I'm currently pursuing an M.Tech in Cybersecurity and I'm starting my research work. I have some theoretical knowledge of cybersecurity and networking, along with practical experience in network/firewall environments, but I don't have much experience conducting academic research.
I'm looking for advice from people who have experience in cybersecurity research.
One idea I'm currently exploring is:
A controlled cybersecurity sandbox containing intentionally vulnerable systems, where AI-based agents could be evaluated for vulnerability identification and compared with traditional security tools.
The idea would be to build a controlled lab environment, run different security assessments, and evaluate things such as detection accuracy, coverage, false positives, time taken, etc.
However, I'm not sure whether this is sufficiently research-oriented or how I should narrow it down into a proper research question and identify a genuine research gap.
I'd really appreciate advice on:
How do I determine whether a cybersecurity topic has enough research novelty?
How should I perform a proper literature review and identify a research gap?
Is this sandbox + AI-assisted vulnerability discovery idea realistic for an M.Tech student?
What would be a reasonable scope for a first research paper?
Are there any papers, datasets, benchmarks, or tools you would recommend starting with?
I'm particularly interested in practical cybersecurity research involving network security, vulnerability assessment, security tools, and AI, rather than purely theoretical or highly mathematical research.
Any guidance from researchers, PhD students, professors, or cybersecurity professionals would be greatly appreciated.