<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JCC</journal-id><journal-title-group><journal-title>Journal of Computer and Communications</journal-title></journal-title-group><issn pub-type="epub">2327-5219</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jcc.2022.1010010</article-id><article-id pub-id-type="publisher-id">JCC-120825</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Preventing Phishing Attack on Voting System Using Visual Cryptography
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Ahood</surname><given-names>Alotaibi</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Lama</surname><given-names>Alhubaidi</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Alghala</surname><given-names>Alyami</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Leena</surname><given-names>Marghalani</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Bashayer</surname><given-names>Alharbi</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Naya</surname><given-names>Nagy</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>College of Cybersecurity and Digital Forensics, Imam Abdulrahman Bin Faisal University, Dammam, Saudi Arabia</addr-line></aff><aff id="aff2"><addr-line>College of Computer Science and Information Technology, Imam Abdulrahman Bin Faisal University, Dammam, Saudi Arabia</addr-line></aff><pub-date pub-type="epub"><day>13</day><month>10</month><year>2022</year></pub-date><volume>10</volume><issue>10</issue><fpage>149</fpage><lpage>161</lpage><history><date date-type="received"><day>24,</day>	<month>May</month>	<year>2022</year></date><date date-type="rev-recd"><day>28,</day>	<month>October</month>	<year>2022</year>	</date><date date-type="accepted"><day>31,</day>	<month>October</month>	<year>2022</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  Phishing is one of the most common social engineering attacks that users over the internet fall for. An example is voting systems, and because such systems should be accurate and error free, phishing prevention techniques are crucial. Visual Cryptography (VC) is utilized for efficient voting system authentication to cast votes. VC is one of the most secure approaches for privacy protection as it ensures the confidentiality of the voting system. This paper discusses proposed phishing prevention methods and compares different proposed methods.
 
</p></abstract><kwd-group><kwd>Remote Voting System (RVS)</kwd><kwd> Voting System (VS)</kwd><kwd> Shares</kwd><kwd> Ballots</kwd><kwd>  Authentication</kwd><kwd> Visual Cryptography</kwd><kwd> Phishing</kwd><kwd> Captcha</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Elections are held around the world, citizens in democratic countries have the power to elect a representative for their party to settle things in a democratic way. However, voters must cast their ballots at a polling location. Area elections are held for the government. To vote, the voter must be present at the polling station. This may weaken voter support, so, web-based voting makes this process easier. Electronic voting systems offer various features that make them different from traditional voting methods, as they also enhanced voting system features over traditional voting methods including mobility, privacy, simplicity, accuracy, and adaptability. On the other hand, voting systems might be exposed to a new threat like phishing which affects the system security. When fraudsters gain your personal information, they can use it to commit various types of identity fraud, jeopardizing voters’ reputation. Having a secure and reliable voting system, cryptographic and steganographic techniques should be applied. One of the suggested solutions is VC. Systems are used to safeguard information from hackers. It’s a mechanism for encrypting visual data that can be decrypted by the human visual system without the use of computers.</p></sec><sec id="s2"><title>2. Background</title><p>Network security is critical in ensuring that enterprises are adequately protected from outside threats and adversaries. System administrators monitor network security, which involves the authorization of access to data on the network. However, different types of threats can be found in networks as described in [<xref ref-type="bibr" rid="scirp.120825-ref1">1</xref>]. For instance, password attacks, IP spoofing, and most notably phishing it is a malicious attempt to obtain personal information such as usernames, passwords, and credit card numbers by impersonating a trustworthy entity. They are seen as a significant risk since they can disrupt a corporate system and result in massive losses. Phishing is one of the most cyber attacks to gain popularity. It is an aim towards identity theft to obtain confidential and private information about individuals or companies in exchange for money or other advantages. In the meanwhile, <xref ref-type="fig" rid="fig1">Figure 1</xref> below demonstrates the various types of voting systems.</p></sec><sec id="s3"><title>3. Proposed Methods</title><sec id="s3_1"><title>3.1. MSE and PSNR Method</title><p>The paper [<xref ref-type="bibr" rid="scirp.120825-ref2">2</xref>], discusses about authentication of voters in a Remote Voting System (RVS), a new VC scheme is suggested. The current technique, unlike classical VC, is based on the creation of a new matrix utilizing the bitwise XOR operation. Because it uses structural similarity measures like Peak Signal to Noise Ratio (PSNR) and Mean Square Error (MSE) for verification, this authentication system is ideal for RVS. The experimental results show that the suggested approach is computationally efficient and achieves a decent balance of security, storage, and performance.</p><p>Proposed Steps:</p><p>1) Matrices Creation: The suggested scheme is not intended to be expandable. As a result, one row of the C0 is randomly chosen to encode a white pixel, and one row of the C1 is randomly chosen to encode a black pixel. Then, for each row, one element will is assigned to one share and the other to another. Furthermore, the Hamming weight H = two and the pixel expansion m equals one.</p><p>2) Shares Generation Phase: If the pixel color is white, choose one block at random from the two blocks in the codebook that are peer to the white pixel shown in <xref ref-type="fig" rid="fig2">Figure 2</xref>, assign one element to share 1 and the other element to share 2. If the pixel is black, choose one block at random, repeat the process that peer to the black pixel shown in <xref ref-type="fig" rid="fig2">Figure 2</xref>. When every pixel of the secret image is scanned, the two shared images will be created.</p><p>3) Recovery Phase: The original secret image is recovered by stacking the shared images using the bitwise XOR method, as shown in <xref ref-type="fig" rid="fig3">Figure 3</xref>.</p><p>Advantages and Results Analysis:</p><p>- Because the reconstructed images are the same size as the original secret image, the pixel expansion equals one.</p><p>- As a result, it saves voters’ and servers’ storage space and allows for quick transmission through public networks, and other communication channels.</p><p>- The image created by stacking the shared photographs is accurate and has no information loss. The PSNR and MSE are mathematically expressed in <xref ref-type="fig" rid="fig4">Figure 4</xref>.</p><p>- Lower variance between the secret image and the reconstructed image with good visual quality is indicated by a greater PSNR and lower MSE. When the PSNR value is equal to and the MSE is zero, the technique gives the best visual quality possible, with no discernible difference between the recovered image and the original secret image.</p><p>- <xref ref-type="fig" rid="fig5">Figure 5</xref> demonstrates the MSE and PSNR values obtained between the original and recovered images for two voters: voter 1 provided the original share, whereas voter 2 submitted a suspected share. These findings show the present scheme’s efficiency and effectiveness by approaching typical MSE and PSNR values. As a result, it is an appropriate strategy for RVS authentication.</p><p>As a result, the proposed method could cut operational costs and time while still fulfilling the security requirements for high-performance RVSs.</p></sec><sec id="s3_2"><title>3.2. Pixel Shuffling Method</title><p>Paper [<xref ref-type="bibr" rid="scirp.120825-ref3">3</xref>] discussed VC techniques that are used for privacy protection. By implementing a cryptographic encryption methodology utilizing pixel shuffling with interchanging their location to generate the ciphered image, it would make it difficult to decipher the image without prior knowledge of the algorithm and the secret key used.</p><sec id="s3_2_1"><title>3.2.1. Error Diffusion Technique</title><p>The quantization error of each pixel is filtered and sent back to a group of upcoming input samples. The output quantized pixel value is the sum of the input</p><p>pixel value and the “diffused” past errors, as shown in <xref ref-type="fig" rid="fig6">Figure 6</xref>. 1’s binary error diffusion diagram. The error filter in <xref ref-type="fig" rid="fig6">Figure 6</xref> filters the error to give us the original image. In the error diffusion approach, the erroneous value is spread on a fractional basis to neighboring pixels in this case the error is calculated and added to the pixel to the right of the currently processed pixel The suggested VC privacy scheme uses the error diffusion technique to simply spread the error values across neighboring pixels.</p></sec><sec id="s3_2_2"><title>3.2.2. Expansion Less Share Technique</title><p>Secret data is divided into two components known as shares in VC. The original secret is revealed by stacking these two shares together using a logical XOR function. Hierarchical VC, on the other hand, encrypts the secret at multiple levels. As a result, the encryption is less expandable. The initial secret size is preserved at all levels of the shares. Secret information is encrypted at two levels in this method. Four shares are created using hierarchical VC, and three shares will be combined to make the key share. Implementing hierarchical VC, first the secret is encrypted with expansion ratio 1:2, resulting in two shares S1 and S2. If both shares are independently encrypted with the same expansion ratio, the resulting four shares will be expanded from the shares S1, and S2.</p></sec><sec id="s3_2_3"><title>3.2.3. Image Captcha Base Authentication Technique</title><p>For the anti-phishing there are two phases:</p><p>1) Registration: During the registration process, the user enters a key, as well as the server, then a captcha image is generated. The image has been separated into two pieces that, when put together, should restore the original captcha. Flow is shown in <xref ref-type="fig" rid="fig7">Figure 7</xref>.</p><p>2) Authentication: Actual authentication takes place at the login step as shown in <xref ref-type="fig" rid="fig8">Figure 8</xref>. The authentication process is designed to detect phishing attacks of any form.</p></sec></sec><sec id="s3_3"><title>3.3. CAPTCHA and Image as Share Based Online Voting System Method</title><p>The authors of paper [<xref ref-type="bibr" rid="scirp.120825-ref4">4</xref>] developed an online voting system for an Indian association named “Maharashtra Carrom”. The system incorporates both a CAPTCHA</p><p>code and split-image in-share technology, as well as anonymous voting to guarantee private and secure voting process. VC is a safe method that divides a secret image into small fragments. Using two-out-of-two VC, authors propose an Internet voting system, in which users provide a secret image as a password, which is then split into two shares. One share is sent to each user’s email address as a password via VC, while the other is saved on the server. As illustrated in <xref ref-type="fig" rid="fig9">Figure 9</xref>, when users log in, they are asked to enter the share password they received through email therefore the system will add share 2, and if the password is correct, a CAPTCHA code will be generated and displayed.</p><p>The CAPTCHA code is the image converted into black and white then it will be split into shares. Each share is composed of equal numbers of black and white</p><p>pixels. The shares will be merged at the time of voting, and the CAPTCHA will appear if the user is legitimate. Voters determined to be malicious will not be allowed to cast their votes, and the system will immediately log them out. Although the authors claim that using their proposed system will result in making people’s life easier, the system not yet been implemented.</p></sec><sec id="s3_4"><title>3.4. E-Ballot and Image as Share Method</title><p>This paper [<xref ref-type="bibr" rid="scirp.120825-ref5">5</xref>] addresses that the voters can vote only if they login to the system with the correct credentials. Share 1 is sent to the voter’s e-mail address before the election and share 2 is provided in the system for the login process throughout the election. Voters will obtain the password to submit their vote by joining share 1 and share 2 using VC. To perform the required services as proposed in the system design stages by [<xref ref-type="bibr" rid="scirp.120825-ref5">5</xref>], the browser must communicate with the HTTP server. Then for users to submit their votes, an e-ballot (gadget used to cast votes in an election) is generated through steganography. The vote is casted using a database server and then encrypted via VC at the application server.</p></sec><sec id="s3_5"><title>3.5. Web Browser and Email Oriented Share Method</title><p>In the proposed system of [<xref ref-type="bibr" rid="scirp.120825-ref6">6</xref>] a connection between the client and server must be established using an algorithm such as in <xref ref-type="fig" rid="fig1">Figure 1</xref>0.</p><p>Afterwards the needed information, such as email address is obtained from the user on the registration page. Then an image is sent to the user to start the subsequent level of the process shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>1.</p><p>It highlights the utilization of VC algorithm to verify, authorize and authenticate user credentials to allow the user to cast their vote. The authors [<xref ref-type="bibr" rid="scirp.120825-ref6">6</xref>] suggested five working modules: initializing the server, sharing password, authenticating, casting the vote, and analyzing the result. The responsible party of the elections must submit the name of the nominees to the host, then the server system will initiate and receives votes. An email attached with a visual key share is sent to the user, while the other share is saved in the database. Authenticating</p><p>the sent visual key share with the one stored in the database is done by cross referencing via the server, which produces an image that must be inserted in the prompted page in <xref ref-type="fig" rid="fig1">Figure 1</xref>2.</p><p>If the user is authenticated, they can progress to casting the vote without a chance of forgery. Also, analysis of election results is possible through the server end. This proposed system implements a combination of client, server, database, and cryptography method to ensure security and integrity as illustrated in <xref ref-type="fig" rid="fig1">Figure 1</xref>3. The aspect of receiving the needed share through email is what makes this method suitable for preventing phishing attacks.</p></sec><sec id="s3_6"><title>3.6. Combining Multi-Party Computation in Share Authentication</title><p>The proposed system aims to guarantee legitimacy, security, and confidentiality of votes casted by users. It is possible by combining biometric information in a multi-party computation, physical characteristics used to assure the identity of a person through electronic devices, with VC [<xref ref-type="bibr" rid="scirp.120825-ref7">7</xref>]. The system takes advantage of multi-party computation features to tally votes. There are four modules in the proposed system that consists of: voter registration, authentication, vote cast and record, and vote count and announcement of the result. In the registration module the algorithm in <xref ref-type="fig" rid="fig1">Figure 1</xref>4 is used for the authentication and enrollment of vote, which each voter must scan their fingerprint before casting a vote. One</p><p>of the shares that contains the biometric minutia is saved in the Voter Identification Card (VIC), while the other is stored in the database. The VIC contains private information belonging to the voter to be used for voting authentication, it serves as a sufficient method for both security and convenience.</p><p>The two shares are reassembled to produce the original fingerprint image, which is used to compare with a new fingerprint image obtained from a scanner. If there is a match the voter is legitimate, therefore allowed to vote as in <xref ref-type="fig" rid="fig1">Figure 1</xref>5.</p><p>There will be a voting machine with buttons to record the votes for each nominee, each press by the user generated a signal in binary. However, storing the vote directly in this form is insecure and a new system is proposed by the authors [<xref ref-type="bibr" rid="scirp.120825-ref8">8</xref>] to be more secure. Where “D” is a number greater than sum of number of voters, and “n” is the number of candidates. Let (Rl*d), (l + R2*d), (R3*d),&#183;&#183;&#183;, and (Rn*D). The database would look like that in <xref ref-type="fig" rid="fig1">Figure 1</xref>6, and each column symbolizes a vote for each nominee.</p></sec><sec id="s3_7"><title>3.7. Discussion and Analysis</title><p>Phishing is a prevalent attack targeted on voters using e-voting systems, the severity of damages done by it calls for the use of secure schemes. Due to its importance, several proposed systems were published in the past decade. Most of the methodologies adopted VC as an integral part of its system in addition to some improvements, such as in paper [<xref ref-type="bibr" rid="scirp.120825-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.120825-ref3">3</xref>] [<xref ref-type="bibr" rid="scirp.120825-ref5">5</xref>] [<xref ref-type="bibr" rid="scirp.120825-ref6">6</xref>] [<xref ref-type="bibr" rid="scirp.120825-ref8">8</xref>]. In paper [<xref ref-type="bibr" rid="scirp.120825-ref2">2</xref>] and [<xref ref-type="bibr" rid="scirp.120825-ref8">8</xref>] a variation of an XOR algorithm was used for verification, which can benefit e-voting systems. However, it can be easily bypassed with proper knowledge. Whereas papers [<xref ref-type="bibr" rid="scirp.120825-ref5">5</xref>] and [<xref ref-type="bibr" rid="scirp.120825-ref6">6</xref>] adopted basic VC schemes, along with email authentication. Implementing a simple combination of authentication methods could pose to be a tremendous security disadvantage. In case the database that stores the image shares becomes compromised, a malicious entity could deceive the authentication. The vantage point in paper [<xref ref-type="bibr" rid="scirp.120825-ref8">8</xref>] pairing fingerprint scanners in the process of registration and authentication for e-voting. This method ensures a lower chance of false authentication, which is an improved security mechanism. As for paper [<xref ref-type="bibr" rid="scirp.120825-ref3">3</xref>] it implemented three VC schemes with two of them discussed anti-phishing in particular expansion less share, and image captcha base authentication.</p></sec></sec><sec id="s4"><title>4. Conclusion</title><p>In conclusion, the suggested methods of all the discussed papers focused on visual cryptography techniques for privacy protection and user validation. With the help of such schemes, it is possible to conduct election processes confidentially with the highest accuracy to reduce the risk of falsification on e-voting systems. The applicability, cost-efficiency, improved performance, and security of visual cryptographic methods is what distinguishes it from other approaches. In the examined methods it was apparent VC could be enhanced by pairing it with other authentication means such as biometric devices, error diffusion scheme, image CAPTCHA, and expansion less share. In despite of the efficiency and convenience of e-voting systems, it has still not been embraced internationally. We suggest for future works that an e-voting system framework should combine a variance of biometric authentication, image CAPTCHA, and an adequate security system for databases or data centers that store essential image shares for the processes.</p></sec><sec id="s5"><title>Conflicts of Interest</title><p>The authors declare no conflicts of interest regarding the publication of this paper.</p></sec><sec id="s6"><title>Cite this paper</title><p>Alotaibi, A., Alhubaidi, L., Alyami, A., Marghalani, L., Alharbi, B. and Nagy, N. (2022) Preventing Phishing Attack on Voting System Using Visual Cryptography. Journal of Computer and Communications, 10, 149-161. https://doi.org/10.4236/jcc.2022.1010010</p></sec></body><back><ref-list><title>References</title><ref id="scirp.120825-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Nisha, S. and Madheswari, A.N. (2016) Prevention of Phishing Attacks in Voting System Using Visual Cryptography. 2016 International Conference on Emerging Trends in Engineering, Technology and Science (ICETETS), Pudukkottai, 24-26 February 2016, 1-4. https://doi.org/10.1109/ICETETS.2016.7603013</mixed-citation></ref><ref id="scirp.120825-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Hodeish, M. and Humbe, V. (2017) A New XOR-Based Visual Cryptography Scheme for Authentic Remote Voting System. https://api.semanticscholar.org/CorpusID:53470499</mixed-citation></ref><ref id="scirp.120825-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Nayan, A. and Ardak, P. (2022) Visual Cryptography Scheme for Privacy Protection. https://ijcsit.com/docs/Volume%205/vol5issue02/ijcsit20140502239.pdf</mixed-citation></ref><ref id="scirp.120825-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Rane, S.S., AdwaitPhansalkar, K., Shinde, M.Y. and Kazi, A. (2020) Avoiding Phishing Attack on Online Voting System Using Visual Cryptography. 2020 International Conference on Computer Communication and Informatics (ICCCI), Coimbatore, 22-24 January 2020, 1-4. https://doi.org/10.1109/ICCCI48352.2020.9104071</mixed-citation></ref><ref id="scirp.120825-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Singh, A., Nandini, S., Pawana, S., Supriya, C. and Biswagar, D. (2021) Prevention of Phishing Attacks on Online Voting Using Visual Cryptography. Journal of University of Shanghai for Science and Technology, 23, 246-249. https://jusst.org/wp-content/uploads/2021/06/Prevention-of-Phishing-Attacks-on-Online-Voting-using-Visual-Cryptography.pdf</mixed-citation></ref><ref id="scirp.120825-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Tiwari, M.G.D. and Kakelli, A.K. (2021) Secure Online Voting System Using Visual Cryptography. Walailak Journal of Science and Technology, 18. https://doi.org/10.48048/wjst.2021.8972</mixed-citation></ref><ref id="scirp.120825-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Walake, A. and Chavan, P. (2015) Efficient Voting System with (2, 2) Secret Sharing Based Authentication. IJCSIT, 6, 3739-3743.</mixed-citation></ref><ref id="scirp.120825-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Naidu, P.S., Kharat, R., Tekade, R., Mendhe, P. and Magade, V. (2016) E-Voting System Using Visual Cryptography &amp; Secure Multi-Party Computation. 2016 International Conference on Computing Communication Control and Automation (ICCUBEA), Pune, 12-13 August 2016, 1-4. https://doi.org/10.1109/ICCUBEA.2016.7860062</mixed-citation></ref></ref-list></back></article>