across multiple continents to collect attack data from geographically separate locations concurrently to answer this research question. We will configure the …


The Impact Of Artificial Intelligence On The Cybersecurity Industry, Lindsey Shearstone 2023 Bryant University

The Impact Of Artificial Intelligence On The Cybersecurity Industry, Lindsey Shearstone

Honors Projects in Information Systems and Analytics

As our world becomes more digitalized, cyber criminals have an increasing landscape to launch their attacks. Developments in Artificial Intelligence are being used both to attack and defend networks, therefore, what is the next step for cybersecurity companies when it comes to beating these criminals? A study was conducted that utilizes previous literature sources written on the topic of Artificial Intelligence (AI) in the cybersecurity industry. In addition, the insights of professionals in the industry today are included through a survey and interviews to dive into the details of this battle and what lays in its future. The purpose of …


Visual Art In The Age Of Ai, Roshnica Gurung 2023 William & Mary

Visual Art In The Age Of Ai, Roshnica Gurung

Cybersecurity Undergraduate Research Showcase

Artists and researchers have been deeply interested in using AI programs that generate art for quite some time now. As a result, there have been many advancements in making AI more accessible and easier to use for the public. This is because AI is not just for business anymore. Nowadays an individual without a college degree with even the slightest interest in art can go on a website like Stable Diffusion and create an artistic image using a text prompt in a quick couple minutes. The only limit is your imagination- and your internet’s stability. This accessibility was a huge …


Assessing The Frequency And Severity Of Malware Attacks: An Exploratory Analysis Of The Advisen Cyber Loss Dataset, Ahmed M. Abdelmagid, Farshid Javadnejad, C. Ariel Pinto, Michael K. McShane, Rafael Diaz, Elijah Gartell 2023 Old Dominion University

Assessing The Frequency And Severity Of Malware Attacks: An Exploratory Analysis Of The Advisen Cyber Loss Dataset, Ahmed M. Abdelmagid, Farshid Javadnejad, C. Ariel Pinto, Michael K. Mcshane, Rafael Diaz, Elijah Gartell

Modeling, Simulation and Visualization Student Capstone Conference

In today's business landscape, cyberattacks present a significant threat that can lead to severe financial losses and damage to a company's reputation. To mitigate this risk, it is essential for stakeholders to have an understanding of the latest types and patterns of cyberattacks. The primary objective of this research is to provide this knowledge by utilizing the Advisen cyber loss dataset, which comprises over 137,000 cyber incidents that occurred across various industry sectors from 2013 to 2020. By using text mining techniques, this paper will conduct an exploratory data analysis to identify the most common types of malware, including ransomware. …


Role Of Ai In Threat Detection And Zero-Day Attacks, Kelly Morgan 2023 Old Dominion University

Role Of Ai In Threat Detection And Zero-Day Attacks, Kelly Morgan

Cybersecurity Undergraduate Research Showcase

Cybercrime and attack methods have been steadily increasing since the 2019 pandemic. In the years following 2019, the number of victims and attacks per hour rapidly increased as businesses and organizations transitioned to digital environments for business continuity amidst lockdowns. In most scenarios cybercriminals continued to use conventional attack methods and known vulnerabilities that would cause minimal damage to an organization with a robust cyber security posture. However, zero-day exploits have skyrocketed across all industries with an increasingly growing technological landscape encompassing internet of things (IoT), cloud hosting, and more advanced mobile technologies. Reports by Mandiant Threat Intelligence (2022) concluded …


Cybersecurity Workforce Development In Nigeria: Transforming The Cybercrime Gangs Into Cybersecurity Specialists, Olohi Favor Anteyi 2023 Old Dominion University

Cybersecurity Workforce Development In Nigeria: Transforming The Cybercrime Gangs Into Cybersecurity Specialists, Olohi Favor Anteyi

Cybersecurity Undergraduate Research Showcase

This paper addresses the issue of cybercrime in Nigeria and the possibility of creating a cybersecurity workforce development program for cyber criminals to develop their skills for the cybersecurity profession, which may facilitate Nigeria’s economic development.


Unveiling The Dark Web And The Impact Of Revil's Cyberattacks, Tanya Sasnouskaya 2023 Old Dominion University

Unveiling The Dark Web And The Impact Of Revil's Cyberattacks, Tanya Sasnouskaya

Cybersecurity Undergraduate Research Showcase

The United States Navy originally created the Dark Web for intelligence purposes, but it was later promoted by Western countries as a tool for safeguarding privacy and anonymity. Currently, the Dark Web serves as a platform for deliberate information leaks by nations that want to keep certain information out of the mainstream media. This paper provides an overview of the dark web and the browser used to access it. It covers the layers of the internet and highlights REvil ransomware and some of its technical details. By understanding these risks, users can take appropriate preventive measures to protect themselves from …


Some Legal And Practical Challenges In The Investigation Of Cybercrime, Ritz Carr 2023 Old Dominion University

Some Legal And Practical Challenges In The Investigation Of Cybercrime, Ritz Carr

Cybersecurity Undergraduate Research Showcase

According to the Internet Crime Complaint Center (IC3), in 2021, the United States lost around $6.9 billion to cybercrime. In 2022, that number grew to over $10.2 billion (IC3, 2022). In one of many efforts to combat cybercrimes, at least 40 states “introduced or considered more than 250 bills or resolutions that deal significantly with cybersecurity” with 24 states officially enacting a total of 41 bills (National Conference on State Legislatures, 2022).

The world of cybercrime evolves each day. Nevertheless, challenges arise when we investigate and prosecute cybercrime, which will be examined in the following collection of essays that highlight …


The Linkage Between The Climate Change And The Cybercrimes, Min Kim 2023 William & Mary

The Linkage Between The Climate Change And The Cybercrimes, Min Kim

Cybersecurity Undergraduate Research Showcase

At the beginning of the new era, the rise of the Fourth Industrial Revolution has been rapidly transforming society into a new form that has never been experienced before. While previous industrial revolutions have also contributed to societal growth through phenomenal inventions and discoveries, the Fourth Industrial Revolution has the potential to break the most conventional rule, and one that has dominated social and economic activities: physical interaction. In the near future, sitting at the office, having an in-person meeting, or going on a business trip may no longer be needed as physical barriers are destroyed by cyberspace. However, two …


Cyber Security In Cyber Space, James D. Lee Jr. 2023 Old Dominion University

Cyber Security In Cyber Space, James D. Lee Jr.

Cybersecurity Undergraduate Research Showcase

For almost twenty years, the Internet has been a driving force in global communication and an integral part of people's everyday lives. As a result of technical developments and declining prices, over 3 billion people worldwide now utilize the Internet. The Internet has created a global infrastructure, and it is worth billions of dollars annually to the global economy (Judge et al.). Today's economic, commercial, cultural, social, and governmental activities and exchanges occur in Cyberspace, involving individuals, enterprises, non-profit organizations, and government and governmental agencies (Aghajani and Ghadimi 220). Cyberspace is the birthplace of much of the world's most essential …


Leveraging Artificial Intelligence And Machine Learning For Enhanced Cybersecurity: A Proposal To Defeat Malware, Emmanuel Boateng 2023 Old Dominion University

Leveraging Artificial Intelligence And Machine Learning For Enhanced Cybersecurity: A Proposal To Defeat Malware, Emmanuel Boateng

Cybersecurity Undergraduate Research Showcase

Cybersecurity is very crucial in the digital age in order to safeguard the availability, confidentiality, and integrity of data and systems. Mitigation techniques used in the industry include Multi-factor Authentication (MFA), Incident Response Planning (IRP), Security Information and Event Management (SIEM), and Signature-based and Heuristic Detection.

MFA is employed as an additional layer of protection in several sectors to help prevent unauthorized access to sensitive data. IRP is a plan in place to address cybersecurity problems efficiently and expeditiously. SIEM offers real-time analysis and alerts the system of threats and vulnerabilities. Heuristic-based detection relies on detecting anomalies when it comes …


Cheating Detection In Online Exams Based On Captured Video Using Deep Learning, Aysha Sultan Alkalbani 2023 United Arab Emirates University

Cheating Detection In Online Exams Based On Captured Video Using Deep Learning, Aysha Sultan Alkalbani

Theses

Today, e-learning has become a reality and a global trend imposed and accelerated by the COVID-19 pandemic. However, there are many risks and challenges related to the credibility of online exams which are of widespread concern to educational institutions around the world. Online exam system continues to gain popularity, particularly during the pandemic, due to the rapid expansion of digitalization and globalization. To protect the integrity of the examination and provide objective and fair results, cheating detection and prevention in examination systems is a must. Therefore, the main objective of this thesis is to develop an effective way of detection …


A Comparative Study On Microchip Implants In Humans And Wearable Devices, Ltifa Mohammed Almansoori 2023 United Arab Emirates University

A Comparative Study On Microchip Implants In Humans And Wearable Devices, Ltifa Mohammed Almansoori

Theses

After the tragic covid pandemic in 2020, many things changed in the world, from learning physically all the way to e-learning, as the whole world was forced to switch digitally. It is expected that a lot of people will be more willing to invest in new technologies that aid in human development and among them are human microchip implants. The emerging technology of human microchip implants is slowly catching the attention of various countries around the world after the sudden surge of adoption in Europe. With the introduction of Biohax microchip implants in the UAE by Etisalat it is most …


Data Leakage In Isolated Virtualized Enterprise Computing Systems, Zechariah D.J. Wolf 2023 Southern Methodist University

Data Leakage In Isolated Virtualized Enterprise Computing Systems, Zechariah D.J. Wolf

Computer Science and Engineering Theses and Dissertations

Virtualization and cloud computing have become critical parts of modern enterprise computing infrastructure. One of the benefits of using cloud infrastructure over in-house computing infrastructure is the offloading of security responsibilities. By hosting one’s services on the cloud, the responsibility for the security of the infrastructure is transferred to a trusted third party. As such, security of customer data in cloud environments is of critical importance. Side channels and covert channels have proven to be dangerous avenues for the leakage of sensitive information from computing systems. In this work, we propose and perform two experiments to investigate side and covert …


A Targeted Study On The Match Between Cybersecurity Higher Education Offerings And Workforce Needs, Diane Murphy, Nektaria Tryfona, Andrew M. Marshall 2023 Marymount University

A Targeted Study On The Match Between Cybersecurity Higher Education Offerings And Workforce Needs, Diane Murphy, Nektaria Tryfona, Andrew M. Marshall

Virginia Journal of Science

The Cybersecurity Workforce Gap is a call to action on a two-fold problem: the worldwide shortage of qualified cybersecurity workers and the need to develop a growing highly-knowledgeable, agile, well-trained cybersecurity workforce. This paper presents a methodological approach to achieve this goal in the Northern Virginia area. The area is characterized by an abundance of cyber-related industries, government agencies, and large businesses with high demand of skilled cybersecurity workers; at the same time, academic institutions offer cutting edge education and training access to highly capable students. Central to this methodology is the collaboration between local academia and industry and it …


An Analysis Of Successful Sqlia For Future Evolutionary Prediction, Andrew Pechin 2023 Liberty University

An Analysis Of Successful Sqlia For Future Evolutionary Prediction, Andrew Pechin

Senior Honors Theses

Web applications are a fundamental component of the internet, many interact with backend databases. Securing web applications and their databases from hackers should be a top priority for cybersecurity researchers. Structured Query Language (SQL) injection attacks (SQLIA) constitute a significant threat to web applications. They can hijack the backend databases to steal personally identifiable information (PII), initiate scams, or launch more sophisticated cyberattacks. SQLIA has evolved since its conception in the early 2000s and will continue to do so in the coming years. This paper analyzes past literature and successful SQLIA from specific time periods to identify themes and methods …


Digital Commons powered by bepress