activity
20172026
most citedCreating a Cybersecurity Concept Inventory: A Status Report on the CATS Project

7 citations · 7 across the 4 of their papers we have counts for

collaborators
Showing cs.CRShow all

9 papers · 1 filter

cs.CR2026

Verifying Provenance of Digital Media: Why the C2PA Specifications Fall Short

Enis Golaszewski, Neal Krawetz, Alan T. Sherman +8

The rapid rise of generative AI has made it easy to create convincing fake media at scale. In response, an industrial coalition has developed the Coalition for Content Provenance a…

cs.CR2025

Analysis of the Security Design, Engineering, and Implementation of the SecureDNA System

Alan T. Sherman, Jeremy J. Romanik Romano, Edward Zieglar +3

We analyze security aspects of the SecureDNA system regarding its system design, engineering, and implementation. This system enables DNA synthesizers to screen order requests agai…

cs.CR2025

Cryptographic Binding Should Not Be Optional: A Formal-Methods Analysis of FIDO UAF Channel Binding

Enis Golaszewski, Alan T. Sherman, Edward Zieglar +2

As a case study in cryptographic binding, we present a formal-methods analysis of the cryptographic channel binding mechanisms in the Fast IDentity Online (FIDO) Universal Authenti…

cs.CR2020

Experiences and Lessons Learned Creating and Validating Concept Inventories for Cybersecurity

Alan T. Sherman, Geoffrey L. Herman, Linda Oliva +5

We reflect on our ongoing journey in the educational Cybersecurity Assessment Tools (CATS) Project to create two concept inventories for cybersecurity. We identify key steps in thi…

cs.CR2020

Formal Methods Analysis of the Secure Remote Password Protocol

Alan T. Sherman, Erin Lanus, Moses Liskov +7

We analyze the Secure Remote Password (SRP) protocol for structural weaknesses using the Cryptographic Protocol Shapes Analyzer (CPSA) in the first formal analysis of SRP (specific…

cs.CR2019

The CATS Hackathon: Creating and Refining Test Items for Cybersecurity Concept Inventories

Alan T. Sherman, Linda Oliva, Enis Golaszewski +12

For two days in February 2018, 17 cybersecurity educators and professionals from government and industry met in a "hackathon" to refine existing draft multiple-choice test items, a…