SearcharxivSearch

arXiv subjects

Iftekhar Salam

Publications and source records attributed to Iftekhar Salam.

4 recordsLinked to original sources

Deep Learning-Assisted Improved Differential Fault Attacks on Lightweight Stream Ciphers

Lightweight cryptographic primitives are widely deployed in resource-constrained environments, particularly in Internet of Things (IoT) devices. Due to their public accessibility, these devices are vulnerable to physical attacks, especially fault attacks. Recently, deep learning-based cryptanalytic techniques have demonstrated promising results; however, their application to fault attacks remains limited, particularly for stream ciphers. In this work, we investigate the feasibility of deep learning assisted differential fault attacks on three lightweight stream ciphers, namely ACORNv3, MORUSv2, and ATOM, under a relaxed fault model in which a single-bit bit-flipping fault is injected at an unknown location. We develop and train multilayer perceptron (MLP) models to identify the fault locations. Experimental results show that the trained models achieve high identification accuracies of 0.999880, 0.999231, and 0.823568 for ACORNv3, MORUSv2 and ATOM, respectively, and outperform traditional signature-based methods. For the secret recovery process, we introduce a threshold-based method to optimize the number of fault injections required to recover the secret information. The results show that the initial state of ACORN can be recovered with 21 to 34 faults, while MORUS requires 213 to 248 faults, with at most 6 bits of guessing. Both attacks reduce the attack complexity compared to existing works. For ATOM, the results show that it possesses a higher security margin, as the majority of state bits in the Nonlinear Feedback Shift Register (NFSR) can only be recovered under a precise control model. To the best of our knowledge, this work provides the first experimental results of differential fault attacks on ATOM.

cs.CR

Optimising Blockchain Scalability for Real-Time IoT Applications

The convergence of blockchain and the Internet of Things (IoT) enables secure, decentralised, and verifiable data exchange across distributed smart environments. However, traditional blockchain frameworks suffer from inherent scalability constraints, limited throughput, and high latency, which conflict with the stringent real-time requirements of IoT applications such as industrial automation, intelligent healthcare, and smart transportation. These systems demand ultra-low latency, high transaction throughput, lightweight computation, and efficient resource utilisation. This review provides a comprehensive, structured analysis of state-of-the-art scalability solutions specifically adapted to blockchain-enabled IoT. The discussion encompasses Layer 1 enhancements, Layer 2 off-chain processing, sharding-based parallelisation, integration of edge and fog computing, and hybrid consensus mechanisms. For each approach, the review highlights operational principles, performance benefits, trade-offs in decentralisation and security, and suitability for latency-sensitive deployments. Furthermore, real-time quality-of-service considerations are examined to understand how scalability strategies impact system responsiveness, energy efficiency, and data integrity. Key open challenges, including the scalability-security trade-off, privacy preservation, interoperability, and sustainable resource management, have been identified as persistent barriers to large-scale adoption. Finally, the review outlines future research directions, emphasising adaptive and AI-driven consensus algorithms, quantum-safe cryptographic models, the convergence of blockchain with 5G/6G networks, and edge intelligence. By consolidating diverse technical insights and emerging trends, this work serves as a timely reference for developing scalable, secure, and sustainable blockchain architectures for real-time IoT applications.

cs.DC

The Evolution of Zero Trust Architecture (ZTA) from Concept to Implementation

Zero Trust Architecture (ZTA) is one of the paradigm changes in cybersecurity, from the traditional perimeter-based model to perimeterless. This article studies the core concepts of ZTA, its beginning, a few use cases and future trends. Emphasising the always verify and least privilege access, some key tenets of ZTA have grown to be integration technologies like Identity Management, Multi-Factor Authentication (MFA) and real-time analytics. ZTA is expected to strengthen cloud environments, education, work environments (including from home) while controlling other risks like lateral movement and insider threats. Despite ZTA's benefits, it comes with challenges in the form of complexity, performance overhead and vulnerabilities in the control plane. These require phased implementation and continuous refinement to keep up with evolving organisational needs and threat landscapes. Emerging technologies, such as Artificial Intelligence (AI) and Machine Learning (ML) will further automate policy enforcement and threat detection in keeping up with dynamic cyber threats.

cs.CR

Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection System

Cybersecurity has become one of the focuses of organisations. The number of cyberattacks keeps increasing as Internet usage continues to grow. An intrusion detection system (IDS) is an alarm system that helps to detect cyberattacks. As new types of cyberattacks continue to emerge, researchers focus on developing machine learning (ML) based IDS to detect zero-day attacks. Researchers usually remove some or all attack samples from the training dataset and only include them in the testing dataset when evaluating the performance of an IDS on detecting zero-day attacks. Although this method may show the ability of an IDs to detect unknown attacks; however, it does not reflect the long-term performance of the IDS as it only shows the changes in the type of attacks. In this paper, we focus on evaluating the long-term performance of ML based IDS. To achieve this goal, we propose evaluating the ML-based IDS using a dataset that is created later than the training dataset. The proposed method can better assess the long-term performance of an ML-based IDS, as the testing dataset reflects the changes in the type of attack and the changes in network infrastructure over time. We have implemented six of the most popular ML models that are used for IDS, including decision tree (DT), random forest (RF), support vector machine (SVM), naïve Bayes (NB), artificial neural network (ANN) and deep neural network (DNN). Our experiments using the CIC-IDS2017 and the CSE-CIC-IDS2018 datasets show that SVM and ANN are most resistant to overfitting. Besides that, our experiment results also show that DT and RF suffer the most from overfitting, although they perform well on the training dataset. On the other hand, our experiments using the LUFlow dataset have shown that all models can perform well when the difference between the training and testing datasets is small.

cs.CR