{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T00:47:32Z","timestamp":1780447652818,"version":"3.54.1"},"reference-count":60,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2022,3,16]],"date-time":"2022-03-16T00:00:00Z","timestamp":1647388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100012639","name":"Prince Sultan University","doi-asserted-by":"publisher","award":["SEED-CCIS-2021-84"],"award-info":[{"award-number":["SEED-CCIS-2021-84"]}],"id":[{"id":"10.13039\/501100012639","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Steganography is a vital security approach that hides any secret content within ordinary data, such as multimedia. This hiding aims to achieve the confidentiality of the IoT secret data; whether it is benign or malicious (e.g., ransomware) and for defensive or offensive purposes. This paper introduces a hybrid crypto-steganography approach for ransomware hiding within high-resolution video frames. This proposed approach is based on hybridizing an AES (advanced encryption standard) algorithm and LSB (least significant bit) steganography process. Initially, AES encrypts the secret Android ransomware data, and then LSB embeds it based on random selection criteria for the cover video pixels. This research examined broad objective and subjective quality assessment metrics to evaluate the performance of the proposed hybrid approach. We used different sizes of ransomware samples and different resolutions of HEVC (high-efficiency video coding) frames to conduct simulation experiments and comparison studies. The assessment results prove the superior efficiency of the introduced hybrid crypto-steganography approach compared to other existing steganography approaches in terms of (a) achieving the integrity of the secret ransomware data, (b) ensuring higher imperceptibility of stego video frames, (3) introducing a multi-level security approach using the AES encryption in addition to the LSB steganography, (4) performing randomness embedding based on RPS (random pixel selection) for concealing secret ransomware bits, (5) succeeding in fully extracting the ransomware data at the receiver side, (6) obtaining strong subjective and objective qualities for all tested evaluation metrics, (7) embedding different sizes of secret data at the same time within the video frame, and finally (8) passing the security scanning tests of 70 antivirus engines without detecting the existence of the embedded ransomware.<\/jats:p>","DOI":"10.3390\/s22062281","type":"journal-article","created":{"date-parts":[[2022,3,16]],"date-time":"2022-03-16T03:36:23Z","timestamp":1647401783000},"page":"2281","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":25,"title":["A Crypto-Steganography Approach for Hiding Ransomware within HEVC Streams in Android IoT Devices"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4639-516X","authenticated-orcid":false,"given":"Iman","family":"Almomani","sequence":"first","affiliation":[{"name":"Security Engineering Lab, Computer Science Department, Prince Sultan University, Riyadh 11586, Saudi Arabia"},{"name":"Computer Science Department, King Abdullah II School of Information Technology, The University of Jordan, Amman 11942, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7685-2689","authenticated-orcid":false,"given":"Aala","family":"Alkhayer","sequence":"additional","affiliation":[{"name":"Security Engineering Lab, Computer Science Department, Prince Sultan University, Riyadh 11586, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7509-2120","authenticated-orcid":false,"given":"Walid","family":"El-Shafai","sequence":"additional","affiliation":[{"name":"Security Engineering Lab, Computer Science Department, Prince Sultan University, Riyadh 11586, Saudi Arabia"},{"name":"Department of Electronics and Electrical Communications Engineering, Faculty of Electronic Engineering, Menoufia University, Menouf 32952, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,3,16]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"125","DOI":"10.1016\/j.comcom.2020.02.078","article-title":"Towards predictive analysis of android vulnerability using statistical codes and machine learning for IoT applications","volume":"155","author":"Cui","year":"2020","journal-title":"Comput. Commun."},{"key":"ref_2","unstructured":"Kumar, R., Wang, W., Kumar, J., Yang, T., Ali, W., and Sharif, A. (2021). IoTMalware: Android IoT Malware Detection based on Deep Neural Network and Blockchain Technology. arXiv."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Oz, H., Aris, A., Levi, A., and Uluagac, A.S. (2021). A Survey on Ransomware: Evolution, Taxonomy, and Defense Solutions. arXiv.","DOI":"10.1145\/3514229"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"20381","DOI":"10.1109\/ACCESS.2018.2888568","article-title":"Detecting Android locker-ransomware on chinese social networks","volume":"7","author":"Su","year":"2018","journal-title":"IEEE Access"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"57674","DOI":"10.1109\/ACCESS.2021.3071450","article-title":"Android Ransomware Detection Based on a Hybrid Evolutionary Approach in the Context of Highly Imbalanced Data","volume":"9","author":"Almomani","year":"2021","journal-title":"IEEE Access"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Alsoghyer, S., and Almomani, I. (2020, January 4\u20135). On the effectiveness of application permissions for Android ransomware detection. Proceedings of the 2020 6th Conference on Data Science and Machine Learning Applications (CDMA), Riyadh, Saudi Arabia.","DOI":"10.1109\/CDMA47397.2020.00022"},{"key":"ref_7","first-page":"29","article-title":"Machine Learning for Android Ransomware Detection","volume":"19","author":"Bagui","year":"2021","journal-title":"Int. J. Comput. Sci. Inf. Secur. (IJCSIS)"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Alsoghyer, S., and Almomani, I. (2019). Ransomware detection system for Android applications. Electronics, 8.","DOI":"10.3390\/electronics8080868"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"100365","DOI":"10.1016\/j.cosrev.2021.100365","article-title":"A survey of android application and malware hardening","volume":"39","author":"Sihag","year":"2021","journal-title":"Comput. Sci. Rev."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1109\/MITP.2018.032501746","article-title":"The new threats of information hiding: The road ahead","volume":"20","author":"Cabaj","year":"2018","journal-title":"IT Prof."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1649","DOI":"10.1109\/TCSVT.2012.2221191","article-title":"Overview of the high efficiency video coding (HEVC) standard","volume":"22","author":"Sullivan","year":"2012","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"4789","DOI":"10.1007\/s11042-020-09881-8","article-title":"Efficient HEVC steganography approach based on audio compression and encryption in QFFT domain for secure multimedia communication","volume":"80","author":"Soliman","year":"2021","journal-title":"Multimed. Tools Appl."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.jnca.2019.02.023","article-title":"SmartEdge: An end-to-end encryption framework for an edge-enabled smart city application","volume":"137","author":"Jan","year":"2019","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Hameed, A., and Alomary, A. (2019, January 22\u201323). Security Issues in IoT: A Survey. Proceedings of the 2019 International Conference on Innovation and Intelligence for Informatics, Computing, and Technologies (3ICT), Sakhier, Bahrain.","DOI":"10.1109\/3ICT.2019.8910320"},{"key":"ref_15","first-page":"153","article-title":"Design and implementation of power and area optimized AES architecture on FPGA for IoT application","volume":"47","author":"Rajasekar","year":"2020","journal-title":"Circuit World"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Ruby, A.M., Soliman, S.M., and Mostafa, H. (2020, January 12\u201314). Dynamically Reconfigurable Resource Efficient AES Implementation for IoT Applications. Proceedings of the 2020 IEEE International Symposium on Circuits and Systems (ISCAS), Seville, Spain.","DOI":"10.1109\/ISCAS45731.2020.9181276"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Harcha, G., Lap\u00f4tre, V., Chavet, C., and Coussy, P. (2020, January 12\u201314). Toward Secured IoT Devices: A Shuffled 8-Bit AES Hardware Implementation. Proceedings of the 2020 IEEE International Symposium on Circuits and Systems (ISCAS), Seville, Spain.","DOI":"10.1109\/ISCAS45731.2020.9180599"},{"key":"ref_18","unstructured":"Dworkin, M.J., Barker, E.B., Nechvatal, J.R., Foti, J., Bassham, L.E., Roback, E., and Dray, J.F. (2001). Advanced Encryption Standard (AES), National Institute of Standards and Technology. Federal Inf. Process. Stds. (NIST FIPS)."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"3531","DOI":"10.1007\/s13369-020-05187-x","article-title":"SEM: Stacking Ensemble Meta-Learning for IOT Security Framework","volume":"46","author":"Mishra","year":"2021","journal-title":"Arab. J. Sci. Eng."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Almomani, I., AlKhayer, A., and Ahmed, M. (2021, January 6\u20137). An Efficient Machine Learning-based Approach for Android v. 11 Ransomware Detection. Proceedings of the 2021 1st International Conference on Artificial Intelligence and Data Analytics (CAIDA), Riyadh, Saudi Arabia.","DOI":"10.1109\/CAIDA51941.2021.9425059"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"102098","DOI":"10.1016\/j.adhoc.2020.102098","article-title":"End-to-end malware detection for android IoT devices using deep learning","volume":"101","author":"Ren","year":"2020","journal-title":"Ad Hoc Netw."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Kumar, R., Zhang, X., Khan, R.U., and Sharif, A. (2019). Research on data mining of permission-induced risk for android IoT devices. Appl. Sci., 9.","DOI":"10.3390\/app9020277"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"6668","DOI":"10.1109\/JIOT.2019.2909745","article-title":"EveDroid: Event-aware Android malware detection against model degrading for IoT devices","volume":"6","author":"Lei","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Liu, X., Du, X., Zhang, X., Zhu, Q., Wang, H., and Guizani, M. (2019). Adversarial samples on android malware detection systems for IoT systems. Sensors, 19.","DOI":"10.3390\/s19040974"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"64411","DOI":"10.1109\/ACCESS.2019.2916886","article-title":"A multimodal malware detection technique for Android IoT devices using various features","volume":"7","author":"Kumar","year":"2019","journal-title":"IEEE Access"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Abawajy, J., Darem, A., and Alhashmi, A.A. (2021). Feature Subset Selection for Malware Detection in Smart IoT Platforms. Sensors, 21.","DOI":"10.3390\/s21041374"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"1141","DOI":"10.1007\/s12652-017-0558-5","article-title":"Detecting crypto-ransomware in IoT networks based on energy consumption footprint","volume":"9","author":"Azmoodeh","year":"2018","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Kaushik, M., Malik, M., and Narwal, B. (2020, January 6\u20138). Developing Malware and Analyzing it Afore & After Steganography with OSINTs. Proceedings of the 2020 IEEE International Conference for Innovation in Technology (INOCON), Bangluru, India.","DOI":"10.1109\/INOCON50539.2020.9298288"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"125345","DOI":"10.1109\/ACCESS.2020.3007577","article-title":"GAN Tunnel: Network Traffic Steganography by Using GANs to Counter Internet Traffic Classifiers","volume":"8","year":"2020","journal-title":"IEEE Access"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"B\u0105k, P., Bieniasz, J., Krzemi\u0144ski, M., and Szczypiorski, K. (2018, January 24\u201327). Application of perfectly undetectable network steganography method for malware hidden communication. Proceedings of the 2018 4th International Conference on Frontiers of Signal Processing (ICFSP), Poitiers, France.","DOI":"10.1109\/ICFSP.2018.8552057"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Alexan, W., Elkhateeb, A., Mamdouh, E., Al-Seba\u2019Ey, F., Amr, Z., and Khalil, H. (2021, January 19\u201322). Utilization of Corner Filters, AES and LSB Steganography for Secure Message Transmission. Proceedings of the 2021 International Conference on Microelectronics (ICM), New Cairo City, Egypt.","DOI":"10.1109\/ICM52667.2021.9664947"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"1417","DOI":"10.12928\/telkomnika.v17i3.9513","article-title":"Optimization of video steganography with additional compression and encryption","volume":"17","author":"Arraziqi","year":"2019","journal-title":"Telkomnika"},{"key":"ref_33","unstructured":"Meng, L., Jiang, X., Zhang, Z., Li, Z., and Sun, T. (2020). Coverless Video Steganography based on Maximum DC Coefficients. arXiv."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"75","DOI":"10.1007\/s11554-016-0630-y","article-title":"Sequential multiple LSB methods and real-time data hiding: Variations for visual cryptography ciphers","volume":"14","author":"Papadopoulos","year":"2018","journal-title":"J. Real-Time Image Process."},{"key":"ref_35","first-page":"1957","article-title":"IoT Contact: A Strategy for Predicting Contagious IoT Nodes in Mitigating Ransomware Attacks","volume":"12","author":"Ibrahim","year":"2021","journal-title":"Turk. J. Comput. Math. Educ. Vol."},{"key":"ref_36","unstructured":"Alzahrani, A., Alshehri, A., Alshahrani, H., and Fu, H. (2020). Ransomware in Windows and Android Platforms. arXiv."},{"key":"ref_37","unstructured":"Nassi, B., Shamir, A., and Elovici, Y. (2017). Oops!\u2026I think I scanned a malware. arXiv."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Mandal, B., Pradhan, A., and Swain, G. (2019, January 23\u201325). Adaptive LSB substitution steganography technique based on PVD. Proceedings of the 2019 3rd International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India.","DOI":"10.1109\/ICOEI.2019.8862579"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Alfa, A.A., Ahmed, K.B., Misra, S., Dhawale, C., and Ahuja, R. (2021). A CRT-LZW-Based Compression of Multiple and Large Size Images for Clustered Embedding in Image Cover. Soft Computing for Problem Solving, Springer.","DOI":"10.1007\/978-981-16-2709-5_45"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Soni, T., Baird, R., Lobo, A., and Heydari, V. (2020). Using Least-Significant Bit and Random Pixel Encoding with Encryption for Image Steganography. National Cyber Summit, Springer.","DOI":"10.1007\/978-3-030-58703-1_9"},{"key":"ref_41","first-page":"706","article-title":"Bit-error-rate (BER) simulation using MATLAB","volume":"3","author":"Ali","year":"2013","journal-title":"Int. J. Eng. Res. Appl."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Krig, S. (2014). Computer Vision Metrics: Survey, Taxonomy, and Analysis, Springer Nature.","DOI":"10.1007\/978-1-4302-5930-5"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1007\/s11277-017-4503-x","article-title":"Enhancement of wireless 3d video communication using color-plus-depth error restoration algorithms and Bayesian Kalman filtering","volume":"97","year":"2017","journal-title":"Wirel. Pers. Commun."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"4810","DOI":"10.1007\/s00034-018-0786-8","article-title":"Recursive Bayesian filtering-based error concealment scheme for 3D video communication over severely lossy wireless channels","volume":"37","year":"2018","journal-title":"Circuits Syst. Signal Process."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Mitsa, T., and Varkur, K.L. (1993, January 27\u201330). Evaluation of contrast sensitivity functions for the formulation of quality measures incorporated in halftoning algorithms. Proceedings of the 1993 IEEE International Conference on Acoustics, Speech, and Signal Processing, Minneapolis, MN, USA.","DOI":"10.1109\/ICASSP.1993.319807"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"636","DOI":"10.1109\/83.841940","article-title":"Image quality assessment based on a degradation model","volume":"9","author":"Kite","year":"2000","journal-title":"IEEE Trans. Image Process."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1064","DOI":"10.1109\/TMI.2019.2930338","article-title":"Comparison of objective image quality metrics to expert radiologists\u2019 scoring of diagnostic quality of MR images","volume":"39","author":"Mason","year":"2019","journal-title":"IEEE Trans. Med. Imaging"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Klette, R., Stiehl, H.S., Viergever, M.A., and Vincken, K.L. (2000). Performance Characterization in Computer Vision, Springer.","DOI":"10.1007\/978-94-015-9538-4"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"27211","DOI":"10.1007\/s11042-019-7448-0","article-title":"Security of 3D-HEVC transmission based on fusion and watermarking techniques","volume":"78","year":"2019","journal-title":"Multimed. Tools Appl."},{"key":"ref_50","unstructured":"Wang, Z., Simoncelli, E.P., and Bovik, A.C. (2003, January 9\u201312). Multiscale structural similarity for image quality assessment. Proceedings of the Thrity-Seventh Asilomar Conference on Signals, Systems & Computers, Pacific Grove, CA, USA."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"2378","DOI":"10.1109\/TIP.2011.2109730","article-title":"FSIM: A feature similarity index for image quality assessment","volume":"20","author":"Zhang","year":"2011","journal-title":"IEEE Trans. Image Process."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"81","DOI":"10.1109\/97.995823","article-title":"A universal image quality index","volume":"9","author":"Wang","year":"2002","journal-title":"IEEE Signal Process. Lett."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"967","DOI":"10.1049\/iet-ipr.2016.1091","article-title":"Proposed adaptive joint error-resilience concealment algorithms for efficient colour-plus-depth 3D video transmission","volume":"12","year":"2018","journal-title":"IET Image Process."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Gokilavani, C., Rajeswaran, N., Karthick, V.A., Kumar, R.S., and Thangadurai, N. (2015, January 27). Comparative results performance analysis of various filters used to remove noises in retinal images. Proceedings of the 2015 Online International Conference on Green Engineering and Technologies (IC-GET), Coimbatore, India.","DOI":"10.1109\/GET.2015.7453859"},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"430","DOI":"10.1109\/TIP.2005.859378","article-title":"Image information and visual quality","volume":"15","author":"Sheikh","year":"2006","journal-title":"IEEE Trans. Image Process."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"35004","DOI":"10.1109\/ACCESS.2021.3062403","article-title":"Optical Bit-Plane-based 3D-JST Cryptography Algorithm with Cascaded 2D-FrFT Encryption for Efficient and Secure HEVC Communication","volume":"9","author":"Almomani","year":"2021","journal-title":"IEEE Access"},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"128548","DOI":"10.1109\/ACCESS.2020.3008644","article-title":"A Novel Hybrid Cryptosystem for Secure Streaming of High Efficiency H. 265 Compressed Videos in IoT Multimedia Applications","volume":"8","author":"Alarifi","year":"2020","journal-title":"IEEE Access"},{"key":"ref_58","first-page":"1209","article-title":"Novel Ransomware Hiding Model Using HEVC Steganography Approach","volume":"70","author":"Almomani","year":"2021","journal-title":"CMC Comput. Mater. Contin."},{"key":"ref_59","unstructured":"Zhu, S., Shi, J., Yang, L., Qin, B., Zhang, Z., Song, L., and Wang, G. (2020, January 12\u201314). Measuring and Modeling the Label Dynamics of Online Anti-Malware Engines. Proceedings of the 29th USENIX Security Symposium (USENIX Security 20), Boston, MA, USA."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Zhu, S., Zhang, Z., Yang, L., Song, L., and Wang, G. (2020, January 9\u201313). Benchmarking Label Dynamics of VirusTotal Engines. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Virtual.","DOI":"10.1145\/3372297.3420013"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/6\/2281\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:37:13Z","timestamp":1760135833000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/6\/2281"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,16]]},"references-count":60,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2022,3]]}},"alternative-id":["s22062281"],"URL":"https:\/\/doi.org\/10.3390\/s22062281","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,16]]}}}