Assumptions in Intrusion Detection - Blind Spots in Analysis
This paper examines one of the common assumptions made as an intrusion analyst looking at network packet captures and explores the possible avenues which could determine that the assumption may not be as trustworthy as has been previously assumed. This paper attempts to guide the analyst by providing a detailed analysis of the TCP/IP standards stack with particular focus on the communication that exists between layers of the stack. As will be shown in this paper, the communication, or lack of communication, provide the possibility of exploitation at various levels as data passes between layers in the standards stack
1751 (PDF, 2.10MB)
28 Mar 2007Related Content
Evaluating the Impact of Log Configuration on Lateral Movement Detection Using Windows Event Logs
Research PaperThese findings demonstrate that effective endpoint logging depends not only on the amount of telemetry collected but also on the configuration and filtering strategy.
- 22 Sep 2026
- Michael Dobbs
Bot or Not? Detecting AI-Driven Web Traffic Using Network Metadata Analysis
Research PaperThis detection method is lightweight, non-intrusive, and easily integrated into existing security toolsets, offering defenders a scalable alternative to traditional bot detection and mitigation techniques.
- 22 Sep 2026
- William Hatfield
Continuous Enforcement vs Out-of-Band Validation: Mitigating Configuration Drift on Windows Server 2022 with Automated Remediation Loops
Research PaperThis paper examines the persistent issue of configuration drift within enterprise data centers, where routine administration, patches, and user activity silently degrade established security postures between scheduled audits.
- 22 Sep 2026
- Christopher Sandoval
WAFstat: External Verification of WAF Enforcement Posture: Measuring Observable WAF Enforcement Beyond Presence Fingerprinting
Research PaperThis study presents WAFstat, a lightweight external verification method that combines a fixed, versioned marker corpus with response-shape baselines, configuration validation, and immutable provenance.
- 22 Sep 2026
- Tiago Kiill
Beyond the Tunnel: A Lab-Based Comparative Evaluation of Network-Layer VPN and Identity-Aware Reverse Proxy Architectures Against the CISA Zero Trust Maturity Model
Research PaperFor the Applications and Data pillars, the results depend primarily on the security features bundled with each product and its platform, and the two architectures converge on Identity because both draw their authentication strength from the same identity provider. The study contributes a repeatable methodology and a scored matrix that shows where the architectures genuinely diverge.
- 17 Sep 2026
- Henry Cheung
Assessing the Feasibility and Effectiveness of AI in CTI-Driven Threat Hunting
Research PaperThis study evaluates three commercial LLMs, OpenAI GPT-4o, Google Gemini, and Microsoft Copilot, against ten recent CTI reports, measuring indicator extraction accuracy and validating generated Kusto Query Language (KQL) and CrowdStrike Query Language (CQL) hunting queries in Microsoft Sentinel and CrowdStrike NG-SIEM.
- 17 Sep 2026
- Devron West
The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection
Research PaperThis paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.
- 11 Aug 2026
- Garo Sinanian
Evaluating LLMs as a Bridge Between Cyber Threats and Business Risk for Executive Decision-Making
Research PaperSecurity leaders cannot act on intelligence they cannot understand, yet most cyber threat intelligence (CTI) reporting is written for analysts, not executives.
- 11 Aug 2026
- Arcadio Aguilar
Entra ID Governance: Insta-IAM/IGA Solution?
Research PaperThis research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.
- 6 Aug 2026
- Scott Fortin
Evaluating the Detection Effectiveness of Network Monitoring Tools Against Modern Command-and-Control Frameworks
Research PaperThis research measures the effectiveness of Zeek, Suricata, and Security Onion against representative modern C2 frameworks in a controlled laboratory environment.
- 9 Jul 2026
- Joseph Zderadicka
Practical MFA for the Enterprise: Enforcing Strong Authentication for Non-Human Identities Using Compensating Controls
Research PaperThis paper’s case study examined a production Microsoft Entra ID environment at a large North American organization encompassing more than 500 app registrations and 21,000 directory accounts.
- 9 Jul 2026
- Fredrick Stock
Cyber Intelligence GraphRAGs for Behavioral Detection
Research PaperThis paper introduces chatAPT, a prototype graphRAG system that extends a hybrid dual-retrieval architecture with domain-contextualized extraction, ontologies, and entity alignment, and exposes tools that enable human analysts and AI agents to query enriched threat intelligence during hypothesis generation.
- 9 Jul 2026
- Robert Heald
USB: Universal Security Breach or Uniquely Secured Bus? Assessing the Effectiveness of Windows 11 Group Policy at Controlling USB Device Installation for Budget-Constrained Security Teams
Research PaperThis study evaluates three progressively granular Windows 11 Group Policy (GPO) configurations—class-based blocking, VID/PID allowlisting, and Device Instance ID allowlisting—against legitimate business peripherals and a Hak5 USB Rubber Ducky configured as a composite BadUSB device, using the Windows 11 v25H2 Security Baseline as the unmodified reference state.
- 22 Jun 2026
- Kire Jacobson
Investigating Operating System Variations in IPv6 Implementations
Research PaperThis research tested the four most common operating system families, Windows, Linux, macOS, and BSD, for RFC compliance and behavioral differences across a controlled set of IPv6 test cases. Because RFC specifications leave many implementation details to the developer, behavior was expected to diverge, and the testing confirmed that it did.
- 22 Jun 2026
- Donovan Rodriguez
macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses
Research PaperThis paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis.
- 22 Jun 2026
- Cory Findley
Untested: An Overlooked Link in the Software Supply Chain
Research PaperThis research explores test code as an attack surface and takes a first step toward creating a tool to help analysts detect and mitigate malware lurking in test libraries.
- 16 Apr 2026
- Evan Ottinger
Cyber Risk Intelligence and Security Posture (CRISP): From Compliance to Threat-Informed Intelligence
Research PaperThis paper presents CRISP (Cyber Risk Intelligence & Security Posture), a platform that automates the transformation of STIG compliance data into threat-informed security intelligence.
- 7 Apr 2026
- Eric Kaden
Operationalizing CTEM within the SOC: A Proactive Approach to Threat Detection and Response
Research PaperWith either an in-house or an outsourced approach, organizations invest in a security operations center (SOC) to perform threat detection, investigation, and response. SOCs may also leverage threat hunting to identify threats earlier and proactively reduce risk.
- 1 Apr 2026
- Jay Yaneza
Enhancing Linux Threat Detection: A Sysmon - Based Approach to Identifying Sandworm TTPs
Research PaperLinux systems have become foundational across modern IT enterprises. Threat actors are increasingly targeting Linux systems, including well - known advanced persistent threats (APTs) such as Sandworm.
- 20 Mar 2026
- Joshua Keller
Open-Source National Security Infrastructure for Sweden’s National Security Apparatus
Research PaperThis paper investigates whether core IT infrastructure implemented using open-source software and infrastructure-as-code techniques can achieve compliance with selected information security requirements defined in Chapter 4 of PMFS 2022:1.
- 18 Mar 2026
- Fredrik Bolinder
