Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Articles 1 - 5 of 5

Full-Text Articles in Cybersecurity

Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson Jul 2026

Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson

Journal of Cybersecurity Education, Research and Practice

In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life …


Understanding Phishing Susceptibility Through Expert Consensus Using Digital Marketing Parallels And A Machine Learning-Based Implementation, Mansoor Ahmad Jan 2026

Understanding Phishing Susceptibility Through Expert Consensus Using Digital Marketing Parallels And A Machine Learning-Based Implementation, Mansoor Ahmad

All Graduate Theses, Dissertations, and Other Capstone Projects

Phishing remains one of the most effective attack vectors for gaining unauthorized access to organizational systems, yet defenders often lack systematic methods to assess their exposure before an attack. This study develops a framework that uses machine learning to encode the collective expertise of cybersecurity practitioners into a portable phishing susceptibility assessment tool, with the goal to help security teams proactively identify patterns, prioritize awareness training, and strengthen detection controls. The study surveyed 27 practitioners with extensive experience in social engineering, red teaming, penetration testing, and threat analysis to identify which factors most influence phishing susceptibility. Practitioners provided quantitative ratings …


Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim Jan 2026

Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim

School of Cybersecurity Faculty Publications

Phishing involves manipulating individuals into revealing private data, e.g., user IDs, bank details, and passwords. The observed surge in fraud is related to increased deception, impersonation, and advanced online attacks. Thus, effective phishing detection methods are required to mitigate escalating global phishing threats. Existing methods (e.g., heuristics-based, signature-based, and visual similarity-based methods) attempt to detect phishing sites, and machine learning (ML) and deep learning (DL) methods are effective in the cybersecurity context in terms of learning from data, offering insights, and forecasting. However, independent ML algorithms are limited when handling complex data, and DL techniques surpass traditional ML methods in …


Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory May 2025

Phishy Pages - The Design Of A User-Interactive Website For Phishing Attack Evaluation, Evan C. Gregory

Honors Theses

Phishing attacks are a widespread, malicious phenomenon. These attacks steal people’s personal information, causing them ruin and lining the pockets of criminals. What makes them so dangerous is that they come in a variety of forms, including emails, websites, phone calls, and social media can be vectors for attackers. Fortunately, these attacks can be stopped by informing potential victims of common signs to look out for. Training is one of the best methods people use to teach web-users how to protect themselves. To train them, however, users must be taken through many examples of phishing attacks to learn the characteristics …


Heuristic Machine Learning Approaches For Identifying Phishing Threats Across Web And Email Platforms, Ramprasath Jayaprakash, Krishnaraj Natarajan, J. Alfred Daniel, Chandru Vignesh Chinnappan, Jayant Giri, Hong Qin, Saurav Mallik Jan 2024

Heuristic Machine Learning Approaches For Identifying Phishing Threats Across Web And Email Platforms, Ramprasath Jayaprakash, Krishnaraj Natarajan, J. Alfred Daniel, Chandru Vignesh Chinnappan, Jayant Giri, Hong Qin, Saurav Mallik

Data Science Faculty Publications

Life has become more comfortable in the era of advanced technology in this cutthroat competitive world. However, there are also emerging harmful technologies that pose a threat. Without a doubt, phishing is one of the rising concerns that leads to stealing vital information such as passwords, security codes, and personal data from any target node through communication hijacking techniques. In addition, phishing attacks include delivering false messages that originate from a trusted source. Moreover, a phishing attack aims to get the victim to run malicious programs and reveal confidential data, such as bank credentials, one-time passwords, and user login credentials. …