A scientific approach to investigating digital attacks and crimes is employed in digital forensics, commonly referred to as computer forensics. The field of digital forensics requires a lot of work. Investigators begin by searching electronic devices for evidence and storing the information on a safe drive. The information is then examined and recorded. Next, they hand over the digital evidence to the police, who can use it to solve crimes or use it as evidence in court to establish the guilt of the accused. Analysing every device that can store digital data is now included in the enlarged definition of digital forensics, which was first coined as a synonym for computer forensics. The foundation of behavioral forensics can be regarded as machine learning, which has strong ties to artificial intelligence. For the purpose of stopping any unlawful activity, software-based pattern recognition can handle enormous volumes of data using machine learning. Using networked software and tools for remote analysis is one way to employ machine learning.
The Internet of Things (IoT) strategy enables physical objects to easily produce, receive, and exchange data. IoT devices are getting more common in our daily lives, with diverse applications ranging from consumer sector to industrial and commercial systems. The rapid expansion and widespread use of IoT devices highlight the critical significance of solid and effective cybersecurity standards across the device development life cycle. Therefore, if vulnerability is exploited directly affects the IoT device and the applications. In this paper we investigated and assessed the various real-world critical IoT attacks/vulnerabilities that have affected IoT deployed in the commercial, industrial and consumer sectors since 2010. Subsequently, we evoke the vulnerabilities or type of attack, exploitation techniques, compromised security factors, intensity of vulnerability and impacts of the expounded real-world attacks/vulnerabilities. We first categorise how each attack affects information security parameters, and then we provide a taxonomy based on the security factors that are affected. Next, we perform a risk assessment of the security parameters that are encountered, using two well-known multi-criteria decision-making (MCDM) techniques namely Fuzzy-Analytic Hierarchy Process (F-AHP) and Fuzzy-Analytic Network Process (F-ANP) to determine the severity of severely impacted information security measures.
Today Internet of Things (IoT) is quickly becoming one of the most popular technologies in the whole world where enormous number of devices are connected to make human life more feasible and comfortable. IoT technologies play a significant role everywhere. It is a coalescence of embedded computing, communication technologies, sensors, and actuators. The aim of the IoT is to endue seamless capabilities to the user anytime, anywhere. Inspite of various benefits, IoT also calls for high levels of security, authentication, privacy, and protection from attacks. There are variegated security mechanisms and solutions for IoT applications that have been introduced in the past works but still IoT facing enormous number of challenges in the field of security and privacy. This paper proposes an improved IoT architecture with a thorough analysis of the variegated architectural approaches given by different researchers ranging from basic architectures to commercial-grade implementations. Specifically, this paper focuses on IoT security scenarios associated with IoT architecture and also examined various security threats and vulnerabilities exists in IoT systems like confidentiality, privacy, authentication, integrity, access control, etc. Author concludes the work by discussing privacy and security issues in IoT architecture and challenges they pose to researchers.
Lymphoma, a malignancy originating from the aberrant proliferation of lymphocytes in the lymphatic system, becomes one of the prime concerns in health care across the world. The traditional, mono-therapeutic interventions using chemotherapeutic agents and radiation showed limitations in relation to disease control, suboptimal response, and development of intractable drug resistance. This study thus opens the reasons for combination therapies in detail by explaining the intrinsic rationale and revealing the intrinsic advantages of lymphoma treatment with an initiative underpinned by scrupulous analysis. Furthermore, the broad analysis had comparisons between combination therapies, were derived from studies, clinical trials, and actual instances. Key performance metrics like as overall response rates, progression-free survival, and overall survival, together with a thorough review of safety profiles, are used to determine the efficacy and long-term tolerability of various combination regimens. Using the PROMETHEE-II technique, this study has attempted to offer a comprehensive knowledge of the complex therapeutic landscape by addressing various issues and factors such as drug-disease interactions, toxicities, cost-effectiveness, and accessibility. This study avails practitioners and researchers with indelible understanding that seeks to enhance the optimum therapeutic trajectory and evidence-based decision-making toward an improved outcome of treatment in lymphoma.
Security testing is a critical concern for organizations worldwide due to the potential financial setbacks and damage to reputation caused by insecure software systems. One of the challenges in software security testing is test case prioritization, which aims to reduce redundancy in fault occurrences when executing test suites. By effectively applying test case prioritization, both the time and cost required for developing secure software can be reduced. This paper proposes a test case prioritization technique based on the Ant Colony Optimization (ACO) algorithm, a metaheuristic approach. The performance of the ACO-based technique is evaluated using the Average Percentage of Fault Detection (APFD) metric, comparing it with traditional techniques. It has been applied to a Mobile Payment Wallet application to validate the proposed approach. The results demonstrate that the proposed technique outperforms the traditional techniques in terms of the APFD metric. The ACO-based technique achieves an APFD of approximately 76%, two percent higher than the second-best optimal ordering technique. These findings suggest that metaheuristic-based prioritization techniques can effectively identify the best test cases, saving time and improving software security overall.
The vast majority of email viruses propagate by ensuring that every address included in the address book of the victim is sent the malicious message or attachment. There are a variety of approaches that can be utilized in order to package and present these viruses. Some of them can be immediately identified as malicious based on the content of the body, the sender, who may or may not be trustworthy, and the subject lines, which are just unintelligible. It may be difficult for receivers to identify individual email messages that include malware since the malicious actor puts a lot of effort into making it appear as though the email message was sent from a respectable sender. Phishing is an attempt to steal sensitive information by impersonating a trustworthy entity, typically a business. Cybersecurity is an extremely important topic in the field of information technology. Information security is one of the most pressing problems facing our generation at the moment. When we think of cyber security, the first thing that comes to mind is cybercrime, which is expanding at an alarming rate. This is because cybercrime is the most common kind of online crime. In order to put an end to these cybercrimes, various governments and businesses are pursuing a variety of preventative measures. In spite of the many safeguards in place, a significant number of people continue to be anxious about the safety of their online activity. The difficulties surrounding the use of email viruses as a threat to cyber security are the primary focus of this article. From the point of view of email viruses, a unified approach for assessing the level of cyber security has been developed. In addition to this, it examines the most recent developments in the methods of cyber security, as well as the ethics and trends that are influencing the industry.
The benefits of feedback for researchers as achievement and development are undisputed. For this reason, researchers have sought to develop ideas and frameworks that describe how feedback works and what factors may influence feedback engagement in it. This review paper aimed to summarize the best-known models and ideas we discovered through a methodical, three-step process. We discussed the definitions, models, historical context, and certain basic mechanisms of feedback systems. At the end of our examination of the models, we reached eight major conclusions. This study aims to advance knowledge in this area and help researchers and educators select the best models for their studies and policy development in feedback model. We further evaluated and analyzed the fourteen models in our supplemental study to classify common features and integrate them into a new comprehensive model.
The advent of Internet-based technology has made daily life much easy than earlier days. The exponential rise in the popularity of social media platforms has not only connected people from faraway places, but has also increased communication among humans. However, in several instances, social media platforms have also been utilized for unethical and criminal activities. The propagation of fake news on social media during the ongoing COVID-19 pandemic has deteriorated the mental and physical health of people. Therefore, to control the flow of fake news regarding the novel coronavirus, several studies have been undertaken to automatically detect the fake news about COVID-19 using various intelligent techniques. However, different studies have shown different results on the performance of the predicting models. In this paper, we have evaluated several machine learning and deep learning models for the automatic detection of fake news regarding COVID-19. The experiments were carried out on two publicly available datasets, and the results were assessed using several evaluation metrics. The traditional machine learning models produced better results than the deep learning models in predicting fake news.
The recent age of cloud computing (CC) has witnessed significant breakthroughs, notably in IoT (Internet of Things), Edge computing, Fog computing, 5G, and subsequently 6G technology. CC allows individuals and businesses to store, process, and manage their data via cloud-enabled systems to facilitate scalability, adaptability, and interconnectivity. The appropriate implementation of numerous cloud computing models aids firms in digital transformation and development with maximum productivity. However, CC integration with IoT allows an extraordinary capability and boosts economies’ ability to develop at a fast pace. Meanwhile, due to the rapid expansion of IoT, the current cloud network cannot keep abreast of the growing data loads and processing extremities, particularly in real-time. Even the most cutting-edge cloud providers are experiencing an inordinate strain as a result of the growing number of consumer and corporate devices connected to the IoT. While it has a centralized design, it lacks bandwidth and has downtime issues. High latency, lack of location awareness, outage concerns, etc., are among the issues that cloud services for IoT confront. Furthermore, due to uninterrupted operating states, the massive volume of data created by the IoT is increasing enormously. IoT devices are creating a flood of data, disrupting predictable data processing and analytics capabilities well managed by the cloud. As a result, securing this ocean of data has become an elite concern for researchers and cyber experts, as organizations jeopardize their reputation and users’ privacy and security. Fog computing (FC) technology has been used, which analyses and acts on the data by bringing the cloud close to the commodities, ultimately reducing the response time. This paper aims to explore various other challenges and issues of incorporating FC into analyzing IoT data.
In today's world, the software makes work more straightforward and more manageable for users, employees, and organizations. It makes our working environment more comfortable, but on the other hand, it has security issues. Over the last two decades, software security has become a prime focus for security organizations as well as security practitioners. As the growth of software increases, the level of security risks compromised with software also increases. In most cases, 'compromising in design’ is one of the critical security risks. Software security risks are the weakness in the software that accidentally allow hazardous operations. To give prime concern to the security mechanism, the valuable assets must be protected. Hence, prompt detection and remediation of software security risks is a crucial issue in software security. In this paper, the researchers have laid stressed on Software security risk at the design phase and listed some common software security risks from CWE, i.e., Common Weakness Enumeration. In addition, researchers have also mentioned the CVSS 3.1 vulnerability scoring mechanism and calculated the scores of listed security risks to prioritize the exploitability impact and its base score.
For the past few years, the role of education is to progressively expand its learning methods and learning environment. The incorporation of various technologies is another factor that intensifies the learning process. By using various sensing devices and Internet-connected devices, growth of students are enriched by continuous assessment and monitoring of their performance. Smart education opens many opportunities for everyone to achieve high standards and unique innovations. And IoT is the technology that pledges to upgrade the basic education system into smart education environment. The ability of IoT is to make objects interconnected and sensed data unavoidable in smart education. The application of IoT will improve the education process, so that students can learn expeditiously, effectively, and comfortably. This chapter encapsulates the basic concepts and definition of smart education with the incarnation of IoT devices.
We lived in the era of technology, where online websites have made communication and interaction much easier than the early decade. The modern world is changing so quickly, and emerging new trends simplify our lives, but on the other hand, it will also create risks. A website acts as a more admired platform by the user to access the different web applications. Because of the functions of the website, all the data on the website is available in the proper structure, which makes the working environment much convenient and efficient. The websites may undoubtedly be a precious resource for young people, but it may also cause severe problems. It is really easy to build a fake website that looks like an original website where hackers like to deceive consumers and businesses for their own benefits. In this paper, researchers have examined online fraud cases through web applications and how fraudulent websites affect financial loss. Researchers also highlighted the current situation regarding the usage of online services, as well as the threats that have an impact on users. In addition, researchers have suggested that new laws and regulations will be implemented for preventing cybercrime.
Software engineering is affecting almost every aspect of our daily life. Software development isthe basic activity in the world of software engineering and information technology. Software developmentinvolves some set of steps that are called as software development life cycle. It is considerable for success ofany software that each step of SDLC is error and defect free. But it is unfortunate to proceed in SDLCwithout any uncertainties. So it is great if we identify and analyze the risks at early steps of SDLC.Requirement engineering is introductory phase of software development life cycle in which the basicrequirements are gathered from customer. If risks are ignored at requirement engineering phase then it willhave negative impacts on the projects ability to achieve performance and outcome goals. The main theme ofthis paper is to highlight the risk factors in the requirement engineering phase and fixing them byincorporating risk management approach. The conclusion of this paper explains the importance of executingthe risk management in requirement engineering process
The digital age has undoubtedly revolutionized the life and work of people. However, this sheen of digital technology remains challenged by the spate of cybercrimes that imperil the privacy and data of the end-users. The alarming rise in cybercrimes has become a major concern for cyber specialists. In this grim context, digital forensics has emerged as a boon for cyber specialists because it has proven to be an effective means for investigating cyber-attacks. This chapter reviews the existing tools and approaches in the field of digital forensics in cybersecurity. This chapter also discusses the current challenges and problems that are faced by a forensic investigator. In addition, it enlists the different categories of digital forensics. The study concludes by underlining the importance and the need for extensive research in digital forensic tools.
The last few decades have shown an incredible rise in the production of different types of software according to the user’s needs. Requirement Elicitation techniques for security requirements are one of the most crucial stage of software development life cycle. Based on the Analytical Network Process (ANP) process, this paper analyzes the weighting of elicitation techniques for security requirements in the production of software applications. In other words, the elicitation strategies of security requirements play an important role in the development of secure software. It also analyzes the relationship between security requirement elicitation techniques and their objectives through the use of ANP method and also demonstrates the application of fuzzy ANP method to achieve higher accuracy. When developing a secure software framework, the results provide a better platform. With these facts in mind, the proposed study will also clarify the priority weights of security requirement elicitation techniques that can be used to analyze trade-offs between competing software security requirement elicitation techniques and provide a new way for developers when constructing the secure software.
In the current scenario, the crime rate has tremendously increased with respect to the Automatic Teller Machine (ATM). During the last few years, criminals are becoming more sophisticated and paid more attention to ATMs. The majority of ATMs in India are working on a single authentication technique. The attacks, such as skimming, shimming, card cloning, card swapping, shoulder surfing, etc. works due to the use of minimal authentication in ATMs. So, the concern about the security of ATMs is reached to its peak level. Nowadays, banks have moved towards the two-tier authentication level. Recently in India, some banks have adopted the One Time Password (OTP) mechanism along with a UID number to perform the transaction in ATMs. In such a case, dependency on the cellular network for OTP is also a significant concern. To overcome these types of issues researcher proposed a two-tier authentication mechanism. The paper addresses the recent problems and their solution with the help of a two-way authentication method. To resolve the network issue, the researcher also proposed a novel technique, i.e., Security Question-based verification mechanism.