An Evaluation Of Data Erasing Tools,
2020
University of Suffolk
An Evaluation Of Data Erasing Tools, Andrew Jones, Isaac Afrifa
Journal of Digital Forensics, Security and Law
The permanent removal of data from media is a major area of concern mainly because of the misconception that once a file is deleted or storage media is formatted, it cannot be recovered. There has been the development of both commercial and freeware data erasing tools, which all claim complete file or disk erasure. This report analyzes the efficiency of a number of these tools in performing erasures on an electromechanical drive. It focuses on a selection of popular and modern erasing tools; taking into consideration their usability, claimed erasing standards and whether they perform complete data erasure with the …
Cybersecurity, Privacy, And Artificial Intelligence: An Examination Of Legal Issues Surrounding The European Union General Data Protection Regulation And Autonomous Network Defense,
2020
University of Minnesota Law School
Cybersecurity, Privacy, And Artificial Intelligence: An Examination Of Legal Issues Surrounding The European Union General Data Protection Regulation And Autonomous Network Defense, Brandon W. Jackson
Minnesota Journal of Law, Science & Technology
No abstract provided.
Disruptive Bussiness Model For Higher Education,
2020
United Arab Emirates University
Disruptive Bussiness Model For Higher Education, Aya Rizik Abushawish
Theses
A business model is a plan for the successful operation of a business, identifying the source of revenue, the intended customers, value proposition, key resources, activities, and financing. It describes how organizations create, deliver and capture value. The recent developments in information and communications technology (ICT) disrupted most business models in different industries. The higher education industry is no exception, where it witnessed enormous integration of information and communications technologies. E-learning in higher education has made a tremendous shift in students’ life and raised the expectations of higher education service quality. The main objective of this thesis to develop a …
Towards Security And Privacy In Networked Medical Devices And Electronic Healthcare Systems,
2020
California Polytechnic State University, San Luis Obispo
Towards Security And Privacy In Networked Medical Devices And Electronic Healthcare Systems, Isabel Jellen
Master's Theses
E-health is a growing eld which utilizes wireless sensor networks to enable access to effective and efficient healthcare services and provide patient monitoring to enable early detection and treatment of health conditions. Due to the proliferation of e-health systems, security and privacy have become critical issues in preventing data falsification, unauthorized access to the system, or eavesdropping on sensitive health data. Furthermore, due to the intrinsic limitations of many wireless medical devices, including low power and limited computational resources, security and device performance can be difficult to balance. Therefore, many current networked medical devices operate without basic security services such …
From Degree To Chief Information Security Officer (Ciso): A Framework For Consideration,
2020
Embry-Riddle Aeronautical University
From Degree To Chief Information Security Officer (Ciso): A Framework For Consideration, Wendi M. Kappers, Martha Nanette Harrell,
Publications
Educational entities are establishing program degree content designed to ensure cybersecurity and information security assurance skills are adequate and efficient for preparing students to be successful in this very important field. Many Master’s level programs include courses that address these skills in an attempt to provide a well-rounded program of study. However, undergraduates who are in the practitioner’s world have other alternatives to gain these skills. These individuals can gain various certifications, such as the Certified Information Systems Security Professional (CISSP) or the Certified Information Security Manager (CISM). Due to a perceived gap between academics and field knowledge, it appears …
Understanding Android Voip Security: A System-Level Vulnerability Assessment,
2020
OPPO ZIWU Cyber Security Lab
Understanding Android Voip Security: A System-Level Vulnerability Assessment, En He, Daoyuan Wu, Robert H. Deng
Research Collection School Of Computing and Information Systems
VoIP is a class of new technologies that deliver voice calls over the packet-switched networks, which surpasses the legacy circuit-switched telecom telephony. Android provides the native support of VoIP, including the recent VoLTE and VoWiFi standards. While prior works have analyzed the weaknesses of VoIP network infrastructure and the privacy concerns of third-party VoIP apps, no efforts were attempted to investigate the (in)security of Android’s VoIP integration at the system level. In this paper, we first demystify Android VoIP’s protocol stack and all its four attack surfaces. We then propose a novel vulnerability assessment approach that assembles on-device Intent/API fuzzing, …
Secure Server-Aided Data Sharing Clique With Attestation,
2020
Guilin University of Electronic Technology
Secure Server-Aided Data Sharing Clique With Attestation, Yujue Wang, Hwee Hwa Pang, Robert H. Deng, Yong Ding, Qianhong Wu, Bo Qin, Kefeng Fan
Research Collection School Of Computing and Information Systems
In this paper, we consider the security issues in data sharing cliques via remote server. We present a public key re-encryption scheme with delegated equality test on ciphertexts (PRE-DET). The scheme allows users to share outsourced data on the server without performing decryption-then-encryption procedures, allows new users to dynamically join the clique, allows clique users to attest the message underlying a ciphertext, and enables the server to partition outsourced user data without any further help of users after being delegated. We introduce the PRE-DET framework, propose a concrete construction and formally prove its security against five types of adversaries regarding …
An Extended Framework Of Privacy-Preserving Computation With Flexible Access Control,
2020
Singapore Management University
An Extended Framework Of Privacy-Preserving Computation With Flexible Access Control, Wenxiu Ding, Rui Hu, Zheng Yan, Xinren Qian, Robert H. Deng, Laurence T. Yang, Mianxiong Dong
Research Collection School Of Computing and Information Systems
Cloud computing offers various services based on outsourced data by utilizing its huge volume of resources and great computation capability. However, it also makes users lose full control over their data. To avoid the leakage of user data privacy, encrypted data are preferred to be uploaded and stored in the cloud, which unfortunately complicates data analysis and access control. In particular, few existing works consider the fine-grained access control over the computational results from ciphertexts. Though our previous work proposed a framework to support several basic computations (such as addition, multiplication and comparison) with flexible access control, privacy-preserving division calculations …
A New Framework For Privacy-Preserving Biometric-Based Remote User Authentication,
2020
Singapore Management University
A New Framework For Privacy-Preserving Biometric-Based Remote User Authentication, Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li, Pengfei Wu, Anyi Liu
Research Collection School Of Computing and Information Systems
In this paper, we introduce the first general framework for strong privacy-preserving biometric-based remote user authentication based on oblivious RAM (ORAM) protocol and computational fuzzy extractors. We define formal security models for the general framework, and we prove that it can achieve user authenticity and strong privacy. In particular, the general framework ensures that: (1) a strong privacy and a log-linear time-complexity are achieved by using a new tree-based ORAM protocol; (2) a constant bandwidth cost is achieved by exploiting computational fuzzy extractors in the challenge-response phase of remote user authentications.
Editing-Enabled Signatures: A New Tool For Editing Authenticated Data,
2020
Singapore Management University
Editing-Enabled Signatures: A New Tool For Editing Authenticated Data, Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng
Research Collection School Of Computing and Information Systems
Data authentication primarily serves as a tool to achieve data integrity and source authentication. However, traditional data authentication does not fit well where an intermediate entity (editor) is required to modify the authenticated data provided by the source/data owner before sending the data to other recipients. To ask the data owner for authenticating each modified data can lead to higher communication overhead. In this article, we introduce the notion of editing-enabled signatures where the data owner can choose any set of modification operations applicable on the data and still can restrict any possibly untrusted editor to authenticate the data modified …
Provably Robust Decisions Based On Potentially Malicious Sources Of Information,
2020
University of Nottingham
Provably Robust Decisions Based On Potentially Malicious Sources Of Information, Tim Muller, Dongxia Wang, Jun Sun
Research Collection School Of Computing and Information Systems
Sometimes a security-critical decision must be made using information provided by peers. Think of routing messages, user reports, sensor data, navigational information, blockchain updates. Attackers manifest as peers that strategically report fake information. Trust models use the provided information, and attempt to suggest the correct decision. A model that appears accurate by empirical evaluation of attacks may still be susceptible to manipulation. For a security-critical decision, it is important to take the entire attack space into account. Therefore, we define the property of robustness: the probability of deciding correctly, regardless of what information attackers provide. We introduce the notion of …
Talk Like Somebody Is Watching: Understanding And Supporting Novice Live Streamers,
2020
University of Calgary
Talk Like Somebody Is Watching: Understanding And Supporting Novice Live Streamers, Terrance Mok, Colin Matthew Au Yueng, Anthony Tang, Lora Oehlberg
Research Collection School Of Computing and Information Systems
We built a chatbot system–Audience Bot–that simulates an audience for novice live streamers to engage with while streaming. New live streamers on platforms like Twitch are expected to perform and talk to themselves, even while no one is watching. We ran an observational lab study on how Audience Bot assists novice live streamers as they acclimate to multitasking–simultaneously playing a video game while performing for a (simulated) audience.
Malware Classification Based On Hidden Markov Model And Word2vec Features,
2020
San Jose State University
Malware Classification Based On Hidden Markov Model And Word2vec Features, Aparna Sunil Kale
Master's Projects
Malware classification is an important and challenging problem in information security. Modern malware classification techniques rely on machine learning models that can be trained on a wide variety of features, including opcode sequences, API calls, and byte ��-grams, among many others. In this research, we implement hybrid machine learning techniques, where we train hidden Markov models (HMM) and compute Word2Vec encodings based on opcode sequences. The resulting trained HMMs and Word2Vec embedding vectors are then used as features for classification algorithms. Specifically, we consider support vector machine (SVM), ��-nearest neighbor
(��-NN), random forest (RF), and deep neural network (DNN) classifiers. …
Detection And Analysis Of Malware Evolution,
2020
San Jose State University
Detection And Analysis Of Malware Evolution, Sunhera Barunkumar Paul
Master's Projects
Malware is a malicious software that causes disruption, allows access to unapproved resources, or performs other unauthorized activity. Developing effective malware detection techniques is a critical aspect of information security. One difficulty that arises is that malware often evolves over time, due to changing goals of malware developers, or to counter advances in detection. This evolution can occur through various modifications in malware code. To maintain effective malware detection, it is necessary to detect and analyze malware evolution so that appropriate countermeasures can be taken. We perform a variety of experiments to detect points in time where a malware family …
Word Embedding Techniques For Malware Classification,
2020
San Jose State University
Word Embedding Techniques For Malware Classification, Aniket Chandak
Master's Projects
Word embeddings are often used in natural language processing as a means to quantify relationships between words. More generally, these same word embedding techniques can be used to quantify relationships between features. In this paper, we conduct a series of experiments that are designed to determine the effectiveness of word embedding in the context of malware classification. First, we conduct experiments where hidden Markov models (HMM) are directly applied to opcode sequences. These results serve to establish a baseline for comparison with our subsequent word embedding experiments. We then experiment with word embedding vectors derived from HMMs— a technique that …
Sentiment Analysis For Troll Activity Detection On Sina Weibo,
2020
San Jose State University
Sentiment Analysis For Troll Activity Detection On Sina Weibo, Zidong Jiang
Master's Projects
The impact of social media on the modern world is difficult to overstate. Virtually all companies and public figures have social media accounts on popular platforms such as Twitter and Facebook. In China, the micro-blogging service provider Sina Weibo is the most popular such service. To overcome negative publicity, Weibo trolls the so called Water Army can be hired to post deceptive comments.
In recent years, troll detection and sentiment analysis have been studied, but we are not aware of any research that considers troll detection based on sentiment analysis. In this research, we focus on troll detection via sentiment …
Real-Time Ad Click Fraud Detection,
2020
San Jose State University
Real-Time Ad Click Fraud Detection, Apoorva Srivastava
Master's Projects
With the increase in Internet usage, it is now considered a very important platform for advertising and marketing. Digital marketing has become very important to the economy: some of the major Internet services available publicly to users are free, thanks to digital advertising. It has also allowed the publisher ecosystem to flourish, ensuring significant monetary incentives for creating quality public content, helping to usher in the information age. Digital advertising, however, comes with its own set of challenges. One of the biggest challenges is ad fraud. There is a proliferation of malicious parties and software seeking to undermine the ecosystem …
Network Traffic Based Botnet Detection Using Machine Learning,
2020
San Jose State University
Network Traffic Based Botnet Detection Using Machine Learning, Anand Ravindra Vishwakarma
Master's Projects
The field of information and computer security is rapidly developing in today’s world as the number of security risks is continuously being explored every day. The moment a new software or a product is launched in the market, a new exploit or vulnerability is exposed and exploited by the attackers or malicious users for different motives. Many attacks are distributed in nature and carried out by botnets that cause widespread disruption of network activity by carrying out DDoS (Distributed Denial of Service) attacks, email spamming, click fraud, information and identity theft, virtual deceit and distributed resource usage for cryptocurrency mining. …
Implementing Tontinecoin,
2020
San Jose State University
Implementing Tontinecoin, Prashant Pardeshi
Master's Projects
One of the alternatives to proof-of-work (PoW) consensus protocols is proof-of- stake (PoS) protocols, which address its energy and cost related issues. But they suffer from the nothing-at-stake problem; validators (PoS miners) are bound to lose nothing if they support multiple blockchain forks. Tendermint, a PoS protocol, handles this problem by forcing validators to bond their stake and then seizing a cheater’s stake when caught signing multiple competing blocks. The seized stake is then evenly distributed amongst the rest of validators. However, as the number of validators increases, the benefit in finding a cheater compared to the cost of monitoring …
Side-Channel Power Resistance For Encryption Algorithms Using Implementation Diversity,
2020
University of New Mexico
Side-Channel Power Resistance For Encryption Algorithms Using Implementation Diversity, Ivan M. Bow
Electrical and Computer Engineering ETDs
This thesis paper investigates countermeasures to hardware side-channel attacks and proposes a new solution to this ever growing threat against data integrity and security. The side-channel attack methods, differential power analysis and correlation power analysis, are both very powerful techniques and are used to gain access to secrets inside of a field programmable gate array that are otherwise inaccessible, in particular the cryptographic key for the Advanced Encryption Standard algorithm. To counter these attacks, we propose a method of changing the internal hardware configuration of the field programmable gate array using dynamic partial reconfiguration. Using this method, we change the …
