
With the advancement of 5G and IoT, the volume of network traffic is growing in a tremendous rate (e.g., 235.7 Exabytes (EB) in Internet traffic, a 3.2-fold increase from 2016), leading to an alarming rise in different types of attacks. As a result, the requirements of an intrusion detection system (IDS) are also evolving. In addition to having a large number of flow-based intrusion detection systems powered by machine learning techniques, achieving higher accuracy including higher recall and precision has become equally important. While most of the existing works successfully achieve accuracy, they still strive to achieve a good recall score or minimize the False Negative Rate (FNR) as well as the False Positive Rate (FPR). In this paper, we investigate the potential of combining the state-of-the-art neural network models (i.e., CNN, LSTM, and GRU) with attention mechanisms (where attention helps the model to selectively concentrate on more relevant factors) for improving the accuracy of intrusion detection systems. We evaluate our model with the most recent and state-of-the-art benchmark datasets (e.g., CSE-CIC-IDS-2018, and NSL-KDD) and compare the obtained results with the existing works. Empirical results show that our proposed model outperforms the existing works in terms of accuracy while achieving a higher recall score (e.g., a maximum recall of 100
In recent years, deep neural networks (DNNs) have achieved great success in many areas and have been deployed as cloud services to bring convenience to people’s daily lives. However, the widespread use of DNNs in the cloud brings critical privacy concerns. Researchers have proposed many solutions to address the privacy concerns of deploying DNN in the cloud, and one major category of solutions rely on a trusted execution environment (TEE). Nonetheless, the DNN inference requires extensive memory and computing resources to achieve accurate decision-making, which does not operate well in TEE with restricted memory space. This paper proposes a network pruning algorithm based on mean shift clustering to reduce the model size and improve the inference performance in TEE. The core idea of our design is to use a mean shift algorithm to aggregate the weight values automatically and prune the network based on the distance between the weight and center. Our experiments prune three popular networks on the CIFAR-10 dataset. The experimental results show that our algorithm successfully reduces the network size without affecting its accuracy. The inference in TEE is accelerated by 20%.
Online education is popular for its flexibility and high accessibility. The transactions of educational multimedia data resources can effectively promote the development of educational informatization and solve the island situation of educational resources. However, educational resources may be facing severe illegal redistribution. And the copyright is not well protected. In most of existing transaction schemes for educational multimedia data, there is always a centralized third party, which may lead to dispute, distrust, or privacy issues. In this paper, we propose a fair and accountable trading scheme for educational multimedia data based on blockchain. We combine anti-collusion code named BIBD-ACC and asymmetric fingerprinting technology to achieve a relatively strong copyright protection. To realize a fair trading, we implement a smart contract with a reasonable pricing model. In addition, we leverage TEE to solve the privacy issues of public chain and IPFS to mitigate the storage cost of the blockchain. We implemented and evaluated the scheme in Ethereum. The results show that our scheme can achieve well copyright protection and preserve the users’ privacy. The overall overhead is reasonable.
The Internet of Things (IoT) has brought new ways for humans and machines to communicate with each other over the internet. Though sensor-driven devices have largely eased our everyday lives, most IoT infrastructures have been suffering from security challenges. Since the emergence of IoT, lightweight block ciphers have been a better option for intelligent and sensor-based applications. When public-key infrastructure dominates worldwide, the symmetric key encipherment such as Advanced Encryption Standard (AES) shows immense prospects to sit with the smart home IoT appliances. As investigated, chaos motivated logistic map shows enormous potential to secure IoT aligned real-time data communication. The unpredictability and randomness features of the logistic map in sync with chaos-based scheduling techniques can pave the way to build a particular dynamic key propagation technique for data confidentiality, availability and integrity. After being motivated by the security prospects of AES and chaos cryptography, the paper illustrates a key scheduling technique using a 3-dimensional S-box (substitution-box). The logistic map algorithm has been incorporated to enhance security. The proposed approach has applicability for lightweight IoT devices such as smart home appliances. The work determines how seeming chaos accelerates the desired key-initiation before message transmission. The proposed model is evaluated based on the key generation delay required for the smart-home sensor devices.
In the area of information retrieval, in order to improve search accuracy and reduce communication overhead, there is an increasing tendency to adopt ranked search in engines. Ranked search allows cloud servers to search for the top k most relevant documents based on the relevance score between the query keywords and the documents. Recently, with the increasing popularity of encrypted search technologies, ranked searchable encryption is proposed accordingly which focuses on solving ranked search problem over encrypted databases. However, recent studies show that some privacy protection methods commonly used in ranked searchable encryption, like order-preserving encryption (OPE), have some security problems. These problems may lead to the leakage of the relevant ranking privacy information. Meanwhile, most of the existing ranked searchable encryption schemes do not consider the problem of payment for outsourced services. In this paper, we propose a scheme called ranked searchable encryption based on differential privacy and blockchain (DPB-RSE). Specifically, we first add noise drawn from a Laplace distribution into the relevance score to disturb its value. Then we design a smart contract to verify the correctness of the results returned by the cloud server and realize payment fairness. The experiment results demonstrate that the accuracy of search results in this scheme can reach 94% in a small privacy budge.
In this paper, we propose a new privacy-preserving scheme for access control in IoT based on blockchain technology and role-based access control (RBAC). The decentralized property and reliability of the blockchain platform make the proposed solution fit the geographically distributed scenario for IoT better. We extend the traditional RBAC with a new device domain to realize more flexible and manageable access control for the diverse IoT devices. Besides, the scheme takes advantage of zero-knowledge proof and the trusted execution environment (TEE) to ensure the transaction information is confidential, to protect the privacy of the details of access control including information of roles, devices, and policies. To demonstrate the feasibility and effectiveness of the architecture, we implemented our scheme and evaluated on the Ethereum private chain to achieve privacy-preserving access control for IoT. The results show that our scheme is feasible and the cost is acceptable.
Recently, most popular cloud storage solutions offer data syncing and federation, but it also brings security risks. Generally, users can deploy encryption technology to dispel data privacy concerns, but the usability of data will be hindered, e.g., searchability. Multi-user searchable encryption (MUSE) scheme is a paradigm that enables search over encrypted data federated from different users. However, to the best of our knowledge, most of the existing MUSEs are vulnerable to the insider keyword guessing attack (IKGA). Besides, therein real-time team collaboration incurs significant communication and computation costs, leading to high latency. To this end, in this paper, we focus on developing a secure and efficient encrypted search scheme with little cost. Specifically, we first propose a dual-server Public-key Puncturable Encryption with Keyword Search (dPPEKS) scheme in a cross data federation scenario by extending the Puncturable Encryption (PE) and searchable encryption (SE) technologies. Our scheme realizes the efficient and dynamic update of teammates, including user joining and exiting. Through analysis, we prove that our scheme can achieve IND-CKA2 security and resist IKGA. In addition, the performance analysis demonstrates that our scheme gains a better balance in security and efficiency.
Due to the open access nature, communication over unlicensed band, suffers from security threats like eavesdropping. Eavesdroppers are unwanted nodes, attempting to overhear the signal transmitted between two legitimate mobile terminals (MTs), often for malicious purposes. Apart from security issues, it results in significant degradation of secrecy throughput, i.e., the throughput achieved by a legitimate user without being overheard by eavesdroppers. Since with the present technology, it is quite difficult to identify the eavesdroppers even in 5G, the average throughput of the legitimate MTs decreases when the serving base station schedules the eavesdroppers as well, based on the channel condition only. So far, the issue of eavesdropping has rarely been considered in the context of scheduling. In this paper, we propose an anti-eavesdropping proportional fairness (APF) mechanism considering the possibility of eavesdroppers. Our proposed APF technique first estimates a set of suspected eavesdroppers based on sleep mode information, and then reduces the possibility of scheduling these eavesdroppers by imposing penalties. Penalty assignments are based on past average throughput, current channel conditions and modulation/coding schemes. Both Hidden Markov model based analysis and simulations confirm that the proposed APF technique outperforms the traditional proportional fairness protocol in terms of anti-eavesdropping efficiency and secrecy throughput.
Traditional cryptographic block cipher algorithms are often unsuitable for low-resource profiled IoT (Internet of Things) devices. A lightweight cryptographic algorithm is thus mandated. The S boxes are often called the heart of a cryptographic protocol, as a considerable amount of resource and time complexities are associated with the design of an S box. A lightweight S box will consume less memory, less power and less time, ensuring a high-level Shanon’s property of confusion. This paper proposes a lightweight S box design to meet all the requirements of lightweight cryptographic ciphers. The proposed method applies a couple of transformations- the multiplicative inverse in the Galois field (2^4) and affine transformations on selected irreducible polynomials to create 4× 4 S-boxes. Several cryptanalyses such as balance test, bijection property, difference distribution table test, and Boomerang Connectivity were performed to demonstrate the robust characteristics of the proposed method.
Dynamic searchable encryption (DSE) is important to enable dynamic updates (addition/deletion) on an encrypted database maintained by an untrusted server hosted on the cloud. It is desired that such updates should reveal as less as possible the information revealed to the server. As a result, advanced security notions of forward and backward privacy have been proposed to categorise the leakage by via addition and historical deletion, respectively. However, recent backward-(forward)-private schemes are not efficient enough to support very large databases. In this paper, we resort to the trusted execution environment, i.e., Intel SGX, to ease the above bottleneck. In detail, we proposed Magnus that guarantees Type I ^- backward privacy. Our key idea is to leverage a compressed Bloom filter within the Intel SGX’s enclave to verify the deletion documents with the search keyword. This optimisation minimises the communication overhead between the SGX and untrusted memory. Then, to reduce the enclave’s memory, Magnus further relies on a position map-free oblivious data structure maintained by the untrusted server. This improvement is to avoid paging effect in the enclave.
Crowdsourcing enables the harnessing of crowd wisdom for data collection. While being widely successful, almost all existing crowdsourcing platforms store and process plaintext data only. Such a practice would allow anyone gaining access to the platform (e.g., attackers, administrators) to obtain the sensitive data, raising potential security and privacy concerns. If actively exploited, this not only infringes the data ownership of the crowdsourcing requester who solicits data, but also leaks the privacy of the workers who provide data. In this paper, we envision a crowdsourcing platform with built-in end-to-end encryption (E2EE), where the crowdsourced data remains always-encrypted secret to the platform. Such a design would serve as an in-depth defence strategy against data breach from both internal and external threats, and provide technical means for crowdsourcing service providers to meet various stringent regulatory compliance. We will discuss the technical requirements and related challenges to make this vision a reality, including: 1) assuring high-quality crowdsourced data to enhance data values, 2) enabling versatile data analytics to uncover data insights, 3) protecting data at the front-end to fully achieve E2EE, and 4) preventing the abuse of E2EE for practical deployment. We will briefly overview the limitations of prior arts in meeting all these requirements, and identify a few potential research directions for the roadmap ahead.
We build on the phantom gradient attack by introducing some new replacement function candidates for XOR. In this work, we put forward four new candidates’ replacement functions and investigate the impact of different learning rates. We also extend and investigate the new replacement functions power on bitwise rotation XOR, of which previous phantom gradient attack works have struggled.
Blockchain, which has a decentralized management structure, is a technology that challenges conventional wisdom about the availability and durability of an unstable structure, because the network system is managed by volunteers, as opposed to cloud- and network-service providers that leverage centralized management structures. The most popular services based on blockchain (e.g., Bitcoin and Ethereum) have structures that make it challenging to close or discontinue services unless all users agree, no matter if they are honest or malicious. Remarkably, this structure shows stable availability and durability, even now. Considering that unpopular services are eventually terminated, there are more than 2,000 service projects forked from Bitcoin and Ethereum, and it is not realistic to expect all of them to operate in the same manner. When users abandon services like these because of low interest, the blockchain, which depends on volunteers to maintain the system, is affected by reduced availability and durability until it is finally closed. However, unlike centralized management organizations, for service closings, both the indicator and closing mechanism are unclear, because management depends on user dynamism. Therefore, we investigate the mechanism of public blockchain closing by focusing on three decentralized roles of blockchain users. Then, we discuss the closing implication of blockchain-based services using the empirical analysis of 200 different systems.
Virtual private networks (VPNs) allow organizations to support their remote employees by creating tunnels that ensure confidentiality, integrity and authenticity of communicated packets. However, these same services are often provided by the application, in protocols such as TLS. As a result, the historical driving force for VPNs may be in decline. Instead, VPNs are often used to determine whether a communicating host is a legitimate member of the network to simplify filtering and access control. However, this comes with a cost: VPN implementations often introduce performance bottlenecks that affect the user experience. To preserve straightforward filtering without the limitations of VPN deployments, we explore a simple network-level identifier that allows remote users to provide evidence that they have previously been vetted. This approach uniquely identifies each user, even if they are behind Carrier-Grade Network Address Translation, which causes widespread IP address sharing. Such identifiers remove the redundant cryptography, packet header overheads, and need for dedicated servers to implement VPNs. This lightweight approach can achieve access control goals with minimal performance overheads.
High demand for bandwidth has been the primary motivation for device to device (D2D) communication. In cases where direct communication is not possible, two D2D devices are allowed to communicate via relay nodes. The relay selection problem is concerned with the selection of suitable relay device for each such D2D pairs while frequency assignment problem aims to optimally share the available spectrum resources among the active devices satisfying their quality of service requirements. In this work, we present a joint approach to solve the relay selection and frequency allocation problem in context of D2D communications. We incorporated a network coding strategy into our problem formulation which halves the required time slots for a two-way D2D communication. Considering the underlying problem is NP-Complete, we formulated a linear programming based greedy method which shows near-optimal performance with polynomial time complexity. We also compare our proposed algorithm with two existing works and show throughput improvement.
SDN controller in the SDN (Software Defined Network) environment needs to know the topology of the whole network under its control to ensure successful delivery and routing of packets to their respective destinations and paths. SDN Controller uses OFDP to learn the topology, for which it uses a variant of LLDP packets used in the legacy network. The current implementations of OFDP in popular SDN controllers suffer mainly two categories of attacks, namely Topology Poisoning by LLDP packet injection and Topology Poisoning by LLDP packet relay. Several solutions have been proposed to deal with these two categories of attacks. Our study found that, while most of these proposed solutions successfully prevented the LLDP packet injection-based attack, none could defend the relay-based attack with promising accuracy. In this paper, we have proposed a solution, namely Topology Validator, along with its implementation as a module of FloodLight SDN controller, which, apart from preventing LLDP injection-based attack, was also able to detect and thwart the LLDP relay-based attack successfully.
Software developers interact with cryptographic components via APIs provided by a cryptographic library to protect sensitive information such as passwords and files. While cryptographic algorithms have been standardised for over a decade, with variety of crypto libraries that implemented the algorithm, many developers struggle to use the library correctly. This paper evaluates 6 different cryptographic libraries written in 3 different programming languages to find out what factors affect usability. We analyse the usability of surveyed libraries with regards to its API call sequence, number of parameters, exception handling mechanism and documentation. In the end, several recommendations are provided to help developers choose which library to use and more importantly, this paper showcases a few common pitfalls for library designers to prevent common misuses when designing a cryptographic library.
Drones are being diversely used in various areas due to their low price. Most of the use cases demand a secure and reliable wireless communication infrastructure to ensure the quality of service. Such demand boosts the deployment of drones in 5G cellular network. The ground base station (BS) is the main component associated with drones in the 5G cellular network. However, the BS in 5G currently broadcasts the system information message without authentication protection. This poses serious security concerns as the system information message will be used to build connection between the BS and cellular devices. Particularly, adversaries can masquerade as BSs, connect drones, and obtain the data captured by them. Although some attacks have been prevented due to the recent enhancements for 5G cellular protocols, the root vulnerability for the bootstrap phase between drones and the BS still existed and not fixed yet. In this work, we consider a scenario where drones are used in a sport venue to capture the match and 5G cellular network is used to disseminate the live stream. To protect drones from fake BSs, we adopt and optimise the authentication protocol proposed by Singla et al. in [26]. Basically, we modify its architecture by deploying aerial balloon drone BSs over the sport venues to provide more reliable communication service. Moreover, we optimise the verification process in order to reduce the computation overhead on drones. We implemented a prototype of the protocol and evaluated its performance. The experiment results show our authentication protocol is practical to be adopted.