BadUSB attacks exploit the implicit trust that operating systems place in USB Human Interface Devices (HIDs), enabling a malicious peripheral to inject automated keystrokes and execute commands as if they originated from a legitimate user. This study develops a low-cost USB passthrough system that operates independently of host-side security software, using a Raspberry Pi 4 as an intermediary security layer between a keyboard and a host computer. The prototype combines VID/PID-based device identification, whitelist and blacklist controls, real-time keystroke-timing analysis, CAPTCHA-based human verification, input forwarding, and security-event logging. A Raspberry Pi Pico configured as a malicious HID was used in a preliminary, attack-driven functional evaluation comprising seven black-box test cases covering device enrolment, normal keyboard passthrough, resilience, malicious-keystroke detection, human verification, logging, and administrative functions. Of 18 predefined functional outcomes, 16 passed, one partially passed, and one failed. These outcomes demonstrate the functional feasibility of the prototype under the tested configuration but do not represent detection accuracy or general classification performance. The limited evaluation did not support the calculation of a confusion matrix, precision, recall, F1-score, or false-positive rate. The preliminary latency comparison indicated an additional average delay of 1.15 ms; however, the available experiment did not provide sufficient statistical evidence for broader performance interpretation. Broader repeated testing involving multiple users, devices, operating systems, attack patterns, and statistically rigorous latency measurements is required before operational deployment.
Muhammad Alif Nukman bin Nor Azman, N. M. Salleh, Siti Rahayu Selamat et al.· International journal of res...· 0 citations
Water quality monitoring is essential in aquaculture to ensure healthy fish growth and sustainable farming practices. In Malaysia, fish farmers commonly rely on manual methods to monitor key water quality parameters, including temperature and turbidity. However, these methods are labour-intensive, time-consuming, and prone to human error, resulting in delayed detection of water quality deterioration and inefficient data management. This study presents an Internet of Things (IoT)-based real-time water quality monitoring system to automate the monitoring process and improve aquaculture management. The system integrates an ESP32 microcontroller, a turbidity sensor, and a DS18B20 temperature sensor to continuously acquire water quality data. The collected data are transmitted wirelessly to the Blynk cloud platform for real-time monitoring, automatically recorded in Google Sheets, and visualized through Google Looker Studio to support historical data analysis. The developed prototype was evaluated through functionality testing to verify sensor connectivity, wireless communication, cloud synchronization, automated notifications, and data logging. The results demonstrate that the system successfully performs continuous data acquisition, real-time monitoring, cloud-based visualization, automated notifications, and historical data storage. The proposed system provides a practical and cost-effective solution for remote water quality monitoring in small-scale fish farming, supporting timely decision-making and more sustainable aquaculture management.
Mohamad Afif Md Gharif, N. M. Salleh, Haniza Nahar et al.· International journal of res...· 0 citations
Smart homes depend on interconnected sensors, cameras, routers, mobile applications, and cloud services. This connectivity improves automation and convenience, but it also expands the attack surface for Distributed Denial of Service (DDoS), Denial of Service (DoS), Mirai botnet, brute-force, spoofing, reconnaissance, and man-in-the-middle attacks. Traditional signature-based security is often insufficient because IoT devices are resource-constrained, heterogeneous, and frequently deployed with weak authentication or delayed firmware updates. This study evaluates supervised machine-learning classifiers for detecting cyberattacks in smart-home IoT network traffic using the CICIoT2023 dataset. Four algorithms, namely Random Forest, Decision Tree, k-Nearest Neighbour, and Support Vector Machine, were compared under 50:50, 70:30, and 80:20 train-test split settings. The models were evaluated using accuracy, precision, recall, and F1-score, with emphasis on DDoS, Mirai, and brute-force attack classes that are particularly relevant to smart-home environments. The findings show that tree-based classifiers are highly effective for IoT attack detection. Random Forest achieved the strongest overall accuracy and precision, while Decision Tree showed the most stable recall and F1-score for brute-force detection. The results indicate that Random Forest is suitable as a general-purpose smart-home IDS classifier, whereas Decision Tree or a hybrid ensemble strategy should be considered when missed brute-force attacks carry high operational risk. The paper contributes a clearer empirical comparison of lightweight supervised learning models and provides implementation guidance for smart-home intrusion detection systems.
Nurin Abyana Balqis Jailani, Haniza Nahar, N. M. Salleh et al.· International journal of res...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.