Research Methodologies for Cybersecurity in Enterprise Environments: A Narrative Review, Synthesis and Executable Guide
cs.CR
Submitted: 2026-08-25
Updated: 2026-08-25
Comments: 31 pages, 16 figures, 4 tables
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- SoK: Evaluations in Industrial Intrusion Detection Research
- A Systematic Review of Algorithmic Red Teaming Methodologies for Assurance and Security of AI Applications
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and Time
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and Time (Extended Version)
- LAMDA: A Longitudinal Android Malware Benchmark for Concept Drift Analysis
- Dos and Don'ts of Machine Learning in Computer Security
- Chasing Shadows: Pitfalls in LLM Security Research
- Context Contamination in LLM Analysis of Network Security Logs: Poison with Passive Prompt Injection and Mitigation Evaluation
- Security in LLM-as-a-Judge: A Comprehensive SoK
- Reliability without Validity: A Systematic, Large-Scale Evaluation of LLM-as-a-Judge Models Across Agreement, Consistency, and Bias
- Measuring Security Without Fooling Ourselves: Why Benchmarking Agents Is Hard
- Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing
- Evaluating LLM Generated Detection Rules in Cybersecurity
- Beyond Collection: Measuring the Detection Efficacy of Modern Security Logging Standards
- Decoding the MITRE Engenuity ATT&CK Enterprise Evaluation: An Analysis of EDR Performance in Real-World Environments
- On fair and realistic performance evaluations for graph-based lateral movement detectors
- NetSecBed: A Container-Native Testbed for Reproducible Cybersecurity Experimentation
- Federated Cybersecurity Testbed as a Service (FCTaaS): A framework to federate cybersecurity testbeds
- Automated Generation of Cybersecurity Exercise Scenarios
- Beyond Reproducibility: Towards Security-Aware Evaluation of Research Artifacts
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs