Saudi Cultural Missions Theses & Dissertations

Permanent URI for this communityhttps://drepo.sdl.edu.sa/handle/20.500.14154/10

Browse

Search Results

Now showing 1 - 10 of 34
  • ItemRestricted
    PRIVACY-PRESERVING INTRUSION DETECTION FOR THE INTERNET OF MEDICAL THINGS USING ENSEMBLE AND FEDERATED LEARNING
    (Saudi Digital Library, 2026) Alsolami, Theyab; Ilyas, Mohammad
    The rapid proliferation of the Internet of Medical Things (IoMT) has transformed healthcare by enabling continuous monitoring, intelligent diagnostics, and data-driven clinical decision-making. However, this increased connectivity has significantly expanded the attack surface of healthcare systems, exposing sensitive patient data and critical medical devices to cyber threats such as intrusion and data exfiltration attacks. Ensuring both strong security and strict privacy preservation in IoMT environments remains a fundamental and unresolved challenge. This dissertation investigates the design and evaluation of robust and privacypreserving intrusion detection systems (IDS) for IoMT networks using advanced machine learning techniques. The research first examines the effectiveness of ensemble learning–based IDS models in centralized settings, evaluating Stacking, Bagging, and Boosting approaches with Random Forest and Support Vector Machine base learners on the WUSTL-EHMS-2020 dataset. Experimental results demonstrate that ensemble learning significantly enhances detection performance, with the Stacking model achieving an accuracy of 98.88%, followed by Bagging at 97.83%, while Boosting exhibits comparatively lower performance. Building on these findings, the dissertation extends intrusion detection to decentralized and privacy-sensitive IoMT environments through a federated learning (FL) framework integrated with Differential Privacy (DP) and secure aggregation mechanisms. Multiple experimental configurations are systematically analyzed, including raw imbalanced data, centralized SMOTE, and clientside (per-client) SMOTE under varying privacy budgets (ϵ = 3.0, 10.0, and non-private baselines). Results show that privacy-preserving federated models frequently match or exceed non-private baselines. In particular, raw imbalanced and per-client SMOTE configurations achieve high detection accuracy (approximately 94.6%) even under strict privacy constraints (ϵ = 3.0), demonstrating effective learning with minimal utility loss. Furthermore, client-side data balancing consistently outperforms centralized balancing, providing improved training stability while maintaining full data decentralization and patient confidentiality. Overall, this dissertation presents a comprehensive, scalable, and privacy compliant intrusion detection framework for IoMT systems. By integrating ensemble learning, federated learning, class imbalance mitigation, and differential privacy, the proposed approach successfully balances detection accuracy, privacy preservation, and computational efficiency. The findings provide both theoretical insights and practical guidelines for deploying secure and regulation-compliant IDS solutions in real-world healthcare IoMT environments.
    4 0
  • ItemRestricted
    Evaluating Employee Awareness and Response to Phishing Attacks in Financial Institutions in Saudi Arabia
    (Saudi Digital Library, 2026) Alduhaish, Omar; Zaynab, Lamoyero
    Phishing is one of the most widespread forms of cybersecurity threat to financial institutions, as it is not a technical flaw, but a human vulnerability. The research evaluates employee awareness and response to phishing attacks in financial institutions in Saudi Arabia, which represents a significant gap in the literature on the behavioural, cultural and organizational aspects of the Saudi context. The quantitative approach was adopted whereby structured online survey was administered to 147 employees working in commercial banks, Islamic banks, and licensed financial service providers. The survey measured phishing knowledge, behavioural responses, training effectiveness, and included scenario-based detection tasks. The results indicate moderate to high awareness of phishing indicators at a theoretical level, but there are important gaps in practical detection, especially of sophisticated and authority-based phishing. Correlation analysis showed that job role affected phishing detection performance, especially in the ability to distinguish between phishing and legitimate emails apart. IT/cybersecurity staff showed the most balanced results, while finance/accounting staff also performed consistently, although the sample size was small. Administrative, management, and customer service staff showed larger gaps between the two tasks. Age did not show a clear linear relationship with detection ability. Therefore, this research finds that just raising awareness is not sufficient, and that financial institutions should have role-specific, continuous and culturally-sensitive training programmes that can transform awareness into consistent and secure behaviour
    21 0
  • ItemRestricted
    Securing Saudi Arabia’s Smart Cities and Critical Infrastructure Against APTs: A Framework for IoT/OT Forensic Readiness
    (Saudi Digital Library, 2025) Alarjani, Abdulaziz; Lutui, Raymond
    The Vision 2030 of Saudi Arabia has encouraged the development of smart cities by means of all-inclusive integration of Internet of Things (IoT) and Operational Technology (OT) systems. While this transformation is very positive, it also makes critical national infrastructure more vulnerable to advanced cyber threats like Advanced Persistent Threats (APTs). This dissertation demonstrates that while the Kingdom is investing heavily in cybersecurity, there is a major gap in the area of forensic preparedness in these complex IoT/OT environments. The main problem is not only technical, but also related to major legal and procedural ambiguities in the applicable frameworks. This paper conducts a Multi-Vocal Literature Review (MVLR) of Saudi Arabia's Anti-Cyber Crime Law and Personal Data Protection Law (PDPL) to show how laws that are intended for conventional IT are causing challenges for investigators in obtaining digital evidence from Smart City systems. A comparative study of international frameworks, followed by a derived SWOT analysis, characterises a pressing demand for clarity of procedure on a jurisdictional basis. The paper concludes with four useful suggestions for how forensic preparedness practice may be enhanced by addressing these gaps in the law through mandatory 'forensics by design', standardised procedures, and capacity building of locally based expertise. This study contributes to a policy-focused approach to securing smart cities through the inclusion of legal and procedural considerations into the technical cybersecurity strategy for the Kingdom of Saudi Arabia.
    19 0
  • ItemRestricted
    Public Awareness, Trust and Perception of Cybersecurity Development in Saudi Digital Governance: A Quantitative Study under Vision 2030 Framework
    (Saudi Digital Library, 2025) ِAlshaeri, Abdulaziz; Knabe-Nicol, Susanne
    Despite extensive digital transformation efforts, Saudi Arabia faces cybersecurity threats, which highlights the need for increased public cybersecurity resilience. This study addresses an important gap in understanding public awareness, trust and perception regarding cybersecurity within Saudi Arabia’s Vision 2030 digital governance initiatives. The primary aim was to analyse the levels of public awareness, trust and perception of cybersecurity practices among Saudi citizens. By employing Technology Acceptance Model (TAM), complemented by literature on institutional trust and digital literacy, this research adopted a positivist, quantitative approach. An online survey of 96 respondents was conducted, analysed through descriptive statistics, Pearson correlation, regression analyses, and independent-sample t-tests. Findings demonstrated formal education significantly improves cybersecurity awareness, whereas technical understanding of cyber threats and risks among citizens alone does not increase further learning motivation. Trust in institutions strongly predicts perceived cybersecurity protection, with notable disparities based on gender and employment sector. Clear government communication strengthens trust, but macro-level cybersecurity threats fail to improve individual data protection confidence. Key recommendations include targeted cybersecurity education programmes for less-educated groups, gender-sensitive cybersecurity initiatives addressing specific threats faced by Saudi women, and personalised, actionable governmental cybersecurity communication.
    38 0
  • ItemRestricted
    Enhancing Learner Engagement and Personalisation in AI-Powered Quiz Application through Adaptive Learning, Gamification, and Mobile Optimisation
    (Saudi Digital Library, 2025) Alnageeb, Moaz Omar; papazoglou, varvara
    This dissertation investigates the integration of adaptive learning techniques, gamification elements, and mobile optimisation into SkillsDotAI, an AI-powered educational platform that dynamically adjusts question difficulty based on real-time user performance. The research addresses three core questions concerning adaptive learning implementation, gamification’s impact on engagement, and mobile accessibility in educational technology. Thesystem employs a sophisticated architecture built on Node.js/Express.js with PostgreSQL database integration, featuring a multi-stage difficulty adjustment algorithm that adapts question complexity across discrete learning phases. Central to the platform is an AI-powered feedback system utilising Claude 3 Haiku, which provides personalised learning guidance based on comprehensive session data analysis. Gamification elements, including achievement badges, global leaderboards, and progress tracking, are implemented to enhance user motivation and engagement. A comprehensive evaluation was conducted with 100 participants who interacted with both adaptive and competitive learning modes. Results demonstrate strong user recognition of adaptive features, with 77% of participants perceiving intelligent difficulty adjustments. Statistical analysis revealed significant positive correlations between perceived adaptability and overall satisfaction (r = 0.305, p = .002), and between feedback helpfulness and satisfaction (r = 0.577, p ≤ .001). The mobile design approach proved highly successful, with 79% of participants using mobile devices and strong positive correlations between mobile preference and satisfaction (r = 0.348, p ≤ .001). Keycontributions include empirical validation of transparent adaptive learning mechanisms, demonstration of relationships between adaptive features and AI-powered feedback, and practical frameworks for mobile-optimised educational technology development. The research provides evidence that users who recognise adaptive system behaviours report higher satisfaction levels, challenging assumptions about transparent versus hidden adaptation strategies. This work advances the field of AI in education by providing a robust technical framework for adaptive learning implementation, comprehensive evaluation methodologies for complex educational systems, and practical insights for developing engaging, accessible learning platforms
    19 0
  • ItemRestricted
    Metadata-Centric Cybersecurity Classification: A Fair Benchmark of LLMs and Classical Models
    (Saudi Digital Library, 2025) Binothman, Elyas; Chaudhry, Umair Bilal
    Cybersecurity breach classification supports triage and risk response but is hindered by heterogeneous reporting, class imbalance, and limited semantic coverage in traditional pipelines. Prior work has relied on rule-based heuristics and classical models (SVM, Random Forest) with heavy feature engineering, while recent LLM studies rarely evaluate breach metadata under identical, fair splits; severity labels are often absent or not reproducibly constructed. We present a metadata-centric benchmark on the Privacy Rights Clearinghouse chronology spanning two tasks: breach-type classification and severity tiering in three and five labels, with severity derived reproducibly from native fields using a Breach Level Index style mapping. All models share one preprocessing recipe and a single stratified 80/20 train–test split. We compare parameter-efficient transformers (DistilBERT and T5 with LoRA) against tuned tabular baselines (Linear SVM, Random Forest, compact ANN). On breach type, DistilBERT achieves the strongest results (Accuracy 0.943; Macro– F1 0.840), surpassing tabular baselines. For severity, a classweighted ANN on TF–IDF and categorical features attains the highest Macro–F1 at both granularities, while T5 shows high accuracy but low Macro–F1, indicating majority-class bias. The study contributes a unified PRC schema with transparent severity construction, a fair head-to-head comparison under identical conditions, and an efficiency-oriented training recipe suitable for modest hardware.
    16 0
  • ItemRestricted
    Evaluating Machine Learning for Intrusion Detection in CAN Bus for in-Vehicle Security
    (Saudi Digital Library, 2025) Alfardus, Asma; Rawat, Danda
    The past decade has seen a potential rise in the automobile industry accompanied by some serious challenges and threats. Increased demand for intelligent transportation system facilities has given a boom to the automotive industry. A safer and better experience is much sought from vehicles. It opens opportunities of including autonomous vehicles and Vehicle to Everything technologies in the automotive sector. Enabling vehicles to connect to various services exposes to compromise and misuse by the adversaries. There are numerous electronic devices in the modern vehicle which communicate with each other using multiple standard communication protocols. State-of-the-art vehicles are the assembly of complex mechanical devices with the sophisticated technology of electronic devices and connections to the external world. Controller Area Network (CAN) is one of the widely used protocols for in-vehicle communications. However, the lack of some fundamental security features such as encryption and authentication in CAN makes it vulnerable to security attacks. The backbone of connecting autonomous vehicles is CAN with limited bandwidth and exposure to unauthorized access. Various attacks compromise the confidentiality, integrity, and availability of vehicular data through intrusions which may endanger the physical safety of vehicles and passengers. These security shortcomings, therefore, lead to accidents and financial loss to the users of vehicles. To protect the in-vehicle electronic devices, researchers have proposed several security countermeasures. In this work, we discuss various security vulnerabilities and potential solutions to CAN’s. Further, a machine learning-based approach is also developed to devise an Intrusion Detection System for the CAN bus network. This study aims to explore the adaptability of the proposed intrusion detection system across diverse vehicular architectures and operational conditions. Furthermore, the findings contribute to advancing the state-ofthe-art in automotive cybersecurity, fostering safer and more resilient transportation ecosystems. Moreover, it investigates the scalability of the intrusion detection system to handle the increasing complexity and volume of data generated by modern vehicles.
    25 0
  • ItemRestricted
    Human Vulnerability Attack in Saudi Arabia
    (University of Portsmouth, 2025) AlZabin, Naif Abdullah M; Zaynab, Lamoyero
    Human vulnerability attacks, which use people rather than technology to get into networks, are a growing cybersecurity problem. This research examines human vulnerability attacks in all key Saudi Arabian industries and proposes effective mitigation techniques. A quantitative survey was used to collect data from Saudi Arabian banking, healthcare, energy, and government professionals. According to the results, psychological biases and repeated lapses dramatically increase cyberattack risk. A majority of respondents agreed that combining training, policy, and technology minimizes the danger of human vulnerability assaults, supporting the theory. Ineffective training and incomplete technical implementation were found, highlighting the need for adjustments. The research underlines the significance of leadership in developing cybersecurity awareness and establishing a security-conscious culture in enterprises. Implementing technical defenses, improving training, and strengthening policies are the study's cybersecurity suggestions. Future studies should increase sample size, examine particular psychological biases, and assess the long-term efficacy of integrated cybersecurity methods.
    15 0
  • ItemRestricted
    Predictors of Cybersecurity Knowledge, Attitude, and Behaviours among Nurses in Saudi Arabia
    (Saudi Digital Library, 2025-05-21) Alanazi, Abdulhamid Khalifah; Khalifeh, Anas
    Background: Cybersecurity is becoming increasingly critical in healthcare, as nurses frequently access sensitive patient data through electronic health records (EHRs) and other digital platforms. Despite this, gaps in nurses' knowledge, attitudes, and behaviors (KAB) regarding cybersecurity pose risks to data security, especially in Saudi Arabia, where healthcare digitization is expanding rapidly. Research in this area remains limited. Aim: The aim of this study is to explore the predictors of cybersecurity knowledge, attitudes, and behaviors among nurses in Saudi Arabia. Methodology: This cross-sectional, descriptive correlational study was conducted in three hospitals in northern Saudi Arabia: King Khalid Hospital, Prince Abdulaziz Bin Musaed Hospital, and Qurayyat General Hospital. A total of 190 nurses were selected using a convenient sampling method, and then they were surveyed using the Human Aspects of Information Security Questionnaire (HAIS-Q) to assess their cybersecurity knowledge, attitude, and behavior (KAB). Sociodemographic, work-related, and organizational variables were analyzed using multiple regression to identify significant predictors of cybersecurity KAB. Results: Overall, 190 nurses participated in the study, with a mean age of 30.69 years (SD = 7.96). The results showed moderate levels of cybersecurity knowledge, attitudes, and behaviors among nurses in Saudi Arabian hospitals. The highest-scoring domain was mobile device usage, while password management scored the lowest. Significant differences in cybersecurity knowledge were found based on educational level (F = 3.626, p = .029) and monthly income (F = 3.196, p = .043), with nurses holding master’s or doctoral degrees and those earning higher salaries showing better knowledge scores. A statistically significant difference in knowledge scores was also observed based on the clarity of cybersecurity policies (F = 3.179, p = .044). No significant differences were found in attitudes or behaviors based on these variables (p > .05). Cybersecurity knowledge was strongly and positively correlated with both attitude and behavior (p < .001). Similarly, cybersecurity attitude was positively associated with behavior (p < .001). No significant correlations were found between the main variables and demographic factors such as age or years of experience. Cybersecurity attitude (β = .696, p < .001) and behavior (β = .231, p < .001) were significant predictors of cybersecurity knowledge. In turn, cybersecurity knowledge (β = .605, p < .001) and behavior (β = .358, p < .001) significantly predicted attitude. Finally, cybersecurity knowledge (β = .333, p < .001) and attitude (β = .571, p < .001) significantly predicted behavior. Conclusion: The study highlights moderate cybersecurity KAB among nurses, influenced by education, policy clarity, and work-related factors. Strong correlations exist between knowledge, attitudes, and behaviors, emphasizing the need for targeted training and institutional cybersecurity reinforcement
    23 0
  • ItemRestricted
    The Influence of Emotions on Employees' Cybersecurity Protection Motivation Behaviour: Examining the Mediating Effect of Self- Efficacy and Moderating Role of Cybersecurity Awareness
    (Aston University, 2024-12) Alshammari, Abdulelah Sulaiman; Vladlena, Benson; Luciano, Batista
    Cyber threats at the employee level are a complex issue that needs more attention. Psychological research shows that emotions influence individuals' motivation to engage in cybersecurity practices. Most existing studies focus on how external factors affect employees' cybersecurity behaviours, including risk perception, rational decision making in cybersecurity policies, security regulations, compliance, and ethical behaviour. However, research into employees' internal capabilities and psychological factors, such as emotions, that enable them to protect organisational information assets is still in its early stages. Therefore, this thesis aims to explore the influence of employees' emotions on their cybersecurity protection motivation behaviours within Saudi Arabia’s context. The research highlights self-efficacy as a mediating factor and cybersecurity awareness as a moderating factor. This thesis is underpinned by the Broaden and Build Theory (BBT) and Protection Motivation Theory (PMT) to explore the influence of negative and positive emotions on employees' cybersecurity protection motivation behaviour. Moreover, it adopted a deductive research design, employing a quantitative approach through an online survey, resulting in 383 responses from participants at King Abdulaziz University in Saudi Arabia. The data were analysed using partial least squares structural equation modelling (PLS-SEM) via SmartPLS 4 software, which included measurement and structural model assessments. The study found that negative emotions do not influence employees' self-efficiency or motivation to protect themselves. Moreover, it found that self-efficacy does not mediate the relationship between negative emotions and employees' protection motivation behaviour. However, positive emotions positively influence employees' self-efficacy and protection motivation behaviour. In addition, self-efficacy positively mediates the relationship between positive emotions and employees’ protection motivation behaviour. Regarding cybersecurity awareness, it was found that it positively influences employees' protection motivation. Moreover, it also moderates the relationships between positive emotions and self-efficacy and protection motivation behaviour, and between self-efficacy and protection motivation behaviour. The study contributes to cybersecurity by showing how emotions influence protective behaviours. It introduces a novel model based on BBT and PMT, exploring how emotions influence employees' self-efficacy and protection motivation behaviour. Moreover, the study's empirical findings address a gap by focusing on how emotions influence cybersecurity protection motivation behaviours.
    23 0

Copyright owned by the Saudi Digital Library (SDL) © 2026