
In this paper, a security mechanism that incorporates remote multifactor authentication [MFA] for bank locker security and similar applications is presented. MFA requires authentication by multiple persons and to make the system customer friendly, remote authentication mechanism is designed and implemented. Similarly, a banking server which is always available is prone to be hacked easily. In the designed system, the server is built over a microcontroller and will be available only during the period of transaction. This system makes use of four factor authentication using RFID, Fingerprint, OTP and Password and a Django web server built on a microcontroller which is available only during the transaction. All these components are integrated with the Raspberry Pi using Python and also a website is designed with the help of Django and hosted using Ngrok service.
Adversarial attacks present significant threats to the robustness and security of neural networks, particularly in Remote Sensing Image (RSI) classification. The Fast Gradient Sign Method (FGSM) is a conventional technique for creating adversarial examples by perturbing input data along the gradient of the loss function. However, FGSM’s limitations, including its linearity assumption and fixed perturbation magnitude, often resulting in suboptimal adversarial examples. This paper presents an innovative approach to enhance FGSM by integrating it with Genetic Algorithm (GA) which optimizes the epsilon value iteratively to improve the attack's success rate and robustness. Experiments on EuroSAT and UCMerced-LandUse datasets utilizing deep learning architectures like ResNet, EfficientNet, and MobileNet demonstrate that the GA-enhanced FGSM significantly outperforms the baseline FGSM across several performance metrics, such as accuracy, precision, recall, F1 score, and loss. For instance, the MobileNet model’s accuracy dropped from 95.23
Nowadays ensures that safeguarding sensitive information involves unauthorized person access, stole of day and destroy the stored data in Internet of Things (IOT) systems. In IOT continuous focus on cyber attacks based on limited processing capabilities and improve the internet speed. So reduced the mentioned challenges to process IOT environment with combine of blockchain technology to get the solution. In this research paper make sure that IOT environment working in secure data processing and managing the access of systems. In initial level in iot devices users registered for domain authority and increase privacy of data using public and private key with help of elliptic curve cryptography algorithm. Requests from IoT devices are transmitted through gateways to gateway nodes, where request filtering is performed based on user attribute validation. Subsequently, filtered requests are received by the server, which utilizes the Rock Hyraxes Swarm Optimization (RHSO) method to execute access delegation. Access control decisions are made using the Quorum Byzantine Fault Tolerance algorithm. Finally, mechanisms for client revocation and preservation of client attributes are implemented to enhance security.
Integrating Industrial Control Systems (ICS) with Internet of Things (IoT) technologies has amplified the vulnerability of ICS to a larger range of cyber-attacks, posing significant risks to Critical Infrastructures (CI). Recent cyber-attacks on oil and gas sectors and water treatment plants highlight this potential threat. Current attack detection methods rely on unified machine learning techniques, which pose data privacy and transfer challenges. To address these issues, the self-attention-based learning method has become a popular and effective solution for detecting attacks in ICS. This paper presents a novel Hypergraph Attention-based Multilayer Perceptron Neural Network (HATT-MLPNN) for detecting cyber-attacks in ICS environments. The hypergraph-based attention layer helps to optimise the Multilayer Perceptron Neural Network (MLPNN) weights for different feature sets. Integrating hypergraph attention mechanisms into an MLPNN has significantly increased the ability to capture and leverage complex feature interactions in ICS datasets. The proposed model is evaluated on iTrust’s Secure Water Treatment (SWaT) and Mississippi’s Gas Pipeline dataset and experimental evaluations reveal that the training of the proposed attack detection model is faster when trained on labeled data. The model is consistently outperformed with recall and F1- scores on both datasets.
Data management and protection is one of the biggest factors in any working field or organization and data protection should not be taken lightly. As such, this work is directed towards improving customer’s data stored in a MongoDB database by utilizing proper encryption methodology like RSA-MD5 and RSASHA with suitable padding methodologies. Efficiency of these algorithms is then compared and determined with the variation in storage space between them, and the implementation procedures within this specific MongoDB context. As observed upon implementation, there is a small difference between the storage of MD5 and SHA, with strong focus on each’s security features. Simulations showed that SHA sustained low and steady processed time at the minimum of 0.0021 to 0.0036 s across different record sizes while the processing time of MD5 was significantly higher from 0.0020 to 116.62 s to complete. From this, SHA was found to be more efficient than MD5 and so it appears to be the likely candidate for increasing the efficiency of the subsequent encryption process. This work produces viable results of the impact, as well as the competency of encryption algorithms which helped in the creation of Secure Mongo Data Protection System (SMDPS) utilizing RSA-SHA with OAEP padding. This system is implemented as an atomic operation and it has the capability to prevent access and misuse of data by illegal access. By this, organisations can protect data and sensitive information effectively eradicating organisational inefficiency in similar situations.
Industrial Control Systems (ICS) in water utilities rely on sensors to monitor quality parameters. Sensor drift, a gradual deviation in sensor readings, threatens operational reliability. This paper presents an adaptive Long Short-Term Memory (LSTM) based drift detection method. The proposed approach models normal process behavior with LSTM networks and detects deviations using statistical thresholds. The adaptive method adjusts to the dynamics of ICS without retraining. A case study using the Secure Water Treatment (SWaT) testbed digital twin demonstrates its effectiveness. The proposed method reduces false positives to zero, compared to the 48-per hour found using traditional LSTM methods, and achieves an average detection time of less than 5-s. The adaptive LSTM method enhances drift detection and ensures reliable plant operation, advancing data-driven maintenance strategies in critical infrastructure.
Malware has intensified due to technological advancements. It is critical to identify malware. To detect malware, both static and dynamic methods are used. Sophisticated malware may evade detection by conventional static and dynamic methods. The static and dynamic methods Memory analysis may reveal harmful activities that traditional file analysis may overlook by adding a review of volatile memory to static and dynamic techniques. This is especially useful in discovering complex or fileless malware. Virus behaviors and actions may be uncovered using memory analysis. Computer memory becomes a breeding ground for malware. Therefore, memory analysis should be the top priority in malware detection research. One study found that RAM data might identify malicious software. The use of machine learning in a massive dataset allowed for the detection of memory-based malware. Though it has persisted in the digital age, the effects of malicious software have grown in recent years. The detection of harmful software has traditionally relied on the identification of malware samples and families. These systems use detection approaches that rely on rules and traditional signatures. Machine learning malware detection is the main topic of the research. Differentiating this method is its emphasis on component-dependent malware. We want to develop smart detecting systems that are more robust and sophisticated. The key characteristics of malware are identified using a combination of random forest and naive Bayes classifiers. Viruses are caught by this. The HRFNB Classifier integrates both Naive Bayes and Hybrid Random Forest. Decision Tree, XGBoost, CatBoost, GBM, and LightGBM were among the HRFNB algorithms that were put to the test. The findings were analyzed using Accuracy, F1-score, Precision, Recall, and AUC. Using HRFNB for memory analysis, malware was detected 99.89
Edge data security became the crucial concern of the network connected framework. It demands for the lightweight solutions where the traditional algorithms have not been suitable for the resource constrained devices. Hence, the development of lightweight crypto-solutions has attained the visibility. This proposed leverages the traditional Lightweight Encryption Algorithm (LEA) on reconfigurable hardware such as Field Programmable Gate Array (FPGA) by addressing its potential pitfalls namely vulnerable to differential cryptanalysis. To overcome this, 5-bit Substitution box (S-box) blended with chaos approach has been adopted on the traditional LEA schema. Which also ensures the lightweightness. The substitution and chaotic diffusion processes improves the strength of the LEA to meet out the statistical requirements which was confirmed by conducting the NIST SP 800 – 22 batteries of test by attaining the pass rate of 99.9
Every field is becoming digitalized to improve their respective performance. Digital forensics is a rapidly developing field. This paper purely focuses on securing fingerprint data in an efficient manner as these fingerprints can be a vital clue in some of the cases. To protect a fingerprint by ensuring confidentiality and integrity, this paper proposes a novel encryption scheme based on neural networks, elephant herd optimization (EHO) and combination of some sequences like Fractional Brownian Motion (FBM), Cellular Automata, Modified Logistic Map and Hermite Polynomials. It comprises of two scrambling and two substitution techniques. First, the image is scrambled using EHO. Secondly, the image will be scrambled using FBM. Thirdly, the image will be encrypted by modifying the pixel values using the values obtained from the complex sequences. Finally, neural network is used to generate a key and encryption is carried out by adding the key to the original pixel based on position based (row) value modulo 256 and XNORs the output with position based (column) value for every pixel. The proposed algorithm is subjected to various experimental test and is proven to be robust and secure and resisting attacks.
Elliptic Curve Cryptography (ECC) offers a highly effective and suitable method for implementing public keys in environments with limited resources. The Edwards curve solves the unifiedness and completeness problems with elliptic curves. A scalar multiplication operation is essential to crypto-processors based on curves. This study presents a distinctive FPGA implementation of a Binary Edwards Curve (BEC) cryptographic processor that enhances scalar multiplication through parallelization. The method significantly reduces clock cycle usage by employing multiple hybrid Karatsuba multipliers specifically two and a parallelized Hex Itoh-Tsujii algorithm for field inversion. The suggested architecture further improves resource sharing between point operations and field inversion, resulting in higher throughput over area efficiency. The proposed architecture performs 233-bit point multiplication on Virtex-4 and Virtex-7 platforms, achieving latencies of 0.033 ms and 0.025 ms, respectively, setting new performance benchmarks. This results in a 13
Intrusion detection is an ongoing and never-ending challenge in the era of networking. Coping up with evolution and technology, intruders tirelessly invade personal and organizational workspace intending to crack their system disrupting the CIA (confidentiality, Integrity and Availability) triad. Though numerous attempts have been made to detect and prevent intrusion, attackers find ways to deceive users with evolved types of attacks. Hence, there is a need for faster and more efficient intrusion detection algorithms to classify the normal and attack traffic accurately. This paper presents an unsupervised approach for intrusion detection based on Percentage Split Clustering (PSC). The proposal exploits Spectral Graph Theory, leveraging the Laplacian Matrix, and applies Percentage Split Clustering exhibiting normalized cut for clustering into normal and abnormal traffic. The performance of the proposed method is evaluated with the KDD cup 1999 dataset, and the results show that the application of PSC is promising in terms of silhouette measure, accuracy, detection rate, and false positive rates.
In this research article, the research challenges and potential solutions in five key areas of advanced computer networking, namely Network Function Virtualization (NFV), Machine Learning in Network Security, 5G Networks, Blockchain-Based Solutions for IoT Security, and Software-Defined Networking (SDN) are introduced and discussed. NFV faces issues in management and performance of the network, and issues in transitioning from traditional hardware. ML in security has issues with data quality, transparency, and adversarial robustness. 5G networks encounter deployment, spectrum, and edge computing integration challenges. Blockchain for IoT security must overcome consensus and interoperability hurdles. SDN adoption is hindered by security concerns and traditional management issues. Addressing these challenges will enhance network agility, efficiency, and security, enabling innovative applications such as dynamic service provisioning, proactive security defenses, high-bandwidth applications, and secure IoT ecosystems, ultimately transforming network management and utilization.
The BugBite vulnerability scanner is a comprehensive tool developed to discover security flaws inside online web applications. By applying a combination of dynamic and static analysis approaches the BugBite successfully discovers an array of significant vulnerabilities which includes SQL injection, cross-site scripting (XSS), HTML injection, command injection, clickjacking, path traversal and cross-site request forgery (CSRF). This powerful scanner rigorously checks both the code and behavior of the web application, methodically discovering exploitable flaws that might be abused by malicious organizations. BugBite’s technique entails crawling the whole website by doing in-depth analyses of individual files and disclosing the underlying website structure. Following this first investigation phase, an automated audit is launched which subjecting the web application to a series of targeted assaults to measure its security posture. Augmenting its capabilities, BugBite combines the sophisticated Nmap tool to extend vulnerability detection across network systems and applications. Through port scans and probing, possible security weak points are found that includes features like OS foot printing and service identification. Upon discovery of vulnerabilities, the scanner delivers a complete report summarizing the discovered issues along with recommended techniques for repair. This confluence of cutting edge approaches and integrated tools makes BugBite a powerful option for ensuring online application security.
This work explores the successful integration of machine learning and cryptography, wherein distinguishers have been designed with machine learning techniques. The primary focus is how effectively the deep learning models can be leveraged to uncover intricate patterns in data. Three Neural Distinguishers have been proposed using LightGBM, CNN, and LSTM algorithms to analyze Lightweight Block Ciphers. These models have a simpler architecture than most other related models previously used in the literature. The proposed methods have been applied to the ciphers, LEA, PRESENT, Piccolo-80, and MIDORI. This has led us to achieve an improved distinguisher for LEA covering 14 rounds and PRESENT covering 16 rounds. For the first time, new distinguishers have been achieved for Piccolo-80, covering 9 rounds. A new idea of employing deep learning-aided related key and weak key attacks has been used to obtain a distinguisher covering full rounds of MIDORI.
In this paper we present a model to solve problems based on quantum machine learning approach using optical neural networks. Quantum computers and quantum-based machine learning approaches are gathering momentum in today’s Industry 4 era to solve certain data centric problems. However, the quantum computers are still in incubation stage and technologies still need to evolve to solve such problems. Optical neural networks provide a solution to solve such problems by carrying out the basic functionality and operations of qubits. It is essential to create a model for the same formulate strategies to solve real world problems. The optical neural network provides an improvement in learning rate and inference reliability improves by 34
The widespread adoption of the Industrial Internet of Things (IIoT) across the globe relatively increases the spread of security issues due to the growth of incursion groups through sophisticated nation-state sponsors. These incursion groups are known as Advanced Persistent Threats (APT) that target valued resources and remain undetected for a prolonged period in the victim’s network. Intelligent Learning models play a vital role in providing effective means of identifying such assaults by capturing the network flow and mapping the features to develop significant attack detection strategies to enhance cyber resilience for the IT OT Infrastructure. However, the dynamic characteristics of APT pose Multi-layered monitoring and the traditional learning models fail to detect multiple attack variants of APT. In addition, these learning methods lack decisive features from the obtained high-dimensional heterogeneous IIoT network traffic data. In contrast to the resource-scarce sensor nodes, these strategies are resource-intensive. To address the limitations of the learning model, a Weighted PCA-based Enhanced Deep Neural Network (WPCA_E-DNN) is proposed to identify the APT characteristics. It employs Weighted PCA deployed to improve the model’s interpretability to extract pertinent features and Improved the Genetic Algorithm (GA) by assigning weights to the fitness function and tuning the hyperparameters of DNN to maintain the generalizability and local optima. Therefore, the efficiency of the proposed model is validated using the CICAPT IIoT 2024 dataset. The proposed model exhibits better results with 95.2
The recent bloom in digital technology and the internet has created many ways to share information. The images are the most commonly used to share the information. Securely sharing of images is essential. Image encryption plays a vital role in maintaining privacy. There are many innovative encrypting algorithms available. This paper proposes a novel key generation algorithm based on Mobile numbers, Syllabification and Elements in the Periodic Table (MSE). The generated key and encryption processes, such as block scrambling, pixel scamming, and substitution, are used to encrypt the image. MATLAB R2024a is used to implement the key generation and encryption algorithm. Evaluation matrices like Entropy, correlation coefficient, histogram, encryption quality analysis, NPCR and UACI are used to analyze the performance. The security study reveals that the proposed encryption algorithm, which has NPCR (Number of pixel change rate) and UACI (Unified average changing intensity) values of 99.6216 and 34.353, respectively, correlation values of 0.0051, −0.0098, −0.0080 for diagonal, vertical and horizontal, respectively, and an entropy of 7.951. The study reveals that the proposed encryption algorithm has a performance equal to that of standard algorithms.
In the field of Data Science, Data Governance is an important aspect. With the promulgation of the GDPR (General Data Protection Regulation), data privacy and security concerns are regularised, and researchers are seeking attention to solve the number of associated issues and challenges. The data may be disclosed at various stages of ML model construction, such as data collection, model training, or even after the trained model is released on the market. To solve this, the Fog-based Federated Learning aspect supports collaborative learning in which ML models are constructed locally, and only gradient/ update parameters are shared with the global server. However, the attacks are still possible if the gradients are disclosed. The differential privacy aspect of privacy preservation can be used to protect sensitive data against those attacks. In this article, we propose a differential privacy preservation enabled by the Fog-based Federated Learning framework to ensure users’ privacy for health care data from renowned attacks such as model inversion and data reconstruction attacks. Validation of the proposed framework is done using the iFogsim simulator.
Despite a wide variety of secured authentication schemes is available for to address the issues in Cyber Physical System (CPS) problems, their security is assured only up to some extent. A novel Hypergraph (HG) based hashing technique to have a secure authentication between the IOT edge devices in any Cyber Physical System/Internet of Things environment which can be used between pairs of edges devices is proposed, which is based on the authentication scheme between the edge devices that can achieve informal verification, prevent key escrow problem and also save from various attacks such as perfect forward secrecy attack, impersonation attack, man-in-the-middle attack. The security analysis of proposed HG authentication scheme has been validated by means of formal verification using AVISPA tool and ROR model. Also, the proposed protocol has been compared with the existing protocol and it provides a high resistance of attacks, low computation and communication cost. Comparative security analysis with recently reported techniques shows that the proposed scheme is superior to many techniques in terms of communication and computational costs. The key findings include the capability of HG in strengthening hashing function during authentication and provides better security when compared to existing ones.
Phishing attacks exploit human vulnerabilities to breach security defenses by either stealing a victim’s credentials or by luring a victim to give away their security details. These attacks have emerged as a primary threat, making the networked world increasingly vulnerable. The evolution of phishing from rudimentary schemes to highly targeted and sophisticated tactics can lead to operational disruptions and even catastrophic failures. In response to this threat, the paper proposes a comprehensive framework for mitigating phishing attacks on email. This includes email filtering and multi-factor authentication wherein the user’s credentials are safeguarded using a custom lightweight hash function. The security of the proposed hash function has also been analysed.