Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons™

Open Access. Powered by Scholars. Published by Universities.®

466 Full-Text Articles 804 Authors 161,915 Downloads 101 Institutions

All Articles in Cybersecurity

Faceted Search

466 full-text articles. Page 2 of 23.

Surveyception: An Exploration Of Deceptive Survey Forms, Muhammad Danish 2026 University of New Mexico

Surveyception: An Exploration Of Deceptive Survey Forms, Muhammad Danish

Computer Science ETDs

Survey platforms such as Google Forms and Microsoft Forms are widely used for feedback, data collection, and engagement, but scammers increasingly exploit them to distribute phishing and deceptive attacks. This thesis presents a large-scale study of survey-form abuse across ten major providers. We collected 140,000 forms from three sources: public posts on X, search-engine results, and web pages from the top 10 million DomCop-ranked domains. Using automated filtering and manual qualitative review, we identified 2,645 forms requesting sensitive information and classified 566 as scams. These forms used techniques including phishing, private-secret theft, account and personal-data harvesting, financial deception, and psychological …


Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap 2026 Capitol Technical University

Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap

Journal of Cybersecurity Education, Research and Practice

 Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking.  The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from …


Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah McClanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson 2026 Shenandoah University

Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson

Journal of Cybersecurity Education, Research and Practice

In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life …


Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry 2026 Pennsylvania State University

Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry

Journal of Cybersecurity Education, Research and Practice

This study presents a PRISMA-based systematic review of 412 cybersecurity education intervention studies, coding assessment methods, evidence types, claimed outcomes, use of established assessment instruments, and artifact availability. Despite frequent claims of skill development and workforce preparation, 45.4% of studies reported no identifiable assessment. Knowledge tests appeared in 11.4% of studies, while performance assessments appeared in 10.2%. From 2015 to 2025, assessment practices remained dominated by post-only designs or no assessment, with no statistically detectable increase in pre/post-capable designs. Use of established assessment instruments was rare, with 94.2% of assessed studies using ad hoc measures or not identifying an established …


Assessing Flaws In Captcha Security Through Progress In Ai, Jaydon Stanislowski 2026 University of Minnesota - Morris

Assessing Flaws In Captcha Security Through Progress In Ai, Jaydon Stanislowski

Scholarly Horizons: University of Minnesota, Morris Undergraduate Journal

Protecting the internet from the threat of malicious bot activity is an important problem as AI tools become more powerful and commonplace over time. To that end, security measures are employed across websites in the form of CAPTCHAs, short challenges designed to identify and block fake web traffic. Yet, they become less effective over time as AI becomes more powerful, and thus more capable of solving them. This paper examines recent research on the threat to CAPTCHA security posed by current AI models and how this security can be reinforced over time, focusing primarily on Google’s reCAPTCHA v3.


Zero Trust Architecture And Ransomware Mitigation, Ely Johnson 2026 University of Minnesota - Morris

Zero Trust Architecture And Ransomware Mitigation, Ely Johnson

Scholarly Horizons: University of Minnesota, Morris Undergraduate Journal

Ransomware has become a critical threat to modern enterprises, exploiting excessive privileges and flat network architectures to spread rapidly. Traditional perimeter-based security models are insufficient, as they rely on implicit trust within internal networks. This paper examines how Zero Trust Architecture (ZTA) mitigates ransomware through least privilege access, continuous monitoring, and micro- segmentation. Experimental results show that ZTA can significantly reduce impact, limiting encryption to about 20% of targeted files while preserving most data. Continuous monitoring enables rapid detection (5.3 seconds) with high accuracy (up to 97.2%) and a 78% reduction in false positives. Micro-segmentation further restricts lateral movement, reducing …


Security Limitations Of The Can Bus And Detection Through Power Fingerprinting, Ken Broden 2026 University of Minnesota - Morris

Security Limitations Of The Can Bus And Detection Through Power Fingerprinting, Ken Broden

Scholarly Horizons: University of Minnesota, Morris Undergraduate Journal

This paper examines the vulnerabilities of the Controller Area Network (CAN), the standard communication protocol used in most modern vehicles. It explains why CAN is widely adopted and outlines key security weaknesses in its design. The paper then reviews recent research efforts to detect and mitigate these vulnerabilities, with particular focus on an approach to origin authentication that relies on the unique power consumption patterns of each individual electronic control unit on a CAN bus.


Geospatial Governance Failures In The Department Of Defense: Contractor Noncompliance, Ai Adoption, And The Parallel Treatment Of Gis And Cybersecurity, Lyndsey Olmstead 2026 University of Denver

Geospatial Governance Failures In The Department Of Defense: Contractor Noncompliance, Ai Adoption, And The Parallel Treatment Of Gis And Cybersecurity, Lyndsey Olmstead

Geography and the Environment: Graduate Student Capstones

The Department of Defense's treatment of geographic information systems and cybersecurity as parallel rather than integrated policy domains produces geographically predictable vulnerability patterns across its global military installation footprint. This capstone investigates that conclusion through original spatial analysis, constructing a five-variable composite geospatial vulnerability index across the six U.S. Combatant Command regions using publicly available unclassified data. EUCOM ranked highest overall, driven by GPS/PNT spoofing density, commercial satellite coverage, and cyber incident frequency; CENTCOM ranked second, driven by OSINT exposure incidents and governance risk. The null hypothesis of random geographic distribution is rejected. Findings confirm the structural governance gap documented …


Residential Ai Data Centers: Security, Privacy, And Governance Concerns, Alan Saquella 2026 Embry-Riddle Aeronautical University

Residential Ai Data Centers: Security, Privacy, And Governance Concerns, Alan Saquella

Publications

The concept of placing mini data centers and distributed AI computer nodes inside residential homes may appear innovative from an energy efficiency perspective, but it introduces significant security, privacy, governance, and liability concerns. What is effectively occurring is the expansion of commercial and potentially critical infrastructure into lightly protected residential environments.

Once a residence becomes part of a distributed computer grid supporting hyper-scalers, AI providers, or enterprise workloads, the home is no longer simply a private residence. It becomes a commercial technology asset, a potential cyber target, and even a physical target. A distributed network of thousands of residential nodes …


A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath 2026 Dakota State University

A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath

Research & Publications

The Internet of Medical Things (IoMT) has transformed health care delivery through medical devices, remote patient monitoring, and real-time clinical decision support. However, the proliferation of IoMT devices introduces security vulnerabilities that put patient safety and data privacy at risk. Intrusion Detection Systems (IDS) have emerged as essential components for protecting IoMT networks from cyberattacks. This article presents a systematic review of IoMT-IDS research, analyzing 53 high-quality papers published between 2020 and 2025, identified through database searches spanning 2016–2025 across IEEE Xplore, Springer, ScienceDirect, and ACM Digital Library. We organize the literature through a comprehensive taxonomy spanning classical machine learning …


2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus 2026 ISTS

2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus

Computer Science Technical Reports

The ISTS and the Dartmouth College Cybersecurity Cluster hosted the successful, inaugural Cyber-Resilient Health Care (CRHC) Workshop, March 5th & 6th, 2026. The event theme was "Innovation and Implementation," in response to the need to shift from reactive to proactive resiliency measures in the healthcare sector. Approximately 30 experts in clinical health care, cybersecurity, medical technology, policy, and innovation met to discuss solution-focused innovations addressing hard, cyber-related problems in health care. The agenda featured keynotes, an expert panel, innovation pitches, small group discussions, and a tabletop infrastructure disaster exercise. Participants gained insights into the obstacles and solutions involved in supporting …


The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala 2026 CUNY John Jay College

The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala

Student Theses

The rapid adoption of Large Language Models (LLMs) in software development has transformed coding practices by enabling automated code generation, completion, and optimization. Despite these advantages, concerns persist regarding the security and reliability of LLM-generated code. This study presents a comprehensive evaluation of both the functional correctness and security of code produced by three prominent LLMs as of early 2026. A total of 4,800 code snippets were generated using 100 security-focused programming prompts derived from the OWASP Top 10:2025, translated across eight natural languages and two phrasing styles (literal and natural developer-oriented prompts). To assess performance, a multi-stage experimental framework …


Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy 2026 CUNY John Jay College

Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy

Student Theses

Social network platforms, child safety organizations, and image provenance systems use perceptual hashing to identify known child sexual abuse material (CSAM), support content moderation and reverse image search, and verify image integrity. Perceptual hashing works by producing similar fingerprints for visually similar images, even after common transformations such as compression, resizing, or minor brightness changes. This useful similarity-preserving property also creates an adversarial attack surface, as attackers can use AI-assisted or conventional image manipulation techniques to move a hash across a matching threshold while maintaining visual similarity, often without access to specialized hardware.

The security failures produced by adversarial attacks …


Anonymity And Accountability In Secure Messaging, Erin Kenney 2026 New Jersey Institute of Technology

Anonymity And Accountability In Secure Messaging, Erin Kenney

Dissertations

Encypted messaging has become more and more prevalent as time moves on, and its benefits in assuring privacy cannot be overstated, but it also brings along with it concerns on how to moderate platforms where all messages are hidden. Message Franking, followed by Traceback systems, addressed these concerns by allowing the sender of a message to be proven when reported, even for forwarded messages in the case of Traceback, however these systems damage the privacy guarantees that originally motivated encrypted messaging to begin with.

In practice, even without those concerns encrypted messaging alone is not enough to prevent the most …


Sound Detection Of Memory Leaks In Llvm Ir Programs Using Accumulation Analysis, Robert Blacha 2026 New Jersey Institute of Technology

Sound Detection Of Memory Leaks In Llvm Ir Programs Using Accumulation Analysis, Robert Blacha

Theses

Resource leaks occur when a limited resource such as memory is allocated by a program and needlessly held past the point of use. Leaks can lead to a degradation of services which can be specifically triggered with malicious behavior, for example abusing a memory leak in a program to cause a server to slow down and crash for a denial-of-service attack.

Prior work has demonstrated that accumulation analysis provides a sound detection of resource leaks with a working implementation for programs written in Java. While useful, current implementations are limited to programs written in Java, which has a garbage collector, …


Distributed File Carving, Brad J. Baudin 2026 Louisiana State University and Agricultural and Mechanical College

Distributed File Carving, Brad J. Baudin

LSU Master's Theses

File carving is a fundamental technique in the digital forensics community, enabling analysts to recover deleted files from disk images without relying on filesystem metadata; however, as storage capacities continue to increase, modern file carving tools face significant scalability challenges, with carving time growing substantially alongside disk image size, particularly in the presence of file fragmentation. Fragmentation, a common behavior in modern filesystems, distributes file data across non-contiguous disk blocks to maximize space utilization, and in large disk images this distribution can span wide logical distances, increasing the search space and reducing carving efficiency, causing traditional approaches to struggle within …


Meeting The Moment With Ai-Employer Informed Education, Brent Terwilliger, John Faraca 2026 Embry-Riddle Aeronautical University

Meeting The Moment With Ai-Employer Informed Education, Brent Terwilliger, John Faraca

Publications

As artificial intelligence transforms aviation, aerospace, and autonomy-related sectors, higher education must adapt to meet evolving workforce demands. This session shares emerging findings from a nationwide study led by Embry-Riddle Aeronautical University, focused on employer perceptions of AI adoption, responsible use, and workforce preparedness in domains including uncrewed systems, space systems, robotics, and advanced air mobility. Based on a structured survey and follow-up interviews, the presentation explores how organizations are using AI tools, from generative platforms to enterprise systems, and defining effective and inappropriate use in operational contexts. Participants will gain insight into critical concerns (e.g., data privacy, compliance, security, …


Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder 2026 Embry-Riddle Aeronautical University

Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder

Doctoral Dissertations and Master's Theses

Cybersecurity has become a global concern as cyber-attacks have become more common, and the cost of the damage caused by them continues to increase. There are several approaches to improve the cyber security of systems such as Digital Signatures, hashing, watermarking, and encryption among others. Digital Signatures are a cryptographic technique used to verify the authenticity and integrity of digital messages or documents. Digital Signatures use a combination of hashing and public-private key encryption to verify the authenticity and integrity of videos, just as they are used for documents and messages. As a result of using a combination of other …


Improving Fairness On Semantic Segmentation Using Large Language Models, Samuel E. Burggraf 2026 Old Dominion University

Improving Fairness On Semantic Segmentation Using Large Language Models, Samuel E. Burggraf

Electrical & Computer Engineering Projects for D. Eng. Degree

As machine learning systems are increasingly integrated into critical decision-making processes, ensuring fairness in their design and implementation has become a significant concern. While fairness research has primarily focused on specific protected attributes, less attention has been given to spatial fairness, which can affect individuals at specific locations. If fairness is not addressed, models may systematically underperform in certain regions or across populations which can lead to unequal access to accurate predictions and potentially biased decision-making. Fairness considerations should extend across all machine learning applications to align with the National Institute of Standards and Technology (NIST) guidelines of fair and …


Friend Or Foe? The Benefits And Risks Of Llms In Cybersecurity, Niklas P. Dobler 2026 University of Tennessee at Chattanooga

Friend Or Foe? The Benefits And Risks Of Llms In Cybersecurity, Niklas P. Dobler

Honors Theses

The rapid growth of Large Language Models (LLMs) and their continuous increase in capabilities have affected many professions and people. Due to advancements in areas such as coding and data analysis, they are now also being utilized in Cybersecurity. Recent research has examined their use in many different areas such vulnerability detection in code and analyzing network traffic. With this rapid growth, most organizations around the world are eager to advance faster than their competition, with limited considerations for the potential harm and risks these tools could bring. Some research has been conducted on malicious uses, but as the benefits …


Digital Commons powered by bepress