Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Business

Institution
Keyword
Publication Year
Publication
Publication Type

Articles 31 - 60 of 485

Full-Text Articles in Information Security

Integrating Adversarial Scenarios Into Llm Security Labs: An Experience Report On A Hands-On Approach, Dominic A. Wilson Jan 2026

Integrating Adversarial Scenarios Into Llm Security Labs: An Experience Report On A Hands-On Approach, Dominic A. Wilson

Journal of Cybersecurity Education, Research and Practice

This paper presents an exploratory case study detailed as a pedagogical experience report on integrating adversarial Large Language Model (LLM) scenarios into a graduate cybersecurity curriculum. In addition to prompt injection, sophisticated techniques such as jailbreaking and model inversion pose emerging threats that traditional computer security curricula often lack. We present the design and implementation of a structured, hands-on module addressing this gap, utilizing a custom Retrieval-Augmented Generation (RAG) platform with local open-source LLMs. A cohort of 16 graduate students participated in this two-week pilot module, engaging in "red team" activities to actively exploit model alignment and privacy vulnerabilities. The …


The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches To Teach Foundational Cybersecurity Failures, Chinedum Amaechi, Doris Asogwa, Samuel Alade Jan 2026

The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches To Teach Foundational Cybersecurity Failures, Chinedum Amaechi, Doris Asogwa, Samuel Alade

Journal of Cybersecurity Education, Research and Practice

SourceURL:file:///home/amaechi/Documents/ *Journal of Cybersecurity Education, Research and Practice (JCERP)*. **Title:** The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches to Teach Foundational Cybersecurity Failures.docx

Background: Between March and April 2026, a single threat actor allegedly compromised four Nigerian institutions across banking, payment infrastructure, government registry, and power distribution sectors. The breaches exposed millions of records and disrupted critical services, yet all four exploited elementary vulnerabilities taught in introductory cybersecurity courses. Objective: This pedagogical case study analyzes the four breaches as a unified phenomenon of "normalized negligence" and provides ready-to-use teaching materials for cybersecurity educators. Methods: Using open-source intelligence analysis of …


Advancing Cybersecurity Practice: Explainable Machine Learning For Network Intrusion Detection, Adam Grabowski, Shengjie Xu Dec 2025

Advancing Cybersecurity Practice: Explainable Machine Learning For Network Intrusion Detection, Adam Grabowski, Shengjie Xu

Journal of Cybersecurity Education, Research and Practice

This research investigates explainable artificial intelligence (XAI) integration within machine learning (ML)-based intrusion detection systems (IDS), focusing on distinguishing malicious from benign network activities. We employed Random Forest and XGBoost models evaluated on widely recognized datasets, including NSL-KDD and UNSW-NB15, using both binary and multi-class classification tasks. The objective was to enhance cybersecurity operations through improved model transparency and interpretability. By integrating SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-Agnostic Explanations), the study offers comprehensive global and local insights into model decision-making processes. Results demonstrate SHAP's effectiveness in providing a broad, dataset-wide understanding of feature interactions and importance, while …


A Study Of Configuration Management Database (Cmdb) Adoption In It Service Management (Itsm) Implementations Within Nj Community Colleges, Fredrick Dande Dec 2025

A Study Of Configuration Management Database (Cmdb) Adoption In It Service Management (Itsm) Implementations Within Nj Community Colleges, Fredrick Dande

All-Inclusive List of Electronic Theses and Dissertations

This study examines the adoption of Configuration Management Databases (CMDBs) in IT Service Management (ITSM) implementations within New Jersey (NJ) community colleges. Despite the well-documented benefits of CMDBs—such as faster issue resolution, improved compliance, and greater visibility across IT infrastructures—implementation success rates remain low. As technology continues to enhance production capabilities and expand access to information, the need for centralized configuration visibility has become critical. A CMDB provides a single system of record for IT assets and services, helping organizations manage outages, assess changes, maintain compliance, and improve asset tracking. This research used an online survey to collect data from …


Software-Defined Networking Powered By Ai-Driven Anomaly Detection, Dina Moloja, Vusumuzi Malele Prof Nov 2025

Software-Defined Networking Powered By Ai-Driven Anomaly Detection, Dina Moloja, Vusumuzi Malele Prof

Journal of Cybersecurity Education, Research and Practice

Software Defined Networking (SDN) revolutionizes network control by separating the control plane from the data plane. Although the latter improves SDN agility and scalability, it creates a security hole, particularly in a central control plane, leading to SDN environments becoming high-profile targets for advanced cybersecurity threats. Due to static and signature-based point-in-time behavior, traditional security methods are unable to keep up with modern attacks that are an anomaly to SDNs. Artificial Intelligence (AI) with its different applications and techniques, has the capability of detecting SDN cyber threats’ anomalies. This paper presents the results of a literature scoping exercise that used …


Experts’ Validation Of The Fundamental Cybersecurity Competency Index (Fcci) Using A Commercial Cyber Range Through Human-Generative Artificial Intelligence (Genai) Teaming, Dariusz Witko, Yair Levy, Catherine Neubauer, Greg Simco, Laurie P. Dringus, Melissa Carlton Nov 2025

Experts’ Validation Of The Fundamental Cybersecurity Competency Index (Fcci) Using A Commercial Cyber Range Through Human-Generative Artificial Intelligence (Genai) Teaming, Dariusz Witko, Yair Levy, Catherine Neubauer, Greg Simco, Laurie P. Dringus, Melissa Carlton

Journal of Cybersecurity Education, Research and Practice

The increasing volume of cyber threats, combined with a critical shortage of skilled professionals and rising burnout among practitioners, highlights the urgent need for innovative solutions in cybersecurity operations. Generative Artificial Intelligence (GenAI) offers promising potential to augment human analysts in cybersecurity, but its integration requires rigorous validation of the fundamental competencies that enable effective collaboration of human-GenAI teams. This research study employed a mixed-methods research project designed to evaluate human-GenAI teams, emphasizing the role of expert consensus in shaping the experimental assessment of the Fundamental Cybersecurity Competency Index (FCCI) in a commercial cyber range. We engaged 20 Subject Matter …


Security And Privacy Of Wearable And Implantable Medical Devices: A Course-Based Approach To Medical Device Cybersecurity Education, Michelle M. Ramim Nov 2025

Security And Privacy Of Wearable And Implantable Medical Devices: A Course-Based Approach To Medical Device Cybersecurity Education, Michelle M. Ramim

Journal of Cybersecurity Education, Research and Practice

As wearable and implantable medical devices become integral to remote patient monitoring and precision medicine, the associated cybersecurity and privacy risks demand urgent attention. These devices are increasingly targeted by cyberattacks, potentially endangering patient safety and data integrity. To address this, we developed an experiential learning course titled Security and Privacy of Wearable and Implantable Medical Devices, designed for advanced undergraduate and graduate students in health and medical fields. The course immerses students in real-world challenges through lectures, labs, and project-based learning, leveraging wearable devices such as FitBitTM to analyze and interpret real-time personal health data. The curriculum …


Higher Education Cybersecurity: A Vulnerability Assessment Of The U.S. South’S Institutional Websites, Zachary W. Taylor, Vivi Vo Oct 2025

Higher Education Cybersecurity: A Vulnerability Assessment Of The U.S. South’S Institutional Websites, Zachary W. Taylor, Vivi Vo

Journal of Cybersecurity Education, Research and Practice

As technology continues to advance, it is critical to understand how higher education institutions protect digital information of their stakeholders including students, faculty, and staff through cybersecurity measures. Although conceptual research has articulated various aspects of cybersecurity, no empirical research has explored the cybersecurity of higher education (.edu) websites through a vulnerability scan of these websites via an open PortScan and analysis. To fill a critical gap in the literature, this study conducted a vulnerability scan and open PortScan and analysis of all higher education websites in three of the lowest-income states in the United States: Louisiana (n=112), Mississippi (n=52), …


Impact Of Information Security Awareness Training On Knowledge, Attitude, And Behavior: A K-12 Case Study, Michael S. Robbins, Christopher Robbins Oct 2025

Impact Of Information Security Awareness Training On Knowledge, Attitude, And Behavior: A K-12 Case Study, Michael S. Robbins, Christopher Robbins

Journal of Cybersecurity Education, Research and Practice

Abstract— Information security breaches remain a serious threat across all sectors, often exploiting human factors rather than technical flaws. This study examines how a structured Information Security Awareness (ISA) training program influences employees’ knowledge of security policies, attitudes towards those policies, and self-reported security behaviors within a K-12 educational environment. A quantitative pre-test/post-test design was employed with 201 staff members (administrators, teachers, and support personnel) in a public school district. Participants completed the Human Aspects of Information Security Questionnaire (HAIS-Q) before and after undergoing an interactive cybersecurity training program. Statistical analysis revealed a significant improvement in information security knowledge, attitudes, …


Prompt Engineering For Genai In Cybersecurity Incident Response: A Multi-Platform Evaluation Based On Nice Pr-Ir-001, Yuanyuan Liu Oct 2025

Prompt Engineering For Genai In Cybersecurity Incident Response: A Multi-Platform Evaluation Based On Nice Pr-Ir-001, Yuanyuan Liu

Journal of Cybersecurity Education, Research and Practice

This study explores the application of prompt engineering in cybersecurity education, mainly by evaluating the performance of different generative artificial intelligence (GenAI) platforms when performing tasks consistent with the NICE framework role pr-ir-001 - Network Defense Incident Responder. The study employed structured prompts designed for a medical technology environment compliant with HIPAA and NIST SP 800-53, while the tasks of the three GenAI models (GPT-4, Gemini, and DeepSeek) were to generate event response scenarios. Their outputs will be evaluated from four aspects: accuracy, relevance, clarity and completeness.

The results show that the three models differ in depth and consistency, but …


Arizona’S Experiential Learning Opportunities: Regional Security Operations Centers And Cybersecurity Clinics, Joshua Kipers, Paul Wagner, Robert J. Honomichl Oct 2025

Arizona’S Experiential Learning Opportunities: Regional Security Operations Centers And Cybersecurity Clinics, Joshua Kipers, Paul Wagner, Robert J. Honomichl

Journal of Cybersecurity Education, Research and Practice

The increasing frequency, sophistication, and economic impact of cybersecurity incidents have intensified the global demand for a skilled cybersecurity workforce. Traditional academic programs often fail to provide the applied experience necessary to prepare graduates for the rapidly evolving threat landscape. This paper examines Arizona’s innovative approaches to experiential cybersecurity education through the establishment of Regional Security Operations Centers (RSOCs) and the Arizona Cybersecurity Clinic. These initiatives integrate Kolb’s Experiential Learning Theory and the NICE Cybersecurity Workforce Framework to align academic preparation with real-world practice. The RSOCs, supported by the Arizona Department of Homeland Security, provide paid student internships focused on …


Static Malware Analysis For Incident Response: Developing A Tactical Aid With Ember, Joel Meoak, Shengjie Xu Oct 2025

Static Malware Analysis For Incident Response: Developing A Tactical Aid With Ember, Joel Meoak, Shengjie Xu

Journal of Cybersecurity Education, Research and Practice

Incident responders face a variety of challenges when identifying malware using existing solutions, particularly when rapid tactical decisions are needed. Traditional malware detection methods are often signature-based, limiting their effectiveness to previously known threats detected by anti-virus (AV) engines. Online analysis tools introduce confidentiality risks, potentially alerting adversaries that their actions are under scrutiny. While free sandbox environments offer useful capabilities, they often require substantial setup time and hardware resources that may not be available in the field. This research leverages the Elastic Malware Benchmark for Empowering Researchers (EMBER) dataset to develop a lightweight, portable tactical decision aid that enables …


Experiential Learning: Innovative Approaches To Post-Secondary Cybersecurity Education, Brendan Bertone, Paul Wagner, Joshua Pauli Sep 2025

Experiential Learning: Innovative Approaches To Post-Secondary Cybersecurity Education, Brendan Bertone, Paul Wagner, Joshua Pauli

Journal of Cybersecurity Education, Research and Practice

The cybersecurity profession continues to face a significant shortfall of qualified professionals despite steady growth in degree programs. Employers consistently cite experience as the main barrier for entry-level cybersecurity hires. This paper argues that clinic-based experiential learning offers a scalable solution to that preparation gap. A systematic literature review spanning academic and professional literature was conducted to examine: (1) barriers to entry for aspiring cybersecurity professionals; (2) the effectiveness of experiential learning compared to traditional instruction; and (3) the viability and scalability of cybersecurity clinics. Screening emphasized workforce development, experiential pedagogy, and alignment with the NICE Cybersecurity Workforce Framework. Findings …


Information Security Awareness And Behavior Of Smartphone Users In The Ibadan Metropolis, Nigeria, Funmilola Olubunmi Omotayo Sep 2025

Information Security Awareness And Behavior Of Smartphone Users In The Ibadan Metropolis, Nigeria, Funmilola Olubunmi Omotayo

Journal of Cybersecurity Education, Research and Practice

Today, there is a rapid increase in the number of people using the Internet via smartphones and relying on them for most of their daily activities. Consequently, smartphones are becoming the target of criminals for atrocious purposes. This study investigated the information security awareness and behavior of smartphone users in the Ibadan metropolis, Nigeria. The study adopted a descriptive survey design. Data was collected with a questionnaire from 400 respondents who were conveniently selected. Findings revealed that most smartphone users knew about the smartphone security features available on their phones. However, most also engaged in behaviors that threatened their information …


A Comprehensive Review On Gamification In Neurocybersecurity, Ms. Kritika Aug 2025

A Comprehensive Review On Gamification In Neurocybersecurity, Ms. Kritika

Journal of Cybersecurity Education, Research and Practice

The research investigates gamification methods as it applies to the emerging interdisciplinary domain that brings together cybersecurity with neuroscience and psychology. Neurocybersecurity implements neural concepts to protect digital systems from security threats while targeting the human vulnerabilities that present as the strongest points of attack. Several researchers have examined gamification techniques which incorporate game design elements to enhance cybersecurity training outcomes by improving user participation and knowledge retention and user conduct compliance. The research incorporates Self-Determination Theory along with Cognitive Load Theory to explain the design principles for efficient gamified interventions. The implementation of both cognitive performance improvement and neuroplasticity …


Optimizing Information Security In Cloud Environments: A Risk Management Approach And Guide For Enterprise Cloud Security, Joshua Olusegun Oyeniyi, Oluwashina Akinloye Oyeniran May 2025

Optimizing Information Security In Cloud Environments: A Risk Management Approach And Guide For Enterprise Cloud Security, Joshua Olusegun Oyeniyi, Oluwashina Akinloye Oyeniran

Journal of Cybersecurity Education, Research and Practice

In recent years, cloud computing has become increasingly integral to organizational operations due to its scalability, accessibility and cost effectiveness in managing data and resources. However, the rise in security threats and attacks on cloud environments necessitates having robust measures in place to protect data confidentiality, integrity and availability. This paper presents an optimized approach to cloud information security management by reviewing the current threat landscape, evaluating key risk management frameworks, and provided practical solutions for enhancing enterprise cloud security. The study examined three leading cloud security frameworks: the Cloud Controls Matrix (CCM) known for its cloud-specific controls, the NIST …


Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green May 2025

Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green

Honors College Theses

As deepfake technology advances, cybercriminals are increasingly using AI-generated videos and audios to impersonate executives and carry out sophisticated CEO fraud schemes. These synthetic forgeries target human trust and corporate communication systems, creating an urgent need for forensic tools capable of authenticating digital evidence with legal accuracy. This thesis presents a forensic-grade AI deepfake detection pipeline designed for this purpose, emphasizing courtroom admissibility, reproducibility, and evidentiary integrity. Built entirely with free, opensource tools, the framework combines metadata analysis, AI-powered spectrogram analysis, neural artifact detection, and facial manipulation recognition into a transparent workflow that accurately identifies synthetic media. It was trained …


Hdwsa2: A Secure Hierarchical Deterministic Wallet Supporting Stealth Address And Signature Aggregation, Xin Yin, Zhen Liu, Guomin Yang, Guoxing Chen, Haojin Zhu May 2025

Hdwsa2: A Secure Hierarchical Deterministic Wallet Supporting Stealth Address And Signature Aggregation, Xin Yin, Zhen Liu, Guomin Yang, Guoxing Chen, Haojin Zhu

Research Collection School Of Computing and Information Systems

Hierarchical Deterministic Wallet (HDW) and Stealth Address (SA) are widely used in cryptocurrency communities due to their functionality and security. In the preliminary version of this work (ESORICS 2022), we formally define the syntax and security models of Hierarchical Deterministic Wallet supporting Stealth Address (HDWSA), capturing the functionality and security requirements imposed by the practice in cryptocurrency. We propose a concrete HDWSA construction and prove its security in the random oracle model. Note that when applied in blockchain, in practice, signature aggregation could reduce the cost of computation, storage, and communication dramatically. In this full version, we develop HDWSA definition …


The National Cybersecurity Teaching Coalition: Expanding Cybersecurity Education Opportunities, Paul Wagner, Melissa Dark, Robert Honomichl, Filipo Sharevski, Sandra Leiterman Apr 2025

The National Cybersecurity Teaching Coalition: Expanding Cybersecurity Education Opportunities, Paul Wagner, Melissa Dark, Robert Honomichl, Filipo Sharevski, Sandra Leiterman

Journal of Cybersecurity Education, Research and Practice

The increasing prevalence of cybersecurity threats and the shortage of qualified professionals necessitate innovative solutions for cybersecurity education at all levels. Despite the expansion of post-secondary cybersecurity programs, employer dissatisfaction with graduates and a lack of standardized introductory curricula highlights the need for structured secondary education pathways. The National Cybersecurity Teaching Coalition (NCTC) and its National Cybersecurity Teaching Academy (NCTA) address this gap by equipping high school educators with the necessary knowledge and credentials to teach cybersecurity effectively. NCTA offers an 18-credit cybersecurity graduate certificate program to ensure teachers are competent and confident to develop and teach cybersecurity curriculum with …


The Impact Of Ai Use In Programming Courses On Critical Thinking Skills, Christian Jay St Francis Clarke, Abdullah Konak Apr 2025

The Impact Of Ai Use In Programming Courses On Critical Thinking Skills, Christian Jay St Francis Clarke, Abdullah Konak

Journal of Cybersecurity Education, Research and Practice

Proficiency in computer programming extends far beyond memorizing syntax; it depends on the cultivation of critical thinking. Computer programming requires multiple interconnected competencies, including systematic problem analysis, algorithmic reasoning, mastery of programming languages, debugging capabilities, a comprehensive understanding of software development methodologies, rigorous testing practices, and systematic troubleshooting approaches. These skills are also essential for cybersecurity experts; cybersecurity programs require several programming courses to enhance students’ technical and critical thinking skills. Generative AI (GenAI) technologies have fundamentally changed the process of developing applications and approaches to teaching coding. The growing use of GenAI technologies by students in writing computer code …


The Urgency Of Instituting Systemic Cybersecurity Curriculum Within Stem At Secondary Educational Levels In Preparation For Postsecondary Institutions., Robert Spencer Mar 2025

The Urgency Of Instituting Systemic Cybersecurity Curriculum Within Stem At Secondary Educational Levels In Preparation For Postsecondary Institutions., Robert Spencer

Journal of Cybersecurity Education, Research and Practice

Over the last 20 years, many secondary institutions have made advances developing curriculum defined as “STEM (Science, Engineering and Mathematics)” in order to ensure secondary students are eligible to apply as well excel in technology degree programs at the college and university levels. Although various initiatives exist, there are studies however, which allude to a great possibility that there will be a lack of cybersecurity professionals filling present day and anticipated future positions. Despite a large number of federal and educational enhancements there is need for additional research regarding instituting overall systemic processes and curriculum which supports secondary student transition …


Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition, Rachel Bleiman, Hwanhee Park, Aunshul Rege Feb 2025

Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition, Rachel Bleiman, Hwanhee Park, Aunshul Rege

Journal of Cybersecurity Education, Research and Practice

The online dating industry generated 2.98 billion USD in 2023 and is estimated to reach 3.6 billion USD by 2025. Not surprisingly, online dating platforms are rife with romance scams that cause financial damages, with estimated losses of 1.3 billion USD in 2022 alone. Additionally, victims suffer emotional and psychological harms. This paper shares findings from a 2023 Romance Scam and Social Engineering Competition (RSSEC) that introduced students to the behavioral and psychological aspects of romance scams. Specifically, the competition aimed to expose students to (i) understanding how victims experience social engineering (SE) - the psychological manipulation of human behavior, …


Managing Cybersecurity In Local Governments: 2022, Donald F. Norris Phd, Laura K. Mateczun Jd Feb 2025

Managing Cybersecurity In Local Governments: 2022, Donald F. Norris Phd, Laura K. Mateczun Jd

Journal of Cybersecurity Education, Research and Practice

This paper, based on data from our second nationwide survey of cybersecurity among local or grassroots governments in the U.S., examines how these governments manage this important function. As we have shown elsewhere, cybersecurity among local governments is increasingly important because these governments are under constant or nearly constant cyberattack. Due to the frequency of cyberattacks, as well as the probability that at least some attacks will succeed and cause damage to local government information systems, these governments have great responsibility to protect their information assets. This, in turn, requires these governments to manage cybersecurity effectively, something our data show …


Exploring School Teachers' Cyber Security Awareness, Experiences, And Practices In The Digital Age, R Ravichandran, Sonam Singh, P Sasikala Jan 2025

Exploring School Teachers' Cyber Security Awareness, Experiences, And Practices In The Digital Age, R Ravichandran, Sonam Singh, P Sasikala

Journal of Cybersecurity Education, Research and Practice

This study investigates the awareness and practices of cyber security among school teachers, exploring their understanding of cyber threats, online behaviours, and response mechanisms to cyber incidents. A structured questionnaire was administered to gather data on demographic information, cyber security training, online practices, and experiences with cybercrime. The findings reveal varying levels of awareness among teachers, with many reporting limited knowledge of prevalent cyber threats such as phishing and identity theft. Despite the increasing reliance on digital tools for teaching, a significant number of respondents indicated a lack of formal training in cyber security. The study highlights the necessity for …


A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings Jan 2025

A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings

Research & Publications

This study investigates the prevalence and underlying causes of work-related stress and burnout among cybersecurity professionals using a quantitative survey approach guided by the Job Demands-Resources model. Analysis of responses from 50 cybersecurity practitioners reveals an alarming reality: 44% report experiencing severe work-related stress and burnout, while an additional 28% are uncertain about their condition. The demanding nature of cybersecurity roles, unrealistic expectations, and unsupportive organizational cultures emerge as primary factors fueling this crisis. Notably, 66% of respondents perceive cybersecurity jobs as more stressful than other IT positions, with 84% facing additional challenges due to the pandemic and recent high-profile …


Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu Jan 2025

Insights In Cybersecurity Of A Smart Campus - A Review, Mircea Ţălu

Journal of Cybersecurity Education, Research and Practice

The profound impact of the Internet of Things (IoT) on various fronts, is driven by technological advancements, the ubiquitous spread of information, and the emergence of transformative events. IoT presents a diverse array of possibilities within university environments, fostering a more connected and enhanced educational experience. This research undertakes a comprehensive review of existing literature to provide context to the IoT and underscore its crucial significance in the realm of smart campuses. Additionally, the paper explores the intricate connections between IoT and key concepts such as cybersecurity and wireless sensor networks to present a holistic perspective. It delves into the …


Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu Jan 2025

Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu

Engineering Management & Systems Engineering Faculty Publications

Port infrastructures are critical to global trade, handling over 80% of the world's cargo by volume. However, their increasing reliance on digital technologies has exposed them to a wide range of cyber threats. This paper provides a comprehensive analysis of cyberattacks targeting port infrastructures from 2011 to the present. We examine the types of attacks, geographical distribution, notable incidents, and underlying vulnerabilities. Additionally, we discuss mitigation strategies and future directions for enhancing cybersecurity in the maritime sector. Our findings highlight the urgent need for robust regulatory frameworks, advanced technological solutions, and collaborative efforts to safeguard critical port operations.


Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang Jan 2025

Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang

Electronic Theses & Dissertations (2024 - present)

The increasing frequency and severity of ransomware attacks pose significant challenges for organizational cybersecurity. Fragmentation across disciplines in cyber defense has created practical gaps in the development of the necessary capabilities needed to address rapidly evolving cyber threats. This study explores the impact of ransomware attacks and the evolving role of cyber insurance as a proactive cybersecurity partner. Bridging the gap between actuarial science and cyber risk management, it proposes an interdisciplinary framework that quantifies the impact of ransomware and integrates cyber insurance into cybersecurity strategies.

The primary contribution of this study is methodology. We present a framework that remains …


Interactive Visualization Workflows For Mitigating Analytical Uncertainty, Kaustav Bhattacharjee Dec 2024

Interactive Visualization Workflows For Mitigating Analytical Uncertainty, Kaustav Bhattacharjee

Dissertations

This dissertation takes a process-centric and stakeholder-first perspective for handling analytical uncertainty: the form of uncertainty that confronts data analysts' insight-generation processes in high-consequence decision-making scenarios. The cost of an incorrect decision when data is used for movie recommendations as opposed to when personal data is used to drive insights or when data-driven modeling is used to drive real-time decisions for maintaining the health of a grid are vastly different in terms of consequences. This dissertation looks at analytical uncertainty in two real-world scenarios: i) how sensitive information leakage can be prevented during the open data release process with data …


Digital Twin And Cybersecurity In Additive Manufacturing, Lidong Wang Dec 2024

Digital Twin And Cybersecurity In Additive Manufacturing, Lidong Wang

Journal of Cybersecurity Education, Research and Practice

Additive manufacturing (AM) has been applied to automotive, aerospace, medical sectors, etc., but there are still challenges such as parts’ porosity, cracks, surface roughness, intrinsic anisotropy, and residual stress because of the high level of thermal gradient. It is significant to conduct the modeling and simulation of the AM process and achieve quality products. Digital Twin (DT) can help AM with forecasting defects/errors through simulation and real-time process monitoring. DT is a concept of Industry 4.0, and its digital structure reflects the real-time behaviors of a cyber-physical or physical system. This paper introduces the progress of DT applications in AM, …