Cookies
O website necessita de alguns cookies e outros recursos semelhantes para funcionar. Caso o permita, o INESC TEC irá utilizar cookies para recolher dados sobre as suas visitas, contribuindo, assim, para estatísticas agregadas que permitem melhorar o nosso serviço. Ver mais
Aceitar Rejeitar
  • Menu
Publicações

Publicações por CTM

2023

A Survey and Risk Assessment on Virtual and Augmented Reality Cyberattacks

Autores
Silva, T; Paiva, S; Pinto, P; Pinto, A;

Publicação
IWSSIP

Abstract
Nowadays, Virtual Reality (VR) and Augmented Reality (AR) systems are not exclusively associated with the gaming industry. Their potential is also useful for other business areas such as healthcare, automotive, and educational domains. Companies need to accompany technological advances and enhance their business processes and thus, the adoption of VR or AR technologies could be advantageous in reducing resource usage or improving the overall efficiency of processes. However, before implementing these technologies, companies must be aware of potential cyberattacks and security risks to which these systems are subject. This study presents a survey of attacks related to VR and AR scenarios and their risk assessment when considering healthcare, automation, education, and gaming industries. The main goal is to make companies aware of the possible cyberattacks that can affect the devices and their impact on their business domain.

2023

Enhanced resource allocation in distributed cloud using fuzzy meta-heuristics optimization

Autores
Sangaiah, AK; Javadpour, A; Pinto, P; Rezaei, S; Zhang, WZ;

Publicação
COMPUTER COMMUNICATIONS

Abstract
Cloud computing is a modern technology that has become popular today. A large number of requests has made it essential to propose a resources allocation framework for arriving requests. The network can be made more efficient and less costly this way. The cloud-edge paradigm has been considered a growing research area in the computing industry in recent years. The increase in the number of customers and requests for cloud data centers (CDCs) has created the need for robust servers and low power consumption mechanisms. Ways to reduce energy in the CDC having appropriate algorithms for resource allocation. The purpose of this study was to develop an intelligent method for dynamic resource allocation using Takagi-Sugeno-Kang (TSK) neural-fuzzy systems and ant colony optimization (ACO) techniques to reduce energy consumption by optimizing resource allocation in cloud networks. It predicts future loads using a drop-down window to track CPU usage. By optimizing virtual machine migration, ACO can reduce energy consumption. Simulations are provided by examining the implementation and a variety of parameters such as the number of requests made wasted resources, and requests rejected. In this paper, we propose the use of virtual machine migration to accomplish two main goals: evacuating additional and non-optimal virtual machines (scaling and shutting down additional active physical machines) and solving the resource granulation problem. We evaluated and compared our results with literature for rejection rates of virtual and physical machine applications. The performances of our algorithms are compared to different criteria such as performance in request rejection, dynamic CPU resource allocation with reinforcement learning, multi-objective resource allocation, NSGAIII, Whale optimization and Forecast Particle Swarm allocation. A comparison of some evaluation criteria showed that the proposed method is more efficient than other methods.

2023

An Analysis on the Implementation of Secure Web-Related Protocols in Portuguese City Councils

Autores
Junior, J; Carneiro, P; Paiva, S; Pinto, P;

Publicação
INTERNATIONAL JOURNAL OF MARKETING COMMUNICATION AND NEW MEDIA

Abstract
The services supporting the websites, both public and private entities, may support security protocols such as HTTPS or DNSSEC. Public and private entities have a responsibility to ensure the security of their online platforms. Entities in the public domain such as city councils provide their services through their websites. However, each city council has its systems, configurations, and IT teams, and this means they have different standings regarding the security protocols supported. This paper analyzes the status of security protocols on Portuguese city council websites, specifically HTTPS and DNSSEC. The study evaluated 308 city council websites using a script developed for the research, and data was collected from the website of Direcao Geral das Autarquias Locais (DGAL) on December 14, 2022, and the websites were scanned on December 22, 2022. The results of this assessment reveal that around 97% of city council websites use RSA as their encryption algorithm and around 84% use 2048-bit length keys for digital certificate signing. Furthermore, about 53% of the city council websites are still supporting outdated and potentially insecure SSL/TLS versions, and around 95% of the councils are not implementing DNSSEC in their domains. These results highlight potential areas for improvement in cybersecurity measures and can serve as a baseline to track progress toward improving cybersecurity maturity in Portuguese city councils.

2023

An Analysis of Infractions and Fines in the Context of the GDPR

Autores
Dias, JC; Martins, A; Pinto, P;

Publicação
INTERNATIONAL JOURNAL OF MARKETING COMMUNICATION AND NEW MEDIA

Abstract
The General Data Protection Regulation (GDPR) is the regulation that determines the directives inherent to the collection, processing, and protection of personal data in European Union (EU) countries. It was implemented in May 2018 and over the past few years, several public and private companies have been affected by serious penalties. With more than 1500 fines already registered, it is important to have an analysis and insights about them. This paper proposes a detailed analysis of the public records of fines under GDPR, understanding the average fines imposed, the main causes for their application and how they have evolved over time. It is also intended to understand the most affected sectors and point ways to mitigate these penalties. It is concluded that fines under GDPR have an increasing trend over time, both in number of fines and in value, with Industry and Commerce & Media, Telecoms and Broadcasting being the most affected sectors.

2023

Prototyping the IDS Security Components in the Context of Industry 4.0 - A Textile and Clothing Industry Case Study

Autores
Torres, N; Chaves, A; Toscano, C; Pinto, P;

Publicação
Communications in Computer and Information Science

Abstract
With the introduction of Industry 4.0 technological concepts, suppliers and manufacturers envision new or improved products and services, cost reductions, and productivity gains. In this context, data exchanges between companies in the same or different activity sectors are necessary, while assuring data security and sovereignty. Thus, it is crucial to select and implement adequate standards which enable the interconnection requirements between companies and also feature security by design. The International Data Spaces (IDS) is a current standard that provides data sharing through data spaces mainly composed of homogeneous rules, certified data providers/consumers, and reliability between partners. Implementing IDS in sectors such as textile and clothing is expected to open new opportunities and challenges. This paper proposes a prototype for the IDS Security Components in the Textile and Clothing Industry context. This prototype assures data sovereignty and enables the interactions required by all participants in this supply chain industry using secure communications. The adoption of IDS as a base model in this activity sector fosters productive collaboration, lowers entry barriers for business partnerships, and enables an innovation environment. © 2023, The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd.

2023

Mapping and embedding infrastructure resource management in software defined networks

Autores
Javadpour, A; Ja'fari, F; Pinto, P; Zhang, WZ;

Publicação
CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS

Abstract
Software-Defined Networking (SDN) is one of the promising and effective approaches to establishing network virtualization by providing a central controller to monitor network bandwidth and transmission devices. This paper studies resource allocation in SDN by mapping virtual networks on the infrastructure network. Considering mapping as a way to distribute tasks through the network, proper mapping methodologies will directly influence the efficiency of infrastructure resource management. Our proposed method is called Effective Initial Mapping in SDN (EIMSDN), and it suggests writing a module in the controller to initialize mapping by arriving at a new request if a sufficient number of resources are available. This would prevent rewriting the rules on the switches when remapping is necessary for an n-time window. We have also considered optimizing resource allocation in network virtualization with dynamic infrastructure resources management. We have done it by writing a module in OpenFlow controller to initialize mapping when there are sufficient resources. EIMSDN is compared with SDN-nR, SSPSM, and SDN-VN in criteria such as acceptance rates, cost, average switches resource utilization, and average link resource utilization.

  • 85
  • 407