Understanding Ransomware Trajectory To Create An Informed Prediction,
2021
Portland State University
Understanding Ransomware Trajectory To Create An Informed Prediction, J. D. Klusnick
University Honors Theses
Ransomware is a form of extortion in which digital files are rendered inaccessible until a ransom payment is made. Modern ransomware emerged in 2006 and its destructive influence has been expanding ever since. In recent years cybercriminals have evolved who they target, what computer systems they target, and how they infect those systems. Meanwhile, cybersecurity experts have modelled ransomware methods allowing them to innovate their defense techniques across three paradigms: recovery, detection, and prevention. Ultimately either ransomware attackers or ransomware defenders will dominate this ongoing conflict. A review of the literature indicates that the ransomware crime wave will likely be …
Windows Kernel Hijacking Is Not An Option: Memoryranger Comes To The Rescue Again,
2021
Independent Researcher
Windows Kernel Hijacking Is Not An Option: Memoryranger Comes To The Rescue Again, Igor Korkin
Journal of Digital Forensics, Security and Law
The security of a computer system depends on OS kernel protection. It is crucial to reveal and inspect new attacks on kernel data, as these are used by hackers. The purpose of this paper is to continue research into attacks on dynamically allocated data in the Windows OS kernel and demonstrate the capacity of MemoryRanger to prevent these attacks. This paper discusses three new hijacking attacks on kernel data, which are based on bypassing OS security mechanisms. The first two hijacking attacks result in illegal access to files open in exclusive access. The third attack escalates process privileges, without applying …
A Method For Comparative Analysis Of Trusted Execution Environments,
2021
Portland State University
A Method For Comparative Analysis Of Trusted Execution Environments, Stephano Cetola
Dissertations and Theses
The problem of secure remote computation has become a serious concern of hardware manufacturers and software developers alike. Trusted Execution Environments (TEEs) are a solution to the problem of secure remote computation in applications ranging from "chip and pin" financial transactions to intellectual property protection in modern gaming systems. While extensive literature has been published about many of these technologies, there exists no current model for comparing TEEs. This thesis provides hardware architects and designers with a set of tools for comparing TEEs. I do so by examining several properties of a TEE and comparing their implementations in several technologies. …
Deterring Intellectual Property Thieves: Algorithmic Generation Of Adversary-Aware Fake Knowledge Graphs,
2021
Dartmouth College
Deterring Intellectual Property Thieves: Algorithmic Generation Of Adversary-Aware Fake Knowledge Graphs, Snow Kang
Dartmouth College Undergraduate Theses
Publicly available estimates suggest that in the U.S. alone, IP theft costs our economy between $225 billion and $600 billion each year. In our paper, we propose combating IP theft by generating fake versions of technical documents. If an enterprise system has n fake documents for each real document, any IP thief must sift through an array of documents in an attempt to separate the original from a sea of fakes. This costs the attacker time and money - and inflicts pain and frustration on the part of its technical staff.
Leveraging a graph-theoretic approach, we created the Clique-FakeKG algorithm …
Capstone Case Study Guide Mapfre,
2021
Clark University
Capstone Case Study Guide Mapfre, Apoorva Arbooj, Ahamad Waqas, K C Prabhat, Manju Jayam, Rashmi Sakleshpur Rajashekar
School of Professional Studies
Mapfre is a Top-Notch insurer and a competitive and fast-evolving insurance company. Clark team will help Mapfre to organize to secure systems availability and resilience to support the business process. Assist and recommend the IT team for further analysis and identify data, trends, and patterns and come up with to improve the services
How Social Media And Embedded Recommender Algorithm Fostered Political Issues,
2021
Clark University
How Social Media And Embedded Recommender Algorithm Fostered Political Issues, Yan Shi
School of Professional Studies
Social media plays a significant role in social communication and interaction, connecting people from different continents and facilitating information flaws worldwide. Meanwhile, along with the evolution of embedded recommender algorithms that clustering people with similar demographic features, social media has become the most important means of communication for modern society. However, the prosper of interconnecting platforms also have potential flows alongside. One of the major issues is the unexpected political consequence. This paper delivers the first comprehensive analysis of the political impacts posed by social media and embedded recommending algorithms. The article identifies three major political concerns through literature review, …
Ultrapin: Inferring Pin Entries Via Ultrasound,
2021
Singapore Management University
Ultrapin: Inferring Pin Entries Via Ultrasound, Liu, Ximing, Robert H. Deng, Robert H. Deng
Research Collection School Of Computing and Information Systems
While PIN-based user authentication systems such as ATM have long been considered to be secure enough, they are facing new attacks, named UltraPIN, which can be launched from commodity smartphones. As a target user enters a PIN on a PIN-based user authentication system, an attacker may use UltraPIN to infer the PIN from a short distance (50 cm to 100 cm). In this process, UltraPIN leverages smartphone speakers to issue human-inaudible ultrasound signals and uses smartphone microphones to keep recording acoustic signals. It applies a series of signal processing techniques to extract high-quality feature vectors from low-energy and high-noise signals …
Lattice-Based Remote User Authentication From Reusable Fuzzy Signature,
2021
Singapore Management University
Lattice-Based Remote User Authentication From Reusable Fuzzy Signature, Yangguang Tian, Yingjiu Li, Robert H. Deng, Binanda Sengupta, Guomin Yang
Research Collection School Of Computing and Information Systems
In this paper, we introduce a new construction of reusable fuzzy signature based remote user authentication that is secure against quantum computers. We investigate the reusability of fuzzy signature, and we prove that the fuzzy signature schemes provide biometrics reusability (aka. reusable fuzzy signature). We define formal security models for the proposed construction, and we prove that it achieves user authenticity and user privacy. The proposed construction ensures: 1) a user’s biometrics can be securely reused in remote user authentication; 2) a third party having access to the communication channel between a user and the authentication server cannot identify the …
Catch You With Cache: Out-Of-Vm Introspection To Trace Malicious Executions,
2021
Singapore Management University
Catch You With Cache: Out-Of-Vm Introspection To Trace Malicious Executions, Chao Su, Xuhua Ding, Qinghai Zeng
Research Collection School Of Computing and Information Systems
Out-of-VM introspection is an imperative part of security analysis. The legacy methods either modify the system, introducing enormous overhead, or rely heavily on hardware features, which are neither available nor practical in most cloud environments. In this paper, we propose a novel analysis method, named as Catcher, that utilizes CPU cache to perform out-of-VM introspection. Catcher does not make any modifications to the target program and its running environment, nor demands special hardware support. Implemented upon Linux KVM, it natively introspects the target's virtual memory. More importantly, it uses the cache-based side channel to infer the target control flow. To …
Efficient Attribute-Based Encryption With Repeated Attributes Optimization,
2021
Singapore Management University
Efficient Attribute-Based Encryption With Repeated Attributes Optimization, Fawad Khan, Hui Li, Yinghui Zhang, Haider Abbas, Tahreem Yaqoob
Research Collection School Of Computing and Information Systems
Internet of Things (IoT) is an integration of various technologies to provide technological enhancements. To enforce access control on low power operated battery constrained devices is a challenging issue in IoT scenarios. Attribute-based encryption (ABE) has emerged as an access control mechanism to allow users to encrypt and decrypt data based on an attributes policy. However, to accommodate the expressiveness of policy for practical application scenarios, attributes may be repeated in a policy. For certain policies, the attributes repetition cannot be avoided even after applying the boolean optimization techniques to attain an equivalent smaller length boolean formula. For such policies, …
Secure Repackage-Proofing Framework For Android Apps Using Collatz Conjecture,
2021
Singapore Management University
Secure Repackage-Proofing Framework For Android Apps Using Collatz Conjecture, Haoyu Ma, Shijia Li, Debin Gao, Chunfu Jia
Research Collection School Of Computing and Information Systems
App repackaging has been raising serious concerns about the health of the Android ecosystem, and repackage-proofing is an important mitigation against threat of such attacks. However, existing app repackage-proofing schemes were only evaluated against trivial adversaries simulated using analyzers for other purposes (e.g., disclosing privacy leakage vulnerabilities), hence were shown “effective” mainly because their key programming features were not even supported by those toolkits. Furthermore, existing works have also neglected dynamic adversaries capable of manipulating victim apps at runtime, making them vulnerable against such stronger opponents. In this paper, we propose a novel repackage-proofing framework, which deploys distributed detection and …
Non-Equivocation In Blockchain: Double-Authentication-Preventing Signatures Gone Contractual,
2021
Singapore Management University
Non-Equivocation In Blockchain: Double-Authentication-Preventing Signatures Gone Contractual, Yannan Li, Willy Susilo, Guomin Yang, Yong Yu, Tran Viet Xuan Phuong, Dongxi Liu
Research Collection School Of Computing and Information Systems
Equivocation is one of the most fundamental problems that need to be solved when designing distributed protocols. Traditional methods to defeat equivocation rely on trusted hardware or particular assumptions, which may hinder their adoption in practice. The advent of blockchain and decentralized cryptocurrencies provides an auspicious breakthrough paradigm to resolve the problem above. In this paper, we propose a blockchain-based solution to address contractual equivocation, which supports user-defined fine-grained policybased equivocation. Specifically, users will be de-incentive if the statements they made breach the predefined access rules. The core of our solution is a newly introduced primitive named Policy-Authentication-Preventing Signature (PoAPS), …
When Program Analysis Meets Bytecode Search: Targeted And Efficient Inter-Procedural Analysis Of Modern Android Apps In Backdroid,
2021
Singapore Management University
When Program Analysis Meets Bytecode Search: Targeted And Efficient Inter-Procedural Analysis Of Modern Android Apps In Backdroid, Daoyuan Wu, Debin Gao, Robert H. Deng, Rocky Chang
Research Collection School Of Computing and Information Systems
Widely-used Android static program analysis tools,e.g., Amandroid and FlowDroid, perform the whole-app interprocedural analysis that is comprehensive but fundamentallydifficult to handle modern (large) apps. The average app size hasincreased three to four times over five years. In this paper, weexplore a new paradigm of targeted inter-procedural analysis thatcan skip irrelevant code and focus only on the flows of securitysensitive sink APIs. To this end, we propose a technique calledon-the-fly bytecode search, which searches the disassembled appbytecode text just in time when a caller needs to be located. In thisway, it guides targeted (and backward) inter-procedural analysisstep by step until reaching …
Expressive Bilateral Access Control For Internet-Of-Things In Cloud-Fog Computing,
2021
Singapore Management University
Expressive Bilateral Access Control For Internet-Of-Things In Cloud-Fog Computing, Shengmin Xu, Jianting Ning, Jinhua Ma, Xinyi Huang, Hwee Hwa Pang, Robert H. Deng
Research Collection School Of Computing and Information Systems
As a versatile system architecture, cloud-fog Internet-of-Things (IoT) enables multiple resource-constrained devices to communicate and collaborate with each other. By outsourcing local data and immigrating expensive workloads to cloud service providers and fog nodes (FNs), resource-constrained devices can enjoy data services with low latency and minimal cost. To protect data security and privacy in the untrusted cloud-fog environment, many cryptographic mechanisms have been invented. Unfortunately, most of them are impractical when directly applied to cloud-fog IoT computing, mainly due to the large number of resource-constrained end-devices (EDs). In this paper, we present a secure cloud-fog IoT data sharing system with …
Convolutional Neural Networks For Deflate Data Encoding Classification Of High Entropy File Fragments,
2021
University of New Orleans, New Orleans
Convolutional Neural Networks For Deflate Data Encoding Classification Of High Entropy File Fragments, Nehal Ameen
LSU New Orleans Theses and Dissertations
Data reconstruction is significantly improved in terms of speed and accuracy by reliable data encoding fragment classification. To date, work on this problem has been successful with file structures of low entropy that contain sparse data, such as large tables or logs. Classifying compressed, encrypted, and random data that exhibit high entropy is an inherently difficult problem that requires more advanced classification approaches. We explore the ability of convolutional neural networks and word embeddings to classify deflate data encoding of high entropy file fragments after establishing ground truth using controlled datasets. Our model is designed to either successfully classify file …
Sounds Of Silence: A Study Of Stability And Diversity Of Web Audio Fingerprints,
2021
University of New Orleans, New Orleans
Sounds Of Silence: A Study Of Stability And Diversity Of Web Audio Fingerprints, Shekhar Chalise
LSU New Orleans Theses and Dissertations
Browser fingerprinting presents a grave threat to privacy as it allows user tracking even in private browsing modes. Prior measurement studies on HTML5-based fingerprinting have been limited to Canvas and WebGL but not Web Audio APIs. We aim to fill this gap by conducting the first large-scale systematic study of web audio fingerprints and studying their stability as well as diversity properties. Using MTurk and social media platforms, we collected 8 different audio fingerprints from 694 users.
Firstly, we show that the audio fingerprints are unstable unlike other fingerprinting methods with some users having as many as 20 different fingerprints. …
A Cancelable Biometric Authentication System Based On Feature-Adaptive Random Projection,
2021
Edith Cowan University
A Cancelable Biometric Authentication System Based On Feature-Adaptive Random Projection, Wencheng Yang, Song Wang, Muhammad Shahzad, Wei Zhou
Research outputs 2014 to 2021
Biometric template data protection is critical in preventing user privacy and identity from leakage. Random projection based cancelable biometrics is an efficient and effective technique to achieve biometric template protection. However, traditional random projection based cancelable template design suffers from the attack via record multiplicity (ARM), where an adversary obtains multiple transformed templates from different applications and the associated parameter keys so as to assemble them into a full-rank linear equation system, thereby retrieving the original feature vector. To address this issue, in this paper we propose a feature-adaptive random projection based method, in which the projection matrixes, the key …
Clickbait Detection In Youtube Videos,
2021
San Jose State University
Clickbait Detection In Youtube Videos, Ruchira Gothankar
Master's Projects
YouTube videos often include captivating descriptions and intriguing thumbnails designed to increase the number of views, and thereby increase the revenue for the person who posted the video. This creates an incentive for people to post clickbait videos, in which the content might deviate significantly from the title, description, or thumbnail. In effect, users are tricked into clicking on clickbait videos. In this research, we consider the challenging problem of detecting clickbait YouTube videos. We experiment with logistic regression, random forests, and multilayer perceptrons, based on a variety of textual features. We obtain a maximum accuracy in excess of 94%.
Malware Classification With Bert,
2021
San Jose State University
Malware Classification With Bert, Joel Lawrence Alvares
Master's Projects
Malware Classification is used to distinguish unique types of malware from each other.
This project aims to carry out malware classification using word embeddings which are used in Natural Language Processing (NLP) to identify and evaluate the relationship between words of a sentence. Word embeddings generated by BERT and Word2Vec for malware samples to carry out multi-class classification. BERT is a transformer based pre- trained natural language processing (NLP) model which can be used for a wide range of tasks such as question answering, paraphrase generation and next sentence prediction. However, the attention mechanism of a pre-trained BERT model can …
Fake Malware Opcodes Generation Using Hmm And Different Gan Algorithms,
2021
San Jose State University
Fake Malware Opcodes Generation Using Hmm And Different Gan Algorithms, Harshit Trehan
Master's Projects
Malware, or malicious software, is a program that is intended to harm systems. In the past decade, the number of malware attacks have grown and, more importantly, evolved. Many researchers have successfully integrated cutting edge Machine Learning techniques to combat this ever present and growing threat to cyber and information security. One big challenge faced by many researchers is the lack of enough data to train machine learning models and specifically deep neural networks properly. Generative modelling has proven to be very efficient at generating synthesized data that can match the actual data distribution.
In this project, we aim to …
