Academia.eduAcademia.edu

IT Security

description2,561 papers
group16,582 followers
lightbulbAbout this topic
IT Security, or Information Technology Security, refers to the processes and methodologies designed to protect sensitive data and information systems from unauthorized access, damage, or disruption. It encompasses various practices, technologies, and policies aimed at safeguarding digital assets and ensuring the confidentiality, integrity, and availability of information.
lightbulbAbout this topic
IT Security, or Information Technology Security, refers to the processes and methodologies designed to protect sensitive data and information systems from unauthorized access, damage, or disruption. It encompasses various practices, technologies, and policies aimed at safeguarding digital assets and ensuring the confidentiality, integrity, and availability of information.

Key research themes

1. What are the predominant threats and vulnerabilities impacting organizational information security and how can they be prioritized?

This research theme centers on identifying, categorizing, and ranking the threats and vulnerabilities that organizations face in protecting their information assets. Understanding these threats is fundamental to designing effective defense postures and allocating resources to mitigate risks efficiently. The focus is on empirical threat assessment across diverse organizational contexts, emphasizing the dynamic and evolving nature of cyber threats and internal weaknesses including human factors and external attackers.

Key finding: This study surveyed IT executives and identified a dozen categories of threats to information security, ranking them by their significance and observed frequency. Internet connectivity was found to be a critical attack... Read more
Key finding: This paper elaborates on the concept of vulnerability within information assurance, presenting a detailed taxonomy spanning hardware, software, network, organizational, and human factors. It argues that vulnerabilities... Read more
Key finding: The report analyzes the most significant data breaches in the first half of 2024, identifying ransomware attacks and supply chain vulnerabilities as dominant threat vectors causing extensive data exposure across multiple... Read more
Key finding: Through a detailed case study of a premier Indian management institute, the paper highlights how even institutions with seemingly adequate security infrastructure are vulnerable to targeted attacks like SMTP server hacks... Read more

2. How can comprehensive Information Security Management Systems (ISMS) and frameworks be implemented to mitigate risks in diverse organizational contexts?

Focusing on information security governance and operationalization, this theme investigates the design, deployment, and evaluation of ISMS frameworks that align with international standards (e.g., ISO/IEC 27001). Research examines risk management processes, systematic controls, compliance, incident management, and business continuity within ISMS to reduce vulnerabilities and ensure confidentiality, integrity, and availability across technology and organizational layers. The goal is to provide actionable models enabling organizations to manage security proactively and adaptively.

Key finding: The study presents a conceptual framework for ISMS emphasizing risk management as its core. It identifies critical components such as asset management, access control, incident management, compliance, and business continuity.... Read more
Key finding: This research underscores the essential role of ISMS in protecting e-business enterprises from escalating cyber risks. By comparing different information security management models and their applicability, it demonstrates the... Read more
Key finding: The paper proposes a conceptual model-based framework for managing and auditing information systems security that aligns with ISO/IEC standards. By integrating hierarchical concepts into an ontology, the framework enables... Read more
Key finding: This comprehensive examination elucidates Information Assurance (IA) as a strategic, interdisciplinary extension of traditional information security. Highlighting IA’s broader scope encompassing risk management, privacy,... Read more

3. What roles do human factors, awareness programs, and cultural practices play in enhancing IT security within organizations?

Research under this theme investigates the social dimensions of IT security, focusing on user behavior, security awareness, and organizational culture. Recognizing that technology alone cannot secure information, these studies emphasize education, targeted security awareness campaigns, and the reframing of security as a collaborative, ongoing practice. This approach includes analyzing how individuals and groups engage with security policies, and developing programs tailored to various organizational roles, particularly emphasizing IT staff as frontline defenders.

Key finding: This work proposes a tailored information security awareness program specifically designed for IT units within organizations, recognizing them as critical actors in security success. By identifying awareness knowledge domains... Read more
Key finding: This ethnographic study reconceptualizes IT security as a form of care involving continuous, collaborative, and often invisible practices deployed by diverse organizational actors. Drawing on feminist Science and Technology... Read more
Key finding: Through systematic literature analysis, this research identifies key knowledge domains in information security, including security management and decision-making as major foci. It finds that human factors such as security... Read more

All papers in IT Security

Information technology (IT) has proliferated at an unprecedented rate in our society. Technical advances have come quickly yet the social and ethical infrastructure to support these advances has been slow in development. A group of... more
This paper develops a theoretically grounded methodology for the selection and evaluation of alternative encryption algorithms based on artificial neural networks (ANNs). We formalize the cryptographic evaluation problem as a mapping f₀ :... more
In recent years, the notion of gamification has gained some interest within the scientific community. Gamification denotes the use of typical gaming mechanisms, like collecting points, reaching different levels or gaining a spot on a... more
In recent years, the notion of gamification has gained some interest within the scientific community. Gamification denotes the use of typical gaming mechanisms, like collecting points, reaching different levels or gaining a spot on a... more
Background: Small and medium-sized enterprises (SMEs) constitute the backbone of national economies globally, yet they remain disproportionately vulnerable to financial distress, regulatory non-compliance, and governance failure. The... more
Small and medium-sized enterprises (SMEs) constitute a foundational pillar of national economies, yet they remain disproportionately susceptible to financial fraud, regulatory noncompliance, and governance failure. Existing scholarship... more
Authentication and authorisation are critical pillars of security in Java-based enterprise systems, ensuring identity verification, controlled access to resources, and protection against unauthorised activities. With the evolution of Java... more
Web server security is a primary concern amid the rising wave of cyber threats. Every user interaction with a web application is recorded in server logs, which contain valuable information including IP addresses, request methods, response... more
This article presents the state of the art of the Quantum Computation, consisting of one brief introduction, what it is, its history and origin, who are the main researchers in the world- wide scope, the difficulties in the use of this... more
Resumo Este artigo apresenta o estado da arte da Computação Quântica, consistindo em uma breve introdução, o que é, sua história e origem, quem são os principais pesquisadores no âmbito mundial, as dificuldades no uso deste tipo de... more
During the struggle between Iranian Prime Minister Mossadegh and the Shah in April 1953, John Foster Dulles noted that under normal circumstances the United States did not want to support dictators (e.g., the Shah), "but in times like... more
During the struggle between Iranian Prime Minister Mossadegh and the Shah in April 1953, John Foster Dulles noted that under normal circumstances the United States did not want to support dictators (e.g., the Shah), "but in times like... more
In this paper we describe architectural changes incorporated into DNS aware Multicast Session Directory (mDNS) that enable it to co-exist in both Any Source Multicast (ASM) and Source Specific Multicast (SSM) environments. mDNS is a... more
Sosemanuk is a new synchronous software-oriented stream cipher, corresponding to Profile 1 of the ECRYPT call for stream cipher primitives. Its key length is variable between 128 and 256 bits. It accommodates a 128-bit initial value. Any... more
4.9.1. Grupo de Intervención. Podrán ser integrantes, entre otros, los siguientes servicios operativos: • Servicios de prevención, extinción de incendios y salvamento de entidades públicas y privadas. • Servicios de rescate y... more
In case of mobile agent based computing system such as agent-based electronic payment and online electronic publishing of multimedia contents, both precise identification and secure authentication schemes are required for its security.... more
The ChatGPT Windows application offers better user interaction in the Windows operating system (OS) by enhancing productivity and streamlining the workflow of ChatGPT's utilization. However, there are potential misuses associated with... more
Security standards in Oceania are developed and applied according to different national regulatory frameworks. The recent growth of the IT economy in the continent, together with the global challenges that Pacific nations are called to... more
The confluence of artificial intelligence, pall-native structure, and payment card security authorizations creates an unknown demand for security professionals who can mastermind, operate, and optimize Security Information and Event... more
A production-hardened, single-file blockchain designed for true decentralization. Runs on a $50 Android phone with 16 GB storage via Pydroid3. IPv6-first networking eliminates firewall barriers, making every phone a first-class node.... more
The backbone of modern economies relies heavily on Critical Information Infrastructure (CII). It helps to provide critical services in the energy, finance, telecommunications, health, and transportation sectors. This growing dependences... more
This paper examines how modern TLS trust models interact with constrained network environments, specifically in-flight connectivity (IFC) systems. Through systematic observational analysis of certificate handling on a major domestic... more
Since the emergence of 3G cellular IP networks, internet usage via 3G data services has become ubiquitous. Therefore such network is an important target for imposters who can disrupt the internet services by attacking the network core,... more
Quantum-safe Bitcoin" is not a property of a subset of well-behaved transactions. It is a global safety property of the consensus state machine: for every reachable consensus state and for every quantum-capable adversary, no... more
In Model-Driven development software system design is represented through models which are created using general purpose modelling languages e.g. UML. Later on system artefacts are automatically generated from these models. Model-Driven... more
Este artigo estuda a adoção de algumas soluções de criptografia em aplicações web visando a melhoria da segurança da informação ao garantir seus objetivos, notadamente a confidencialidade e a integridade. Conceituada a arquitetura de uma... more
This monograph will examine the armed forces of the DPRK, both conventional and unconventional. The official North Korean name of all branches of North Korea's armed
This paper addresses a basic security requirement of electronic voting, namely that a voter can correct or abort his vote at any time prior to his final vote casting. This requirement serves as a protection against voter precipitance... more
Remote electronic voting systems are more and more used -not so much for parliamentary elections, but nevertheless for elections on lower levels as in associations and at universities. In order to have a basis for the evaluation and... more
Ezen ügyben ugyancsak tetten érhető a legfőbb gyermeki érdek, valamint a gyermek meghallgatáshoz való jogának felhívása, bár vitatott eredménnyel. Fontos intézményi fejleményként utalni szükséges a 2008-ban bevezetett sürgősségi eljárásra... more
With numerous new websites being created every day, it's getting increasingly challenging to tell which ones are safe and which could be dangerous. These websites frequently gather sensitive user data that may be hacked in the absence of... more
This paper presents the possibilities of tracking technologies application in the postal systems. There could be the postal items, vehicles, production tools and employees tracked in the postal system. Based on the tracking object and the... more
Let X : y 2 = f (x) be a hyperelliptic curve over Q(T ) of genus g ≥ 1. Assume that the jacobian of X over Q(T ) has no subvariety defined over Q. Denote by Xt the specialization of X to an integer T = t, let a Xt (p) be its trace of... more
Computationally recognizing humor is an aspect of natural language understanding. Although there appears to be no complete computational model for recognizing verbal humor, it may be possible to recognize jokes based on statistical... more
É preciso aprender com a prática, pois, embora você pense que sabe, só terá certeza depois que experimentar. A digitalização de documentos históricos apresenta-se como forma eficaz de viabilizar o acesso público a grandes acervos e... more
Medical Information Systems (MedIS 1 ) of today are increasingly vulnerable to attacks by malicious software (or malware). Malware, also referred to as a virus or malicious logic, includes such things as Trojan horses, denial of service... more
Medical Information Systems (MedIS 1 ) of today are increasingly vulnerable to attacks by malicious software (or malware). Malware, also referred to as a virus or malicious logic, includes such things as Trojan horses, denial of service... more
The advancement of quantum computing poses a direct threat to classical cryptographic systems, necessitating the adoption of quantum-resistant encryption techniques to maintain data integrity, confidentiality, and trust in digital... more
In this research, the critical task of enhancing information security within a higher education institution is addressed through the implementation of a methodology grounded in the ISO/IEC 27001 and 27002 standards. The current context,... more
Modern information systems face persistent threats wherein adversaries often remain undetected for extended periods, with average breach costs exceeding USD 4.88 million and containment times surpassing 200 days across industries [1],... more
Many significant functionalities of vehicular ad hoc networks (VANETs) require that nodes have knowledge of the positions of other vehicles, and notably of those within communication range. However, adversarial nodes could provide false... more
Many significant functionalities of vehicular ad hoc networks (VANETs) require that nodes have knowledge of the positions of other vehicles, and notably of those within communication range. However, adversarial nodes could provide false... more
Breve disamina dell'impatto del decreto legislativo 231 del 2001 sulla gig-economy, a 25 anni dalla sua introduzione.
The advent of sufficiently powerful quantum computers poses an existential cryptographic threat to elliptic-curve-based public key infrastructure, upon which major blockchain networks depend for transaction security and identity. This... more
The construction industry increasingly relies on complex IT ecosystems to coordinate project management, field operations, and compliance workflows. However, the volume of institutional knowledge scattered across emails, ticketing... more
Jeg-forsker-i-USAs-milit%C3%A6re-interventioner-og-en-ting-ermeget-sl%C3%A5ende-Vestens-hykleri) Hypocrisy and Double Standards Deepen the Divide Between the West and the Global South Dr. Niels Hahn PhD in Development Studies, with focus... more
Download research papers for free!