808 research outputs found

    Towards Automated Security Design Flaw Detection

    No full text
    sponsorship: This research is partially funded by the Research Fund KU Leuven. Katja Tuma was partially supported by the Swedish VINNOVA FFI project "CyReV: Cyber Resilience for Vehicles-Cybersecurity for automotive systems in a changing environment". (Research Fund KU Leuven, Swedish VINNOVA FFI project "CyReV: Cyber Resilience for Vehicles-Cybersecurity for automotive systems in a changing environment")status: Published onlin

    Generating and solving Sudoku puzzles

    Get PDF
    V diplomskem delu so raziskani različni pristopi in algoritmi generiranja, ocenjevanja ter reševanja sudoku mreže. Cilj je ugotoviti, kateri pristopi in algoritmi so za posamezen del programa bolj učinkoviti ter kako se med seboj razlikujejo. Matematična uganka sudoku je neke vrste latinski kvadrat, katerega lastnosti narekujejo obliko rešitve problema ter posledično število možnih rešitev problema. Generiranje mrež lahko poteka na dva nasprotna si načina: generiranje s polnenjem prazne mreže ter generiranje z brisanjem vrednosti iz polne mreže. Generiranje mreže je s strani računalnika podoben problem kot reševanje mreže. Ocenjevanje težavnostne stopnje mreže je delikaten problem, saj je potrebno upoštevati tudi načine človeškega reševanja. S pomočjo prebrane literature in programske rešitve sem tekom diplomskega dela potrdila ugotovitve o časovni zahtevnosti reševanja sudoku mrež ter uporabnosti ocenjevanja težavnostne stopnje mreže s pomočjo entropije.The thesis explores different approaches and algorithms for generating, grading and solving the sudoku grid. The aim of the thesis is to determine which approaches and algorithms are more efficient and how they differ from each other. Mathematical puzzle sudoku is a kind of Latin square, features of which dictate the form of a solution and, consequently, the number of possible solutions to the problem. Generating grids can be done in two opposite ways: generating with filling an empty grid and generating with deleting values from a full grid. Generating a grid is from a computer\u27s perspective similar to solving one. Determining the difficulty level of a grid is a delicate problem, since it is necessary to consider human techniques of solving sudoku. With the help of listed literature and software solution I confirm, during the thesis, the findings on time complexity of solving sudoku grids and usefulness of grading sudoku grids by using information entropy

    Efficiency and Automation in Threat Analysis of Software Systems

    Get PDF
    Context: Security is a growing concern in many organizations. Industries developing software systems plan for security early-on to minimize expensive code refactorings after deployment. In the design phase, teams of experts routinely analyze the system architecture and design to find potential security threats and flaws. After the system is implemented, the source code is often inspected to determine its compliance with the intended functionalities. Objective: The goal of this thesis is to improve on the performance of security design analysis techniques (in the design and implementation phases) and support practitioners with automation and tool support. Method: We conducted empirical studies for building an in-depth understanding of existing threat analysis techniques (Systematic Literature Review, controlled experiments). We also conducted empirical case studies with industrial participants to validate our attempt at improving the performance of one technique. Further, we validated our proposal for automating the inspection of security design flaws by organizing workshops with participants (under controlled conditions) and subsequent performance analysis. Finally, we relied on a series of experimental evaluations for assessing the quality of the proposed approach for automating security compliance checks. Findings: We found that the eSTRIDE approach can help focus the analysis and produce twice as many high-priority threats in the same time frame. We also found that reasoning about security in an automated fashion requires extending the existing notations with more precise security information. In a formal setting, minimal model extensions for doing so include security contracts for system nodes handling sensitive information. The formally-based analysis can to some extent provide completeness guarantees. For a graph-based detection of flaws, minimal required model extensions include data types and security solutions. In such a setting, the automated analysis can help in reducing the number of overlooked security flaws. Finally, we suggested to define a correspondence mapping between the design model elements and implemented constructs. We found that such a mapping is a key enabler for automatically checking the security compliance of the implemented system with the intended design. The key for achieving this is two-fold. First, a heuristics-based search is paramount to limit the manual effort that is required to define the mapping. Second, it is important to analyze implemented data flows and compare them to the data flows stipulated by the design

    Measuring Vulnerability to Poverty Using Long-Term Panel Data

    No full text
    Measuring Vulnerability to Poverty Using Long-Term Panel Data Author & abstract Download & other version 16 References 4 Citations Related works & more Corrections Author Listed: Katja Landau (Georg-August-University Göttingen) Stephan Klasen (Georg-August-University Göttingen) Walter Zucchini (Georg-August-University Göttingen) Registered: Stephan Klasen Abstract We investigate the accuracy of ex ante assessments of vulnerability to income poverty using cross-sectional data and panel data. We use long-term panel data from Germany and apply di fferent regression models, based on household covariates and previous-year equivalence income, to classify a household as vulnerable or not. Predictive performance is assessed using the Receiver Operating Characteristics (ROC), which takes account of false positive as well as true positive rates. Estimates based on cross-sectional data are much less accurate than those based on panel data, but for Germany, the accuracy of vulnerability predictions is limited even when panel data are used. In part this low accuracy is due to low poverty incidence and high mobility in and out of poverty

    Resilience as a positive lever: An analysis of sensemaking and meaningful work in the context of organizational change

    No full text
    Author Katja SchwarzMasterarbeit Johannes Kepler Universität Linz 2024Arbeit nach Ablauf der Sperre auf den öffentlichen PCs in den Bibliotheken der JKU+Medizin abrufba

    Measuring Vulnerability to Poverty Using Long-Term Panel Data

    No full text
    Measuring Vulnerability to Poverty Using Long-Term Panel Data Author & abstract Download & other version 16 References 4 Citations Related works & more Corrections Author Listed: Katja Landau (Georg-August-University Göttingen) Stephan Klasen (Georg-August-University Göttingen) Walter Zucchini (Georg-August-University Göttingen) Registered: Stephan Klasen Abstract We investigate the accuracy of ex ante assessments of vulnerability to income poverty using cross-sectional data and panel data. We use long-term panel data from Germany and apply di fferent regression models, based on household covariates and previous-year equivalence income, to classify a household as vulnerable or not. Predictive performance is assessed using the Receiver Operating Characteristics (ROC), which takes account of false positive as well as true positive rates. Estimates based on cross-sectional data are much less accurate than those based on panel data, but for Germany, the accuracy of vulnerability predictions is limited even when panel data are used. In part this low accuracy is due to low poverty incidence and high mobility in and out of poverty

    Resilience as a positive lever: An analysis of sensemaking and meaningful work in the context of organizational change

    No full text
    Author Katja SchwarzMasterarbeit Johannes Kepler Universität Linz 2024Arbeit nach Ablauf der Sperre auf den öffentlichen PCs in den Bibliotheken der JKU+Medizin abrufba

    Mapping of CIS Cloud Security Policies and Security Best Practices for Helm Charts

    No full text
    This dataset describes the mapping between the security policies and the security best practices of CIS (Center for Internet Security) for Helm Charts among the tools  Checkov by BridgeCrew (36 policies) Datree by Datree (60 polices) KICS by Checkmarx (146 policies) Kubelinter by StackRox (56 policies) Kubeaudit by Shopify (14 policies) Kubescape by ARMO (48 policies) Terrascan by Tenable (35 policies) The work is reported in the paper Francesco Minna, Agathe Blaise, Katja Tuma, Fabio Massacci. "Automated Analysis of Security Policy Violations in Helm Charts". IEEE Transaction on Dependable and Secure Computing. To appear.

    A new, evidence-based, theory for knowledge reuse in security risk analysis

    Get PDF
    Security risk analysis (SRA) is a key activity in software engineering but requires heavy manual effort. Community knowledge in the form of security patterns or security catalogs can be used to support the identification of threats and security controls. However, no evidence-based theory exists about the effectiveness of security catalogs when used for security risk analysis. We adopt a grounded theory approach to propose a conceptual, revised and refined theory of SRA knowledge reuse. The theory refinement is backed by evidence gathered from conducting interviews with experts (20) and controlled experiments with both experts (15) and novice analysts (18). We conclude the paper by providing insights into the use of catalogs and managerial implications.</p

    Monte Carlo Tree Search with Thompson sampling in The Settlers of Catan

    Get PDF
    Drevesno preiskovanje Monte Carlo (MCTS) je ena izmed najbolj uporabljenih metod pri implementaciji močnega računalniškega igralca iger v umetni inteligenci, brez uporabe predhodnega znanja o domeni. Najmočnejši in najbolj popularni algoritmi, ki se pogosto uporabljajo za rešitev t.i. dileme raziskovanja (engl. exploration) proti izkoriščanju znanja (engl. exploitation) pri problemu več-rokih banditov, so raziskani in predstavljeni s pomočjo pregleda literature. Na podlagi empiričnih študij Thompsonovega vzorčenja v primerjavi s pristopom zgornje meje zaupanja (UCB) ter različicami podobnih algoritmov smo v magistrskem delu spremenili drevesno strategijo širjenja v MCTS. Končna domena aplikacije spremenjenega algoritma je družabna igra Prebivalci otoka Catan (SoC), implementirana v programskem jeziku C, skupaj z MCTS-UCT agentom, MCTS-TS agentom ter dvema preprosto igrajočima agentoma. Meritve učinkovitosti naštetih agentov prikazujejo povečano moč igranja agenta s spremenjeno drevesno strategijo, v primerjavi z najbolj pogosto uporabljenim pristopom, t.j. UCT.Monte Carlo Tree search (MCTS) is a popular method of choice for addressing the problem of a strong computer based game playing agent in Artificial Intelligence, without any prior domain knowledge. The strongest and most popular algorithms used to tackle the so-called exploration vs. exploitation dilemma in Multi-armed Bandit (MAB) problems were identified and presented in a literature review. Empirical studies measuring the performance of Thompson sampling (TS) and the state-of-the-art Upper Confidence Bound (UCB) approach in the classical MAB problem have been found, results of which support our modified tree policy in MCTS. The domain of application is the board game of the Settlers of Catan (SoC), which is implemented as a multi-agent environment in the programming language C, along with a MCTS-UCT agent, MCTS-TS agent and two strategy playing agents, namely the ore-grain and wood-clay agent. Performance measurements of the aforementioned agents, presented and discussed in this work, demonstrate an increase in the performance of the agent with the modified tree policy, when compared to the state-of-the-art approach (UCT)
    corecore