Saudi Cultural Missions Theses & Dissertations

Permanent URI for this communityhttps://drepo.sdl.edu.sa/handle/20.500.14154/10

Browse

Search Results

Now showing 1 - 10 of 82
  • ItemRestricted
    CYBERSECURITY STANDARDS FOR AGENTIC AI SYSTEMS
    (Saudi Digital Library, 2025) AlAlmai, Ahmed; Zaki, Hamdani
    This project examines the cybersecurity challenges associated with Agentic Artificial Intelligence (AI) systems, which are capable of autonomous decision-making and adaptive behaviour. It evaluates the limitations of existing cybersecurity and governance frameworks, with particular emphasis on ISO/IEC 42001, in addressing emerging AI-specific threats. The study investigates key risks including adversarial machine learning, data poisoning, model inversion, unauthorized model use, and ethical concerns such as bias and transparency. Based on these findings, the project proposes practical security enhancements, including adversarial testing, secure data pipelines, robust access controls, explainable AI techniques, continuous monitoring, and AI-specific governance policies. The report also highlights the importance of lifecycle-based security management and awareness programs to improve organizational resilience against evolving AI threats. The findings provide a foundation for developing secure, trustworthy, and responsible Agentic AI systems while supporting future technical implementation and compliance with emerging AI security standards.
    12 0
  • ItemRestricted
    Zero Trust Adoption in Saudi Critical Infrastructure Systems of the Energy Sector
    (Saudi Digital Library, 2026) ALAMRI, TARIQ; Adamos, Vasileios
    This study critically examines the practicality and contextual application of Zero Trust Architecture (ZTA) within Saudi Arabia’s critical energy infrastructure and develops a literature-based adoption strategy tailored to this environment. The research is motivated by the increasing cybersecurity risks associated with IT/OT convergence, smart grid expansion, and the growing reliance on interconnected energy systems under Saudi Vision 2030. A qualitative research design was adopted, based on a Systematic Literature Review (SLR) supported by PRISMA guidelines and thematic analysis following Braun and Clarke. A total of 20 high-quality studies were selected and analysed to identify key patterns related to Zero Trust principles, cybersecurity threats, and implementation challenges in energy-critical environments. The findings show that ZTA provides a strong conceptual foundation through continuous authentication, identity-based access control, micro-segmentation, and adaptive security mechanisms. However, its implementation in Saudi energy systems is constrained by technical limitations in legacy OT environments, organisational resistance, and fragmented regulatory frameworks. The study further reveals that IT/OT convergence and IoT integration significantly expand the attack surface, reinforcing the need for advanced and adaptive security models. In response, this research proposes a phased, risk-based ZTA adoption approach aligned with national cybersecurity governance frameworks and operational constraints of OT systems. The study concludes that while ZTA is highly relevant and feasible, its successful implementation requires contextual adaptation, gradual deployment, and strong organisational alignment.
    5 0
  • ItemRestricted
    Leveraging Digital Technology Determinants to Enhance Operational Efficiency: Insights from the Saudi Transport Sector
    (Saudi Digital Library, 2026) ALSUBAIE, Sultan Bader A; AlHamad, Salah
    Saudi Arabia’s transportation sector is undergoing rapid transformation under Vision 2030 as the country aims to become a global logistics hub. Despite major investments in transport infrastructure, many organizations continue to face operational inefficiencies such as delayed deliveries, fleet underutilization, high maintenance costs, and fragmented operational systems. Digital technologies have emerged as critical tools for addressing these challenges; however, limited research has examined their collective impact within Saudi Arabia’s transportation sector. This study investigates how artificial intelligence, Internet of Things (IoT), big data analytics, cloud computing, blockchain, cybersecurity readiness, and workforce digital readiness influence operational efficiency in Saudi transport organizations. A quantitative research design was adopted using a structured survey distributed to transportation professionals across Riyadh, Jeddah, Dammam, and NEOM. A total of 287 valid responses were analyzed using descriptive statistics, regression analysis, ANOVA, and simulation modeling. The findings revealed that IoT recorded the highest adoption level, while blockchain remained the least adopted technology. Artificial intelligence, IoT, workforce readiness, and cybersecurity readiness were identified as the strongest predictors of operational efficiency. The study concludes that digital transformation significantly improves transportation efficiency, but success depends on effective implementation, employee readiness, and cybersecurity capabilities.
    2 0
  • ItemRestricted
    Data Protection in Online Banking in the United Kingdom
    (Saudi Digital Library, 2025) Albalawi, Reham; Warburton, Joshua
    The rise of online banking has fundamentally transformed financial services by increasing accessibility and operational efficiency. However, this transformation has introduced significant challenges concerning the protection of personal data. In light of escalating cyber threats and data breaches, this dissertation critically evaluates the efficacy of existing legal and regulatory frameworks governing data protection in online banking. It begins by outlining the core legal principles underpinning data privacy, including the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and key provisions of the UK's Financial Services legislation. The analysis proceeds to examine how financial institutions implement data protection standards, with particular attention to data minimisation, consent mechanisms, encryption practices, and third-party access. Case studies are employed to highlight persistent vulnerabilities in both regulatory enforcement and corporate compliance, revealing a gap between theoretical protection and practical implementation. It is argued that while the legal framework provides a robust foundation, its fragmented application and reactive enforcement often permit systemic weaknesses to persist. Accordingly, this dissertation asserts the need for enhanced accountability mechanisms, greater regulatory harmonisation, and mandatory cybersecurity certifications for financial technology systems. Through a doctrinal and comparative methodology, it is submitted that reform must strike a balance between technological innovation and safeguarding individual privacy rights. The study concludes that a proactive and unified approach to data governance is essential for maintaining public trust and resilience in the digital banking sector.
    9 0
  • ItemRestricted
    Evaluating Hybrid AI Approaches in email Spam Detection: A Literature Review
    (Saudi Digital Library, 2026) Alshamrani, Husam A; Sabar, Nasser
    Spam is still one of the most serious cybersecurity issues of the day, and serves as a method of delivering phishing and malware. In this thesis, two complementary parts are integrated: First, a PRISMA-based systematic review of 55 studies that were published from 2023 to 2025 and analyze the classical, AI-based and ensemble spam detection techniques; and second, a controlled proof-of-concept experiment on the Enron-Spam corpus, where three distinct classical classifiers (Naïve Bayes with Bag-of-Words, Logistic Regression with TF-IDF, Linear SVM with TF-IDF) are compared against a stacking ensemble of the three classifiers with a Logistic Regression meta-classifier. All four configurations were very close together and obtained an accuracy of between 0.989 and 0.993, with the stacking ensemble having the highest F1-score (0.9923) and the lowest false-positive rate (0.0088); but there were no significant differences between the four configurations when a paired statistical test was not used. The thesis contribution lies in the synthesis of the various perspectives of the 2023–2025 hybrid and ensemble approaches and an internally consistent baseline comparison on a standard corpus. The study is restricted to English-language email and to lexical features; further extensions of the study using deep-learning, multilingual, and adversarial techniques are suggested.
    17 0
  • ItemRestricted
    DEEP REINFORCEMENT LEARNING BASED SEMI AUTONOMOUS CYBERATTACK DETECTION FOR INTERNET OF THINGS (IOT) SYSTEMS
    (Saudi Digital Library, 2026) AlRuwaili, Ibtihaj; AlQawasmi, Khaled
    Abstract The Internet of Things (IoT) has made today's networked world more complex and vulnerable, thus making it an appealing target for advanced cyberattacks. Limited adaptability, poor generalization and responsiveness to new and evolving attack behaviors are common problems with the traditional cybersecurity approaches that rely on static rules and supervised Machine Learning (ML). Furthermore, traditional IPSs are not equipped with the ability to adapt and learn over time in response to changing threats and vulnerabilities in the cyber landscape. To overcome the restrictions a novel Deep Reinforcement Learning (DRL) based cybersecurity framework is proposed for adaptive intrusion detection in heterogeneous enterprise-network and IoT based environment.The framework turns intrusion detection into a sequence of decisions, where a DRL agent keeps interacting with the environment and optimizes intrusion detection policies using rewards-driven learning. In order to test the diversity of the experiments and analyze the adaptive learning behavior, the framework was experimentally evaluated on two cybersecurity benchmark datasets: CICIDS2017 and TON_IoT.It was evaluated experimentally using CICIDS2017 and TON_IoT datasets, which are both widely used in the cybersecurity research community. Three DRL algorithms DDQN,PPO,DDPG were implemented and tested with various performance measures such as Accuracy, Precision, Recall, F1-Score, False positive rate (FPR) and ROC-AUC.Results of the experiments showed that the different evaluated DRL algorithms performed well in both cybersecurity test environments. However DDQN was found to be the best in terms of classification consistency, convergence stability and adaptive learning behavior in comparison to PPO and DDPG models and it was the most consistently and stably performing model. In particular, on the CICIDS2017 dataset, DDQN scored 97.3% on the Accuracy metric, 97.4% on the F1-Score metric, and 0.989 on the ROC-AUC metric, and on the TON_IoT dataset, the metrics were 95.6% for Accuracy, 95.6% for f1-score, and 0.978 for ROC-AUC. Moreover, DDQN achieved an FP rate of merely 2.1% and 3.4% in CICIDS2017 and TON_IoT respectively, suggesting a strong intrusion-classification capability under heterogeneous traffic conditions.The findings further showed that IoT environments bring in more complexity in cybersecurity with heterogeneous telemetry and dynamic communication patterns. Moreover, comparison showed that DRL-based method offers better adaptability, ongoing policy optimization, and better decision-support capability in dynamic cybersecurity scenarios.
    8 0
  • ItemRestricted
    Study of Drastic Effects of Different Social Engineering Campaigns on Saudi Financial Sectors
    (Saudi Digital Library, 2026) Alnefaie, Muteb; Lamoyero, Zaynab
    This study examines the impacts of social engineering campaigns on the Saudi financial sector, focusing on operational disruption, financial losses, awareness effectiveness, and employee behaviour. A mixed-method approach was adopted, combining a systematic literature review (SLR) using the PRISMA framework with a quantitative survey of 90 professionals from Saudi financial institutions. The qualitative analysis, based on six selected peer-reviewed studies, identified key themes including operational vulnerabilities, financial risks, limitations of awareness programs, and behavioural factors influencing susceptibility. The quantitative findings supported these insights, revealing that social engineering attacks frequently disrupt communication systems and IT operations, result in significant financial losses and fraud, and impose additional recovery costs. While awareness programs are widely implemented, their effectiveness is limited due to inconsistent training and low compliance. Furthermore, behavioural weaknesses such as poor decision-making, low reporting tendencies, and non-adherence to security protocols remain critical vulnerabilities. The study concludes that the human factor is the central weakness in cybersecurity within Saudi financial institutions. It recommends continuous training, stronger communication security controls, and behaviour-focused security strategies. This research contributes both empirical and contextual insights to the limited Saudi-specific literature and highlights the need for integrated socio-technical cybersecurity frameworks.
    12 0
  • ItemRestricted
    A MULTI-LAYER DEFENSE FRAMEWORK FOR ENHANCING ADVERSARIAL ROBUSTNESS OF MACHINE LEARNING-BASED INTRUSION DETECTION SYSTEMS
    (Saudi Digital Library, 2026) alshmmri, Eiman Salem; Almatarneh, Rami Jibreel
    The rapid evolution and increasing sophistication of cyber threats, especially the adversary attacks have revealed significant weaknesses in the traditional Intrusion Detection Systems (IDS). The traditional signature-based systems can no longer identify a zero-day attack or respond to an ever-changing pattern of threats. Even though the Intrusion Detection Systems based on Machine Learning (ML-IDS) have enhanced detection performance, most of the existing systems are not robust in the adversarial settings and are commonly tested at fixed and static settings. This restricts the knowledge of model resilience, stability and generalization in real and unstable cybersecurity conditions. This thesis will solve those issues by introducing a single, configuration-sensitive assessment system of ML-based intrusion detectors. The framework combines tree models, such as Random Forest, Extra Trees, and XGBoost, and an optimized ensemble method to improve predictive performance, stability, and generalization. It also includes feature selection as a way of minimizing redundancy and enhancing efficiency and class imbalance management as a way of stabilizing learning when the data distribution is skewed. Moreover, the adversarial perturbation testing is done both in white-box and black-box to represent real-life attack conditions. A multi-level defense mechanism is also implemented to enhance model resilience and reduce the effect of adversarial attack. The framework is tested on two non-homogeneous benchmark datasets, namely the CIC-IDS2018, published in 2018, and the updated release of the ToN-IoT dataset, update published in 2025. It allows assessment in various time frames and changing threat patterns, so that the offered approach will be highly efficient in both well-established and recently re-evaluated data sets. The experimental results demonstrate that the proposed framework achieves a high level of performance, with accuracy exceeding 95% in many cases, alongside strong F1- score and AUC values across different attack categories. The ensemble model exhibits enhanced stability and generalization capability, while feature selection and class imbalance handling contribute significantly to improving efficiency and robustness. Moreover, the proposed defense mechanism effectively reduces performance degradation in adversarial environments and enhances system recovery. These findings highlight the effectiveness of the proposed framework in developing robust, adaptive, and resilient Intrusion Detection Systems capable of maintaining high performance under diverse and evolving cybersecurity conditions.
  • ItemRestricted
    NLP-Based Cybersecurity Threat Intelligence Management Framework In Manufacturing Sector: A Framework For Predicting Cyberattacks And Security Incidents - Toward The Transformation Of Industry 4.0.
    (Saudi Digital Library, 2026) Albarrak, Majed; Sandeep, Jagtap; Konstantinos, Salonitis
    Industry 4.0 manufacturing environments depend on interconnected cyber-physical systems, Industrial Control Systems (ICS), and IoT technologies, significantly increasing exposure to sophisticated cyber threats. Modern attacks are faster, increasingly malware-free, and often detected too late by traditional signature-based defences. Early indicators of such threats frequently appear in unstructured open-source text, including social media and technical forums, long before formal advisories are issued. However, existing Cyber Threat Intelligence (CTI) practices in manufacturing make limited use of these early signals, restricting proactive defence. This limitation arises because CTI systems predominantly rely on structured and validated intelligence feeds, while early threat indicators are embedded in large volumes of noisy, unstructured textual data that are difficult to process automatically. Furthermore, extracting actionable intelligence from such sources requires complex NLP pipelines and high-quality labelled data, which remain scarce, making the timely and accurate integration of these signals into standardised frameworks (e.g., MITRE ATT&CK) challenging (Büchel et al., 2025; Rahman, Hezaveh and Williams, 2023). This research adopts a design science approach to develop and validate an NLP-based CTI management framework tailored to Industry 4.0. The framework integrates three components: (i) an urgency-aware topic modelling approach (U-BERTopic) to detect emerging threats from unstructured text streams, (ii) a transformer-based classification model (AC_MAPPER) that automatically maps extracted threat narratives to MITRE ATT&CK techniques using class-aware augmentation, and (iii) an end-to-end CTI framework embedding these models across the CTI lifecycle. Quantitative evaluation was conducted using standard NLP and classification metrics across five publicly available cyber threat intelligence (CTI) datasets: TRAM, TRAM Bootstrap, CAPEC, TTPHunter, and HALdata. These datasets consist of sentence-level annotations linking unstructured threat intelligence text to MITRE ATT&CK techniques. Their sizes vary significantly, ranging from 803 sentences in HALdata to 12,945 sentences in CAPEC, with intermediate datasets including TRAM (5,089 sentences), TRAM Bootstrap (11,130 sentences), and TTPHunter (8,887 sentences). The datasets also differ in label diversity, covering between 46 and 188 ATT&CK techniques, and exhibit substantial class imbalance, with some techniques occurring frequently (e.g., T1027, T1059) while many others appear fewer than ten times, reflecting real-world CTI data challenges. The findings show that urgency-aware topic modelling improves early identification of high-risk threat signals, with U-BERTopic achieving a higher topic diversity score of up to 0.88, compared to 0.56 for LDA, indicating more distinct and informative cybersecurity topics. Furthermore, AC_MAPPER demonstrates robust performance in mapping CTI text to ATT&CK techniques, achieving a macro F1-score of 0.83 on the CAPEC dataset, significantly outperforming baseline models such as PRIMUS (0.72) and CTI-BERT (0.65). Expert evaluation confirms that the integrated framework enhances interpretability, traceability, and practical relevance for industrial cybersecurity operations. This thesis demonstrates that NLP and Large Language Models can effectively transform unstructured textual intelligence into structured, ATT&CK-aligned CTI for manufacturing systems. The proposed framework supports earlier threat awareness and proactive defence, advancing industrial cybersecurity from reactive response toward predictive and intelligence-driven protection in Industry 4.0.
    13 0
  • ItemRestricted
    Adversarial Robustness of Intrusion Detection Systems for the In-Vehicle Networks of Connected and Autonomous Vehicles
    (Saudi Digital Library, 2026) ALORAINI, FATIMAH SULAIMAN; Javed, Amir
    Connected and autonomous vehicles (CAVs) rely on machine learning (ML)-based intrusion detection systems (IDSs) to secure in-vehicle network (IVN) communications. However, ML models are inherently vulnerable to adversarial attacks. While prior adversarial research in CAVs has predominantly focused on perception models, particularly object detection, the robustness of IVN-based IDSs remains largely underexplored. This thesis addresses this gap by investigating the adversarial robustness of IVN-based IDSs, introducing an IVN-specific threat taxonomy, and developing an attack method capable of generating adversarial IVN frames under varying levels of attacker knowledge of the deployed IDS model. Experimental results demonstrate that adversarial manipulation poses a severe threat to IVN-based IDSs. Under complete attacker knowledge of the deployed IDS model, detection performance drops from an F1-score of 99%toaslowas19%, withattacksuccess rates reaching up to 89%. Even under limited knowledge, detection performance decreases from 95% to 38%, with success rates of up to 60%. To mitigate these vulnerabilities, this thesis proposes Explainability guided Counterfactual Adversarial Training (EXCAT), a novel defense mechanism that leverages model explainability to generate more representative adversarial training examples. EXCAT restores detection performance to up to 94% and reduces attack success rates to as low as 7.55%, demonstrating that explainability-guided training offers a promising direction for strengthening IVN-based IDS robustness and improving the safety of deployed CAV systems.
    21 0

Copyright owned by the Saudi Digital Library (SDL) © 2026