T3-Ciders: Train-The-Trainer And Community Building To Increase Cyberinfrastructure Adoption In Cybersecurity Research And Education,
2025
Old Dominion University
T3-Ciders: Train-The-Trainer And Community Building To Increase Cyberinfrastructure Adoption In Cybersecurity Research And Education, Wirawan Purwanto, Mohan Yang, Peng Jiang, Shanan Chappell Moots, Masha Sosonkina, Hongyi Wu
University Administration Publications
T³-CIDERS is a train-the-trainer program to increase the adoption of advanced cyberinfrastructure (CI) and data skills into the fabric of research and education in cybersecurity and cyber-related disciplines. T³-CIDERS trains faculty, researchers, and students as “future trainers” (FTs) with hands-on technical and instructional skills to enable more people to effectively leverage CI in cybersecurity. The program includes a series of technical pre-training modules, a weeklong summer institute, ongoing learning engagements conducted over an academic year; it culminates with the FTs conducting locally tailored CI-infused training events at their respective home institutions. Ultimately, T³-CIDERS aims to build a “CI+cybersecurity” community of …
Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance,
2025
University at Albany, State University of New York
Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang
Electronic Theses & Dissertations (2024 - present)
The increasing frequency and severity of ransomware attacks pose significant challenges for organizational cybersecurity. Fragmentation across disciplines in cyber defense has created practical gaps in the development of the necessary capabilities needed to address rapidly evolving cyber threats. This study explores the impact of ransomware attacks and the evolving role of cyber insurance as a proactive cybersecurity partner. Bridging the gap between actuarial science and cyber risk management, it proposes an interdisciplinary framework that quantifies the impact of ransomware and integrates cyber insurance into cybersecurity strategies.
The primary contribution of this study is methodology. We present a framework that remains …
A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective,
2025
Old Dominion University
A Governance-Centric Framework For Strengthening Healthcare Cybersecurity: A Systems Perspective, Sujatha Alla, Sai Gireesh Komaragiri, Teresa Duvall, Satluk Karahan, Nagesh Bheesetty, Vijay Kumar Chattu
Engineering Management & Systems Engineering Faculty Publications
Healthcare systems face unprecedented security and privacy challenges due to increasing digitization and interconnectedness. This paper provides a comprehensive analysis of these challenges by examining various cyberattacks, defensive mechanisms, and governance frameworks within modern healthcare infrastructure. The research systematically categorizes prevalent security threats, such as ransomware, insider threats, and data breaches, identifying vulnerabilities specific to healthcare systems. Furthermore, the study evaluates current defensive strategies, including encryption techniques, access control systems, and intrusion detection tools, assessing their effectiveness against complex cyber threats. A key focus is placed on governance structures and their role in cybersecurity resilience. The research explores how regulatory …
Potsdam: Pareto Optimization Targeting Security, Data, And Mediation,
2025
Dartmouth College
Potsdam: Pareto Optimization Targeting Security, Data, And Mediation, J Peter Brady
Dartmouth College Ph.D Dissertations
Given the growing amount and variety of data handled by modern systems, it is crucial to guarantee the accuracy and protection of input data without errors or malicious intentions. The need to improve security in software programs often conflicts with the assurance of maximum performance, making developers and maintainers hesitant to incorporate more testing.
LangSec (Language-Theoretic Security) is a security approach that treats input validation as a formal language recognition problem, ensuring that only well-defined, unambiguous inputs are processed to eliminate exploitable parsing flaws. This dissertation explores integrating LangSec principles with Pareto optimization to enhance safety and robustness in digital …
Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024),
2025
University Politehnica of Bucharest, Romania
Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu
Engineering Management & Systems Engineering Faculty Publications
Port infrastructures are critical to global trade, handling over 80% of the world's cargo by volume. However, their increasing reliance on digital technologies has exposed them to a wide range of cyber threats. This paper provides a comprehensive analysis of cyberattacks targeting port infrastructures from 2011 to the present. We examine the types of attacks, geographical distribution, notable incidents, and underlying vulnerabilities. Additionally, we discuss mitigation strategies and future directions for enhancing cybersecurity in the maritime sector. Our findings highlight the urgent need for robust regulatory frameworks, advanced technological solutions, and collaborative efforts to safeguard critical port operations.
Effective Pii Extraction From Llms Through Augmented Few-Shot Learning,
2025
Zhejiang University
Effective Pii Extraction From Llms Through Augmented Few-Shot Learning, Shuai Cheng, Shu Meng, Haitao Xu, Haoran Zhang, Shuai Hao, Chuan Yue, Wenrui Ma, Meng Han, Fang Zhang, Zhao Li
Computer Science Faculty Publications
Large Language Models (LLMs) exhibit strong natural language processing capabilities but also pose significant privacy risks, particularly regarding the leakage of Personally Identifiable Information (PII) embedded in their training data. Existing PII extraction methods suffer from the limitations of low success rates or impracticality for large-scale PII extraction. In this study, we propose a novel PII extraction approach based on enhanced few-shot learning techniques, which achieves efficient and cost-effective PII retrieval without relying on fine-tuning or jailbreaking. We evaluated our approach on both open-source and closed-source LLMs. The experimental results demonstrate that, for non-targeted PII extraction, the attack success rate …
Cyber Warfare And The Future Of Conflict,
2025
Missouri State University
Cyber Warfare And The Future Of Conflict, Victor A. Mercado
Graduate Theses/Dissertations
This thesis examines whether cyber warfare now poses a more immediate threat to U.S. national security than weapons of mass destruction (WMD). Cyber operations have become a dominant instrument of contemporary conflict, with malicious actors operating in a persistent “grey zone” that blurs traditional boundaries between war and peace. These operations target military and civilian entities, both directly and often as collateral damage due to the uncontrollable nature of cyber threats. WMDs, despite their catastrophic destructive potential, remain largely constrained by established deterrence frameworks.
The evolving nature of cyber warfare warrants comparison to WMD effects and impact, as cyber capabilities …
Studies On Convexity Of Dnf Formulae,
2025
University at Albany, State University of New York
Studies On Convexity Of Dnf Formulae, Josue A. Ruiz
Electronic Theses & Dissertations (2024 - present)
In this dissertation, we investigate the problem of determining whether a Boolean formula given in disjunctive normal form (DNF) is convex. Although Boolean formulas have various applications, our research focuses on the practical application for rule-based access control policies, where policies are often expressed as a set of Boolean rules. Understanding the structural properties of such formulas is crucial for determining whether a policy can be efficiently represented within a specific access control model.
The main contribution of this research is the conception and analysis of convexity derived from the “gap problem.” In this context, convexity is characterized by the …
Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework,
2025
Old Dominion University
Enhancing Cyber Situational Awareness Through Dynamic Adaptive Symbology: The Dass Framework, Nicholas Macrino, Sergio Pallas Enguita, Chung-Hao Chen
Electrical & Computer Engineering Faculty Publications
The static nature of traditional military symbology, such as MIL-STD-2525D, hinders effective real-time threat detection and response in modern cybersecurity operations. This research introduces the Dynamic Adaptive Symbol System (DASS), a novel framework enhancing cyber situational awareness in military and enterprise environments. The DASS addresses static symbology limitations by employing a modular Python 3.10 architecture that uses machine learning-driven threat detection to dynamically adapt symbol visualization based on threat severity and context. Empirical testing assessed the DASS against a MIL-STD-2525D baseline using active cybersecurity professionals. Results show that the DASS significantly improves threat identification rates by 30% and reduces response …
An Overview Of Video Game Biometrics Collection And Considerations For Cyberbiosecurity,
2025
BiosView Labs
An Overview Of Video Game Biometrics Collection And Considerations For Cyberbiosecurity, Lucas Potter, Christen Westberry, Xavier-Lewis Palmer
Electrical & Computer Engineering Faculty Publications
Over the past fifty years, the global cost of consumer electronics has significantly decreased, leading to greater accessibility to both biosensing systems and interactive entertainment platforms. This increased access has naturally resulted in higher usage of medical and entertainment electronics. However, the intersection of these technologies, combined with invasive data harvesting practices, has raised concerns about the potential misuse of biological signals to manipulate individuals' behavior both within and beyond the video game environment. Currently, biometric data in video games are employed in various ways, such as using Heart Rate Variability (HRV) as a performance metric and integrating eye tracking …
Grosafe: In-Classroom Technology-Enabled Solution To Build Societal Resilience Against Child Grooming,
2024
Technological University Dublin
Grosafe: In-Classroom Technology-Enabled Solution To Build Societal Resilience Against Child Grooming, Christina Thorpe, Fiona Jennings
Conference Papers
GroSafe is an innovative initiative developed by TU Dublin in partnership with the ISPCC to address the critical issue of child grooming. By leveraging cutting-edge digital technologies, GroSafe focuses on educating children, caregivers, and educators to recognise, report, and prevent grooming behaviours. It integrates a 3D educational gaming environment with adaptive learning tools, enabling safe and effective engagement for children, including those with diverse learning needs. Designed to align with Ireland’s SPHE curriculum, GroSafe empowers schools and communities to tackle grooming through early intervention and resilience building.
Toward An Insider Threat Education Platform: A Theoretical Literature Review,
2024
Dakota State University
Toward An Insider Threat Education Platform: A Theoretical Literature Review, Haywood Gelman, John D. Hastings, David Kenley, Eleanor Loiacono
Research & Publications
Insider threats (InTs) within organizations are small in number but have a disproportionate ability to damage systems, information, and infrastructure. Existing InT research studies the problem from psychological, technical, and educational perspectives. Proposed theories include research on psychological indicators, machine learning, user behavioral log analysis, and educational methods to teach employees recognition and mitigation techniques. Because InTs are a human problem, training methods that address InT detection from a behavioral perspective are critical. While numerous technological and psychological theories exist on detection, prevention, and mitigation, few training methods prioritize psychological indicators. This literature review studied peer-reviewed, InT research organized by …
Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy,
2024
Dakota State University
Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang
Research & Publications
The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach …
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation,
2024
Dakota State University
Microsegmented Cloud Network Architecture Using Open-Source Tools For A Zero Trust Foundation, Sunil Arora, John Hastings
Research & Publications
This paper presents a multi-cloud networking architecture built on zero trust principles and micro-segmentation to provide secure connectivity with authentication, authorization, and encryption in transit. The proposed design includes the multi-cloud network to support a wide range of applications and workload use cases, compute resources including containers, virtual machines, and cloud-native services, including IaaS (Infrastructure as a Service), PaaS (Platform as a service). Furthermore, open-source tools provide flexibility, agility, and independence from locking to one vendor technology. The paper provides a secure architecture with micro-segmentation and follows zero trust principles to solve multi-fold security and operational challenges.
Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension,
2024
Air Force Institute of Technology
Mitigating Code Reuse Attacks On Risc-V Binaries: Minimizing Gadget Availability Using The Compressed Extension, Heitor Vieira
Theses and Dissertations
Embedded systems are vital in civilian and military applications, requiring high performance and security. The open RISC-V Instruction Set Architecture (ISA) offers significant advantages, including security through community review and strategic independence in microchip supplies. Brazil’s recent partnership with RISC-V highlights its potential for national technological sovereignty. However, RISC-V is not inherently resistant to code reuse attacks (CRAs), highlighting the need to integrate security measures early in development. The RISC-V Compressed extension, while beneficial for optimizing performance and code flexibility, introduces security trade-offs. As RISC-V adoption grows, particularly in critical systems, addressing these security challenges from the start is crucial …
Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns,
2024
University of New Orleans
Enhancing Password Security And Memorability Using Machine Learning And Linguistic Patterns, Jared Wise
LSU New Orleans Theses and Dissertations
In the digital age, text-based passwords remain a primary method for securing online accounts. Yet, users frequently face a dilemma between creating passwords that are easy to remember and sufficiently secure against cyberattacks. This research introduces an approach to password generation that bridges this gap by utilizing linguistic patterns, particularly song lyrics, to develop highly secure and naturally memorable passwords. Using large lyric datasets gained from web scrapes from popular song lyric websites (AZ Lyrics, Genius), features are extracted from a corpus of over 5 million lyrics using sentence structure and natural language processing in a novel way. In using …
Dynamic Key-Based Privacy-Preserving Authentication Scheme For Internet Of Drones,
2024
The University of Southern Mississippi
Dynamic Key-Based Privacy-Preserving Authentication Scheme For Internet Of Drones, Zain Chaudhary
Honors Theses
The Internet of Drones (IoD) proliferation has catalyzed transformative changes across various industries, from agriculture to urban management. However, expanding drone networks also presents significant security challenges concerning secure communication and authentication. This paper introduces a robust privacy-preserving key-based authentication scheme tailored explicitly for the IoD, utilizing a matrix key generated by Hierarchical Message Authentication Codes (HMAC) and the SHA-256 algorithm to address these vulnerabilities. Our system enhances security by ensuring each drone in the network can authenticate securely and reliably with a central unit, preventing unauthorized access and securing communications against common threats like eavesdropping and impersonation attacks. Our …
A Web Application For Comparing Llm And Knowledge Graph Performance On Cybersecurity Queries,
2024
University of Tennessee at Chattanooga
A Web Application For Comparing Llm And Knowledge Graph Performance On Cybersecurity Queries, Major Schwartz
Honors Theses
The evolution of cybersecurity has led to a spike in digital threats, both in frequency and complexity, necessitating advanced, intelligent solutions to protect sensitive information. Traditional defense mechanisms are increasingly inadequate, pushing cybersecurity professionals to seek innovative approaches for threat detection, response, and data analysis. This thesis investigates the integration of Large Language Models (LLMs) and Knowledge Graphs into cybersecurity workflows to address these challenges. Specifically, it explores the development of a web application that enables real-time, interactive use of state-of-the-art LLMs, such as OpenAI’s GPT-4 and similar models, for improved threat response and workflow efficiency. Built with a React …
Phantom Jam Sybil Attack In Connected Vehicular Networks,
2024
University of Tennessee at Chattanooga
Phantom Jam Sybil Attack In Connected Vehicular Networks, Ahmed Ali Elamin Mohamed
Masters Theses and Doctoral Dissertations
Vehicular Ad-hoc Networks (VANETs) are vulnerable to Sybil attacks, mostly due to the lack of encryption in BSMs. In VANETs, multiple digital certificates (pseudonyms) are assigned to each vehicle to ensure their privacy. However, malicious nodes can exploit these pseudonyms to create ghost vehicles, inducing fake traffic jams and disturbance to other vehicles which may lead to accidents. In this work, we have developed the first sophisticated sybil attack, in which an attacker uses legitimate pseudonyms to create multiple ghost vehicles. These ghost vehicles transmit realistic kinematic data, using trajectory formulas and road maps. Additionally, the ghost vehicles randomly simulate …
A Comparative Study Of Patterns, Causes, And Impacts Of Data Breaches Across Geographical Regions And Time Frames,
2024
California State University – San Bernardino
A Comparative Study Of Patterns, Causes, And Impacts Of Data Breaches Across Geographical Regions And Time Frames, Bhavish Balsara
Electronic Theses, Projects, and Dissertations
The rise of digital technologies and interconnected systems has made data breaches a growing global concern. This culmination project explores the patterns, causes, and impacts of data breaches across various countries with varying levels of economic development and cybersecurity infrastructure from 2020 to 2023. This research aims to provide insights into the global landscape of data breaches and how they have evolved in recent years. The research questions are: (Q1) How do data breach patterns differ between countries with different levels of economic development and cybersecurity infrastructure? (Q2) What patterns and trends can be identified in data breaches when analyzing …
