Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Old Dominion University

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 1 - 30 of 92

Full-Text Articles in Cybersecurity

Improving Fairness On Semantic Segmentation Using Large Language Models, Samuel E. Burggraf May 2026

Improving Fairness On Semantic Segmentation Using Large Language Models, Samuel E. Burggraf

Electrical & Computer Engineering Projects for D. Eng. Degree

As machine learning systems are increasingly integrated into critical decision-making processes, ensuring fairness in their design and implementation has become a significant concern. While fairness research has primarily focused on specific protected attributes, less attention has been given to spatial fairness, which can affect individuals at specific locations. If fairness is not addressed, models may systematically underperform in certain regions or across populations which can lead to unequal access to accurate predictions and potentially biased decision-making. Fairness considerations should extend across all machine learning applications to align with the National Institute of Standards and Technology (NIST) guidelines of fair and …


Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir Apr 2026

Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir

Cybersecurity Undergraduate Research Showcase

Universities face heightened vulnerability to phishing attacks due to their open information-sharing culture and diverse user populations. This study examines how phishing exploits human factors within campus environments and evaluates three major training strategies: embedded phishing, microlearning, and role-based instruction to understand their individual and combined effectiveness. I explored studies that implement these strategies in pairs and use the strategies alone, identified trends in susceptibility reduction, behavioral reinforcement, and contextual relevance. I suggest that, while each method independently improves user awareness, multiple approaches offer stronger, more adaptable protection by addressing both psychological triggers and role-specific risks. The paper contributes a …


Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs Apr 2026

Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs

Cybersecurity Undergraduate Research Showcase

Prompt injection attacks, ranked the number-one vulnerability in AI systems by OWASP's 2025 Top 10 for Large Language Model Applications, remain largely unsolved, and this survey examines why. As large language models (LLMs) are deployed across enterprise workflows, agentic systems, and consumer tools, their fundamental inability to distinguish trusted instructions from untrusted user data has created a persistent and expanding attack surface. This paper presents a structured taxonomy of prompt injection attack vectors, including direct injection, indirect injection, multimodal attacks, tool and agent exploitation, hybrid chained techniques, and autonomous propagating threats. These vectors are mapped across five impact categories (data …


Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry Apr 2026

Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry

Cybersecurity Undergraduate Research Showcase

Network Intrusion Detection Systems are tools used to monitor network traffic and alert to suspicious or harmful activity before it can cause harm. Signature-based versions of these systems are a foundation for intrusion detection, operating by finding common patterns and forming malicious signatures. However, three developments in modern network environments have greatly impacted the significance of Network Intrusion Detection Systems. These three developments are the near-complete adoption of end-to-end encryption, the use of sophisticated packet fragmentation techniques, and the processing demands of high-throughput networks. Encryption makes deep packet inspection practically infeasible by transforming inspectable payloads into ciphertext, forcing NIDS to …


Artificial Intelligence Moderation In Online Gaming: A Cybersecurity Analysis Of Risks And Defenses, Labib Khan Apr 2026

Artificial Intelligence Moderation In Online Gaming: A Cybersecurity Analysis Of Risks And Defenses, Labib Khan

Cybersecurity Undergraduate Research Showcase

This research paper will examine the role of artificial intelligence (AI) moderation systems in enhancing cybersecurity within online gaming environments. As multiplayer platforms increasingly rely on real-time text, voice communication, and user-generated content, developers have implemented AI-driven tools such as natural language processing (NLP), speech recognition, and behavioral analytics to detect harassment, toxic behavior, cheating coordination, and other malicious activity. These systems enable gaming companies to efficiently monitor large volumes of player interactions, improving response times and helping maintain safer and more controlled digital environments for users across global gaming communities of varying sizes and activity levels.

While these technologies …


Escaping Isolation: An Analysis Of Virtual Machine And Container Breakout Vulnerabilities, Felix Iov Apr 2026

Escaping Isolation: An Analysis Of Virtual Machine And Container Breakout Vulnerabilities, Felix Iov

Cybersecurity Undergraduate Research Showcase

Cloud computing providers rely on multi-tenant architectures to maximize resource efficiency. This infrastructure depends on virtualization, which provides isolation between clients. This comes primarily in the form of Virtual Machines (VMs) and Containers. However, “breakout attacks” or “escapes” are a critical threat where attackers bypass these isolation layers to gain unauthorized access to the host system and neighboring environments. This paper surveys virtualization escape threats and analyzes three case studies: a runc container escape (Leaky Vessels), a VMware ESXi VM escape (VSOCKPuppet), and an NVIDIA GPU container escape (NVIDIAScape). Each demonstrates different attack surfaces, including file descriptor misuse, kernel driver …


Bio-Cybersecurity: Securing The Healthcare Industry, Amanda D. Coleman Apr 2026

Bio-Cybersecurity: Securing The Healthcare Industry, Amanda D. Coleman

Cybersecurity Undergraduate Research Showcase

Bio-cybersecurity refers to the aspect of cybersecurity that applies to the biological sciences and the protection of digital biomedical information. Today’s healthcare industry has evolved with the enhancement of internet and biomedical technology. While hospitals and private medical providers remain compliant with the Health Information Portability and Accountability Act (HIPAA) through traditional means of securing documented patient information, the emergence of beneficial internet-based healthcare services like virtual appointments and digital patient records requires new policies and healthcare cybersecurity frameworks to protect sensitive information from unauthorized access. This paper examines the role of cybersecurity in healthcare, the vulnerabilities that exist and …


Ai's Double Edged Sword: Fighting Against Synthetic Csam, Shekhinah Adra Green Apr 2026

Ai's Double Edged Sword: Fighting Against Synthetic Csam, Shekhinah Adra Green

Cybersecurity Undergraduate Research Showcase

The rapid advancements in generative artificial intelligence has introduced new challenges in the production and distribution of synthetic child sexual abuse material (CSAM). AI has the capabilities of creating highly realistic imagery and videos, which  raises serious legal and ethical concerns, increasing the risk of harm, exploitation, and revictimization.

This paper discusses the legal improvements needed in order to lower the change of legal loopholes, how digital forensic analyst use advanced tools to identify and investigate synthetic material, and different methods to start the reduction of synthetic CSAM.


The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds Apr 2026

The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds

School of Cybersecurity Master's Level Projects and Papers

Cybercrime has evolved significantly with the integration of artificial intelligence (AI), transforming traditional phishing and social engineering attacks into highly sophisticated and personalized threats. While early phishing attempts relied on generic messaging and low success rates, modern AI-driven attacks leverage advanced data analytics, natural language processing, and behavioral prediction to manipulate victims more effectively.

This research examines how cybercriminals utilize AI to enhance psychological manipulation techniques in phishing and social engineering attacks, increasing victim susceptibility. Drawing from interdisciplinary literature in cybersecurity and psychology, this study explores key psychological mechanisms, including cognitive biases, emotional triggers, and decision-making processes that influence victim …


Pong Revised: Network-Based Competitions Through Secure Socket Services, Noah T. Jennings, Destiny D. Hale, Jared D. Williams, Michael J. Lively-Scholz Mar 2026

Pong Revised: Network-Based Competitions Through Secure Socket Services, Noah T. Jennings, Destiny D. Hale, Jared D. Williams, Michael J. Lively-Scholz

Knowledge and Creativity Expo

We aim to provide a safe, thrilling, locally hosted, and educational multiplayer experience that can be quickly replicated in modern Capture The Flag (CTF) events.


Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty Jan 2026

Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty

Center for Secure and Intelligent Critical Systems (CSICS) Publications

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models …


Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim Jan 2026

Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim

School of Cybersecurity Faculty Publications

Phishing involves manipulating individuals into revealing private data, e.g., user IDs, bank details, and passwords. The observed surge in fraud is related to increased deception, impersonation, and advanced online attacks. Thus, effective phishing detection methods are required to mitigate escalating global phishing threats. Existing methods (e.g., heuristics-based, signature-based, and visual similarity-based methods) attempt to detect phishing sites, and machine learning (ML) and deep learning (DL) methods are effective in the cybersecurity context in terms of learning from data, offering insights, and forecasting. However, independent ML algorithms are limited when handling complex data, and DL techniques surpass traditional ML methods in …


Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis, Olusesi Balogun, Mohammad Ghasemigol, Zhipeng Cai, Daniel Takabi Jan 2026

Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis, Olusesi Balogun, Mohammad Ghasemigol, Zhipeng Cai, Daniel Takabi

School of Cybersecurity Faculty Publications

Attribute-Based Access Control (ABAC) frameworks coordinate access requests based on subject, object, and environment attributes, as well as policy rules, and are widely used in corporate security systems. Recently, machine learning has been applied to ABAC to address policy-generation imbalances, misassigned privileges, and attribute leakages. However, existing MLBAC techniques do not consider the structural constraints and attribute interdependencies present in traditional ABAC systems. Moreover, these frameworks have not been extensively evaluated under black-box attack scenarios. To address these gaps, we propose extensions to MLBAC that integrate structural constraints, attribute dynamism, and attribute weighting into the MLBAC objective function. Additionally, we …


The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li Jan 2026

The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li

Computer Science Faculty Publications

Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …


Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol Jan 2026

Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol

Computer Science Faculty Publications

Large Language Models (LLMs) are becoming critical infrastructure in scientific, healthcare, and governmental contexts. As frontier AI laboratories increasingly partner with government agencies, a fundamental question arises: Who should control the safety and policy-enforcement layers that constrain model behavior? Current safety mechanisms (LLM guardrails) are typically designed for generic "harmlessness" and operate by detecting semantic patterns and refusing requests. However, they are inadequate governance instruments because they cannot implement auditable, domain-specific controls tied to external regulatory policy objects (e.g., control lists or rules governing personally identifying information). Even a perfectly aligned model is not able to express institution-specific policy without …


An Explainable Cs-Mitigation Triangular (Ecsmt) Framework To Secure Graph Neural Networks, Sabah Ettahri, Sergio Pallas Enguita, Chung-Hao Chen, Wen-Chao Yang Jan 2026

An Explainable Cs-Mitigation Triangular (Ecsmt) Framework To Secure Graph Neural Networks, Sabah Ettahri, Sergio Pallas Enguita, Chung-Hao Chen, Wen-Chao Yang

Electrical & Computer Engineering Faculty Publications

This research addresses cyber risk by defending against backdoor attacks on Graph Neural Networks (GNNs). We propose the Explainable Complex System-Mitigation Triangular (ECSMT) Framework, which integrates Robust Training, Graph Regularization, and Data Sanitization into a lightweight, hardware-efficient defense layer. To evaluate structural generalizability, we conducted empirical evaluations across three distinct benchmark domains (AIDS, MUTAG, and PROTEINS) using a Graph Isomorphism Network (GIN) backbone. Under a baseline 5% backdoor subgraph trigger injection ratio, ECSMT achieves excellent utility retention, securing a Clean Accuracy (CA) of 97.33% (±0.62%) while reducing the Attack Success Rate (ASR) from 97.00% down to 69.45% on the primary …


Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias Jan 2026

Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias

Electrical & Computer Engineering Faculty Publications

This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.

The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …


Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han Jan 2026

Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han

Accounting Faculty Publications

This study examines whether firms strategically adjust the readability of Item 1A (“Risk Factors”) disclosures following data breaches. Using U.S. firm-year observations from 2006 to 2023, we find that data breaches are associated with a significant decline in Item 1A readability. This decline is not accompanied by a meaningful increase in informational content; instead, post-breach disclosures exhibit higher syntactic complexity, more positive tone, and lower textual similarity to prior and industry peers' filings, consistent with strategic obfuscation rather than transparent reporting. The readability decline is amplified among firms facing higher litigation risk but attenuated among firms with stronger reputations for …


Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities, Thomas Pham Dec 2025

Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities, Thomas Pham

Cybersecurity Undergraduate Research Showcase

Open-source software ecosystems have become critical infrastructure for modern software development, yet they remain vulnerable to sophisticated supply chain attacks. This paper presents a comprehensive empirical analysis of supply chain attacks targeting npm, PyPI, and Docker Hub, examining 23 documented campaigns affecting over 2.6 billion weekly downloads. Through systematic analysis of attack vectors including typosquatting, dependency confusion, and maintainer account compromise, we identify recurring patterns and structural vulnerabilities across package registries. Our analysis reveals that 86.1% of detected typosquatted packages contained malware, with cryptocurrency theft emerging as the predominant attack objective. We document the September 2025 npm compromise affecting 18 …


Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson Dec 2025

Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson

Cybersecurity Undergraduate Research Showcase

This paper presents throughout research on the security issues related to drone transmission. These topics were addressed and explained, in particular the aspects relating to cybersecurity, for utmost clarity. These include threats and vulnerabilities, drone transmission the impact of encryption on latency, and the details of the encryption methods AES-128, AES-256, and ChaCha20 that were used in the experiment described in the paper. Each encryption method performance was measured and outputted by the Python code developed and used in the experiment. Afterwards, the performance of each method was analyzed in relation to their decryption time, encryption time, end to end …


Rogue Access Points And Their Impact On Networks, Sami Belmokhtar Dec 2025

Rogue Access Points And Their Impact On Networks, Sami Belmokhtar

Cybersecurity Undergraduate Research Showcase

This paper focuses on rogue access points (rogue APs) and how they can impact the security and stability of a network, and consequently, the safety and privacy of the users. Wireless access points (WAPs) are nodes that allow a user to connect to a local network. This includes devices such as the routers typically used in a home network. This paper examines how an unauthorized WAP may pose a threat to a network in both a public environment and an enterprise environment. Furthermore, it shows how a hacker can mimic a real wireless network and gain access to both user …


Bridging The Gap Between Network Science And Network Systems To Identify And Mitigate Cyber Risk: Identify And Mitigate Backdoor Attacks On Graph Neural Networks And On Complex Systems, Sabah Ettahri Dec 2025

Bridging The Gap Between Network Science And Network Systems To Identify And Mitigate Cyber Risk: Identify And Mitigate Backdoor Attacks On Graph Neural Networks And On Complex Systems, Sabah Ettahri

Electrical & Computer Engineering Projects for D. Eng. Degree

This doctoral project aims to bridge the gap between graph theory and network science to identify and mitigate cyber risk, represented as a CY-Triangular Network that connects different networks. The CY-Triangular Framework is a cybersecurity system that integrates graph theory and network science through an interoperable learning approach. The objective of this project is to bridge the gap between two domains: network science and network systems. Accordingly, it examines one representative network from each field, focuses on a complex system network, and explores Graph Neural Networks (GNNs). The connection between these domains lies in graph theory. This research demonstrates that …


Insider Threat: A Case Study Of The Maroochy Water Services Attack, Samuel Rector Nov 2025

Insider Threat: A Case Study Of The Maroochy Water Services Attack, Samuel Rector

Cybersecurity Undergraduate Research Showcase

In 2000, a former employee at Hunter Watertech went rogue and caused a spill of 800,000 liters of sewage. He leveraged his insider knowledge and access to stolen equipment in order to seek retribution for the company that wronged him. After three months of torment police arrested him and an investigation and many studies were done on the incident. A consensus remains that much of this chaos was preventable with simple cybersecurity implementations.


Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman Nov 2025

Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman

Cybersecurity Undergraduate Research Showcase

The Model Context Protocol (MCP) has emerged as a critical standard for connecting AI agents to external data sources and tools. Still, its adoption has introduced significant security vulnerabilities across multiple attack surfaces. While recent research has catalogued extensive vulnerability taxonomies and attack implementations, automated detection methodologies remain limited. Current detection tools primarily employ static code analysis, which fails to identify behavioral vulnerabilities that only manifest during runtime server interactions. This study explores behavioral detection approaches for identifying MCP server vulnerabilities through systematic query-based testing, with particular emphasis on context manipulation techniques. Preliminary analysis of existing vulnerability research reveals 48 …


Game Hacking & Anti-Cheat Analysis, Quang Hoang Nov 2025

Game Hacking & Anti-Cheat Analysis, Quang Hoang

Cybersecurity Undergraduate Research Showcase

Reverse engineering and analyzing game hacking and anti-cheat mechanisms is a complex and evolving field. This research document explores the history of game hacking, various techniques used in game hacking, and the countermeasures implemented by anti-cheat systems. Through case studies, we illustrate the strategies involved in creating cheats. Specifically, we demonstrate how to hack the open-source game AssaultCube using memory editing and code injection techniques available in Cheat Engine in a step-by-step manner so that the reader can theoretically reproduce the results shown in this paper. We also dissect the game’s anti-cheat mechanisms, identifying their strengths and weaknesses. This document …


A Scalable Cybersecurity Model For Academic Makerspaces, William Faircloth Nov 2025

A Scalable Cybersecurity Model For Academic Makerspaces, William Faircloth

Cybersecurity Undergraduate Research Showcase

Academic makerspaces have become integral hubs of innovation on university campuses, providing students with access to industrial-grade operational technology (OT) such as 3D printers and CNC machines. However, the security posture for these spaces has overwhelmingly focused on physical safety, creating a significant cybersecurity gap. This oversight leaves networked OT vulnerable to cyberattacks, which threaten student intellectual property, expensive equipment, and the integrity of the broader institutional network. This research addresses this critical vulnerability by developing and implementing a secure and scalable cybersecurity model at the Old Dominion University Computer Science Makerspace, founded on two core principles: robust network segmentation …


Deconstructing Tycoon 2fa: A Static Analysis Approach To Threat Intelligence And Automated Defense, Daniel A. Austin Jr Nov 2025

Deconstructing Tycoon 2fa: A Static Analysis Approach To Threat Intelligence And Automated Defense, Daniel A. Austin Jr

Cybersecurity Undergraduate Research Showcase

It's gotten much easier to be a cybercriminal. We're seeing a boom in "Phishing-as-a-Service" (PaaS) platforms, which sell advanced phishing attacks as a ready-to-use product. This means almost anyone can now get the tools to launch sophisticated attacks, even if they don't have a lot of technical skill.

This research dives into one of the most prominent threats, the Tycoon 2FA phishing kit. This kit is dangerous because it's designed to bypass Multi-Factor Authentication (MFA) using what is known as an Adversary-in-the-Middle (AiTM) attack.

This paper covers how I built and tested a set of Python-based tools to perform "static …


A Systematic Review Of Poisoning Attacks Against Large Language Models (Llm), Patrick Mcguffin Nov 2025

A Systematic Review Of Poisoning Attacks Against Large Language Models (Llm), Patrick Mcguffin

Cybersecurity Undergraduate Research Showcase

This paper provides a comprehensive review of poisoning attacks against large language models (LLMs), drawing primarily from Fendley et al. (2025) and complementary studies from 2022–2025. It categorizes poisoning research into two key dimensions, Metrics and Specifications, to evaluate how attack success is measured and how attacks are implemented. This paper synthesizes quantitative results, experimental findings, and defense strategies across data, model, and multi-modal poisoning contexts. Finally, it highlights emerging challenges posed by self-adaptive and synthetic-data-driven LLMs, and proposes future research directions to strengthen model security and reliability.


Detecting Generative-Ai-Enabled Polymorphic Malware: A Semantic-Behavior Approach, Allyson M. Morris Nov 2025

Detecting Generative-Ai-Enabled Polymorphic Malware: A Semantic-Behavior Approach, Allyson M. Morris

Cybersecurity Undergraduate Research Showcase

AI drastically reduces the effort required to produce malware that mutates both its code and behavior, thereby creating polymorphic and nondeterministic variants in which traditional signatures and many heuristic defenses fail. In this paper, I survey recent developments in AI-assisted malware generation, explain why conventional defenses are insufficient, and propose a layered detection architecture emphasizing semantic behavior, streaming anomaly detection, and defensive generative augmentation. I also outline why this approach generalizes to previously unseen AI-mutated samples, provide an evaluation plan with meaningful metrics, and describe a feasible MVP roadmap for practical deployment. Recent disclosures and threat intelligence further highlight the …


A Comprehensive Evaluation Of Next-Generation Firewall Effectiveness Against Encrypted And Evasive Threats In Enterprise Networks, John Costanzo, Favour Anene Nov 2025

A Comprehensive Evaluation Of Next-Generation Firewall Effectiveness Against Encrypted And Evasive Threats In Enterprise Networks, John Costanzo, Favour Anene

Cybersecurity Undergraduate Research Showcase

Encrypted traffic is becoming a pillar of security and privacy in enterprise networks. According to Google Transparency Report, over 95 percent of internet traffic is encrypted with the use of Hypertext Transfer Protocol secure (HTTPS), Transport Layer Security (TLS) 1.3 and Quick UDP Internet Connections (QUIC). Although encryption safeguards confidentiality and integrity, it has also introduced new blind spots to the conventional security solutions. Encrypted channels are used to hide command-and-control (C2) traffic, issue malware and extract sensitive data without their notice.

To make the issue even harder, the opponents have sophisticated avoidance methods including traffic fragmentation, tunneling, and polymorphic …