Advancing Cybersecurity Through Userland Memory Forensics: From Runtime Analysis To Security Applications,
2026
Virginia Commonwealth University
Advancing Cybersecurity Through Userland Memory Forensics: From Runtime Analysis To Security Applications, Hala Ali
Theses and Dissertations
Memory forensics has become a crucial component of digital investigations, particularly for detecting malware operating solely in system memory. As operating system vendors implemented kernel access restrictions, malware authors shifted to userland malware. However, existing memory forensics techniques have largely focused on kernel-level analysis, leaving userland runtimes insufficiently covered. This dissertation addresses this gap by expanding memory analysis capabilities across two distinct paradigms: interpreted and compiled runtimes. The first phase targets the Python runtime, developing automated recovery techniques that enable several security applications. For malware detection, these techniques extract critical forensic artifacts such as encryption keys and command-and-control configurations. For …
Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems,
2026
Virginia Commonwealth University
Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems, Gustaf Barkstrom
Theses and Dissertations
Businesses lose millions of dollars every year when they can’t restore data from backups. Research shows that Disaster Recovery Plan (DRP) testing is not conducted frequently enough, nor are records maintained that demonstrate full data recovery from backups. This work introduces a design science artifact called PRTOK that aims to increase DRP testing. The design science artifact is a software solution that integrates with Data Management Systems (DMS)
such as iRODS and DSpace, and can work with formats such as HDF5 and BagIt. Proof-of- recovery records, or tokens, are recorded in a replicated, resilient, and indelible proof-of- authority blockchain data …
When Helpfulness Becomes Harmful: Jailbreaking Llms For Malicious Code Generation,
2026
University at Albany, State University of New York
When Helpfulness Becomes Harmful: Jailbreaking Llms For Malicious Code Generation, Noelle Capodieci
Electronic Theses & Dissertations (2024 - present)
Generative AI (GenAI) and Large Language Models (LLMs) have made large strides in coding task capabilities, with many software developers integrating agentic engineering into their workflow. While GenAI has largely benefited professional software engineers who can automate their work, it has also created room for those with little coding expertise to also create fully fledged programs and applications. It is commonly noted that GenAI is trained with two major goals in mind: to be as helpful as possible, and be as harmless as possible. There exist moments where helpfulness may be prioritized over harmlessness when these goals conflict. LLMs may …
A Knowledge-Driven, Ai-Assisted Cyber Defence Framework For Iomt Remote Patient Monitoring,
2026
Edith Cowan University
A Knowledge-Driven, Ai-Assisted Cyber Defence Framework For Iomt Remote Patient Monitoring, Kulsoom S. Bughio, David M. Cook, Abdul M. Unar
Research outputs 2022 to 2026
The rapid adoption of Internet Medical Things (IoMT) technologies in remote patient monitoring has reshaped healthcare delivery by enabling continuous, real-time clinical observation outside traditional care settings. However, this shift has also expanded the cyber-attack surface across heterogeneous, resource-constrained medical devices, wireless networks, cloud services, and third-party platforms. In cyber warfare, healthcare has become an incorporated target of geopolitics, with hospitals, remote monitoring systems, and emergency health systems being used to broaden the attack surface for adversaries to exploit. Existing security approaches for IoMT environments remain largely manual, fragmented, and reactive, limiting their effectiveness in dynamically assessing vulnerabilities and supporting …
Ordered Mini-Batch Training For Differentially Private And Encrypted Logistic Regression,
2026
Montclair State University
Ordered Mini-Batch Training For Differentially Private And Encrypted Logistic Regression, Ryan Leone
Theses, Dissertations and Culminating Projects
Logistic regression has found extensive use as a supervised machine learning algorithm due to its simplicity and efficiency in binary and multivariate classification tasks. As data sharing grows across connected devices, safeguarding sensitive personal and industrial information is of increased importance. Privacy-preserving machine learning techniques such as differential privacy and homomorphic encryption offer mathematically rigorous security guarantees, but introduce difficult accuracy, privacy loss, and computational overhead issues. This thesis investigates PPML for logistic regression through a collaborative mini-batch training framework. I propose and implement an ordered mini-batch strategy, compare it to standard shuffled methods, then integrate differential privacy noise injection …
Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures,
2026
Old Dominion University
Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han
Accounting Faculty Publications
This study examines whether firms strategically adjust the readability of Item 1A (“Risk Factors”) disclosures following data breaches. Using U.S. firm-year observations from 2006 to 2023, we find that data breaches are associated with a significant decline in Item 1A readability. This decline is not accompanied by a meaningful increase in informational content; instead, post-breach disclosures exhibit higher syntactic complexity, more positive tone, and lower textual similarity to prior and industry peers' filings, consistent with strategic obfuscation rather than transparent reporting. The readability decline is amplified among firms facing higher litigation risk but attenuated among firms with stronger reputations for …
Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac,
2026
University of North Florida
Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac, Hafizullah Kakar
UNF Graduate Theses and Dissertations
The Narrowband Internet of Things (NB-IoT) continues to expand but faces challenges such as cryptographic overhead and energy consumption. Security frameworks such as blockchain and Energy-Performance Cumulative Message Authentication Codes (EP-CuMAC) rely heavily on SHA-256, which is not optimized for energy-limited devices.
This work unifies two complementary approaches, a hybrid blockchain-based NB-IoT framework and an EP-CuMAC-based framework, by engineering their cryptographic core with an Energy Complexity Model-optimized SHA-256 (ECM-SHA256). ECM applies parallel memory-bank mapping and block-level access optimization to reduce redundant power usage while preserving algorithmic integrity.
Experimental evaluation on identical Intel DDR3 systems using pyRAPL shows energy savings of …
Ai-Driven Penetration Testing For Arm Systems: A Comprehensive Framework With Experimental Validation,
2026
Georgia Southern University
Ai-Driven Penetration Testing For Arm Systems: A Comprehensive Framework With Experimental Validation, Matthew Ragsdale
College of Graduate Studies: Theses & Dissertations
The convergence of artificial intelligence and cybersecurity presents new opportunities for automated penetration testing capable of discovering, prioritizing, and remediating vulnerabilities at machine speed. However, deployment on resource-constrained ARM platforms remains unexplored despite ARM’s dominance in mobile, IoT, and edge computing with over 280 billion chips deployed globally. This thesis presents systematic experimental evaluation of AI-driven penetration testing across four paradigms—traditional machine learning, deep learning, large language models, and reinforcement learning—on three ARM platform tiers: Raspberry Pi 5 (8GB, Cortex-A76), Radxa ROCK 5B Plus (16GB LPDDR5 with NPU), and NVIDIA Jetson Nano (4GB with Maxwell GPU). The experimental framework generates …
Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era,
2025
Lynn University
Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou
Faculty and Staff Publications & Presentations
This framework addresses the critical gap between post-quantum standards and workforce readiness. Shor's algorithm demonstrates that sufficiently powerful quantum computers can break the cryptographic foundations of internet security. While the cryptography research community has developed quantum-resistant algorithms, educational institutions have not prepared students to implement these solutions. Recent surveys show fewer than half of organizations have begun planning for post-quantum cryptography (PQC) transitions (Entrust Cybersecurity Institute, 2024; U.S. Government Accountability Office, 2023; (ISC)², 2024). The NICE Framework (Newhouse, Keith, Scribner, & Witte, 2017) outlines the knowledge and skills that cybersecurity professionals should possess. The framework omits post-quantum cryptography entirely. Organizations …
Three Decades Of Chinese Internet Technology: Social Risks And Prevention Pathways,
2025
School of Information Management, Nanjing University, Nanjing 210023, China
Three Decades Of Chinese Internet Technology: Social Risks And Prevention Pathways, Zhaokai Yin, Weifu Zhang
Bulletin of Chinese Academy of Sciences (Chinese Version)
With the rapid advancement and application of big data, artificial intelligence, and mobile Internet technologies, network technology has been driving social development, while its negative effects have gradually emerged. Based on a critical perspective and logical reasoning, this study systematically reviews the evolution and characteristic manifestations of social risks in China’s network technology over the past 30 years, revealing multiple hidden dangers it has caused in data governance, capital operation, and political communication. Under the new situation, to prevent and defuse the social risks of network technology, precise measures should be taken from aspects such as value guidance, institutional regulation, …
Cybercamp: An Experience Report On The Transformations Of An Intensive Cybersecurity Summer Camp For High School Students,
2025
University of Puerto Rico, Rio Piedras
Cybercamp: An Experience Report On The Transformations Of An Intensive Cybersecurity Summer Camp For High School Students, Jose R. Ortiz Ubarri, Kariluz Dávila Diaz Ph.D., Rafael A. Arce Nazario
Journal of Cybersecurity Education, Research and Practice
The Cybercamp is a Cybersecurity summer camp for high school students that has been held for the last nine years at a Hispanic Serving Institution. Since its inception in 2016 the Cybercamp has undergone several transformations in response to budget reductions and the COVID pandemic, to finally become its current version: a rich, hands-on learning experience that we believe is easily replicable even in resource-challenged environments.
In this paper, we document the transformations of the Cybercamp and discuss the developed curriculum and materials in hopes that others will reuse, adapt, and improve upon them. In the Cybercamp, we apply active …
Patterns Of Llm Weaponization: A Comparative Analysis Of Exploitation Incidents Across Commercial Ai Systems,
2025
Lynn University
Patterns Of Llm Weaponization: A Comparative Analysis Of Exploitation Incidents Across Commercial Ai Systems, George Antoniou
Faculty and Staff Publications & Presentations
This comparative study examines patterns of Large Language Model (LLM) weaponization through systematic analysis of four major exploitation incidents spanning 2023-2025. While existing research focuses on isolated incidents or theoretical vulnerabilities, this study provides the first comprehensive comparative framework analyzing exploitation patterns across state-sponsored cyber-espionage (Anthropic Claude incident), academic security research (GPT-4 autonomous privilege escalation), social engineering platforms (SpearBot phishing framework), and underground criminal commoditization (WormGPT/FraudGPT ecosystem). Through comparative analysis across eight dimensions—adversary sophistication, target selection, exploitation techniques, autonomy levels, detection evasion, attribution challenges, defensive gaps, and capability democratization—this research identifies critical cross-case patterns informing defensive prioritization. Findings reveal three …
Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities,
2025
Old Dominion University
Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities, Thomas Pham
Cybersecurity Undergraduate Research Showcase
Open-source software ecosystems have become critical infrastructure for modern software development, yet they remain vulnerable to sophisticated supply chain attacks. This paper presents a comprehensive empirical analysis of supply chain attacks targeting npm, PyPI, and Docker Hub, examining 23 documented campaigns affecting over 2.6 billion weekly downloads. Through systematic analysis of attack vectors including typosquatting, dependency confusion, and maintainer account compromise, we identify recurring patterns and structural vulnerabilities across package registries. Our analysis reveals that 86.1% of detected typosquatted packages contained malware, with cryptocurrency theft emerging as the predominant attack objective. We document the September 2025 npm compromise affecting 18 …
Viability Of Widely Used Encryption Schemes In Drone Transmission,
2025
Old Dominion University
Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson
Cybersecurity Undergraduate Research Showcase
This paper presents throughout research on the security issues related to drone transmission. These topics were addressed and explained, in particular the aspects relating to cybersecurity, for utmost clarity. These include threats and vulnerabilities, drone transmission the impact of encryption on latency, and the details of the encryption methods AES-128, AES-256, and ChaCha20 that were used in the experiment described in the paper. Each encryption method performance was measured and outputted by the Python code developed and used in the experiment. Afterwards, the performance of each method was analyzed in relation to their decryption time, encryption time, end to end …
Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca,
2025
Imperial College London
Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz
Other Faculty Materials
Confidential Virtual Machines (CVMs) are increasingly adopted to protect sensitive workloads from privileged adversaries such as the hypervisor. While they provide strong isolation guarantees, existing CVM architectures lack first-class mechanisms for inter-CVM data sharing due to their disjoint memory model, making inter-CVM data exchange a performance bottleneck in compartmentalized or collaborative multi-CVM systems. Under this model, a CVM's accessible memory is either shared with the hypervisor or protected from both the hypervisor and all other CVMs. This design simplifies reasoning about memory ownership; however, it fundamentally precludes plaintext data sharing between CVMs because all inter-CVM communication must pass through hypervisor-accessible …
Rogue Access Points And Their Impact On Networks,
2025
Virginia Peninsula Community College
Rogue Access Points And Their Impact On Networks, Sami Belmokhtar
Cybersecurity Undergraduate Research Showcase
This paper focuses on rogue access points (rogue APs) and how they can impact the security and stability of a network, and consequently, the safety and privacy of the users. Wireless access points (WAPs) are nodes that allow a user to connect to a local network. This includes devices such as the routers typically used in a home network. This paper examines how an unauthorized WAP may pose a threat to a network in both a public environment and an enterprise environment. Furthermore, it shows how a hacker can mimic a real wireless network and gain access to both user …
Sme Cyber Resilience State Of The Sector 2025,
2025
Chair of Cyber Security, Faculty of Science and Informatics, Munster Technological University, Cork, Ireland
Sme Cyber Resilience State Of The Sector 2025, Hazel Murray, Gillian O'Carroll, Aoibheann Brangan, Jason Holland, Stephanie Chevanne Wallace, Miriam Curtain, Glenda Deveney
Department of Computer Science Publications
Ireland's small and medium enterprises (SMEs) face a critical cyber resilience gap. SMEs account for 99.8% of all enterprises in Ireland and employ over 2.29 million people, representing 67.9% of total employment (based on the latest CSO 2022 figures). This cyber resilience assessment reveals that the majority of SMEs remain underprepared for modern cyber threats.
Bridging The Gap Between Network Science And Network Systems To Identify And Mitigate Cyber Risk: Identify And Mitigate Backdoor Attacks On Graph Neural Networks And On Complex Systems,
2025
Old Dominion University
Bridging The Gap Between Network Science And Network Systems To Identify And Mitigate Cyber Risk: Identify And Mitigate Backdoor Attacks On Graph Neural Networks And On Complex Systems, Sabah Ettahri
Electrical & Computer Engineering Projects for D. Eng. Degree
This doctoral project aims to bridge the gap between graph theory and network science to identify and mitigate cyber risk, represented as a CY-Triangular Network that connects different networks. The CY-Triangular Framework is a cybersecurity system that integrates graph theory and network science through an interoperable learning approach. The objective of this project is to bridge the gap between two domains: network science and network systems. Accordingly, it examines one representative network from each field, focuses on a complex system network, and explores Graph Neural Networks (GNNs). The connection between these domains lies in graph theory. This research demonstrates that …
Nonlinear Phase Space Analysis For Anomaly Detection In Ros 2 Communications: Detecting Man-In-The-Middle Attacks In Simulated Environments,
2025
University of South Alabama
Nonlinear Phase Space Analysis For Anomaly Detection In Ros 2 Communications: Detecting Man-In-The-Middle Attacks In Simulated Environments, William L. Locklier
Graduate Theses and Dissertations (2019 - present)
Robot Operating System 2 (ROS 2) marks a significant advancement over its predecessor through the transition from a centralized to a decentralized architecture, integrating the Data Distribution Service (DDS) to support real-time, scalable communications. Despite these improvements, inherent vulnerabilities in the ROS 2 communication stack continue to leave these systems exposed to sophisticated network-based attacks. This study leveraged nonlinear phase space analysis (NLPSA) as an intrusion detection system (IDS) to detect man-in-the-middle (MitM) attack anomalies in ROS 2 traffic. Grounded in Takens’ embedding theorem, NLPSA reconstructs the phase space of communication features and compares the resulting structure against a baseline …
Application Of Graph Neural Networks On Phase Space Graphs For Cybersecurity,
2025
University of South Alabama
Application Of Graph Neural Networks On Phase Space Graphs For Cybersecurity, Parker H. Cole
Graduate Theses and Dissertations (2019 - present)
Non-linear phase space analysis may be used to represent time-series data as graph data with transitions between states in the time domain. By studying these transitions, we can predict anomalies within the system. Previous research has demonstrated success in learning from phase graphs for malware and seizure detection. These solutions either require extracting global features or converting the graph into an image for convolutional neural networks (CNNs), which adds a layer of complexity and limits the size and potential expressiveness of a graph. To sidestep current limitations, this study proposed Graph Neural Networks (GNNs) for analyzing phase graphs. GNNs do …
