Choosing Protection: User Investments In Security Measures For Cyber Risk Management,
2019
Singapore Management University
Choosing Protection: User Investments In Security Measures For Cyber Risk Management, Yoav Ben Yaakov, Xinrun Wang, Joachim Meyer, Bo An
Research Collection School Of Computing and Information Systems
Firewalls, Intrusion Detection Systems (IDS), and cyber-insurance are widely used to protect against cyber-attacks and their consequences. The optimal investment in each of these security measures depends on the likelihood of threats and the severity of the damage they cause, on the user’s ability to distinguish between malicious and non-malicious content, and on the properties of the different security measures and their costs. We present a model of the optimal investment in the security measures, given that the effectiveness of each measure depends partly on the performance of the others. We also conducted an online experiment in which participants classified …
When Players Affect Target Values: Modeling And Solving Dynamic Partially Observable Security Games,
2019
Singapore Management University
When Players Affect Target Values: Modeling And Solving Dynamic Partially Observable Security Games, Xinrun Wang, Milind Tambe, Branislav Bosanky, Bo An
Research Collection School Of Computing and Information Systems
Most of the current security models assume that the values of targets/areas are static or the changes (if any) are scheduled and known to the defender. Unfortunately, such models are not sufficient for many domains, where actions of the players modify the values of the targets. Examples include wildlife scenarios, where the attacker can increase value of targets by secretly building supporting facilities. To address such security game domains with player-affected values, we first propose DPOS3G, a novel partially observable stochastic Stackelberg game where target values are determined by the players’ actions; the defender can only partially observe these targets’ …
Learning-Guided Network Fuzzing For Testing Cyber-Physical System Defences,
2019
Singapore Management University
Learning-Guided Network Fuzzing For Testing Cyber-Physical System Defences, Yuqi Chen, Chris Poskitt, Jun Sun, Sridhar Adepu, Fan Zhang
Research Collection School Of Computing and Information Systems
The threat of attack faced by cyber-physical systems (CPSs), especially when they play a critical role in automating public infrastructure, has motivated research into a wide variety of attack defence mechanisms. Assessing their effectiveness is challenging, however, as realistic sets of attacks to test them against are not always available. In this paper, we propose smart fuzzing, an automated, machine learning guided technique for systematically finding 'test suites' of CPS network attacks, without requiring any knowledge of the system's control programs or physical processes. Our approach uses predictive machine learning models and metaheuristic search algorithms to guide the fuzzing of …
Work-In-Progress: Iot Device Signature Validation,
2019
Regis University
Work-In-Progress: Iot Device Signature Validation, Jeffrey Hemmes
Regis University Faculty Publications
Device fingerprinting is an area of security that has received renewed attention in recent years, with a number of classification methods proposed that rely on characteristics unique to a particular vendor or device type. Current works are limited to determining device type for purposes of access control and MAC address spoof prevention. This work synthesizes multiple sources of information to verify device capabilities in a device profile, which can be used in a number of applications not limited to authentication and authorization. The approach proposed in this paper relies on existing protocols and methods proposed in the literature, using a …
Effectiveness Of Tools In Identifying Rogue Access Points On A Wireless Network,
2019
University of North Georgia
Effectiveness Of Tools In Identifying Rogue Access Points On A Wireless Network, Ryan Vansickle, Tamirat Abegaz, Bryson Payne
KSU Proceedings on Cybersecurity Education, Research and Practice
Wireless access points have greatly improved users' ability to connect to the Internet. However, they often lack the security mechanisms needed to protect users. Malicious actors could create a rogue access point (RAP), using a device such as the WiFi Pineapple Nano, that could trick users into connecting to an illegitimate access point (AP). To make them look legitimate, adversaries tend to setup RAPs to include a captive portal. This is very effective, since most public networks use captive portals as a means to provide genuine access. The objective of this study is to examine the effectiveness of RAP identification …
Automatic Security Bug Detection With Findsecuritybugs Plugin,
2019
Kennesaw State University
Automatic Security Bug Detection With Findsecuritybugs Plugin, Hossain Shahriar, Kmarul Riad, Arabin Talukder, Hao Zhang, Zhuolin Li
KSU Proceedings on Cybersecurity Education, Research and Practice
The security threats to mobile application are growing explosively. Mobile app flaws and security defects could open doors for hackers to easily attack mobile apps. Secure software development must be addressed earlier in the development lifecycle rather than fixing the security holes after attacking. Early eliminating against possible security vulnerability will help us increase the security of software and mitigate the consequence of damages of data loss caused by potential malicious attacking. In this paper, we present a static security analysis approach with open source FindSecurityBugs plugin for Android StThe security threats to mobile application are growing explosively. Mobile app …
Automated Reverse Engineering Of Automotive Can Bus Controls,
2019
University of North Georgia
Automated Reverse Engineering Of Automotive Can Bus Controls, Charles Barron Kirby, Bryson Payne
KSU Proceedings on Cybersecurity Education, Research and Practice
This research provides a means of automating the process to reverse engineer an automobile’s CAN Bus to quickly recover CAN IDs and message values to control the various systems in a modern automobile. This approach involved the development of a Python script that uses several open-source tools to interact with the CAN Bus, and it takes advantage of several vulnerabilities associated with the CAN protocol. These vulnerabilities allow the script to conduct replay attacks against the CAN Bus and affect various systems in an automobile without the operator’s knowledge or interaction.
These replay attacks can be accomplished by capturing recorded …
A World Of Cyber Attacks (A Survey),
2019
Saintleo University
A World Of Cyber Attacks (A Survey), Mubarak Banisakher, Marwan Omar
KSU Proceedings on Cybersecurity Education, Research and Practice
The massive global network that connects billions of humans and millions of devices and allow them to communicate with each other is known as the internet. Over the last couple of decades, the internet has grown expeditiously and became easier to use and became a great educational tool. Now it can used as a weapon that can steal someone’s identity, expose someone’s financial information, or can destroy your networking devices. Even in the last decade, there have been more cyber attacks and threats destroying major companies by breaching the databases that have millions of personal information that can be sold …
An Exploratory Analysis Of Mobile Security Tools,
2019
Kennesaw State University
An Exploratory Analysis Of Mobile Security Tools, Hossain Shahriar, Md Arabin Talukder, Md Saiful Islam
KSU Proceedings on Cybersecurity Education, Research and Practice
The growing market of the mobile application is overtaking the web application. Mobile application development environment is open source, which attracts new inexperienced developers to gain hands on experience with applicationn development. However, the security of data and vulnerable coding practice is an issue. Among all mobile Operating systems such as, iOS (by Apple), Android (by Google) and Blackberry (RIM), Android dominates the market. The majority of malicious mobile attacks take advantage of vulnerabilities in mobile applications, such as sensitive data leakage via the inadvertent or side channel, unsecured sensitive data storage, data transition and many others. Most of these …
Iot: Challenges In Information Security Training,
2019
The University of Auckland
Iot: Challenges In Information Security Training, Lech J. Janczewski, Gerard Ward
KSU Proceedings on Cybersecurity Education, Research and Practice
Both consumers and businesses are rapidly adopting IoT premised on convenience and control. Industry and academic literature talk about billions of embedded IoT devices being implemented with use-cases ranging from smart speakers in the home, to autonomous trucks, and trains operating in remote industrial sites. Historically information systems supporting these disparate use-cases have been categorised as Information Technology (IT) or Operational Technology (OT), but IoT represents a fusion between these traditionally distinct information security models.
This paper presents a review of IEEE and Elsevier peer reviewed papers that identifies the direction in IoT education and training around information security. It …
Proposal For A Joint Cybersecurity And Information Technology Management Program,
2019
National University
Proposal For A Joint Cybersecurity And Information Technology Management Program, Christopher Simpson, Debra Bowen, William Reid, James Juarez
KSU Proceedings on Cybersecurity Education, Research and Practice
Cybersecurity and Information Technology Management programs have many similarities and many similar knowledge, skills, and abilities are taught across both programs. The skill mappings for the NICE Framework and the knowledge units required to become a National Security Agency and Department of Homeland Security Center of Academic Excellence in Cyber Defense Education contain many information technology management functions. This paper explores one university’s perception on how a joint Cybersecurity and Information Technology Management program could be developed to upskill students to be work force ready.
Adversarial Thinking: Teaching Students To Think Like A Hacker,
2019
Georgia Southern University
Adversarial Thinking: Teaching Students To Think Like A Hacker, Frank Katz
KSU Proceedings on Cybersecurity Education, Research and Practice
Today’s college and university cybersecurity programs often contain multiple laboratory activities on various different hardware and software-based cybersecurity tools. These include preventive tools such as firewalls, virtual private networks, and intrusion detection systems. Some of these are tools used in attacking a network, such as packet sniffers and learning how to craft cross-site scripting attacks or man-in-the-middle attacks. All of these are important in learning cybersecurity. However, there is another important component of cybersecurity education – teaching students how to protect a system or network from attackers by learning their motivations, and how they think, developing the students’ “abilities to …
Internet Core Functions: Security Today And Future State,
2019
Kennesaw State University
Internet Core Functions: Security Today And Future State, Jeffrey Jones
KSU Proceedings on Cybersecurity Education, Research and Practice
Never in the history of the world has so much trust been given to something that so few understand. Jeff reviews three core functions of the Internet along with recent and upcoming changes that will impact security and the world.
Preparing For Tomorrow By Looking At Yesterday,
2019
InterContinental Hotels Group PLC
Preparing For Tomorrow By Looking At Yesterday, Peter Dooley
KSU Proceedings on Cybersecurity Education, Research and Practice
Why do we learn? Why do we study history? Why do we research the work of others? The answer is that there is value today in what was already learned and experienced, successes and failures. Mr. Dooley, a 25-year security professional and 20-year hospitality executive, will share his experiences and how our history in security will help us in thinking about our future.
Concolic Testing Heap-Manipulating Programs,
2019
Singapore Management University
Concolic Testing Heap-Manipulating Programs, Long H. Pham, Quang Loc Le, Quoc-Sang Phan, Jun Sun
Research Collection School Of Computing and Information Systems
Concolic testing is a test generation technique which works effectively by integrating random testing generation and symbolic execution. Existing concolic testing engines focus on numeric programs. Heap-manipulating programs make extensive use of complex heap objects like trees and lists. Testing such programs is challenging due to multiple reasons. Firstly, test inputs for such program are required to satisfy non-trivial constraints which must be specified precisely. Secondly, precisely encoding and solving path conditions in such programs are challenging and often expensive. In this work, we propose the first concolic testing engine called CSF for heap-manipulating programs based on separation logic. CSF …
Privacidad Digital En Ecuador: El Papel De La Vigilancia, La Jurisprudencia Y Los Derechos Humanos,
2019
SIT Study Abroad
Privacidad Digital En Ecuador: El Papel De La Vigilancia, La Jurisprudencia Y Los Derechos Humanos, Giselle Valdez
Independent Study Project (ISP) Collection
Este documento es un estudio de caso sobre la privacidad digital en Ecuador, cómo se protege y cómo se debe mejorar las protecciones. Comienzo presentando la falta de privacidad de la persona en Ecuador, a través de la reciente violación de datos y las tecnologías de vigilancia en todo el país desde China. Luego, para analizar la jurisprudencia y la falta de protección de la privacidad en la ley, hago la transición a un análisis legal de la privacidad de datos en Ecuador a través de la Constitución de 2008. Cuando establezco que falta privacidad digital en Ecuador, demuestro una …
A Study Of Existing Cross-Site Scripting Detection And Prevention Techniques Using Xampp And Virtualbox,
2019
Norfolk State University
A Study Of Existing Cross-Site Scripting Detection And Prevention Techniques Using Xampp And Virtualbox, Jalen Mack, Yen-Hung (Frank) Hu, Mary Ann Hoppa
Virginia Journal of Science
Most operating websites experience a cyber-attack at some point. Cross-site Scripting (XSS) attacks are cited as the top website risk. More than 60 percent of web applications are vulnerable to them, and they ultimately are responsible for over 30 percent of all web application attacks. XSS attacks are complicated, and they often are used in conjunction with social engineering techniques to cause even more damage. Although prevention techniques exist, hackers still find points of vulnerability to launch their attacks. This project explored what XSS attacks are, examples of popular attacks, and ways to detect and prevent them. Using knowledge gained …
Enhancing Symbolic Execution Of Heap-Based Programs With Separation Logic For Test Input Generation,
2019
Singapore Management University
Enhancing Symbolic Execution Of Heap-Based Programs With Separation Logic For Test Input Generation, Long H. Pham, Quang Loc Le, Quoc-Sang Phan, Jun Sun, Shengchao Qin
Research Collection School Of Computing and Information Systems
Symbolic execution is a well established method for test input generation. Despite of having achieved tremendous success over numerical domains, existing symbolic execution techniques for heap-based programs are limited due to the lack of a succinct and precise description for symbolic values over unbounded heaps. In this work, we present a new symbolic execution method for heap-based programs based on separation logic. The essence of our proposal is context-sensitive lazy initialization, a novel approach for efficient test input generation. Our approach differs from existing approaches in two ways. Firstly, our approach is based on separation logic, which allows us to …
Esdra: An Efficient And Secure Distributed Remote Attestation Scheme For Iot Swarms,
2019
Singapore Management University
Esdra: An Efficient And Secure Distributed Remote Attestation Scheme For Iot Swarms, Boyu Kuang, Anmin Fu, Shui Yu, Guomin Yang, Mang Su, Yuqing Zhang
Research Collection School Of Computing and Information Systems
An Internet of Things (IoT) system generally contains thousands of heterogeneous devices which often operate in swarms-large, dynamic, and self-organizing networks. Remote attestation is an important cornerstone for the security of these IoT swarms, as it ensures the software integrity of swarm devices and protects them from attacks. However, current attestation schemes suffer from single point of failure verifier. In this paper, we propose an Efficient and Secure Distributed Remote Attestation (ESDRA) scheme for IoT swarms. We present the first many-to-one attestation scheme for device swarms, which reduces the possibility of single point of failure verifier. Moreover, we utilize distributed …
Tighter Security Proofs For Post-Quantum Key Encapsulation Mechanism In The Multi-Challenge Setting,
2019
Singapore Management University
Tighter Security Proofs For Post-Quantum Key Encapsulation Mechanism In The Multi-Challenge Setting, Zhengyu Zhang, Puwen Wei, Haiyang Xue
Research Collection School Of Computing and Information Systems
Due to the threat posed by quantum computers, a series of works investigate the security of cryptographic schemes in the quantum-accessible random oracle model (QROM) where the adversary can query the random oracle in superposition. In this paper, we present tighter security proofs of a generic transformations for key encapsulation mechanism (KEM) in the QROM in the multi-challenge setting, where the reduction loss is independent of the number of challenge ciphertexts. In particular, we introduce the notion of multi-challenge OW-CPA (mOW-CPA) security, which captures the one-wayness of the underlying public key encryption (PKE) under chosen plaintext attack in the multi-challenge …
