
The pressing societal concern for cyber security is highly dependent on the performance of human operators defending critical infrastructure. Cyber security training and Cyber Defence Exercises (CDXs) are increasingly used to improve the skills and awareness of cyber defenders. This paper investigates challenges with measuring and evaluating the impact of CDXs and the potential benefit of introducing Situation Awareness (SA) measurements. First, a systematic literature review identified challenges regarding CDX measures and evaluation. Five main challenges were identified: Defining Wanted Outcomes, Operationalising Human Factors, Choosing Metrics, Data Gathering and Analysis and Assessing Long-term Impact. Second, existing SA measurement methods were reviewed in consideration of their compatibility with the context of CDXs. No currently available SA measurements were found to be compatible. Based on these findings, a discussion is presented focusing on a new proposed outcome of CDXs. If CDXs are used to identify present SA-related challenges, several new opportunities are revealed. A new measurement of SA in CDXs was proposed based on self-rated SA combined with self-reported SA challenges. The proposed method has the potential to identify specific needs for increased domain knowledge and contextual understanding for individuals and teams, identify lacking team communication and coordination and the presence of stress-induced overconfidence in cyber defence responses. This implies that an SA measurement tool should be developed and researched further to validate its benefit for CDX evaluation. We conclude that such a tool might enable the use of CDXs to identify specific training and team development needs of cyber guardians.
Large Language Models (LLMs) offer promising capabilities for enhancing cybersecurity, particularly in generating rules for firewalls and intrusion detection systems (IDS). This study investigates the effectiveness of fine-tuning several LLMs, namely Mistral-7B, LLaMA2-7B, and Qwen2-7B, in generating correct rules for nftables firewall and Snort IDS. Initial experiments assessed multiple Parameter-Efficient Fine-Tuning (PEFT) techniques, including prefix tuning and prompt tuning, on a single model. Based on these results, Low-Rank Adaptation (LoRA) was selected as the most effective approach and subsequently applied to all models for comprehensive evaluation. The performance of these models was compared to assess their rule generation capabilities. Comparative analysis revealed that Qwen2-7B outperforms the other models, achieving a success rate of 85
Differential cryptanalysis, publicly introduced by Eli Biham and Adi Shamir at the CRYPTO’90 conference, is still one of the most used methods for evaluating the security of symmetric-key ciphers, particularly those with round-based structures. A common bottleneck in these attacks is the need to analyse large sets of plaintext–ciphertext pairs, in which only a small fraction contributes to successful key recovery. To reduce this overhead, many attacks apply filtering techniques that aim to discard useless pairs. While filtering is widely applied, its concrete impact on performance has not, to our knowledge, been studied in a systematic and reproducible manner. In this work, we revisit the classical differential attack on the FEAL-8 cipher as a case study to evaluate the role of filtering in practice. We reimplement the attack by Biham and Shamir, analyse the proposed filters for its early stages, and introduce a synthetic perfect filter to estimate upper bounds in reductions without known filters. We observe that filtering can reduce runtime by up to 17× and significantly lower data requirements, particularly in early stages of the attack. These results provide a clear and quantitative picture of filtering’s role in making differential attacks more efficient. Our implementation is publicly available for reproducibility.
Identity Management systems (IdMs) provide digital identities to billions of internet users. They are the foundation of modern information systems and key enablers of access control, security, and privacy. However, IdMs are complex socio-technical systems that require the orchestration of technical, organizational, legal, and human factors to ensure their security, privacy, and resilience. Achieving this is easier said than done, since IdM designers need to navigate the multitude of possible system designs, analyzing their trade-offs and shortcomings. In this context, the lack of a comprehensive body of knowledge on IdMs constitutes a key challenge for IdM design and analysis. We address this issue with a systematic review of the literature to build a comprehensive knowledge base that encompasses technical, organizational, and legal aspects of IdMs. The knowledge base is built on an ontology representing information systems with a focus on entities relevant for threat modeling. We propose a prototype tool that enables the exploration of the knowledge base to help IdM designers analyze their solutions and visualize possible alternative design choices. By connecting design goals and requirements to mitigations and threats, the tool provides practitioners with actionable solutions to harden the system and achieve their security and privacy goals through a threat modeling workflow. This research paper provides academia and industry with a significant contribution through an IdM Knowledge Base to support policymakers, IdM designers, and researchers in creating secure, robust, and privacy-preserving IdMs.
Trust is a critical yet often overlooked factor in network routing, especially in decentralized and dynamic environments such as IoT and ad-hoc networks. The DrATC algorithm addressed this gap by incorporating a comprehensive set of trust characteristics into dynamic routing decisions. In this paper, we propose DrATC+, an extension of the original model that applies the divide et impera (divide and conquer) principle to trust-based routing. DrATC+ enhances resilience and security by splitting messages into segments and routing them through multiple trusted paths, selected based on composite trust evaluations. We present the design and operational workflow of the algorithm, supported by evaluation scenarios. Our results demonstrate that DrATC+ can improve fault tolerance and mitigate the impact of malicious nodes adapting effectively to changing trust conditions. This work lays the foundation for more robust and adaptive trust-aware routing protocols in future networked systems.
In smart homes, remote control of appliances enhances comfort and efficiency but also raises security concerns. While access control policies can restrict access, their configuration and maintenance are often difficult for non-expert users. This paper introduces a logic-based administrative model that simplifies policy specification and maintenance through user and device categorisation. Our approach unifies RBAC, ABAC and hybrid models, with distinct operational and administrative layers specified in a uniform setting. We also identify a simple yet expressive sub-model aligned with usability findings from user studies.
Formal modeling and verification is a powerful and widely adopted tool in the field of cybersecurity. It consists of devising and analyzing abstract models of real-life systems or situations to be evaluated. Creating accurate formal models that faithfully represent reality is crucial for performing meaningful analysis. Due to the diversity of aspects – technical, physical, human, and environmental – that may impact ceremony execution, formal modeling of ceremonies is a challenging task. The objective of our work is to scrutinize an existing formal framework for ceremony modeling and assess its ability to capture unexpected situations caused by faults, errors, negligence, or misbehavior. We analyze the framework’s building components and formulate pragmatic guidelines to assist modelers in designing meaningful, rich ceremony models. We validate our findings on a two-factor authentication case study.
Continuous authentication enhances security by verifying users beyond their initial login. While it mitigates risks of one-time authentication, it often requires ongoing biometric data transmission, raising privacy concerns due to their sensitivity and non-revocability. To address this, we explore privacy-preserving continuous authentication using Zero-Knowledge Proofs (ZKP), which enable verification without revealing biometric data. We developed and evaluated two continuous authentication protocols: one using interactive ZKPs and another using Non-Interactive ZKPs (NIZKPs). Based on existing work, we selected and adapted a suitable one-time biometric authentication protocol, implemented a proof of concept, and tested different training sizes to optimize the trade-off between execution time and performance. With 30 training users, our system achieved a false acceptance rate of 0.0065, false rejection rate of 0.0048, and execution time of 0.1261 s. The NIZKP variant proved significantly faster due to reduced network overhead. Our approach demonstrates that continuous authentication can be made both secure and privacy-preserving, offering a scalable and highly adaptable alternative for existing systems.
The stock market plays a crucial role in shaping the global economy, yet the factors influencing its fluctuations remain a subject of ongoing analysis. In recent years, major stock prices have been increasingly impacted by public figures’ opinions shared on social media. These posts, which can be collected and analyzed without explicit consent, present an opportunity for stock market prediction using Sentiment Analysis. However, this raises ethical concerns and questions about the practicality of such an approach. Our research addresses these issues by utilising a widely recognized Kaggle dataset containing tweets about 25 publicly traded companies. After preprocessing the data, we systematically experimented with various classification algorithms and a transformer model. Our findings revealed that the pretrained bidirectional DistilBERT model achieved the highest accuracy at 82.79
Nicknames for Group Signatures (NGS) is a new signature scheme that extends Group Signatures (GS) with Signatures with Flexible Public Keys (SFPK). Via GS, each member of a group can sign messages on behalf of the group without revealing his identity, except to a designated auditor. Via SFPK, anyone can create new identities for a particular user, enabling anonymous transfers with only the intended recipient able to trace these new identities. To prevent the potential abuses that this anonymity brings, NGS integrates flexible public keys into the GS framework to support auditable transfers. In addition to introducing NGS, we describe its security model and provide a mathematical construction proved secure in the Random Oracle Model. As a practical NGS use case, we build NickHat, a blockchain-based token-exchange prototype system on top of Ethereum.
The European Union's (CRA) establishes a comprehensive regulatory framework designed to enhance the cybersecurity of digital products throughout their entire lifecycle. This paper presents a systematic analysis of the technical and organizational requirements imposed by the CRA, offering a structured overview of its provisions and requirements. From this analysis, we derive an architecture that supports a compliance-by-design approach, enabling the CRA obligations to be met from the early stages of product development. This work fills a gap in the literature by providing a generalizable technical perspective on CRA compliance, supporting developers and manufacturers with a clear list of security requirements and a set of architectural guidelines.
Google Tag Manager (GTM) is a tag manager that allows third-party scripts to be inserted, modified, or deleted on a website from a graphical interface, without having to modify the source code. These tags collect data such as visits, clicks, form submissions, traffic sources, user behavior, and purchase actions. While Google establishes control mechanisms to maintain good practices and comply with the respective legislation, the fact that GTM operates at a more abstract level means that if privacy breaches arise, such as personal data leaks, web publishers would have a hard time detecting them. This paper analyzes the behavior of official GTM tags in a sandbox environment and GTM’s behavior in the wild, looking at the million most popular websites and the tags available to web publishers in the Community Template Gallery. The results reveal flaws in the tool’s permission system, particularly related to the use of the Inject Scripts permission, affecting 62.4
The pressing societal concern for cyber security is highly dependent on the performance of human operators defending critical infrastructure. Cyber security training and Cyber Defence Exercises (CDXs) are increasingly used to improve the skills and awareness of cyber defenders. This paper investigates challenges with measuring and evaluating the impact of CDXs and the potential benefit of introducing Situation Awareness (SA) measurements. First, a systematic literature review identified challenges regarding CDX measures and evaluation. Five main challenges were identified: Defining Wanted Outcomes, Operationalising Human Factors, Choosing Metrics, Data Gathering and Analysis and Assessing Long-term Impact. Second, existing SA measurement methods were reviewed in consideration of their compatibility with the context of CDXs. No currently available SA measurements were found to be compatible. Based on these findings, a discussion is presented focusing on a new proposed outcome of CDXs. If CDXs are used to identify present SA-related challenges, several new opportunities are revealed. A new measurement of SA in CDXs was proposed based on self-rated SA combined with self-reported SA challenges. The proposed method has the potential to identify specific needs for increased domain knowledge and contextual understanding for individuals and teams, identify lacking team communication and coordination and the presence of stress-induced overconfidence in cyber defence responses. This implies that an SA measurement tool should be developed and researched further to validate its benefit for CDX evaluation. We conclude that such a tool might enable the use of CDXs to identify specific training and team development needs of cyber guardians.
Phishing attacks frequently use email body obfuscation to bypass detection filters, but quantitative insights into how techniques are combined and their impact on filter scores remain limited. This paper addresses this gap by empirically investigating the prevalence, co-occurrence patterns, and spam score associations of body obfuscation techniques. Analyzing 386 verified phishing emails, we quantified ten techniques and identified significant pairwise co-occurrences revealing strategic layering. Text in Image (47.0
In this paper we consider the integer factorization problem that constitutes a base of security for cryptographic schemes from the family of solutions based on the Rivest-Shamir-Adleman concept. Apart from quantum Shor’s algorithm, an efficient classical algorithm which enables to solve this problem in polynomial time has not been made so far. The best known classical algorithms carry out factorization in merely subexponential time. We show how a natural extension from the generalized approach to smoothness leads us to the concepts of decomposition witnesses, and on this basis, we present a new approach to elliptic-curve factorization. Instead of assuming that we have the witness of large order, what we did in [8], we assume there is given the set X of witnesses generating large subgroup in G⊂ E(ℤ_N) that have some additional properties. We justify that either X contains the separating witness or the subgroup generated by the set X in E(ℤ_N) is noncyclic. The main result of this paper shows how to factor an integer, which is a product of two primes, in time L( 1-θ _σ (1-β )/σα _0+σα _0 + o(1), r) . This is an improvement as compared to the previous results provided that θ _σ≥(2-2σ +σ ^2)/2(1-β ).
User authentication has evolved from simple password-based procedures to phishing-resistant biometric methods. NIST, in special publication 800-63, provides definitions and requirements for digital identities. However, there is a growing need to also identify and authenticate the device in use. Such information can be included in fine-grained policy decisions to further enhance an enterprise's security posture. In addition, device authentication has been described in the literature as a significant factor in zero trust architectures. Despite the adoption of this security architecture by major stakeholders, device authentication remains lacking. Therefore, we propose extensions to SP 800-63 that cover device identity aspects. In addition, we present a best-of-breed solution using FIDO2 and an extension for OpenID Connect. Our results demonstrate that the integration of device identity aspects is feasible and aligns well with the existing guidelines. The proposed scheme can pave the way for a future where device authentication will become the norm in enterprise networks.
Over the years, the frequency of cybersecurity attacks has surged as cybercriminals continually exploit vulnerabilities to amass profits through the unauthorized acquisition and resale of personal information on the dark web or by demanding ransoms. Fueled by this malicious motivation, researchers have diligently sought innovative methodologies to detect and thwart these cyber threats across various environments. Among the targeted landscapes, Android stands out due to its widespread usage, making it a prime target for attempted attacks. In response to this escalating challenge, in this paper we design and develop a method for identifying malicious and benign system calls through the usage of Deep Learning and an algorithm of Dynamic programming such as the Longest Common Subsequence algorithm. To conduct our research, we meticulously extracted System Calls from Android applications, transforming them into images to create a robust dataset comprising 13,570 samples. With the dataset in hand, we employed four different Convolutional Neural Networks, utilizing them to train and test various models. At the end of this process, our model achieved an accuracy rate of 0.890. To enhance the explainability of our findings, we applied two distinct Class Activation Mapping algorithms. These algorithms help spotlight the most significant areas during the classification process. Once these visual representations were obtained, we merged the original images with the heat maps generated by Class Activation Mapping algorithms. This fusion allowed to identify and extract the most discriminative system calls, providing valuable insights into the distinguishing features between malicious and benign behaviors.
To avoid potential bugs and vulnerabilities, it is crucial to confine process execution within well-defined boundaries, specifying which resources are accessible and what operations are allowed. Numerous technologies have emerged in Linux environments to address process confinement or isolation. However, these solutions often lacked tailored support, leading to a fragmented landscape of complex implementations. Given the need to support different security abstractions, the Extended Berkeley Packet Filter (eBPF) has emerged as a promising technology for extending the capabilities of the Linux kernel functionalities, offering a simple and flexible approach for process confinement. This paper introduces a framework that leverages eBPF to achieve flexible and secure process confinement. We developed a prototype implementation and evaluated its overhead in limiting filesystem capabilities. Experimental findings underscore the effectiveness of our framework, demonstrating that it can seamlessly integrate into Linux systems without incurring remarkable overhead.
In this paper, we propose a dynamic routing algorithm that leverages various trust characteristics to determine the most trusted path in a network. Trust, a multifaceted concept, encompasses attributes such as direct and indirect experiences, transitivity, directionality, context-dependence, and more. Our approach allows the routing protocol to selectively incorporate these characteristics to enhance the decision-making process. For instance, in scenarios prioritizing direct trust, nodes route packets based solely on direct interactions with their neighbors. In more complex scenarios, both direct and indirect trust are considered, utilizing recommendations from trusted nodes to establish trust with previously un-contacted nodes. We also explore the use of alternative routes based on specific trust values, ensuring sensitive data is routed through the most trustworthy paths. By integrating these trust metrics, the proposed algorithm dynamically adapts to varying network conditions and requirements, improving the overall reliability and security of the data transmission. Our experimental results demonstrate the algorithm's effectiveness in selecting trusted paths and highlight the importance of context and adaptability in trust-based routing. This work contributes to the field by providing a flexible and robust framework for incorporating trust into dynamic routing decisions, paving the way for more secure and reliable network communication.
The contemporary cybersecurity landscape faces an ongoing and dynamic threat environment, characterized by the persistent evolution of tactics employed by malicious actors. The detection and mitigation of these threats pose significant challenges, especially when dealing with individuals possessing intimate knowledge of an organization's security measures and vulnerabilities. Intrusion Detection Systems (IDS) play a crucial role in monitoring network traffic and systems for anomalies, providing alerts and defensive actions when suspicious activities are detected. While traditional IDS solutions exist, there is an increasing demand for adaptable and portable intrusion detection mechanisms. Honeypots, deceptive cybersecurity mechanisms designed to lure potential attackers, play a pivotal role in modern cyber-defense. By emulating vulnerable services, the honeypot captures data on the attacker's activities and diverts the attention away from the actual critical systems, enabling the enhancement of the overall network security. We describe the design, implementation and evaluation of a portable honeypot for intrusion detection in a corporate network, able to detect internal and external threats. Portability and platform-independency are ensured using Docker containers with a strong emphasis on security through the implementation of necessary measures to mitigate risk. The system adopts a microservices architecture and utilizes the Grafana stack for log collection, data visualization, and alert management. The study provides insights into security best practices and contributes to the ongoing efforts to strengthen cybersecurity defenses in an evolving threat landscape.