Research

A Zero-Day Cloud Timing Channel Attack

IEEE has published Dr. Robert Flower’s paper titled “A Zero-Day Cloud Timing Channel Attack.”

Abstract:
The Intrusion Detection and Prevention System (IDPS) services of a North American cloud service provider were ineffective against a simulated network timing channel attack. During the tests, three conspiring white hat agents exchanged a total of 33,024 network packets. As the proxy based attack executed, the vendor’s intrusion detection service did not generate a warning, nor did its intrusion prevention service drop packets. Throughout the experiment, 4,096 bytes of randomized data (simulating covert traffic) were exchanged over a 2.06 hour period (4.4 bits-per-second); however, the vendor’s Artificial Intelligence (AI) enabled threat detection service did not issue an alert. A Wilcoxon Ranked Sum test on the before-and-after throughput confirmed none of the vendor’s countermeasures triggered/intervened to a statistically significant degree (threat intel: p=0.703, IDPS: p=0.998 , threat intel +  IDPS: p=0.118 ). These results indicate those accountable for data-oriented Service Organization Control (SOC) 2/3 reports (e.g., auditors, cybersecurity executives, etc.) should carefully examine the assurances offered by cloud service providers with regard to their network steganography defenses.

Read full paper here: https://ieeexplore.ieee.org/document/9973314

Careers

Career Services Winter Workshops & Micro-Internship Platform

Winter 2022 Career Services Virtual Workshops

Join us for one of our virtual workshops this winter term.  This term Career Services will address topics such as internships, cover letter basics, career exploration, and job scams. We will also be reprising our job search basic workshop. So come to one, or better yet, come to all! More information is shared below in the event links. Sign up today!

Job Search Basics 101 Virtual Workshop – Tuesday, December 6, 2022, 12-1 pm @ Handshake

Not sure where to start when looking for a job or internship? Then this virtual workshop is for you! Career Services will share their top two job search sites along with essential tips to get you on the right path to employment! Register via Handshake @ https://bellevue.joinhandshake.com/events/1170671  Registration closes 12/5/22 at 11:59 pm CDT.

Interests in Life & Work Virtual Workshop – Wednesday, December 14, 2022, 4-5 pm @ Handshake

The term “interests” has a very specific meaning in career development. Clarify how your interests influence the work you enjoy through the Strong Interest Inventory assessment. Explore how interests relate to job families and opportunities on campus. PRE-WORK REQUIRED- Instructions for taking the RAISC Interest Inventory (at least 3 days in advance) will be sent in your registration confirmation.  Register via Handshake @ https://bellevue.joinhandshake.com/events/1170718/  Registration closes 12/8/22 at 11:59 pm CDT.

Job Scams and How to Identify Them Workshop – Wednesday, January 11, 2023, 12-1 pm @ Handshake

Career Services will share some warning signs to watch for during your job search and how to know if a job is a scam so you can find a genuine opportunity! Register via Handshake @ https://bellevue.joinhandshake.com/events/1170750 Registration closes 1/9/23 at 11:59 pm CDT.

Internship FAQ Workshop – Thursday, January 19, 2023, 4-5 pm @ Handshake

Looking for an internship and not sure where to start?  In this workshop, Career Services will share their top 2 search sites along with basic tips to get you headed down the right path with your internship search! Register via Handshake @ https://bellevue.joinhandshake.com/events/1170763Registration closes 1/17/23 at 11:59 pm CDT.

Cover Letter Basics Workshop – Tuesday, February 21, 2023, 12-1 pm @ Handshake

Career Services will share the purpose and elements of a compelling cover letter. This session will also be full of examples that will guide you to write your exceptional cover letter. Register via Handshake @ https://bellevue.joinhandshake.com/events/1170770Registration closes 2/19/23 at 11:59 pm CDT.

Micro Internships Opportunities on Parker Dewey

Micro-Internships opportunities are a great way to gain experience if a 12-week internship just doesn’t fit your busy schedule. Micro-Internships involve five to 40 hours of work, and many can be completed remotely, with you in one location and the employer-based in another. They are offered by companies of all shapes and sizes – from start-ups to Fortune 100 companies. Assignments go across all departments, including sales, marketing, technology, human resources, and finance. For more information on the Micro-Internship Program or to create an account, please visit our Micro-Internship page here.

Research

Faculty Paper Published by IEEE

Adjunct Professor Robert Flowers, Sc.D., latest research has been published in IEEE Access (Volume: 10).

Abstract:

Cybersecurity executives, engineers, and decision-makers should not presume effective network steganographic countermeasures come at the cost of performance. A performance assessment of network steganographic countermeasures during an experimental data exfiltration attack revealed a negligible influence on latency. Despite the advanced nature of the attack, preventative controls did not degrade packet round-trip times to a statistically significant degree. During the experiment, synthetic credit card numbers were exfiltrated at a rate equivalent to (US) $ 74,702 per second. The measured round trip time between a covert transmitting host and covert receiving host was nearly identical regardless of whether interventions were active or inactive. The de minimis effect suggests similar preventative controls in an enterprise environment would not have an adverse effect on large volumes of business network traffic in the presence of an actual attack.

Performance Impact of Header-Based Network Steganographic Countermeasures | IEEE Journals & Magazine | IEEE Xplore

Careers

Upcoming Career Fairs

SAVE THE DATE – Fall 2022 Virtual Career Fair

Save the Date! The Fall Career Fair is Oct 27, 2022 from 10 am – 3 pm hosted virtually via Handshake. The fair is open to all BU students & alumni.  Registration open Monday, October 17th at 10 am CDT. For more information about the fair is available here – http://ow.ly/iro650KFYt6

Fall 2022 Career Services Virtual Workshops

Join us for one of our virtual workshops on various career readiness topics such as basic job searches, getting Career Fair ready, and networking. So come to one, or better yet, come to all three! More information is shared below in the event links. Sign up today!

Job Search Basics 101 Virtual Workshop – Tuesday, September 27, 2022, 4-5 pm @ Handshake

Not sure where to start when looking for a job or internship? Then this virtual workshop is for you! Career Services will share their top two job search sites along with essential tips to get you on the right path to employment! Register via Handshake @ https://bellevue.joinhandshake.com/events/1115052     Registration closes 9/25/22 at 11:59 pm CDT.

Career Fair Ready Virtual Workshop – Wednesday, October 19, 2022, 4-5 pm @ Handshake

The Fall Career Fair is approaching but are you ready? Learn how a virtual career fair works, what to expect during the fair, and quick tips to prepare you for the big event. Register via Handshake @  https://bellevue.joinhandshake.com/events/1116177/   Registration closes 10/16/22 at 11:59 pm CDT.

How to Network in a Virtual World Workshop – Thursday, November 3, 2022, 4-5 pm @ Handshake

Learn how to network in a virtual environment (i.e., Handshake, LinkedIn) and how to establish connections that can benefit you throughout your career.  Register via Handshake @ https://bellevue.joinhandshake.com/events/1116208   Registration Closes 11/1/22 at 11:59 pm CDT.

Security Education

Bellevue University Participates in Center of Academic Excellence Designation Ceremony

Douglas Rausch, Director of the Bellevue University Center for Cybersecurity Education, receives Bellevue University’s formal re-Designation as a National Center of Academic Excellence in Cyber Defense Education at the Midwest Regional Hub meeting held in Chicago on August 19th. Presenting Bellevue’s Designation was Lynne Clark, the Chief of NSA’s Center for Education, Innovation and Outreach.
Careers

National Cybersecurity Virtual Career Fair September 16, 2022

Students in the Bellevue University Cybersecurity program who are actively searching for jobs are encouraged to take advantage of the National Cybersecurity Virtual Career Fair taking place on September 16, 2022 from 11am to 3pm Central time. This is a great opportunity to circulate your resume and participate in some discussions with prospective employers. See this link for more information and to sign-up.

https://www.caecommunity.org/news/2022-national-cybersecurity-virtual-career-fair-registration-now-open

CTF

NSA Codebreaker Challenge is Live!

The NSA Codebreaker Challenge is an opportunity for students to develop and test their low level analysis and reverse engineering skills on a realistic scenario. This year scenario is to help a US company which has been crippled by a ransomeware attack. Your mission is to investigate the attack and discover the tools and techniques used, unravel and expose a Ransomeware-as-a-Service ring, and to recover the victim’s files. You will utilize skills in the following areas:

  • Log Analysis
  • Computer Forensics
  • Packet Analysis
  • Web Analysis
  • Reverse Engineering
  • Web Hacking
  • Cryptography
  • Cryptoanalysis
  • Software Development

Each year Bellevue University has several students participate in the NSA Codebreaker challenge, is this year your year to participate? More information and register here: https://nsa-codebreaker.org/home

Careers

NICE Webinar: Optimize your LinkedIn Profile

Your LinkedIn profile is key to growing your professional network and establishing credibility with employers and recruiters. LinkedIn is a professional social network whose mission is to connect the world’s professionals to make them more productive and successful. During this webinar, LinkedIn pros will share tips and tricks on how to optimize your LinkedIn profile – “rock your profile” — so that employers, recruiters and other professionals can easily find you and help you grow your network with the goal of advancing you in your career.

The webinar is free and open to the public and will take place on July 20th from 1:00 – 2:00pm CDT. Register and more info at link below.

https://www.nist.gov/news-events/events/2022/07/nice-webinar-optimizing-your-linkedin-profile-your-cybersecurity-career

Conference, Security Education

Omaha ISACA Spring Seminar

On April 7th, the ISACA Omaha chapter is hosting its annual spring seminar. This will be held at Bellevue University in the MASB Symposium Room. See the above link for full details, this is a great opportunity to keep up to date on current topics as well as network with local cybersecurity professionals.

As a bonus to students, the chapter is offering 1 free entrance for a Bellevue University student to attend. Interested individuals should contact Ron Woerner, rwoerner@bellevue.edu

Careers

Spring 2022 Career Fair

Registration for the Spring 2022 Virtual Career Fair is open! The event will occur on Thursday, March 31st, from 12 – 4 pm CDT in our online job platform, Handshake. Students will be able to meet with employers in live synchronous group or 1:1 sessions. We currently have over  30 employers participating in the fair with various job and internship opportunities nationwide. The career fair is ideal for all current job seekers and upcoming and recent graduates. To attend the Career Fair, students will need to log in to Handshake and register for the event. An overview video on how to utilize Handshake’s Virtual Career Fair Platform along with the Career Fair registration link is available on the Career Fair page. For questions about the career fair, reach out to Career Services at careerservices@bellevue.edu.