Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 1 of 201.

Bridg-Ics: Ai-Grounded Knowledge Graphs For Intelligent Threat Analytics In Industry 5.0 Cyber-Physical Systems, Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim, Iqbal H. Sarker, Helge Janicke 2026 Edith Cowan University

Bridg-Ics: Ai-Grounded Knowledge Graphs For Intelligent Threat Analytics In Industry 5.0 Cyber-Physical Systems, Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim, Iqbal H. Sarker, Helge Janicke

Research outputs 2022 to 2026

Industry 5.0’s increasing integration of IT and OT systems is transforming industrial operations but also expanding the cyber–physical attack surface. Industrial Control Systems (ICS) face escalating security challenges as traditional siloed defenses fail to provide coherent, cross-domain threat insights. We present BRIDG-ICS (BRIDge for Industrial Control Systems), an AI-enriched Knowledge Graph (KG) framework for context-aware threat analysis and quantitative assessment of cyber resilience in smart manufacturing environments. BRIDG-ICS fuses heterogeneous industrial and cybersecurity data into an integrated Industrial Security Knowledge Graph linking assets, vulnerabilities, and adversarial behaviors with probabilistic risk metrics (e.g., exploit likelihood, attack cost). This unified graph representation …


Assessor Experiences In Cmmc Level 2 Certification Assessments: An Interpretative Phenomenological Analysis Of Role Expectations, Samuel Heuchert, John Hastings 2026 Dakota State University

Assessor Experiences In Cmmc Level 2 Certification Assessments: An Interpretative Phenomenological Analysis Of Role Expectations, Samuel Heuchert, John Hastings

Research & Publications

The Cybersecurity Maturity Model Certification program requires that third-party assessments be conducted under a non-consultative model. The model is intended to ensure impartiality for organizations seeking certification. While this structure defines expectations for assessor behavior, assessor experiences and interpretations of these constraints remain underexamined. The study examines the lived experiences of CMMC-Certified Assessors and how they navigate role expectations within the non-consultative model. Using Role Conflict Theory as a guiding framework, the study applied Interpretative Phenomenological Analysis (IPA) to semi-structured interviews to explore how assessors make sense of their roles. The analysis identified experiential themes that describe how assessors construct …


Hands-On Ransomware: An Experiential Wannacry Case Study For Undergraduate Cybersecurity Education, Eli Creek Richmond, Thomas R. Devine 2026 West Virginia University

Hands-On Ransomware: An Experiential Wannacry Case Study For Undergraduate Cybersecurity Education, Eli Creek Richmond, Thomas R. Devine

Military Cyber Affairs

Ransomware represents one of the most disruptive threats in the cyber landscape, yet hands-on malware analysis remains rare in undergraduate cybersecurity curricula. This paper presents the design, implementation, and evaluation of an experiential learning module centered on the WannaCry ransomware case study, deployed in a senior-level course at West Virginia University. Students performed static and dynamic analysis using industry-standard tools. Pre- and post-module assessments demonstrated measurable gains in self-reported competency across seven technical dimensions. The module's competencies align directly with DoD Cyber Workforce Framework Work Role 212, Cyber Defense Forensics Analyst, supporting education-to-workforce pipeline development.


From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance, Shelby C. Snyder 2026 Northeastern University

From Framework To Toolchain: Implementing Zero Trust Architecture In Cloud-Native Environments For Dow Compliance, Shelby C. Snyder

Military Cyber Affairs

Federal agencies face a fiscal year 2027 target for enterprise-wide Zero Trust deployment, but NIST SP 800-207A defines logical components without identifying the Kubernetes technologies that implement them. This paper proposes a three-tier mapping of the Policy Engine, Policy Administrator, and Policy Enforcement Point to service mesh, microsegmentation, and perimeter tooling, stating the criteria by which each component is classified. It then applies a defined rubric to six Zero Trust vendors across component alignment, Kubernetes capability, federal authorization posture, and evidence quality, finding that no single vendor covers all three tiers. The mapping is a testable architectural proposition; a Stage …


Characterizing Advanced Persistent Threats With Cyber Attack Flow Metrics, Tyler Miller, Caleb Chang, Shouhuai Xu 2026 Pikes Peak State College

Characterizing Advanced Persistent Threats With Cyber Attack Flow Metrics, Tyler Miller, Caleb Chang, Shouhuai Xu

Military Cyber Affairs

Cyber attack campaigns vary not only in scale but in structure, yet conventional characterizations often reduce them to a single dimension such as technique count or impact severity. In this paper we extend the concept of cyber attack flows by defining three new metrics, novelty, technique complexity and flow complexity. Then we characterize the attack flows of three advanced persistent threat campaigns using these metrics and draw insights regarding their capabilities. Our findings include that low novelty does not equate to low attack capabilities and that exploitation of an internet-facing appliance is a common initial attack vector.


Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck 2026 The Ohio State University

Semantic Shields: Automating Critical Infrastructure Defense Via Nlp-Driven Ransomware Profiling, Henry Trowbridge, Ian Zalcberg, Ryan Schley, Carter Yagemann, Natasha Phan, Srikar Maduposu, Vimal Buck

Military Cyber Affairs

Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public safety consequences. However, attributing ransomware incidents to specific threat actors remains challenging due to ransomware-as-a-service ecosystems, actor rebranding, and the obfuscation of traditional indicators of compromise. This paper presents Semantic Shields, an NLP-driven attribution framework that leverages BERT-generated semantic embeddings and DBSCAN clustering to profile ransomware actors through the linguistic characteristics of ransom notes. Using a dataset of 295 ransom notes from 189 distinct threat groups, the framework achieved an 87.2% true positive clustering rate and …


From Dissertation To Deployment: A Unified Software Platform Operationalizing Clinical-Prediction And Sequential-Security Ai For Healthcare, Olsi Shehu, Damiana Teliti, Jasmin Kevrić, Bekir Karlik 2026 International Burch University, Sarajevo

From Dissertation To Deployment: A Unified Software Platform Operationalizing Clinical-Prediction And Sequential-Security Ai For Healthcare, Olsi Shehu, Damiana Teliti, Jasmin Kevrić, Bekir Karlik

Communications of the IIMA

Advances in machine learning for healthcare are abundant, yet most validated models remain confined to research notebooks and never reach secure, usable clinical software. This paper addresses that deployment gap by presenting a unified, security-hardened software platform that operationalizes two complementary streams of doctoral research inside a single, role-based hospital information system. The first stream contributes a clinical-prediction capability: an ultra-hybrid ensemble that couples a quantum-inspired feature transformation, particle-swarm feature selection, and calibrated soft voting for cancer-outcome prediction (96.41% accuracy, AUC-ROC 0.983 on TCGA-BRCA), survival stratification, multi-cancer generalization, and pharmacogenomic drug-response classification (89.31% mean accuracy across 25 compounds). The second …


Prune: A Patching Based Repair Framework For Certifiable And Privacy-Robust Unlearning Of Neural Networks, Xuran Li, Jingyi Wang, Xiaohan Yuan, Peixin ZHANG 2026 Singapore Management University

Prune: A Patching Based Repair Framework For Certifiable And Privacy-Robust Unlearning Of Neural Networks, Xuran Li, Jingyi Wang, Xiaohan Yuan, Peixin Zhang

Research Collection School Of Computing and Information Systems

Machine unlearning has emerged as a key mechanism for enabling the “right to be forgotten” in neural network models, allowing the selective removal of specific training data upon request. Existing approaches typically rely on retraining models with the remaining data, which is computationally expensive and difficult to verify, especially when deployed models are distributed or resource-constrained. To address this challenge, our prior conference work introduced PRUNE, a patching-based framework that formulates unlearning as a neural network repair problem. PRUNE achieves targeted forgetting by learning lightweight patch networks that redirect model predictions on the data to be unlearned while preserving performance …


Clinic-In-A-Box: A Portable, Software-Defined Cyber Range For Realistic, Scenario-Based Cybersecurity Training, Ethan Chumley, Aaron Nair, Royce Yaezenko, Joshua Payne, Veronika Kyles, Paul Wagner, Robert J. Honomichl, Ryan Straight, Shengjie Xu 2026 University of Arizona

Clinic-In-A-Box: A Portable, Software-Defined Cyber Range For Realistic, Scenario-Based Cybersecurity Training, Ethan Chumley, Aaron Nair, Royce Yaezenko, Joshua Payne, Veronika Kyles, Paul Wagner, Robert J. Honomichl, Ryan Straight, Shengjie Xu

Journal of Cybersecurity Education, Research and Practice

Realistic, hands-on cybersecurity training has traditionally depended on fixed infrastructure such as dedicated lab hardware, cloud subscriptions, or permanent network connectivity, limiting where and how often it can be delivered. This paper presents the design and implementation of a portable, scenario-based cybersecurity training platform housed in a single travel case and built from commodity hardware, type-1 hypervisor virtualization, containerized service orchestration, and software-defined networking. The platform clones, isolates, and resets complete lab environments on demand, allowing the same physical system to support repeated classroom, workshop, or field deployments with minimal manual reconfiguration. Training scenarios are grounded in generated organizational profiles …


Between Digital Transformation And Regulatory Vacuum: Cybersecurity Of Public Services In Mozambique, Faztudo Languisse Eng. 2026 Instituto Superior Politécnico de Tete

Between Digital Transformation And Regulatory Vacuum: Cybersecurity Of Public Services In Mozambique, Faztudo Languisse Eng.

Journal of Cybersecurity Education, Research and Practice

The rapid expansion of digital public services in Mozambique—including e-government platforms, digital health systems, and electronic tax administration—has outpaced the development of a coherent legal framework for cybersecurity. While Law No. 3/2017 (Electronic Transactions Law) of 9 January 2017 introduced foundational data-protection principles, Mozambique long lacked a dedicated cybersecurity regulatory authority, mandatory security standards, and formal incident-notification mechanisms. This regulatory vacuum exposed critical public services to escalating cyber risks as digital transformation was actively promoted as a development priority. This article examines the legal and institutional gaps in Mozambique's cybersecurity governance framework prior to the 2026 Cybersecurity and Cybercrime Laws, …


Self Efficacy And Instructional Support Predict Cyber Deception Acceptance In Ics And Ot Cybersecurity, Daniel Ward 2026 Southern New Hampshire University

Self Efficacy And Instructional Support Predict Cyber Deception Acceptance In Ics And Ot Cybersecurity, Daniel Ward

Journal of Cybersecurity Education, Research and Practice

Cyber deception can produce high-confidence evidence of unauthorized activity in industrial control systems (ICS) and operational technology (OT), but practitioners must consider the technology useful, safe, understandable, and supported before they will use it. This study reports a secondary quantitative analysis of a deidentified survey of United States-based ICS and OT professionals to determine whether psychological and instructional factors predict adoption readiness and effective utilization beyond education, experience, and sector. Hierarchical ordinary least squares regression with HC3 robust standard errors was conducted on 262 complete cases. The demographics-only model was not significant and explained 2.8 percent of outcome variance. Adding …


Opengrcrmf: A Vendor-Neutral Framework For Teaching And Modeling Rmf Automation, Continuous Authorization, And Zero Trust Governance, Anand Janjal 2026 CyberSecurity Subject Matter Expert

Opengrcrmf: A Vendor-Neutral Framework For Teaching And Modeling Rmf Automation, Continuous Authorization, And Zero Trust Governance, Anand Janjal

Journal of Cybersecurity Education, Research and Practice

Abstract—Federal and regulated organizations continue to rely on document-centric Authorization to Operate (ATO) processes even as the NIST Risk Management Framework (RMF), continuous monitoring guidance, Zero Trust Architecture (ZTA), and continuous authorization initiatives require more continuous, evidence-driven risk management [1]-[3], [13], [15]. Manual System Security Plan (SSP) updates, spreadsheet-based Plan of Action and Milestones (POA&M) tracking, and disconnected assessment evidence create governance latency: the delay between operational security events and authorization-ready governance response. This paper presents OpenGRCRMF, a proposed open, vendor-neutral reference framework that models RMF lifecycle activities as workflow states, treats authorization artifacts as structured governance objects, and …


Personal Authenticity For Engagement And Transfer In Introductory Cybersecurity Education, Daniel T. Hickey, Ronald J. Kantor 2026 Indiana University - Bloomington

Personal Authenticity For Engagement And Transfer In Introductory Cybersecurity Education, Daniel T. Hickey, Ronald J. Kantor

Journal of Cybersecurity Education, Research and Practice

Abstract—This conceptual/theoretical paper explores how personal authenticity might promote generative learning in introductory cybersecurity courses. Generative learning transfers confidently to future educational, professional, personal, and testing situations. This cycle of design-based research addresses the concern that more typical professionally authentic contexts (e.g., hospitals, banks, etc.) may be alien and overwhelming to many students, particularly those in introductory courses and/or from non-professional families and communities. If so, this leads to “inert” knowledge that does not transfer. Personal authenticity is rooted in expansive framing, a modern theory of learning transfer. We reframe expansive framing as personal authenticity to make it …


A Return On Investment (Roi) Evaluation Tool For Quantifying The Value Of Cybersecurity Certifications, Nicolas Meysmans, Kelly Hughes 2026 University of Maine at Augusta, Augusta

A Return On Investment (Roi) Evaluation Tool For Quantifying The Value Of Cybersecurity Certifications, Nicolas Meysmans, Kelly Hughes

Journal of Cybersecurity Education, Research and Practice

The growing reliance on cybersecurity certifications has increased the financial and professional stakes associated with certification decision-making for cybersecurity professionals. Despite their widespread use in hiring and career advancement, there is limited objective guidance available to help individuals evaluate the return on investment (ROI) of specific certifications. This gap has created uncertainty regarding which credentials provide the greatest value relative to their cost and market impact. This study presents a data-driven, design science–based tool that supports cybersecurity professionals in evaluating certification ROI using practitioner survey data combined with certification cost and labor-market demand indicators. The paper also demonstrates how such …


From Disruption To Replacement: The 2026 Cae Cybersecurity Community Symposium And The Emerging Federal-Academic Compact For An Ai Workforce, Sunday Oludare Ogunlana 2026 Collin College

From Disruption To Replacement: The 2026 Cae Cybersecurity Community Symposium And The Emerging Federal-Academic Compact For An Ai Workforce, Sunday Oludare Ogunlana

Journal of Cybersecurity Education, Research and Practice

The cybersecurity workforce gap in the United States is estimated at several hundred thousand unfilled positions, and the rapid integration of artificial intelligence into adversary tradecraft and federal cyber operations is widening that gap qualitatively as well as quantitatively, threatening national security and the operational readiness of graduates entering the field. This perspective article synthesizes the principal arguments advanced by five federal and academic speakers at the 2026 CAE Cybersecurity Community Symposium, using verbatim session transcripts, a structured thematic extraction process, and triangulation against published workforce policy and peer-reviewed literature. Findings document a unified speaker thesis that artificial intelligence now …


Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery, Pavan Kumar Satram 2026 Grand Valley State University

Lightweight End-To-End Cryptographic Framework With Semantic Qos For Ar-Based Telesurgery, Pavan Kumar Satram

Masters Theses

This thesis presents the design, implementation, and evaluation of a lightweight end-to-end cryptographic framework integrated with a semantic quality-of-service classification system for augmented reality based telesurgery. Telesurgery can deliver expert surgical care to underserved populations, but adoption has been limited by unresolved cybersecurity, network performance, and resilience challenges. The core tension is that strong encryption adds latency that may exceed the clinical safety threshold, while unencrypted systems remain vulnerable to attacks that could endanger patients during live procedures.

The framework addresses this tension through a dual-edge security middlebox that performs per-flow encryption using semantically selected ciphers: AES-128-GCM for latency-critical haptic …


Navigating Enhanced Exploration Assistance (Nexa), Azhari Abbas, Caleb Fakunle, Ryan Powell, Donovan Livingston 2026 Embry-Riddle Aeronautical University

Navigating Enhanced Exploration Assistance (Nexa), Azhari Abbas, Caleb Fakunle, Ryan Powell, Donovan Livingston

Discovery Day - Daytona Beach

NEXA is an artificial intelligence software platform developed to enhance residential security and property monitoring through seamless integration with autonomous drone systems. This research application of advanced AI in surveillance aims to create a standalone solution capable of real-time threat detection and intelligent alert management. By processing visual and sensory data, NEXA facilitates autonomous drone operation with minimal human intervention. Secure communication channels ensure that instant alerts are delivered to property owners and, potentially, law enforcement, improving response times in security incidents, search-and-rescue operations, and perimeter surveillance. Additionally, NEXA is capable of interfacing with commercially available drone platforms and presents …


A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland 2026 Embry-Riddle Aeronautical University

A Survey On Machine Learning Applications For Operating System Fingerprinting, Siri Siqveland

Discovery Day - Daytona Beach

In the modern age of computers and interconnected networks, cybersecurity and cyber-attackers are evolving in tandem to exploit each other’s vulnerabilities. One technique used by both parties is Operating System Fingerprinting (OSF): with the knowledge of what Operating System a target system is running, innate vulnerabilities can be identified and patched or exploited. Historically, OSF utilizes two main methods: passive and active—the former trades accuracy with undetectability while the latter is generally more detectable but more accurate. However, recent work has combined OSF with Machine Learning (ML) to improve accurate identification. The work presented here is a survey for the …


Closing The Awareness–Behavior Gap: A Role-Based Phishing Training Framework For Higher Education, Ranylene O. Olaybal, Ryan A. Olaybal 2026 Notre Dame of Dadiangas University

Closing The Awareness–Behavior Gap: A Role-Based Phishing Training Framework For Higher Education, Ranylene O. Olaybal, Ryan A. Olaybal

Journal of Cybersecurity Education, Research and Practice

Phishing remains one of the most persistent cybersecurity threats facing higher education institutions, where diverse user populations and highly connected digital environments increase exposure to social engineering attacks. Although cybersecurity awareness initiatives are widely implemented, high awareness does not always translate into secure behavior. This study examined phishing awareness, phishing-related practices, phishing susceptibility, and phishing experiences among college students, teaching faculty, and administrative staff in a private higher education institution in the Philippines. Using a quantitative cross-sectional design, data were collected from 553 respondents through a validated survey instrument and analyzed using descriptive statistics, one-way analysis of variance, Tukey's honestly …


Technique-Level Normalization For Cybersecurity Intelligence: An Empirical Evaluation Of Att&Ck Attribution From Hids Alerts Using Fine-Tuned Transformers And Metadata Re-Ranking, Emad Sherif 2026 De Montfort University

Technique-Level Normalization For Cybersecurity Intelligence: An Empirical Evaluation Of Att&Ck Attribution From Hids Alerts Using Fine-Tuned Transformers And Metadata Re-Ranking, Emad Sherif

International Journal of Cybersecurity Intelligence & Cybercrime

Cybercrime investigations increasingly depend on the ability to interpret large volumes of automated security events. For organizations without dedicated security operations centres, a situation common among small and medium enterprises, the manual translation of raw alerts into structured threat intelligence represents a critical bottleneck that slows investigative triage and limits cross-case comparability. This paper evaluates an automated enrichment pipeline designed to address this bottleneck by mapping security events to standardised adversary behaviour labels drawn from the MITRE ATT&CK framework, supporting both operational response and cybercrime investigation workflows. We compare three pipeline configurations, a general-purpose encoder model, a cybersecurity domain-adapted variant, …


Digital Commons powered by bepress