<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">72281</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.072281</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A Novel Signature-Based Secure Intrusion Detection for Smart Transportation Systems</article-title>
<alt-title alt-title-type="left-running-head">A Novel Signature-Based Secure Intrusion Detection for Smart Transportation Systems</alt-title>
<alt-title alt-title-type="right-running-head">A Novel Signature-Based Secure Intrusion Detection for Smart Transportation Systems</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Nafea</surname><given-names>Hanaa</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Qasim</surname><given-names>Awais</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Sattar</surname><given-names>Sana Abdul</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Munawar</surname><given-names>Adeel</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Ali</surname><given-names>Muhammad Nadeem</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<contrib id="author-6" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Kim</surname><given-names>Byung-Seo</given-names></name><xref ref-type="aff" rid="aff-4">4</xref><email>jsnbs@hongik.ac.kr</email></contrib>
<aff id="aff-1"><label>1</label><institution>College of Computer Science and Engineering, Taibah University, Al-Madinah Al-Munawwarah</institution>, <addr-line>42353</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Science, GC University Lahore</institution>, <addr-line>Lahore, 54000</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-3"><label>3</label><institution>Sirindhorn International Institute of Technology, Thammasat University</institution>, <addr-line>Pathum Thani, 12121</addr-line>, <country>Thailand</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Software and Communication Engineering, Hongik University</institution>, <addr-line>Sejong-City, 30016</addr-line>, <country>Republic of Korea</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Byung-Seo Kim. Email: <email>jsnbs@hongik.ac.kr</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2026</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>12</day><month>1</month><year>2026</year>
</pub-date>
<volume>86</volume>
<issue>3</issue>
<elocation-id>54</elocation-id>
<history>
<date date-type="received">
<day>23</day>
<month>08</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>29</day>
<month>10</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_72281.pdf"></self-uri>
<abstract>
<p>The increased connectivity and reliance on digital technologies have exposed smart transportation systems to various cyber threats, making intrusion detection a critical aspect of ensuring their secure operation. Traditional intrusion detection systems have limitations in terms of centralized architecture, lack of transparency, and vulnerability to single points of failure. This is where the integration of blockchain technology with signature-based intrusion detection can provide a robust and decentralized solution for securing smart transportation systems. This study tackles the issue of database manipulation attacks in smart transportation networks by proposing a signature-based intrusion detection system. The introduced signature facilitates accurate detection and systematic classification of attacks, enabling categorization according to their severity levels within the transportation infrastructure. Through comparative analysis, the research demonstrates that the blockchain-based IDS outperforms traditional approaches in terms of security, resilience, and data integrity.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Smart transportation</kwd>
<kwd>intrusion detection</kwd>
<kwd>network security</kwd>
<kwd>blockchain</kwd>
<kwd>smart contract</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>National Research Foundation</funding-source>
<award-id>4299990213939</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The rapid advancement of smart transportation systems has brought about significant improvements in efficiency, safety, and convenience. Traditional Intrusion Detection Systems (IDS) have limitations in terms of centralized architecture, lack of transparency, and vulnerability to single points of failure [<xref ref-type="bibr" rid="ref-1">1</xref>]. Signature-based intrusion detection depends on a database of known attack patterns or signatures to identify and prevent malicious activities [<xref ref-type="bibr" rid="ref-2">2</xref>]. By enhancing the immutable and distributed nature of blockchain, this approach can be enhanced with improved data integrity, transparency, and resilience against tampering or manipulation. The decentralized architecture of blockchain eliminates single point of failure, ensuring the continuous availability and reliability of the IDS [<xref ref-type="bibr" rid="ref-3">3</xref>]. Smart transportation systems encompass a wide range of technologies and applications focusing on enhancing the efficiency, safety, and sustainability of transportation systems. Intelligent traffic management systems, autonomous cars, vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication, and intelligent transportation management centers are just a few of the components that these systems combine. The communication and data sharing of these components allow the monitoring, decision making, and optimization of real-time transportation operations [<xref ref-type="bibr" rid="ref-4">4</xref>].</p>
<sec id="s1_1">
<label>1.1</label>
<title>Attacks on Smart Transportation Systems</title>
<p>Smart transportation systems are more susceptible to cyberattacks as a result of their growing reliance on digital technologies and network connectivity. Attacks are defined as unwelcome access by an individual or group aiming to harm, plunder, or misuse confidential and sensitive information belonging to an individual or organization. Potential attacks may include everything from malware infections and unauthorized access to data breaches and distributed denial-of-service (DDoS) attacks, as well as physical disruptions caused by compromised systems. Serious repercussions of these risks can include jeopardized security, interrupted operations, monetary losses, and infrastructure damage [<xref ref-type="bibr" rid="ref-5">5</xref>]. <xref ref-type="table" rid="table-1">Table 1</xref> lists some of the most common types of attacks on smart transportation systems.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Common attack types on smart transportation systems</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Attack name</th>
<th>Definition of the attack</th>
<th>Mode of prevention</th>
</tr>
</thead>
<tbody>
<tr>
<td>Man-in-the-middle (MITM) attack</td>
<td>The attacker intercepts and manipulates communication between two parties in order to steal, alter, or inject information.</td>
<td>Implement strong encryption algorithms and secure communication protocols.</td>
</tr>
<tr>
<td>Data injection attack</td>
<td>The attacker inserts malicious data or code into the system to alter records, disrupt processes, or expose sensitive information.</td>
<td>Employ intrusion detection systems (IDS) and validate input data.</td>
</tr>
<tr>
<td>Spoofing attack</td>
<td>The attacker impersonates a legitimate node within the network to gain unauthorized access, manipulate data, or steal information.</td>
<td>Use robust authentication mechanisms and update cryptographic keys frequently.</td>
</tr>
<tr>
<td>Denial-of-service (DoS) attack</td>
<td>The attacker overwhelms the system or server with excessive traffic, exhausting resources, and preventing legitimate communication.</td>
<td>Conduct traffic analysis, apply rate limiting, and use anomaly detection systems.</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s1_2">
<label>1.2</label>
<title>Traditional Intrusion Detection Systems</title>
<p>In many different fields, traditional IDS have been used extensively to identify and stop cyber-attacks [<xref ref-type="bibr" rid="ref-6">6</xref>]. Usually, these systems use anomaly-based or signature-based detection techniques. While anomaly-based IDS looks for departures from typical system behavior, signature-based IDS employs a database of known attack patterns or signatures to find and stop malicious activity. Furthermore, it can be difficult to update and maintain the signature database, particularly in light of the constantly changing nature of cyber threats [<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-8">8</xref>]. The swift progress of intelligent transportation systems, distinguished by the incorporation of Internet of Things gadgets, connected vehicles, and intelligent infrastructure, has significantly enhanced the efficiency and safety of urban mobility. However, in case of attacks, IDS becomes inefficient as it does not have access to the valid conditions of the attacks.</p>
<p>Blockchain is a distributed ledger system that operates decentralized manner, allowing record-keeping to be transparent and safe without requiring a central authority. Because blockchain can improve trust, security, and traceability, it has drawn a lot of attention from a variety of industries, including finance, supply chain management, and healthcare [<xref ref-type="bibr" rid="ref-9">9</xref>]. Blockchain technology and signature-based intrusion detection can be combined to create a transparent and decentralized smart transportation network security system. A signature-based IDS system is essential for a smart transportation system using blockchain because it provides an additional layer of security to detect and respond to known attack patterns and signatures. By detecting and responding to known attack patterns and signatures, a signature-based IDS system can help prevent financial loss, reputation damage, and disruptions to the transportation system [<xref ref-type="bibr" rid="ref-10">10</xref>]. This research focuses on solving the problem of database manipulation by an attacker by using a signature-based intrusion detection system tailored for smart transportation networks, incorporating blockchain technology to maximize the security, reliability, and transparency of the detection process.</p>
<p>The rest of this paper is organized as follows. In <xref ref-type="sec" rid="s2">Section 2</xref>, we discuss the limitations of the related work and how the proposed approach overcomes these limitations. <xref ref-type="sec" rid="s3">Section 3</xref> provides a comprehensive explanation of the proposed framework. In <xref ref-type="sec" rid="s4">Section 4</xref>, we demonstrate the application of the proposed framework using a case study. <xref ref-type="sec" rid="s5">Section 5</xref> concludes the paper.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>In [<xref ref-type="bibr" rid="ref-11">11</xref>], a novel approach for intrusion detection in IoT networks is discussed. The system works to detect intrusions in real-time, learn from other nodes in the network, and improve detection accuracy while reducing false positives. But the collaborative IDS model, while scalable, assumes homogeneous device behavior and static network topologies, which do not reflect the dynamic and heterogeneous landscape of smart transportation environments. In [<xref ref-type="bibr" rid="ref-12">12</xref>], the authors present a novel approach to enhance the accuracy of IDS using blockchain technology. The working of the approach involves integrating a blockchain-based framework with traditional IDS, where blockchain is utilized to store and organize intrusion detection rules, and to ensure the integrity and immutability of the detection data. Their limitation is that the proposed model operates in a generic computing/networking environment, not accounting for the real-time, mobile, and safety-critical nature of smart transportation systems. The authors of [<xref ref-type="bibr" rid="ref-13">13</xref>] have proposed a distributed intrusion detection system (DIDS), which detects and reacts to cyber-attacks instantly by utilizing cloud computing and blockchain technologies. Their approach relies heavily on cloud computing, which introduces significant latency and centralized dependencies, unsuitable for high-speed vehicular networks that require local, edge-level intrusion detection and response.</p>
<p>In [<xref ref-type="bibr" rid="ref-14">14</xref>], the purpose of the Blockchain-Enabled Intrusion Detection System (BIDS) is to improve security and efficiency in identifying and addressing cyber threats in smart cities. Their approach lacks a threat model tailored to vehicular networks and emphasizes collaborative intelligence across static nodes, which may not work efficiently in a highly dynamic, mobile transportation environment. In [<xref ref-type="bibr" rid="ref-15">15</xref>], federated learning and blockchain technology are used in the proposed Federated Intrusion Detection System (FIDS) for blockchain-based smart transportation systems to improve efficiency and security. But their approach relies heavily on computationally intensive ML models that increases overhead on resource-constrained vehicular devices. This, in turn, introduces delays in detection and response, which are unacceptable in high-speed transportation environments. The potential of using blockchain for intrusion detection in an intelligent transportation system is highlighted in [<xref ref-type="bibr" rid="ref-16">16</xref>]. However, they discussed the IDS integration conceptually but didn&#x2019;t present a specific detection technique (e.g., signature-based, anomaly-based), nor do they detail the detection logic or threat model.</p>
<p>According to [<xref ref-type="bibr" rid="ref-17">17</xref>], the distribution of cyber-attack signatures is a critical component of IDS. CIoTA (Collaborative IoT Anomaly Detection via Blockchain) is a decentralized framework that leverages blockchain technology to enable collaborative IoT anomaly detection. Their model is designed for static or low-mobility IoT devices, and does not address the challenges of highly mobile nodes (e.g., vehicles in VANETs). The authors of [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed a technique that builds a decentralized network of edge nodes and Internet of Things devices that exchange threat intelligence and anomaly detection models via a blockchain. But their approach focuses on blockchain-specific behaviors and anomalies, such as unexpected transactions, blocks, or peer behavior, rather than network-level or communication-layer attacks relevant to smart transportation systems. The application of blockchain technology to collaborative intrusion detection based on trust is investigated in [<xref ref-type="bibr" rid="ref-19">19</xref>], and they suggest an architecture that makes use of the tamper-proof nature of blockchain technology. But the approach lacks consideration of latency, mobility, and real-time communication challenges faced in vehicular environments. A distributed intrusion detection system is necessary for next-generation networks, such as 5G and the Internet of Things, because of their size, complexity, and dynamic nature. This plan uses machine learning, artificial intelligence, and advanced analytics to construct a network of agents that monitor and analyze traffic locally [<xref ref-type="bibr" rid="ref-20">20</xref>]. However, their model is for infrastructure-centric network environments and is not suited for vehicular or transportation systems, where nodes are highly mobile. The authors in [<xref ref-type="bibr" rid="ref-21">21</xref>&#x2013;<xref ref-type="bibr" rid="ref-23">23</xref>] recommend the use of blockchain for improved security in IoTs. In <xref ref-type="table" rid="table-2">Table 2</xref>, we provide a comparison table of our related work.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Comparison table of the related work</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Related Work</th>
<th>Method/Technique</th>
<th>Limitation</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td>Collaborative blockchain-based signature IDS for IoT</td>
<td>Their approach is limited to IoT devices, lacks efficiency for large-scale transportation systems and the consensus overhead is not optimized.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
<td>Consensus algorithm for collaborative signature IDS</td>
<td>Their focus is on the consensus mechanism only. The approach has high latency under large network load and lacks integration with real transport systems.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
<td>Blockchain-based IDS accuracy enhancement</td>
<td>Their approach, although it improves detection accuracy, but does not address database manipulation or attack classification.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
<td>Distributed IDS using Blockchain &#x002B; Cloud</td>
<td>Their approach is dependent on cloud that creates potential latency and privacy issues. Hence, the approach is not lightweight enough for real-time smart transport.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
<td>BIDS: blockchain-enabled IDS for smart cities</td>
<td>The proposed work is focused on Smart cities and does not explicitly address signature-based severity classification.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-23">23</xref>]</td>
<td>Federated IDS in blockchain-based smart transportation</td>
<td>They handled distributed detection of attacks, limited attack categorization, but the proposed method has high computational overhead due to federated learning.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The comparative analysis of existing intrusion detection approaches reveals several common limitations that hinder their effectiveness in securing smart transportation systems. Traditional IDS solutions such as blockchain-based models [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>], and [<xref ref-type="bibr" rid="ref-16">16</xref>] often suffer from high consensus overhead and latency issues when deployed in large-scale environments. Several works [<xref ref-type="bibr" rid="ref-14">14</xref>,<xref ref-type="bibr" rid="ref-16">16</xref>&#x2013;<xref ref-type="bibr" rid="ref-18">18</xref>], and [<xref ref-type="bibr" rid="ref-20">20</xref>] fail to provide fine-grained intrusion categorization or severity-based classification, limiting their applicability for real-time threat prioritization. Moreover, critical aspects such as database manipulation remain largely unaddressed in studies like [<xref ref-type="bibr" rid="ref-14">14</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>], and [<xref ref-type="bibr" rid="ref-19">19</xref>], leaving systems exposed to tampering attacks. Additionally, many proposed models [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>] are tailored to generic IoT or smart city contexts, rather than transportation-specific infrastructures. These gaps collectively highlight the need for a novel framework that ensures decentralized security, mitigates database manipulation, and incorporates signature-based severity classification specifically for smart transportation systems.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Proposed Blockchain-Based Intrusion Detection for Smart Transportation Framework</title>
<p>Our proposed framework, Blockchain based Intrusion Detection for Smart Transportation (BIDST), is shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>. There are two major modules: Blockchain Initialization and Intrusion Detection Module. Below we will explain the working of each module in detail.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Proposed blockchain-based intrusion detection for smart transportation framework</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_72281-fig-1.tif"/>
</fig>
<sec id="s3_1">
<label>3.1</label>
<title>Blockchain Initialization</title>
<p>This module is responsible for making sure that before the system is deployed it has signatures of all the common attacks on smart transportation systems. It has two submodules, i.e., Data Extraction Module and Signatures Extraction.</p>
<sec id="s3_1_1">
<label>3.1.1</label>
<title>Data Extraction Module</title>
<p>This module will extract the data of common attacks from four repositories. The designer of the system can provide help in this to narrow down which attacks are most common. The whole purpose of keeping data of attacks in blockchain is to make it secure from attacks. In such attacks the attacker can manipulate the signatures of the attack rather than attacking on system&#x2019;s data. This can have severe consequences, like the intrusion detection failing because of compromised signatures. For our framework we have selected four repositories.</p>
<p><italic>National Vulnerability Database (NVD):</italic> This database is managed by the National Institute of Standards and Technology (NIST). We can use it to identify vulnerabilities in software and hardware components of transportation systems, such as traffic management software, vehicle control systems, and communication protocols.</p>
<p><italic>Common Vulnerabilities and Exposures (CVE):</italic> This database contains a list of publicly disclosed information security vulnerabilities and exposures. We can use it to match network traffic against known vulnerability patterns, helping to identify and prevent attacks on transportation networks.</p>
<p><italic>Common Weakness Enumeration (CWE):</italic> It is a database of a community-developed list of common software security weaknesses. It helps to identify the root causes of vulnerabilities, making it easier to prevent and detect them.</p>
<p><italic>Open-Source Vulnerability Database (OSVDB):</italic> It is an open-source vulnerability database that provides comprehensive information about vulnerabilities.</p>
</sec>
<sec id="s3_1_2">
<label>3.1.2</label>
<title>Signatures Extraction</title>
<p>This is the major contribution of our framework where we have designed the signature for our intrusion detection system. The signature is generic enough to capture all the details of common attacks on smart transportation systems. The signature defines the characteristics of the threat, the conditions under which the signature will trigger an alert, and the actions to be taken. The details of the attributes are given below.</p>
</sec>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Attributes of BIDST Signatures</title>
<p>The signature has seven sections as listed in <xref ref-type="table" rid="table-3">Table 3</xref>. The section Meta Data contains information about the metadata of an attack. The section Description provides a summary of an attack. The section Conditions provides information about patterns/rules that can be used to detect an attack. The section Action contains information about what actions should be taken in case an attack is detected. The section Examples provides some sample traffic of the attack. The section References is useful if we want to get more information about an attack. It can contain links to the official documentation. Lastly, the section Additional Information contains information about how the attack is commonly carried out.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Attributes of signatures to be used in the proposed BIDST framework</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Tag</th>
<th>Attribute 1</th>
<th>Attribute 2</th>
<th>Attribute 3</th>
<th>Attribute 4</th>
<th>Attribute 5</th>
<th>Attribute 6</th>
</tr>
</thead>
<tbody>
<tr>
<td>Meta data</td>
<td>Signature ID: unique identifier for the signature.</td>
<td>Name: descriptive name indicating the type of attack detected.</td>
<td>Severity: threat level (low, medium, high, critical).</td>
<td>Category: attack type (e.g., DoS, malware, unauthorized access).</td>
<td>Revision number: version of the signature for updates and tracking.</td>
<td>Source context: storage of contextual information.</td>
</tr>
<tr>
<td>Description</td>
<td>Summary: brief description of the detected behavior or threat.</td>
<td>Target systems: systems, devices, or networks applicable (e.g., web servers, IoT).</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
<tr>
<td>Conditions</td>
<td>Pattern/Rule: specific rules that define malicious activity.</td>
<td>Payload content: strings, commands, or patterns in the payload.</td>
<td>Header information: attributes like IP, ports, and protocols.</td>
<td>Anomalous behavior: deviations from normal behavior (e.g., unusual traffic).</td>
<td>Timing: repeated requests within a short interval.</td>
<td>Contextual information: additional conditions such as presence of files, services, or user actions.</td>
</tr>
<tr>
<td>Actions</td>
<td>Alert: type of alert generated (e.g., log entry, SOC notification).</td>
<td>Response: automated actions (e.g., block traffic, terminate session).</td>
<td>Logging: details recorded for analysis.</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
<tr>
<td>Examples</td>
<td>Matching traffic: example packet or log triggering the signature.</td>
<td>False positives: possible sources of false positives and mitigation.</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
<tr>
<td>References</td>
<td>Documentation: links or references to technical resources.</td>
<td>CVE IDs: known vulnerabilities if applicable.</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td></td>
</tr>
<tr>
<td>Additional information</td>
<td>Attack vector: method typically used (e.g., phishing, network-based).</td>
<td>Mitigation strategies: recommended preventive measures.</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Smart Contract for Saving Signatures in Blockchain</title>
<p>In this section, we write a smart contract to store the signatures of common attacks in blockchain. The complete code is provided in the supplementary file. The smart contract is written in Solidity Language and it is implemented on the Ethereum blockchain. When the system is deployed then if a new attack is recognized then it will also be saved in it. The smart contract includes structures to store various details, including the signature ID, metadata, description, conditions, actions, examples, references, and additional information. We have created seven structs namely Metadata, Description, Conditions, Actions, Examples, References, Additional Information to store the signatures data. We can call the storeSignature function with the required data to store an IDS signature. The function emits an event, SignatureStored, to log the addition of a new signature. The getAllSignatures function allows retrieving all stored signatures.</p>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Intrusion Detection Module</title>
<p>This module is responsible for monitoring all the traffic being communicated in a smart transportation system. It monitors not only the outbound traffic but also the traffic exchanged locally between the nodes of the system. This is to ensure that in case a compromised node tries to initiate an attack from within the system, it can be easily traced.</p>
<p><italic>Smart Transportation System:</italic> This module represents the working of an STS, which will integrate advanced technologies and data analytics to enhance the efficiency, safety, and sustainability of transportation networks. It will comprise smart vehicles like smart cars, smart trains, smart planes, communication networks, data processing, and automation to manage and improve transportation in real-time. The major purpose of this system will be to improve traffic flow, enhance safety, increase cost efficiency, and provide user convenience.</p>
<p><italic>Traffic Analyzer Module:</italic> In this module, the collected data will be processed to optimize traffic flow by adjusting traffic signals, providing real-time route guidance, and managing congestion.</p>
<p><italic>Pattern Recognition Module:</italic> The purpose of this module is to detect patterns of data that will lead to any intrusions.</p>
<p><italic>Alert Generation Module:</italic> This module will only be used if the system detects an intrusion. The designer of the system can decide what type of alerts he wants to be raised and what type of mitigation strategies need to be adopted.</p>
<p><italic>Blockchain Updation Module:</italic> In case a new attack is detected that does not match with any of the previously stored signatures then its signatures will be saved in the blockchain for future.</p>
<fig id="fig-6">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_72281-fig-6.tif"/>
</fig>
<p>Algorithm 1 demonstrates how the proposed BIDST framework begins by initializing the core components of the Intrusion Detection System (IDS), including the blockchain-based signature database, detection engine, and alerting system. Network traffic is continuously captured and processed, with relevant features extracted from each packet. These features are then compared against the existing signature database. If a direct match is found, the system immediately detects an intrusion, triggers alerts, logs the details, and executes predefined responses while generating a comprehensive report. In cases where the traffic does not match any known signature but exhibits suspicious activity, the system dynamically creates a new signature, stores it securely on the blockchain to ensure immutability and transparency, and emits an event log for auditability. Reports are also generated to summarize attack types, sources, frequencies, and response effectiveness. If neither a match nor suspicious activity is identified, the traffic is classified as benign, and the system continues monitoring.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Application of the Proposed BIDST Framework</title>
<p>In this section, we will show the working of the proposed BIDST framework with the help of a case study. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> shows the working of a smart transportation system. In this system, various cars interact seamlessly to create a more efficient, safe, and user-friendly transportation environment. The connected vehicle will receive real-time traffic updates from the Regional Processing Unit (RPU), allowing it to reroute to avoid congestion. At the same time, the vehicle communicates with nearby traffic lights to ensure that it hits green lights along the way, further reducing travel time. Every vehicle needs to be preregistered in the system for it to be part of the blockchain. The RPU will use real-time data from sensors, cameras, and connected vehicles to monitor and manage traffic flow. It will help in optimizing traffic signal timings, managing congestion, and reducing travel times. To improve traffic flow and reduce congestion, the RPU will modify the timing of traffic signals based on current traffic circumstances. The RPU is initialized with signatures of common attacks on smart transportation systems, and every message before being sent to a vehicle is scanned for suspicious activity.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>A sample smart transportation example</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_72281-fig-2.tif"/>
</fig>
<sec id="s4_1">
<label>4.1</label>
<title>Intrusion Attempt on a Car</title>
<p>The intrusion detection system will scan the incoming network packets that are being sent to cars. These packets can be from other cars or from outside the private blockchain territory. The RPU will compare the data against our database of known attack signatures. In case a match is found, the RPU will trigger the alert. Otherwise, if there is certain network traffic activity that is not present in our database, but it is categorized as malicious then the IDS will ask for human intervention before saving the signature of the suspicious activity.</p>
<sec id="s4_1_1">
<title>Sample Network Traffic with SQL Injection Attempt</title>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> is an example of network traffic that contains an SQL injection. The IDS will analyze the data when capturing packets.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>A sample SQL injection attempt on a car</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_72281-fig-3.tif"/>
</fig>
<p>It shows an HTTP request where a malicious user attempts an SQL injection by manipulating a URL parameter. The attacker targets the system&#x2019;s vehicle tracking page or traffic signal management interface with two parameters: <monospace>vehicleID</monospace> and <monospace>action</monospace>. The <monospace>vehicleID</monospace> parameter is set to <monospace>12345; DELETE FROM traffic_signals WHERE 1 &#x003D; 1; &#x2013;</monospace>, which attempts to alter the SQL query and delete all entries in the <monospace>traffic_signals</monospace> table. The <monospace>action</monospace> parameter is set to <monospace>view</monospace>, indicating the intention to display vehicle details after the malicious query is executed. By injecting the SQL command <monospace>DELETE FROM traffic_signals WHERE 1 &#x003D; 1;</monospace>, and since the condition <monospace>1 &#x003D; 1</monospace> always evaluates to true, a successful attack would delete all rows from the <monospace>traffic_signals</monospace> table.</p>
</sec>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Potential Impact of the Attack</title>
<p>In a smart transportation system, the traffic signals table might store critical information about the state of traffic lights across a city. If this table is deleted, it could result in traffic lights going offline or malfunctioning, leading to traffic chaos or accidents. Additionally, if the attack succeeds, it could also disrupt the vehicle tracking system, preventing authorities from monitoring the location and status of vehicles within the transportation network.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Extraction of Signature Data in the BIDST Framework for Blockchain Storage</title>
<p><xref ref-type="table" rid="table-4">Table 4</xref> presents the structured signature data, extracted in accordance with the proposed BIDST framework, and prepared for secure storage in the blockchain. Each element provides essential information required for accurate detection, response, and long-term traceability.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Detected attributes of the attack as per the BIDST framework</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Tag</th>
<th>Attribute 1</th>
<th>Attribute 2</th>
<th>Attribute 3</th>
<th>Attribute 4</th>
<th>Attribute 5</th>
<th>Attribute 6</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>Meta data</bold></td>
<td>Signature ID: 10123</td>
<td>Name: SQL injection attempt</td>
<td>Severity: high.</td>
<td>Category: web application attack</td>
<td>Revision number: 1</td>
<td>Source context: V2V</td>
</tr>
<tr>
<td><bold>Description</bold></td>
<td>Summary: identifies SQL injection attempts in HTTP requests by detecting suspicious patterns commonly used in SQL-based attacks.</td>
<td>Target systems: web servers and application servers</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
<tr>
<td><bold>Conditions</bold></td>
<td>Pattern/Rule: presence of common SQL injection signatures such as &#x201C;1&#x003D;1 &#x2013;&#x201D; within the HTTP request payload.</td>
<td>Payload content: NA</td>
<td>Header information: HTTP method is either POST or GET</td>
<td>Anomalous behavior: NA</td>
<td>Timing: repeated similar requests within a short time frame.</td>
<td>Contextual information: NA</td>
</tr>
<tr>
<td><bold>Actions</bold></td>
<td>Alert: generate a high-severity log entry and notify the Security Operations Center (SOC).</td>
<td>Response: temporarily block the offending IP address for 30 min</td>
<td>Logging: record full HTTP request details along with response codes.</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
<tr>
<td><bold>Examples</bold></td>
<td>Matching traffic: a GET request containing parameters with the string &#x201C;1&#x003D;1 &#x2013;&#x201D;</td>
<td>False positives: ensure legitimate queries resembling SQL injection patterns are properly whitelisted</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
<tr>
<td><bold>References</bold></td>
<td>Documentation: OWASP SQL Injection Guide: <ext-link ext-link-type="uri" xlink:href="https://owasp.org/www-community/attacks/">https://owasp.org/www-community/attacks/</ext-link> (accessed on 23 October 2025) SQLInjection</td>
<td>CVE IDs: CVE-2020-26623: SQL Injection in Web Application</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td></td>
</tr>
<tr>
<td><bold>Additional Information</bold></td>
<td>Attack vector: typically executed via user input fields in web applications.</td>
<td>Mitigation strategies: implement prepared statements and parameterized queries to prevent SQL injection.</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Smart Contract for Saving Signatures in Blockchain</title>
<p>Now we execute the smart contract to store the signature of attack in the blockchain. <xref ref-type="fig" rid="fig-4">Fig. 4</xref> shows the output of the successful execution of the smart contract. We can note the transaction cost and gas required for saving a single signature in the blockchain.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Successful execution of smart contract</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_72281-fig-4.tif"/>
</fig>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Discussion</title>
<p>The rapid advancement of smart transportation systems necessitates robust security measures to protect critical infrastructure from cyber threats. Traditional signature-based IDS has long been employed to safeguard these systems, but it faces limitations in the face of increasingly sophisticated attacks. Blockchain technology, with its decentralized and immutable nature, offers a promising enhancement to these traditional systems. In this section we explore the effectiveness of traditional signature-based IDS against the proposed BIDST framework, focusing on security, efficiency, scalability, data integrity, cost, resilience against attacks, and regulatory compliance. <xref ref-type="table" rid="table-5">Table 5</xref> presents a comparison between the proposed approach and the traditional signature-based IDS.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Comparison of traditional signature-based IDS and proposed BIDST IDS for smart transportation</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Criteria</th>
<th>Traditional signature-based IDS</th>
<th>Proposed BIDST IDS</th>
</tr>
</thead>
<tbody>
<tr>
<td>Security</td>
<td>Centralized architecture can become a single point of failure.</td>
<td>Decentralized verification enhances security, ensuring resilience against zero-day attacks. Immutability guarantees data integrity and reliable forensic analysis.</td>
</tr>
<tr>
<td>Efficiency</td>
<td>Fast detection for known threats but prone to high false positives, especially in complex environments.</td>
<td>Slightly slower due to consensus mechanisms, but achieves higher accuracy with reduced false positives, validated by multiple nodes.</td>
</tr>
<tr>
<td>Scalability</td>
<td>Difficult to scale in large transportation networks because of centralized processing constraints.</td>
<td>Better scalability through decentralized design, though it requires additional resources and infrastructure to support the network.</td>
</tr>
<tr>
<td>Data integrity</td>
<td>Vulnerable to tampering and manipulation in centralized systems, compromising audit trails.</td>
<td>Immutable blockchain records ensure data integrity, preventing tampering and providing trustworthy audit trails for investigations.</td>
</tr>
<tr>
<td>Cost</td>
<td>Lower initial and operational costs due to minimal infrastructure requirements.</td>
<td>Higher setup and operational costs from distributed infrastructure and increased computational demand.</td>
</tr>
<tr>
<td>Resilience against attacks</td>
<td>Less resilient against advanced attacks targeting central system availability or integrity.</td>
<td>Highly resilient to diverse cyberattacks, strengthened by its decentralized and immutable architecture.</td>
</tr>
<tr>
<td>Regulatory compliance</td>
<td>May face compliance challenges, particularly in data integrity and traceability requirements.</td>
<td>Facilitates compliance with regulations due to transparent, immutable records supporting auditability and reporting.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In <xref ref-type="fig" rid="fig-5">Fig. 5</xref>, we have created a radar chart for comparing the performance metrics of traditional IDS vs. blockchain-based IDS across different parameters. By looking at the chart, it is evident that the blockchain based signature IDS has covered a large area, which means it has a better performance across the measured parameters. This allows us to visually analyze and present the effectiveness of traditional and blockchain based IDS systems in smart transportation. We can see that in two criteria, i.e., cost and efficiency the proposed framework&#x2019;s performance might be less than the traditional approach. This is because of the fact that as the number of nodes (which in our case represents the number of vehicles in the smart network) grow, the overhead of maintaining the blockchain grows rapidly. Blockchain-based intrusion detection systems, while offering decentralization, transparency, and immutability, inevitably introduce performance trade-offs due to consensus mechanisms such as Proof-of-Work (PoW) or Proof-of-Stake (PoS). These mechanisms increases computational and communication overhead. In terms of cost, for smart transportation systems, where IoT-enabled vehicles and roadside units may have limited hardware capacity, this overhead directly translates into infrastructure costs for additional processing and storage resources. In terms of efficiency, the requirement for multiple nodes to validate an intrusion signature update can lead to latency in detection and response time, particularly under real-time traffic scenarios. High verification delays may reduce the IDS&#x2019;s ability to provide timely alerts. Furthermore, large-scale deployment across urban transportation networks amplifies the efficiency challenges due to increased synchronization traffic among blockchain nodes. However, there are some ways in which we can try to balance these trade-offs like using permissioned blockchains (to reduce the number of validators), lightweight consensus algorithms tailored for IoT/vehicular systems (e.g., RAFT, DPoS), and hybrid architectures where critical real-time detection is handled locally by agents while blockchain ensures secure logging and auditability.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Comparison of signature-based IDS and blockchain-based IDS</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_72281-fig-5.tif"/>
</fig>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion and Future Work</title>
<p>In this research, we proposed a framework for a signature-based intrusion detection system integrated with blockchain technology for enhancing the security of smart transportation systems. With the increasing adoption of intelligent transportation solutions, the need for robust, scalable, and secure communication frameworks has become critical. Traditional intrusion detection methods, while effective in some scenarios, face challenges in adapting to the decentralized and dynamic nature of smart transportation networks. We devised a method for storing the signatures of known attacks and wrote a smart contract for storing the signatures in blockchain. With the help of a case study, we showed how the usage of blockchain makes sure that the intrusion detection process is tamper-resistant, transparent, and auditable, thereby significantly reducing the risk of attacks such as tampering, man-in-the-middle, and unauthorized access. We then discussed the limitations of traditional IDS for smart transportation and how the usage of blockchain provides improved resilience against attacks, enhanced data integrity, and a more secure communication framework.</p>
<p>The current approach is based on signature-based intrusion detection but for enhanced security for the detection of unknown and emerging threats, we can include the anomaly-based detection that will result in a hybrid intrusion detection system. Within this integration, the signature-based component would continue to provide precise identification and classification of known attacks, ensuring low false positives, while the anomaly-based component would leverage statistical and machine learning techniques to flag deviations from normal traffic patterns, thereby detecting novel or zero-day threats.</p>
</sec>
<sec sec-type="supplementary-material" id="s6">
<title>Supplementary Materials</title>
<supplementary-material id="SD1">
<media xlink:href="CMC_72281-s001.docx"/>
</supplementary-material></sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported by the National Research Foundation (NRF), Republic of Korea, under project BK21 FOUR (4299990213939).</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: Conceptualization, Hanaa Nafea, Awais Qasim, and Sana Abdul Sattar; Methodology, Hanaa Nafea, Awais Qasim, Sana Abdul Sattar, and Adeel Munawar; Software, Hanaa Nafea, Awais Qasim, and Sana Abdul Sattar; Validation, Awais Qasim, Adeel Munawar, and Muhammad Nadeem Ali; Formal Analysis, Sana Abdul Sattar, Adeel Munawar, and Byung-Seo Kim; Investigation, Sana Abdul Sattar, Adeel Munawar, and Muhammad Nadeem Ali; Resources, Awais Qasim, Muhammad Nadeem Ali, and Byung-Seo Kim; Data Curation, Hanaa Nafea, Awais Qasim, and Sana Abdul Sattar; Original Draft Preparation, Hanaa Nafea, Awais Qasim, and Sana Abdul Sattar; Rreview and Editing, Awais Qasim, Muhammad Nadeem Ali, and Byung-Seo Kim; Visualization, Hanaa Nafea, Awais Qasim, and Sana Abdul Sattar; Supervision, Awais Qasim and Byung-Seo Kim; Project Administration, Awais Qasim and Byung-Seo Kim; Funding Acquisition, Byung-Seo Kim. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The datasets generated or analyzed during the current study are available in <ext-link ext-link-type="uri" xlink:href="https://nvd.nist.gov/">https://nvd.nist.gov/</ext-link> (accessed on 23 October 2025).</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<sec>
<title>Supplementary Materials</title>
<p>The supplementary material is available online at <ext-link ext-link-type="uri" xlink:href="https://www.techscience.com/doi/10.32604/cmc.2025.072281/s1">https://www.techscience.com/doi/10.32604/cmc.2025.072281/s1</ext-link>.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Paul</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ganguli</surname> <given-names>I</given-names></string-name>, <string-name><surname>Bhowmick</surname> <given-names>RS</given-names></string-name>, <string-name><surname>Badotra</surname> <given-names>S</given-names></string-name>, <string-name><surname>Bharany</surname> <given-names>S</given-names></string-name>, <string-name><surname>Rehman</surname> <given-names>AU</given-names></string-name></person-group>. <article-title>DRL based traffic signal control method featuring masked approach to redress transmission error in ITS</article-title>. <source>Int J Intell Trans Syst Res</source>. <year>2025</year>;<volume>23</volume>(<issue>2</issue>):<fpage>774</fpage>&#x2013;<lpage>93</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s13177-025-00482-z</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ahmed</surname> <given-names>U</given-names></string-name>, <string-name><surname>Nazir</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sarwar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ali</surname> <given-names>T</given-names></string-name>, <string-name><surname>Aggoune</surname> <given-names>EHM</given-names></string-name>, <string-name><surname>Shahzad</surname> <given-names>T</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Signature-based intrusion detection using machine learning and deep learning approaches empowered with fuzzy clustering</article-title>. <source>Sci Rep</source>. <year>2025</year>;<volume>15</volume>(<issue>1</issue>):<fpage>1726</fpage>. doi:<pub-id pub-id-type="doi">10.1038/s41598-025-92132-3</pub-id>; <pub-id pub-id-type="pmid">40055395</pub-id></mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ali</surname> <given-names>MN</given-names></string-name>, <string-name><surname>Imran</surname> <given-names>M</given-names></string-name>, <string-name><surname>Din</surname> <given-names>MSu</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>BS</given-names></string-name></person-group>. <article-title>Low rate DDoS detection using weighted federated learning in SDN control plane in IoT network</article-title>. <source>Appl Sci</source>. <year>2023</year>;<volume>13</volume>(<issue>3</issue>):<fpage>1431</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app13031431</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>WU</given-names></string-name>, <string-name><surname>Bashir</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Dutta</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Rehman</surname> <given-names>AU</given-names></string-name>, <string-name><surname>Al Dabel</surname> <given-names>MM</given-names></string-name></person-group>. <article-title>Sum rate maximization for 6g beyond diagonal RIS-assisted multi-cell transportation systems</article-title>. <source>IEEE Trans Intell Trans Syst</source>. <year>2025</year>;<volume>26</volume>(<issue>10</issue>):<fpage>17601</fpage>&#x2013;<lpage>11</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tits.2024.3521196</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Haider</surname> <given-names>A</given-names></string-name>, <string-name><surname>Adnan Khan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Rehman</surname> <given-names>A</given-names></string-name>, <string-name><surname>Rahman</surname> <given-names>M</given-names></string-name>, <string-name><surname>Seok Kim</surname> <given-names>H</given-names></string-name></person-group>. <article-title>A real-time sequential deep extreme learning machine cybersecurity intrusion detection system</article-title>. <source>Comput Mater Contin</source>. <year>2021</year>;<volume>66</volume>(<issue>2</issue>):<fpage>1785</fpage>&#x2013;<lpage>98</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2020.013910</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Raza</surname> <given-names>M</given-names></string-name>, <string-name><surname>Barket</surname> <given-names>AR</given-names></string-name>, <string-name><surname>Rehman</surname> <given-names>AU</given-names></string-name>, <string-name><surname>Rehman</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ullah</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Mobile crowdsensing based architecture for intelligent traffic prediction and quickest path selection</article-title>. In: <conf-name>2020 International Conference on UK-China Emerging Technologies (UCET)</conf-name>; 2020 Aug 20&#x2013;21; Glasgow, UK. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2020</year>. p. <fpage>1</fpage>&#x2013;<lpage>4</lpage>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aloqaily</surname> <given-names>M</given-names></string-name>, <string-name><surname>Otoum</surname> <given-names>S</given-names></string-name>, <string-name><surname>Al Ridhawi</surname> <given-names>I</given-names></string-name>, <string-name><surname>Jararweh</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>An intrusion detection system for connected vehicles in smart cities</article-title>. <source>Ad Hoc Netw</source>. <year>2019</year>;<volume>90</volume>(<issue>4</issue>):<fpage>101842</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.adhoc.2019.02.001</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Qasim</surname> <given-names>A</given-names></string-name>, <string-name><surname>Bilal</surname> <given-names>M</given-names></string-name>, <string-name><surname>Munawar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Rehman Baig</surname> <given-names>SU</given-names></string-name></person-group>. <article-title>Blockchain based intrusion detection in agent-driven flight operations</article-title>. <source>Multiagent Grid Syst</source>. <year>2024</year>;<volume>20</volume>(<issue>2</issue>):<fpage>161</fpage>&#x2013;<lpage>83</lpage>. doi:<pub-id pub-id-type="doi">10.3233/mgs-240017</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nafea</surname> <given-names>H</given-names></string-name>, <string-name><surname>Qasim</surname> <given-names>A</given-names></string-name>, <string-name><surname>Hussain</surname> <given-names>A</given-names></string-name>, <string-name><surname>Fakhir</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Blockchain-based reputation model for vehicle platooning with common global goal</article-title>. <source>Multiagent Grid Syst</source>. <year>2025</year>;<volume>21</volume>(<issue>1</issue>):<fpage>21</fpage>&#x2013;<lpage>37</lpage>. doi:<pub-id pub-id-type="doi">10.1177/15741702251338060</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Farooq</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Abbas</surname> <given-names>S</given-names></string-name>, <string-name><surname>Atta-Ur-Rahman</surname></string-name>, <string-name><surname>Sultan</surname> <given-names>K</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Mosavi</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A fused machine learning approach for intrusion detection system</article-title>. <source>Comput Mater Contin</source>. <year>2023</year>;<volume>74</volume>(<issue>2</issue>):<fpage>2607</fpage>&#x2013;<lpage>23</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2023.032617</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liao</surname> <given-names>HJ</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>CHR</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>YC</given-names></string-name>, <string-name><surname>Tung</surname> <given-names>KY</given-names></string-name></person-group>. <article-title>Intrusion detection system: a comprehensive review</article-title>. <source>J Netw Comput Appl</source>. <year>2013</year>;<volume>36</volume>(<issue>1</issue>):<fpage>16</fpage>&#x2013;<lpage>24</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jnca.2012.09.004</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>W</given-names></string-name>, <string-name><surname>Tug</surname> <given-names>S</given-names></string-name>, <string-name><surname>Meng</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Designing collaborative blockchained signature-based intrusion detection in iot environments</article-title>. <source>Future Gener Comput Syst</source>. <year>2019</year>;<volume>96</volume>(<issue>3</issue>):<fpage>481</fpage>&#x2013;<lpage>9</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2019.02.064</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Winanto</surname> <given-names>EA</given-names></string-name>, <string-name><surname>Idris</surname> <given-names>MY</given-names></string-name>, <string-name><surname>Stiawan</surname> <given-names>D</given-names></string-name>, <string-name><surname>Nurfatih</surname> <given-names>MS</given-names></string-name></person-group>. <article-title>Designing consensus algorithm for collaborative signature-based intrusion detection system</article-title>. <source>Indones J Electr Eng Comput Sci</source>. <year>2021</year>;<volume>22</volume>(<issue>1</issue>):<fpage>485</fpage>&#x2013;<lpage>96</lpage>. doi:<pub-id pub-id-type="doi">10.11591/ijeecs.v22.i1.pp485-496</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abubakar</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Gilliard</surname> <given-names>E</given-names></string-name></person-group>. <article-title>An efficient blockchain-based approach to improve the accuracy of intrusion detection systems</article-title>. <source>Electron Lett</source>. <year>2023</year>;<volume>59</volume>(<issue>18</issue>):<fpage>e12888</fpage>. doi:<pub-id pub-id-type="doi">10.1049/ell2.12888</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kumar</surname> <given-names>M</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>AK</given-names></string-name></person-group>. <article-title>Distributed intrusion detection system using blockchain and cloud computing infrastructure</article-title>. In: <conf-name>2020 4th International Conference on Trends in Electronics and Informatics (ICOEI)(48184)</conf-name>; 2020 Jun 15&#x2013;17; Tirunelveli, India. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2020</year>. p. <fpage>248</fpage>&#x2013;<lpage>52</lpage>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sani</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Iranmanesh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Salarian</surname> <given-names>H</given-names></string-name>, <string-name><surname>Raad</surname> <given-names>R</given-names></string-name>, <string-name><surname>Jamalipour</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Bids: blockchain-enabled intrusion detection system in smart cities</article-title>. <source>IEEE Int Things Magaz</source>. <year>2024</year>;<volume>7</volume>(<issue>2</issue>):<fpage>107</fpage>&#x2013;<lpage>13</lpage>. doi:<pub-id pub-id-type="doi">10.1109/iotm.001.2300191</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abdel-Basset</surname> <given-names>M</given-names></string-name>, <string-name><surname>Moustafa</surname> <given-names>N</given-names></string-name>, <string-name><surname>Hawash</surname> <given-names>H</given-names></string-name>, <string-name><surname>Razzak</surname> <given-names>I</given-names></string-name>, <string-name><surname>Sallam</surname> <given-names>KM</given-names></string-name>, <string-name><surname>Elkomy</surname> <given-names>OM</given-names></string-name></person-group>. <article-title>Federated intrusion detection in blockchain-based smart transportation systems</article-title>. <source>IEEE Trans Intell Transp Syst</source>. <year>2021</year>;<volume>23</volume>(<issue>3</issue>):<fpage>2523</fpage>&#x2013;<lpage>37</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tits.2021.3119968</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Krishna</surname> <given-names>AM</given-names></string-name>, <string-name><surname>Tyagi</surname> <given-names>AK</given-names></string-name></person-group>. <article-title>Intrusion detection in intelligent transportation system and its applications using blockchain technology</article-title>. In: <conf-name>2020 International Conference on Emerging Trends in Information Technology and Engineering (IC-ETITE)</conf-name>; 2020 Feb 24&#x2013;25; Vellore, India. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2020</year>. p. <fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ajayi</surname> <given-names>O</given-names></string-name>, <string-name><surname>Cherian</surname> <given-names>M</given-names></string-name>, <string-name><surname>Saadawi</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Secured cyberattack signatures distribution using blockchain technology</article-title>. In: <conf-name>2019 IEEE International Conference on Computational Science and Engineering (CSE) and IEEE International Conference on Embedded and Ubiquitous Computing (EUC)</conf-name>; <year>2019 Aug 1&#x2013;3</year>; <publisher-loc>New York, NY, USA</publisher-loc>. p. <fpage>482</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Golomb</surname> <given-names>T</given-names></string-name>, <string-name><surname>Mirsky</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Elovici</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Ciota: collaborative iot anomaly detection via blockchain</article-title>. <comment>arXiv:1803.03807. 2018</comment>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Signorini</surname> <given-names>M</given-names></string-name>, <string-name><surname>Pontecorvi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Kanoun</surname> <given-names>W</given-names></string-name>, <string-name><surname>Di Pietro</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Bad: a blockchain anomaly detection solution</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>173481</fpage>&#x2013;<lpage>90</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.3025622</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Kolokotronis</surname> <given-names>N</given-names></string-name>, <string-name><surname>Brotsis</surname> <given-names>S</given-names></string-name>, <string-name><surname>Germanos</surname> <given-names>G</given-names></string-name>, <string-name><surname>Vassilakis</surname> <given-names>C</given-names></string-name>, <string-name><surname>Shiaeles</surname> <given-names>S</given-names></string-name></person-group>. <chapter-title>On blockchain architectures for trust-based collaborative intrusion detection</chapter-title>. In: <source>2019 IEEE world congress on services (SERVICES)</source>; 2019 Jul 8&#x2013;13; Milan, Italy. Vol. <volume>2642</volume>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2019</year>. p. <fpage>21</fpage>&#x2013;<lpage>8</lpage>. doi: <pub-id pub-id-type="doi">10.1109/services.2019.00019</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Alexopoulos</surname> <given-names>N</given-names></string-name>, <string-name><surname>Vasilomanolakis</surname> <given-names>E</given-names></string-name>, <string-name><surname>Iv&#x00E1;nk&#x00F3;</surname> <given-names>NR</given-names></string-name>, <string-name><surname>M&#x00FC;hlh&#x00E4;user</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Towards blockchain-based collaborative intrusion detection systems</article-title>. In: <conf-name>Critical Information Infrastructures Security: 12th International Conference, CRITIS 2017; 2017 Oct 8&#x2013;13</conf-name>; <publisher-loc>Lucca, Italy. Cham, Switzerland</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2018</year>. p. <fpage>107</fpage>&#x2013;<lpage>18</lpage>.</mixed-citation></ref>
</ref-list>
</back></article>