Hands-On Ransomware: An Experiential Wannacry Case Study For Undergraduate Cybersecurity Education,
2026
West Virginia University
Hands-On Ransomware: An Experiential Wannacry Case Study For Undergraduate Cybersecurity Education, Eli Creek Richmond, Thomas R. Devine
Military Cyber Affairs
Ransomware represents one of the most disruptive threats in the cyber landscape, yet hands-on malware analysis remains rare in undergraduate cybersecurity curricula. This paper presents the design, implementation, and evaluation of an experiential learning module centered on the WannaCry ransomware case study, deployed in a senior-level course at West Virginia University. Students performed static and dynamic analysis using industry-standard tools. Pre- and post-module assessments demonstrated measurable gains in self-reported competency across seven technical dimensions. The module's competencies align directly with DoD Cyber Workforce Framework Work Role 212, Cyber Defense Forensics Analyst, supporting education-to-workforce pipeline development.
From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance,
2026
Northeastern University
From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance, Shelby C. Snyder
Military Cyber Affairs
Federal agencies face a fiscal year 2027 target for enterprise-wide Zero Trust deployment, but NIST SP 800-207A defines logical components without identifying the Kubernetes technologies that implement them. This paper proposes a three-tier mapping of the Policy Engine, Policy Administrator, and Policy Enforcement Point to service mesh, microsegmentation, and perimeter tooling, stating the criteria by which each component is classified. It then applies a defined rubric to six Zero Trust vendors across component alignment, Kubernetes capability, federal authorization posture, and evidence quality, finding that no single vendor covers all three tiers. The mapping is a testable architectural proposition; a Stage …
Characterizing Advanced Persistent Threats With Cyber Attack Flow Metrics,
2026
Pikes Peak State College
Characterizing Advanced Persistent Threats With Cyber Attack Flow Metrics, Tyler Miller, Caleb Chang, Shouhuai Xu
Military Cyber Affairs
Cyber attack campaigns vary not only in scale but in structure, yet conventional characterizations often reduce them to a single dimension such as technique count or impact severity. In this paper we extend the concept of cyber attack flows by defining three new metrics, novelty, technique complexity and flow complexity. Then we characterize the attack flows of three advanced persistent threat campaigns using these metrics and draw insights regarding their capabilities. Our findings include that low novelty does not equate to low attack capabilities and that exploitation of an internet-facing appliance is a common initial attack vector.
Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling,
2026
The Ohio State University
Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck
Military Cyber Affairs
Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public safety consequences. However, attributing ransomware incidents to specific threat actors remains challenging due to ransomware-as-a-service ecosystems, actor rebranding, and the obfuscation of traditional indicators of compromise. This paper presents Semantic Shields, an NLP-driven attribution framework that leverages BERT-generated semantic embeddings and DBSCAN clustering to profile ransomware actors through the linguistic characteristics of ransom notes. Using a dataset of 295 ransom notes from 189 distinct threat groups, the framework achieved an 87.2% true positive clustering rate and …
Closing The Interpretability Gap: Explainable Ml-Based Malware Detection For Defensive Cyberspace Operations,
2026
Washington State University
Closing The Interpretability Gap: Explainable Ml-Based Malware Detection For Defensive Cyberspace Operations, Tashi Stirewalt, Sean Hodgson, Puumaaya Tahiru, Assefaw Gebremedhin
Military Cyber Affairs
This paper presents an end-to-end, explainable malware triage pipeline designed for defense-oriented cyber operations. It combines high-performance static detection methods with analyst-centered interpretability. Utilizing the EMBER 2024 Windows PE subset, we train and evaluate four classifiers and select LightGBM as the production model based on its predictive performance, inference efficiency, and compatibility with exact tree-based attribution. The deployed system consists of four sequential components: PE feature extraction, malware probability scoring, dual explainability (using SHAP and LIME), and large language model (LLM) report generation, all integrated within a Flask web interface. On a temporal test set of 1,080,000 samples, LightGBM achieves …
Cyberspace Collaborative Awareness: A Model For Unity Of Effort In Homeland Defense,
2026
Joint and Combined Warfighting School
Cyberspace Collaborative Awareness: A Model For Unity Of Effort In Homeland Defense, Mike Knapp, Sean Atkins, Matthew Mclaughlin
Joint Force Quarterly
The increasing frequency and severity of cyberattacks against U.S. critical infrastructure continue to confound homeland defense efforts. Defending against state cyber campaigns that threaten the nation’s most critical systems requires a new awareness model that can enable unity of effort across public and private actors. Examining homeland defense awareness in other domains reveals principles and approaches that can inform the development of a collaborative awareness model in cyberspace. This new framework acknowledges the interconnectedness of government and commercial networks and the independent goals of each player in the domain. Doing so provides a viable path to achieving shared domain awareness …
From Dissertation To Deployment: A Unified Software Platform Operationalizing Clinical-Prediction And Sequential-Security Ai For Healthcare,
2026
International Burch University, Sarajevo
From Dissertation To Deployment: A Unified Software Platform Operationalizing Clinical-Prediction And Sequential-Security Ai For Healthcare, Olsi Shehu, Damiana Teliti, Jasmin Kevrić, Bekir Karlik
Communications of the IIMA
Advances in machine learning for healthcare are abundant, yet most validated models remain confined to research notebooks and never reach secure, usable clinical software. This paper addresses that deployment gap by presenting a unified, security-hardened software platform that operationalizes two complementary streams of doctoral research inside a single, role-based hospital information system. The first stream contributes a clinical-prediction capability: an ultra-hybrid ensemble that couples a quantum-inspired feature transformation, particle-swarm feature selection, and calibrated soft voting for cancer-outcome prediction (96.41% accuracy, AUC-ROC 0.983 on TCGA-BRCA), survival stratification, multi-cancer generalization, and pharmacogenomic drug-response classification (89.31% mean accuracy across 25 compounds). The second …
Ecu-Malnett V2,
2026
Edith Cowan University
Ecu-Malnett V2, Matthew G. Gaber, Mohiuddin Ahmed, Michael N. Johnstone
Research Datasets
ECU-MALNETT (ECU MALware NETwork Traffic) is a real world, reproducible dataset of labeled benign and malicious network flows built from the Peekaboo execution corpus. Peekaboo runs evasive malware with dynamic binary instrumentation and records raw host-level PCAPs while granting full Internet access, yielding noisy, real-world captures with background OS activity and concurrent processes. To derive trustworthy labels from these traces, we apply Construct, a baseline aware, zero-trust labeling framework. Construct first ingests a baseline capture to establish reference sets (DNS qnames, HTTP hosts, TLS SNIs, and socket endpoints) and grows a conservative benign IP pool only via whitelisted DNS resolutions. …
Energy Security Strategy Empowered By Artificial Intelligence,
2026
Institutes of Science and Development, Chinese Academy of Sciences, Beijing 100190, China; School of Public Policy and Management, University of Chinese Academy of Sciences, Beijing 100049, China
Energy Security Strategy Empowered By Artificial Intelligence, Qiang Ji, Jiaofeng Pan, Yu Song
Bulletin of Chinese Academy of Sciences (Chinese Version)
Against the backdrop of unprecedented changes in a century, geopolitical restructuring has led to the fragmentation of energy game camps, climate change has impacted the resilience of energy infrastructure, and energy transformation has promoted the multidimensional and coordinated expansion of security connotations. Artificial intelligence, with its core advantages such as optimizing geopolitical risk prevention and control, enhancing infrastructure protection, improving energy system efficiency, and accelerating the integration of renewable energy, has promoted the shift of energy security strategy from experience driven to data-driven intelligence, achieving comprehensive risk identification, dynamic evaluation, collaborative response, and full chain monitoring, significantly improving the efficiency, …
Large Models Empowering Cybersecurity: Opportunities And Challenges,
2026
Business School, Central South University, Changsha 410083, China; Xiangjiang Laboratory, Changsha 410205, China
Large Models Empowering Cybersecurity: Opportunities And Challenges, Zhuofeng He, Dongbin Hu, Yige Yuan
Bulletin of Chinese Academy of Sciences (Chinese Version)
Cybersecurity serves as a critical pillar for national security and social stability. Large models in cybersecurity are emerging as key enablers for the intelligent transformation of cyber offense and defense systems. As one of the most advanced core technologies in artificial intelligence, large models are introducing new research directions and application paradigms in the cybersecurity domain. This study systematically reviews the current landscape of cybersecurity-oriented large model applications and products, and explores their deployment scenarios in practice. It further analyzes the development trends in model capabilities, industry ecosystems, and trustworthiness, while identifying major practical challenges such as data privacy protection, …
Critical Core Technology Breakthroughs In Large-Scale Models: Industrialization Strategies And Policy Implications,
2026
Institutes of Science and Development, Chinese Academy of Sciences, Beijing 100190, China; School of Computer and Artificial Intelligence, Beijing Technology and Business University, Beijing 100048, China
Critical Core Technology Breakthroughs In Large-Scale Models: Industrialization Strategies And Policy Implications, Zhongqi Wu, Yinshan Liu, Tao Dai, Xiaolong Zheng
Bulletin of Chinese Academy of Sciences (Chinese Version)
As a pivotal direction for breakthroughs in key core technologies within the artificial intelligence domain, large-scale models hold strategic significance in securing national scientific and technological sovereignty. This study employs a multidimensional framework encompassing “technological breakthroughs, industrial transformation, and governance policies” to systematically investigate the developmental trajectories and industrialization bottlenecks of large-scale models. At the technological level, while large-scale models exhibit exponential growth in parameter scale and computing power demands, they face critical challenges including the scarcity of high-quality data, insufficient transfer learning capabilities, and reliability-explainability trade-offs. Industrially, these models are reshaping the global industrial chain landscape through a dual-track …
Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery,
2026
Grand Valley State University
Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery, Pavan Kumar Satram
Masters Theses
This thesis presents the design, implementation, and evaluation of a lightweight end-to-end cryptographic framework integrated with a semantic quality-of-service classification system for augmented reality based telesurgery. Telesurgery can deliver expert surgical care to underserved populations, but adoption has been limited by unresolved cybersecurity, network performance, and resilience challenges. The core tension is that strong encryption adds latency that may exceed the clinical safety threshold, while unencrypted systems remain vulnerable to attacks that could endanger patients during live procedures.
The framework addresses this tension through a dual-edge security middlebox that performs per-flow encryption using semantically selected ciphers: AES-128-GCM for latency-critical haptic …
Geometry-Conditioned Adversarial Defense For Sar Automatic Target Recognition Via Regime-Specialist Classification Heads,
2026
Embry-Riddle Aeronautical University
Geometry-Conditioned Adversarial Defense For Sar Automatic Target Recognition Via Regime-Specialist Classification Heads, Skyler Fabre
Discovery Day - Daytona Beach
This project, titled Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads, addresses the critical vulnerability of deep neural networks deployed in Synthetic Aperture Radar (SAR) Automatic Target Recognition (ATR) systems to adversarial perturbations. This is where imperceptible pixel-level modifications cause confident misclassification, posing serious risks in defense and aerospace applications. The objective is to develop and evaluate RegimeResNet, a geometry-conditioned classification architecture that exploits sensor metadata unique to SAR collection systems. Rather than treating all images uniformly, RegimeResNet partitions the SAR capture space into nine geometric regimes defined by depression angle and target azimuth angle extracted …
Determinants And Invertibility In Finite Modular Systems,
2026
Embry-Riddle Aeronautical University
Determinants And Invertibility In Finite Modular Systems, Osasu Omobude
Discovery Day - Daytona Beach
This project investigates determinants and matrix invertibility in finite modular systems, focusing on matrices over Zn. Using the Hill cipher as context, it examines the algebraic conditions under which a matrix is invertible in modular arithmetic. In particular, the project studies how the determinant determines invertibility, showing that a matrix over Zn is invertible if and only if its determinant is coprime with n. The project further compares invertibility over the real numbers with invertibility over modular systems, highlighting the distinction between prime moduli Zp and composite moduli. In the prime case, matrices behave similarly to those over fields, where …
Small Uas Detection: Threat Intelligence & Risk Management Project,
2026
Embry-Riddle Aeronautical University
Small Uas Detection: Threat Intelligence & Risk Management Project, Tyler Johnson
Discovery Day - Daytona Beach
The TRANSPORTATION SECURITY ADMINISTRATION / FEDERAL AIR MARSHAL SUAS DETECTION: THREAT INTELLIGENCE & RISK MANAGEMENT PROJECT addresses the emerging safety and security challenges posed by the rapid growth of small Unmanned Aircraft Systems (sUAS) in complex airspace environments. This study analyzed 92 days of sensor-captured Remote Identification (RID) data collected near Fort Lauderdale-Hollywood International Airport (FLL) to assess operational behaviors, aviation risk, and ground risk associated with drone activity. The primary objective of this research is to identify patterns of unauthorized or hazardous sUAS operations to enhance situational awareness and inform actionable risk-mitigation strategies. The analysis identified 335 flights from …
An Evaluation Of Machine Learning Models' Efficacy In Determining Uav Spoofing Attacks,
2026
Embry-Riddle Aeronautical University
An Evaluation Of Machine Learning Models' Efficacy In Determining Uav Spoofing Attacks, Nicolas Machado, Jaxon Selzer
Discovery Day - Daytona Beach
An Evaluation of Machine Learning Models' Efficacy in Determining UAV Spoofing Attacks - The rapid integration of Unmanned Aerial Vehicles (UAVs) into urban airspace has introduced significant cybersecurity concerns, particularly due to vulnerabilities in Automatic Dependent Surveillance–Broadcast (ADS-B), which lacks authentication and encryption. This project addresses the problem of detecting spoofing and data manipulation attacks that can compromise UAV safety and mission reliability. The objective of this work is to evaluate the effectiveness of machine learning–based anomaly detection, specifically Long Short-Term Memory (LSTM) and Gated Recurrent Unit (GRU) networks, as protocol-agnostic solutions for identifying anomalous UAV behavior. To achieve this, …
A Survey On Machine Learning Applications For Operating System Fingerprinting,
2026
Embry-Riddle Aeronautical University
A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland
Discovery Day - Daytona Beach
In the modern age of computers and interconnected networks, cybersecurity and cyber-attackers are evolving in tandem to exploit each other’s vulnerabilities. One technique used by both parties is Operating System Fingerprinting (OSF): with the knowledge of what Operating System a target system is running, innate vulnerabilities can be identified and patched or exploited. Historically, OSF utilizes two main methods: passive and active—the former trades accuracy with undetectability while the latter is generally more detectable but more accurate. However, recent work has combined OSF with Machine Learning (ML) to improve accurate identification. The work presented here is a survey for the …
Dcat - Distributed Computing And Analysis Tool,
2026
Embry-Riddle Aeronautical University
Dcat - Distributed Computing And Analysis Tool, Asher Zwickel, Jacob Burdge
Discovery Day - Daytona Beach
This project uses distributed computing to process and analyze large datasets related to cyber breaches and attacks. Its main goal is to find patterns between initial cyber incidents and what happens next. It looks at whether responses tend to escalate, calm down, or stay about the same over time. Understanding this helps explain how digital conflicts develop and whether they follow predictable paths. The project was built as part of university research and runs on custom software across a cluster of 17 Chromebooks. While the system can study many topics, it is currently focused on cyber activity. The software uses …
Bridging The Gap: Cybersecurity And Occupational Safety Frameworks In Ai Data Centers,
2026
Embry-Riddle Aeronautical University
Bridging The Gap: Cybersecurity And Occupational Safety Frameworks In Ai Data Centers, Athena Leader
Discovery Day - Daytona Beach
Bridging the Gap: Cybersecurity and Occupational Safety Frameworks in AI Data Centers As artificial intelligence infrastructure expands, AI data centers represent a critical and underexamined convergence of cybersecurity and occupational safety risk. Existing frameworks such as NIST, OSHA, and ISO standards were largely developed in isolation, leaving significant gaps in how organizations manage risks that are simultaneously digital and physical in nature. This study investigates the gaps and overlaps between cybersecurity and occupational safety frameworks as they apply specifically to AI data center environments. Drawing on a targeted literature review of established regulatory and standards-based frameworks, this research identifies where …
Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain,
2026
Minnesota State University Moorhead
Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen
Dissertations, Theses, and Projects
The increasing adoption of the Internet of Medical Things (IoMT) has improved healthcare delivery through connected medical devices while simultaneously expanding the cybersecurity risks facing healthcare organizations. Although machine learning based intrusion detection systems have demonstrated high detection accuracy, their ability to respond reliably to previously unseen cyberattacks remains uncertain. This study investigated how a Neural Network model and a Logistic Regression model classified novel cyberattacks within the IoMT environment. The Neural Network and Logistic Regression models were both trained and tested using a subset of the CICIoMT2024 benchmark dataset. The Neural Network achieved 99.82% test accuracy and a 0.94 …
