Large amount of digital educational data is becoming more widely available, which offers an opportunity to gain better insights into the educational system. Sharing this data with data analysts raises serious privacy issues. K-anonymization and l -diversity are popular existing privacy-preserving techniques used by many researchers. The disadvantages of these techniques are that they are vulnerable to background knowledge, homogeneity and similarity attacks. In response to these challenges the Differential privacy has emerged as another popular privacy preserving technique. It allows researchers and scientists to analyse the data efficiently without invading privacy of individual. Unlike other techniques, Differential privacy does not control the access of data analyst. In the proposed work an improved privacy preserving approach is suggested which uses ε-differential privacy for securing the data to maximize the privacy while maintaining the utility of data. In comparison with other existing privacy techniques ε-Differential Privacy does not partition the dataset into different attributes and it is also difficult for the adversary to apply background knowledge attack, homogeneity and similarity attack. The results of our experiments demonstrate that the proposed approach achieves higher privacy while maintaining competitive levels of data utility as compared to existing approaches. An educational dataset is used for experimentation and results are compared with existing work available in literature. Experiments are conducted for different values of ε which facilitate in deciding the appropriate value of ε to maintain proper balance in privacy and utility of data.
In this paper, we propose BDSecChain, a blockchain-assisted conceptual security framework designed to secure communication within a multi-controller software-defined networking environment. Unlike existing work that solely uses the proof-of-work (PoW) or proof-of-stake (PoS) consensus mechanism for security, the BDSecChain conceptually integrates practical Byzantine fault-tolerance consensus (PBFT), zero-knowledge proofs (ZKPs), and a dual-chain architecture for enhanced security. Our proposed Byzantine Controller Detection and Isolation algorithm (BCDI) identifies the malicious controllers via decentralised voting and the zero-knowledge proof flow validation protocol algorithm. BDSecChain framework verifies the cryptographic proofs without revealing their content to other SDN controllers. Furthermore, our architecture uses permissioned blockchains like C-Chain and D-Chain to ensure scalability and transparency, and we have also provided a comparative analysis against related state-of-the-art approaches. Our comprehensive theoretical security analysis suggests BDSecChain can thwart switch hijacking, flow rule injection, and replay threats, confirming the method’s suitability for next-generation SDN deployment.
In the realm of network management, the integration of Software-Defined Networking (SDN) with blockchain-based smart contracts is an emerging frontier with significant potential to enhance inter-domain communications. This paper presents an in-depth analysis of the application of smart contracts within SDN, particularly focusing on the automation and security of inter-domain interactions. Smart contracts, characterized by their immutable and autonomous nature, offer a novel approach to enforcing network policies and agreements across different SDN domains seamlessly. We explore the inherent benefits of this integration, including enhanced security through the tamper-proof nature of blockchain, and the efficiency gains achieved by automating network policy enforcement. The paper also addresses critical challenges such as scalability, interoperability, and the complexity of smart contract development within the SDN context. Through a combination of theoretical analysis and practical case studies, this research illuminates the transformative potential of smart contracts in SDN, paving the way for more secure, efficient, and self-regulating network environments. The findings and discussions in this paper aim to contribute to the ongoing evolution of SDN, particularly in scenarios where multiple administrative domains necessitate robust, automated, and secure communication frameworks.
Software Defined Networking (SDN) introduced the third layer, known as the control layer, due to which management and updating of devices became easy. The control layer in SDN provides an additional remote controlling feature of devices, which offers better management over traditional hardware networks. Traditional networking uses a hardwired mechanism for controlling the apparatus, a slow and complicated management approach. Unlike conventional networks, where every device needs to be updated separately, the SDN Control layer handles all the devices simultaneously. Only one command from the control layer can change, update, and manage hundreds of devices simultaneously. ONOS is the most popular and widely used Open Source SDN controller. So far, efforts have been made to improve the performance and availability of the ONOS controller. ONOS provides better performance and fault tolerance than any other controller available. However, no security module in the ONOS Controller can protect itself from DDoS attacks. This paper used the popular Suricata Intrusion Prevention System (IPS) to mitigate these web-based attacks. Wireshark statistics showed that our experimental study removed malicious DDoS traffic sent toward the control layer. This is the first study where Suricata actively detects and mitigates DDoS traffic sent toward the ONOS Controller.
In the evolving landscape of network management, multi-Software Defined Networking (SDN) controller environments represent a paradigm shift toward more dynamic and flexible network architectures. However, this advancement brings forth complex challenges in maintaining robust access control mechanisms. This paper proposes a novel approach by integrating Ethereum smart contracts and the Proof of Work (PoW) mechanism to address these challenges. Using Blockchain with SDN, Denial of Service (DoS) attacks, spoofing attacks, and authentication attacks are effectively mitigated. We explore the potential of Ethereum blockchain technology, particularly its smart contracts and PoW consensus algorithm, as tools for enhancing access control within multi-SDN environments. The paper presents a comprehensive analysis of how smart contracts can automate and secure access policies, mitigating traditional access control limitations. Additionally, the role of PoW in maintaining the integrity and security of these contracts within a decentralized framework is examined. This study aims to pave the way for future research and practical applications of blockchain in network security, highlighting the transformative potential of combining these cutting-edge technologies in multi-SDN controller environments.
Steganography, a data hiding technique, has trended into a lucrative means to hide malware within digital media and other files to avoid detection. Such malware hidden by means of steganography is known as stegomalware. Detecting stegomalware has been difficult and indeed removing such malware from the file is a big challenge. A tool has been created (Verma V, Muttoo SK, Singh VB Detecting stegomalware: malicious image steganography and its intrusion in windows. In: International conference on security, privacy and data analytics. Springer, Singapore (2022). 10.1007/978–981-16–9089-1_9) to detect such malware hidden within widely used JPEG file format. This paper introduces new and significant functionality to our tool (Verma V, Muttoo SK, Singh VB Detecting stegomalware: malicious image steganography and its intrusion in windows. In: International conference on security, privacy and data analytics. Springer, Singapore (2022). 10.1007/978–981-16–9089-1_9) to remove such malware from the file after detection, unlike the existing techniques limited to detection. The tool proposed in this paper has rendered the malicious image files benign with a success rate of 99.92%.
Reversible data hiding (RDH) is an approach that facilitates data hiding in a way that both the secret data and cover media can be extracted and recovered in their untouched form. Various RDH schemes have been proposed that utilize pixel value ordering mechanisms for pixel prediction and utilize histogram shifting (HS) criteria for prediction error expansion to implant secret data. However, such schemes are inefficient when it comes to hiding large volumes of data. In this paper, we propose a novel and improved RDH technique that divides the image into two using a checkboard pattern. One part of the image exploits the pixels of another part for prediction and vice versa. Also, as a parameter of smoothness, a fluctuation value is calculated for each pixel to avoid embedding in unsmooth regions of the image. The scheme is efficient in terms of hiding larger capacities of data and better stego-image quality.
Substitution-boxes (S-boxes) are very important nonlinear components used for achieving strong confusion for enhancing cryptographic security in most of the block ciphers. Designing cryptographically strong S-boxes has been a major research domain for the designers of symmetric crypto systems. In the proposed research work, Bat Algorithm based swarm technique is proposed to design strong S-boxes. Cryptographic strong S-boxes are obtained by the developed swarm technique. Authors analyze cryptographic strength of the obtained S-box by evaluating properties like Bijectivity, Nonlinearity, Bit-Independence Criterion, Linear Probability and Differential Uniformity. The obtained performance parameters for the designed new S-box by the swarm technique are compared with some recently reported S-boxes in the literature. The designed S-box has good cryptographic strength. The designed S-box has good cryptographic strength like nonlinearity = 110.75 and average Strict Avalanche Criterion (SAC) value = 0.506. For the constructed S-box, most of the Differential uniformity components are 4 and shows uniform distribution approximately. The proposed new S-box is also free from the fixed points.
Now a days educational data has been produced in large amount by learners. Educational data contains online as well as offline learning resources of individuals, learning experience, attendance record, assignment records and many other records. Some useful information can be extracted from this available data which can be further used in improving teaching practises and learning experience of learners. It can also help in increasing the success rate of students. Sharing and analysis of data introduces risk of privacy. This is the responsibility of data curator to provide privacy to individuals data. There are many exiting privacy-preserving algorithms which are used by researchers to sustain privacy of the data. Differential privacy is one of the popular privacy-preserving techniques which tries to reduce privacy leakage of data by adding noise to data. Differential privacy protects individuals' information from attacker and also maintains accuracy of data. In the proposed work different techniques to implement differential privacy have been explored in detail with their comparative analysis. Different types of differential privacy, sequential decomposition and their comparison with other privacy-preserving techniques is also provided.
Educational data is available in today’s world in abundance; it can be leveraged to improve students’ performance based on their academic records and to predict their future performances. Data sharing without intruding the privacy of individuals is a major concern. The present work proposes an improved privacy preserving k-anonymization Cluster-based Algorithm for a multi-relational educational dataset. To overcome the limitations of k-Anonymization, anonymized data is l-diversified to protect sensitive data from attacks. Further, Text Steganography is applied to avoid similarity attacks on l-diversified data to provide the second layer of privacy. Since the utility of data is an important factor, it must be maintained along with privacy to get useful information from the analysis. A Loss Metric is used to find the distortion of k-anonymized data to evaluate the balance between privacy and utility. Earth’s mover distance has been calculated for l-diversified data with steganography and without steganography to validate the results. For experiment purposes, an educational dataset has been used and results are compared with the existing approaches available in the literature. Statistical analysis has also been performed to justify the results.
Software-Defined Networking (SDN) is becoming an increasingly relevant networking approach day by day, due to its myriad benefits over Traditional hardwired-based Networks. Still, SDN Controllers are popular for their weak security mechanism. This paper discusses the vulnerability issues in the security of SDN Controllers. The Control layer is the most vulnerable to network attacks in the three-layered SDN architecture. DDoS attacks on the Control layer can cause a Single Point of Failure for the entire SDN network. OpenDaylight (ODL) and Open Networking Operating System (ONOS) are the top two leading open-source SDN Controllers. We found out that ODL and ONOS Controller fail to provide any protection from DDoS attacks. SDN developers have compromised the security aspects of the Controller to improve its performance. In this research article, an attempt is being made to address such security vulnerabilities of SDN with ODL and ONOS Controllers for DDoS attacks.
Social media platforms provide an opportunity to the users to express their views and emotions on any topic. Various researchers have successfully used the content posted on these platforms to capture the emotions of the people about the given event or topic. During COVID-19 pandemic, Indians extensively used Twitter owing to an increased need for virtual interaction. In this work, we analyse the tweets posted in India during COVID-19 outbreak to understand how individuals in India reacted to the pandemic. We identified the timelines of three major COVID-19 waves from May 2020 to March 2022 and retrieved 13,818 tweets from COV19Tweets dataset available at IEEE DataPort for the respective duration of each of the three waves. Lexicon based sentiment analysis of the tweets indicated a positive mindset of the Indian population during the pandemic. Further, visual analysis through word clouds revealed that a few words were common for all waves whereas some words were wave-specific. It was observed that the words used in tweets cannot be compulsorily associated with positive or negative emotions, as the context or the set of words taken together may be a better indicator. Hence, machine learning approach was followed for the identification of sentiments by extracting BoW (Bag-of-Words) and TF–IDF (Term Frequency–Inverse Document Frequency) features from the tweet text. Comparative performance analysis of the four classification algorithms, namely, Decision Tree (DT), Logistic Regression (LR), Naive Bayes (NB), and Support Vector Machines (SVM) and two ensemble methods Adaboost and Random Forest revealed that LR applied to BoW featureset was the best performer. Finally, we performed Latent Dirichlet Allocation (LDA) based topic modeling on the COVID-19 tweets to identify topics of discussion in each of the waves. The topics evolved from informative messages related to the pandemic during the first wave, to wider discussions related to the impact of COVID-19 on nifty, tourism, etc. for the second wave, and the omicron virus, availability of beds, and ventilators in the third wave. This study can be of great interest to governments, as they may undertake similar studies to understand human behavior when natural calamities or pandemics occur at the local or global levels. The automated capture of public sentiments and identification of topics may expedite the appropriate execution of preventive measures taken by governments and address the concerns of citizens almost instantly.
Nowadays, immense educational data is available for analysis. To extract useful information from huge data, data analysis is required. For analysis, data has to be shared with a third party called data analyst. Sharing data with data analyst introduces the risk of privacy for individuals whose sensitive information is present in the shared data. Privacy is the right of an individual, so it needs to be maintained while sharing the data with a third party. There are many privacy-preserving algorithms available. k-anonymization is one of the most popular and traditional privacy-preserving methods. It modifies data to protect an individual's sensitive information by disconnecting the link between an individual and its sensitive information. k-anonymization uses generalization and suppression tools to anonymize the data. Generalization replaces specific values of attributes with general values, and suppression deletes unmatched values of attributes. There are many existing single table anonymization algorithms. The proposed work presents how a single table anonymization algorithm can be applied on multi-relation dataset. It also discusses the problems encountered when single table anonymization algorithms are used for the multi-relation dataset. Present work also discusses the limitations of k-anonymization and gives future research directions.
Steganography, a data hiding technique has trended into hiding the malware within digital media, giving rise to stegomalware. Specifically, digital images pose a potential threat due to their massive use, innocuous appearance, and ability to hide data without noticeably degrading the quality. Detecting malicious image steganography is a challenge for intrusion detection systems or static detection that lack analyzing the pixels of an image. This paper presents a tool in python to detect malware in widely used JPEG image format. The existing methods have mostly focused on finding steganography artifacts or used feature-based analysis that lacks revealing the hidden malign data. Unlike existing ones, the proposed tool alongside classification locates malicious content in JPEG images with revealing the found malign data along with its location as the output. This functionality to the best of our knowledge has not been found in the available literature. The tool has analyzed three types of JPEG images: malicious, benign, and stego images. Though malicious images are also stego ones, the paper refers to those hiding non-malicious data as the stego images. This is to evaluate the effectiveness of our tool in classifying the images with malicious and non-malicious data hidden. As a result, the tool has attained a low False Negative Rate (FNR) of 0.08 and False Positive Rate (FPR) of 0.001 with a better detection rate relative to state-of-the-art techniques. Indeed, it has predicted all stego images as non-malicious. Also, the paper has assessed the detection of Windows applications containing stegomalware.
Defect classification is a process to classify defects based on predefined categories. It is time consuming and manual process. Many automatic defect classification methods have been proposed to speed up the process of defect classification. However, these methods have not utilized the inter relations among the defect reports. In the literature for defect classification, Term Frequency-Inverse Document Frequency and Bag of words based approaches have been proposed. In this paper, we have proposed word embedding based model for the defect classification which is proven to be better in comparison with the existing methods. We have also proposed models for inter project defect classification by considering combination of different datasets of the same domain. We tested the proposed approach on 4096 defect reports using K nearest neighbor, Random forest, Decision tree, Support vector machine, Stochastic gradient descent and Ada boost classifiers in terms of accuracy, precision, recall and F1-score. Experimental results show that Decision tree achieves highest accuracy 98.21% while trained and tested on GloVe word embedding. We have also generated new word embedding using the bug reports corpus. Further, we compare the proposed model with Lopes et.al., 2020 and results show that our model outperforms.
Recent years have witnessed a noticeable growth in the development of stealthy Android-based malware which has led to a pressing need for accurate malware detection systems. In this paper, we propose a graph-based ensemble classifier - GENDroid that performs ensemble learning using different graph-based classification techniques. The proposed classifier combines the predictions of three graph-based base classifiers using majority voting. The main advantage of our proposed classifier is that by combining diverse graph-based classifiers, a more accurate classifier can be learned. We experimentally demonstrate a substantial improvement of our proposed method over the individual graph-based classifiers on three datasets of benign and malicious Android apps. The results are backed up by using statistical tests. The robustness of GENDroid against one of the most widely used anti-forensics techniques - code obfuscation, is also verified empirically. GENDroid is also found to be resilient to the evolution of APIs and achieved very high accuracy.
Substitution-boxes are important nonlinear components used for achieving strong confusion as well as cryptographic security in a majority of modern symmetric cryptosystems. Designing cryptographically strong S-boxes has been a major research domain for the designers of symmetric ciphers. In this research work, Firefly algorithm based technique is proposed for designing S-boxes. The proposed Swarm Intelligence (SI) based technique generates cryptographically strong S-boxes. Furthermore, authors analyze strength of the computed S-boxes by testing: nonlinearity, bijectivity, bit-independence criterion (BIC), linear probability and differential uniformity. For the S-box constructed by the proposed technique; average nonlinearity is 109.25 and average strict avalanche criteria (SAC) value is 0.504. The computed performance results for the S-box are compared with some recently reported S-boxes.
Software systems have become an integral part of all the organizations. These systems are performing many critical operations. A defect in these systems affects the product quality and the software development process. Prediction of the impact category of these defects helps in improving defect management process as well as taking correct decisions to fix defects. Orthogonal defect classification is a popular model for classifying defects and it provides an in-depth analysis of the defects. In this study, we proposed an auto classify approach to classify the defects into impact categories as defined by Orthogonal Defect Classification (ODC). Bag of words, term frequency-inverse document frequency and word embedding have been used to represent the textual data into numeric vectors. For experimental work, we have used 4,096 reports form three NoSQL databases. We have trained and tested the proposed autoclassify approach using Support Vector Machine (SVM) and Random Forest Classifier (RFC). We achieved maximum accuracy 94% and 85.99% using SVM and RFC respectively.
In machine learning, feature selection is a very important step to reduce the dimensionality of data by removing irrelevant features, redundant data to improve the learning accuracy. As the dimensionality of data has increased, feature selection has become a challenging task. Various approaches have been proposed for feature selection. In this study, we have analyzed the effectiveness of three widely used feature selection methods namely Chi square; information gain and latent semantic analysis (LSA) to classify the software bugs. The performance of four classifiers K nearest neighbor, Random Forest, naïve bayes and support vector machine are evaluated for the above feature selection methods in terms of accuracy, precision and recall.