
The Automatic Identification System (AIS) has become a cornerstone of modern maritime navigation, traffic management, and situational awareness, enabling continuous exchange of vessel identity, position, speed, and voyage‐related information across global maritime networks. While AIS significantly enhances navigational safety and operational efficiency, its open and unauthenticated broadcast design introduces critical cybersecurity vulnerabilities that can be exploited through spoofing, message replay, data manipulation, and denial‐of‐service attacks. These threats not only undermine trust in AIS data but also pose serious risks to maritime safety, security, and environmental protection. This paper presents a comprehensive and systematic review of AIS within the broader maritime communication and cybersecurity ecosystem. It examines the architectural foundations of AIS, its integration with physical and digital maritime infrastructures, and its evolving role in maritime domain awareness (MDA). Particular emphasis is placed on identifying inherent protocol‐level weaknesses and analyzing documented cyberattack vectors enabled by software‐defined radio technologies and unencrypted VHF communications. The review further synthesizes recent advances in machine learning and artificial intelligence techniques applied to AIS data, including anomaly detection, trajectory analysis, intrusion detection systems, and federated learning–based privacy‐preserving frameworks. By critically evaluating existing methodologies, datasets, and deployment challenges, this study highlights key limitations related to scalability, real‐time applicability, explainability, and adversarial robustness. Drawing insights from parallel developments in aviation cybersecurity, the paper outlines future research directions aimed at strengthening AIS resilience through adaptive, explainable, and policy‐aligned AI‐driven defenses. Overall, this work provides a structured foundation for advancing AIS cybersecurity research and supports the development of robust, data‐driven strategies to safeguard increasingly digitalized maritime operations.
With the rising penetration of smartphones and mobile applications (apps), mobile apps provide a perspective to interpret and profile their users. Considering that privacy concerns make it increasingly difficult to obtain rich data on users’ app usage, user profiling is implemented solely based on the list of apps installed by the user in this paper. For existing methods, most of them only conduct simple feature engineering and ignore the latent relationships that exist in the installed app list. In this paper, novel multichannel features are proposed to represent users. In addition to mining the app property, the proposed multichannel features exploit the relationships between apps, users, and user attributes. Combined with a 2-dimensional convolutional neural network, the prediction of four user attributes is realized in this paper. Experimental results show that the proposed feature can effectively infer user attributes with the best accuracy of 79.85%, 52.34%, 69.76%, and 69.95% for gender, age, the device’s screen size, and the device’s price, which is 12.39%, 11.75%, 17.61%, and 29.23% higher than the guess based on maximum probability, respectively. Besides, the proposed prediction method has better prediction performance compared to the existing methods and can handle features with high dimensionality well.
As the ability to circumvent internet censorship, encrypted proxies are widely used by criminals in illegal activities (e.g., online gambling and darknet transactions). Thus, detection of encrypted proxy traffic is important. In recent years, deep learning-based approaches have become mainstream approaches. Many deep learning-based approaches transform internet traffic into images, but the transformed images are normally large, leading to huge computational and storage resource overhead. To solve this issue, a novel approach is proposed to compress the image size for reducing overhead in detecting encrypted proxy traffic while still achieving comparable performance. By analyzing the spatiotemporal features of the flow, we discovered that the sequences of sizes, directions, and interval times of the first few packets of a flow can be used to detect encrypted proxy traffic. We compare and analyze the characteristics of the size, direction, interval time of the packet, and the pixel value of the image, and design several equations to encode the sequences of sizes, directions, and interval times of only the first N packets of a flow into an image. Furthermore, a lightweight convolutional neural network (CNN) is constructed to classify the converted images. The experimental results exhibit that the proposed approach could reduce the image size by at least 90% and achieve F1 scores of 99.67% in ShadowsocksR traffic detection and 99.44% in VPN traffic detection. These results show that the proposed approach is effective and efficient. Because of its high efficiency, the proposed method can be applied to large-scale network traffic analysis tasks.
Efficient traffic management in large metropolitan cities has become an increasingly challenging task due to the exponential rise in transportation demands. The optimization of traffic flow in vehicular ad-hoc networks (VANETs) to minimize congestion and delays remains an important research area. Numerous studies have proposed different methods and tools for the development of efficient Traffic Management Systems (TMS). However, contemporary methods often show limitations in scalability, adaptability, and responsiveness, particularly in dynamic vehicular environments where rapid changes in traffic patterns are common. This paper proposes a novel and effective TMS by employing a two-tier architecture that combines fog computing with a centralized system to optimize traffic flow and mitigate congestion. The proposed system integrates the Edmonds–Karp algorithm for maximum flow optimization with clustering techniques implemented at the Roadside Unit (RSU) level. These clustering techniques dynamically classify and manage vehicular requests, enabling real-time traffic decisions. Extensive evaluation and comparison with existing solutions reveal remarkable improvements in traffic optimization, showing the effectiveness of the proposed solution. The two-tier nature of the proposed architecture that balances centralized and distributed decision-making ensures high scalability and adaptability to varying traffic conditions. Through experiments, proposed solution has demonstrated significantly improved results, thus, offers a robust and efficient solution for modern urban environments.
Mobile money services have become essential in providing financial inclusion, particularly in underserved and developing regions, by enabling access to banking, payments, and commerce through mobile devices. Despite their benefits, these services are increasingly targeted by fraudsters employing sophisticated text-based schemes such as phishing, spoofing, and fraudulent short message services (SMS) verification codes. This review of the literature examines how to predict and stop text-based fraud in mobile payment systems. In this review, we systematically analyzed 160 studies from eight databases between 2017 and 2023 to measure, map, and investigate papers released during this period. Research gaps in mobile money payment systems (MMPS) have been highlighted, along with prevalent fraud types that occur in these systems. There was not a single paper that used the NLP approach to identify fraud in MMPS.
The number of companies offering their services online has grown enormously in recent years. Customer confidence in these web applications is, therefore, vital. However, the number of attacks on these sites has also multiplied exponentially, requiring the use of new tools to prevent and defend against them. In this scenario, web application firewalls (WAFs) are emerging as one of the main defenses against website attacks. Their goal is to block those requests that could be considered malicious. Most WAFs are based on filtering requests using regular expressions; nevertheless, this approach has many difficulties in dealing with issues such as detecting zero-day vulnerabilities or replay attacks and requires frequent and exhaustive updates. Thanks to advances in machine learning techniques, it is now possible to simplify the update process and combine manually configured rules with learned rules. In this work, we present a solution for the open-source WAF Shadow Daemon that incorporates a machine learning module for attack detection. The proposed solution improves the detection capability of Shadow Daemon while keeping the latency of the detection process within limits that allow for pleasant interaction with users.
Private set intersection (PSI) is a technique that enables two or multiple parties to find their common elements while keeping all other data confidential and hidden. The research on two-party PSI has been well-developed. However, their dataset is often updated dynamically. When both parties add a new dataset and update their dataset, they need to calculate a new updatable intersection. As new datasets are continually added, there will be multiple PSI between the updated datasets. The research on existing PSI protocols has paid little attention to this scenario. We build upon this and design an efficient multiple PSI protocol ensuring semihonest security under the plain model. Overall, based on the oblivious pseudorandom functions (OPRFs), we build the streaming PSI first, as it allows the OPRF from the previous PSI to be reused in subsequent PSI. Then, we combine it with some lightweight operations to construct our multiple PSI protocol. Furthermore, the idea of our protocol is applicable to many two-party PSI protocols, for which we provide a general framework. Compared to existing works, ours has the lowest communication and runtime in multiple PSI scenarios. For instance, in the second PSI, when the dataset size is 2 24 + 2 16 in both parties, our protocol achieves a 50 × (2.6 ×) improvement in terms of communication (runtime).
This study introduces a novel graphical multifactor authentication (MFA) algorithm that integrates user image hashes and dynamic image grids with cell addresses, called dynamic image grids and cell addresses (DIGCA), aiming to optimize storage requirements while delivering robust security. The algorithm stores image hashes rather than actual images, significantly reducing storage space while maintaining security integrity. In contrast to an existing image recognition algorithm, the algorithm shows a drastic reduction of 99.9% in storage requirements. The MFA system is further secured by the use of dynamic grids, which ensures that even if user’s images are compromised, the specific grid positions remain unknown. Performance analysis demonstrates that the algorithm provides a high level of accuracy with a 95.36% success rate in user authentication over an extended period. Again, aside from the password space and strength of conventional text passwords, the image grid and cell addresses provided a large password space and entropy. With the minimum assumption grid size, it achieves a password space of 1.36 × 10 40 , which makes it virtually impossible for an attacker to guess the correct combination. In addition, the system is optimized for web‐based applications, ensuring cross‐platform compatibility and a consistent user experience across devices, from desktops to mobile platforms. The posttest survey demonstrated users’ satisfaction with the authentication process. Balancing storage efficiency with robust security measures, the proposed MFA algorithm offers a scalable and effective solution for environments requiring high levels of security with minimal data storage demands. The results underscore the algorithm’s potential as a superior alternative to existing MFA schemes, offering both security and practicality in modern authentication systems.
In the era of advanced networking with 5G integration, the need for efficient and scalable intrusion detection systems has become critical to securing large‐scale digital infrastructures. Traditional intrusion detection approaches either analyze individual packets yielding high computational costs or rely solely on flow‐based data, which can miss important sequence‐level information critical to identifying interservice communications and attack behaviors. To address this, we propose a unified machine learning approach that integrates flow‐based and packet‐based detection using convolutional neural networks (CNNs) for advanced intrusion detection. Our method prioritizes flow‐based detection for short flows as the first defense layer and selectively invokes packet‐based detection for longer flows or cases deemed uncertain. Uncertain predictions from the flow‐based stage are identified using a confidence threshold and re‐evaluated by the packet‐based system. We validate our method using a systematically generated dataset from a microservices environment alongside benchmark datasets, including CIC‐IDS‐2017, CIC‐IDS‐2018, and CREMEv2. This hybrid detection strategy yields strong performance in both accuracy and efficiency. Specifically, our approach reduces the computational cost by up to 24 × (approximately 1.38 orders of magnitude) compared to relying solely on packet‐based analysis. Additionally, the model demonstrates strong generalization with detection rates of 95% and 100% for flow‐ and packet‐based detection, respectively, even against previously unseen attacks generated through behavioral variations and command‐level perturbations.
Vehicular ad hoc networks (VANETs) are nodes moving at a high speed compared to mobile ad hoc networks (MANETs). Network‐connected nodes can exchange safety or nonsafety messages within themselves or other infrastructures, such as vehicle‐to‐vehicle (V2V) or vehicle‐to‐everything (V2X). In vehicular communication, emergency messages are crucial for safety and must be distributed to all nodes to alert them of potential issues. Different broadcasting methods, such as single‐hop, multihop, and flooding, have disseminated these messages as part of the broadcast storm mitigation strategy (BSMs). Disseminating safety messages in an urban scenario is challenging due to crowded nodes participating in the communication. The main issues are packet broadcast storms, packet collision, and end‐to‐end delays (E2EDs). When multiple nodes rebroadcast the same message, packet redundancies occur, which can impact the performance and stability of the network, especially in urban areas. This study proposes a safety message dissemination (SMD) approach to address these broadcast storms. This approach can select a single relay node within a single transmission range. The node with the longest time to leave, high density, and appropriate signal strength was chosen as the relay node. This approach ensured that a fair safety message was disseminated to all nodes. The real‐world scenario was also generated using the simulation of urban mobility (SUMO) traffic generator. The performance of the proposed approach was also analyzed and compared with existing standard algorithms, such as fast broadcasting and the effective emergency message dissemination schemes (EEMDS) approach. The results showed that the SMD outperformed all of them in terms of E2ED, packet loss ratio (PLR), and packet delivery ratio (PDR). It has enhanced EED by 0.54% for 20 and 60 nodes at different simulation times, PLR by 4%, and PDR by 17.5%. As the number of nodes and simulation times increased, E2ED and PLR increased proportionally, while PDR decreased.
The Internet of Things (IoT) is increasingly becoming a ubiquitous computing service, wherein data storage and sharing are outsourced to multiple cloud providers, considering IoT’s resource‐constrained, self‐organizing networks and short‐range communication characteristics. Recently, DUCE, a distributed usage control enforcement model, was proposed to mitigate the privacy concerns brought about by the loss of control over sharing data. DUCE utilizes blockchain and trusted execution environment (TEE) technologies to achieve reliable and continuous life‐cycle enforcement for cross‐domain data‐sharing scenarios. However, the requirement that maintains an individual TEE in each application agent makes DUCE deployment difficult, and data transferring to the application makes for less trustworthy usage. In this paper, we propose an alternate architecture called DUCEx to support the functionality of DUCE; nevertheless, DUCEx constructs the TEE via commitments of blockchain rather than one‐to‐one correspondence with application agents. Further, the policy administration point is also distributed and controlled by the data owner, who can modify the rules anywhere and anytime. The eXtensible Access Control Markup Language (XACML) expression rules are parsed and enforced as the smart contract at run time. A detailed explanation of the enforcement process is given for a typical example of the “delete‐after‐use” rule subsequently. By using Intel Software Guard eXtensions (SGX) to implement the prototype system, the experimental results show that DUCEx achieves a more trustworthy usage than DUCE and is easier to deploy along with appropriate performance. We believe our study will contribute to building secure, scalable, and privacy‐preserving infrastructure for the IoT era.
CRYSTALS‐KYBER is a postquantum key exchange mechanism based on the MLWE problem. At present, it is a major challenge to realize CRYSTALS‐KYBER with high‐performance and low‐resource consumption on the FPGA platform. The design proposed in this paper aims at the high efficiency implementation of CRYSTALS‐KYBER based on the MLWE scheme. In this work, multipath delay commutator–number theoretic transform (MDC‐NTT) and area‐optimized hash unit are employed to optimize the overhead and clock cycle occupancy of the whole implementation. The CRYSTALS‐KYBER public‐key encapsulation circuit requires only 5551 clock cycles to execute, reducing the latency by 38.9% compared to the best existing iteration NTT designs and improving hardware efficiency by 1.6–1.9 times. The maximum operating frequency also reaches up to 225 MHz.
Since wireless sensor networks (WSNs) have the requirements of high security and energy conservation, a distributed secure low-energy routing protocol (SLERP) based on dynamic trust awareness and load balancing is proposed. In order to reduce the adverse influence of malicious nodes in the network, the Chebyshev neural network is used to predict the dynamic trust degree of network nodes to accelerate the speed and accuracy of malicious node detection. Based on the comprehensive consideration of the average dynamic trust degree of cluster-head nodes, the load of the cluster-head node, network energy consumption, network lifetime, and accurate route evaluation model are established by the analytic hierarchy process (AHP). The search methods of secure low-energy routing and chromosome crossing and the mutation method are designed based on the genetic algorithm (GA), so as to quickly establish the optimal cluster-head node-set and the optimal routing path of each node. Simulation results show that SLERP can significantly improve the detection speed and detection success rate of malicious nodes, reduce the network energy consumption and load, and effectively extend the network lifetime.