Aug 2026· 2026 IEEE 34th International Requirements Engineering Conference Workshops (REW)· pp. 162-169· 0 citations· 22 references
Abstract
Internet Relay Chat (IRC) server development remains a cornerstone of computer networking education. However, these academic practices often prioritize functional concurrency over defensive design, leading to an accumulation of security vulnerabilities. This paper analyzes how functionality-first designs unconsciously expose broad attack surfaces. Using the Microsoft Threat Modeling Tool (MTMT), we apply the STRIDE framework to IRC command flows (NICK, JOIN, PRIVMSG, LIST/NAMES). We then map the resulting architectural vulnerabilities to the MITRE ATT&CK framework. Our findings demonstrate that the absence of cryptographic authentication, strict state validation, and encryption transforms basic protocol operations into native vectors for masquerading (T1036), privilege elevation (T1548), command-and-control (T1071), and discovery activities (T1018/T1087). By demonstrating that educational networking projects across computing disciplines often share architectural similarities with real-world attack infrastructures, we highlight a significant gap in networking and cybersecurity education across the computing field. Consequently, we argue that threat modeling and secure design principles must be explicitly integrated into these assignments to align educational practices with real life cybersecurity requirements.
This paper presents the design of SecureXon, a modular, full-stack security reconnaissance and threat-intelligence platform built around a Python/Flask backend that consolidates fifteen asynchronous reconnaissance modules with a large-language-model-driven Security Operations Center (SOC) assistant for false-positive v...
Sahil Bagde, Swapnil Meshram, Harish Dange et al.· International Journal of Cre...· 0 citations
This research evaluates how these threats have metastasized and traces the origins of modern security vectors to determine if established defensive protocols remain effective against increasingly complex modern exploitation tactics, and reveals a definitive and strategic maturation in adversarial approach.
Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas et al.· Iconic research and engineer...· 0 citations
This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.
Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al.· International Journal of Inf...· 0 citations
This work presents TENET, a purpose-built auditing tool whose design decisions are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset, and proposes mitigation measures and best practices for both Telegram platform developers and third-party Mini App cr...
Andrea Ciccotelli, Federico Zappone, R. Di Pietro· 0 citations
Abstract Domain Name System (DNS) is the way that Internet domain names are located and translated into IP addresses. The security architecture of the original design suffers from a lack of strength, as it was designed without built-in security. Among the most pervasive threats is DNS spoofing, in which attackers injec...
Sura Aljassim, M. A. Hussain, Z. Abduljabbar et al.· Cybernetics and Information...· 0 citations
The rapid expansion of remote collaboration has made video conferencing systems complex web services that combine authentication, session management, media streaming, recording repositories, and external integrations. These systems include not only general web application vulnerabilities, but also structural threats su...
Si Hwan Kim, Geun Hyeong Kim, Taek Lee· International journal of com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.