{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T19:13:40Z","timestamp":1780082020035,"version":"3.54.0"},"reference-count":98,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000001","name":"U.S. National Science Foundation","doi-asserted-by":"publisher","award":["2028397"],"award-info":[{"award-number":["2028397"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>In an increasingly interconnected world, cybersecurity professionals play a pivotal role in safeguarding organizations from cyber threats. To secure their cyberspace, organizations are forced to adopt a cybersecurity framework such as the NIST National Initiative for Cybersecurity Education Workforce Framework for Cybersecurity (NICE Framework). Although these frameworks are a good starting point for businesses and offer critical information to identify, prevent, and respond to cyber incidents, they can be difficult to navigate and implement, particularly for small-medium businesses (SMBs). To help overcome this issue, this paper identifies the most frequent attack vectors to SMBs (Objective 1) and proposes a practical model of both technical and non-technical tasks, knowledge, skills, abilities (TKSA) from the NICE Framework for those attacks (Objective 2). This research develops a scenario-based curriculum. By immersing learners in realistic cyber threat scenarios, their practical understanding and preparedness in responding to cybersecurity incidents is enhanced (Objective 3). Finally, this work integrates practical experience and real-life skill development into the curriculum (Objective 4). SMBs can use the model as a guide to evaluate, equip their existing workforce, or assist in hiring new employees. In addition, educational institutions can use the model to develop scenario-based learning modules to adequately equip the emerging cybersecurity workforce for SMBs. Trainees will have the opportunity to practice both technical and legal issues in a simulated environment, thereby strengthening their ability to identify, mitigate, and respond to cyber threats effectively. We piloted these learning modules as a semester-long course titled \u201cHack Lab\u201d for both Computer Science (CS) and Law students at CSU during Spring 2024 and Spring 2025. According to the self-assessment survey by the end of the semester, students demonstrated substantial gains in confidence across four key competencies (identifying vulnerabilities and using tools, applying cybersecurity laws, recognizing steps in incident response, and explaining organizational response preparation) with an average improvement of +2.8 on a 1\u20135 scale. Separately, overall course evaluations averaged 4.4 for CS students and 4.0 for Law students, respectively, on a 1\u20135 scale (college average is 4.21 and 4.19, respectively). Law students reported that hands-on labs were difficult, although they were the most impactful experience. They demonstrated a notable improvement in identifying vulnerabilities and understanding response processes.<\/jats:p>","DOI":"10.3390\/jcp5040106","type":"journal-article","created":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T13:03:02Z","timestamp":1764594182000},"page":"106","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Bridging Cybersecurity Practice and Law: A Hands-On, Scenario-Based Curriculum Using the NICE Framework to Foster Skill Development"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9398-3330","authenticated-orcid":false,"given":"Colman","family":"McGuan","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, Washkewicz College of Engineering, Cleveland State University, Cleveland, OH 44115, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9525-9557","authenticated-orcid":false,"given":"Aadithyan","family":"Vijaya Raghavan","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Washkewicz College of Engineering, Cleveland State University, Cleveland, OH 44115, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Komala M.","family":"Mandapati","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Washkewicz College of Engineering, Cleveland State University, Cleveland, OH 44115, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3318-9087","authenticated-orcid":false,"given":"Chansu","family":"Yu","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Washkewicz College of Engineering, Cleveland State University, Cleveland, OH 44115, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Brian E.","family":"Ray","sequence":"additional","affiliation":[{"name":"College of Law, Cleveland State University, Cleveland, OH 44115, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Debbie K.","family":"Jackson","sequence":"additional","affiliation":[{"name":"Department of Instructional Excellence, Administration Center, Cleveland State University, Cleveland, OH 44115, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sathish","family":"Kumar","sequence":"additional","affiliation":[{"name":"College of Law, Cleveland State University, Cleveland, OH 44115, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,1]]},"reference":[{"key":"ref_1","unstructured":"Hiscox Group (2024). Cyber Readiness Report 2024, Hiscox Group. Technical Report."},{"key":"ref_2","unstructured":"Ponemon Institute, and IBM Security (2024). Cost of a Data Breach Report 2024, IBM. Technical Report."},{"key":"ref_3","unstructured":"Dojkovski, S., Lichtenstein, S., and Warren, M.J. (2007, January 7\u20139). Fostering Information Security Culture in Small and Medium Size Enterprises: An Interpretive Study in Australia. Proceedings of the 2007 European Conference on Information System (ECIS), St. Gallen, Switzerland."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1109\/MC.2016.223","article-title":"Cybersecuring Small Businesses","volume":"49","author":"Paulsen","year":"2016","journal-title":"Computer"},{"key":"ref_5","unstructured":"U.S. Small Business Administration, Office of Advocacy (2024). 2024 Small Business Profile: United States, Technical Report."},{"key":"ref_6","unstructured":"Raghavan, A.V., and Yu, C. (2024, January 3). Task, Knowledge, Skill, and Ability: Equipping the Small-Medium Businesses Cybersecurity Workforce. Proceedings of the 2024 ASEE Annual Conference & Exposition, American Society for Engineering Education, Portland, OR, USA."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Newhouse, W.D., Keith, S., Scribner, B., and Witte, G.A. (2017). National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework, Special Publication NIST SP 800-181.","DOI":"10.6028\/NIST.SP.800-181"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"101607","DOI":"10.1016\/j.cose.2019.101607","article-title":"A framework for competence development and assessment in hybrid cybersecurity exercises","volume":"88","author":"Bukauskas","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"539","DOI":"10.3390\/jcp1040027","article-title":"Assessing Competencies Using Scenario-Based Learning in Cybersecurity","volume":"1","author":"Ghosh","year":"2021","journal-title":"J. Cybersecur. Priv."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Joint Task Force on Cybersecurity Education (2017). Cybersecurity 2017 Version 1.0: Curriculum Guidelines for Post-Secondary Degree Programs in Cybersecurity, Association for Information Systems SIGSEC. Technical Report.","DOI":"10.1145\/3184594"},{"key":"ref_11","first-page":"6","article-title":"Problem-Based Learning for Cybersecurity Education","volume":"7","author":"Shivapurkar","year":"2020","journal-title":"J. Colloq. Inf. Syst. Secur. Educ."},{"key":"ref_12","unstructured":"Clark, R. (2009). Accelerating Expertise with Scenario-Based Learning, Learning Blueprint\/American Society for Training and Development."},{"key":"ref_13","first-page":"5","article-title":"Overview of Problem-Based Learning: Definitions and Distinctions","volume":"9","author":"Savery","year":"2006","journal-title":"Interdiscip. J.-Probl.-Based Learn."},{"key":"ref_14","unstructured":"(2025, October 04). NICE Challenge Project. 2014. Available online: https:\/\/www.nice-challenge.com\/."},{"key":"ref_15","unstructured":"Cowan, C., Arnold, S., Beattie, S., Wright, C., and Viega, J. (2003, January 22\u201324). Defcon Capture the Flag: Defending Vulnerable Code from Intense Attack. Proceedings of the DARPA Information Survivability Conference and Exposition (DISCEX III), Washington, DC, USA."},{"key":"ref_16","unstructured":"Cheung, R.S., Cohen, J.P., Lo, H.Z., and Elia, F. (2011, January 18\u201321). Challenge-Based Learning in Cybersecurity Education. Proceedings of the 2011 International Conference on Security & Management (SAM 2011), Las Vegas, NV, USA."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Wagner, P.J., and Wudi, J.M. (2003, January 3\u20137). Designing and Implementing a Cyberwar Laboratory Exercise for a Computer Security Course. Proceedings of the 35th SIGCSE Technical Symposium on Computer Science Education, SIGCSE \u201904, Norfolk, VA, USA.","DOI":"10.1145\/971300.971438"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Doupe, A., Egele, M., Caillat, B., Stringhini, G., Yakin, G., Zand, A., Cavedon, L., and Vigna, G. (2011, January 5\u20139). Hit\u2019em Where It Hurts: A Live Security Exercise on Cyber Situational Awareness. Proceedings of the 27th Annual Computer Security Applications Conference ACSAC \u201911, New York, NY, USA.","DOI":"10.1145\/2076732.2076740"},{"key":"ref_19","unstructured":"Ohio Cyber Range Institute (2025, October 04). Available online: https:\/\/www.ohiocyberrangeinstitute.org."},{"key":"ref_20","unstructured":"NIST (2017). National Initiative for Cybersecurity Education (NICE)\u2014The National Cybersecurity Workforce Framework."},{"key":"ref_21","unstructured":"National Institute of Standards and Technology (2020). Workforce Framework for Cybersecurity (NICE Framework), Technical Report NIST SP 800-181r1; Revision 1."},{"key":"ref_22","unstructured":"(2022). Information Security, Cybersecurity and Privacy Protection\u2014Information Security Management Systems\u2014Requirements (Standard No. ISO\/IEC 27001:2022)."},{"key":"ref_23","unstructured":"Barrett, M. (2018). Framework for Improving Critical Infrastructure Cybersecurity Version 1.1."},{"key":"ref_24","unstructured":"Freund, J., and Jones, J. (2014). Measuring and Managing Information Risk: A FAIR Approach, Butterworth-Heinemann."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"85701","DOI":"10.1109\/ACCESS.2022.3197899","article-title":"A Survey on the Cyber Security of Small-to-Medium Businesses: Challenges, Research Focus and Recommendations","volume":"10","author":"Chidukwani","year":"2022","journal-title":"IEEE Access"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"472","DOI":"10.1093\/comjnl\/bxx093","article-title":"Risk and the Small-Scale Cyber Security Decision Making Dialogue\u2014A UK Case Study","volume":"61","author":"Osborn","year":"2017","journal-title":"Comput. J."},{"key":"ref_27","unstructured":"Organisation for Economic Co-Operation and Development (OECD) (2008). OECD Glossary of Statistical Terms\u2013Small and Medium-Sized Enterprises (SMEs) Definition, OECD."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Petersen, R., Santos, D., Wetzel, K.A., Smith, M.C., and Witte, G. (2020). Workforce Framework for Cybersecurity (NICE Framework), Technical Report.","DOI":"10.6028\/NIST.SP.800-181r1"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kim, K., Smith, J., Yang, T.A., and Kim, D.J. (2018, January 5\u20137). An Exploratory Analysis on Cybersecurity Ecosystem Utilizing the NICE Framework. Proceedings of the 2018 National Cyber Summit (NCS), Huntsville, AL, USA.","DOI":"10.1109\/NCS.2018.00006"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"393","DOI":"10.1108\/ICS-07-2018-0080","article-title":"Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs)","volume":"27","author":"Bada","year":"2019","journal-title":"Inf. Comput. Secur."},{"key":"ref_31","first-page":"1","article-title":"Applying Competency-Based Learning Methodologies to Cybersecurity Education and Training: Creating a Job-Ready Cybersecurity Workforce","volume":"1","author":"Tobey","year":"2018","journal-title":"Infragard J."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Wetzel, K. (2021). NICE Framework Competencies: Assessing Learners for Cybersecurity Work, Technical Report.","DOI":"10.6028\/NIST.IR.8355-draft2"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Verizon (2022). 2022 Data Breach Investigations Report, Verizon. Technical Report.","DOI":"10.12968\/S1361-3723(22)70578-7"},{"key":"ref_34","unstructured":"Ponemon Institute (2019). 2019 Global State of Cybersecurity in Small and Medium-Sized Businesses, Ponemon Institute. Technical Report."},{"key":"ref_35","unstructured":"CISA (2019). CISA INSIGHTS."},{"key":"ref_36","unstructured":"Hiscox Group (2022). Cyber Readiness Report 2022, Hiscox Group. Technical Report."},{"key":"ref_37","unstructured":"ENISA (2021). Cybersecurity for SMEs\u2014Challenges and Recommendations, Technical Report."},{"key":"ref_38","unstructured":"ENISA (2022). ENISA Threat Landscape 2020\u2014Web-Based Attacks, Technical Report."},{"key":"ref_39","unstructured":"ENISA (2020). ENISA Threat Landscape 2020\u2014List of Top 15 Threats, Technical Report."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1016\/j.ins.2019.09.013","article-title":"YAKE! Keyword extraction from single documents using multiple local features","volume":"509","author":"Campos","year":"2020","journal-title":"Inf. Sci."},{"key":"ref_41","unstructured":"CISA (2021). Capacity Enhancement Guide: Counter-Phishing Recommendations for Non-Federal Organizations."},{"key":"ref_42","unstructured":"CISA (2021). Capacity Enhancement Guide: Counter-Phishing Recommendations for Federal Organizations."},{"key":"ref_43","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA) (2021). Website Security."},{"key":"ref_44","unstructured":"Australian Cyber Security Centre (ACSC) (2022). Ransomware Prevention Guide, Technical Report."},{"key":"ref_45","unstructured":"National Cyber Security Centre (NCSC) (2021). Mitigating Malware and Ransomware Attacks."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Souppaya, M., and Scarfone, K. (2013). Guide to Malware Incident Prevention and Handling for Desktops and Laptops, Technical Report.","DOI":"10.6028\/NIST.SP.800-83r1"},{"key":"ref_47","unstructured":"European Union Agency for Cybersecurity (ENISA) (2020). ENISA Threat Landscape 2020\u2014Web-Based Attacks, Technical Report."},{"key":"ref_48","unstructured":"Federal Trade Commission (FTC) (2018). Cybersecurity for Small Business: Phishing, Federal Trade Commission. Technical Report."},{"key":"ref_49","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA) (2021). Guidance for Managed Service Providers and Small- and Mid-Sized Businesses, Technical Report."},{"key":"ref_50","first-page":"1","article-title":"Science Mapping: A Systematic Review of the Literature","volume":"2","author":"Chen","year":"2017","journal-title":"J. Data Inf. Sci."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"803","DOI":"10.1007\/s11192-010-0294-5","article-title":"Development and application of a keyword-based knowledge map for effective R&D planning","volume":"85","author":"Yoon","year":"2010","journal-title":"Scientometrics"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1109\/TEM.2019.2963489","article-title":"Knowledge Management in the Fourth Industrial Revolution: Mapping the Literature and Scoping Future Avenues","volume":"68","author":"Pellegrini","year":"2021","journal-title":"IEEE Trans. Eng. Manag."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Sun, C., Hu, L., Li, S., Li, T., Li, H., and Chi, L. (2020). A Review of Unsupervised Keyphrase Extraction Methods Using Within-Collection Resources. Symmetry, 12.","DOI":"10.3390\/sym12111864"},{"key":"ref_54","first-page":"8","article-title":"Binary codes capable of correcting deletions, insertions, and reversals","volume":"10","author":"Levenshtein","year":"1965","journal-title":"Sov. Phys.-Dokl."},{"key":"ref_55","unstructured":"Winkler, W.E. (1990). String Comparator Metrics and Enhanced Decision Rules in the Fellegi-Sunter Model of Record Linkage, Educational Resources Information Center (ERIC). Technical Report."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1002\/j.1538-7305.1950.tb00463.x","article-title":"Error detecting and error correcting codes","volume":"29","author":"Hamming","year":"1950","journal-title":"Bell Syst. Tech. J."},{"key":"ref_57","first-page":"63","article-title":"The performance of text similarity algorithms","volume":"4","author":"Prasetya","year":"2018","journal-title":"Int. J. Adv. Intell. Inform."},{"key":"ref_58","unstructured":"National Initiative for Cybersecurity Careers and Studies (NICCS) (2025, October 04). NICE Framework Keyword Search, Available online: https:\/\/niccs.cisa.gov\/tools\/nice-framework."},{"key":"ref_59","unstructured":"Bada, M., Sasse, A.M., and Nurse, J.R.C. (2019). Cyber Security Awareness Campaigns: Why do they fail to change behaviour?. arXiv."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Shojaifar, A., Fricker, S.A., and Gwerder, M. (2020, January 21\u201323). Automating the Communication of Cybersecurity Knowledge: Multi-case Study. Proceedings of the Information Security Education. Information Security in Action, Maribor, Slovenia.","DOI":"10.1007\/978-3-030-59291-2_8"},{"key":"ref_61","unstructured":"Schaffer, S., and Chen, X. (2009, January 3\u20134). Cross-Disciplinary Team Learning: Assessment Guidelines. Proceedings of the EPICS Annual Conference on Service-Learning in Engineering and Computing, Austin, TX, USA."},{"key":"ref_62","unstructured":"Global Investigations Review (2021). The Guide to Cybersecurity Investigations, Global Investigations Review. [2nd ed.]. Available online: https:\/\/globalinvestigationsreview.com\/guide\/the-guide-cyber-investigations-archived\/first-edition\/article\/the-cyber-threat-landscape."},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Chesney, R. (2021). Cybersecurity Law, Policy, and Institutions (Version 3.1), SSRN. Technical Report.","DOI":"10.2139\/ssrn.3547103"},{"key":"ref_64","unstructured":"(2025, October 04). Darknet Diaries. Russia vs. Ukraine: The Biggest Cyber Attack Ever. Darknet Diaries Ep. 54: NotPetya. Available online: https:\/\/www.youtube.com\/watch?v=N20q-ZMop0w."},{"key":"ref_65","unstructured":"(2025, October 04). The Sedona Conference. Incident Response Guide. 2020. Available online: https:\/\/www.thesedonaconference.org\/sites\/default\/files\/publications\/IncidentResponseGuide.pdf."},{"key":"ref_66","unstructured":"WannaCry: The World\u2019s Largest Ransomware Attack (2025, October 04). Video, YouTube. Available online: https:\/\/www.youtube.com\/watch?v=PKHH_gvJ_hA."},{"key":"ref_67","unstructured":"(2025, October 04). WannaCry Ransomware CyberAttack Raises Legal Issues. The National Law Review, 22 May 2017. Available online: https:\/\/natlawreview.com\/article\/wannacry-ransomware-cyberattack-raises-legal-issues."},{"key":"ref_68","unstructured":"Schmitt, M., and Fahey, S. (2025, October 04). WannaCry and the International Law of Cyberspace. Just Security, 22 December 2017. Available online: https:\/\/www.justsecurity.org\/50038\/wannacry-international-law-cyberspace\/."},{"key":"ref_69","unstructured":"(2025, October 04). Hooked By Phisherman: Quarterbacking Breach Response with Law Enforcement. Presentation at RSA Conference. 2021. Available online: https:\/\/www.rsaconference.com\/library\/Presentation\/USA\/2021\/hooked-by-phisherman-quarterbacking-breach-response-with-law-enforcement."},{"key":"ref_70","unstructured":"Global Investigations Review (2023). The Guide to Cybersecurity Investigations, Global Investigations Review. [3rd ed.]. Available online: https:\/\/globalinvestigationsreview.com\/guide\/the-guide-cyber-investigations\/third-edition."},{"key":"ref_71","unstructured":"(2025, October 04). BakerHostetler. U.S. Data Breach Notification Law Interactive Map. Available online: https:\/\/www.bakerlaw.com\/us-data-breach-interactive-map\/."},{"key":"ref_72","unstructured":"Kroah-Hartman, G. (2025, October 04). Keynote: Spectre, Meltdown, & Linux. Video, The Linux Foundation\/YouTube. 2018. Available online: https:\/\/www.youtube.com\/watch?v=lQZzm9z8g_U."},{"key":"ref_73","unstructured":"Simpson, A.P., and Solomon, A.H. (2019). Complying with Breach Notification Obligations in a Global Setting: A Legal Perspective. The Guide to Cyber Investigations, Global Investigations Review. [3rd ed.]."},{"key":"ref_74","unstructured":"(2025, October 04). Celerium. The Complete Guide to Understanding Cybersecurity Frameworks. Available online: https:\/\/www.celerium.com\/cybersecurity-frameworks-a-comprehensive-guide."},{"key":"ref_75","unstructured":"(2025, October 04). Thomson Reuters. Performing Data Security Risk Assessments Checklist. Practical Law\/Thomson Reuters. 2018. Available online: https:\/\/mena.thomsonreuters.com\/content\/dam\/ewp-m\/documents\/mena\/en\/pdf\/other\/data-security-risk-assessments-checklist-thomson-reuters.pdf."},{"key":"ref_76","unstructured":"Basu, A., and Grover, G. (2021). Scenario 24: Internet Blockage, NATO Cooperative Cyber Defence Centre of Excellence. International Cyber Law Toolkit, NATO Cooperative Cyber Defence Centre of Excellence."},{"key":"ref_77","unstructured":"(2025, October 04). RSA Conference. Cyber and Modern Conflict: The Changing Face of Modern Warfare. Session Presented at RSA Conference. 7 June 2022. Available online: https:\/\/www.rsaconference.com."},{"key":"ref_78","unstructured":"Kushner, D. (2025, October 04). The Hacker Who Cared Too Much. Rolling Stone, 29 June 2017. Available online: https:\/\/www.rollingstone.com\/culture\/culture-features\/the-hacker-who-cared-too-much-196425\/."},{"key":"ref_79","unstructured":"(2025, October 04). Darknet Diaries. Ep. 14: OpJustina. YouTube Video. 2021. Available online: https:\/\/www.youtube.com\/watch?v=0qvBYj7F3jo&list=PLtN43kak3fFEEDNo0ks9QVKYfQpT2yUEo&index=14."},{"key":"ref_80","unstructured":"(2025, October 04). Computer Fraud and Abuse Act (CFAA). YouTube Video. 2020. Available online: https:\/\/www.youtube.com\/watch?v=cPr6hZfoBfQ."},{"key":"ref_81","unstructured":"Burt, T. (2025, October 04). Microsoft Takes Court Action Against Fourth Nation-State Cybercrime Group. Microsoft (On the Issues Blog). 30 December 2019. Available online: https:\/\/blogs.microsoft.com\/on-the-issues\/2019\/12\/30\/microsoft-court-action-against-nation-state-cybercrime\/."},{"key":"ref_82","unstructured":"(2025, July 27). Microsoft Corporation. Complaint for Civil Action No. 1:19-cv-01582 (LO\/JFA). United States District Court for the Eastern District of Virginia, Alexandria Division, 2019. Available online: https:\/\/noticeofpleadings.com\/thallium\/files\/FINAL%20COMPLAINT.pdf."},{"key":"ref_83","unstructured":"(2025, October 04). The CyberWire. Taking Down Thallium. YouTube Video. 2020. Available online: https:\/\/www.youtube.com\/watch?v=jGC-UwKVkYc."},{"key":"ref_84","unstructured":"Lubin, A., and Marinotti, E. (2025, October 04). Why Current Botnet Takedown Jurisprudence Should Not Be Replicated. Lawfare. 2024. Available online: https:\/\/www.lawfaremedia.org\/article\/why-current-botnet-takedown-jurisprudence-should-not-be-replicated."},{"key":"ref_85","unstructured":"(2025, October 04). Microsoft. Microsoft Security Bulletin, (n.d.). Available online: https:\/\/learn.microsoft.com\/en-us\/security-updates\/securitybulletins\/2017\/ms17-010."},{"key":"ref_86","unstructured":"U.S. Congress (1996). Health Insurance Portability and Accountability Act of 1996, U.S. Congress. Enacted by the 104th U.S. Congress on August 21, 1996."},{"key":"ref_87","unstructured":"(2025, October 04). Meltdown and Spectre, (n.d.). Available online: https:\/\/meltdownattack.com\/."},{"key":"ref_88","unstructured":"Powell, B.A., and Mercer, S.T. (2023). The Guide to Cyber Investigations, Global Investigations Review. [3rd ed.]."},{"key":"ref_89","doi-asserted-by":"crossref","unstructured":"McInnes, N., and Wills, G. (2021, January 23\u201325). The VoIP PBX Honeypot Advance Persistent Threat Analysis. Proceedings of the 6th International Conference on Internet of Things, Big Data and Security, Online.","DOI":"10.5220\/0010443500700080"},{"key":"ref_90","doi-asserted-by":"crossref","unstructured":"Khan, S., and Sadiq, N. (2017, January 8\u201310). Design and configuration of VoIP based PBX using asterisk server and OPNET platform. Proceedings of the 2017 International Electrical Engineering Congress (iEECON), Pattaya, Thailand.","DOI":"10.1109\/IEECON.2017.8075808"},{"key":"ref_91","unstructured":"U.S. Congress (1986). Computer Fraud and Abuse Act, 1986, U.S. Congress. 18 U.S. Code \u00a7 1030."},{"key":"ref_92","unstructured":"U.S. Congress (1952). 18 U.S. Code \u00a7 1343\u2014Fraud by Wire, Radio, or Television, 1952, U.S. Congress. United States Code, Title 18, Section 1343."},{"key":"ref_93","unstructured":"U.S. Congress (1982). 18 U.S. Code \u00a7 1028\u2014Fraud and Related Activity in Connection with Identification Documents, Authentication Features, and Information, 1982, U.S. Congress. United States Code, Title 18, Section 1028."},{"key":"ref_94","unstructured":"Cherubin, G., Jansen, R., and Troncoso, C. (2022, January 10\u201312). Online Website Fingerprinting: Evaluating Website Fingerprinting Attacks on Tor in the Real World. Proceedings of the 31st USENIX Security Symposium (USENIX Security 22), Boston, MA, USA."},{"key":"ref_95","unstructured":"The Tcpdump Group (2025, October 04). tcpdump\u2014A Powerful Command-Line Packet Analyzer; The Tcpdump Group. 2024. Available online: https:\/\/www.tcpdump.org\/."},{"key":"ref_96","first-page":"39","article-title":"Distributed Denial of Service (DDOS) Attacks Detection Mechanism","volume":"5","author":"Kumarasamy","year":"2012","journal-title":"Int. J. Comput. Sci. Eng. Inf. Technol."},{"key":"ref_97","unstructured":"htr tech (2025). Zphisher: Automated Phishing Tool with 30+ Templates, HTR Tech."},{"key":"ref_98","unstructured":"ngrok, Inc. (2025). ngrok\u2014Secure Introspectable Tunnels to Localhost, ngrok, Inc."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/106\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T13:52:20Z","timestamp":1764597140000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/106"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,1]]},"references-count":98,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040106"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040106","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,1]]}}}