research
Open AccessPublished: Sep 2, 2026 Mohammed Almaiah , Santosh Reddy Addula
Abstract.Traditional cloud security controls tend to treat access, vulnerability exposure, and audit integrity as distinct functions, reducing the ability to be aware of risks on an ongoing basis. In this study, the authors present a blockchain-based zero-trust risk auditing framework for adaptive cloud protection (ACP) called BAZTRA. BAZTRA is a combination of a GBDT-based network-risk estimator and identity, device-posture, provenance, vulnerability, and compliance evidence. The CICIoT2023 corpus, controlled contextual replay, and repeated ten-seed experiments were used to evaluate the following techniques: availability-aware fusion, temporal smoothing, four-state enforcement, EPSS-KEV prioritization, hash chaining, and Merkle-based audit anchoring. Statistical significance was assessed using Friedman and Holm-corrected Wilcoxon tests across repetitions. The selected network-risk estimator achieved 78.96% accuracy, 55.01% macro-F1, 0.964 ROC-AUC, and 0.718 MCC. The complete BAZTRA framework produced 89.44% decision macro-F1, reduced unsafe access to 0.67%, and limited false denial to 0.03%. Ablation confirmed that adaptive enforcement, network evidence, provenance analysis, and availability-aware normalization were the most influential components. Merkle batching reduced effective ledger payload by 98.21% while preserving detection of modification, deletion, reordering, and replay attempts. BAZTRA provides a unified approach to continuous access assessment, vulnerability prioritization, and accountable cloud auditing. Future work will validate the framework on complete multi-source telemetry and a physical multi-peer Hyperledger Fabric deployment.
research
Open AccessPublished: Sep 2, 2026 Rami Shehab
Abstract.Phishing detectors typically only detect whether a message is a phishing attempt or not and offer little context to aid in incident response. This study is a contribution to fill this gap by providing a single framework for early detection and automatic generation of cyber threat intelligence based on URL. The proposed model is based on multi-kernel character convolution, BiLSTM attention, and 18 lexical–structural URL features, which are fused adaptively based on the samples. It was tested with a domain-grouped internal partitions set and an independent URL-phish test set. The source confidence, temporal freshness, entity correlation, ATT&CK mapping, and STIX 2.1 reporting were all used to enhance the high-risk predictions. The framework achieved 96.96% macro-F1, 96.51% phishing recall, and an MCC of 0.939 on the internal test set. Under cross-dataset evaluation, macro-F1 remained 95.57%, showing a smaller performance decline than conventional machine-learning, CNN–BiLSTM, transformer, and direct-fusion baselines. The CTI layer reached 92.8% indicator completeness, 93.8% entity F1, and 90.7% ATT&CK mapping F1, with a mean actionability score of 4.46/5. Adaptive evidence fusion improved detection stability, while conditional CTI enrichment converted suspicious URLs into structured and operationally useful intelligence.
research
Open AccessPublished: Sep 2, 2026 Rejwan Bin Sulaiman, Mohammed Amin Almaiah
Abstract.The study proposed an explainable framework for real-time intrusion detection and cybersecurity risk assessment in enterprise networks, XRisk-IDS. The model was an adaptive fusion of LightGBM and a CNN–BiGRU temporal branch. The decision process was enhanced by incorporating the concepts of probability calibration, predictive uncertainty, explanation fidelity, explanation stability, asset criticality, and network exposure. The test partition was the official UNSW-NB15 with 82,332 flows in 10 classes, which was used for evaluation. XRisk-IDS achieved 71.68% accuracy, 60.18% balanced accuracy, 48.03% macro-F1, and 95.63% macro-AUROC. It achieved an 18.59 percentage point increase in macro-F1 compared to the standalone CNN–BiGRU, while Random Forest was still better overall. The mean of the explanation quality was 0.7172, and the high-impact attack coverage was 99.45%. The framework was able to process ~26,274 flows/s and had a model footprint of 2.74 MB. XRisk-IDS offers an audit trail between detection and explanation reliability and operational risk. More research is needed to decrease benign false positives and improve multiclass calibration and test performance in real enterprise settings.
research
Open AccessPublished: Sep 2, 2026 Vugar Abdullayev, Udit Mamodiya, Mohammed Almaayah
Abstract.The critical infrastructure is increasingly relying on cyber-physical systems that are interconnected and have long lifetimes and legacy cryptography, which puts them at increasing risk of future quantum attacks. This research proposes an artificial intelligence (AI)-based framework for attack detection, risk assessment for quantum attacks, and selection of feasible cybersecurity controls under operational constraints. The framework is comprised of a CNN–BiGRU temporal detector, graph-attention-based dependency analysis, deterministic cryptographic profiling, explainable risk fusion, and mixed-integer mitigation optimization. Separate train, calibration, validation, and test sets were used for water, industrial-control, and IoT applications, with the use of a reproducible multi-domain benchmark. The proposed model outperformed the conventional, temporal, and graph-only baseline models with a macro-F1 of 0.9387 and an AUROC of 0.9878 over 10 runs. Quantum exposure and dependency propagation improved high-risk prioritization without inflating attack-classification scores. Performance remained stable under moderate telemetry loss, graph perturbation, delayed threat intelligence, and alternative cryptographic profiles. The optimized mitigation plans reduced aggregate risk by 62.99–97.28%, depending on budget and downtime limits. Cross-domain transfer was strong for process-oriented environments but weaker for the network-centric IoT domain. The framework links together attack detection, the necessity of moving to post-quantum, explainable risk assessment, and mitigation with operational limitations in one process of reproducible protection for infrastructure management.
research
Open AccessPublished: Sep 5, 2026 Sopheaktra Huy, Mony Ho, Sokroeurn Ang, Midhunchakkaravarthy Janarthanan
Abstract.Organizations across all industries continue to face challenges in quantifying and monitoring cyber risk in a consistent, actionable, and predictive manner. Although cybersecurity frameworks such as NIST CSF, ISO/IEC 27001, and COBIT provide guidance for establishing controls, they offer limited support for operationalizing cyber risk measurement. Traditional qualitative assessments often rely on subjective scoring and static evaluations that fail to reflect the dynamic nature of cyber threats. This research addresses these limitations by proposing a comprehensive cyber risk measurement framework grounded in Key Risk Indicators (KRIs). The framework introduces a multi-domain taxonomy encompassing technology, human behavior, governance processes, and external threat conditions, supported by a quantitative scoring and threshold model that enables objective and comparable measurement. It further provides an integration approach for embedding KRIs into governance reporting and a five-level maturity model that guides organizations in developing their KRI capabilities. Drawing on design science research principles, the framework synthesizes cybersecurity standards, academic literature, and industry practices to deliver a practical and sector-agnostic method for transforming fragmented security metrics into data-driven cyber risk intelligence. The proposed framework enhances predictive risk management, strengthens decision-making, and supports continuous improvement in organizational cyber resilience. Practically, the framework supports risk managers, auditors, and boards in transitioning from fragmented security metrics to governance-ready cyber risk intelligence that enables timely prioritization and accountable decision-making.