Next Issue
Volume 6, June
Previous Issue
Volume 6, February
 
 

J. Cybersecur. Priv., Volume 6, Issue 2 (April 2026) – 37 articles

Cover Story (view full-size image): Darknet traffic classification is vital for detecting malicious activity in encrypted communications but is challenged by feature redundancy and class imbalance. In this work, we propose a reliability-driven framework that combines Adaptive Weighted Feature Aggregation (AWFA) with Traffic-Aware SMOTE (TA-SMOTE). AWFA selects stable, high-impact features using cross-validated model reliability, while TA-SMOTE generates semantically valid minority samples through controlled perturbations that preserve flow structure. Evaluated in a hierarchical setting, the framework improves macro-F1 while maintaining behavioural integrity. The results show that reliability-aware feature selection with semantics-preserving balancing enables accurate, interpretable, and trustworthy darknet traffic analysis for cybersecurity applications. View this paper
  • Issues are regarded as officially published after their release is announced to the table of contents alert mailing list.
  • You may sign up for e-mail alerts to receive table of contents of newly released issues.
  • PDF is the official format for papers published in both, html and pdf forms. To view the papers in pdf format, click on the "PDF Full-text" link, and use the free Adobe Reader to open them.
Order results
Result details
Section
Select all
Export citation of selected articles as:
29 pages, 1346 KB  
Article
An Ontology-Based Framework for Semantic Representation of the Cyber Range Domain
by Vyron Kampourakis, Michail Takaronis, Vasileios Gkioulos and Sokratis Katsikas
J. Cybersecur. Priv. 2026, 6(2), 76; https://doi.org/10.3390/jcp6020076 - 21 Apr 2026
Cited by 1 | Viewed by 1274
Abstract
Cyber Ranges (CRs) are complex socio-technical ecosystems, combining infrastructure resources, software services, learning mechanisms, and human-in-the-loop processes for cybersecurity training, education, and experimentation. However, their design and representation are conventionally described by diverse architectural representations and a lack of standardization, making them difficult [...] Read more.
Cyber Ranges (CRs) are complex socio-technical ecosystems, combining infrastructure resources, software services, learning mechanisms, and human-in-the-loop processes for cybersecurity training, education, and experimentation. However, their design and representation are conventionally described by diverse architectural representations and a lack of standardization, making them difficult to compare, integrate, and reason in an automated manner. This paper proposes a novel framework that uniquely integrates the structural, functional, informational, and decisional aspects of CR platforms, formalizing them into a common semantic framework. It models the architectural and learning characteristics of CRs, allowing the representation of design choices, operational processes, information resources, and capability development. The ontology is implemented using OWL 2 DL, which includes logical constraints and enables consistency checking and automated reasoning. Validation through instantiation and competency question assessment shows that the model allows for structured querying, traceability across abstraction levels, and capability-level reasoning. The findings indicate that ontology-based modeling can serve as a basis for more formalized CR configuration analysis and capability-focused evaluation of diverse CR platforms. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

27 pages, 28194 KB  
Article
Tracking the Gaze of Secure Coders: Behavioral Insights into Attention, Transitions, and Training
by Daniel Davis and Feng Zhu
J. Cybersecur. Priv. 2026, 6(2), 75; https://doi.org/10.3390/jcp6020075 - 20 Apr 2026
Viewed by 924
Abstract
Secure coding is essential, yet the strategies developers use to detect and mitigate flaws are not well understood. We present an eye-tracking-based approach that captures developers’ visual patterns while reading, coding, and applying security tools. Our framework uses participant-editable stimuli and dynamic environments [...] Read more.
Secure coding is essential, yet the strategies developers use to detect and mitigate flaws are not well understood. We present an eye-tracking-based approach that captures developers’ visual patterns while reading, coding, and applying security tools. Our framework uses participant-editable stimuli and dynamic environments to reflect authentic coding development. By visualizing gaze transitions and attention shifts, we expose how developers allocate effort during secure coding. By leveraging techniques that reveal gaze transitions, attention levels, and pupil size changes, we are able to gain insight into their behavior. Our study provides a fine-grained, process-oriented account of behavior in CWE-based secure coding educational tasks, uncovering attentional patterns and decision timelines that traditional methods may not capture. These contributions provide a foundation for improving training and understanding developer differences. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

23 pages, 1706 KB  
Review
Contextual Integrity in Large Language Models: A Review
by Ahmad Hassanpour and Bian Yang
J. Cybersecur. Priv. 2026, 6(2), 74; https://doi.org/10.3390/jcp6020074 - 15 Apr 2026
Cited by 1 | Viewed by 1889
Abstract
The rapid advancements in large language models (LLMs) have transformed natural language processing, enabling their application in diverse domains such as conversational agents and decision-support systems in sensitive areas like healthcare, finance, and eldercare. However, as LLMs are increasingly integrated into real-world contexts, [...] Read more.
The rapid advancements in large language models (LLMs) have transformed natural language processing, enabling their application in diverse domains such as conversational agents and decision-support systems in sensitive areas like healthcare, finance, and eldercare. However, as LLMs are increasingly integrated into real-world contexts, concerns about their adherence to ethical principles, privacy norms, and contextual expectations have become critical. Privacy preservation is particularly pressing in interactions involving personal or sensitive data, where ensuring that LLMs align with societal norms while mitigating risks of information leakage is essential to fostering trust and ensuring responsible deployment. Contextual integrity (CI) provides a robust framework to address these challenges, emphasizing that information flows should adhere to context-specific social norms. This principle is especially vital in sensitive applications, where LLMs must evaluate roles, information attributes, and transmission principles to maintain ethical behavior. Despite their linguistic proficiency, LLMs often fail to recognize and adapt to nuanced contextual norms, a limitation exacerbated by their probabilistic nature and the biases in their training data, which can lead to inappropriate or harmful outputs. Addressing these shortcomings requires rigorous evaluation methodologies and fine-tuning strategies that embed societal and contextual norms into the models. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

17 pages, 280 KB  
Article
Evaluating the Effectiveness of Information Security Management Systems: An Analysis Framework and Key Metrics
by Safia El Moutaouakil, John Lindström and Karl Andersson
J. Cybersecur. Priv. 2026, 6(2), 73; https://doi.org/10.3390/jcp6020073 - 14 Apr 2026
Viewed by 2079
Abstract
As large scale digitization continues to reform business processes, one critical challenge organizations are currently facing is managing the staggering amount of data flowing. Further, with large datasets comes the added complexity of insuring a cyber secure environment and shielding the information security [...] Read more.
As large scale digitization continues to reform business processes, one critical challenge organizations are currently facing is managing the staggering amount of data flowing. Further, with large datasets comes the added complexity of insuring a cyber secure environment and shielding the information security management system (ISMS) from undesirable manipulations. Today’s drastic rise of cyberattacks urges the need for effective security frameworks to guard against unauthorized access and malicious acts impeding business operations. The latter of which compelled organizations to adopt holistic information security approaches, commonly implemented via ISMS frameworks. Further, to maintain an effective ISMS, ongoing monitoring and measurements are highly required. Considering the aforementioned points, this paper explores how organizations measure the effectiveness of their ISMS focusing on key performance indicators, metrics, and foundational components involved in information security management by categorizing metrics into governance, risk, and incident response as well as determining the maturity level based on ISO alignment, the presence, specificity and automation of KPIs. Based on empirical interviews with eight diverse organizations, the research findings reveal a wide range of maturity among organizations, from those lacking clear defined KPIs to those with sophisticated multi-layered systems. While special attention is paid to incident-response management, companies with a strong ISMS stand out because they use automated and proactive metrics for strategic reporting, whereas companies with a weaker ISMS often do not have organized KPIs and depend on random manual audits. Based on these results, the present work suggests an analysis framework for evaluating ISMS effectiveness. While previous studies have struggled to define clear ISMS measurement practices, this paper aims to provide insights on measurements by identifying the core building blocks of ISMS and revealing how they are evaluated to drive continual ISMS improvement. Full article
(This article belongs to the Special Issue Current Trends in Data Security and Privacy—2nd Edition)
Show Figures

Figure 1

28 pages, 473 KB  
Article
De-Anonymization Techniques in the Tor Network Using an Experimental Testbed
by Ondrej Kainz, Sebastián Petro, Miroslav Michalko, Miroslav Murin and Ervín Šimko
J. Cybersecur. Priv. 2026, 6(2), 72; https://doi.org/10.3390/jcp6020072 - 13 Apr 2026
Cited by 1 | Viewed by 5369
Abstract
Tor is an anonymization network that enables access to hidden services and protects user identity through layered encryption. While its core technology offers strong privacy, users can still be exposed through indirect attack methods or configuration mistakes. This research not only explores de-anonymization [...] Read more.
Tor is an anonymization network that enables access to hidden services and protects user identity through layered encryption. While its core technology offers strong privacy, users can still be exposed through indirect attack methods or configuration mistakes. This research not only explores de-anonymization techniques but also provides a practical guide for constructing a fully functional experimental Tor environment using virtual machines. The custom-built testbed allows for safe simulation of attacks without impacting the public Tor network. Within this environment, three key information-gathering approaches were evaluated: (1) malware-based reverse shells that establish external communication, (2) malicious PDF and Office files used to trigger outbound connections, and (3) analysis of service misconfigurations that may reveal the IP address of hidden services. The results confirm that although the Tor network itself is resilient, user behavior, improper configurations, and insecure content handling can lead to significant privacy risks. By combining practical environment setup with real-world attack scenarios, this paper serves both as a reference for building experimental Tor networks and as a security-oriented analysis of known de-anonymization vectors. The findings emphasize the critical need for user awareness and precise configuration in privacy-focused technologies. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

26 pages, 1413 KB  
Article
A Novel Hybrid Quantum Circuit for Integer Factorization: End-to-End Evaluation in Simulation and Real Quantum Hardware
by Jesse Van Griensven Thé, Victor Oliveira Santos and Bahram Gharabaghi
J. Cybersecur. Priv. 2026, 6(2), 71; https://doi.org/10.3390/jcp6020071 - 10 Apr 2026
Viewed by 1491
Abstract
The literature indicates that the qubit requirements for factoring RSA-2048 remain on the order of 1 million, under commonly assumed architectures and error-correction models, leaving a substantial gap between current resource estimates and near-term practical feasibility. Reducing this requirement to the low-thousand-qubit regime [...] Read more.
The literature indicates that the qubit requirements for factoring RSA-2048 remain on the order of 1 million, under commonly assumed architectures and error-correction models, leaving a substantial gap between current resource estimates and near-term practical feasibility. Reducing this requirement to the low-thousand-qubit regime therefore remains an important open research objective. This work proposes a hybrid classical–quantum algorithm that uses a classical modular exponentiation subroutine with a Quantum Number Theoretic Transform (QNTT) circuit to increase the speed and reduce the required quantum resources relative to Shor’s algorithm for integer factorization, which underpins cryptographic systems like RSA and ECC. We evaluate multiple coprime numbers, the result of multiplication of two primes, in both simulation and real quantum hardware, using IBM’s reference Shor implementation as the baseline. Because Shor and proposed Jesse–Victor–Gharabaghi (JVG) use different register sizes for the same coprime N, the reported gate/depth reductions should be interpreted as end-to-end quantum-resource budgets for factoring the same N, rather than a per-qubit or transform-only efficiency claim. In simulation, the JVG algorithm achieved substantial practical reductions in computational resources, decreasing runtime from 174.1 s to 5.4 s, memory usage from 12.5 GB to 0.27 GB, and quantum gate counts by approximately 99%. On quantum hardware, JVG reduced the required runtime from 67.8 s to 2 s, and the quantum gate counts by over 98%. We showed that the proposed algorithm can address the relevant RSA-1024 case scenario, establishing that this method can provide validation for large-scale situations. Furthermore, extrapolation to RSA-2048 indicates that the JVG algorithm significantly outperforms Shor’s approach, requiring a projected quantum runtime of 29 h for ten thousand runs for factorization under identical scaling assumptions. Overall, these results support JVG as a more hardware-compatible and robust noise-tolerant substitute for Shor’s framework, offering a viable research direction toward practical quantum integer factorization on near-term Noisy Intermediate-Scale Quantum (NISQ) devices. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Figure 1

26 pages, 914 KB  
Article
AI-Amplification Indicator: An Actor-Level Scoring Framework for Ransomware Operations on the Dark Web
by Mostafa Moallim, Seokhee Lee, Ibrahim Alzahrani, Faisal Abdulaziz Alfouzan and Kyounggon Kim
J. Cybersecur. Priv. 2026, 6(2), 70; https://doi.org/10.3390/jcp6020070 - 8 Apr 2026
Viewed by 1620
Abstract
Ransomware operations have evolved from isolated malware incidents into organized ransomware-as-a-service (RaaS) ecosystems that employ coordinated tactics, techniques, and procedures and increasingly rely on automation and artificial intelligence to scale intrusions. However, most assessments remain artifact-centric, focusing on malware signatures or aggregate victim [...] Read more.
Ransomware operations have evolved from isolated malware incidents into organized ransomware-as-a-service (RaaS) ecosystems that employ coordinated tactics, techniques, and procedures and increasingly rely on automation and artificial intelligence to scale intrusions. However, most assessments remain artifact-centric, focusing on malware signatures or aggregate victim counts, which provide limited visibility into differences in actor-level behavior and operational capability. This study introduces the AI-Amplification Indicator (AIAI), an interpretable actor-level scoring framework that transforms publicly observable leak-site disclosures and verifiable open-source evidence into quantitative behavioral profiles. Using continuous monitoring of dark web leak portals, we construct a standardized dataset of ransomware disclosures for 2025 with temporal, geographic, and sector metadata. AIAI measures four complementary dimensions: GenAI-enabled social engineering, operational tempo and orchestration, targeting breadth and diversification, and temporal scaling dynamics. Indicators are computed for all observed actors, while comparative profiling focuses on the ten most active actors to ensure stable behavioral estimation. The analysis reveals substantial heterogeneity in posting cadence, targeting strategies, and scaling dynamics, as well as limited but measurable evidence of automated or AI-assisted deception. These differences are not captured by victim counts alone. The proposed framework provides a transparent and reproducible approach for actor-level ransomware intelligence, enabling systematic comparison of operational styles and supporting data-driven defensive prioritization. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

25 pages, 2957 KB  
Article
Automating the Detection of Evasive Windows Malware: An Evaluated YARA Rule Library for Anti-VM and Anti-Sandbox Techniques
by Sebastien Kanj, Gorka Vila and Josep Pegueroles
J. Cybersecur. Priv. 2026, 6(2), 69; https://doi.org/10.3390/jcp6020069 - 8 Apr 2026
Viewed by 3021
Abstract
Anti-analysis techniques, also known as evasive techniques, enable Windows malware to detect and evade dynamic inspection environments, undermining the effectiveness of virtual-machine and sandbox-based inspection. Despite extensive prior research, no unified classification has been paired with a large-scale empirical evaluation of static detection [...] Read more.
Anti-analysis techniques, also known as evasive techniques, enable Windows malware to detect and evade dynamic inspection environments, undermining the effectiveness of virtual-machine and sandbox-based inspection. Despite extensive prior research, no unified classification has been paired with a large-scale empirical evaluation of static detection capabilities for these behaviors. This paper addresses this gap by presenting a comprehensive classification and detection framework. We consolidate 94 anti-analysis techniques from academic, community, and threat-intelligence sources into nine mechanistic categories and derive corresponding YARA rules for static identification. In total, 82 YARA signatures were authored or refined and evaluated on 459,508 malware and 92,508 goodware samples. After iterative refinement using precision thresholds, 42 rules achieved high accuracy (≥75%), 16 showed moderate precision (50–75%), and 24 were discarded due to unreliability. The results indicate strong static detectability for firmware- and BIOS-based checks, but limited precision for timing-based evasions, which frequently overlap with benign behavior. Although YARA provides broad coverage of observable artifacts, its static nature limits detection under obfuscation or runtime mutation; our measurements therefore represent conservative estimates of technique prevalence. All validated rules are released in an open-source repository to support reproducibility, improve incident-response workflows, and strengthen prevention and mitigation against real-world threats. Future work will explore hybrid validation, container-evasion extensions, and forensic attribution based on signature co-occurrence patterns. Full article
(This article belongs to the Special Issue Intrusion/Malware Detection and Prevention in Networks—2nd Edition)
Show Figures

Figure 1

29 pages, 3152 KB  
Article
Enhancing Darknet Traffic Classification: Integrating Traffic-Aware SMOTE and Adaptive Weighted Feature Aggregation
by Javeriah Saleem, Rafiqul Islam, Irfan Altas and Md Zahidul Islam
J. Cybersecur. Priv. 2026, 6(2), 68; https://doi.org/10.3390/jcp6020068 - 7 Apr 2026
Cited by 1 | Viewed by 1119
Abstract
With the widespread adoption of anonymity networks such as Tor, I2P, and JonDonym, reliably classifying darknet traffic remains challenging due to feature redundancy and severe class imbalance in encrypted flows. Existing approaches often rely on static feature-selection strategies and generic oversampling methods, which [...] Read more.
With the widespread adoption of anonymity networks such as Tor, I2P, and JonDonym, reliably classifying darknet traffic remains challenging due to feature redundancy and severe class imbalance in encrypted flows. Existing approaches often rely on static feature-selection strategies and generic oversampling methods, which limit robustness and may distort traffic semantics. This study proposes an adaptive classification framework integrating Adaptive Weighted Feature Aggregation (AWFA) for reliability-aware feature selection and Traffic-Aware SMOTE (TA-SMOTE) for semantically constrained perturbations of packet-size and timing features while preserving flow-level structure. The framework is evaluated on a two-layer hierarchy comprising browser-level (L1) and application-level (L2) classification. At the L2, the proposed AWFA and TA-SMOTE pipeline attains a macro-F1 score of 73.81%, significantly exceeding PCA-based reduction and traditional RF-based selection with SMOTE. At the browser level (L1), macro-F1 rises from 91.58% to 96.09% while reducing the feature space from 84 to 40 attributes, highlighting both performance improvements and structural efficiency gains. Additional semantic validation confirms that the balancing process preserves the statistical and structural characteristics of genuine darknet traffic. These results indicate that reliability-aware feature aggregation and traffic-aware balancing provide a practical, trustworthy approach to modern darknet traffic classification. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

29 pages, 1206 KB  
Article
An Evidence-Based Architecture for Trustworthy Asset Discovery in Cybersecurity-Critical IT Environments
by Ivana Ogrizek Biškupić, Mislav Balković and Ivan Bencarić
J. Cybersecur. Priv. 2026, 6(2), 67; https://doi.org/10.3390/jcp6020067 - 7 Apr 2026
Viewed by 1464
Abstract
Asset discovery is a fundamental but inherently flawed capability in cybersecurity, as current methodologies frequently confuse preliminary discovery observations with definitive asset inventories, thereby obscuring uncertainty, restricting auditability, and eroding trust in security-critical decision-making. This work addresses the issue of inconsistent asset identification [...] Read more.
Asset discovery is a fundamental but inherently flawed capability in cybersecurity, as current methodologies frequently confuse preliminary discovery observations with definitive asset inventories, thereby obscuring uncertainty, restricting auditability, and eroding trust in security-critical decision-making. This work addresses the issue of inconsistent asset identification in dynamic IT settings by presenting an evidence-based architectural paradigm that clearly distinguishes observation, identity resolution, and inventory representation. The principal research aim is to develop and authenticate an architecture that maintains discovery evidence, facilitates deterministic, verifiable identity resolution, and supports interpretable inventory derivation. In contrast to state-centric and model-driven methodologies, the proposed architecture enhances (i) traceability through the preservation of time-scoped, method-attributed observations, (ii) identity continuity amidst dynamic conditions such as IP reassignment and infrastructure modifications, and (iii) auditability by facilitating the reconstruction of inventory claims from foundational evidence. An examined proof-of-concept implementation in a controlled yet realistic network environment shows superior identity stability, greater discovery traceability, and retention of historical context relative to traditional inventory models. The results validate the practicality and architectural benefits of the strategy; nevertheless, the evaluation is constrained by a lack of formalised performance indicators and adversarial robustness, which are recognised as priorities for further investigation. Full article
(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity)
Show Figures

Figure 1

15 pages, 275 KB  
Article
Deciding on Cybersecurity Awareness Initiatives: Insights from the Public Sector
by Joakim Kävrestad, Erik Bergström, Rebecca Gunnarsson, Ali Mazeh and Linus Stenlund
J. Cybersecur. Priv. 2026, 6(2), 66; https://doi.org/10.3390/jcp6020066 - 6 Apr 2026
Viewed by 1331
Abstract
Raising cybersecurity awareness (CSA) of employees is crucial for all modern organisations. To meet the organisational need for CSA, activities aimed at increasing CSA have been the focus of both industry and research in the past. There are, subsequently, a plethora of CSA [...] Read more.
Raising cybersecurity awareness (CSA) of employees is crucial for all modern organisations. To meet the organisational need for CSA, activities aimed at increasing CSA have been the focus of both industry and research in the past. There are, subsequently, a plethora of CSA activities for organisations to choose from. Nevertheless, research consistently reports that organisations struggle to raise CSA to an appropriate level, and a core issue lies in their ability to select CSA activities and effectively adopt them. This paper used semi-structured interviews with practitioners working on CSA adoption in public-sector organisations to identify what practitioners perceive as success factors. The interviews were analysed through a socio-technical lens and resulted in a taxonomy that groups success factors for CSA adoption in the three socio-technical dimensions: organisational, user-centric, and technical. The taxonomy outlines ten success factors and demonstrates how the participants see success of CSA activities as not only dependent on technical factors but also, and perhaps even more important, user-adaptability and organisational readiness. The results were validated in a workshop with CSA experts across Europe, who highlighted the practical usefulness of the taxonomy as both a map of potential challenges and a teaching tool for educating new CSA practitioners. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

21 pages, 1172 KB  
Article
An Examination of LPWAN Security in Maritime Applications
by Zachary Larkin and Chuck Easttom
J. Cybersecur. Priv. 2026, 6(2), 65; https://doi.org/10.3390/jcp6020065 - 3 Apr 2026
Cited by 1 | Viewed by 998
Abstract
LoRaWAN’s role in global maritime logistics has allowed for efficient monitoring of ships and cargo, but it also comes with critical cybersecurity vulnerabilities. Experimental validation of three attack vectors—replay attacks, narrowband jamming and metadata inference—is conducted using a reproducible digital-twin LoRaWAN dataset reflecting [...] Read more.
LoRaWAN’s role in global maritime logistics has allowed for efficient monitoring of ships and cargo, but it also comes with critical cybersecurity vulnerabilities. Experimental validation of three attack vectors—replay attacks, narrowband jamming and metadata inference—is conducted using a reproducible digital-twin LoRaWAN dataset reflecting Rotterdam port-like operational patterns (N = 20,000 baseline transmissions). Using controlled simulations and Kolmogorov–Smirnov statistical analysis, we show that: (1) replay attacks are feasible under Activation by Personalization (ABP) configurations lacking enforced frame-counter validation and exhibit no univariate separation from legitimate traffic under Kolmogorov–Smirnov analysis (p > 0.46 for all evaluated radio features); (2) narrowband jamming leads to significant SNR degradation (p = 2.36 × 10−5) on targeted channels without inducing broad distributional anomalies across other radio features; and (3) metadata-only analysis supports elevated metadata-based re-identification susceptibility (median Rd=0.834), indicating high predictability under passive observation which can reveal operationally relevant signals even when AES-128 is employed. Our proposed layered mitigation framework consists of mandatory Over-the-Air Activation (OTAA), cryptographic key rotation, channel diversity incorporating Adaptive Data Rate (ADR), gateway hardening, and protocol-level enforcement considerations, customized for maritime LPWAN scenarios. We provide experiment-backed evidence and actionable recommendations to connect academic LPWAN security research to that of industrial maritime practice. Full article
(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity)
Show Figures

Figure 1

21 pages, 3346 KB  
Article
Hybrid-Pipeline-Based Detection and Classification of HTTP Slow Denial-of-Service Attacks Using Radial Basis Function Neural Networks
by Bashaer H. Alrashid, Mazen Alwadi and Qasem Abu Al-Haija
J. Cybersecur. Priv. 2026, 6(2), 64; https://doi.org/10.3390/jcp6020064 - 2 Apr 2026
Cited by 1 | Viewed by 1106
Abstract
Detecting denial of service traffic remains challenging when malicious sessions exhibit flow characteristics that closely resemble benign network behavior, particularly in low-rate attack settings. This study examines whether autoencoder-based feature compression can improve flow-based intrusion detection while maintaining a deployment-oriented design. We develop [...] Read more.
Detecting denial of service traffic remains challenging when malicious sessions exhibit flow characteristics that closely resemble benign network behavior, particularly in low-rate attack settings. This study examines whether autoencoder-based feature compression can improve flow-based intrusion detection while maintaining a deployment-oriented design. We develop a lightweight pipeline that learns a low-dimensional latent representation of tabular flow features using an autoencoder and performs classification using Random Forest, LightGBM, and a radial basis function neural network. Using the CICIDS 2017 dataset, the best performing configurations achieve 99.43 percent accuracy with autoencoder plus Random Forest and 99.39 percent with autoencoder plus LightGBM, while autoencoder plus radial basis function neural network achieves 98.27 percent, with consistently strong precision, recall, and F1-score. The findings support practice by showing that high detection performance can be achieved using compact learned features that reduce input complexity for downstream models, which is beneficial for operational monitoring environments. The study advances knowledge by providing a reproducible evaluation of representation learning as a feature compression step for tabular intrusion detection, and by linking model performance to measurable computational considerations relevant to real-world deployment. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

28 pages, 495 KB  
Review
Securing the Cognitive Layer: A Survey on Security Threats, Defenses, and Privacy-Preserving Architectures for LLM-IoT Integration
by Ayan Joshi and Sabur Baidya
J. Cybersecur. Priv. 2026, 6(2), 63; https://doi.org/10.3390/jcp6020063 - 2 Apr 2026
Cited by 3 | Viewed by 2895
Abstract
The convergence of Large Language Models (LLMs) and Internet of Things (IoT) systems has created a new class of intelligent applications across healthcare, industrial automation, smart cities, and connected homes. However, this integration introduces a complex and largely underexplored security landscape. LLMs deployed [...] Read more.
The convergence of Large Language Models (LLMs) and Internet of Things (IoT) systems has created a new class of intelligent applications across healthcare, industrial automation, smart cities, and connected homes. However, this integration introduces a complex and largely underexplored security landscape. LLMs deployed in IoT contexts face threats spanning both the AI and embedded systems domains, including prompt injection through sensor-driven inputs, model extraction from edge devices, data poisoning of IoT data streams, and privacy leakage through LLM-generated responses grounded in personal data. Simultaneously, LLMs are proving to be powerful tools for IoT security, with LLM-based intrusion detection systems achieving 95–99% accuracy on standard IoT datasets and LLM-driven threat intelligence outperforming traditional machine learning by significant margins. We systematically review 88 papers from IEEE, ACM, MDPI, and arXiv (2020–2025), providing: (1) a structured taxonomy of security threats targeting LLM-IoT systems, (2) a review of LLMs as security enablers for IoT, (3) an evaluation of privacy-preserving architectures including federated learning, differential privacy, homomorphic encryption, and trusted execution environments, (4) domain-specific security analysis across healthcare, industrial, smart home, smart grid, and vehicular IoT, and (5) a literature-based comparative analysis of LLM-based security systems. A central finding is the accuracy–efficiency–privacy trilemma: the model compression techniques needed to deploy LLMs on resource-constrained IoT devices can degrade security and even introduce new vulnerabilities. Our analysis provides researchers and practitioners with a structured understanding of both the risks and opportunities at the frontier of LLM-IoT security. Full article
Show Figures

Figure 1

17 pages, 561 KB  
Article
Assessing Information Privacy Awareness, Expectations, and Confidence of Students: Evidence from a Diagnostic Survey in a Developing Country’s Higher Education Sector
by Kudakwashe Maguraushe, Adéle Da Veiga and Nico Martins
J. Cybersecur. Priv. 2026, 6(2), 62; https://doi.org/10.3390/jcp6020062 - 2 Apr 2026
Viewed by 924
Abstract
The protection of personal information has become a defining challenge for higher education institutions, particularly in developing contexts where regulatory frameworks are often strong on paper but weak in practice. This study investigates student perceptions of privacy within Zimbabwe’s higher education system, focusing [...] Read more.
The protection of personal information has become a defining challenge for higher education institutions, particularly in developing contexts where regulatory frameworks are often strong on paper but weak in practice. This study investigates student perceptions of privacy within Zimbabwe’s higher education system, focusing on three constructs: awareness, expectations, and confidence across nine core privacy components derived from international principles (FIPPs, OECD, GDPR) and the Zimbabwe Data Protection Act (ZDPA). Using survey data from 287 students across diverse programmes and modes of study, descriptive and comparative analyses reveal a striking pattern: students demonstrate high awareness and very strong expectations, yet their confidence in institutional compliance remains significantly lower. The largest deficits were found in privacy education, consent, and notice/openness, suggesting that institutions are perceived as technically competent in data handling but weak in transparency, accountability, and student engagement. The research extends privacy perception models by considering the discrepancy between the students’ expectations and the institutional trust. It also encourages universities to go beyond mere compliance by implementing concrete measures such as privacy training, clear consent, and frequent data audits. The findings contribute to global debates on privacy by offering evidence from the Global South, showing that the key challenge is not student ignorance but institutional trustworthiness. Bridging this awareness-confidence gap is essential for building a privacy-conscious academic environment. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

26 pages, 1444 KB  
Article
Evaluating the Operational Impact of Automated Endpoint Compliance and Security Monitoring in Linux Environments
by Zlatan Morić, Mislav Balković and Donis Isić
J. Cybersecur. Priv. 2026, 6(2), 61; https://doi.org/10.3390/jcp6020061 - 2 Apr 2026
Cited by 1 | Viewed by 1464
Abstract
Ensuring ongoing endpoint security compliance across diverse, hybrid IT infrastructures poses a continual operational challenge, especially in enterprise Linux systems, where manual verification methods are difficult to scale and prone to inconsistency. This study offers an empirical assessment of an automated methodology for [...] Read more.
Ensuring ongoing endpoint security compliance across diverse, hybrid IT infrastructures poses a continual operational challenge, especially in enterprise Linux systems, where manual verification methods are difficult to scale and prone to inconsistency. This study offers an empirical assessment of an automated methodology for monitoring endpoint compliance and security, applied within a mid-sized IT consulting firm. The suggested methodology incorporates automated compliance scanning, malware detection, endpoint verification, and remediation utilising open-source technology, all orchestrated through centralised automation and reporting systems. The evaluation follows an observational comparative methodology, contrasting manual compliance operations with automated enforcement across 60 Linux endpoints (30 Fedora and 30 Ubuntu systems) over two equivalent eight-week operational periods. The analysis emphasises operational parameters such as administrative workload, configuration uniformity, and audit preparedness. The findings demonstrate that automation reduced manual compliance-related tasks by roughly 70–80%, enhanced configuration consistency across endpoints through continuous enforcement, and enabled automated production of audit-ready compliance reports. The findings provide concrete evidence that operational security automation can markedly improve endpoint compliance management in business Linux and hybrid IT environments. Full article
(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity)
Show Figures

Figure 1

34 pages, 4190 KB  
Article
Towards Effective Cybersecurity Governance: Jordan Compliance System and Self-Assessment Tools
by Iman Almomani, Shahed Mehdawi and Yazeed Allabadi
J. Cybersecur. Priv. 2026, 6(2), 60; https://doi.org/10.3390/jcp6020060 - 1 Apr 2026
Viewed by 1906
Abstract
Enforcing cybersecurity governance is no longer a choice. It has become essential to protect nations’ safety and economy. In addition to the well-known cybersecurity standards that provide guidelines for implementing security controls, many countries have introduced national cybersecurity frameworks to meet their requirements [...] Read more.
Enforcing cybersecurity governance is no longer a choice. It has become essential to protect nations’ safety and economy. In addition to the well-known cybersecurity standards that provide guidelines for implementing security controls, many countries have introduced national cybersecurity frameworks to meet their requirements and needs. These countries also provide assessment tools to check that organizations comply with these frameworks. This research emphasizes the importance of efficient cybersecurity governance practices, highlighting the Jordanian National Cyber Security Framework (JNCSF) that was announced in 2019. We have chosen this framework because, since its launch, it has not been presented or analyzed thoroughly by any of the existing studies. Moreover, the National Cyber Security Center (NCSC) in Jordan has not announced any public self-assessment tools for organizations to evaluate their compliance with the JNCSF. Therefore, the absence of a structured and publicly available self-assessment mechanism for the JNCSF creates a challenge for organizations in objectively measuring their cybersecurity governance readiness. Accordingly, the main contributions of this paper are to provide a detailed breakdown and discussion of the JNCSF, which supports organizations in Jordan and also shares the JNCSF philosophy regionally and internationally. Additionally, this study introduces an efficient self-assessment tool (named JCCT) that can be used both offline and online. JCCT accurately measures the institution’s cybersecurity compliance against JNCSF and international standards (ISO and NIST), reflecting its current state and the potential impact on its risk profile. Moreover, this paper proposes new compliance score equations based on a comprehensive mathematical model that generally benefits any governance system. The JCCT tool offers rich, interactive, customized dashboards and automatically generates reports with recommended action plans for the organization. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

41 pages, 4416 KB  
Article
A Novel Approach to Sybil Attack Detection in VANETs Using Verifiable Delay Functions and Hierarchical Fog-Cloud Architecture
by Habiba Hadri, Mourad Ouadou and Khalid Minaoui
J. Cybersecur. Priv. 2026, 6(2), 59; https://doi.org/10.3390/jcp6020059 - 1 Apr 2026
Viewed by 1479
Abstract
Vehicular Ad Hoc Networks (VANETs) have become the foundation for the implementation of intelligent transportation systems and new vistas for road safety and traffic efficiency. However, these networks are still susceptible to Sybil attacks, a form of attack that requires malicious entities to [...] Read more.
Vehicular Ad Hoc Networks (VANETs) have become the foundation for the implementation of intelligent transportation systems and new vistas for road safety and traffic efficiency. However, these networks are still susceptible to Sybil attacks, a form of attack that requires malicious entities to create a series of fake identities in order to have an out-of-proportion influence. The present paper puts forth a new Sybil attack detection framework that combines Verifiable Delay Functions (VDFs) in synergistic cooperation with a hierarchical fog-cloud computing structure. Our method does not rely on any additional properties of VDFs but uses them to prove uniqueness computationally, deploying purposefully placed fog nodes for effective localized detection. We mathematically formulate a multi-layered detection algorithm that processes interactions between vehicles on two fog (and cloud) layers to produce suspicion scores using spatiotemporal consistency and VDF challenge-response patterns. Security analysis proves the system’s ability to resist a range of Sybil attack variants with performance evaluation outperforming at detection above 97.8% and false positives below 2.3%. The incorporation of machine learning techniques also extends detection capabilities, and our hybrid VDF-ML method proves better adaptation to the changing attack patterns. Details of implementation and detailed simulations in various traffic situations prove the feasibility and efficiency of our proposed solution to set a new level playing ground for secure VANET communications. Full article
(This article belongs to the Special Issue Intrusion/Malware Detection and Prevention in Networks—2nd Edition)
Show Figures

Figure 1

17 pages, 2196 KB  
Article
Machine Learning-Based Static Ransomware Detection Using PE Header Features and SHAP Interpretation
by Gabryella Barnes and Ahmad Ghafarian
J. Cybersecur. Priv. 2026, 6(2), 58; https://doi.org/10.3390/jcp6020058 - 1 Apr 2026
Viewed by 1887
Abstract
Cybercriminals use advanced techniques to launch an attack against organizations, which causes disruption of normal business activities. The traditional signature-based malware detection methods are not effective in the detection of ransomware. Therefore, the use of machine learning and deep learning for malware detection [...] Read more.
Cybercriminals use advanced techniques to launch an attack against organizations, which causes disruption of normal business activities. The traditional signature-based malware detection methods are not effective in the detection of ransomware. Therefore, the use of machine learning and deep learning for malware detection is becoming a major area of research. There are two types of malware detection strategies, namely, static and dynamic. This work investigates the task-dependent effectiveness of static PE header-based detection by systematically evaluating three binary classification problems of increasing difficulty: ransomware vs. benign, malware vs. benign, and ransomware vs. other malware families. An end-to-end machine learning pipeline is implemented, including dataset-specific preprocessing, class imbalance handling, model training, and evaluation using imbalance-aware metrics. Random Forest, Support Vector Machine, and XGBoost models are assessed across all tasks, with SHAP used to analyze feature contribution and explain performance degradation. The experimental results demonstrate that tree-based ensemble models, particularly XGBoost, achieve strong detection performance when class boundaries are structurally distinct, but they struggle when ransomware must be distinguished from structurally similar malware. The results indicate that static analysis based on PE header features can be a viable approach for pre-execution triage, but they exhibit clear limitations for fine-grained ransomware discrimination. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

25 pages, 1873 KB  
Article
An Empirical Assessment of Digital Forensic Process Reliability Using Integrated ISO/IEC 27037 and 27041 Standards
by Zlatan Morić, Vedran Dakić and Ivana Ogrizek Biškupić
J. Cybersecur. Priv. 2026, 6(2), 57; https://doi.org/10.3390/jcp6020057 - 30 Mar 2026
Cited by 1 | Viewed by 3014
Abstract
The escalating scale and complexity of cybercrime necessitate standardized digital forensic protocols to ensure the integrity and admissibility of digital evidence. This study empirically assesses the use of ISO/IEC 27037 and ISO/IEC 27041 through three real-world digital forensic case studies conducted in organizational [...] Read more.
The escalating scale and complexity of cybercrime necessitate standardized digital forensic protocols to ensure the integrity and admissibility of digital evidence. This study empirically assesses the use of ISO/IEC 27037 and ISO/IEC 27041 through three real-world digital forensic case studies conducted in organizational settings. A multi-case methodology was employed, encompassing a multinational corporate criminal investigation, an internal employee misbehaviour probe, and an examination into mobile- and cloud-based data leaks. The effect of synchronized standard implementation was evaluated using audit-based and quantitative indicators that measure forensic process quality as a system attribute. The findings demonstrate that the systematic implementation of ISO/IEC 27037 and ISO/IEC 27041 improves investigative traceability, documentation quality, and evidentiary robustness. In the worldwide case study, documentation completeness increased by 18%, and all digital evidence was deemed admissible in judicial proceedings, surpassing the institutional baseline admissibility rate of 82%. In other instances, evidence gathered within the same framework was acknowledged in organizational or disciplinary review processes, resulting in similar enhancements in documentation quality and procedural consistency, notwithstanding technological and organizational limitations. The paper develops and empirically substantiates an integrated procedural validation model that connects evidence-handling practices with method and instrument validation. The results indicate that the synchronized implementation of ISO/IEC forensic standards improves the transparency, dependability, and auditability of digital forensic investigations. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

30 pages, 1345 KB  
Article
HyperShield: An Automated Evaluation Platform for Security and Performance Trade-Offs in Virtual Systems
by Faiz Alam, Mohammed Mubeen Mifthak, Sahil Bhalchandra Purohit, Md Shadab, Gregory T. Byrd and Khaled Harfoush
J. Cybersecur. Priv. 2026, 6(2), 56; https://doi.org/10.3390/jcp6020056 - 24 Mar 2026
Viewed by 1012
Abstract
Virtualization is the building block of modern cloud computing infrastructure. However, it remains vulnerable to a range of security threats, including malicious co-located tenants, hypervisor vulnerabilities, and side-channel attacks. These threats are generally mitigated by developing and deploying advanced and complex security solutions [...] Read more.
Virtualization is the building block of modern cloud computing infrastructure. However, it remains vulnerable to a range of security threats, including malicious co-located tenants, hypervisor vulnerabilities, and side-channel attacks. These threats are generally mitigated by developing and deploying advanced and complex security solutions that incur significant performance overhead. Prior work on virtual machines (VMs) and containers has mainly evaluated basic security solutions, such as firewalls, using narrow performance metrics and synthetic models within limited evaluation frameworks. These studies often overlook advanced security modules in both user and kernel space, lack the flexibility to incorporate emerging features, and fail to capture detailed system-level impacts. We address these gaps with HyperShield, an open-source framework for unified security evaluation across VMs and containers that mimics a realistic cloud infrastructure. HyperShield supports advanced security modules in both user and kernel space, providing rich system-level performance metrics for comprehensive evaluation. Our performance evaluation shows that containers generally outperform VMs due to their lower virtualization overhead, achieving a throughput of 9.38 Gb/s compared to 1.98 Gb/s for VMs for our benchmarks. However, VMs’ performance is comparable for kernel-space deployments, as Docker uses the shared kernel space of the Docker bridge, which can result in packet congestion. In latency-sensitive workloads, VM access latency of 14.91 ms is comparable to Docker’s 12.86 ms. In storage benchmarks, FIO, however, VMs outperform Docker due to the overhead of Docker’s layered, copy-on-write file system, whereas VMs leverage optimized virtual block devices with near-native I/O performance. These results highlight performance dependencies on benchmark choice, trade-offs in deploying security workloads between user and kernel space, and the choice of containers and virtual machines as virtualization environments. Therefore, HyperShield provides a comprehensive evaluation toolkit for exploring an optimal security-module deployment strategy. Full article
(This article belongs to the Topic Recent Advances in Security, Privacy, and Trust)
Show Figures

Figure 1

35 pages, 9308 KB  
Article
Tracking Real-Time Anomalies in Cyber–Physical Systems Through Dynamic Behavioral Analysis
by Prashanth Krishnamurthy, Ali Rasteh, Ramesh Karri and Farshad Khorrami
J. Cybersecur. Priv. 2026, 6(2), 55; https://doi.org/10.3390/jcp6020055 - 23 Mar 2026
Cited by 3 | Viewed by 2095
Abstract
Embedded devices in modern power systems offer increased connectivity and remote reprogrammability/reconfigurability. These features along with interconnections between Information Technology (IT) and Operational Technology (OT) networks enable greater agility, reduced operator workload, and enhanced power system performance and capabilities, as well as expanding [...] Read more.
Embedded devices in modern power systems offer increased connectivity and remote reprogrammability/reconfigurability. These features along with interconnections between Information Technology (IT) and Operational Technology (OT) networks enable greater agility, reduced operator workload, and enhanced power system performance and capabilities, as well as expanding the cyber-attack surface. This increased cyber-attack surface, as well as increasingly complex, diverse, and potentially untrustworthy software/hardware supply chains, increases the need for robust real-time monitoring in power systems, and more generally in cyber–physical systems (CPS). We propose a novel framework for real-time monitoring and anomaly detection in CPS, specifically smart grid substations and SCADA systems. The proposed framework enables real-time signal temporal logic condition-based anomaly monitoring by processing raw captured packets from the communication network through a hierarchical semantic extraction and tag processing pipeline into a time series of semantic events and observations, that are then evaluated against expected temporal properties to detect and localize anomalies. We demonstrate the efficacy of our methodology on a hardware in the loop (HITL) testbed under several attack scenarios. The HITL testbed includes multiple physical power system devices (real-time automation controllers and relays) and simulated devices (Phasor Measurement Units—PMUs, relays, Phasor Data Concentrators—PDCs), all interfaced to a dynamic power system simulator. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

20 pages, 1014 KB  
Article
Blockchain as a Cybersecurity Enabler in Federated Networks for Resilience and Interoperability
by Jorge Álvaro González, Ana María Saiz García and Victor Monzon Baeza
J. Cybersecur. Priv. 2026, 6(2), 54; https://doi.org/10.3390/jcp6020054 - 13 Mar 2026
Viewed by 1223
Abstract
In increasingly interconnected tactical environments, cybersecurity, trust, and interoperability must evolve in tandem. Federated Coalition Networks (FCNs) enable multinational cooperation while preserving national sovereignty; however, the secure management of identities, policies, and configurations across coalition domains remains a critical challenge, particularly under adversarial [...] Read more.
In increasingly interconnected tactical environments, cybersecurity, trust, and interoperability must evolve in tandem. Federated Coalition Networks (FCNs) enable multinational cooperation while preserving national sovereignty; however, the secure management of identities, policies, and configurations across coalition domains remains a critical challenge, particularly under adversarial and resource-constrained conditions. This paper proposes a blockchain-enabled management framework aligned with the defense-in-depth paradigm, focusing on management-plane functions such as policy enforcement, public key infrastructure (PKI) management, and auditable governance, rather than time-critical tactical communications. The solution relies on a permissioned blockchain architecture with Byzantine Fault Tolerant consensus, avoiding energy-intensive Proof-of-Work mechanisms and supporting operation under Disconnected, Intermittent, and Low-bandwidth (DIL) conditions. A coalition-level trust-and-governance model is introduced to prevent unilateral control while preserving national autonomy. A realistic use case and a proof-of-concept implementation demonstrate the feasibility of the approach, showing bounded latency, limited energy overhead, and sufficient throughput for FCN management. These results indicate that appropriately tailored blockchain solutions can effectively enhance resilience, trust, and compliance in federated defense networks. Full article
(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity)
Show Figures

Figure 1

33 pages, 1175 KB  
Article
Security Compliance as a Catalyst for Sustainable Partnerships: A Design Science Approach for SMEs
by Francisco Conceição, Manuel Rocha and Fernando Almeida
J. Cybersecur. Priv. 2026, 6(2), 53; https://doi.org/10.3390/jcp6020053 - 13 Mar 2026
Viewed by 1576
Abstract
Small-and-medium-sized enterprises (SMEs) increasingly depend on business partnerships to access markets and scale operations, yet they often face trust barriers during contract formation due to the complexity of the verification of their cybersecurity posture and compliance status by their partners. This problem is [...] Read more.
Small-and-medium-sized enterprises (SMEs) increasingly depend on business partnerships to access markets and scale operations, yet they often face trust barriers during contract formation due to the complexity of the verification of their cybersecurity posture and compliance status by their partners. This problem is intensified by rising regulatory expectations, notably the EU Cyber Resilience Act (CRA), which many SMEs struggle to interpret and operationalize under constraints of budget, skills, and fragmented responsibilities. This study adopts a Design Science Research approach to blueprint and evaluate a lightweight mapping framework that links commonly implemented security controls to CRA requirements and to widely recognized benchmarks (ISO/IEC 27001 and CIS). Grounded in Institutional Theory and Socio-Technical Systems Theory, the artefact translates regulatory obligations into actionable, evidence-backed controls and produces partner-facing outputs that support transparency in negotiations and service level agreements. The framework is iteratively co-created with a multidisciplinary expert community. Expected contributions include a practical mechanism for making cybersecurity maturity visible, accelerating partnership formation, and enabling sustainable interorganizational relationships while remaining feasible for resource-constrained SMEs. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

23 pages, 831 KB  
Article
Security Aspects of Zones and Conduits in IEC 62443
by Martin Gilje Jaatun, Mary Ann Lundteigen, Christoph Thieme, Lars Halvdan Flå, Karin Bernsmed, Roald Lygre and Fredrik Gratte
J. Cybersecur. Priv. 2026, 6(2), 52; https://doi.org/10.3390/jcp6020052 - 12 Mar 2026
Cited by 1 | Viewed by 5086
Abstract
The IEC 62443 standard defines that, based on risk assessment, different parts of an Industrial Automation and Control System (IACS) may have different security levels, and that parts with the same security level can be designated as separate zones. Furthermore, communication between different [...] Read more.
The IEC 62443 standard defines that, based on risk assessment, different parts of an Industrial Automation and Control System (IACS) may have different security levels, and that parts with the same security level can be designated as separate zones. Furthermore, communication between different zones, both intra-IACS and inter-IACS, can be done via conduits. In this article, we argue that zones and particularly conduits can benefit from more detailed discussions of their architecture and implementation. Consequently, as novel contributions we (1) describe detailed principles for implementing conduits; (2) outline a process for connecting zones with potentially different Security Levels (SLs), expressed in the form of a flow chart; and (3) discuss challenges related to the application of zones and conduits in practice. Full article
(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity)
Show Figures

Figure 1

32 pages, 4199 KB  
Article
Beyond Semantic Noise: A Dual-Verification Framework for Thai–English Code-Mixed Malicious Script Detection via XAI-Guided Selective Integration
by Prasert Teppap, Wirot Ponglangka, Panudech Tipauksorn and Prasert Luekhong
J. Cybersecur. Priv. 2026, 6(2), 51; https://doi.org/10.3390/jcp6020051 - 9 Mar 2026
Cited by 1 | Viewed by 2250
Abstract
In the evolving cybersecurity landscape, detecting Thai-English code-mixed malicious scripts within high-trust domains such as governmental and academic portals presents a significant defensive challenge. While Transformer-based architectures excel in semantic parsing, they often exhibit ‘Structural Bias,’ misinterpreting the high-entropy syntax of benign legacy [...] Read more.
In the evolving cybersecurity landscape, detecting Thai-English code-mixed malicious scripts within high-trust domains such as governmental and academic portals presents a significant defensive challenge. While Transformer-based architectures excel in semantic parsing, they often exhibit ‘Structural Bias,’ misinterpreting the high-entropy syntax of benign legacy HyperText Markup Language (HTML) as malicious obfuscation due to inherent ‘Attention Deficit’ in token-limited models. To address this, we propose an Explainable AI (XAI)-Driven Hybrid Architecture grounded in a ‘Selective Integration’ strategy. Unlike traditional hybrid models, our framework mathematically formalizes the fusion process by synergizing context-aware WangChanBERTa embeddings with orthogonal structural statistics through Dempster-Shafer Theory and Conditional Mutual Information (CMI). The proposed model was validated on a high-fidelity corpus, achieving a state-of-the-art F1-score of 0.9908, significantly outperforming standalone Transformers, Random Forest, and unsupervised baselines. XAI diagnostics revealed a ‘Dual-Validation’ mechanism where structural features act as an epistemic anchor. This mechanism effectively triggers a ‘Semantic Veto’ to filter hallucinations caused by benign complexity, achieving a remarkably low False Positive Rate (FPR) of 0.0116. Our findings demonstrate that hybridization is most effective when engineered features provide mathematical orthogonality to semantic embeddings. This work offers a robust, theoretically grounded framework for securing critical digital infrastructures in low-resource linguistic environments. Full article
(This article belongs to the Collection Machine Learning and Data Analytics for Cyber Security)
Show Figures

Figure 1

18 pages, 1286 KB  
Article
Performance Evaluation of Advanced Encryption Standard and Blowfish Encryption on WearOS: Implications for Wearable Device Security
by Sirapat Boonkrong and Papitchaya Kaensawan
J. Cybersecur. Priv. 2026, 6(2), 50; https://doi.org/10.3390/jcp6020050 - 7 Mar 2026
Viewed by 1434
Abstract
In this study, we evaluated the performance of the Advanced Encryption Standard (AES)-128, AES-256, and Blowfish algorithms on WearOS for messages ranging from 8 to 128 bytes, which are typical message sizes for contemporary smartwatch applications. Using a WearOS emulator, we measured encryption [...] Read more.
In this study, we evaluated the performance of the Advanced Encryption Standard (AES)-128, AES-256, and Blowfish algorithms on WearOS for messages ranging from 8 to 128 bytes, which are typical message sizes for contemporary smartwatch applications. Using a WearOS emulator, we measured encryption time, memory usage, central processing unit (CPU) utilization, and battery consumption across 16 messages sizes with 10 repetitions over each configuration. The AES-128 algorithm consistently outperformed the others with approximately 1.0 ms of encryption time at 128 bytes, less than 6 KB memory, and less than 39% peak CPU utilization. The AES-256 algorithm added 25–30% processing overhead and higher energy consumption with negligible extra memory cost. The Blowfish algorithm consumed approximately three times more memory and exhibited the highest battery consumption per operation. It also scales poorly due to its 64-bit block size and large key scheduling approach. In addition, all performance differences are highly statistically significant (p < 0.001). Given the widespread hardware AES acceleration on WearOS devices and memory constraints, AES-128 is recommended as the default symmetric encryption algorithm for confidentiality in smartwatch applications. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Graphical abstract

36 pages, 2037 KB  
Article
Operational Threat Modeling of Adversarial Disturbances in Continuous-Variable Quantum Communication
by José R. Rosas-Bustos, Jesse Van Griensven Thé, Roydon Andrew Fraser, Nadeem Said, Sebastian Ratto Valderrama, Mark Pecen, Alexander Truskovsky and Andy Thanos
J. Cybersecur. Priv. 2026, 6(2), 49; https://doi.org/10.3390/jcp6020049 - 7 Mar 2026
Cited by 1 | Viewed by 1027
Abstract
Continuous-variable quantum communication (CVQC) relies on finite-window estimation of phase space moments, making receiver decisions sensitive to finite measurement resolution, calibration uncertainty, and confidence-calibrated tolerances. This paper develops a receiver-centric threat modeling framework for structured (including adversarial) physical-layer disturbances under finite-sample inference. We [...] Read more.
Continuous-variable quantum communication (CVQC) relies on finite-window estimation of phase space moments, making receiver decisions sensitive to finite measurement resolution, calibration uncertainty, and confidence-calibrated tolerances. This paper develops a receiver-centric threat modeling framework for structured (including adversarial) physical-layer disturbances under finite-sample inference. We introduce an operational taxonomy, reconnaissance, exploratory, and denial-of-service, defined by statistical visibility relative to acceptance regions rather than by assumed physical mechanisms. Using an effective estimator space Gaussian model r^=Gr^+ξ with additive covariance N, we show how distinct mechanisms can be observationally equivalent within finite tolerances and we propose a protocol-agnostic scalar severity coordinate ΔE based on the covariance trace. We derive χ2-based missed-detection expressions and a soft detectability boundary scaling as 1/n, and we corroborate the predicted Pmiss(ν) behavior via Monte Carlo simulations across representative block sizes. The resulting framework clarifies the delimitation from conventional CV-QKD excess noise parameterization and provides a structured basis for monitoring-layer design and comparative threat-taxonomy mapping. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

34 pages, 2208 KB  
Article
Small Language Models for Phishing Website Detection: Cost, Performance, and Privacy Trade-Offs
by Georg Goldenits, Philip König, Sebastian Raubitzek and Andreas Ekelhart
J. Cybersecur. Priv. 2026, 6(2), 48; https://doi.org/10.3390/jcp6020048 - 5 Mar 2026
Cited by 3 | Viewed by 3141
Abstract
Phishing websites pose a major cybersecurity threat, exploiting unsuspecting users and causing significant financial and organisational harm. Traditional machine learning approaches for phishing detection often require extensive feature engineering, continuous retraining, and costly infrastructure maintenance. At the same time, proprietary large language models [...] Read more.
Phishing websites pose a major cybersecurity threat, exploiting unsuspecting users and causing significant financial and organisational harm. Traditional machine learning approaches for phishing detection often require extensive feature engineering, continuous retraining, and costly infrastructure maintenance. At the same time, proprietary large language models (LLMs) have demonstrated strong performance in phishing-related classification tasks, but their operational costs and reliance on external providers limit their practical adoption in many business environments. This paper presents a detection pipeline for malicious websites and investigates the feasibility of Small Language Models (SLMs) using raw HTML code and URLs. A key advantage of these models is that they can be deployed on local infrastructure, providing organisations with greater control over data and operations. We systematically evaluate 15 commonly used SLMs, ranging from 1 billion to 70 billion parameters, benchmarking their classification accuracy, computational requirements, and cost-efficiency. Our results highlight the trade-offs between detection performance and resource consumption. While SLMs underperform compared to state-of-the-art proprietary LLMs, the gap is moderate: the best SLM achieves an F1-score of 0.893 (Llama3.3:70B), compared to 0.929 for GPT-5.2, indicating that open-source models can provide a viable and scalable alternative to external LLM services. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

20 pages, 2485 KB  
Article
Gated Residual Chebyshev KAN for Lightweight IoT DDoS Detection
by Fray L. Becerra-Suarez, Edwin Valencia-Castillo, Ana G. Borrero-Ramírez and Manuel G. Forero
J. Cybersecur. Priv. 2026, 6(2), 47; https://doi.org/10.3390/jcp6020047 - 4 Mar 2026
Viewed by 1437
Abstract
Distributed denial-of-service (DDoS) attacks have become a critical threat to Internet of Things (IoT) infrastructures due to their high traffic dynamics, strong class imbalance, and strict resource constraints at the edge. This paper proposes ChebyKANRes, a lightweight intrusion detection model that combines Chebyshev [...] Read more.
Distributed denial-of-service (DDoS) attacks have become a critical threat to Internet of Things (IoT) infrastructures due to their high traffic dynamics, strong class imbalance, and strict resource constraints at the edge. This paper proposes ChebyKANRes, a lightweight intrusion detection model that combines Chebyshev polynomial expansions to parameterize learnable univariate transformations, a gate mechanism to modulate feature flow, and residual connections to stabilize optimization in deeper KAN-style stacks. Experiments were conducted on the CICIoT2023 dataset focusing on benign traffic and 12 DDoS subtypes, using a reproducible pipeline with stratified splitting, cross-validation (k = 5), and early stopping. The proposed model consistently improves multi-class performance (Accuracy: 0.9983) over an optimized MLP baseline (Accuracy: 0.9641), while maintaining a compact size suitable for edge deployment (≈123 k parameters; ~0.47 MB). Within CICIoT2023 and the evaluated split/training protocol, the proposed ChebyKANRes configuration shows improved imbalance-robust multiclass detection while maintaining a compact model size and comparable batch inference time. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

Previous Issue
Next Issue
Back to TopTop