Denise Dragos

dblp:286/7208 · also Denise M. Dragos · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
5since 2021 · last 2024
0000-0002-7750-0703ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 5 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 A Global Cybersecurity Embedded Course: Student Learnings and Curricular Design
abstract
This full paper research reports on the curriculum design and voluntary Institutional Review Board (IRB) approved student laboratory learning and surveys from a global cybersecurity embedded travel course. The Cybersecurity in a Global Context embedded course is designed as a global spring break graduate and undergraduate enrichment program centered in Rome, Italy. The program curriculum was designed to expose students to classroom laboratory assignments, participate in related guest lectures, university site visits, and cybersecurity-related museum activities to enrich their understanding of international cybersecurity topics of relevance. The curriculum was designed for the graduate and under-graduate students to add breadth to their growth in knowledge extended from their classroom experience. Topics covered in the course include foundational cybersecurity and digital forensic concepts, network infrastructure security, and secure software and scripting development. The goal of the week was for students to submit assignments and participate in discussions within the four domains of knowledge. In the first two labs, students explored global topics including international criminal activities, the dark web, and networking concepts such as virtual private networks. In the third lab, students worked on securing portable WiFI routers. In the last labs, the students worked on securing the software running on the WIFI portable routers. The students worked in teams to complete the labs based on the classes they were enrolled into. A graduate student was a team captain of every team that consisted of 1–2 undergraduate students. Students were also asked to keep a daily journal for cybersecurity lessons learned from site visits, guest speakers, and laboratory assignments. These journals were transformed into blogs about their experience. Students were encouraged to publish their experience blog to raise awareness of international cybersecurity concerns. We report on the laboratory lesson objectives, guest lectures, and report on our site visit curricular designs. On learning, we report on the laboratory assignments and on the IRB-approved embedded student artifacts submitted from their assignments. We lastly report on student feedback from lessons learned along with insights from both faculty and students for next iterations of this course and similar embedded courses.
Suzanna Schmeelk, Denise Dragos
FIE2
2023 Foundational Digital Forensics Skills and Learning: Exemplifying Social Justice
abstract
This full paper reports on the curricular design and IRB-approved participant feedback of a digital forensics workshop curriculum to either be a standalone learning or experience or integrated within a forensics component of a cyber security course (e.g. Network Perimeter Security). The workshop showcases skills needed for foundational digital forensics (DFR) fieldwork and explains pedagogical techniques and successful environments for building inclusive classrooms that have been successful as reported by heterogeneous students. Forensics topics in the curriculum are be selected from the following areas found in our foundational digital forensics course: data acquisition; processing crime/incident scenes; information retrieval from Windows, Macintosh, and Linux systems; recovering graphic, Word, Acrobat, and other file types; virtual machine forensics; investigating emails; examining social media data; writing investigation reports; studying the importance of ethics for expert witnesses; and, understanding expert testimony in digital investigations. The anticipated skills learned from the workshop are components of a full semester course which covers the basics for cybercrime and cyber-incidents to prepare students for interaction with law enforcement agencies, interaction with organizational forensic teams, and further digital forensic courses (e.g. Advanced Digital Forensics, Mobile Device Forensics, Incident Response, Malware Analysis, and Management of Digital Evidence).
Denise Dragos, Suzanna Schmeelk
FIE1
2023 Penetration Testing and Ethical Hacking: Risk Assessments and Student Learning
abstract
This full paper describes a semester-long graduate penetration testing course curriculum; and, discusses student leanings as reported from the final project over multiple years of IRB-approved coursework participation. The curriculum is designed to support career changers where students work in small teams of students in potentially different time zones. The graduate students spend the term learning technical skills to perform industry-based risk assessments. Over the term, the students build a risk assessment based on the National Institute of Standards and Technology (NIST) Risk Assessment guidance. Each week of the semester focuses on a different technical aspect of penetration testing. Weekly topics are constructed around the CompTIA PenTest+ and Certified Ethical Hacker (CEH) certifications. Topics include: Penetration Test Standards, Passive Reconnaissance, Active Reconnaissance, Exploiting Operating Systems, Exploiting Web Applications, Building Custom Exploits, Mobile Device Security, Networking Exploits, Physical Security, and Advanced Research Topics (i.e. SCADA, loT Pen Testing). Graduate students work on weekly assignments and build a semester-long written report to showcase how the different aspects of penetration testing integrate into a final deliverable to a customer. The students build their technical experience each week across multiple operating systems and web application. They document findings in a self-developed risk assessment report template built from open source industry risk assessment examples. The graduate students are expected to not only find weaknesses in systems while studying the different topics, they are asked to map findings to risk levels (e.g. MITRE's ATT&CK framework), missing controls (e.g. NIST 800–53 SP), and provide a remediation and/or mitigation discussion (e.g. mapping to Open Web Application Security Project (OWASP), MITRE's ATT&CK, etc.). The final deliverable for the course is a completed risk assessment encompassing each of the weekly topics, a presentation of their completed risk assessment, and a graduate research aspect on a specific tool in the aforementioned weekly pentest topics. This full report shares example projects from students who volunteered (n=7) to participate in our IRB-approved coursework study.
Suzanna Schmeelk, Denise Dragos
FIE2
2022 Teaching effective Cybersecurity through escape the classroom paradigm
abstract
Cybersecurity has become ubiquitous with the exponential growth of consumer applications and Internet of Things (IoT) devices. It is a discipline which intersects other important industries such as energy, manufacturing, and healthcare. Cybersecurity curriculum has traditionally been taught through a mixture of technical-track and non-technical-track (policy, legal and ethical) related courses. In this paper, we chronicle our Division’s efforts to gamify the technical-track curriculum through the Escape the Classroom (ETC) paradigm. The aim of the curriculum gamification is to provide students a fun, interesting, and rewarding experience while learning Cybersecurity through the appropriate Bloom taxonomy levels. The paper discusses our approach and highlights challenges that our faculty encountered while applying ETC towards the Cybersecurity curriculum.
Joan DeBello, Suzanna Schmeelk, Denise Dragos, Erald Troja, Laura M. Truong
EDUCON3
2021 ABET Cybersecurity Continual Course Improvements for Secure Software Development
abstract
This is an innovative practice full paper. The need to develop software securely cannot be over-emphasized. The changing legal and regulatory international and local landscape for software requirements is astounding. For example, the European Union's General Data Protection Regulation (GDPR), the United States' Health Insurance Portability and Accountability Act (HIPAA), the Chinese Cybersecurity laws, and the credit card industry's Payment Card Industry Data Security Standard (PCI-DSS) are all upholding higher standards for system development and deployment. Such legal and regulatory changes of necessity require modifications and updating in software development methods that must be incorporated into cybersecurity software development courses to properly prepare students for successfully working in the field. To address these and other changes within the computing field, the Accreditation Board for Engineering (ABET) recently proposed preliminary cybersecurity accreditation criteria for which fewer than 20 universities have both applied and become ABET Cybersecurity accredited. The accreditation requires maintaining continuous course improvement in the core courses including a secure software development course. This research first reports on important topics incorporated into a senior-level secure software development for cybersecurity majors. Our research then analyses student Institutional Review Board (IRB) approved surveys to learn which course components could benefit from continuous course improvements. We apply machine learning to help build categories for ABET continual improvement. Finally, we share lessons learned and plans for future work.
Suzanna Schmeelk, Denise Dragos, Joan DeBello
FIE2
2020 What are they Reporting? Examining Student Cybersecurity Course Surveys through the Lens of Machine Learning
abstract
This paper examines IRB-approved student surveys across five cybersecurity and digital forensics courses during Spring 2020 for the benefit of continual course improvement for regulatory requirements such as the Accreditation Board for Engineering and Technology (ABET) (re)accreditation. There is very little research on qualitative machine-learning based methods for the analysis of student feedback in cybersecurity courses, if any courses. This research fills the literature gap by analyzing the feedback from 114 open-ended surveys across five cybersecurity and digital forensic courses to categorize areas of course improvement. To gain insights into the qualitative survey feedback, we employed term frequency-inverse document frequency (TF-IDF) with a K-Means clustering algorithm on cleaned and pre-processed survey data. This methodology provides more useful insights for curriculum developers than a standard sentiment analysis. The methodology can be further extended to be directly integrated into continual course improvement (e.g. ABET, NSA, DoD, etc.) indicators.
Denise Dragos, Suzanna Schmeelk
ICMLA1