Passwords remain the dominant mechanism for user authentication despite their well-known security weaknesses. Human-chosen passwords frequently exhibit predictable patterns, making them vulnerable to systematic guessing attacks. While prior work has explored statistical and deep learning-based password guessing techniques, these approaches often suffer from limited adaptability or high computational overhead. In this paper, we investigate the effectiveness of Gradient Boosting Machines (GBM) for password guessability analysis under a ranking-based evaluation framework. By leveraging structured feature engineering and synthetically generated password data, the proposed approach captures common password characteristics while avoiding reliance on real user credentials. We evaluate model performance using a Top-N guessing success metric and compare it against established ensemble and deep learning-based baselines. Experimental results demonstrate that the GBM-based model achieves a Top-N success rate of up to 97% while significantly reducing computational cost compared to deep learning approaches. Feature importance and error analysis further reveal that password length, character diversity, and common structural patterns play dominant roles in guessability. These findings indicate that classical machine learning techniques, when carefully engineered, remain highly competitive for practical password security analysis, particularly in data- and resource-constrained environments.
Cross-platform frameworks such as Flutter and React Native are increasingly adopted in Android application development, yet their security characteristics at scale remain insufficiently understood. In this paper, we present an empirical security characterization of 3,000 Android applications, consisting of 1,000 Flutter-based applications, 1,000 React Native apps, and 1,000 Kotlin-based native applications used as a baseline. Using MobSF and FlowDroid static analysis, we analyze security assessment scores as well as the prevalence of warning-level and high-severity findings across these development ecosystems. The results show consistent but modest differences in average scores and reported finding distributions, with cross-platform applications exhibiting distinct distributional patterns compared to native Kotlin applications. These observations do not imply framework-level vulnerabilities. Rather, they reflect ecosystemlevel tendencies associated with framework architectures, build configurations, and commonly used dependencies. This study characterizes Android security traits reported by static analysis tools and demonstrates that cross-platform and native applications should be interpreted with framework context in mind.
Malware often employs encryption to obfuscate its network communications, posing challenges for network-based anomaly detection techniques. Distinguishing encrypted packets from one another becomes particularly difficult, especially when operating under zero knowledge setting, such as detecting new malware. Existing approaches rely on unique features extracted from network connections to train deep learning algorithms. However, these methods fall short when dealing with new malware due to limited information. To address this challenge, we propose Anti-EMP, an algorithm designed to filter encrypted malware packets. Specifically, Anti-EMP identifies and sifts out encrypted packets originating from the same malware across multiple clients. Our approach is grounded in two practical assumptions: (a) the packets were encrypted using an unknown, identical stream cipher and encryption key and (b) a suspicious packet related to malware can be captured. We also propose a novel method for generating Anti-EMP, significantly enhancing the capability to detect encrypted malware packets without prior knowledge, i.e., zero knowledge settings. Our experiments show that Anti-EMP can be generated in approximately one second, facilitating easy iteration and easy selection of another suspicious packet if it turns out to be ineffective. Notably, our proposed scheme demonstrates high effectiveness, achieving a True-Positive Rate (TPR) of 0.998 and a False-Positive Rate (FPR) of 0.001.
Recently, Software-Defined Networking (SDN) has emerged as an increasingly popular network paradigm due to its virtualization capabilities and flexibility. However, its robustness in link connectivity is threatened by Link Flooding Attacks (LFAs). To launch LFAs, adversaries use probing tools to infer network topologies and identify target links with bottlenecks. Thus, protecting SDN topologies against disclosure is crucial to ensure system security and preserve infrastructure functionality. We propose TEPS (Tunnel-Enabled Programmable Switches), a proactive defense system that dynamically obfuscates network topologies to defend against adversarial reconnaissance in SDN. TEPS generates false topologies by leveraging the flexibility of emerging programmable switches to construct customized tunnels and manipulate probing packets using the P4 language. This prevents adversaries from obtaining accurate knowledge of network topologies, making it difficult to reconstruct the true topologies. Furthermore, TEPS counters Round-Trip Time (RTT)-based fingerprinting attacks by dynamically adjusting packet delays and routing traffic to conceal RTT variations. Our evaluation demonstrates that TEPS effectively reduces the distribution of link importance in network topologies compared to the latest proactive defense method, thereby concealing bottlenecks and disrupting adversarial topology reconnaissance, including thwarting RTT-based fingerprinting attempts. Furthermore, by leveraging the capabilities of P4 switches, TEPS introduces minimal network overhead, with at most a 3% reduction in throughput and a 9.57% increase in resource utilization, showing practical feasibility under real-world operational constraints. By implementing TEPS, network administrators can enhance the security of their SDN infrastructures against LFAs and maintain robust connectivity through a lightweight approach.
Cryptographic network protocols play a crucial role in enabling secure data exchange over insecure media in modern network environments. However, even minor vulnerabilities can make protocols an easy target for cyber attackers. Therefore, it is essential to investigate the threats and vulnerabilities stemming from the cryptographic network protocols. Furthermore, it is necessary to comprehensively investigate the weaknesses of network protocols that use cryptographic primitives to inform users and developers about potential attack points. This comprehensive survey examines the relationship between encryption schemes and network protocols and presents an in-depth review of associated threats and vulnerabilities. Given that most cryptographic protocols operate in the Transport and Application layers of the Transmission Control Protocol/Internet Protocol (TCP/IP) protocol stack, our investigation primarily centers around encryption algorithms used by representative and notable cryptographic network protocols such as Transport Layer Security (TLS) and Secure Shell (SSH). Furthermore, we delve into the attackers’ methods to exploit the already identified and existing vulnerabilities, seeking to understand the mechanisms employed to compromise these protocols. Through this survey, we aim to provide the readership with an in-depth understanding of the existing and new vulnerabilities associated with modern cryptographic protocols and provide valuable insights into securing them effectively. We also discuss the existing challenges and future research directions in this domain.
Group Key Exchange (GKE) is an important tool to develop secure multi-user applications such as group text messages, ad-hoc networks, and so on.Most of the currently deployed GKE schemes are synchronous, i.e., they require all the participants to be online during their execution.However, with more battery-powered devices being used in such applications, the synchronicity requirement is challenging to fulfill.To fill the gaps, asynchronous GKE schemes have been introduced in the literature.Nevertheless, the currently available asynchronous and synchronous GKE schemes rely on Trusted Third Parties (TTPs) for key establishment and management.To this end, reliance on TTPs is a serious shortcoming since TTPs are well known to be the single point of failure.Furthermore, the existing GKE schemes require participants to perform all computations, which can degrade the performance of resource-constrained devices such as Internet of Things (IoT) devices.To solve these problems, in this paper, we propose an asynchronous GKE scheme that uses blockchain and smart contracts to store the security keys-related material and reduce the computational load of the participants.Furthermore, our proposed scheme provides Perfect Forward Secrecy (PFS) and Post-Compromised Security (PCS).Our implementation on Ethereum shows that the proposed scheme can scale to more than 100 participants when combined with a distributed storage system.
Federated Learning (FL) is a technology that facilitates a sophisticated way to train distributed data. As the FL does not expose sensitive data in the training process, it was considered privacy-safe deep learning. However, a few recent studies proved that it is possible to expose the hidden data by exploiting the shared models only. One common solution for the data exposure is differential privacy that adds noise to hinder such an attack, however, it inevitably involves a trade-off between privacy and utility. This paper demonstrates the effectiveness of image augmentation as an alternative defense strategy that has less impact of the trade-off. We conduct comprehensive experiments on the CIFAR-10 and CIFAR-100 datasets with 14 augmentations and 9 magnitudes. As a result, the best combination of augmentation and magnitude for each image class in the datasets was discovered. Also, our results show that a well-fitted augmentation strategy can outperform differential privacy.
One significant security challenge in vehicular networks is defending against malicious members’ attacks, including insiders and compromised authorities. Insiders are legitimate vehicles who have passed the registration process. Since they can exploit all the information related to the network and other members’ communication, it is easier to perform various attacks with a high impact. In addition, an authority takes charge of registering and managing legitimate vehicles. Thus, if the authority is compromised, it will cause significant damage to the system, including the leaking of private information, such as identity, location, and membership. Many authentication schemes have been proposed to protect vehicular communication from these security issues. However, most existing schemes still face the vulnerability of malicious members. Furthermore, most conventional schemes require additional interactions between the vehicles and infrastructure for authentication, which can cause communication overheads. To overcome these issues, we propose a novel blockchain-based one-time authentication scheme to protect vehicular communication against malicious members. One-time authentication provides higher security and efficiency as every message is authenticated with different proof at a time. We use publicly verifiable secret sharing with blockchain for this property, which brings two benefits. First, it prevents even an authority from obtaining members’ identities by distributing encrypted shares instead of their real identities. Second, it enables robust vehicular communication against insiders’ attacks by allowing a vehicle to send unique proof generated from its private information with messages. Receivers can authenticate the messages by comparing attached values to the information through the blockchain in a noninteractive manner. Security analysis shows that our scheme assures secure vehicle-to-everything communication against insider attacks, and efficiency analysis shows how both authentication and consensus delay change.
Searchable Encryption (SE) enables data owners to search remotely stored ciphertexts selectively. A practical model that is closest to real life should be able to handle search queries with multiple keywords and multiple data owners/users, and even return the top-k most relevant search results when requested. We refer to a model that satisfies all of the conditions a 3-multi ranked search model. However, SE schemes that have been proposed to date use fully trusted trapdoor generation centers, and several methods assume a secure connection between the data users and a trapdoor generation center. That is, they assume the trapdoor generation center is the only entity that can learn the information regarding queried keywords, but it will never attempt to use it in any other manner than that requested, which is impractical in real life. In this study, to enhance the security, we propose a new 3-multi ranked SE scheme that satisfies all conditions without these security assumptions. The proposed scheme uses randomized keywords to protect the interested keywords of users from both outside adversaries and the honest-but-curious trapdoor generation center, thereby preventing attackers from determining whether two different queries include the same keyword. Moreover, we develop a method for managing multiple encrypted keywords from every data owner, each encrypted with a different key. Our evaluation demonstrates that, despite the trade-off overhead that results from the weaker security assumption, the proposed scheme achieves reasonable performance compared to extant schemes, which implies that our scheme is practical and closest to real life.
In this article, we introduce a cooperative obstacle-aware surveillance system for virtual emotion intelligence which is supported by low energy configuration with the minimal wasted communication cost in self-sustainable network with 6G components. We make a formal definition of the main research problem whose goal is to minimize the wasted communication range of system members on condition that the required detection accuracy with the given number of obstacles is satisfied when the requested number of obstacle-aware surveillance low energy barriers are built in self-sustainable network. To solve the problem, we have originally designed and implemented two different approaches, and then thoroughly evaluated them through extensive simulations. Then, their performances based on numerical outcomes are demonstrated with detailed discussions.
Middlebox is primarily used in Software-Defined Network (SDN) to enhance operational performance, policy compliance, and security operations. Therefore, security of the middlebox itself is essential because incorrect use of the middlebox can cause severe cybersecurity problems for SDN. Existing attacks against middleboxes in SDN (for instance, middlebox-bypass attack) use methods such as cloned tags from the previous packets to justify that the middlebox has processed the injected packet. Flowcloak as the latest solution to defeat such an attack creates a defence using a tag by computing the hash of certain parts of the packet header. However, the security mechanisms proposed to mitigate these attacks are compromise-able since all parts of the packet header can be imitated, leaving the middleboxes insecure. To demonstrate our claim, we introduce a novel attack against SDN middleboxes by hijacking TCP/IP headers. The attack uses crafted TCP/IP headers to receive the tags and signatures and successfully bypasses the middleboxes.
Advancements in artificial intelligence (AI) based on machine and deep learning are transforming certain medical disciplines [...]
Electrocardiogram (ECG) based user identification has received considerable attention with the advent of wearable devices. It provides emerging applications including personal healthcare a convenient way to authenticate users as the process can be performed at the moment the user makes contact with the device. However, a recent study discovered that injecting noise into the signal transmitted from the user to an application can effectively hinder the classification process. Many efforts have been made to deal with this noise injection attack, but most approaches have focused on noise removal. In contrast, this paper proposes Defensive Adversarial Training (DAT), which involves training a model with various noisy data to enhance the robustness of deep learning-based identification algorithms. We used two types of noise, Gaussian and Laplacian, to create noisy data. In addition, a sliding-window technique was used to effectively extract useful features and to achieve better accuracy. Our simulation results demonstrate that the proposed approach is highly robust to noise injection attacks and even against random noise. A comparative analysis with noise removal schemes also shows that the proposed DAT significantly enhances the robustness of ECG-based user identification.
Classification of fashion item attributes, such as neckline types, graphic patterns, sleeve lengths, hem types/length, etc., plays an essential role in the fashion item recommender systems by means of providing precise categorization and recommendations. With recent advances in Artificial Intelligence, many online retailers have adopted deep learning models to detect and classify the attributes of their product images effectively. However, these deep learning models require large and diverse datasets with labels to achieve an acceptable accuracy, which takes time and effort to collect and annotate. Another challenge of deep learning is its limited generalization capability to a new type of sample data. We hypothesize that imbuing a neural classification model with a human’s cognitive capability, such as recognizing complex patterns by simple geometric shapes, can improve fashion attribute classification performance. This paper proposes a transfer learning-based image classification model that exploits synthetic examples of canonical shapes (e.g., circles, triangles, rectangles, etc.) from publicly available datasets and our examples created using simple graphic tools. We use these datasets of geometric shapes as a source domain to pre-train a model and fine-tune it with labeled images to solve the target problem (i.e., fashion attribute classification). Our proposed framework increases the accuracy of the neckline type and graphical pattern classifications of Resnet50 by 40.7% and 19.8%, from 49.4% and 54.8% to 90.1% and 74.6%, respectively.
Federated Learning (FL) is an efficient and secure machine learning technique designed for decentralized computing systems such as fog and edge computing. Its learning process employs frequent communications as the participating local devices send updates, either gradients or parameters of their models, to a central server that aggregates them and redistributes new weights to the devices. In FL, private data does not leave the individual local devices, and thus, rendered as a robust solution in terms of privacy preservation. However, the recently introduced membership inference attacks pose a critical threat to the impeccability of FL mechanisms. By eavesdropping only on the updates transferring to the center server, these attacks can recover the private data of a local device. A prevalent solution against such attacks is the differential privacy scheme that augments a sufficient amount of noise to each update to hinder the recovering process. However, it suffers from a significant sacrifice in the classification accuracy of the FL. To effectively alleviate the problem, this paper proposes a Digestive Neural Network (DNN), an independent neural network attached to the FL. The private data owned by each device will pass through the DNN and then train the FL. The DNN modifies the input data, which results in distorting updates, in a way to maximize the classification accuracy of FL while the accuracy of inference attacks is minimized. Our simulation result shows that the proposed DNN shows significant performance on both gradient sharing- and weight sharing-based FL mechanisms. For the gradient sharing, the DNN achieved higher classification accuracy by 16.17% while 9% lower attack accuracy than the existing differential privacy schemes. For the weight sharing FL scheme, the DNN achieved at most 46.68% lower attack success rate with 3% higher classification accuracy.
During the past few years, serverless computing has changed the paradigm of application development and deployment in the cloud and edge due to its unique advantages, including easy administration, automatic scaling, built-in fault tolerance, etc. Nevertheless, serverless computing is also facing challenges such as long latency due to the cold start. In this paper, we present an in-depth performance analysis of cold start in the serverless framework and propose HotC, a container-based runtime management framework that leverages the lightweight containers to mitigate the cold start and improve the network performance of serverless applications. HotC maintains a live container runtime pool, analyzes the user input or configuration file, and provides available runtime for immediate reuse. To precisely predict the request and efficiently manage the hot containers, we design an adaptive live container control algorithm combining the exponential smoothing model and Markov chain method. Our evaluation results show that HotC introduces negligible overhead and can efficiently improve the performance of various applications with different network traffic patterns in both cloud servers and edge devices.
MPEG-DASH is a video streaming standard that outlines protocols for sending audio and video content from a server to a client over HTTP. However, it creates an opportunity for an adversary to invade users’ privacy. While a user is watching a video, information is leaked in the form of meta-data, the size of data and the time the server sent the data to the user. After a fingerprint of this data is created, the adversary can use this to identify whether a target user is watching the corresponding video. Only one defense strategy has been proposed to deal with this problem: differential privacy that adds sufficient noise in order to muddle the attacks. However, that strategy still suffers from the trade-off between privacy and efficiency. This paper proposes a novel defense strategy against the attacks with rigorous privacy and performance goals creating a private, scalable solution. Our algorithm, “No Data are Alone” (NDA), is highly efficient. The experimental results show that our scheme is more than two times efficient in terms of excess downloaded video (represented as waste) compared to the most efficient differential privacy-based scheme. Additionally, no classifier can achieve an accuracy above 7.07% against videos obfuscated with our scheme.
Federated Learning (FL) is a promising technique for edge computing environments as it provides better data privacy protection. It enables each edge node in the system to send a central server a computed value, named gradient, rather than sending raw data. However, recent research results show that the FL is still vulnerable to an inference attack, which is an adversarial algorithm that is capable of identifying the data used to compute the gradient. One prevalent mitigation strategy is differential privacy which computes a gradient with noised data, but this causes another problem that is accuracy degradation. To effectively deal with this problem, this paper proposes a new digestive neural network (DNN) and integrates it into FL. The proposed scheme distorts raw data by DNN to make it unrecognizable then computes a gradient by a classification network. The gradients generated by edge nodes will be sent to the server to complete a trained model. The simulation results show that the proposed scheme has 9.31% higher classification accuracy and 19.25% lower attack accuracy on average than the differential private schemes.