Foster Multidisciplinary Approach

group_project

Visible to the public TWC SBE: Small: Building the human firewall: Developing organizational resistance to semantic security threats

Semantic attacks are efforts by others to steal valuable information by imitating electronic communications from a trustworthy source. A common example of a semantic attack is phishing where a phisher sends unsolicited messages to potential targets. When a targeted individual responds, the phisher then steals valuable information from the individual. Semantic attacks flow through established channels of communication (e.g., email, social media) and are difficult to distinguish from legitimate messages.

group_project

Visible to the public SBE: Small: The Force of Habit: Using fMRI to Explain Users' Habituation to Security Warnings

Warning messages are one of the last lines of defense in computer security, and are fundamental to users' security interactions with technology. Unfortunately, research shows that users routinely ignore security warnings. A key contributor to this disregard is habituation, the diminishing of attention due to frequent exposure. However, previous research examining habituation has done so only indirectly, by observing the influence of habituation on security behavior, rather than measuring habituation itself.

group_project

Visible to the public  EAGER: Age-Targeted Automated Cueing Against Cyber Social Engineering Attacks

Online social engineering attacks have been often used for cybercrime activities. These attacks are low cost and complicate attack attribution. Pure technical defense solutions cannot counter them, which rely on human gullibility. Humans often engage in short-cut decision-making, which can lead to errors. Another expectation is that users should be able to understand complex security tips, which do not consider user demographics. User age has been overlooked in understanding these attacks and user behavior related to them.

group_project

Visible to the public CRII: SaTC: Design, Implementation, and Analysis of Quantum-Resistant Algorithms on Smart Handheld Embedded Devices

The prospect of quantum computers is a threat against the security of currently used public key cryptographic algorithms. It has been widely accepted that, both public key cryptosystems including RSA and ECC will be broken by quantum computers employing certain algorithms. Although large-scale quantum computers do not yet exist, but the goal is to develop quantum-resistant cryptosystems in anticipation of quantum computers as most of the public key cryptography that is used on the Internet today is based on algorithms that are vulnerable to quantum attacks.

group_project

Visible to the public  EAGER: Digital Interventions for Reducing Social Networking Risks in Adolescents

Adolescents are at higher risk of engaging in risky behaviors in online social networks. This project develops digital intervention solutions to motivate, educate, support and engender safe social networking behaviors among adolescents. It significantly extends the current understanding of adolescent motivations for engaging in risky online behaviors and the state-of-the-art solutions for reducing adolescent exposure to such behaviors.

group_project

Visible to the public Breakthrough: Enhancing Privacy in Smart Buildings and Homes

The design of smart electric grids and buildings that automatically optimize their energy generation and consumption is critical to advancing important societal goals, including increasing energy-efficiency, improving the grid's reliability, and gaining energy independence. To enable such optimizations, smart grids and buildings increasingly rely on Internet-connected sensors in smart devices, including digital electric meters, web-enabled appliances and lighting, programmable outlets and switches, and intelligent HVAC systems.

group_project

Visible to the public Breakthrough: Collaborative: Secure Algorithms for Cyber-Physical Systems

Modern systems such as the electric smart grid consist of both cyber and physical components that must work together; these are called cyber-physical systems, or CPS. Securing such systems goes beyond just cyber security or physical security into cyber-physical security. While the threats multiply within a CPS, physical aspects also can reduce the threat space. Unlike purely cyber systems, such as the internet, CPS are grounded in physical reality.

group_project

Visible to the public TWC SBE: Medium: Context-Aware Harassment Detection on Social Media

As social media permeates our daily life, there has been a sharp rise in the use of social media to humiliate, bully, and threaten others, which has come with harmful consequences such as emotional distress, depression, and suicide. The October 2014 Pew Research survey shows that 73% of adult Internet users have observed online harassment and 40% have experienced it. The prevalence and serious consequences of online harassment present both social and technological challenges.

group_project

Visible to the public TWC: Medium: CRYPTOGRAPHIC APPLICATIONS OF CAPACITY THEORY

The primary goal of this project is to develop a mathematical foundation underlying the analysis of modern cryptosystems. Cryptography is a core tool used to secure communications over the Internet. Secure and trustworthy communications and data storage are essential to national security and to the functioning of the world economy. Recent spectacular research results have enabled the development of new types of cryptography, exciting new potential applications, and hopes for stronger guarantees of cryptographic security in the long term.

group_project

Visible to the public TWC SBE: Small: Collaborative: Brain Password: Exploring A Psychophysiological Approach for Secure User Authentication

Cryptographic systems often rely on the secrecy of cryptographic credentials; however, these are vulnerable to eavesdropping and can resist neither a user's intentional disclosure nor coercion attacks where the user is forced to reveal the credentials. Conventional biometric keys (e.g., fingerprint, iris, etc.), unfortunately, can still be surreptitiously duplicated or adversely revealed. In this research, the PIs argue that the most secure cryptographic credentials are ones of which the users aren't even aware.