The Experts below are selected from a list of 783 Experts worldwide ranked by ideXlab platform

Zahradník Jiří - One of the best experts on this subject based on the ideXlab platform.

  • Vulnerabilities assessment for industrial protocols
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2020
    Co-Authors: Zahradník Jiří
    Abstract:

    Práce simuluje vybrané zranitelnosti standardu IEC 61850 a následně řeší mitigační opatření pro zvolené zranitelnosti. Autor simuloval zranitelnosti protokolu GOOSE, útok na NTP a útok na MMS klienta. Konkrétně se jedná o GOOSE stNum, GOOSE semantic, GOOSE test bit, GOOSE replay, GOOSE flood, NTP spoofing a MMS Password Capture. Útoky na protokoly GOOSE a MMS byly úspěšné, útok na NTP byl pouze částečně úspěšný, kdy došlo k potvrzení přijatého času, ale ne k jeho převzetí. Autor následně navrhnul možná mitigační opatření. Byl také vytvořen automatizační nástroj pro testování daných zranitelností, parser pro protokol GOOSE a přenositelný parser konfiguračních souborů.Výsledky práce umožňují implementovat rozsáhlejší nástroj pro penetrační testování prů-myslových sítí, stejně jako umožňují implementovat daná mitigační opatření.Thesis deals with testing of selected vulnerabilities from the IEC 61850 standard and following design of mitigation measures for selected vulnerabilities. Author simulated vulnerabilities of the GOOSE protocol, NTP attack and attack ona MMS client. Those attacks were GOOSE stNum, GOOSE semantic, GOOSE test bit,GOOSE replay, GOOSE flood, NTP spoofing and MMS Password Capture. Attacks on protocols GOOSE and MMS were successful, attack on NTP was only partially successful since the device confirmed receiving spoofed time, however it did not change it’s inner clock. Author then designed possible mitigation measures. Tool for automatic testing of selected vulnerabilities, parser for the GOOSE protocol and lightweight multiplatform parser for configuration files were created as well.The outcome of this thesis allows the implementation of lager scale tool for penetration testing of industrial networks as well as it allows implementation of discussed mitigation measures.

  • Vulnerabilities assessment for industrial protocols
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2020
    Co-Authors: Zahradník Jiří
    Abstract:

    Thesis deals with testing of selected vulnerabilities from the IEC 61850 standard and following design of mitigation measures for selected vulnerabilities. Author simulated vulnerabilities of the GOOSE protocol, NTP attack and attack ona MMS client. Those attacks were GOOSE stNum, GOOSE semantic, GOOSE test bit,GOOSE replay, GOOSE flood, NTP spoofing and MMS Password Capture. Attacks on protocols GOOSE and MMS were successful, attack on NTP was only partially successful since the device confirmed receiving spoofed time, however it did not change it’s inner clock. Author then designed possible mitigation measures. Tool for automatic testing of selected vulnerabilities, parser for the GOOSE protocol and lightweight multiplatform parser for configuration files were created as well.The outcome of this thesis allows the implementation of lager scale tool for penetration testing of industrial networks as well as it allows implementation of discussed mitigation measures

Navi Mumbai Maharashtra - One of the best experts on this subject based on the ideXlab platform.

  • Usability and Security of Recognition based Graphical Password Scheme
    2016
    Co-Authors: Pranita Binnar, Navi Mumbai Maharashtra
    Abstract:

    Authentication is the first line of defense against compromising confidentiality and integrity. People can remember pictures better and for longer periods than alphanumeric Passwords. All graphical Passwords have two different aspects which are usability and security. Woefully none of these schemes were being able to fulfill both of these aspects at the same time. We analyze the known attack method and categorize them into two kinds Attack by Password Space and Attack by Password Capture. In this paper we summarized the usability and security reported in some user‟s studies of recognition based graphical Password schemes. Finally some suggestion were give

Pranita Binnar - One of the best experts on this subject based on the ideXlab platform.

  • Usability and Security of Recognition based Graphical Password Scheme
    2016
    Co-Authors: Pranita Binnar, Navi Mumbai Maharashtra
    Abstract:

    Authentication is the first line of defense against compromising confidentiality and integrity. People can remember pictures better and for longer periods than alphanumeric Passwords. All graphical Passwords have two different aspects which are usability and security. Woefully none of these schemes were being able to fulfill both of these aspects at the same time. We analyze the known attack method and categorize them into two kinds Attack by Password Space and Attack by Password Capture. In this paper we summarized the usability and security reported in some user‟s studies of recognition based graphical Password schemes. Finally some suggestion were give