Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons™

Open Access. Powered by Scholars. Published by Universities.®

Articles 1 - 5 of 5

Full-Text Articles in Cybersecurity

Hands-On Ransomware: An Experiential Wannacry Case Study For Undergraduate Cybersecurity Education, Eli Creek Richmond, Thomas R. Devine Sep 2026

Hands-On Ransomware: An Experiential Wannacry Case Study For Undergraduate Cybersecurity Education, Eli Creek Richmond, Thomas R. Devine

Military Cyber Affairs

Ransomware represents one of the most disruptive threats in the cyber landscape, yet hands-on malware analysis remains rare in undergraduate cybersecurity curricula. This paper presents the design, implementation, and evaluation of an experiential learning module centered on the WannaCry ransomware case study, deployed in a senior-level course at West Virginia University. Students performed static and dynamic analysis using industry-standard tools. Pre- and post-module assessments demonstrated measurable gains in self-reported competency across seven technical dimensions. The module's competencies align directly with DoD Cyber Workforce Framework Work Role 212, Cyber Defense Forensics Analyst, supporting education-to-workforce pipeline development.


From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance, Shelby C. Snyder Sep 2026

From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance, Shelby C. Snyder

Military Cyber Affairs

Federal agencies face a fiscal year 2027 target for enterprise-wide Zero Trust deployment, but NIST SP 800-207A defines logical components without identifying the Kubernetes technologies that implement them. This paper proposes a three-tier mapping of the Policy Engine, Policy Administrator, and Policy Enforcement Point to service mesh, microsegmentation, and perimeter tooling, stating the criteria by which each component is classified. It then applies a defined rubric to six Zero Trust vendors across component alignment, Kubernetes capability, federal authorization posture, and evidence quality, finding that no single vendor covers all three tiers. The mapping is a testable architectural proposition; a Stage …


Characterizing Advanced Persistent Threats With Cyber Attack Flow Metrics, Tyler Miller, Caleb Chang, Shouhuai Xu Sep 2026

Characterizing Advanced Persistent Threats With Cyber Attack Flow Metrics, Tyler Miller, Caleb Chang, Shouhuai Xu

Military Cyber Affairs

Cyber attack campaigns vary not only in scale but in structure, yet conventional characterizations often reduce them to a single dimension such as technique count or impact severity. In this paper we extend the concept of cyber attack flows by defining three new metrics, novelty, technique complexity and flow complexity. Then we characterize the attack flows of three advanced persistent threat campaigns using these metrics and draw insights regarding their capabilities. Our findings include that low novelty does not equate to low attack capabilities and that exploitation of an internet-facing appliance is a common initial attack vector.


Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck Sep 2026

Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck

Military Cyber Affairs

Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public safety consequences. However, attributing ransomware incidents to specific threat actors remains challenging due to ransomware-as-a-service ecosystems, actor rebranding, and the obfuscation of traditional indicators of compromise. This paper presents Semantic Shields, an NLP-driven attribution framework that leverages BERT-generated semantic embeddings and DBSCAN clustering to profile ransomware actors through the linguistic characteristics of ransom notes. Using a dataset of 295 ransom notes from 189 distinct threat groups, the framework achieved an 87.2% true positive clustering rate and …


Closing The Interpretability Gap: Explainable Ml-Based Malware Detection For Defensive Cyberspace Operations, Tashi Stirewalt, Sean Hodgson, Puumaaya Tahiru, Assefaw Gebremedhin Sep 2026

Closing The Interpretability Gap: Explainable Ml-Based Malware Detection For Defensive Cyberspace Operations, Tashi Stirewalt, Sean Hodgson, Puumaaya Tahiru, Assefaw Gebremedhin

Military Cyber Affairs

This paper presents an end-to-end, explainable malware triage pipeline designed for defense-oriented cyber operations. It combines high-performance static detection methods with analyst-centered interpretability. Utilizing the EMBER 2024 Windows PE subset, we train and evaluate four classifiers and select LightGBM as the production model based on its predictive performance, inference efficiency, and compatibility with exact tree-based attribution. The deployed system consists of four sequential components: PE feature extraction, malware probability scoring, dual explainability (using SHAP and LIME), and large language model (LLM) report generation, all integrated within a Flask web interface. On a temporal test set of 1,080,000 samples, LightGBM achieves …