1194 research outputs found
Sort by
Konzeption und Prototyp eines konfigurierbaren Storefrontsystems mit Plugin- und Theme-Architektur
Die Abacus Research AG hat im Rahmen ihrer ERP-Lösung 'Abacus' die E-Commerce-Applikation 'AbaShop' entwickelt, deren Wartung Ende 2025 eingestellt wird. Aus diesem Grund muss die Customize AG, ein Vertriebspartner von Abacus, eine Nachfolgelösung für ihre Shop-Kunden finden. In einer vorangegangenen Studienarbeit wurde das E-Commerce-System 'nopCommerce' evaluiert und über das entwickelte Plugin 'Abacus Connector' an das ERP angebunden. Um die individuellen Anforderungen der breiten Kundschaft mit einem System bedienen zu können, soll ein Storefrontsystem entwickelt werden, das die Services von nopCommerce nutzt und den Consultants von Customize vielfältige Möglichkeiten zur Konfiguration des Webshop-Frontends bietet.
In dieser Bachelorarbeit wurden gemeinsam mit den Consultants die Anforderungen an die Konfigurationsmöglichkeiten des Storefrontsystems anhand von Kunden-Use-Cases erfasst. Die Implementierung eines Prototyps zeigt, wie individuelle Anforderungen durch die erhobenen Use-Cases abgedeckt werden können. Durch einen Benutzertest wurde sichergestellt, dass die Consultants die Kundenanforderungen über die Konfigurationsmöglichkeiten erfüllen können. Die Entwicklung eines Migrationspfades zeigt auf, wie Kunden von 'AbaShop' auf das neue Storefrontsystem migrieren können.
Die Implementierung einer RESTful HTTP-Schnittstelle als Plugin für nopCommerce ermöglicht einen 'headless' Zugriff auf dessen Services. Der entwickelte Storefront Prototyp bietet ein Kernsystem mit Standard-Webshop-Funktionalitäten für alle Kunden. Die Integration einer Plugin- und Theme-Architektur ermöglicht umfangreiche kundenspezifische Anpassungen des Kernsystems. Themes können das visuelle Erscheinungsbild des Storefronts komplett verändern, während Plugins eigene Seiten und Logik hinzufügen. Die Entwicklung von zwei Themes und mehreren Beispiel-Plugins zeigt, wie Consultants das Storefrontsystem individualisieren können. Darüber hinaus ermöglicht ein Admin-Bereich umfassende Konfigurationen, um einfache Kundenanforderungen schnell umzusetzen, ohne ein Theme oder Plugin entwickeln zu müssen
Enhancing Cybersecurity with Machine Learning: Beaconing Detection in PCAP Data
Enhancing Cybersecurity with Machine Learning: Beaconing Detection in PCAP Data
Abstract
This study explores the enhancement of cybersecurity through the application of machine learning techniques, specifically focusing on the detection of beaconing activity in network traffic (PCAP) data. PCAP, or packet capture, refers to the process of intercepting and logging traffic that passes over a computer network.
Beaconing, a communication technique and a common indicator of malicious activity requires complex multilevel detection methods due to its discreet and repetitive nature. My approach involves the development of a dual-model framework with a combination of a Histogram Gradient Booster Classifier (HGBC) and a Long Short-Term Memory (LSTM) neural network. The HGBC classifies the initial features extracted from the PCAP data, while the LSTM model further refines the detection by capturing temporal dependencies between consecutive packet flows.
The combined model achieves an accuracy rate of 99.37%, demonstrating its effectiveness in identifying beaconing patterns. This high level of accuracy illustrates the potential of a combination of machine learning and deep learning algorithms in advancing cybersecurity measures for unmasking threats in network traffic analysis
React Security Labs
Introduction
In the field of web development, ensuring security is crucial.
This project, React Security Labs, under the School of Computer Science at OST Eastern Switzerland University of Applied Sciences and Compass Security, focuses on enhancing web security education.
The aim is to create practical, hands-on labs on the Hacking Lab platform that simulate common security vulnerabilities within a React application. Those vulnerabilities will be implemented into a Swiss-themed webshop.
Approach
The project began with research, particularly focusing on the most common web vulnerabilities in React and the selection of relevant vulnerabilities. Afterwards, the requirements were defined, and the React frontend of the webshop was developed. The Flask backend could be reused from a different webshop. The security vulnerabilities were integrated, based on the research on the most common React-specific vulnerabilities. Step-by-step solutions were developed to demonstrate how exploits could occur if prevention mechanisms are not used. Docker was used for containerization and delivered as a zip file to Compass Security AG, which maintains labs on the Hacking Lab platform. This setup allows for starting and stopping the vulnerable webshop within the labs.
Result
The project successfully developed a functional React-based cheese-themed webshop incorporating various React security labs. These labs cover a range of common vulnerabilities, including three different Cross-Site Scripting (XSS) scenarios and Cross-Site Request Forgery (CSRF). The CSRF lab demonstrates a CSRF attack scenario if no protection mechanisms are used. Since React does not have built-in CSRF protection (unlike e.g. Angular), a solution was provided on how CSRF protection can be implemented using React and Flask. Additionally, a vulnerable setup lab was included to demonstrate the risks associated with not regularly updating application dependencies. Also, a comparison was made between security mechanisms in React, Angular, and Vue.
The React Security Labs project achieved its goal of creating challenges that allow users to see and exploit the most common React-specific web vulnerabilities. Additionally, research showed that most websites use reasonably up-to-date versions of React, similar to Angular and Vue websites. While React offers protection against XSS, it does not provide built-in protection against CSRF. Therefore, it is vital to adhere to security best practices to achieve the most secure React application
FlatFeeStack: Fraud Resistant Multiplier Feature
Open-source software development relies heavily on community support and financial contributions.
This Term Project presents a novel extension to the existing sponsorship platform FlatFeeStack. This
project introduces two critical innovations: a Multiplier Option and a comprehensive Fraud Prevention
Mechanism.
The Multiplier Option enables foundations to conditionally sponsor open-source repositories, wherein
donations are triggered only after an initial user sponsorship. This approach establishes a collabo-
rative funding model designed to encourage broader community participation. At the same time, it
preserves the core values of FlatFeeStack: making the donation process as equitable, fair, and trans-
parent as possible.
The Fraud Prevention Mechanism incorporates a sophisticated health scoring system that evalu-
ates Git metrics and various internal sponsoring activities. Together, these six metrics form the Health
Value. The scoring model enables administrators to review and evaluate repository assessments, al-
lowing them to decide whether to certify the repository based on the provided evaluation. Moreover,
only repositories within sponsoring bundles that include at least one verified repository are eligible to
receive multiplier funding.
By integrating these features, the extension addresses key challenges in open-source funding,
namely incentivize sponsorship and mitigating potential fraudulent activities. The implementation
demonstrates a flexible, security-conscious approach to supporting open-source ecosystem sustain-
ability
Swiss Emergency Map: Eine Feuerwehrkarten-Webapplikation
Ziel dieser Arbeit ist die Entwicklung einer Webapplikation mit Übersichtskarte und Lageplanverwaltung
für die Feuerwehr. Als Basis dient die Notfallkarte der Feuerwehr Gossau ZH, die Verbesserungspoten-
tial aufweist. Zurzeit werden vertrauliche Dokumente beispielsweise über einen Dropbox-Link verwaltet,
was den direkten Zugriff darauf erschwert. Zudem bietet die App keine Möglichkeit, Lagepläne einfach
und sicher abzulegen und auf der Karte zu visualisieren. Nun soll eine App entwickelt werden, die Points-
of-Interest (POI) und die genannten Dokumente auf einer interaktiven Karte visualisiert. Dadurch sollen
Feuerwehrleute schnell auf die benötigten Informationen zugreifen können.
Nach der Einarbeitung in die bestehende Webapplikation wurden die wichtigsten Software-Technologien
evaluiert. Für das Frontend wurden React mit TypeScript, für das Backend Django und Python gewählt. Die
Software ermöglicht das Hochladen von Lageplänen und deren Verknüpfung mit POIs. Zusätzlich zu den
Lageplänen können Nutzer weitere Dokumente verwalten, die ausschliesslich lokal gespeichert werden.
Ausserdem ist die App mandantenfähig, so dass sie von mehreren unabhängigen Benutzergruppen (d.h.
Feuerwehren) gleichzeitig genutzt werden kann. Im Mittelpunkt steht eine Hintergrundkarte (Satelliten-
bild oder Standard-Karte), die auf Basis von OpenStreetMap-Daten POI anzeigt, wie Hydranten, Schlüs-
selrohre, Defibrillatoren, Notfalltreffpunkte, Solaranlagen, Brandmeldezentralen und Feuerwachen. Die
OSM-Daten werden in einer eigenen Datenbank gecached, um Ausfällen und Vandalismus vorzubeugen.
Das Ergebnis der Arbeit ist eine dockerisierte Webapplikation namens Swiss Emergency Map (Open Sour-
ce) mit einer intuitiv bedienbaren grafischen Benutzeroberfläche, die auch unter schwierigen Einsatzbe-
dingungen einen schnellen Zugriff auf alle wesentlichen Funktionen gewährleistet. Die konfigurierbare
App kann sowohl von der Feuerwehr Gossau ZH als auch von anderen Feuerwehren genutzt werden.
Damit wird die Einsatzvorbereitung und -durchführung der Feuerwehren verbessert und es werden Zeit
und Ressourcen optimal genutzt
Network Configuration Automation with Infrahub and Nornir
Abstract:
This document outlines the design and implementation of an automated system for VLAN management as part of the project “Network Configuration Automation with Infrahub and Nornir”. The solution leverages Infrahub as a single source of truth, providing a unified platform for managing network infrastructure data. Nornir, a Python-based automation framework, handles configuration deployment with dry-run validation to detect potential misconfigurations:
- Infrahub serves as the central repository for network infrastructure data, providing version control and collaboration through GitLab.
- Python Transformers: convert Infrahub data into a Pydantic model representing YANG models.
- NETCONF XML Exporter generates valid NETCONF payloads.
- Nornir automates the deployment of NETCONF configurations, offering flexibility and scalability.
- Conditional Runner enforces concurrency limits and controlled task execution, enhancing automation stability.
Key Features:
- Dry-Run Validation: Identifies misconfigurations preemptively.
- Reconciliation Mechanism: Detects configuration drifts for remediation.
- Centralized Management: Streamlines oversight of network configurations.
Benefits:
Automating VLAN configuration reduces human intervention, minimizes errors, and enhances network reliability. Validation and centralized management improve efficiency, reliability, and scalability.
Conclusion:
The “Network Configuration Automation with Infrahub and Nornir” project automates VLAN management by enforcing validation and centralizing oversight, modernizing network management for greater efficiency and scalability
Photochef
Introduction: The Smarteating application is a web application that allows users to manage recipes in a smart way. Among its other features, the application is capable of converting photos of recipes to text and suggesting meal plans depending on the user's nutritional needs. The application, however, lacks essential user-centric features and an intuitive user experience.
The objective of the project is to survey and implement additional features that improve the usability of the Smart Eating application. These features include editing, saving, and sharing recipes, user authentication and user management as well as a new dashboard. Furthermore, the user interface (UI) should be improved to make the application more user-friendly and appealing.
Approach: To approach said features, widespread software practices are applied. Requirements engineering is conducted via user research. The problem domain is analyzed to
determine which parts of the application need modification and extension. After understanding how the application works and analysing the UI, mockups are created. Furthermore, additional features are discussed and planned for during the elaboration phase.
The smart eating web application offers a sophisticated and intricate structure. While documentation is limited, it presents an excellent opportunity for collaboration, encouraging productive discussions and meetings with advisors to ensure smooth and informed implementation.
Result: The possibility to log in/register through GitLab is added to the existing login window. The dashboard is also added along with mock data. User-Roles are added to the data structure and admin-users are now able to manage other users of the application in the newly added admin panel. Furthermore, it is now possible to edit the recipe
information that is extracted during the analysis of a recipe. The general UI appearance is redesigned through many changes including the shape of components, the colours, the general layout, etc. Finally, these changes are all verified by an intricate usability test to ensure that the changes truly improve the user experience and overall appearance
Exploring the use of Haskell to Program Microcontrollers used in Educational Robotics Platforms
Nowadays children are introduced to electronics and programming by developing applications for “educational robotic kits”.
These kits allow children to write simple applications for a robot that interacts with its environment. Because Python or a block based system like Scratch are beginner friendly, they are often supported by these kits. Sometimes event C/C++ SDKs are available for more advanced users. None of the common kits support a functional programming language and therefore the children do not have a chance to try a different approach to programming. Previous research has proved that it is possible to write a Haskell application on bare metal by implementing an operating system. With MicroHs, a newer Haskell compiler is developed, that is based on combinators.
The author of MicroHs has already demonstrated that it is possible to write simple MiroHs applications that run on micro controllers.
A different approach is used in the project Categorifier. It utilizes the "Compiling to categories" to transform Haskell code into C code. In this project, MicroHs is used to develop a line following algorithm that runs on a Raspberry Pi Pico.
The Raspberry Pi Pico controls a PicoGo robot to demonstrate, how a functional programming language can be used for an educational robotic kit. While it is possible to develop Haskell applications for devices with little memory, it is rather difficult as the Haskell runtime must be adjusted and a lot of C code is still required to get it on to the device
Integration of Deep Computer Vision Foundation Models for Document Interpretation and Anonymisation
Visual Document Understanding (VDU) models, combined with Optical Character Recognition (OCR) or OCR-free, offer businesses and institutions a great opportunity to digitalise their processes and improve workflows. The digitalisation is progressing. However, challenges like sufficient knowhow to integrate VDU models, compliance with data protection regulations and identifying the processes, where VDU models offer the most significant benefit, have to be resolved.
The main goal of the work is to analyse and evaluate the practicality and appropriateness of available VDU models for processing of documents (e.g. PDF of scanned documents) and to demonstrate these in a Proof-of-Concept (POC) application. Even though some regulatory aspects, especially regarding anonymisation, are discussed in the work, the developed application does not aspire to be regulatory compliant.
During this work, two areas have been identified, where a tool to extract text from an image, identify relevant entities of personal information and anonymise these, is beneficial. First, the anonymisation of medical documents makes more data available for research and educational purposes. A second application is data leakage prevention, where detecting client data from screenshots would lower the risk of data breaches.
Various tools exist to extract text from an image. In the scope of this project, three tools have been integrated i.e., Tesseract, Amazon Textract and OpenAI GPT-4V(ison). The application extracts the text of uploaded documents or images and provides the user with the resulting text from all three tools. The user will be able to select the text with the best quality. Afterwards, a Named Entity Recognition (NER) Transformer model (i.e., bert-base-NER model) is used to identify the names of persons in the extracted text. The last step is the pseudonymisation of the entities. A randomly generated unique string replaces the entities in the text, so that a person cannot be identified based on the name in the text.
Another feature of the application is the evaluation of the OCR accuracy. The user is able to upload an additional ground truth file, which will then be compared with the output of the uploaded images. To calculate the OCR accuracy the Jaro Similarity string comparison algorithm is used. Furthermore, the NER model can also be tested by uploading the expected entities of the document in a separate file. The test will then show how many of the provided entities have been found in the extracted text.
It is impressive how powerful today's text extraction and NER models have become. However, during the work, it was recognised that they are not yet off-the-shelf and just ready to use. Neither works each tool perfectly, so errors are propagated to subsequent processes nor are the outputs of each tool standardised. To overcome such limitations, the process of text extraction and entity recognition should be executed by one model, which is also fine-tuned on the specific document types
Proof of Concept: Integrierte Webshoplösung fur Abacus
Der Softwarehersteller Abacus Research AG hat als Teil ihrer Enterprise-Resource-Planning ERP Lösung 'Abacus' bis anhin eine E-Commerce-Applikation namens 'AbaShop' entwickelt.
Da die Wartung dieser Shop-Lösung per Ende des Jahres 2025 eingestellt wird, steht die Customize AG, ein Vertriebspartner von Abacus und Industriepartner dieser Arbeit, vor der Aufgabe eine Nachfolgelösung für ihre bestehenden und zukünftigen Shop-Kunden zu finden. Um dies zu ermöglichen, stellt die Abacus eine neue RESTful HTTP-Schnittstelle zur Verfügung, über welche Kunden in Zukunft ihre eigenen Shop-Lösungen an das ERP anbinden können.
In dieser Studienarbeit wurden die Anforderungen der Kunden der Customize AG an die Shop-Lösung in Form von Use Cases festgehalten. Diese beinhalten sowohl bestehende als auch neue, häufig nachgefragte Funktionen. Basierend auf diesen Use Cases erfolgte eine Analyse der neuen Abacus-Schnittstelle um die Machbarkeit eines integrierten Webshops zu beurteilen. Durch eine Nutzwertanalyse wurden verschiedene E-Commerce-Frameworks evaluiert, um zu entscheiden, ob die Customize AG auf eine Eigenentwicklung setzt oder ein bestehendes Shop-System in Abacus integrieren soll. Um die Machbarkeit des erarbeiteten Konzepts aufzuzeigen, wurde ein Proof of Concept (PoC) implementiert.
Der in dieser Arbeit entwickelte Proof of Concept basiert auf einem Plugin für das Shop-System 'nopCommerce'. Anhand einer Auswahl von Use Cases konnte aufgezeigt werden, dass die neue Abacus-Schnittstelle die Anforderungen der Kunden erfüllt. Notwendige API-Erweiterungen wurden identifiziert und dokumentiert. Mittels einem Synchronisationsdienst werden die Produkt-Stammdaten aus dem Abacus mit dem Shop-System abgeglichen. Im Warenkorb werden kundenspezifische Preise und Rabatte ausgegeben und die getätigten Bestellungen werden automatisch als Aufträge in Abacus erfasst. Ebenfalls wird aufgezeigt, wie die restlichen Anforderungen auf Basis des entwickelten Prototyps umgesetzt werden können