Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Articles 1 - 30 of 55

Full-Text Articles in Cybersecurity

Geometry-Conditioned Adversarial Defense For Sar Automatic Target Recognition Via Regime-Specialist Classification Heads, Skyler Fabre Aug 2026

Geometry-Conditioned Adversarial Defense For Sar Automatic Target Recognition Via Regime-Specialist Classification Heads, Skyler Fabre

Discovery Day - Daytona Beach

This project, titled Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads, addresses the critical vulnerability of deep neural networks deployed in Synthetic Aperture Radar (SAR) Automatic Target Recognition (ATR) systems to adversarial perturbations. This is where imperceptible pixel-level modifications cause confident misclassification, posing serious risks in defense and aerospace applications. The objective is to develop and evaluate RegimeResNet, a geometry-conditioned classification architecture that exploits sensor metadata unique to SAR collection systems. Rather than treating all images uniformly, RegimeResNet partitions the SAR capture space into nine geometric regimes defined by depression angle and target azimuth angle extracted …


Determinants And Invertibility In Finite Modular Systems, Osasu Omobude Aug 2026

Determinants And Invertibility In Finite Modular Systems, Osasu Omobude

Discovery Day - Daytona Beach

This project investigates determinants and matrix invertibility in finite modular systems, focusing on matrices over Zn. Using the Hill cipher as context, it examines the algebraic conditions under which a matrix is invertible in modular arithmetic. In particular, the project studies how the determinant determines invertibility, showing that a matrix over Zn is invertible if and only if its determinant is coprime with n.   The project further compares invertibility over the real numbers with invertibility over modular systems, highlighting the distinction between prime moduli Zp and composite moduli. In the prime case, matrices behave similarly to those over fields, where …


Small Uas Detection: Threat Intelligence & Risk Management Project, Tyler Johnson Aug 2026

Small Uas Detection: Threat Intelligence & Risk Management Project, Tyler Johnson

Discovery Day - Daytona Beach

The TRANSPORTATION SECURITY ADMINISTRATION / FEDERAL AIR MARSHAL SUAS DETECTION: THREAT INTELLIGENCE & RISK MANAGEMENT PROJECT addresses the emerging safety and security challenges posed by the rapid growth of small Unmanned Aircraft Systems (sUAS) in complex airspace environments. This study analyzed 92 days of sensor-captured Remote Identification (RID) data collected near Fort Lauderdale-Hollywood International Airport (FLL) to assess operational behaviors, aviation risk, and ground risk associated with drone activity. The primary objective of this research is to identify patterns of unauthorized or hazardous sUAS operations to enhance situational awareness and inform actionable risk-mitigation strategies. The analysis identified 335 flights from …


An Evaluation Of Machine Learning Models' Efficacy In Determining Uav Spoofing Attacks, Nicolas Machado, Jaxon Selzer Aug 2026

An Evaluation Of Machine Learning Models' Efficacy In Determining Uav Spoofing Attacks, Nicolas Machado, Jaxon Selzer

Discovery Day - Daytona Beach

An Evaluation of Machine Learning Models' Efficacy in Determining UAV Spoofing Attacks - The rapid integration of Unmanned Aerial Vehicles (UAVs) into urban airspace has introduced significant cybersecurity concerns, particularly due to vulnerabilities in Automatic Dependent Surveillance–Broadcast (ADS-B), which lacks authentication and encryption. This project addresses the problem of detecting spoofing and data manipulation attacks that can compromise UAV safety and mission reliability. The objective of this work is to evaluate the effectiveness of machine learning–based anomaly detection, specifically Long Short-Term Memory (LSTM) and Gated Recurrent Unit (GRU) networks, as protocol-agnostic solutions for identifying anomalous UAV behavior. To achieve this, …


A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland Aug 2026

A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland

Discovery Day - Daytona Beach

In the modern age of computers and interconnected networks, cybersecurity and cyber-attackers are evolving in tandem to exploit each other’s vulnerabilities. One technique used by both parties is Operating System Fingerprinting (OSF): with the knowledge of what Operating System a target system is running, innate vulnerabilities can be identified and patched or exploited. Historically, OSF utilizes two main methods: passive and active—the former trades accuracy with undetectability while the latter is generally more detectable but more accurate. However, recent work has combined OSF with Machine Learning (ML) to improve accurate identification. The work presented here is a survey for the …


Dcat - Distributed Computing And Analysis Tool, Asher Zwickel, Jacob Burdge Aug 2026

Dcat - Distributed Computing And Analysis Tool, Asher Zwickel, Jacob Burdge

Discovery Day - Daytona Beach

This project uses distributed computing to process and analyze large datasets related to cyber breaches and attacks. Its main goal is to find patterns between initial cyber incidents and what happens next. It looks at whether responses tend to escalate, calm down, or stay about the same over time. Understanding this helps explain how digital conflicts develop and whether they follow predictable paths. The project was built as part of university research and runs on custom software across a cluster of 17 Chromebooks. While the system can study many topics, it is currently focused on cyber activity. The software uses …


Bridging The Gap: Cybersecurity And Occupational Safety Frameworks In Ai Data Centers, Athena Leader Aug 2026

Bridging The Gap: Cybersecurity And Occupational Safety Frameworks In Ai Data Centers, Athena Leader

Discovery Day - Daytona Beach

Bridging the Gap: Cybersecurity and Occupational Safety Frameworks in AI Data Centers   As artificial intelligence infrastructure expands, AI data centers represent a critical and underexamined convergence of cybersecurity and occupational safety risk. Existing frameworks such as NIST, OSHA, and ISO standards were largely developed in isolation, leaving significant gaps in how organizations manage risks that are simultaneously digital and physical in nature. This study investigates the gaps and overlaps between cybersecurity and occupational safety frameworks as they apply specifically to AI data center environments. Drawing on a targeted literature review of established regulatory and standards-based frameworks, this research identifies where …


Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir Apr 2026

Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir

Cybersecurity Undergraduate Research Showcase

Universities face heightened vulnerability to phishing attacks due to their open information-sharing culture and diverse user populations. This study examines how phishing exploits human factors within campus environments and evaluates three major training strategies: embedded phishing, microlearning, and role-based instruction to understand their individual and combined effectiveness. I explored studies that implement these strategies in pairs and use the strategies alone, identified trends in susceptibility reduction, behavioral reinforcement, and contextual relevance. I suggest that, while each method independently improves user awareness, multiple approaches offer stronger, more adaptable protection by addressing both psychological triggers and role-specific risks. The paper contributes a …


Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs Apr 2026

Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs

Cybersecurity Undergraduate Research Showcase

Prompt injection attacks, ranked the number-one vulnerability in AI systems by OWASP's 2025 Top 10 for Large Language Model Applications, remain largely unsolved, and this survey examines why. As large language models (LLMs) are deployed across enterprise workflows, agentic systems, and consumer tools, their fundamental inability to distinguish trusted instructions from untrusted user data has created a persistent and expanding attack surface. This paper presents a structured taxonomy of prompt injection attack vectors, including direct injection, indirect injection, multimodal attacks, tool and agent exploitation, hybrid chained techniques, and autonomous propagating threats. These vectors are mapped across five impact categories (data …


Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry Apr 2026

Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry

Cybersecurity Undergraduate Research Showcase

Network Intrusion Detection Systems are tools used to monitor network traffic and alert to suspicious or harmful activity before it can cause harm. Signature-based versions of these systems are a foundation for intrusion detection, operating by finding common patterns and forming malicious signatures. However, three developments in modern network environments have greatly impacted the significance of Network Intrusion Detection Systems. These three developments are the near-complete adoption of end-to-end encryption, the use of sophisticated packet fragmentation techniques, and the processing demands of high-throughput networks. Encryption makes deep packet inspection practically infeasible by transforming inspectable payloads into ciphertext, forcing NIDS to …


Artificial Intelligence Moderation In Online Gaming: A Cybersecurity Analysis Of Risks And Defenses, Labib Khan Apr 2026

Artificial Intelligence Moderation In Online Gaming: A Cybersecurity Analysis Of Risks And Defenses, Labib Khan

Cybersecurity Undergraduate Research Showcase

This research paper will examine the role of artificial intelligence (AI) moderation systems in enhancing cybersecurity within online gaming environments. As multiplayer platforms increasingly rely on real-time text, voice communication, and user-generated content, developers have implemented AI-driven tools such as natural language processing (NLP), speech recognition, and behavioral analytics to detect harassment, toxic behavior, cheating coordination, and other malicious activity. These systems enable gaming companies to efficiently monitor large volumes of player interactions, improving response times and helping maintain safer and more controlled digital environments for users across global gaming communities of varying sizes and activity levels.

While these technologies …


Escaping Isolation: An Analysis Of Virtual Machine And Container Breakout Vulnerabilities, Felix Iov Apr 2026

Escaping Isolation: An Analysis Of Virtual Machine And Container Breakout Vulnerabilities, Felix Iov

Cybersecurity Undergraduate Research Showcase

Cloud computing providers rely on multi-tenant architectures to maximize resource efficiency. This infrastructure depends on virtualization, which provides isolation between clients. This comes primarily in the form of Virtual Machines (VMs) and Containers. However, “breakout attacks” or “escapes” are a critical threat where attackers bypass these isolation layers to gain unauthorized access to the host system and neighboring environments. This paper surveys virtualization escape threats and analyzes three case studies: a runc container escape (Leaky Vessels), a VMware ESXi VM escape (VSOCKPuppet), and an NVIDIA GPU container escape (NVIDIAScape). Each demonstrates different attack surfaces, including file descriptor misuse, kernel driver …


Bio-Cybersecurity: Securing The Healthcare Industry, Amanda D. Coleman Apr 2026

Bio-Cybersecurity: Securing The Healthcare Industry, Amanda D. Coleman

Cybersecurity Undergraduate Research Showcase

Bio-cybersecurity refers to the aspect of cybersecurity that applies to the biological sciences and the protection of digital biomedical information. Today’s healthcare industry has evolved with the enhancement of internet and biomedical technology. While hospitals and private medical providers remain compliant with the Health Information Portability and Accountability Act (HIPAA) through traditional means of securing documented patient information, the emergence of beneficial internet-based healthcare services like virtual appointments and digital patient records requires new policies and healthcare cybersecurity frameworks to protect sensitive information from unauthorized access. This paper examines the role of cybersecurity in healthcare, the vulnerabilities that exist and …


Ai's Double Edged Sword: Fighting Against Synthetic Csam, Shekhinah Adra Green Apr 2026

Ai's Double Edged Sword: Fighting Against Synthetic Csam, Shekhinah Adra Green

Cybersecurity Undergraduate Research Showcase

The rapid advancements in generative artificial intelligence has introduced new challenges in the production and distribution of synthetic child sexual abuse material (CSAM). AI has the capabilities of creating highly realistic imagery and videos, which  raises serious legal and ethical concerns, increasing the risk of harm, exploitation, and revictimization.

This paper discusses the legal improvements needed in order to lower the change of legal loopholes, how digital forensic analyst use advanced tools to identify and investigate synthetic material, and different methods to start the reduction of synthetic CSAM.


A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*, Ryan Lopez, Ysani Peña Apr 2026

A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*, Ryan Lopez, Ysani Peña

Campus Research Month

Universities face a common cybersecurity threat: their own users. Although organizations may meet compliance standards and implement robust security infrastructures, the individual user remains the weakest link. This is particularly evident in higher education institutions, where both students and employees are frequent targets of cyber threats due to a lack of cybersecurity awareness. This paper proposes a strategic roadmap for assessing university student bodies and employee populations through cybersecurity domains that directly affect personal cyber hygiene awareness and practice.

Our proposed roadmap was validated in a U.S. university by using a domain-focused survey and simulated phishing campaigns. After the identification …


Pong Revised: Network-Based Competitions Through Secure Socket Services, Noah T. Jennings, Destiny D. Hale, Jared D. Williams, Michael J. Lively-Scholz Mar 2026

Pong Revised: Network-Based Competitions Through Secure Socket Services, Noah T. Jennings, Destiny D. Hale, Jared D. Williams, Michael J. Lively-Scholz

Knowledge and Creativity Expo

We aim to provide a safe, thrilling, locally hosted, and educational multiplayer experience that can be quickly replicated in modern Capture The Flag (CTF) events.


Development Of An Artificial Immune System Based Intruder Detection Algorithm For Comparison With A Novel Intruder Detection Strategy., Jaden Caradine Feb 2026

Development Of An Artificial Immune System Based Intruder Detection Algorithm For Comparison With A Novel Intruder Detection Strategy., Jaden Caradine

Student Research Symposium (SRS)

"This project aims to develop an Artificial Immune System inspired intruder detection system based on current state-of-the-art strategies. Traditional intruder detection systems are not equipped to handle the evolving landscape of cyber security. Signature based detection systems require a database of known signatures and traditional anomaly detection systems are plagued with false positives. By contrast, Artificial Immune Systems can respond to threats never encountered. They are adaptive, proactive, and resilient to interference. This makes them ideal for determining when a system is behaving abnormally. Researchers are developing a novel intruder detection system, but they need a baseline to compare it …


Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities, Thomas Pham Dec 2025

Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities, Thomas Pham

Cybersecurity Undergraduate Research Showcase

Open-source software ecosystems have become critical infrastructure for modern software development, yet they remain vulnerable to sophisticated supply chain attacks. This paper presents a comprehensive empirical analysis of supply chain attacks targeting npm, PyPI, and Docker Hub, examining 23 documented campaigns affecting over 2.6 billion weekly downloads. Through systematic analysis of attack vectors including typosquatting, dependency confusion, and maintainer account compromise, we identify recurring patterns and structural vulnerabilities across package registries. Our analysis reveals that 86.1% of detected typosquatted packages contained malware, with cryptocurrency theft emerging as the predominant attack objective. We document the September 2025 npm compromise affecting 18 …


Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson Dec 2025

Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson

Cybersecurity Undergraduate Research Showcase

This paper presents throughout research on the security issues related to drone transmission. These topics were addressed and explained, in particular the aspects relating to cybersecurity, for utmost clarity. These include threats and vulnerabilities, drone transmission the impact of encryption on latency, and the details of the encryption methods AES-128, AES-256, and ChaCha20 that were used in the experiment described in the paper. Each encryption method performance was measured and outputted by the Python code developed and used in the experiment. Afterwards, the performance of each method was analyzed in relation to their decryption time, encryption time, end to end …


Rogue Access Points And Their Impact On Networks, Sami Belmokhtar Dec 2025

Rogue Access Points And Their Impact On Networks, Sami Belmokhtar

Cybersecurity Undergraduate Research Showcase

This paper focuses on rogue access points (rogue APs) and how they can impact the security and stability of a network, and consequently, the safety and privacy of the users. Wireless access points (WAPs) are nodes that allow a user to connect to a local network. This includes devices such as the routers typically used in a home network. This paper examines how an unauthorized WAP may pose a threat to a network in both a public environment and an enterprise environment. Furthermore, it shows how a hacker can mimic a real wireless network and gain access to both user …


Insider Threat: A Case Study Of The Maroochy Water Services Attack, Samuel Rector Nov 2025

Insider Threat: A Case Study Of The Maroochy Water Services Attack, Samuel Rector

Cybersecurity Undergraduate Research Showcase

In 2000, a former employee at Hunter Watertech went rogue and caused a spill of 800,000 liters of sewage. He leveraged his insider knowledge and access to stolen equipment in order to seek retribution for the company that wronged him. After three months of torment police arrested him and an investigation and many studies were done on the incident. A consensus remains that much of this chaos was preventable with simple cybersecurity implementations.


Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman Nov 2025

Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman

Cybersecurity Undergraduate Research Showcase

The Model Context Protocol (MCP) has emerged as a critical standard for connecting AI agents to external data sources and tools. Still, its adoption has introduced significant security vulnerabilities across multiple attack surfaces. While recent research has catalogued extensive vulnerability taxonomies and attack implementations, automated detection methodologies remain limited. Current detection tools primarily employ static code analysis, which fails to identify behavioral vulnerabilities that only manifest during runtime server interactions. This study explores behavioral detection approaches for identifying MCP server vulnerabilities through systematic query-based testing, with particular emphasis on context manipulation techniques. Preliminary analysis of existing vulnerability research reveals 48 …


Game Hacking & Anti-Cheat Analysis, Quang Hoang Nov 2025

Game Hacking & Anti-Cheat Analysis, Quang Hoang

Cybersecurity Undergraduate Research Showcase

Reverse engineering and analyzing game hacking and anti-cheat mechanisms is a complex and evolving field. This research document explores the history of game hacking, various techniques used in game hacking, and the countermeasures implemented by anti-cheat systems. Through case studies, we illustrate the strategies involved in creating cheats. Specifically, we demonstrate how to hack the open-source game AssaultCube using memory editing and code injection techniques available in Cheat Engine in a step-by-step manner so that the reader can theoretically reproduce the results shown in this paper. We also dissect the game’s anti-cheat mechanisms, identifying their strengths and weaknesses. This document …


A Scalable Cybersecurity Model For Academic Makerspaces, William Faircloth Nov 2025

A Scalable Cybersecurity Model For Academic Makerspaces, William Faircloth

Cybersecurity Undergraduate Research Showcase

Academic makerspaces have become integral hubs of innovation on university campuses, providing students with access to industrial-grade operational technology (OT) such as 3D printers and CNC machines. However, the security posture for these spaces has overwhelmingly focused on physical safety, creating a significant cybersecurity gap. This oversight leaves networked OT vulnerable to cyberattacks, which threaten student intellectual property, expensive equipment, and the integrity of the broader institutional network. This research addresses this critical vulnerability by developing and implementing a secure and scalable cybersecurity model at the Old Dominion University Computer Science Makerspace, founded on two core principles: robust network segmentation …


Deconstructing Tycoon 2fa: A Static Analysis Approach To Threat Intelligence And Automated Defense, Daniel A. Austin Jr Nov 2025

Deconstructing Tycoon 2fa: A Static Analysis Approach To Threat Intelligence And Automated Defense, Daniel A. Austin Jr

Cybersecurity Undergraduate Research Showcase

It's gotten much easier to be a cybercriminal. We're seeing a boom in "Phishing-as-a-Service" (PaaS) platforms, which sell advanced phishing attacks as a ready-to-use product. This means almost anyone can now get the tools to launch sophisticated attacks, even if they don't have a lot of technical skill.

This research dives into one of the most prominent threats, the Tycoon 2FA phishing kit. This kit is dangerous because it's designed to bypass Multi-Factor Authentication (MFA) using what is known as an Adversary-in-the-Middle (AiTM) attack.

This paper covers how I built and tested a set of Python-based tools to perform "static …


A Systematic Review Of Poisoning Attacks Against Large Language Models (Llm), Patrick Mcguffin Nov 2025

A Systematic Review Of Poisoning Attacks Against Large Language Models (Llm), Patrick Mcguffin

Cybersecurity Undergraduate Research Showcase

This paper provides a comprehensive review of poisoning attacks against large language models (LLMs), drawing primarily from Fendley et al. (2025) and complementary studies from 2022–2025. It categorizes poisoning research into two key dimensions, Metrics and Specifications, to evaluate how attack success is measured and how attacks are implemented. This paper synthesizes quantitative results, experimental findings, and defense strategies across data, model, and multi-modal poisoning contexts. Finally, it highlights emerging challenges posed by self-adaptive and synthetic-data-driven LLMs, and proposes future research directions to strengthen model security and reliability.


Detecting Generative-Ai-Enabled Polymorphic Malware: A Semantic-Behavior Approach, Allyson M. Morris Nov 2025

Detecting Generative-Ai-Enabled Polymorphic Malware: A Semantic-Behavior Approach, Allyson M. Morris

Cybersecurity Undergraduate Research Showcase

AI drastically reduces the effort required to produce malware that mutates both its code and behavior, thereby creating polymorphic and nondeterministic variants in which traditional signatures and many heuristic defenses fail. In this paper, I survey recent developments in AI-assisted malware generation, explain why conventional defenses are insufficient, and propose a layered detection architecture emphasizing semantic behavior, streaming anomaly detection, and defensive generative augmentation. I also outline why this approach generalizes to previously unseen AI-mutated samples, provide an evaluation plan with meaningful metrics, and describe a feasible MVP roadmap for practical deployment. Recent disclosures and threat intelligence further highlight the …


A Comprehensive Evaluation Of Next-Generation Firewall Effectiveness Against Encrypted And Evasive Threats In Enterprise Networks, John Costanzo, Favour Anene Nov 2025

A Comprehensive Evaluation Of Next-Generation Firewall Effectiveness Against Encrypted And Evasive Threats In Enterprise Networks, John Costanzo, Favour Anene

Cybersecurity Undergraduate Research Showcase

Encrypted traffic is becoming a pillar of security and privacy in enterprise networks. According to Google Transparency Report, over 95 percent of internet traffic is encrypted with the use of Hypertext Transfer Protocol secure (HTTPS), Transport Layer Security (TLS) 1.3 and Quick UDP Internet Connections (QUIC). Although encryption safeguards confidentiality and integrity, it has also introduced new blind spots to the conventional security solutions. Encrypted channels are used to hide command-and-control (C2) traffic, issue malware and extract sensitive data without their notice.

To make the issue even harder, the opponents have sophisticated avoidance methods including traffic fragmentation, tunneling, and polymorphic …


Investigating The Security Vulnerabilities Of Ip Cameras: Classifications And Trends From Public Cve Data, Sam Oliver Nov 2025

Investigating The Security Vulnerabilities Of Ip Cameras: Classifications And Trends From Public Cve Data, Sam Oliver

Cybersecurity Undergraduate Research Showcase

Internet of Things (IoT) devices are increasingly targeted by cyber attacks due to weak authentication, insecure communication protocols, outdated firmware, and many other vulnerabilities. Internet Protocol (IP) cameras, a subset of these IoT devices, are particularly vulnerable and often transmit sensitive information. This paper analyzes vulnerability data from the National Vulnerability Database (NVD) to classify security vulnerabilities affecting IP cameras. Using this dataset, the paper examines the types and frequencies of these vulnerabilities, including authentication bypass, web interface exploits, and default and weak credentials. We additionally examine trends over time and across categories. This research aims to identify the primary …


Securing The Digital Harvest: Cybersecurity As A Core Agribusiness Skill, Jody Herchenbach, George Grispos Oct 2025

Securing The Digital Harvest: Cybersecurity As A Core Agribusiness Skill, Jody Herchenbach, George Grispos

Mountain Plains Business Conference

The digitization of agriculture, through IoT-enabled equipment, cloud platforms, and precision technologies, has improved efficiency and profitability while also introducing significant cybersecurity risks. These vulnerabilities can disrupt supply chains, compromise sensitive data, and undermine financial stability. Yet agribusiness degree programs often overlook cybersecurity education. This paper proposes integrating cybersecurity content on threat awareness, incident response, and data protection into agribusiness curricula. Embedding these elements equips graduates to manage both digital and financial risks, enhancing resilience and competitiveness. Such curricular innovation aligns technical and managerial training, preparing future agribusiness professionals to lead securely and sustainably in an increasingly connected industry.