Suzanna Schmeelk

dblp:67/8151 · also Suzanna E. Schmeelk · DBLP profile ↗
← Back
12ranked-venue papers
7as first author
6since 2021 · last 2024
0000-0003-1886-3798ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 8 · 5 first-author · 6 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 A Global Cybersecurity Embedded Course: Student Learnings and Curricular Design
abstract
This full paper research reports on the curriculum design and voluntary Institutional Review Board (IRB) approved student laboratory learning and surveys from a global cybersecurity embedded travel course. The Cybersecurity in a Global Context embedded course is designed as a global spring break graduate and undergraduate enrichment program centered in Rome, Italy. The program curriculum was designed to expose students to classroom laboratory assignments, participate in related guest lectures, university site visits, and cybersecurity-related museum activities to enrich their understanding of international cybersecurity topics of relevance. The curriculum was designed for the graduate and under-graduate students to add breadth to their growth in knowledge extended from their classroom experience. Topics covered in the course include foundational cybersecurity and digital forensic concepts, network infrastructure security, and secure software and scripting development. The goal of the week was for students to submit assignments and participate in discussions within the four domains of knowledge. In the first two labs, students explored global topics including international criminal activities, the dark web, and networking concepts such as virtual private networks. In the third lab, students worked on securing portable WiFI routers. In the last labs, the students worked on securing the software running on the WIFI portable routers. The students worked in teams to complete the labs based on the classes they were enrolled into. A graduate student was a team captain of every team that consisted of 1–2 undergraduate students. Students were also asked to keep a daily journal for cybersecurity lessons learned from site visits, guest speakers, and laboratory assignments. These journals were transformed into blogs about their experience. Students were encouraged to publish their experience blog to raise awareness of international cybersecurity concerns. We report on the laboratory lesson objectives, guest lectures, and report on our site visit curricular designs. On learning, we report on the laboratory assignments and on the IRB-approved embedded student artifacts submitted from their assignments. We lastly report on student feedback from lessons learned along with insights from both faculty and students for next iterations of this course and similar embedded courses.
Suzanna Schmeelk, Denise Dragos
FIE1
2024 Building a Cryptography Rotation Pipeline Intervention for Cyber Athletes: Curriculum Design and Coaching Lessons Learned
abstract
The United States Cyber Games started in 2021 to compete internationally in the annual International Cyber Competition (ICC). The United States Team prepares a seasonal team based on yearlong, volunteer coaches, volunteer athletes, and a rigorous virtual national training program to prepare cyber athletes to compete. Historically, the ICC has aimed to attract early-career professionals and raise global awareness of the education and skills needed in the area of cybersecurity. Teams from around the globe come together annually to compete in the ICC. Each year the areas of focus are updated and in general include: web application and system exploitation, cryptography, reverse engineering, hardware challenges, and attack/defense challenges. Early in the development of the first US team preparation to participate in their first ICC, it was realized a need to create a pipeline program to prepare strong athletes for potential entrance onto a future team if they were not already on the current team. This research reports on the volunteer pipeline coaching for building the curriculum, assessment challenges, and voluntary Institutional Review Board approved athlete feedback from the cryptography (crypto) training sessions of Season II in the US Cyber Games pipeline program. The crypto rotation is one of at least five rotations in the pipeline program where each rotation lasts a month on average. This full paper reports on our volunteer coaching insights, feedback, and curriculum for the crypto rotation sessions for need to know crypto topics for likely capture the flag and attack/defend competition questions and exercises including: symmetric, asymmetric, weak modes, padding schemas, key con-cepts, certificates, pseudo random number generators (PRNG), PRNG weaknesses, general crypto CTF tooling, socat usage, pcap extraction/interpretation related to RSA, Python related cryp-tography tools, Transport Layer Security (TLS) vulnerabilities, TLS packet exchange, and other cryptographic concepts, Given a research literature gap on building such a volunteer national team to compete international, we also report on the coaching experiences, challenges topics created for the rotation as well as the importance of proper tooling and preparation for the athletes. We share international topics advised for coverage for ICC training competitions. And, then report on coaching feedback and student voluntary IRB-approved feedback. Lastly, we share coach and athlete feedback and insights for next iterations of building a similar training session.
Suzanna Schmeelk, Tom McGuire
FIE1
2023 Foundational Digital Forensics Skills and Learning: Exemplifying Social Justice
abstract
This full paper reports on the curricular design and IRB-approved participant feedback of a digital forensics workshop curriculum to either be a standalone learning or experience or integrated within a forensics component of a cyber security course (e.g. Network Perimeter Security). The workshop showcases skills needed for foundational digital forensics (DFR) fieldwork and explains pedagogical techniques and successful environments for building inclusive classrooms that have been successful as reported by heterogeneous students. Forensics topics in the curriculum are be selected from the following areas found in our foundational digital forensics course: data acquisition; processing crime/incident scenes; information retrieval from Windows, Macintosh, and Linux systems; recovering graphic, Word, Acrobat, and other file types; virtual machine forensics; investigating emails; examining social media data; writing investigation reports; studying the importance of ethics for expert witnesses; and, understanding expert testimony in digital investigations. The anticipated skills learned from the workshop are components of a full semester course which covers the basics for cybercrime and cyber-incidents to prepare students for interaction with law enforcement agencies, interaction with organizational forensic teams, and further digital forensic courses (e.g. Advanced Digital Forensics, Mobile Device Forensics, Incident Response, Malware Analysis, and Management of Digital Evidence).
Denise Dragos, Suzanna Schmeelk
FIE2
2023 Penetration Testing and Ethical Hacking: Risk Assessments and Student Learning
abstract
This full paper describes a semester-long graduate penetration testing course curriculum; and, discusses student leanings as reported from the final project over multiple years of IRB-approved coursework participation. The curriculum is designed to support career changers where students work in small teams of students in potentially different time zones. The graduate students spend the term learning technical skills to perform industry-based risk assessments. Over the term, the students build a risk assessment based on the National Institute of Standards and Technology (NIST) Risk Assessment guidance. Each week of the semester focuses on a different technical aspect of penetration testing. Weekly topics are constructed around the CompTIA PenTest+ and Certified Ethical Hacker (CEH) certifications. Topics include: Penetration Test Standards, Passive Reconnaissance, Active Reconnaissance, Exploiting Operating Systems, Exploiting Web Applications, Building Custom Exploits, Mobile Device Security, Networking Exploits, Physical Security, and Advanced Research Topics (i.e. SCADA, loT Pen Testing). Graduate students work on weekly assignments and build a semester-long written report to showcase how the different aspects of penetration testing integrate into a final deliverable to a customer. The students build their technical experience each week across multiple operating systems and web application. They document findings in a self-developed risk assessment report template built from open source industry risk assessment examples. The graduate students are expected to not only find weaknesses in systems while studying the different topics, they are asked to map findings to risk levels (e.g. MITRE's ATT&CK framework), missing controls (e.g. NIST 800–53 SP), and provide a remediation and/or mitigation discussion (e.g. mapping to Open Web Application Security Project (OWASP), MITRE's ATT&CK, etc.). The final deliverable for the course is a completed risk assessment encompassing each of the weekly topics, a presentation of their completed risk assessment, and a graduate research aspect on a specific tool in the aforementioned weekly pentest topics. This full report shares example projects from students who volunteered (n=7) to participate in our IRB-approved coursework study.
Suzanna Schmeelk, Denise Dragos
FIE1
2022 Teaching effective Cybersecurity through escape the classroom paradigm
abstract
Cybersecurity has become ubiquitous with the exponential growth of consumer applications and Internet of Things (IoT) devices. It is a discipline which intersects other important industries such as energy, manufacturing, and healthcare. Cybersecurity curriculum has traditionally been taught through a mixture of technical-track and non-technical-track (policy, legal and ethical) related courses. In this paper, we chronicle our Division’s efforts to gamify the technical-track curriculum through the Escape the Classroom (ETC) paradigm. The aim of the curriculum gamification is to provide students a fun, interesting, and rewarding experience while learning Cybersecurity through the appropriate Bloom taxonomy levels. The paper discusses our approach and highlights challenges that our faculty encountered while applying ETC towards the Cybersecurity curriculum.
Joan DeBello, Suzanna Schmeelk, Denise Dragos, Erald Troja, Laura M. Truong
EDUCON2
2021 ABET Cybersecurity Continual Course Improvements for Secure Software Development
abstract
This is an innovative practice full paper. The need to develop software securely cannot be over-emphasized. The changing legal and regulatory international and local landscape for software requirements is astounding. For example, the European Union's General Data Protection Regulation (GDPR), the United States' Health Insurance Portability and Accountability Act (HIPAA), the Chinese Cybersecurity laws, and the credit card industry's Payment Card Industry Data Security Standard (PCI-DSS) are all upholding higher standards for system development and deployment. Such legal and regulatory changes of necessity require modifications and updating in software development methods that must be incorporated into cybersecurity software development courses to properly prepare students for successfully working in the field. To address these and other changes within the computing field, the Accreditation Board for Engineering (ABET) recently proposed preliminary cybersecurity accreditation criteria for which fewer than 20 universities have both applied and become ABET Cybersecurity accredited. The accreditation requires maintaining continuous course improvement in the core courses including a secure software development course. This research first reports on important topics incorporated into a senior-level secure software development for cybersecurity majors. Our research then analyses student Institutional Review Board (IRB) approved surveys to learn which course components could benefit from continuous course improvements. We apply machine learning to help build categories for ABET continual improvement. Finally, we share lessons learned and plans for future work.
Suzanna Schmeelk, Denise Dragos, Joan DeBello
FIE1
2020 What are they Reporting? Examining Student Cybersecurity Course Surveys through the Lens of Machine Learning
abstract
This paper examines IRB-approved student surveys across five cybersecurity and digital forensics courses during Spring 2020 for the benefit of continual course improvement for regulatory requirements such as the Accreditation Board for Engineering and Technology (ABET) (re)accreditation. There is very little research on qualitative machine-learning based methods for the analysis of student feedback in cybersecurity courses, if any courses. This research fills the literature gap by analyzing the feedback from 114 open-ended surveys across five cybersecurity and digital forensic courses to categorize areas of course improvement. To gain insights into the qualitative survey feedback, we employed term frequency-inverse document frequency (TF-IDF) with a K-Means clustering algorithm on cleaned and pre-processed survey data. This methodology provides more useful insights for curriculum developers than a standard sentiment analysis. The methodology can be further extended to be directly integrated into continual course improvement (e.g. ABET, NSA, DoD, etc.) indicators.
Denise Dragos, Suzanna Schmeelk
ICMLA2
2019 Where Are We Looking? Understanding Android Static Analysis Techniques
abstract
Static analysis is a traditional technique for software transformation and analysis. It has also become a means to detect cyber security vulnerabilities and malware and recently has been extended to the mobile-computing arena for security-related analyses. This paper examines 50 security papers that are published in top conferences, journals and technical reports, and characterizes the current research. The papers were selected based their high citings by other top research or because they introduced either a novel analysis technique or a novel security issue analysis. Our research systematically constructs a static analysis landscape by charting and characterizing analysis strengths and limitations in both accuracy and security threats. For completeness and to aid the community by providing a coverage map, we have connected technique motivations found to Mitre's attack taxonomy and Mitre's vulnerability taxonomy. Our Findings include identifying vulnerabilities which are not being systematically researched.
Suzanna Schmeelk
SERVICES1
2018 Doctor of Professional Studies in Computing: A Categorization of Applied Industry Research
abstract
This is a full paper in the Innovate Practice category examining a Doctor of Professional Studies (D.P.S.) in Computing program at Pace University which is a specialized degree program designed for active Information Technology (IT) professionals with at least five years of full time experience in the computing field. The first question that guided our research is how is the Pace University D.P.S. program related to other doctoral computing programs in the United States and globally. The second question that guided our inquiry is dissertation topics pursued by graduates in dissertation research, specifically by IT professionals in the Pace University program. To answer this second question, we analyzed the first 114 dissertation abstracts that have been defended at Pace University in the Seidenberg School of Computer Science and Information Systems. We used machine learning and natural language processing to determine commonalities among research topics in order to gain an understanding of the topic categories and topic spread produced by the program.
Lisa Ellrodt, Ion Freeman, Ashley Haigler, Suzanna Schmeelk
FIE4
2018 What are they Researching? Examining Industry-Based Doctoral Dissertation Research through the Lens of Machine Learning
abstract
This paper examines industry-based doctoral dissertation research in a professional computing doctoral program for full time working professionals through the lens of different machine learning algorithms to understand topics explored by full time working industry professionals. This research paper examines machine learning algorithms and the IBM Watson Discovery machine learning tool to categorize dissertation research topics defended at Pace University. The research provides insights into differences in machine learning algorithm categorization using natural language processing.
Ion Freeman, Ashley Haigler, Suzanna Schmeelk, Lisa Ellrodt, Tonya Fields
ICMLA3
2017 Learning Java in a New York City immigrant engineer retraining program
abstract
This research explores the psychology of programming and the pedagogical environment in a certificate granting urban immigrant engineer retraining program in New York City. The program is aimed at teaching under-represented immigrant engineer students to learn how to program in the Java programming language. The programming concepts and the fostered pedagogical environment were implemented in three-hour evening sessions over 15 weeks in which the students were encouraged to develop programming communities while working on computational thinking concept strands. The research findings that we report are threefold. First, we report on how we fostered building programming concepts into the curriculum into a set of activities specifically designed for an immigrant engineer retraining program with students ranging in backgrounds. We found that at that the program curriculum must be flexible enough for student learning regardless of the fact that a student may miss sessions. Second, we report on how an effective pedagogical environment, which fosters student-centered learning, was promoted so that the students could construct their own meanings of the programming concepts. Third, we report on implementation strategies unique to a retraining program, such as specific environmental constraints as well as how sessions were partitioned into components that fostered computational thinking while learning Java. Our findings provide unique insights into intervention constraints for an urban retraining program which can be used to guide and inform further retraining computer learning program research.
Suzanna Schmeelk, Fred Fontaine, Larisa Ackerman, Alfred V. Aho
FIE1
2010 Towards a unified fault-detection benchmark
abstract
Developing a unified benchmark to compare and contrast ways to detect faults is an important aspect for the future of fault detection. In this paper, we explore benchmarks used in the evaluation of popular static analysis tools in order to raise awareness for the community to work towards a unified benchmark. Additionally, we introduce an initial design for a bottom-up repository to integrate benchmarks directly with the web interface of the accessible fault taxonomy, the Common Weakness Enumeration (CWE). The repository would be dynamically linked directly into the evolving CWE. It would reflect new faults, new fault attributes, new test cases and test case attributes. The repository could be dynamically used to aggregate, compare, improve and store information about benchmarks.
Suzanna Schmeelk
PASTE1