Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 92 of 201.

Founding The Domain Of Ai Forensics, Ibrahim Baggili, Vahid Behzadan 2019 University of New Haven

Founding The Domain Of Ai Forensics, Ibrahim Baggili, Vahid Behzadan

Electrical & Computer Engineering and Computer Science Faculty Publications

With the widespread integration of AI in everyday and critical technologies, it seems inevitable to witness increasing instances of failure in AI systems. In such cases, there arises a need for technical investigations that produce legally acceptable and scientifically indisputable findings and conclusions on the causes of such failures. Inspired by the domain of cyber forensics, this paper introduces the need for the establishment of AI Forensics as a new discipline under AI safety. Furthermore, we propose a taxonomy of the subfields under this discipline, and present a discussion on the foundational challenges that lay ahead of this new research …


Advanced Security Analysis For Emergent Software Platforms, Mohannad Alhanahnah 2019 University of Nebraska-Lincoln

Advanced Security Analysis For Emergent Software Platforms, Mohannad Alhanahnah

School of Computing: Dissertations, Theses, and Student Research

Emergent software ecosystems, boomed by the advent of smartphones and the Internet of Things (IoT) platforms, are perpetually sophisticated, deployed into highly dynamic environments, and facilitating interactions across heterogeneous domains. Accordingly, assessing the security thereof is a pressing need, yet requires high levels of scalability and reliability to handle the dynamism involved in such volatile ecosystems.

This dissertation seeks to enhance conventional security detection methods to cope with the emergent features of contemporary software ecosystems. In particular, it analyzes the security of Android and IoT ecosystems by developing rigorous vulnerability detection methods. A critical aspect of this work is the …


Evaluating The Resiliency Of Industrial Internet Of Things Process Control Using Protocol Agnostic Attacks, Hector L. Roldan 2019 Air Force Institute of Technology

Evaluating The Resiliency Of Industrial Internet Of Things Process Control Using Protocol Agnostic Attacks, Hector L. Roldan

Theses and Dissertations

Improving and defending our nation's critical infrastructure has been a challenge for quite some time. A malfunctioning or stoppage of any one of these systems could result in hazardous conditions on its supporting populace leading to widespread damage, injury, and even death. The protection of such systems has been mandated by the Office of the President of the United States of America in Presidential Policy Directive Order 21. Current research now focuses on securing and improving the management and efficiency of Industrial Control Systems (ICS). IIoT promises a solution in enhancement of efficiency in ICS. However, the presence of IIoT …


Countering Cybersecurity Vulnerabilities In The Power System, Fengli Zhang 2019 University of Arkansas, Fayetteville

Countering Cybersecurity Vulnerabilities In The Power System, Fengli Zhang

Graduate Theses and Dissertations

Security vulnerabilities in software pose an important threat to power grid security, which can be exploited by attackers if not properly addressed. Every month, many vulnerabilities are discovered and all the vulnerabilities must be remediated in a timely manner to reduce the chance of being exploited by attackers. In current practice, security operators have to manually analyze each vulnerability present in their assets and determine the remediation actions in a short time period, which involves a tremendous amount of human resources for electric utilities. To solve this problem, we propose a machine learning-based automation framework to automate vulnerability analysis and …


Ldakm-Eiot: Lightweight Device Authentication And Key Management Mechanism For Edge-Based Iot Deployment, Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Youngho Park 2019 Old Dominion University

Ldakm-Eiot: Lightweight Device Authentication And Key Management Mechanism For Edge-Based Iot Deployment, Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Joel J. P. C. Rodrigues, Youngho Park

VMASC Publications

In recent years, edge computing has emerged as a new concept in the computing paradigm that empowers several future technologies, such as 5G, vehicle-to-vehicle communications, and the Internet of Things (IoT), by providing cloud computing facilities, as well as services to the end users. However, open communication among the entities in an edge based IoT environment makes it vulnerable to various potential attacks that are executed by an adversary. Device authentication is one of the prominent techniques in security that permits an IoT device to authenticate mutually with a cloud server with the help of an edge node. If authentication …


Building Datasets From Publicly Accessible Social Media Images For Biometric Analysis, Giordano Roberto Benitez Torres 2019 Florida Institute of Technology

Building Datasets From Publicly Accessible Social Media Images For Biometric Analysis, Giordano Roberto Benitez Torres

Theses and Dissertations

The world is developing at a rapid pace, and some of its advancement can be accredited to technological innovations that are affecting many aspects of society. A field within computer science that is increasingly reaching many industries is Biometrics, specifically the area face recognition. Researchers, scientists, and organizations actively try to improve the performance of tools and algorithms. Nevertheless, for it to occur, there is a need for high-quality datasets to test and develop new techniques. Never had humanity, in the course of the history of civilization, produced massive amounts of data as it currently does. Social media networks play …


Strongly Secure Authenticated Key Exchange From Supersingular Isogenies, Xiu XU, Haiyang XUE, Kunpeng WANG, Ho Man AU, Song TIAN 2019 Singapore Management University

Strongly Secure Authenticated Key Exchange From Supersingular Isogenies, Xiu Xu, Haiyang Xue, Kunpeng Wang, Ho Man Au, Song Tian

Research Collection School Of Computing and Information Systems

This paper aims to address the open problem, namely, to find new techniques to design and prove security of supersingular isogeny-based authenticated key exchange (AKE) protocols against the widest possible adversarial attacks, raised by Galbraith in 2018. Concretely, we present two AKEs based on a double-key PKE in the supersingular isogeny setting secure in the sense of CK+, one of the strongest security models for AKE. Our contributions are summarised as follows. Firstly, we propose a strong OW-CPA secure PKE, 2PKEsidh, based on SI-DDH assumption. By applying modified Fujisaki-Okamoto transformation, we obtain a [OW-CCA, OW-CPA] secure KEM, 2KEMsidh. Secondly, we …


The Information Disclosure Trilemma: Privacy, Attribution And Dependency, Ping Fan KE 2019 Singapore Management University

The Information Disclosure Trilemma: Privacy, Attribution And Dependency, Ping Fan Ke

Research Collection School Of Computing and Information Systems

Information disclosure has been an important mechanism to increase transparency and welfare in various contexts, from rating a restaurant to whistleblowing the wrongdoing of government agencies. Yet, the author often needs to be sacrificed during information disclosure process – an anonymous disclosure will forgo the reputation and compensation whereas an identifiable disclosure will face the threat of retaliation. On the other hand, the adoption of privacy-enhancing technologies (PETs) lessens the tradeoff between privacy and attribution while introducing dependency and potential threats. This study will develop the desirable design principles and possible threats of an information disclosure system, and discuss how …


When Keystroke Meets Password: Attacks And Defenses, Ximing LIU 2019 Singapore Management University

When Keystroke Meets Password: Attacks And Defenses, Ximing Liu

Dissertations and Theses Collection (Open Access)

Password is a prevalent means used for user authentication in pervasive computing environments since it is simple to be deployed and convenient to use. However, the use of password has intrinsic problems due to the involvement of keystroke. Keystroke behaviors may emit various side-channel information, including timing, acoustic, and visual information, which can be easily collected by an adversary and leveraged for the keystroke inference. On the other hand, those keystroke-related information can also be used to protect a user's credentials via two-factor authentication and biometrics authentication schemes. This dissertation focuses on investigating the PIN inference due to the side-channel …


Improving The Classification Of Tiny Images For Forensic Analysis, Roba Jafar Alharbi 2019 Florida Institute of Technology

Improving The Classification Of Tiny Images For Forensic Analysis, Roba Jafar Alharbi

Theses and Dissertations

Forensics can be defined as the approach that connects with and uses in governments and different organizations in order to detect any malicious activity. Digital forensics has become an essential approach to cyber investigation. Image forensics is one of the most beneficial ways that are used in digital forensics in order to help investigators in cybercrimes. Therefore, investigators can discover some new evidence besides what is already available on their systems when they use some digital forensics techniques. This thesis focuses on identifying an image based on its contents, especially tiny images. We investigated ways to improve the performance of …


An Empirical Study Of Sms One-Time Password Authentication In Android Apps, Siqi MA, Runhan FENG, Juanru LI, Yang LIU, Surya NEPAL, Elisa BERTINO, Robert H. DENG, Zhuo MA, Sanjay JHA 2019 Singapore Management University

An Empirical Study Of Sms One-Time Password Authentication In Android Apps, Siqi Ma, Runhan Feng, Juanru Li, Yang Liu, Surya Nepal, Elisa Bertino, Robert H. Deng, Zhuo Ma, Sanjay Jha

Research Collection School Of Computing and Information Systems

A great quantity of user passwords nowadays has been leaked through security breaches of user accounts. To enhance the security of the Password Authentication Protocol (PAP) in such circumstance, Android app developers often implement a complementary One-Time Password (OTP) authentication by utilizing the short message service (SMS). Unfortunately, SMS is not specially designed as a secure service and thus an SMS One-Time Password is vulnerable to many attacks. To check whether a wide variety of currently used SMS OTP authentication protocols in Android apps are properly implemented, this paper presents an empirical study against them. We first derive a set …


A Taxonomy Of Security Features For The Comparison Of Home Automation Protocols, Amal Abdullah Alasiri 2019 Florida Institute of Technology

A Taxonomy Of Security Features For The Comparison Of Home Automation Protocols, Amal Abdullah Alasiri

Theses and Dissertations

Both academia and industry environments are getting significant attention to the Internet-of-Things (IoT) technology because of the unlimited benefits that this technology can bring to the environment. The technology presents a vision of a future Internet where computing systems, nodes, users, and daily nodes such as sensors and actuators cooperate with unprecedented convenience and economic benefits. The umbrella of IoT covers various applications as the following (smart home, transport, community, and national applications). Most of the studies focus on its technical and usage more than the security perspective. Especially, there are limited papers focus on smart home protocols security regarding …


Computing Maximum And Minimum With Privacy Preservation And Flexible Access Control, Wenxiu DING, Zheng YAN, Xinren QIAN, Robert H. DENG 2019 Singapore Management University

Computing Maximum And Minimum With Privacy Preservation And Flexible Access Control, Wenxiu Ding, Zheng Yan, Xinren Qian, Robert H. Deng

Research Collection School Of Computing and Information Systems

With the fast development of Internet of Things, huge volume of data is being collected from various sensors and devices, aggregated at gateways, and processed in the cloud. Due to privacy concern, data are usually encrypted before being outsourced to the cloud. However, encryption seriously impedes both computation over the data and sharing of the computation results. Computing maximum and minimum among a data set are two of the most basic operations in machine learning and data mining algorithms. In this paper, we study how to compute maximum and minimum over encrypted data and control the access to the computation …


Appmod: Helping Older Adults Manage Mobile Security With Online Social Help, Zhiyuan WAN, Lingfeng BAO, Debin GAO, Eran TOCH, Xin XIA, Tamir MENDEL, David LO 2019 Singapore Management University

Appmod: Helping Older Adults Manage Mobile Security With Online Social Help, Zhiyuan Wan, Lingfeng Bao, Debin Gao, Eran Toch, Xin Xia, Tamir Mendel, David Lo

Research Collection School Of Computing and Information Systems

The rapid adoption of Smartphone devices has caused increasing security and privacy risks and breaches. Catching up with ever-evolving contemporary smartphone technology challenges leads older adults (aged 50+) to reduce or to abandon their use of mobile technology. To tackle this problem, we present AppMoD, a community-based approach that allows delegation of security and privacy decisions a trusted social connection, such as a family member or a close friend. The trusted social connection can assist in the appropriate decision or make it on behalf of the user. We implement the approach as an Android app and describe the results of …


Strongly Leakage Resilient Authenticated Key Exchange, Revisited, Guomin YANG, Rongmao CHEN, Yi MU, Willy SUSILO, GUO Fuchun, Jie LI 2019 Singapore Management University

Strongly Leakage Resilient Authenticated Key Exchange, Revisited, Guomin Yang, Rongmao Chen, Yi Mu, Willy Susilo, Guo Fuchun, Jie Li

Research Collection School Of Computing and Information Systems

Authenticated Key Exchange (AKE) protocols allow two (or multiple) parties to authenticate each other and agree on a common secret key, which is essential for establishing a secure communication channel over a public network. AKE protocols form a central component in many network security standards such as IPSec, TLS/SSL, and SSH. However, it has been demonstrated that many standardized AKE protocols are vulnerable to side-channel and key leakage attacks. In order to defend against such attacks, leakage resilient (LR-) AKE protocols have been proposed in the literature. Nevertheless, most of the existing LR-AKE protocols only focused on the resistance to …


Compositional Verification Of Heap-Manipulating Programs Through Property-Guided Learning, Long H. PHAM, Jun SUN, Quang LOC LE 2019 Singapore University of Technology and Design

Compositional Verification Of Heap-Manipulating Programs Through Property-Guided Learning, Long H. Pham, Jun Sun, Quang Loc Le

Research Collection School Of Computing and Information Systems

Analyzing and verifying heap-manipulating programs automatically is challenging. A key for fighting the complexity is to develop compositional methods. For instance, many existing verifiers for heap-manipulating programs require user-provided specification for each function in the program in order to decompose the verification problem. The requirement, however, often hinders the users from applying such tools. To overcome the issue, we propose to automatically learn heap-related program invariants in a property-guided way for each function call. The invariants are learned based on the memory graphs observed during test execution and improved through memory graph mutation. We implemented a prototype of our approach …


Detection And Countermeasure Of Saturation Attacks In Software-Defined Networks, Samer Yousef Khamaiseh 2019 Boise State University

Detection And Countermeasure Of Saturation Attacks In Software-Defined Networks, Samer Yousef Khamaiseh

Boise State University Theses and Dissertations

The decoupling of control and data planes in software-defined networking (SDN) facilitates orchestrating the network traffic. However, SDN suffers from critical security issues, such as DoS saturation attacks on the data plane. These attacks can exhaust the SDN component resources, including the computational resources of the control plane, create a high packet loss rate and a long delay in delivering the OpenFlow messages due to the bandwidth consumption of the OpenFlow connection channel, and exhausting the buffer memory of the data plane.

Currently, most of the existing machine learning detection methods rely on a predefined time-window to start analyzing the …


Bullynet: Unmasking Cyberbullies On Social Networks, Aparna Sankaran 2019 Boise State University

Bullynet: Unmasking Cyberbullies On Social Networks, Aparna Sankaran

Boise State University Theses and Dissertations

Social media has changed the way people communicate with each other, and consecutively affected people's ability to empathize in both positive and negative ways. One of the most harmful consequences of social media is the rise of cyberbullying, which tends to be more sinister than traditional bullying given that online records typically live on the internet for quite a long time and are hard to control. In this thesis, we present a three-phase algorithm, called BullyNet, for detecting cyberbullies on Twitter social network. We exploit bullying tendencies by proposing a robust method for constructing a cyberbullying signed network. BullyNet analyzes …


Innovative Business Model For Smart Healthcare Insurance, Maryam Hasan Al Thawadi 2019 United Arab Emirates University

Innovative Business Model For Smart Healthcare Insurance, Maryam Hasan Al Thawadi

Information Security Theses

Information revolution and technology growth have made a considerable contribution to restraining the cost expansion and empowering the customer. They disrupted most business models in different industries. The customer-centric business model has pervaded the different sectors. Smart healthcare has made an enormous shift in patient life and raised their expectations of healthcare services quality. Healthcare insurance is an essential business in the healthcare sector; patients expect a new business model to meet their needs and enhance their wellness. This research develops a holistic smart healthcare architecture based on the recent development of information and communications technology. Then develops a disruptive …


Data Security Issues In Deep Learning: Attacks, Countermeasures, And Opportunities, Guowen XU, Hongwei LI, Hao REN, Kan YANG, Robert H. DENG 2019 University of Electronic Science and Technology of China

Data Security Issues In Deep Learning: Attacks, Countermeasures, And Opportunities, Guowen Xu, Hongwei Li, Hao Ren, Kan Yang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Benefiting from the advancement of algorithms in massive data and powerful computing resources, deep learning has been explored in a wide variety of fields and produced unparalleled performance results. It plays a vital role in daily applications and is also subtly changing the rules, habits, and behaviors of society. However, inevitably, data-based learning strategies are bound to cause potential security and privacy threats, and arouse public as well as government concerns about its promotion to the real world. In this article, we mainly focus on data security issues in deep learning. We first investigate the potential threats of deep learning …


Digital Commons powered by bepress