Cookies
O website necessita de alguns cookies e outros recursos semelhantes para funcionar. Caso o permita, o INESC TEC irá utilizar cookies para recolher dados sobre as suas visitas, contribuindo, assim, para estatísticas agregadas que permitem melhorar o nosso serviço. Ver mais
Aceitar Rejeitar
  • Menu
Publicações

Publicações por CTM

2023

An Overview of HTTPS and DNSSEC Services Adoption in Higher Education Institutions in Brazil

Autores
Barreto, J; Almeida, H; Pinto, P;

Publicação
2023 25TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, ICACT

Abstract
Cyberattacks are performed against all organizations including Higher Education Institutions (HEIs). When these attacks are successful, they can affect the regular operation of these institutions and may cause the leak of essential or sensitive data that can be misused or become inaccessible. Therefore, the adoption of current security services is important for devices and services exposed to the Internet that should run the latest and secure versions of web-related protocols and comply with the latest security-related guidelines and recommendations. This article surveys and analyzes the status of web-related security services, namely the Hyper Text Transfer Protocol Secure (HTTPS) and the Domain Name System Security Extensions (DNSSEC) services, in Brazilian HEIs. The results of this survey show that regarding HTTPS around 15% do not use any SSL / TLS certificate and of those supporting it, about 14% do not demand its usage. Regarding DNSSEC, the analysis shows that only around 2% of the HEIs are implementing this protocol. These results show that it is important to design an effective and continuous action plan for HEIs regarding the support or discontinuity of versions of these protocols, in order to improve their protection against cyberattacks.

2023

Cost-Effective Resources for Computing Approximation Queries in Mobile Cloud Computing Infrastructure

Autores
Sangaiah, AK; Javadpour, A; Pinto, P; Chiroma, H; Gabralla, LA;

Publicação
SENSORS

Abstract
Answering a query through a peer-to-peer database presents one of the greatest challenges due to the high cost and time required to obtain a comprehensive response. Consequently, these systems were primarily designed to handle approximation queries. In our research, the primary objective was to develop an intelligent system capable of responding to approximate set-value inquiries. This paper explores the use of particle optimization to enhance the system's intelligence. In contrast to previous studies, our proposed method avoids the use of sampling. Despite the utilization of the best sampling methods, there remains a possibility of error, making it difficult to guarantee accuracy. Nonetheless, achieving a certain degree of accuracy is crucial in handling approximate queries. Various factors influence the accuracy of sampling procedures. The results of our studies indicate that the suggested method has demonstrated improvements in terms of the number of queries issued, the number of peers examined, and its execution time, which is significantly faster than the flood approach. Answering queries poses one of the most arduous challenges in peer-to-peer databases, as obtaining a complete answer is both costly and time-consuming. Consequently, approximation queries have been adopted as a solution in these systems. Our research evaluated several methods, including flood algorithms, parallel diffusion algorithms, and ISM algorithms. When it comes to query transmission, the proposed method exhibits superior cost-effectiveness and execution times.

2023

A Survey and Risk Assessment on Virtual and Augmented Reality Cyberattacks

Autores
Silva, T; Paiva, S; Pinto, P; Pinto, A;

Publicação
IWSSIP

Abstract
Nowadays, Virtual Reality (VR) and Augmented Reality (AR) systems are not exclusively associated with the gaming industry. Their potential is also useful for other business areas such as healthcare, automotive, and educational domains. Companies need to accompany technological advances and enhance their business processes and thus, the adoption of VR or AR technologies could be advantageous in reducing resource usage or improving the overall efficiency of processes. However, before implementing these technologies, companies must be aware of potential cyberattacks and security risks to which these systems are subject. This study presents a survey of attacks related to VR and AR scenarios and their risk assessment when considering healthcare, automation, education, and gaming industries. The main goal is to make companies aware of the possible cyberattacks that can affect the devices and their impact on their business domain.

2023

Enhanced resource allocation in distributed cloud using fuzzy meta-heuristics optimization

Autores
Sangaiah, AK; Javadpour, A; Pinto, P; Rezaei, S; Zhang, WZ;

Publicação
COMPUTER COMMUNICATIONS

Abstract
Cloud computing is a modern technology that has become popular today. A large number of requests has made it essential to propose a resources allocation framework for arriving requests. The network can be made more efficient and less costly this way. The cloud-edge paradigm has been considered a growing research area in the computing industry in recent years. The increase in the number of customers and requests for cloud data centers (CDCs) has created the need for robust servers and low power consumption mechanisms. Ways to reduce energy in the CDC having appropriate algorithms for resource allocation. The purpose of this study was to develop an intelligent method for dynamic resource allocation using Takagi-Sugeno-Kang (TSK) neural-fuzzy systems and ant colony optimization (ACO) techniques to reduce energy consumption by optimizing resource allocation in cloud networks. It predicts future loads using a drop-down window to track CPU usage. By optimizing virtual machine migration, ACO can reduce energy consumption. Simulations are provided by examining the implementation and a variety of parameters such as the number of requests made wasted resources, and requests rejected. In this paper, we propose the use of virtual machine migration to accomplish two main goals: evacuating additional and non-optimal virtual machines (scaling and shutting down additional active physical machines) and solving the resource granulation problem. We evaluated and compared our results with literature for rejection rates of virtual and physical machine applications. The performances of our algorithms are compared to different criteria such as performance in request rejection, dynamic CPU resource allocation with reinforcement learning, multi-objective resource allocation, NSGAIII, Whale optimization and Forecast Particle Swarm allocation. A comparison of some evaluation criteria showed that the proposed method is more efficient than other methods.

2023

An Analysis on the Implementation of Secure Web-Related Protocols in Portuguese City Councils

Autores
Junior, J; Carneiro, P; Paiva, S; Pinto, P;

Publicação
INTERNATIONAL JOURNAL OF MARKETING COMMUNICATION AND NEW MEDIA

Abstract
The services supporting the websites, both public and private entities, may support security protocols such as HTTPS or DNSSEC. Public and private entities have a responsibility to ensure the security of their online platforms. Entities in the public domain such as city councils provide their services through their websites. However, each city council has its systems, configurations, and IT teams, and this means they have different standings regarding the security protocols supported. This paper analyzes the status of security protocols on Portuguese city council websites, specifically HTTPS and DNSSEC. The study evaluated 308 city council websites using a script developed for the research, and data was collected from the website of Direcao Geral das Autarquias Locais (DGAL) on December 14, 2022, and the websites were scanned on December 22, 2022. The results of this assessment reveal that around 97% of city council websites use RSA as their encryption algorithm and around 84% use 2048-bit length keys for digital certificate signing. Furthermore, about 53% of the city council websites are still supporting outdated and potentially insecure SSL/TLS versions, and around 95% of the councils are not implementing DNSSEC in their domains. These results highlight potential areas for improvement in cybersecurity measures and can serve as a baseline to track progress toward improving cybersecurity maturity in Portuguese city councils.

2023

An Analysis of Infractions and Fines in the Context of the GDPR

Autores
Dias, JC; Martins, A; Pinto, P;

Publicação
INTERNATIONAL JOURNAL OF MARKETING COMMUNICATION AND NEW MEDIA

Abstract
The General Data Protection Regulation (GDPR) is the regulation that determines the directives inherent to the collection, processing, and protection of personal data in European Union (EU) countries. It was implemented in May 2018 and over the past few years, several public and private companies have been affected by serious penalties. With more than 1500 fines already registered, it is important to have an analysis and insights about them. This paper proposes a detailed analysis of the public records of fines under GDPR, understanding the average fines imposed, the main causes for their application and how they have evolved over time. It is also intended to understand the most affected sectors and point ways to mitigate these penalties. It is concluded that fines under GDPR have an increasing trend over time, both in number of fines and in value, with Industry and Commerce & Media, Telecoms and Broadcasting being the most affected sectors.

  • 79
  • 401