1,480 research outputs found

    A Novel Computer Virus Propagation Model under Security Classification

    Get PDF

    Global Dynamics and Optimal Control of a Viral Infection Model with Generic Nonlinear Infection Rate

    Get PDF
    This paper is devoted to exploring the combined impact of a generic nonlinear infection rate and infected removable storage media on viral spread. For that purpose, a novel dynamical model with an external compartment is proposed, and the explanations of the main model assumptions (especially the generic nonlinear infection rate) are also examined. The existence and global stability of the unique equilibrium of the model are fully investigated, from which it can be seen that computer virus would persist. On this basis, a next-best approach to controlling the level of infected computers is suggested, and the theoretical analysis of optimal control of the model is also performed. Additionally, some numerical examples are given to illustrate the main results

    Enterprise Cyber Risk Management

    Get PDF

    Measuring Cybersecurity Competency: An Exploratory Investigation of the Cybersecurity Knowledge, Skills, and Abilities Necessary for Organizational Network Access Privileges

    Get PDF
    Organizational information system users (OISU) that are victimized by cyber threats are contributing to major financial and information losses for individuals, businesses, and governments. Moreover, it has been argued that cybersecurity competency is critical for advancing economic prosperity and maintaining national security. The fact remains that technical cybersecurity controls may be rendered useless due to a lack of cybersecurity competency of OISUs. All OISUs, from accountants to cybersecurity forensics experts, can place organizational assets at risk. However, that risk is increased when OISUs do not have the cybersecurity competency necessary for operating an information system (IS). The main goal of this research study was to propose and validate, using subject matter experts (SME), a reliable hands-on prototype assessment tool for measuring the cybersecurity competency of an OISU. To perform this assessment, SMEs validated the critical knowledge, skills, and abilities (KSA) that comprise the cybersecurity competency of OISUs. Primarily using the Delphi approach, this study implemented four phases of data collection using cybersecurity SMEs for proposing and validating OISU: KSAs, KSA measures, KSA measure weights, and cybersecurity competency threshold. A fifth phase of data collection occurred measuring the cybersecurity competency of 54 participants. Phase 1 of this study performed five semi-structured SME interviews before using the Delphi method and anonymous online surveys of 30 cybersecurity SMEs to validate OISU cybersecurity KSAs found in literature and United States government (USG) documents. The results of Phase 1 proposed and validated three OISU cybersecurity abilities, 23 OISU cybersecurity knowledge units (KU), and 22 OISU cybersecurity skill areas (SA). In Phase 2, two rounds of the Delphi method with anonymous online surveys of 15 SMEs were used to propose and validate OISU cybersecurity KSA measures. The results of Phase 2 proposed and validated 90 KSA measures for 47 knowledge topics (KT) and 43 skill tasks (ST). In Phase 3, using the Delphi method with anonymous online surveys, a group of 15 SMEs were used to propose and validate OISU cybersecurity KSA weights. The results of Phase 3 proposed and validated the weights for four knowledge categories (KC) and four skill categories (SC). When Phase 3 was completed, the MyCyberKSAsTM prototype assessment tool was developed using the results of Phases 1-3, and Phase 4 was initiated. In Phase 4, using the Delphi method with anonymous online surveys, a group of 15 SMEs were used to propose and validate an OISU cybersecurity competency threshold (index score) of 80%, which was then integrated into the MyCyberKSAsTM prototype tool. Before initiating Phase 5, the MyCyberKSAsTM prototype tool was fully tested by 10 independent testers to verify the accuracy of data recording by the tool. After testing of the MyCyberKSAsTM prototype tool was completed, Phase 5 of this study was initiated. Phase 5 of this study measured the cybersecurity competency of 54 OISUs using the MyCyberKSAsTM prototype tool. Upon completion of Phase 5, data analysis of the cybersecurity competency results of the 54 OISUs was conducted. Data analysis was conducted in Phase 5 by computing levels of dispersion and one-way analysis of variance (ANOVA). The results of the ANOVA data analysis from Phase 5 revealed that annual cybersecurity training and job function are significant, showing differences in OISU cybersecurity competency. Additionally, ANOVA data analysis from Phase 5 showed that age, cybersecurity certification, gender, and time with company were not significant thus showing no difference in OISU cybersecurity competency. The results of this research study were validated by SMEs as well as the MyCyberKSAsTM prototype tool; and proved that the tool is capable of assessing the cybersecurity competency of an OISU. The ability for organizations to measure the cybersecurity competency of OISUs is critical to lowering risks that could be exploited by cyber threats. Moreover, the ability for organizations to continually measure the cybersecurity competency of OISUs is critical for assessing workforce susceptibility to emerging cyber threats. Furthermore, the ability for organizations to measure the cybersecurity competency of OISUs allows organizations to identify specific weaknesses of OISUs that may require additional training or supervision, thus lowering risks of being exploited by cyber threats

    A New Model for Capturing the Spread of Computer Viruses on Complex-Networks

    Get PDF
    Based on complex network, this paper proposes a novel computer virus propagation model which is motivated by the traditional SEIRQ model. A systematic analysis of this new model shows that the virus-free equilibrium is globally asymptotically stable when its basic reproduction is less than one, and the viral equilibrium is globally attractive when the basic reproduction is greater than one. Some numerical simulations are finally given to illustrate the main results, implying that these results are applicable to depict the dynamics of virus propagation

    Attacks on the Android Platform

    Get PDF
    The focus of this research revolves around Android platform security, specifically Android malware attacks and defensive techniques. Android is a mobile operating system developed by Google, based on the Linux kernel and designed primarily for touchscreen mobile devices such as smartphones and tablets. With the rise of device mobility in our data-driven world, Android constitutes most of the operating systems on these mobile devices playing a dominant role in today’s world. Hence, this paper analyzes attacks and the various defensive mechanisms that have been proposed to prevent those attacks

    Challenges encountered by NATED information system students at Majuba TVET College, Newcastle

    Get PDF
    A large number of students are struggling with Information System and other computer related subjects. This has a negative impact on students’ academic performance at large. In fact, a number of students from various institutions of higher learning are facing serious Information System challenges. Information System student on NATED curriculum at Majuba TVET College are facing serious challenges on their studies. This has been indicated by their performance on Information System. This article intends to draw an attention of education stakeholders, College management and lecturers to this matter. A number of reasons leading to students poor performance in this field has been mentioned. Various studies have been conducted but yet the lack of Information System skills still persists. The main question that guided this study was: What are the stakeholders’ perceptions of the challenges encountered Information System students? In order to explore and to get some findings for this case qualitative study, semi-structured interviews with relevant stakeholders were conducted. Sample of lecturers, student’s focus groups and college management members was conducted. Data collected from various participants were transcribed verbatim. A combination of literature and data collected produced some findings on the matter. In an attempt to answer the main question, recommendations were made.Educational Leadership and ManagementM. Ed. (Education Management

    A framework to implement information security awareness, education and training within the Limpopo economic development agency group

    Get PDF
    Cybersecurity awareness, education and training of employees is key in reducing and preventing cyber-attack opportunities. The ignorance and/or lack of understanding of employees about the information security risks around them might expose the LEDA Group to cyber-attacks. This led to the problem that the level of awareness of employees regarding information security was not known. The implication of this not knowing was that an argument for the nature of an intervention to ensure awareness, as well as to educate and train employees regarding information security was not possible. The aim of this treatise was to develop a framework as an effective guideline for the implementation of cybersecurity awareness, education and training of employees. In the study, the LEDA Group employees were surveyed to determine their cybersecurity knowledge gap. An online questionnaire was randomly sent to 314 LEDA Group employees. The survey was voluntary and confidential. One hundred and thirty seven (137) employees completed the survey. The results of the survey were analysed to determine the gap between the current cybersecurity knowledge of the LEDA Group employees and state-of-the-art cybersecurity knowledge. The gap was used in the development of the framework for the implementation of the cybersecurity awareness, education and training (F-CSAET). Central to F-CSAET is the governance principles guided by best practices such as King IV, COBIT5, ISO27001, ISO27005, ISO27008 and ISO27032 and the compliance requirements to POPIA, the Copyright Act and the Cybercrimes and Cybersecurity Bill. The F-CSAET has six steps, namely Assess, Analyse, Create, Plan, Implement and Reinforce. The framework was evaluated for applicability by the team called the cyber security interest team, which was established specifically for the purpose of the F-CSAET
    • …
    corecore