An Intelligent Cyber Defense Architecture: Integrating Real-Time Vulnerability Scanning, Asymmetric Encryption, and Network Reconnaissance in Modern Attack Surfaces
Main Article Content
Abstract
Cybersecurity professionals who work in ethical hacking and incident response and digital forensics need whole self-operating systems that examine data to develop their threat detection potential. The contemporary digital infrastructure which relies on self-operating opinion systems and integrated systems but the security systems that shield these networks design additional security dangers. The main difficulty with contemporary forensic tools is the need for security professionals to transmit private information which contains image metadata, passwords and plaintext binary files and network design details to cloud-based storage services. The conventional procedures cause large-scale data leakage threats which break fundamental principles of privacy and security and data accessibility because it detaches control over data from organizations.
The research found that the Cyber Suite which functions as an united Cyber Security Dashboard results in an edge-computing security system for native use. The platform found a new system because it shifts in-depth cryptographic functions and password validation procedures and digital proof analysis duty to the user interface of client devices. The system produces a shielded environment for private operations through the evolution of a multi-vector toolkit which works within a whole React.js platform.
The platform has four active modules which reveal whole integration with native security characteristics through their active security modules. The Cryptography & Hashes engine utilises browser-based systems to manage 2048-bit Asymmetric RSA key sets and Symmetric AES-GCM encryption. The system utilises all of its parts which involves Hash Generator (MD5, SHA1, SHA256) and Data Converters (Base64, URL, Hex encoding/decoding) and Steganography tool which allows users to conceal and exhibit secret messages through PNG image layers utilising Least Significant Bit (LSB) procedures.
The Password Toolkit merges three components which work together to shield digital identities while defending user privacy. The system utilises a k-anonymity model to achieve its rigorous data breach detection system which uses the Have I Been Pwned API. The system shields user credentials by using native SHA-1 hash creation which carries only a 5-character prefix through the network to confirm user identity against billions of compromised data.
The Network & Web Utilities authorise teams to achieve whole external tracking activities. The system utilises CIDR Subnet computations for network mapping and a URL Analyser to recognise possible phishing links and a DNS Record Fetcher which utilises Google's public DNS-over-HTTPS (DoH) API to get A records and AAAA records and MX records and TXT records without revealing the user's DNS queries to native ISPs.
Article Details
Section
COPYRIGHT
Submission of a manuscript implies: that the work described has not been published before, that it is not under consideration for publication elsewhere; that if and when the manuscript is accepted for publication, the authors agree to automatic transfer of the copyright to the publisher.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work
- The journal allows the author(s) to retain publishing rights without restrictions.
- The journal allows the author(s) to hold the copyright without restrictions.
References
[1] World Wide Web Consortium (W3C). (2017). "Web Cryptography API." W3C Recommendation.
[2] Mozilla Developer Network (MDN). (2023). "Using Web Workers for Background Processing." MDN Web Docs.
[3] Alkhalil, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). "Phishing Attacks: A Recent Comprehensive Study and a New Anatomy." Frontiers in Computer Science, vol. 3.
[4] Hunt, T. (2018). "Pwned Passwords API V2 and k-Anonymity." Troy Hunt Security Blog.
[5] Patel, Mayank, Neelam Badi, and Amit Sinhal. "The role of fuzzy logic in improving accuracy of phishing detection system." International Journal of Innovative Technology and Exploring Engineering 8.8 (2019): 3162-3164.
[6] Internet Engineering Task Force (IETF). (2018). "DNS Queries over HTTPS (DoH)." RFC 8484.
[7] Kessler, G. C. (2022). "File Signature (Magic Bytes) Table." GaryKessler.net Digital Forensics Resources.
[8] Sommer, R., & Paxson, V. (2010). "Outside the Closed World: On Using Machine Learning for Network Intrusion Detection." IEEE Symposium on Security and Privacy.
[9] Denning, D. (1987). "An Intrusion Detection Model." IEEE Transactions on Software Engineering, SE-13(2), 222-232.
[10] Scarfone, K., & Mell, P. (2007). "Guide to Intrusion Detection and Prevention Systems (IDPS)."National Institute of Standards and Technology (NIST) Special Publication 800-94.
[11] Garcia, L., et al. (2021). "Edge computing for real-time malware detection." Journal of Cloud Computing, vol. 10.