<?xml version="1.0" encoding="utf-8"?>
 <ArticleSet>
	
		<Article>
		<Journal>
			<PublisherName>انجمن رمز ایران</PublisherName>
			<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
			<PISSN>2476-3047</PISSN>
			<EISSN>2476-3047</EISSN>
			<Volume>14</Volume>
			<Issue>1</Issue>
			<PubDate PubStatus="epublish">
				<Year>2025</Year>
				<Month>9</Month>
				<Day>1</Day>
			</PubDate>
		</Journal>
			
		<ArticleTitle>Cryptanalysis of Modular Operations</ArticleTitle>
		<FirstPage>1</FirstPage>
		<LastPage>18</LastPage>
		<Language>FA</Language>
		

	<AuthorList>
	<Author>
	<FirstName>Marzieh</FirstName>
	<MiddleName></MiddleName>
	<LastName>Vahid Dastjerdi</LastName>
	<Affiliation>Cryptography and Data Security Group, Reserch Center for Development of Advanced Technologies, Tehran, Iran</Affiliation>
	<AuthorEmails>m.vahiddastjerdi@gmail.com</AuthorEmails>
	<CorrespondingAuthor>Y</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Majid</FirstName>
	<MiddleName></MiddleName>
	<LastName>Rahimi</LastName>
	<Affiliation>Cryptography and Data Security Group, Reserch Center for Development of Advanced Technologies, Tehran, Iran</Affiliation>
	<AuthorEmails>rahimi@rcdat.ac.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	</AuthorList>
	<DOI></DOI>
	<Abstract>The objective of this paper is to analyze and evaluate the behaviour of modular addition and subtraction in symmetric cipher attacks. Modular addition is one of the most widely used nonlinear operators in symmetric cryptographic algorithms. In ARX symmetric algorithms, only three operators are utilized: modular addition, rotation, and XOR. In ARX-like algorithms, modular subtraction or a substitution box is employed, in addition to the standard ARX operations. Since modular subtraction exhibits similar behaviour to modular addition, its behaviour against cryptanalytic attacks has not been explicitly studied in the literature. Therefore, this paper aims to provide a comprehensive overview of the behaviour of modular addition and subtraction in differential, linear, integral cryptanalysis based on division property, and rotational attacks, using both manual analysis and automated methods via MILP (Mixed-Integer Linear Programming). We demonstrate that there is no difference between modular addition and subtraction in differential, linear, and rotational cryptanalysis. However, in integral cryptanalysis based on the division property, these two operations behave differently.</Abstract>
	<Keywords>Cryptography,  Symmetric Algorithms,  Cryptanalysis Attacks,  Modular Operations, MILP Method</Keywords>

			<URLs>
				<abstract>http://monadi.isc.org.ir/article-1-284-en.html</abstract>
				<Fulltext>
					<pdf>http://monadi.isc.org.ir/article-1-284-en.pdf</pdf>
				</Fulltext>
			</URLs>
			
			
	</Article>
	
		<Article>
		<Journal>
			<PublisherName>انجمن رمز ایران</PublisherName>
			<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
			<PISSN>2476-3047</PISSN>
			<EISSN>2476-3047</EISSN>
			<Volume>14</Volume>
			<Issue>1</Issue>
			<PubDate PubStatus="epublish">
				<Year>2025</Year>
				<Month>9</Month>
				<Day>1</Day>
			</PubDate>
		</Journal>
			
		<ArticleTitle>Analysis of frameworks, standards, platforms, and coalitions supporting the development of cyber threat intelligence in organizations</ArticleTitle>
		<FirstPage>19</FirstPage>
		<LastPage>44</LastPage>
		<Language>FA</Language>
		

	<AuthorList>
	<Author>
	<FirstName>Amin</FirstName>
	<MiddleName></MiddleName>
	<LastName>Chahardoli</LastName>
	<Affiliation>Faculty of Management, Central Tehran Branch, Islamic Azad University, Tehran, Iran</Affiliation>
	<AuthorEmails>amin.chahardoli@aut.ac.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Abouzar</FirstName>
	<MiddleName></MiddleName>
	<LastName>Arabsorkhi</LastName>
	<Affiliation>Iran Telecommunication Research Center, Tehran, Iran</Affiliation>
	<AuthorEmails>abouzar_arab@itrc.ac.ir</AuthorEmails>
	<CorrespondingAuthor>Y</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	</AuthorList>
	<DOI></DOI>
	<Abstract>In today&#8217;s modern world, with the emergence of technological advancements, cybersecurity has become one of the most critical issues. Every day, millions of data items are exchanged across the internet, exposing organizations and individuals to threats such as cyber intrusions, unauthorized access to information, and more. In this dynamic environment, Threat Intelligence has emerged as a prominent and effective tool to combat these threats&#8212;without overlooking necessary sensitivities. This modern approach enables organizations to analyze threat intelligence data meticulously, respond proactively to cyberattacks, and ensure the desired level of information security.
Given the increasing trend of cyberattacks, governments and organizations worldwide are pursuing strategies to strengthen institutional capacities for threat intelligence. In this article, through a comparative study of frameworks, standards, platforms, and coalitions (as key tools for enhancing cybersecurity and preventing attacks), the researcher provides a detailed analytical examination of these tools and their role in reinforcing cybersecurity systems. By focusing on the structural strengths and implementation components of threat intelligence in organizations&#8212;and leveraging the experiences of governments and international coalitions&#8212;this research aims to illustrate the essential role of these components in the production, dissemination, and utilization of threat intelligence. It also highlights the importance of effectively integrating these solutions into an organization&#8217;s information security cycle.
Achieving threat intelligence through frameworks, standards, platforms, and related coalitions requires attention to diverse requirements and actions. Based on the findings of this research, decision-makers and stakeholders can anticipate and operationalize necessary measures to implement threat intelligence approaches at an organizational level. Furthermore, adopting these frameworks, standards, platforms, and coalitions not only helps organizations utilize threat intelligence more effectively but also plays a critical role in decision-making and countering cyberattacks.
Frameworks, standards, platforms, and coalitions supporting threat intelligence development represent the most vital components, tools, and approaches used in the collection, analysis, and application of threat intelligence. These tools and standards have advanced significantly over time to assist organizations in effectively combating cyber threats. They enable organizations to better produce, disseminate, and implement threat intelligence strategies to address diverse attacks and threats.
This article is based on an extensive and in-depth study of major international frameworks for implementing and developing threat intelligence, as well as adopting standards and structures aligned with organizational needs&#8212;including principles, processes, responsibilities, and roles&#8212;within the threat intelligence lifecycle. By analyzing published best practices and insights from this research, practical recommendations are provided to organizations for managing threat intelligence. The production, dissemination, analysis, and application of threat intelligence are critically important for organizations due to the following reasons:
&#8226; Threat Identification and Prediction: Threat intelligence helps organizations identify and analyze patterns and trends in cyberattacks. This information guides organizations in predicting future attack types and planning appropriate countermeasures.
&#8226; Enhancing Incident Response: By leveraging threat intelligence, organizations can respond swiftly and effectively to cyberattacks. This minimizes potential damages and reduces the costs associated with attacks.
&#8226; Strengthening Cybersecurity: Organizations can implement necessary improvements to their systems and networks using threat intelligence, thereby better protecting their resources. These measures include researching and developing security technologies, enforcing efficient security policies, and enhancing employee awareness and trainin.
The development and implementation of frameworks, standards, platforms, and coalitions not only empower organizations to leverage threat intelligence more effectively but are also pivotal in strategic decision-making and countering cyberattacks. In the pervasive world of information technology, threat intelligence serves as a vital and undeniable tool in addressing organizations&#8217; security challenges. The use of threat intelligence in cybersecurity management&#8212;encompassing concepts such as threat identification, data-driven security decision-making, protection of sensitive information, defensive strategies, early detection and rapid response, and risk prediction and mitigation&#8212;emerges as a key factor in elevating security standards. By emphasizing the importance of these issues and the unparalleled role of threat intelligence in preventing and countering cyber threats, organizations are encouraged to leverage this powerful tool in the realm of cybersecurity.
Based on the outlined considerations, the primary research question of this study is:
&#8226; What are the functional roles of frameworks, standards, platforms, and alliances supporting threat intelligence in organizations? Addressing this main question requires answering the following sub-questions:
&#8226; What are the constituent components and elements of frameworks, standards, platforms, and alliances supporting threat intelligence in organizations?
&#8226; What are the factors influencing the selection and implementation of frameworks, standards, platforms, and alliances supporting threat intelligence in organizations?
&#8226; What are the criteria influencing the selection and implementation of frameworks, standards, platforms, and alliances supporting threat intelligence in organizations?
&#8226; What is the status of these influential criteria concerning each selected framework, standard, platform, or alliance supporting threat intelligence in organizations?
&#8226; How will the evaluation and assessment of selected frameworks, standards, platforms, and alliances supporting threat intelligence be conducted based on these criteria?</Abstract>
	<Keywords>Cyber Threat Intelligence, Frameworks, Platforms, Reference Standards, Leagues</Keywords>

			<URLs>
				<abstract>http://monadi.isc.org.ir/article-1-277-en.html</abstract>
				<Fulltext>
					<pdf>http://monadi.isc.org.ir/article-1-277-en.pdf</pdf>
				</Fulltext>
			</URLs>
			
			
	</Article>
	
		<Article>
		<Journal>
			<PublisherName>انجمن رمز ایران</PublisherName>
			<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
			<PISSN>2476-3047</PISSN>
			<EISSN>2476-3047</EISSN>
			<Volume>14</Volume>
			<Issue>1</Issue>
			<PubDate PubStatus="epublish">
				<Year>2025</Year>
				<Month>9</Month>
				<Day>1</Day>
			</PubDate>
		</Journal>
			
		<ArticleTitle>A secure and privacy-preserving electronic invoice based on blockchain technology</ArticleTitle>
		<FirstPage>45</FirstPage>
		<LastPage>63</LastPage>
		<Language>FA</Language>
		

	<AuthorList>
	<Author>
	<FirstName>Vahideh</FirstName>
	<MiddleName></MiddleName>
	<LastName>Ghanooni Shishavan</LastName>
	<Affiliation>Department of Information Technology Management, Faculty of Management and Economics, Tarbiat Modares University, Tehran, Iran</Affiliation>
	<AuthorEmails>vahideh.ghanooni@ modares.ac.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Shaban</FirstName>
	<MiddleName></MiddleName>
	<LastName>Elahi</LastName>
	<Affiliation>Department of Management, Faculty of Administrative Science and Economics, Vali-e-Asr University, Kerman, Iran</Affiliation>
	<AuthorEmails>elahi@ vru.ac.ir</AuthorEmails>
	<CorrespondingAuthor>Y</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Sadegh</FirstName>
	<MiddleName></MiddleName>
	<LastName>Dorri Nogoorani</LastName>
	<Affiliation>Department of Computer System Architecture, Faculty of Electrical and Computer Engineering, Tarbiat Modares University, Tehran, Iran</Affiliation>
	<AuthorEmails>dorri@modares.ac.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Ali</FirstName>
	<MiddleName></MiddleName>
	<LastName>Yazdian Varjani</LastName>
	<Affiliation>Department of Power, Faculty of Electrical and Computer Engineering, Tarbiat Modares University, Tehran, Iran</Affiliation>
	<AuthorEmails>yazdian@ modares.ac.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	</AuthorList>
	<DOI></DOI>
	<Abstract>The issuance of electronic invoices in the tax system, although a new topic, has not yet been able to fully provide an optimized tax system. Some of the challenges in the tax system include transaction data forgery, the complexity of the invoicing process, and the risks associated with storing data in centralized databases. Blockchain technology, with features such as transparency, resistance to tampering, and decentralization, can be a suitable solution. Ensuring the privacy and security of tax data and maintaining a balance between transparency and confidentiality in tax systems is of utmost importance. In this paper, a tax system model has been proposed base on a permissioned private blockchain. In this type of blockchain, only validating nodes have access to the information, and data access is restricted. This approach prevents the exposure of confidential information. Our proposed model consists of several processing nodes that are part of the blockchain network. These nodes are responsible for validating transactions and verifying information. In this model, various organizations, including the tax. All rights reserved. administration, banks, and other entities, connect to the blockchain network via nodes, but the network is not organizationally part of any single entity. Each organization interacts with the network through its own specific processing nodes. The model includes six layers, explained as follows: 1) Network Layer: This layer consists of processing nodes that represent various organizations (e.g., the tax administration, banks, tax payers, chambers of commerce, and official accountants). These nodes are responsible for validating transactions and maintaining the distributed ledger. The network generally includes organizations, processing nodes, and users. 2) Protocol Layer: This layer manages transaction processes, consensus, and data storage. Here, sales transactions are recorded, and the global state is maintained in the distributed ledger. Consensus in this model is achieved through the Raft algorithm, which is resistant to potential failures. 3) Privacy Layer: Private data is isolated and stored in different channels to prevent unauthorized access. For each transaction, data related to goods and services, exemptions, and liabilities are stored in private datasets. These data are only accessible by authorized processing nodes. 4) Governance Layer: This layer is responsible for managing electronic certificates and network security. Security is ensured through a certificate authority, public and private keys, and access control mechanisms. Additionally, identity management and member access control within the network are handled in this layer. 5) Integration Layer: This layer uses tools like gRPC and Oracles to communicate with external systems. Events are recorded and sent to other network members, and the necessary data for completing transactions is supplied through Oracles. 6) Application Layer: This layer consists of applications that provide a user interface for interacting with the blockchain. These applications connect to smart contracts and other blockchain components through a Software Development Kit (SDK). The model has been evaluated from four perspectives: (1) Qualitative Evaluation: Experts in various fields have reviewed the model. (2) Technical perspective: the model ensures data security through consensus protocols and digital certificates. It also offers better scalability due to the use of a private blockchain. (3) Organizational Perspective: The model is compatible with traditional systems and can be easily implemented on existing infrastructures. (4) Environmental Perspective: Some challenges, such as coordination with tax laws and processes, require attention. From a security perspective, three main aspects have been examined: (1) Confidentiality: This is ensured by storing data in the private blockchain, identity verification through digital certificates, and appropriate access control. (2) Data Integrity: This is guaranteed through the consensus protocol and the recording of transactions via smart contracts. (3) Availability: This is maintained by designing a distributed network that is resilient to node failures. Regarding the efficiency of the proposed model, it is suitable for large-scale and national implementations. The system continuously records transactions and, compared to traditional systems, places less strain on the infrastructure. Tests have shown that the Raft consensus protocol has low latency and good performance. Our comparison with previous systems that use public or centralized blockchains shows that our proposed model has more advantages. The most significant benefits are its transparency, security, and scalability. In comparison to other models, this system has successfully addressed challenges related to data forgery and the complexity of the invoicing process.</Abstract>
	<Keywords>Electronic invoice, Blockchain technology, Hyperledger fabric</Keywords>

			<URLs>
				<abstract>http://monadi.isc.org.ir/article-1-269-en.html</abstract>
				<Fulltext>
					<pdf>http://monadi.isc.org.ir/article-1-269-en.pdf</pdf>
				</Fulltext>
			</URLs>
			
			
	</Article>
	
		<Article>
		<Journal>
			<PublisherName>انجمن رمز ایران</PublisherName>
			<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
			<PISSN>2476-3047</PISSN>
			<EISSN>2476-3047</EISSN>
			<Volume>14</Volume>
			<Issue>1</Issue>
			<PubDate PubStatus="epublish">
				<Year>2025</Year>
				<Month>9</Month>
				<Day>1</Day>
			</PubDate>
		</Journal>
			
		<ArticleTitle>A systematic review of the literature on security and privacy and improving an onymity in the blockchain network</ArticleTitle>
		<FirstPage>64</FirstPage>
		<LastPage>96</LastPage>
		<Language>FA</Language>
		

	<AuthorList>
	<Author>
	<FirstName>Fatemeh</FirstName>
	<MiddleName></MiddleName>
	<LastName>Charlank Bakhtiari</LastName>
	<Affiliation>Department of Computer Science, Faculty of Engineering, Ferdowsi University, Mashhad, Iran</Affiliation>
	<AuthorEmails>fatemeh.bakhtiari1126@gmail.com</AuthorEmails>
	<CorrespondingAuthor>Y</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Abbas</FirstName>
	<MiddleName></MiddleName>
	<LastName>Ghaemi Bafghi</LastName>
	<Affiliation>Department of Computer Science, Faculty of Engineering, Ferdowsi University, Mashhad, Iran</Affiliation>
	<AuthorEmails>ghaemib@um.ac.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	</AuthorList>
	<DOI></DOI>
	<Abstract>With the rapid development of digital technolo gies, the need for new solutions to protect privacy and data security has increased. One technology that has attracted much attention is blockchain, a distributed ledger known for its features like transparency, de centralization, and security, particularly regarding privacy. However, this technology can pose a threat to users&#8217; privacy, especially concerning the origin, destination, and flow of cryptocurrency transactions. Therefore, anonymity in blockchain transactions and the protection of users&#8217; privacy are key aspects of this technology. In this paper, we review the secu rity features of blockchain, which include integrity, transparency, traceability, honesty, anonymity, and immutability. Each feature plays a fundamental role in maintaining the security and integrity of blockchain-based systems. Also, the problems in pro tecting privacy in permissionless blockchains have been examined. For this purpose, a systematic re view of the existing articles and research in this field has been reviewed and categorized. A systematic literature review is an efficient research tool. It in cludes three main stages: planning, implementation, and reporting. In the planning phase, research ques tions are extracted and appropriate databases are selected for searching. In the implementation phase, data is extracted from various articles and publi cations, and in the reporting phase, the results are&#160; presented in detail. Finally, this research method answers fundamental questions in various blockchain f ields, including privacy, anonymity, and threats. The four main research questions are: 1) What are the characteristics, advantages, and disadvantages of different types of blockchains? 2) What are the concepts of anonymity, pseudo-anonymity, privacy, and confidentiality, and how are privacy practices implemented? 3) What are the vulnerabilities and threats to privacy and anonymity? 4) What methods can address threats to privacy and anonymity? To carry out this research, a detailed plan was de veloped to search for and collect scientific articles and resources from reputable databases, including IEEE Xplore, ACM, ScienceDirect, Springer, and Google Scholar. The searches were conducted using keywords like &#8221;blockchain,&#8221; &#8221;privacy,&#8221; &#8221;anonymity,&#8221; and &#8221;se curity.&#8221; A review was conducted of articles published between 2018 and 2023. Based on the established in clusion and exclusion criteria, duplicate studies were eliminated, refining the final results. The initial stage of searching using the keyword &#8221;Blockchain&#8221; in various databases identified numer ous articles from diverse fields such as the Internet of Things, healthcare, smart contracts, banking and f inance, and other fields. After reviewing the titles, keywords, and abstracts, it was determined that a sig nificant challenge in this field is ensuring the privacy and security of users&#8217; identities in the blockchain. In the nextstage, thekeywords&#8221;Blockchain,&#8221;&#8221;Privacy,&#8221; &#8221;Anonymity,&#8221; and &#8221;Security&#8221; were used to search and identify morearticles. The article filtering process was divided into three stages. In the first stage, the ini tial review of titles and keywords reduced the number&#160; of articles from 1,233 to 947. In the second stage, af ter reviewing the abstracts, 404 relevant articles were identified. Finally, in the third stage, the full texts of the remaining articles were read, and the same num ber of articles was selected for more accurate infor mation extraction. The distribution of articles was analyzed in three ways: year of publication, source of publication, and topic. This survey indicates that the scientific com munity&#8217;s attention has fluctuated, increasing and then decreasing until 2019. IEEE and ScienceDirect have contributed the most to this topic, with 328 and 251 papers, respectively, while ACM has contributed the least. Figures 1, 2, and 3 demonstrate an increas ing use of blockchain technology across various fields, including cybersecurity, privacy, and anonymity. Answer to the first research question: Blockchains can be classified into three categories: public (permis sionless), private (permissioned), and consortium. Public chains like Bitcoin and Ethereum offer high transparency and decentralized security, enabling participation from everyone. The need for widespread consensus leads to decreased efficiency and increased energy consumption. In contrast, private chains allow access only to specific individuals or organizations and are suitable for corporate applications with high efficiency, faster processing, and greater control over data, but may lead to centralization and are vulner able to changes. Consortium chains blend elements of both public and private blockchains. They main tain a balance between transparency and privacy by being managed by a group of trusted organizations. Nonetheless, this management approach can compli cate processes because it necessitates coordination among the various network members. Answertothesecondresearchquestion:Anonymity, pseudo-anonymity, privacy, and confidentiality are key concepts in blockchain security. Anonymity refers to the concealment of users&#8217; identities, while pseudo-anonymity refers to the use of pseudonymous addresses that still allow indirect identification of users. Privacy gives users control over their personal information and transactions, while confidentiality protects against unauthorized disclosure of that in formation. Although these concepts are related, they have distinct differences. Anonymity can improve user security but may also foster abuse, while privacy mainly focuses on the management of user data. To preserve privacy on the blockchain, methods such as one-time addresses (generating a new address for each transaction), group signatures (allowing an in dividual&#8217;s identity to remain hidden among a group of users), zero-knowledge proofs (which allow a claim to be verified without revealing information), and transaction mixers (which combine transaction data to prevent tracking) are used, each of which offers different levels of security and efficiency. The follow ing is a comparison of various privacy methods and their key features, including security level, efficiency, level of anonymity, and implementation challenges. Some methods, such as zero-knowledge proofs, are highly secure but computationally expensive, while methods such as one-time addresses are simpler but provide a lower level of anonymity. This table helps you decide which method is best for your needs. Answer to the third research question: Blockchain threats and vulnerabilities are categorized into nine main groups: application attacks, consensus attacks, cryptanalysis, double spending, identity privacy, net work attacks, smart contracts, mining attacks, and unclassified attacks, each of which threatens user se curity and privacy differently. Network attacks such as sibyl attacks, denial of service, and data inter ception are the most common threats that can ex pose user information and reduce network perfor mance. Consensus and cryptanalysis attacks can dis rupttransactionsecurityandputuserdataatrisk.On the other hand, double spending attacks and smart contract vulnerabilities (such as the DAO attack) mayleadtofinancialfraudandassettheft. Also, iden tity privacy attacks such as impersonation and wal let information leakage can reveal user identities. Ad dressing these threats necessitates the use of stronger cryptography, enhanced consensus mechanisms, and the application of privacy-preserving methods. Addi tionally, the focus of the scientific community high lights that network attacks are particularly critical due to their direct impact on the security and per formance of blockchain technology. To address the fourth research question, various security solutions have been evaluated to counter threats to the chain of custody, tailored to the specific type of attack. Self-organizing maps, access control layer encryption, and rigorous transaction validation are employed to combat application and consensus attacks. Network attacks and cryptanalysis can be mitigated through data encryption, traffic analysis, security protocols like BGPsec,andstrongdigitalsignatures. Toprevent double spending, techniques such as utilizing nonces in transactions and combining digital signatures are employed. Smart contracts are secured through dy namicrules, secure payment methods, and smart con tracts. Also, to prevent user identity extraction and general threats, techniques such as zero-knowledge proofs, zero-blocks, anonymity, and intrusion detec tion are implemented in the network, which plays an important role in maintaining user security and pri vacy. This study can be used as a research basis to identify open issues and create new research direc tions in the future. The statistical data presented in tables and graphs indicate the positive impact of&#160; the blockchain on improving the performance of in formation systems and reducing costs. The findings of this study can guide the development of secure blockchain-based systems in the future and provide new directions for further research.</Abstract>
	<Keywords>Blockchain, Privacy, Anonymity, Security</Keywords>

			<URLs>
				<abstract>http://monadi.isc.org.ir/article-1-274-en.html</abstract>
				<Fulltext>
					<pdf>http://monadi.isc.org.ir/article-1-274-en.pdf</pdf>
				</Fulltext>
			</URLs>
			
			
	</Article>
	
		<Article>
		<Journal>
			<PublisherName>انجمن رمز ایران</PublisherName>
			<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
			<PISSN>2476-3047</PISSN>
			<EISSN>2476-3047</EISSN>
			<Volume>14</Volume>
			<Issue>1</Issue>
			<PubDate PubStatus="epublish">
				<Year>2025</Year>
				<Month>9</Month>
				<Day>1</Day>
			</PubDate>
		</Journal>
			
		<ArticleTitle>A comprehensive review of cyber deception concepts, comparative analysis of deception platforms, and proposal of three exemplary implementations for deceiving attackers</ArticleTitle>
		<FirstPage>97</FirstPage>
		<LastPage>119</LastPage>
		<Language>FA</Language>
		

	<AuthorList>
	<Author>
	<FirstName>Seyed Ali</FirstName>
	<MiddleName></MiddleName>
	<LastName>Samouti</LastName>
	<Affiliation>Kashef Company, Tehran, Iran</Affiliation>
	<AuthorEmails>a_samouti@kashef.ir</AuthorEmails>
	<CorrespondingAuthor>Y</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Sajad</FirstName>
	<MiddleName></MiddleName>
	<LastName>Tarhani</LastName>
	<Affiliation>Kashef Company, Tehran, Iran</Affiliation>
	<AuthorEmails>s_tarhani@kashef.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName>Mohsen</FirstName>
	<MiddleName></MiddleName>
	<LastName>Babakhani</LastName>
	<Affiliation>Kashef Company, Tehran, Iran</Affiliation>
	<AuthorEmails>m_babakhani@kashef.ir</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	</AuthorList>
	<DOI></DOI>
	<Abstract>Cyber deception, as a groundbreaking and transformative strategy in cyber defense, holds an unparalleled position in countering advanced and complex threats within the cyberspace. By designing deceptive and simulated environments, it prevents attackers from achieving their primary objectives while providing defenders with unique opportunities for monitoring, detecting, and neutralizing attacks. Beyond being a mere defensive tool, this technology serves as a strategic lever in safeguarding critical infrastructure and sensitive information, significantly increasing the operational costs for adversaries and elevating cyber deterrence to an unprecedented level.

This paper aims to present a comprehensive and in-depth conceptual framework by meticulously elucidating the foundational concepts of cyber deception and its structured taxonomy, while critically analyzing the lifecycle of this strategy. Existing methodologies proposed in the scientific literature are reviewed, and diverse classifications of techniques, tools, and deception architectures are provided. In this context, several leading platforms, recognized as effective tools for simulating vulnerable services and precisely logging malicious activities, are introduced. Furthermore, three practical implementations of deception technologies are proposed, with a detailed explanation of their technical and operational aspects.

Finally, by precisely identifying current needs and research gaps, future research directions are outlined, including the development of automated systems based on artificial intelligence and integration with modern security architectures. These directions aim to pave the way for a fundamental transformation in enhancing cybersecurity against emerging threats.</Abstract>
	<Keywords>Cyber Deception, Cyber Defence, Cyber attack, Cyber kill chain, Cyber Security</Keywords>

			<URLs>
				<abstract>http://monadi.isc.org.ir/article-1-313-en.html</abstract>
				<Fulltext>
					<pdf>http://monadi.isc.org.ir/article-1-313-en.pdf</pdf>
				</Fulltext>
			</URLs>
			
			
	</Article>
	
		<Article>
		<Journal>
			<PublisherName>انجمن رمز ایران</PublisherName>
			<JournalTitle>Biannual Journal Monadi for Cyberspace Security (AFTA)</JournalTitle>
			<PISSN>2476-3047</PISSN>
			<EISSN>2476-3047</EISSN>
			<Volume>14</Volume>
			<Issue>1</Issue>
			<PubDate PubStatus="epublish">
				<Year>2025</Year>
				<Month>9</Month>
				<Day>1</Day>
			</PubDate>
		</Journal>
			
		<ArticleTitle>An Overview of Transient Fault Attacks on Block Ciphers</ArticleTitle>
		<FirstPage>120</FirstPage>
		<LastPage>134</LastPage>
		<Language>FA</Language>
		

	<AuthorList>
	<Author>
	<FirstName>Mehdi</FirstName>
	<MiddleName></MiddleName>
	<LastName>Farzanegan</LastName>
	<Affiliation>Cyberspace Research Institute, Shahid Beheshti University, Tehran, Iran</Affiliation>
	<AuthorEmails>m.farzanegan@yahoo.com</AuthorEmails>
	<CorrespondingAuthor>N</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	<Author>
	<FirstName></FirstName>
	<MiddleName></MiddleName>
	<LastName></LastName>
	<Affiliation>Cyberspace Research Institute, Shahid Beheshti University, Tehran, Iran</Affiliation>
	<AuthorEmails>hadi.soleimany@gmail.com</AuthorEmails>
	<CorrespondingAuthor>Y</CorrespondingAuthor>
	<ORCID></ORCID>
	 </Author>
	</AuthorList>
	<DOI></DOI>
	<Abstract>Fault injection attacks are a category of active attacks within the gray-box model, where the attacker, having physical access to the cryptographic device, deliberately introduces an error into the system. This error leads to alterations in the intermediate and output values of the device, allowing the attacker to extract sensitive information, such as cryptographic keys, by analyzing the resulting discrepancies. Due to their ease of execution and high effectiveness, these attacks present a serious threat to the security of cryptographic implementations and can even compromise systems with protective mechanisms in place. Recent trends indicate a significant increase in research within this field, marking it as an active area of study in the context of cryptographic algorithm implementations. Therefore, there is a pressing need for a comprehensive study that encompasses fault injection attacks and their countermeasures. In this paper, we introduce fault injection attacks, discussing their characteristics, strengths, and weaknesses. We then explore and compare various attack analysis methods and conclude by examining strategies to mitigate these attacks.&#160;</Abstract>
	<Keywords>Fault Attack, Fault Injection, Active Attack, Fault Countermeasures</Keywords>

			<URLs>
				<abstract>http://monadi.isc.org.ir/article-1-289-en.html</abstract>
				<Fulltext>
					<pdf>http://monadi.isc.org.ir/article-1-289-en.pdf</pdf>
				</Fulltext>
			</URLs>
			
			
	</Article>
 </ArticleSet>
 
  
  
  
  
 