International Journal of Computer Network and Information Security (IJCNIS)

ISSN: 2074-9090 (Print)

ISSN: 2074-9104 (Online)

DOI: https://doi.org/10.5815/ijcnis

Website: https://www.mecs-press.org/ijcnis

Published By: MECS Press

Frequency: 6 issues per year

Number(s) Available: 145

(IJCNIS) in Google Scholar Citations / h5-index

IJCNIS is committed to bridge the theory and practice of computer network and information security. From innovative ideas to specific algorithms and full system implementations, IJCNIS publishes original, peer-reviewed, and high quality articles in the areas of computer network and information security. IJCNIS is well-indexed scholarly journal and is indispensable reading and references for people working at the cutting edge of computer network, information security, and their applications.

 

IJCNIS has been abstracted or indexed by several world class databases: Scopus, SCImago, Google Scholar, CrossRef, Baidu Wenku, IndexCopernicus, IET Inspec, EBSCO, VINITI, JournalSeek, ULRICH's Periodicals Directory, WorldCat, Academic Journals Database, Stanford University Libraries, Cornell University Library, UniSA Library, CNKI Scholar, ProQuest, J-Gate, ZDB, BASE, OhioLINK, iThenticate, Open Access Articles, Open Science Directory, National Science Library of Chinese Academy of Sciences, The HKU Scholars Hub, etc..

Latest Issue
Most Viewed
Most Downloaded

IJCNIS Vol. 18, No. 5, Oct. 2026

REGULAR PAPERS

Optimized Hybrid IDS Using HBA, LightGBM, and LSTM for DDoS Attack Detection

By Rudragouda G. Hiregoudar S. V. Saboji

DOI: https://doi.org/10.5815/ijcnis.2026.05.01, Pub. Date: 8 Oct. 2026

The rapid growth of digital networks has made online platforms more vulnerable to Distributed Denial of Service (DDoS) attacks. These attacks can cause serious service interruptions and performance degradation. Traditional Intrusion Detection Systems (IDSs) often struggle with poor detection accuracy, frequent false alerts, and delays in recognizing ongoing attacks. This study proposes an improved hybrid IDS that uses the Honey Badger Algorithm (HBA) to choose essential traffic features, Light Gradient Boosting Machine (LightGBM) for accurate and fast classification, and Long Short-Term Memory (LSTM) networks to analyze time-based traffic patterns. The system was tested with the CICDDoS2019 dataset using 10-fold cross-validation. To ensure generalization and robustness, the proposed IDS was further validated on the NSL-KDD dataset. Comparative analysis demonstrates superior detection accuracy, faster convergence, and reduced false positive rates compared to traditional and recent hybrid IDS models. The study emphasizes novelty, includes multiple dataset evaluations, and presents ablation testing to demonstrate reliability. Results show that the model achieves more than 98% detection accuracy with a low false positive rate and quick processing time. Hence the proposed IDS provides a scalable and real-time-capable framework for modern DDoS detection across diverse network environments.

[...] Read more.
Model for calculating the level of Cybersecurity of Critical Infrastructure Facilities

By Sergiy Gnatyuk Diana Yudina

DOI: https://doi.org/10.5815/ijcnis.2026.05.02, Pub. Date: 8 Oct. 2026

The article examines the problem of ensuring the cyber resilience of critical information infrastructure in the context of the global transformation of cyberattack methods and the growing role of foreign state actors in destabilizing critical systems. Given the unprecedented increase in the number of incidents and the emergence of new threat vectors associated with the use of artificial intelligence, traditional approaches to security assessment are becoming insufficient. This creates a critical need to develop tools for quantitatively calculating the level of critical information infrastructure cybersecurity in order to respond quickly to challenges and objectively predict risks. Based on a systematic analysis of international standards and frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework, the article justifies the need for a formalized mathematical apparatus for the transition from a qualitative description of security measures to their quantitative measurement. The authors propose a hierarchical Multi-Criteria Decision Making model for calculating an integral indicator of the level of cybersecurity. This model is based on a synthesis of the theoretical-multiple approach, the Analytic Hierarchy Process, and non-compensatory gating thresholds. The mathematical apparatus allows for the inequality of different groups of cybersecurity measures to be taken into account by applying a system of weighting coefficients calculated on the basis of expert assessments using the Saaty scale. The development process includes eight distinct stages, from determining criteria sets to integrating non-compensatory gating mechanisms to prevent technical deficiencies from being masked by administrative achievements. Experimental testing of the model was conducted using a representative critical infrastructure facility grounded in anonymized real-world audit data from the energy sector. The results confirmed the model's effectiveness, yielding an integral indicator of 0.56, while specifically identifying the detection domain as a vulnerable segment with a score of 0.36. This confirms the practical significance of the model for supporting management decisions on priority resource allocation.

[...] Read more.
Secure and Efficient Image Encryption Scheme Based on Compressive Sensing and AES

By Shimaa Sayed Mohamed Marwa M. A. Hadhoud Fatty M. Salem

DOI: https://doi.org/10.5815/ijcnis.2026.05.03, Pub. Date: 8 Oct. 2026

Secure and efficient transmission of medical images requires integrating compression, encryption, and substitution mechanisms to protect sensitive patient data. Compression reduces image size, improving transmission and storage while preserving diagnostic quality. Encryption ensures confidentiality and the Health Insurance Portability and Accountability Act (HIPAA) compliance, safeguarding patient information from unauthorized access. Nonlinear substitution using dynamic S-boxes increases confusion and strengthens resistance to cryptanalysis. This paper presents a hybrid medical image encryption scheme comprising three sequential stages for high security and computational efficiency. In preprocessing, images are resized, normalized, partitioned into uniform blocks, and compressed using compressive sensing based on partial discrete Fourier transform sampling. The encryption stage applies adaptive S-boxes with block interleaving, followed by the Advanced Encryption Standard in Galois/Counter Mode to provide integrity-preserving encryption. During decryption, the Fast Iterative Shrinkage-Threshold Algorithm reconstructs images accurately. Experimental results demonstrate that the scheme preserves image quality, achieves effective compression, and resists statistical and cryptographic attacks, making it suitable for secure medical image communication in resource-limited environments.

[...] Read more.
Anomaly Detection in Cloud API Access Patterns Using Temporal Convolutional Networks

By Narendra Kumar D. Lakshmi Padmaja M. Rajanidevi Dasaradha Ramayya Lanka A. Mahendar V. Gokula Krishnan

DOI: https://doi.org/10.5815/ijcnis.2026.05.04, Pub. Date: 8 Oct. 2026

Cloud platforms generate massive API access logs, where abnormal patterns may indicate security breaches, insider threats, or compromised credentials, demanding intelligent and automated anomaly detection mechanisms. Conventional approaches employ segmentation, statistical profiling, clustering, recurrent networks, and supervised classifiers to model sequential API behavior and distinguish normal activities from malicious deviations. These techniques generally achieve high detection accuracy and improved threat visibility, enhancing cybersecurity monitoring systems while reducing manual auditing efforts in large-scale distributed cloud environments. However, they struggle with evolving attack patterns, high false-positive rates, limited temporal dependency modelling, data imbalance, and poor generalization across heterogeneous cloud infrastructures. This study proposes a self-supervised Temporal Convolutional Network with adaptive anomaly scoring, achieving robust sequential modelling, reduced false alarms, and improved detection stability in cloud APIs. A self-supervised Temporal Convolutional Network models sequential API behavior using causal dilated convolutions and adaptive scoring, enabling accurate, scalable, and real-time cloud anomaly detection.

[...] Read more.
A Performance Optimized Privacy-Aware Edge Computing Architecture Using Selective Homomorphic Encryption and Adaptive Differential Privacy

By Apurva Khandekar Prathipati Ratna Kumar

DOI: https://doi.org/10.5815/ijcnis.2026.05.05, Pub. Date: 8 Oct. 2026

Edge computing has become a fundamental paradigm in real-time data processing of latency-sensitive applications like smart healthcare, Internet of Things (IoT), and financial systems. Nevertheless, current edge and cloud-based solutions do not provide a high level of privacy or have a high level of computational and communication overhead because of intensive cryptographic actions. In this paper, a lightweight privacy-conscious edge computing architecture is proposed and can be used to provide secure and low-latency computation on sensitive data based on a combination of feature-level selective lightweight homomorphic encryption, context-sensitive differential privacy, and fully edge-enforced privacy control. In contrast to traditional solutions, which use consistent encryption or fixed privacy controls, the proposed system only encrypts privacy-sensitive data characteristics and dynamically adjusts differential privacy noise depending on the actual system state. The design utilizes significantly fewer resources and offers superior scalability without compromising privacy guarantees. Extensive simulations in a realistic edge computing environment show that the proposed architecture can reduce the encryption overhead by up to 60 percent, reduce the communication latency to approximately 2 ms, and maintain an accuracy of over 98 percent under strict privacy requirements. The comparison of results indicates that the suggested framework is more efficient in computing, scalable, and compliant with regulations than cloud-based and current edge computing solutions. The suggested solution offers a realistic and scalable answer to real-time privacy-preserving edge analytics within resource-constrained environments.

[...] Read more.
Attention Guided Graph Neural Network and Bayesian Reasoning Framework for Cross-Zone Cyber-Physical Threat Intelligence and Context-Aware Predictive Smart Defense

By Macherla Malleswara Rao Pavan Kumar Tummala

DOI: https://doi.org/10.5815/ijcnis.2026.05.06, Pub. Date: 8 Oct. 2026

Context-sensitive smart defense represents a crucial element in protecting distributed cyber-physical systems against advanced and well-coordinated adversarial actions. The current defense architectures face serious issues, such as incompleteness of situational observability and a lack of cross-zone coordination during uncertainty conditions. In order to overcome these constraints, a context-aware smart defense system was proposed that integrates multi-source data and different learning approaches for Intrusion Detection System (IDS) and mitigation. The framework is a collection of data from a variety of sensors, surveillance cameras, radars, and threat databases scattered across numerous Defense Zones. During data transmission from multi-modality devices, there is a possibility of intrusion. For IDS, the network data is pre-processed using Deep Ladder Imputation Networks (DLIN) to fill in gaps and then dispersion-based normalization. Structured sensor and network data are used by the TabNet encoder, and cross-modal attention modules are used to preserve essential network features from different modalities. Graph Neural Networks are used to enable the spatial-temporal analysis to extract the contextual threat information. In the case of emerging or data-sparse zones, Auto Encoder-based Transfer-Learning (AE-TL) methods can be used to produce domain adaptation based on data-rich zones. When attacks are detected, a federated learning-based multi-agent reinforcement learning based on FedQMIX coordinates defense measures without violating data privacy. Bayesian threat inference is used to assess the possibility of future adversarial attacks in non-attack conditions. Empirical assessments indicate that the suggested transfer-learning approach achieves an accuracy of 98.50% and an F-beta of 97.85%. Federated learning combined with reinforcement learning attains an accuracy of 98.1% and 95.6% on attack data and generated data, respectively. Overall, the framework enhances threat detection and coordinated response capabilities, providing a solution to the protection of distributed cyber-physical infrastructures.

[...] Read more.
Efficient Hybrid Post-Quantum File Security Framework

By Moulay Ibrahim El-Khalil Ghembaza

DOI: https://doi.org/10.5815/ijcnis.2026.05.07, Pub. Date: 8 Oct. 2026

The shift towards a quantum-secured future has driven the demand for more practical ways of protecting files that can add post-quantum cryptographic components without creating a massive increase in computational or storage demands. This study proposes and tests a hybrid file-security approach combining a post-quantum key encapsulation mechanism and authenticated symmetric encryption for real-world file security. An experimental research design was followed with the use of a valid subset of GovDocs1 corpus as the evaluation sample, and the files were stratified based on the format, size and entropy characteristics. Three different architectures were designed, built and evaluated for design evolution from direct lattice-style architecture to standards-based hybrid architecture. Correctness, runtime, and ciphertext expansion were used to measure performance and compared to other files of various types and data characteristics. The results demonstrate the capability of the final framework to retain the exact reconstruction of the file and gain significantly in storage efficiency and execution time over previous model generations. A comparison of performance over different heterogeneous categories of files showed no significant difference, and overhead was seen to be a consistent decreasing function of file size. The results show that a hybrid design that can provide quantum resistant key protection and efficient authenticated encryption can be used to provide practical post-quantum-ready file security. The study offers an empirically supported framework for the security of files in a post-quantum era and offers a repeatable foundation for research into implementing it for deployment.

[...] Read more.
A Multi-Modal Deep Learning Framework for Robust Detection of Obfuscated API Calls in Malware Analysis

By Nayankumar M. Mali Narendrasinh C. Chauhan

DOI: https://doi.org/10.5815/ijcnis.2026.05.08, Pub. Date: 8 Oct. 2026

Malware developers employ advanced API obfuscation techniques, such as name randomization, dynamic resolution, call stack manipulation, parameter spoofing, and API chaining, to bypass detection. Existing unimodal analysis systems frequently fail to identify these threats due to their limited scope. To address this, we introduce a novel multi-modal deep learning framework that combines temporal, structural, and parametric analysis for malware detection. This multi‑modal method uses a temporal encoder with self‑attention to detect name obfuscation and API chaining, Graph attention networks analyze call graphs for call stack tampering and dynamic API resolution, while a contrastive learning module identifies anomalous parameter usage. A key novel approach is the dynamic fusion mechanism, which uses attention-based weighting to combine features, enhancing accuracy and interpretability. Additionally, adversarial training ensures robustness against evasion attempts, with theoretical guarantees on performance under variations. Evaluated on 29,505 real‑world malware samples, the proposed multi‑modal framework achieves a 94.2% F1‑score (an 18% improvement over unimodal baselines) and a 98.1% AUC‑ROC. The framework notably maintains 82% robustness against adversarial variations, significantly outperforming conventional LSTM‑based approaches (45%). Beyond detection, the proposed method provides explainable attention maps for forensic analysis and low latency (<1ms/sample), making it suitable for real-time security deployment. These results suggest that multi-modal fusion is critical for next-generation endpoint protection.

[...] Read more.
An Efficient Hash-Based Caching Mechanism to Minimize Computational Overhead in Hyperledger Fabric for Healthcare IoT

By B. J. Praveena N. Arivazhagan

DOI: https://doi.org/10.5815/ijcnis.2026.05.09, Pub. Date: 8 Oct. 2026

As the Internet of Things (IoT) health monitoring systems expand, measures must be taken to ensure the safe, real-time handling of data, particularly for highly infectious diseases which limit the ability for human interaction. Blockchain provides the necessary transparency and immutability so that patient families and hospitals can align on trust with health data. Hyperledger Fabric is the most commonly used solution for these scenarios, as it operates on X.509 certificates for the authentication of device identity. Yet, with the frequent transmission of the IoT sensors, the need for repeated certificate authentication causes considerable computational lags, which can hinder critical real-time assessments in the care continuum. We propose CAVIC (Certificate Authentication Verification Intelligent Cache), which is aimed at simplifying the verification and caching processes with the goal of diminishing the effects of redundant cryptographic activities. CAVIC tracks the high-traffic IoT devices in a network, including temperature, heart rate, and oxygen saturation sensors, and creates a secured cache for their authenticated certificates. Further processes from these devices are verified via instant cache lookups rather than comprehensive certificate re-evaluations, which drastically reduce verification overhead. In situations where a patient's condition can worsen to an extent requiring immediate action from a doctor, CAVIC guarantees that the system's time is dedicated to the analysis of patient data instead of the continual validation of trusted sensors. Incorporating CAVIC into a Hyperledger-based healthcare testbed, we show reduced latency, lower computational costs, and better responsiveness, all of which add to the safety and efficiency of managing patients remotely.

[...] Read more.
Implementation of Adaptive Sleep Modes for Enhancing Energy Efficiency of Ultra Dense Networks Using Traffic-Aware Grasshopper Optimization Algorithm

By Nilakshee Rajule Mithra Venkatesan Radhika Menon Anju Kulkarni

DOI: https://doi.org/10.5815/ijcnis.2026.05.10, Pub. Date: 8 Oct. 2026

Energy consumption has emerged as a critical concern in next-generation wireless communication networks due to the increasing demand for high data rates and seamless connectivity. Ultra-Dense Networks (UDNs) in fifth-generation (5G) systems have been identified as a promising solution to support this demand by deploying a large number of small cell base stations (SBSs) alongside macro base stations (MBSs). However, the dense deployment significantly increases overall power consumption, especially when SBSs remain active under low traffic conditions caused by user mobility.
To address this issue, this paper proposes a novel adaptive sleep mode optimization framework that integrates traffic prediction with the Grasshopper Optimization Algorithm (GOA). Specifically, historical traffic patterns are analyzed to predict future traffic loads at each base station, and these predicted loads are used as input to the GOA to optimally determine the operational mode (active, light sleep, deep sleep, or off) of SBSs under QoS and coverage constraints. This predictive optimization enables dynamic and energy-efficient network adaptation.
The proposed approach enhances the overall energy efficiency (EE) and spectral efficiency (SE) of a two-tier heterogeneous network. Simulation results demonstrate that the proposed method achieves up to 29% improvement in energy efficiency and 21% improvement in spectral efficiency compared to existing approaches.

[...] Read more.
Graph Neural Networks for Predictive Maintenance in IoT Sensor Systems Using Device Telemetry Data

By M. Poonguzhali R. Sujitha A. Mahendar Siva Reddy Sonti Malapati Naresh Anjali B. V.

DOI: https://doi.org/10.5815/ijcnis.2026.05.11, Pub. Date: 8 Oct. 2026

Industrial IoT systems generate massive telemetry streams, requiring intelligent predictive maintenance models to detect failures early, reduce downtime, and improve operational reliability and safety. Traditional approaches employ statistical analysis, sequence segmentation techniques, CNN-LSTM hybrids, and graph-based classification models to capture spatial-temporal dependencies and identify abnormal device behaviour patterns. These methods typically achieve high classification accuracy but often exhibit moderate RUL estimation performance, demonstrating strong fault detection capability across industrial, energy, and smart infrastructure applications. However, static graph structures, limited temporal attention, imbalanced fault distributions, and poor generalization under noisy conditions restrict robustness and real-world deployment scalability. This paper proposes a dynamic graph-based GAT-BiLSTM with cross-attention and gated fusion, achieving 99.50% accuracy and superior RUL prediction stability under noisy conditions. The framework incorporates adaptive adjacency learning and multi-task optimization to enhance predictive maintenance accuracy and robustness in IoT sensor networks.

[...] Read more.
Coherence of UI Component Interaction in Distributed Client Software Systems

By Kateryna Savenko

DOI: https://doi.org/10.5815/ijcnis.2026.05.12, Pub. Date: 8 Oct. 2026

The aim of the study is to quantitatively assess the execution time consistency of UI in distributed systems to identify invariant risk profiles and degradation mechanisms and justify consistency-first, event-aware orchestration . The methodology integrates baseline-profiling, latency-, offline-replay- and concurrency-induction with event-level  telemetry, replication and non-parametric inference. The purpose is causal isolation of the degradation mechanisms for execution time consistency of UI in distributed systems. It is empirically established that the execution time consistency of UI in distributed client systems is an infrastructure invariant that systematically degrades under perturbations. Median shifts of ≈+6%, +9% and +13% ΔSDR  were recorded, respectively, with large effect sizes (r≈0.57–1.00) for latency, offline→replay, and concurrency. A stable risk profile of UI components was identified. It was maintained in 65–85% of cases regardless of the type of failures and was explained by confirmation delays, merge conflicts, and causal/order violations. Statistical verification confirmed the significance of all effects (p<0.01 after Holm–Bonferroni) with non-overlapping 95% bootstrap CIs, which indicates generalized non-artifact degradation and justifies the necessity of event/state-aware orchestration. Further research prospects are the expansion of domains and multi-tenant architectures, the integration of causal tracing and idempotency auditing, and the combination of infrastructure and UX metrics to reduce ΔSDR ≥30% in distributed scenarios.

[...] Read more.
Machine Learning-based Intrusion Detection Technique for IoT: Simulation with Cooja

By Ali H. Farea Kerem Kucuk

DOI: https://doi.org/10.5815/ijcnis.2024.01.01, Pub. Date: 8 Feb. 2024

The Internet of Things (IoT) is one of the promising technologies of the future. It offers many attractive features that we depend on nowadays with less effort and faster in real-time. However, it is still vulnerable to various threats and attacks due to the obstacles of its heterogeneous ecosystem, adaptive protocols, and self-configurations. In this paper, three different 6LoWPAN attacks are implemented in the IoT via Contiki OS to generate the proposed dataset that reflects the 6LoWPAN features in IoT. For analyzed attacks, six scenarios have been implemented. Three of these are free of malicious nodes, and the others scenarios include malicious nodes. The typical scenarios are a benchmark for the malicious scenarios for comparison, extraction, and exploration of the features that are affected by attackers. These features are used as criteria input to train and test our proposed hybrid Intrusion Detection and Prevention System (IDPS) to detect and prevent 6LoWPAN attacks in the IoT ecosystem. The proposed hybrid IDPS has been trained and tested with improved accuracy on both KoU-6LoWPAN-IoT and Edge IIoT datasets. In the proposed hybrid IDPS for the detention phase, the Artificial Neural Network (ANN) classifier achieved the highest accuracy among the models in both the 2-class and N-class. Before the accuracy improved in our proposed dataset with the 4-class and 2-class mode, the ANN classifier achieved 95.65% and 99.95%, respectively, while after the accuracy optimization reached 99.84% and 99.97%, respectively. For the Edge IIoT dataset, before the accuracy improved with the 15-class and 2-class modes, the ANN classifier achieved 95.14% and 99.86%, respectively, while after the accuracy optimized up to 97.64% and 99.94%, respectively. Also, the decision tree-based models achieved lightweight models due to their lower computational complexity, so these have an appropriate edge computing deployment. Whereas other ML models reach heavyweight models and are required more computational complexity, these models have an appropriate deployment in cloud or fog computing in IoT networks.

[...] Read more.
Public vs Private vs Hybrid vs Community - Cloud Computing: A Critical Review

By Sumit Goyal

DOI: https://doi.org/10.5815/ijcnis.2014.03.03, Pub. Date: 8 Feb. 2014

These days cloud computing is booming like no other technology. Every organization whether it’s small, mid-sized or big, wants to adapt this cutting edge technology for its business. As cloud technology becomes immensely popular among these businesses, the question arises: Which cloud model to consider for your business? There are four types of cloud models available in the market: Public, Private, Hybrid and Community. This review paper answers the question, which model would be most beneficial for your business. All the four models are defined, discussed and compared with the benefits and pitfalls, thus giving you a clear idea, which model to adopt for your organization.

[...] Read more.
Ethical Network Surveillance using Packet Sniffing Tools: A Comparative Study

By Ibrahim Ali Ibrahim Diyeb Anwar Saif Nagi Ali Al-Shaibany

DOI: https://doi.org/10.5815/ijcnis.2018.07.02, Pub. Date: 8 Jul. 2018

Nowadays, with growing of computer's networks and Internet, the security of data, systems and applications is becoming a real challenge for network's developers and administrators. An intrusion detection system is the first and reliable technique in the network's security that is based gathering data from computer network. Further, the need for monitoring, auditing and analysis tools of data traffic is becoming an important factor to increase an overall system and network security by avoiding external attackers and monitoring abuse of the IT assets by employees in the workplace. The techniques that used for collecting and converting data to a readable format are called packet sniffing. Packet Sniffer is a tool that used to capture packets in binary format, converts that binary data into a readable data format and log of that captured data for analyzing and monitoring, displaying different used applications, clear-text user names, passwords, and other vulnerabilities. It is used by network administrator to keep the network is more secured, safe and to support better decision. There are many different sniffing tools for monitoring, analyzing, and reporting the network's traffic. In this paper we will compare between three different sniffing tools; TCPDump, Wireshark, and Colasoft according to various parameters such as their detection ability, filtering, availability, supported operating system, open source, GUI, their characteristics and features, qualitative and quantitative parameters. In addition, this paper may be considered as an insight for the new researchers to guide them to an overview, essentials, and understanding of the packet sniffing techniques and their working.

[...] Read more.
Password Security: An Analysis of Password Strengths and Vulnerabilities

By Katha Chanda

DOI: https://doi.org/10.5815/ijcnis.2016.07.04, Pub. Date: 8 Jul. 2016

Passwords can be used to gain access to specific data, an account, a computer system or a protected space. A single user may have multiple accounts that are protected by passwords. Research shows that users tend to keep same or similar passwords for different accounts with little differences. Once a single password becomes known, a number of accounts can be compromised. This paper deals with password security, a close look at what goes into making a password strong and the difficulty involved in breaking a password. The following sections discuss related work and prove graphically and mathematically the different aspects of password securities, overlooked vulnerabilities and the importance of passwords that are widely ignored. This work describes tests that were carried out to evaluate the resistance of passwords of varying strength against brute force attacks. It also discusses overlooked parameters such as entropy and how it ties in to password strength. This work also discusses the password composition enforcement of different popular websites and then presents a system designed to provide an adaptive and effective measure of password strength. This paper contributes toward minimizing the risk posed by those seeking to expose sensitive digital data. It provides solutions for making password breaking more difficult as well as convinces users to choose and set hard-to-break passwords.

[...] Read more.
A Critical appraisal on Password based Authentication

By Amanpreet A. Kaur Khurram K. Mustafa

DOI: https://doi.org/10.5815/ijcnis.2019.01.05, Pub. Date: 8 Jan. 2019

There is no doubt that, even after the development of many other authentication schemes, passwords remain one of the most popular means of authentication. A review in the field of password based authentication is addressed, by introducing and analyzing different schemes of authentication, respective advantages and disadvantages, and probable causes of the ‘very disconnect’ between user and password mechanisms. The evolution of passwords and how they have deep-rooted in our life is remarkable. This paper addresses the gap between the user and industry perspectives of password authentication, the state of art of password authentication and how the most investigated topic in password authentication changed over time. The author’s tries to distinguish password based authentication into two levels ‘User Centric Design Level’ and the ‘Machine Centric Protocol Level’ under one framework. The paper concludes with the special section covering the ways in which password based authentication system can be strengthened on the issues which are currently holding-in the password based authentication.

[...] Read more.
Forensics Image Acquisition Process of Digital Evidence

By Erhan Akbal Sengul Dogan

DOI: https://doi.org/10.5815/ijcnis.2018.05.01, Pub. Date: 8 May 2018

For solving the crimes committed on digital materials, they have to be copied. An evidence must be copied properly in valid methods that provide legal availability. Otherwise, the material cannot be used as an evidence. Image acquisition of the materials from the crime scene by using the proper hardware and software tools makes the obtained data legal evidence. Choosing the proper format and verification function when image acquisition affects the steps in the research process. For this purpose, investigators use hardware and software tools. Hardware tools assure the integrity and trueness of the image through write-protected method. As for software tools, they provide usage of certain write-protect hardware tools or acquisition of the disks that are directly linked to a computer. Image acquisition through write-protect hardware tools assures them the feature of forensic copy. Image acquisition only through software tools do not ensure the forensic copy feature. During the image acquisition process, different formats like E01, AFF, DD can be chosen. In order to provide the integrity and trueness of the copy, hash values have to be calculated using verification functions like SHA and MD series. In this study, image acquisition process through hardware-software are shown. Hardware acquisition of a 200 GB capacity hard disk is made through Tableau TD3 and CRU Ditto. The images of the same storage are taken through Tableau, CRU and RTX USB bridge and through FTK imager and Forensic Imager; then comparative performance assessment results are presented.

[...] Read more.
Classification of HHO-based Machine Learning Techniques for Clone Attack Detection in WSN

By Ramesh Vatambeti Vijay Kumar Damera Karthikeyan H. Manohar M. Sharon Roji Priya C. M. S. Mekala

DOI: https://doi.org/10.5815/ijcnis.2023.06.01, Pub. Date: 8 Dec. 2023

Thanks to recent technological advancements, low-cost sensors with dispensation and communication capabilities are now feasible. As an example, a Wireless Sensor Network (WSN) is a network in which the nodes are mobile computers that exchange data with one another over wireless connections rather than relying on a central server. These inexpensive sensor nodes are particularly vulnerable to a clone node or replication assault because of their limited processing power, memory, battery life, and absence of tamper-resistant hardware. Once an attacker compromises a sensor node, they can create many copies of it elsewhere in the network that share the same ID. This would give the attacker complete internal control of the network, allowing them to mimic the genuine nodes' behavior. This is why scientists are so intent on developing better clone assault detection procedures. This research proposes a machine learning based clone node detection (ML-CND) technique to identify clone nodes in wireless networks. The goal is to identify clones effectively enough to prevent cloning attacks from happening in the first place. Use a low-cost identity verification process to identify clones in specific locations as well as around the globe. Using the Optimized Extreme Learning Machine (OELM), with kernels of ELM ideally determined through the Horse Herd Metaheuristic Optimization Algorithm (HHO), this technique safeguards the network from node identity replicas. Using the node identity replicas, the most reliable transmission path may be selected. The procedure is meant to be used to retrieve data from a network node. The simulation result demonstrates the performance analysis of several factors, including sensitivity, specificity, recall, and detection.

[...] Read more.
Comparative Analysis of KNN Algorithm using Various Normalization Techniques

By Amit Pandey Achin Jain

DOI: https://doi.org/10.5815/ijcnis.2017.11.04, Pub. Date: 8 Nov. 2017

Classification is the technique of identifying and assigning individual quantities to a group or a set. In pattern recognition, K-Nearest Neighbors algorithm is a non-parametric method for classification and regression. The K-Nearest Neighbor (kNN) technique has been widely used in data mining and machine learning because it is simple yet very useful with distinguished performance. Classification is used to predict the labels of test data points after training sample data. Over the past few decades, researchers have proposed many classification methods, but still, KNN (K-Nearest Neighbor) is one of the most popular methods to classify the data set. The input consists of k closest examples in each space, the neighbors are picked up from a set of objects or objects having same properties or value, this can be considered as a training dataset. In this paper, we have used two normalization techniques to classify the IRIS Dataset and measure the accuracy of classification using Cross-Validation method using R-Programming. The two approaches considered in this paper are - Data with Z-Score Normalization and Data with Min-Max Normalization.

[...] Read more.
Social Engineering: I-E based Model of Human Weakness for Attack and Defense Investigations

By Wenjun Fan Kevin Lwakatare Rong Rong

DOI: https://doi.org/10.5815/ijcnis.2017.01.01, Pub. Date: 8 Jan. 2017

Social engineering is the attack aimed to manipulate dupe to divulge sensitive information or take actions to help the adversary bypass the secure perimeter in front of the information-related resources so that the attacking goals can be completed. Though there are a number of security tools, such as firewalls and intrusion detection systems which are used to protect machines from being attacked, widely accepted mechanism to prevent dupe from fraud is lacking. However, the human element is often the weakest link of an information security chain, especially, in a human-centered environment. In this paper, we reveal that the human psychological weaknesses result in the main vulnerabilities that can be exploited by social engineering attacks. Also, we capture two essential levels, internal characteristics of human nature and external circumstance influences, to explore the root cause of the human weaknesses. We unveil that the internal characteristics of human nature can be converted into weaknesses by external circumstance influences. So, we propose the I-E based model of human weakness for social engineering investigation. Based on this model, we analyzed the vulnerabilities exploited by different techniques of social engineering, and also, we conclude several defense approaches to fix the human weaknesses. This work can help the security researchers to gain insights into social engineering from a different perspective, and in particular, enhance the current and future research on social engineering defense mechanisms.

[...] Read more.
D2D Communication Using Distributive Deep Learning with Coot Bird Optimization Algorithm

By Nethravathi H. M. Akhila S. Vinayakumar Ravi

DOI: https://doi.org/10.5815/ijcnis.2023.05.01, Pub. Date: 8 Oct. 2023

D2D (Device-to-device) communication has a major role in communication technology with resource and power allocation being a major attribute of the network. The existing method for D2D communication has several problems like slow convergence, low accuracy, etc. To overcome these, a D2D communication using distributed deep learning with a coot bird optimization algorithm has been proposed. In this work, D2D communication is combined with the Coot Bird Optimization algorithm to enhance the performance of distributed deep learning. Reducing the interference of eNB with the use of deep learning can achieve near-optimal throughput. Distributed deep learning trains the devices as a group and it works independently to reduce the training time of the devices. This model confirms the independent resource allocation with optimized power value and the least Bit Error Rate for D2D communication while sustaining the quality of services. The model is finally trained and tested successfully and is found to work for power allocation with an accuracy of 99.34%, giving the best fitness of 80%, the worst fitness value of 46%, mean value of 6.76 and 0.55 STD value showing better performance compared to the existing works.

[...] Read more.
Machine Learning-based Intrusion Detection Technique for IoT: Simulation with Cooja

By Ali H. Farea Kerem Kucuk

DOI: https://doi.org/10.5815/ijcnis.2024.01.01, Pub. Date: 8 Feb. 2024

The Internet of Things (IoT) is one of the promising technologies of the future. It offers many attractive features that we depend on nowadays with less effort and faster in real-time. However, it is still vulnerable to various threats and attacks due to the obstacles of its heterogeneous ecosystem, adaptive protocols, and self-configurations. In this paper, three different 6LoWPAN attacks are implemented in the IoT via Contiki OS to generate the proposed dataset that reflects the 6LoWPAN features in IoT. For analyzed attacks, six scenarios have been implemented. Three of these are free of malicious nodes, and the others scenarios include malicious nodes. The typical scenarios are a benchmark for the malicious scenarios for comparison, extraction, and exploration of the features that are affected by attackers. These features are used as criteria input to train and test our proposed hybrid Intrusion Detection and Prevention System (IDPS) to detect and prevent 6LoWPAN attacks in the IoT ecosystem. The proposed hybrid IDPS has been trained and tested with improved accuracy on both KoU-6LoWPAN-IoT and Edge IIoT datasets. In the proposed hybrid IDPS for the detention phase, the Artificial Neural Network (ANN) classifier achieved the highest accuracy among the models in both the 2-class and N-class. Before the accuracy improved in our proposed dataset with the 4-class and 2-class mode, the ANN classifier achieved 95.65% and 99.95%, respectively, while after the accuracy optimization reached 99.84% and 99.97%, respectively. For the Edge IIoT dataset, before the accuracy improved with the 15-class and 2-class modes, the ANN classifier achieved 95.14% and 99.86%, respectively, while after the accuracy optimized up to 97.64% and 99.94%, respectively. Also, the decision tree-based models achieved lightweight models due to their lower computational complexity, so these have an appropriate edge computing deployment. Whereas other ML models reach heavyweight models and are required more computational complexity, these models have an appropriate deployment in cloud or fog computing in IoT networks.

[...] Read more.
Optimal Route Based Advanced Algorithm using Hot Link Split Multi-Path Routing Algorithm

By Akhilesh A. Waoo Sanjay Sharma Manjhari Jain

DOI: https://doi.org/10.5815/ijcnis.2014.08.07, Pub. Date: 8 Jul. 2014

Present research work describes advancement in standard routing protocol AODV for mobile ad-hoc networks. Our mechanism sets up multiple optimal paths with the criteria of bandwidth and delay to store multiple optimal paths in the network. At time of link failure, it will switch to next available path. We have used the information that we get in the RREQ packet and also send RREP packet to more than one path, to set up multiple paths, It reduces overhead of local route discovery at the time of link failure and because of this End to End Delay and Drop Ratio decreases. The main feature of our mechanism is its simplicity and improved efficiency. This evaluates through simulations the performance of the AODV routing protocol including our scheme and we compare it with HLSMPRA (Hot Link Split Multi-Path Routing Algorithm) Algorithm. Indeed, our scheme reduces routing load of network, end to end delay, packet drop ratio, and route error sent. The simulations have been performed using network simulator OPNET. The network simulator OPNET is discrete event simulation software for network simulations which means it simulates events not only sending and receiving packets but also forwarding and dropping packets. This modified algorithm has improved efficiency, with more reliability than Previous Algorithm.

[...] Read more.
Classification of HHO-based Machine Learning Techniques for Clone Attack Detection in WSN

By Ramesh Vatambeti Vijay Kumar Damera Karthikeyan H. Manohar M. Sharon Roji Priya C. M. S. Mekala

DOI: https://doi.org/10.5815/ijcnis.2023.06.01, Pub. Date: 8 Dec. 2023

Thanks to recent technological advancements, low-cost sensors with dispensation and communication capabilities are now feasible. As an example, a Wireless Sensor Network (WSN) is a network in which the nodes are mobile computers that exchange data with one another over wireless connections rather than relying on a central server. These inexpensive sensor nodes are particularly vulnerable to a clone node or replication assault because of their limited processing power, memory, battery life, and absence of tamper-resistant hardware. Once an attacker compromises a sensor node, they can create many copies of it elsewhere in the network that share the same ID. This would give the attacker complete internal control of the network, allowing them to mimic the genuine nodes' behavior. This is why scientists are so intent on developing better clone assault detection procedures. This research proposes a machine learning based clone node detection (ML-CND) technique to identify clone nodes in wireless networks. The goal is to identify clones effectively enough to prevent cloning attacks from happening in the first place. Use a low-cost identity verification process to identify clones in specific locations as well as around the globe. Using the Optimized Extreme Learning Machine (OELM), with kernels of ELM ideally determined through the Horse Herd Metaheuristic Optimization Algorithm (HHO), this technique safeguards the network from node identity replicas. Using the node identity replicas, the most reliable transmission path may be selected. The procedure is meant to be used to retrieve data from a network node. The simulation result demonstrates the performance analysis of several factors, including sensitivity, specificity, recall, and detection.

[...] Read more.
A Critical appraisal on Password based Authentication

By Amanpreet A. Kaur Khurram K. Mustafa

DOI: https://doi.org/10.5815/ijcnis.2019.01.05, Pub. Date: 8 Jan. 2019

There is no doubt that, even after the development of many other authentication schemes, passwords remain one of the most popular means of authentication. A review in the field of password based authentication is addressed, by introducing and analyzing different schemes of authentication, respective advantages and disadvantages, and probable causes of the ‘very disconnect’ between user and password mechanisms. The evolution of passwords and how they have deep-rooted in our life is remarkable. This paper addresses the gap between the user and industry perspectives of password authentication, the state of art of password authentication and how the most investigated topic in password authentication changed over time. The author’s tries to distinguish password based authentication into two levels ‘User Centric Design Level’ and the ‘Machine Centric Protocol Level’ under one framework. The paper concludes with the special section covering the ways in which password based authentication system can be strengthened on the issues which are currently holding-in the password based authentication.

[...] Read more.
Ethical Network Surveillance using Packet Sniffing Tools: A Comparative Study

By Ibrahim Ali Ibrahim Diyeb Anwar Saif Nagi Ali Al-Shaibany

DOI: https://doi.org/10.5815/ijcnis.2018.07.02, Pub. Date: 8 Jul. 2018

Nowadays, with growing of computer's networks and Internet, the security of data, systems and applications is becoming a real challenge for network's developers and administrators. An intrusion detection system is the first and reliable technique in the network's security that is based gathering data from computer network. Further, the need for monitoring, auditing and analysis tools of data traffic is becoming an important factor to increase an overall system and network security by avoiding external attackers and monitoring abuse of the IT assets by employees in the workplace. The techniques that used for collecting and converting data to a readable format are called packet sniffing. Packet Sniffer is a tool that used to capture packets in binary format, converts that binary data into a readable data format and log of that captured data for analyzing and monitoring, displaying different used applications, clear-text user names, passwords, and other vulnerabilities. It is used by network administrator to keep the network is more secured, safe and to support better decision. There are many different sniffing tools for monitoring, analyzing, and reporting the network's traffic. In this paper we will compare between three different sniffing tools; TCPDump, Wireshark, and Colasoft according to various parameters such as their detection ability, filtering, availability, supported operating system, open source, GUI, their characteristics and features, qualitative and quantitative parameters. In addition, this paper may be considered as an insight for the new researchers to guide them to an overview, essentials, and understanding of the packet sniffing techniques and their working.

[...] Read more.
Public vs Private vs Hybrid vs Community - Cloud Computing: A Critical Review

By Sumit Goyal

DOI: https://doi.org/10.5815/ijcnis.2014.03.03, Pub. Date: 8 Feb. 2014

These days cloud computing is booming like no other technology. Every organization whether it’s small, mid-sized or big, wants to adapt this cutting edge technology for its business. As cloud technology becomes immensely popular among these businesses, the question arises: Which cloud model to consider for your business? There are four types of cloud models available in the market: Public, Private, Hybrid and Community. This review paper answers the question, which model would be most beneficial for your business. All the four models are defined, discussed and compared with the benefits and pitfalls, thus giving you a clear idea, which model to adopt for your organization.

[...] Read more.
D2D Communication Using Distributive Deep Learning with Coot Bird Optimization Algorithm

By Nethravathi H. M. Akhila S. Vinayakumar Ravi

DOI: https://doi.org/10.5815/ijcnis.2023.05.01, Pub. Date: 8 Oct. 2023

D2D (Device-to-device) communication has a major role in communication technology with resource and power allocation being a major attribute of the network. The existing method for D2D communication has several problems like slow convergence, low accuracy, etc. To overcome these, a D2D communication using distributed deep learning with a coot bird optimization algorithm has been proposed. In this work, D2D communication is combined with the Coot Bird Optimization algorithm to enhance the performance of distributed deep learning. Reducing the interference of eNB with the use of deep learning can achieve near-optimal throughput. Distributed deep learning trains the devices as a group and it works independently to reduce the training time of the devices. This model confirms the independent resource allocation with optimized power value and the least Bit Error Rate for D2D communication while sustaining the quality of services. The model is finally trained and tested successfully and is found to work for power allocation with an accuracy of 99.34%, giving the best fitness of 80%, the worst fitness value of 46%, mean value of 6.76 and 0.55 STD value showing better performance compared to the existing works.

[...] Read more.
Password Security: An Analysis of Password Strengths and Vulnerabilities

By Katha Chanda

DOI: https://doi.org/10.5815/ijcnis.2016.07.04, Pub. Date: 8 Jul. 2016

Passwords can be used to gain access to specific data, an account, a computer system or a protected space. A single user may have multiple accounts that are protected by passwords. Research shows that users tend to keep same or similar passwords for different accounts with little differences. Once a single password becomes known, a number of accounts can be compromised. This paper deals with password security, a close look at what goes into making a password strong and the difficulty involved in breaking a password. The following sections discuss related work and prove graphically and mathematically the different aspects of password securities, overlooked vulnerabilities and the importance of passwords that are widely ignored. This work describes tests that were carried out to evaluate the resistance of passwords of varying strength against brute force attacks. It also discusses overlooked parameters such as entropy and how it ties in to password strength. This work also discusses the password composition enforcement of different popular websites and then presents a system designed to provide an adaptive and effective measure of password strength. This paper contributes toward minimizing the risk posed by those seeking to expose sensitive digital data. It provides solutions for making password breaking more difficult as well as convinces users to choose and set hard-to-break passwords.

[...] Read more.
Enhancing Adversarial Examples for Evading Malware Detection Systems: A Memetic Algorithm Approach

By Khadoudja Ghanem Ziad Kherbache Omar Ourdighi

DOI: https://doi.org/10.5815/ijcnis.2025.01.01, Pub. Date: 8 Feb. 2025

Malware detection using Machine Learning techniques has gained popularity due to their high accuracy. However, ML models are susceptible to Adversarial Examples, specifically crafted samples intended to deceive the detectors. This paper presents a novel method for generating evasive AEs by augmenting existing malware with a new section at the end of the PE file, populated with binary data using memetic algorithms. Our method hybridizes global search and local search techniques to achieve optimized results. The Malconv Model, a well-known state-of-the-art deep learning model designed explicitly for detecting malicious PE files, was used to assess the evasion rates. Out of 100 tested samples, 98 successfully evaded the MalConv model. Additionally, we investigated the simultaneous evasion of multiple detectors, observing evasion rates of 35% and 44% against KNN and Decision Tree machine learning detectors, respectively. Furthermore, evasion rates of 26% and 10% were achieved against Kaspersky and ESET commercial detectors. In order to prove the efficiency of our memetic algorithm in generating evasive adversarial examples, we compared it to the most used evolutionary-based attack: the genetic algorithm. Our method demonstrated significantly superior performance while utilizing fewer generations and a smaller population size.

[...] Read more.
Detecting Remote Access Network Attacks Using Supervised Machine Learning Methods

By Samuel Ndichu Sylvester McOyowo Henry Okoyo Cyrus Wekesa

DOI: https://doi.org/10.5815/ijcnis.2023.02.04, Pub. Date: 8 Apr. 2023

Remote access technologies encrypt data to enforce policies and ensure protection. Attackers leverage such techniques to launch carefully crafted evasion attacks introducing malware and other unwanted traffic to the internal network. Traditional security controls such as anti-virus software, firewall, and intrusion detection systems (IDS) decrypt network traffic and employ signature and heuristic-based approaches for malware inspection. In the past, machine learning (ML) approaches have been proposed for specific malware detection and traffic type characterization. However, decryption introduces computational overheads and dilutes the privacy goal of encryption. The ML approaches employ limited features and are not objectively developed for remote access security. This paper presents a novel ML-based approach to encrypted remote access attack detection using a weighted random forest (W-RF) algorithm. Key features are determined using feature importance scores. Class weighing is used to address the imbalanced data distribution problem common in remote access network traffic where attacks comprise only a small proportion of network traffic. Results obtained during the evaluation of the approach on benign virtual private network (VPN) and attack network traffic datasets that comprise verified normal hosts and common attacks in real-world network traffic are presented. With recall and precision of 100%, the approach demonstrates effective performance. The results for k-fold cross-validation and receiver operating characteristic (ROC) mean area under the curve (AUC) demonstrate that the approach effectively detects attacks in encrypted remote access network traffic, successfully averting attackers and network intrusions.

[...] Read more.