Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons

Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity

Discipline
Institution
Publication Year
Publication
Publication Type
File Type

Articles 1 - 30 of 557

Full-Text Articles in Computer Sciences

Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck Sep 2026

Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck

Military Cyber Affairs

Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public safety consequences. However, attributing ransomware incidents to specific threat actors remains challenging due to ransomware-as-a-service ecosystems, actor rebranding, and the obfuscation of traditional indicators of compromise. This paper presents Semantic Shields, an NLP-driven attribution framework that leverages BERT-generated semantic embeddings and DBSCAN clustering to profile ransomware actors through the linguistic characteristics of ransom notes. Using a dataset of 295 ransom notes from 189 distinct threat groups, the framework achieved an 87.2% true positive clustering rate and …


Adaptive Phishing Url Detection Using Hybrid Fuzzy C-Means Clustering And Xgboost, Muntadher Mohammed Kareem, Rawaa I. Farhan Aug 2026

Adaptive Phishing Url Detection Using Hybrid Fuzzy C-Means Clustering And Xgboost, Muntadher Mohammed Kareem, Rawaa I. Farhan

Karbala International Journal of Modern Science

Phishing attacks continue to evolve in sophistication, rendering static detection methods increasingly ineffective. Existing URL-based approaches suffer from limited adaptability to emerging phishing patterns, mislabeled training data, and insufficient validation protocols. This paper proposes a hybrid phishing URL detection system that integrates Fuzzy C-Means (FCM) clustering with XGBoost classification, enhanced by a novel Micro Adaptive Feature Extractor (MAFE). The system employs a multi-stage pipeline: feature engineering generating 36 statistical and interaction features, MAFE producing 15 adaptive features through class-aware dynamic weighting, micro-pattern detection, and entropy analysis, and FCM with K=2 clusters providing soft membership features to XGBoost. A two-pass confidence-based …


Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen Jul 2026

Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen

Dissertations, Theses, and Projects

The increasing adoption of the Internet of Medical Things (IoMT) has improved healthcare delivery through connected medical devices while simultaneously expanding the cybersecurity risks facing healthcare organizations. Although machine learning based intrusion detection systems have demonstrated high detection accuracy, their ability to respond reliably to previously unseen cyberattacks remains uncertain. This study investigated how a Neural Network model and a Logistic Regression model classified novel cyberattacks within the IoMT environment. The Neural Network and Logistic Regression models were both trained and tested using a subset of the CICIoMT2024 benchmark dataset. The Neural Network achieved 99.82% test accuracy and a 0.94 …


A Hybrid Deep Learning Model Combining Cnn And Extreme Learning Machine For Cyberattack Classification, Israa S. Kamil Jul 2026

A Hybrid Deep Learning Model Combining Cnn And Extreme Learning Machine For Cyberattack Classification, Israa S. Kamil

Journal of Intelligent Informatics, Networking, and Cybersecurity

As ransomware attacks and zero-day exploits grow sophisticated, the need for intelligent, accurate systems to detect such threats becomes clearer. In this paper, a hybrid learning model based on Convolutional Neural Networks (CNNs) and Extreme Learning Machine (ELM) is presented to improve multiclass classification performance for cybersecurity applications. The framework combines CNNs' hierarchical feature learning with ELMs' fast classification. An attention mechanism that assigns weights to each feature based on importance is included in the final model. The hybrid model performed well on the metrics: precision = 0.97, recall = 0.98, and F1- score = 0.97, and, as expected from …


Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson Jul 2026

Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson

Journal of Cybersecurity Education, Research and Practice

In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life …


Security Limitations Of The Can Bus And Detection Through Power Fingerprinting, Ken Broden Jul 2026

Security Limitations Of The Can Bus And Detection Through Power Fingerprinting, Ken Broden

Scholarly Horizons: University of Minnesota, Morris Undergraduate Journal

This paper examines the vulnerabilities of the Controller Area Network (CAN), the standard communication protocol used in most modern vehicles. It explains why CAN is widely adopted and outlines key security weaknesses in its design. The paper then reviews recent research efforts to detect and mitigate these vulnerabilities, with particular focus on an approach to origin authentication that relies on the unique power consumption patterns of each individual electronic control unit on a CAN bus.


The Nist Artificial Intelligence Risk Management Framework: Adoption Challenges And Opportunities, Gillian Kennedy, Devin Patel, Humza Sheikh, Paul Wagner, Robert J. Honomichl Jun 2026

The Nist Artificial Intelligence Risk Management Framework: Adoption Challenges And Opportunities, Gillian Kennedy, Devin Patel, Humza Sheikh, Paul Wagner, Robert J. Honomichl

Journal of Cybersecurity Education, Research and Practice

Artificial intelligence (AI) is being adopted at an exponential rate to improve efficiency, decision-making, and cybersecurity, but its rapid integration introduces new and often poorly understood risks, including system errors, algorithmic bias, data privacy concerns, security vulnerabilities, and ethical dilemmas. This paper examines how organizations are implementing AI and evaluates the National Institute of Standards and Technology's AI Risk Management Framework (NIST AI RMF) as a tool for managing these risks. It reviews the benefits of AI adoption alongside the risks emerging from its use in business and broader society and examines the legal and ethical challenges organizations face when …


The Intersection Between Mindfulness And Cybersecurity: A Tool To Reduce Burnout And Improve Operational Effectiveness, Ivo Ricardo Dias Rosa Jun 2026

The Intersection Between Mindfulness And Cybersecurity: A Tool To Reduce Burnout And Improve Operational Effectiveness, Ivo Ricardo Dias Rosa

Journal of Cybersecurity Education, Research and Practice

Abstract: This paper offers a conceptual discussion of how mindfulness, understood as present moment awareness and deliberate attention regulation, can support cybersecurity professionals. Drawing on a narrative synthesis of workplace mindfulness, burnout, and high pressure decision making literature, we map plausible self regulation mechanisms to typical cyber defense tasks. Rather than presenting new empirical data, we develop an explanatory framework linking attention, reactivity, and recovery to decision quality, team communication, and adherence to incident playbooks. We focus on two connected outcomes: reducing burnout in roles with sustained cognitive and emotional demands, and improving operational effectiveness during critical situations such as …


Cyber-Ready Libraries, Building Digital Fortresses For Tomorrow, Adeyinka B. Tella, Oluchi Precious Ogbonna Dr, Adebola Aderemi Olatoye Mrs Jun 2026

Cyber-Ready Libraries, Building Digital Fortresses For Tomorrow, Adeyinka B. Tella, Oluchi Precious Ogbonna Dr, Adebola Aderemi Olatoye Mrs

Journal of Cybersecurity Education, Research and Practice

Background and Purpose: Libraries are evolving into highly networked information ecosystems in this age of fast digital transformation, which increases their susceptibility to cybersecurity risks. The study "Cyber-Ready Libraries: Building Digital Fortresses for Tomorrow" looks into how prepared libraries are to face cyber threats and considers methods for creating information systems that are safe, robust, and ready for the future. To safeguard digital assets and user data, the study aims to assess existing cybersecurity practices in library settings and offer a roadmap for combining technological, human, and governance solutions.

Design/Method: The existing literature, case studies, and policy frameworks pertaining …


Probabilistic Characterization Of Voltage Glitching Attacks, Anna Filyurina Jun 2026

Probabilistic Characterization Of Voltage Glitching Attacks, Anna Filyurina

Computer Science Senior Theses

Glitching, or Fault Injection, is an effective hardware hacking technique used in industry but largely unstudied in academia. Industry-led study of glitching is result-driven and overwhelmingly proprietary, meaning that a scientific approach to glitching is seen infrequently and published even less.

This thesis aims to be part of the effort to bring glitching to the attention of the academic side of the cyber security community. Specifically, this work aims to characterize and explore the probabilistic nature of fault injection that has been previously overlooked. Although from a purely result-driven point of view probabilistic nature of a phenomenon suggests unreliability and …


2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus Jun 2026

2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus

Computer Science Technical Reports

The ISTS and the Dartmouth College Cybersecurity Cluster hosted the successful, inaugural Cyber-Resilient Health Care (CRHC) Workshop, March 5th & 6th, 2026. The event theme was "Innovation and Implementation," in response to the need to shift from reactive to proactive resiliency measures in the healthcare sector. Approximately 30 experts in clinical health care, cybersecurity, medical technology, policy, and innovation met to discuss solution-focused innovations addressing hard, cyber-related problems in health care. The agenda featured keynotes, an expert panel, innovation pitches, small group discussions, and a tabletop infrastructure disaster exercise. Participants gained insights into the obstacles and solutions involved in supporting …


The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala Jun 2026

The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala

Student Theses

The rapid adoption of Large Language Models (LLMs) in software development has transformed coding practices by enabling automated code generation, completion, and optimization. Despite these advantages, concerns persist regarding the security and reliability of LLM-generated code. This study presents a comprehensive evaluation of both the functional correctness and security of code produced by three prominent LLMs as of early 2026. A total of 4,800 code snippets were generated using 100 security-focused programming prompts derived from the OWASP Top 10:2025, translated across eight natural languages and two phrasing styles (literal and natural developer-oriented prompts). To assess performance, a multi-stage experimental framework …


Principles Of Privacy And Security In Artificial Intelligence And Applications, Khang Tran May 2026

Principles Of Privacy And Security In Artificial Intelligence And Applications, Khang Tran

Dissertations

Modern artificial intelligence (AI) systems have transformed critical domains such as healthcare, software engineering, finance, and the legal system. Despite their broad impact, concerns about trustworthiness, especially regarding privacy and security, remain major obstacles to wider adoption. Addressing these concerns requires both a systematic understanding of the privacy and security risks inherent in AI systems and the development of principled foundations for trustworthy AI that safeguard client privacy and security. This goal is particularly challenging because of the complexity of modern large-scale AI systems, the trade-offs between privacy and model utility, and the need to simultaneously ensure other important properties …


Automated Evaluation Of Web Accessibility In Cybersecurity Tools, William Robert Cox May 2026

Automated Evaluation Of Web Accessibility In Cybersecurity Tools, William Robert Cox

Theses and Dissertations

Screen reader users face significant barriers when using web-based cybersecurity tools, however, the accessibility of these interfaces has received minimal systematic research attention. Existing automated evaluation tools assess Web Content Accessibility Guidelines (WCAG) conformance but do not measure the practical operability of complex and domain-specific interfaces for users of assistive technology. This dissertation presents the Deciphering Interfaces for Your Accessibility (DIYA) framework, an open-source automated auditing framework that evaluates cybersecurity tool web interfaces across eight normalized dimensions: WCAG conformance, Accessible Rich Internet Applications (ARIA) usage, semantic structure, keyboard operability, form accessibility, dynamic content accessibility, interaction cost, and screen reader readiness. …


Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder May 2026

Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder

Doctoral Dissertations and Master's Theses

Cybersecurity has become a global concern as cyber-attacks have become more common, and the cost of the damage caused by them continues to increase. There are several approaches to improve the cyber security of systems such as Digital Signatures, hashing, watermarking, and encryption among others. Digital Signatures are a cryptographic technique used to verify the authenticity and integrity of digital messages or documents. Digital Signatures use a combination of hashing and public-private key encryption to verify the authenticity and integrity of videos, just as they are used for documents and messages. As a result of using a combination of other …


The Impact Of Quantum Computing On Ransomware, Byron Denham May 2026

The Impact Of Quantum Computing On Ransomware, Byron Denham

Graduate Theses and Dissertations

Ransomware is one of the most pervasive and dangerous threats to cybersecurity today. Attacks involving ransomware have been responsible for the disruption of critical services in many fields including healthcare, education, and government. In the current paradigm, crypto ransomware relies on asymmetric cryptography to perform its operations in a way that ensure the victim’s only chance for file recovery is by paying the attacker’s requested ransom payment. However, advancements in quantum computing threaten the asymmetric cryptography that ransomware relies on. It has been shown that, once developed, a sufficiently powerful quantum computer will have the ability to break asymmetric cryptography …


A Generative Ai Method For Minority Class Handling In Anomaly Detection With Drift And Explainability Analysis, Kelvin J. Mwiga, Mussa A. Dida, Ahmad Mohsin, Iqbal H. Sarker May 2026

A Generative Ai Method For Minority Class Handling In Anomaly Detection With Drift And Explainability Analysis, Kelvin J. Mwiga, Mussa A. Dida, Ahmad Mohsin, Iqbal H. Sarker

Research outputs 2022 to 2026

Artificial Intelligence, particularly machine learning (ML) algorithms, plays a crucial role in detecting cyberattacks, including anomalies and intrusions. However, machine learning models trained on imbalanced cybersecurity datasets often struggle to accurately detect minority data instances and potential threats, thereby weakening overall system security. Despite extensive research, a persistent challenge is the inadequate explanation for model predictions concerning minority data classes. This study aims to address these limitations by developing a generative AI-based approach to manage minority classes in anomaly detection, incorporating concept drift handling and explainability analysis. We introduce an over-sampling technique, CGGReaT, designed to enhance the presence of minority …


The Texture Of A Threat: Adversarial Training, Cnns, And Obfuscated Malware Detection, Kaelyn Haynie Apr 2026

The Texture Of A Threat: Adversarial Training, Cnns, And Obfuscated Malware Detection, Kaelyn Haynie

Senior Honors Theses

Accurately detecting malicious programs is an expanding field of research for machine learning (ML), with a novel approach incorporating a bytecode-to-image pipeline that produces images representative of software. These images are provided to convolutional neural networks (CNNs) to be examined for malicious pattern indicators. However, CNNs struggle to generalize these patterns effectively while still being robust against adversarial data, an issue which this research addresses with adversarial training. In this paper, three unique CNN architectures (a DBFS-MC-inspired baseline, MIRACLE, and PSP-CNN) are trained for binary classification with 15,000 benign and malicious software samples encoded into images for Android, Windows, and …


Adopting Artificial Intelligence: Cross-Sector Analysis Of Ai Adoption Risks, Brandon Saari, Yona Berger, Yanett Munoz, Alex Agnick, Paul Wagner, Robert J. Honomichl Apr 2026

Adopting Artificial Intelligence: Cross-Sector Analysis Of Ai Adoption Risks, Brandon Saari, Yona Berger, Yanett Munoz, Alex Agnick, Paul Wagner, Robert J. Honomichl

Journal of Cybersecurity Education, Research and Practice

Artificial intelligence (AI) is rapidly being adopted across public and private sectors. This offers significant gains in efficiency, decision making, and access to information. At the same time, AI introduces complex risks related to cybersecurity, privacy, bias, transparency, accountability, and equity that existing governance and security frameworks do not fully address. This paper presents a cross-sector literature review and comparative analysis of AI adoption risks and mitigation strategies across four critical domains: the federal government, libraries, K–12 education, and healthcare. Drawing on peer-reviewed research, institutional frameworks, and policy guidance, the study identifies sector-specific challenges alongside shared systemic gaps, including insufficient …


Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs, Brittni Hardie Apr 2026

Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs, Brittni Hardie

Theses and Dissertations

This study examines the intersection of cybersecurity education, open educational resources (OER), and rural higher education through a systematic review of current literature and an exploratory survey of rural community college faculty. The purpose of this research, consistent with the approved Institutional Review Board (IRB) protocol, was to understand how OER can be leveraged to design and deliver an affordable, high-quality System Security course within a rural higher-education environment. As cybersecurity workforce shortages continue to grow across the United States, rural institutions face persistent challenges in sustaining high-quality programs due to financial constraints, limited faculty capacity, and rapidly evolving curriculum …


Behavioral, System, And Informational Cyberattacks: A Human-In-The-Loop Driving Simulator Experiment, Samuel Petkac Apr 2026

Behavioral, System, And Informational Cyberattacks: A Human-In-The-Loop Driving Simulator Experiment, Samuel Petkac

Psychology Theses & Dissertations

Advanced technologies such as sensors and AI/ML algorithms have enabled increasing levels of automated driving system that detects, responds, and even predicts changes in a driving environment supported by wireless connectivity to nearby vehicles and infrastructure. Such connected and automated vehicles (CAVs) can be particularly vulnerable to cyberattacks targeting not only infotainment systems but also firmware and other applications, critically compromising driver safety. As we anticipate a “mixed” traffic where vehicles with various levels of automated technologies share the road for the foreseeable future, it is urgent to systematically examine types of possible cyberattacks and control human behaviors in such …


A.I.R.E., Laurene Robinson Apr 2026

A.I.R.E., Laurene Robinson

Presentations - 2026

•Cybersecurity analysts rely on reverse engineering to understand suspicious software. •Ghidra can surface decompiled code, but it does not fully explain function purpose, behavioral meaning, or analyst priority. •When symbols are stripped and context is weak, analysts must still reconstruct intent manually from low-level output. •That process is Time-consuming , complex and , operationally costly


A.I.R.E. - Ai-Assisted Reverse Engineering, Laurene Robinson Apr 2026

A.I.R.E. - Ai-Assisted Reverse Engineering, Laurene Robinson

Posters - 2026

Reverse engineering plays a vital role in cybersecurity by helping analysts examine unknown binaries, investigate malware, identify vulnerabilities, and better protect sensitive systems. However, once a program is compiled and stripped, the meaningful names that describe its behavior are lost, leaving behind generic function labels like FUN_00401a30. Analysts must then manually interpret decompiled code, trace call chains, and infer program behavior function by function, which is slow and mentally demanding on large binaries. To address this challenge, this project introduces A.I.R.E., a local Ghidra extension that extracts contextual evidence from stripped functions and uses a locally hosted language model to …


Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni Apr 2026

Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni

Research outputs 2022 to 2026

Cybersecurity operations in IoT and edge environments require fast, evidence-grounded decisions under strict resource and trust constraints. While large language models can support triage and incident analysis, their parametric knowledge may be outdated and prone to hallucination. Retrieval-augmented generation (RAG) improves grounding by conditioning responses on retrieved evidence, but also introduces new risks such as knowledge-base poisoning, indirect prompt injection, and embedding leakage. Federated learning enables collaborative adaptation without centralizing sensitive data, motivating federated RAG (FedRAG) architectures for distributed cybersecurity deployments. This study presents a deployment-oriented scoping review of FedRAG for cybersecurity. The review follows PRISMA-ScR reporting guidance and synthesizes …


Foxbuddy, Luis Eduardo Garza Jr. Apr 2026

Foxbuddy, Luis Eduardo Garza Jr.

Posters - 2026

Emergency preparedness remains a significant challenge for individuals due to disorganized resource management and lack of accessible guidance. Additionally, cybersecurity risks during emergencies are often overlooked, leaving individuals vulnerable to digital threats such as phishing, scams, and data exposure. FoxBuddy provides a centralized, user-friendly platform that enhances both physical preparedness and cybersecurity awareness.


Review On Data Privacy And Security For Iot-Based Multifunctional Layers Of Cyber-Physical Systems In Smart Grids, Mohammad Kamrul Hasan, Md Mehedi Hasan, Nabeel Al-Qirim, Siti Norul Huda Sheikh Abdullah, Shayla Islam, Md Abdur Razzaque Mar 2026

Review On Data Privacy And Security For Iot-Based Multifunctional Layers Of Cyber-Physical Systems In Smart Grids, Mohammad Kamrul Hasan, Md Mehedi Hasan, Nabeel Al-Qirim, Siti Norul Huda Sheikh Abdullah, Shayla Islam, Md Abdur Razzaque

All Works

Smart grid cyber-physical systems (SG-CPS) are intelligent platforms that incorporate IoT-enabled multifunctional layers including the physical, perception, communication, cyber, and application layers. It includes supervisory control and data acquisition, wide-area measurement systems, and advanced metering infrastructure for remote data aggregation, monitoring, and control operations. From an environmental perspective, these green technologies support two-way operations, which generate and transmit data over wired and wireless communication systems. However, this critical infrastructure faces data privacy and cybersecurity challenges. Hence, extensive research is required to address data privacy and security gaps to strengthen national grid cybersecurity and reduce economic losses. Therefore, this review highlights …


Cyber Science Education Meets Healthcare Technology, Angela Spencer Feb 2026

Cyber Science Education Meets Healthcare Technology, Angela Spencer

Journal of Cybersecurity Education, Research and Practice

The research investigates how cyber science education combines with healthcare technology during the digital age to resolve a fundamental research gap in these two advancing areas. A combined approach utilizing extensive surveys and detailed interviews evaluates the functionality of learning platforms as well as cybersecurity measures and potential uses of emerging virtual reality (VR) and augmented reality (AR) tools to improve both educational and clinical environments. The research document describes its methodologies thoroughly while. The research documents multiple quantitative and qualitative results before performing its analysis, which leads to strategy development for digit. The researchers worked to find ways that …


Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty Jan 2026

Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty

Center for Secure and Intelligent Critical Systems (CSICS) Publications

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models …


Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach, Md Al Amin, Mohammad Shafat Ahsan, Jannatul Maua, Arifa Akter Eva, M.F. Mridha, Md. Jakir Hossen Jan 2026

Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach, Md Al Amin, Mohammad Shafat Ahsan, Jannatul Maua, Arifa Akter Eva, M.F. Mridha, Md. Jakir Hossen

Student Publications [Scholarly]

Modern intelligent transportation systems (ITS) increasingly rely on connected electronic control units (ECUs), exposing in-vehicle networks to cyber-attacks such as message injection on the Controller Area Network (CAN) bus. While prior work has focused on post-factum detection, this paper addresses the underexplored task of forecasting cyber-attacks before they occur. We propose a spatio-temporal graph neural network (STGNN) architecture that models CAN traffic as a dynamic graph sequence, where nodes represent active CAN IDs and edges capture statistical co-activation patterns. Each graph snapshot encodes temporal features such as inter-arrival statistics and entropy, and is processed using graph attention layers followed by …


A Preliminary Exploratory Assessment Of Chatgpt To Generating Stride Data Flow Diagrams, Hassan Alsayegh, Mohamed El-Attar Jan 2026

A Preliminary Exploratory Assessment Of Chatgpt To Generating Stride Data Flow Diagrams, Hassan Alsayegh, Mohamed El-Attar

All Works

Threat modeling is a core activity in security-by-design practices, enabling early identification of architectural weaknesses before system implementation. The drawings used during STRIDE analysis are typically Data Flow Diagrams (DFDs), referred to as “STRIDE diagrams” in this paper. STRIDE diagrams provide a visual approach for categorizing security threats; however, constructing accurate STRIDE diagrams require experience and is often time-consuming. Recent advances in Large Language Models (LLMs), such as ChatGPT, raise important questions about their suitability for supporting structured security modeling tasks. This study presents a preliminary exploratory assessment of ChatGPT’s ability to generate, analyse, and iteratively refine STRIDE diagrams from …