Nov 2026· Computer Science and Information Technology· 0 citations· 25 references
Abstract
Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and reliability. This study proposes a network-based security information system (NBSIS) designed specifically for CBT environments. The framework integrates layered defense, including pfSense firewalls (FW), Snort intrusion detection, Splunk security information and event management (SIEM), and artificial intelligence (AI)-powered analytics, into a unified architecture. A human-centered dashboard ensures usability for non-technical exam administrators, providing real-time alerts and intuitive controls. Validation through simulated attack scenarios demonstrated strong resilience, with high detection accuracy, reduced false positives, and rapid response times. Comparative analysis against intrusion detection system (IDS)-only and SIEM-only systems confirmed superior performance. The findings highlight NBSIS as a robust, scalable, and adaptive solution that safeguards exam integrity while remaining practical for diverse organizational contexts. This research contributes to computer science by advancing secure architecture, applying AI-driven anomaly detection, and integrating human-computer interaction principles into cybersecurity for education.
Cybersecurity has emerged as a key issue in contemporary computing environments due to an increasing dependence on digital systems and networked infrastructures. By discovering and exploiting vulnerabilities in a controlled and ethical manner, penetration testing has become an essential method for evaluating system security. Reducing cyber risks helps organisations assess their security posture, identify potential vulnerabilities, and implement appropriate defences. This review paper offers a comprehensive overview of the current literature on penetration testing, covering its methodologies, tools, frameworks, and applications across diverse areas, including network security, web application security, and enterprise systems. This study includes findings from various research projects, focusing on the efficacy of both manual and automated testing methodologies, including the application of structured frameworks, vulnerability scanning tools, and exploitation platforms. It also examines how standardised guidelines and methods can ensure that security assessments are systematic and reliable. The review goes into more detail on important topics, such as common attack methods (e.g., man-in-the-middle attacks, packet sniffing, SQL injection, cross-site scripting, and cross-site request forgery), and how to protect against them. It also points out how important automation and ongoing security assessment are becoming for making penetration testing more accurate and efficient. This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk. The paper concludes by highlighting the need for structured, thorough penetration testing and advocating further research into advanced, automated security testing to address new cyber threats.
Cybersecurity threats in academic institutions continue to increase, requiring layered protection mechanisms to secure academic services, student records, and research data from unauthorized modification. This study aims to analyze the effectiveness of File Integrity Monitoring (FIM) using Wazuh Security Information and Event Management (SIEM) as a host-based security layer within a Defense in Depth strategy. The research employed the PPDIOO (Prepare, Plan, Design, Implement, Operate, Optimize) methodology because it provides a systematic lifecycle framework for cybersecurity deployment, monitoring, and evaluation in academic server environments. The proposed monitoring system was implemented on three academic servers and tested through 90 controlled experimental scenarios involving file addition, modification, and deletion, while performance was evaluated based on detection accuracy, detection time, and resource efficiency. The experimental results showed that the Wazuh-based FIM successfully detected all unauthorized file changes with 100% accuracy (90/90 scenarios) within the predefined testing environment. The average detection time was 25.4 seconds, ranging from 24.7 to 26.3 seconds across all test cases, while system resource utilization remained stable with minimal operational overhead during continuous monitoring. These findings indicate that Wazuh-based FIM provides reliable near real-time detection of unauthorized file modifications under controlled integrity-monitoring conditions. Therefore, the proposed system demonstrates the potential to serve as an effective and practical host-level security layer for strengthening cybersecurity resilience in academic server environments, although the evaluation was limited to three monitored servers and did not include advanced adversarial attack scenarios.
The rapid expansion of networked systems has led to an increase in sophisticated cyber threats that frequently bypass traditional security mechanisms. Conventional defenses largely rely on signature-based or rule-based techniques, which are limited in their ability to detect unknown or advanced attacks. To address these challenges, this paper proposes a Deceptive Intrusion Prevention System (DIPS) that transitions network security from a reactive model to a proactive, intelligence-driven approach. The proposed architecture employs strategically deployed decoy resources and deceptive information to divert attackers away from critical assets while monitoring their behavior within a controlled environment. The framework combines deception, behavioral analysis, and automated mitigation within a unified intrusion prevention architecture. By analyzing attacker interactions with deceptive components, the system accurately identifies malicious activity and enables real-time response actions such as isolation and blocking. Experimental evaluation conducted in a controlled network environment demonstrates that the proposed approach improves detection accuracy, reduces false positives, and enhances overall system resilience. The results further show that deception-based intrusion prevention effectively delays attackers and generates actionable threat intelligence, strengthening proactive network defense.
Priyanka Tuppad, Vinit Kumar Shukla· International Journal For Mu...· 0 citations
Abstract This review paper focuses on and addresses Endpoint Detection and Response (EDR) tools, providing an overview of their purpose, functions, operations, services, and benefits within the cybersecurity landscape. Specifically, EDR solutions are designed to detect, prevent, investigate, and respond to advanced cyber threats that often bypass traditional antivirus programs. To achieve this, these tools continuously collect and analyze data in real time using behavioral analytics, artificial intelligence (AI), and machine learning (ML). This enables the identification of anomalous activities and sophisticated attack patterns, such as zero-day exploits and fileless malware. Furthermore, the integration of open-source tools strengthens an organization's security posture by enhancing service capabilities, scalability, reliability, and availability. The paper also discusses the evolution of EDR from standalone tools to integrated, interoperable, automated, and intelligence-driven platforms that utilize behavioral and predictive analysis to counter increasingly sophisticated threats. Such integration, in turn, enables faster decision-making while reducing code complexity, operational costs, and response times. Ultimately, the sustainability of open-source tools contributes to higher quality, improved performance, effective cost management, better decision-making, and reduced risk. In summary, this review synthesizes key developments and innovations in the EDR-SIEM domain, drawing from academic research, industry analysis, and real-world applications.
P. Pradhan· Journal of Information Assur...· 0 citations
5G-Advanced (3GPP Release 18) architectural changes include multi-access edge computing (MEC) architectural changes, network automation, and non-public networks (NPNs). It is important to note that even though these advancements provide substantial performance advantages, they destroy fixed-perimeter security models, providing a distributed attack surface. The use of current security assessment strategies, which are usually non-fluid and isolated, is inadequate to offer the required runtime security health assurance needed in such fluid environments. This study presents a new security assurance framework (SAF) that would be used to provide ongoing evidence-based protection on core, edge, and private network domains. This framework employs a four-layer architecture, including monitoring, analytics (LM), policy engine, and enforcement, to convert security periodically audited to a dynamic threat-control-metric evidence chain. A 96% attack detection rate and a 99.8% reduction in response time (with a mean of 20.1 s) are proven by validation on an emulated 5G-Advanced testbed (approximating Release 18 features using Open5GS (v2.7.2 Rel-17, community developed, Seoul, Republic of Korea and custom extensions) based on a design science research (DSR) paradigm. Although the overhead (13% CPU, 21.4% memory) is manageable, the findings prove that all-time, multi-domain assurance is crucial to the healthy functioning of 5G-Advanced and is a key roadmap to autonomous 6G security.
E. Egho-Promise, Ekereuke Udoh, Edita Gashi et al.· Information· 0 citations
This article discusses the development of a universal, comprehensive testing methodology for intrusion detection and prevention systems, designed to objectively evaluate their effectiveness in the face of increasingly complex network attacks. Existing approaches are often vendor-specific, which hinders independent comparative analysis. The methodology is based on a modular approach and is implemented on a test bench with the system directly integrated into the network traffic path. The study formulates requirements for the methodology, including universality, reproducibility, ease of use, and transparency of results analysis. Functional tests verify real-time attack blocking, logging accuracy, rule processing for various protocols, content filtering, and system behavior in failure mode. The article proposes an evaluation framework consistent with the recommendations of ISO/IEC 27034-1 and NIST SP 800-94. The developed solution enables independent, vendor-neutral comparative analysis of security measures, reduces testing costs, ensures test reproducibility, and enhances the soundness of security measure selection for critical infrastructure.
Kirill A. Biryukov, A. V. Ivanov· Digital Technology Security· 0 citations