Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons™

Open Access. Powered by Scholars. Published by Universities.®

466 Full-Text Articles 804 Authors 161,915 Downloads 101 Institutions

All Articles in Cybersecurity

Faceted Search

466 full-text articles. Page 7 of 23.

Patterns Of Llm Weaponization: A Comparative Analysis Of Exploitation Incidents Across Commercial Ai Systems, George Antoniou 2025 Lynn University

Patterns Of Llm Weaponization: A Comparative Analysis Of Exploitation Incidents Across Commercial Ai Systems, George Antoniou

Faculty and Staff Publications & Presentations

This comparative study examines patterns of Large Language Model (LLM) weaponization through systematic analysis of four major exploitation incidents spanning 2023-2025. While existing research focuses on isolated incidents or theoretical vulnerabilities, this study provides the first comprehensive comparative framework analyzing exploitation patterns across state-sponsored cyber-espionage (Anthropic Claude incident), academic security research (GPT-4 autonomous privilege escalation), social engineering platforms (SpearBot phishing framework), and underground criminal commoditization (WormGPT/FraudGPT ecosystem). Through comparative analysis across eight dimensions—adversary sophistication, target selection, exploitation techniques, autonomy levels, detection evasion, attribution challenges, defensive gaps, and capability democratization—this research identifies critical cross-case patterns informing defensive prioritization. Findings reveal three …


Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities, Thomas Pham 2025 Old Dominion University

Supply Chain Attacks Through Open Source Software: A Comprehensive Analysis Of Npm, Pypi, And Docker Hub Vulnerabilities, Thomas Pham

Cybersecurity Undergraduate Research Showcase

Open-source software ecosystems have become critical infrastructure for modern software development, yet they remain vulnerable to sophisticated supply chain attacks. This paper presents a comprehensive empirical analysis of supply chain attacks targeting npm, PyPI, and Docker Hub, examining 23 documented campaigns affecting over 2.6 billion weekly downloads. Through systematic analysis of attack vectors including typosquatting, dependency confusion, and maintainer account compromise, we identify recurring patterns and structural vulnerabilities across package registries. Our analysis reveals that 86.1% of detected typosquatted packages contained malware, with cryptocurrency theft emerging as the predominant attack objective. We document the September 2025 npm compromise affecting 18 …


Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson 2025 Old Dominion University

Viability Of Widely Used Encryption Schemes In Drone Transmission, Emanuel Yasir Nelson

Cybersecurity Undergraduate Research Showcase

This paper presents throughout research on the security issues related to drone transmission. These topics were addressed and explained, in particular the aspects relating to cybersecurity, for utmost clarity. These include threats and vulnerabilities, drone transmission the impact of encryption on latency, and the details of the encryption methods AES-128, AES-256, and ChaCha20 that were used in the experiment described in the paper. Each encryption method performance was measured and outputted by the Python code developed and used in the experiment. Afterwards, the performance of each method was analyzed in relation to their decryption time, encryption time, end to end …


Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz 2025 Imperial College London

Confidential, Attestable, And Efficient Inter-Cvm Communication With Arm Cca, Sina Abdollahi, Amir Al Sadi, Marios Kogias, Hamed Haddadi, David Kotz

Other Faculty Materials

Confidential Virtual Machines (CVMs) are increasingly adopted to protect sensitive workloads from privileged adversaries such as the hypervisor. While they provide strong isolation guarantees, existing CVM architectures lack first-class mechanisms for inter-CVM data sharing due to their disjoint memory model, making inter-CVM data exchange a performance bottleneck in compartmentalized or collaborative multi-CVM systems. Under this model, a CVM's accessible memory is either shared with the hypervisor or protected from both the hypervisor and all other CVMs. This design simplifies reasoning about memory ownership; however, it fundamentally precludes plaintext data sharing between CVMs because all inter-CVM communication must pass through hypervisor-accessible …


Rogue Access Points And Their Impact On Networks, Sami Belmokhtar 2025 Virginia Peninsula Community College

Rogue Access Points And Their Impact On Networks, Sami Belmokhtar

Cybersecurity Undergraduate Research Showcase

This paper focuses on rogue access points (rogue APs) and how they can impact the security and stability of a network, and consequently, the safety and privacy of the users. Wireless access points (WAPs) are nodes that allow a user to connect to a local network. This includes devices such as the routers typically used in a home network. This paper examines how an unauthorized WAP may pose a threat to a network in both a public environment and an enterprise environment. Furthermore, it shows how a hacker can mimic a real wireless network and gain access to both user …


Sme Cyber Resilience State Of The Sector 2025, Hazel Murray, Gillian O'Carroll, Aoibheann Brangan, Jason Holland, Stephanie Chevanne Wallace, Miriam Curtain, Glenda Deveney 2025 Chair of Cyber Security, Faculty of Science and Informatics, Munster Technological University, Cork, Ireland

Sme Cyber Resilience State Of The Sector 2025, Hazel Murray, Gillian O'Carroll, Aoibheann Brangan, Jason Holland, Stephanie Chevanne Wallace, Miriam Curtain, Glenda Deveney

Department of Computer Science Publications

Ireland's small and medium enterprises (SMEs) face a critical cyber resilience gap. SMEs account for 99.8% of all enterprises in Ireland and employ over 2.29 million people, representing 67.9% of total employment (based on the latest CSO 2022 figures). This cyber resilience assessment reveals that the majority of SMEs remain underprepared for modern cyber threats.


Nonlinear Phase Space Analysis For Anomaly Detection In Ros 2 Communications: Detecting Man-In-The-Middle Attacks In Simulated Environments, William L. Locklier 2025 University of South Alabama

Nonlinear Phase Space Analysis For Anomaly Detection In Ros 2 Communications: Detecting Man-In-The-Middle Attacks In Simulated Environments, William L. Locklier

Graduate Theses and Dissertations (2019 - present)

Robot Operating System 2 (ROS 2) marks a significant advancement over its predecessor through the transition from a centralized to a decentralized architecture, integrating the Data Distribution Service (DDS) to support real-time, scalable communications. Despite these improvements, inherent vulnerabilities in the ROS 2 communication stack continue to leave these systems exposed to sophisticated network-based attacks. This study leveraged nonlinear phase space analysis (NLPSA) as an intrusion detection system (IDS) to detect man-in-the-middle (MitM) attack anomalies in ROS 2 traffic. Grounded in Takens’ embedding theorem, NLPSA reconstructs the phase space of communication features and compares the resulting structure against a baseline …


Bridging The Gap Between Network Science And Network Systems To Identify And Mitigate Cyber Risk: Identify And Mitigate Backdoor Attacks On Graph Neural Networks And On Complex Systems, Sabah Ettahri 2025 Old Dominion University

Bridging The Gap Between Network Science And Network Systems To Identify And Mitigate Cyber Risk: Identify And Mitigate Backdoor Attacks On Graph Neural Networks And On Complex Systems, Sabah Ettahri

Electrical & Computer Engineering Projects for D. Eng. Degree

This doctoral project aims to bridge the gap between graph theory and network science to identify and mitigate cyber risk, represented as a CY-Triangular Network that connects different networks. The CY-Triangular Framework is a cybersecurity system that integrates graph theory and network science through an interoperable learning approach. The objective of this project is to bridge the gap between two domains: network science and network systems. Accordingly, it examines one representative network from each field, focuses on a complex system network, and explores Graph Neural Networks (GNNs). The connection between these domains lies in graph theory. This research demonstrates that …


Application Of Graph Neural Networks On Phase Space Graphs For Cybersecurity, Parker H. Cole 2025 University of South Alabama

Application Of Graph Neural Networks On Phase Space Graphs For Cybersecurity, Parker H. Cole

Graduate Theses and Dissertations (2019 - present)

Non-linear phase space analysis may be used to represent time-series data as graph data with transitions between states in the time domain. By studying these transitions, we can predict anomalies within the system. Previous research has demonstrated success in learning from phase graphs for malware and seizure detection. These solutions either require extracting global features or converting the graph into an image for convolutional neural networks (CNNs), which adds a layer of complexity and limits the size and potential expressiveness of a graph. To sidestep current limitations, this study proposed Graph Neural Networks (GNNs) for analyzing phase graphs. GNNs do …


Privacy In Flux: A 35-Year Review Of Trends, Legal Evolution, And Emerging Challenges, Kong Phang, Jihene Kaabi 2025 Dakota State University

Privacy In Flux: A 35-Year Review Of Trends, Legal Evolution, And Emerging Challenges, Kong Phang, Jihene Kaabi

Research & Publications

Privacy harms have expanded alongside rapid technological change, challenging the adequacy of existing regulatory frameworks. This systematic review (1990–2025) systematically maps documented privacy harms to specific legal mechanisms and observed enforcement outcomes across jurisdictions, using PRISMA-guided methods and ROBIS risk-of-bias assessment. We synthesize evidence on major regimes (e.g., GDPR, COPPA, CCPA, HIPAA, GLBA) and conduct comparative legal analysis across the U.S., E.U., and underexplored regions in Asia, Latin America, and Africa. Key findings indicate increased recognition of data subject rights, persistent gaps in cross-border data governance, and emerging risks from AI/ML/LLMs, IoT, and blockchain, including data breaches, algorithmic discrimination, and …


Insider Threat: A Case Study Of The Maroochy Water Services Attack, Samuel Rector 2025 Tidewater Community College

Insider Threat: A Case Study Of The Maroochy Water Services Attack, Samuel Rector

Cybersecurity Undergraduate Research Showcase

In 2000, a former employee at Hunter Watertech went rogue and caused a spill of 800,000 liters of sewage. He leveraged his insider knowledge and access to stolen equipment in order to seek retribution for the company that wronged him. After three months of torment police arrested him and an investigation and many studies were done on the incident. A consensus remains that much of this chaos was preventable with simple cybersecurity implementations.


Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman 2025 Old Dominion University

Behavioral Detection Methods For Automated Mcp Server Vulnerability Assessment, Christian Coleman

Cybersecurity Undergraduate Research Showcase

The Model Context Protocol (MCP) has emerged as a critical standard for connecting AI agents to external data sources and tools. Still, its adoption has introduced significant security vulnerabilities across multiple attack surfaces. While recent research has catalogued extensive vulnerability taxonomies and attack implementations, automated detection methodologies remain limited. Current detection tools primarily employ static code analysis, which fails to identify behavioral vulnerabilities that only manifest during runtime server interactions. This study explores behavioral detection approaches for identifying MCP server vulnerabilities through systematic query-based testing, with particular emphasis on context manipulation techniques. Preliminary analysis of existing vulnerability research reveals 48 …


Game Hacking & Anti-Cheat Analysis, Quang Hoang 2025 William & Mary

Game Hacking & Anti-Cheat Analysis, Quang Hoang

Cybersecurity Undergraduate Research Showcase

Reverse engineering and analyzing game hacking and anti-cheat mechanisms is a complex and evolving field. This research document explores the history of game hacking, various techniques used in game hacking, and the countermeasures implemented by anti-cheat systems. Through case studies, we illustrate the strategies involved in creating cheats. Specifically, we demonstrate how to hack the open-source game AssaultCube using memory editing and code injection techniques available in Cheat Engine in a step-by-step manner so that the reader can theoretically reproduce the results shown in this paper. We also dissect the game’s anti-cheat mechanisms, identifying their strengths and weaknesses. This document …


Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou 2025 Lynn University

Quantum Readiness In Cybersecurity Education: A Framework For Preparing The Next Generation In The Post-Quantum Era, George Antoniou

Faculty and Staff Publications & Presentations

The rapid advancement of quantum computing represents both a revolutionary opportunity and an existential threat to contemporary cybersecurity infrastructure. While quantum computers promise unprecedented computational capabilities, they simultaneously pose a critical risk to current cryptographic protocols that protect sensitive data, financial systems, and national security frameworks. Post-quantum cryptography (PQC) standards, recently formalized by NIST in 2024, provide a roadmap for quantum-resistant encryption. However, a significant gap exists between technological advancement and educational preparedness, with most cybersecurity curricula failing to adequately prepare students for the quantum era. This paper addresses the urgent need for comprehensive quantum readiness in cybersecurity education across …


A Scalable Cybersecurity Model For Academic Makerspaces, William Faircloth 2025 Old Dominion University

A Scalable Cybersecurity Model For Academic Makerspaces, William Faircloth

Cybersecurity Undergraduate Research Showcase

Academic makerspaces have become integral hubs of innovation on university campuses, providing students with access to industrial-grade operational technology (OT) such as 3D printers and CNC machines. However, the security posture for these spaces has overwhelmingly focused on physical safety, creating a significant cybersecurity gap. This oversight leaves networked OT vulnerable to cyberattacks, which threaten student intellectual property, expensive equipment, and the integrity of the broader institutional network. This research addresses this critical vulnerability by developing and implementing a secure and scalable cybersecurity model at the Old Dominion University Computer Science Makerspace, founded on two core principles: robust network segmentation …


Deconstructing Tycoon 2fa: A Static Analysis Approach To Threat Intelligence And Automated Defense, Daniel A. Austin Jr 2025 Virginia Community Colleges

Deconstructing Tycoon 2fa: A Static Analysis Approach To Threat Intelligence And Automated Defense, Daniel A. Austin Jr

Cybersecurity Undergraduate Research Showcase

It's gotten much easier to be a cybercriminal. We're seeing a boom in "Phishing-as-a-Service" (PaaS) platforms, which sell advanced phishing attacks as a ready-to-use product. This means almost anyone can now get the tools to launch sophisticated attacks, even if they don't have a lot of technical skill.

This research dives into one of the most prominent threats, the Tycoon 2FA phishing kit. This kit is dangerous because it's designed to bypass Multi-Factor Authentication (MFA) using what is known as an Adversary-in-the-Middle (AiTM) attack.

This paper covers how I built and tested a set of Python-based tools to perform "static …


Cv: Mathias Plass (Cybersecurity), Mathias Plass 2025 Lewis University

Cv: Mathias Plass (Cybersecurity), Mathias Plass

ECaMS Department Faculty Curricula Vitae

No abstract provided.


A Systematic Review Of Poisoning Attacks Against Large Language Models (Llm), Patrick McGuffin 2025 Christopher Newport University

A Systematic Review Of Poisoning Attacks Against Large Language Models (Llm), Patrick Mcguffin

Cybersecurity Undergraduate Research Showcase

This paper provides a comprehensive review of poisoning attacks against large language models (LLMs), drawing primarily from Fendley et al. (2025) and complementary studies from 2022–2025. It categorizes poisoning research into two key dimensions, Metrics and Specifications, to evaluate how attack success is measured and how attacks are implemented. This paper synthesizes quantitative results, experimental findings, and defense strategies across data, model, and multi-modal poisoning contexts. Finally, it highlights emerging challenges posed by self-adaptive and synthetic-data-driven LLMs, and proposes future research directions to strengthen model security and reliability.


Detecting Generative-Ai-Enabled Polymorphic Malware: A Semantic-Behavior Approach, Allyson M. Morris 2025 William & Mary

Detecting Generative-Ai-Enabled Polymorphic Malware: A Semantic-Behavior Approach, Allyson M. Morris

Cybersecurity Undergraduate Research Showcase

AI drastically reduces the effort required to produce malware that mutates both its code and behavior, thereby creating polymorphic and nondeterministic variants in which traditional signatures and many heuristic defenses fail. In this paper, I survey recent developments in AI-assisted malware generation, explain why conventional defenses are insufficient, and propose a layered detection architecture emphasizing semantic behavior, streaming anomaly detection, and defensive generative augmentation. I also outline why this approach generalizes to previously unseen AI-mutated samples, provide an evaluation plan with meaningful metrics, and describe a feasible MVP roadmap for practical deployment. Recent disclosures and threat intelligence further highlight the …


A Comprehensive Evaluation Of Next-Generation Firewall Effectiveness Against Encrypted And Evasive Threats In Enterprise Networks, John Costanzo, Favour Anene 2025 Old Dominion University

A Comprehensive Evaluation Of Next-Generation Firewall Effectiveness Against Encrypted And Evasive Threats In Enterprise Networks, John Costanzo, Favour Anene

Cybersecurity Undergraduate Research Showcase

Encrypted traffic is becoming a pillar of security and privacy in enterprise networks. According to Google Transparency Report, over 95 percent of internet traffic is encrypted with the use of Hypertext Transfer Protocol secure (HTTPS), Transport Layer Security (TLS) 1.3 and Quick UDP Internet Connections (QUIC). Although encryption safeguards confidentiality and integrity, it has also introduced new blind spots to the conventional security solutions. Encrypted channels are used to hide command-and-control (C2) traffic, issue malware and extract sensitive data without their notice.

To make the issue even harder, the opponents have sophisticated avoidance methods including traffic fragmentation, tunneling, and polymorphic …


Digital Commons powered by bepress