Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 2 of 201.

Technique-Level Normalization For Cybersecurity Intelligence: An Empirical Evaluation Of Att&Ck Attribution From Hids Alerts Using Fine-Tuned Transformers And Metadata Re-Ranking, Emad Sherif 2026 De Montfort University

Technique-Level Normalization For Cybersecurity Intelligence: An Empirical Evaluation Of Att&Ck Attribution From Hids Alerts Using Fine-Tuned Transformers And Metadata Re-Ranking, Emad Sherif

International Journal of Cybersecurity Intelligence & Cybercrime

Cybercrime investigations increasingly depend on the ability to interpret large volumes of automated security events. For organizations without dedicated security operations centres, a situation common among small and medium enterprises, the manual translation of raw alerts into structured threat intelligence represents a critical bottleneck that slows investigative triage and limits cross-case comparability. This paper evaluates an automated enrichment pipeline designed to address this bottleneck by mapping security events to standardised adversary behaviour labels drawn from the MITRE ATT&CK framework, supporting both operational response and cybercrime investigation workflows. We compare three pipeline configurations, a general-purpose encoder model, a cybersecurity domain-adapted variant, …


Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen 2026 Minnesota State University Moorhead

Evaluating Machine Learning Models On Classification Of Novel Cyber Attacks In The Healthcare Domain, Promise Ehimen

Dissertations, Theses, and Projects

The increasing adoption of the Internet of Medical Things (IoMT) has improved healthcare delivery through connected medical devices while simultaneously expanding the cybersecurity risks facing healthcare organizations. Although machine learning based intrusion detection systems have demonstrated high detection accuracy, their ability to respond reliably to previously unseen cyberattacks remains uncertain. This study investigated how a Neural Network model and a Logistic Regression model classified novel cyberattacks within the IoMT environment. The Neural Network and Logistic Regression models were both trained and tested using a subset of the CICIoMT2024 benchmark dataset. The Neural Network achieved 99.82% test accuracy and a 0.94 …


Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap 2026 Capitol Technical University

Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap

Journal of Cybersecurity Education, Research and Practice

 Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking.  The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from …


Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah McClanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson 2026 Shenandoah University

Escaping The Cyberstorm: A Gamified Social Engineering Training Program, Noah Mcclanahan, Fadi Abu-Amara, Ali Khattab, Travis Jett, Andre Jackson

Journal of Cybersecurity Education, Research and Practice

In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life …


Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry 2026 Pennsylvania State University

Assessment And Evidence Practices In Cybersecurity Education: A Systematic Review (2015–2025), James K. Mayberry

Journal of Cybersecurity Education, Research and Practice

This study presents a PRISMA-based systematic review of 412 cybersecurity education intervention studies, coding assessment methods, evidence types, claimed outcomes, use of established assessment instruments, and artifact availability. Despite frequent claims of skill development and workforce preparation, 45.4% of studies reported no identifiable assessment. Knowledge tests appeared in 11.4% of studies, while performance assessments appeared in 10.2%. From 2015 to 2025, assessment practices remained dominated by post-only designs or no assessment, with no statistically detectable increase in pre/post-capable designs. Use of established assessment instruments was rare, with 94.2% of assessed studies using ad hoc measures or not identifying an established …


Building The Next Cybersecurity Workforce: A Grades 7–12 Curriculum To Close The Cyber Talent Gap, Mohammed A. Salam, Iqbal Shareef, Rich P. Manprisio 2026 Governors State University

Building The Next Cybersecurity Workforce: A Grades 7–12 Curriculum To Close The Cyber Talent Gap, Mohammed A. Salam, Iqbal Shareef, Rich P. Manprisio

Journal of Cybersecurity Education, Research and Practice

In today’s rapidly evolving technological landscape, cyberattacks pose increasing threats, yet a global shortage of cybersecurity and digital forensics professionals leaves industries vulnerable, similar to having too few law enforcement officers in a densely populated city. The judicial system faces rising digital crimes and fraud cases, further strained by the lack of experts to analyze and extract digital evidence. Despite high demand, millions of positions remain unfilled. This paper identifies the root causes of the cybersecurity workforce shortage and proposes a targeted solution: a curriculum for Grades 7–12 designed to foster cybersecurity awareness and interest. The methodology included a comprehensive …


Cybersecurity Governance Of Industrial Iot In Sub-Saharan Africa: Policy Gaps, Threat Landscape, And Lessons From Comparative African Contexts, Faztudo Languisse Eng. 2026 Instituto Superior Politécnico de Tete

Cybersecurity Governance Of Industrial Iot In Sub-Saharan Africa: Policy Gaps, Threat Landscape, And Lessons From Comparative African Contexts, Faztudo Languisse Eng.

Journal of Cybersecurity Education, Research and Practice

The rapid deployment of Industrial Internet of Things (IIoT) systems across Sub-Saharan Africa's extractive, energy, logistics, and agro-industrial sectors has introduced a cybersecurity challenge of growing urgency: industrial networks that were designed for operational efficiency are increasingly exposed to cyber threats for which neither the organizations nor the regulatory frameworks are adequately prepared. This article examines the cybersecurity governance of IIoT systems in a developing African economy, using Mozambique as a primary case study and drawing comparative lessons from South Africa, Rwanda, and Kenya. Through an integrative literature review and documentary analysis of national digital, cybersecurity, and industrial policies, the …


Contemporary Cybersecurity Challenges In Emerging Technologies: A Systematic Literature Analysis, Faztudo Languisse Prof 2026 Instituto Superior Politécnico de Tete

Contemporary Cybersecurity Challenges In Emerging Technologies: A Systematic Literature Analysis, Faztudo Languisse Prof

Journal of Cybersecurity Education, Research and Practice

The accelerating convergence of artificial intelligence (AI), the Internet of Things (IoT), cloud computing, blockchain, and quantum computing has fundamentally transformed the global threat landscape, introducing cybersecurity challenges of unprecedented complexity and scale. This systematic literature review synthesizes findings from peer-reviewed publications, institutional reports, and regulatory documents published primarily between 2020 and 2025 to provide an integrated analysis of contemporary cybersecurity challenges across five key emerging technology domains. The review identifies critical vulnerabilities inherent to each domain, documents the evolution of threat actors and attack methodologies — including AI-powered ransomware, adversarial machine learning, and harvest-now-decrypt-later quantum attacks — and evaluates …


Security Architecture Decision Framework For Endpoint Protection In Resource-Constrained K-12 Environments, Jason Folker 2026 Indiana State Universtiy

Security Architecture Decision Framework For Endpoint Protection In Resource-Constrained K-12 Environments, Jason Folker

Journal of Cybersecurity Education, Research and Practice

K-12 educational institutions face an ongoing challenge in protecting endpoints when budgets and staffing prevent the implementation of standard security best practices. Technology directors routinely make difficult decisions about administrative rights, software controls, and security tooling, but they lack frameworks designed for the constraints and priorities specific to educational environments. This paper develops a security architecture decision framework tailored for K-12 endpoint protection. The framework integrates five weighting dimensions to help technology directors evaluate competing architectural choices. These dimensions include educational impact, security risk reduction, resource requirements, compliance obligations, and operational feasibility. The framework creates structured documentation that helps decision-makers …


Spatiotemporal Sycophancy: Negation-Based Gaslighting In Video Large Language Models, Ziyao TANG, Pengkun JIAO, Bin ZHU, Huiyan QI, Jingjing CHEN, Yu-Gang JIANG 2026 Singapore Management University

Spatiotemporal Sycophancy: Negation-Based Gaslighting In Video Large Language Models, Ziyao Tang, Pengkun Jiao, Bin Zhu, Huiyan Qi, Jingjing Chen, Yu-Gang Jiang

Research Collection School Of Computing and Information Systems

Video Large Language Models (Vid-LLMs) have demonstrated remarkable performance in video understanding tasks, yet their robustness under conversational interaction remains largely underexplored. In this paper, we identify spatiotemporal sycophancy, a failure mode in which Vid-LLMs retract initially correct, visually grounded judgments and conform to misleading user feedback under negation-based gaslighting. Rather than merely changing their answers, the models often fabricate unsupported temporal or spatial explanations to justify incorrect revisions. To systematically investigate this phenomenon, we propose a negation-based gaslighting evaluation framework and introduce GasVideo-1000, a curated benchmark designed to probe spatiotemporal sycophancy with clear visual grounding and temporal reasoning requirements. …


Rendering Data Unlearnable By Exploiting Llm Alignment Mechanisms, Ruihan ZHANG, Jun SUN 2026 Singapore Management University

Rendering Data Unlearnable By Exploiting Llm Alignment Mechanisms, Ruihan Zhang, Jun Sun

Research Collection School Of Computing and Information Systems

Large language models (LLMs) are increasingly trained on massive, heterogeneous text corpora, raising serious concerns about the unauthorised use of proprietary or personal data during model training. In this work, we address the problem of data protection against unwanted model learning in a realistic blackbox setting. We propose Disclaimer Injection, a novel data-level defence that renders text unlearnable to LLMs. Rather than relying on model-side controls or explicit data removal, our approach exploits the models’ own alignment mechanisms: injecting carefully designed alignment-triggers to prevent effective learning. Through layer-wise analysis, we find that finetuning on such protected data induces persistent activation …


Air: Improving Agent Safety Through Incident Response, Zibo XIAO, Jun SUN, Junjie CHEN 2026 Singapore Management University

Air: Improving Agent Safety Through Incident Response, Zibo Xiao, Jun Sun, Junjie Chen

Research Collection School Of Computing and Information Systems

Large Language Model (LLM) agents are increasingly deployed in practice across a wide range of autonomous applications. Yet current safety mechanisms for LLM agents focus almost exclusively on preventing failures in advance, providing limited capabilities for responding to, containing, or recovering from incidents after they inevitably arise. In this work, we introduce AIR, the first incident response framework for LLM agent systems. AIR defines a domain-specific language for managing the incident response lifecycle autonomously in LLM agent systems, and integrates it into the agent's execution loop to (1) detect incidents via semantic checks grounded in the current environment state and …


A Robust Hybrid Security Framework: Integrating Multi-Layered Text Encryption With Barcode-Based Steganography, Mohamed Sayed, Talaat M. Wahbi, Farooq Abdalwahab Haboub 2026 Joaan Bin Jassim Academy for Defense Studies, Qatar

A Robust Hybrid Security Framework: Integrating Multi-Layered Text Encryption With Barcode-Based Steganography, Mohamed Sayed, Talaat M. Wahbi, Farooq Abdalwahab Haboub

BAU Journal - Science and Technology

The widespread use of the Internet is causing increasing security concerns regarding online communications. One method for achieving secure communication between authorized parties is steganography. We herein employ multilevel technologies, including compression, encryption, barcoding, and steganography to secure a secret text message. Type I multilevel steganography is used with a two-level setup. The first level uses enhanced least significant bit (secure LSB-L1) image steganography; the output is a stego-image file, the cover is an image file, and the secret data in this level is English text. The output from the first level is encrypted using the RSA algorithm, and the …


Operationalizing Supply-Chain Hygiene In Graduate Is Education: A Hands-On Module For Secure Software And Ai/Ml Pipelines, Dominic A. Wilson 2026 University of Findlay

Operationalizing Supply-Chain Hygiene In Graduate Is Education: A Hands-On Module For Secure Software And Ai/Ml Pipelines, Dominic A. Wilson

Journal of Cybersecurity Education, Research and Practice

Supply-chain attacks (including typosquatting, dependency confusion, compromised builds, dataset poisoning, and backdoored models) pose growing threats to analytics platforms central to Information Systems (IS). While frameworks like the Secure Software Development Framework (SSDF) and Supply-chain Levels for Software Artifacts (SLSA) offer guidance, IS curricula often lack accessible, infrastructure-light modules that build practical skills for mitigating these risks. This experience report presents a two-week module embedded in a graduate Secure Coding course required for a Master’s in Applied Security and Analytics degree. The module operationalizes secure development habits across both traditional software and machine learning (ML) pipelines. The module addresses a …


The Nist Artificial Intelligence Risk Management Framework: Adoption Challenges And Opportunities, Gillian Kennedy, Devin Patel, Humza Sheikh, Paul Wagner, Robert J. Honomichl 2026 University of Arizona

The Nist Artificial Intelligence Risk Management Framework: Adoption Challenges And Opportunities, Gillian Kennedy, Devin Patel, Humza Sheikh, Paul Wagner, Robert J. Honomichl

Journal of Cybersecurity Education, Research and Practice

Artificial intelligence (AI) is being adopted at an exponential rate to improve efficiency, decision-making, and cybersecurity, but its rapid integration introduces new and often poorly understood risks, including system errors, algorithmic bias, data privacy concerns, security vulnerabilities, and ethical dilemmas. This paper examines how organizations are implementing AI and evaluates the National Institute of Standards and Technology's AI Risk Management Framework (NIST AI RMF) as a tool for managing these risks. It reviews the benefits of AI adoption alongside the risks emerging from its use in business and broader society and examines the legal and ethical challenges organizations face when …


To What Extent Could Quantum Computing Pose A Threat To Global Modern Data Security?, Aniket Maheshwari 2026 Independent Researcher

To What Extent Could Quantum Computing Pose A Threat To Global Modern Data Security?, Aniket Maheshwari

Journal of Cybersecurity Education, Research and Practice

Quantum computing has emerged as a transformative technology with the potential to fundamentally disrupt modern cryptographic systems that underpin global data security. This paper examines the extent to which quantum computing could pose a threat to modern global data security by synthesising existing technical, institutional, and policy-oriented literature. Drawing on a narrative review of scholarly research, industry reports, and government frameworks, the analysis focuses on the implications of quantum algorithms such as Shor’s and Grover’s, which challenge the mathematical foundations of widely used cryptographic schemes. The findings suggest that while quantum computing presents a credible long-term threat to asymmetric encryption …


Data Governance Maturity, Ai Integration, And Equity In Colorado K-12 Public Schools, John R. Curtin 2026 University of Denver

Data Governance Maturity, Ai Integration, And Equity In Colorado K-12 Public Schools, John R. Curtin

Electronic Theses and Dissertations

Colorado's 179 K-12 public school districts operate as autonomous governance units, each responsible for securing and managing student data assets that span health, financial, residential, and academic records. The accelerating integration of artificial intelligence (AI) and machine learning (ML) tools into administrative workflows, productivity software, and instructional platforms has fundamentally altered the risk landscape for student data, yet governance frameworks at the state, district, and school levels have not kept pace. This dissertation investigates whether Colorado's decentralized educational governance structure is institutionally capable of producing equitable, secure, and sustainable data governance outcomes in the AI era.

Drawing on Institutional Theory …


Predicting Cybermindfulness With The Cyber-Health Belief Model, James Robinson, Yan Tian, Thomas Skill 2026 University of Dayton

Predicting Cybermindfulness With The Cyber-Health Belief Model, James Robinson, Yan Tian, Thomas Skill

Journal of Cybersecurity Education, Research and Practice

This study describes the development of a Cyber-Health Belief Model (CHBM). The health belief model (HBM) is a message strategy that is widely and successfully used in public health research [1] and has been extended into phish training. Most phish training programs assume  end users are victimized because they have insufficient information to defend themselves. While near-term training effectiveness has shown to be effective, evidence for sustained behavioral change is thin [4]-[7].  This problem indicates that the traditional approaches need to be reconsidered and that new models are needed.  Recent research suggests attentional deficits, cyber-fatigue and fatalism and a sense …


The Intersection Between Mindfulness And Cybersecurity: A Tool To Reduce Burnout And Improve Operational Effectiveness, Ivo Ricardo Dias Rosa 2026 ISTEC - Instituto Superior de Tecnologias Avançadas

The Intersection Between Mindfulness And Cybersecurity: A Tool To Reduce Burnout And Improve Operational Effectiveness, Ivo Ricardo Dias Rosa

Journal of Cybersecurity Education, Research and Practice

Abstract: This paper offers a conceptual discussion of how mindfulness, understood as present moment awareness and deliberate attention regulation, can support cybersecurity professionals. Drawing on a narrative synthesis of workplace mindfulness, burnout, and high pressure decision making literature, we map plausible self regulation mechanisms to typical cyber defense tasks. Rather than presenting new empirical data, we develop an explanatory framework linking attention, reactivity, and recovery to decision quality, team communication, and adherence to incident playbooks. We focus on two connected outcomes: reducing burnout in roles with sustained cognitive and emotional demands, and improving operational effectiveness during critical situations such as …


Cyber-Ready Libraries, Building Digital Fortresses For Tomorrow, Adeyinka B. Tella, Oluchi Precious Ogbonna Dr, Adebola Aderemi Olatoye Mrs 2026 UNiversity of Ilorin, Nigeria; and University of South Africa

Cyber-Ready Libraries, Building Digital Fortresses For Tomorrow, Adeyinka B. Tella, Oluchi Precious Ogbonna Dr, Adebola Aderemi Olatoye Mrs

Journal of Cybersecurity Education, Research and Practice

Background and Purpose: Libraries are evolving into highly networked information ecosystems in this age of fast digital transformation, which increases their susceptibility to cybersecurity risks. The study "Cyber-Ready Libraries: Building Digital Fortresses for Tomorrow" looks into how prepared libraries are to face cyber threats and considers methods for creating information systems that are safe, robust, and ready for the future. To safeguard digital assets and user data, the study aims to assess existing cybersecurity practices in library settings and offer a roadmap for combining technological, human, and governance solutions.

Design/Method: The existing literature, case studies, and policy frameworks pertaining …


Digital Commons powered by bepress