1,720,977 research outputs found
Understanding and Simulation of Attacks in Power Networks
Etterspørselen etter vedlikehold og reinvestering i kraftsystemet vokser etter hvert
som krafttransformatorene eldes. For å hjelpe beslutningstaking er det for tiden
mangel på egnede data og analyseteknikker for å estimere tilstand og gjenværende
levetid. Å restrukturere kapitalforvaltningen for å samle inn passende data og
etablere nye metoder for å administrere og analysere dataene er en vanskelig op-
pgave. Som et resultat av dette utgjør Confidentiality, Integrity and Availability
(CIA)-triaden – et konsept som fokuserer på balansen mellom konfidensialitet, in-
tegritet og tilgjengelighet av data under beskyttelse av brukernes informasjonssik-
kerhetsprogram, visse problemer for cybersikkerhet. Disse investeringene erstat-
ter de gamle systemene til digitale nettstasjoner. Utviklingen tillater kraftindus-
tridrift, sanntidsfunksjonalitet og informasjonstilgang. I ds er sikring av sikker-
het og tilgjengelighet av kraftsystemer, samt interoperabilitetsevne for forskjel-
lige produsenter, en stor bekymring. Statnett [1] studerer nye funksjonalitetsfor-
deler og tilhørende kostnader med IEC 61850 prosessbussteknologi som en del av
et R&D-pilotprosjekt for digital transformatorstasjon kalt Engineering and Con-
dition monitoring in Digital Substation (ECODIS). Med trusselagenter som blir
mer sofistikerte etter hvert, har sikkerheten aldri vært viktigere. Dette får Cyber-
samfunnet til å jobbe ekstra hardt for å følge etterspørselen og beskytte tjenestene.The demand for maintenance and reinvestment in the power system grows as
power transformers age. To aid decision-making, there is currently a scarcity of
suitable data and analysis techniques for estimating condition and residual life-
time. Restructuring asset management in order to collect appropriate data and
establish new methods for managing and analyzing the data is a difficult task.
As a result, the CIA triad — a concept that focuses on the balance between the
Confidentiality, Integrity, and Availability of data under the protection of users
information security program poses certain problems to Cyber security. These in-
vestments replace the old systems to digital substations. The development allows
for power industrial operation, real-time functionality, and information access.
In DS, ensuring security, and Availability of power systems, as well as interop-
erability capability for diverse manufacturers, is a major concern. Statnett [1]
is studying new functionality advantages and associated costs with international
Electrotechnical Commission (IEC) 61850 process buss technology as part of an
R&D digital substation pilot project called Engineering and Condition monitoring
in Digital Substation (ECODIS). With threat agents becoming more sophisticated
by the second, IT security has never been more vital. This causes Cyber community
to work extra hard in order to stay up with demand and protect the services
Securing the Software Development Life Cycle
Denne rapporten fokuserer på å adressere viktigheten av å sikre systemer og applikasjoner ved å fokusere på implementering av sikkerhetstesting og integrering av verktøy i en utviklingspipeline. Rapporten gir et proof of concept for å bygge en sikker pipeline, og legger vekt på beste praksis og sikkerhetsverktøy for å oppdage sårbarheter tidlig i Software Development Life Cycle (SDLC). Funnene og anbefalingene kan bidra til industriens forståelse av å sikre SDLC og redusere trusler.This research aims to address the importance of securing systems and applications by focusing on implementing security testing and integrating tools into a development pipeline. The report provides a proof of concept for building a secure pipeline, emphasizing best practices and security tools to detect vulnerabilities early in the Software Development Life Cycle (SDLC). The findings and recommendations can contribute to the industry's understanding of securing the SDLC and mitigating threats
Kryptovirus - Ahus
I moderne tider blir teknologien stadig mer avansert og sofistikert. Denne hektiske utviklingsprosessen fører til økt risiko for å bli angrepet av ondsinnede aktører på nettet. De mest utbredte truslene av denne typen er kryptovirus, etter som at disse har et bredt antall angrepsvektorer tilgjengelig og er i stand til å forårsake betydelig skade på sine ofre. Derfor har Akershus universitetssykehus (Ahus) bedt om en gjennomgang av konsekvensene av kryptovirusangrep i helsesektoren, på grunn av mange helseforetak er blitt angrepet i Europa og resten av verden. Ahus har også bedt om at denne oppgaven inkluderer et attack tree diagram som dekker informasjon om tidligere angrep utført de siste årene, andre mulige angrepsvektorer som er identifisert, og hvordan et kryptovirusangrep kan påvirke pasientens kvalitetsjusterte leveår (QALYs).In modern times, technology is becoming more advanced and sophisticated. This hectic process of development leads to an increased risk of being attacked by threat actors on the web. The most prevalent threats of this kind are crypto viruses, as these have a vast amount of attack vectors available, and are capable of causing massive damage to their victims. Thus, Akershus universitetssykehus (Ahus) has requested a review of the consequences of crypto virus attacks in the healthcare sector, due to numerous healthcare companies being attacked in Europe and the rest of the world. Ahus has also requested that this thesis includes an attack tree covering information about previous attacks performed in recent years, possible other attack vectors that are identified, and how a crypto virus attack can affect a patient’s quality-adjusted life years (QALYs)
Modeling tool of TRILL protocol
This paper proposes the first modeling tool of TRILL protocol. The application implements TRILL features, which include the most fundamental concepts of IS-IS protocol. Simplified STP protocol is also implemented. The application can be used to didactically and interactively present the advantages of the TRILL protocol over STP. Alternatively, the tool can be utilized as a decision tool for TRILL deployment in enterprise networks. The functionality of the TRILL protocol is discussed with emphasis on the main differences between STP. The application was tested on five scenarios of TRILL deployment in a typical enterprise network. Data traffic of these different deployments was compared using the application. Finally, results are further discussed
Understanding and Simulation of Attacks in Power Networks
Etterspørselen etter vedlikehold og reinvestering i kraftsystemet vokser etter hvert
som krafttransformatorene eldes. For å hjelpe beslutningstaking er det for tiden
mangel på egnede data og analyseteknikker for å estimere tilstand og gjenværende
levetid. Å restrukturere kapitalforvaltningen for å samle inn passende data og
etablere nye metoder for å administrere og analysere dataene er en vanskelig op-
pgave. Som et resultat av dette utgjør Confidentiality, Integrity and Availability
(CIA)-triaden – et konsept som fokuserer på balansen mellom konfidensialitet, in-
tegritet og tilgjengelighet av data under beskyttelse av brukernes informasjonssik-
kerhetsprogram, visse problemer for cybersikkerhet. Disse investeringene erstat-
ter de gamle systemene til digitale nettstasjoner. Utviklingen tillater kraftindus-
tridrift, sanntidsfunksjonalitet og informasjonstilgang. I ds er sikring av sikker-
het og tilgjengelighet av kraftsystemer, samt interoperabilitetsevne for forskjel-
lige produsenter, en stor bekymring. Statnett [1] studerer nye funksjonalitetsfor-
deler og tilhørende kostnader med IEC 61850 prosessbussteknologi som en del av
et R&D-pilotprosjekt for digital transformatorstasjon kalt Engineering and Con-
dition monitoring in Digital Substation (ECODIS). Med trusselagenter som blir
mer sofistikerte etter hvert, har sikkerheten aldri vært viktigere. Dette får Cyber-
samfunnet til å jobbe ekstra hardt for å følge etterspørselen og beskytte tjenestene
Decrypting Privacy: A Forensic Tool for Extracting Encrypted Data from the Session Application on Android Devices
I dagens digitaliserte samfunn er overvåkning en faktor som gjør det stadig vanskeligere å ivareta personvern. Dette har ført til en økning i bruken av ende-til-ende-krypterte kommunikasjonstjenester. Selv om disse tjenestene beskytter brukernes personvern, blir de også utnyttet av kriminelle nettverk for å unngå å bli oppdaget. I forbindelse med digital etterforskning har den nasjonale enheten for bekjempelse av organisert og annen alvorlig kriminalitet, Kripos, sett et behov for verktøy som muliggjør uthenting av data fra slike tjenester. Applikasjonen Session er én slik tjeneste, og Kripos har behov for tilgang til dens krypterte data. Denne bacheloroppgaven presenterer en løsning for Android-plattformen, bestående av en Android-applikasjon og en tilhørende backend-tjeneste. Applikasjonen, Tyven, dekrypterer og henter ut data fra Session, mens backend-tjenesten, Egon, lagrer dataene for videre bruk i Kripos’ etterforskningsverktøy.In today’s digital society, surveillance is widespread, making it increasingly difficult to maintain personal privacy. This has driven the rise of end-to-end encrypted communication services. While these protect user privacy, they are also misused by criminal networks to evade detection. The Norwegian National Criminal Investigation Service, Kripos, has recognized the need for tools to extract data from such services to support investigations. The Session application is one such service, and Kripos require access to its encrypted data. This thesis presents a solution for the Android platform, consisting of an Android application and a supporting backend. The application, Tyven, decrypts and extracts data from Session, while the backend service, Egon, stores the data for further use in Kripos' investigative tools
Implementing SDN into computer network lessons
This paper describes the issue of introducing SDN to students of computer networks. The most important theoretical knowledge is summarized in the form of key points, students should know about. Practical experience is presented in the area of deployment of SDN in data centers with aim on connecting the existing knowledge from traditional computer networks. This connection is explained on problems of traditional networks in data centers and mitigation of these problems by using SDN. Learned information is then extended by presenting a practical demo application in Mininet environment. The application shows possible usage of SDN for making a data center more power-efficient. This application is put in context by the theory of power consumption of data center devices which can be significantly reduced if SDN are used. Purpose of the application is to motivate students to continue in research of SDN area
Going Beyond Counting First Authors in Author Co-citation Analysis
The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation
counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings
are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that
only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into
account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed
Variations on the Author
“Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
- …
