ArXivCSExplorer
☆☆Bookmarks🏆RSSHow to UseFAQ
Built with and by Teycir Ben Soltane•
How to Use•FAQ•GitHub•arXiv.org•
Share:

~ similar to 2605.19367v1· 20 results

cs.CRRecentApr 15, 2026

Understanding Student Experiences with TLS Client Authentication

Abubakar Sadiq Shittu, Clay Shubert, John Sadik, Scott Ruoti

This study empirically demonstrates that even highly technical students struggle significantly with the long-term usability and security understanding of Mutual TLS (mTLS) client authentication, sugge…

View →
cs.CRcs.CYRecentMar 23, 2026

Cybersecurity Guidance for Smart Homes: A Cross-National Review of Government Sources

Victor Jüttner, Erik Buchmann

This cross-national review analyzed government cybersecurity guidance for smart homes, finding that while general security advice is abundant, structured, step-by-step incident response guidance is ra…

View →
cs.CRRecentApr 1, 2026

"The System Will Choose Security Over Humanity Every Time": Understanding Security and Privacy for U.S. Incarcerated Users

Yael Eiger, Nino Migineishvili, Emi Yoshikawa, Liza Nadtochiy +2 more

The paper investigates how digital devices in U.S. prisons create privacy and security risks for incarcerated users, finding that pervasive surveillance and arbitrary policies negatively impact their…

View →
cs.CRcs.NIRecentMay 29, 2026

Thou Shall Not Pass: Gatekeeping Outbound TLS Connections

Henrique B. Brum, Matteo Franzil, Riccardo Germenia, Salvatore Manfredi +2 more

The paper analyzes persistent TLS misconfigurations and introduces TLSGatekeeper, a high-performance, network-based tool that enforces security policies by monitoring TLS handshakes without requiring…

View →
cs.CRcs.CYRecentMay 17, 2026

Towards Zero Trust Architecture: A Pilot Study on Information Systems Security Readiness amongst Small and Medium Enterprises

Yu Deng, Anushia Inthiran

This pilot study investigates SME readiness for Zero Trust Architecture (ZTA) and proposes a realistic three-stage adoption path based on survey data from IT professionals.

View →
cs.CYcs.CRRecentApr 29, 2026

Taking a Bite Out of the Forbidden Fruit: Characterizing Third-Party Iranian iOS App Stores

Amirhossein Khanlari, Amir Rahmati

This paper empirically characterizes the clandestine third-party iOS app stores in Iran, revealing a complex ecosystem driven by sanctions and censorship that facilitates piracy, unauthorized monetiza…

View →
cs.CRRecentMay 21, 2026

A First Measurement Study on Authentication Security in Real-World Remote MCP Servers

Huijun Zhou, Xiaohan Zhang, Haozhe Zhang, Haoyang Zhang +2 more

This study provides the first measurement of authentication security in real-world remote Model Context Protocol (MCP) servers, finding pervasive and critical authentication weaknesses, particularly i…

View →
cs.CRcs.NIRecentApr 3, 2026

Open Challenges for Secure and Scalable Wi-Fi Connectivity in Rural Areas

Philip Virgil Berrer Astillo, Jayasree Sengupta, Mathy Vanhoef

This paper analyzes the security vulnerabilities of emerging pay-for-use Wi-Fi hotspots in rural areas, demonstrating practical attacks like connection hijacking and rogue hotspots.

View →
cs.CRcs.CYRecentMay 23, 2026

From Frontier to Shadow AI: A Simmering Threat to Assurance and Security in Critical Infrastructure

Mohan Baruwal Chhetri, Shahroz Tariq, Tooba Aamir, Marthie Grobler +2 more

The paper empirically characterizes 'shadow AI'—the unsanctioned use of frontier AI in critical infrastructure—as a systemic threat that erodes established assurance and security controls.

View →
cs.CRRecentApr 22, 2026

An Analysis of Attack Vectors Against FIDO2 Authentication

Alexander Berladskyy, Andreas Aßmuth

This paper analyzes various attack vectors against FIDO2 passkeys, demonstrating that while sophisticated attacks are possible, the overall security posture significantly raises the bar compared to tr…

View →
cs.CRRecentApr 15, 2026

Where Trust Fails: Mapping Location-Data Provenance Risks in Europe

Eduardo Brito, Liina Kamm

This paper analyzes location-data provenance risks across multiple European sectors, proposing a risk taxonomy and architectural design for a next-generation digital trust infrastructure that treats l…

View →
cs.CRcs.HCRecentMar 26, 2026

Usability of Passwordless Authentication in Wi-Fi Networks: A Comparative Study of Passkeys and Passwords in Captive Portals

Martiño Rivera-Dourado, Rubén Pérez-Jove, Alejandro Pazos, Jose Vázquez-Naya

This study comparatively assessed the usability of passkeys versus passwords for Wi-Fi captive portal authentication, finding that while passkeys were perceived as more usable, captive portal limitati…

View →
cs.CRcs.AIRecentApr 11, 2026

Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit

Souradip Nath, Chih-Yi Huang, Aditi Ganapathi, Kashyap Thimmaraju +2 more

Analyzing Reddit discussions, the paper finds that while security practitioners see LLMs as useful for boosting productivity, their adoption is constrained by concerns over reliability, verification,…

View →
cs.CRcs.AIRecentApr 3, 2026

Towards Secure Agent Skills: Architecture, Threat Taxonomy, and Security Analysis

Zhiyuan Li, Jingzheng Wu, Xiang Ling, Xing Cui +1 more

This paper provides the first comprehensive security analysis of the Agent Skills framework, identifying severe structural vulnerabilities that require fundamental architectural changes rather than si…

View →
cs.CRRecentMar 23, 2026

CTF as a Service: A reproducible and scalable infrastructure for cybersecurity training

Carlos Jimeno Miguel, Mikel Izal

This paper introduces and evaluates a scalable, reproducible 'CTF as a Service' (CaaS) platform designed to simplify the infrastructure management required for cybersecurity training.

View →
cs.NIcs.CRRecentMar 17, 2026

Persistent Device Identity for Network Access Control in the Era of MAC Address Randomization: A RADIUS-Based Framework

Premanand Seralathan

The paper proposes a RADIUS-based framework to maintain persistent device identity for Network Access Control (NAC) despite modern operating system MAC address randomization, ensuring regulatory compl…

View →
cs.CRRecentMay 23, 2026

Reframing LLM Agent Security as an Agent-Human Interaction Problem

Peiran Wang, Ying Li, Yuan Tian

The paper argues that LLM agent security is fundamentally an agent-human interaction (AHI) problem, demonstrating that industry practices rely on human-centric mechanisms while academic research focus…

View →
cs.CRcs.CYcs.HCRecentJun 1, 2026

Human Factors in Cybersecurity in Icelandic Small and Medium-sized Enterprises

Goda Cicėnaitė, Thomas Welsh, Helmut Neukirchen

This study surveyed Icelandic organizations to find that human factors, such as poor training and culture, pose significant cybersecurity risks that often bypass technical controls.

View →
cs.CRRecentApr 30, 2026

I can't recognize (yet): Delayed Rendering to Defeat Visual Phishing Detectors

Ying Yuan, Cristiano Alex Rado, Giovanni Apruzzese, Mauro Conti +1 more

This paper demonstrates that visual phishing detectors can be completely bypassed by employing simple timing-based attacks that delay the rendering of key webpage elements.

View →
cs.CRcs.HCRecentMay 17, 2026

LITE-SOC: Lightweight Security Operations Center Simulator for Cybersecurity Education

Martin Higgins, Shawn Thompson, Cherry Mangla

The paper introduces LITE-SOC, a lightweight, web-based simulator designed to provide a practical, accessible alternative for teaching cybersecurity SOC workflows without requiring complex, expensive…

View →