The lack of adequate system resources can significantly affect the safety and security of intrusion detection systems implemented to work within the Internet of Things, edge or fog settings. Deployed devices in these environments should balance the operational and security requirements of the systems. This issue is critical since operational environments are stochastic, and deploying devices that have static configurations or scalarized optimization approaches cannot adequately respond to the changing conditions. This work proposes the use of A2DAPT - A Two-Stage Pareto-Driven Framework for Adaptive Resource Optimization in Lightweight Intrusion Detection Systems. This new scheme divides the proposed framework into an offline and an online stage and adapts the resource utilization of lightweight IDS to resource budget levels. In the offline stage, the exploration of the Non-dominated Sorting Genetic Algorithm II (NSGA-II) is used to determine the Pareto set of optimal IDS settings. In the online stage, A2DAPT enforces a deep reinforcement learning controller based on a Dueling Double Deep Q-Network with Prioritized Experience Replay that adapts the intrusion detection system’s configuration in relation to the non-stationary traffic by taking actions from the Pareto set determined in the offline stage. The use of the Pareto set as an action space ensures the use of safe and interpretable decisions by the intrusion detection system during non-stationary traffic. Therefore, the evaluation of the A2DAPT, in this study, focuses on its runtime behavior while operating in a resource-constrained environment under non-stationary traffic consisting of benign and malicious denial-of-service traffic. The evaluation demonstrated that A2DAPT continuously achieves savings compared to a competitive static baseline with approximately 15% CPU, 10% memory, and 7% bandwidth, all of that without significant degradation of the detection performance. The results confirm that the combination of Pareto optimization solutions with deep reinforcement learning agents enables efficient intrusion detection operation in resource-constrained environments.
The ongoing digital transformation caused by emerging technologies poses novel challenges but also opportunities. Western Balkan (WB) leaders are lagging behind the ongoing processes of this transformation. The article argues that WB leaders need to comprehend digital transformation and use this process to improve governance, boost the economy and address existing social challenges.
The future of mobile and Internet technologies envisions advances beyond the existing scope of science. The concepts of automatic driving and machine-type communication are quite sophisticated and require the upgrading and improvement of the current mobile infrastructure. 5G mobile technology serves as a solution, although there is no approximate network infrastructure to meet the service guarantees. The mobile network is today’s demand, and the telecommunications industries are creating new infrastructures and technologies to provide more benefits to end-users and to meet their demands. Compared to the 4G network, 5G provides many new security features and has more sophisticated and robust security mechanisms, although there are still many potential security issues with the 5G network. Therefore, security analysis of 5G infrastructure is very crucial. This article analyzes the security requirements of 5G business applications, network architecture, and user privacy. At the same time, it is a comprehensive study of various threats and solutions to ensure the security and privacy of 5G.
The security of the Internet of Things (IoT) is a key worry since it deals with personal data that must be dependable and can be used dangerously to control and manipulate device operations. In addition, the data generating process is heterogeneous, and the data is enormous in bulk, requiring complicated management. Quantum IoT, or Quantum Computing and IoT, is a notion of higher security design that utilizes quantum-mechanical principles on IoT security management. On the one hand, IoT is beneficial to us, but it also poses several major security risks, such as data leaks, side-channel attacks, malware, and data authentication. Classical cryptographic techniques, such as the Rivest-Shamir-Adleman (RSA) algorithm, perform admirably on traditional machines. However, quantum computing, which has enormous processing capacity and is more than capable of readily breaking current cryptographic algorithms, is steadily gaining traction. As a result, even before quantum computers are commercially available, we must create post-quantum cryptography algorithms to protect our systems from security breaches. Lattice-based cryptography, as a possible option for the future post-quantum cryptography standard, has the features of strong security guarantees and great efficiency, making it ideal for IoT applications. We discuss the benefits of lattice-based cryptography and its implementations for IoT devices in this study.
The progress of information and communication technology has a positive impact, and it is a part of our everyday activities. In the same time, it presents an attack vector and vulnerability used by attackers to generate advanced cyber threats. Attackers use new and advanced tools to perform cyber-attacks, including AI-based malware, and in most of cases, they are ahead of the cyber defenders. The tools and attacks used by attackers require extensive time if analyzed manually and require significant automation so cyberspace can be effectively defended. As one of the best tools for the first line of defense is AI (Artificial intelligence)-based cyber defense mechanisms that can be used to react proactively (before the cyber-attack) or reactively (during the cyber-attack) in order to detect, restrict and stop the attack. This chapter gives a brief review of the usage of artificial intelligence as the first line of defense in cyberspace, using the model of defense in-depth, presenting AI-based tools and applications that already exist and are used for cyber defense.
This study aims to analyse the occupationaliaccidents in the Republic of North Macedonia as a “lower-middle-income economy” during the period 2014-2019. In line with the theoretical findings and other similar state cases, the available data, and the subsequent analysis there of demonstrate that North Macedonia possesses a workplace environment that is more vulnerable than that of other countries when it comes to occupational accidents. The case of North Macedonia indeed provides a prominent example of change in the national economy and legal framework, while exhibiting certain deficiencies, common to “lower-middle-income” economies that could potentially be improved or eliminated.
The work suggests a potential solution to contemporary Corporate and National security concerns, with regards to the use in the future of 5G technologies.In today's digital age, individuals, groups and some states, (ab)use the easy access to modern technologies to further their economic and political objectives.In these endeavors, among others, these actors utilize jamming attacks (i.e.electronic warfare tactics exclusively used by the military in the past), in order to produce the well-known effect of DoS (Denial of Service).Up to now there is no communication technology that is immune to the jamming attacks, so there is no expectation that the new 5G concept, that is still under development will be fully resistant to well-known traditional jamming and other types of attacks.The proposed Security and Quality of Service (QoS) framework provides high levels of security features and safety, through high-performance mobile broadband networks, using Mobile Cloud computing.It guarantees QoS provisioning for different broadband services, with present jamming, as well as, other types of distributed DoS (DDoS) attacks.Moreover, the trend of integrating various criminal activities in the cyberspace is also presented.The performance of the proposed security and QoS framework is evaluated through simulations and analysis with multimedia traffic, in a heterogeneous mobile broadband Cloud environment with the coexistence of multiple radio technologies.
This paper presents an advanced Security QoS provisioning module with vertical multi-homing and multi-streaming framework for 5G mobile terminals with radio network aggregation capability in next generation mobile and wireless broadband networks. The proposed mobile terminal framework is leading to high performance opportunities for multimedia services with high level of QoS provisioning and secure communications. It is using vertical multi-homing and multi-streaming features with IPSec encapsulations within the mobile equipments, which are able to handle simultaneously multiple radio network secure connections and speed up the transfer of the multimedia services by transmitting each object in a separate stream, achieving high level of QoS and security provisioning. Our proposed model is user-centric, targeted to always-on connectivity, maximal network throughput, with ability to provide various multimedia services with high level of security and confidentiality. The performance of the proposed framework is evaluated though simulations and analysis with multimedia traffic in Next Generation Mobile broadband scenarios with coexistence of multiple heterogeneous radio access technologies, such as existing and future (5G) mobile broadband networks.
In the last decade of the twentieth century, the rapid development of computer technology and its application in the military doctrine prompted the idea of network-centric warfare. Besides sea, air, land and space, the contemporary strategy defines cyberspace as the fifth battlefield and important part to conduct information operations. The purpose of this was to introduce a new revolution in military affairs, but also to demonstrate the superiority of the Western way of war. However, the opponent always adapts. Computers and internet are available to everyone, so the new paradigm did not become an exclusive right to the rich nations and powerful armies. Terrorist organizations around the world quickly recognized the usefulness of cyberspace, first to collect information, then for communication, planning and conducting terrorist actions. Especially the militant religious extremists from the beginning started to use cyberspace for propaganda, recruitment and training of new members, and trying to carry out cyber attacks. There is skepticism that the threat of terrorist cyber attacks is exaggerated, but the analysis of the most recent attempts shows that we have to understand the seriousness of their intention to cause severe damage on computer systems of critical infrastructure. In this context, the intention of this chapter is to show that the terrorists not only recognized cyberspace as the new battlefield, but there is a trend of their increased presence, suggesting the necessity to monitor their adaptation to new technologies and to estimate their capacities and capabilities, or to bring the war against terrorism into cyberspace as well.
In the digital age, contemporary international security has dramatically changed and continues to rapidly evolve. These new security dynamics after the Cold War have caused a marked change in global power structures. Modern information and communication technologies have emboldened non-state actors (corporations, groups and individuals) with the ability to project strategic global power like never before. The power shifts have caused certain states to vow to assert physical force in response to the perceived threat. The polarising nature of this potential solution has stimulated international debate. Therefore, this article proposes a possible solution that should be further developed. The main argument is that to reduce the threat from cyberspace, states could apply swarming-based cyber defence built under the framework of collective security. Modelled on the United States' current cyber security strategy and the North Atlantic Treaty Organization's concrete efforts to strengthen collective responses, the article describes the challenges provided in the digital age and justifies the importance of adopting relevant approaches. Finally, the article explores how swarming-based cyber defence could serve as a viable solution under the existing concept of collective security in the international arena.
Much of the social, economic and political activities in the region of South-East-Europe (SEE) take place via so-called cyberspace. Even though there is evidence of growing dependence of cyberspace in SEE countries the practice shows that there is no parallel match to security. Giving that no one is safe in the cyberspace the main argument of this article is that in order to provide effective defense from malicious and aggressive actors against their own citizens, the SEE countries should focus on building cyber resilient societies. In doing so, they need to concentrate on building an effective strategy, adjust the law and develop appropriate doctrine.
In this chapter, an analysis of security attacks on network elements along with the appropriate countermeasures is presented. The main goal of this chapter is to present the practical execution of various security attacks and their mitigation techniques due to more resilient cyber infrastructure. The network topology that has been attacked is designed in GNS3 software tool installed on Windows operating system, while the attacks are performed in Kali Linux operating system. Three groups of security attacks (Denial of Service, Man in the Middle, and Control Plane attacks) are observed in simulation scenarios with a detailed analysis on each of them, followed by a presentation of practical performance and ways of prevention (protection) against the attacks.
There are many freeware and commercial tools which can be used to provide forensics information based on dead and live forensics acquisition. The main problem with these tools is that in many cases the investigator cannot explain the script functionality and generated results and information during the trial. Because of this reason there is an increased need for developing and using script which can be easy explained and adapted to any analysis which should be made by the examiners. The chapter presents a novel developed First Responder script which can be used to perform a live and dead forensics analysis in support of Law Enforcement during the investigation process.
The growing network attacks and intrusions have put the government organizations at a great risk. In cyberspace, humans have great limitations in data analyze and cyber defense because of the amount of data they have to process and the limited response time. Considering these parameters one of the best solutions is when the cyber defense mechanisms are AI (Artificial intelligence)-based because they can easily determine and respond to the attacks that are underway. The responses can be easily managed using man in the loop or fully atomized techniques. This chapter gives brief review of the usage of artificial intelligence in support of cyber defense, explains some useful applications that already exist, emphasizing the neural nets, expert systems and intelligent agents in cyber defense. Furthermore the chapter will propose a technical AI-based cyber defense model which can support the governmental and non-governmental efforts against cyber threats and can improve the success against malicious attack in the cyberspace.
In this chapter, an analysis of security attacks on network elements along with the appropriate countermeasures is presented. The main goal of this chapter is to present the practical execution of various security attacks and their mitigation techniques due to more resilient cyber infrastructure. The network topology that has been attacked is designed in GNS3 software tool installed on Windows operating system, while the attacks are performed in Kali Linux operating system. Three groups of security attacks (Denial of Service, Man in the Middle, and Control Plane attacks) are observed in simulation scenarios with a detailed analysis on each of them, followed by a presentation of practical performance and ways of prevention (protection) against the attacks.
The paper shows detailed analysis of the effects of the AuthRF (Authentication Request Flooding) and AssRF (Association Request Flooding) MAC Layer DoS (Denial of Service) attacks on 802.11e wireless standard based on a proposed queuing model. More specific, the paper analyzes the Access Point (AP) behavior under AuthRF DoS attacks with different frequency of the requests arrival, i.e. Low Level (LL), Medium Level (ML) and High Level (HL), at the same time considering different traffic priorities. The proposed queuing model and the developed analytical approach can be also used on each protocol layer, especially if the attacks are seen in terms of the flooding influence over AP with too many requests (ICMP, TCP SYN, UDP etc.).