
Cybersecurity is the basis of information dissemination in the internet age.The Journal of Cyber Security focuses on all aspects of sciences, technologies, and applications relating to hardware security, software security and system security.
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 577-607, 2026, DOI:10.32604/jcs.2026.085303 - 21 August 2026
Abstract A hybrid approach to pseudorandom number generation that couples ensemble learning with the Residue Number System (RNS) is presented in this paper. Unlike conventional deterministic generators that depend solely on direct algorithmic transformation, the proposed method first maps a seed-driven integer sequence into its RNS representation under the coprime moduli set {3, 5, 7, 11}, whose dynamic range is M = 1155, thereby introducing modular non-linearity through a static, stateless feature transformation. A soft-voting ensemble of Logistic Regression, Random Forest, and Support Vector Machine then serves as a decision layer that classifies and re-maps the… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 559-576, 2026, DOI:10.32604/jcs.2026.086559 - 21 August 2026
Abstract Conventional multi-factor and one-time authentication approaches, such as passwords and one-time passwords (OTPs), have become increasingly vulnerable to advanced attack methods, motivating the need for continuous authentication (CA) systems that can verify user identity throughout an active session rather than only at login. For such a system to be effective, it must analyze user behavior reliably and in real time. This paper presents a novel approach to implementing CA on mobile devices using tap and swipe behavioral biometrics combined with machine learning (ML) and multimodal fusion. The dataset was collected from 400 volunteer participants using… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 541-558, 2026, DOI:10.32604/jcs.2026.083592 - 21 August 2026
(This article belongs to the Special Issue: Next-Generation Cyber Defense: Agentic AI, Autonomous Threat Response, and Identity-Aware Security in the Cloud Era)
Abstract Zero-day attacks pose a significant threat to computer systems and networks as they exploit weaknesses that have not been recognized by security professionals or software creators and for which there are no existing protective measures. This study introduced an innovative method for identifying Zero-day attacks through a Recurrent neural network model. To effectively mitigate these risks, not only is continuous monitoring essential, but also the implementation of machine learning. The model was trained on network traffic data and leveraged on the ability of Recurrent Neural Networks (RNNs) to learn complex patterns and identify anomalies that… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 525-539, 2026, DOI:10.32604/jcs.2026.085438 - 21 August 2026
Abstract The widespread adoption of Artificial Intelligence (AI) coding assistants across enterprise software development teams has accelerated delivery velocity while simultaneously introducing a persistent and empirically documented security quality gap in the code these tools produce. Vulnerability classes including insecure output handling, prompt injection constructs, sensitive information disclosure patterns, and cryptographic misuse appear at elevated rates in AI-generated output regardless of model advancement, while organizational governance frameworks have failed to keep pace with the speed of AI tool deployment, creating conditions in which vulnerable code reaches production through informal risk acceptance rather than accountable remediation processes.… More >
Open Access
REVIEW
Journal of Cyber Security, Vol.8, pp. 487-523, 2026, DOI:10.32604/jcs.2026.080111 - 21 August 2026
Abstract Background: Novel cyber threats to organizations have greatly escalated due to the high digitalization rates of organizations, and cybersecurity readiness is a critical capability of organizations and not a technical issue. Although there is increased awareness, most organizations are ill-equipped due to weaknesses in human behavior, governance, leadership commitment, technology infrastructure, and incident response mechanisms. This paper discusses organizational factors that play a major role in cybersecurity readiness. Methods: Primary data from 230 participants were collected using a questionnaire approach and analyzed using IBM SPSS software. The quantitative methods adopted include descriptive statistics, Cronbach’s reliability More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 469-486, 2026, DOI:10.32604/jcs.2026.083943 - 21 August 2026
Abstract The rapid evolution of adversarial cyber threats demands proactive, scalable security testing methodologies capable of producing realistic, organization-specific attack scenarios. Conventional approaches, including manual red-teaming, scripted Breach and Attack Simulation (BAS) platforms, and tabletop exercises, are constrained by high expert dependency, limited scenario variability, and an inability to dynamically adapt to an organization’s unique threat profile. This paper proposes and evaluates a Large Language Model (LLM)-Assisted Threat-Driven Testing System that integrates the MITRE Adversarial Tactics, Techniques, and Common Knowledge (MITRE ATT&CK) framework v14, a structured knowledge base of adversarial tactics, techniques, and procedures (TTPs), with… More >
Open Access
REVIEW
Journal of Cyber Security, Vol.8, pp. 397-468, 2026, DOI:10.32604/jcs.2026.082741 - 06 July 2026
Abstract Ransomware has emerged as one of the most disruptive and financially damaging forms of cybercrime, affecting individuals, enterprises, and critical infrastructures worldwide. Over the past decade, ransomware attacks have evolved from simple file-encryption malware to sophisticated, multi-stage campaigns involving data exfiltration, double extortion, and ransomware-as-a-service (RaaS) ecosystems. In response, a large body of research has proposed diverse techniques for detecting, preventing, mitigating, and recovering from ransomware attacks. This paper presents a comprehensive survey of ransomware research spanning behavioral and runtime detection, machine learning and deep learning-based approaches, network and SDN-based detection, platform-specific defenses for mobile… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 373-396, 2026, DOI:10.32604/jcs.2026.083953 - 01 July 2026
(This article belongs to the Special Issue: Next-Generation Cyber Defense: Agentic AI, Autonomous Threat Response, and Identity-Aware Security in the Cloud Era)
Abstract The rapid proliferation of Internet of Things (IoT) devices across smart homes, healthcare facilities, industrial networks, and smart cities has raised critical security concerns, particularly regarding device authentication. IoT devices are typically characterized by limited computational resources, constrained memory, and restricted energy budgets, which renders the deployment of traditional cryptographic protocols infeasible; consequently, lightweight authentication schemes are required. Although numerous lightweight authentication protocols have been proposed, a systematic risk evaluation of such protocols against established threat modeling frameworks remains largely absent from the existing literature. This paper presents a systematic literature review (SLR) based on… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 357-371, 2026, DOI:10.32604/jcs.2026.084201 - 18 June 2026
Abstract Background: In March 2026, Nigeria’s financial sector experienced a cascading cybersecurity breach that compromised both a commercial bank and the nation’s primary government payment infrastructure. Objective: This paper provides the first academic analysis of the Sterling Bank–Remita chain breach, examining how a single unpatched vulnerability led to the exposure of approximately 900,000 customer records and 3 terabytes of national payment data. Methods: Using open-source intelligence (OSINT) methodology and the MITRE ATT&CK framework (version 16), the attack chain was reconstructed from actor-published artefacts on the spear.cx cybercrime forum, cross-referenced with regulatory statements and vulnerability databases. The… More >
Open Access
REVIEW
Journal of Cyber Security, Vol.8, pp. 319-356, 2026, DOI:10.32604/jcs.2026.080477 - 08 June 2026
Abstract Background: The evolution of modern networked systems in complexity, volume, and diversity has markedly increased the cyber-attack area. Conventional signature-based intrusion detection systems (IDS) will no longer be adequate for identifying advanced threats. A data-driven, adaptive approach that can identify malicious network activity is provided by machine learning (ML) techniques. This review aims to study, compare, and analyze ML-based approaches in IDS and improve the security defense mechanism. Methods: This systematic review followed the PRISMA 2020 guidelines. ML-based IDS peer-reviewed papers were identified from five scientific databases. Abstracts, full texts, and titles were filtered using… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 281-317, 2026, DOI:10.32604/jcs.2026.079750 - 29 May 2026
Abstract Phishing has become the most common cybersecurity threat and increasingly exploits human factors rather than technical vulnerabilities. This study examined the relationships between cybersecurity awareness, training frequency, user cyber-hygiene behaviour, organisational culture, risk perception, and self-reported phishing vulnerability and the theoretical basis of this research is the Technology Threat Avoidance Theory (TTAT). A quantitative correlational design was used for data collection and analysis with Pearson correlation in structured questionnaires. The results indicated that the five independent variables have a significant positive relationship with phishing vulnerability. The increased awareness and regular training correlate with greater recognition… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 241-279, 2026, DOI:10.32604/jcs.2026.075976 - 25 May 2026
Abstract Modern cyberattacks evolve rapidly, overwhelming static and rule-based defenses. This paper proposes GenAI-Powered Autonomous Cyber Offense-Defense, a closed-loop framework in which large language models (LLMs) control both a red-team attacker and a blue-team defender. The agents operate in a simulated enterprise network, generate natural-language rationales for every action, and update defensive policies through a self-adaptive learning loop. We instantiate the framework with LLM-based agents that plan multi-stage attacks, detect anomalies, and autonomously execute containment and hardening actions. In experiments on a three-host virtualized testbed and a scalable multi-node emulation, the adaptive blue agent reduces the More >
Open Access
REVIEW
Journal of Cyber Security, Vol.8, pp. 211-240, 2026, DOI:10.32604/jcs.2026.077850 - 25 May 2026
Abstract The convergence of Operational Technology (OT) and Information Technology (IT) within Critical Infrastructures gives rise to complex and heterogeneous network architectures in the Industrial Internet of Things (IIoT). Traditional Intrusion Detection Systems (IDS), designed for conventional IT environments, are suited for mitigating vulnerabilities inherent in these systems; however, they often fail to address vulnerabilities intrinsic to heterogeneous IIoT architectures, most notably adversarial threats. To address this challenge, this study undertakes a systematic review of 23 representative papers published between 2016 and 2025, analyzing the IIoT-based IDS approaches. Distinguishing itself from existing reviews, this work classifies More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 189-210, 2026, DOI:10.32604/jcs.2026.078232 - 18 May 2026
Abstract The rapid integration of IoT technologies in modern power systems, while enhancing operational efficiency, has introduced critical cybersecurity vulnerabilities. The proliferation of interconnected terminal devices across diverse operational domains has escalated cybersecurity risks, particularly from sophisticated malware attacks targeting critical grid infrastructure. These threats manifest through Application Programming Interface (API) call hijacking, command injection in industrial control protocols, and evasion of conventional signature-based detection systems. To address these challenges, this paper proposes a novel malware detection framework specifically designed for power IoT ecosystems. First, a malware detection model based on long short-term memory network (LSTM)… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 171-187, 2026, DOI:10.32604/jcs.2026.079617 - 15 April 2026
Abstract The Distributed Network Protocol 3 (DNP3) is widely deployed in SCADA-based microgrids; however, it was not originally designed to meet the cybersecurity requirements of modern decentralized energy infrastructures. Although DNP3 Secure Authentication (DNP3-SA) introduces HMAC-based session-level protection, it does not ensure fragment-level integrity, leaving the protocol vulnerable to fragmentation disruption, replay attacks, and sequence manipulation. Such vulnerabilities can cause desynchronization between master and outstation devices, compromising the operational reliability of distributed energy resources. This paper proposes DNP3Chain, a blockchain-enabled framework that provides real-time fragment-level validation and enforces end-to-end message integrity in DNP3 communications. An OpenDNP3-based… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 153-169, 2026, DOI:10.32604/jcs.2026.079097 - 06 April 2026
Abstract The rapid expansion of IoT and cloud services has increased the scale and complexity of modern networks, making intrusion detection challenging. Although deep learning-based Network Intrusion Detection Systems (NIDS) often report high accuracy, such metrics can be misleading on highly imbalanced datasets, where performance is dominated by majority classes and rare attacks remain poorly detected. This issue stems from global optimization strategies that encourage models to rely on dominant feature patterns, limiting their ability to capture the class-specific features required to identify infrequent attack types. To address this limitation, this work proposes a domain knowledge-guided… More >
Open Access
REVIEW
Journal of Cyber Security, Vol.8, pp. 129-151, 2026, DOI:10.32604/jcs.2026.077183 - 11 March 2026
Abstract The rapid digitization of microfinance institutions (MFIs) has strengthened financial inclusion but has simultaneously increased exposure to phishing attacks and other cybersecurity threats driven by organizational, technical, and human vulnerabilities. Grounded in socio-technical systems theory, this systematic analysis evaluates AI-based mitigation strategies, with particular emphasis on gated recurrent unit (GRU) architectures. It compares them with Transformer and LSTM models. GRUs are prioritized due to their computational efficiency and suitability for low-resource environments typical of digital MFIs. Following PRISMA 2020 guidelines, 32 empirical studies published between January 2012 and April 2025 were analyzed from the Web… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 111-127, 2026, DOI:10.32604/jcs.2026.077021 - 24 February 2026
Abstract Mobile payment applications processed trillions of dollars globally in 2024, making them extremely profitable targets for attackers exploiting Android manifest vulnerabilities. Current security solutions demonstrate critical weaknesses; previous hardware-attestation frameworks, such as SafetyNet, demonstrated susceptibility to evasion by sophisticated dynamic instrumentation tools. While the Google Play Integrity API improves upon this baseline, it adds noticeable latency overhead, and traditional code signing cannot detect runtime permission manipulations. This research introduces SM-AAPIV (Split Merkle Android Apps Permissions Integrity Verifier), a novel cryptographic framework that partitions Merkle tree verification across hardware-isolated segments using the Android Keystore, achieving 99.89%… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 93-109, 2026, DOI:10.32604/jcs.2026.074197 - 20 January 2026
Abstract Nowadays, cyberattacks are considered a significant threat not only to the reputation of organizations through the theft of customers’ data or reducing operational throughput, but also to their data ownership and the safety and security of their operations. In recent decades, machine learning techniques have been widely employed in cybersecurity research to detect various types of cyberattacks. In the domain of cybersecurity data, and especially in Trojan detection datasets, it is common for datasets to record multiple statistical measures for a single concept. We referred to them as SWMF features in this paper, which include… More >
Open Access
REVIEW
Journal of Cyber Security, Vol.8, pp. 33-92, 2026, DOI:10.32604/jcs.2026.074265 - 20 January 2026
Abstract The rapid growth of digital payment systems and remote financial services has led to a significant increase in Card-Not-Present (CNP) fraud, which is now the primary source of card-related losses worldwide. Traditional rule-based fraud detection methods are becoming insufficient due to several challenges, including data imbalance, concept drift, privacy concerns, and limited interpretability. In response to these issues, a systematic review of twenty-four CNP fraud detection frameworks developed between 2014 and 2025 was conducted. This review aimed to identify the technologies, strategies, and design considerations necessary for adaptive solutions that align with evolving regulatory standards.… More >
Open Access
ARTICLE
Journal of Cyber Security, Vol.8, pp. 1-31, 2026, DOI:10.32604/jcs.2026.073923 - 07 January 2026
Abstract Federated learning (FL) enables collaborative model training across decentralized datasets, thus maintaining the privacy of training data. However, FL remains vulnerable to malicious actors, posing significant risks in privacy-sensitive domains like healthcare. Previous machine learning trust frameworks, while promising, often rely on resource-intensive blockchain ledgers, introducing computational overhead and metadata leakage risks. To address these limitations, this study presents a novel Decentralized Identity (DID) framework for mutual authentication that establishes verifiable trust among participants in FL without dependence on centralized authorities or high-cost blockchain ledgers. The proposed system leverages Decentralized Identifiers (DIDs) and Verifiable Credentials… More >