Spelling suggestions: "subject:"anda security."" "subject:"ando security.""
191 |
Warum wir ein Security-Engineering-Informationsmodell brauchen: Motivation, Anwendungsfälle und Konzept für ein neues Domänenmodell für Security-EngineeringTaştan, Emre, Fluchs, Sarah, Drath, Rainer 27 January 2022 (has links)
Security ist eine der größten Herausforderungen bei der industriellen Digitalisierung und der Einführung von Internettechnologien. Während die funktionale Sicherheit tief in die Entwicklung von Produkten oder Prozessen integriert ist, ist dies bei der Security nicht der Fall. Security-Engineering muss sich also – analog zur funktionalen Sicherheit – in den bestehenden und sich gerade stark verändernden Automation-Engineering-Prozess eingliedern, vor allem muss es aber für Automatisierungsingenieure effizient durchführbar sein. Dieser Beitrag begründet den Bedarf an einem Security-Engineering-Modell und berichtet über die laufenden Arbeiten zu den Anwendungsfällen und einem Modellierungsansatz mit AutomationML.
|
192 |
Automated Vulnerability Assessment of Mobile Device VulnerabilitiesShambra, Stephen M 06 May 2017 (has links)
Mobile device security presents a unique challenge in the realm of cyber security, one which is difficult to assess and ultimately defend. Mobile devices, like other computing devices, should possess a secure environment by which a mobile user may operate safely and securely. However, insecure coding when developing applications, incomplete assessment tools to determine platform/application security, and security shortcomings in the Android platform and mobile communications standards result in an insecure environment. This thesis presents an analysis of aspects of a Mobile Station to identify components that contribute to the attack surface. An investigation is conducted to highlight vulnerabilities at the Application, Communications, and Resource Layers. The thesis also identifies current efforts to assess and identify mobile vulnerabilities and weaknesses in application and system settings. Finally, an automated vulnerability assessment solution is developed and introduced in this thesis that can aid in combating potential threats to mobile security.
|
193 |
An open virtual testbed for industrial control system security researchReaves, Bradley Galloway 06 August 2011 (has links)
ICS security has been a topic of scrutiny and research for several years, and many security issues are well known. However, research efforts are impeded by a lack of an open virtual industrial control system testbed for security research. This thesis describes a virtual testbed framework using Python to create discrete testbed components (including virtual devices and process simulators). This testbed is designed such that the testbeds are interoperable with real ICS devices and that the virtual testbeds can provide comparable ICS network behavior to a laboratory testbed. Two testbeds based on laboratory testbeds have been developed and have been shown to be interoperable with real industrial control systemequipment and vulnerable to attacks in the samemanner as a real system. Additionally, these testbeds have been quantitatively shown to produce traffic close to laboratory systems (within 90% similarity on most metrics).
|
194 |
How is it possible to calculate IT security effectiveness?Kivimaa, Kristjan January 2022 (has links)
In IT Security world, there is lack of available, reliable systems for measuring securitylevels/posture. They lack the range of quantitative measurements and easy and fast deployment,and potentially affects companies of all sizes.Readily available security standards provide qualitative security levels, but not quantitative results– that would be easily comparable. This deficiency makes it hard for companies to evaluate theirsecurity posture accurately. Absence of security metrics makes it complicated for customers toselect the appropriate measures for particular security level needed.The research question for this research project is – “How is it possible to calculate IT securityeffectiveness?”.The aim of this research is to use this reference model to calculate and to optimize majoruniversity’s and a small CSP-s (Cloud Service Provider) security posture and their spending’s onsecurity measures. Aim is to develop a reference model to support IT Security team and businessside to make reasoned and optimal decisions about IT security and all that with a reasonablenumber of manhours.In this Graded Security Expert System (GSES) aka Graded Security Reference Model (GSRM) thequantitative metrics of the graded security approach are used to express the relations betweensecurity goals, security confidence and security costs.What makes this model unique, is the option to use previous customers security templates/models– cutting the implementation time from 500+ manhours to as low as 50 manhours. The firstcustomers 500+ manhours will also be cut down to 50+ manhours on the second yearimplementing the expert system.The Graded Security Reference Model (GSRM) was developed using a combination oftheoretical method and design science research. The model is based on InfoSec (info security)activities and InfoSec spendings from previous year – cost and effectiveness – gathered fromexpert opinionsBy implementing GSRM, user can gather quantitative security levels as no other model, or astandard provides those.GSRM delivers very detailed and accurate (according to university’s IT Security Team)effectiveness levels per spendings brackets.GSRM was created as a graded security reference model on CoCoViLa platform, which is unique asit provides quantitative results corresponding to company’s security posture.Freely available models and standards either provide vague quantitative security postureinformation or are extremely complicated to use – BIS/ISKE (not supported any more).This Graded Security Reference Model has turned theories presented in literature review into afunctional, graphical model.The GSRM was used with detailed data from the 15+k users university and their IT security team(all members have 10+ years of IT security experience) concluded that the model is reasonablysimple to implement/modify, and results are precise and easily understandable. It was alsoobserved that the business side had no problems understanding the results and very fewexplanatory remarks were needed.
|
195 |
European Security Development: From Maastricht to BosniaThompson, Beth A. 11 September 2012 (has links)
No description available.
|
196 |
PRIMA - Privilege Management and Authorization in Grid Computing EnvironmentsLorch, Markus 28 April 2004 (has links)
Computational grids and other heterogeneous, large-scale distributed systems require more powerful and more flexible authorization mechanisms to realize fine-grained access-control of resources. Computational grids are increasingly used for collaborative problem-solving and advanced science and engineering applications. Usage scenarios for advanced grids require support for small, dynamic working groups, direct delegation of access privileges among users, procedures for establishing trust relationships without requiring organizational level agreements, precise management by individuals of their privileges, and retention of authority by resource providers. Existing systems fail to provide the necessary flexibility and granularity to support these scenarios. The reasons include the overhead imposed by required administrator intervention, coarse granularity that only allows for all-or-nothing access control decisions, and the inability to implement finer-grained access control without requiring trusted application code.
PRIMA, the model and system developed in this research, focuses on management and enforcement of fine-grained privileges. The PRIMA model introduces novel approaches that can be used in place of, or in combination with existing access control mechanisms. PRIMA enables the users of a system to manage access to their own assets directly without the need for, and costs of intervention by technical personnel. System administrators benefit from more flexible and fine-grained definition of access privileges and policies. A novel access control decision and enforcement model with support for legacy applications has been developed. The model uses on-demand account leasing and implements expressive enforcement mechanisms built on existing low-overhead security primitives of the operating systems. The combination of the PRIMA components constitutes a comprehensive security model that facilitates highly dynamic authorization scenarios and increases security through least privilege access to resources. In summary, PRIMA mechanisms enable the use of fine-grained access rights, reduce administrative costs to resource providers, enable ad-hoc and dynamic collaboration scenarios, and provide improved security service to long-lived grid communities. / Ph. D.
|
197 |
Improving Water Security with Innovation and Transition in Water Infrastructure: From Emergence to Stabilization of Rainwater Harvesting in the U.S.Reams, Gary A. 12 November 2021 (has links)
Globally, two-thirds of the population face significant water shortages and eighty percent of the U.S. states' water managers predict water shortages in the near future. Additionally, the current centralized system in the United States is facing significant problems of scarcity, groundwater depletion, high energy consumption and needs a trillion dollars investment in repairs, replacement, and expansion. Furthermore, due to increased urban/suburban development, runoff (stormwater) pollutes our waterways and is causing increased flooding. The status quo is unsustainable in its present form and the water security of the nation is at risk. Fortunately, in recent decades there has been a resurgence in the use of a millenniums old approach, rainwater harvesting (RWH), that if deployed broadly, will mitigate those issues created by the current centralized municipal water system and the expanding development of our cities, suburbs, and towns reducing permeable surface area and lower water security vulnerabilities. This study enlists Multi-Level Perspective (MLP) to examine the transitioning that is occurring from the current centralized municipal water system to one in which it is significantly complemented by an alternative water source, RWH. MLP posits that pressures originating in the broader landscape exerts pressures on the existing regime, as well as the community as a whole, creating an opportunity for the niche to emerge and either replace or change the regime. In the case of RWH, the myriad of pressures are only partially placed on the current centralized water supply regime providing them less pressure to change. Alongside water shortages another significant pressure being placed on the public and governing authorities is increased flooding and pollution resulting in the RWH niche emerging in the construction industry. In response to these pressures a RWH niche formed, largely outside of the existing water supply regime, and grew until it was joined by actors within the regime (e.g., plumbers, plumbing engineers, standards development organizations). This research is framed using MLP's three phases Start-up (niche), Acceleration, and Stabilization. This dissertation does three things. First it shows the internal processes occurring between the MLP levels (landscape, sociotechnical regime, and niche) and mechanisms created that foster the broader adoption of RWH. Secondly, it reveals that while the incumbent regime is not being significantly influenced by the RWH niche, the construction industry is embracing RWH (especially the commercial sector) and following the MLP pathway of Reconfiguration. Third, it looks at RWH in a phase of stabilization. / Doctor of Philosophy / Today the world, as well as the United States, faces significant water problems. These problems include scarcity, groundwater depletion, high energy consumption, and is in need of a trillion dollars to repair or replace US water infrastructure. Additionally, due to urban sprawl and diminishment of permeable surfaces, runoff is a problem causing flooding and pollution. One mitigation is the use of a millennium old technology, rainwater harvesting (RWH). This research uses Multi-Level Perspective (MLP) framework to examine the transition occurring today in the construction industry to build sustainable RWH into new construction, especially commercial buildings. This research examines the dynamic processes and the mechanisms used to grow the RWH niche and then accelerate its adoption. Those mechanisms include building demonstration projects, manuals, standards, and incentive programs. This research also looks at RWH in the U.S. Virgin Islands where RWH has been mandated since 1964. The practical value of this research is to provide policy makers insight into the useful mechanisms aiding a transition to sustainable infrastructure. The theoretical value is that it reveals a transition occurring outside of the dominate regime, the centralized water suppliers, in the construction industry. Additionally, it shows that the creation of RWH standards and the administration of building code has created a new form of water governance.
|
198 |
Nuclear weapons in global securityChristoph, Bluth, 03 December 2020 (has links)
no / Published 2017, © 2018.
|
199 |
Learning-based Cyber Security Analysis and Binary Customization for SecurityTian, Ke 13 September 2018 (has links)
This thesis presents machine-learning based malware detection and post-detection rewriting techniques for mobile and web security problems. In mobile malware detection, we focus on detecting repackaged mobile malware. We design and demonstrate an Android repackaged malware detection technique based on code heterogeneity analysis. In post-detection rewriting, we aim at enhancing app security with bytecode rewriting. We describe how flow- and sink-based risk prioritization improves the rewriting scalability. We build an interface prototype with natural language processing, in order to customize apps according to natural language inputs. In web malware detection for Iframe injection, we present a tag-level detection system that aims to detect the injection of malicious Iframes for both online and offline cases. Our system detects malicious iframe by combining selective multi-execution and machine learning algorithms. We design multiple contextual features, considering Iframe style, destination and context properties. / Ph. D. / Our computing systems are vulnerable to different kinds of attacks. Cyber security analysis has been a problem ever since the appearance of telecommunication and electronic computers. In the recent years, researchers have developed various tools to protect the confidentiality, integrity, and availability of data and programs. However, new challenges are emerging as for the mobile security and web security. Mobile malware is on the rise and threatens both data and system integrity in Android. Furthermore, web-based iframe attack is also extensively used by web hackers to distribute malicious content after compromising vulnerable sites.
This thesis presents on malware detection and post-detection rewriting for both mobile and web security. In mobile malware detection, we focus on detecting repackaged mobile malware. We propose a new Android repackaged malware detection technique based on code heterogeneity analysis. In post-detection rewriting, we aim at enhancing app security with bytecode rewriting. Our rewriting is based on the flow and sink risk prioritization. To increase the feasibility of rewriting, our work showcases a new application of app customization with a more friendly user interface. In web malware detection for Iframe injection, we developed a tag-level detection system which aims to detect injection of malicious Iframes for both online and offline cases. Our system detects malicious iframe by combining selective multi-execution and machine learning. We design multiple contextual features, considering Iframe style, destination and context properties.
|
200 |
A Study of the Government's Loyalty and Security ProgramsJohnagin, L. A 01 1900 (has links)
The purpose of this study is to show just how a loyalty or security program may affect the government employee or armed service personnel as individuals and as a unit of a department.
|
Page generated in 0.0667 seconds