Inquire Now
Industry Research and Analysis from ECCU’s Sharpest Minds
Chief Academic Officer & Dean
Manager of Student Affairs & University Registrar
Senior Executive, Content Management
The modern enterprise IT landscape is undergoing a fundamental transformation. Organizations worldwide are moving away from proprietary Unix-based systems toward open-source Linux infrastructure, driven by demands for cost efficiency, scalability, and security. Linux now powers more than 90% of the world’s cloud infrastructure and over 70% of all internet servers (Red Hat, 2023). For a multinational company transitioning from legacy Unix to Linux, a thorough comparative understanding of both systems is essential to formulating a successful migration strategy.
This report addresses five critical areas: the similarities and differences between Unix and Linux; the Linux shell environment and its role in system interaction and automation; commonly used shell commands and their practical applications; productivity-enhancing shell features; and the strategic benefits of adopting open source Linux distributions. The analysis draws on Security Strategies in Linux Platforms and Applications (3rd ed.) as a primary academic source, alongside additional credible industry and academic references.
This research project investigates strategies for mitigating SQL Injection (SQLi) and Cross-Site Scripting (XSS) vulnerabilities in cloud-hosted e-commerce web applications, examined through the lens of cloud security architecture. As organizations increasingly migrate e-commerce workloads to platforms such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), the attack surface for SQLi and XSS expands to encompass cloud-native components, including API gateways, serverless functions, and managed database services. These two attack vectors remain among the most prevalent threats in the OWASP Top Ten, often leading to unauthorized data access, session hijacking, credential theft, and reputational damage.
This study conducts a theoretical comparative analysis of mitigation strategies—including parameterized queries, input validation frameworks, Content Security Policy (CSP), and cloud-native Web Application Firewalls (WAFs)—evaluating their effectiveness across on-premises and cloud-hosted environments. A systematic literature review synthesizes current academic and industry findings, identifying gaps in the application of cloud-native controls to SQLi and XSS threats. The findings highlight the importance of adopting layered, cloud-aware defense architectures that combine proactive secure coding standards, automated detection tooling, and platform-level controls.
Recommendations are provided for cloud security architects and developers to strengthen resilience against evolving threats in multi-tenant, distributed cloud environments. This project contributes to the broader discourse on cloud application security by bridging theoretical insights with architectural best practices.
This study analyzes the economic and ethical dimensions of vulnerability discovery through a comparative assessment of corporate bug bounty programs and underground exploit markets. This study examines whether companies, by offering bug bounty incentives, are unintentionally promoting or reducing the hacker economy by directing hackers toward ethical disclosure practices. Utilizing secondary data and literature, such as industry reports and academic studies, the project demonstrates that bug bounty programs have experienced significant growth, disbursing millions in rewards and involving thousands of hackers (Bugcrowd, 2024; HackerOne, n.d.).
Simultaneously, dark web markets and exploit brokers provide substantially greater financial rewards for exclusive zero-day exploits (Zetter, 2015; ZERODIUM, n.d.), thereby appealing to a distinct group of hackers. The analysis indicates a complex relationship: bug bounties enhance the professionalism of vulnerability discovery and diminish certain criminal incentives; however, substantial financial rewards in the black market persist, enticing individuals to pursue high-value exploits. The report examines the implications for policy and industry, concluding with recommendations to enhance ethical disclosure frameworks, align incentives, and ensure that corporate practices support cybersecurity while avoiding unintended contributions to illicit exploit trade.
By 2027, agentic AI systems are predicted to conduct more than 25% of business workflows. However, 80% of firms utilizing these agents have already experienced hazardous behaviors in operational settings. This study offers a comprehensive examination of the bidirectional danger landscape confronting agentic AI, differentiating between threats directed at agents (threats-TO) and threats emanating from agents towards organizations and users (threats-FROM). The research employs the MAESTRO seven-layer threat model as an analytical framework, enumerating 30 threat and control categories across both dimensions, systematically arranged by architectural layer from foundational models to human-agent interaction. The paper assesses three agentic-specific security frameworks—MAESTRO (Cloud Security Alliance), the OWASP Top 10 for Agentic Applications, and SHIELD—showing that no single framework provides comprehensive coverage on its own. However, when used together as an integrated defense stack, they provide more than 90% coverage across all threat categories. Governance research shows that current regulatory frameworks, including the NIST AI RMF and the EU AI Act, require agent-specific overlays to address the specific needs of autonomous systems. The article offers bidirectional threat categories, a comparative framework analysis featuring quantitative coverage metrics, sector-specific governance recommendations, and a proposed three-framework defense stack for safeguarding enterprise agentic AI implementations.
Reach out to our Editorial Panel for more information
The EC-Council University Cyber Journal is a scholarly publication that disseminates academic, professional, and creative works produced by faculty, students, and affiliated scholars. The journal is designed to publish content that falls outside the scope of Institutional Review Board (IRB) oversight as defined by applicable federal regulations and institutional policies governing human subject research.
"*" indicates required fields
"*" indicates required fields