Global ETD Search
Search theses and dissertations gathered from participating repositories worldwide. Every result links back to the library that holds it. No account is needed.
Results
Showing 1 to 20 of 21 for “"application security"”.
-
Application security testing tools study and proposal
Nowadays the need for a shorter time-to-market of applications is evident. However, even though the time needed for developing them gets reduced, we still need to be able to deliver reliable and secure apps. This was already a challenging task, and it is even more so with the time restrictions and …
-
A framework for specifying and formally verifying application security policies
One challenge of building software applications that handle sensitive information is ensuring that they meet certain security and privacy policies, which guide how the application should be written in order to satisfy particular security properties. Common examples of security policies include …
-
Enhancing Android application security through source code vulnerability mitigation using artificial intelligence: a privacy-preserved, community-driven, federated-learning-based approach.
… rapidly increasing. It is crucial to adhere to security protocols during app development, especially as many apps lack sufficient safeguards. Despite the use of automated tools for risk mitigation, their ability to detect vulnerabilities is limited. Therefore, this doctoral research endeavours …
-
A Framework for Hybrid Intrusion Detection Systems
<p>Web application security is a definite threat to the world’s information technology infrastructure. The Open Web Application Security Project (OWASP), generally defines web application security violations as unauthorized or unintentional exposure, disclosure, or loss of personal information. …
-
Vývoj kalkulátoru pro hodnocení zranitelností v Javascriptu
… Vulnerability Scoring System) a OWASP (Open Web Application Security Project) Risk Rating Methodology. Jsou popsány jejich části, metriky a metody samotného výpočtu hodnocení. Následně jsou tyto systémy porovnány a jsou určeny jejich silné a slabé stránky. Práce dále hodnotí některé známe …
-
Secure Programming with Dispersed Compartments
… proposes novel approaches and mechanisms for application compartmental- ization and isolation to reduce their ever-growing attack surface. Our approach is motivated by the key observation that while hardware vendors compete to provide security features, notably memory safety and privilege …
-
A commercially viable computer security implementation framework
Commercial computer security concerns have grown in importance with the continued rise of computer literacy among the general populace. Despite this, the education of management information system professionals in the application of computer security techniques has been largely ignored. This study …
-
LIDS: An Extended LSTM Based Web Intrusion Detection System With Active and Distributed Learning
… detection systems are an integral part of web application security. As Internet use continues to increase, the demand for fast, accurate intrusion detection systems has grown. Various IDSs like Snort, Zeek, Solarwinds SEM, and Sleuth9, detect malicious intent based on existing patterns of …
-
Using a Web Server Test Bed to Analyze the Limitations of Web Application Vulnerability Scanners
The threat of cyber attacks due to improper security is a real and evolving danger. Corporate and personal data is breached and lost because of web application vulnerabilities thousands of times every year. The large number of cyber attacks can partially be attributed to the fact that web …
-
Rules Based Analysis Engine for Application Layer IDS
<p>Web application attack volume, complexity, and costs have risen as people, companies, and entire industries move online. Solutions implemented to defend web applications against malicious activity have traditionally been implemented at the network or host layer. While this is helpful for …
-
A Quantitative Security Assessment of Modern Cyber Attacks. A Framework for Quantifying Enterprise Security Risk Level Through System's Vulnerability Analysis by Detecting Known and Unknown Threats
Cisco 2014 Annual Security Report clearly outlines the evolution of the threat landscape and the increase of the number of attacks. The UK government in 2012 recognised the cyber threat as Tier-1 threat since about 50 government departments have been either subjected to an attack or a direct threat …
-
J-WAVE: A Java Web Application for Vulnerability Education
Static application security testing (SAST) tools are commonly used by professionals to identify security vulnerabilities before deployment. While there are many such tools, they offer competing features and can be difficult and time-consuming to install and configure. To simplify the usage of these …
-
Bridging Security and Agility: A Comprehensive Approach to Integrating Security Practices in Agile Development through DAST, LLMs, and Automation
Effectively integrating security practices within Agile software development is essential as software systems become complex and critical. While Agile methodologies are widely adopted for their responsiveness and efficiency, many security practices remain documentation-heavy and process-driven, …
-
A Comparison of the Usability of Security Mechanisms Provided by iOS and Android
<p>The Open Web Application Security Project identifies that the number one vulnerability in mobile applications is the misuse of platform-provided security mechanisms. This means that platforms like iOS and Android, which now account for 99.8\% of the mobile phone market, are providing mechanisms …
-
The Web Engineering Security (WES) methodology
… organizations to provide justification for security from a business case perspective and to focus on security from a web application development environment perspective. This increased focus on security was the basis of a business case discussion and led to the acquisition of empirical …
-
Investigating attack-aware web applications
… of static content towards a platform for dynamic applications. This transformation, however, took place on top of the Web’s original design rather than being initiated by a complete makeover – a move which has consequences on the security of the Web and its applications. One of them is the lack of …
-
Design and Analysis of QoS-Aware Key Management and Intrusion Detection Protocols for Secure Mobile Group Communications in Wireless Networks
Many mobile applications in wireless networks such as military battlefield, emergency response, and mobile commerce are based on the notion of secure group communications. Unlike traditional security protocols which concern security properties only, in this dissertation research we design and …
-
An analysis of service oriented architectures
… of resources. These systems house several applications for internal sales, purchasing, finance, HR and so on. In any such typical organization, IT systems are a heterogeneous mix of hardware, operating systems and applications. Many of these applications run on different operating systems …
-
Protecting enclaves from side-channel attacks through physical isolation
… transportation. It is therefore no surprise that security solutions like trusted execution environments (TEEs) have been introduced in many systems ranging from small embedded networking devices to large server racks. One of the main challenges of this ever growing functionality is keeping the …
-
Detection of malicious content in JSON structured data using multiple concurrent anomaly detection methods
<p>Web applications and Web services often use a data format known as JavaScript Object Notation (JSON) to exchange information. An attacker can tamper with these exchanges to cause the Web service or application to malfunction in a way that is detrimental to the interests of the owners of the Web …
Page 1 of 2