Showing posts with label tool. Show all posts
Showing posts with label tool. Show all posts

Thursday, 8 June 2017

Model-based tool for Tactical Data Links

Ajit, S., Holmes, C., Johnson, J., Kolovos, D. S. and Paige, R. F. (2017) Model-based tool support for Tactical Data Links: an experience report from the defence domain. Software & Systems Modeling. 16(2), pp. 559-586. 1619-1366

DOI: 10.1007/s10270-015-0480-2

Abstract
The Tactical Data Link (TDL) allows the exchange of information between cooperating platforms as part of an integrated command and control (C2) system. Information exchange is facilitated by adherence to a complex, message-based protocol defined by document-centric standards. In this paper, we report on a recent body of work investigating migration from a document-centric to a model-centric approach within the context of the TDL domain, motivated by a desire to achieve a positive return on investment. The model-centric approach makes use of the Epsilon technology stack and provides a significant improvement to both the level of abstraction and rigour of the network design. It is checkable by a machine and, by virtue of an MDA-like approach to the separation of domains and model transformation between domains, is open to integration with other models to support more complex workflows, such as by providing the results of interoperability analyses in human-readable domain-specific reports conforming to an accepted standard.

More information can be found at: http://nectar.northampton.ac.uk/7750/

All views and opinions are the author's and do not necessarily reflected those of any organisation they are associated with. Twitter: @scottturneruon

Thursday, 10 September 2015

Model-Based Tool Support for Tactical Data Links: An Experience Report from the Defence Domain

(2015) Ajit, S, Holmes, C, Johnson, J, Kolovos, D, Paige, R: Model-Based Tool Support for Tactical Data Links: An Experience Report from the Defence Domain. Software and Systems Modeling, DOI 10.1007/s10270-015-0480-2, ISSN: 1619-1366, Springer Berlin Heidelberg. 

Abstract:
The Tactical Data Link (TDL) allows the exchange of information between cooperating platforms as part of an integrated command and control (C2) system. Information exchange is facilitated by adherence to a complex, message-based protocol defined by document-centric standards. In this paper, we report on a recent body of work investigating migration from a document-centric to a model-centric approach within the context of the TDL domain, motivated by a desire to achieve a positive return on investment. The model-centric approach makes use of the Epsilon technology stack and provides a significant improvement to both the level of abstraction and rigour of the network design. It is checkable by a machine and, by virtue of an MDA-like approach to the separation of domains and model transformation between domains, is open to integration with other models to support more complex workflows, such as by providing the results of interoperability analyses in human-readable domain-specific reports conforming to an accepted standard.

http://link.springer.com/article/10.1007%2Fs10270-015-0480-2

If you'd like to find out more about Computing at the University of Northampton go to: www.computing.northampton.ac.uk. All views and opinions are the author's and do not necessarily reflected those of any organisation they are associated with

Monday, 28 January 2013

Tool for web application vulnerability scanning

A recent MSc student project by Akhil Antony looked at a website that allows certain security risks (SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery) to be tested for.




Abstract:
Web applications are open and available on the internet 24/7 and the attackers can easily access the applications from anywhere and can penetrate the system by identifying and exploiting the vulnerability exists within it. Probability of web applications to be attacked is very high compared to the offline applications. The number of new developments for security enhancements is tend to be increasing, on the other hand the new modern technologies like HTML5, CSS3, jQuery, Silverlight and so on creates new vulnerabilities every minute and the number of such attacks increasing in a very high order. The attacker not just looking for the sensitive information from the victims web application; these applications could be used for further criminal activities including terrorism, drug dealing etc. The research is to investigate the vulnerabilities affecting the web applications and to develop an automated web application vulnerability scanner. The investigation is also focuses on the motivations and profits behind these attacks. With this application users could be able to test the web application’s security rating based on the possible vulnerabilities and developers could be able to perform penetration search within their application.
Most of the web applications suffers from generic validation errors and causes security vulnerabilities. SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery etc are examples of popular vulnerabilities exist within web applications. Majority of these web vulnerabilities are easy to identify and avoid, but unfortunately the developers are not much security aware or they work in very small time constraints. As a result more and more web applications on the internet would be vulnerable. (Stefan Kals, 2006)
The cyber crimes and the cyber attacks to web applications could be categorized on a general principle that what illegal offline is illegal online. The research is on the crimes which can only be carried out using the internet, including attacks on computer systems to disrupt IT infrastructure, and the stealing of data over a network using malware, often to enable further crime. The cyber attackers attempt to access information stored on a computer. Information may have a sale value (corporate espionage), may be valuable to the owner (ransom opportunity) or may be useful for further illegal activity such as fraud. Threats, motivations and profit achieved from cyber attacks being investigated.


Friday, 3 February 2012

waste as tool to inspire potential computing students



A recent article in the Northampton Herald and Post " How a university is using waste as tool to inspire students" by Lawrence John discusses the Junkbots project. 
"FUNNY looking robots called junkbots could be the key to encouraging more children across the county to become engineers, computer programmers or scientists.

One force which is driving this idea forward is the University of Northampton.

For the past few years, staff from its science and technology department have been going out to primary and secondary schools to spread the word that science is fun.
By working with schools, the university hopes to show pupils a different side to computing and hopefully raise their interest in what they can achieve" Lawrence John
For the whole article click here.