Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

454 Full-Text Articles 779 Authors 151,534 Downloads 99 Institutions

All Articles in Cybersecurity

Faceted Search

454 full-text articles. Page 5 of 23.

Ransomware As Organization: A Comparative Analysis Of Corporate And Criminal Structures In Conti, George Urling 2026 Marshall University

Ransomware As Organization: A Comparative Analysis Of Corporate And Criminal Structures In Conti, George Urling

Theses, Dissertations and Capstones

Cybercriminal groups continue to pose major threats to global cybersecurity. One of the most common types of cybercriminal groups are, “Ransomware-as-a-Service (RaaS)" groups, who create and sell ransomware. While research is conducted into the development of ransomware, there is limited reporting on the organizational structure and habits of RaaS groups. In 2022, prominent RaaS group Conti had their chat logs leaked, with the logs ranging from 2020 to 2022. This study seeks to provide a deeper understanding of RaaS group structures by utilizing the Conti leaked logs as a case study. The study, entitled “Ransomware as Organization: A Comparative Analysis …


Systematic Approaches To Characterizing Vulnerabilities And Enhancing Robustness Of Text And Vision-Language Models, Poojitha Thota 2026 University of Texas at Arlington

Systematic Approaches To Characterizing Vulnerabilities And Enhancing Robustness Of Text And Vision-Language Models, Poojitha Thota

Computer Science and Engineering Dissertations

The proliferation of artificial intelligence (AI) across critical domains, including news summarization, privacy-policy analysis, and medical decision support, has raised growing concerns about the security and robustness of these systems against adversarial manipulation. This dissertation investigates adversarial robustness in generative AI by addressing three key research goals: (1) characterizing adversarial vulnerabilities across generative models, (2) developing systematic defenses to improve the robustness of generative models, and (3) designing deployment-time safeguards for securing LLM interactions.

Towards the first goal, we characterize adversarial vulnerabilities across text-based and multimodal systems. In abstractive text summarization, we show that inference-time perturbations can exploit lead bias …


Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty 2026 Old Dominion University

Cybersecurity Center For Offshore Wind Energy (Final Project Round), Sachin Shetty

Center for Secure and Intelligent Critical Systems (CSICS) Publications

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models …


Evaluating Llms For Cpe Identification In Iot Reconnaissance, Christopher Davisson 2026 Eastern Washington University

Evaluating Llms For Cpe Identification In Iot Reconnaissance, Christopher Davisson

EWU Masters Thesis Collection

Vulnerability identification during penetration testing relies on rigid string-matching to map network scan data to Common Platform Enumeration (CPE) identifiers and downstream Common Vulnerabilities and Exposures (CVEs). The approach frequently fails on physical Internet of Things (IoT) devices, which produce non-standard, irregular service banners that resist deterministic parsing. Large Language Models can reason through these fuzzy associations, but cloud-hosted models introduce cost, latency, and operational security concerns when processing reconnaissance data from live networks. This thesis asks whether locally-hosted open-weight Large Language Models (LLMs) can perform this task well enough to be useful, and how performance varies with model scale, …


Data Defines Success: Algorithm For Dataset Quality Assessment In Deep Learning For Malware Detection, Matei Ionescu 2026 Illinois State University

Data Defines Success: Algorithm For Dataset Quality Assessment In Deep Learning For Malware Detection, Matei Ionescu

Theses and Dissertations

The field of artificial intelligence is based upon the premise of constructing architectures through which to propagate training data. However, the majority of existing research literature is focused on architecture. While necessary, the attention devoted to the architecture should not so precipitously exceed that of the data. It should be noted that this disparity is not without reasonable cause. Data quality is often exceedingly difficult to verify due to particularities of the field or subfield; LLM repositories of text are distinct from image recognition pictures of dog breeds which are distinct from EEG waveforms of human brains which are distinct …


Understanding Phishing Susceptibility Through Expert Consensus Using Digital Marketing Parallels And A Machine Learning-Based Implementation, Mansoor Ahmad 2026 Minnesota State University, Mankato

Understanding Phishing Susceptibility Through Expert Consensus Using Digital Marketing Parallels And A Machine Learning-Based Implementation, Mansoor Ahmad

All Graduate Theses, Dissertations, and Other Capstone Projects

Phishing remains one of the most effective attack vectors for gaining unauthorized access to organizational systems, yet defenders often lack systematic methods to assess their exposure before an attack. This study develops a framework that uses machine learning to encode the collective expertise of cybersecurity practitioners into a portable phishing susceptibility assessment tool, with the goal to help security teams proactively identify patterns, prioritize awareness training, and strengthen detection controls. The study surveyed 27 practitioners with extensive experience in social engineering, red teaming, penetration testing, and threat analysis to identify which factors most influence phishing susceptibility. Practitioners provided quantitative ratings …


Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach, Md Al Amin, Mohammad Shafat Ahsan, Jannatul Maua, Arifa Akter Eva, M.F. Mridha, Md. Jakir Hossen 2026 St. Francis College

Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach, Md Al Amin, Mohammad Shafat Ahsan, Jannatul Maua, Arifa Akter Eva, M.F. Mridha, Md. Jakir Hossen

Student Publications [Scholarly]

Modern intelligent transportation systems (ITS) increasingly rely on connected electronic control units (ECUs), exposing in-vehicle networks to cyber-attacks such as message injection on the Controller Area Network (CAN) bus. While prior work has focused on post-factum detection, this paper addresses the underexplored task of forecasting cyber-attacks before they occur. We propose a spatio-temporal graph neural network (STGNN) architecture that models CAN traffic as a dynamic graph sequence, where nodes represent active CAN IDs and edges capture statistical co-activation patterns. Each graph snapshot encodes temporal features such as inter-arrival statistics and entropy, and is processed using graph attention layers followed by …


Ai-Driven Real-Time Detection Of Zero-Day Browser Exploits Using Webassembly-Based Instrumentation, Temitope Damilola Elijah 2026 Georgia Southern University

Ai-Driven Real-Time Detection Of Zero-Day Browser Exploits Using Webassembly-Based Instrumentation, Temitope Damilola Elijah

College of Graduate Studies: Theses & Dissertations

The rapid evolution of web browsers into fully fledged application execution environments has significantly expanded their attack surface, making them prime targets for sophisticated zero-day exploits that evade traditional signature-based security mechanisms. To address this challenge, this research proposes an AI-driven framework for real-time detection and analysis of zero-day exploits in web browsers by integrating browser-level telemetry monitoring, unsupervised anomaly detection, and large language model–based threat interpretation. The framework introduces a lightweight WebAssembly telemetry agent embedded within the browser runtime to capture low-level execution behaviors, including WASM module instantiation, memory growth patterns, network interactions, and runtime API activity. These telemetry …


Rockyou2024: What’S Your Password?, Yixuan Zhang 2026 University of Richmond

Rockyou2024: What’S Your Password?, Yixuan Zhang

Honors Theses

Passwords remain a critical part of almost every account security system. As a result, password guessing attacks remain one of the most widespread yet profitable attacks possible. Setting a password resistant to attacks is thus an important task for account holders. In this paper, we use the RockYou2024 database, a collection of approximately 10 billion real-world passwords collected from data breaches, to analyze the characteristics of passwords found in real life. We start with basic statistical property analysis, such as length, distribution of digits and symbols, and proceed onto more complicated properties such as frequencies of combinations of characters, entropy …


Characterizing Cyber Intrusions In Critical Infrastructure Networks Using Discrete-Event Simulation, Lawrence M. Dilworth 2026 Michigan Technological University

Characterizing Cyber Intrusions In Critical Infrastructure Networks Using Discrete-Event Simulation, Lawrence M. Dilworth

Dissertations, Master's Theses and Master's Reports

Over the past two decades, cybersecurity compliance frameworks such as the North American Electric Reliability Corporation Critical Infrastructure Protection (CIP) have introduced prescriptive measures for protecting power system networks, emphasizing restricted access, segmentation, and minimizing routable exposure. While effective for baseline cyber hygiene, these approaches do not capture system-level risks or adversarial propagation across interconnected infrastructure. In contrast, Cyber-Informed Engineering (CIE), advanced by Idaho National Laboratory, embeds security in system design by considering threat vectors and physical constraints.

Despite CIP guidance, many deployments rely on IP-routable, bidirectional communication that enables handshaking, allowing adversaries to infer reachable targets. This work presents …


Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim 2026 Bangladesh University of Business and Technology

Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim

School of Cybersecurity Faculty Publications

Phishing involves manipulating individuals into revealing private data, e.g., user IDs, bank details, and passwords. The observed surge in fraud is related to increased deception, impersonation, and advanced online attacks. Thus, effective phishing detection methods are required to mitigate escalating global phishing threats. Existing methods (e.g., heuristics-based, signature-based, and visual similarity-based methods) attempt to detect phishing sites, and machine learning (ML) and deep learning (DL) methods are effective in the cybersecurity context in terms of learning from data, offering insights, and forecasting. However, independent ML algorithms are limited when handling complex data, and DL techniques surpass traditional ML methods in …


Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis, Olusesi Balogun, Mohammad GhasemiGol, Zhipeng Cai, Daniel Takabi 2026 Georgia State University

Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis, Olusesi Balogun, Mohammad Ghasemigol, Zhipeng Cai, Daniel Takabi

School of Cybersecurity Faculty Publications

Attribute-Based Access Control (ABAC) frameworks coordinate access requests based on subject, object, and environment attributes, as well as policy rules, and are widely used in corporate security systems. Recently, machine learning has been applied to ABAC to address policy-generation imbalances, misassigned privileges, and attribute leakages. However, existing MLBAC techniques do not consider the structural constraints and attribute interdependencies present in traditional ABAC systems. Moreover, these frameworks have not been extensively evaluated under black-box attack scenarios. To address these gaps, we propose extensions to MLBAC that integrate structural constraints, attribute dynamism, and attribute weighting into the MLBAC objective function. Additionally, we …


The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li 2026 Zhejiang University

The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li

Computer Science Faculty Publications

Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …


Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol 2026 Biosview Labs

Biosecure-Llm Framework: Protecting Llms From Cyberbiosecurity Threats And The Case For Independent Ai Safety Governance, Xavier-Lewis Palmer, Lucas Potter, Srdjan Lesaja, Sotirios Karathanasis, Mohammad Ghasemigol

Computer Science Faculty Publications

Large Language Models (LLMs) are becoming critical infrastructure in scientific, healthcare, and governmental contexts. As frontier AI laboratories increasingly partner with government agencies, a fundamental question arises: Who should control the safety and policy-enforcement layers that constrain model behavior? Current safety mechanisms (LLM guardrails) are typically designed for generic "harmlessness" and operate by detecting semantic patterns and refusing requests. However, they are inadequate governance instruments because they cannot implement auditable, domain-specific controls tied to external regulatory policy objects (e.g., control lists or rules governing personally identifying information). Even a perfectly aligned model is not able to express institution-specific policy without …


An Explainable Cs-Mitigation Triangular (Ecsmt) Framework To Secure Graph Neural Networks, Sabah Ettahri, Sergio Pallas Enguita, Chung-Hao Chen, Wen-Chao Yang 2026 Old Dominion University

An Explainable Cs-Mitigation Triangular (Ecsmt) Framework To Secure Graph Neural Networks, Sabah Ettahri, Sergio Pallas Enguita, Chung-Hao Chen, Wen-Chao Yang

Electrical & Computer Engineering Faculty Publications

This research addresses cyber risk by defending against backdoor attacks on Graph Neural Networks (GNNs). We propose the Explainable Complex System-Mitigation Triangular (ECSMT) Framework, which integrates Robust Training, Graph Regularization, and Data Sanitization into a lightweight, hardware-efficient defense layer. To evaluate structural generalizability, we conducted empirical evaluations across three distinct benchmark domains (AIDS, MUTAG, and PROTEINS) using a Graph Isomorphism Network (GIN) backbone. Under a baseline 5% backdoor subgraph trigger injection ratio, ECSMT achieves excellent utility retention, securing a Clean Accuracy (CA) of 97.33% (±0.62%) while reducing the Attack Success Rate (ASR) from 97.00% down to 69.45% on the primary …


Towards Breach Hypothesis Based Predictive Autonomous Cyber Defense Ecosystem: Proactive Prevention Of Imminent Threats And Productivity Losses, Yogesh Chavarkar 2026 Eastern Michigan University

Towards Breach Hypothesis Based Predictive Autonomous Cyber Defense Ecosystem: Proactive Prevention Of Imminent Threats And Productivity Losses, Yogesh Chavarkar

Master's Theses and Doctoral Dissertations

As cyberattack tools and techniques get sophisticated and persistent, reactive cybersecurity has been unable to effectively prevent breaches and compromises. Organizations and institutions with large complex environments have wide vulnerable exposure with higher chances of a cyberattack. This also increases overall security and financial risk. Possibility of repetitive attacks from cyber threats increases, too, despite the use of standard defense measures. Security tools and system vulnerabilities often need manual patching and updates to keep the environment secure and functioning effectively. Productivity suffers from manual trade-offs in keeping the systems secure from adverse impact. Persistent high-severity cyberattacks, despite continued reactive defensive …


Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias 2026 North Carolina A&T State University

Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias

Electrical & Computer Engineering Faculty Publications

This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.

The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …


Defending A Soho Network Against Mitm Attacks, Braeden J. Wise 2026 University of Akron

Defending A Soho Network Against Mitm Attacks, Braeden J. Wise

Williams Honors College, Honors Research Projects

Cybersecurity is a vast domain that consists of many threats that target sensitive information found on wired and wireless networks. One of those threats is a man-in-the-middle (MITM) attack, which involves an attacker situating themselves between a sender and a receiver to intercept or redirect network traffic. These kinds of attacks can run rampant on a small office home office (SOHO) network due to the vulnerabilities and lack of enterprise level tools. The intent of this project is to perform and defend against MITM attacks for a SOHO network. In the context of the project, three MITM attacks will be …


Analyzing Network Traffic And Data Exfiltration Via Smb In Post-Vm Escape Scenarios, Noah M. DiSanza 2026 The University of Akron

Analyzing Network Traffic And Data Exfiltration Via Smb In Post-Vm Escape Scenarios, Noah M. Disanza

Williams Honors College, Honors Research Projects

Virtual machines (VMs) play a crucial role in modern IT infrastructure environments by providing isolation and enhanced security, among other things, for both personal and corporate systems. VMs are heavily rely upon to safely test malware, manage infrastructure, and reduce risk to host systems. This reliance is so substantial that the idea of reducing risk to the host system is believed to be erasing risk entirely. However, this mindset has shown to be challenged time and time again by the emergence of exploits known as virtual machine escapes. These exploits allow malicious actors to break out of the virtualized environment …


Secure The Database: A Red Team, Blue Team Analysis Of Sql Injection, Andrew N. Miller 2026 The University of Akron

Secure The Database: A Red Team, Blue Team Analysis Of Sql Injection, Andrew N. Miller

Williams Honors College, Honors Research Projects

SQL injection (SQLi) attacks are a type of cyberattack that seeks to bypass website logins and gain entry to sensitive information. These pose a significant danger to organizations holding confidential user information. Personally Identifiable Information (PII) like physical addresses, emails, phone numbers, social security numbers are at risk of theft. Login credentials like usernames, passwords, and other sensitive information like financial details and social security numbers are also exposed through SQLi attacks. SQLi attacks harm the confidentiality, integrity, and availability of people’s identity. Additionally, data breaches that reach public battention harm the reputation and trust of organizations. SQLi attacks rank …


Digital Commons powered by bepress