In today's dynamic networking environment, securing access to resources has become increasingly challenging due to the growth and progress of connected devices. This study explores the integration of Role-Based Access Control (RBAC) and OAuth 2.0 protocols to enhance network access management and security enforcement in an Android mobile application. The study adopts a waterfall methodology to implement access control mechanisms that govern authentication and authorization. OAuth 2.0, a widely adopted open-standard authorization framework, was implemented to secure user authentication by allowing third-party access without exposing user credentials. Meanwhile, RBAC was leveraged to streamline access permissions based on predefined user roles, ensuring that access privileges are granted according to hierarchical role structures. The main outcomes of this study show significance towards the improvements in security enforcement and user access management. Specifically, the implementation of multi-factor authentication, session timeout mechanisms, and user role-based authorization ensured robust protection of sensitive data while maintaining system usability. RBAC proved effective in controlling access to various system resources, such as database operations which was presented in scenario of physical access to doors, while OAuth 2.0 provided a secure communication channel for authentication events. These protocols, working in tandem, addressed key issues like unauthorized access, data integrity, and scalability in network security policy enforcement. This research deduces that combining RBAC and OAuth 2.0 protocols in mobile applications enhances security posture, simplifies access management, and mitigates evolving threats.
Intrusion severity classification or the analysis of the impact of intrusion is a much needed solution to effectively manage intrusion events in an organization. A lot of intrusion scenarios have been carried out by systems administrators or the internal workers over the years in different organizations and the external hackers are berated for it. Many deliberate inversions have happened from the internal actors with top management board members only swinging into actions to manage the effect of it without digging into the inversion to apprehend the actors or the source of the intrusion. So, this work has been designed to assist IT firms to effectively carry out the analysis of the impact of intrusion, especially those from the internal workers. In this work, we proposed a Machine Learning Enabled System for Intelligent Classification of Host-based Intrusion Severity. The proposed model is aimed at detecting the severity of intrusion problems, carryout source analysis and give security recommendation for effective management of intrusion problems. The model is divided into three phases; the detection of intrusion severity, source analysis and security recommendation using counterfacatual reasoning.We built a system that aided us to gather user interaction over time, we captured these interaction in the activity log, our dataset was extracted from these activity log data.We used Bayesian Network to design the intrusion severity classification system, source analysis is carried out immediately, then counterfactual model is employed to give security recommendation. The accuracy of Bayesian Network in the intrusion severity classification model is 82%. An API was generated and deployed to allow scalability.
Most disease that affects the heart or blood vessels is referred to as cardiovascular disease(CVD). The main aim of this work is to build a system capable of modeling and predicting early syndromic cardiovascular diseases (CVD) based on electrocardiogram (ECG). The study considers the implementation of computationally intelligent system for detecting and classifying early syndromic assessment of CVD. The clinical and ECG recordings of patients diagnosed with pulmonary hypertension at the University of Uyo Teaching Hospital (UUTH) were obtained. The datasets were segmented into Demographic and ECG datasets. A quantitative research approach was used for the study with examination of several segments based on recommended framework. Three (3) classifier models were adopted to detect cardiac related problems using specified datasets. The classifiers such as; Random Forest Ensemble (RFE), Support Vector (SVM) Classifier and Artificial Neural Network (ANN) was employed for Machine Learning process. The models were implemented using a robust programming languages (Python and Jupyter notebook). The datasets were further segmented into two categories: training sets and testing in the ratio of 80:20 respectively. The test data reflects; precision, recall and sensitivity: Results show Radom Forest Model: 0.50 (50%) accuracy, 0.48 (48%) precision score and 0.65 (65%) recall sensitivity score (RSS), SVM classifier indicated 0.70 (70%) accuracy score, 0.47 (47) % precision score as well as 0.52 (52 %) sensitivity score. The ANN model illustrates 0.50 (50%) score for accuracy, precision and recall. Research Findings demonstrated that, RFE, SVM, ANN illustrate 100% accuracy in precision and recall sensitivity. The interaction effects of the various clinical factors influencing the CVD of patient was appraised and performance evaluation were further done using standard data science measures; Confusion Matrix (CM), MAP, MAPE, RMSE was deployed. The final results obtained shows that RFE, SVM, ANN models support satisfactorily the assessment and classification of early syndromic conditions of CVD.
Spectrum Scheduling is an efficient scheme of improving spectrum utilization for faster communications, higher definition media (HDM) and data transmission. Radio spectrum is very limited in supply resulting in enormous problems related to scarcity. It owes the physical support for wireless communication, both fixed applications and mobile broadband. Basically, effective use of the spectrum depends on the channel settings, sensing performance, detection of spectrum prospect as well as effective transmission of both Primary Users (PUs) and Secondary Users (SUs) packets at a specific time slot. In order to improve spectrum utilization this paper adopted quantitative method which employs Probability Theorem to identify the probabilities of both primary Users (PUs) and secondary users (SUs) in the spectrum datasets allocation and further used conditional probability to compare two Frequency Bands i.e., High Frequency (HF) and Very High Frequency (VHF). The result indicates available spectrum holes (SH) left unutilized in the Secondary User (SU) resulting in the need for spectrum scheduling for the SU. The procedure makes the secondary users occupy a probability of 0.002mhz compared to the primary users on 0.00004mhz utilization. This further indicates that some spectrum holes were left unutilized by the license users (Primary Users). However, spectrum allocation is one of the major issues of improving spectrum efficiency and has become a considerable tool in cognitive wireless networks (CWN). Consequently, the goal of spectrum allocation is to assign leisure spectrum resources efficiently to achieve the optimal Quality of Service (QOS and cognitive user requirements of wireless network. Again, classification of spectrum allocation was carried out through difference methods. Firstly, we employ a probability theorem to identify the probability of both Primary Users (PUs) and Secondary Users (SUs) in the allocated spectrum data sets. Secondly, conditional probability was used to compare two frequency band based on primary and secondary allocation policies designed to identify the specific allocation of each band. Thirdly, Machine Learning (ML) Algorithm based on Decision Tree-Supervised Learning (DTSL) approach was adopted to classified our data sets. The result yielded 68% which correctly classified instances based on the total records of sixty-nine (69) data sets. Research findings demonstrate a highly optimized spectrum scheduling for efficient networks service provisions.
MANET is a self-organizing system of mobile nodes that can be connected by wireless links on an ad hoc basis. In a MANET, the nodes are free to move randomly, causing the network's topology to change dynamically. Their high mobility and ad hoc nature poses greater security threats. Moreover, because they do not have a centralized controlling entity, it may be advantageous for individual nodes not to cooperate. Misbehavior of nodes can be commonly found in either forwarding or routing. Among these, timing attack at the MAC layer leads to serious consequences such as violation of QoS. Reputation systems can handle such kind of misbehavior that is observable. This paper proposes a MAC Layer based Reputation System for MANETs. It incorporates misbehavior observation, statistical calculation of reputation index, diagnosis and mitigation. The proposed model is implemented with modifications in the MAC component of ns2 and the results are compared with the existing MAC protocol. Result shows that the proposed model enhances the network performance by reducing the number of packet drops by 11% and increasing the throughput in the network by 23%.
IEEE 802.11n standard is deployed virtually everywhere: on residences, offices, university campuses, and even market places. However, throughput obtained by end users have not measured up to the speed range of between 100 and 600 Mbps stipulated in the standard due to the Physical (PHY) technology involved and timing headers at the Media access control (MAC). To overcome this, two frames aggregation schemes, namely, A-MSDU and A-MPDU were introduced as a means of utilizing channel efficiency at the MAC through amortization of the overheads over multiple frames. However, there are still issues with additional headers from aggregating frames. We know that A-MSDU performs well in clear channels and small aggregation sizes but poorly with increasing channel error and larger aggregation sizes, while the opposite is true for A-MPDU. Thus, several authors exploited their complimentary efficiencies to derive two-level aggregation schemes, resulting in higher throughput, headers reduction, and channel utilization. However, these gains are totally eroded at SNR of 19 dB and below. Using NS3 discrete event simulator, we therefore propose a two-level frame aggregation scheme that utilizes the enhanced A-MSDU and A-MPDU, using appropriate algorithm depending on the SNR value. Our work increased the SNR range for throughput performance by 37.5%; increased channel utilization by 40%, 36%, and 31% at SNR variants of 19 dB, 17 dB, and 16 dB respectively.
Denial of Service (DoS) attacks are a major network security threat which affects both wired and wireless networks. The effect of DoS attacks is even more damaging in Delay Tolerant Networks (DTNs) due to their unique features and network characteristics. DTN is vulnerable to resource exhaustion and flooding DoS attacks. Several DoS mitigating schemes for wired and wireless networks have been investigated and most of them have been found to be highly interactive requiring several protocol rounds, resource-consuming, complex, assume persistent connectivity and hence not suitable for DTN. To mitigate the impact of resource exhaustion and flooding attacks in DTN, we propose a security scheme which integrates ingress filtering, rate limiting and light-weight authentication security mechanisms to monitor, detect and filter attack traffic. We propose three variants of light-weight bundle authenticators called DTNCookies. To make the proposed DTNCookies random and hard to forge, we exploit the assumption that DTN nodes are loosely time-synchronized to generate different nonce values in different timeslots for the computation and verification of our proposed DTNCookies. The results demonstrate the efficiency and effectiveness of the proposed scheme to detect and drop attack traffic. The simulation results also show good performance for the proposed scheme in terms of energy and bandwidth efficiency, high delivery ratio and low latency.
The implementation of the Session Initiation Protocol (SIP)-based Voice over Internet Protocol (VoIP) and multimedia over MANET is still a challenging issue. Many routing factors affect the performance of SIP signaling and the voice Quality of Service (QoS). Node mobility in MANET causes dynamic changes to route calculations, topology, hop numbers, and the connectivity status between the correspondent nodes. SIP-based VoIP depends on the caller's registration, call initiation, and call termination processes. Therefore, the SIP signaling performance has an important role for the overall QoS of SIP-based VoIP applications for both IPv4 and IPv6 MANET. Different methods have been proposed to evaluate and benchmark the performance of the SIP signaling system. However, the efficiency of these methods vary and depend on the identified performance metrics and the implementation platforms. This survey examines the implementation of the SIP signaling system for VoIP applications over MANET and highlights the available performance enhancement methods.
Denial of Service (DoS) attacks have been amajor threat in the Internet and in other emerging networks including DelayTolerant Networks (DTNs). A DTN is characterized by limited bandwidth, longqueuing delays, low data rate, low power and intermittent connectivity. Most ofthe proposed DoS mitigation schemes for wired and wireless networks are highlyinteractive requiring several protocol rounds. They are also resourceconsuming, complex and assume intermittent connectivity. These features makethe applicability of proposed schemes unsuitable in a DTN scenario. An attackercan exploit the DTN message forwarding mechanism to inject fake bundles intothe network. The attacker’s overall objective is to deplete node and linkresources such as CPU processing cycles, battery power, memory and bandwidth.In this paper, we propose a proactive DoS-Resilient Authentication Mechanism(DoSRAM). The proposed mechanism uses three message authenticator variantscalled DTN-Cookies to minimize computational and communication costs. Theproposed mechanism has been verified through simulations using theOpportunistic Network Environment (ONE) simulator. Results show that DoSRAMoutperforms solutions which are based on RSA-Digital Signatures in terms ofthroughput, energy and bandwidth efficiency. DoSRAM can accurately detect andfilter out DoS traffic.
Providing Web services from the mobile cloud is a current research topic. The mobile cloud provides the computing resources and infrastructure to support the seamless provision of Web services in a lightweight manner. Security has become a major concern with the emergence of mobile cloud Web services. In this paper, we investigate the security aspects of a system for complex mobile Web service provisioning. We characterize the security requirements of the individual components and present a security framework to provide authentication and confidentiality between clients and mobile hosts. Our solution is based on the use of existing security protocols between clients and the mobile hosts as well as a key management protocol between the individual mobile hosts implementing an out-of-band key exchange that is simple in practice, flexible and secure. We examine the performance of this approach by evaluating a prototype implementation of our security framework.
A delay tolerant network is a highly constrained networking environment which is low in resources such as memory, bandwidth and battery power. In opportunistic DTNs, nodes cooperatively forward packets for each other through the carry-store-and-forward paradigm. Opportunistic data forwarding can be abused by an adversary by injecting spurious packets in order to waste the resources of the network. To guard against such attacks, it is important to authenticate packets at intermediate nodes. Packet authentication in itself comes with overheads such as computation cost and energy consumption which can be exploited by an attacker to mount a denial of service attack. We propose the use of light-weight DTN-cookies to protect this vital security service from such malicious exploitation. We show through simulations that our proposed mechanisms can improve network performance and save considerable amount of power even in the presence of attackers.
Denial of Service (DOS) attacks are a major threat faced by all types of networks. The effect of DOS in a delay tolerant network (DTN) is even more aggravated due to the scarcity of resources. Perpetrators of DOS attacks in DTN-like environments look beyond the objective of rendering a target node useless. The aim of an attacker is to cause a network-wide degradation of resources, service and performance. This can easily be achieved by exhausting node or link resources and partitioning the network. In this paper we seek to provide a proactive approach in making the DTN authentication process robust against DOS. Our aim is to make security protocols which provide mandatory DTN security services resilient to DOS attacks. The overall objective is to make it hard to launch a DOS attack and ensure the availability of DTN services. A DTN-cookie mechanism has been proposed to quickly identify and filter out illegitimate traffic.
Packet injection by an attacker can trigger flooding-based DOS attacks. This paper seeks to provide a simple and robust approach to protect the access control, data integrity and sender authentication security services in resource-constrained delay tolerant networks. The aim is to make security protocols providing these mandatory security services resilient to resource exhaustion DOS attacks. To achieve this we propose a hierarchical design based on the use of light-weight and hard to forge cookies. The DOS defense mechanism can proactively identify and discard attack bundles. Compromised insider nodes are identified and isolated.
Delay Tolerant Network suffers from lack of resources and disconnected contact nature. In DTN, all possible methods are used to transmit data including the physical transportations means. Aircrafts in commercial routes have been proposed to carry data from ground users along their flying routes. Delivery probability is compared when using aircrafts, buses and ferries. Results show that aircrafts provide higher delivery probability which is up to 62% better compared with buses and ferries. Furthermore, when there is lack of resources, it is difficult to satisfy all users' demands for traffic. We propose a Fairness and Satisfaction (FS) model to enhance the users' satisfaction during DTN limited and scarce resources. Various scenarios are tested for the FS model through intense simulations. FS model, when implemented, will improve user's satisfaction up to 18 % and DTN fairness up to 20 % compared with the same scenario lacking the model.
The emergence of DTN as an option for sustaining communication in environments with high delay/frequent disruption have rendered existing access control mechanisms inappropriate hence the need for a new concept in DTN access control. This is primarily due to contradicting assumptions like low delay and constant connectivity on which the existing mechanisms are built. This paper discusses the security issues in DTN, investigate existing access control mechanisms and relate their design principles as well as operational mode to DTN. We proposed a lightweight hierarchical architecture based on AAA architecture concept and explored the DTN architecture to identify those features that will support the implementation of AAA architecture concept. We present the proposed architecture for an intra-domain scenario with a brief description.
There is a growing interest in providing communications to “Challenged” environments which have been hitherto isolated and disconnected due to the lack of communications infrastructure. These are regions which lie at the edge of the current Internet. Confidentiality, integrity and availability are the three major security requirements of any secured system or network. This paper presents our work on Denial of Service mitigation in Delay-and Disruption-Tolerant Networks. We propose three examples of a light-weight bundle authenticator (DTN-cookie) based on XOR and HMAC operations to thwart DoS attacks that lead to resource exhaustion.