<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "http://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.2" xml:lang="en">
    <front>
        <journal-meta>
            <journal-id journal-id-type="pmc">F1000Research</journal-id>
            <journal-title-group>
                <journal-title>F1000Research</journal-title>
            </journal-title-group>
            <issn pub-type="epub">2046-1402</issn>
            <publisher>
                <publisher-name>F1000 Research Limited</publisher-name>
                <publisher-loc>London, UK</publisher-loc>
            </publisher>
        </journal-meta>
        <article-meta>
            <article-id pub-id-type="doi">10.12688/f1000research.168473.1</article-id>
            <article-categories>
                <subj-group subj-group-type="heading">
                    <subject>Research Article</subject>
                </subj-group>
                <subj-group>
                    <subject>Articles</subject>
                </subj-group>
            </article-categories>
            <title-group>
                <article-title>Quantum Threat Analysis of TLS, IPsec, and DNSSEC Protocols Using STRIDE and PASTA Models</article-title>
                <fn-group content-type="pub-status">
                    <fn>
                        <p>[version 1; peer review: awaiting peer review]</p>
                    </fn>
                </fn-group>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author" corresp="yes">
                    <name>
                        <surname>SWAIN</surname>
                        <given-names>SUJATA</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <uri content-type="orcid">https://orcid.org/0000-0001-7089-1863</uri>
                    <xref ref-type="corresp" rid="c1">a</xref>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Saha</surname>
                        <given-names>Saunak</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Poddar</surname>
                        <given-names>Ritoja</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Validation</role>
                    <role content-type="http://credit.niso.org/">Visualization</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <uri content-type="orcid">https://orcid.org/0009-0008-1202-7127</uri>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Bera</surname>
                        <given-names>Swapnanil</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Validation</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Bandyopadhyay</surname>
                        <given-names>Anjan</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Chouhan</surname>
                        <given-names>Vikas</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <xref ref-type="aff" rid="a2">2</xref>
                </contrib>
                <aff id="a1">
                    <label>1</label>Kalinga Institute of Industrial Technology, Bhubaneswar, Odisha, India</aff>
                <aff id="a2">
                    <label>2</label>University of New Brunswick Fredericton, Fredericton, New Brunswick, Canada</aff>
            </contrib-group>
            <author-notes>
                <corresp id="c1">
                    <label>a</label>
                    <email xlink:href="mailto:sujata.swainfcs@kiit.ac.in">sujata.swainfcs@kiit.ac.in</email>
                </corresp>
                <fn fn-type="conflict">
                    <p>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>6</day>
                <month>6</month>
                <year>2026</year>
            </pub-date>
            <pub-date pub-type="collection">
                <year>2026</year>
            </pub-date>
            <volume>15</volume>
            <elocation-id>881</elocation-id>
            <history>
                <date date-type="accepted">
                    <day>26</day>
                    <month>5</month>
                    <year>2026</year>
                </date>
            </history>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2026 SWAIN S et al.</copyright-statement>
                <copyright-year>2026</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access article distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <self-uri content-type="pdf" xlink:href="https://f1000research.com/articles/15-881/pdf"/>
            <abstract>
                <sec>
                    <title>Background</title>
                    <p>The advent of quantum computing poses significant challenges to traditional cryptographic methods employed in securing network protocols.</p>
                </sec>
                <sec>
                    <title>Methods</title>
                    <p>This study evaluates the vulnerabilities of Transport Layer Security (TLS), Internet Protocol Security (IPsec), and Domain Name System Security Extensions (DNSSEC) under quantum threat scenarios. Leveraging the STRIDE and PASTA threat modeling frameworks, the research categorizes threats and simulates attack scenarios to provide a comparative analysis of these protocols.</p>
                </sec>
                <sec>
                    <title>Results</title>
                    <p>The findings reveal critical vulnerabilities, particularly in public-key cryptography, and highlight the urgency of transitioning to quantum- resistant cryptographic solutions.</p>
                </sec>
                <sec>
                    <title>Conclusions</title>
                    <p>The study proposes practical mitigation strategies to enhance the resilience of these protocols, contributing to the advancement of post-quantum cryptography and secure digital communications.</p>
                </sec>
            </abstract>
            <kwd-group kwd-group-type="author">
                <kwd>Quantum Computing</kwd>
                <kwd>Cryptographic Vulnerabilities</kwd>
                <kwd>STRIDE Threat Model</kwd>
                <kwd>PASTA Framework</kwd>
                <kwd>Quantum-Resistant Cryptography</kwd>
                <kwd>Post-Quantum Security</kwd>
            </kwd-group>
            <funding-group>
                <award-group id="fund-1" xlink:href="https://doi.org/10.13039/501100020612">
                    <funding-source>Kalinga Institute of Industrial Technology</funding-source>
                    <award-id>KIIT-DU/1202/25</award-id>
                </award-group>
                <funding-statement>This work was funded by the Kalinga Institute of Industrial Technology, Bhubaneswar (KIIT-DU/1202/25). The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript.</funding-statement>
                <funding-statement>
                    <italic>The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript.</italic>
                </funding-statement>
            </funding-group>
        </article-meta>
    </front>
    <body>
        <sec id="sec5" sec-type="intro">
            <title>1. Introduction</title>
            <p>The rapid advancement of quantum computing presents significant challenges to traditional cryptographic techniques like RSA and Elliptic Curve Cryptography (ECC), which are integral to securing protocols such as TLS, IPsec, and DNSSEC. Quantum computers can solve complex mathematical problems exponentially faster than classical computers, making existing encryption methods vulnerable to attacks. Specifically, quantum algorithms like Shor&#x2019;s algorithm threaten to break widely used public-key cryptographic schemes, which could severely impact sensitive data&#x2019;s confidentiality, integrity, and authenticity. As quantum technology continues to evolve, addressing these vulnerabilities becomes increasingly urgent. Quantum resilient cryptography is paramount to protect digital communication and prevent the collapse of current security frameworks, which could be rendered obsolete by quantum-enabled attacks.
                <sup>
                    <xref ref-type="bibr" rid="ref1">1</xref>
                </sup>
            </p>
            <p>Protocols such as TLS, IPsec, and DNSSEC are essential for secure communication in various sectors, including e-commerce, healthcare, and government. They facilitate encrypted exchanges of sensitive data, such as payment information, medical records, and government communications. However, quantum computing could exploit the cryptographic weaknesses of these protocols, potentially disrupting secure transactions and compromising sensitive data. This research focuses on evaluating and mitigating quantum-specific threats to these key protocols by employing established frameworks like STRIDE and PASTA. STRIDE, which categorizes threats into spoofing, tampering, repudiation, information disclosure, denial of service, and privilege elevation, offers a structured method for identifying potential quantum vulnerabilities. Complementing STRIDE, the PASTA framework provides a simulation-driven approach to predict and counteract real-world quantum attack scenarios.
                <sup>
                    <xref ref-type="bibr" rid="ref2">2</xref>,
                    <xref ref-type="bibr" rid="ref3">3</xref>
                </sup>
            </p>
            <p>By integrating these frameworks, this study aims to systematically analyze the vulnerabilities introduced by quantum computing and propose countermeasures to safeguard these critical protocols. The paper explores quantum-resistant algorithms and hybrid cryptographic solutions, contributing to the development of post-quantum cryptographic standards. By leveraging these methodologies, the study addresses gaps in the current literature and aims to advance the state of quantum-safe encryption. This research is pivotal in ensuring the long-term security of global communications, providing robust solutions that can with stand quantum threats and preserving the integrity of the digital infrastructure in a quantum-enabled future.
                <sup>
                    <xref ref-type="bibr" rid="ref4">4</xref>,
                    <xref ref-type="bibr" rid="ref5">5</xref>,
                    <xref ref-type="bibr" rid="ref6">6</xref>
                </sup>
            </p>
            <sec id="sec6">
                <title>1.1 Motivation</title>
                <p>This research is motivated by the pressing need to develop quantum-resilient strategies to safeguard these foundational protocols. By adapting and integrating advanced threat modeling frameworks such as STRIDE and PASTA, this study aims to identify quantum-specific vulnerabilities, assess risks systematically, and propose robust mitigation techniques. The motivation lies in ensuring that as quantum computing evolves, so too does the resilience of our digital infrastructure, enabling secure communications and data exchanges in a post-quantum era. This work aspires to contribute to the growing field of post-quantum cryptography and provide actionable insights for the development of next-generation cryptographic solutions.</p>
            </sec>
            <sec id="sec7">
                <title>1.2 The primary objectives of this research paper are outlined as follows:</title>
                <p>

                    <list list-type="bullet">
                        <list-item>
                            <label>&#x2022;</label>
                            <p>We identify quantum threats to core security protocols such as TLS, IPsec, and DNSSEC, and evaluate their quantum vulnerabilities using comparative analyses based on the STRIDE and PASTA models.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>We develop a comprehensive threat matrix and conduct detailed risk assessments for the analyzed protocols, enabling a structured understanding of their security gaps.</p>
                        </list-item>
                        <list-item>
                            <label>&#x2022;</label>
                            <p>We propose quantum-resistant enhancements to these protocols, contributing to the advancement of post-quantum cryptography through the application of advanced threat modeling methodologies.</p>
                        </list-item>
                    </list>
                </p>
            </sec>
            <sec id="sec8">
                <title>1.3 Organization of paper</title>
                <p>
This research paper is structured into eight comprehensive sections, each designed to systematically address the quantum threat analysis of TLS, IPsec, and DNSSEC protocols through the application of STRIDE and PASTA threat modeling frameworks. Section 2 presents related work and background. Section 3 provides quantum threat analysis and risk assessment protocol. Section 4 contains the threat identification in widely used protocols. Section 5 provides a comparative study of threats and risk assessment. Section 6 contains the attack scenarios for widely used protocols. Section 7 contains mainly the mitigation strategies and recommendations. In the final section 8, we have the conclusion and future work.</p>
            </sec>
        </sec>
        <sec id="sec9">
            <title>2. Related work</title>
            <p>Several studies
                <sup>
                    <xref ref-type="bibr" rid="ref7">7</xref>,
                    <xref ref-type="bibr" rid="ref1">1</xref>,
                    <xref ref-type="bibr" rid="ref8">8</xref>
                </sup> highlight the vulnerabilities posed by quantum computing to classical cryptographic protocols like TLS, IPsec, and DNSSEC. Research has shown that widely used encryption methods, such as RSA and ECC, are particularly susceptible to quantum attacks due to algorithms like Shor&#x2019;s, which can factorize large integers and solve discrete logarithms exponentially faster than classical methods.
                <sup>
                    <xref ref-type="bibr" rid="ref3">3</xref>,
                    <xref ref-type="bibr" rid="ref9">9</xref>
                </sup> These vulnerabilities necessitate a proactive approach to assess and mitigate risks in existing protocols.</p>
            <p>Threat modeling is a crucial step in identifying vulnerabilities and designing robust systems. The STRIDE model has been extensively used to classify threats into spoofing, tampering, repudiation, information disclosure, denial of service, and privilege escalation. It has been applied in scenarios such as secure software development and protocol design to systematize threat identification.
                <sup>
                    <xref ref-type="bibr" rid="ref6">6</xref>,
                    <xref ref-type="bibr" rid="ref7">7</xref>
                </sup>
            </p>
            <p>Similarly, the PASTA (Process for Attack Simulation and Threat Analysis) framework offers a dynamic approach by simulating potential attacks in real-world environments. Studies have combined these methodologies to provide a holistic view of potential threats and their mitigation strategies.
                <sup>
                    <xref ref-type="bibr" rid="ref10">10</xref>,
                    <xref ref-type="bibr" rid="ref11">11</xref>
                </sup>
            </p>
            <p>Recent advancements in post-quantum cryptography (PQC) have focused on developing algorithms resilient to quantum attacks. Studies have proposed transitioning protocols like TLS and IPsec to use quantum-resistant primitives such as lattice-based and hash-based cryptography.
                <sup>
                    <xref ref-type="bibr" rid="ref7">7</xref>,
                    <xref ref-type="bibr" rid="ref10">10</xref>
                </sup> Research emphasizes the need for these adaptations to be implemented proactively to maintain confidentiality and data integrity in a quantum era.</p>
            <p>Comparative studies on protocol vulnerabilities provide valuable insights into their quantum-era challenges. For instance, papers have explored TLS&#x2019;s handshake process, IPsec&#x2019;s key exchange mechanisms, and DNSSEC&#x2019;s chain of trust to evaluate their robustness under quantum threats. These works emphasize the importance of evaluating protocols under varied attack models and threat scenarios, leveraging tools like STRIDE and PASTA to guide this assessment.
                <sup>
                    <xref ref-type="bibr" rid="ref6">6</xref>,
                    <xref ref-type="bibr" rid="ref7">7</xref>,
                    <xref ref-type="bibr" rid="ref10">10</xref>,
                    <xref ref-type="bibr" rid="ref11">11</xref>
                </sup>
            </p>
            <p>Hybrid cryptographic approaches that combine classical and quantum-resistant methods are gaining importance as transitional solutions while cryptographic standards evolve in response to the quantum threat. These hybrid mechanisms, such as those proposed for TLS and IPsec, integrate traditional cryptographic algorithms like RSA and ECC with post-quantum algorithms, offering immediate security while preparing systems for future-proofing against quantum attacks. By employing this dual-pronged strategy, systems ensure backward compatibility with existing protocols, reducing the risk of disruptions during the transition. This approach not only mitigates potential vulnerabilities associated with quantum computing but also provides a bridge to fully quantum-resistant systems. It enables secure communication and key exchange without requiring an immediate over haul of the infrastructure, making it crucial for industries such as finance, government, and military communications. In the long term, hybrid cryptography plays a pivotal role in safe guarding digital systems, ensuring they are resilient to quantum threats while maintaining compatibility with current standards.
                <sup>
                    <xref ref-type="bibr" rid="ref1">1</xref>,
                    <xref ref-type="bibr" rid="ref3">3</xref>,
                    <xref ref-type="bibr" rid="ref8">8</xref>
                </sup> 
                <xref ref-type="fig" rid="f1">Figure. 1</xref> provides the flow chart of the structured process of quantum threat modeling applied to network security protocols like TLS, IPsec, and DNSSEC.</p>
            <fig fig-type="figure" id="f1" orientation="portrait" position="float">
                <label>Figure 1. </label>
                <caption>
                    <title>Detailed flow chart for quantum threat analysis of widely used protocols.</title>
                </caption>
                <graphic id="gr1" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/185658/d7f8ea08-95c4-4394-87c7-6cfba6904682_figure1.gif"/>
            </fig>
            <p>It begins with identifying potential quantum threats, which is the first step in understanding how quantum computing could impact cryptographic systems. Once these threats are identified, the next step involves recognizing specific vulnerabilities within the protocols under scrutiny. After identifying these weaknesses, the STRIDE model is applied to categorize the threats according to the six categories: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. Following this, the PASTA (Process for Attack Simulation and Threat Analysis) model is employed to simulate realistic attack scenarios and evaluate the impact of these threats on the protocols. A comparative analysis is then conducted between TLS, IPsec, and DNSSEC to identify how they each respond to quantum threats. The results of the analysis are carefully examined, leading to the final step where quantum-resistant recommendations are provided to enhance the security and resilience of these protocols in the quantum era. The flow chart visually encapsulates these critical stages, illustrating the systematic approach used in assessing and addressing quantum threats to modern cryptographic systems. 
                <xref ref-type="fig" rid="f2">Figure. 2</xref> shows us the overall mitigation workflow for a generalized threat model.</p>
            <fig fig-type="figure" id="f2" orientation="portrait" position="float">
                <label>Figure 2. </label>
                <caption>
                    <title>Threat modelling and mitigation workflow.</title>
                </caption>
                <graphic id="gr2" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/185658/d7f8ea08-95c4-4394-87c7-6cfba6904682_figure2.gif"/>
            </fig>
            <p>Threat modeling is an essential process in cyber security, designed to identify, assess, and mitigate potential threats and vulnerabilities in systems, especially those critical to secure communication protocols like 
                <bold>Transport Layer Security (TLS)</bold>, 
                <bold>Internet Protocol Security (IPsec)</bold>, and 
                <bold>Domain Name System Security Extensions (DNSSEC)</bold>. These protocols, while foundational to current internet security, are vulnerable to emerging threats, particularly those posed by quantum computing. Traditional cryptographic defenses are increasingly challenged by the capabilities of quantum technologies, potentially rendering current encryption methods ineffective. Therefore, threat modeling helps predict attack vectors and assess risks, offering proactive measures to address these vulnerabilities and ensure continued security, even in the quantum era.
                <sup>
                    <xref ref-type="bibr" rid="ref6">6</xref>,
                    <xref ref-type="bibr" rid="ref7">7</xref>,
                    <xref ref-type="bibr" rid="ref10">10</xref>,
                    <xref ref-type="bibr" rid="ref11">11</xref>
                </sup>
            </p>
            <p>Two primary threat modeling frameworks, STRIDE and PASTA, are utilized to analyze potential vulnerabilities in TLS, IPsec, and DNSSEC. The STRIDE model, developed by Microsoft, categorizes threats into six types: 
                <bold>Spoofing</bold>, 
                <bold>Tampering</bold>, 
                <bold>Repudiation</bold>, 
                <bold>Information Disclosure</bold>, 
                <bold>Denial of Service (DoS)</bold>, and 
                <bold>Elevation of Privilege</bold>. Each of these categories represents a distinct type of risk that could compromise the security of systems, making STRIDE a useful tool for identifying and evaluating the impact of quantum threats on protocols. For example, quantum computing could expose vulnerabilities in the encryption mechanisms of TLS and IPsec, making it easier for attackers to intercept and manipulate sensitive data during transmission. In DNSSEC, quantum attacks could lead to the manipulation of DNS data, undermining its authenticity.
                <sup>
                    <xref ref-type="bibr" rid="ref12">12</xref>,
                    <xref ref-type="bibr" rid="ref13">13</xref>
                </sup>
            </p>
            <p>The PASTA (
                <italic toggle="yes">Process for Attack Simulation and Threat Analysis</italic>) model,
                <sup>
                    <xref ref-type="bibr" rid="ref14">14</xref>
                </sup> on the other hand, focuses on a risk-driven, attacker-centric approach to threat analysis. It operates through seven stages, starting with defining the objectives of potential attackers, followed by a detailed break down of the system&#x2019;s technical scope, and then a deeper analysis of how attackers might exploit weaknesses in system components. PASTA emphasizes simulating real-world attack scenarios, offering a practical perspective on how quantum-based threats could exploit vulnerabilities in protocols. For instance, quantum algorithms like Shor&#x2019;s algorithm, which can factor large numbers efficiently, could potentially break the RSA and ECDSA encryption used in TLS and IPsec, while Grover&#x2019;s algorithm might make symmetric encryption methods susceptible to faster brute-force attacks.
                <sup>
                    <xref ref-type="bibr" rid="ref15">15</xref>
                </sup>
            </p>
            <p>When combined, the STRIDE and PASTA models provide a robust framework for threat modeling, offering both a structured categorization of potential threats and a simulated attack process that helps visualize and assess their real-world implications. This dual-model approach ensures a comprehensive understanding of the vulnerabilities in TLS, IPsec, and DNSSEC, particularly in the context of quantum computing. By combining insights from both models, this analysis offers valuable information for mitigating quantum threats and adapting these protocols to the post-quantum world.
                <sup>
                    <xref ref-type="bibr" rid="ref1">1</xref>,
                    <xref ref-type="bibr" rid="ref9">9</xref>,
                    <xref ref-type="bibr" rid="ref16">16</xref>
                </sup>
            </p>
            <p>TLS, IPsec, and DNSSEC each play crucial roles in securing internet communications. TLS ensures the confidentiality and integrity of data transmitted over networks, particularly in web traffic. However, TLS&#x2019;s reliance on public-key encryption algorithms such as RSA and ECDSA poses a significant vulnerability to quantum computing, as these algorithms are susceptible to attacks from quantum algorithms. IPsec, which secures IP communications through encryption and authentication at the network layer, also relies on similar cryptographic methods, including Diffie-Hellman key exchange, making it vulnerable to quantum attacks. DNSSEC enhances the security of the Domain Name System (DNS) by signing DNS data with digital signatures, but its reliance on public-key cryptography also makes it susceptible to quantum decryption techniques, potentially allowing attackers to manipulate DNS records and redirect users to malicious ssites.
                <sup>
                    <xref ref-type="bibr" rid="ref17">17</xref>,
                    <xref ref-type="bibr" rid="ref18">18</xref>
                </sup> The threat modeling analysis, particularly using STRIDE and PASTA, reveals the critical need to transition these protocols to quantum-resistant cryptographic methods. Current methods, such as lattice-based cryptography, offer promising alternatives to existing public-key schemes and are more resilient to quantum decryption attacks. These findings are echoed in comparative studies on the vulnerabilities of TLS, IPsec, and DNSSEC to both classical and quantum threats, emphasizing the urgency of adopting post-quantum cryptographic solutions.
                <sup>
                    <xref ref-type="bibr" rid="ref19">19</xref>
                </sup>
            </p>
        </sec>
        <sec id="sec10">
            <title>3. Quantum threat analysis and risk assessment of protocol</title>
            <sec id="sec11">
                <title>3.1 Threat modelling approach using STRIDE</title>
                <p>The STRIDE model, developed by Microsoft, offers a structured approach to identifying and categorizing threats, making it an effective framework for assessing security vulnerabilities in protocols such as TLS, IPsec, and DNSSEC. By categorizing threats into six distinct types&#x2014;Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service (DoS), and Elevation of Privilege&#x2014;STRIDE enables a comprehensive assessment of each protocol&#x2019;s security posture against potential attacks. This section outline show the STRIDE model is applied to TLS, IPsec, and DNSSEC within this study to evaluate their resilience to conventional and emerging quantum-based threats. In the context of TLS, IPsec, and DNSSEC, each STRIDE category targets specific threat areas within these protocols.</p>
                <p>Spoofing involves impersonating users or systems to gain unauthorized access to secure communications. For TLS, IPsec, and DNSSEC, spoofing threats may arise if attackers by pass authentication mechanisms, potentially exploiting vulnerabilities in public-key cryptography that could accelerate quantum computing. STRIDE&#x2019;s Spoofing analysis in this study focuses on the potential risks associated with identity impersonation, especially within the handshake or authentication stages of each protocol. The rise of quantum computing could undermine the security of public key algorithms like RSA, making identity verification more susceptible to quantum-powered spoofing attacks.</p>
                <p>Tampering refers to unauthorized modifications of data during transmission. In TLS, this could mean altering encrypted messages between client and server; for IPsec, it could involve modifying packet data within VPNs or secured networks; and in DNSSEC, tampering might entail manipulating DNS records. STRIDE&#x2019;s Tampering analysis examines the integrity mechanisms within these protocols, assessing how quantum-based attacks might compromise these safeguards. Quantum algorithms, such as Shor&#x2019;s and Grover&#x2019;s, could potentially break the encryption mechanisms that protect data integrity in these protocols, making them vulnerable to tampering.</p>
                <p>Repudiation threats occur when an entity denies having performed an action, such as a transaction or message transmission, creating accountability issues. TLS, IPsec, and DNSSEC all rely on authentication logs and audit trails to prevent repudiation. However, if quantum computing disrupts the integrity of digital signatures used in these protocols, attackers may exploit this to bypass accountability measures. The STRIDE analysis in this study evaluates the effectiveness of each protocol&#x2019;s non-repudiation mechanisms and their susceptibility to quantum interference. A quantum attacker could potentially forge or alter signatures, undermining trust in transaction histories and audit trails.</p>
                <p>Information disclosure involves unauthorized access to confidential information. This threat is particularly relevant in TLS, where encryption ensures confidentiality in web transactions, and in IPsec, where data within a VPN must remain protected. For DNSSEC, ensuring the integrity of DNS responses is critical. STRIDE&#x2019;s Information Disclosure category assesses the encryption methods employed by each protocol, particularly focusing on the vulnerability of public-key algorithms to quantum decryption. Quantum computing could potentially expose sensitive data by breaking the encryption keys that protect communications, leading to unauthorized disclosure of information. Denial of Service (DoS) attacks aim to disrupt access to services, there by affecting system availability. In TLS, DoS attacks can overwhelm web servers by flooding them with requests, leading to service unavailability. In IPsec, DoS attacks can compromise the availability of secure network communications by targeting VPNs or disrupting data transmission. In DNSSEC, DoS attacks can overload DNS servers, preventing the resolution of domain names, and potentially compromising the availability of services that rely on DNS. The STRIDE DoS analysis investigates potential quantum-based DoS attacks, assessing each protocol&#x2019;s defense mechanisms against high computation demands that quantum attacks might exploit.</p>
                <p>Elevation of Privilege occurs when unauthorized users gain elevated access levels within a system. If quantum-based attacks break cryptographic barriers, attackers may exploit this to escalate privileges within TLS sessions, IPsec connections, or DNSSEC&#x2019;s zone management. STRIDE&#x2019;s Elevation of Privilege analysis in this study examines whether quantum vulnerabilities could allow attackers to bypass authentication controls and gain unauthorized access to system resources or privileged operations.</p>
                <p>The STRIDE model, traditionally effective in identifying vulnerabilities across various systems, requires adaptation to address the unique challenges posed by quantum computing. Quantum algorithms, such as Shor&#x2019;s and Grover&#x2019;s, have the potential to compromise the cryptographic underpinnings of protocols like TLS, IPsec, and DNSSEC. To account for these emerging risks, this study extends STRIDE to include quantum-specific attack scenarios within each threat category&#x2014;Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privileges. For example, quantum-enabled attackers could break asymmetric encryption used in authentication (Spoofing) or compromise data integrity by decrypting encrypted data in transit (Tampering). This adaptation of STRIDE highlights areas where these protocols need quantum- resistant solutions, such as post-quantum cryptographic algorithms and enhanced key management practices, to mitigate vulnerabilities effectively.</p>
                <p>However, STRIDE&#x2019;s static framework, focused on categorizing threats, has limitations in addressing the dynamic and evolving nature of quantum-enabled attacks. Its lack of an attacker-centric and scenario-driven perspective makes it less suited for assessing the sophistication of quantum threats. To address these shortcomings, this study incorporates the PASTA (Process for Attack Simulation and Threat Analysis) model alongside STRIDE. PASTA&#x2019;s staged, simulation-based approach complements STRIDE by offering a dynamic framework that evaluates the feasibility of quantum attacks and aligns mitigation strategies with real-world scenarios. Together, STRIDE and PASTA provide a more comprehensive and adaptive methodology for identifying and mitigating both traditional and quantum-specific vulnerabilities, ensuring a robust defense against emerging threats.</p>
            </sec>
            <sec id="sec12">
                <title>3.2 Threat modelling approach using PASTA</title>
                <p>The Process for Attack Simulation and Threat Analysis (PASTA) model is a risk-based, attacker centric threat modeling approach designed to simulate real-world attacks. Unlike STRIDE, which focuses on categorizing threats, PASTA offers a detailed, multi-stage process for analyzing how attackers might exploit system vulnerabilities. Given the dynamic nature of quantum threats, PASTA&#x2019;s comprehensive, simulation-based approach is well-suited to examining how TLS, IPsec and DNSSEC might respond to attacks enabled by quantum computing. This section outlines the seven stages of the PASTA model as they apply to the threat landscape of each protocol and discusses the adaptations made to account for quantum-based threats.</p>
                <p>In this research, each stage of the PASTA model is used to methodically examine TLS, IPsec, and DNSSEC, identifying vulnerabilities and assessing potential risks posed by quantum computing capabilities. 
                    <xref ref-type="fig" rid="f3">Figure. 3</xref> Shows us the overall stages of Threat Modeling in PASTA.</p>
                <fig fig-type="figure" id="f3" orientation="portrait" position="float">
                    <label>Figure 3. </label>
                    <caption>
                        <title>PASTA Threat Modeling Stages.</title>
                    </caption>
                    <graphic id="gr3" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/185658/d7f8ea08-95c4-4394-87c7-6cfba6904682_figure3.gif"/>
                </fig>
                <p>Stage 1: Definition of Objectives (DO) for the Analysis stage involves defining the objectives of the threat analysis, focusing on protecting the confidentiality, integrity, and availability of data transmitted over TLS, IPsec, and DNSSEC. Given the emergence of quantum computing, the objective includes identifying quantum-specific vulnerabilities that could compromise these protocols. The goal is to evaluate each protocol&#x2019;s security measures and assess their preparedness for post-quantum threats.</p>
                <p>Stage 2: Definition of the Technical Scope (DTS) stage identifies the technical scope by examining the protocol architecture, cryptographic mechanisms, and configurations. ForTLS, this includes the handshake process and encryption algorithms like RSA and ECDSA. For IPsec, the scope includes key exchange methods like Diffie-Hellman, and for DNSSEC, it involves digital signatures used to authenticate DNS records. The aim is to understand where quantum attacks might exploit weaknesses in each protocol&#x2019;s cryptographic structure.</p>
                <p>Stage 3: Application Decomposition and Analysis (ADA) stage breaks down each protocol into its functional components to understand its security boundaries and potential attack surfaces. For TLS, components include the session establishment and encryption layers. IPsec includes encapsulation and authentication protocols, and for DNSSEC, it involves DNS record signing and verification processes. Decomposition helps pinpoint specific functions vulnerable to quantum decryption or spoofing attacks.</p>
                <p>Stage 4: In Threat Analysis (TA) the PASTA model conducts a detailed threat analysis, focusing on identifying and cataloging potential threats that could be exploited by quantum computing. Using attacker personas, this analysis evaluates how an attacker with quantum capabilities could by pass encryption, impersonate entities, or intercept data. For instance, Shor&#x2019;s algorithm poses a direct threat to TLS&#x2019;s public-key algorithms, while Grover&#x2019;s algorithm could speedup brute-force attacks, affecting all three protocols.</p>
                <p>Stage 5: The Vulnerability and Weakness Analysis (VWA) stage assesses the protocols&#x2019; vulnerabilities, specifically their reliance on public-key cryptography, which is susceptible to quantum decryption. For TLS, IPsec, and DNSSEC, this includes weaknesses in RSA, ECDSA, and other asymmetric cryptographic mechanisms that could be compromised. Vulnerability analysis in this stage focuses on how these weaknesses could be targeted by quantum-enabled attacks, identifying potential areas where quantum-resistant algorithms should be implemented.</p>
                <p>Stage 6: Attack Simulation and Modeling (ASM) (PASTA&#x2019;s simulation stage) is critical for visualizing and understanding how real-world quantum attacks might unfold. By simulating scenarios like a quantum-enabled man-in-the-middle attack in TLS or an impersonation attack in DNSSEC, this stage demonstrates the protocols&#x2019; responses to quantum-based threats. Attack simulations provide insights into potential security gaps and highlight the effectiveness (or lack thereof
) of each protocol&#x2019;s existing defense mechanisms in the face of quantum-based threats.</p>
                <p>Stage 7: Risk and Impact Analysis (RIA) is the final stage of PASTA which involves assessing the potential impact and risk of quantum threats on each protocol. This analysis considers the consequences of a successful quantum attack, such as data exposure or compromised network integrity. For TLS, IPsec, and DNSSEC, this includes evaluating the implications for user trust, data confidentiality, and network availability. Risk assessment further prioritizes the need for quantum-resistant adaptations to minimize potential impacts.</p>
                <p>The PASTA model, typically used for traditional security threats, has been adapted in this study to address quantum-specific challenges. Quantum computing introduces new vulnerabilities, particularly through quantum algorithms like Shor&#x2019;s and Grover&#x2019;s, which could break conventional cryptographic systems such as RSA and ECC. Shor&#x2019;s algorithm can efficiently factor large numbers, threatening RSA encryption, while Grover&#x2019;s algorithm speeds up brute-force attacks on symmetric- key cryptography. This adaptation of the PASTA model revises each stage to consider quantum threats. The model&#x2019;s attacker-centric approach allows for a dynamic examination of how quantum computing could exploit weaknesses in protocols like TLS, IPsec, and DNSSEC. By simulating these quantum-enabled threats, the model offers a more comprehensive analysis than traditional methods, highlighting the evolving risks posed by quantum algorithms and providing insights into how to enhance system resilience in a quantum future.</p>
                <p>While the PASTA model provides a detailed, seven-stage framework for simulating and analyzing threats, it has limitations when applied to quantum threats. One of the primary limitations lies in the model&#x2019;s reliance on attacker simulation, which assumes a certain level of predictability about how attackers behave. However, the nature of quantum advancements is highly uncertain, and it is challenging to predict how quantum algorithms, such as Shor&#x2019;s and Grover&#x2019;s, evolve and be implemented in real-world attacks. The current model does not account for the rapid and unpredictable developments in quantum technologies, which means that simulations based on existing understanding may not always reflect the most advance do remerging quantum capabilities. For instance, although quantum computing research has made substantial progress, the practical application of quantum algorithms to real-world systems is still in its infancy. As such, future iterations of the PASTA model may need to incorporate quantum-specific simulations, which are still largely theoretical. These updates could lead to more accurate threat simulations as quantum technologies develop, providing a more robust tool for assessing the impact of quantum-enabled attacks on systems like TLS, IPsec, and DNSSEC.</p>
            </sec>
            <sec id="sec13">
                <title>3.3 Protocol selection criteria (TLS, IPsec, DNSSEC)</title>
                <p>The selection of TLS, IPsec, and DNSSEC protocols for this study is based on their critical roles in securing internet communications and their susceptibility to quantum computing threats. Each protocol was chosen to represent different layers and functions within network security, providing a comprehensive assessment of quantum threat impact across diverse security contexts. 
                    <xref ref-type="fig" rid="f4">Figure. 4</xref> Shows us the overall threat modeling procedure.</p>
                <fig fig-type="figure" id="f4" orientation="portrait" position="float">
                    <label>Figure 4. </label>
                    <caption>
                        <title>Threat Modelling process.</title>
                    </caption>
                    <graphic id="gr4" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/185658/d7f8ea08-95c4-4394-87c7-6cfba6904682_figure4.gif"/>
                </fig>
                <p>TLS, IPsec, and DNSSEC are widely used in prevalence in network security to secure communications across the internet, making them high-priority targets for security assessments. TLS (Transport Layer Security) is essential for protecting web communications and securing data exchanged between clients and servers. IPsec (Internet Protocol Security) provides network-level security, protecting data at the IP layer and enabling secure VPN connections. DNSSEC (Domain Name System Security Extensions) secures DNS data, ensuring the integrity of DNS queries. Given their widespread use and integral roles, analyzing the security of these protocols is essential for understanding the impact of potential quantum threats on the broader internet infrastructure.</p>
                <p>All three protocols rely heavily or depend on public key cryptography for encryption, authentication, and data integrity. This reliance on asymmetric algorithms&#x2014;such as RSA and Elliptic Curve Cryptography (ECC)&#x2014;makes these protocols especially vulnerable to quantum computing, as quantum algorithms (e.g., Shor&#x2019;s algorithm) could potentially break these encryption methods. Studying these protocols provides insight into which aspects of their cryptographic foundations are most susceptible to quantum attacks, allowing for an analysis of how quantum-resistant methods could be incorporated.</p>
                <p>TLS, IPsec, and DNSSEC each address different security objectives and operate at various layers of the network stack. TLS ensures secure communication at the application layer, IPsec operates at the network layer to protect IP communications, and DNSSEC provides data integrity for the DNS system. By selecting protocols from distinct layers, this study achieves a broader evaluation of quantum vulnerabilities, enabling a cross-layer assessment that highlights both common and unique threats across the stack.</p>
                <p>A successful quantum attack on TLS, IPsec, or DNSSEC would have severe consequences for internet security and user trust. Compromised TLS could lead to wide spread data exposure, IPsec vulnerabilities could allow attackers to intercept or tamper with network traffic, and weaknesses in DNSSEC could lead to DNS spoofing, redirecting users to malicious sites. Given the significant risk each protocol faces, evaluating them provides a meaningful basis for developing quantum-resilient strategies with a high-security impact.</p>
                <p>These protocols have been the focus of numerous security studies, making them well-documented and suitable for comparative analysis. Leveraging prior research, this study can effectively use the STRIDE and PASTA models to examine known and emerging threats. Comparing these well-established protocols allows for a clearer evaluation of the potential effectiveness of quantum resistant algorithms and highlights where traditional threat models may need adjustments for quantum-era security.</p>
            </sec>
            <sec id="sec14">
                <title>3.4 Attack simulation environment and setup</title>
                <p>To analyze and validate the effectiveness of the STRIDE and PASTA threat models in assessing the quantum vulnerability of TLS, IPsec, and DNSSEC protocols, an attack simulation environment is established. [
                    <xref ref-type="fig" rid="f5">Figure. 5</xref> Shows us the overall threat identification model of Stride and Pasta]. This environment is designed to simulate quantum-capable adversary scenarios, allowing for practical testing of the protocols under realistic attack conditions. This section outlines the simulation setup, software tools, and configurations used to evaluate protocol resilience.</p>
                <fig fig-type="figure" id="f5" orientation="portrait" position="float">
                    <label>Figure 5. </label>
                    <caption>
                        <title>Threat identification of STRIDE and PASTA.</title>
                    </caption>
                    <graphic id="gr5" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/185658/d7f8ea08-95c4-4394-87c7-6cfba6904682_figure5.gif"/>
                </fig>
                <p>The primary objective of the simulation environment is to evaluate the resilience of TLS, IPsec, and DNSSEC protocols against potential quantum computing threats, specifically targeting their cryptographic underpinnings. This involves testing the vulnerabilities of existing algorithms like RSA and ECC, which are foundational to these protocols, under hypothetical quantum attacks leveraging Shor&#x2019;s algorithm. Additionally, the simulations aim to explore attack vectors such as man- in-the-middle exploits, data tampering, and impersonation attacks, which quantum computing could amplify. These scenarios are analyzed using the STRIDE and PASTA threat modeling frameworks to assess their effectiveness in identifying, categorizing, and addressing quantum- induced security challenges, providing insights into protocol weaknesses and the development of quantum-resistant enhancements.</p>
                <p>The simulation environment for assessing the impact of quantum threats on cryptographic protocols like TLS, IPsec, and DNSSEC is built on a robust virtualized network infrastructure. This setup uses virtual machines or Docker containers to simulated is distinct roles, such as clients, servers, and adversaries, ensuring an isolated and controlled testing environment. The simulations integrate quantum-safe cryptography libraries, particularly those implementing algorithms proposed by NIST for post-quantum cryptography, to model quantum-resistant alternatives. These libraries benchmark the security and performance of existing cryptographic mechanisms like RSA and ECC against prospective quantum-resistant protocols.</p>
                <p>Additionally, tools such as Metasploit, Wireshark, and Scapy are employed for detailed packet inspection, protocol analysis, and attack simulation. These are complemented by custom scripts crafted to emulate quantum-specific attacks, like leveraging Shor&#x2019;s algorithm to decrypt RSA-based encryption. Specific scenarios include simulating a quantum-enabled man-in-the-middle attack on TLS to evaluate its reliance on RSA and ECC for key exchange and encryption, testing IPsec&#x2019;s Diffie-Hellman key exchange under quantum attack scenarios to assess the confidentiality of encrypted communications, and examining DNSSEC for potential vulnerabilities to quantum-enabled digital signature spoofing, focusing on RSA-based authentication.</p>
                <p>Despite its comprehensive design, this simulation environment has certain limitations due to quantum computing&#x2019;s current technological constraints. The computational power of advanced quantum systems is approximated through theoretical attack algorithms rather than real quantum hardware. Consequently, while these simulations offer valuable insights into potential quantum threats and protocol vulnerabilities, future research benefits significantly from the inclusion of real quantum computing systems to achieve a more precise evaluation of post-quantum cryptographic solutions. This highlights the need for ongoing refinement of testing methodologies as quantum technologies evolve.</p>
            </sec>
        </sec>
        <sec id="sec15">
            <title>4. Threat identification for widely used protocols</title>
            <p>This section analyzes potential threats associated with widely used network security protocols, focusing on vulnerabilities that could be exploited by attackers, including quantum-based risks.</p>
            <sec id="sec16">
                <title>4.1 Threat analysis for TLS</title>
                <p>Transport Layer Security (TLS) is a widely used protocol that ensures privacy and data integrity in internet communications by encrypting the data transmitted between clients and servers. However, the TLS protocol faces significant challenges in the face of advancing quantum computing, which threatens to compromise its cryptographic underpinnings. This threat analysis uses both the STRIDE and PASTA models to assess and categorize potential vulnerabilities in TLS, especially focusing on the risks associated with quantum computing advancements. 
                    <xref ref-type="fig" rid="f5">Figure. 5</xref> Shows us the overall threat identification workflow of Stride and Pasta.</p>
                <p>

                    <italic toggle="yes">4.1.1 STRIDE analysis</italic>
                </p>
                <p>Using the STRIDE threat model, the vulnerabilities of TLS in the face of quantum computing threats are categorized into six key dimensions, offering a detailed perspective on potential risks. Spoofing poses a significant risk as quantum algorithms like Shor&#x2019;s can break public-key cryptographic methods such as RSA and ECDSA. This capability could allow attackers to impersonate legitimate servers or clients during the TLS handshake, enabling unauthorized connections and the compromise of session authenticity. Tampering, another critical threat, could arise if attackers decrypt messages using quantum computing and then modify the data in transit, by passing TLS&#x2019;s Message Authentication Codes (MACs). This undermines the integrity of sensitive data exchanges. Repudiation risks escalate as quantum computing could enable the forging of digital signatures, like those based on ECDSA, eroding the non-repudiation assurances provided by TLS and allowing malicious actors to deny involvement in fraudulent activities. Information disclosure represents one of the most alarming vulnerabilities, as quantum computers could decrypt previously se-cure communications, exposing private data and causing severe confidentiality breaches. While denial-of-service (DoS) attacks are not directly enhanced by quantum computing, the additional computational overhead required for quantum-resistant cryptographic algorithms may strain server resources, making them more susceptible to overload or disruption. Lastly, the elevation of privilege becomes plausible as attackers could use quantum decryption to hijack authenticated sessions, gaining unauthorized access to privileged information and services. These vulnerabilities underscore the pressing need to develop and integrate quantum-resistant mechanisms into TLS to safeguard against emerging threats in the quantum era.</p>
                <p>

                    <italic toggle="yes">4.1.2 PASTA analysis</italic>
                </p>
                <p>The Process for Attack Simulation and Threat Analysis (PASTA) model provides a systematic, attacker-centric framework for evaluating the resilience of TLS against quantum computing threats. The analysis begins with the Definition of Objectives (DO), which focuses on identifying risks to the confidentiality, integrity, and availability of TLS-protected data due to vulnerabilities in its cryptographic mechanisms, including key exchange, encryption, and authentication. Next, the Definition of the Technical Scope (DTS) narrows the focus to RSA and ECC key exchange methods, digital signatures, and Message Authentication Codes (MACs), all of which are examined for susceptibility to quantum decryption algorithms like Shor&#x2019;s.</p>
                <p>In the Application Decomposition and Analysis (ADA) stage, TLS is broken into its core components&#x2014;handshake protocols, cipher suite negotiations, key exchange, and encrypted communication. Each element is individually scrutinized to determine how quantum threats might exploit these processes. The Threat Analysis (TA) phase identifies potential attack vectors, suchas a quantum-enabled man-in-the-middle (MitM) attack, where an adversary compromises RSA or ECC-based key exchanges during the TLS handshake, intercepting and decrypting sensitive data. The analysis progresses to Vulnerability and Weakness Analysis (VWA), which emphasizes the reliance of TLS on RSA and ECC, both vulnerable to quantum decryption. The Attack Simulation and Modeling (ASM) phase simulates quantum attacks in a controlled environment, demonstrating real-world implications, such as MitM attacks that compromise the confidentiality and integrity of TLS-encrypted data. Finally, Risk and Impact Analysis (RIA) evaluates the consequences of successful quantum-based attacks, highlighting severe risks such as compromised data privacy and weakened trust in TLS-based communication systems. These findings underscore the urgency of transitioning to quantum-resistant cryptographic solutions to safeguard against emerging threats.</p>
            </sec>
            <sec id="sec17">
                <title>4.2 Threat analysis for IPsec</title>
                <p>Internet Protocol Security (IPsec) is a suite of protocols widely used for securing communications at the network layer, primarily in VPNs and other secure IP-based connections. [
                    <xref ref-type="fig" rid="f6">Figure. 6</xref> Shows us the overall threat analysis framework with Stride, Pasta, and the security protocols]. IPsec provides confidentiality, integrity, and authentication, enabling secure transmission of sensitive information across IP networks. However, advancements in quantum computing present substantial risks to IPsec&#x2019;s cryptographic algorithms, particularly those used in key exchange and data encryption. This section applies the STRIDE and PASTA threat models to analyze and categorize quantum-based threats to IPsec.</p>
                <fig fig-type="figure" id="f6" orientation="portrait" position="float">
                    <label>Figure 6. </label>
                    <caption>
                        <title>Importance of Threat Modeling.</title>
                    </caption>
                    <graphic id="gr6" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/185658/d7f8ea08-95c4-4394-87c7-6cfba6904682_figure6.gif"/>
                </fig>
                <p>

                    <italic toggle="yes">4.2.1 STRIDE analysis</italic>
                </p>
                <p>Using the STRIDE threat model, the potential vulnerabilities of IPsec in the quantum era are systematically analyzed across six key dimensions. Spoofing poses a significant threat as quantum computing compromises the Diffie-Hellman (DH) key exchange, a cornerstone of the Internet Key Exchange (IKE) protocol. This allows attackers to recover keys, impersonate legitimate VPN endpoints, and gain unauthorized access. Tampering becomes critical when quantum attackers decrypt or derive crypto graphic keys, enabling them to modify data packets in transit and bypass IPsec&#x2019;s integrity mechanisms, suchas HMA Chashing and AES encryption, leading to undetected alterations of transmitted data.</p>
                <p>Repudiation risks emerge as quantum algorithms like Shor&#x2019;s could forge digital signatures used in IPsec authentication, allowing malicious actors to conduct harmful activities while denying responsibility. Information disclosure is perhaps the most severe risk, as quantum attacks on public-key algorithms like DH and RSA would enable adversaries to decrypt IPsec-secured data in transit, compromising privacy and exposing sensitive information. Denial of Service (DoS) attacks may be indirectly facilitated by quantum-resistant encryption demands that increase server computational loads. Additionally, attackers leveraging quantum capabilities could manipulate IKE sessions to disrupt or terminate active IPsec connections. Lastly, the elevation of privilege could occur when quantum attackers decrypt session keys, granting them unauthorized access to privileged IPsec sessions, and potentially allowing full control over VPN connections and administrative privileges. These vulnerabilities highlight the urgent need to develop quantum- resistant cryptographic protocols for IPsec.</p>
                <p>

                    <italic toggle="yes">4.2.2 PASTA analysis</italic>
                </p>
                <p>The Process for Attack Simulation and Threat Analysis (PASTA) model offers a systematic, attacker-centric framework to evaluate the potential vulnerabilities of IPsec in a quantum environment. The analysis begins with the Definition of Objectives (DO), aiming to identify weaknesses in IPsec&#x2019;s key exchange, encryption, and authentication mechanisms that could be exploited by quantum computing. This step highlights the need to explore quantum-resistant solutions by understanding where current cryptographic protocols fallshort. Next, the Definition of the Technical Scope (DTS) focuses on IPsec&#x2019;s core components, such as the Internet Key Exchange (IKE) protocol, Encapsulating Security Payload (ESP) for encryption, and Authentication Header (AH) for packet authentication. Each of these components is scrutinized for quantum vulnerabilities, particularly the susceptibility of Diffie-Hellman (DH) key exchange and RSA encryption methods.</p>
                <p>Following this, the Application Decomposition and Analysis (ADA) stage breaks IPsec into its modules for a detailed evaluation of its cryptographic mechanisms. Special attention is given to how quantum attacks might target IKE&#x2019;s DH-based key exchange, which could compromise the security of entire IPsec sessions. The Threat Analysis (TA) simulates potential quantum attack vectors, such as an adversary using quantum decryption capabilities to intercept or impersonate IPsec peers by breaking the DH-based key exchange. The Vulnerability and Weakness Analysis (VWA) evaluates the reliance of IPsec on algorithms like DH and RSA, both of which are vulnerable to quantum algorithms like Shor&#x2019;s, and assesses the impact of quantum attacks on hashing mechanisms such as HMAC. In the Attack Simulation and Modeling (ASM) stage, simulated quantum-enabled attacks on IPsec protocols are carried out in a controlled environment to observe the impact on data confidentiality and session integrity, emphasizing the real-world risks of quantum decryption. Finally, the Risk and Impact Analysis (RIA) evaluates the significant implications of quantum attacks on IPsec, especially regarding compromised confidentiality and integrity. This highlights the critical need for quantum-resistant cryptographic solutions to ensure the continued security of IPsec in the quantum era.</p>
            </sec>
            <sec id="sec18">
                <title>4.3 Threat analysis for DNSSEC</title>
                <p>Domain Name System Security Extensions (DNSSEC) is a suite of security protocols that enhances the DNS system by providing authentication of DNS data to prevent certain types of attacks, such as DNS spoofing. DNSSEC achieves this through digital signatures and public key cryptography, ensuring the integrity and authenticity of DNS records. However, as quantum computing advances, DNSSEC faces challenges, particularly concerning the robustness of its cryptographic foundations. This section uses the STRIDE and PASTA threat models to analyze potential threats to DNSSEC in the context of quantum computing.</p>
                <p>

                    <italic toggle="yes">4.3.1 STRIDE analysis</italic>
                </p>
                <p>The STRIDE threat model highlights several quantum-based vulnerabilities that can significantly affect DNSSEC, a protocol designed to ensure DNS integrity through cryptographic digital signatures. Spoofing threats could arise if quantum computers break the RSA or ECDSA signature algorithms used by DNSSEC. Quantum decryption capabilities could allow attackers to forge DNS responses and impersonate legitimate DNS servers, leading to unauthorized traffic redirection. This vulnerability could allow malicious actors to direct users to fraudulent websites, undermining the integrity of the DNS system. Similarly, Tampering risks are amplified in a quantum context. If quantum computers can decrypt or break the cryptographic signatures used in DNSSEC, attackers could alter DNS records and then sign them with forged signatures. This would allow attackers to manipulate DNS responses, potentially redirecting users to harmful websites or disrupting services reliant on DNSSEC&#x2019;s integrity checks.</p>
                <p>Repudiation threats would also be exacerbated, as attackers could use quantum computing to forge digital signatures, enabling them to deny responsibility for manipulating DNS records. This could undermine the core non-repudiation guarantees that DNSSEC provides, leaving the authenticity of DNS responses vulnerable to tampering. Furthermore, information disclosure risks are heightened when quantum computers break encryption methods that protect DNSSEC keys. Attackers could potentially decrypt protected communications, exposing sensitive DNS record information and even full domain configurations, compromising privacy and security. As DNSSEC transitions to more complex quantum-resistant cryptographic algorithms, Denial of Service (DoS) attacks might be come more prevalent. These algorithms could require significantly more computational power, and malicious actors could exploit this by overloading DNS servers, and disrupting services through resource exhaustion.</p>
                <p>Finally, the Elevation of Privilege threats could allow attackers to leverage quantum computing capabilities to break DNSSEC&#x2019;s keying mechanisms, granting them unauthorized control over DNS zones. This would enable attackers to manipulate DNS records at a higher level, directing internet traffic to their desired destinations, and potentially compromising entire networks and services. These vulnerabilities underscore the need for quantum-resistant cryptographic solutions to maintain the security of DNSSEC in the future.</p>
                <p>

                    <italic toggle="yes">4.3.2 PASTA analysis</italic>
                </p>
                <p>The Process for Attack Simulation and Threat Analysis (PASTA) model offers a structured approach for evaluating DNSSEC vulnerabilities in the context of quantum computing threats. This model is used to understand how quantum-enabled adversaries could exploit weaknesses in DNSSEC&#x2019;s cryptographic mechanisms, especially focusing on its public-key signing system that currently relies on RSA and ECC algorithms, both vulnerable to quantum decryption via Shor&#x2019;s algorithm.</p>
                <p>The Definition of Objectives (DO) stage aims to assess DNSSEC&#x2019;s susceptibility to quantum threats, primarily targeting the authenticity, integrity, and availability of DNS records. The goal is to identify potential cryptographic weaknesses in the system, particularly where quantum computing could potentially break current algorithms, leaving DNS infrastructure open to advanced cyber attacks. In the Definition of the Technical Scope (DTS), the analysis specifically targets DNSSEC&#x2019;s cryptographic components, particularly its use of RSA and ECC for signing DNS records. The scope of the analysis covers the vulnerabilities these algorithms have to quantum decryption methods, especially the potential impact of Shor&#x2019;s algorithm on DNSSEC&#x2019;s security.</p>
                <p>During the Application Decomposition and Analysis (ADA) stage, DNSSEC is broken down into key components such as the Zone Signing Key (ZSK), Key Signing Key (KSK), and the verification process performed by DNS resolvers. Each element is examined for quantum vulnerabilities, with a particular focus on how the signing and validation processes could be compromised by quantum computing. Threat Analysis (TA) identifies potential attack vectors that a quantum- enabled adversary might exploit. A key scenario involves an attacker using quantum decryption to break digital signatures, allowing them to impersonate DNS zones and redirect users to malicious websites by altering DNS records.</p>
                <p>The Vulnerability and Weakness Analysis (VWA) stage highlights DNSSEC&#x2019;s dependence on cryptographic signatures for integrity and authenticity. With quantum computing, the signature keys could be compromised, potentially allowing attackers to intercept or manipulate DNS responses. This breaks the fundamental role of DNSSEC in ensuring the authenticity of DNS records. During the Attack Simulation and Modeling (ASM) phase, simulated quantum attacks provide insight into the real-world implications of broken cryptographic signatures. For instance, a simulated attack might involve a quantum-enabled adversary breaking a DNSSEC-protected response and redirecting users to a malicious server by presenting a forged, yet seemingly authentic, DNS signature.</p>
                <p>Finally, Risk and Impact Analysis (RIA) evaluates the consequences of quantum attacks on DNSSEC. The analysis underscores the severe implications for internet security, as forged DNS records could undermine the entire trust model of DNSSEC. Such attacks would facilitate wide spread information disclosure, redirection, and potentially devastating security breaches for critical infrastructures relying on DNSSEC for safe communication. The results from this analysis further stress the urgent need for quantum-resistant algorithms to protect DNSSEC from future threats posed by quantum computing.</p>
            </sec>
        </sec>
        <sec id="sec19">
            <title>5. Comparative study of threats and risk assessment</title>
            <p>This section presents a comparative analysis of two widely recognized threat models&#x2014;STRIDE and PASTA&#x2014;focusing on their respective categories and the main threats associated with each protocol. It delves into the strengths and limitations of each model, highlighting their applicability in different security contexts. Additionally, the section includes a risk and impact assessment for several commonly used security protocols, offering a nuanced understanding of their vulnerabilities in the face of both classical and emerging quantum threats. These comprehensive comparisons, 
                <xref ref-type="table" rid="T1">
Table 1</xref> and 
                <xref ref-type="table" rid="T2">
Table 2</xref> allow for an in depth evaluation of threat modeling techniques and their relevance in addressing the evolving landscape of cyber security risks.</p>
            <table-wrap id="T1" orientation="portrait" position="float">
                <label>
Table 1. </label>
                <caption>
                    <title>Difference between Stride and Pasta.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Aspect</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">STRIDE</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">PASTA</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Purpose and Perspective</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Threat-centric; focuses on categorizing threats by six threat types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. Ideal for identifying general security vulnerabilities.
                                <sup>
                                    <xref ref-type="bibr" rid="ref20">20</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Attacker-centric and risk-oriented; aims to understand the attacker&#x2019;s perspective, motivations, and impact of threats. Suitable for complex attack scenarios like those involving quantum computing.
                                <sup>
                                    <xref ref-type="bibr" rid="ref21">21</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Structure and Process</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Straight forward; threats are categorized and mapped to system components. Limited in depth as it primarily identifies threats without extensive risk analysis.
                                <sup>
                                    <xref ref-type="bibr" rid="ref20">20</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Multi-stage process (seven stages), including objectives definition, application decomposition, threat and vulnerability analysis, and risk assessment. Provides a comprehensive view of threats andrisks.
                                <sup>
                                    <xref ref-type="bibr" rid="ref22">22</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Level of Granularity</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High-level categorization; suitable for quickly identifying security issues in the system components. Limited in assessing sophisticated threats requiring deeper analysis.
                                <sup>
                                    <xref ref-type="bibr" rid="ref20">20</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High granularity and depth, involving detailed risk and impact analysis as well as attack simulation. Effective for identifying and analyzing complex threats like those posed by quantum decryption.
                                <sup>
                                    <xref ref-type="bibr" rid="ref23">23</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Applicability to Quantum Threats</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Useful for broadly identifying quantum threats in cryptographic protocols. However, it lacks a risk-focused approach and may not fully capture the evolving threat landscape of quantum computing.
                                <sup>
                                    <xref ref-type="bibr" rid="ref2">2</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Highly suitable for quantum threat analysis. Can simulate quantum attack scenarios, assess risks, and evaluate the impact of quantum-enabled threats on protocols like TLS, IPsec, and DNSSEC.
                                <sup>
                                    <xref ref-type="bibr" rid="ref24">24</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Strengths</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Simple and systematic; allows quick categorization and identification of potential threats to system components.
                                <sup>
                                    <xref ref-type="bibr" rid="ref20">20</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Comprehensive and attacker-focused; evaluates complex attack vectors, risk, and impact, making it ideal for advanced threats.
                                <sup>
                                    <xref ref-type="bibr" rid="ref23">23</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Limitations</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Limited risk assessment and lack of attacker motivation analysis; less effective for in depth risk and impact studies.
                                <sup>
                                    <xref ref-type="bibr" rid="ref20">20</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Complex and time intensive process; requires more resources and expertise to complete the multi-stage analysis.
                                <sup>
                                    <xref ref-type="bibr" rid="ref2">2</xref>
                                </sup>
                            </td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <table-wrap id="T2" orientation="portrait" position="float">
                <label>
Table 2. </label>
                <caption>
                    <title>Categories of threat and their details.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Protocol</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Threat Category</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Main Threats</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Description</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="4" valign="top">
                                <bold>TLS</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Spoofing</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Certificate Forgery
                                <sup>
                                    <xref ref-type="bibr" rid="ref25">25</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Quantum-enabled attackers could break TLS certificates&#x2019; cryptographic signatures (e.g., RSA or ECC), allowing for man-in-the-middle (MITM) attacks.
                                <sup>
                                    <xref ref-type="bibr" rid="ref9">9</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Tampering</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Altered Communication
                                <sup>
                                    <xref ref-type="bibr" rid="ref26">26</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">An attacker may intercept and modify data transmitted over TLS by breaking cryptographic keys and altering messages.
                                <sup>
                                    <xref ref-type="bibr" rid="ref27">27</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Information Disclosure</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Eavesdropping
                                <sup>
                                    <xref ref-type="bibr" rid="ref28">28</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Quantum computers could decrypt intercepted TLS traffic, leading to data leakage of sensitive information such as passwords and personal data
                                <sup>
                                    <xref ref-type="bibr" rid="ref29">29</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Denial of Service</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Computational Overload
                                <sup>
                                    <xref ref-type="bibr" rid="ref30">30</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">More complex quantum-resistant algorithms could increase TLS processing requirements, making systems vulnerable to DoS attacks by over whelming resources.
                                <sup>
                                    <xref ref-type="bibr" rid="ref31">31</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="4" valign="top">
                                <bold>IPsec</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Spoofing</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Identity Impersonation
                                <sup>
                                    <xref ref-type="bibr" rid="ref28">28</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Quantum decryption may allow attackers to spoof IPsec end points, enabling unauthorized network access.
                                <sup>
                                    <xref ref-type="bibr" rid="ref32">32</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Tampering</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Data Manipulation
                                <sup>
                                    <xref ref-type="bibr" rid="ref33">33</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Attackers could alter the data in IPsec-secured communication channels by breaking encryption keys, affecting data integrity.
                                <sup>
                                    <xref ref-type="bibr" rid="ref31">31</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Information Disclosure</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Confidentiality Breach
                                <sup>
                                    <xref ref-type="bibr" rid="ref34">34</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Quantum attacks could decrypt encrypted IPsec tunnels, exposing private communications and network configurations.
                                <sup>
                                    <xref ref-type="bibr" rid="ref35">35</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Elevation of Privilege</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Unauthorized
                                <break/>Network Access
                                <sup>
                                    <xref ref-type="bibr" rid="ref30">30</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Through quantum decryption of authentication protocols, attackers could gain unauthorized, privileged access to secure network segments.
                                <sup>
                                    <xref ref-type="bibr" rid="ref36">36</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="4" valign="top">
                                <bold>DNSSEC</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Spoofing</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">DNS Record Forgery
                                <sup>
                                    <xref ref-type="bibr" rid="ref37">37</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Quantum-based attacks on DNSSEC&#x2019;s cryptographic key scould allow attackers to forge DNS responses, redirecting traffic to malicious sites.
                                <sup>
                                    <xref ref-type="bibr" rid="ref38">38</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Tampering</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">DNS Data Modification
                                <sup>
                                    <xref ref-type="bibr" rid="ref39">39</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Attackers could modify DNS records by forging digital signatures, affecting the integrity of DNS responses.
                                <sup>
                                    <xref ref-type="bibr" rid="ref40">40</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Information Disclosure</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">DNS Information
                                <break/>Exposure
                                <sup>
                                    <xref ref-type="bibr" rid="ref41">41</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Decrypted DNSSEC-protected records could reveal sensitive information about DNS zone configurations.
                                <sup>
                                    <xref ref-type="bibr" rid="ref42">42</xref>
                                </sup>
                            </td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Denial of Service</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Increased Processing Overhead
                                <sup>
                                    <xref ref-type="bibr" rid="ref43">43</xref>
                                </sup>
                            </td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Adoption of quantum-resistant cryptographic techniques could slow down DNSSEC verification, making it susceptible to DoS attacks.
                                <sup>
                                    <xref ref-type="bibr" rid="ref44">44</xref>
                                </sup>
                            </td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <sec id="sec20">
                <title>5.1 Comparative analysis: Stride vs Pasta</title>
            </sec>
            <sec id="sec21">
                <title>5.2 Threat categories and main threats for each protocol</title>
                <p>Various network security protocols face distinct threats due to evolving attack methodologies, particularly with advancements in quantum computing. The primary threat categories include spoofing, tampering, information disclosure, denial of service, and elevation of privilege. Each protocol&#x2014;TLS, IPsec, and DNSSEC&#x2014;has specific vulnerabilities that attackers can exploit, potentially compromising data confidentiality, integrity, and availability.</p>
            </sec>
            <sec id="sec22">
                <title>5.3 Risk and impact analysis for TLS, IPSEC, and DNSSEC</title>
                <p>With the growing threat of quantum-enabled attacks, traditional security protocols such as TLS, IPsec, and DNSSEC face significant risks. These risks include unauthorized access, data breaches, man-in-the-middle attacks, and service disruptions. The impact of these threats can range from confidentiality breaches and data manipulation to system downtime and loss of trust in secure communications.</p>
                <p>For a detailed assessment of the risks and their potential impact on each protocol, refer to 
                    <xref ref-type="table" rid="T3">
Table 3</xref>.</p>
                <table-wrap id="T3" orientation="portrait" position="float">
                    <label>
Table 3. </label>
                    <caption>
                        <title>Risk and impact analysis for TLS, IPsec, and DNSSEC.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Protocol</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Risk</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Impact</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Description</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="3" valign="top">
                                    <bold>TLS</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Quantum Decryption of Traffic
                                    <sup>
                                        <xref ref-type="bibr" rid="ref45">45</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High: Confidentiality Breach
                                    <sup>
                                        <xref ref-type="bibr" rid="ref46">46</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">A quantum attacker could decrypt TLS sessions, exposing sensitive data like passwords, credit card details, and personal information.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref47">47</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Man-in-the-Middle (MITM) Attacks
                                    <sup>
                                        <xref ref-type="bibr" rid="ref48">48</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High: Loss of Data Integrity and Privacy
                                    <sup>
                                        <xref ref-type="bibr" rid="ref49">49</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">If digital certificates are compromised, attackers could intercept and alter communications in real-time, affecting trust and data integrity.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref49">49</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Increased Processing Requirements for Quantum-Resistant

                                    <break/>Algorithms
                                    <sup>
                                        <xref ref-type="bibr" rid="ref50">50</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Moderate: Potential Denial of Service
                                    <sup>
                                        <xref ref-type="bibr" rid="ref51">51</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implementing quantum-safe algorithms may require more resources, leading to slower processing and potential DoS vulnerabilities.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref52">52</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="3" valign="top">
                                    <bold>IPsec</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Unauthorized Network Access
                                    <sup>
                                        <xref ref-type="bibr" rid="ref53">53</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High: Confidentiality and Integrity Breach
                                    <sup>
                                        <xref ref-type="bibr" rid="ref54">54</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Decryption of IPsec Tunnels would expose network traffic, allowing attackers to monitor and manipulate sensitive communications within secured networks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref55">55</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Network Configuration Exposure
                                    <sup>
                                        <xref ref-type="bibr" rid="ref56">56</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High: Operational Security Risk
                                    <sup>
                                        <xref ref-type="bibr" rid="ref57">57</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Quantum decryption could reveal critical network configurations, enabling attackers to navigate secure network segments and potentially escalate privileges.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref34">34</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">DoS from Quantum-Resistant Protocol Overhead
                                    <sup>
                                        <xref ref-type="bibr" rid="ref58">58</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Moderate: Availability Risk
                                    <sup>
                                        <xref ref-type="bibr" rid="ref59">59</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Increased computational demand for quantum-resistant cryptography might strain resources, making IPsec deployments more vulnerable to DoS attacks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref60">60</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="3" valign="top">
                                    <bold>DNSSEC</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">DNS Spoofing and RedirectingTraffic
                                    <sup>
                                        <xref ref-type="bibr" rid="ref61">61</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">High: Integrity and Availability Breach
                                    <sup>
                                        <xref ref-type="bibr" rid="ref54">54</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">With quantum-based attacks, DNSSEC records could be forged, redirecting users to malicious sites and disrupting trust in DNS security.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref62">62</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Exposure of Sensitive DNSData
                                    <sup>
                                        <xref ref-type="bibr" rid="ref41">41</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Moderate: Confidentiality
                                    <sup>
                                        <xref ref-type="bibr" rid="ref63">63</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Decrypted DNSSEC records could expose data about internal network structures, facilitating further attacks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref64">64</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">DoS due to Performance Overheads with Quantum-Resistant

                                    <break/>Cryptography
                                    <sup>
                                        <xref ref-type="bibr" rid="ref65">65</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Moderate: System and Network Downtime
                                    <sup>
                                        <xref ref-type="bibr" rid="ref66">66</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Quantum-resistant algorithms could slow DNSSEC operations, increasing vulnerability to DoS attacks and impacting networkavailability.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref31">31</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
            <sec id="sec23">
                <title>5.4 Threat intelligence: Key insights</title>
                <p>Quantum computing poses significant challenges to the security of protocols like TLS, IPsec, and DNSSEC, which are foundational for the security of Internet communications. One of the most pressing concerns is the increased vulnerability of the public key infrastructure (PKI) that underpins these protocols. Quantum algorithms, especially Shor&#x2019;s algorithm, threaten to break the cryptographic algorithms that rely on public key encryption, such as RSA and ECC. As quantum computing advances, these vulnerabilities become more critical, and there is an urgent need to develop quantum-resistant cryptographic solutions before malicious actors exploit them.</p>
                <p>Confidentiality is another major concern across all three protocols. Quantum decryption techniques could potentially expose sensitive data that was previously secured through traditional encryption methods used in TLS, IPsec, and DNSSEC. This includes personal data, financial transactions, and DNS configurations that are crucial for network security. To mitigate these risks, quantum-safe encryption methods need to be adopted to safeguard privacy. The computational power of quantum machines demands the creation of encryption algorithms that are resistant to quantum decryption, requiring significant advancements in cryptography to keep pace with quantum capabilities. Data integrity and trust are at particular risk, especially for TLS and DNSSEC, which rely heavily on digital signatures and certificates to verify the authenticity of communications and data. Quantum-powered attacks could enable spoofing or man-in-the-middle attacks, where attackers could forge certificates or manipulate DNS responses to redirect users to malicious sites. The ability to maintain data integrity and trust is essential in preventing these types of attacks. Quantum-resistant algorithms must be developed to protect against such threats, ensuring that authentication processes remain secure and that users can trust the systems they rely on. The shift to quantum-resistant cryptography, however, is not without its challenges. These algorithms are likely to impose greater computational demands on the systems using them, which could affect the performance of protocols like IPsec and DNSSEC, both of which require high-speed processing. The increased computational burden could lead to vulnerabilities such as Denial of Service (DoS) attacks, where adversaries could overload systems with processing heavy operations. Ensuring that quantum-resistant algorithms are optimized for efficiency and scalability is crucial in maintaining protocol performance, especially in real time network functions. As quantum threats affect multiple aspects of security&#x2014;confidentiality, integrity, and availability&#x2014;adopting a multilayered security approach is vital. A comprehensive defense strategy combining quantum-resistant encryption with additional security controls like network segmentation and continuous monitoring is necessary to mitigate quantum-driven vulnerabilities. This layered defense approach provides robust protection against the broad spectrum of quantum threats that could compromise the security of internet communications. Early adoption of quantum-resistant algorithms is critical to safeguarding sensitive data and communications before quantum technologies mature. Transitioning to quantum-safe encryption now can protect not only future data but also historical data that could be vulnerable to retroactive decryption by quantum systems. High-risk sectors and critical infrastructure should prioritize this transition to ensure long-term security and avoid the vulnerabilities associated with quantum decryption techniques. 
                    <xref ref-type="table" rid="T3">
Table 3</xref> shows us the comparative risk and impact analysis for widely used protocols.</p>
                <p>Finally, the inter connected nature of TLS, IPsec, and DNSSEC means that vulnerabilities in one protocol could have cascading effects on others. For example, a DNSSEC breach could undermine the security of TLS-based web applications, while an IPsec breach could exposed at a crucial for DNSSEC&#x2019;s integrity. To mitigate these cross-protocol risks, a coordinated and synchronized approach to security across these protocols is necessary. This comprehensive strategy helps protect the entire network infrastructure from quantum-driven threats, ensuring that all protocols remain secure in the face of quantum computing advancements.</p>
            </sec>
        </sec>
        <sec id="sec24">
            <title>6. Attack scenarios for widely used protocols</title>
            <p>In this section, we analyze the attack scenarios for widely used protocols.</p>
            <sec id="sec25">
                <title>6.1 Attack scenarios for TLS</title>
                <p>We explore attack scenarios targeting TLS (Transport Layer Security) to assess the vulnerabilities and impact of quantum-related threats. The focus is on understanding how advancements in quantum computing, particularly quantum decryption techniques, could compromise TLS security by exploiting weaknesses in its cryptographic foundations. Each scenario highlights a distinct quantum threat vector, shedding light on the need for quantum-resistant measures to protect against these emerging risks.</p>
                <p>One such scenario involves a Man-in-the-Middle (MITM) attack using quantum-decrypted certificates. In this attack, an adversary intercepts communications between a client and a server and impersonates a legitimate participant. Quantum decryption capabilities could enable attackers to break the asymmetric cryptographic keys used in TLS, such as RSA or ECC. These widely used cryptographic algorithms rely on the assumption that breaking their encryption is computationally infeasible with classical computing methods. However, quantum algorithms like Shor&#x2019;s algorithm could efficiently decrypt the private keys, allowing attackers to forge digital certificates. The emulation involves an attacker intercepting and decrypting TLS certificates in transit, thereby gaining unauthorized access to confidential data. Once the certificates are forged, the attacker can manipulate the data being exchanged, potentially altering messages or injecting malicious content into the communication stream. This type of attack undermines both the confidentiality and integrity of the session, as the attacker can access sensitive information without detection and tamper with the communication flow. This scenario aims to assess the feasibility and impact of a quantum-driven MITM attack on TLS communications. The expected outcome demonstrate show quantum decryption could facilitate certificate forgery, which would allow attackers to manipulate data, impersonate legitimate entities, and compromise session confidentiality and integrity. This highlights the urgency of transitioning to quantum-resistant cryptographic algorithms that can with stand the power of quantum computing, ensuring the continued trust worthiness and security of TLS communications in the quantum era.</p>
                <p>Another scenario reproduces a sophisticated eavesdropping attack in which quantum computing capabilities break the encryption key used in a TLS session, enabling attackers to decrypt traffic in real time. In traditional TLS encryption, symmetric algorithms like AES (Advanced Encryption Standard) are employed to protect data during transmission. These algorithms rely on the secrecy of the encryption key, which ensures that only authorized parties can decrypt the data. However, with the advent of quantum computing, attackers can leverage quantum decryption techniques to break these encryption methods much more efficiently than classical computers. In this attack, the focus is on how quantum algorithms, particularly Grover&#x2019;s algorithm, could be used to expedite the process of breaking AES encryption. While Grover&#x2019;s algorithm offers a quadratic speedup over classical brute force methods, it could still significantly reduce the time needed to decrypt encrypted traffic. By intercepting a TLS session, an attacker could use quantum computing to decrypt sensitive data, such as passwords, credit card numbers, personal identification details, and other private information, all without alerting the communicating parties. This breach would compromise confidentiality, as sensitive data would be exposed without the knowledge of the users involved in the communication. The objective of this is to evaluate the threat level and the data exposure risk if quantum decryption techniques were applied to TLS-protected data. The expected outcome of this scenario illustrates how quantum attacks could breach the confidentiality of encrypted communications, under scoring the critical need for quantum-resistant encryption methods. These advanced encryption algorithms must be developed to safeguard data privacy in the quantum computing era, ensuring that encryption remains robust even against quantum-powered decryption techniques. This scenario highlights the urgency for transitioning to quantum-safe encryption protocols to protect against future threats to data confidentiality.</p>
                <p>In the third scenario, an attack is downgraded where the attacker forces a TLS session to negotiate and use older, weaker encryption algorithms that are no longer considered secure. The focus here is on legacy cryptographic algorithms, such as RSA-1024, which were once widely used but have since been deemed vulnerable to modern attacks. Specifically, quantum computing&#x2019;s potential to break these older algorithms more efficiently than classical methods presents a serious risk. By emulating quantum decryption attacks on out dated encryption methods like RSA-1024, this scenario highlights the possibility that TLS, due to backward compatibility, could fall back to using these weaker algorithms during the negotiation phase. Quantum algorithms, such as Shor&#x2019;s algorithm, can efficiently factorize large numbers, rendering RSA-1024 particularly susceptible to quantum attacks. If an attacker can exploit this weakness, they can intercept or decrypt data, undermining the security of the TLS session. The objective of this simulation is to understand the risk posed by these downgrade attacks, especially when a protocol such as TLS negotiates encryption standards that include weak backward compatibility. In the face of quantum advancements, legacy encryption methods are highly vulnerable and should no longer be supported. The expected outcome is a demonstration of the importance of eliminating deprecated algorithms from TLS configurations. By ensuring that the protocol no longer supports weak encryption methods such as RSA-1024, the overall security of TLS can be reinforced. This scenario emphasizes the need for the adoption of quantum-resistant cryptographic algorithms, which makes TLS more resilient to quantum-based attacks and ensure that backward compatibility does not introduce new vulnerabilities into the system.</p>
                <p>The final scenario explores the potential performance degradation of TLS servers when quantum- resistant algorithms are implemented, focusing on the risk of Denial of Service (DoS) attacks. Quantum-resistant cryptographic algorithms, designed to with stand the capabilities of quantum computing, are expected to require significantly more computational resources than current cryptographic techniques. As a result, this increased demand could overwhelm systems not optimized for these new algorithms, leading to as low down or even complete service disruption. In this, the attacker targets a TLS server by sending an overwhelming number of requests that are resource intensive due to the increased cryptographic load of quantum-resistant encryption. The goal is to evaluate how the server manages its computational resources when faced with a flood of these requests. By emulating this scenario, we assess whether the TLS server&#x2019;s performance can withstand the added strain and continue to function effectively. The objective of this simulation is to determine the impact of quantum-resistant encryption on server performance, particularly under high load. As quantum-resistant algorithms are expected to be more computationally demanding, this scenario tests whether TLS servers can continue to operate efficiently without being susceptible to DoS attacks that exploit these increased resource requirements. The expected outcome of this scenario is a demonstration of potential availability issues arising from the adoption of quantum-resistant cryptography. It highlights the need for a careful balance between security and performance when implementing quantum-resistant algorithms in TLS. To avoid performance bottlenecks and ensure system availability, it is crucial for TLS implementations to optimize quantum-safe encryption techniques, ensuring they can handle high traffic volumes without succumbing to DoS attacks.</p>
            </sec>
            <sec id="sec26">
                <title>6.2 Attack scenarios for IPsec</title>
                <p>This section examines the potential attack scenarios for IPsec (Internet Protocol Security) in the context of quantum computing advancements. IPsec, a suite of protocols used to secure IP communications through encryption and authentication relies on cryptographic techniques that are vulnerable to quantum attacks. These highlight the specific risks posed by quantum computing to IPsec&#x2019;s security, including confidentiality, integrity, and availability.</p>
                <p>The first scenario is where the quantum adversary leverages advanced decryption techniques to break the encryption protocols commonly used in IPsec, such as the Diffie-Hellman key exchange and RSA encryption. Quantum computing&#x2019;s potential to solve mathematical problems much faster than classical computers enables attackers to decrypt IPsec packets that were previously secure. The decryption process involves breaking the cryptographic keys used to protect data transmitted over VPNs and other secure communication channels. By bypassing these encryption measures, attackers can gain unauthorized access to sensitive information, compromising the privacy of data in transit. The objective of this analysis is to assess the potential risk of IPsec&#x2019;s current encryption standards becoming obsolete in the face of quantum decryption. Given the power of quantum computing to efficiently solve mathematical problems that underlie traditional encryption algorithms, it&#x2019;s critical to evaluate whether the cryptographic techniques used in IPsec withstands quantum attacks. The expected outcome of this scenario reveals that quantum capabilities could easily break existing encryption methods, allowing attackers to expose private communications and sensitive data flow. This underscores the need for the development and adoption of quantum-resistant encryption techniques, particularly quantum-safe key exchange methods, to ensure the continued confidentiality and integrity of IPsec-secured communications.</p>
                <p>In another scenario, the quantum decryption capabilities of an attacker are used to break the digital signatures that IPsec relies on to authenticate communication parties. Digital signatures are a key component of IPsec&#x2019;s security mechanism, assuring that the entities involved in a communication session are legitimate. However, with the advent of quantum decryption, attackers could easily forge these signatures, making it possible to impersonate a trusted entity. The attacker could then intercept an ongoing IPsec session, manipulate the data packets being transmitted, and insert malicious data into the communication stream by exploiting the forged authentication credentials. The objective of this analysis is to evaluate how the decryption of authentication keys using quantum techniques could undermine the integrity of IPsec. By breaking the cryptographic keys that underpin the authentication process, quantum-enabled attackers would have the ability to disrupt the trust worthiness of an IPsec session. This would allow them to covertly manipulate secure communications, undetected by the legitimate participants. The expected outcome of this scenario highlights the potential risks to data integrity in IPsec communications. It demonstrates that quantum decryption could enable attackers to compromise data integrity, disrupt secure connections, and manipulate information without raising any alarms, thus severely undermining the trust and security that IPsec provides in protecting network traffic.</p>
                <p>In the third scenario, attackers leverage quantum decryption techniques to break the session keys used in IPsec, enabling them to execute are play attack. A replay attack occurs when an attacker captures legitimate data packets from a secure communication session and retransmits them to trick the receiving system into acting on outdated or manipulated information. By decrypting the session keys, the attacker can easily access and manipulate the captured data packets, injecting them back into the IPsec stream. This could lead to confusion or manipulation of the receiving system, which would interpret there played data as valid, potentially leading to malicious actions or disruptions. The objective of this analysis is to assess the feasibility of replay attacks under the influence of quantum decryption. Quantum computing has the potential to break the encryption mechanisms securing session keys, allowing adversaries to intercept and replay data without detection. The expected outcome of this investigation highlights vulnerabilities in both data integrity and session management within IPsec, underscoring the importance of incorporating quantum-resistant techniques. Specifically, nonce-based methods could be employed to prevent replay attacks, as nonces ensure that data packets are not reused in appropriately, protecting against potential quantum-enabled replays. This reinforces the need for updated, quantum-secure protocols to safeguard the integrity of data and session continuity.</p>
                <p>In the final scenario, the increased computational demands of quantum-resistant encryption methods could make IPsec more susceptible to Denial of Service (DoS) attacks. As quantum- resistant algorithms require more processing power and resources to execute, attackers could exploit these increased demands by overloading the IPsec server with resource-intensive cryptographic requests. This overload would exhaust the system&#x2019;s resources, potentially leading to performance degradation or complete service interruptions. The attacker could send a flood of requests that require substantial computational work to be processed, testing the IPsec server&#x2019;s ability to maintain service and performance under high cryptographic loads. The objective of this scenario is to evaluate IPsec&#x2019;s availability and performance when subjected to the increased computational demands of quantum-resistant encryption. The expected outcome highlights the potential for bottlenecks in performance or service disruption, illustrating the need for optimized and efficient quantum- resistant encryption algorithms. These optimized algorithms would need to strike a balance between ensuring quantum security and maintaining IPsec&#x2019;s high availability, thus preventing the system from becoming vulnerable to DoS attacks due to excessive resource consumption. This underscores the importance of designing encryption methods that are both secure against quantum threats and efficient in their computational requirements, ensuring robust network performance even under load.</p>
            </sec>
            <sec id="sec27">
                <title>6.3 Attack scenarios for DNSSEC</title>
                <p>In this section, we examine the attack scenarios on DNSSEC (Domain Name System Security Extensions) in light of quantum computing advancements. DNSSEC adds security to DNS by enabling authentication of responses to domain name queries, preventing data tampering and spoofing. However, the cryptographic foundations of DNSSEC are vulnerable to quantum decryption, which could undermine DNS integrity, authenticity, and availability. These demonstrate the potential risks and help identify areas for enhancing DNSSEC&#x2019;s resilience.</p>
                <p>In the first scenario, DNSSEC&#x2019;s reliance on digital signatures to authenticate DNS records makes it vulnerable to quantum decryption attacks. These signatures are based on public-key cryptography, which quantum computers could potentially break using advanced decryption algorithms. This would allow an attacker to intercept DNS responses, decrypt the digital signatures, and forge valid-looking DNS records. By manipulating these records, the attacker could redirect users to fraudulent websites or otherwise alter DNS information, compromising the integrity of DNSSEC. The objective of this scenario is to assess the risks posed by quantum decryption of DNSSEC signatures, specifically in enabling DNS spoofing attacks. The expected outcome demonstrates how quantum decryption could facilitate the forgery of DNSSEC signatures, leading to the manipulation of DNS records. Such attacks could have serious consequences, including the redirection of users to malicious sites, theft of sensitive information, or the spread of malware. This scenario underscores the critical need for quantum-resistant cryptographic signatures in DNSSEC to protect the integrity and trustworthiness of DNS systems in the future.</p>
                <p>In this scenario, cache poisoning is explored as a potential threat to DNSSEC under quantum decryption conditions. Cache poisoning occurs when an attacker injects false DNS data into a DNS resolver&#x2019;s cache, causing the resolver to store and potentially serve incorrect DNS records. With quantum decryption, adversaries would have the ability to forge DNSSEC responses by decrypting the cryptographic signatures used to verify DNS records. This enables attackers to insert malicious records into the cache, tricking DNS resolvers into accepting and storing falsified data. The objective of this scenario is to examine the potential for large-scale cache poisoning attacks facilitated by quantum decryption techniques. If attackers can inject in correct or malicious DNS records into the resolver&#x2019;s cache, they can redirect users to harmful sites or intercept communications, effectively manipulating the integrity of the DNS system. The expected outcome reveals how quantum decryption could make DNSSEC vulnerable to such attacks, emphasizing the need for stronger, quantum-resistant verification methods to prevent widespread DNS manipulations and maintain trust in DNSSEC systems. The scenario highlights the necessity of preparing DNS systems for quantum threats to ensure continued protection against cache poisoning attacks.</p>
                <p>In another scenario, the focus is on a downgrade attack that targets DNSSEC by exploiting its support for multiple cryptographic algorithms, some of which are weaker and more susceptible to quantum attacks. DNSSEC typically supports a variety of algorithms, with some legacy algorithms, such as RSA-1024, being far more vulnerable to the computational power of quantum decryption techniques. An attacker could exploit this weakness by forcing the DNSSEC protocol to fall back to these less secure, outdated algorithms. With quantum decryption capabilities, the attacker could easily break the weaker cryptography, exposing the DNSSEC infrastructure to further vulnerabilities. The objective of this scenario is to assess the risk posed by such quantum-enabled downgrade attacks. If DNSSEC is coerced into using obsolete cryptographic standards, it significantly weakens the overall security of the system. By leveraging quantum decryption to break weaker algorithms, attackers could potentially intercept or manipulate DNS traffic, undermining the trust and integrity that DNSSEC is designed to provide. The expected outcome of this scenario emphasizes the vulnerabilities introduced when outdated cryptographic standards are used, underlining the importance of phasing out legacy algorithms and adopting quantum-resistant protocols across all DNSSEC transactions to prevent such attacks. The scenario highlights the critical need for modernizing cryptographic practices to withstand quantum threats and ensure the continued security of DNSSEC.</p>
                <p>In the final scenario, the adoption of quantum-resistant algorithms in DNSSEC introduces a significant challenge related to increased computational requirements. These algorithms, designed to protect against quantum decryption, demand considerably more processing power than current cryptographic methods. This strain on resources can potentially expose DNS servers to Denial of Service (DoS) attacks, where the server is overwhelmed by a high volume of resource-intensive DNSSEC queries. The test here is to understand how well DNS servers can handle such high computational loads while maintaining their availability and performance. The goal of this assessment is to evaluate whether DNS servers can continue to operate effectively under the increased cryptographic demands posed by quantum-resistant algorithms. If DNS servers cannot handle these demands efficiently, it could lead to service disruptions, with performance bottlenecks or even complete service outages. This scenario underscores the need for optimized, efficient quantum- resistant algorithms that can safeguard DNSSEC against quantum attacks without compromising the server&#x2019;s ability to maintain availability. Therefore, ensuring that quantum-resistant protocols are both secure and efficient is essential to the future of DNS security.</p>
            </sec>
            <sec id="sec28">
                <title>6.4 Comparative results from STRIDE and PASTA models</title>
                <p>The comparative analysis of STRIDE and PASTA models (
                    <xref ref-type="table" rid="T4">
Table 4</xref>) highlights their distinct approaches to threat modeling, emphasizing their strengths and limitations in addressing security challenges, including quantum threats.</p>
                <table-wrap id="T4" orientation="portrait" position="float">
                    <label>
Table 4. </label>
                    <caption>
                        <title>STRIDE VS. PASTA.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Criteria</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">STRIDE Model</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">PASTA Model</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Approach and Focus</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Threat-based, focusing on categorizing threats by type (e.g., Spoofing, Tampering).
                                    <sup>
                                        <xref ref-type="bibr" rid="ref67">67</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Process-based, analyzing each phase of an attack life cycle, from reconnaissance to exploitation and impact assessment.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref68">68</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>TLS Key Insights</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Identifies risks like Information Disclosure due to quantum decryption.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref69">69</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Highlights vulnerabilities in reconnaissance and exploitation phases due to quantum decryption of session keys.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref70">70</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Notes spoofing and tampering risks from compromised certificates.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref71">71</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Emphasizes potential for persistent access to decrypted sessions in the post-exploitation phase.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref72">72</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>IPsec Key Insights</bold>
</td>
                                <td align="left" colspan="1" rowspan="2" valign="top">Highlights Information Disclosure and Elevation of Privilege risks via quantum decryption of IPsec channels.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref31">31</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Shows initial exploitation phase vulnerabilities through interception of encrypted data.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref73">73</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Impact analysis phase reveals risks of widespread data leaks if channels are decrypted.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref74">74</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>DNSSEC Key Insights</bold>
</td>
                                <td align="left" colspan="1" rowspan="2" valign="top">Identifies Spoofing and Tampering as a major risk from quantum-decrypted digital signatures.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref75">75</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">The escalation and exploitation phases show how attackers could redirect traffic through altered DNS records.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref41">41</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Impact assessment phase shows potential for large scale DNS manipulation.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref76">76</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Depth of Analysis</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Provides high-level threat categorization, useful for broad quantum risk identification.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref73">73</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Offers detailed insights into attack stages, useful for complex scenario simulation and impact assessment.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref77">77</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Attack Lifecycle Analysis</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Focuses on categorizing threats without a step-by-step attack life cycle break down.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref23">23</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Provides a comprehensive view across the attack lifecycle stages, revealing phase-specific vulnerabilities.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref78">78</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Risk Identification</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Efficient for quickly identifying types of quantum-related threats in each protocol.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref39">39</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Suited for simulating detailed attack scenarios and understanding attack evolution.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref79">79</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Overall Usefulness</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Useful for summarizing quantum risks across protocols and identifying broad vulnerabilities.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref80">80</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Effective for in depth attack progression analysis and understanding quantum attack feasibility at each stage.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref81">81</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Best Use Case</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Quick categorization of threats, ideal for a high-level overview.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref82">82</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Detailed attack simulation and phased threat analysis, ideal for deeper investigation into specific vulnerabilities.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref23">23</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
        </sec>
        <sec id="sec29">
            <title>7. Mitigation strategies and recommendations</title>
            <p>This section provides a detailed discussion of the various solutions and strategies to solve the threats followed by recommendations for them, respectively.</p>
            <sec id="sec30">
                <title>7.1 Mitigation for TLS threats</title>
                <p>Quantum computing poses significant challenges to the security of TLS (Transport Layer Security) due to its reliance on public-key cryptography for secure communications. With the advent of quantum decryption capabilities, several proactive and defensive strategies must be implemented to safeguard TLS against quantum-enabled threats. 
                    <xref ref-type="table" rid="T5">
Table 5</xref> below contains the mitigation strategies focusing on protecting the confidentiality, integrity, and authenticity of TLS communications.</p>
                <table-wrap id="T5" orientation="portrait" position="float">
                    <label>
Table 5. </label>
                    <caption>
                        <title>Mitigation strategies for TLS against quantum threats.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Mitigation Area</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Strategy</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Details</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Transition to Post Quantum Cryptography</bold>
                                    <xref ref-type="bibr" rid="ref83">
                                        <sup>83</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implementation of Quantum Resistant Algorithms.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref84">84</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Replace RSA and ECC with NIST-recommended post-quantum cryptographic algorithms to secure key exchange and encryption in TLS.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref85">85</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Hybrid Cryptography
                                    <sup>
                                        <xref ref-type="bibr" rid="ref86">86</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use hybrid cryptographic solutions that combine traditional and quantum-resistant algorithms to provide dual layers of security during the transitionphase.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref87">87</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Enhancing Key Management Practices</bold>
                                    <xref ref-type="bibr" rid="ref88">
                                        <sup>88</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Shorten Key Lifespans
                                    <sup>
                                        <xref ref-type="bibr" rid="ref89">89</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Reduce key life spans to limit the potential for retrospective decryption by quantum attackers.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref90">90</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Forward Secrecy Implementation
                                    <sup>
                                        <xref ref-type="bibr" rid="ref91">91</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Ensure TLS sessions use forward secrecy so that past session data remains secure even if session keys are compromised in the future.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref91">91</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Protocol Updates and Version Control</bold>
                                    <xref ref-type="bibr" rid="ref92">
                                        <sup>92</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adopt TLS1.3
                                    <sup>
                                        <xref ref-type="bibr" rid="ref93">93</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implement TLS 1.3, which features stronger encryption algorithms and a simplified handshake process to reduce quantum related vulnerabilities.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref93">93</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Regular Patch Management
                                    <sup>
                                        <xref ref-type="bibr" rid="ref94">94</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Ensure timely updates and patches for TLS libraries to address vulnerabilities that may be exploited by classical or quantum attacks
                                    <sup>
                                        <xref ref-type="bibr" rid="ref94">94</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Use of Extended Validation Certificates and Certificate Transparency</bold>
                                    <xref ref-type="bibr" rid="ref95">
                                        <sup>95</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Extended Validation (EV) Certificates
                                    <sup>
                                        <xref ref-type="bibr" rid="ref96">96</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use EV certificates to enhance domain identity verification and reduce the risk of impersonation.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref96">96</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Certificate Transparency
                                    <sup>
                                        <xref ref-type="bibr" rid="ref97">97</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Utilize certificate transparency logs to detect and respond to unauthorized or forged certificates ensuring only valid certificates are trusted.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref97">97</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Strengthening Network and Server Configurations</bold>
                                    <xref ref-type="bibr" rid="ref98">
                                        <sup>98</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Strict Cipher Suite Policies
                                    <sup>
                                        <xref ref-type="bibr" rid="ref99">99</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Enforce strict policies to avoid out dated or weak cipher suites and mandate the use of strong, quantum-resistantoptions.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref3">3</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Secure Server Configurations
                                    <sup>
                                        <xref ref-type="bibr" rid="ref100">100</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Configure servers to reject insecure connections, require strong authentication and restrict access to trusted networks and devices to prevent unauthorized decryption.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref100">100</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
            <sec id="sec31">
                <title>7.2 Mitigation recommendations for IPsec threats</title>
                <p>IPsec (Internet Protocol Security) is widely used for secure communication over IP networks, particularly in VPNs. The potential of quantum computing to break traditional cryptographic algorithms pose significant risks to IPsec, especially regarding confidentiality, integrity, and data authenticity. 
                    <xref ref-type="table" rid="T6">
Table 6</xref> below outlines the effective mitigation strategies for safeguarding IPsec from quantum-enabled threats.</p>
                <table-wrap id="T6" orientation="portrait" position="float">
                    <label>
Table 6. </label>
                    <caption>
                        <title>Mitigation strategies for IPSec against quantum threats.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Mitigation Area</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Strategy</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Details</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Quantum- Resistant Cryptography</bold>
                                    <xref ref-type="bibr" rid="ref43">
                                        <sup>43</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Post-Quantum Algorithms
                                    <sup>
                                        <xref ref-type="bibr" rid="ref101">101</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Replace RSA and ECC with NIST-recommended post-quantum algorithms to secure key exchanges and data protection.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref102">102</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Hybrid Cryptography for Key Exchange
                                    <sup>
                                        <xref ref-type="bibr" rid="ref86">86</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Utilize hybrid systems combining traditional and quantum resistant encryption until fully standardized quantum algorithms are implemented.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Enhanced Key Management and Forward Secrecy</bold>
                                    <xref ref-type="bibr" rid="ref103">
                                        <sup>103</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Shortened Key
                                    <break/>Lifespans
                                    <sup>
                                        <xref ref-type="bibr" rid="ref89">89</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Minimize key life spans for sessions involving sensitive data to reduce the risk of future quantum decryption.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref90">90</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Perfect Forward Secrecy (PFS)
                                    <sup>
                                        <xref ref-type="bibr" rid="ref91">91</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Configure IPsec to support PFS, ensuring session keys are independently generated so past sessions remain secure even if a key is compromised.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref104">104</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Protocol and Cipher Suite Updates</bold>
                                    <xref ref-type="bibr" rid="ref99">
                                        <sup>99</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adopt the Latest IPsec Standards
                                    <sup>
                                        <xref ref-type="bibr" rid="ref105">105</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Update protocols like IKEv2 and ESP with strong, secure cryptographic suites to mitigate known vulnerabilities.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref104">104</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use Strong Cipher Suites Only
                                    <sup>
                                        <xref ref-type="bibr" rid="ref3">3</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Disable weak or out dated cipher suites and implement quantum resistant options to limit legacy encryption use.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref3">3</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Enhanced Authentication Mechanisms</bold>
                                    <xref ref-type="bibr" rid="ref106">
                                        <sup>106</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Mutual Authentication
                                    <sup>
                                        <xref ref-type="bibr" rid="ref107">107</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Require mutual authentication to ensure both end points verify each other&#x2019;s identities, reducing quantum-induced spoofing risks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref107">107</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Certificate Transparency and Monitoring
                                    <sup>
                                        <xref ref-type="bibr" rid="ref97">97</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Utilize certificate transparency logs to detect unauthorized or forged certificates, ensuring only validated ones are trusted during communications.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref97">97</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Network and Endpoint Security</bold>
                                    <xref ref-type="bibr" rid="ref108">
                                        <sup>108</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Network Segmentation
                                    <sup>
                                        <xref ref-type="bibr" rid="ref109">109</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Segment networks and restrict access to sensitive IPsec connections to limit the spread and impact of compromised communications.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref109">109</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">End point Hardening
                                    <sup>
                                        <xref ref-type="bibr" rid="ref110">110</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Patch and update end points involved in IPsec communications to reject insecure connections and prevent unauthorized decryption attempts.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref110">110</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
            <sec id="sec32">
                <title>7.3 Mitigation Recommendations for DNSSEC Threats</title>
                <p>DNSSEC (Domain Name System Security Extensions) enhances DNS security by providing digital signatures to validate DNS records. However, quantum computing&#x2019;s potential to decrypt cryptographic keys used in DNSSEC poses serious threats, including DNS spoofing, data tampering, and traffic interception. 
                    <xref ref-type="table" rid="T7">
Table 7</xref> outlines strategies to mitigate quantum threats to DNSSEC.</p>
                <table-wrap id="T7" orientation="portrait" position="float">
                    <label>
Table 7. </label>
                    <caption>
                        <title>Mitigation strategies for DNSSEC against quantum threats.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Mitigation Area</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Strategy</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Details</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Transition to Post-Quantum Cryptographic Algorithms</bold>
                                    <xref ref-type="bibr" rid="ref83">
                                        <sup>83</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adopt Quantum Resistant Algorithms
                                    <sup>
                                        <xref ref-type="bibr" rid="ref111">111</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Replace RSA and ECC digital signatures used in DNSSEC with NIST-recommended post-quantum algorithms to ensure DNS data authenticity against quantum enabled attacks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref111">111</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use Hybrid Cryptographic Approaches
                                    <sup>
                                        <xref ref-type="bibr" rid="ref19">19</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Until fully standardized post-quantum algorithms are available, implement hybrid cryptographic solutions combining traditional and quantum-resistant algorithms to protect DNSSEC.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref19">19</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Strengthening Key Management Practices</bold>
                                    <xref ref-type="bibr" rid="ref112">
                                        <sup>112</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Frequent Key Rotations
                                    <sup>
                                        <xref ref-type="bibr" rid="ref113">113</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implement shorter key rotation periods for DNSSEC signing keys to limit the window of quantum attack exposure and reduce the impact of any compromised keys over time.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref113">113</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">ZSK and KSK Separation
                                    <sup>
                                        <xref ref-type="bibr" rid="ref114">114</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use separate Zone Signing Keys (ZSKs) and Key Signing Keys (KSKs) for added security. Rotate ZSKs regularly while maintaining secure KSK rotation schedules to minimize quantum risk.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref114">114</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Enhanced Validation and Monitoring</bold>
                                    <xref ref-type="bibr" rid="ref115">
                                        <sup>115</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Enable Strict Validation Policies
                                    <sup>
                                        <xref ref-type="bibr" rid="ref116">116</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Configure DNS resolvers to enforce DNSSEC validation, rejecting unsigned or improperly signed records to protect against spoofed responses.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref116">116</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">DNSSEC Log Monitoring
                                    <sup>
                                        <xref ref-type="bibr" rid="ref115">115</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Monitor DNSSEC logs regularly to identify unusual activities such as unauthorized key changes or invalid DNS responses, which may indicate quantum-enabled attacks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref115">115</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Deployment of Multi-Layered Security and Redundancy</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implement DNS firewall rules
                                    <sup>
                                        <xref ref-type="bibr" rid="ref117">117</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implement DNS firewall rules to block malicious or suspicious DNS queries, preventing exploitation of DNSSEC vulnerabilities even if signatures are compromised.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref117">117</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use DNSSEC Enabled Redundant DNS Servers
                                    <sup>
                                        <xref ref-type="bibr" rid="ref118">118</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Deploy redundant DNS servers with DNSSEC capabilities to ensure availability and consistency of DNS records, reducing risks if one server&#x2019;s keys are compromised.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref118">118</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Implementing DNS Query Rate Limiting and Anomaly Detection</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Rate Limiting on DNS Queries
                                    <sup>
                                        <xref ref-type="bibr" rid="ref119">119</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Set rate limits on DNS queries to prevent attackers from flooding DNS servers with spoofed queries or manipulating responses.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref119">119</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Anomaly Detection Systems
                                    <sup>
                                        <xref ref-type="bibr" rid="ref120">120</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use anomaly detection tools to identify irregular DNS query patterns (e.g., sudden spikes), which could signal quantum driven DNS attacks or other malicious activities.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref120">120</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
            <sec id="sec33">
                <title>7.4 Cross-Protocol Mitigation Recommendation</title>
                <p>With the rapid advancements in quantum computing, TLS, IPsec, and DNSSEC face significant cryptographic vulnerabilities that require strategic, cross-protocol mitigations to safeguard data confidentiality, integrity, and authenticity. This comparative study in 
                    <xref ref-type="table" rid="T8">
Table 8</xref> provides comprehensive recommendations applicable across these protocols, focusing on quantum resistant cryptography, robust key management, and layered security measures to effectively mitigate risks.</p>
                <table-wrap id="T8" orientation="portrait" position="float">
                    <label>
Table 8. </label>
                    <caption>
                        <title>Mitigation strategies for Cross-Protocol against quantum threats.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Mitigation Area</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Recommendations</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Details</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Quantum-Resistant Cryptography</bold>
                                    <xref ref-type="bibr" rid="ref83">
                                        <sup>83</sup>
                                    </xref>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adopt Post Quantum Algorithms
                                    <sup>
                                        <xref ref-type="bibr" rid="ref111">111</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Standardize NIST-recommended post-quantum cryptographic algorithms to replace RSA and ECC, ensuring secure key exchanges, signatures, and encryption.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref111">111</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Hybrid Cryptographic Models
                                    <sup>
                                        <xref ref-type="bibr" rid="ref19">19</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implement hybrid models combining current encryption with quantum-resistant algorithms during the transition to post-quantum standards.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref19">19</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Key Management Practices</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Regular Key Rotations
                                    <sup>
                                        <xref ref-type="bibr" rid="ref113">113</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Rotate cryptographic keys frequently to minimize exposure to quantum decryption, especially for sensitive data and long sessions.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref113">113</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Forward Secrecy
                                    <break/>Protocols
                                    <sup>
                                        <xref ref-type="bibr" rid="ref91">91</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Enable forward secrecy mechanisms to ensure past session data remains secure even if a key is compromised.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref121">121</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Protocol and Cipher Suite Updates</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Enforce Strong Cipher Suites
                                    <sup>
                                        <xref ref-type="bibr" rid="ref99">99</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Disable out dated or weak cipher suites (e.g.,SHA-1,MD5) and adopt robust quantum-resistant cipher suites.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref43">43</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Mandatory protocol Updates
                                    <sup>
                                        <xref ref-type="bibr" rid="ref105">105</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use the latest protocol versions (e.g.,TLS1.3, IKEv2 for IPsec) to benefit from enhanced security and reduced attack surfaces.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref104">104</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Authentication Mechanisms</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Two-Factor Authentication (2FA)
                                    <sup>
                                        <xref ref-type="bibr" rid="ref122">122</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Implement 2FA across TLS, IPsec, and DNSSEC to mitigate quantum-based spoofing attacks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref122">122</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Enhanced Certificate Transparency
                                    <sup>
                                        <xref ref-type="bibr" rid="ref123">123</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adopt certificate transparency to detect unauthorized or forged certificates vulnerable to quantum decryption attacks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref123">123</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">
                                    <bold>Multi-Layered Security and Redundancy</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Segmented Network Design
                                    <sup>
                                        <xref ref-type="bibr" rid="ref124">124</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Segment networks to isolate critical infrastructure, reducing risks of quantum-powered breaches spreading across systems.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref124">124</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">DNS and IP Redundancy
                                    <sup>
                                        <xref ref-type="bibr" rid="ref125">125</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Use redundant DNS and IP routes with DNSSEC and IPsec protocols to maintain continuity during quantum-related attacks.
                                    <sup>
                                        <xref ref-type="bibr" rid="ref125">125</xref>
                                    </sup>
                                </td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Continuous Monitoring and Threat Intelligence</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Unified Threat Detection Systems
                                    <sup>
                                        <xref ref-type="bibr" rid="ref126">126</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Employ anomaly detection and intrusion detection systems (IDS) to monitor quantum-related vulnerabilities or anomalies (e.g., unusual certificate activity).
                                    <sup>
                                        <xref ref-type="bibr" rid="ref126">126</xref>
                                    </sup>
                                </td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
        </sec>
        <sec id="sec34">
            <title>8. Conclusion and future work</title>
            <p>This paper examines the evolving quantum threat landscape for critical network security protocols&#x2014;TLS, IPsec, and DNSSEC&#x2014;using the STRIDE and PASTA threat modeling frameworks. The analysis highlights the significant vulnerabilities of these protocols to quantum computing, primarily due to their capability to break asymmetric cryptographic algorithms such as RSA, ECC, and DH, which are foundational to key exchange and encryption mechanisms. Through STRIDE, the research provides a protocol-specific assessment of vulnerabilities across six dimensions, while PASTA emphasizes the practical feasibility of attacks and aligns mitigation strategies with real- world scenarios. A comparative analysis reveals that TLS and IPsec are particularly susceptible to breaches in confidentiality and integrity, whereas DNSSEC faces critical challenges in maintaining authenticity. Simulated quantum attack scenarios further under score vulnerabilities such as compromised TLS handshakes, intercepted IPsec VPN traffic, and forged DNSSEC signatures, illustrating the urgency of adopting post-quantum cryptography, hybrid cryptographic models, and robust key management practices. The paper proposes cross-protocol mitigation strategies to enhance resilience and offers a roadmap for future research. Key recommendations include integrating post-quantum cryptographic algorithms, deploying hybrid models, and exploring Quantum Key Distribution (QKD) for enhanced security. Furthermore, the study advocates for the development of standardized frameworks, large-scale quantum attack simulations, and leveraging AI and ML for real-time threat detection and response. These measures are critical to ensuring secure communication and robust digital infrastructure in the quantum computing era.</p>
        </sec>
    </body>
    <back>
        <sec id="sec37" sec-type="data-availability">
            <title>Data availability</title>
            <p>No data are associated with this article.</p>
        </sec>
        <ref-list>
            <title>References</title>
            <ref id="ref1">
                <label>1</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>D&#x00a8;oring</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Geitz</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <chapter-title>Post-quantum cryptography in use: Empirical analysis of the tls handshake performance.</chapter-title>
                    <source>

                        <italic toggle="yes">NOMS 2022&#x2013;2022 IEEE/IFIP Network Operations and Management Symposium.</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2022</year>; pp.<fpage>1</fpage>&#x2013;<lpage>5</lpage>.</mixed-citation>
            </ref>
            <ref id="ref2">
                <label>2</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bellizia</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>El Mrabet</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Fournaris</surname>
                            <given-names>AP</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Post-quantum cryptography: Challenges and opportunities for robust and secure hw design.</chapter-title>
                    <source>

                        <italic toggle="yes">2021 IEEE International Symposium on Defect and fault tolerance in VLSI and Nanotechnology systems (DFT).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2021</year>; pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation>
            </ref>
            <ref id="ref3">
                <label>3</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hasan</surname>
                            <given-names>KF</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Simpson</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Baee</surname>
                            <given-names>MAR</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A framework for migrating to post-quantum cryptography: Security dependency analysis and case studies.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <volume>12</volume>:<fpage>23427</fpage>&#x2013;<lpage>23450</lpage>.
                    <pub-id pub-id-type="doi">10.1109/access.2024.3360412</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref4">
                <label>4</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zeydan</surname>
                            <given-names>E</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Turk</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Aksoy</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ozturk</surname>
                            <given-names>SB</given-names>
                        </name>
</person-group>:
                    <chapter-title>Recent advances in post-quantum cryptography for networks: A survey.</chapter-title>
                    <source>

                        <italic toggle="yes">2022 Seventh International Conference On Mobile And Secure Services (MobiSecServ).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2022</year>; pp.<fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation>
            </ref>
            <ref id="ref5">
                <label>5</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ambika</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Balaji</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rajasekaran</surname>
                            <given-names>RT</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Explore the impact of quantum computing to enhance cryptographic protocols and network security measures.</chapter-title>
                    <source>

                        <italic toggle="yes">2024 IEEE International Conference on Computing, Power and Communication Technologies (IC2PCT).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2024</year>; Vol.<volume>5</volume>: pp.<fpage>1603</fpage>&#x2013;<lpage>1607</lpage>.</mixed-citation>
            </ref>
            <ref id="ref6">
                <label>6</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kumar</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pattnaik</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <chapter-title>Post quantum cryptography (pqc)-an overview.</chapter-title>
                    <source>

                        <italic toggle="yes">2020 IEEE High Performance Extreme Computing Conference (HPEC).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2020</year>; pp.<fpage>1</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation>
            </ref>
            <ref id="ref7">
                <label>7</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Herzinger</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gazdag</surname>
                            <given-names>S-L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Loebenberger</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <chapter-title>Real-world quantum-resistant ipsec.</chapter-title>
                    <source>

                        <italic toggle="yes">2021 14th International Conference on Security of Information and Networks (SIN).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2021</year>; Vol.<volume>1</volume>: pp.<fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation>
            </ref>
            <ref id="ref8">
                <label>8</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bhatt</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gautam</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <chapter-title>Quantum computing: A new era of computer science.</chapter-title>
                    <source>

                        <italic toggle="yes">2019 6
                            <sup>th</sup> International Conference on Computing for Sustainable Global Development (INDIACom).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2019</year>; pp.<fpage>558</fpage>&#x2013;<lpage>561</lpage>.</mixed-citation>
            </ref>
            <ref id="ref9">
                <label>9</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chen</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chen</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jordan</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <source>

                        <italic toggle="yes">Report on post-quantum cryptography</italic>
</source>
                    <publisher-name>US Department of Commerce, National Institute of Standards and Technology</publisher-name>;<year>2016</year>; Vol.<volume>12</volume>.</mixed-citation>
            </ref>
            <ref id="ref10">
                <label>10</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Knight</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Hacking connected cars: Tactics, techniques, and procedures.</italic>
</source>
                    <publisher-name>John Wiley &amp; Sons</publisher-name>;<year>2020</year>.</mixed-citation>
            </ref>
            <ref id="ref11">
                <label>11</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Balamurugan</surname>
                            <given-names>K</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>An analysis of various cyber threat modeling.</chapter-title>
                    <source>

                        <italic toggle="yes">2023 Third International Conference on Artificial Intelligence and Smart Energy (ICAIS).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2023</year>; pp.<fpage>426</fpage>&#x2013;<lpage>429</lpage>.</mixed-citation>
            </ref>
            <ref id="ref12">
                <label>12</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sentamilselvan</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Suresh</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kamalam</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Security threats and privacy challenges in the quantum blockchain: A contemporary survey, Quantum Blockchain: An Emerging Cryptographic Paradigm.</article-title>
                    <year>2022</year>;<fpage>293</fpage>&#x2013;<lpage>316</lpage>.</mixed-citation>
            </ref>
            <ref id="ref13">
                <label>13</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Atmaca</surname>
                            <given-names>UI</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Maple</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Epiphaniou</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Challenges in threat modelling of new space systems: A tele operation use-case.</article-title>
                    <source>

                        <italic toggle="yes">Adv. Space Res.</italic>
</source>
                    <year>2022</year>;<volume>70</volume>(<issue>8</issue>):<fpage>2208</fpage>&#x2013;<lpage>2226</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.asr.2022.07.013</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref14">
                <label>14</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Khan</surname>
                            <given-names>SK</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shiwakoti</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Stasinopoulos</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Cyber-attacks in the next-generation cars, mitigation techniques, anticipated readiness and future directions.</article-title>
                    <source>

                        <italic toggle="yes">Accid. Anal. Prev.</italic>
</source>
                    <year>2020</year>;<volume>148</volume>:<fpage>105837</fpage>.
                    <pub-id pub-id-type="pmid">33120180</pub-id>
                    <pub-id pub-id-type="doi">10.1016/j.aap.2020.105837</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref15">
                <label>15</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhang</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Taal</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Cushing</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A risk-level assessment system based on the stride/dread model for digital data marketplaces.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Inf. Secur.</italic>
</source>
                    <year>2022</year>;<fpage>1</fpage>&#x2013;<lpage>17</lpage>.</mixed-citation>
            </ref>
            <ref id="ref16">
                <label>16</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Das</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Asif</surname>
                            <given-names>MRA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jahan</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Stride-based cybersecurity threat modeling, risk assessment and treatment of an in-vehicle infotainment system.</article-title>
                    <source>

                        <italic toggle="yes">Vehicles.</italic>
</source>
                    <year>2024</year>;<volume>6</volume>(<issue>3</issue>):<fpage>1140</fpage>&#x2013;<lpage>1163</lpage>.
                    <pub-id pub-id-type="doi">10.3390/vehicles6030054</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref17">
                <label>17</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Benli</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>&#x00d6;zcan</surname>
                            <given-names>E</given-names>
                        </name>

                        <name name-style="western">
                            <surname>T&#x00fc;reli</surname>
                            <given-names>U</given-names>
                        </name>
</person-group>:
                    <chapter-title>A custom key-value store hardware on fpga for ipsec protocol.</chapter-title>
                    <source>

                        <italic toggle="yes">2020 12th International Conference on Electrical and Electronics Engineering (ELECO).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2020</year>; pp.<fpage>150</fpage>&#x2013;<lpage>154</lpage>.</mixed-citation>
            </ref>
            <ref id="ref18">
                <label>18</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rahul</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Geetha</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Priyatharsini</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Cybersecurity issues and challenges in quantum computing, Topics in Artificial Intelligence Applied to Industry 4.0.</article-title>
                    <year>2024</year>;<fpage>203</fpage>&#x2013;<lpage>221</lpage>.</mixed-citation>
            </ref>
            <ref id="ref19">
                <label>19</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Beernink</surname>
                            <given-names>G</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Taking the quantum leap: Preparing dnssec for post quantum cryptography.</italic>
</source>
                    <publisher-name>University of Twente</publisher-name>;<year>2022</year>. Master&#x2019;s thesis.</mixed-citation>
            </ref>
            <ref id="ref20">
                <label>20</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shostack</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Threat modeling: Designing for security.</italic>
</source>
                    <publisher-name>JohnWiley &amp; Sons</publisher-name>;<year>2014</year>.</mixed-citation>
            </ref>
            <ref id="ref21">
                <label>21</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Myagmar</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lee</surname>
                            <given-names>AJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yurcik</surname>
                            <given-names>W</given-names>
                        </name>
</person-group>:
                    <article-title>Threat modeling as a basis for security requirements.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref22">
                <label>22</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>UcedaVelez</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Morana</surname>
                            <given-names>MM</given-names>
                        </name>
</person-group>:
                    <article-title>Intro to pasta.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref23">
                <label>23</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>UcedaVelez</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Morana</surname>
                            <given-names>MM</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Risk Centric Threat Modeling: process for attack simulation and threat analysis.</italic>
</source>
                    <publisher-name>JohnWiley &amp; Sons</publisher-name>;<year>2015</year>.</mixed-citation>
            </ref>
            <ref id="ref24">
                <label>24</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bhatia</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sumbaly</surname>
                            <given-names>R</given-names>
                        </name>
</person-group>;
                    <article-title>Framework for wireless network security using quantum cryptography.</article-title>
                    <source>

                        <italic toggle="yes">arXiv preprint arXiv:1412.2495.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref25">
                <label>25</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Maurer</surname>
                            <given-names>U</given-names>
                        </name>
</person-group>:
                    <chapter-title>Modelling a public-key infrastructure.</chapter-title>
                    <source>

                        <italic toggle="yes">Computer Security&#x2014;ESORICS 96: 4
                            <sup>th</sup> European Symposium on Research in Computer Security Rome, Italy, September 25&#x2013;27, 1996 Proceedings 4.</italic>
</source>
                    <publisher-name>Springer</publisher-name>;<year>1996</year>; pp.<fpage>325</fpage>&#x2013;<lpage>350</lpage>.</mixed-citation>
            </ref>
            <ref id="ref26">
                <label>26</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shor</surname>
                            <given-names>PW</given-names>
                        </name>
</person-group>:
                    <article-title>Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer.</article-title>
                    <source>

                        <italic toggle="yes">SIAM Rev.</italic>
</source>
                    <year>1999</year>;<volume>41</volume>(<issue>2</issue>):<fpage>303</fpage>&#x2013;<lpage>332</lpage>.
                    <pub-id pub-id-type="doi">10.1137/S0036144598347011</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref27">
                <label>27</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Boneh</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shoup</surname>
                            <given-names>V</given-names>
                        </name>
</person-group>;
                    <article-title>A graduate course in applied cryptography, Draft 0.5.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref28">
                <label>28</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mavroeidis</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Vishi</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zych</surname>
                            <given-names>MD</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>The impact of quantum computing on present cryptography.</article-title>, arXiv preprint arXiv:1804.00200.</mixed-citation>
            </ref>
            <ref id="ref29">
                <label>29</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kokare</surname>
                            <given-names>PN</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Vora</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Patil</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Post quantum cryptography: A survey of past and future.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref30">
                <label>30</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Althobaiti</surname>
                            <given-names>OS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dohler</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Cybersecurity challenges associated with the internet of things in a post-quantum world.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <year>2020</year>;<volume>8</volume>:<fpage>157356</fpage>&#x2013;<lpage>157381</lpage>.
                    <pub-id pub-id-type="doi">10.1109/access.2020.3019345</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref31">
                <label>31</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Baseri</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chouhan</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hafid</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Navigating quantum security risks in networked environments: A comprehensive study of quantum-safe network protocols.</article-title>
                    <source>

                        <italic toggle="yes">Comput. Secur.</italic>
</source>
                    <year>2024</year>;<volume>142</volume>:<fpage>103883</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.cose.2024.103883</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref32">
                <label>32</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Emmanni</surname>
                            <given-names>PS</given-names>
                        </name>
</person-group>:
                    <article-title>The impact of quantum computing on cybersecurity.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Mathematical &amp; Computer Applications.</italic>
</source>
                    <year>2023</year>;<volume>2</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>4</lpage>.
                    <pub-id pub-id-type="doi">10.47363/JMCA/2023(2)140</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref33">
                <label>33</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cavaliere</surname>
                            <given-names>F</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mattsson</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Smeets</surname>
                            <given-names>B</given-names>
                        </name>
</person-group>:
                    <article-title>The security implications of quantum cryptography and quantum computing.</article-title>
                    <source>

                        <italic toggle="yes">Netw. Secur.</italic>
</source>
                    <year>2020</year>;<volume>2020</volume>(<issue>9</issue>):<fpage>9</fpage>&#x2013;<lpage>15</lpage>.
                    <pub-id pub-id-type="doi">10.1016/S1353-4858(20)30105-7</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref34">
                <label>34</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Akter</surname>
                            <given-names>MS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rodriguez-Cardenas</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shahriar</surname>
                            <given-names>H</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Quantum cryptography for enhanced network security: A comprehensive survey of research, developments, and future directions.</chapter-title>
                    <source>

                        <italic toggle="yes">2023 IEEE International Conference on Big Data (BigData).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2023</year>; pp.<fpage>5408</fpage>&#x2013;<lpage>5417</lpage>.</mixed-citation>
            </ref>
            <ref id="ref35">
                <label>35</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shor</surname>
                            <given-names>PW</given-names>
                        </name>
</person-group>:
                    <chapter-title>Algorithms for quantum computation: discrete logarithms and factoring.</chapter-title>
                    <source>

                        <italic toggle="yes">Proceedings 35th annual symposium on foundations of computer science.</italic>
</source>
                    <publisher-name>Ieee</publisher-name>;<year>1994</year>; pp.<fpage>124</fpage>&#x2013;<lpage>134</lpage>.</mixed-citation>
            </ref>
            <ref id="ref36">
                <label>36</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Alagic</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Alagic</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Apon</surname>
                            <given-names>D</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Status report on the third round of the nist post-quantum cryptography standardization process.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref37">
                <label>37</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pan</surname>
                            <given-names>SWS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nguyen</surname>
                            <given-names>DDN</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Doss</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Double-signed fragmented dnssec for countering quantum threat.</article-title>
                    <source>

                        <italic toggle="yes">arXiv preprint arXiv:2411.07535.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref38">
                <label>38</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>M&#x00a8; uller</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jong</surname>
                            <given-names>J</given-names>
                            <prefix>de</prefix>
                        </name>

                        <name name-style="western">
                            <surname>Heesch</surname>
                            <given-names>M</given-names>
                            <prefix>van</prefix>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Retrofitting postquantum cryptography in internet protocols: a case study of dnssec.</article-title>
                    <source>

                        <italic toggle="yes">ACM SIGCOMM Comput Commun Rev.</italic>
</source>
                    <year>2020</year>;<volume>50</volume>(<issue>4</issue>):<fpage>49</fpage>&#x2013;<lpage>57</lpage>.</mixed-citation>
            </ref>
            <ref id="ref39">
                <label>39</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Baseri</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chouhan</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ghorbani</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Cybersecurity in the quantum era: Assessing the impact of quantum computing on infrastructure.</article-title>
                    <source>

                        <italic toggle="yes">Comput. Secur.</italic>
</source>
                    <volume>167</volume>:<fpage>2404.10659</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.cose.2026.104917</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref40">
                <label>40</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jowarder</surname>
                            <given-names>RA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jahan</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Quantum computing in cyber security: Emerging threats, mitigation strategies, and future implications for data protection.</article-title>
                    <source>

                        <italic toggle="yes">World Journal of Advanced Engineering Technology and Sciences.</italic>
</source>
                    <year>2024</year>;<volume>13</volume>(<issue>1</issue>):<fpage>330</fpage>&#x2013;<lpage>339</lpage>.</mixed-citation>
            </ref>
            <ref id="ref41">
                <label>41</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Schmid</surname>
                            <given-names>G</given-names>
                        </name>
</person-group>:
                    <article-title>Thirty years of dns insecurity: Current issues and perspectives.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Commun Surv Tutor.</italic>
</source>
                    <year>2021</year>;<volume>23</volume>(<issue>4</issue>):<fpage>2429</fpage>&#x2013;<lpage>2459</lpage>.
                    <pub-id pub-id-type="doi">10.1109/COMST.2021.3105741</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref42">
                <label>42</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rodriguez</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Perceptions of IT Decision-Makers on the Use of Domain Name System Security Extension (DNSSEC): Qualitative Exploratory Case Study.</italic>
</source>
                    <publisher-name>University of Phoenix</publisher-name>;<year>2020</year>.</mixed-citation>
            </ref>
            <ref id="ref43">
                <label>43</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mattsson</surname>
                            <given-names>JP</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Smeets</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Thormarker</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>Quantum-resistant cryptography.</article-title>
                    <source>

                        <italic toggle="yes">arXiv preprint arXiv:2112.00399.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref44">
                <label>44</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Malina</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dobias</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hajny</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>On deploying quantum-resistant cybersecurity in intelligent infrastructures.</chapter-title>
                    <source>

                        <italic toggle="yes">Proceedings of the 18th International Conference on Availability, Reliability and Security.</italic>
</source>
                    <year>2023</year>; pp.<fpage>1</fpage>&#x2013;<lpage>10</lpage>.</mixed-citation>
            </ref>
            <ref id="ref45">
                <label>45</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>AlMudaweb</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Elmedany</surname>
                            <given-names>W</given-names>
                        </name>
</person-group>:
                    <article-title>Securing smart cities in the quantum era: challenges, solutions, and regulatory considerations.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref46">
                <label>46</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Blightman</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Griffiths</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Danbury</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>Patient confidentiality: when can a breach be justified?.</article-title>
                    <source>

                        <italic toggle="yes">Contin. Educ. Anaesth. Crit. Care Pain.</italic>
</source>
                    <year>2014</year>;<volume>14</volume>(<issue>2</issue>):<fpage>52</fpage>&#x2013;<lpage>56</lpage>.
                    <pub-id pub-id-type="doi">10.1093/bjaceaccp/mkt032</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref47">
                <label>47</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Adams</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Broadbent</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <chapter-title>Password authentication schemes on a quantum computer.</chapter-title>
                    <source>

                        <italic toggle="yes">2021 IEEE International Conference on Quantum Computing and Engineering (QCE).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2021</year>; pp.<fpage>346</fpage>&#x2013;<lpage>350</lpage>.</mixed-citation>
            </ref>
            <ref id="ref48">
                <label>48</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bhushan</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sahoo</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rai</surname>
                            <given-names>AK</given-names>
                        </name>
</person-group>:
                    <chapter-title>Man-in-the-middle attack in wireless and computer networking&#x2014;a review.</chapter-title>
                    <source>

                        <italic toggle="yes">2017 3rd International Conference on Advances in Computing, Communication &amp; Automation (ICACCA)(Fall).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2017</year>; pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation>
            </ref>
            <ref id="ref49">
                <label>49</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pina</surname>
                            <given-names>E</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ramos</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jorge</surname>
                            <given-names>H</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Data privacy and ethical considerations in database management.</article-title>
                    <source>

                        <italic toggle="yes">J Cybersecur Privacy.</italic>
</source>
                    <year>2024</year>;<volume>4</volume>(<issue>3</issue>):<fpage>494</fpage>&#x2013;<lpage>517</lpage>.
                    <pub-id pub-id-type="doi">10.3390/jcp4030024</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref50">
                <label>50</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Alagic</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Alagic</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Alperin-Sheriff</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Status report on the first round of the nist post-quantum cryptography standardization process.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref51">
                <label>51</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rios</surname>
                            <given-names>VDM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>In&#x2019;acio</surname>
                            <given-names>PR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Magoni</surname>
                            <given-names>D</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Detection and mitigation of low-rate denial-of-service attacks: A survey.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <year>2022</year>;<volume>10</volume>:<fpage>76648</fpage>&#x2013;<lpage>76668</lpage>.</mixed-citation>
            </ref>
            <ref id="ref52">
                <label>52</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vishnu</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Batth</surname>
                            <given-names>RS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Singh</surname>
                            <given-names>G</given-names>
                        </name>
</person-group>:
                    <chapter-title>Denial of service: types, techniques, defence mechanisms and safe guards.</chapter-title>
                    <source>

                        <italic toggle="yes">2019 International Conference on Computational Intelligence and Knowledge Economy (ICCIKE).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2019</year>; pp.<fpage>695</fpage>&#x2013;<lpage>700</lpage>.</mixed-citation>
            </ref>
            <ref id="ref53">
                <label>53</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>AbdAllah</surname>
                            <given-names>EG</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zulkernine</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hassanein</surname>
                            <given-names>HS</given-names>
                        </name>
</person-group>:
                    <article-title>Preventing unauthorized access in information centric networking.</article-title>
                    <source>

                        <italic toggle="yes">Secur. Priv.</italic>
</source>
                    <year>2018</year>;<volume>1</volume>(<issue>4</issue>):<fpage>e33</fpage>.
                    <pub-id pub-id-type="doi">10.1002/spy2.33</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref54">
                <label>54</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rijah</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Security analysis, threats, &amp; challenges in database.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref55">
                <label>55</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Luo</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ji</surname>
                            <given-names>Q</given-names>
                        </name>
</person-group>:
                    <chapter-title>Password acquisition and traffic decryption based on l2tp/ipsec.</chapter-title>
                    <source>

                        <italic toggle="yes">2020 IEEE 20th International Conference on Communication Technology (ICCT).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2020</year>; pp.<fpage>1567</fpage>&#x2013;<lpage>1571</lpage>.</mixed-citation>
            </ref>
            <ref id="ref56">
                <label>56</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lai</surname>
                            <given-names>Y-P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hsia</surname>
                            <given-names>P-L</given-names>
                        </name>
</person-group>:
                    <article-title>Using the vulnerability information of computer systems to improve the network security.</article-title>
                    <source>

                        <italic toggle="yes">Comput. Commun.</italic>
</source>
                    <year>2007</year>;<volume>30</volume>(<issue>9</issue>):<fpage>2032</fpage>&#x2013;<lpage>2047</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.comcom.2007.03.007</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref57">
                <label>57</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wilshusen</surname>
                            <given-names>GC</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gilmore</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lawrence</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <source>

                        <italic toggle="yes">Cybersecurity: Threats impacting the nation.</italic>
</source>
                    <publisher-name>United States Government Accountability Office</publisher-name>;<year>2012</year>; Vol.<volume>3</volume>.</mixed-citation>
            </ref>
            <ref id="ref58">
                <label>58</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sikeridis</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kampanakis</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Devetsikiotis</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <chapter-title>Assessing the overhead of post-quantum cryptography in tls 1.3 and ssh.</chapter-title>
                    <source>

                        <italic toggle="yes">Proceedings of the 16th International Conference on emerging Networking EXperiments and Technologies.</italic>
</source>
                    <year>2020</year>; pp.<fpage>149</fpage>&#x2013;<lpage>156</lpage>.</mixed-citation>
            </ref>
            <ref id="ref59">
                <label>59</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kumar</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sridhar</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sudhindra</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>A case study: risk rating methodology for e-governance application security risks.</article-title>
                    <source>

                        <italic toggle="yes">i-Manager&#x2019;s Journal on Software Engineering.</italic>
</source>
                    <year>2019</year>;<volume>13</volume>(<issue>3</issue>):<fpage>39</fpage>.
                    <pub-id pub-id-type="doi">10.26634/jse.13.3.15546</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref60">
                <label>60</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Halak</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gibson</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Henley</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Evaluation of performance, energy, and computation costs of quantum-attack resilient encryption algorithms for embedded devices.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref61">
                <label>61</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Dissanayake</surname>
                            <given-names>I</given-names>
                        </name>
</person-group>, D
                    <chapter-title>ns cache poisoning: A review on its technique and countermeasures.</chapter-title>
                    <source>

                        <italic toggle="yes">2018 National Information Technology Conference (NITC).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2018</year>; pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation>
            </ref>
            <ref id="ref62">
                <label>62</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Southam</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Dnssec: What it is and why it matters.</article-title>
                    <source>

                        <italic toggle="yes">Netw. Secur.</italic>
</source>
                    <year>2014</year>;<volume>2014</volume>(<issue>5</issue>):<fpage>12</fpage>&#x2013;<lpage>15</lpage>.
                    <pub-id pub-id-type="doi">10.1016/S1353-4858(14)70050-9</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref63">
                <label>63</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chapple</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Confidentiality, integrity and availability&#x2013;the cia triad.</article-title>
                    <year>2020</year>.</mixed-citation>
            </ref>
            <ref id="ref64">
                <label>64</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Heftrig</surname>
                            <given-names>E</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Schulmann</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Vogel</surname>
                            <given-names>N</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>The harder you try, the harder you fail: The key trap denial-of-service algorithmic complexity attacks on dnssec.</chapter-title>
                    <source>

                        <italic toggle="yes">Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security.</italic>
</source>
                    <year>2024</year>; pp.<fpage>497</fpage>&#x2013;<lpage>510</lpage>.</mixed-citation>
            </ref>
            <ref id="ref65">
                <label>65</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Opi&#x0142;ka</surname>
                            <given-names>F</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Niemiec</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gagliardi</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Performance analysis of post-quantum cryptography algorithms for digital signature.</article-title>
                    <source>

                        <italic toggle="yes">Appl. Sci.</italic>
</source>
                    <year>2024</year>;<volume>14</volume>(<issue>12</issue>):<fpage>4994</fpage>.
                    <pub-id pub-id-type="doi">10.3390/app14124994</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref66">
                <label>66</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jammal</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hawilo</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kanso</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Mitigating the risk of cloud services downtime using live migration and high availability-aware placement.</chapter-title>
                    <source>

                        <italic toggle="yes">2016 IEEE International Conference on Cloud Computing Technology and Science (CloudCom).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2016</year>; pp.<fpage>578</fpage>&#x2013;<lpage>583</lpage>.</mixed-citation>
            </ref>
            <ref id="ref67">
                <label>67</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Khan</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>McLaughlin</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Laverty</surname>
                            <given-names>D</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Stride-based threat modeling for cyber-physical systems.</chapter-title>
                    <source>

                        <italic toggle="yes">2017 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGTEurope).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2017</year>; pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation>
            </ref>
            <ref id="ref68">
                <label>68</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Karantzas</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Patsakis</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>An empirical assessment of endpoint detection and response systems against advanced persistent threats attack vectors.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Cybersecurity and Privacy.</italic>
</source>
                    <year>2021</year>;<volume>1</volume>(<issue>3</issue>):<fpage>387</fpage>&#x2013;<lpage>421</lpage>.
                    <pub-id pub-id-type="doi">10.3390/jcp1030021</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref69">
                <label>69</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Parker</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>When a quantum computer is able to break our encryption, it won&#x2019;t be a secret.</article-title>
                    <year>2023</year>.</mixed-citation>
            </ref>
            <ref id="ref70">
                <label>70</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lindsay</surname>
                            <given-names>JR</given-names>
                        </name>
</person-group>:
                    <article-title>Surviving the quantum cryptocalypse.</article-title>
                    <source>

                        <italic toggle="yes">Strateg Stud Q.</italic>
</source>
                    <year>2020</year>;<volume>14</volume>(<issue>2</issue>):<fpage>49</fpage>&#x2013;<lpage>73</lpage>.</mixed-citation>
            </ref>
            <ref id="ref71">
                <label>71</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ahmed</surname>
                            <given-names>AA</given-names>
                        </name>
</person-group>:
                    <article-title>Lightweight digital certificate management and efficacious symmetric cryptographic mechanism over industrial internet of things.</article-title>
                    <source>

                        <italic toggle="yes">Sensors.</italic>
</source>
                    <year>2021</year>;<volume>21</volume>(<issue>8</issue>):<fpage>2810</fpage>.
                    <pub-id pub-id-type="pmid">33923644</pub-id>
                    <pub-id pub-id-type="doi">10.3390/s21082810</pub-id>
                    <pub-id pub-id-type="pmcid">PMC8073767</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref72">
                <label>72</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Singh</surname>
                            <given-names>H</given-names>
                        </name>
</person-group>:
                    <chapter-title>Managing the quantum cyber security threat: Harvest now, decrypt later.</chapter-title>
                    <source>

                        <italic toggle="yes">Quantum Computing.</italic>
</source>
                    <publisher-name>CRC Press</publisher-name>;
pp.<fpage>142</fpage>&#x2013;<lpage>158</lpage>.</mixed-citation>
            </ref>
            <ref id="ref73">
                <label>73</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Faruk</surname>
                            <given-names>MJH</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tahora</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tasnim</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>A review of quantum cyber security: threats, risks and opportunities.</chapter-title>
                    <source>

                        <italic toggle="yes">2022 1st International Conference on AI in Cyber security (ICAIC).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2022</year>; pp.<fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation>
            </ref>
            <ref id="ref74">
                <label>74</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mehmood</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shafique</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Alawida</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Advances and vulnerabilities in modern cryptographic techniques: A comprehensive survey on cyber security in the domain of machine/deep learning and quantum techniques.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <year>2024</year>;<volume>12</volume>:<fpage>27530</fpage>&#x2013;<lpage>27555</lpage>.
                    <pub-id pub-id-type="doi">10.1109/access.2024.3367232</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref75">
                <label>75</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kuznetsov</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kiian</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Babenko</surname>
                            <given-names>V</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>New approach to the implementation of post-quantum digital signature scheme.</chapter-title>
                    <source>

                        <italic toggle="yes">2020 IEEE 11th international conference on dependable systems, services and technologies (DESSERT).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2020</year>; pp.<fpage>166</fpage>&#x2013;<lpage>171</lpage>.</mixed-citation>
            </ref>
            <ref id="ref76">
                <label>76</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>George</surname>
                            <given-names>AS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sagayarajan</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Baskar</surname>
                            <given-names>T</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Extending detection and response: how mxdr evolves cybersecurity.</article-title>
                    <source>

                        <italic toggle="yes">Partners Universal International Innovation Journal.</italic>
</source>
                    <year>2023</year>;<volume>1</volume>(<issue>4</issue>):<fpage>268</fpage>&#x2013;<lpage>285</lpage>.</mixed-citation>
            </ref>
            <ref id="ref77">
                <label>77</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Baseri</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chouhan</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ghorbani</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Evaluation framework for quantum security risk assessment: A comprehensive study for quantum-safe migration.</article-title>
                    <source>

                        <italic toggle="yes">arXiv preprint arXiv:2404.08231.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref78">
                <label>78</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mohammed</surname>
                            <given-names>AS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jha</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tabbassum</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Malik</surname>
                            <given-names>V</given-names>
                        </name>
</person-group>:
                    <chapter-title>Assessing the vulnerability of machine learning models to cyber attacks and developing mitigation strategies.</chapter-title>
                    <source>

                        <italic toggle="yes">2024 International Conference on Intelligent Systems and Advanced Applications (ICISAA).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2024</year>; pp.<fpage>1</fpage>&#x2013;<lpage>5</lpage>.</mixed-citation>
            </ref>
            <ref id="ref79">
                <label>79</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Yamin</surname>
                            <given-names>MM</given-names>
                        </name>
</person-group>:
                    <article-title>Modelling and analyzing attack-defense scenarios for cyber-ranges.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref80">
                <label>80</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Huang</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Barz</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Andersson</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Implementation vulnerabilities in general quantum cryptography.</article-title>
                    <source>

                        <italic toggle="yes">New J. Phys.</italic>
</source>
                    <year>2018</year>;<volume>20</volume>(<issue>10</issue>):<fpage>103016</fpage>.
                    <pub-id pub-id-type="doi">10.1088/1367-2630/aade06</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref81">
                <label>81</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shamoo</surname>
                            <given-names>Y</given-names>
                        </name>
</person-group>:
                    <chapter-title>Adversarial attacks and defense mechanisms in the age of quantum computing.</chapter-title>
                    <source>

                        <italic toggle="yes">Leveraging Large Language Models for Quantum-Aware Cybersecurity.</italic>
</source>
                    <publisher-name>IGI Global Scientific Publishing</publisher-name>;<year>2025</year>; pp.<fpage>301</fpage>&#x2013;<lpage>344</lpage>.</mixed-citation>
            </ref>
            <ref id="ref82">
                <label>82</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shevchenko</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chick</surname>
                            <given-names>TA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>O&#x2019;Riordan</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <source>

                        <italic toggle="yes">Threat modeling: a summary of available methods.</italic>
</source>
                    <publisher-name>Software Engineering Institute&#x2014; Carnegie Mellon University</publisher-name>;<year>2018</year>;<fpage>1</fpage>&#x2013;<lpage>24</lpage>.</mixed-citation>
            </ref>
            <ref id="ref83">
                <label>83</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Joseph</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Misoczki</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Manzano</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Transitioning organizations to post-quantum cryptography.</article-title>
                    <source>

                        <italic toggle="yes">Nature.</italic>
</source>
                    <year>2022</year>;<volume>605</volume>(<issue>7909</issue>):<fpage>237</fpage>&#x2013;<lpage>243</lpage>.
                    <pub-id pub-id-type="pmid">35546191</pub-id>
                    <pub-id pub-id-type="doi">10.1038/s41586-022-04623-2</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref84">
                <label>84</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>K&#x00a8;appler</surname>
                            <given-names>SA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Schneider</surname>
                            <given-names>B</given-names>
                        </name>
</person-group>:
                    <article-title>Post-quantum cryptography: An introductory overview and implementation challenges of quantum-resistant algorithms.</article-title>
                    <source>

                        <italic toggle="yes">Proc Soc.</italic>
</source>
                    <year>2022</year>;<volume>84</volume>:<fpage>61</fpage>&#x2013;<lpage>71</lpage>.</mixed-citation>
            </ref>
            <ref id="ref85">
                <label>85</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sadeghi</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chouhan</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Aldarwbi</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Securing financial sector applications in the quantum era: A comprehensive evaluation of nist&#x2019;s recommended algorithms through use-case analysis.</article-title>
                    <source>

                        <italic toggle="yes">SSRN 4836780.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref86">
                <label>86</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jain</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Agrawal</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Implementation of hybrid cryptography algorithm.</article-title>
                    <source>

                        <italic toggle="yes">International Journal Of Core Engineering &amp; Management (IJCEM).</italic>
</source>
                    <year>2014</year>;<volume>1</volume>(<issue>3</issue>):<fpage>126</fpage>&#x2013;<lpage>142</lpage>.</mixed-citation>
            </ref>
            <ref id="ref87">
                <label>87</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bishwas</surname>
                            <given-names>AK</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sen</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Strategic roadmap for quantum-resistant security: A framework for preparing industries for the quantum threat.</article-title>
                    <source>

                        <italic toggle="yes">arXiv preprint arXiv:2411.09995.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref88">
                <label>88</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Devulapally Swetha</surname>
                            <given-names>DSKM</given-names>
                        </name>
</person-group>:
                    <article-title>Quantum-enhanced security advances for cloud computing environments.</article-title>
                    <source>

                        <italic toggle="yes">Quantum.</italic>
</source>
                    <volume>15</volume>(<issue>6</issue>).</mixed-citation>
            </ref>
            <ref id="ref89">
                <label>89</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hale</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bindel</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Van Bossuyt</surname>
                            <given-names>DL</given-names>
                        </name>
</person-group>:
                    <chapter-title>Quantum computers: The need for a new cryptographic strategy.</chapter-title>
                    <source>

                        <italic toggle="yes">Handbook for Management of Threats: Security and Defense, Resilience and Optimal Strategies.</italic>
</source>
                    <publisher-name>Springer</publisher-name>;<year>2023</year>; pp.<fpage>125</fpage>&#x2013;<lpage>158</lpage>.
                    <pub-id pub-id-type="doi">10.1007/978-3-031-39542-0_7</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref90">
                <label>90</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rodr&#x2019;&#x0131;guez-P&#x2019;erez</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Costa</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Finogina</surname>
                            <given-names>T</given-names>
                        </name>
</person-group>:
                    <article-title>An electoral exception? quantum computing readiness and internet voting.</article-title>
                    <source>

                        <italic toggle="yes">JeDEM-eJournal of eDemocracy and Open Government.</italic>
</source>
                    <volume>16</volume>(<issue>3</issue>).</mixed-citation>
            </ref>
            <ref id="ref91">
                <label>91</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Aviram</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gellert</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jager</surname>
                            <given-names>T</given-names>
                        </name>
</person-group>:
                    <article-title>Session resumption protocols and efficient forward security for tls 1.3 0-rtt.</article-title>
                    <source>

                        <italic toggle="yes">J. Cryptol.</italic>
</source>
                    <year>2021</year>;<volume>34</volume>(<issue>3</issue>):<fpage>20</fpage>.
                    <pub-id pub-id-type="doi">10.1007/s00145-021-09385-0</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref92">
                <label>92</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Fingerhuth</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Babej</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wittek</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Open source software in quantum computing.</article-title>
                    <source>

                        <italic toggle="yes">PloS one.</italic>
</source>
                    <year>2018</year>;<volume>13</volume>(<issue>12</issue>):<fpage>e0208561</fpage>.
                    <pub-id pub-id-type="pmid">30571700</pub-id>
                    <pub-id pub-id-type="doi">10.1371/journal.pone.0208561</pub-id>
                    <pub-id pub-id-type="pmcid">PMC6301779</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref93">
                <label>93</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lee</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kim</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kwon</surname>
                            <given-names>Y</given-names>
                        </name>
</person-group>:
                    <chapter-title>Tls 1.3 in practice: How tls 1.3 contributes to the internet.</chapter-title>
                    <source>

                        <italic toggle="yes">Proceedings of theWeb Conference 2021.</italic>
</source>
                    <year>2021</year>; pp.<fpage>70</fpage>&#x2013;<lpage>79</lpage>.</mixed-citation>
            </ref>
            <ref id="ref94">
                <label>94</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ahn</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hussain</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kang</surname>
                            <given-names>K</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Exploring encryption algorithms and network protocols: A comprehensive survey of threats and vulnerabilities.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Commun Surv Tutor.</italic>
</source>
                    <volume>27</volume>:<fpage>3587</fpage>&#x2013;<lpage>3614</lpage>.
                    <pub-id pub-id-type="doi">10.1109/comst.2025.3526605</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref95">
                <label>95</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>Z</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lin</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Cai</surname>
                            <given-names>Q</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Blockchain-based certificate transparency and revocation transparency.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Trans Depend Secure Comput.</italic>
</source>
                    <year>2020</year>;<volume>19</volume>(<issue>1</issue>):<fpage>681</fpage>&#x2013;<lpage>697</lpage>.</mixed-citation>
            </ref>
            <ref id="ref96">
                <label>96</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Borgolte</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Fiebig</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hao</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Cloud strife: mitigating the security risks of domain-validated certificates.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref97">
                <label>97</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Laurie</surname>
                            <given-names>B</given-names>
                        </name>
</person-group>:
                    <article-title>Certificate transparency: Public, verifiable, append-only logs.</article-title>
                    <source>

                        <italic toggle="yes">Queue.</italic>
</source>
                    <year>2014</year>;<volume>12</volume>(<issue>8</issue>):<fpage>10</fpage>&#x2013;<lpage>19</lpage>.</mixed-citation>
            </ref>
            <ref id="ref98">
                <label>98</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bul&#x2019;ajoul</surname>
                            <given-names>W</given-names>
                        </name>

                        <name name-style="western">
                            <surname>James</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pannu</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Improving network intrusion detection system performance through quality of service configuration and parallel technology.</article-title>
                    <source>

                        <italic toggle="yes">J. Comput. Syst. Sci.</italic>
</source>
                    <year>2015</year>;<volume>81</volume>(<issue>6</issue>):<fpage>981</fpage>&#x2013;<lpage>999</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.jcss.2014.12.012</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref99">
                <label>99</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Simos</surname>
                            <given-names>DE</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kleine</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Voyiatzis</surname>
                            <given-names>AG</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Tls cipher suites recommendations: A combinatorial coverage measurement approach.</chapter-title>
                    <source>

                        <italic toggle="yes">2016 IEEE International Conference on Software Quality, Reliability and Security (QRS).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2016</year>; pp.<fpage>69</fpage>&#x2013;<lpage>73</lpage>.</mixed-citation>
            </ref>
            <ref id="ref100">
                <label>100</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Karygiannis</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Owens</surname>
                            <given-names>L</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Wireless Network Security.</italic>
</source>
                    <publisher-name>US Department of Commerce, Technology Administration, National Institute of</publisher-name>;<year>2002</year>.</mixed-citation>
            </ref>
            <ref id="ref101">
                <label>101</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Gorbenko</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ponomar</surname>
                            <given-names>V</given-names>
                        </name>
</person-group>:
                    <article-title>Examining a possibility to use and the benefits of post-quantum algorithms dependent on the conditions of their application.</article-title>
                    <source>

                        <italic toggle="yes">Eastern-European Journal of Enterprise Technologies.</italic>
</source>
                    <year>2017</year>;<volume>2</volume>:<fpage>21</fpage>&#x2013;<lpage>32</lpage>.
                    <pub-id pub-id-type="doi">10.15587/1729-4061.2017.96321</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref102">
                <label>102</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Darzi</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ahmadi</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Aghapour</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Envisioning the future of cyber security in post-quantum era: A survey on pq standardization, applications, challenges and opportunities.</article-title>
                    <source>

                        <italic toggle="yes">arXiv preprint arXiv:2310.12037.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref103">
                <label>103</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Alrashed</surname>
                            <given-names>EA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bagci</surname>
                            <given-names>F</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Alquraishi</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>A key management approach for forward and backward secrecy in unattended wsns.</article-title>
                    <source>

                        <italic toggle="yes">J. Eng. Res.</italic>
</source>
                    <volume>4</volume>(<issue>4</issue>):<fpage>24</fpage>&#x2013;<lpage>45</lpage>.
                    <pub-id pub-id-type="doi">10.1016/S2307-1877(25)00896-X</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref104">
                <label>104</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cremers</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <chapter-title>Key exchange in ipsec revisited: Formal analysis of ikev1 and ikev2.</chapter-title>
                    <source>

                        <italic toggle="yes">Computer Security&#x2013;ESORICS 2011: 16th European Symposium on Research in Computer Security, Leuven, Belgium, September 12&#x2013;14, 2011. Proceedings 16.</italic>
</source>
                    <publisher-name>Springer</publisher-name>;<year>2011</year>; pp.<fpage>315</fpage>&#x2013;<lpage>334</lpage>.</mixed-citation>
            </ref>
            <ref id="ref105">
                <label>105</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Dunbar</surname>
                            <given-names>N</given-names>
                        </name>
</person-group>:
                    <article-title>Ipsec networking standards&#x2014;an overview.</article-title>
                    <source>

                        <italic toggle="yes">Inf. Secur. Tech. Rep.</italic>
</source>
                    <year>2001</year>;<volume>6</volume>(<issue>1</issue>):<fpage>35</fpage>&#x2013;<lpage>48</lpage>.
                    <pub-id pub-id-type="doi">10.1016/S1363-4127(01)00106-6</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref106">
                <label>106</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hussain</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Enhanced authentication mechanism using multilevel security model.</article-title>
                    <source>

                        <italic toggle="yes">Int Arab J e Technol.</italic>
</source>
                    <year>2009</year>;<volume>1</volume>(<issue>2</issue>):<fpage>49</fpage>&#x2013;<lpage>57</lpage>.</mixed-citation>
            </ref>
            <ref id="ref107">
                <label>107</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zheng</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chang</surname>
                            <given-names>C-H</given-names>
                        </name>
</person-group>:
                    <chapter-title>Secure mutual authentication and key-exchange protocol between puf-embedded iot endpoints.</chapter-title>
                    <source>

                        <italic toggle="yes">2021 IEEE International Symposium on Circuits and Systems (ISCAS).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2021</year>; pp.<fpage>1</fpage>&#x2013;<lpage>5</lpage>.</mixed-citation>
            </ref>
            <ref id="ref108">
                <label>108</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Heino</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jalio</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hakkala</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A method for endpoint aware inspection in a network security solution.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <year>2022</year>;<volume>10</volume>:<fpage>44517</fpage>&#x2013;<lpage>44530</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ACCESS.2022.3170456</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref109">
                <label>109</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sundholm</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Hardening industrial network using isolated segments.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref110">
                <label>110</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Frankel</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kent</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lewkowski</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Guide to ipsec vpns.</article-title>.</mixed-citation>
            </ref>
            <ref id="ref111">
                <label>111</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hageman</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">The performance of ecc algorithms in dnssec: A model-based approach.</italic>
</source>
                    <publisher-name>University of Twente</publisher-name>;<year>2015</year>. Master&#x2019;s thesis.</mixed-citation>
            </ref>
            <ref id="ref112">
                <label>112</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ogala</surname>
                            <given-names>JO</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ahmad</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shakeel</surname>
                            <given-names>I</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Strengthening kms security with advanced cryptography, machine learning, deep learning, and iot technologies.</article-title>
                    <source>

                        <italic toggle="yes">SN Computer Science.</italic>
</source>
                    <year>2023</year>;<volume>4</volume>(<issue>5</issue>):<fpage>530</fpage>.
                    <pub-id pub-id-type="doi">10.1007/s42979-023-02073-9</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref113">
                <label>113</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chung</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rijswijk-Deij</surname>
                            <given-names>R</given-names>
                            <prefix>van</prefix>
                        </name>

                        <name name-style="western">
                            <surname>Chandrasekaran</surname>
                            <given-names>B</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>A longitudinal,{End-to-End} view of the {DNSSEC} ecosystem.</chapter-title>
                    <source>

                        <italic toggle="yes">26th USENIX Security Symposium (USENIX Security 17).</italic>
</source>
                    <year>2017</year>; pp.<fpage>1307</fpage>&#x2013;<lpage>1322</lpage>.</mixed-citation>
            </ref>
            <ref id="ref114">
                <label>114</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Huque</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Aras</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dickinson</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Rfc 8901: Multi-signer dnssec models.</article-title>
                    <year>2020</year>.</mixed-citation>
            </ref>
            <ref id="ref115">
                <label>115</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ariyapperuma</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mitchell</surname>
                            <given-names>CJ</given-names>
                        </name>
</person-group>:
                    <chapter-title>Security vulnerabilities in dns and dnssec.</chapter-title>
                    <source>

                        <italic toggle="yes">The Second International Conference on Availability, Reliability and Security (ARES&#x2019;07).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2007</year>; pp.<fpage>335</fpage>&#x2013;<lpage>342</lpage>.</mixed-citation>
            </ref>
            <ref id="ref116">
                <label>116</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rijswijk-Deij</surname>
                            <given-names>RM</given-names>
                            <prefix>van</prefix>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Improving DNS security: a measurement-based approach.</italic>
</source>
                    <publisher-name>University of Twente</publisher-name>;<year>2017</year>.</mixed-citation>
            </ref>
            <ref id="ref117">
                <label>117</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hock</surname>
                            <given-names>F</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kort&#x01d0;s</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <chapter-title>Design, implementation and monitoring of the firewall system for a dns server protection.</chapter-title>
                    <source>

                        <italic toggle="yes">2016 International Conference on Emerging eLearning Technologies and Applications (ICETA).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2016</year>; pp.<fpage>91</fpage>&#x2013;<lpage>96</lpage>.</mixed-citation>
            </ref>
            <ref id="ref118">
                <label>118</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jahromi</surname>
                            <given-names>AS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Abdou</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Oorschot</surname>
                            <given-names>PC</given-names>
                            <prefix>van</prefix>
                        </name>
</person-group>:
                    <article-title>Dnssec+: An enhanced dns scheme motivated by benefits and pitfalls of dnssec.</article-title>
                    <source>

                        <italic toggle="yes">arXiv preprint arXiv:2408.00968.</italic>
</source>
                </mixed-citation>
            </ref>
            <ref id="ref119">
                <label>119</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Deccio</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Argueta</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Demke</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <chapter-title>A quantitative study of the deployment of dns rate limiting.</chapter-title>
                    <source>

                        <italic toggle="yes">2019 International Conference on Computing, Networking and Communications (ICNC).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2019</year>; pp.<fpage>442</fpage>&#x2013;<lpage>447</lpage>.</mixed-citation>
            </ref>
            <ref id="ref120">
                <label>120</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shan</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Xie</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Visual detection of anomalies in dns query log data.</chapter-title>
                    <source>

                        <italic toggle="yes">2014 IEEE Pacific Visualization Symposium.</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2014</year>; pp.<fpage>258</fpage>&#x2013;<lpage>261</lpage>.</mixed-citation>
            </ref>
            <ref id="ref121">
                <label>121</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Canetti</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Halevi</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Katz</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <chapter-title>Aforward-secure public-key encryption scheme.</chapter-title>
                    <source>

                        <italic toggle="yes">Advances in Cryptology&#x2014;EUROCRYPT 2003: International Conference on the Theory and Applications of Cryptographic Techniques,Warsaw, Poland, May 4&#x2013;8, 2003 Proceedings 22.</italic>
</source>
                    <publisher-name>Springer</publisher-name>;<year>2003</year>; pp.<fpage>255</fpage>&#x2013;<lpage>271</lpage>.</mixed-citation>
            </ref>
            <ref id="ref122">
                <label>122</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chauhan</surname>
                            <given-names>AS</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Practical Network Scanning: Capture network vulnerabilities using standard tools such as Nmap and Nessus.</italic>
</source>
                    <publisher-name>Packt Publishing Ltd</publisher-name>;<year>2018</year>.</mixed-citation>
            </ref>
            <ref id="ref123">
                <label>123</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vermeer</surname>
                            <given-names>MJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Heitzenrater</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Parker</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Evaluating cryptographic vulnerabilities created by quantum computing in industrial control systems.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Critical Infrastructure Policy.</italic>
</source>
                    <year>2024</year>;<volume>5</volume>(<issue>2</issue>):<fpage>88</fpage>&#x2013;<lpage>110</lpage>.
                    <pub-id pub-id-type="doi">10.1002/jci3.12024</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref124">
                <label>124</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Daniel</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>Building a more secure network: A comprehensive guide to network segmentation strategies and best practices.</article-title>
                    <source>

                        <italic toggle="yes">Revista de Inteligencia Artificial en Medicina.</italic>
</source>
                    <year>2024</year>;<volume>15</volume>(<issue>1</issue>):<fpage>959</fpage>&#x2013;<lpage>968</lpage>.</mixed-citation>
            </ref>
            <ref id="ref125">
                <label>125</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bates</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bowers</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Greenstein</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <source>

                        <italic toggle="yes">Evidence of decreasing internet entropy: the lack of redundancy in dns resolution by major websites and services, Tech. rep.</italic>
</source>
                    <publisher-name>National Bureau of Economic Research</publisher-name>;<year>2018</year>.</mixed-citation>
            </ref>
            <ref id="ref126">
                <label>126</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jabez</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Muthukumar</surname>
                            <given-names>B</given-names>
                        </name>
</person-group>:
                    <article-title>Intrusion detection system (ids): Anomaly detection using outlier detection approach.</article-title>
                    <source>

                        <italic toggle="yes">Procedia Computer Science.</italic>
</source>
                    <year>2015</year>;<volume>48</volume>:<fpage>338</fpage>&#x2013;<lpage>346</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.procs.2015.04.191</pub-id>
                </mixed-citation>
            </ref>
        </ref-list>
    </back>
</article>
