OJS (University of Applied Sciences Velika Gorica)
Not a member yet
306 research outputs found
Sort by
Cyber Situational Awareness in Critical Infrastructure Protection
The European Union promotes collaboration between authorities and the private sector, and the providers of the most critical services to society face security related obligations. In this paper, critical infrastructure is seen as a system of systems that can be subject to cyber-attacks and other disturbances. Situational awareness (SA) enhances preparations for and decision-making during assessed and unforeseen disruptive incidents, and promoting Cyber effective situational awareness (CSA) requires information sharing between the different interest groups. This research is constructive in nature, where innovative constructions developed as solutions for domain-specific real world problems, while the research question is: “How can cyber situational awareness protect critical infrastructures?” The Observe – Orient – Decide – Act (OODA) loop is examined as a way to promote collaboration towards a shared situational picture, awareness and understanding to meet challenges of forming CSA in relation to risk assessment (RA) and improving resilience. Three levels of organizational decision-making are examined in relation a five-layer cyber structure of an organization to provide a more comprehensive systems view of organizational cyber security. Successful, crisis-management efforts enable organizations to sustain and resume operations, minimize losses, and adapt to manage future incidents, as many critical infrastructures typically lack resilience and may easily lose essential functionality when hit by an adverse event. Situation awareness is the main prerequisite towards cyber security. Without situation awareness, it is impossible to systematically prevent, identify, and protect the system from cyber incidents
Hybrid VLC Communications System for Increased Security Based on Raspberry Pi Microcomputer
VLC (Visible Light Communications) technology represents nowadays a new paradigm that could have a significant impact on future wireless communications. Although this technology has many advantages, one of the most common problem generated by the use of optical communication systems (based on the light in the visible spectrum), is the increased degree of disruption of the communication channel under the direct sunlight influence. The purpose of this article is to present the technological developments specific to the VLC/IR-RF (Visible Light Communication / Infrared - Radio-Frequency) hybrid system developed in the framework of a scientific research project started in 2017, which were recorded during the first half of 2019. This system based on multiple sensory devices such as temperature, motion, light intensity, dust, IR and microbolometer sensors will present the ability of intelligent monitoring and control of indoor environments (houses, office buildings, universities, campuses, etc.). From the point of view of the final purpose of the project, this will result in a hybrid bidirectional optical communication system capable of supporting high transfer rates, increased resistance to the specific sunlight disturbance, and the possibility of transmitting sensory information over long distances. The previous experimentation activities undertaken during the project were based on the use of the Arduino UNO development boards. Currently, it has been chosen to replace them with the development boards based on the ARM Cortex-A53 processor, in order to improve the system’s performance. The Arduino development boards have limited the performance of the communications system from the point of view of the transfer speeds and distances. The new Raspberry Pi development boards, being a complete operating and control system, presents high operational performances that can be used in favor of the final goal of the project
Case for Geospatial Border Surveillance on the Bosnia-Herzegovina and Croatia Border in Response to the Migrant Crisis and Hybrid Warfare
Bosnia-Herzegovina and Republic of Croatia share 931km of border (494km land and 425km riverine), which has been contentious for the greater part of the modern European history and represented one of the hardest and most-militarized border demarcating the frontiers of the major empires. Nowadays, it is in the process of becoming another hard-border between the Schengen-Zone EU and non-EU Western Balkans. In this study we are considering several strategic elements required for planning of effective and constructive border security, while countering variety of pseudo-hybrid warfare operations as well as tactical considerations when responding to crisis, communications and overall control of the fluid frontier. Strategic elements taken into consideration are: a) overall contiguity of the border, b) communications network / trafficability at border-crossing and c) geospatial support in the intelligence preparation of the area. Tactical elements considered are a) real-time geospatial support during operations b) alternative communications and vetting of alternative communications c) defensive operations (e.g. drone defense, jamming defense, incursion prevention). We are considering lessons-learned from the hostilities and frozen-conflicts in Yugoslavia, Ukraine, Afghanistan, Yemen and potential future conflagrations in Trans-Dnistria, Bosnia-Herzegovina, Kosovo* and the Baltics. We are using several criteria in understanding the required geospatial preparations required to undertake or defend against mass-migrations and potential hybrid threats such as unresolved territorial issues, population density information, infrastructure condition, land-use and overall completeness and availability of geospatial data.
* Designation without prejudice to positions on status, and is in line with UNSCR 1244 and the ICJ Opinion on the Kosovo Declaration of Independenc
Overall Seismic Risk in Bosnia-Herzegovina/Dalmatia Region of Croatia and Elements of Perfect Crisis in an Earthquake Aftermath
Bosnia-Herzegovina and southern-coastal/hinterland-region of Dalmatia, Republic of Croatia are a part of the same seismo-tectonic province and share a considerable and real threat of high-magnitude earthquakes. Numerous Magnitude 6 (Richter) and above earthquakes have been recorded in the past 500 years and some of them have resulted in a considerable loss of life, material and even prestige or geopolitical significance (e.g. the demise of Ragusa in the earthquake of 1667). Given the propensity of the region for destructive earthquakes, complex geomorphological framework and challenging infrastructure, still recovering in parts from the Yugoslav civil wars of the 1990s., the region may yield a “perfect” crisis in the aftermath of a major earthquake event. Taking into consideration unchecked development of several metropolitan areas, lack of oversight and permitting, decaying infrastructure as well as unresolved political ambiguities and territorial disputes, a potential destructive earthquake may create several cascading crises, especially if it coincides with some other challenging events (e.g. winter storms). This study is taking into consideration several scenarios, their possible effects and resulting conditions upon which cascading crises may arise in the aftermath of a magnitude 7+ earthquake affecting several major urban areas in southern and central Bosnia-Herzegovina and the southern Dalmatian region of Croatia. These scenarios are intended to provide training aids and risk assessments in countering the destructive forces after the earthquake, expected to test the current crisis-management models. 
Beyond Physical Threats: Cyber-attacks on Critical Infrastructure as a Challenge of Changing Security Environment – Overview of Cyber-security legislation and implementation in SEE Countries
States, organizations and individuals are becoming targets of both individual and state-sponsored cyber-attacks, by those who recognize the impact of disrupting security systems and effect to people and governments. The energy sector is seen as one of the main targets of cyber-attacks against critical infrastructure, but transport, public sector services, telecommunications and critical (manufacturing) industries are also very vulnerable. One of most used example of cyber-attack is the Ukraine power grid attack in 2015 that left 230,000 people without power for up to 6 hours. Another most high profile example of a cyber-attack against critical infrastructure is the Stuxnet computer virus (first used on Iranian nuclear facility) which could be adapted to attack the SCADA systems (industrial control systems) used by many critical infrastructures in Europe.Wide range of critical infrastructure sectors are reliant on industrial control systems for monitoring processes and controlling physical devices (sensors, pumps, etc.) and for that reason, physical connected devices that support industrial processes are becoming more vulnerable. Not all critical infrastructure operators in all sectors are adequately prepared to manage protection (and raise resilience) effectively across both cyber and physical environments. Additionally there are few challenges in implementation of protection measures, such as lack of collaboration between private and public sector and low levels of awareness on existence of national key legislation.From supranational aspect, in relation to this papers topic, the European Union has took first step in defense to cyber threats in 2016 with „Directive on security of network and information systems“ (NIS Directive) by prescribing member states to adopt more rigid cyber-security standards. The aim of directive is to improve the deterrent and increase the EU’s defenses and reactions to cyber attacks by expanding the cyber security capacity, increasing collaboration at an EU level and introducing measures to prevent risk and handle cyber incidents. There are lot of other „supporting tools“ for Member States countries, such as European Union Agency for Network and Information Security – ENISA (which organize regular cyber security exercises at an EU level, including a large and comprehensive exercise every two years, raising preparedness of EU states); Network of National Coordination Centers and the European Cybersecurity Industrial, Technology and Research Competence Centre; and Coordinated response to major cyber security incidents and crises (Blueprint) with aim to ensure a rapid and coordinated response to large-scale cyber attacks by setting out suitable processes within the EU.Yet, not all Member States share the same capacities for achieving the highest level of cyber-security. They need to continuously work on enhancing the capability of defense against cyber threats as increased risk to state institutions information and communication systems but also the critical infrastructure objects. In Southeast Europe there are few additional challenges – some countries even don't have designated critical infrastructures (lower level of protection; lack of „clear vision“ of criticality) and critical infrastructures are only perceived through physical prism; non-EU countries are not obligated to follow requirements of European Union and its legislation, and there are interdependencies and transboundary cross-sector effects that needs to be taken in consideration. Critical infrastructure Protection (CIP) is the primary area of action, and for some of SEE countries (like the Republic of Croatia) the implementation of cyber security provisions just complements comprehensive activities which are focused on physical protection.This paper will analyze few segments of how SEE countries cope with new security challenges and on which level are they prepared for cyber-attacks and threats: 1. Which security mechanisms they use; 2. The existing legislation (Acts, Strategies, Plan of Action, etc.) related to cyber threats in correlation with strategic critical infrastructure protection documents. Analysis will have two perspectives: from EU member states and from non-EU member states point of view. Additionally, for EU member states it will be analyzed if there were any cyber security legislation before NIS directive that meets same aims. The aim of research is to have an overall picture of efforts in region regarding cyber-security as possibility for improvement thorough cooperation, organizational measures, etc. providing also some recommendations to reduce the gap in the level of cyber-security development with other regions of EU
Security in Quantum Computing
Quantum key distribution will bring more confidentiality and privacy of communication in the future ICT world and will solve the eavesdropping issue. Domains regarded are e-government, e-commerce, e-health, transmission of biometric data, intelligent transport systems and more. So far, quantum researches focus on using properties of the qubit to bring improvements in technologies from our days. The purpose of this paper is to describe the quantum encryption methods. These methods can bring more efficiency of security in existing communications. In this matter, many encryption architectures have been proposed. As an example, the QKD architecture is presented in this paper
IoT Platform for Personal Data Protection
Since the establishment of IoT (Internet of Things), a variety of end devices become interconnected with one another, and thus, new types of security challenges appeared which have to be taken care of. Personal data, at the moment, have a higher risk of being hacked by various types of cyberattacks, as a result of the abundance of connectivity in the cloud realm. To face this type of challenges, the European Union decided to implement in 2018 the GDPR (General Data Protection Regulation) that implies that personal data of any kind can be shared with a third party only with their accord and can be, as well, deleted by them, whenever they desire. Henceforth, this paper introduces the PARFAIT project that will take into account this regulation and will integrate a platform with the purpose of protecting the personal data in IoT based applications, especially for smart home, smart office and smart hotel use cases
Improving Cyber Security with Resilience
Cyber security is commonly defined as the practice of protecting computers, networks, programs and data from unauthorized access or malicious attacks that are aimed for exploitation. Hence, cyber security is focused primary on malicious activities prevention and protection from occurring. Prevention and protection objectives have been usually achieved by applying traditional risk assessment and management procedures. Despite these efforts it has been shown that complete security of IT systems and data is almost impossible to achieve. Namely, by increasing number and type of different cyber threats the cyber incidents are becoming inevitable. Thus, even the strong cyber security is not enough anymore. Because of that organizations need to build the cyber resilience which mainly deals with system respond and recovery after disruptive event occurring. Cyber security combined with cyber resilience opens a new perspective towards better overall security of IT systems
Airports’ Crisis Management Processes and Stakeholders Involved
Airports are exposed to various physical incidents that can be classified as aviation and non-aviation related incidents, including terrorist attacks, bombings, natural disasters (e.g. earthquake or tsunami and man-made disasters such as terrorist attacks) etc. (Kanyi, Kamau, & Mireri, 2016). In addition to this, cyber-attacks to airport operations are emerging especially with the increasing use of Information Systems (IS), such as electronic tags for baggage handling and tracking, remote check-in, smart boarding gates, faster and more reliable security screening technologies and biometric immigration controls etc. Any physical or cyber incident that causes loss of infrastructure or massive patient surge, such as natural disasters, terrorist acts, or chemical, biological, radiological, nuclear, or explosive hazards could affect the airports’ services provision and could cause overwhelming pressure. During the crisis management, several stakeholders that have different needs and requirements, get involved in the process, trying to cooperate, respond and support recovery and impact mitigation. The aim of this paper is to present a holistic security agenda that defines the stakeholders involved in the respective processes followed during the crisis management cycle. This agenda is based both on normative literature, such as relevant standards, guidelines, and practices and on knowledge and feedback extrapolated from a case study conducted in the context of the SATIE project (H2020-GA832969). In meeting paper’s aim, initially the normative review of the phases of the crisis management cycle (preparedness, response, recovery and mitigation) in the context of airports as well as general practices applied, are presented. Moreover, the key airport stakeholders and operation centres involved in airports operations, as well as during the crisis management are analysed. By combining the information collected, a holistic cyber and physical crisis management cycle including the stakeholders and the relevant processes are proposed. The crisis management process is taken into consideration into the SATIE project, which aims to build a security toolkit in order to protect critical air transport infrastructures against combined cyber-physical threats. This toolkit will rely on a complete set of semantic rules that will improve the interoperability between existing systems and enhanced security solutions, in order to ensure more efficient threat prevention, threat and anomaly detection, incident response and impact mitigation, across infrastructures, populations and environment
Implementing Cybersecurity Measures in Transport Organisation
The Article describes the phases of implementing the necessary measures according to Cybersecurity Regulation for critical infrastructure and ISO 27032 standard. As a base for identification of the necessary measures in transport organization the risk assessment has been done. The Risk Management Methodology has been described as well as the results of the risk assessment. The main aspects of risk treatment with the most suitable measures for Cyber risks are identified. Also as very important aspect of protecting critical transport infrastructure we have identified the critical services and prepared business continuity plans. The main steps and results in providing the acceptable level of availability and opportunities for continuity are presented and explained