Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

2025

Discipline
Institution
Keyword
Publication
Publication Type
File Type

Articles 31 - 60 of 182

Full-Text Articles in Cybersecurity

Ecu-Malnett, Matthew G. Gaber, Mohiuddin Ahmed, Michael N. Johnstone Oct 2025

Ecu-Malnett, Matthew G. Gaber, Mohiuddin Ahmed, Michael N. Johnstone

Research Datasets

ECU-MALNETT (ECU MALware NETwork Traffic) is a real world, reproducible dataset of labeled benign and malicious network flows built from the Peekaboo execution corpus. Peekaboo runs evasive malware with dynamic binary instrumentation and records raw host-level PCAPs while granting full Internet access, yielding noisy, real-world captures with background OS activity and concurrent processes. To derive trustworthy labels from these traces, we apply Construct, a baseline aware, zero-trust labeling framework. Construct first ingests a baseline capture to establish reference sets (DNS qnames, HTTP hosts, TLS SNIs, and socket endpoints) and grows a conservative benign IP pool only via whitelisted DNS resolutions. …


Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi Oct 2025

Better Digital Contracts With Prosocial Friction-In-Design, Brett Frischmann, Moshe Y. Vardi

Faculty Publications

Contract law is supposed to enable people to reach genuine agreements and cooperate. If this ideal was ever a reality, the rise of mass market contracts and boil­erplate rendered it pure fiction. Modern consumer contracts are incomprehensible to most people. No one reads them anyway.

Digital contracting involves design features that amplify traditional boilerplate harms and create others. For example, digital contracting is too cheap; low marginal costs lead to overexpansion in scale and scope. To make matters worse, the loss of autonomy from repeat engagement with digital contracting systems is pernicious. People become increasingly predictable and programmable as digital …


Optimizing Cybersecurity Through Ai Predictive Analytics And Human Expertise, Cathy Mae C. Dutong Sep 2025

Optimizing Cybersecurity Through Ai Predictive Analytics And Human Expertise, Cathy Mae C. Dutong

Journal of the Symposium of University Research and Creative Expression

Project Mentor(s): Hideki Takei, DBA

As cybersecurity threats evolve in complexity and scale, the reliance on artificial intelligence (AI) has become increasingly prevalent across both public and private sectors. This study examines the dual role of AI-driven predictive analytics in strengthening organizational cybersecurity, while addressing the ongoing need for human oversight. Through a mixed-method approach, combining survey data from cybersecurity professionals with an extensive literature review, this research analyzes AI's capacity to detect emerging threats, the systemic challenges associated with AI integration, and the indispensable role of human expertise in interpreting AI outputs. Findings indicate that while AI enhances proactive …


Microarchitectural Malware Detection Via Translation Lookaside Buffer (Tlb) Events, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert Kabban, Jose R. Gutierrez Del Arroyo, Scott R. Graham Sep 2025

Microarchitectural Malware Detection Via Translation Lookaside Buffer (Tlb) Events, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert Kabban, Jose R. Gutierrez Del Arroyo, Scott R. Graham

Faculty Publications

Prior work has shown that Translation Lookaside Buffer (TLB) data contains valuable behavioral information. Many existing methodologies rely on timing features or focus solely on workload classification. In this study, we propose a novel approach to malware classification using only TLB-related Hardware Performance Counters (HPCs), explicitly excluding any dependence on timing features such as task execution duration or memory access timing. Our methodology evaluates whether TLB data alone, without any timing information, can effectively distinguish between malicious and benign programs. We test this across three classification scenarios: (1) A binary classification problem involving distinguishing malicious from benign tasks, (2) a …


Cybersecurity And Intention To Use Mobile Banking Applications, Ishmael Chikoo, Salah Kabanda Aug 2025

Cybersecurity And Intention To Use Mobile Banking Applications, Ishmael Chikoo, Salah Kabanda

African Conference on Information Systems and Technology

The adoption rate of mobile banking amongst consumers remains low, especially in developing countries where there is a knowledge gap in understanding why consumers do not engage in the frequent use of mobile banking applications. Given that most financial institutions see mobile banking as a strategy for their competitive advantage; it is important that they understand how best to address consumer’s fears brought about by cybersecurity threats. The purpose of this study is to investigate the perceived influence of cybersecurity on the user’s intentions to use mobile banking applications. Data collected from 90 participants was statistically analysed in Smart PLS …


Machine Learning And Crime Prevention, Emily Lizewski Aug 2025

Machine Learning And Crime Prevention, Emily Lizewski

Student Theses

Predictive policing uses machine learning to analyze crime patterns and help law enforcement better efficient use their resources. These tools can improve accuracy by highlighting complex trends in large sets of data. While this technology has its advantages, it also raises important ethical and social questions. Within this paper we looks at how predictive policing works, focusing on the machine learning models often used such as decision trees, random forests, gradient boosting, and models that factor in both time and location. It also explores how these tools might unintentionally reinforce biases already present in historical crime data. In reviewing the …


Not-So-Secret Authentication: The Syncbleed Attacks And Defenses For Zero-Involvement Authentication Systems, Isaac Ahlgren, Rushikesh Shirsat, Omar Achkar, George K. Thiruvathukal, Kyu In Lee, Neil Klingensmith Aug 2025

Not-So-Secret Authentication: The Syncbleed Attacks And Defenses For Zero-Involvement Authentication Systems, Isaac Ahlgren, Rushikesh Shirsat, Omar Achkar, George K. Thiruvathukal, Kyu In Lee, Neil Klingensmith

Computer Science: Faculty Publications and Other Works

Zero-involvement authentication (ZIA) offers a promising solution for autoprovisioning large IoT device networks by enabling devices to extract identical authentication keys from ambient environmental signals without user intervention.

However, we demonstrate that existing ZIA systems leak critical information during key negotiation when they exchange synchronization messages over public wireless channels.

Our novel passive attack, SyncBleed, exploits these leaked messages to reconstruct ZIA-generated keys, successfully cracking approximately 50% of keys in under one second in our testbed experiments.

To address this vulnerability, we introduce TREVOR (Time shift REsistant VEctor ExtractOR), which generates nearly identical bit sequences from environmental signals without exchanging …


A Study On Webassembly And Its Security, Thomas Crossman Aug 2025

A Study On Webassembly And Its Security, Thomas Crossman

Research from the Berry Summer Thesis Institute, 2025

This project studies WebAssembly, a binary language specification that enables non-native languages, such as C/C++ and Rust, to run efficiently on webpages, supporting complex tasks like gaming or data processing. It functions by translating a non-native language into a WebAssembly binary, which is natively supported by most browsers. Notably, WebAssembly uses a linear memory model, storing all non-code data in a single linear array. Unfortunately, this design compromises some security principles, introducing security risks and complications.

Our overall project goal is to investigate WebAssembly functionality, develop a test program, and address a critical security challenge to enhance the safety of …


Cybersecurity: Digital Stewardship In A Violent World, Rocky K. C. Chang Aug 2025

Cybersecurity: Digital Stewardship In A Violent World, Rocky K. C. Chang

University Faculty Publications and Creative Works

This paper defines cybersecurity based on the principle of biblical stewardship. The focus of this principle is God, not the technologies, who is the creator and owner of cyberspace and everything in it. Humankind is called by God to steward them by protecting the digital property of our neighbors in cyberspace from malicious attacks. In the context of cybersecurity, a neighbor can be any individual cyber user, practitioner, educator, organization, tech company, or even hacker. However, as argued from the perspectives of human sin and human finitude, the defending stewards can never win over evil in this spiritual battle. Instead, …


Exploitation For All: The Factors That Enable Pig Butchering Schemes To Weaponize Cybersecurity's Weakest Link, Melaney Freeman Aug 2025

Exploitation For All: The Factors That Enable Pig Butchering Schemes To Weaponize Cybersecurity's Weakest Link, Melaney Freeman

Boise State Graduate Student Projects

This paper discusses pig butchering schemes and how they leverage human weaknesses through advanced social engineering and manipulation techniques that are enabled through the use of human trafficking, forced labor, and government corruption in Southeast Asia. Details regarding scammer exploitation and the formation of a victim-offender identity is presented, followed by the explanation of factors that allow organized crime groups to exist. Essential tactics used by scammers are examined to understand how they weaponize people's vulnerabilities for the duration of the scam to build a relationship with the victim and earn their trust in order to financially exhaust them through …


Broadband Resilience By Zero Trust Community Network Policy Design, Lee W. Mcknight, Danielle Smith Aug 2025

Broadband Resilience By Zero Trust Community Network Policy Design, Lee W. Mcknight, Danielle Smith

The Lender Center for Social Justice

This paper proposes a Zero Trust framework for broadband policy design to enhance community network resilience. It provides a governance and policy perspective for ensuring secure, equitable broadband access.


Robustness Investigation, Detection, And Defense Of Deep Learning Models Against False Data Injection, Amirhossein Nazeri Aug 2025

Robustness Investigation, Detection, And Defense Of Deep Learning Models Against False Data Injection, Amirhossein Nazeri

All Dissertations

This dissertation addresses the critical challenge of adversarial robustness in deep learning systems, focusing on two fundamental domains: time-series prediction and object detection. As these AI systems become increasingly deployed in safety-critical applications from power grid management to autonomous vehicles their vulnerability to adversarial attacks poses significant risks to infrastructure and human safety.

The first contribution introduces a novel stealthy black-box False Data Injection (FDI) attack specifically designed for quasi-periodic time-series data. Unlike existing attacks that produce easily detectable anomalies, our method generates adversarial perturbations that preserve the underlying periodicity and statistical properties of the data, effectively bypassing traditional anomaly …


Complex System Governance And Cyber Operations, Willie Gernard Mccallister Aug 2025

Complex System Governance And Cyber Operations, Willie Gernard Mccallister

Engineering Management & Systems Engineering Theses & Dissertations

This dissertation examines the potential integration of Complex System Governance (CSG) within cybersecurity, emphasizing the development of a reference model for Cybersecurity Infrastructures. Traditional strategies for securing digital environments have struggled to address the intricate and dynamic layers inherent in modern cybersecurity systems. The purpose of this research is to explore the applicability of CSG as a framework to assess cybersecurity infrastructure using a case study research design. The research addresses two key questions: (1) How can the CSG reference model be adapted to explore cybersecurity infrastructure? (2) What results from CSG based exploration of cybersecurity infrastructure through a case …


Low-Level Memory Attacks On Edge Assisted Robotic Applications, William Arnold Aug 2025

Low-Level Memory Attacks On Edge Assisted Robotic Applications, William Arnold

Master of Engineering Theses

This thesis investigates how low-level memory faults can undermine edge-assisted robotic systems that rely on memory optimization. As robots are utilized in real world applications, the ability to operate safely and successfully in mission critical deployment becomes important. To help achieve these goals, developers are increasingly starting to place computation nodes at network edges to meet latency and reliability requirements. Edge nodes, however, are resource-constrained and resources conservation techniques such as Kernel Same-page Merging (KSM) are enabled to deduplicate identical pages across processes or virtual machines. This thesis shows that this optimization technique quietly widens the attack surface and can …


Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeffrey K. Holifield Aug 2025

Out-Of-Band Anomaly Detection For Real Time Operating Systems, Jeffrey K. Holifield

Graduate Theses and Dissertations (2019 - present)

Real Time Operating Systems (RTOS) are increasing present throughout the industrial, business, defense, and healthcare spaces. These lightweight and efficient operating systems are designed to run on embedded, resource constrained devices, often within cyber-physical systems (CPS). A defining characteristic ofRTOSs is that they are deterministic. Tasks are scheduled to run on fixed timelines within guaranteed execution windows. In Industry 4.0 applications for example, sensors must receive and process inputs within a fixed schedule to ensure products are properly manufactured. This requires guaranteed service at fixed time periods. To accomplish this, RTOSs must conform to worst case execution times (WCETs) as …


Towards Securing Ai Systems: Investigating Threats In Multimodal Autonomous Driving & Rag Systems, Saket Sanjeev Chaturvedi Aug 2025

Towards Securing Ai Systems: Investigating Threats In Multimodal Autonomous Driving & Rag Systems, Saket Sanjeev Chaturvedi

All Dissertations

Artificial Intelligence (AI) systems have become central to high-stakes applications such as autonomous driving and language-based decision support. As their deployment accelerates, ensuring the security and trustworthiness of these systems becomes paramount. Among the most stealthy and potent threats are backdoor attacks, where models behave as expected under normal conditions but exhibit malicious behavior when triggered by specific inputs, either digital or physical.

This thesis investigates novel backdoor and adversarial vulnerabilities across two emerging classes of AI architectures: (1) multimodal 3D object detection systems that fuse LiDAR and camera data, and (2) Retrieval-Augmented Generation (RAG) systems that pair large language …


Exploring Adversarial Threats To Neuralhash: A Perceptual Hashing Algorithm, Gurleen Kaur Jul 2025

Exploring Adversarial Threats To Neuralhash: A Perceptual Hashing Algorithm, Gurleen Kaur

Student Theses

Perceptual hashing algorithms are algorithms that generate content-based image hashes by extracting perceptual features from the images. Unlike cryptographic hashes, which exhibit significant changes with even slight input alterations, perceptual hashes do not change when modifications like compression, color correction and brightness are applied to the images. These hashes are designed to remain similar for inputs that are visually or perceptually alike, which has led to their widespread application in detecting duplicate images, finding similar images for reverse image search and to detecting inappropriate content of Child sexual abuse (CSAM) images by comparing image hashes with dataset of known perceptual …


Zero Trust Architecture For Electric Transportation Systems: A Systematic Survey And Deep Learning Framework For Replay Attack Detection, Grace Muriithi, Behnaz Papari, Ali Arsalan, Laxman Timilsina, Alex Muriithi, Elutunji Buraimoh, Asif Khan, Gokhan Ozkan, Christopher Edrington, Akram Papari Jul 2025

Zero Trust Architecture For Electric Transportation Systems: A Systematic Survey And Deep Learning Framework For Replay Attack Detection, Grace Muriithi, Behnaz Papari, Ali Arsalan, Laxman Timilsina, Alex Muriithi, Elutunji Buraimoh, Asif Khan, Gokhan Ozkan, Christopher Edrington, Akram Papari

Montclair State University Scholarship & Creative Works

Modern and autonomous hybrid electric vehicles (HEVs), as complex cyber-physical systems, represent a key innovation in the future of transportation. However, the increasing interconnectivity and reliance on digital components expose these vehicles to significant cybersecurity risks. To address these challenges, Zero Trust Architecture (ZTA) has emerged as a promising security framework. Operating on the principle of ‘never trust, always verify,’ ZTA offers a comprehensive approach to ensuring continuous trust verification in HEV systems. Despite its potential, the application of ZTA within cyber-physical vehicular systems remains underexplored, and its practical benefits and limitations are not yet fully understood by the engineering …


Securing Ai-Generated Code, Andreas E. Nelson Jul 2025

Securing Ai-Generated Code, Andreas E. Nelson

Scholarly Horizons: University of Minnesota, Morris Undergraduate Journal

The increasing use of AI for code generation presents significant security challenges, as these tools often lack inherent security awareness and can produce vulnerable code. This paper investigates these security risks, outlining common types of vulnerabilities (such as injection flaws and improper resource handling) found in AI-generated code. It further explores and evaluates mitigation techniques aimed at im-proving code security, including model fine-tuning and adversarial strategies like Security Verifier Enhanced Neural Steering (SVEN). Findings indicate that while current methods offer promising ways to reduce vulnerabilities, ongoing research and development are crucial for the secure and responsible deployment of AI in …


Digital Forensics And Ai: Artifact Analysis And Using Ai In The Forensics Domain, Clinton Joel Walker Jul 2025

Digital Forensics And Ai: Artifact Analysis And Using Ai In The Forensics Domain, Clinton Joel Walker

LSU Doctoral Dissertations

Digital Forensics (DF) is a field of forensic science focusing on the acquisition, authentication, and analysis of digital evidence while maintaining integrity of that data. DF analysts use forensic tools to parse large volumes of data for investigations and depend on them for identification of pertinent digital evidence in vast amounts of data. Keeping up with innovations and ever-expanding data volumes is a constant challenge for these investigators. The prevalence of Artificial Intelligence (AI) in everyday computing is rapidly expanding, with the use of Machine Learning (ML) and Large Language Models (LLM)s becoming increasingly commonplace. Innovations in technology bring new …


Application Of Hyflex In The Application Security Module, Vanessa Ayala-Rivera Jul 2025

Application Of Hyflex In The Application Security Module, Vanessa Ayala-Rivera

Case studies: Digital Education

No abstract provided.


An Evening With Mobile Hyflex, Peter Alexander Jul 2025

An Evening With Mobile Hyflex, Peter Alexander

Case studies: Digital Education

Network Security is a 10-credit module taught on the part-time Bachelor of Science in Computing in Digital Forensics & Cyber Security course in TU Dublin. While the overall course is mainly delivered online, there are some topics in this particular module which benefit from having a hands-on interactive element. The challenge though with facilitating learners to have that interactive experience is that the ones who cannot travel to campus should not be excluded. The mobile Hyflex project helped address this challenge by giving students both on campus and online a comparable interactive experience. Changes made to practice (100-150 words).


Enhancing Proof-Of-Learning Security Against Spoofing Attacks Using Model Watermarking, Ozgur Ural Jul 2025

Enhancing Proof-Of-Learning Security Against Spoofing Attacks Using Model Watermarking, Ozgur Ural

Doctoral Dissertations and Master's Theses

With the rapid expansion of machine learning (ML) technologies across diverse domains such as healthcare, finance, and autonomous systems, ensuring secure and trustworthy training methodologies has become more critical than ever. Proof-of-Learning (PoL) has recently emerged as a foundational mechanism for verifying the computational effort invested in training ML models, thereby certifying the authenticity and reproducibility of the training process. Yet PoL, when deployed in isolation, remains vulnerable to sophisticated spoofing attacks that manipulate its subset-verification pathways and tolerance parameters. In parallel, model watermarking has become indispensable for safeguarding intellectual property and detecting unauthorized model usage. Motivated by these complementary …


The Effectiveness Of Scenario-Based Cybersecurity Day Camps In Southern Rural Appalachia, Anna P. Rodgers-Stine, Tania Williams Jun 2025

The Effectiveness Of Scenario-Based Cybersecurity Day Camps In Southern Rural Appalachia, Anna P. Rodgers-Stine, Tania Williams

Journal of Cybersecurity Education, Research and Practice

As the emphasis on cybersecurity instruction in the K12 environment continues to expand, furthering access to cybersecurity education is paramount across the United States. While designated cybersecurity courses are not available in many schools, the implementation of cybersecurity camps may help to bridge the gap and increase student interest in and awareness of cybersecurity as a field. From 2021 through 2024, cybersecurity day camps were held in a region in rural southern Appalachia with the goal of increasing student interest and access to cybersecurity topics. Through the creation and implementation of these camps, it was found that scenario-based cybersecurity day …


Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez Del Arroyo, Tor J. Langehaug, Scott R. Graham Jun 2025

Exploring The Translation Lookaside Buffer (Tlb) For Low-Level Task Differentiation And Classification, Cristian Agredo, Daniel F. Koranek, Christine M. Schubert, Jose A. Gutierrez Del Arroyo, Tor J. Langehaug, Scott R. Graham

Faculty Publications

The primary focus of modern Central Processing Unit (CPU) technologies is performance improvement, with security often considered a secondary concern. As a result, vulnerabilities within the system are overlooked. While significant research, both offensive and defensive, has been conducted on CPU caches, relatively little attention has been given to the Translation Lookaside Buffer (TLB) due to its perceived lack of data granularity. Prior studies have typically combined multiple Hardware Performance Counters (HPCs) or relied on timing analysis to extract meaningful insights. In contrast, this study introduces a novel methodology that leverages only TLB related HPCs for multi-task classification, without incorporating …


Context-Switch Attacks: Understanding And Mitigating The Threat To Llm Applications, Sydney Holder, Bivin Sadler Jun 2025

Context-Switch Attacks: Understanding And Mitigating The Threat To Llm Applications, Sydney Holder, Bivin Sadler

SMU Data Science Review

Large Language Models (LLMs) are transforming conversational AI, yet their dependence on prompt-supplied context exposes them to context-switch attacks that covertly steer dialogue toward sensitive or malicious ends. A 70 one-sided conversation transcript evaluation set was constructed spanning various fraudulent scenarios. Each transcript embeds adversarial patterns drawn while preserving natural conversational flow. We introduce a hybrid defense that pairs a BERT-based semantic-drift detector (cosine-similarity threshold = 0.70) with a curated keyword and hack-phrase scanner to counter these threats. In aggregate, the system delivered 100 % recall, intercepting every simulated phishing or data-harvesting attempt. The keyword layer achieved perfect precision, generating …


Diversifying Cybersecurity: Evaluation Of An Internet Of Things (Iot)-Based Cybersecurity Training Course Designed To Bridge The Diversity Gap, Maureen Namukasa, Bhoomin B. Chauhan, Carlie Swords, Curtice Gough, Weronika Dymanus, Catherine Diresta, John Vitali, Vivek Sharma, T J. Oconnor, Meredith Carroll Jun 2025

Diversifying Cybersecurity: Evaluation Of An Internet Of Things (Iot)-Based Cybersecurity Training Course Designed To Bridge The Diversity Gap, Maureen Namukasa, Bhoomin B. Chauhan, Carlie Swords, Curtice Gough, Weronika Dymanus, Catherine Diresta, John Vitali, Vivek Sharma, T J. Oconnor, Meredith Carroll

Aeronautics Faculty Publications

This study aimed to evaluate the effectiveness of an eight-module Cybersecurity course at increasing the learning outcomes of middle and high school students with little to no experience, including underrepresented minorities (URMs) in Cybersecurity. Twice we administered and evaluated the Cybersecurity course, which included hands-on IoT-based activities, utilizing collaborative learning, scaffolding, and representation-based learning strategies. Using a quasi-experimental, within-subjects, repeated measures design, each participant experienced a pretest, the course, and a post-test to evaluate the impact on learners’ self-efficacy, interest, and knowledge. The results revealed that (1) at pre-test, female (p = .001) and in one course administration minority …


Video Game Hacking, A General Problem With Generalized Solutions, Luke Rowe Jun 2025

Video Game Hacking, A General Problem With Generalized Solutions, Luke Rowe

Master's Theses

As video games continue to get more popular and lucrative, the number of malicious actors seeking to exploit them grows with it. As this industry expands, so does the importance of securing games against cheating and abuse. This thesis aims to educate developers to help mitigate the abuse of video games by these malicious actors. The goal of this thesis is to provide a foundational framework for thinking like a hacker and how to make games harder to abuse once a hacker bypasses conventional anti-cheat software.

This thesis outlines some of the most common cheating methods and provides general context …


Property Testing Ai: An Efficient Frontier, Paul Sopher Lintilhac Jun 2025

Property Testing Ai: An Efficient Frontier, Paul Sopher Lintilhac

Dartmouth College Ph.D Dissertations

In this dissertation, we take a step towards addressing the major problem of a lack of standardized and rigorous approaches to testing and evaluation of AI systems. Taking inspiration from both the fields of Property Testing and Property Based Testing (for programs), we develop a novel taxonomy of partially overlapping classes of properties of AI systems, including simple properties, compound properties, higher order properties, data relation properties, and architecture-utility properties. We argue that this taxonomy categorizes a diverse set of AI traits -- including accuracy, fairness, robustness, monotonicity, point-wise and global privacy properties, sensitivity, and more -- according to the …


Spos: An Attestation Solution For The Detection And Mitigation Of Point Of Sale Malware, Damian Singh Dhesi Jun 2025

Spos: An Attestation Solution For The Detection And Mitigation Of Point Of Sale Malware, Damian Singh Dhesi

Master's Theses

Securing 95% of card present transactions, accounting for billions of transactions a year, has made EMV the premier protocol for card-based payment. Created by and named after Europay, Mastercard, and Visa, the EMV protocol provides multiple solutions to resolve security concerns with the outdated, swipe-based, magnetic stripe payment. Such solutions are Chip and PIN which provides a more secure transaction at a significant time cost and EMV contactless which provides improved security to Chip and PIN at greater ease of use with its quick, tap-to-pay based payment. However, regardless of how secure the EMV protocol makes the card side of …