Enlem: Ensemble Learning-Based Model To Detect Phishing Websites,
2026
Bangladesh University of Business and Technology
Enlem: Ensemble Learning-Based Model To Detect Phishing Websites, Most Nilufa Yeasmin, Md Abu Rumman Refat, Bikash Chandra Singh, Zulfikar Alom, Zeyar Aung, Mohammad Azim
School of Cybersecurity Faculty Publications
Phishing involves manipulating individuals into revealing private data, e.g., user IDs, bank details, and passwords. The observed surge in fraud is related to increased deception, impersonation, and advanced online attacks. Thus, effective phishing detection methods are required to mitigate escalating global phishing threats. Existing methods (e.g., heuristics-based, signature-based, and visual similarity-based methods) attempt to detect phishing sites, and machine learning (ML) and deep learning (DL) methods are effective in the cybersecurity context in terms of learning from data, offering insights, and forecasting. However, independent ML algorithms are limited when handling complex data, and DL techniques surpass traditional ML methods in …
Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis,
2026
Georgia State University
Toward Secure And Practical Machine Learning-Based Access Control: A Framework With Real-World Constraints And Adversarial Analysis, Olusesi Balogun, Mohammad Ghasemigol, Zhipeng Cai, Daniel Takabi
School of Cybersecurity Faculty Publications
Attribute-Based Access Control (ABAC) frameworks coordinate access requests based on subject, object, and environment attributes, as well as policy rules, and are widely used in corporate security systems. Recently, machine learning has been applied to ABAC to address policy-generation imbalances, misassigned privileges, and attribute leakages. However, existing MLBAC techniques do not consider the structural constraints and attribute interdependencies present in traditional ABAC systems. Moreover, these frameworks have not been extensively evaluated under black-box attack scenarios. To address these gaps, we propose extensions to MLBAC that integrate structural constraints, attribute dynamism, and attribute weighting into the MLBAC objective function. Additionally, we …
Towards Breach Hypothesis Based Predictive Autonomous Cyber Defense Ecosystem: Proactive Prevention Of Imminent Threats And Productivity Losses,
2026
Eastern Michigan University
Towards Breach Hypothesis Based Predictive Autonomous Cyber Defense Ecosystem: Proactive Prevention Of Imminent Threats And Productivity Losses, Yogesh Chavarkar
Master's Theses and Doctoral Dissertations
As cyberattack tools and techniques get sophisticated and persistent, reactive cybersecurity has been unable to effectively prevent breaches and compromises. Organizations and institutions with large complex environments have wide vulnerable exposure with higher chances of a cyberattack. This also increases overall security and financial risk. Possibility of repetitive attacks from cyber threats increases, too, despite the use of standard defense measures. Security tools and system vulnerabilities often need manual patching and updates to keep the environment secure and functioning effectively. Productivity suffers from manual trade-offs in keeping the systems secure from adverse impact. Persistent high-severity cyberattacks, despite continued reactive defensive …
Defending A Soho Network Against Mitm Attacks,
2026
University of Akron
Defending A Soho Network Against Mitm Attacks, Braeden J. Wise
Williams Honors College, Honors Research Projects
Cybersecurity is a vast domain that consists of many threats that target sensitive information found on wired and wireless networks. One of those threats is a man-in-the-middle (MITM) attack, which involves an attacker situating themselves between a sender and a receiver to intercept or redirect network traffic. These kinds of attacks can run rampant on a small office home office (SOHO) network due to the vulnerabilities and lack of enterprise level tools. The intent of this project is to perform and defend against MITM attacks for a SOHO network. In the context of the project, three MITM attacks will be …
Analyzing Network Traffic And Data Exfiltration Via Smb In Post-Vm Escape Scenarios,
2026
The University of Akron
Analyzing Network Traffic And Data Exfiltration Via Smb In Post-Vm Escape Scenarios, Noah M. Disanza
Williams Honors College, Honors Research Projects
Virtual machines (VMs) play a crucial role in modern IT infrastructure environments by providing isolation and enhanced security, among other things, for both personal and corporate systems. VMs are heavily rely upon to safely test malware, manage infrastructure, and reduce risk to host systems. This reliance is so substantial that the idea of reducing risk to the host system is believed to be erasing risk entirely. However, this mindset has shown to be challenged time and time again by the emergence of exploits known as virtual machine escapes. These exploits allow malicious actors to break out of the virtualized environment …
Secure The Database: A Red Team, Blue Team Analysis Of Sql Injection,
2026
The University of Akron
Secure The Database: A Red Team, Blue Team Analysis Of Sql Injection, Andrew N. Miller
Williams Honors College, Honors Research Projects
SQL injection (SQLi) attacks are a type of cyberattack that seeks to bypass website logins and gain entry to sensitive information. These pose a significant danger to organizations holding confidential user information. Personally Identifiable Information (PII) like physical addresses, emails, phone numbers, social security numbers are at risk of theft. Login credentials like usernames, passwords, and other sensitive information like financial details and social security numbers are also exposed through SQLi attacks. SQLi attacks harm the confidentiality, integrity, and availability of people’s identity. Additionally, data breaches that reach public battention harm the reputation and trust of organizations. SQLi attacks rank …
Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems,
2026
Virginia Commonwealth University
Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems, Gustaf Barkstrom
Theses and Dissertations
Businesses lose millions of dollars every year when they can’t restore data from backups. Research shows that Disaster Recovery Plan (DRP) testing is not conducted frequently enough, nor are records maintained that demonstrate full data recovery from backups. This work introduces a design science artifact called PRTOK that aims to increase DRP testing. The design science artifact is a software solution that integrates with Data Management Systems (DMS)
such as iRODS and DSpace, and can work with formats such as HDF5 and BagIt. Proof-of- recovery records, or tokens, are recorded in a replicated, resilient, and indelible proof-of- authority blockchain data …
A Knowledge-Driven, Ai-Assisted Cyber Defence Framework For Iomt Remote Patient Monitoring,
2026
Edith Cowan University
A Knowledge-Driven, Ai-Assisted Cyber Defence Framework For Iomt Remote Patient Monitoring, Kulsoom S. Bughio, David M. Cook, Abdul M. Unar
Research outputs 2022 to 2026
The rapid adoption of Internet Medical Things (IoMT) technologies in remote patient monitoring has reshaped healthcare delivery by enabling continuous, real-time clinical observation outside traditional care settings. However, this shift has also expanded the cyber-attack surface across heterogeneous, resource-constrained medical devices, wireless networks, cloud services, and third-party platforms. In cyber warfare, healthcare has become an incorporated target of geopolitics, with hospitals, remote monitoring systems, and emergency health systems being used to broaden the attack surface for adversaries to exploit. Existing security approaches for IoMT environments remain largely manual, fragmented, and reactive, limiting their effectiveness in dynamically assessing vulnerabilities and supporting …
Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac,
2026
University of North Florida
Energy-Efficient Security For Narrowband Iot Using Blockchain And Ep-Cumac, Hafizullah Kakar
UNF Graduate Theses and Dissertations
The Narrowband Internet of Things (NB-IoT) continues to expand but faces challenges such as cryptographic overhead and energy consumption. Security frameworks such as blockchain and Energy-Performance Cumulative Message Authentication Codes (EP-CuMAC) rely heavily on SHA-256, which is not optimized for energy-limited devices.
This work unifies two complementary approaches, a hybrid blockchain-based NB-IoT framework and an EP-CuMAC-based framework, by engineering their cryptographic core with an Energy Complexity Model-optimized SHA-256 (ECM-SHA256). ECM applies parallel memory-bank mapping and block-level access optimization to reduce redundant power usage while preserving algorithmic integrity.
Experimental evaluation on identical Intel DDR3 systems using pyRAPL shows energy savings of …
Advancing Cybersecurity Through Userland Memory Forensics: From Runtime Analysis To Security Applications,
2026
Virginia Commonwealth University
Advancing Cybersecurity Through Userland Memory Forensics: From Runtime Analysis To Security Applications, Hala Ali
Theses and Dissertations
Memory forensics has become a crucial component of digital investigations, particularly for detecting malware operating solely in system memory. As operating system vendors implemented kernel access restrictions, malware authors shifted to userland malware. However, existing memory forensics techniques have largely focused on kernel-level analysis, leaving userland runtimes insufficiently covered. This dissertation addresses this gap by expanding memory analysis capabilities across two distinct paradigms: interpreted and compiled runtimes. The first phase targets the Python runtime, developing automated recovery techniques that enable several security applications. For malware detection, these techniques extract critical forensic artifacts such as encryption keys and command-and-control configurations. For …
Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset,
2026
Marshall University
Machine Learning-Based Intrusion Detection System For Iot Networks Using The Rt-Iot 2022 Dataset, Bukunmi Ebenezer Afolabi
Theses, Dissertations and Capstones
The rapid expansion of the Internet of Things (IoT) has transformed modern computing by enabling seamless connectivity among heterogeneous devices across diverse application domains. However, this increased interconnectivity has significantly enlarged the attack surface of IoT networks, exposing them to a wide range of sophisticated cyber threats. Conventional security mechanisms often lack the capability to detect emerging attacks in real time, thereby necessitating the development of intelligent Intrusion Detection Systems (IDS) capable of accurately identifying malicious network activities. This study developed and evaluated a machine learning-based intrusion detection framework for multiclass IoT attack detection using the RT-IoT2022 dataset. The dataset …
The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage,
2026
Zhejiang University
The Privacy Paradox Of Llms: User Perceptions And The Reality Of Pii Leakage, Shuai Cheng, Haitao Xu, Shu Meng, Shuai Hao, Chuan Yue, Zhao Li
Computer Science Faculty Publications
Large language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify …
When Helpfulness Becomes Harmful: Jailbreaking Llms For Malicious Code Generation,
2026
University at Albany, State University of New York
When Helpfulness Becomes Harmful: Jailbreaking Llms For Malicious Code Generation, Noelle Capodieci
Electronic Theses & Dissertations (2024 - present)
Generative AI (GenAI) and Large Language Models (LLMs) have made large strides in coding task capabilities, with many software developers integrating agentic engineering into their workflow. While GenAI has largely benefited professional software engineers who can automate their work, it has also created room for those with little coding expertise to also create fully fledged programs and applications. It is commonly noted that GenAI is trained with two major goals in mind: to be as helpful as possible, and be as harmless as possible. There exist moments where helpfulness may be prioritized over harmlessness when these goals conflict. LLMs may …
Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures,
2026
Old Dominion University
Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han
Accounting Faculty Publications
This study examines whether firms strategically adjust the readability of Item 1A (“Risk Factors”) disclosures following data breaches. Using U.S. firm-year observations from 2006 to 2023, we find that data breaches are associated with a significant decline in Item 1A readability. This decline is not accompanied by a meaningful increase in informational content; instead, post-breach disclosures exhibit higher syntactic complexity, more positive tone, and lower textual similarity to prior and industry peers' filings, consistent with strategic obfuscation rather than transparent reporting. The readability decline is amplified among firms facing higher litigation risk but attenuated among firms with stronger reputations for …
Evaluating Llms For Cpe Identification In Iot Reconnaissance,
2026
Eastern Washington University
Evaluating Llms For Cpe Identification In Iot Reconnaissance, Christopher Davisson
EWU Masters Thesis Collection
Vulnerability identification during penetration testing relies on rigid string-matching to map network scan data to Common Platform Enumeration (CPE) identifiers and downstream Common Vulnerabilities and Exposures (CVEs). The approach frequently fails on physical Internet of Things (IoT) devices, which produce non-standard, irregular service banners that resist deterministic parsing. Large Language Models can reason through these fuzzy associations, but cloud-hosted models introduce cost, latency, and operational security concerns when processing reconnaissance data from live networks. This thesis asks whether locally-hosted open-weight Large Language Models (LLMs) can perform this task well enough to be useful, and how performance varies with model scale, …
Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research,
2026
North Carolina A&T State University
Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias
Electrical & Computer Engineering Faculty Publications
This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.
The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …
Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach,
2026
St. Francis College
Look-Ahead Cyber-Threat Forecasting For Connected And Automated Transport: A Spatio-Temporal Graph Learning Approach, Md Al Amin, Mohammad Shafat Ahsan, Jannatul Maua, Arifa Akter Eva, M.F. Mridha, Md. Jakir Hossen
Student Publications [Scholarly]
Modern intelligent transportation systems (ITS) increasingly rely on connected electronic control units (ECUs), exposing in-vehicle networks to cyber-attacks such as message injection on the Controller Area Network (CAN) bus. While prior work has focused on post-factum detection, this paper addresses the underexplored task of forecasting cyber-attacks before they occur. We propose a spatio-temporal graph neural network (STGNN) architecture that models CAN traffic as a dynamic graph sequence, where nodes represent active CAN IDs and edges capture statistical co-activation patterns. Each graph snapshot encodes temporal features such as inter-arrival statistics and entropy, and is processed using graph attention layers followed by …
Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era,
2025
Lynn University
Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou
Faculty and Staff Publications & Presentations
This framework addresses the critical gap between post-quantum standards and workforce readiness. Shor's algorithm demonstrates that sufficiently powerful quantum computers can break the cryptographic foundations of internet security. While the cryptography research community has developed quantum-resistant algorithms, educational institutions have not prepared students to implement these solutions. Recent surveys show fewer than half of organizations have begun planning for post-quantum cryptography (PQC) transitions (Entrust Cybersecurity Institute, 2024; U.S. Government Accountability Office, 2023; (ISC)², 2024). The NICE Framework (Newhouse, Keith, Scribner, & Witte, 2017) outlines the knowledge and skills that cybersecurity professionals should possess. The framework omits post-quantum cryptography entirely. Organizations …
Three Decades Of Chinese Internet Technology: Social Risks And Prevention Pathways,
2025
School of Information Management, Nanjing University, Nanjing 210023, China
Three Decades Of Chinese Internet Technology: Social Risks And Prevention Pathways, Zhaokai Yin, Weifu Zhang
Bulletin of Chinese Academy of Sciences (Chinese Version)
With the rapid advancement and application of big data, artificial intelligence, and mobile Internet technologies, network technology has been driving social development, while its negative effects have gradually emerged. Based on a critical perspective and logical reasoning, this study systematically reviews the evolution and characteristic manifestations of social risks in China’s network technology over the past 30 years, revealing multiple hidden dangers it has caused in data governance, capital operation, and political communication. Under the new situation, to prevent and defuse the social risks of network technology, precise measures should be taken from aspects such as value guidance, institutional regulation, …
Cybercamp: An Experience Report On The Transformations Of An Intensive Cybersecurity Summer Camp For High School Students,
2025
University of Puerto Rico, Rio Piedras
Cybercamp: An Experience Report On The Transformations Of An Intensive Cybersecurity Summer Camp For High School Students, Jose R. Ortiz Ubarri, Kariluz Dávila Diaz Ph.D., Rafael A. Arce Nazario
Journal of Cybersecurity Education, Research and Practice
The Cybercamp is a Cybersecurity summer camp for high school students that has been held for the last nine years at a Hispanic Serving Institution. Since its inception in 2016 the Cybercamp has undergone several transformations in response to budget reductions and the COVID pandemic, to finally become its current version: a rich, hands-on learning experience that we believe is easily replicable even in resource-challenged environments.
In this paper, we document the transformations of the Cybercamp and discuss the developed curriculum and materials in hopes that others will reuse, adapt, and improve upon them. In the Cybercamp, we apply active …
