中文
相关论文

相关论文: STRisk: A Socio-Technical Approach to Assess Hacki…

200 篇论文

Anonymized data is highly valuable to both businesses and researchers. A large body of research has however shown the strong limits of the de-identification release-and-forget model, where data is anonymized and shared. This has led to the…

密码学与安全 · 计算机科学 2019-10-31 Andrea Gadotti , Florimond Houssiau , Luc Rocher , Benjamin Livshits , Yves-Alexandre de Montjoye

Compromising social network accounts has become a profitable course of action for cybercriminals. By hijacking control of a popular media or business account, attackers can distribute their malicious messages or disseminate fake information…

密码学与安全 · 计算机科学 2015-09-14 Manuel Egele , Gianluca Stringhini , Christopher Kruegel , Giovanni Vigna

To avoid costly security patching after software deployment, security-by-design techniques (e.g., STRIDE threat analysis) are adopted in organizations to root out security issues before the system is ever implemented. Despite the global gap…

密码学与安全 · 计算机科学 2022-08-03 Winnie Mbaka , Katja Tuma

We show that adding noise before publishing data effectively screens $p$-hacked findings: spurious explanations produced by fitting many statistical models (data mining). Noise creates "baits" that affect two types of researchers…

理论经济学 · 经济学 2024-05-21 Federico Echenique , Kevin He

It is very challenging to predict the cost of a cyber incident owing to the complex nature of cyber risk. However, it is inevitable for insurance companies who offer cyber insurance policies. The time to identifying an incident and the time…

应用统计 · 统计学 2022-09-27 Maochao Xu , Quynh Nhu Nguyen

The rise of cyber threats on social media platforms necessitates advanced metrics to assess and mitigate social cyber vulnerabilities. This paper presents the Social Cyber Vulnerability Index (SCVI), a novel framework integrating…

Big data and algorithmic risk prediction tools promise to improve criminal justice systems by reducing human biases and inconsistencies in decision making. Yet different, equally-justifiable choices when developing, testing, and deploying…

计算机与社会 · 计算机科学 2022-09-23 Travis Greene , Galit Shmueli , Jan Fell , Ching-Fu Lin , Han-Wei Liu

Prior work has extensively studied misinformation related to news, politics, and health, however, misinformation can also be about technological topics. While less controversial, such misinformation can severely impact companies'…

计算机与社会 · 计算机科学 2023-06-19 Mohit Singhal , Nihal Kumarswamy , Shreyasi Kinhekar , Shirin Nilizadeh

A distribution inference attack aims to infer statistical properties of data used to train machine learning models. These attacks are sometimes surprisingly potent, but the factors that impact distribution inference risk are not well…

机器学习 · 计算机科学 2024-04-09 Anshuman Suri , Yifu Lu , Yanjin Chen , David Evans

The number of disclosed vulnerabilities has been steadily increasing over the years. At the same time, organizations face significant challenges patching their systems, leading to a need to prioritize vulnerability remediation in order to…

密码学与安全 · 计算机科学 2023-06-19 Jay Jacobs , Sasha Romanosky , Octavian Suciu , Benjamin Edwards , Armin Sarabi

As more businesses and users adopt cloud computing services, security vulnerabilities will be increasingly found and exploited. There are many technological and political challenges where investigation of potentially criminal incidents in…

计算机与社会 · 计算机科学 2015-02-19 Joshua I. James , Ahmed F. Shosha , Pavel Gladyshev

This paper attempts to strengthen the pursued research on social engineering (SE) threat identification, and control, by means of the author's illustrated classification, which includes attack types, determining the degree of possible harm…

密码学与安全 · 计算机科学 2019-02-25 V. Y. Sokolov , O. Y. Korzhenko

Industrial systems are increasingly threatened by cyberattacks with potentially disastrous consequences. To counter such attacks, industrial intrusion detection systems strive to timely uncover even the most sophisticated breaches. Due to…

密码学与安全 · 计算机科学 2023-11-07 Olav Lamberts , Konrad Wolsing , Eric Wagner , Jan Pennekamp , Jan Bauer , Klaus Wehrle , Martin Henze

Security associated threats are often increased for online social media during a pandemic, such as COVID-19, along with changes in a work environment. For example, employees in many companies and organizations have started to work from home…

密码学与安全 · 计算机科学 2023-03-24 Kamal Raj Sharma , Wei-Yang Chiu , Weizhi Meng

Threat hunting is a proactive methodology for exploring, detecting and mitigating cyberattacks within complex environments. As opposed to conventional detection systems, threat hunting strategies assume adversaries have infiltrated the…

密码学与安全 · 计算机科学 2023-10-09 Ángel Casanova Bienzobas , Alfonso Sánchez-Macián

Our systematisation of knowledge on Social Engineering Attacks (SEAs), identifies the human, organisational, and adversarial dimensions of cyber threats. It addresses the growing risks posed by SEAs, highly relevant in the context physical…

密码学与安全 · 计算机科学 2026-01-09 Scott Thomson , Michael Bewong , Arash Mahboubi , Tanveer Zia

Social engineering through social media channels targeting organizational employees is emerging as one of the most challenging information security threats. Social engineering defies traditional security efforts due to the method of attack…

密码学与安全 · 计算机科学 2020-05-11 Heidi Wilcox , Maumita Bhattacharya

With rise in security breaches over the past few years, there has been an increasing need to mine insights from social media platforms to raise alerts of possible attacks in an attempt to defend conflict during competition. In this study,…

社会与信息网络 · 计算机科学 2020-06-23 Soumajyoti Sarkar , Mohammad Almukaynizi , Jana Shakarian , Paulo Shakarian

Inductive kriging supports high-resolution spatio-temporal estimation with sparse sensor networks, but conventional training-evaluation setups often suffer from information leakage and poor out-of-distribution (OOD) generalization. We find…

机器学习 · 计算机科学 2025-09-30 Chen Yang , Changhao Zhao , Chen Wang , Jiansheng Fan

Enterprise networks are growing ever larger with a rapidly expanding attack surface, increasing the volume of security alerts generated from security controls. Security Operations Centre (SOC) analysts triage these alerts to identify…

密码学与安全 · 计算机科学 2025-05-16 Melissa Turcotte , François Labrèche , Serge-Olivier Paquette