Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 81 of 201.

Exploring The Learning Efficacy Of Digital Forensics Concepts And Bagging & Tagging Of Digital Devices In Immersive Virtual Reality, Courtney Hassenfeldt, Jillian Jacques, Ibrahim Baggili 2020 University of New Haven

Exploring The Learning Efficacy Of Digital Forensics Concepts And Bagging & Tagging Of Digital Devices In Immersive Virtual Reality, Courtney Hassenfeldt, Jillian Jacques, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

This work presents the first account of evaluating learning inside a VR experience created to teach Digital Forensics (DF) concepts, and a hands-on laboratory exercise in Bagging & Tagging a crime scene with digital devices. First, we designed and developed an immersive VR experience which included a lecture and a lab. Next, we tested it with (n = 57) participants in a controlled experiment where they were randomly assigned to a VR group or a physical group. Both groups were subjected to the same lecture and lab, but one was in VR and the other was in the real world. …


Implement Multi-Factor Authentication On All Federal Systems Now, Megan Walsh 2020 Purdue University

Implement Multi-Factor Authentication On All Federal Systems Now, Megan Walsh

Student Papers in Public Policy

The White House Office of Management and Budget recorded 31,107 information security incidents in fiscal year 2018. The most common attacks to gain access to a user’s login credentials were e-mail/phishing, web-based attack, and brute force entering of username/password combinations. Given this high number of incidents, strong reliance on computers for everyday business, and common attacks that target passwords, information security should be a priority for information technology administrators working in federal agencies.


Toward A Sustainable Cybersecurity Ecosystem, Shahrin Sadik, Mohiuddin Ahmed, Leslie F. Sikos, A.K.M. Najmul Islam 2020 Edith Cowan University

Toward A Sustainable Cybersecurity Ecosystem, Shahrin Sadik, Mohiuddin Ahmed, Leslie F. Sikos, A.K.M. Najmul Islam

Research outputs 2014 to 2021

© 2020 by the authors. Licensee MDPI, Basel, Switzerland. Cybersecurity issues constitute a key concern of today’s technology-based economies. Cybersecurity has become a core need for providing a sustainable and safe society to online users in cyberspace. Considering the rapid increase of technological implementations, it has turned into a global necessity in the attempt to adapt security countermeasures, whether direct or indirect, and prevent systems from cyberthreats. Identifying, characterizing, and classifying such threats and their sources is required for a sustainable cyber-ecosystem. This paper focuses on the cybersecurity of smart grids and the emerging trends such as using blockchain in …


An Enhancement Of Age And Gender Classification Accuracy With Hybrid Handcrafted And Deep Features Using Hierarchical Extreme Learning Machine, Mohammad Javidan Darugar 2020 Universiti Malaya

An Enhancement Of Age And Gender Classification Accuracy With Hybrid Handcrafted And Deep Features Using Hierarchical Extreme Learning Machine, Mohammad Javidan Darugar

Student Works (2020-2029)

Age and gender classification are some of the essential algorithms that have many use cases in our everyday life. For example, in robotics, field robots can interact with a human base on their gender in data analysis, to have statistics about age and gender of audiences in social events, YouTube video analysis, and many other applications. In this research, we have addressed limitations in deep neural networks, which by overcoming this limitation, we can gain better accuracy and performance. Our study has several other possible applications which are not limited only to age and gender classification. This dissertation is about …


Efficient Fine-Grained Data Sharing Mechanism For Electronic Medical Record Systems With Mobile Devices, Hui MA, Rui ZHANG, Guomin YANG, Zishuai ZONG, Kai HE, Yuting XIAO 2020 Singapore Management University

Efficient Fine-Grained Data Sharing Mechanism For Electronic Medical Record Systems With Mobile Devices, Hui Ma, Rui Zhang, Guomin Yang, Zishuai Zong, Kai He, Yuting Xiao

Research Collection School Of Computing and Information Systems

Sharing digital medical records on public cloud storage via mobile devices facilitates patients (doctors) to get (offer) medical treatment of high quality and efficiency. However, challenges such as data privacy protection, flexible data sharing, efficient authority delegation, computation efficiency optimization, are remaining toward achieving practical fine-grained access control in the Electronic Medical Record (EMR) system. In this work, we propose an innovative access control model and a fine-grained data sharing mechanism for EMR, which simultaneously achieves the above-mentioned features and is suitable for resource-constrained mobile devices. In the model, complex computation is outsourced to public cloud servers, leaving almost no …


Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. CHIK 2020 Singapore Management University

Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik

Research Collection Yong Pung How School Of Law

This chapter discusses the hearing of essential and urgent court matters in the Singapore courts during the COVID-19 pandemic. On 27 march 2020, the Singapore judiciary notified courst users that remote hearings were to be implemented for certain types of hearings by means of video and telephone conferencing facilities. Court users were also provided with indicative lists of matters which might be considered essential and urgent.


Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. CHIK 2020 Singapore Management University

Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik

Research Collection Yong Pung How School Of Law

This chapter discusses the hearing of essential and urgent court matters in the Singapore courts during the COVID-19 pandemic. On 27 march 2020, the Singapore judiciary notified courst users that remote hearings were to be implemented for certain types of hearings by means of video and telephone conferencing facilities. Court users were also provided with indicative lists of matters which might be considered essential and urgent.


Pine: Enabling Privacy-Preserving Deep Packet Inspection On Tls With Rule-Hiding And Fast Connection Establishment, Jianting NING, Xinyi HUANG, Geong Sen POH, Shengmin XU, Jia-Chng LOH, Jain WENG, Robert H. DENG 2020 Fujian Normal University

Pine: Enabling Privacy-Preserving Deep Packet Inspection On Tls With Rule-Hiding And Fast Connection Establishment, Jianting Ning, Xinyi Huang, Geong Sen Poh, Shengmin Xu, Jia-Chng Loh, Jain Weng, Robert H. Deng

Research Collection School Of Computing and Information Systems

Transport Layer Security Inspection (TLSI) enables enterprises to decrypt, inspect and then re-encrypt users’ traffic before it is routed to the destination. This breaks the end-to-end security guarantee of the TLS specification and implementation. It also raises privacy concerns since users’ traffic is now known by the enterprises, and third-party middlebox providers providing the inspection services may additionally learn the inspection or attack rules, policies of the enterprises. Two recent works, BlindBox (SIGCOMM 2015) and PrivDPI (CCS 2019) propose privacy-preserving approaches that inspect encrypted traffic directly to address the privacy concern of users’ traffic. However, BlindBox incurs high preprocessing overhead …


Is The Transit Industry Prepared For The Cyber Revolution? Policy Recommendations To Enhance Surface Transit Cyber Preparedness, Scott Belcher, Terri Belcher, Eric Greenwald, Brandon Thomas 2020 Mineta Transportation Institute

Is The Transit Industry Prepared For The Cyber Revolution? Policy Recommendations To Enhance Surface Transit Cyber Preparedness, Scott Belcher, Terri Belcher, Eric Greenwald, Brandon Thomas

Mineta Transportation Institute

The intent of this study is to assess the readiness, resourcing, and structure of public transit agencies to identify, protect from, detect, respond to, and recover from cybersecurity vulnerabilities and threats. Given the multitude of connected devices already in use by the transit industry and the vast amount of data generated (with more coming online soon), the transit industry is vulnerable to malicious cyber-attack and other cybersecurity-related threats. This study reviews the state of best cybersecurity practices in public surface transit; outlines U.S. public surface transit operators’ cybersecurity operations; assesses U.S. policy on cybersecurity in public surface transportation; and provides …


Privacy-Preserving Outsourced Calculation Toolkit In The Cloud, Ximeng LIU, Robert H. DENG, Kim-Kwang Raymond CHOO, Yang YANG, Hwee Hwa PANG 2020 Singapore Management University

Privacy-Preserving Outsourced Calculation Toolkit In The Cloud, Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang, Hwee Hwa Pang

Research Collection School Of Computing and Information Systems

In this paper, we propose a privacy-preserving outsourced calculation toolkit, Pockit, designed to allow data owners to securely outsource their data to the cloud for storage. The outsourced encrypted data can be processed by the cloud server to achieve commonly-used plaintext arithmetic operations without involving additional servers. Specifically, we design both signed and unsigned integer circuits using a fully homomorphic encryption (FHE) scheme, construct a new packing technique (hereafter referred to as integer packing), and extend the secure circuits to its packed version. This achieves significant improvements in performance compared with the original secure signed/unsigned integer circuit. The secure integer …


A Lattice-Based Key-Insulated And Privacy-Preserving Signature Scheme With Publicly Derived Public Key, Wenling LIU, Zhen LIU, Khoa NGUYEN, Guomin YANG, Yu YU 2020 Shanghai Jiaotong University

A Lattice-Based Key-Insulated And Privacy-Preserving Signature Scheme With Publicly Derived Public Key, Wenling Liu, Zhen Liu, Khoa Nguyen, Guomin Yang, Yu Yu

Research Collection School Of Computing and Information Systems

As a widely used privacy-preserving technique for cryptocurrencies, Stealth Address constitutes a key component of Ring Confidential Transaction (RingCT) protocol and it was adopted by Monero, one of the most popular privacy-centric cryptocurrencies. Recently, Liu et al. [EuroS&P 2019] pointed out a flaw in the current widely used stealth address algorithm that once a derived secret key is compromised, the damage will spread to the corresponding master secret key, and all the derived secret keys thereof. To address this issue, Liu et al. introduced Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key (PDPKS scheme), which captures the functionality, …


Attribute-Based Encryption For Cloud Computing Access Control: A Survey, Yinghui ZHANG, Robert H. DENG, Shengmin XU, Jianfei SUN, Qi LI, Dong ZHENG 2020 Singapore Management University

Attribute-Based Encryption For Cloud Computing Access Control: A Survey, Yinghui Zhang, Robert H. Deng, Shengmin Xu, Jianfei Sun, Qi Li, Dong Zheng

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) for cloud computing access control is reviewed in this article. A taxonomy and comprehensive assessment criteria of ABE are first proposed. In the taxonomy, ABE schemes are assorted into key-policy ABE (KP-ABE) schemes, ciphertext-policy ABE (CP-ABE) schemes, anti-quantum ABE schemes, and generic constructions. In accordance with cryptographically functional features, CP-ABE is further divided into nine subcategories with regard to basic functionality, revocation, accountability, policy hiding, policy updating, multi-authority, hierarchy, offline computation, and outsourced computation. In addition, a systematical methodology for discussing and comparing existing ABE schemes is proposed. For KP-ABE and each type of CP-ABE, the corresponding …


Cryptography, Passwords, Privacy, And The Fifth Amendment, Gary C. Kessler, Ann M. Phillips 2020 Gary Kessler Associates / Embry-Riddle Aeronautical University - Daytona Beach

Cryptography, Passwords, Privacy, And The Fifth Amendment, Gary C. Kessler, Ann M. Phillips

Journal of Digital Forensics, Security and Law

Military-grade cryptography has been widely available at no cost for personal and commercial use since the early 1990s. Since the introduction of Pretty Good Privacy (PGP), more and more people encrypt files and devices, and we are now at the point where our smartphones are encrypted by default. While this ostensibly provides users with a high degree of privacy, compelling a user to provide a password has been interpreted by some courts as a violation of our Fifth Amendment protections, becoming an often insurmountable hurdle to law enforcement lawfully executing a search warrant. This paper will explore some of the …


A Two-Stage Model For Social Network Investigations In Digital Forensics, Anne David, Sarah Morris, Gareth Appleby-Thomas 2020 Cranfield University

A Two-Stage Model For Social Network Investigations In Digital Forensics, Anne David, Sarah Morris, Gareth Appleby-Thomas

Journal of Digital Forensics, Security and Law

This paper proposes a two-stage model for identifying and contextualizing features from artefacts created as a result of social networking activity. This technique can be useful in digital investigations and is based on understanding and the deconstruction of the processes that take place prior to, during and after user activity; this includes corroborating artefacts. Digital Investigations are becoming more complex due to factors such as, the volume of data to be examined; different data formats; a wide range of sources for digital evidence; the volatility of data and the limitations of some of the standard digital forensic tools. This paper …


Snitch Application: Addressing Cyber Trust In Future Living Spaces, Russell Moore 2020 Christopher Newport University

Snitch Application: Addressing Cyber Trust In Future Living Spaces, Russell Moore

Cybersecurity Undergraduate Research Showcase

The future of smart homes is filled with excitement and ample opportunity to live in an environment that features extraordinary convenience and energy efficiency. Devices such as Amazon Alexa and Roku Smart TV’s feature voice interaction options that provide the user with enhanced functionality. While voice-activated devices are accommodating, it is imperative to acknowledge how they work on the backend. The problem is that these devices collect and share a large amount of data from users who are oftentimes unaware that it’s even happening. The Snitch App is being developed in order to inform the user of what exactly is …


Cyber-Assets At Risk (Car): Monetary Impact Of Personally Identifiable Information Data Breaches On Companies, Omer Ilker Poyraz 2020 Old Dominion University

Cyber-Assets At Risk (Car): Monetary Impact Of Personally Identifiable Information Data Breaches On Companies, Omer Ilker Poyraz

Engineering Management & Systems Engineering Theses & Dissertations

Cyber-systems provide convenience, ubiquity, economic advantage, and higher efficiency to both individuals and organizations. However, vulnerabilities of the cyber domain also offer malicious actors with the opportunities to compromise the most sensitive information. Recent cybersecurity incidents show that a group of hackers can cause a massive data breach, resulting in companies losing competitive advantage, reputation, and money. Governments have since taken some actions in protecting individuals and companies from such crime by authorizing federal agencies and developing regulations. To protect the public from losing their most sensitive records, governments have also been compelling companies to follow cybersecurity regulations. If companies …


Privacy Preserving Search Services Against Online Attack, Yi ZHAO, Jianting NIAN, Kaitai LIANG, Yanqi ZHAO, Liqun CHEN, Bo YANG 2020 Chang'an University

Privacy Preserving Search Services Against Online Attack, Yi Zhao, Jianting Nian, Kaitai Liang, Yanqi Zhao, Liqun Chen, Bo Yang

Research Collection School Of Computing and Information Systems

Searchable functionality is provided in many online services such as mail services or outsourced data storage. To protect users privacy, data in these services is usually stored after being encrypted using searchable encryption. This enables the data user to securely search encrypted data from a remote server without leaking data and query information. Public key encryption with keyword search is one of the research branches of searchable encryption; this provides privacy-preserving searchable functionality for applications such as encrypted email systems. However, it has an inherent vulnerability in that the information of a query may be leaked using a keyword guessing …


A Generalised Bound For The Wiener Attack On Rsa, Willy SUSILO, Joseph TONIEN, Guomin YANG 2020 Singapore Management University

A Generalised Bound For The Wiener Attack On Rsa, Willy Susilo, Joseph Tonien, Guomin Yang

Research Collection School Of Computing and Information Systems

Since Wiener pointed out that the RSA can be broken if the private exponent d is relatively small compared to the modulus N, it has been a general belief that the Wiener attack works for d


Measuring Privacy Concerns With Government Surveillance And Right-To-Be-Forgotten In Nomological Net Of Trust And Willingness-To-Share, Gaurav BANSAL, Fiona Fui-hoon NAH 2020 Singapore Management University

Measuring Privacy Concerns With Government Surveillance And Right-To-Be-Forgotten In Nomological Net Of Trust And Willingness-To-Share, Gaurav Bansal, Fiona Fui-Hoon Nah

Research Collection School Of Computing and Information Systems

In the post Snowden revelations era, concerns related to government surveillance and oversight have come to the forefront. The ability of the Internet to remember “everything” (or forget anything) also raises a privacy concern associated with the “right to be forgotten”. Hence, in this paper, we propose and examine privacy concerns by extending the Hong and Thong’s (2013) model with the addition of two dimensions: right to be forgotten as well as government surveillance and oversight. We tested two different measurement models using privacy concerns as a second-order and a third-order construct within a nomological net that includes trusting beliefs …


Resource Optimization In Support Of Iot Applications, Ihab Ahmed Mohammed 2020 Western Michigan University

Resource Optimization In Support Of Iot Applications, Ihab Ahmed Mohammed

Dissertations

With the rise of the Internet of Things (IoT) and smart communities, managing computation and communication resources required by billions of smart devices becomes a concern. To tackle this problem, we develop algorithms for resource management to ensure better Quality of Service (QoS), safety, and performance. We focus our efforts on three problems.

In the first problem, we studied the strict QoS requirements of applications and differentiated service requirements in different situations of vehicular networks. We propose a generic prioritization and resource management algorithm that can be used to prioritize the processing of received packets in vehicular networks. We formulate …


Digital Commons powered by bepress