Business Email Compromise (BEC) has emerged as one of the most financially devastating and strategically sophisticated forms of cyber-enabled fraud, leveraging advanced social engineering techniques to circumvent conventional email security infrastructures. Existing detection mechanisms, predominantly rule-based or static in nature, exhibit limited adaptability to the dynamic, context-aware, and linguistically nuanced strategies employed by modern attackers. This study proposes an adversarially resilient hybrid detection framework that synergistically integrates Natural Language Processing (NLP), classical machine learning models (Support Vector Machines and Random Forest), and deep learning architectures, including Long Short-Term Memory (LSTM) networks and Bidirectional Encoder Representations from Transformers (BERT). To address the critical challenge of limited labeled BEC datasets, a controlled synthetic data augmentation strategy was implemented using a fine-tuned Generative Pre-Trained Transformer (GPT), enabling the generation of high-fidelity adversarial email samples. A comprehensive hybrid feature engineering approach was adopted to capture the multifaceted characteristics of BEC emails, encompassing linguistic, structural, metadata, stylometric, and contextual attributes. Model training and evaluation were conducted using stratified cross-validation, with performance assessed through accuracy, precision, recall, F1-score, and Area Under the Receiver Operating Characteristic Curve (AUC-ROC). Model interpretability was enhanced through SHapley Additive exPlanations (SHAP), providing transparent insights into feature contributions. Empirical results demonstrate that the LSTM model achieved superior performance, attaining an accuracy of 98.5%, significantly outperforming Random Forest (95.3%), Support Vector Machines (94.8%), and baseline rule-based approaches (85.4%). The proposed framework demonstrates strong potential for real-world deployment within enterprise email security ecosystems. Future work will focus on multilingual detection, real-time system integration, and large-scale validation within operational Security Operations Center (SOC) environments.
Facial recognition is increasingly adopted for automated classroom attendance; however, real-world deployment in schools remains constrained by privacy risks, ethical obligations, demographic bias, spoofing threats, and limited computational resources. Recent incidents involving Microsoft Teams in New South Wales in 2025 and Chelmer Valley High School in the United Kingdom show how poorly governed systems violate student rights and regulatory compliance. Despite growing adoption, many existing attendance systems focus narrowly on recognition accuracy or efficiency, while overlooking spoof resistance, open-set identity handling, fairness mitigation, auditability, and privacy protection. This paper presents LaED, a lightweight, edge-aware, and explainable deep learning framework for privacy-preserving classroom attendance in resource-constrained educational environments. The framework combines multimodal spoof detection, open-set facial recognition, and fairness-aware representation learning within a unified edge-based design. Spoofing attacks, including replay and deepfake attempts, are mitigated through the fusion of physiological and temporal facial cues, while unknown identities are explicitly rejected to reduce proxy attendance. To support responsible deployment, LaED incorporates federated learning with differential privacy, ensuring that biometric data remain local to schools while enabling accountable model updates. Experimental evaluation on CASIA-FASD, CelebA-Spoof, DFDC, FairFace, and a consent-driven classroom dataset shows that LaED achieves over 97.8% recognition accuracy, APCER and BPCER values below 2%, demographic fairness gaps under 2%, and inference latency below 150 milliseconds on edge hardware. Additional tests confirm reliable operation under realistic classroom conditions. These results demonstrate that regulation-aligned and trustworthy facial attendance is feasible on low-cost devices, offering a practical pathway for responsible biometric AI in education.
The rapid expansion of drones otherwise known as Unmanned Aerial Vehicles (UAVs), in critical sectors has increased their exposure to cyber threats such as GPS spoofing, command hijacking, and firmware tampering. Existing forensic tools often fail to address UAV-specific challenges like volatile memory and limited storage, hindering effective investigations. Hence, to address this gap, this study proposes the Enhanced UAV Forensic Framework (EUAVFF) a modular, forensic-by-design model integrating blockchain audit trails, secure logging, telemetry offloading, and UAV-friendly encryption. Validated through a literature review and a stakeholder survey (n = 100), results showed that over 70% of respondents lacked awareness of UAV cyber risks, and current drones were rated poorly in key forensic areas, including tamper-proof logging and legal evidence handling. Only 28% were familiar with drone-specific threats, reflecting critical gaps in preparedness.These findings emphasize the urgent need for proactive forensic integration. EUAVFF offers a structured path to secure, accountable, and resilient UAV operations in increasingly hostile cyber environments.
Over 5.44 billion people now use the Internet, making it a vital part of daily life, enabling communication, e-commerce, education, and more. However, this huge Internet connectivity also raises concerns about online privacy and security, particularly with the rise of malicious Uniform Resource Locators (URLs). Recently, conventional ensemble models have attracted attention due to their notable benefits of reducing the variance in models, enhancing predictive performance, improving prediction accuracy, and demonstrating high generalization potential. But, its application in addressing the challenge of malicious URLs is still an open problem. These URLs often hide behind static links in emails or web pages, posing a threat to individuals and organizations. Despite blacklisting services, many harmful sites evade detection due to inadequate scrutiny or recent creation. Hence, to improve URL detection, a Diverse and Efficient Ensemble (DaE2) machine learning algorithm was developed using four ensemble models, that is, AdaBoost, Bagging, Stacking, and Voting to classify URLs. After preprocessing, the experimental result shown that all models achieved over 80 % accuracy, with AdaBoost reaching 98.5 % and Stacking offering the fastest runtime. AdaBoost and Bagging also delivered strong performance, with F1 scores of 0.980 and 0.976, respectively.
The Chat Generative Pre-training Transformer (GPT), also known as ChatGPT, is a powerful generative AI model that can simulate human-like dialogues across a variety of domains. However, this popularity has attracted the attention of malicious actors who exploit ChatGPT to launch cyberattacks. This paper examines the tactics that adversaries use to leverage ChatGPT in a variety of cyberattacks. Attackers pose as regular users and manipulate ChatGPT’s vulnerability to malicious interactions, particularly in the context of cyber assault. The paper presents illustrative examples of cyberattacks that are possible with ChatGPT and discusses the realm of ChatGPT-fueled cybersecurity threats. The paper also investigates the extent of user awareness of the relationship between ChatGPT and cyberattacks. A survey of 253 participants was conducted, and their responses were measured on a three-point Likert scale. The results provide a comprehensive understanding of how ChatGPT can be used to improve business processes and identify areas for improvement. Over 80% of the participants agreed that cyber criminals use ChatGPT for malicious purposes. This finding underscores the importance of improving the security of this novel model. Organizations must take steps to protect their computational infrastructure. This analysis also highlights opportunities for streamlining processes, improving service quality, and increasing efficiency. Finally, the paper provides recommendations for using ChatGPT in a secure manner, outlining ways to mitigate potential cyberattacks and strengthen defenses against adversaries.
Email classification is essential to the trouble of email and pattern recognition. Nowadays, a number of unsolicited messages are circulated over the internet. While plenty of machine learning techniques are a success in detecting textual primarily based on totally unsolicited mail, this isn’t the case for messages spams, which can without difficulty avoid those textual-unsolicited mail detection systems. This paper proposes the introduction of MOBGOA constructed on the binary version of the GOA algorithm, for multi-objective selection of features purposes and the wrapper approach of selection of features and purpose of the EGOAMLP algorithm utilized this algorithm as the wrapper classifier. Spam assassin dataset was used to validate the performance of the MOB-EGOAMLP. The result uncovered that the new technique outflanks the wide selection of different methods in previously published works.
Different encryption algorithms such as Advanced Encryption Standard (AES), Rivest, Shamir, Adleman (RSA) were proposed to protect the privacy of the data. However, most of these existing methods are vulnerable to a brute-force attack because the cipher text remains unintelligible until the original data is found. Consequently, this problem prompted researchers to introduce honey encryption (HE). HE helps to withstand the vulnerability of the encryption algorithms in brute force attacks making transmitted data more secure and efficient. Hence to reduce processing time we proposed a hybridized HE with Residue Number System. Traditional Moduli Set {2n-1, 2n, 2n+1} was used to generate the Key while Chinese Remainder Theorem (CRT), and HE technique were used for decrypting the data, based on the Distribution Transformation Decoder. Thus, anytime an attacker tries to access the data, so long the length of the guessed key is the same as the original key, the HE algorithm will generate meaningful but fake data, this helps to deter an attacker from further threat. The result showed that the proposed system was able to withstand brute force attacks with less processing time compared to other systems. N-values for the moduli set used were varied against encryption and decryption time. Comparing the obtained results with the existing system, the proposed system processing time was faster and more secure.
Security threats posed by Ponzi schemes present a considerably higher risk compared to many other online crimes. These fraudulent online businesses, including Ponzi schemes, have witnessed rapid growth and emerged as major threats in societies like Nigeria, particularly due to the high poverty rate. Many individuals have fallen victim to these scams, resulting in significant financial losses. Despite efforts to detect Ponzi schemes using various methods, including machine learning (ML), current techniques still face challenges, such as deficient datasets, reliance on transaction records, and limited accuracy. To address the negative impact of Ponzi schemes, this paper proposes a novel approach focusing on detecting Ponzi schemes on Ethereum using ML algorithms like random forest (RF), neural network (NN), and K-nearest neighbor (KNN). Over 20,000 datasets related to Ethereum transaction networks were gathered from Kaggle and preprocessed for training the ML models. After evaluating and comparing the three models, RF demonstrated the best performance with an accuracy of 0.94, a class-score of 0.8833, and an overall-score of 0.96667. Comparative evaluations with previous models indicate that our model achieves high accuracy. Moreover, this innovative work successfully detects key fraud features within the Ponzi scheme dataset, reducing the number of features from 70 to only 10 while maintaining a high level of accuracy. The main strength of this proposed method lies in its ability to detect clever Ponzi schemes from their inception, offering valuable insights to combat these financial threats effectively.
This paper presented an exhaustive survey on the security and privacy issues of drones. These security concerns were thoroughly dissected, particularly the aspect of cybersecurity, which was classified into nine levels. These levels include emerging issues, communication-based attacks, sensors, hardware, hardware-based attacks, software attacks, and physical attacks on the drone itself. Furthermore, we discussed the other non-cybersecurity challenges of drones, such as terrorism, mid-air collisions, illegal surveillance, smuggling, electronic snooping, and reconnaissance, alongside proffering possible solutions. Many of the discovered aspects of drone cybersecurity issues were then quantitatively analyzed using a multi-criteria decision-making problem-solving technique. The questionnaire responses from the general public, experts, and stakeholders in the aviation industry were analyzed. The findings revealed variations in cyber-attack techniques such as distributed denial-of-service (DDoS), denial-of-service (DoS), hacking, jamming, spoofing, electronic snooping, eavesdropping, advanced persistent threat (APT), reconnaissance, hijacking, man-in-the-middle attack, and so on. However, the majority of the participants in the survey, which constitute 70%, were unaware of the existing drone cybersecurity challenges. The remaining 30% were aware of the current drone security issues. Meanwhile, both parties are looking for an immediate solution that will fully provide an atmosphere of prospects in the drone industry. Following that, we presented our experience with drone security and privacy, as well as potential future research directions. This paper is unique in that it discusses the various types of drone cyber-attacks and non-cyber-attack scenarios that threaten the socio-economic system, aviation industry, national security, as well as public security and privacy concerns. It also offers solutions to the cyber-attack and non-cyber-attack cases that have been investigated. As a result, the findings of this study could be used to create, develop, and implement more secure cloud systems to safeguard drones from cyber and non-cyber-attacks.
Abstract Different encryption algorithms such as Advanced Encryption Standard (AES), Rivest, Shamir, Adleman (RSA) were proposed to protect the privacy of the transmitted data. However, most of these existing methods are vulnerable to a brute-force attack because the cipher text remains unintelligible until the original data is found. Consequently, this problem prompted researchers to introduce honey encryption (HE). HE helps to withstand the vulnerability of the encryption algorithms in brute force attacks making transmitted data more secure and efficient. Hence to reduce processing time we proposed a hybridized HE with Residue Number System. Traditional Moduli Set {2n-1, 2n, 2n + 1} was used to generate the Key while Chinese Remainder Theorem (CRT), and HE technique were used for decrypting the data, based on the Distribution Transformation Decoder (DTE). Thus, anytime an attacker tries to access the data, so long the length of the guessed key is the same as the original key, the HE algorithm will generate meaningful but fake data, this helps to deter an attacker from further threat. The result showed that the proposed system was able to withstand brute force attacks with less processing time compared to other systems. N-values for the moduli set used were varied against encryption and decryption time. Comparing the obtained results with the existing system, the proposed system processing time was faster and more secure.
The exponential increase in the compromise of sensitive and intellectual properties alludes to the huge price the global community must pay for the digital revolution we are currently experiencing. This irrefutable reality is a major reason why cybersecurity defences continue to be a pressing and timely area of research. Traditional countermeasures of cyber defence using boundary controllers and filters such as intrusion detection, access controls, firewalls and so on, have proven ineffective. Such measures fail to account for the attacker’s inherent advantage of being increasingly techno-savvy, as well as their persistence in attempting to compromise the security of not only high-value targets, but also the vast pool of oblivious users of technology. The use of decoys and deception is one of the emerging solutions for cyber defence. Leveraging decoys and deception for security pre-date the advent of the digital revolution as centuries have witnessed the military using human decoys to deceive and successfully defeat their adversaries during wars. However, its benefits for reducing cyberattacks in these digital times have not been thoroughly investigated. One of its use requires that fake text documents are positioned in the repository of critical documents in order to mislead and catch hackers attempting to exfiltrate sensitive documents. Current methods of generating fake text documents involve using symbols, junk documents, randomly generated texts. Such approaches fail to capture the empirical and linguistic properties of language, resulting in messages that do not scale well, are not realistic, fail in the context of syntax and are semantically void. Consequently, failing to convince the attackers to believe they are the original messages. This paper presents a Cognitive Deception Model (CDM) based on a neural model which takes an input message and generates syntactically cohesive and semantically coherent independent looking but plausible and convincing decoy messages to cognitively burden and deceive the adversaries. The experimental results used to validate the models, as well as the comparison with state-of-the-art tools, show that it outperforms existing systems.
It is extremely difficult to track down the original source of sensitive data from a variety of sources in the cloud during transit and processing. For instance, data provenance, which records the origins of data, and the record of data usage, update and processing can be introduced to trace malicious vulnerabilities. Thus, data provenance process makes it easy to monitor the sources and causes of any problems in cloud computing. However, data provenance is one of the most prominent drawbacks in cloud storage. Despite many studies, a full assessment of data provenance in cloud forensics is still missing from the literature, especially in wireless sensor networks, blockchain, Internet of Things (IoT), security and privacy. Importantly, one of the major challenges in data provenance is “how to reduce the complexity of evidence.“ That is, ensuring volatile data is captured before being overwritten. Hence, this study presents a survey of recent data provenance problems in cloud computing, provenance taxonomy, and security issues. It also, discusses how volatile data can be captured before being overwritten and then helps identify current provenance limitations and future directions for further study. More also, it examined how data is collected as evidence for digital crime in a real-world scenario. Furthermore, future work in digital provenance for cloud forensics, wireless sensor network, IoT, and blockchain is recommended.
The cosmic evolution of the Internet of things (IoTs) in par with its realization in all spheres of life undertakings, mandates continuous research pursuits in IoT and its associated components. While the rapid evolution of IoTs has facilitated monumental opportunities for humanity, it has also acted as a catalyst precipitating diverse security issues. Cybercrimes have been on the rise as criminals and hackers continue to take advantage of IoT's security loopholes and vulnerabilities. The enormity of the attacks has not only been damaging to the quality of life, but it poses a disservice and an unquantifiable risk to human safety. Thus, a timely and comprehensive review, analysis and investigation of the security of IoTs is crucial. Through a systematic literature review of over 200 articles, we set out the latest findings and trends to provide new insights into the security of IoTs, taking cognizant of its social, economic, technical and legal implications, which will be beneficial to researchers, manufacturers, individuals, organizations, and governments. Although many studies reviewing the state of IoT exist in the literature, no studies shape the area of its security well. Hence, there is currently no study that provides an in-depth survey of the emerging security concerns of IoT from diverse perspectives and in tandem with the current condition of the global world today. Compared to other related reviews on the security of IoTs, this survey encompasses much more technical angles to the security of IoT. It begins with the review of the concept of IoTs, the assessments of its industrial development trends, revolutionary paradigms and updated security of the IoT. Key challenges in the security of blockchain technology, a recent spike in distributed denial of service (DDoS) attacks due to the COVID-19 pandemic are sensitive areas that have remained untouched by previous review works. Additionally, politics and security of electoral votes, forensic issues in the IoT era and much more are some of the new depths missing in the literature of IoT security. Thus, a huge divide in the total adoption and actualization of IoT in diverse areas of human endeavour. This review formalizes the IoT concept, illuminating deep insights into possible solutions to the heterogeneous nature of IoT's security challenges, emerging issues, gaps, opportunities, foresight, and recommendations.
Networks are strained by spam, which also overloads email servers and blocks mailboxes with unwanted messages and files. Setting the protective level for spam filtering might become even more crucial for email users when malicious steps are taken since they must deal with an increase in the number of valid communications being marked as spam. By finding patterns in email communications, spam detection systems (SDS) have been developed to keep track of spammers and filter email activity. SDS has also enhanced the tool for detecting spam by reducing the rate of false positives and increasing the accuracy of detection. The difficulty with spam classifiers is the abundance of features. The importance of feature selection (FS) comes from its role in directing the feature selection algorithm's search for ways to improve the SDS's classification performance and accuracy. As a means of enhancing the performance of the SDS, we use a wrapper technique in this study that is based on the multi-objective grasshopper optimization algorithm (MOGOA) for feature extraction and the recently revised EGOA algorithm for multilayer perceptron (MLP) training. The suggested system's performance was verified using the SpamBase, SpamAssassin, and UK-2011 datasets. Our research showed that our novel approach outperformed a variety of established practices in the literature by as much as 97.5%, 98.3%, and 96.4% respectively.
The staggering development of cyber threats has propelled experts, professionals and specialists in the field of security into the development of more dependable protection systems, including effective intrusion detection system (IDS) mechanisms which are equipped for boosting accurately detected threats and limiting erroneously detected threats simultaneously. Nonetheless, the proficiency of the IDS framework depends essentially on extracted features from network traffic and an effective classifier of the traffic into abnormal or normal traffic. The prime impetus of this study is to increase the performance of the IDS on networks by building a two-phase framework to reinforce and subsequently enhance detection rate and diminish the rate of false alarm. The initial stage utilizes the developed algorithm of a proficient wrapper-approach-based feature selection which is created on a multi-objective BAT algorithm (MOBBAT). The subsequent stage utilizes the features obtained from the initial stage to categorize the traffic based on the newly upgraded BAT algorithm (EBAT) for training multilayer perceptron (EBATMLP), to improve the IDS performance. The resulting methodology is known as the (MOB-EBATMLP). The efficiency of our proposition has been assessed by utilizing the mainstream benchmarked datasets: NLS-KDD, ISCX2012, UNSW-NB15, KDD CUP 1999, and CICIDS2017 which are established as standard datasets for evaluating IDS. The outcome of our experimental analysis demonstrates a noteworthy advancement in network IDS above other techniques.
This study analyzed the Coronavirus (COVID-19) crisis from the angle of cyber-crime, highlighting the wide spectrum of cyberattacks that occurred around the world. The modus operandi of cyberattack campaigns was revealed by analyzing and considering cyberattacks in the context of major world events. Following what appeared to be substantial gaps between the initial breakout of the virus and the first COVID-19-related cyber-attack, the investigation indicates how attacks became significantly more frequent over time, to the point where three or four different cyber-attacks were reported on certain days. This study contributes in the direction of fifteen types of cyber-attacks which were identified as the most common pattern and its ensuing devastating events during the global COVID-19 crisis. The paper is unique because it covered the main types of cyber-attacks that most organizations are currently facing and how to address them. An intense look into the recent advances that cybercriminals leverage, the dynamism, calculated measures to tackle it, and never-explored perspectives are some of the integral parts which make this review different from other present reviewed papers on the COVID-19 pandemic. A qualitative methodology was used to provide a robust response to the objective used for the study. Using a multi-criteria decision-making problem-solving technique, many facets of cybersecurity that have been affected during the pandemic were then quantitatively ranked in ascending order of severity. The data was generated between March 2020 and December 2021, from a global survey through online contact and responses, especially from different organizations and business executives. The result show differences in cyber-attack techniques; as hacking attacks was the most frequent with a record of 330 out of 895 attacks, accounting for 37%. Next was Spam emails attack with 13%; emails with 13%; followed by malicious domains with 9%. Mobile apps followed with 8%, Phishing was 7%, Malware 7%, Browsing apps with 6%, DDoS has 6%, Website apps with 6%, and MSMM with 6%. BEC frequency was 4%, Ransomware with 2%, Botnet scored 2% and APT recorded 1%. The study recommends that it will continue to be necessary for governments and organizations to be resilient and innovative in cybersecurity decisions to overcome the current and future effects of the pandemic or similar crisis, which could be long-lasting. Hence, this study's findings will guide the creation, development, and implementation of more secure systems to safeguard people from cyber-attacks.
The Internet of Things (IoT) has emerged as a modern wave of Internet technologies that promises great transformation of life in areas such as smart health, smart cities, smart homes, intelligent transport, amongst others. However, security often serves as a critical reason for the widespread adoption of any innovation. While the IoT has increased business productivity and enriched diverse areas of life over the years, the world is yet to see a methodical revolution of its humongous application and transformation given its ubiquity and highly interconnected global network structure. The main culprit for such lapses is principally attributed to security and privacy issues which have been widely discussed in research articles and reviews but remain largely unaddressed in the literature. Hence, this paper provides a state-of-the-art review of IoT security and its challenges. It overviews technical and legal solutions that are useful to private, organizational, and governmental enterprises. The study encompasses the review and security analysis of IoT’s evolution and revolution, IoT security assessments, requirements, current research challenges in security and much more. Consequently, it offers potential solutions to address the security challenges discussed and further present open research issues, research gaps, opportunities, future development, and recommendations. This overview is intended to serve as a knowledgebase that will proffer novel foresight to guide users and administrators in positioning themselves and their organizations in a manner that is consistent with their overall objectives, mission, and vision for remarkable outcomes. Likewise, interested scholars and researchers can explore topics and directions from the study in providing better solutions to the numerous problems in IoT security.
Advancements in electronic health record system allow patients to store and selectively share their medical records as needed with doctors. However, privacy concerns represent one of the major threats facing the electronic health record system. For instance, a cybercriminal may use a brute-force attack to authenticate into a patient's account to steal the patient's personal, medical or genetic details. This threat is amplified given that an individual's genetic content is connected to their family, thus leading to security risks for their family members as well. Several cases of patient's data theft have been reported where cybercriminals authenticated into the patient's account, stole the patient's medical data and assumed the identity of the patients. In some cases, the stolen data were used to access the patient's accounts on other platforms and in other cases, to make fraudulent health insurance claims. Several measures have been suggested to address the security issues in electronic health record systems. Nevertheless, we emphasize that current measures proffer security in the short-term. This work studies the feasibility of using a decoy-based system named HoneyDetails in the security of the electronic health record system. HoneyDetails will serve fictitious medical data to the adversary during his hacking attempt to steal the patient's data. However, the adversary will remain oblivious to the deceit due to the realistic structure of the data. Our findings indicate that the proposed system may serve as a potential measure for safeguarding against patient's information theft.
In this paper, an enhanced honey encryption (HE) scheme for reinforcing the security of instant messaging systems and confounding the time and resources of malicious persons is presented. HE offers security beyond the brute-force bound by yielding plausible-looking but fake plaintext upon decryption with an incorrect key. Recent developments have seen the application of HE in the security of specific real-world systems, such as passwords and credit cards. However, applying the HE scheme to address other economic problems remains a daunting task as it requires modifying the HE algorithm to fit into the problem-in-view. For instance, applying the scheme for robust transmission of chat-messages upon decryption with an incorrect key will demand to generate contextually correct, valid-looking but fake chat-message which is indistinguishable from a human-generated message. This paper enhances the HE scheme by leveraging natural language processing techniques to build semantically plausible but fake chat-messages which will be served to the adversary during his attacks. Findings from evaluations reveal that the novel system is resilient to eavesdropping as an adversary is unable to distinguish decoy messages from the plaintext upon decryption with an incorrect key.