Scopus Index Publications
Permanent URI for this communityhttps://rda.sliit.lk/handle/123456789/2162
This collection consists of all Scopus-indexed publications produced by SLIIT researchers. Scopus is recognized worldwide as a leading and reputable academic indexing database.
Browse
5 results
Search Results
Item Embargo Secure Enhanced JWT Framework with Post-Quantum Cryptography(Institute of Electrical and Electronics Engineers Inc., 2026-05-22) Sunera, A; Ransika, Y; Rasiru, M; Gunawardane, A; Abeywardena, K. Y; Senarathne, AJSON Web Tokens (JWTs) are widely used in distributed authentication, but many implementations still rely on classical algorithms such as RSA and provide limited support for key transparency, guarded validation, and secure revocation. These limitations reduce their suitability for future-ready security environments [1], [2], [3]. This research proposes a secure enhanced JWT framework built on four integrated components: a post-quantum signing and verification service, a transparency-driven key distribution service, a guard layer for policy enforcement, and a secure revocation service. The framework introduces ML-DSA-based post-quantum signatures while strengthening key integrity, token validation, and revocation control. A classical RS256-based authentication system was used as the baseline and compared against the integrated post-quantum system. The baseline recorded an average login latency of 77.891 ms, verification latency of 17.078 ms, protected endpoint latency of 14.608 ms, and an average token size of 519 bytes. The integrated post-quantum system achieved an overall average request latency of 67.245 ms, 97.667 ms p95 request latency, zero request failures, and 71.943 requests per second in the scoped live benchmark. The results show that the proposed framework maintains operational stability while delivering stronger security properties than conventional JWT systems, contributing a unified JWT security architecture that integrates post-quantum signatures, transparency-based key distribution, guarded validation, and revocation-aware trust enforcement into a single end-to-end authentication model.Item Embargo Post-Quantum Cryptography for Web Authentication Protocols: A Systematic Review of OAuth 2.0, OpenID Connect, and SAML Migration(Institute of Electrical and Electronics Engineers Inc., 2026-03-19) Dissanayake, R; Wijesinghe, H; Vindinu, J; Jayasinghe, K; Abeywardena, K; Senarathne, AOAuth 2.0, OpenID Connect (OIDC), and SAML rely on classical public-key primitives such as RSA and ECDSA, which are vulnerable to quantum attacks via Shor's algorithm. This systematic review examines migration of these protocols to Post-Quantum Cryptography (PQC) following the 2024 NIST standardization of ML-DSA and ML-KEM. We map cryptographic dependencies across all three protocols, evaluate NIST-standardized algorithms for authentication use cases, and analyze practical migration challenges. Token size explosion, with ML-DSA-65 signatures approximately 52 times larger than ECDSA P-256, represents the dominant implementation barrier, compounded by incomplete JOSE standardization and limited ecosystem maturity. Missing formal security proofs and federation migration frameworks are identified as critical priorities before production deployment.Item Embargo Project HyperAdapt: An Agent-Based Intelligent Sandbox Design to Deceive and Analyze Sophisticated Malware(Institute of Electrical and Electronics Engineers Inc., 2025) Perera, S; Dias, S; Vithanage, V; Dilhara, A; Senarathne, A; Siriwardana, D; Liyanapathirana, CMalware increasingly employs sophisticated evasion techniques to bypass sandbox-based analysis, rendering traditional detection methods ineffective. This research presents Project HyperAdapt: Agent-Based Intelligent Sandbox, a framework that integrates both offensive and defensive machine learning models to enhance malware detection, deception, and behavioral analysis. The offensive RL model generates evasive malware samples, challenging the sandbox, while the defensive models including hybrid evasion detection, GAN-based behavior simulation, and a dynamically adapting RL agent work collectively to improve sandbox resilience. By continuously learning from evasive malware behavior, the defensive RL agent adapts in real-time, strengthening detection capabilities. Experimental results demonstrate that this approach enhances sandbox effectiveness, ensuring long-term adaptability against evolving malware threats.Item Embargo Dynamic Resource Allocation and Management in SDN for Multi-Service Network(Institute of Electrical and Electronics Engineers Inc., 2025) Fernando U.S.K; Pieris M.H.N; Abhayathunge H.I; Athapattu A.R.B.L; Dharmakeerthi, U; Senarathne, AThe increase in network traffic due to technological advancements has led to considerable network congestion, complicating manual network management. Software Defined Networking (SDN) addresses these limitations by decoupling the control plane from the data plane, thereby facilitating centralized and programmable network management. This study introduces a novel dynamic resource allocation method utilizing the Ryu controller and Mininet to optimize traffic flow by identifying congestion-free channels based on critical network attributes such as link bandwidth utilization, latency, and packet loss. The proposed method comprises four principal components: traffic categorization, a dynamic queuing system, an advanced status collection module, and a path selection module. The Ryu controller's dynamic packet direction based on priority levels ensures efficient resource utilization and improved Quality of Service (QoS). Simulated traffic scenarios demonstrate the efficacy of the proposed algorithm, hence highlighting its ability to enhance network performance beyond traditional static routing methods.Publication Embargo A Notion of Real-Time Anomaly Detection for IoT Devices Based on Hardware-Level Performance(Institute of Electrical and Electronics Engineers, 2022-11-03) Umagiliya, T; Senarathne, A; Rupasinghe, LInternet of Things (IoT) is becoming a considerable topic due to its benefits in the modern world. IoT devices carry out simple routine duties, but they can be valuable. IoT devices or a group of devices are connected to the internet, anomaly detection is essential, considering securing the IoT devices within the isolated environments. The most known and typical attacking modes for IoT devices are denial-of-service (DoS) and password brute-force attacks. The most dangerous attack is the Zero-day attack. The best mechanism for finding those issues as a solution is the concept of anomaly detection. Considering IoT device hardware-level anomaly detection mechanism uses the heat and the power consumption for detections. The results of those concepts can be misleading due to environmental situations. Here, it discusses the distinct approach to merely overcoming those problems using CPU and RAM utilization and driving the solution efficiently and effectively up to 99.9%.
