Norziana Jamil

dblp:22/10851 · DBLP profile ↗
← Back
14ranked-venue papers
1as first author
12since 2021 · last 2026
0000-0002-7363-1466ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 6 since 2021Security and privacy · 5 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Novel Stateful Authentication Framework Approach With LLM-Based IDS for MQTT Security
abstract
Message Queue Telemetry Transport (MQTT), a widely used messaging protocol in IoT applications, faces significant security challenges, particularly with denial-of-service attacks and ensuring continuous, secure communication. Traditional security measures, like TLS/SSL, often introduce CPU overhead, bandwidth issues, and require complex certificate management. This paper has two main objectives: first, to provide a comprehensive review of MQTT security, detailing how MQTT operates, the associated security vulnerabilities, and existing solutions; and second, to propose a framework called the Stateful Authentication Framework (SAF). SAF enhances MQTT security through two key components: the SAF authentication protocol and a Large Language Model (LLM)-based Intrusion Detection System (IDS). The SAF protocol uses client-state information to establish secure, stateful interactions between clients and brokers, and incorporates a multi-factor authentication mechanism to prevent replay attacks and unauthorized access. Our evaluation of SAF shows that it significantly improves MQTT security, with Scyther simulations confirming the robustness of the protocol against known generic attacks. Additionally, the LLM-based IDS that integrates SAF’s security policies provides an advanced approach for detecting intrusions. To our knowledge, this is the first integrated approach combining a state-based authentication protocol and LLM-based IDS to tackle MQTT security challenges.
Norziana Jamil, Mohd Shariq, Syed Shakir Hameed Shah, Hala Shaker Mehdy, Zaid Abdi Alkareem Alyasseri, Eghbal Hosseini, Aymen Dia Eddine Berini, Zuhaira Muhammad Zain
IEEE Internet Things J.1
2026 RanVisStat: a statistical feature engineering approach for ransomware binary and multiclass classification using machine learning
Syed Shakir Hameed Shah, Norziana Jamil, Lariyah Mohd Sidek, Atta ur Rehman Khan, Ezedin Baraka
Neural Comput. Appl.2
2026 A Secure and Reliable Privacy-Preserving Authentication Protocol for UAV-UAV Communications in IoT Systems
abstract
The technology of Autonomous Vehicles (AVs) and Unmanned Aerial Vehicles (UAVs) has evolved and contributed to improving road safety and traffic efficiency in Intelligent Transportation Systems (ITS). ITS applications are dependent on a communication network formed between AVs and UAVs suffer from security and privacy issues owing to vulnerable wireless communication channels. Considering these issues, SP2AP, a Physically Unclonable Function (PUF) and Elliptic Curve Cryptography (ECC)-based efficient and reliable privacy-preserving authentication protocol for secure UAV-UAV communications in IoT systems is presented in this paper. The proposed protocol not only offers anonymity and untraceability features but also mitigates UAV capture attacks. A robust informal security analysis confirms that the SP2AP protocol safeguards against various known security attacks, such as masquerade, Man-In- The-Middle (MITM), Ephemeral Secret Leakage (ESL), replay, node tampering, cloning, etc. The proposed protocol offers other security features, including mutual authentication, secure key agreement, no clock synchronization, user anonymity, untraceability, (for/back)ward secrecy, property, and drone-to-drone direct authentication. The formal security proof is performed using the Real-OR-Random (ROR) model, and the Scyther tool also demonstrates that the SP2AP protocol is more robust in terms of security and privacy. Performance analysis evaluates computation and communication costs, which show better superiority compared to similar existing protocols.
Mohd Tajammul, Mohd Shariq, Gopal Singh Rawat, Sanjeev Kumar Dwivedi, Mehedi Masud, Norziana Jamil
IEEE Trans. Dependable Secur. Comput.6
2026 Provably Secure and Reliable Privacy-Preserving Authentication Scheme for Drone-to-Drone Communications in Internet of Autonomous Things
abstract
With the rapid advancements in wireless communication technologies, Unmanned Aerial Vehicles (UAVs), also known as Small Unmanned Aerial Vehicles (SUAVs) or drones, have been increasingly used in various applications, including the civilian sector. As a result, the security of SUAVs has garnered significant attention from the research community. Furthermore, drones are resource-constrained in nature and can be vulnerable to various known cybersecurity attacks over wireless communication. In light of these considerations, we propose aProvablySecure andReliable Privacy-Preserving AuthenticationScheme forDrone-to-Drone Communications in Internet of Autonomous Things (PSRS-D2D). The proposed scheme employs a secure one-way cryptographic hash and Elliptic Curve Cryptography (ECC) to accomplish a certain level of security. We provide security and privacy analysis, comparing it with competing UAV authentication schemes. This ensures that the PSRS-D2D scheme can withstand various prominent security properties, including mutual authentication and strong anonymity, and is secure against several attacks, such as replay, impersonation, and Man-In-The-Middle (MITM) attacks. We evaluated the performance of the proposed scheme in terms of computational and communicational costs. Furthermore, we conducted a formal security analysis using the Real-Or-Random (ROR) model and the Scyther simulation tools, which demonstrate that our scheme offers significant advantages in terms of security and performance.
Mohd Shariq, Norziana Jamil, Gopal Singh Rawat, Shehzad Ashraf Chaudhry, Mehedi Masud, Ashok Kumar Das
IEEE Trans. Mob. Comput.2
2025 Design of a provable secure lightweight privacy-preserving authentication protocol for autonomous vehicles in IoT systems
abstract
The rapid advancement of the Internet of Things (IoT) has enabled the adoption of autonomous vehicles (AVs) and drones in intelligent transportation systems (ITS), improving traffic efficiency and safety. However, security and privacy in interconnected ITS environments is a major concern. It is imperative to safeguard sensitive information from various known attacks while enabling secure communication. Keeping in view the security and privacy of autonomous vehicles in IoT systems, this paper puts forward Provable Secure Lightweight Privacy-Preserving Authentication Protocol (PSLAP). The proposed PSLAP protocol achieves high-level security by utilizing cryptographic primitives such as exclusive-OR, secure one-way hash, elliptic curve cryptography (ECC), and concatenation operators . The proposed PSLAP protocol is demonstrated to be resistant to numerous known security assaults through an informal security and privacy assessment. This study presents a formal security analysis using a widely accepted real-or-random (ROR) model which demonstrates the security hardness of the proposed scheme. Additionally, the performance analysis shows that the proposed protocol has minimal computation and communication costs compared to other existing protocols.
Mohd Shariq, Ismail Taha Ahmed, Mehedi Masud, Aymen Dia Eddine Berini, Norziana Jamil
Comput. Networks5
2025 An anonymous and privacy-preserving lightweight authentication protocol for secure communication in UAV-assisted IoAV networks
abstract
With the rapid proliferation of the Internet of Things (IoT), autonomous vehicles (AVs), or self-driving cars, rely heavily on real-time data sharing and message exchanges over wireless networks. AVs use sensors, artificial intelligence, machine learning, and advanced algorithms to perform various functions, enabling users to operate without human intervention. Owing to the flexibility and high mobility of drones, they could aid in the operations of AVs. However, the security and privacy are the main concerns; specifically, the threat of physical capture and violation of anonymity are the main hurdles for realization of secure communication among the AVs and drones. To address these challenges, we propose an anonymous and provably secure lightweight authentication protocol for unmanned-aerial-vehicle-assisted Internet of Autonomous Vehicles (SLAP-IoAV). The proposed protocol uses cryptographic primitives such as exclusive-OR operations, elliptic-curve cryptography, collision-resistant one-way hashing, and concatenation to ensure robust security. An informal security analysis found that SLAP-IoAV is secure against several known attacks, and a performance analysis established that the protocol has less computational and communication overhead than existing competitive protocols. Additionally, Scyther simulation results confirm that no security vulnerabilities are present. Overall, our protocol delivers superior security and performance, making it well-suited to real-world applications in the AV industry.
Mohd Shariq, Norziana Jamil, Gopal Singh Rawat, Shehzad Ashraf Chaudhry, Mehedi Masud, Angelo Cangelosi
Comput. Commun.2
2025 Design of a Provable Secure ECC and HMAC-Based Robust and Efficient Authentication Scheme for Maritime Transportation System
abstract
With the rapid development of the Internet of Things (IoT), modern Maritime Transportation Systems (MTS) have played a crucial role in the transport industry. The various potential privacy and security concerns (such as vessels’ location tracking, message tampering, unauthorized access to data, etc.) have increased substantially in IoT-enabled MTS. Considering the above issues, we propose a secure, robust, and efficient authentication scheme for MTS based on Elliptic-Curve Cryptography (ECC) and Hash-based Message Authentication Code (HMAC) called PSAS-MTS. The proposed PSAS-MTS scheme not only monitors the vessel’s condition but also ensures protection against collisions in route management and provides safety to the vessel’s passengers. The scheme uses simple XOR, a cryptographic one-way hash, an ECC cryptosystem, and HMAC to achieve a high level of security in MTS. The formal security analysis is carried out using a well-known Real-Or-Random (ROR) model, which ensures the security harness features. A rigorous informal security analysis is also done, which ensures various privacy and security features such as mutual authentication, anonymity, forward and backward secrecy, etc. The proposed PSAS-MTS scheme resists various possible well-known active and passive security attacks. The performance analysis shows that the proposed PSAS-MTS scheme is more efficient in terms of computation and communication overheads when compared to other competitive schemes.
Sanjeev Kumar Dwivedi, Mohammad Abdussami, Mohd Shariq, Ruhul Amin 0001, Shehzad Ashraf Chaudhry, Ashok Kumar Das, Norziana Jamil
IEEE Trans. Intell. Transp. Syst.7
2025 Transfer learning with dual-stage discrete wavelet transform for enhanced visual malware image compression and classification
Syed Shakir Hameed Shah, Norziana Jamil, Atta ur Rehman Khan
J. Supercomput.2
2023 SIM-P - A Simplified Consensus Protocol Simulator: Applications to Proof of Reputation-X and Proof of Contribution
abstract
Blockchain is a distributed ledger in which participating users with varying levels of trust agree on the ledger’s content using a consensus mechanism called consensus protocols. There has been a rising interest in the design of consensus protocols since they play a central role in blockchain architecture. However, many recently proposed consensus protocols lack experimental verification which hampers the possible deployment of these protocols in real-world blockchain networks. In this article, we propose a simple tool called simplified consensus protocol simulator (SIM-P) that can accurately simulate the behavior of these consensus protocols with ease. It is an agent-based stochastic simulator that relies on the sequential Monte Carlo method to model how block publishers are selected. The likelihood of each node (represented as agents) being selected as a block publisher is represented by independent trials in a binomial experiment. We provide a base SIM-P model that simulates Proof of Work (PoW) for benchmarking purposes. The PoW model also serves as the basic structure of the simulator that can be adapted to other protocols. We showcase the flexibility of SIM-P by proposing two additional simulation models for Proof of Reputation-X and Proof of Contribution, both of which lack experimental verification in their original design specifications. We show how the simulator can be used to produce vital metrics, such as throughput, resistance against the 51% attack, and energy consumption. We verify the accuracy of SIM-P by comparing PoW’s simulated results with theoretical estimates and historical Bitcoin data.
Damilare Peter Oyinloye, Je Sen Teh, Norziana Jamil, Jiashen Teh
IEEE Internet Things J.3
2023 On the security of lightweight block ciphers against neural distinguishers: Observations on LBC-IoT and SLIM
Weijian Teng, Je Sen Teh, Norziana Jamil
J. Inf. Secur. Appl.3
2023 Enhancing Federated Learning With Spectrum Allocation Optimization and Device Selection
abstract
Machine learning (ML) is a widely accepted means for supporting customized services for mobile devices and applications. Federated Learning (FL), which is a promising approach to implement machine learning while addressing data privacy concerns, typically involves a large number of wireless mobile devices to collect model training data. Under such circumstances, FL is expected to meet stringent training latency requirements in the face of limited resources such as demand for wireless bandwidth, power consumption, and computation constraints of participating devices. Due to practical considerations, FL selects a portion of devices to participate in the model training process at each iteration. Therefore, the tasks of efficient resource management and device selection will have a significant impact on the practical uses of FL. In this paper, we propose a spectrum allocation optimization mechanism for enhancing FL over a wireless mobile network. Specifically, the proposed spectrum allocation optimization mechanism minimizes the time delay of FL while considering the energy consumption of individual participating devices; thus ensuring that all the participating devices have sufficient resources to train their local models. In this connection, to ensure fast convergence of FL, a robust device selection is also proposed to help FL reach convergence swiftly, especially when the local datasets of the devices are not independent and identically distributed (non-iid). Experimental results show that (1) the proposed spectrum allocation optimization method optimizes time delay while satisfying the individual energy constraints; (2) the proposed device selection method enables FL to achieve the fastest convergence on non-iid datasets.
Tinghao Zhang, Kwok-Yan Lam, Jun Zhao 0007, Feng Li 0008, Huimei Han, Norziana Jamil
IEEE/ACM Trans. Netw.6
2022 New differential cryptanalysis results for the lightweight block cipher BORON
Je Sen Teh, Li Jing Tham, Norziana Jamil, Wun-She Yap
J. Inf. Secur. Appl.3
2019 A review of security assessment methodologies in industrial control systems
abstract
Purpose The common implementation practices of modern industrial control systems (ICS) has left a window wide open to various security vulnerabilities. As the cyber-threat landscape continues to evolve, the ICS and their underlying architecture must be protected to withstand cyber-attacks. This study aims to review several ICS security assessment methodologies to identify an appropriate vulnerability assessment method for the ICS systems that examine both critical physical and cyber systems so as to protect the national critical infrastructure. Design/methodology/approach This paper reviews several ICS security assessment methodologies and explores whether the existing methodologies are indeed sufficient to meet the cyber security assessment exercise required to validate the security of electrical power control systems. Findings The study showed that most of the examined methodologies seem to concentrate on vulnerability identification and prioritisation techniques, whilst other security techniques received noticeably less attention. The study also showed that the least attention is devoted to patch management process due to the critical nature of the SCADA system. Additionally, this review portrayed that only two security assessment methodologies exhibited absolute fulfilment of all NERC-CIP security requirements, whilst the others only partially fulfilled the essential requirements. Originality/value This paper presents a review and a comparative analysis of several standard SCADA security assessment methodologies and guidelines published by internationally recognised bodies. In addition, it explores the adequacy of the existing methodologies in meeting cyber security assessment practices required for electrical power networks.
Qais Saif Qassim, Norziana Jamil, Maslina Daud, Ahmed Patel, Norhamadi Ja'affar
Inf. Comput. Secur.2
2013 S-box construction from non-permutation power functions
abstract
A substitution box (s-box) is a nonlinear component function used in most block ciphers. It must fulfill several cryptographic properties such as high nonlinearity, low differential uniformity and complex algebraic expression to resist against linear, differential and interpolation attacks. In this paper, we extend and improve the s-box construction method proposed by Mamadolimov et al. [26, 27] which construct an s-box from power and binomial functions over the finite field F28. We study the cryptographic properties exhibited from our s-box and do a comparative analysis with several known 8X8 bijective s-boxes. Our analysis shows that our proposed s-box is ranked seventh compared to known 8X8 bijective s-boxes in terms of strong cryptographic properties. It even surpasses some known s-boxes used in popular block ciphers.
Herman Isa, Norziana Jamil, Muhammad Reza Z'aba
SIN2