Proceedings of the International Conference on Cybersecurity, Situational Awareness and Social Media: Cyber Science 2022; 20–21 June; Wales
Book information
Description
This book highlights advances in Cyber Security, Cyber Situational Awareness (CyberSA), Artificial Intelligence (AI) and Social Media. It brings together original discussions, ideas, concepts and outcomes from research and innovation from multidisciplinary experts. It offers topical, timely and emerging original innovations and research results in cyber situational awareness, security analytics, cyber physical systems, blockchain technologies, machine learning, social media and wearables, protection of online digital service, cyber incident response, containment, control, and countermeasures (CIRC3). The theme of Cyber Science 2022 is Ethical and Responsible use of AI. Includes original contributions advancing research in Artificial Intelligence, Machine Learning, Blockchain, Cyber Security, Social Media, Cyber Incident Response & Cyber Insurance. Chapters “Municipal Cybersecurity―A Neglected Research Area? A Survey of Current Research", "The Transnational Dimension of Cybersecurity: The NIS Directive and its Jurisdictional Challenges" and "Refining the Mandatory Cybersecurity Incident Reporting under the NIS Directive 2.0: Event Types and Reporting Processes” are available open access under a Creative Commons Attribution 4.0 International License via link.springer.com. Cyber Science 2022 Committee Preface Sponsors and Partners Keynote and Industry Panel Speakers Contents Contributors Cyber Threat Intelligence, Ransomware Datasets and Attack Detection Practical Cyber Threat Intelligence in the UK Energy Sector 1 Introduction 2 Background 2.1 Barriers to CTI Sharing 2.2 Current CTI Sharing in the UK Energy Sector 2.3 Evaluation of Sharing Methods and Platforms 3 Methodology 3.1 Experimental Configuration 3.2 CTI Sharing Models 3.3 Tags and Taxonomies 3.4 Sharing in MISP 4 Verifying Sharing Models 4.1 Source and Subscriber 4.2 Hub and Spoke 4.3 Peer to Peer 4.4 Hybrid 5 Verifying Taxonomies—Events and Tags 6 Discussion 7 Conclusions 7.1 Future Work References A Free and Community-Driven Critical Infrastructure Ransomware Dataset 1 Introduction 2 Ransomware Datasets 2.1 Strain-Based Ransomware Datasets 2.2 Detection-Based Ransomware Datasets 2.3 Payment-Based Ransomware Datasets 2.4 The Need for a Critical Infrastructure Ransomware Dataset 3 Critical Infrastructure Ransomware Dataset 3.1 Obtain 3.2 Scrub 3.3 Explore 3.4 Limitations 3.5 Dataset Format, Hosting, and Usage Tracking 4 Requesters and Dataset Use 4.1 Industry 4.2 Government 4.3 Educators 4.4 Students 4.5 Journalists/reporters 5 Incorporating Recommendations to Make the Dataset Community-Driven 5.1 Recommendation 1: Document Modifications (V10.1, August 2020) 5.2 Recommendation 2: MITRE ATT&CK Mapping (V10.1, August 2020) 5.3 Reporting Missing Incidents and the Contributors Tab (V10.4, Oct 2020) 6 Conclusion 6.1 Recommendations that Could not Be Accommodated References Criteria for Realistic and Expedient Scenarios for Tabletop Exercises on Cyber Attacks Against Industrial Control Systems in the Petroleum Industry 1 Introduction 2 Background 2.1 Scenario Development 2.2 Characteristics of a Scenario 2.3 Characteristics of a Tabletop Exercise 3 Method 4 Results 4.1 Interview Findings 4.2 List of Criteria 4.3 Example Scenarios 5 Discussion 6 Conclusion References CERTs and Maritime Cybersecurity Exploring the Need for a CERT for the Norwegian Construction Sector 1 Introduction 2 Background 2.1 Challenges Specific to the Construction Sector 2.2 Working Method and Analytical Framework 2.3 Limitations 3 National Frameworks for ICT Security 3.1 Framework for Handling ICT Security Incidents 3.2 Sectoral Response Units 3.3 ICT Security Units (CERT) 3.4 International Collaboration Forums 4 Results from Interviews 4.1 Vulnerabilities 4.2 Incident Management 4.3 Challenges Facing the Industry 4.4 Sector CERT 5 Summary and Conclusions 5.1 The Needs of the Industry 5.2 Organization of an ISAC References Holistic Approach of Integrated Navigation Equipment for Cybersecurity at Sea 1 Introduction 2 Architecture of the System 3 Methodology for Data Collection 4 Conclusion References Building Maritime Cybersecurity Capacity Against Ransomware Attacks 1 Introduction 2 Related Work 3 Profiling Ransomware Attacks in the Maritime Domain 3.1 Analysis of Recent Ransomware Cases 3.2 Attack Methodology 4 Situation—Aware Training Curriculum: Design Directions 4.1 Audience and Scope 4.2 Learning Objectives 4.3 Learning Content and Pedagogy 5 Training Platform 5.1 High-Level Architecture 5.2 Example of a Training Scenario 6 Conclusions References Cyber Situational Awareness Applications A Decade of Development of Mental Models in Cybersecurity and Lessons for the Future 1 Introduction 2 Folk Metaphors and Formal Models 2.1 Folk Models 2.2 Formal Models 3 Interface Design and Perceptions of Security 3.1 Interface Design 3.2 Perceptions of Security 4 Mental Models in Specific Cybersecurity Domains 4.1 Platform 4.2 Technology 4.3 Type of User 4.4 Social Factors 4.5 Tools 4.6 Applications 5 Discussion 6 Conclusions References Exploring the MITRE ATT&CK® Matrix in SE Education 1 Introduction 2 Adversarial Frameworks 2.1 MITRE ATT&CK 3 ATT&CK Mapping Project 3.1 Cybercrime Class Overview 3.2 Project Description 4 Results 4.1 Part 1 (Sub)Techniques Identified and Excerpt Evidence 4.2 Mapping Ratios, Indications, Redesign 5 Discussion 5.1 Lessons Learned 5.2 ATT&CK Matrix Revisions and Extensions 5.3 Biases 5.4 Limitations 6 Conclusion References Municipal Cybersecurity—A Neglected Research Area? A Survey of Current Research 1 Introduction 1.1 Research Motivation 2 Methodology 2.1 Selection of Studies 2.2 Inclusion and Exclusion Criteria 2.3 Search Results and Reduction Process 3 Literature Review 3.1 Smart Cities 3.2 Operational Technology 3.3 Elections 3.4 Human Issues and Cybersecurity Awareness 3.5 Crisis Management 3.6 Management and Governance 3.7 Municipal Technology 3.8 Research Methods 4 Discussion 4.1 Thematic Contributions 4.2 Identified Gaps and Need for Research 5 Conclusion References Novel and Emerging Cyber Techniques Near-Ultrasonic Covert Channels Using Software-Defined Radio Techniques 1 Introduction 2 Background 2.1 Related Work 3 Methodology 3.1 Implementation 3.2 Channel Bandwidth 3.3 Testing 4 Results 4.1 Results at 18 kHz 4.2 Results at 20 kHz 4.3 Results at 22 kHz 5 Discussion 5.1 Input Devices 5.2 Output Devices 5.3 Observations 5.4 Countermeasures 6 Conclusion 7 Future Work References A Preventative Moving Target Defense Solution for Web Servers Using Iptables 1 Introduction 2 Prior Work 3 Threat Model and Assumptions 4 Methodology 4.1 Design Overview 4.2 Implementation 4.3 Restrictions 4.4 Testing 4.5 Hardware Platforms Used 5 Understanding the Performance 5.1 Iptables Live Modification 5.2 Website Performance Is Degraded 5.3 DIM Temporarily Impacts Performance When Switching Between Web Servers 5.4 Fingerprinting Accuracy Is Decreased as the Frequency of DIM Rotation Increases 6 Discussion 6.1 Modifying Iptables Rules 6.2 Performance Observation 6.3 Security Observation 6.4 Challenges and Future Work 7 Conclusions References Hardening Containers with Static and Dynamic Analysis 1 Introduction 2 Review of Literature 2.1 Background on Container Technology 2.2 Container Security 2.3 Hardening of Containers 2.4 Threat Models 2.5 Rule-Based Security Monitoring of Containers 2.6 Software Protection Mechanisms 2.7 Static Analysis 2.8 Dynamic Analysis 3 Approach 3.1 Static Analysis 3.2 Dynamic Analysis 4 Findings and Analysis 4.1 Static Analysis 4.2 Dynamic Analysis 4.3 Hardening Policy 5 Limitations 6 Conclusion 7 Future Scope References Efficient Cyber-Evidence Sharing Using Zero-Knowledge Proofs 1 Introduction 2 Previous Work 2.1 Traditional Cyber-Evidence Sharing Approaches 2.2 The Fiat-Shamir ZKP Scheme 3 Design 3.1 Merkle-Trees 3.2 ZKP 3.3 Protocol 4 System Implementation and Evaluation 4.1 Implementation 4.2 Fiat-Shamir Identity Scheme Performance 4.3 Merkle Tree Performance 4.4 Subset Data Verification 5 Related Work 6 Conclusion References Artificial Intelligence Applications Uncertainty and Risk: Investigating Line Graph Aesthetic for Enhanced Cybersecurity Awareness 1 Introduction 2 Cybersecurity Awareness and Data Visualisation 2.1 How to Improve Cybersecurity Awareness? 3 Visualising Uncertainty in Data 3.1 Risk and Uncertainty in Cybersecurity 4 Study 5 Findings and Discussion 6 Conclusions 7 Future Work References An Explainable AI Solution: Exploring Extended Reality as a Way to Make Artificial Intelligence More Transparent and Trustworthy 1 Introduction 2 Explainable AI and Methods 3 Extended Reality for Collaboration 4 Augmented and Virtual Reality: Affordances for Transparency and Trustworthiness 5 Development of the XAI XR Solution 5.1 Solution Functionality 5.2 Development of the Web Application 5.3 Development of the VR Environment 6 Solution Evaluation 6.1 Focus Group Study 6.2 Video Presentation Study 6.3 Discussion 7 Recommendations 8 Conclusion References A Study on the Development of Crisis Management Compliance by Personal Information Infringement Factors in Artificial Intelligence Service 1 Introduction 2 Overview of Personal Information Infringement Factors and Risk Management Compliance 2.1 Cases of Personal Information Infringement Incidents 2.2 Crisis Management System to Response to Personal Information Infringement 3 Framework and Method of Research 4 Factors of Personal Information Infringement in AI Service and Method of Calculating Infringement Response 4.1 Composition of Personal Information Infringement Factors 4.2 Calculation Method of Personal Information Infringement Risk in AI Service 4.3 Simulation of Estimating and Responding to the Risk of Infringement of Personal Information 4.4 Personal Information Protection Matters of Response to Personal Information Infringement 5 Conclusion References Multidisciplinary Cybersecurity—Journalism and Legal Perspectives Threats to Journalists from the Consumer Internet of Things 1 Introduction 2 Related Work 2.1 IoT and Journalism Threat Modelling 2.2 IoT Privacy Threats 2.3 IoT Material Threats 3 Methods 3.1 Research Questions 3.2 Literature Synthesis 3.3 Analysis 3.4 Category Creation 3.5 Threat Modelling 4 Categorisation 4.1 Regulatory Gaps 4.2 Legal Threats 4.3 Profiling Threats 4.4 Tracking Threats 4.5 Data and Device Modification Threats 4.6 Networked Devices Threats 5 Discussion 5.1 What Are the Distinctive and Novel Threats to Journalism from the Consumer IoT? 5.2 How Can We Categorise These Threats in a Way That Is Easily Comprehensible by Journalists? 5.3 Challenging Areas and Known Unknowns 5.4 Future Work 6 Conclusion References The Transnational Dimension of Cybersecurity: The NIS Directive and Its Jurisdictional Challenges 1 Introduction 2 The Jurisdictional Regime of the NIS Directive 2.1 Regulatory Jurisdiction Over Operators of Essential Services (OES) 2.2 Regulatory Jurisdiction Over Digital Service Providers (DSPs) 3 The Jurisdictional Regime of the NIS 2 Proposal 3.1 Negotiations Between Co-legislators 3.2 Stakeholder Consultations 4 A Comparative Review of Other One-Stop-Shop Mechanisms Based on ‘Main Establishment’ 4.1 The GDPR One-Stop-Shop Mechanism 4.2 The DSA Proposal One-Stop-Shop Mechanism 5 Recapitulation and Concluding Remarks References Refining the Mandatory Cybersecurity Incident Reporting Under the NIS Directive 2.0: Event Types and Reporting Processes 1 Introduction 2 Reporting Obligations from NIS Directive to NIS 2.0 Proposal 2.1 Reporting Framework Under the NIS Directive 2.2 Reporting Framework Under the NISD 2.0 Proposal 2.3 The European Parliament’s Position on the Reporting Framework Envisaged Under the NISD 2.0 Proposal 2.4 The European Council’s Compromise on the Reporting Framework Envisaged Under the NISD 2.0 Proposal 2.5 How the NISD 2.0 Proposal Responds to the Flaws of the NISD 3 Conclusion References Multidisciplinary Cybersecurity—Healthcare, IoT and National Perspectives Assessing Cyber-Security Readiness of Nigeria to Industry 4.0 1 Introduction 2 Review of Related Works 3 Industry 4.0 and Cyber-Security 3.1 Threat Sophistication, Landscapes and Industry 4.0 3.2 Cyber-Attack Sophistication: AI-Based Attacks 3.3 Cyber-Attack Sophistication: Bio-inspired Attacks 4 Intangible Assets and Knowledge-Based Economy of Industry 4.0 5 Education Curriculum and Industry 4.0 6 Method and Survey Materials 7 Analysis, Results and Discussions 8 Conclusion and Recommendations Appendix References Case Studies in the Socio-technical Analysis of Cybersecurity Incidents: Comparing Attacks on the UK NHS and Irish Healthcare Systems 1 Introduction 2 The STAMP Approach on the NHS WannaCry Cyberincident 3 The STAMP Approach on the Irish Healthcare Cyberincident 4 Common Areas of Concerns and Difference Between Case Studies 5 STAMP Control Structures for Flaws in Case Studies 6 Integrating NIST Control Taxonomies to STAMP Approach 7 Conclusions References A Study on the Impact of Gender, Employment Status, and Academic Discipline on Cyber-Hygiene: A Case Study of University of Nigeria, Nsukka 1 Introduction 2 Literature Review 3 Materials and Methods 3.1 Survey Participants 3.2 Research Goal and Procedure 3.3 Research Hypothesis 3.4 Data Analysis 4 Result 4.1 Descriptive Statistics of Demographics 4.2 Descriptive Statistics of Cyber-Hygiene Knowledge Concept and Threats 4.3 Descriptive Statistics of Cyber-Hygiene Culture 4.4 Demographics and Cyber-Hygiene Culture 5 Discussion 6 Conclusion and Future Work References Coexisting Blockchain and Machine Learning Blockchain-Based Cardinal E-Voting System Using Biometrics, Watermarked QR Code and Partial Homomorphic Encryption 1 Introduction 1.1 Related Works 1.2 Objectives and Contributions 2 Mathematical Background 2.1 Discrete Wavelet Transform (DWT) 2.2 Blockchain Technology 2.3 ElGamal Homomorphic Cryptosystem 2.4 Cardinal Voting 2.5 Range Proof of Knowledge 3 Scheme Methodology 3.1 Voter Authentication 3.2 Authorized Cardinal E-Voting 4 Security Analysis 5 Performance Analysis 5.1 Theoretical Analysis 5.2 Experimental Analysis 5.3 Usability Analysis 6 Future Work and Conclusion References Neutralizing Adversarial Machine Learning in Industrial Control Systems Using Blockchain 1 Introduction 2 System Architecture 2.1 Layer 1: VNWTS Testbed 2.2 Layer 2: Data Management 2.3 Layer 3: ML Training Engine 2.4 Layer 4: Blockchain Virtual Machine 2.5 Layer 5: ML Testing Engine 2.6 Layer 6: Interface 3 Architecture Overview 4 Experimental Results 4.1 Adversarial Machine Learning 4.2 Blockchain-Based Evaluation 5 Conclusion and Future Work References A User-Centric Evaluation of Smart Contract Analysis Tools in Decentralised Finance (DeFi) 1 Introduction 2 Related Work 2.1 Smart Contract Vulnerabilities 2.2 Decentralised Finance (DeFi) and Related Smart Contract Attacks 2.3 Smart Contract Analysis Tools 3 Research Approach 3.1 Methodology Used for Selecting Tools 3.2 Survey 3.3 Evaluated Tools 3.4 Vulnerabilities Dataset 4 Evaluation of Results 4.1 Evaluation Criteria 4.2 Effectiveness—Test Results 4.3 Accuracy—False Positives 4.4 Test Results and Tools’ Rating 5 Conclusion Appendix—Rating Criteria References
Similar books
Digital Towns: Accelerating and Measuring the Digital Transformation of Rural Societies and Economies
2022 · PDF
Measuring the Business Value of Cloud Computing
2020 · PDF
Disrupting Finance: FinTech and Strategy in the 21st Century
2019 · PDF
Cloud Computing: First International Conference, CloudCom 2009, Beijing, China, December 1-4, 2009. Proceedings
2009 · PDF
Cloud Computing: First International Conference, CloudCom 2009, Beijing, China, December 1-4, 2009. Proceedings
2009 · PDF
Autonomic and Trusted Computing: 5th International Conference, ATC 2008, Oslo, Norway, June 23-25, 2008 Proceedings
2008 · PDF
Autonomic and Trusted Computing: 5th International Conference, ATC 2008, Oslo, Norway, June 23-25, 2008 Proceedings
2008 · PDF
MySQL® Notes for Professionals book
2018 · PDF