University of Applied Sciences Rapperswil

eprints OST (Ostschweider Fachhochschule)
Not a member yet
    1194 research outputs found

    Reverse Engineering Labs (Folgearbeit)

    Get PDF
    Background: This bachelor thesis is based on a previously created "Reverse Engineering Lab" term project by the team, which consists of beginner level hands-on exercises (challenges) for students at OST to get into software reverse engineering. However, some important aspects were not covered in the previous lab. This bachelor thesis is geared towards advanced reverse engineering in order to go deeper and into in-depth reverse engineering techniques. Purpose: This bachelor thesis extends the existing "Reverse Engineering Lab", adding 10 more complex practice labs and exercises by introducing new reversing methods, tools, and frameworks. The new and advanced exercises can then be used by the teachers at the OST to lecture on the subject of reverse engineering. This gives the students a better insight into the subject and a more enriched, practical, and hands-on experience. Methods: First, we created a collection of topics not yet covered in the previously created "Reverse Engineering Lab". These topics were then evaluated by the team and the advisor based on personal interest, usefulness, and importance in the field of reverse engineering. This evaluation was used to discuss which topics we should create challenges for. During the semester we used Scrum to iteratively create the challenges. Whenever a challenge was finished, it was tested by us, fellow students, and other volunteers. This process ensured the high quality of the challenges. Results: The goal of this bachelor thesis, the creation of 10 new reverse engineering challenges covering new methods, tools, and frameworks, was successfully achieved. All the challenges are hosted on Hacking-Lab, an online platform for cybersecurity training and ethical hacking. Hacking-Lab provides students with everything they need to improve their reverse engineering skills. Conclusions: The aim was to teach students techniques that would reveal potential attack vectors. The final product is a collection of many advanced reverse engineering topics, providing deeper insight and teaching problem-solving skills. Legal disclaimer: This course aims to understand hacking methods in order to effectively counter them. It is unethical and potentially illegal to use the knowledge gained for malicious purposes. This course promotes responsible use with an emphasis on digital security and protection

    Microservice Architektur in Spring Boot: Generierung & Verwaltung von Individualreisen

    No full text
    Die Vanlife Travel GmbH möchte als Start-up Campingreisen revolutionieren. Campingplatzbesitzer stellen Vanlife Travel einzelne Stellplätze zur Vermittlung zur Verfügung. Aus den Stellplätzen generiert ein Algorithmus Reiserouten für registrierte Camper und Reisende. Abschliessend individualisieren die Interessenten die Reiserouten nach persönlichen Vorlieben und buchen ihre Reise. Die Rechnungstellung für die Servicegebühr ist mit einem ERP-System zu verwalten. Die Applikation soll zu Testzwecken verschiedener Stakeholder in die Cloud migriert werden. Die Grundlage dieser Arbeit knüpft an die Studienarbeit "Buchungs-App für einen Reiseanbieter" an, deren bestehende Architektur und Software weiterentwickelt wurde. Diese Bachelorarbeit befasst sich mit der Umsetzung eines Backends, die den Businessanforderungen des Industriepartners entspricht. Die Durchführung der Bachelorarbeit erfolgt in enger Zusammenarbeit mit dem Frontend-Team, siehe Bachelorarbeit “Entwicklung einer Single Page Application in React TS für personalisierte Campingtouren”. Beide Teams arbeiten nach Scrum, um schnell und unkompliziert auf veränderte Anforderungen reagieren zu können. Die Entwickler analysierten, entwarfen und implementierten die neuen Anforderungen des Industriepartners in die Microservicearchitektur. Die Entwickler setzten den genannten Anforderungskatalog Generierung, Individualisierung, und Buchung von Reisen entsprechend um. Die Individualisierung ermöglicht es den Reisenden einen Campingplatz durch einen anderen auszutauschen oder den Aufenthalt auf einem Campingplatz zu verlängern. Das Erstellen von Rechnungen verwaltet das externe ERP-System Bexio. Die Entwicklung erfolgte mit den Technologien Spring-Boot, Java, gRPC, HTTP-API, PostgreSQL Docker und die Programmiersprache R. Der Prototyp erfüllte die Anforderungen des Industriepartners, manuelle Integrationstests verifizierten dessen Qualität. Der Prototyp hat noch nicht den Reifegrad, um produktiv in Betrieb zu gehen. Durch den Einsatz von Microservices ist das Backend flexibel. Zudem kann das Backend dank der Skalierbarkeit von Microservices langfristig an das Wachstum des Unternehmens angepasst werden

    Buchungs-App für einen Reiseanbieter

    No full text
    Einleitung: Das Bedürfnis nach Erlebnissen in der Natur ist für viele eine Möglichkeit die persönliche Freiheit zu entfalten. Viele Vanlifer würden gerne in ihren Camper einsteigen, unbeschwert drauflosfahren und spontan irgendwo Übernachten. Da Wildcampen vielfach verboten ist und sich die Suche nach einem Stellplatz oft schwierig gestaltet, tritt häufig bereits vor dem Reisestart der erste Frust auf. Die Vanlife Travel GmbH hat sich zum Ziel gesetzt, das Planen eines Campingausflugs einfacher zu machen. Dafür soll eine Webapplikation erstellt werden, welche Anbieter und Kunden zusammenbringt und den Kunden während der ganzen Reise begleitet. Aufgrund des Umfangs der Studienarbeit arbeiten zwei Teams daran, die Arbeit wurde in Frontend und Backend aufgeteilt. Diese Arbeit umfasst den gesamten Backend-Teil des Systems. Ergebnis: Das Backend sollte für viele Benutzeranfragen ausgelegt sein, da der Kunde plant, den gesamten europäischen Mark zu bedienen. Deshalb fiel der Architekturentscheid im Backend zugunsten einer Microservice-Architektur aus, mit dem Ziel die einzelnen Services möglichst unabhängig voneinander zu gestalten und nach Bedarf mehrere Instanzen starten zu können. Die Microservices werden dazu nach Geschäftsbereichen aufgeteilt und durch unterstützende Services ergänzt, dadurch kann die Entwicklung auch auf mehrere Entwicklerteams aufgeteilt werden, welche nur geringe Abhängigkeiten voneinander haben. Für das Frontend soll dabei nicht ersichtlich sein, welche Microservices im Backend aufgerufen werden. Weiter soll durch die Architektur keine merkbare Verzögerung zwischen Request und Response auftreten. Um diesen Anforderungen gerecht zu werden, wurde auf das gRPC Framework gesetzt, da dessen Nachrichten schlank sind und effizient übertragen werden. gRPC hat zudem den Vorteil, dass es technologisch Unabhängig ist. Alle Microservices wurden in Java unter Verwendung des Spring Boot Frameworks implementiert. Für die Automatisierung des Build-Prozesses wird Gradle mit Kotlin DSL eingesetzt. Als Datenbank wurde PostgreSQL und für die Persistenz JPA verwendet. Die Datenbanken werden dabei mithilfe von Docker Compose automatisiert erstellt und beim Start der Applikation wird automatisch eine Datenbankmigration mit Flyway durchgeführt, das garantiert die Kompatibilität zwischen Applikationen und Datenbank. Für das Login wurde auf OAuth 2.0 gesetzt, um dem User grösstmögliche Sicherheit und einen einfachen Login-Prozess zu bieten. Als Standard für die Beschreibung des HTTP API wird OpenAPI verwendet. Fazit: Aufgrund der umfangreichen Anforderungen wurden die wesentlichen Anforderungen identifiziert und implementiert, wodurch die technische Machbarkeit nachgewiesen werden konnte. Dank der Microservice-Architektur ist das System gut skalierbar und die Modularisierung ermöglicht es neue Anforderungen mit geringem Aufwand zu implementieren

    Graph properties of a telecommunication network

    Get PDF
    Objective: Every telecommunication network has a different topology. Additionally, the topology is often complex and unstructured. In the current telecommunications industry, graph properties are not broadly used for network capacity planning or network comparisons. The goal of this thesis is to create a system that conveys the structure of a graph in an understandable way. This is achieved through the visualization of a multitude of graph properties. Included explanations provide context and link to additional sources. Furthermore, it should be possible to obtain network topology data from the Jalapeño API Gateway, which is an ongoing project by the INS. Approach: The system is composed of three separate applications that interact with each other. The Data Collector is responsible for reading network topology data, be it from the Jalapeño API Gateway via gRPC or from an alternative source. The read data is persisted in a graph database. Calculations of the graph properties are triggered by requests to the API. These calculations are performed based on the graph that is kept in the graph database, the results are exposed via a REST API. The Frontend consumes data from the API and displays the various graph properties. In order to provide context, explanations are provided for each property. Conclusion: A system composed of multiple applications was created that allows network administrators to analyze a provided network based on graph properties. Additional features like querying for cut edges and vertices have also been implemented. The system is developed in a cloud-native way in order to achieve a high scalability and availability. It currently supports the import of network topology data from the Jalapeño API Gateway and files in the GEXF format. The system is designed in an extensible way so that other data sources can be added in the future. It also acts as a platform for future works in the area of network topology analysis

    Matching (engineering) problems to competence profiles

    No full text
    The company PATRIZ AG is establishing a new platform for crowd-engineering. A base frame with a project and user management system has been setup by a preceding bachelor thesis. The goal of this term paper is to extend the platforms functionality with a competence ecosystem, a feedback option and a matching logic. The competence system applies to users and projects, meaning both can possess competences. Concerning feedback, users should be able to voice their opinions to PATRIZ AG so the platform can improve. The matching logic is the connecting link between projects and users, which generates matches based on their competences. First, functional requirements are elaborated and specified. For the implementation of the competence system a data model has to be created to support a tree data structure and CRUDoperations. The tree will be used to store connections between competences and their respective categories. To manage the competence system an admin interface will be implemented to enable CRUDoperations and to manage the tree. Furthermore, a project and user front-end for the competences will be implemented. For the feedback system, the data model has to be extended to support CRUDoperations for the feedback entity. User can submit feedback via the front-end and admins can view all feedbacks via an admin page. The matching logic uses selected competences for a project and maps those onto user competences to show potential partners. The users now can add competences to their profiles. Customers now can assign needed competences to their projects. This process is directly integrated in the existing process of the project creation via the project creation wizard. This enables a matching which now allows to see potential partners for a project based on the competences. Furthermore, an easy handling of those competences and categories is possible with the introduction of an admin and the corresponding interface. The whole feedback process has been realized as well, allowing a fast and organic exchange between the users and PATRIZ AG

    Entwicklung einer Animationsbibliothek für SimPy (Folgearbeit)

    Get PDF
    Ausgangslage Simulationen werden verwendet, um reale Situationen unter reproduzierbaren sowie steuerbar variierenden Bedingungen nachzubilden, und damit Verhaltensweisen und Systeme zu untersuchen und vorherzusagen. SimPy ist ein schlankes Python Framework für diskrete Ereignissimulation und wird zum Beschreiben von Simulationen verwendet. JupyterLab bietet die Möglichkeit, sogenannte Notebooks zu erstellen. Notebooks stellen eine webbasierte interaktive Programmierumgebung zur Verfügung, in welcher unter anderem SimPy Simulationen geschrieben und verwendet werden können. Zur Verifikation der Ergebnisse einer solchen Simulation ist es wünschenswert, eine zur Simulation passende Animation zur Hand zu haben. Momentan bietet SimPy noch keine integrierte Möglichkeit eine Simulation zu visualisieren und zu animieren. Ziel Aufbauend auf eine vorhergehende Studienarbeit soll eine Bibliothek für die Animation von Simulationsmodellen entwickelt werden. Die in der Studienarbeit gewonnenen Erkenntnisse sowie die darin erarbeiteten Konzepte sollen, wo möglich, infrage gestellt, angepasst, erweitert und übernommen werden. Die Bibliothek soll, integriert in eine JupyterLab Extension, als Open-Source Projekt veröffentlicht werden, inklusive der Distribution über die gängigen Paketverwaltungssysteme. Weiter sollen als Beispiele für die Verwendung der Bibliothek die Beispiele SimPy’s um eine Animation erweitert werden. Ergebnisse Die drei Komponenten simplay, simplay-web und simplay-jupyter sind veröffentlicht und über die gängigen Paketverwaltungssysteme installierbar. Die Komponente simplay-jupyter ermöglicht es, unter Verwendung von simplay und simplay-web, SimPy Animation zu visualisieren und in JuptyerLab anzuzeigen. Es existiert ein Open-Source Projekt, gehostet auf GitHub, welches öffentlich dokumentiert ist. Die Beispiele aus SimPy wurden um eine Animation erweitert und können als Anwendungsbeispiel dienen. User-Tests haben gezeigt, dass die Komponenten einfach zu installieren und zu verwenden sind. Die API des Python Packages simplay ist verständlich für Entwicklerinnen und Entwickler welche mit SimPy vertraut sind

    City Trip Planner: Kurztrip-Planer für Fussgänger (Folgearbeit)

    Get PDF
    Die vorliegende Arbeit befasst sich mit der Thematik der Wegfindung für Fussgänger:innen in der Schweiz. Es wurde eine Applikation entworfen, welche Rundgänge und Einwegtrips unter Einbezug von kategorisierten Interessen in Schweizer Städten erstellen kann. Bei der Berechnung werden persönliche Präferenzen wie Distanz oder Dauer berücksichtigt, sodass ein individuelles Erlebnis geschaffen werden kann. In Zusammenarbeit mit Schweiz Tourismus wurden touristische Zwecke bei der Entwicklung berücksichtigt, damit auch Tourist:innen aus dem In- und Ausland die Anwendung nutzen können. Als Ausgangslage dient die gleichnamige Studienarbeit. Die darin erworbenen Erkenntnisse sollen in dieser Bachelorarbeit vertieft und genutzt werden, um daraus eine weitere Iteration eines Minimal Viable Product zu schaffen. Dabei steht der Ausbau der Funktionalität und die Verbesserung der Benutzerfreundlichkeit im Vordergrund. Die Applikation City Trip Planner ermöglicht es, den Benutzer:innen individuelle Routen mit kategorisierten Interessen im städtisch-urbanen Raum zu planen. Sie kann sowohl am Computer wie auch am Smartphone genutzt werden. Es handelt sich um eine Webapplikation, welche ohne Installation zusätzlicher Software im Browser läuft. Um Tourist:innen einen zusätzlichen Mehrwert zu bieten und die Erkundung spannender zu gestalten, werden Hintergrundinformationen zu einzelnen Stationen auf der Route gesammelt und dargestellt. Die Arbeit vereint agile Projektplanung, moderne Entwicklungsansätze, bekannte Entwurfsmuster und aktuelle Technologien. Folgende Technologien sind elementar wichtig für die Umsetzung des Projekts: Python, FastAPI, TypeScript, Angular, PostgreSQL, Keycloak, OpenStreetMap, OSRM, GraphHopper und openrouteservice

    Different Approaches to control GPIO Pins of the Raspberry Pi using Haskell

    Get PDF
    The functional programming language Haskell allows the writing of elegant code and reduces the likelihood of runtime errors. This advantage can also be used when programming the General Purpose Input/Output (GPIO) pins on the Raspberry Pi. This paper presents three approaches in Haskell for controlling GPIO pins. The first method uses the GPIO sysfs interface, the second sends commands via sockets to the Python library gpiozero, and the third uses the Foreign Function Interface (FFI) to call functions from the C library bcm2835. The approaches described have different strengths and weaknesses, and it depends on the use case which approach is most suitable

    Open Source Intelligence Training in Hacking-Lab (BA)

    Get PDF
    In cyber security the topic of Open-source intelligence (OSINT) plays a major role. With OSINT security defender and researcher may find valuable information about cyber crime and attackers. OSINT helps to understand the effects of sharing public information. OSINT is not yet part of the curriculum at OST. An e-learning platform called Hacking-Lab already exists and is used at OST. In Hacking-Lab, students can apply what they have learned in the lecture in a controlled environment in the form of practical hands-on exercises. The goal of this thesis was to create ten OSINT challenges in the Hacking-Lab for students to solve and practice. In every OSINT challenge, students are given a set of tasks and summative assessment questions. The students are guided through the proposed steps in order to answer the posed questions in form of a write-up. Each OSINT challenge is framed by a story to make them more engaging. These stories were chosen in a way that many different OSINT techniques are applicable and can be practiced by the students. In OSINT there is not only one way to find the correct answer hence the students are also encouraged to find their own way to reach the expected solution. To guarantee a high quality of the challenges, multiple quality assurance tests were conducted with students and colleagues working in IT. The results of these quality tests are an indicator whether the goal was reached. As a result of this work, the goal of creating ten OSINT challenges in Hacking-Lab was achieved. These challenges provide some insight into the topic of OSINT without getting lost in details and technicalities. This project provides a foundation which a lecturer can build upon by creating a lecture on OSINT. This lecture could be integrated in a course on cyber security. Social media was purposely neglected in this project because social media is difficult to maintain and make future-proof, which makes it incompatible with the project's requirements. Therefore, it could also be a future project to expand upon these challenges with a focus on social media as it is an indispensable part of OSINT

    Type Systems for the OO Programmer

    Get PDF
    Many software developers learn imperative and/or objectoriented programming first in their career. Meanwhile, most of the research done on programming languages is based on the Lambda-Calculus and functional programming languages. These are often not intuitive to grasp for someone who has worked exclusively with object-oriented languages. Some might even be intimidated by the mathematical terminology. This paper aims to show that most of these methods are in common use in Java, but sometimes better known under different names

    1,015

    full texts

    1,194

    metadata records
    Updated in last 30 days.
    eprints OST (Ostschweider Fachhochschule)
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇