National College of Ireland

TRAP
Not a member yet
    8333 research outputs found

    A Smart Cloud – Based Document Search Engine for Query Retrieval Using Large Learning Models (LLM's)

    No full text
    A set of documents grows rather fast; at the moment, there are more than 140 million documents, and this number increases every year, so, retrieving documents should be effective. Today’s issues are connected with the utilization of special language, relationships between documents, and imprecise queries uttered by users. Sophisticated NLP approaches such as semantic search and embeddings are central to fixing most these problems. This paper focuses on the possibility of populating text-to-text transformers such as Google T5 and BART Large models refinished for summarizing and retrieving purposes. Through fine-tuning, the authors observed improved performance in BART Large model with ROUGE-1 scores increasing from 0.269 to 0.461 and improved unigram overlap and context relevance. Moreover, the application of models such as Sentence Encoder and FastText demonstrated a near perfect of 98% and 96% of retrieval accuracy, respectively, which was more efficient than the traditional TF-IDF and Count Vectorizer models. Thus utilizing cloud-native architectures along with databases such as MySQL or FAISS, the system enables accurate and efficient document search on a large-scale. This research offers an ideal foundation for most contemporary semantic search architectures that answer user expectations of accuracy and value

    Comparative Analysis of Splunk vs. AWS Native Monitoring Tools for Cloud Security and Threat Detection

    No full text
    Cloud security monitoring remains critical and challenging for organizations as cyber threats have continued to evolve. While previous research by the author Ananthapadmanabhan and Achuthan (2022) explored threat detection using Splunk in cloud environments, there has been limited comparative analysis between the third-party security information and the event management (SIEM) solutions and native cloud monitoring tools. This research will address this gap by thoroughly comparing Splunk and AWS native monitoring tools, focusing on their effectiveness in threat detection and analysis. The experimental evaluation assessed both platforms across three key security scenarios: unauthorized login attempts, data exfiltration, and malware detection. The results demonstrate that while AWS native tools generally provided faster detection times, Splunk consistently achieved higher precision and recall rates. And For unauthorized login attempts, Splunk achieved 97% precision and 98% recall compared to AWS’s 94% precision and 95% recall, although AWS detected events marginally faster (6 seconds vs. 8 seconds). Similarly, in data exfiltration scenarios, Splunk showed superior accuracy with 95% precision and recall, outperforming AWS’s 89% precision and 90% recall, despite AWS’s quicker detection time (10 seconds vs. 13 seconds). We will see how these findings will provide valuable insights for organizations’ decisions about cloud security monitoring strategies. It also suggests how AWS native tools offer speed advantages, whereas Splunk delivers more comprehensive and accurate threat detection capabilities, helping organizations optimize their cloud security posture against emerging threats

    Designing and Implementing a Comprehensive Cloud Security Monitoring Tool with CloudWatch Logs and CloudWatch Console

    No full text
    The reliability, performance, and safety of cloud-based systems can be ensured through cloud security monitoring. This research discusses the design and implementation of a comprehensive cloud security monitoring tool based on AWS-native services, particularly CloudWatch Logs and CloudWatch Console. Motivation for this work came from the need for real-time monitoring solutions that are designed to seamlessly integrate with cloud environments in order to offer efficient log collection, performance tracking, and troubleshooting capabilities. The project included provisioning an Amazon EC2 instance, configuring it with the CloudWatch Agent to collect both system logs and metrics. A CloudWatch log group monitorloggroupec22024 had the logs streamed from critical system activities such as initialization and resource usage. CloudWatch Metrics monitors CPU, memory, and disk utilization in real time. These logs and metrics would primarily be visualized from a central place, the CloudWatch Console, instead of using some third-party tools like Elasticsearch or Kibana. During implementing the solution, there have been a few permission errors caused by IAM roles and configuration validation errors. Those issues were iteratively debugged and solved with the policy change. The final system would create a seamless pipeline of log collection, processing, and visualization, thus proving that the AWS-native tools could be used effectively in security monitoring. This research emphasizes the ease, cost-effectiveness, and scalability of using CloudWatch for comprehensive monitoring solutions in cloud environments. It concludes by suggesting potential future enhancements, including automated alerting and advanced integrations with third-party tools for further analysis. This work focuses much on the practicality of monitoring for modern IT infrastructure

    Detection of Security Vulnerabilities in IoT Devices using Advanced Deep Learning methods within Cloud Computing Framework

    No full text
    The rapid proliferation of IoT devices, along with cloud computing capabilities, has made disruptive changes to modern industry by enabling seamless connectivity, scalabilities, and data processing. While this incorporation gave rise to many advancements, it, however, raised some of the most critical vulnerabilities from a security perspective, as IoT systems are becoming vulnerable to synthetic malware attacks. Traditional security mechanisms, usually static and rule-based, always have limitations in identifying and mitigating these complex threats, especially in real-time scenarios of dynamic IoT-cloud environments. This research proposed a deep learning solution to tackle problems with regard to malware detection in IoT systems hosted in the cloud environment. Upon implementing and evaluating three deep learning models based on accuracy, precision, recall, and F1-score among CNN, RNN, and auto encoders, we have identified CNN as the top model, consistently outperforming as compared to the other models across all metrics. This trained CNN model was deployed in a cloud-based web application running on an AWS EC2 instance for real-time monitoring and classification of network traffic. It comes with a user-friendly interface to allow the classification of traffic into benign or malicious in order to address the threats on time to the system administrators. The proposed framework successfully provides detection and handling of bulk IoT traffic and addresses important security challenges by leveraging the strength and availability of the cloud

    Optimizing Particle Swarm Optimization Algorithm on Serverless Computing for Cost-Efficiency and Performance

    No full text
    Serverless computing has enables the rise of the application deployment with cost efficiency and scalability and no overhead in managing infrastructure. But current challenges lies in optimization of resource utilization especially among dynamic workloads. To solve the problems and enhance serverless performance, optimizing it with Particle Swarm Optimization. A novel approach to dynamic optimal resources threshold optimization in introduced through the combinations of PSO to overcome any limitations to traditional optimization techniques. This research deals with train the model, increased resource statistics and strategies of pre-warming. By comparing it with Grid search (Without PSO), PSO is shown to be adaptable to real time optimization tasks. This work represents a valuable insights on the deployment of advanced optimization techniques in serverless architectures. These findings fills the gaps and presents a scalable, cost effective framework for applications across industries like finance, healthcare, e-commerce and logistics

    Honeypots and the Use of AI in keeping the IoT Systems Secure

    No full text
    Honeypots play a crucial role in a comprehensive cybersecurity strategy by offering early detection, useful intelligence, and improved reaction capabilities. They also increase the overall security posture of a business. This study centers on implementing a sophisticated security solution for IoT using honeypots. The honeypots are monitored using the most efficient machine learning model to identify illegal access and deploy honeypots in a dynamic manner. The system utilizes models such as LightGBM, which have shown to be highly accurate and efficient, to accurately detect threats while decreasing the occurrence of false positives. This strategy enhances memory efficiency by selectively activating honeypots just in high-confidence threat scenarios, hence minimizing superfluous resource utilization. Machine learning integration improves the ability to identify and respond to threats in real-time, offering a security solution that is adaptable, effective, and strong, specifically designed for critical IoT settings. This solution is then deployed in the real time monitoring of the iOT devices

    Data Privacy in Buy Now Pay Later (BNPL) - A Comprehensive PIA Framework

    No full text
    The rapid expansion of the BNPL sector has introduced unique set of privacy challenges, concerning the usage, processing, and sharing of user data. This study develops a tailored Privacy Impact Assessment (PIA) framework specific to the BNPL sector, integrating privacy-by-design principles and ISO/IEC 27701 standards. The research employs systematic layers that includes a custom data mining tool, risk assessment matrix and a qualitative evaluation using the PEGS methodology. These tools identify key risks that arises from extensive data collection, third-party sharing, cross-border transfers, and automated decision-making practices. The tailored framework ensures compliance with GDPR and international standards while focusing on transparency, accountability, and privacy solutions. Evaluation of the framework by PEGS method demonstrated high efficiency. Future research aims to include stakeholder engagement to refine the privacy practices. This research largely contributes to advancing privacy frameworks for Fintech ecosystem, safeguarding user data in a digital era

    Mitigating Social Engineering Risks: An Integrated Framework Concurrently Addressing Human Vulnerabilities and Technical Defences in Cybersecurity

    No full text
    Cyber security continues to be a key concern with growing use of social engineering techniques such as phishing, pretexting, baiting, and tailgating, exploiting psychological triggers such as trust, urgency, and fear, to attack humans. In an attempt to address both technical and human defences, this work introduces an integrated model for social engineering countermeasures. Analysing 154 real-life cases through qualitative analysis, the work identifies repeat attack patterns, psychological exploit mechanisms, and sector-specific vulnerabilities. Drawing a dataset from industry reports, academic studies, and case studies, the work underlines the importance of integration between technology and humans in countering social engineering threats. Composed of three principal pillars, namely, simulation training and awareness programs, multi-factor authentication and behaviour anomaly, and an organizational environment focused on cybersecurity awareness and governance, the proposed model aims to counter social engineering attacks through a balanced integration of humans and technology. Findings reveal that technology alone cannot suffice and must be supplemented with behaviour-related insights for a strong security stance. Emphasis is placed in the work for an inter-disciplinary model combining psychology, cybersecurity, and organizational behaviour for proactive countering of emerging social engineering attack techniques. AI-powered personalized training, real-time adaptability in security protocols, and larger datasets with emerging threats such as deepfake-related phishing must be researched in future studies

    How Can Homomorphic Encryption Be Used In Healthcare Industries

    No full text
    The healthcare industry faces challenges in protecting sensitive data amidst rising cyber threats. Fully Homomorphic Encryption (FHE) offers a transformative solution by enabling computations on encrypted data without decryption. This ensures privacy throughout data handling. This study explores the practical implementation of FHE in healthcare, leveraging the Microsoft SEAL library to create a secure framework for encrypted data analytics and sharing. The framework integrates BFV and CKKS encryption schemes for integer and real-number computations, respectively. It is tested using synthetic datasets simulating healthcare scenarios. Evaluations demonstrate high accuracy, robust noise management, and scalability for moderate dataset sizes. Results from encrypted computations align closely with plaintext benchmarks validating FHE's effectiveness in privacy preservation. While challenges such as computational overhead and noise depletion in complex operations remain, this research underscores the potential of FHE to secure healthcare data, meeting HIPAA standards and enabling safe, efficient data usage. Future work will focus on scalability and optimization strategies

    Comparing the Capabilities of Ensemble Learning Algorithms and SAST Tools for Effective Code Based Vulnerability Detection

    No full text
    Based on the VUDENC and DiverseVul benchmarks, this work evaluates ensemble learning algorithms and SAST tools for software vulnerability detection. Secondary qualitative research data was collected between 2016 and 2024, and quantitative experiments were employed. For handling class imbalance, both Random Forest, XGBoost, LightGBM, and CatBoost ensemble models were experimented on with and without SMOTE. Ensemble models perform better than SAST techniques with XGBoost having the highest ROC-AUC score of 0.76 and Random Forest having stable majority class accuracy. SAST tools were okay for level L concerns but had higher levels of false positives and lower precision. Hybrid techniques can be used in the future to minimize false alarms and enhance immunity to software attacks in ensemble models

    0

    full texts

    8,333

    metadata records
    Updated in last 30 days.
    TRAP
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇