Information Sciences and Technology Department https://computing.gmu.edu/ en New scoring framework addresses software vulnerabilities https://computing.gmu.edu/news/2022-10/new-scoring-framework-addresses-software-vulnerabilities <span>New scoring framework addresses software vulnerabilities</span> <span><span lang="" about="/user/571" typeof="schema:Person" property="schema:name" datatype="">Tama Moni</span></span> <span>Tue, 10/25/2022 - 13:50</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> <div data-block-plugin-id="field_block:node:news_release:field_associated_people" class="block block-layout-builder block-field-blocknodenews-releasefield-associated-people"> <h2>In This Story</h2> <div class="field field--name-field-associated-people field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">People Mentioned in This Story</div> <div class='field__items'> <div class="field__item"><a href="/profiles/malbanes" hreflang="und">Massimiliano Albanese</a></div> <div class="field__item"><a href="/profiles/ldurant2" hreflang="und">Liza Wilson Durant</a></div> </div> </div> </div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><p><span><span>The George Mason University <a href="https://cec.gmu.edu">College of Engineering and Computing</a> has launched the Mason Vulnerability Scoring Framework (MVSF), which publishes a continuously updated ranking of the most-common global software weaknesses. The work, in conjunction with <a href="https://www.parc.com/" target="_blank">PARC</a> (Palo Alto Research Center), relies on the <a href="//nist.gov">National Institute of Standards and Technology’s</a> (NIST)—Common Vulnerabilities and Exposures data and other sources of vulnerability information to create an up-to-date database that can be used to identify and mitigate risks. This line of work has resulted in multiple pending patent applications and a Best Paper Award at the 19th International Conference on Security and Cryptography.</span></span></p> <figure role="group" class="align-right"><div> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq476/files/2022-10/Vulnerability-scoring-NS-thumbnail_600x600.jpg" width="600" height="600" alt="Graphic with blue computer code and yellow locks on a black background" loading="lazy" typeof="foaf:Image" /></div> </div> <figcaption>Cybersecurity code with 1s and 0s<br /> Photo provided by iStock images</figcaption></figure><p><span><span>Liza Wilson Durant, Mason’s associate provost for strategic initiatives and community engagement, says, "This preemptive tool to guide strategic defense against cybersecurity vulnerabilities will not only safeguard systems but mitigate potential business revenue losses for those who leverage the tool. “ </span></span></p> <p><span><span>An existing list called the Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses, compiled by The <a href="https://mitre.org">MITRE Corporation</a>, has long been the industry standard. MVSF improves on the CWE Top 25 by having data input monthly, compared to MITRE’s yearly reporting. This improvement allows researchers, programmers, developers, and others to have an accurate, almost real-time picture of where software vulnerabilities are most likely to be exploited. Additionally, where MITRE ranks the top 25 vulnerabilities, MVSF ranks the top 150. </span></span></p> <p><span><span>Associate Professor, <a href="https://ist.gmu.edu">Department of Information Sciences and Technology</a> and Associate Director, <a href="https://csis.gmu.edu/">Center for Secure Information Systems</a>, Max Albanese oversees the project for Mason. He says, “If there is a trend where a certain type of vulnerability is becoming more severe, you don’t have to wait for a full year to discover that; you’ll see that class of vulnerability getting worse – or better – month-to-month.”  MVSF can even correct course based on new information, going back and re-ranking weaknesses’ order in a previous month based on new information that was not known at the time of original ranking. </span></span></p> <p><span><span>Albanese further notes that NIST assigns a severity score to vulnerabilities based on a combination of an exploitability score – how difficult the vulnerability is to exploit – and an impact score – how bad the consequences would be if the vulnerability were exploited. MVSF uses those components as variables but allows users to add their own, additional variables not considered by NIST. MVSF also allows users to decide how to weigh the variables that rank the vulnerabilities. This customizability, still under development, is an important feature of the new system. </span></span></p> <p><span><span>Mason and PARC’s collaboration on the Mason Vulnerability Scoring Framework builds on a relationship that started with both of them working on a Defense Advanced Research Projects Agency (DARPA) project dubbed SCIBORG: Secure Configurations for the Internet of Things (IoT) based on Optimization and Reasoning on Graphs. The goal of SCIBORG was to devise fundamentally new approaches to determine security configurations that protect critical infrastructure and IoT-based systems.</span></span></p> <p><span><span>The association with PARC here was important to making the project a success. “Working with GMU was a productive collaboration,” says Marc Mosko, principal scientist, PARC. “Configuration vulnerabilities are growing, now comprising over 15 percent of all Common Vulnerability and Exposure (CVE) notices. We appreciate that across many different industry sectors, there are often gaps in context between management, software security teams, and those who are responsible for ensuring systems are performing optimally on an ongoing basis. Our work addresses these evolving configuration security needs, and we look forward to exploring opportunities to apply this work in the future.”</span></span></p> <p>Mason and PARC’s collaboration on the Mason Vulnerability Scoring Framework builds on a relationship that started with both of them working on a Defense Advanced Research Projects Agency (DARPA) program <a href="https://www.darpa.mil/program/configuration-security" target="_blank">ConSec</a> in a project dubbed SCIBORG: Secure Configurations for the Internet of Things (IoT) based on Optimization and Reasoning on Graphs. The goal of SCIBORG was to devise fundamentally new approaches to determine security configurations that protect critical infrastructure and IoT-based systems.</p> <p><span><span>Albanese, who is also an external consultant for MITRE, has initiated a collaboration with MITRE’s group responsible for CWE to leverage synergies between the two organizations.</span></span></p> <p><span><span>In addition to the excitement of the innovation, it is equally impactful to see undergraduate students involved in its design and implementation and innovating alongside their mentor faculty," says Wilson Durant.</span></span></p> <p><span><span>The <a href="https://www.cci-novanode.org/">Virginia Commonwealth Cyber Initiative (CCI)</a> will provide continued support for two Mason undergraduate students to assist with the project, which Albanese says is key for the continued maintenance of the system. </span></span></p> </div> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class='field__items'> <div class="field__item"><a href="/taxonomy/term/3081" hreflang="en">cryptography</a></div> <div class="field__item"><a href="/taxonomy/term/3291" hreflang="en">configuration vulnerabilities</a></div> <div class="field__item"><a href="/taxonomy/term/2901" hreflang="en">Internet of Things</a></div> <div class="field__item"><a href="/taxonomy/term/3181" hreflang="en">Information Sciences and Technology Department</a></div> <div class="field__item"><a href="/taxonomy/term/86" hreflang="en">Research</a></div> <div class="field__item"><a href="/taxonomy/term/3626" hreflang="en">CEC faculty research</a></div> </div> </div> </div> </div> </div> Tue, 25 Oct 2022 17:50:54 +0000 Tama Moni 7641 at https://computing.gmu.edu Zhisheng Yan nabs Best Student Paper Award https://computing.gmu.edu/news/2022-10/zhisheng-yan-nabs-best-student-paper-award <span>Zhisheng Yan nabs Best Student Paper Award</span> <span><span lang="" about="/user/711" typeof="schema:Person" property="schema:name" datatype="">Teresa Donnellan</span></span> <span>Wed, 10/05/2022 - 14:57</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> <div data-block-plugin-id="field_block:node:news_release:field_associated_people" class="block block-layout-builder block-field-blocknodenews-releasefield-associated-people"> <h2>In This Story</h2> <div class="field field--name-field-associated-people field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">People Mentioned in This Story</div> <div class='field__items'> <div class="field__item"><a href="/profiles/zyan4" hreflang="en">Zhisheng Yan</a></div> </div> </div> </div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><p>A recent paper by Department of Information Sciences and Technology Assistant Professor Zhisheng Yan received the Best Student Paper Award at ACM Multimedia Systems (MMSys) 2022 conference held in Athlone, Ireland. ACM MMSys is a premier conference on multimedia. The awarded paper results from a collaborative project between Yan and researchers at the <a href="https://illinois.edu/" target="_blank">University of Illinois Urbana-Champaign</a>.</p> <p>In his paper, Yan writes, “Image compression standards such as JPEG and its variants designed for human viewing are no longer the optimal choice for emerging video analytics applications where machines and computer algorithms are the end consumers. We show in this paper that it is necessary and feasible to achieve fast and compact image compression while maximizing the accuracy of image classification and object detection algorithms through a machine-centered design.” </p> <p>To read the paper, “Context-aware Image Compression Optimization for Visual Analytics Offloading,” go to <a href="https://mason.gmu.edu/~zyan4/papers/cico_mmsys22.pdf" target="_blank">https://mason.gmu.edu/~zyan4/papers/cico_mmsys22.pdf</a>. </p> </div> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class='field__items'> <div class="field__item"><a href="/taxonomy/term/3181" hreflang="en">Information Sciences and Technology Department</a></div> <div class="field__item"><a href="/taxonomy/term/1331" hreflang="en">information sciences and technology</a></div> <div class="field__item"><a href="/taxonomy/term/3586" hreflang="en">Media Research</a></div> </div> </div> </div> </div> </div> Wed, 05 Oct 2022 18:57:56 +0000 Teresa Donnellan 8156 at https://computing.gmu.edu New Mason IT grad says ‘just go for it’ https://computing.gmu.edu/news/2022-04/new-mason-it-grad-says-just-go-it <span>New Mason IT grad says ‘just go for it’ </span> <span><span lang="" about="/user/566" typeof="schema:Person" property="schema:name" datatype="">Rena Malai</span></span> <span>Mon, 04/25/2022 - 15:59</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><div class="align-left"> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq476/files/styles/small_content_image/public/2022-04/abuirshaidpic.png?itok=qoxadY6B" width="349" height="350" alt="Dania O Abu-Irshaid" loading="lazy" typeof="foaf:Image" /></div> </div> <p><span><span><span><span><span><span><span>It was a friend’s serendipitous homework assignment that had Dania O Abu-Irshaid, upcoming George Mason graduate from the <a href="https://ist.gmu.edu">Department of Information Sciences and Technology,</a> switch her undergrad work from pre-law to a STEM path.</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>She says she’s always had a natural knack for coding, and it’s something that’s always interested her. But when she helped a fellow Mason student with a Python coding exercise, that’s when it clicked.</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>“I was thinking about pre-law, but after taking a class in it, I didn’t feel like it suited me. I was undecided,” says Abu-Irshaid. “Then my friend was struggling with this homework assignment and I ended up finishing it for her in five minutes. She looked at me and said, this is what you should be doing.”</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>When Abu-Irshaid made the move to study IT, with a concentration in cybersecurity, that’s when things really picked up for her. As the oldest child in her family, she was relied on to be the tech savvy expert and help fix wifi routers in the house or explain internet nuances to her parents. Although she is the first female in her family to study and work in STEM, she’s confident of the opportunities coming her way. </span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>After graduation, Abu-Irshaid will enter a ten weeklong internship with the <a href="https://www.elections.virginia.gov/">Virginia Department of Elections</a>, where she will work in the cybersecurity sector. She also sees potential for a corporate position with one of the big contenders—namely Walmart. As a resident advisor at Mason to freshman engineering students, Abu-Irshaid says some of her mentees good naturedly tease her about her Walmart aspirations to this day.</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>“I’m like, guys, Walmart isn’t just about celery and sticky buns, they have a corporate side,” she says. “But they’ll still ask me how Walmart’s going and what kind of merchandise I have.”</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>With a bright future ahead, she says she’ll miss her time at Mason, particularly the diverse community and her role as an advisor.</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>“I love the community and culture at Mason. There’s always something to do, and something to look forward to on campus. But I’ll hopefully be back, in some capacity,” says Abu-Irshaid.</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>Her message for future grads is to just go for it, whether it’s a job, course of study, or opportunity.</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>“It’s really as simple as that, and it’s what got me everywhere,” she says. “Just go to that club meeting, go to that class, ask your professor that question. You’re not going to get the results unless you go for it.”</span></span></span></span></span></span></span></p> </div> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class='field__items'> <div class="field__item"><a href="/taxonomy/term/541" hreflang="en">STEM</a></div> <div class="field__item"><a href="/taxonomy/term/181" hreflang="en">Cybersecurity</a></div> <div class="field__item"><a href="/taxonomy/term/2581" hreflang="en">women in computing</a></div> <div class="field__item"><a href="/taxonomy/term/1401" hreflang="en">diversity</a></div> <div class="field__item"><a href="/taxonomy/term/3181" hreflang="en">Information Sciences and Technology Department</a></div> <div class="field__item"><a href="/taxonomy/term/1026" hreflang="en">Graduation</a></div> <div class="field__item"><a href="/taxonomy/term/3201" hreflang="en">CEC 2022 graduates</a></div> </div> </div> </div> </div> </div> Mon, 25 Apr 2022 19:59:42 +0000 Rena Malai 7091 at https://computing.gmu.edu Mason NSF CAREER award looks at compressing and transmitting panoramic video for accurate analysis https://computing.gmu.edu/news/2022-02/mason-nsf-career-award-looks-compressing-and-transmitting-panoramic-video-accurate <span>Mason NSF CAREER award looks at compressing and transmitting panoramic video for accurate analysis </span> <span><span lang="" about="/user/566" typeof="schema:Person" property="schema:name" datatype="">Rena Malai</span></span> <span>Mon, 02/07/2022 - 14:37</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> <div data-block-plugin-id="field_block:node:news_release:field_associated_people" class="block block-layout-builder block-field-blocknodenews-releasefield-associated-people"> <h2>In This Story</h2> <div class="field field--name-field-associated-people field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">People Mentioned in This Story</div> <div class='field__items'> <div class="field__item"><a href="/profiles/zyan4" hreflang="en">Zhisheng Yan</a></div> </div> </div> </div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><div class="align-left"> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq476/files/styles/small_content_image/public/2022-02/Yan.jpg?itok=lGuT6rSC" width="263" height="350" alt="Zhisheng Yan" loading="lazy" typeof="foaf:Image" /></div> </div> <p>Panoramic video footage is a useful tool to capture important information, like identifying suspects or monitoring a natural disaster response during an earthquake or wildfire. </p> <p>George Mason University assistant professor Zhisheng Yan in the Department of Information Sciences and Technology will lead a National Science Foundation (NSF) CAREER research project called <a href="https://nsf.gov/awardsearch/showAward?AWD_ID=2144764&amp;HistoricalAwards=false" target="_blank">Machine-centered Cyberinfrastructure for Panoramic Video Analytics in Science and Engineering Monitoring</a> to further develop and enhance machine centric video compression and transmission. This will look at developing a method for video footage captured by a 360 degree panoramic camera—which uses copious amounts of data—to get compressed and transmitted into a more usable, sizeable unit for data analysis in computing servers. </p> <p>According to Yan, the benefit of 360 video footage is having a larger scope of footage available but transmission can be challenging without efficient compression. </p> <p>“The use of 360 degree panoramic video is seen as an important tool for data collection in a variety of spaces, particularly when it comes to identifying wildlife, filming airport traffic, and suspect recognition,” says Yan. “All the views are available.” </p> <p>The end consumer of 360 degree video footage is now not always a human eye, but a computer algorithm, says Yan. This is why redesigning video compression and transmission capabilities is necessary to make sure the algorithms are properly analyzing footage, and retaining the data that’s needed. </p> <p>“The need to redesign compression and transmission is not necessarily for video quality, but to optimize analytic results and accuracy for the computer systems ‘viewing’ the video,” says Yan.  </p> <p>He adds that research done around traditional camera and video systems have shown that there are often issues when software programs are used to analyze panoramic videos that are too large for the systems to handle. This is where machine centric video compression and transmission can help these systems generate an accurate analysis.   </p> <p>Yan will be the single principal investigator for the project and anticipates working alongside student researchers throughout the duration. The Machine-centered Cyberinfrastructure for Panoramic Video Analytics in Science and Engineering Monitoring project will begin June 2022 and run for about five years. </p> <p>Until June, Yan says he will focus on some literature reviews and preparation.  </p> <p>“Our first focus will be in compression technology, and then we will focus on the transmission aspect,” he says. “We’ll do testing on 360 degree panoramic video samples to see what works best.” </p> </div> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class='field__items'> <div class="field__item"><a href="/taxonomy/term/3091" hreflang="en">visual art</a></div> <div class="field__item"><a href="/taxonomy/term/3181" hreflang="en">Information Sciences and Technology Department</a></div> <div class="field__item"><a href="/taxonomy/term/1676" hreflang="en">College of Engineering and Computing</a></div> <div class="field__item"><a href="/taxonomy/term/3096" hreflang="en">Media</a></div> <div class="field__item"><a href="/taxonomy/term/1241" hreflang="en">data analytics</a></div> <div class="field__item"><a href="/taxonomy/term/1666" hreflang="en">data</a></div> <div class="field__item"><a href="/taxonomy/term/486" hreflang="en">National Science Foundation</a></div> <div class="field__item"><a href="/taxonomy/term/86" hreflang="en">Research</a></div> </div> </div> </div> </div> </div> Mon, 07 Feb 2022 19:37:10 +0000 Rena Malai 6936 at https://computing.gmu.edu