Skip to main content

Cybersecurity Research Papers

Master's degree candidates at SANS.edu conduct research that is relevant, has real world impact, and often provides cutting-edge advancements to the field of cybersecurity, all under the guidance and review of our world-class instructors.

Showing 12 of 775

Beyond the Tunnel: A Lab-Based Comparative Evaluation of Network-Layer VPN and Identity-Aware Reverse Proxy Architectures Against the CISA Zero Trust Maturity Model

Research PaperCyber Defense

For the Applications and Data pillars, the results depend primarily on the security features bundled with each product and its platform, and the two architectures converge on Identity because both draw their authentication strength from the same identity provider. The study contributes a repeatable methodology and a scored matrix that shows where the architectures genuinely diverge.

  • 17 Sep 2026
  • Henry Cheung

Assessing the Feasibility and Effectiveness of AI in CTI-Driven Threat Hunting

Research PaperArtificial Intelligence, Cyber Defense

This study evaluates three commercial LLMs, OpenAI GPT-4o, Google Gemini, and Microsoft Copilot, against ten recent CTI reports, measuring indicator extraction accuracy and validating generated Kusto Query Language (KQL) and CrowdStrike Query Language (CQL) hunting queries in Microsoft Sentinel and CrowdStrike NG-SIEM.

  • 17 Sep 2026
  • Devron West

The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection

Research PaperDigital Forensics and Incident Response, Cyber Defense

This paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.

  • 11 Aug 2026
  • Garo Sinanian

Evaluating LLMs as a Bridge Between Cyber Threats and Business Risk for Executive Decision-Making

Research PaperArtificial Intelligence, Cyber Defense

Security leaders cannot act on intelligence they cannot understand, yet most cyber threat intelligence (CTI) reporting is written for analysts, not executives.

  • 11 Aug 2026
  • Arcadio Aguilar

Network Artifacts of Trusted Service Abuse

Research PaperOffensive Operations

This study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).

  • 6 Aug 2026
  • Nicholas Vaniscak

Dual-Module QR Codes: Bypassing QR Code Scanners in Enterprise Email Gateways

Research PaperOffensive Operations

By exploiting the decoding algorithm and leveraging existing QR data-layering techniques, this research provides the security industry with a working proof-of-concept to bypass email security gateway detection systems.

  • 6 Aug 2026
  • Steven Legere

Entra ID Governance: Insta-IAM/IGA Solution?

Research PaperCyber Defense

This research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.

  • 6 Aug 2026
  • Scott Fortin

Reconstructing Deleted File Activity Using FSEvents from macOS

Research PaperDigital Forensics and Incident Response

This paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.

  • 30 Jul 2026
  • Josh Clevenger

Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence

Research PaperDigital Forensics and Incident Response

Modern Security Operations Centers (SOCs) face a deepening burnout crisis.

  • 20 Jul 2026
  • Jose "Ricky" Banda

Evaluating the Detection Effectiveness of Network Monitoring Tools Against Modern Command-and-Control Frameworks

Research PaperCyber Defense

This research measures the effectiveness of Zeek, Suricata, and Security Onion against representative modern C2 frameworks in a controlled laboratory environment.

  • 9 Jul 2026
  • Joseph Zderadicka

Practical MFA for the Enterprise: Enforcing Strong Authentication for Non-Human Identities Using Compensating Controls

Research PaperCyber Defense

This paper’s case study examined a production Microsoft Entra ID environment at a large North American organization encompassing more than 500 app registrations and 21,000 directory accounts.

  • 9 Jul 2026
  • Fredrick Stock

Cyber Intelligence GraphRAGs for Behavioral Detection

Research PaperCyber Defense

This paper introduces chatAPT, a prototype graphRAG system that extends a hybrid dual-retrieval architecture with domain-contextualized extraction, ontologies, and entity alignment, and exposes tools that enable human analysts and AI agents to query enriched threat intelligence during hypothesis generation.

  • 9 Jul 2026
  • Robert Heald