Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Information Security (10)
- Artificial Intelligence and Robotics (9)
- Social and Behavioral Sciences (5)
- Medicine and Health Sciences (4)
- Psychology (4)
-
- Business (3)
- OS and Networks (3)
- Systems Architecture (3)
- Technology and Innovation (3)
- Education (2)
- Educational Technology (2)
- Health Information Technology (2)
- Organizational Behavior and Theory (2)
- Public Health (2)
- Social Psychology (2)
- Sociology (2)
- Software Engineering (2)
- Telemedicine (2)
- Applied Behavior Analysis (1)
- Child Psychology (1)
- Clinical Psychology (1)
- Communication (1)
- Communication Technology and New Media (1)
- Consumer Protection Law (1)
- Criminology (1)
- Criminology and Criminal Justice (1)
- Curriculum and Instruction (1)
- Keyword
-
- Machine Learning (4)
- Cybersecurity (3)
- Artificial intelligence (2)
- Binary Security (2)
- Buffer Overflows (2)
-
- GPT-2 (2)
- LLVM (2)
- Machine learning (2)
- Networks (2)
- Privacy (2)
- RoBERTa (2)
- Romance scams (2)
- Unikernel Security (2)
- Word2vec (2)
- AI governance (1)
- Adversarial Robustness (1)
- Application protection (1)
- Attacker-Centric Approach (1)
- BERT (1)
- Behavioral Analytics (1)
- Bidirectional encoder (1)
- Binary security (1)
- Buffer Over- flows (1)
- Buffer overflow (1)
- Burnout (1)
- CI/CD pipelines (1)
- Calico (1)
- Cloud networking (1)
- Computing methodologies (1)
- Corpus Analysis (1)
Articles 1 - 23 of 23
Full-Text Articles in Cybersecurity
A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath
A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath
Research & Publications
The Internet of Medical Things (IoMT) has transformed health care delivery through medical devices, remote patient monitoring, and real-time clinical decision support. However, the proliferation of IoMT devices introduces security vulnerabilities that put patient safety and data privacy at risk. Intrusion Detection Systems (IDS) have emerged as essential components for protecting IoMT networks from cyberattacks. This article presents a systematic review of IoMT-IDS research, analyzing 53 high-quality papers published between 2020 and 2025, identified through database searches spanning 2016–2025 across IEEE Xplore, Springer, ScienceDirect, and ACM Digital Library. We organize the literature through a comprehensive taxonomy spanning classical machine learning …
Romance Scam Reporting And Support: Help-Seeking Timing, Trust, And Escalation, Ld Herrera
Romance Scam Reporting And Support: Help-Seeking Timing, Trust, And Escalation, Ld Herrera
Research & Publications
Built on social engineering and identity deception, romance scams often create financial loss and distress. For victims, it can be difficult to know where to go, what information is needed, and what outcomes are realistic. This paper reports results from an anonymous survey of people who were targeted by or experienced a romance scam (completed surveys: n=386), focusing on (1) when and whether victims first reach out for help, (2) perceived difficulty and confidence in navigating support, (3) how trust relates to expectations of assistance, and (4) how loss severity relates to transfer-method complexity. When help was sought, it was …
Bridging The Gap: A Systematic Review Of Cyber Conflict Forecasting Models And The Case For Ai-Driven Dynamic Frameworks, Salim Arfaoui, Youssef Harrath, Omar El-Gayar
Bridging The Gap: A Systematic Review Of Cyber Conflict Forecasting Models And The Case For Ai-Driven Dynamic Frameworks, Salim Arfaoui, Youssef Harrath, Omar El-Gayar
Research & Publications
Cyber conflict forecasting remains constrained by static models that overlook the integration of geopolitical context with technical indicators. This systematic literature review examines 58 studies (2010–2025) using PRISMA guidelines and an InputProcess-Output framework to classify approaches and identify key gaps. Quantitative methods dominate (67%), yet only 14% incorporate geopolitical variables, despite the political nature of cyber conflict. Major limitations include adversarial adaptation blindness (85% assume static behavior), coarse temporal granularity (72% use daily+ intervals), lack of uncertainty quantification (75%), and minimal modeling of cross-domain escalation (92% cyber-only focus). Strategic forecasting is rare, with just 14% providing long-term insights and 16% …
Privacy In Flux: A 35-Year Review Of Trends, Legal Evolution, And Emerging Challenges, Kong Phang, Jihene Kaabi
Privacy In Flux: A 35-Year Review Of Trends, Legal Evolution, And Emerging Challenges, Kong Phang, Jihene Kaabi
Research & Publications
Privacy harms have expanded alongside rapid technological change, challenging the adequacy of existing regulatory frameworks. This systematic review (1990–2025) systematically maps documented privacy harms to specific legal mechanisms and observed enforcement outcomes across jurisdictions, using PRISMA-guided methods and ROBIS risk-of-bias assessment. We synthesize evidence on major regimes (e.g., GDPR, COPPA, CCPA, HIPAA, GLBA) and conduct comparative legal analysis across the U.S., E.U., and underexplored regions in Asia, Latin America, and Africa. Key findings indicate increased recognition of data subject rights, persistent gaps in cross-border data governance, and emerging risks from AI/ML/LLMs, IoT, and blockchain, including data breaches, algorithmic discrimination, and …
Romance Scam Victimization: A Survey-Based Examination Of Financial, Psychological, And Reporting Factors, Ld Herrera
Romance Scam Victimization: A Survey-Based Examination Of Financial, Psychological, And Reporting Factors, Ld Herrera
Research & Publications
Romance scams are a growing type of cybercrime in which perpetrators develop and exploit fraudulent romantic relationships with victims to obtain financial resources. These schemes cause substantial economic and psychological damage, yet they are significantly underreported. Official 2022 reports indicate only \$1.3 billion lost to romance scams in the US, but the true financial toll is likely much higher.
Using survey data from 366 victims, this study examines the financial and psychological toll of romance scams, reporting patterns, obstacles to seeking help, and victims' perceptions of received help. Most of the victims (60.9\%) did not seek help from any source, …
Ceker: A Generalizable Llm Framework For Literature Analysis With A Case Study In Unikernel Security, Alex Wollman, John Hastings
Ceker: A Generalizable Llm Framework For Literature Analysis With A Case Study In Unikernel Security, Alex Wollman, John Hastings
Research & Publications
Literature reviews are a critical component of formulating and justifying new research, but are a manual and often time-consuming process. This research introduces a novel, generalizable approach to literature analysis called CEKER which uses a three-step process to streamline the collection of literature, the extraction of key insights, and the summarized analysis of key trends and gaps. Leveraging Large Language Models (LLMs), this methodology represents a significant shift from traditional manual literature reviews, offering a scalable, flexible, and repeatable approach that can be applied across diverse research domains. A case study on unikernel security illustrates CEKER's ability to generate novel …
Impact Of Data Snooping On Deep Learning Models For Locating Vulnerabilities In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu
Impact Of Data Snooping On Deep Learning Models For Locating Vulnerabilities In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu
Research & Publications
This study examines the impact of data snooping on neural networks used to detect vulnerabilities in lifted code, and builds on previous research that used word2vec and unidirectional and bidirectional transformer-based embeddings. The research specifically focuses on how model performance is affected when embedding models are trained with datasets, which include samples used for neural network training and validation. The results show that introducing data snooping did not significantly alter model performance, suggesting that data snooping had a minimal impact or that samples randomly dropped as part of the methodology contained hidden features critical to achieving optimal performance. In addition, …
Advancing Devsecops In Smes: Challenges And Best Practices For Secure Ci/Cd Pipelines, Jayaprakashreddy Cheenepalli, John Hastings, Khandaker Mamun Ahmed, Chad Fenner
Advancing Devsecops In Smes: Challenges And Best Practices For Secure Ci/Cd Pipelines, Jayaprakashreddy Cheenepalli, John Hastings, Khandaker Mamun Ahmed, Chad Fenner
Research & Publications
This study evaluates the adoption of DevSecOps among small and medium-sized enterprises (SMEs), identifying key challenges, best practices, and future trends. Through a mixed methods approach backed by the Technology Acceptance Model (TAM) and Diffusion of Innovations (DOI) theory, we analyzed survey data from 405 SME professionals, revealing that while 68% have implemented DevSecOps, adoption is hindered by technical complexity (41%), resource constraints (35%), and cultural resistance (38%). Despite strong leadership prioritization of security (73%), automation gaps persist, with only 12% of organizations conducting security scans per commit. Our findings highlight a growing integration of security tools, particularly API security …
Scalable And Ethical Insider Threat Detection Through Data Synthesis And Analysis By Llms, Haywood Gelman, John Hastings
Scalable And Ethical Insider Threat Detection Through Data Synthesis And Analysis By Llms, Haywood Gelman, John Hastings
Research & Publications
Insider threats wield an outsized influence on organizations, disproportionate to their small numbers. This is due to the internal access insiders have to systems, information, and infrastructure. Signals for such risks may be found in anonymous submissions to public web-based job search site reviews. This research studies the potential for large language models (LLMs) to analyze and detect insider threat sentiment within job site reviews. Addressing ethical data collection concerns, this research utilizes synthetic data generation using LLMs alongside existing job review datasets. A comparative analysis of sentiment scores generated by LLMs is benchmarked against expert human scoring. Findings reveal …
Comparing Unidirectional, Bidirectional, And Word2vec Models For Discovering Vulnerabilities In Compiled Lifted Code, Gary Mccully, John Hastings, Shengjie Xu, Adam Fortier
Comparing Unidirectional, Bidirectional, And Word2vec Models For Discovering Vulnerabilities In Compiled Lifted Code, Gary Mccully, John Hastings, Shengjie Xu, Adam Fortier
Research & Publications
Ransomware and other forms of malware cause significant financial and operational damage to organizations by exploiting long-standing and often difficult-to-detect software vulnerabilities. To detect vulnerabilities such as buffer overflows in compiled code, this research investigates the application of unidirectional transformer-based embeddings, specifically GPT-2. Using a dataset of LLVM functions, we trained a GPT-2 model to generate embeddings, which were subsequently used to build LSTM neural networks to differentiate between vulnerable and non-vulnerable code. Our study reveals that embeddings from the GPT-2 model significantly outperform those from bidirectional models of BERT and RoBERTa, achieving an accuracy of 92.5\% and an F1-score …
A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings
A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings
Research & Publications
This study investigates the prevalence and underlying causes of work-related stress and burnout among cybersecurity professionals using a quantitative survey approach guided by the Job Demands-Resources model. Analysis of responses from 50 cybersecurity practitioners reveals an alarming reality: 44% report experiencing severe work-related stress and burnout, while an additional 28% are uncertain about their condition. The demanding nature of cybersecurity roles, unrealistic expectations, and unsupportive organizational cultures emerge as primary factors fueling this crisis. Notably, 66% of respondents perceive cybersecurity jobs as more stressful than other IT positions, with 84% facing additional challenges due to the pandemic and recent high-profile …
Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu
Tedvil: Leveraging Transformer-Based Embeddings For Vulnerability Detection In Lifted Code, Gary Mccully, John Hastings, Shengjie Xu
Research & Publications
Ransomware and other malware inflict devastating financial and operational damage on organizations worldwide by exploiting deeply embedded, hard-to-detect vulnerabilities in their systems. Detecting these vulnerabilities in compiled code before malicious actors exploit them remains a critical challenge in cybersecurity. This research introduces TEDVIL (Transformer-based Embeddings for Discovering Vulnerabilities in Lifted Code), a novel framework which uses transformer-based embeddings to train neural networks to detect vulnerabilities in lifted code. The framework was implemented using bidirectional (BERT and RoBERTa) and unidirectional (GPT-1 and GPT-2) transformer-based models to generate embeddings for training Long Short-Term Memory (LSTM) neural networks to detect stack-based buffer overflows …
A Systematic Review And Taxonomy For Privacy Breach Classification: Trends, Gaps, And Future Directions, Clint Fuchs, John Hastings
A Systematic Review And Taxonomy For Privacy Breach Classification: Trends, Gaps, And Future Directions, Clint Fuchs, John Hastings
Research & Publications
In response to the rising frequency and complexity of data breaches and evolving global privacy regulations, this study presents a comprehensive examination of academic literature on the classification of privacy breaches and violations between 2010-2024. Through a systematic literature review, a corpus of screened studies was assembled and analyzed to identify primary research themes, emerging trends, and gaps in the field. A novel taxonomy is introduced to guide efforts by categorizing research efforts into seven domains: breach classification, report classification, breach detection, threat detection, breach prediction, risk analysis, and threat classification. An analysis reveals that breach classification and detection dominate …
Toward An Insider Threat Education Platform: A Theoretical Literature Review, Haywood Gelman, John D. Hastings, David Kenley, Eleanor Loiacono
Toward An Insider Threat Education Platform: A Theoretical Literature Review, Haywood Gelman, John D. Hastings, David Kenley, Eleanor Loiacono
Research & Publications
Insider threats (InTs) within organizations are small in number but have a disproportionate ability to damage systems, information, and infrastructure. Existing InT research studies the problem from psychological, technical, and educational perspectives. Proposed theories include research on psychological indicators, machine learning, user behavioral log analysis, and educational methods to teach employees recognition and mitigation techniques. Because InTs are a human problem, training methods that address InT detection from a behavioral perspective are critical. While numerous technological and psychological theories exist on detection, prevention, and mitigation, few training methods prioritize psychological indicators. This literature review studied peer-reviewed, InT research organized by …
Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang
Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang
Research & Publications
The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach …
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings
Research & Publications
This paper presents a multi-cloud networking architecture built on zero trust principles and micro-segmentation to provide secure connectivity with authentication, authorization, and encryption in transit. The proposed design includes the multi-cloud network to support a wide range of applications and workload use cases, compute resources including containers, virtual machines, and cloud-native services, including IaaS (Infrastructure as a Service), PaaS (Platform as a service). Furthermore, open-source tools provide flexibility, agility, and independence from locking to one vendor technology. The paper provides a secure architecture with micro-segmentation and follows zero trust principles to solve multi-fold security and operational challenges.
Bridging The Protection Gap: Innovative Approaches To Shield Older Adults From Ai-Enhanced Scams, Ld Herrera, London Van Sickle, Ashley L. Podhradsky
Bridging The Protection Gap: Innovative Approaches To Shield Older Adults From Ai-Enhanced Scams, Ld Herrera, London Van Sickle, Ashley L. Podhradsky
Research & Publications
Artificial Intelligence (AI) is rapidly gaining popularity as individuals, groups, and organizations discover and apply its expanding capabilities. Generative AI creates or alters various content types including text, image, audio, and video that are realistic and challenging to identify as AI-generated constructs. However, guardrails preventing malicious use of AI are easily bypassed. Numerous indications suggest that scammers are already using AI to enhance already successful scams, improving scam effectiveness, speed and credibility, while reducing detectability of scams that target older adults, who are known to be slow to adopt new technologies. Through hypothetical cases analysis of two leading scams, the …
Bi-Directional Transformers Vs. Word2vec: Discovering Vulnerabilities In Lifted Compiled Code, Gary Mccully, John Hastings, Shengjie Xu, Adam Fortier
Bi-Directional Transformers Vs. Word2vec: Discovering Vulnerabilities In Lifted Compiled Code, Gary Mccully, John Hastings, Shengjie Xu, Adam Fortier
Research & Publications
Detecting vulnerabilities within compiled binaries is challenging due to lost high-level code structures and other factors such as architectural dependencies, compilers, and optimization options. To address these obstacles, this research explores vulnerability detection using natural language processing (NLP) embedding techniques with word2vec, BERT, and RoBERTa to learn semantics from intermediate representation (LLVM IR) code. Long short-term memory (LSTM) neural networks were trained on embeddings from encoders created using approximately 48k LLVM functions from the Juliet dataset. This study is pioneering in its comparison of word2vec models with multiple bidirectional transformers (BERT, RoBERTa) embeddings built using LLVM code to train neural …
The Psychological Impacts Of Algorithmic And Ai-Driven Social Media On Teenagers: A Call To Action, Sunil Arora, Sahil Arora, John Hastings
The Psychological Impacts Of Algorithmic And Ai-Driven Social Media On Teenagers: A Call To Action, Sunil Arora, Sahil Arora, John Hastings
Research & Publications
This study investigates the meta-issues surrounding social media, which, while theoretically designed to enhance social interactions and improve our social lives by facilitating the sharing of personal experiences and life events, often results in adverse psychological impacts. Our investigation reveals a paradoxical outcome: rather than fostering closer relationships and improving social lives, the algorithms and structures that underlie social media platforms inadvertently contribute to a profound psychological impact on individuals, influencing them in unforeseen ways. This phenomenon is particularly pronounced among teenagers, who are disproportionately affected by curated online personas, peer pressure to present a perfect digital image, and the …
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings
Transforming Information Systems Management: A Reference Model For Digital Engineering Integration, John Bonar, John Hastings
Research & Publications
Digital engineering practices offer significant yet underutilized potential for improving information assurance and system lifecycle management. This paper examines how capabilities like model-based engineering, digital threads, and integrated product lifecycles can address gaps in prevailing frameworks. A reference model demonstrates applying digital engineering techniques to a reference information system, exhibiting enhanced traceability, risk visibility, accuracy, and integration. The model links strategic needs to requirements and architecture while reusing authoritative elements across views. Analysis of the model shows digital engineering closes gaps in compliance, monitoring, change management, and risk assessment. Findings indicate purposeful digital engineering adoption could transform cybersecurity, operations, service …
Confronting The Reproducibility Crisis: A Case Study Of Challenges In Cybersecurity Ai, Richard H. Moulton, Gary A. Mccully, John D. Hastings
Confronting The Reproducibility Crisis: A Case Study Of Challenges In Cybersecurity Ai, Richard H. Moulton, Gary A. Mccully, John D. Hastings
Research & Publications
In the rapidly evolving field of cybersecurity, ensuring the reproducibility of AI-driven research is critical to maintaining the reliability and integrity of security systems. This paper addresses the reproducibility crisis within the domain of adversarial robustness—a key area in AI-based cybersecurity that focuses on defending deep neural networks against malicious perturbations. Through a detailed case study, we attempt to validate results from prior work on certified robustness using the VeriGauge toolkit, revealing significant challenges due to software and hardware incompatibilities, version conflicts, and obsolescence. Our findings underscore the urgent need for standardized methodologies, containerization, and comprehensive documentation to ensure the …
Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan
Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan
Research & Publications
As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …
A Survey Of Unikernel Security: Insights And Trends From A Quantitative Analysis, Alex Wollman, John Hastings
A Survey Of Unikernel Security: Insights And Trends From A Quantitative Analysis, Alex Wollman, John Hastings
Research & Publications
Unikernels, an evolution of LibOSs, are emerging as a virtualization technology to rival those currently used by cloud providers. Unikernels combine the user and kernel space into one ``uni''fied memory space and omit functionality that is not necessary for its application to run, thus drastically reducing the required resources. The removed functionality is significant however, and includes components that have become common security technologies such as Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), and Non-executable bits (NX bits). This raises questions about the security of unikernels. This research presents a quantitative methodology using TF-IDF to analyze the focus …