Formally Designing And Implementing Cyber Security Mechanisms In Industrial Control Networks.,
2019
University of Louisville
Formally Designing And Implementing Cyber Security Mechanisms In Industrial Control Networks., Mehdi Sabraoui
Electronic Theses and Dissertations
This dissertation describes progress in the state-of-the-art for developing and deploying formally verified cyber security devices in industrial control networks. It begins by detailing the unique struggles that are faced in industrial control networks and why concepts and technologies developed for securing traditional networks might not be appropriate. It uses these unique struggles and examples of contemporary cyber-attacks targeting control systems to argue that progress in securing control systems is best met with formal verification of systems, their specifications, and their security properties. This dissertation then presents a development process and identifies two technologies, TLA+ and seL4, that can be …
Cybersecurity Education In Utah High Schools: An Analysis And Strategy For Teacher Adoption,
2019
Brigham Young University
Cybersecurity Education In Utah High Schools: An Analysis And Strategy For Teacher Adoption, Cariana June Cornel
Theses and Dissertations
The IT Education Specialist for the USBE, Brandon Jacobson, stated:I feel there is a deficiency of and therefore a need to teach Cybersecurity.Cybersecurity is the “activity or process, ability or capability, or state whereby information and communications systems and the information contained therein are protected from and/or defended against damage, unauthorized use or modification, or exploitation” (NICE, 2018). Practicing cybersecurity can increase awareness of cybersecurity issues, such as theft of sensitive information. Current efforts, including but not limited to, cybersecurity camps, competitions, college courses, and conferences, have been created to better prepare cyber citizens nationwide for such cybersecurity occurrences. In …
Constructing Strong Designated Verifier Signatures From Key Encapsulation Mechanisms,
2019
Singapore Management University
Constructing Strong Designated Verifier Signatures From Key Encapsulation Mechanisms, Borui Gong, Ho Man Au, Haiyang Xue
Research Collection School Of Computing and Information Systems
A designated verifier signature (DVS) allows a signer to convince a verifier that a message has been endorsed in a way that the conviction cannot be transferred to any third party. This is achieved by the property that the signature can be generated by one of them. Since DVS is publicly verifiable, a valid DVS implies that the signature must be created by either the signer or the verifier. To enhance privacy of signers' identity, a strong DVS (SDVS) disallows public verification. In this paper, we investigate various aspects of SDVS with making two contributions. Firstly, we consider SDVS in …
Iot Ignorance Is Digital Forensics Research Bliss: A Survey To Understand Iot Forensics Definitions, Challenges And Future Research Directions,
2019
University of Oxford
Iot Ignorance Is Digital Forensics Research Bliss: A Survey To Understand Iot Forensics Definitions, Challenges And Future Research Directions, Tina Wu, Frank Breitinger, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
Interactions with IoT devices generates vast amounts of personal data that can be used as a source of evidence in digital investigations. Currently, there are many challenges in IoT forensics such as the difficulty in acquiring and analysing IoT data/devices and the lack IoT forensic tools. Besides technical challenges, there are many concepts in IoT forensics that have yet to be explored such as definitions, experience and capability in the analysis of IoT data/devices and current/future challenges. A deeper understanding of these various concepts will help progress the field. To achieve this goal, we conducted a survey which received 70 …
A Secure Iot Cloud Storage System With Fine-Grained Access Control And Decryption Key Exposure Resistance,
2019
Singapore Management University
A Secure Iot Cloud Storage System With Fine-Grained Access Control And Decryption Key Exposure Resistance, Shengmin Xu, Guomin Yang, Yi Mu, Ximeng Liu
Research Collection School Of Computing and Information Systems
Internet of Things (IoT) cloud provides a practical and scalable solution to accommodate the data management in large-scale IoT systems by migrating the data storage and management tasks to cloud service providers (CSPs). However, there also exist many data security and privacy issues that must be well addressed in order to allow the wide adoption of the approach. To protect data confidentiality, attribute-based cryptosystems have been proposed to provide fine-grained access control over encrypted data in loT cloud. Unfortunately, the existing attributed-based solutions are still insufficient in addressing some challenging security problems, especially when dealing with compromised or leaked user …
Cybersecurity Education: The Quest To Building Bridge Skills,
2019
Franklin University
Cybersecurity Education: The Quest To Building Bridge Skills, Andy Igonor, Raymond L. Forbes, Jonathan Mccombs
All Faculty and Staff Scholarship
Today's employers differ in what skills and abilities they believe make for a competent cybersecurity professional; however, they concur on the importance of technical and soft skills, which we collectively refer to as "bridge skills" - in other words, skills needed to bridge employer needs and what higher education teaches. Higher education, on the other hand favors producing a holistic and rounded graduate, with soft skills incorporated into the first one or two years of study. Somewhere between these two dichotomies is a missing link which currently manifests as higher education not meeting the needs of industry relative to cybersecurity …
Who Should Pay The Cost: A Game-Theoretic Model For Government Subsidized Investments To Improve National Cybersecurity,
2019
Singapore Management University
Who Should Pay The Cost: A Game-Theoretic Model For Government Subsidized Investments To Improve National Cybersecurity, Xinrun Wang, Bo An, Hau Chan
Research Collection School Of Computing and Information Systems
Due to the recent cyber attacks, cybersecurity is becoming more critical in modern society. A single attack (e.g., WannaCry ransomware attack) can cause as much as $4 billion in damage. However, the cybersecurity investment by companies is far from satisfactory. Therefore, governments (e.g., in the UK) launch grants and subsidies to help companies to boost their cybersecurity to create a safer national cyber environment. The allocation problem is hard due to limited subsidies and the interdependence between self-interested companies and the presence of a strategic cyber attacker. To tackle the government's allocation problem, we introduce a Stackelberg game-theoretic model where …
Suitability Of Finite State Automata To Model String Constraints In Probablistic Symbolic Execution,
2019
Boise State University
Suitability Of Finite State Automata To Model String Constraints In Probablistic Symbolic Execution, Andrew Harris
Boise State University Theses and Dissertations
Probabilistic Symbolic Execution (PSE) extends Symbolic Execution (SE), a path-sensitive static program analysis technique, by calculating the probabilities with which program paths are executed. PSE relies on the ability of the underlying symbolic models to accurately represent the execution paths of the program as the collection of input values following these paths. While researchers established PSE for numerical data types, PSE for complex data types such as strings is a novel area of research.
For string data types SE tools commonly utilize finite state automata to represent a symbolic string model. Thus, PSE inherits from SE automata-based symbolic string models …
Process/Equipment Design Implications For Control System Cybersecurity,
2019
Wayne State University
Process/Equipment Design Implications For Control System Cybersecurity, Helen Durand
Chemical Engineering and Materials Science Faculty Research Publications
An emerging challenge for process safety is process control system cybersecurity. An attacker could gain control of the process actuators through the control system or communication policies within control loops and potentially drive the process state to unsafe conditions. Cybersecurity has traditionally been handled as an information technology (IT) problem in the process industries. In the literature for cybersecurity specifically of control systems, there has been work aimed at developing control designs that seek to fight cyberattacks by either giving the system appropriate response mechanisms once attacks are detected or seeking to make the attacks difficult to perform. In this …
Design Of Personnel Big Data Management System Based On Blockchain,
2019
Embry-Riddle Aeronautical University
Design Of Personnel Big Data Management System Based On Blockchain, Houbing Song, Jian Chen, Zhihan Lv
Publications
With the continuous development of information technology, enterprises, universities and governments are constantly stepping up the construction of electronic personnel information management system. The information of hundreds of thousands or even millions of people’s information are collected and stored into the system. So much information provides the cornerstone for the development of big data, if such data is tampered with or leaked, it will cause irreparable serious damage. However, in recent years, electronic archives have exposed a series of problems such as information leakage, information tampering, and information loss, which has made the reform of personnel information management more and …
Control-Flow Carrying Code,
2019
Singapore Management University
Control-Flow Carrying Code, Yan Lin, Debin Gao
Research Collection School Of Computing and Information Systems
Control-Flow Integrity (CFI) is an effective approach in mitigating control-flow hijacking attacks including code-reuse attacks. Most conventional CFI techniques use memory page protection mechanism, Data Execution Prevention (DEP), as an underlying basis. For instance, CFI defenses use read-only address tables to avoid metadata corruption. However, this assumption has shown to be invalid with advanced attacking techniques, such as Data-Oriented Programming, data race, and Rowhammer attacks. In addition, there are scenarios in which DEP is unavailable, e.g., bare-metal systems and applications with dynamically generated code. We present the design and implementation of Control-Flow Carrying Code (C3), a new CFI enforcement without …
An Architecture For Blockchain-Based Collaborative Signature-Based Intrusion Detection System,
2019
Kennesaw State University
An Architecture For Blockchain-Based Collaborative Signature-Based Intrusion Detection System, Daniel Laufenberg
Master of Science in Information Technology Theses
Collaborative intrusion detection system (CIDS), where IDS hosts work with each other and share resources, have been proposed to cope with the increasingly sophisticated cyberattacks. Despite the promising benefits such as expanded signature databases and alert data from multiple sites, trust management and consensus building remain as challenges for a CIDS to work effectively. The blockchain technology with built-in immutability and consensus building capability provides a viable solution to the issues of CIDS. In this paper, we introduce an architecture for a blockchain-enabled signature-based collaborative IDS, discuss the implementation strategy of the proposed architecture and developed a prototype using Hyperledger …
Dynopvm: Vm-Based Software Obfuscation With Dynamic Opcode Mapping,
2019
Singapore Management University
Dynopvm: Vm-Based Software Obfuscation With Dynamic Opcode Mapping, Xiaoyang Cheng, Yan Lin, Debin Gao
Research Collection School Of Computing and Information Systems
VM-based software obfuscation has emerged as an effective technique for program obfuscation. Despite various attempts in improving its effectiveness and security, existing VM-based software obfuscators use potentially multiple but static secret mappings between virtual and native opcodes to hide the underlying instructions. In this paper, we present an attack using frequency analysis to effectively recover the secret mapping to compromise the protection, and then propose a novel VM-based obfuscator in which each basic block uses a dynamic and control-flow-aware mapping between the virtual and native instructions. We show that our proposed VM-based obfuscator not only renders the frequency analysis attack …
Ethical Hacking For Effective Defense (Modules, Labs, And Lectures),
2019
Kennesaw State University
Ethical Hacking For Effective Defense (Modules, Labs, And Lectures), Hossain Shahriar
Computer Science and Information Technology Ancillary Materials
Summer 2019 Update: Through a Round Twelve ALG Mini-Grant for Ancillary Materials Creation and Revision, five new modules have been added to this collection:
- Enumeration with Sparta
- Enumeration with Inguma
- Hacking Web Servers with Dirbuster
- Hacking Web Servers with Skipfish
- Hacking Wireless and IoT with Bluehydra
The following set of materials is used in the Textbook Transformation Grants implementation of Ethical Hacking for Effective Defense:
https://oer.galileo.usg.edu/compsci-collections/8/
Topics include:
- TCP/IP Level Attacks
- Port Scanning
- DDoS
- Footprinting and Social Engineering
- Enumeration
- Programming for Security Professionals
- Operating System Vulnerabilities
- Embedded System Security
- Hacking Web Servers
- Hacking Wireless Networks
- Cryptography
- Protecting Networks with …
Towards Understanding Android System Vulnerabilities: Techniques And Insights,
2019
Singapore Management University
Towards Understanding Android System Vulnerabilities: Techniques And Insights, Daoyuan Wu, Debin Gao, Eric K. T. Cheng, Yichen Cao, Jintao Jiang, Robert H. Deng
Research Collection School Of Computing and Information Systems
As a common platform for pervasive devices, Android has been targeted by numerous attacks that exploit vulnerabilities in its apps and the operating system. Compared to app vulnerabilities, systemlevel vulnerabilities in Android, however, were much less explored in the literature. In this paper, we perform the first systematic study of Android system vulnerabilities by comprehensively analyzing all 2,179 vulnerabilities on the Android Security Bulletin program over about three years since its initiation in August 2015. To this end, we propose an automatic analysis framework, upon a hierarchical database structure, to crawl, parse, clean, and analyze vulnerability reports and their publicly …
A Closer Look Tells More: A Facial Distortion Based Liveness Detection For Face Authentication,
2019
Xidian University
A Closer Look Tells More: A Facial Distortion Based Liveness Detection For Face Authentication, Yan Li, Zilong Wang, Yingjiu Li, Robert H. Deng, Binbin Chen, Weizhi Meng, Hui Li
Research Collection School Of Computing and Information Systems
Face authentication is vulnerable to media-based virtual face forgery (MVFF) where adversaries display photos/videos or 3D virtual face models of victims to spoof face authentication systems. In this paper, we propose a liveness detection mechanism, called FaceCloseup, to protect the face authentication on mobile devices. FaceCloseup detects MVFF-based attacks by analyzing the distortion of face regions in a user's closeup facial videos captured by built-in camera on mobile device. It can detect MVFF-based attacks with an accuracy of 99.48%.
Splitsecond: Flexible Privilege Separation Of Android Apps,
2019
Singapore Management University
Splitsecond: Flexible Privilege Separation Of Android Apps, Jehyun Lee, Akshaya Venkateswara Venkateswara Raja, Debin Gao
Research Collection School Of Computing and Information Systems
Android applications have been attractive targets to attackers due to the large number of users and the sensitive information they possess. After the success of the first step of an attack exploiting a software vulnerability, the consequential damage is primarily determined by the criticality and the amount of Android permissions that a victim application has. As a countermeasure, process separation techniques that isolate potentially vulnerable components — usually native libraries — from the critical data and permissions, have been proposed. However, existing techniques offer little flexibility in the separation, e.g., with all native code being placed into one process without …
Securing Messaging Services Through Efficient Signcryption With Designated Equality Test,
2019
Guilin University of Electronic Technology
Securing Messaging Services Through Efficient Signcryption With Designated Equality Test, Yujue Wang, Hwee Hwa Pang, Robert H. Deng, Yong Ding, Qianhong Wu, Bo Qin
Research Collection School Of Computing and Information Systems
To address security and privacy issues in messaging services, we present a public key signcryption scheme with designated equality test on ciphertexts (PKS-DET) in this paper. The scheme enables a sender to simultaneously encrypt and sign (signcrypt) messages, and to designate a tester to perform equality test on ciphertexts, i.e., to determine whether two ciphertexts signcrypt the same underlying plaintext message. We introduce the PKS-DET framework, present a concrete construction and formally prove its security against three types of adversaries, representing two security requirements on message confidentiality against outsiders and the designated tester, respectively, and a requirement on message unforgeability …
Oblidc: An Sgx-Based Oblivious Distributed Computing Framework With Formal Proof,
2019
Peking University
Oblidc: An Sgx-Based Oblivious Distributed Computing Framework With Formal Proof, Pengfei Wu, Qingni Shen, Robert H. Deng, Ximeng Liu, Yinghui Zhang, Zhonghai Wu
Research Collection School Of Computing and Information Systems
Data privacy is becoming one of the most critical concerns in cloud computing. Several proposals based on Intel SGX such as VC3 and M2R have been introduced in the literature to protect data privacy during job execution in the cloud. However, a comprehensive formal proof of their security guarantees is still lacking. In this paper, we propose ObliDC, a general UC-secure SGX-based oblivious distributed computing framework. First, we model the life-cycle of a distributed computing job as data-flow graphs. Under the assumption of malicious, adaptive adversaries in the cloud, we then formally define data privacy of a distributed computing job …
Pruneable Sharding-Based Blockchain Protocol,
2019
Singapore Management University
Pruneable Sharding-Based Blockchain Protocol, Xiaoqin Feng, Jianfeng Ma, Yinbin Miao, Qian Meng, Ximeng Liu, Qi Jiang, Hui Li
Research Collection School Of Computing and Information Systems
As a distributed ledger technology, the block-chain has gained much attention from both the industrical and academical fields, but most of the existing blockchain protocols still have the cubical dilatation problem. Although the latest Rollerchain has mitigated this issue by changing the blockheader's contents, the low efficiency, severe capacity expansion and non-scalability problems still hinder the adoption of Rollerchain in practice. To this end, we present the pruneable sharding-based blockchain protocol by utilizing the sharding technique and PBFT(Practical Byzantine Fault Tolerance) algorithm in the improved Rollerchain, which has high efficiency, slow cubical dilatation, small capacity expansion and high scalability. Moreover, …
