Post-Quantum Cryptography Encryption Implementation For Messaging App,
2026
University of Nebraska at Omaha
Post-Quantum Cryptography Encryption Implementation For Messaging App, Callum S. Ward
Theses/Capstones/Creative Projects
This paper and complementary capstone project aim to explore the state of post-quantum cryptography today by defining the algorithms with which quantum computers can decipher modern asymmetric cryptographic algorithms in exponentially accelerated time, exploring national standards body NIST’s recommendations to circumvent these weaknesses with post-quantum solutions, and implementing recommended algorithms in my group’s project for the UNO Computer Science Capstone course, LockTalk. After having decided on ML-KEM for quantum-resistant asymmetric key transfer and AES-256 for symmetric message encryption and decryption, I was able to cryptographically encode messages to obscure their plaintext values from communication interceptions without any discernible increase in …
Blockchain Message Integrity For Messaging App: Python-Based Implementation Of Blockchain-Backed Verification And Tamper Detection,
2026
University of Nebraska at Omaha
Blockchain Message Integrity For Messaging App: Python-Based Implementation Of Blockchain-Backed Verification And Tamper Detection, Brendan J. Farrell
Theses/Capstones/Creative Projects
With the rapid development and use of digital communication, the need for maintaining the integrity and authenticity of transmitted information becomes more pressing than ever. However, existing methods of data exchange have several flaws and drawbacks such as reliance on centralized networks which are subject to manipulation, modifications, and potential failures. Thus, the current project offers an innovative approach to improving the integrity and detection capabilities of messages in real-time communication platforms using the power of blockchain technology. The proposed solution uses the inherent features of blockchain-based systems to ensure secure and safe message transmission.
Message Malware: File Vulnerability Scanning In Messaging Apps,
2026
University of Nebraska at Omaha
Message Malware: File Vulnerability Scanning In Messaging Apps, Miah Mason
Theses/Capstones/Creative Projects
As messaging platforms become primary communication hubs within highly secure environments, they introduce significant vulnerabilities regarding file sharing with potential malicious content. This research, an honors extension of the Northrop Grumman sponsored Capstone project ‘LockTalk’, evaluates the technical abilities of automated file scanning methods within messaging platforms like Slack, Microsoft Teams, or our own developed platform LockTalk. This paper investigates a variety of scanning methods and their applications, with particular emphasis on comparing the qualities of static scanning, used in signature-based detection, and dynamic scanning with heuristics. Furthermore, this paper investigates the differences and advantages of both End-to-End Encryption (E2EE), …
Using Ai For Data Loss Prevention,
2026
University of Nebraska at Omaha
Using Ai For Data Loss Prevention, Camden A. Wright
Theses/Capstones/Creative Projects
Data Loss Prevention (DLP) systems play a critical role in protecting modern systems that handle sensitive information from both accidental and malicious exposure. Traditional DLP approaches often rely on static rules and methods that can struggle to adapt to complex and evolving data patterns. This paper presents a hybrid DPL system that integrates machine learning-based message classification, rule based policy enforcement, and context-aware access control to improve both detection accuracy and decision reliability. In addition, the system introduces a second stage access control model that evaluates user context, including role of clearance level and job title to determine whether access …
The Privacy Paradox: How Does Concern About Privacy Impact Actions In The Digital Age?,
2026
University of Tennessee at Chattanooga
The Privacy Paradox: How Does Concern About Privacy Impact Actions In The Digital Age?, Julia Laduke
Honors Theses
The privacy paradox occurs when people claim to care about their digital privacy, but do not take actions to keep their data from being spread across the internet. This study examines college students, being primarily Generation Z, and their concerns and actions regarding digital privacy and security. A survey of 15 college students, 7 in humanities and 8 in STEM, was used to analyze their thoughts and concerns about their digital privacy. This survey also asked whether they took actions concerning their privacy, and if so, what tools they used to protect it. The results show that about 50% of …
F.L.A.I.R. -- A Flow-Level Autoencoder For Intrusion Recognition,
2026
University of Arkansas, Fayetteville
F.L.A.I.R. -- A Flow-Level Autoencoder For Intrusion Recognition, Joseph P. Dumond
Electrical Engineering and Computer Science Undergraduate Honors Theses
Industrial Internet of Things (IIoT) networks underpin critical infrastructure worldwide, yet securing them remains an open challenge. Traditional intrusion detection systems require labeled attack data for training, a resource that is rarely available in real industrial deployments. They also fail against novel threats, a model trained on known attacks has no basis for detecting anything outside its training set. This thesis presents a Flow-Level Autoencoder for Intrusion Recognition, or FLAIR, a fully unsupervised deep learning system for network intrusion detection in IIoT environments. FLAIR is built on a Gated Recurrent Unit (GRU) autoencoder trained exclusively on normal network traffic. Rather …
A Case Study On Using Large Language Models To Drive Convergence-Oriented Literature Discovery In Critical Infrastructure Security,
2026
University of Arkansas, Fayetteville
A Case Study On Using Large Language Models To Drive Convergence-Oriented Literature Discovery In Critical Infrastructure Security, Caden J. Williamson
Electrical Engineering and Computer Science Undergraduate Honors Theses
In the world of cybersecurity, the rapid development of artificial intelligence proposes a constant challenge for researchers to defend critical infrastructure. Attacks on critical infrastructure can be catastrophic, and emerging strategies of cyber-adversaries that implement leading AI models can expose vulnerabilities in critical infrastructure much faster than previous tools. To defend against this emerging threat, the Cybersecurity Research Working Group at the University of Arkansas is aiming to develop a cross-domain and cross-discipline center of excellence. To support this effort, the group is writing a literature review on the topics of AI and critical systems security. Literature review is an …
Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation,
2026
Liberty University
Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation, Caleb J. Chen
Senior Honors Theses
Command and Control (C2) is a critical part of any cyberattack. It serves many purposes, including Distributed Denial of Service (DDoS) attacks, data exfiltration, and malware deployment. Consequently, C2 frameworks play an important part in red team engagements and adversary emulation. However, many adversary emulation solutions focus on comprehensive testing through sequential technique execution instead of realistic chained and automated attacks. The proposed solution is Centurion, an open-source C2 framework that integrates MITRE's ATT&CK framework and several cybersecurity tools into modular playbooks for effective threat emulation. This paper provides background by defining key terms and concepts before delving into a …
Weavecc: Symbolically-Guided Joint Exploration Of Inputs And Schedules For Concurrency Bug Detection,
2026
Dartmouth College
Weavecc: Symbolically-Guided Joint Exploration Of Inputs And Schedules For Concurrency Bug Detection, William Philip Dinauer
Dartmouth College Master’s Theses
Concurrent programs introduce a class of bugs that depend jointly on both program inputs and thread schedules. Exposing these bugs requires simultaneously reasoning about which code paths are reachable and which thread interleavings are possible. At the same time, many existing tools handle the problem insufficiently. Race detectors observe only the interleavings that the OS happens to produce. Fuzzers explore inputs without controlling schedules. Tools that address both dimensions together exist, but are built on interpretation-based symbolic executors that incur considerable overhead.
We present WeaveCC, a practical concurrency testing tool for C/C++ programs that jointly explores inputs and thread schedules. …
Using Siamese Neural Networks To Effectively Detect Trojans In Fpgas When Trojans Manipulate Encryption Operations At The Bitstream Level,
2026
University of South Alabama
Using Siamese Neural Networks To Effectively Detect Trojans In Fpgas When Trojans Manipulate Encryption Operations At The Bitstream Level, Kylie Arnett
Graduate Theses and Dissertations (2019 - present)
This research investigates security vulnerabilities in Field-Programmable Gate Arrays (FPGAs) at the bitstream level, focusing on hardware trojans (HTs) that manipulate encryption operations. This study addresses two critical questions: (1) The feasibility of exploiting FPGA bitstreams to selectively bypass encryption operations when a predefined input pattern is observed (all ones), thereby exposing sensitive data, and (2) the efficacy of Siamese Neural Networks (SNNs) in detecting such trojans with high accuracy. FPGAs are vulnerable to malicious modifications during manufacturing or deployment, posing risks to data integrity and system functionality. In this work, a trojan is inserted into a Xilinx series-7 FPGA …
Polyglot File Detection For Forensic Investigations,
2026
University of South Alabama
Polyglot File Detection For Forensic Investigations, Chase Stevens
Graduate Theses and Dissertations (2019 - present)
As technology has become far more ubiquitous over the years, so too has the amount of digital evidence that can and needs to be collected and processed. Forensic tools are developed in response to the growing need, but are limited to what they are programmed to do. One such forensic tool is Autopsy, one of the most widely used open-source tools. Autopsy uses known file-type signatures (e.g., headers, trailers) to identify and recover files from forensic images. Polyglot files introduce a unique problem to both these forensic tools and investigators alike. In the context of the research conducted, polyglot files …
Detecting Sophisticated Cyberattacks On Public Water Infrastructure,
2026
University of South Alabama
Detecting Sophisticated Cyberattacks On Public Water Infrastructure, Ayrton Purdy
Graduate Theses and Dissertations (2019 - present)
In recent years there has been an increasing number of cyberattacks on public water generation and distribution systems. Advanced persistent attackers could usurp sensors and control systems to contaminate public drinking water. In order to conceal their malicious activity, they can manipulate sensor data flows to give the appearance of normal activity. The compromised sensors would report normal chemical levels even though unsafe water is entering the distribution system. In response, this research proposes a multi-sensor, cross-comparison approach to anomaly detection. The proposed approach is designed to detect sophisticated cyberattacks which are not easily detectable using traditional cyber tools. The …
Developing A Framework For Microchip Design Recovery,
2026
University of South Alabama
Developing A Framework For Microchip Design Recovery, Eric Diep
Graduate Theses and Dissertations (2019 - present)
Due to the increase in diverse chip production over the past decade, reverse engineering has become a difficult and daunting task. This research develops a methodology for microchip design recovery, seeking to validate and reproduce prior approaches to physical reverse engineering using low-cost tools and techniques. We used mechanical hardware abrasion tools and techniques to delayer and capture silicon integrated chip (IC) layout. We focused on the Mifare Classic EVl microchip, commonly implemented in public transit/transportation cards, to extract information for design recovery. The research explores limitations and advantages of mechanical abrasion and optical microscopy in context to modem chip …
Enhancing Control Charting Schemes And Exploring New Assessment Metrics To Advance Quality Control And Cyber-Attack Detection In Manufacturing,
2026
Western Michigan University
Enhancing Control Charting Schemes And Exploring New Assessment Metrics To Advance Quality Control And Cyber-Attack Detection In Manufacturing, Ahmad Al Majali
Dissertations
The increasing integration of digital technologies and industrial control systems in modern manufacturing has introduced new cybersecurity vulnerabilities within cyber–physical production environments. Malicious actors can exploit these vulnerabilities to induce subtle process deviations that degrade product quality while remaining undetected by conventional statistical monitoring tools. Such attacks can be deliberately engineered to manipulate process behavior through transient shifts that vary in magnitude, duration, and frequency. Despite extensive research on transient shifts caused by assignable causes in Statistical Process Control (SPC), limited attention has been given to intelligently designed cyber–physical attacks that exploit the structural characteristics and limitations of control charting …
Automated, Modular, Agentless Adversarial Emulation In Cloud Environments For Higher Education And Student Training,
2026
Liberty University
Automated, Modular, Agentless Adversarial Emulation In Cloud Environments For Higher Education And Student Training, Doc Harley
Senior Honors Theses
Currently, the leading technologies in the market of adversarial emulation are MITRE Caldera, Atomic Red Team by IBM, and multiple proprietary products that come with support packages for different vendors like AttackIQ, Cymulate, SafeBreach, and many more. While it is clear that much work has been done in the broad category of adversarial emulation, when it comes to open source solutions, there are no agentless options with built in automation and modularity that have good support for cloud environments. Agentless adversarial emulation provides a unique advantage in that it can be both simpler and a better representation of the true …
Phishing Restraint: University Simulated Phishing Campaigns,
2026
Old Dominion University
Phishing Restraint: University Simulated Phishing Campaigns, Alexander M. Abou Khir
Cybersecurity Undergraduate Research Showcase
Universities face heightened vulnerability to phishing attacks due to their open information-sharing culture and diverse user populations. This study examines how phishing exploits human factors within campus environments and evaluates three major training strategies: embedded phishing, microlearning, and role-based instruction to understand their individual and combined effectiveness. I explored studies that implement these strategies in pairs and use the strategies alone, identified trends in susceptibility reduction, behavioral reinforcement, and contextual relevance. I suggest that, while each method independently improves user awareness, multiple approaches offer stronger, more adaptable protection by addressing both psychological triggers and role-specific risks. The paper contributes a …
Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models,
2026
Christopher Newport University
Hijacking The Prompt: A Survey Of Prompt Injection Attacks, Detection, And Defense In Large Language Models, Edward J. Griggs
Cybersecurity Undergraduate Research Showcase
Prompt injection attacks, ranked the number-one vulnerability in AI systems by OWASP's 2025 Top 10 for Large Language Model Applications, remain largely unsolved, and this survey examines why. As large language models (LLMs) are deployed across enterprise workflows, agentic systems, and consumer tools, their fundamental inability to distinguish trusted instructions from untrusted user data has created a persistent and expanding attack surface. This paper presents a structured taxonomy of prompt injection attack vectors, including direct injection, indirect injection, multimodal attacks, tool and agent exploitation, hybrid chained techniques, and autonomous propagating threats. These vectors are mapped across five impact categories (data …
The Texture Of A Threat: Adversarial Training, Cnns, And Obfuscated Malware Detection,
2026
Liberty University
The Texture Of A Threat: Adversarial Training, Cnns, And Obfuscated Malware Detection, Kaelyn Haynie
Senior Honors Theses
Accurately detecting malicious programs is an expanding field of research for machine learning (ML), with a novel approach incorporating a bytecode-to-image pipeline that produces images representative of software. These images are provided to convolutional neural networks (CNNs) to be examined for malicious pattern indicators. However, CNNs struggle to generalize these patterns effectively while still being robust against adversarial data, an issue which this research addresses with adversarial training. In this paper, three unique CNN architectures (a DBFS-MC-inspired baseline, MIRACLE, and PSP-CNN) are trained for binary classification with 15,000 benign and malicious software samples encoded into images for Android, Windows, and …
Leveraging Convolutional Neural Networks For Through-The-Wall Radar Imaging: Challenges, Impacts, And Future Directions,
2026
Department of Computer Science, Ruaha Catholic University, Tanzania
Leveraging Convolutional Neural Networks For Through-The-Wall Radar Imaging: Challenges, Impacts, And Future Directions, Tumaini Edgar, Abdulla F. Ally, Abdi T. Abdalla
Tanzania Journal of Engineering and Technology (TJET)
Through-the-wall radar imaging (TWRI) is an essential technology for military and rescue applications; however, its performance in detecting and visualizing high-quality images of targets behind walls is significantly degraded by multipath reflections and signal attenuation. This paper reviews the current state of TWRI and its challenges, and explores the transformative potential of deep learning, particularly convolutional neural networks (CNNs), in addressing these challenges. Peer-reviewed articles published from 2018 to 2024 were analysed to examine CNN applications in addressing TWRI challenges. The analysis reveals that using CNNs, TWRI systems can be more effective by filtering wall distortions, reducing noise, lowering computational …
Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions,
2026
Christopher Newport University
Limitations Of Signature-Based Network Intrusion Detection Under Modern Traffic Conditions, Henry Guidry
Cybersecurity Undergraduate Research Showcase
Network Intrusion Detection Systems are tools used to monitor network traffic and alert to suspicious or harmful activity before it can cause harm. Signature-based versions of these systems are a foundation for intrusion detection, operating by finding common patterns and forming malicious signatures. However, three developments in modern network environments have greatly impacted the significance of Network Intrusion Detection Systems. These three developments are the near-complete adoption of end-to-end encryption, the use of sophisticated packet fragmentation techniques, and the processing demands of high-throughput networks. Encryption makes deep packet inspection practically infeasible by transforming inspectable payloads into ciphertext, forcing NIDS to …
