77 research outputs found
Sensor Data Security Level Estimation Scheme for Wireless Sensor Networks
Due to their increasing dissemination, wireless sensor networks (WSNs) have become the target of more and more sophisticated attacks, even capable of circumventing both attack detection and prevention mechanisms. This may cause WSN users, who totally trust these security mechanisms, to think that a sensor reading is secure, even when an adversary has corrupted it. For that reason, a scheme capable of estimating the security level (SL) that these mechanisms provide to sensor data is needed, so that users can be aware of the actual security state of this data and can make better decisions on its use. However, existing security estimation schemes proposed for WSNs fully ignore detection mechanisms and analyze solely the security provided by prevention mechanisms. In this context, this work presents the sensor data security estimator (SDSE), a new comprehensive security estimation scheme for WSNs. SDSE is designed for estimating the sensor data security level based on security metrics that analyze both attack prevention and detection mechanisms. In order to validate our proposed scheme, we have carried out extensive simulations that show the high accuracy of SDSE estimates
Automated Emerging Cyber Threat Identification and Profiling Based on Natural Language Processing
The time window between the disclosure of a new cyber vulnerability and its use by cybercriminals has been getting smaller and smaller over time. Recent episodes, such as Log4j vulnerability, exemplifies this well. Within hours after the exploit being released, attackers started scanning the internet looking for vulnerable hosts to deploy threats like cryptocurrency miners and ransomware on vulnerable systems. Thus, it becomes imperative for the cybersecurity defense strategy to detect threats and their capabilities as early as possible to maximize the success of prevention actions. Although crucial, discovering new threats is a challenging activity for security analysts due to the immense volume of data and information sources to be analyzed for signs that a threat is emerging. In this sense, we present a framework for automatic identification and profiling of emerging threats using Twitter messages as a source of events and MITRE ATT&CK as a source of knowledge for threat characterization. The framework comprises three main parts: identification of cyber threats and their names; profiling the identified threat in terms of its intentions or goals by employing two machine learning layers to filter and classify tweets; and alarm generation based on the threat’s risk. The main contribution of our work is the approach to characterize or profile the identified threats in terms of their intentions or goals, providing additional context on the threat and avenues for mitigation. In our experiments, the profiling stage reached an F1 score of 77% in correctly profiling discovered threats
A Lossless Compression Method for Internet Packet Headers
A critical requirement for performance evaluation and design of network elements is the availability of realistic traffic traces. There are, however, several reasons that makes it difficult to have access to them. Firstly, Internet providers are usually reluctant to make real traces public, secondly, hardware for collecting traces at high speed is usually expensive, and finally, with the increase of link rates, the required storage for packet traces of meaningful duration becomes too large. In this paper we address the problem of compression of these potentially huge packet traces. We propose a novel packet header compression, focused not on the problem of reducing transmission bandwidth or latency, but on the problem of saving storage space. As far as we know, ours is the first method specifically oriented to this goal. With our proposed method, storage size requirements for .tsh packet headers are reduced to 16% of its original size. The compression proposed here is more efficient than any other existing method and simple to implement. Others known methods have their compression ratio bounded to 50% and 32%
Sistema especialista monitor de redes de computadores
Dissertação (mestrado) - Universidade Federal de Santa Catarina, Centro Tecnológico. Programa de Pós-Graduação em Ciência da Computação.O propósito deste trabalho, que abrange a área de informática, mais especificamente a gerência de redes e a Inteligência Artificial é implementar uma ferramenta para auxiliar a gerência de redes locais ou distribuídas. Através da leitura de parâmetros da rede, como por exemplo fragmentação de pacotes ou nível de "broadcast", e a comparação destes com valores limites pré-definidos, esta ferramenta indica ao administrador da rede possíveis problemas com os elementos da rede como roteadores, hub's, switches etc, relacionados a parâmetros fora dos limites pré-estabelecidos. Para o desenvolvimento foram utilizadas tecnologias como agentes RMON, software instalado em elementos de rede, que colhem e armazenam parâmetros de rede para posterior utilização por um software gerente, protocolo SNMP, protocolo que facilita a troca de informações de gerência entre agente e gerente, linguagem de programação C e linguagem Prolog. Foi desenvolvida uma "SHELL" de sistema especialista, com a qual o especialista irá interagir, inserindo o seu próprio conhecimento, adequando a ferramenta às suas necessidades, de maneira que a base de conhecimento desta "Shell" crescerá até o limite do próprio conhecimento do administrador
Controle Externo da governança de Tecnologia da Informação
O crescente processo de informatização da Administração Pública brasileira contribui para uma maior agilidade e qualidade nos serviços públicos prestados para a sociedade e um consequente aumento na transparência das ações governamentais. Por outro lado, os gastos nos investimentos e na manutenção dos recursos de Tecnologia da Informação (TI) vêm aumentando consideravelmente, bem como tem-se verificado uma forte dependência das instituições com relação aos sistemas informatizados e à segurança das suas bases de dados. Com o aumento da importância estratégica da área de TI, houve uma busca pela aplicação de modelos de governança, com o objetivo de tornar a área controlável, com resultados mensuráveis e orientada aos objetivos do negócio da instituição. A auditoria de TI tem como função principal avaliar o processo de gestão, no que se refere aos seus diversos aspectos, tais como a governança corporativa, gestão de riscos de TI e procedimentos de aderência às normas regulatórias, apontando eventuais desvios e vulnerabilidades, como também oferecendo alternativas de soluções para esses diversos problemas. No âmbito do controle externo, os Tribunais de Contas começam a reconhecer a necessidade de implantar áreas especializadas na realização de Auditoria de TI. Neste contexto, o presente trabalho pretende apresentar quais as abordagens utilizadas nesta área de fiscalização, destacando a importância da Governança de TI como importante instrumento na atuação do controle externo na fiscalização da gestão e do uso da Tecnologia da Informação na Administração Pública
- …
