Several challenges exist in disseminating multi-level secure (MLS) data in multi-domain environments. First, the security domains participating in data dissemination generally use different MLS labels and lattice structures. Second, when MLS data objects are transferred across multiple domains, there is a need for an agreed security policy that must be properly applied, and correctly enforced for the data objects. Moreover, the data sender may not be able to predetermine the data recipients located beyond its trust boundary. To address these challenges, we propose a new framework that enables secure dissemination and access of the data as intended by the owner. Our novel framework leverages simple public key infrastructure and active bundle, and allows domains to securely disseminate data without the need to repackage it for each domain.
In response to the dynamic and ever-evolving landscape of network attacks and cybersecurity, this study aims to enhance network security by identifying critical nodes and optimizing resource allocation within budget constraints. We introduce a novel approach leveraging node centrality scores from four widely-recognized centrality measures. Our unique contribution lies in converting these centrality metrics into actionable insights for identifying network attack probabilities, providing an unconventional yet effective method to bolster network robustness. Additionally, we propose a closed-form expression correlating network robustness with node-centric features, including importance scores and attack probabilities. At the core of our approach lies the development of a nonlinear optimization model that integrates predictive insights into node attack likelihood. Through this framework, we successfully determine an optimal resource allocation strategy, minimizing cyberattack risks on critical nodes while maximizing network robustness. Numerical results validate our approach, offering further insights into network dynamics and improved resilience against emerging cybersecurity threats.
Despite the heightened popularity of entrepreneurship education, there remain open questions regarding best practices in co-curricular programs. Using the theory of planned behavior, the authors examine how students' intention is shaped to increase the likelihood of participation in entrepreneurship co-curricular programs. To the best of the authors' knowledge, this study is the first to examine the relation between entrepreneurial identity and entrepreneurial intention theory. They find the popular personality trait, openness, is related to ambition, which reveals the interaction between personal elements (personality/identity) and contextual elements (aspirations to success/intention), a novel finding in the literature. This further illustrates the interconnectedness between the theory of planned behavior and the entrepreneurial event model
We describe different approaches taken to teaching security labs at ECPI University (ECPI), University of Maryland University College (UMUC) and Western Michigan University (WMU).These three approaches are then compared in various perspectives such as the type of the educational institution offering them; the lab platform, its accessibility and performance; instructional support and materials; software installation and configuration effort; as well as cost and implementation issues. We believe that an academic institution designing and building a security lab would benefit from reviewing our comparison and examining all three approaches: a pure virtual lab at UMUC, the traditional physical computing lab at WMU, and a hybrid approach at ECPI University. Selecting the appropriate deployment model should then be based on the individual institutional requirements. In addition, we briefly present the challenges we faced and lessons we learned while integrating security labs into the curriculum. Finally, we provide our rationale and conclude that security labs should be an essential part of the curriculum.
The purpose of this panel is to provide a forum to discuss the main IT security issues confronting organizations today. The panelists and attendees will discuss the existing gap between current IT security practices vs. best practices based on survey trends on IT security for the past 5 years, explore popular models used to justify IT security investments, and showcase some of the most popular hacking tools to demonstrate why it is so easy to compromise organizational IT security assets. The panel will conclude by discussing the emerging IT security standards and practices that may help deter, detect, and mitigate the impact of cyber-attacks. As the title suggests, we posit the question: Is Managing IT Security a Mirage?
In this paper the authors describe their experience of designing a virtual lab architecture capable of providing hundreds of students with a hands on learning experience in support of an online educational setting. The authors discuss alternative approaches of designing a virtual lab and address the criteria in selecting the optimal deployment method. The authors conclude that virtualization offers a significant instructional advantage in delivering a cost effective and flexible hands on learning experience.
In this paper, the authors describe their experience of designing a virtual lab architecture capable of potentially providing thousands of students with a hands-on learning experience in support of an online educational offering.The authors discuss alternative approaches of designing a virtual lab and address the criteria in selecting the optimal deployment method.The authors suggest that virtualization offers a significant instructional advantage in delivering a cost effective and flexible hands-on learning experience.
We view Multi-Level Secure (MLS) real-time systems as systems in which MLS real-time tasks are scheduled and execute, according to a scheduling algorithm employed by the system. From this perspective, we develop a general trace-based framework that can carry out a covert-timing channel analysis of a real-time system. In addition, we propose a set of covert-timing channel free policies: If a system satisfies one of our proposed security policies, we demonstrated that the system can achieve a certain level of real-time information flow security. Finally, we compare the relative strength of the proposed covert-timing channel free security policies and analyze whether each security policy can be regarded as a property (a set of execution sequences).
Mathematical analysis of possible covert timing channels is a requirement for certification of high assurance Multi-Level Secure (MLS) systems. In this dissertation, we present a mathematical approach for analysis of covert timing channels in MLS real-time systems. This approach includes an analytical model which can specify the types of real-time tasks running, the real-time scheduling algorithm in use, and real-time constraints imposed on task executions. Using this analytical real-time system model, we characterize timing vulnerabilities present in real-time systems, present a methodology for measuring covert timing channel capacity, and devise countermeasures to remove or mitigate the impact of covert timing channels. Finally, we present a precise mathematical model for evaluating how performance overhead/delays of real-time systems vary with respect to the different degrees of security measures being applied.
Cryptographic communication protocols frequently employ random numbers to achieve desirable properties. Often, generators for pseudo-random numbers (PRNGs) are employed. A class of PRNGs that currently gains popularity are chaotic PRNGs which are derived ...
Joon Son and Jim Alves-FossCenter for Secure and Dependable SystemsUniversity of IdahoPOBOX 441008 Moscow, ID 83844-1008email: [son2320,jimaf]@uidaho.eduABSTRACTReal-time systems must satisfy timing constraints. In ourprevious work, we showed that a covert timing channelcannot be completely closed in some system configura-tions due to the timing constraints imposed by the Rate-Monotonic (RM) real-time scheduling algorithm. In thispaper, we construct a probabilistic model to measure twoquantities of a covert timing channel in RM based systems:channel capacity and quantity of specific information. Weshow how these two metrics can be calculated from ourprobabilistic model and why they are useful metrics in eval-uation of a covert (timing) channel.KEYWORDSCovert timing channel capacity, quantity of specific infor-mation, Rate-Monotonic scheduling.
The modern digital battlesphere requires the development and deployment of multi-level secure computing systems and networks. A portion of these systems are necessarily be operating under real-time processing constraints. High assurance systems processing national security information must be analyzed for possible information leakages, including covert channels. In this paper we provide a mathematical framework for examining the impact the rate-monotonic real-time scheduling algorithm has on covert timing channels. We prove that in some system configurations, it would not be possible to completely close the covert channel due to the rate-monotonic timing constraints. In addition, we propose a simple method to formulate a security metric to compare covert channels in terms of the relative amount of possible information leakage
Lotfi Ben Othmane合作论文数Laboratory for Quality Software (Laquso),
Department of Mathematics and Computer Science,
Eindhoven University of Technology2