834 research outputs found
sj-docx-1-eae-10.1177_0958305X231193873 - Supplemental material for Comparative analysis of triboelectric behavior of natural waste biomaterials and green energy harvesting
Supplemental material, sj-docx-1-eae-10.1177_0958305X231193873 for Comparative analysis of triboelectric behavior of natural waste biomaterials and green energy harvesting by Jaspreet Kaur, Ravinder Singh Sawhney, Harminder Singh, Manjit Sandhu and
Rajdeep Singh Sohal, Amandeep Singh, Maninder Singh, Sandeep Kaur in Energy & Environment</p
Design and Development of Honeypot for Proactive Monitoring of Campus Network
ME, CSEDHoneypots are closely monitored decoys that are employed in a network to study the rail of hackers and to alert network administrators of a possible intrusion. Honeypots are a relatively new technique for achieving network security.
In this thesis a new honeypot is developed using Honeyd and other opensource technologies. In the process a way to overcome the OS fingerprint mismatch is shown and arpd program is patched to allow it to send unicast ARP replies and to send replies faster
Design and Develop a Campus Honeypot to Detect Intrusions
Internet has become the largest public data network so it is to be prevented from internal and external intruders.A campus honeypot is a honeypot which has capabilities of both production and research honeypot.Campus honeypos prevent production system and keep track on intruders’s activities and analyze their actions to take decision accordingly
Ant Colony Optimzation (ACO) based Intrusion Detection System
M.E.Thesis (Computer Science and Engineering), August 2010Security is a big issue for all networks in todays enterprise environment. Hackers
and intruders have made many successful attempts to bring down high-pro le com-
pany networks and web services. Many methods have been developed to secure the
network infrastructure and communication over the Internet, among them the use of
rewalls, encryption, and virtual private networks. Intrusion detection is a relatively
new addition to such techniques.
This work explain working of IDS speci cally Bro and also suggests the use of ACO
for Intrusion Detection. The major emphasis is on the design and development of
the policy scripts to detect various network intrusions.
It also has signature-matching features to make
threat signatures to match against various attacks and detect them later
Implement Software Access Point using Linux Hotspot
As the internet growing day by day secure transmission of data is very crucial. In
IEEE 802.11 Wireless Local Area Network (WLAN) deployments, supporting user and
devices security is a critical issue, continuous connectivity and network security are
highly desirable. Wi-Fi networks are prone to a large number of Denial of Service (DoS)
attacks due to vulnerabilities at the MAC layer of 802.11 protocol. The impact of deauthentication
DoS attacks is severe and easier to orchestrate as the victim gets
disconnected from the network. This attack can be launched easily using minimal
resources. It becomes highly recommended to have a Wi-Fi network capable with
Intrusion Detecion System (IDS) along with Intrusion Prevention System (IPS) that not
only detects the de-authentication DoS attack in a Wi-Fi network but also helps the
victim station (STA) in recovering swiftly from the attack
Designing Masking Ruleset for Hiding Operating System Identity
M.E. Software Engineering (Thesis)Computers have virtually revolutionized every sphere of our life. The rapid growth in the development of computers focused primarily on making the computer easy to use i.e. usability. The idea was to make computer easy to use for all sections of society. The rapid growth did not emphasize much on the security of the Computer system thereby rendering system as vulnerable to attacks. Had security been considered earlier in the development of computer system, our systems would have been more secure these days. Thus the preference of usability over security has made system more prone to attacks.
Further, Internet has made hacking much easier. The skill level required for hacking has gone down considerably. One can easily get exploits for latest vulnerabilities and threats. Almost all the attacks are operating system specific and sometime application version specific. All the vulnerabilities are generally indexed based on the operating system. From a hacker’s point of view, it is important to know which operating system is running on the target machine. Thus determining the operating system running on the remote machine is a key step to the hacking process. From the Network administration point of view, it is important that various key machines i.e. Web server, Mail server, etc in the network are properly masked from easy operating system detection. Masking the operating system is a must in case of zero day attacks.
Operating system fingerprinting makes use of the fact that different operating system vendors implement the TCP/IP stack in different ways thereby providing the attacker with enough opportunity to detect the Operating system running on the system. Various tools are available that can reveal remote operating system with great degree of accuracy and in minimum time. Specially crafted packets are sent to remote machine and the response is compared to database thereby revealing the running operating system. Default configuration of a computing system can easily reveal the underline operating system.
Thus it’s important that the operating system is masked from easy detection. Intrusion prevention system (IPS) is one such way that masks the operating system from easy detection. An IPS makes use of rules that governs which packet to accept and which one to reject. IPS is not a substitute for a Firewall. Instead an IPS works along with the firewall. Firewall basically deploys rules for incoming and outgoing packets. IPS can further investigate the packets for Intrusions. Various rules can be designed that makes that will make sure that all attempts for operating system detection are treated as Intrusions, various specially crafted packets are dropped, logged and appropriate action taken against intruding machines
Design and Implementation of Computer and Network Forensics Framework
Doctor of Philosophy -CSEWith an exponential increase in the data size and complexity of various seized items to be investigated, existing methods of network and computer forensics are not very efficient when it comes to dealing with accuracy and detection ratio. Till the time a well-established forensic technique is developed to handle security threats, a much more sophisticated attacks strike on network. Traditional Intrusion Detection Systems (IDS) and forensics techniques used to detect and prevent malicious network behaviours, fail to handle new or zero day attacks. The accuracy of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) is questionable, which can’t be trusted for forensics. Another important drawback with the exiting techniques, is their inability to tackle high velocity and huge amount of heterogeneous data.
Cyber forensic investigation mechanism has volume constraint, while processing the fast growing data from Information and Communication Technology (ICT) infrastructure, including IoT based devices and platforms. Non-tangible sources often don’t have the limit of flowing data through them, especially through communication media. Hence, increasing the desperate requirement for an efficient benchmarking of big data analysis. Existing techniques exhibit inherent limitations in processing huge volume, variety, and velocity of data. It makes the process time-consuming and resource intensive. Available solutions to date have used an anomaly-based approach or have proposed approaches based on the deviation from a regular pattern. To tackle the seized bytes, authors have proposed an approach for big data forensics, with efficient sensitivity and precision.
In order to maintain a balance between processing time and output efficiency, existing techniques put a limit on the amount of data under analysis, which results in a non-polynomial time complexity of these solutions. In this thesis, a scalable, practical framework to overcome the limitation to handle large volume, variety, and velocity of data, is proposed. The proposed architectural setup consists of the MapReduce framework on top of the Hadoop Distributed File System environment.
The proposed framework demonstrates its capability to handle issues of storage and processing of big data using cloud computing infrastructure. In the presented work, a
generalized forensic framework has been proposed that use Google’s programming model, MapReduce as the backbone for traffic translation, extraction, and analysis of dynamic traffic features. For the proposed technique, authors have used open source tools like Hadoop, Hive, and Mahout and R. Apart from being open source, these tools support scalability and parallel processing. Also, comparative analysis of globally accepted machine learning models of P2P malware analysis in mocked real-time is presented. Supervised machine learning (Random Forest based Decision Tree) algorithm has been implemented to demonstrate better sensitivity and specificity. For training and validating the model, CAIDA dataset [1] along with university network traffic samples from GitHub [2], with increasing size, has been taken. Results thus obtained confirm the superiority of the proposed framework, with an accuracy of 99%. The work encompasses computer and network forensics, which is being referred as cyber forensics, collectively in this thesis, due to the nature of the data being dealt and experimented
Gene Mutation Analysis -Role of Open Source Tools for Personalized Medication and Designer Drugs in a Cost-Effective and Efficient Manner
ME, CSEDWe have established Gene Mutation Analysis platform of software pipelines using Open Sources
tools (BWA, GATK, Bioconductor, Samtools, VarScan2) on Linux based Operating System. We
have implemented GATK best practices for mutation detection. Also, developed browser-based
tools for visual analysis of the gene mutations using Open Source tools (JBrowse, HTML5,
Javascript, Python). Browser-based visual tool enables clinicians to look atupstream/downstream
of the mutation/SNP. The visual tool enables identification of mutation hot-spots, driver
mutations and passenger mutation.
Quality Checks are made part of the software tools for minimizing possible false-positive
detection of gene mutation/SNP. The quality checks based on minimum coverage, Phred scores,
ratio of supporting variant and reference alleles. Mutations are further validated using COSMIC,
HapMap, Geome Wide Association Studies and clinically flagged SNPs from dbSNP.
With help of the above platform and visual tools, the Oncologist is now able to do a triage – look
at a patient, look at their lab results and look at their genetic profile visually; they are now able to
do more personalized medicine
Three-Dimensional Evaluation of Condyle-Glenoid Fossa Complex Following Treatment with Herbst Appliance
The purpose of the present retrospective observational study was to compare the effects of treatment with Herbst appliance and fixed therapy with elastics on the condyle and glenoid fossa complex. Thirty patients aged between twelve and sixteen years with skeletal Class II malocclusion who met the inclusion criteria were included in the study: fifteen patients treated with Herbst appliance (Group 1), and fifteen patients treated with orthodontic camouflage using MBT prescription (MBTTM Versatile+ Appliance System) (Group 2). For Group 2, patients had CBCT scans taken before treatment either after Herbst appliance removal or at the end of treatment. CBCT scans were evaluated for changes in condyle-glenoid fossa complex using the In Vivo Dental 5.1 software. Statistical significance was set at p ≤ 0.05. On inter-group comparison, the Herbst group showed statistically significant increases in the condylar height of 1.35 mm (p ≤ 0.001) on the right and 1.21 mm (p ≤ 0.01) on the left side, and a condylar volume of 111.03 mm3 (p ≤ 0.01) on the right and 127.80 mm3 (p ≤ 0.001) on the left side. The Herbst group showed anterior remodelling on the postero-superior aspect of glenoid fossa. Herbst appliance treatment induced growth at the condylar head and anterior remodelling of glenoid fossa, thereby improving the maxilla-mandibular relationship in growing skeletal Class II patients
Anomaly based Botnet Detection using DNS Traffic Analysis
PhD ThesisCybercrimes are evolving on a regular basis and these crimes are becoming a greater threat day by day. Earlier these threats were very general and unorganized. In the last decade, these attacks
have become highly sophisticated in nature. This higher level of coordination is possible mainly
due to Botnet which is a cluster of infected hosts controlled remotely by an attacker (Botmaster).
The number of infected machines is continuously rising thereby resulting in Botnets with many
of these having even over a million infected machines. This innumerous set of machines with
varied computational and storage capabilities give the botmaster a lethal weapon to launch
various security attacks. This never-ending menace of the botnet is causing many serious
problems on the Internet.
Domain Name System is a large-scale distributed database on the Internet, which is being
abused as a Botnet communication channel. Significant efforts have been made in detecting
botnet at the global level which relies heavily on finding failed queries and domain flux
information for botnet detection, there are very few efforts being made to detect bot infection
at an enterprise level. Detecting bot-infected machines are vital for any organization in
combating various security threats.
This research work proposes a novel anomaly-based detection technique which considers
captured DNS traffic from LAN hosts on hourly basis to generate DNS fingerprint and attempts
to find anomalous behavior which is quite different from normal machine behavior. This
research work successfully demonstrates the DNS Anomaly Detection (named BotDAD)
technique for detecting bot-infected machine in a network using DNS fingerprinting. It uses a
feature extractor module to extract DNS attributes and build a host profile for all hosts in the
network. The host profile is then parsed to generate DNS fingerprint. BotDAD creates DNS
fingerprint of each host in the network and uses anomaly detection engine to label them as bot
or clean. BotDAD uses a machine learning classifier to develop a trained model for future
predictions. The system is evaluated against DNS network traffic captured from TIET Patiala
campus on an hourly basis. The system was able to detect Bot infected machines in the network.
The domains used for C&C by these bots were validated against online DGA domains database.
Results from BotDAD gives an accuracy of 0.9978. To improve the accuracy of the BotDAD, a multi-layer neural network named DeepDAD was implemented. DeepDAD is a Deep
Learning based DNS Anomaly Detection tool created as part of this research which considers
multipoint anomaly detection and uses deep learning algorithms. Instead of relying on a single
point anomaly for labeling DNS fingerprint as malicious, an improved labeling technique which
uses multipoint anomaly detection is implemented. Two machine learning frameworks namely
Scikit-learn and TensorFlow were used to train and test the model showing significant
improvement over the results obtained using BotDAD. Finally, a graphical user interface for
easy testing and comparison is presented
- …
