Dakota State University

Beadle Scholar at Dakota State University
Not a member yet
    1393 research outputs found

    Endpoint Defense as Code (EDAC): Configurable Contextual Analysis of Process Behaviors From Kernel/User Event Tracing

    Get PDF
    The current industry standard to detect cyber threat activity on endpoints (workstations, servers, etc.) centers around the use of endpoint defense software. The software products marketed are Endpoint Protection Platforms (EPP), Endpoint Detection and Response (EDR), and eXtended Detection and Response (XDR) solutions. These solutions are typically deployed onto endpoints across enterprises and monitor various aspects of each operating system for malicious activity. Current generations of these three solutions have similar underlying software architectures, user workflows, and detection capabilities. These solutions also have a number of issues that inadvertently allow advanced cyber threat actors to succeed in their operations, such as, lack of resilience to intentional evasions against critical software components, lack of resilience against user configuration errors, low detection rates of atomic techniques, low configurability for process-level behaviors, and semantically inappropriate alert messages. As proven in prior research and research that the author is conducting concurrently alongside this research, these issues can be capitalized on by knowledgeable and observant attackers to enable their technique chains to succeed undetected. Through years of professional experience deploying, testing, and evaluating various commercial endpoint solutions in various system architectures (commercial enterprise systems, government systems, disconnected/air-gapped systems, etc.), the author has learned that many commercial endpoint defense technologies are designed to make decisions for the operators on what activity is benign and what activity is malicious, without giving operators the ability to change this decision making. Vendors of these solutions add to this by illustrating a measure of trust in the solution’s ecacy by releasing their detection statistics of known Indicators of Compromise (IOCs). These IOCs may or may not be used by attackers in the future as new attack techniques are developed. This creates a iv detection gap between known techniques that can be detected, and actual techniques that are being executed. In addition to this, the author has observed in organizations across many industries a level of indiscriminate trust in commercial endpoint solutions. Many organizations fully trust endpoint solutions to be the sole defense mechanism on an endpoint without fully testing the solution for resiliency or detection gaps. All of these facts and circumstances create gaps, inconsistencies, and avenues for highly observant cyber attackers to maneuver in and out of systems undetected. This document illustrates all of the research that has been completed as part of this dissertation to solve the identified issues with current-generation endpoint defense solutions. The overarching approach to solving the identified problems was to use the Design Science Research (DSR) methodology to develop a software artifact that is su- ciently di↵erent and more impactful than existing solutions, and test the designed artifact against real-world attack technique stimulus to prove its validity and usefulness within real-world system architectures. The developed artifact gives operators the flexibility to define attack technique behaviors of interest through a custom developed configuration syntax and utilizes Event Tracing for Windows (ETW) telemetry emanating from the Windows operating system in a unique way to detect the defined attack behaviors. Validation experiments on the developed artifact proved that the artifact, along with the user-defined configuration file, successfully detected 36/48 of the chosen atomic attack technique stimuli. The results represent a significantly broad coverage of detection that current-generation endpoint solutions fail to accomplish, thereby illustrating the need to incorporate the developed artifact into real-world environments to combat cyber-attack activity

    Academic Hall of Fame Flyer

    Get PDF

    A False Sense of Security - Organizations Need a Paradigm Shift on Protecting Themselves against APTs

    Get PDF
    Organizations Advanced persistent threats (APTs) are the most complex cyberattacks and are generally executed by cyber attackers linked to nation-states. The motivation behind APT attacks is political intelligence and cyber espionage. Despite all the awareness, technological advancements, and massive investment, the fight against APTs is a losing battle for organizations. An organization may implement a security strategy to prevent APTs. However, the benefits to the security posture might be negligible if the measurement of the strategy’s effectiveness is not part of the plan. A false sense of security exists when the focus is on implementing a security strategy but not its effectiveness. This research verifies whether organizations are in a false sense of security while preventing APT attacks, what factors influence the false sense of security, and whether organizational culture influences factors contributing to the false sense of security. The research method utilized was survey-based quantitative research. Confirmatory Factor Analysis (CFA) and Structural Equation Modeling (SEM) were employed in the research model evaluation and hypotheses testing. The data analysis found that the sense of security value among the employees is low, which proves that employees are not confident about their organization’s cybersecurity posture and organizations are in a false sense of security. Since Security Awareness and Training, Security Controls, Redundant IDS/IPS, and Cybersecurity Insurance positively influence the sense of security, recommendations were provided to enhance their effectiveness. The research study highlighted that sense of security of the employees is low when the security controls are ineffective. The contribution of this research is to highlight the paradigm shift required for organizations while setting up defenses against APTs. While organizations focus on setting up security controls to satisfy the compliance requirements, the research study outcome emphasizes the importance of the effectiveness of security controls. The dissertation includes limitations of the research and suggestions for further study

    Knowledge Management in Higher Education: Effectiveness, Success factors, and Organisational Performance

    Get PDF
    In today business environment, Higher education institutions are facing a common challenge in the wake of rapid changes due to substantial drops in public funding for public colleges and universities, a larger number of calls for transparency, rapid expansion of the global business. To survive, organizations of higher education must improve their performance continually. Researchers reported that knowledge and effectively managing knowledge can help HEIs improve their performance by solving many of these problems and acquire and sustain competitive advantage. It is beneficial to explore the factors that impact the effective implementation of knowledge management within higher education institutions. These factors are organizational culture, and leadership styles. Additionally, it is essential to investigate the leadership style that best supports effective implementation of knowledge management. This study sought to examine the relationship between organizational culture (mission, adaptability, involvement, consistency), leadership styles (transformational and transactional), knowledge management effectiveness, and organizational performance. The study also analyzed the mediating role of organizational culture on the relationship between leadership styles and knowledge management effectiveness. Based on existing literature, eight hypotheses and a conceptual model were developed regarding the relationships of the five constructs: organizational culture, transformational and transformational leadership, knowledge management effectiveness and organizational performance. All constructs are measured by multi-items scales. For this study, organizational performance and knowledge management effectiveness were taken as dependents variables. Leadership styles of transformational and transactional and organizational culture were taken as independent variables. Organizational culture (mission, consistency, adaptability, and involvement) served as mediator variable. A questionnaire was used to collect data; this questionnaire was administered to 251 faculty and administrative leaders employed at 20 universities and colleges across the United States of America. Only 136 were entirely completed and deemed useful for the study. Structural equation modeling and Confirmatory Factor Analysis within SEM were adopted for data analysis. Results were presented using frequency distribution tables and graphs. Key findings suggested that organizational culture and transformational leadership impacted knowledge management effectiveness. But transactional leadership did not. Consequently, knowledge management effectiveness impacted organizational performance. While organizational culture mediated the effects of transformational leadership on knowledge management effectiveness, no mediating effect of organizational culture was found on the effect of transactional leadership on knowledge management effectiveness. Organizational culture has the largest positive impact on knowledge management effectiveness. These results may inform the successful implementation of KM practices, which in term improve the performance of higher educational institutions across the United States of America

    Quantitative Real-Time PCR Identification of Soybean Pathogens in Eastern South Dakota Soil

    Get PDF
    According to the 2021 State Agricultural Overview, South Dakota (SD) planted 5,450,000 acres of soybeans in 2021, and 5.8% of potential soybean production was lost due to diseases. Revealing prevalent soil borne soybean pathogens throughout the state and utilizing the proper management strategies could in crease SD soybean yields. With the relatively recent (2014) first report of soybean sudden death syndrome (SDS) in SD and confirmation of SOS in three more counties in 2017, we utilized quantitative realtime polymerase chain reaction (qPCR) assays to detect pathogens that cause SDS and other soilborne soybean pathogens using DNA extracted from the soil. qPCR-based diagnostics efficiently and specifically test for pathogens with high sensitivity. The soil was sampled from six fields under commercial soybean production in Deuel County and Brookings County. The collected soil was dried at ss·c for two days, and three DNA extractions were done for each field sampled. qPCR assays were performed on a BioRad CFX Opus 96 Real-Time PCR system for several soybean pathogens such as Fusarium virguliforme, Fusarium brasi/iense, Phytophthora sojae, Phytophthara sansomeana, and Phiolophora gregata. qPCR reactions were run in triplicate, with three technical replicates on each biological replicate per field assessed. The presence of P. gregata was detected in three out of the six fields evaluated, while F. virguliforme, F. brasiliense, P. sojae, and P. sansomena were not detected. Our primary objective was to develop distinct qPCR protocols on samples of DNA extracted directly from the soil for a more extensive SD soil borne soybean pathogen survey in Fall 2022 and Summer 2023. Providing SD soybean growers with accurate, timely information about pathogens detect ed in their soil should allow them to take proper management strategies and increase their yields.https://scholar.dsu.edu/erposters/1008/thumbnail.jp

    Assessing Commercial Biological Control Agents for Activity Against Alfalfa Root Rotting Pathogens

    Get PDF
    Alfalfa is the fourth most valuable crop in the United States and is widely grown as feed for livestock due to Its high protein content. According to the USDA 2021 Crop Production Summary, the United States planted 1,646,000 acres of newly seeded alfalfa, and alfalfa seedlings are highly susceptible to disease. Pathogens such as Aphanomyces euteiche.s and Pythium sp. have devastating effects on newly seeded alfalfa stands causing seed rot, reduced root development, and diminished stand establishment. Current management strategies for these diseases are fungicidal seed treatments and planting of disease resistant alfalfa varieties. To expand upon these management strategies, we investigated commercial biological control (biocontrol) treatments. Isolates of both A. euteiches and Pythium sp. were tested against commercial biocontrol agents with active ingredients such as: Streptomyces octinobacterium K61 {Mycostop), Bacillus amyloliquefociens D747 (Southern Ag), Srrepromyces lydicus WYEC 108 (Actinovate), Bacillus subrilis QST 713 (Minuet/Serenade), Trichoderma aspere/fum ICC012 and Trichodermo gamsii ICC080 (Tenet), and Trichodermo hawanum Rifai KRL-AG2 (RootShield). Biocontrol activity against A. euteiches and Pythium sp. was evaluated in growth chamber assays using a susceptible alfalfa variety, Saranac. Treatment effectiveness against A. ,uteiches was assessed by rating seedling roots using the NAAIC Standard Test rating scale of 1-5, with a score\u3e 2 indicating susceptibility. Seedlings in pots inoculated with Pythium sp. were counted after 5 days to calculate percent germination. Biological controls with the active ingredient, 8. amylolique/aciens 0747 have antagonistic effects ,gains! Pythium sp. increasing percent germination of alfalfa by 21-70% depending on the pathogen isolate. 5. 1ctinobacterium K6! (Mycostop) had high activity against A. euteiches. Several biological control agents demonstrated activity against both A. euteiches and Pythium sp., providing an additional management strategy against these root rotting pathogens.https://scholar.dsu.edu/erposters/1004/thumbnail.jp

    Privacy and Security Concerns Associated with MHealth Technologies: A Social Media Mining Perspective

    Get PDF
    mHealth technologies seek to improve personal wellness; however, there are stillsignificant privacy and security challenges. With social networking sites serving as lens through which public sentiments and perspectives can be easily accessed, little has been done to investigate the privacy and security concerns of users, associated with mHealth technologies, through social media mining. Therefore, this study investigated various privacy and security concerns conveyed by social media users, in relation to the use of mHealth wearable technologies, using text mining and grounded theory. In addition, the study examined the general sentiments toward mHealth privacy and security related issues, while unearthing how the various issues have evolved over time. Our target social media platform for data collection was the microblogging platform Twitter, which was accessed through Brandwatch providing access to the “Twitter firehose” to extract English tweets. Triangulation was conducted on a representative sample to confirm the results of the Latent Dirichlet Allocation (LDA) Topic Modeling using manual coding through ATLAS.ti. By using the grounded theory analysis methodology, we developed the D-MIT Emergent Theoretical Model which explains that the concerns of users can be categorized as relating to data management, data invasion, or technical safety issues. This model claims that issues affecting data management of mHealth users through the misuse of their data by entities such as wearable companies and other third-party applications, negatively impact their adoption of these devices. Also, concerns of data invasion via real-time data, security breaches, and data surveillance inhibit the adoption of mHealth wearables, which is further impacted by technical safety issues. Further, when users perceived that they do not have full control over their wearables or patient applications, then their acceptance of these mHealth technologies is diminished. While a lack of data and privacy protection policies contribute negatively to users’ adoption of these devices, it also plays a pivotal role in the data management issues presented in this emergent model. Therefore, the importance of having robust legal and policy frameworks that can support mHealth users is desired. Theoretically, the results support the literature on user acceptance of mHealth wearables. These findings were compared with extant literature, and confirmations found across several studies. Further, the results show that over time, mHealth users are still concerned about areas such as security breaches, real-time data invasion, surveillance, and how companies use the data collected from these devices. The findings reveal that more than 75% of the posts analyzed were categorized as depicting anger, fear, or demonstrating levels of disgust. Additionally, 70% of the posts exhibited negative sentiments, whereas 26% were positive, which indicates that users are ambivalent concerning privacy and security, notwithstanding mentions of privacy or security issues in their posts

    Fake News Detection on the Web: A Deep Learning Based Approach

    Get PDF
    The acceptance and popularity of social media platforms for the dispersion and proliferation of news articles have led to the spread of questionable and untrusted information (in part) due to the ease by which misleading content can be created and shared among the communities. While prior research has attempted to automatically classify news articles and tweets as credible and non-credible. This work complements such research by proposing an approach that utilizes the amalgamation of Natural Language Processing (NLP), and Deep Learning techniques such as Long Short-Term Memory (LSTM). Moreover, in Information System’s paradigm, design science research methodology (DSRM) has become the major stream that focuses on building and evaluating an artifact to solve emerging problems. Hence, DSRM can accommodate deep learning-based models with the availability of adequate datasets. Two publicly available datasets that contain labeled news articles and tweets have been used to validate the proposed model’s effectiveness. This work presents two distinct experiments, and the results demonstrate that the proposed model works well for both long sequence news articles and short-sequence texts such as tweets. Finally, the findings suggest that the sentiments, tagging, linguistics, syntactic, and text embeddings are the features that have the potential to foster fake news detection through training the proposed model on various dimensionality to learn the contextual meaning of the news content

    Fox in the Henhouse: The Delegation of Regulatory and Privacy Enforcement to Big Tech

    Get PDF
    The Federal Trade Commission (FTC) has ordered tech giants to police the app developers that use their platforms, requiring them to remove apps that employ deceitful sales tactics or violate consumer privacy. Tech giants have often resisted FTC orders to police the companies on their platforms because policing takes significant resources and diminishes profits. But some firms, after paying modest fines for neglecting enforcement, have eventually complied with FTC demands, removing predatory apps and banning problematic developers. Other firms have continued to shirk enforcement obligations at the risk of escalating fines. What accounts for the differences? Using process tracing to track decisions by Apple and Facebook, we find that tech giants willingly police consumer fraud but not consumer privacy violations. Failures to police fraud leads to public complaints and negative press attention, while failures to police data breaches often go undetected by consumers, the media, and thus the FTC

    998

    full texts

    1,393

    metadata records
    Updated in last 30 days.
    Beadle Scholar at Dakota State University
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇