eprints (HSR Hochschule für Technik Rapperswil)
Not a member yet
1196 research outputs found
Sort by
Discord Exploitation Lab
Discord Exploitation Lab
Red teaming Hacking-Lab for Discord bots inspired by the OWASP Top Ten
Initial Situation: Discord is an instant messaging and VoIP based platform, popular in gaming, tech and communities of all kind. Servers created by users can have their functionalities extended and automated by community-made bots. These bots, while useful, can be vulnerable to issues like injection flaws and broken authentication, aligning with the vulnerabilities described in the newest OWASP Top Ten. There's a noticeable lack of practical, interactive training for securing Discord bots, even though there's plenty of theoretical information available. This highlights the need for hands-on learning experiences to effectively understand and address these vulnerabilities.
Approach / Technology: Our goal was not only to create an educational lab about Discord Bots but also to present it in a playful and game-like form. The aim was to make solving challenges enjoyable, resembling a role-playing game where students walk through an adventure, encountering five different characters represented by Discord bots, each with their own vulnerability and challenge. For the development of this lab we used Python in combination with the Nextcord library to develop our bots and Docker Compose for instance management, within the Hacking-Lab framework.
Result: In total 5 different challenges were implemented. The challenges are included in OST's Hacking-Lab and covers most of the OWASP Top Ten. The challenges each bot itself poses could be solved on it's own but in our lab we integrated each bot in a bigger story to make the journey more interesting. Within the bots, we made a clear distinction between singleton and pseudo-bots due to their significant operational differences. In the challenges where pseudo-bots are used, the student is in full control of the pseudo-bot, orchestrated by the management framework we developed. This allows us to display all the pseudo-bots as a single Discord bot, while ensuring that users can't interfere with each other
Settingsapplikation mit integriertem Plugin System
In this thesis, a plugin system for the existing ReSet application is developed.
ReSet is a settings application for Linux which aims to provide support for
multiple desktop environments and window managers/compositors. Therefore, ReSet
offers only a small set of core features due to its focus on universal
environment support. As such a plugin system is needed in order to offer
additional functionality.
The architecture of the plugin system was developed by analyzing existing
solutions for other software and by creating various prototypes to prove the
viability of each system on ReSet and its potential plugins.
The plugin system was ultimately developed with shared libraries which allows
for resource sharing in both the daemon and the user interface of ReSet without
the additional overhead of an interpreter.
To prove the plugin system, two exemplary plugins were developed in this thesis.
The first is a monitor plugin, which allows users to change individual settings
of each monitor and to rearrange their monitors. The second is a keyboard plugin
which allows users to add, remove and rearrange keyboard layouts. Combined with
the plugin system is a testing framework which also allows plugin developers to
include their tests within ReSet in order to allow integration tests.
In summary, the plugin system was successfully implemented, with both plugins
expanding the functionality as expected. Additionally, the plugin system offers
ReSet the opportunity to offer limitless potential in both environment and
hardware support, while also giving users the option to choose their own options
within ReSet
Web Anwendung für Medical Wellness Beratung
Abstract
Ausgangslage
Das Erstgespräch in der Physiotherapie, auch Anamnese genannt, bildet die Grundlage für die individuelle Behandlungsplanung. Physiotherapeuten erheben dabei relevante Informationen zur Krankengeschichte, den aktuellen Beschwerden sowie den Lebensumständen der Patientinnen und Patienten. Eine bedeute Herausforderung in der klinischen Arbeit ist es, das multidimensionale Profil der Patienten zu erfassen und darauf basierend eine für den Patienten nachvollziehbare Therapieplanung zu entwickeln. Trotz der zentralen Rolle dieser Anamnese existieren bisher keine allgemein anerkannten „Best Practices“ oder standardisierten Verfahren. Dies eröffnet Potenziale für die Entwicklung eines standardisierten Gesprächsprozesses, der durch ein digitales Tool unterstützt wird.
Ziel der Arbeit
Ziel dieser Studienarbeit aus dem Studiengang Informatik, die in interdisziplinärer Zusammenarbeit mit Studierenden des Studiengangs Physiotherapie durchgeführt wurde, ist die Entwicklung einer Webanwendung zur Unterstützung eines strukturierten und digitalisierten Anamnese Prozesses, inklusive Gespräch, Assessments und Therapieplanung. Die Physiotherapiestudierenden entwickelten den Gesprächsprozess, während Inhalte und Darstellung der Anwendung in enger Abstimmung beider Teams definiert wurden. Der Prozess umfasst die strukturierte Erfassung von Problembereichen mit der PRISM-Methode, eine situativ angepasste Patientenbefragung anhand von 1–5 standardisierten Fragebögen sowie die Durchführung von 4 physischen Assessments. Zum Abschluss präsentiert die Anwendung Therapeuten und Patienten eine visuell aufbereitete Ergebnisübersicht zur Diskussion der weiteren Behandlungsplanung.
Vorgehen / Technologien
Das Projekt wurde nach agilen SCRUM-Methoden umgesetzt. Die Entwicklung der Single-Page-Webanwendung basiert auf React, Tailwind CSS und Next.js. Datenschutzkonforme Datenverarbeitung wurde durch lokale Speicherung und Ausgabe mittels QR-Codes auf PDFs sichergestellt. Mockups wurden in Figma erstellt und iterativ getestet. Zwei erfolgreiche Tests des Gesprächsprozesses und der Anwendung in realistischen Settings im Kantonsspital Winterthur zeigten die hohe Usability, intuitive Bedienung und einfache Integrierbarkeit in bestehende IT Infrastrukturen. Die entwickelte Lösung ermöglicht eine sichere, flexible und benutzerfreundliche Unterstützung des Anamnesegesprächs und bietet Potenzial für den Einsatz in weiteren Kontexten
Analyse Intranet Content
Im Rahmen unserer Studienarbeit haben wir ein Tool entwickelt, das Unternehmen dabei unterstützt, Trends und Muster in ihren Daten zu
erkennen, relevante Informationen zu vernetzen und datenbasierte Entscheidungen für ein effektives Wissensmanagement und eine fundierte
strategische Analyse zu treffen. Solche Analysen sind ohne entsprechende automatische Aufbereitung äusserst zeitaufwändig.
In vielen Organisationen sammeln sich über die Zeit Dokumente, oder allgemeiner, Informationen an. Allerdings bleibt oft unklar,
welche Themen, Trends oder Schlüsselpersonen über einen bestimmten Zeitraum hinweg relevant sind.
Unser Tool adressiert dieses Problem, indem es Inhalte ausliest, analysiert und visuell aufbereitet.
Daten von festgelegten Webseiten wie internen Blogs, Geschäftsberichten oder firmeninternen sozialen Plattformen werden regelmässig
extrahiert, geparst und mit Large Language Models (LLMs) analysiert. Die Originaltexte und Analysen werden in einer Datenbank gespeichert,
welche als Grundlage für weiterführende Analysen und Auswertungen dient. Die Analyseergebnisse ermöglichen die Auswertung der Entwicklung
bestimmter Themenbereiche, etwa die Feststellung, dass in den letzten sechs Monaten die Anzahl der Dokumente im Bereich Künstliche
Intelligenz gestiegen ist.
Der Zugriff auf die aufbereiteten Daten erfolgt über eine benutzerfreundliche Webanwendung mit umfangreichen Visualisierungsmöglichkeiten.
Nutzer haben die Möglichkeit, mithilfe von Filtern gezielt Themen und Trends zwischen den Dokumenten und Plattformen zu erkunden.
Die unterschiedlichen Abfragemöglichkeiten und die grafische Aufbereitung der Daten erlauben es, ein umfassendes Verständnis der Inhalte
zu entwickeln, Muster zu erkennen und datenbasierte Entscheidungen zu treffen
Open GIS-to-BIM-Converter - LKMap 2025 Data to IFC 4.3 Data
Underground utility networks in Switzerland are typically managed using normed formats such as the SIA 405-INTERLIS standard within 2D Geo-Information Systems (GIS). However, due to the increasing demand for 3D representation, particularly in the context of Building Information Modeling (BIM), there is a need to represent these networks in a 3D format. This research project focuses on the SIA405_LKMap model, which describes the minimum information required for cadastral registers and is currently being revised to support 3D Geo-Information. The research presents an evaluation of the recommended changes in the revision of SIA405_LKMap and a Python Command Line Interface (CLI) prototype that enables the conversion of SIA405_LKMap data into valid 3D data in the Industry Foundation Classes (IFC) format.
The resulting prototype has a CLI that requires users to input a INTERLIS LKMap transfer data file and a reference null point, while also providing other optional arguments. The provided arguments are validated, and the conversion process is performed using Python libraries such as Pyogrio and IfcOpenShell. The resulting 3D data includes element attributes as IfcPropertySets and the visualization of geometric uncertainties.
The prototype provides a strong basis for future development. The outlook includes additional improvements, such as optimizing geometric representations and adding configurability and extensibility features for users. Overall, this thesis demonstrates the feasibility of converting INTERLIS LKMap data to the IFC 4.3 format, opening up possibilities for improved representation and visualization of underground utility networks in the field of BIM.
Keywords: 2D to 3D conversion, INTERLIS, LKMap, IFC, Python CLI, GeoPackage, Building Information Modeling (BIM)
Network insights in OpenTelemetry
The complexity of modern applications demands comprehensive observability to pinpoint performance bottlenecks and optimize application performance. OpenTelemetry, a vendor-neutral observability framework, excels at capturing application-level insights, but the inclusion of network visibility is crucial. This thesis explores the integration of network telemetry data into OpenTelemetry, aiming to provide a holistic understanding of application performance and detect network-related issues.
The project successfully establishes the groundwork for incorporating network visibility into application monitoring using OpenTelemetry. The developed system is positioned for submission as an open-source project. Focusing on the network connecting a 3-tier application, the project ensures that the network path and associated latency are visible during the evaluation of application performance.
The achieved objectives include displaying individual network components, capturing ingress and egress timestamps, and seamlessly integrating network monitoring data into existing traces in OpenTelemetry. These enhancements empower the system to offer insights into latency, network component processing time, and their correlation with requests and existing traces.
Despite these accomplishments, the project falls short of fully identifying the reasons for latency. The selected data retrieval method, Netflow / IPFIX, lacks detailed information about the device's status, limiting the ability to precisely determine the causes of latency. Nevertheless, the project significantly advances observability in distributed applications, providing valuable troubleshooting and performance optimization insights.
Future enhancements could focus on capturing more detailed device status information to identify the root causes of latency better, thereby continuing the trajectory of improvement in observability within distributed applications
Post Quantum P2P Chat
Introduction
Our application, qChat, is a decentralized, peer-topeer chat application meant for future-proof privacy. It uses the latest encryption algorithms to ensure secret message exchange in the post-quantum era.
Quantum computing poses a significant threat to current encryption methods, particularly due to advancements like Shor's Algorithm. This algorithm, in theory, allows quantum computers to break widelyused encryption schemes such as RSA and ECC much faster than conventional computers.
Result
The solution involves developing a peer-to-peer chat application using post-quantum cryptography, eliminating reliance on external servers for data storage. The project has successfully created a prototype demonstrating peer-to-peer functionality with integrated post-quantum cryptography.
Conclusion
These developments are significant as they provide a practical approach to secure communication, setting a precedent in the field of quantum-resistant digital communication.
The insights and technologies developed in qChat lay the groundwork for future advancements in secure communications. This also marks a significant advancement in protecting the private sphere in an increasingly interconnected post-quantum world
Training a simulated drone with deep reinforcement learning
This report details the comprehensive planning, execution, and evaluation of a solodeveloped project in the field of artificial intelligence (AI) and software engineering.
The project, focused on implementing a drone capable of autonomous navigation and delivery, follows the Agile Scrum methodology for project management. The report covers various aspects, including risk management, iterative development processes, and the application of the Soft Actor-Critic (SAC) algorithm for AI training.
A key aspect of the report is the detailed description of the SAC algorithm, which outlines the mathematical principles of this algorithm in an understandable way.
The development lifecycle is outlined through a series of sprints, each encompassing planning, review, and retrospective meetings. The report underscores the importance of risk management, categorizing and addressing potential challenges throughout the project.
Detailed insights into the project’s structure, from backlogs to sprints, provide a transparent view of the iterative development process. The challenges faced, such as lack of experience with AI and Unreal Engine, are mitigated through proactive measures, including research and adaptation.
The long-term plan, presented in a Gantt chart, highlights key milestones, phases, and features. Primary and secondary features, along with epics and milestones, are meticulously defined, allowing for a clear understanding of project progress.
The report concludes with a thorough retrospective, highlighting successes, areas for improvement, and personal reflections. Key achievements include overcoming the hyperparameter problem and implementing the SAC algorithm to control the drone
TypeSearch: Type-Directed API Search For All
Software developers spend a lot of their time finding and composing pre-existing functions from various libraries. Almost all developers today use general-purpose search engines for this search. Specialized search engines such as Hoogle additionally use type information to improve this search, and have been successful for some typed functional programming languages. The options currently available for type-directed search for mainstream object-oriented languages is limited. Existing approaches for these languages do not have first-class support for subtyping or parametric polymorphism.
The splitting and composition of a desired functionality into and from a number of pre-existing functions is also a task that needs to be done manually. In this Master’s Thesis we present a proof-search-based approach to type-directed search with first-class support for subtyping, parametric polymorphism, splitting, and composition. The approach is language agnostic, and can be specialized to simultaneously support multiple typed object-oriented languages. Given that most mainstream languages fall under this category, this approach would extend the benefits of type-directed search to the majority of programmers. As a proof of concept, we provide a running implementation of the core language-agnostic approach and extend it to support the Java programming language. Further extensions would allow the tool to simultaneously support multiple programming languages using the same query syntax
3D-Visualization of Utility Lines in the Browser using Augmented Reality on Tablets
Locating underground utility lines, such as water pipes is a complex task because they are usually hidden underground.
The aim of this project is to extend and improve the existing solution from the preceding term thesis, which represents an innovative, cost-effective alternative to current solutions.
Other solutions are native applications and depend on expensive hardware.
This project is a web-based augmented reality (AR) application for visualizing underground utility lines on Android tablets.
It utilizes WebXR and WebGL to integrate Building Information Modeling (BIM) data, specifically Industry Foundation Classes (IFC), into a 3D environment.
This involves converting IFC data to a web-optimized 3D format (glTF), using Blender with the BlenderBIM add-on.
The web frameworks used for this application are Vue.js with TypeScript for the frontend and Flask for the backend.
Some other key technologies of this project are Three.js, Turf.js, IfcOpenShell, Keycloak and PostgreSQL with PostGIS.
The original application has its flaws with accurate positioning of utility line models and has limited functionality.
One source of the imprecise alignment of utility line models with the real world is the inaccuracy of the compass sensors used in mobile devices.
Therefore, various features to correct these inaccuracies are introduced with this bachelor thesis.
These features consist of manual position and rotation controls, as well as a guided compass correction.
Other features include colorizing utility lines based on their type, filtering utility lines by their type and automatic loading of utility lines based on the user's location.
Additionally, it's now possible to upload IFC files within the application.
After uploading, the IFC files are converted to glTF in the backend and saved in the database along with the extracted metadata.
In order to upload and view their IFC files, users must first authenticate themselves with either Google or GitHub.
A challenge in this project was the lack of available IFC files to properly test the application.
Nonetheless, the application was developed with the data available and heavy reliance on the IFC standard, which is publicly available