1,721,034 research outputs found
Project Title: CYBEX Automation & Virtualization
The University of Nevada, Reno Libraries will promptly respond to removal requests related to content that violates intellectual property laws, data protections, or has been uploaded without creator consent. Takedown notices should be directed to our ScholarWolf team ([email protected]) with information about the object, including its full URL and the nature of your complaint.Cybersecurity is an issue that affects virtually everybody in the digital age. Attacks such as the Equifax breach or the Wannacry ransomware attack are becoming more and more commonplace and are becoming harder to defend against as attackers become more sophisticated. Many organizations that are breached are often entirely unaware of the breach until after it has occurred, or slow to react during the event. CYBEX is a project to help mitigate this. CYBEX is an automated cybersecurity response system designed to import and analyze log files from many organizations, develop defensive rules against an attack on any one of them, and send the solution out to all other members in order to stop attacks before they can spread. CYBEX primarily targeted at businesses in order to facilitate faster and more effective incident response. CYBEX was successful in testing at being able to securely disseminate security rules out to a group of computers and preemptively stop attacks against them
Integrity and Privacy Protection for Cyber-physical Systems (CPS)
The present-day interoperable and interconnected cyber-physical systems (CPS) provides significant value in our daily lives with the incorporation of advanced technologies. Still, it also increases the exposure to many security privacy risks like (1) maliciously manipulating the CPS data and sensors to compromise the integrity of the system (2) launching internal/external cyber-physical attacks on the central controller dependent CPS systems to cause a single point of failure issues (3) running malicious data and query analytics on the CPS data to identify internal insights and use it for achieving financial incentive. Moreover, (CPS) data privacy protection during sharing, aggregating, and publishing has also become challenging nowadays because most of the existing CPS security and privacy solutions have drawbacks, like (a) lack of a proper vulnerability characterization model to accurately identify where privacy is needed, (b) ignoring data providers privacy preference, (c) using uniform privacy protection which may create inadequate privacy for some provider while overprotecting others.Therefore, to address these issues, the primary purpose of this thesis is to orchestrate the development of a decentralized, p2p connected data privacy preservation model to improve the CPS system's integrity against malicious attacks. In that regard, we adopt blockchain to facilitate a decentralized and highly secured system model for CPS with self-defensive capabilities. This proposed model will mitigate data manipulation attacks from malicious entities by introducing bloom filter-based fast CPS device identity validation and Merkle tree-based fast data verification. Finally, the blockchain consensus will help to keep consistency and eliminate malicious entities from the protection framework. Furthermore, to address the data privacy issues in CPS, we propose a personalized data privacy model by introducing a standard vulnerability profiling library (SVPL) to characterize and quantify the CPS vulnerabilities and identify the necessary privacy requirements. Based on this model, we present our personalized privacy framework (PDP) in which Laplace noise is added based on the individual node's selected privacy preferences. Finally, combining these two proposed methods, we demonstrate that the blockchain-based system model is scalable and fast enough for CPS data's integrity verification. Also, the proposed PDP model can attain better data privacy by eliminating the trade-off between privacy, utility, and risk of losing information
Wireless Network Congestion Management Using Predictive Analytics
Wi-Fi Access Points (APs) deployed publicly are facing serious demands due tothe proliferation in Wi-Fi enabled devices. This becomes more prominent whenthe user crowd moves dynamically in space creating a sporadic usage pattern. Inorder to cater for the dynamically changing spectrum demands, we need to identifyareas with high spectrum usage that needs betterWi-Fi coverage. In this thesis,we aim to understand the dynamic spectrum usage over space, time and channels.The temporal and spatial analysis helps us to identify places that are highly congestedat any given time. The channel usage pattern determines channels that areover utilized and under utilized in the congested areas.The usage data from user devices can be analyzed to answer a number of possiblequestions in regards to congestion, access point load balancing, user mobilitytrends and efficient channel allocation. Using this data, we attempt to identifyWi-Fi usage trends in a dynamic environment and use it to further predict thecongestion in various locations. To accomplish this, we have used University ofNevada, Reno (UNR) to conduct our experiments where we use various supervisedlearning algorithms to find the existing patterns in spectrum usage insideUNR. Using these patterns, we predict the values for certain key attributes thatdirectly correlate to the congestion status of any location. Finally, we apply unsupervisedlearning algorithms to these predicted data instances to cluster them intodifferent groups. Each group will determine the level of congestion for any buildingat any time of any day. This way, we will be able to ascertain whether or notany place at any time in the future might require additional resources to be able todeliver wireless services efficiently.In an attempt to deliver wireless services in a resourceful manner, we also talkabout self-coexistence among networks where the secondary networks can accesslicensed bands without interfering with the primary networks. This technologyis referred to as dynamic spectrum access that allows the underutilized frequencybands to be used avoiding the need for additional resources. With all the secondarynetworks trying to access an available channel, there arises a game theoretic competitionwhere they want to get a channel for themselves by incurring as minimumcost/time as possible. We implement a predictive strategy in the networks forthem to land on an available channel in the shortest time possible minimizing thecollisions among themselves. Thus, we investigate various predictive algorithmsand observe how a self-learning approach can be helpful in maximizing utilities ofthe players in comparison to traditional game theoretic approaches
Smart Home or Smart Hell?: Modeling Smart Home IoT-Facilitated Abuse as a Cybersecurity Threat
Smart homes are just one application of IoT or the “Internet of Things.” As a solution to create a more automated “smart home” experience, users have the ability to control the temperature, or turn off their lights with a single command. However, smart home technology is vulnerable to unique cybersecurity and privacy issues due to the personal nature of user-device interactions. In addition, the multi-user environments in which IoT has been implemented has considerable social nuances which play a factor in interpersonal cybersecurity threats. Smart Home-IoT Facilitated Abuse (SH-IoTFA) is an alarming phenomenon of users weaponizing smart home technology as a tool to perpetrate “Intimate Partner Violence” (IPV) using the built-in, convenient features. Despite the emergence of research on SH-IoTFA, there is a need to implement greater consideration for potentially abusive affordances in the development process through an attacker-centric threat model framework. This thesis explores how Sh-IoTFA has emerged and evolved from traditional Technology- Facilitated Abuse (TFA) and demonstrates, through a thematic review of the current literature, how attacker motivations influence their relationship with a device, and in turn, transform seemingly innocuous convenience features into tools for surveillance, power exertion, and harassment. Furthermore, this thesis breaks down the relational aspect between the attacker’s motivations, the device features, and the assets at risk for a victim. Utilizing the threat scenario, the Google Nest Hub was then analyzed to identify how an abuse perpetrator may potentially misuse the device. Overall, through an integration of interdisciplinary perspectives, this research highlighted interpersonal threats as a cybersecurity concern and proposed a threat model that may reduce inadvertent harm to consumers
Blockchain Based Decentralized Applications & Trust Management for VANETs
Decentralized vehicular Ad-hoc Networks (VANETs), a promising technology to improve the Intelligent Transportation System (ITSs), face severe lagging in actual deployment and its extensive usage due to major unresolved issues such as security, data reliability, user privacy, and safe routing protocols. To overcome these issues, there is an urge to identify a platform that best suits VANET's easy deployment and usage in a decentralized fashion. In this regard, blockchain has received much attention as an emerging technology to provide better security on data sharing among many participants without an intermediary. This thesis aims to investigate blockchain technology's capability to secure vehicular data and vehicular node trust scores over a tamper-proof decentralized ledger that guarantees security, immutability, and accountability in Peer-to-Peer (P2P) networks such as VANET.Firstly, we explore how to leverage blockchain technology to design a specific application in the domain of decentralized VANETs, such as ride-sharing. We analyze the decentralized architecture for this application using smart contracts, and through experiments, we evaluate the costs associated with it. This framework serves as a basis for our further study to solve more challenging research problems in the consensus algorithm. The choice of a consensus algorithm directly affects the performance of a blockchain-based system in terms of transaction confirmation delays. In a VANET based on blockchain, the Proof of Work (PoW) and Proof of Stake (PoS) consensus might not be the best selection due to resource constraints and unfairness, respectively. In an attempt to improve consensus in a VANET application based on blockchain, we present the design of a novel consensus mechanism named Proof Of Driving for our previously presented ride-sharing application. We demonstrated that POD clubbed with a real-time service standard score protocol efficiently optimizes the number of miner nodes. The extensive experimental and security analyses presented on proposed consensus and service standard protocols demonstrate the effectiveness, security, and feasibility of miner node selection. However, VANET is not secure as vehicular communication is critically vulnerable to several kinds of active and passive routing protocol attacks. The most severe attack in routing is the Black Hole attack, which deteriorates the network's performance by dropping or misusing the intercepted data packets without forwarding them to the correct destination. This greatly hinders the application availability. Hence in the final chapter of this thesis, we experiment by incorporating trust models in VANET routing protocols to achieve a more efficient packet forwarding process. The results showed an improved packet delivery ratio and throughput of the entire network. The trust model should be able to resist various attacks and preserve the privacy of vehicles simultaneously. Hence we presented how to leverage consortium blockchain to secure vehicles' trust scores and distribute node trust in a decentralized network more efficiently. We evaluated the trust score aggregation process by the authorized RSUs, the time consumed for consensus, and updated trust score distribution. The results showed that the blockchain-based trust management provides an effective trust model for VANETs with transparency, conditional anonymity, efficiency, and robustness while efficiently eliminates the black hole nodes
Analysis of Failed SSH Attempts for Intrusion Detection
SSH brute force attacks remain among the most common attack types in computer systems. Recent threat analysis reports consistently highlight their prevalence as a top web security vulnerability. Various passive and active methodologies have been developed to deal with this problem, each with its unique set of advantages and disadvantages. Amongst all, analysis of monitoring logs is important to understand the root cause of the problem and implementing necessary countermeasures. Hence, this thesis focus on implementing automated intrusion detection solutions by analyzing historical failed SSH attempts. The data is captured between March 2022 and June 2022 from a server located at University of Nevada, Reno (UNR) campus. We first present thorough analysis of the dataset understand common patterns in the dataset such as origin of IP addresses, usernames, and time of SSH attempts. We identified various types of attack patterns, including slow, steady, and stealthy ones. Since the logs contain both benign and malicious attempts, we utilized external databases (e.g., IPWHOIS and ABUSEIPDB) to classify them as malicious or not, which served as a training data for machine learning models. We developed several machine learning models to categorize SSH attempts as malicious or benign. The models relied on several features including username, time difference of the attacks, the number of previous attempts, and similarity of IP addresses. We trained Random Forest, Decision Tree, XGBoost, SVM, and Logistic Regression models to evaluate their performance. The Decision Tree model exhibited the best performance, achieving 100% precision and a recall rate of 97.9%. In comparison, the best performed rule-based formulation failed to identify 1.5% malicious IPs whereas the Decision Tree model only missed 0.01%. We also validated the results against the public datasets. We noticed that the proposed model detected five malicious IP addresses before they appear in public databases such as ABUSEIPDB, which is a promising result for the proposed model
Real-Time Inference of Topological Structure and Vulnerabilities for Adaptive Jamming Against Covert Ad Hoc Networks
With the emerging reliance of critical communications on ad hoc architectures, ensuring the security of such networks is paramount. Even though the independence of ad hoc networks from a single point of failure is seen as an advantage, the distributed nature of ad hoc communications introduces a variety of complex security problems. These problems are further intensified in mission critical networks deployed in hostile environments such as modern battlefields, where analysis and disruption of opponents' wireless communications is an essential component of combat. Therefore, resilience of network connectivity to disruption and concealment of communications is a priority in design of critical ad hoc networks. To this end, various techniques have been proposed for mitigation of disruptive attacks, the majority of which focus on routing and upper layers of the protocol stack, while very few consider implementing mitigation in the physical and link layers.This thesis aims at demonstrating the vulnerability of covert ad hoc networks to adaptive jamming attacks that rely only on physical layer parameters. A novel transmission timing analysis technique is proposed to estimate the existence of hop-to-hop links based on the synchronicity of transmission timings in both time and frequency domains, complemented with a minimal thresholding method for classification of link estimations. Furthermore, this work proposes a computationally efficient method for identification of the most vulnerable region of the network via graph theoretical modeling. The computational cost of this method is further reduced by employment of a fast search space generation algorithm, as well as percolation modeling of the system. Both methods are shown to increase the efficiency of adaptive jamming when no a priori information about the topology or protocols of the network is available. Performance of the proposed methods is measured through graph theoretical and network simulations
Going Beyond Counting First Authors in Author Co-citation Analysis
The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation
counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings
are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that
only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into
account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed
A Game Theoretic Approach Applied in k- Anonymization for Preserving Privacy in Shared Data
Privacy preservation is one of the greatest concerns when data is shared between different organizations. On the one hand, releasing data for research purposes is inevitable. On the other hand, sharing this data can jeopardize users' privacy. An effective solution, for the sharing organizations, is to use anonymization techniques to hide the users' sensitive information. One of the most popular anonymization techniques is k-Anonymization in which any data record is indistinguishable from at least k-1 other records. However, one of the fundamental challenges in choosing the value of k is the trade-off between achieving a higher privacy and the information loss associated with the anonymization. In this work, the problem of choosing the optimal anonymization level for k-anonymization, under possible attacks, is studied when multiple organizations share their data to a common platform which is data collector (Cybex) in this case. In particular, we have considered two common types of attacks, namely, Homogeneity attack and Background knowledge attack, which have the capability of compromising k-anonymization technique. To this end, a novel game-theoretic framework is proposed to model the interactions between the sharing organizations and the attacker along with contract theoretic framework to model interactions between organizations and data collector (Cybex). The problem is first formulated as a static game and its different Nash equilibria solutions are analytically derived. Later, we have used a contract theoretic model on interactions between data collector (Cybex) and the organizations. We also show how data collector varies the rewards of the organizations to increase it's utility over the stages
- …
