Pub Crawl summarizes, by hard problems, sets of publications that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers. Select the topic name to view the corresponding list of publications. Submissions and suggestions are welcome.
A covert channel is a simple, effective mechanism for sending and receiving data between machines without alerting any firewalls or intrusion detectors on the network. In cybersecurity science, they have value both as a means for defense and attack. For the Science of Security community, this work is relevant to the hard problems of resilience, scalability and compositionality.
Ciphertext Policy Attribute Based Encryption (CP-ABE) techniques provide fine grained access control to securely share organizational data where role-based access rights are in use. For the Science of Security community, CP-ABE is related to policy-based governance and scalability.
CPS Modeling and Simulation 2021
Modeling and simulation of Cyber-physical systems is a way to develop resiliency, composability, and predictive metrics in a laboratory environment and then test against their algorithms against real world situations. The challenge, of course, is to develop models and simulations that are accurate and reliable.
The research work cited here looks at the Science of Security hard problem of human factors and privacy in the context of cyber physical systems.
The research work cited here looks at the Science of Security hard problem of resiliency in the context of cyber physical systems.
Cross Layer Security 2021
Protocol architectures traditionally followed strict layering principles to ensure interoperability, rapid deployment, and efficient implementation. But a lack of coordination between layers limits the performance of these architectures. More important, the lack of coordination may introduce security vulnerabilities and potential threat vectors. For the Science of Security community, this work is relevant to the problems of resiliency and composability.
Cross Site Scripting 2021
A type of computer security vulnerability typically found in Web applications, cross-site scripting (XSS) enables attackers to inject client-side script into Web pages viewed by other users. Attackers may use a cross-site scripting vulnerability to bypass access controls such as the same origin policy. Consequences may range from petty nuisance to significant security risk, depending on the value of the data handled by the vulnerable site and the nature of any security mitigation implemented by the site's owner. A frequent method of attack, research is being conducted on methods to prevent, detect, and mitigate XSS attacks. For the Science of Security community, this work is relevant to the hard problems of human behavior, scalability, and resilience.
The ability to assess damage accurately and quickly is critical to resilience.
The Dark Web, or Darknet, is a subset of the deep web that is not indexed and requires something special to access it. Much of the activity on it is extra- or illegal, pornographic, or otherwise unseemly. For the Science of Security community, understanding of the activities on the Dark Web related to human behavior issues.
Data deletion has many implications for security and for data structures. For the Science of Security community, the problem has implications for privacy and scalability.
For security researchers, privacy protection during data mining is a major concern. Sharing information over the Internet or holding it in a database requires methods of sanitizing data so that personal information cannot be obtained. For the Science of Security community, this work is relevant to human behavior and privacy, resilience, and compositionality.
DDOS Attack Detection 2021
Distributed Denial of Service Attacks continue to be among the most prolific forms of attack against information systems. Detection is a key step in dealing the problem. For the Science of Security community, this research is related to the problems of resilience, composability, metrics, and human behavior.
DDOS Attack Mitigation 2021
Distributed Denial of Service Attacks continue to be among the most prolific forms of attack against information systems. Mitigation is a key step in dealing the problem. For the Science of Security community, this research is related to the problems of resilience, composability, metrics, and human behavior.
DDOS Attack Prevention 2021
Distributed Denial of Service Attacks continue to be among the most prolific forms of attack against information systems. Prevention is the first step in dealing the problem. For the Science of Security community, this research is related to the problems of resilience, composability, metrics, and human behavior
Science of Security 2020
Many more articles and research studies are appearing with “Science of Security” as a keyword. The articles cited here discuss the degree to which security is a science and various issues surrounding its development, ranging from basic approach to essential elements. The articles cited here address the fundamental concepts of the Science of Security.
Scientific Computing Security 2021
Scientific computing is concerned with constructing mathematical models and quantitative analysis techniques and using computers to analyze and solve scientific problems. As a practical matter, scientific computing is the use of computer simulation and other forms of computation from numerical analysis and theoretical computer science to solve specific problems such as cybersecurity. For the Science of Security community, it relates to predictive metrics, compositionality, and resiliency.
Software Defined Network (SDN) architectures have been developed to provide improved routing and networking performance for broadband networks by separating the control plain from the data plain. This separation also provides opportunities and challenges for SDN as a security element in IoT and cyberphysical systems. For the Science of Security community, it is relevant to scalability and resiliency.
Searchable Encryption 2021
Searchable encryption allows one to store encrypted data externally, but still allow for easy data searches that do not require the search to download everything before decrypting and to allow others to search data without having access to plaintext. As an application, it is becoming increasingly important in the Cloud environment. For the Science of Security community, it is an area of research related to cryptography, resilience, and composability.
Secure File Sharing 2021
Data leakage while file sharing continues to be a major problem for cybersecurity, especially with the advent of cloud storage. Secure file sharing is relevant to the Science of Security community hard topics of resilience, composability, metrics, and human behavior.
The ability to conduct automated security audits rapidly and accurately helps to reduce the time between attack and its detection, hopefully reducing the consequences of the attack. Research into security audit methods and techniques supports addressing the hard problem of human behavior, as well as resiliency and scalability.
Security Heuristics 2021
Heuristic analysis is a method employed by many computer antivirus programs designed to detect “Zero Day” or previously unknown computer viruses and new variants of viruses already “in the wild." It is an expert-based analytic method that uses various decision rules or weighing methods. For the Science of Security community, it is relevant to the hard problems of resilience, scalability, and predictability.
Measurement and metrics are one of the five hard problems in the Science of Security.
Policy-based access controls and security policies are intertwined in most commercial systems. Analytics use abstraction and reduction to improve policy-based security. For the Science of Security community, policy-based governance is one of the five Hard Problems.
Security Risk Estimation 2021
Calculating risk in cyberphysical systems is a complex process. The work cited here approaches the problem relative to the Science of Security hard problems of human factors, scalability, resilience, and metrics.
Security Scalability 2021 (all)
Scalability, along with compositionality, is one of the five hard problems for the Science of Security community.
Security Weaknesses 2021
Attackers need only find one or a few exploitable vulnerabilities to mount a successful attack while defenders must shore up as many weaknesses as practicable. The research presented here covers a range of weaknesses and approaches for identifying and securing against attacks. Many articles focus on key systems, both public and private. Hard problems addressed include human behavior, policy-based governance, resilience and metrics.
Research into the use of malware signatures to inform defensive methods is a standard research exercise for the Science of Security community. This work addresses issues related to scalability and resilience.
Signature Based Defense 2021
Signal Processing Security 2021
Broadly speaking, signal processing covers signal acquisition and reconstruction, quality improvement, signal compression and feature extraction. Each of these processes introduces vulnerabilities into communications and other systems. The research articles cited here explore trust between networks, steganalysis, tracing passwords across networks, and certificates. They address the Science of Security hard problems related to privacy, resilience, metrics, and composability.
Pub Crawl contains bibliographical citations, abstracts if available, links on specific topics, and research problems of interest to the Science of Security community.
How recent are these publications?
These bibliographies include recent scholarly research on topics that have been presented or published within the stated year. Some represent updates from work presented in previous years; others are new topics.
How are topics selected?
The specific topics are selected from materials that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are also chosen for their usefulness for current researchers.
How can I submit or suggest a publication?
Researchers willing to share their work are welcome to submit a citation, abstract, and URL for consideration and posting, and to identify additional topics of interest to the community. Researchers are also encouraged to share this request with their colleagues and collaborators.
What are the hard problems?
- Scalability and Composability: Develop methods to enable the construction of secure systems with known security properties from components with known security properties, without a requirement to fully re-analyze the constituent components.
- Policy-Governed Secure Collaboration: Develop methods to express and enforce normative requirements and policies for handling data with differing usage needs and among users in different authority domains.
- Security Metrics Driven Evaluation, Design, Development, and Deployment: Develop security metrics and models capable of predicting whether or confirming that a given cyber system preserves a given set of security properties (deterministically or probabilistically), in a given context.
- Resilient Architectures: Develop means to design and analyze system architectures that deliver required service in the face of compromised components.
- Understanding and Accounting for Human Behavior: Develop models of human behavior (of both users and adversaries) that enable the design, modeling, and analysis of systems with specified security properties.