The Experts below are selected from a list of 76863 Experts worldwide ranked by ideXlab platform
Marco Vieira - One of the best experts on this subject based on the ideXlab platform.
-
trustworthiness assessment of web applications approach and experimental study using input validation coding practices
International Symposium on Software Reliability Engineering, 2019Co-Authors: Cristiano Inacio Lemes, Vincent Naessens, Marco VieiraAbstract:The popularity of web applications and their world-wide use to support business critical operations raised the interest of hackers on exploiting Security vulnerabilities to perform malicious operations. Fostering trust calls for assessment techniques that provide indicators about the quality of a web application from a Security Perspective. This paper studies the problem of using coding practices to characterize the trustworthiness of web applications from a Security Perspective. The hypothesis is that applying feasible Security practices results in applications having a reduced number of unknown vulnerabilities, and can therefore be considered more trustworthy. The proposed approach is instantiated for the concrete case of input validation practices, and includes a Quality Model to compute trustworthiness scores that can be used to compare different applications or different code elements in the same application. Experimental results show that the higher scores are obtained for more secure code, suggesting that it can be used in practice to characterize trustworthiness, also providing guidance to compare and/or improve the Security of web applications.
-
ISSRE - Trustworthiness Assessment of Web Applications: Approach and Experimental Study using Input Validation Coding Practices
2019 IEEE 30th International Symposium on Software Reliability Engineering (ISSRE), 2019Co-Authors: Cristiano Inacio Lemes, Vincent Naessens, Marco VieiraAbstract:The popularity of web applications and their world-wide use to support business critical operations raised the interest of hackers on exploiting Security vulnerabilities to perform malicious operations. Fostering trust calls for assessment techniques that provide indicators about the quality of a web application from a Security Perspective. This paper studies the problem of using coding practices to characterize the trustworthiness of web applications from a Security Perspective. The hypothesis is that applying feasible Security practices results in applications having a reduced number of unknown vulnerabilities, and can therefore be considered more trustworthy. The proposed approach is instantiated for the concrete case of input validation practices, and includes a Quality Model to compute trustworthiness scores that can be used to compare different applications or different code elements in the same application. Experimental results show that the higher scores are obtained for more secure code, suggesting that it can be used in practice to characterize trustworthiness, also providing guidance to compare and/or improve the Security of web applications.
Cristiano Inacio Lemes - One of the best experts on this subject based on the ideXlab platform.
-
trustworthiness assessment of web applications approach and experimental study using input validation coding practices
International Symposium on Software Reliability Engineering, 2019Co-Authors: Cristiano Inacio Lemes, Vincent Naessens, Marco VieiraAbstract:The popularity of web applications and their world-wide use to support business critical operations raised the interest of hackers on exploiting Security vulnerabilities to perform malicious operations. Fostering trust calls for assessment techniques that provide indicators about the quality of a web application from a Security Perspective. This paper studies the problem of using coding practices to characterize the trustworthiness of web applications from a Security Perspective. The hypothesis is that applying feasible Security practices results in applications having a reduced number of unknown vulnerabilities, and can therefore be considered more trustworthy. The proposed approach is instantiated for the concrete case of input validation practices, and includes a Quality Model to compute trustworthiness scores that can be used to compare different applications or different code elements in the same application. Experimental results show that the higher scores are obtained for more secure code, suggesting that it can be used in practice to characterize trustworthiness, also providing guidance to compare and/or improve the Security of web applications.
-
ISSRE - Trustworthiness Assessment of Web Applications: Approach and Experimental Study using Input Validation Coding Practices
2019 IEEE 30th International Symposium on Software Reliability Engineering (ISSRE), 2019Co-Authors: Cristiano Inacio Lemes, Vincent Naessens, Marco VieiraAbstract:The popularity of web applications and their world-wide use to support business critical operations raised the interest of hackers on exploiting Security vulnerabilities to perform malicious operations. Fostering trust calls for assessment techniques that provide indicators about the quality of a web application from a Security Perspective. This paper studies the problem of using coding practices to characterize the trustworthiness of web applications from a Security Perspective. The hypothesis is that applying feasible Security practices results in applications having a reduced number of unknown vulnerabilities, and can therefore be considered more trustworthy. The proposed approach is instantiated for the concrete case of input validation practices, and includes a Quality Model to compute trustworthiness scores that can be used to compare different applications or different code elements in the same application. Experimental results show that the higher scores are obtained for more secure code, suggesting that it can be used in practice to characterize trustworthiness, also providing guidance to compare and/or improve the Security of web applications.
Rui Zhang - One of the best experts on this subject based on the ideXlab platform.
-
safeguarding wireless network with uavs a physical layer Security Perspective
IEEE Wireless Communications, 2019Co-Authors: Weidong Mei, Rui ZhangAbstract:Integrating unmanned aerial vehicles (UAVs) into future wireless systems such as the fifth-generation cellular network is anticipated to bring significant benefits for both the UAV and telecommunication industries. Generally speaking, UAVs can be used as new aerial platforms in the cellular network to provide communication services for terrestrial users, or become new aerial users of the cellular network served by the terrestrial base stations. Due to their high altitude, UAVs usually have dominant line-ofsight channels with the ground nodes, which, however, pose new Security challenges to future wireless networks with widely deployed UAVs. On one hand, UAV-ground communications are more prone than terrestrial communications to eavesdropping and jamming attacks by malicious nodes on the ground. On the other hand, compared to malicious ground nodes, malicious UAVs can launch more effective eavesdropping and jamming attacks to terrestrial communications. Motivated by the above, in this article, we aim to identify such new issues from a physical-layer Security viewpoint and present novel solutions to tackle them efficiently. Numerical results are provided to validate their effectiveness, and promising directions for future research are also discussed.
-
safeguarding wireless network with uavs a physical layer Security Perspective
arXiv: Information Theory, 2019Co-Authors: Weidong Mei, Rui ZhangAbstract:Integrating unmanned aerial vehicles (UAVs) into future wireless systems such as the fifth-generation (5G) cellular network is anticipated to bring significant benefits for both UAV and telecommunication industries. Generally speaking, UAVs can be used as new aerial platforms in the cellular network to provide communication services for terrestrial users, or become new aerial users of the cellular network served by the terrestrial base stations. Due to their high altitude, UAVs usually have dominant line-of-sight (LoS) channels with the ground nodes, which, however, pose new Security challenges to future wireless networks with widely deployed UAVs. On one hand, UAV-ground communications are more prone than terrestrial communications to eavesdropping and jamming attacks by malicious nodes on the ground. On the other hand, compared to malicious ground nodes, malicious UAVs can launch more effective eavesdropping and jamming attacks to terrestrial communications. Motivated by the above, in this article, we aim to identify such new issues from a physical-layer Security viewpoint and propose novel solutions to tackle them efficiently. Numerical results are provided to validate their effectiveness and promising directions for future research are also discussed.
Vincent Naessens - One of the best experts on this subject based on the ideXlab platform.
-
trustworthiness assessment of web applications approach and experimental study using input validation coding practices
International Symposium on Software Reliability Engineering, 2019Co-Authors: Cristiano Inacio Lemes, Vincent Naessens, Marco VieiraAbstract:The popularity of web applications and their world-wide use to support business critical operations raised the interest of hackers on exploiting Security vulnerabilities to perform malicious operations. Fostering trust calls for assessment techniques that provide indicators about the quality of a web application from a Security Perspective. This paper studies the problem of using coding practices to characterize the trustworthiness of web applications from a Security Perspective. The hypothesis is that applying feasible Security practices results in applications having a reduced number of unknown vulnerabilities, and can therefore be considered more trustworthy. The proposed approach is instantiated for the concrete case of input validation practices, and includes a Quality Model to compute trustworthiness scores that can be used to compare different applications or different code elements in the same application. Experimental results show that the higher scores are obtained for more secure code, suggesting that it can be used in practice to characterize trustworthiness, also providing guidance to compare and/or improve the Security of web applications.
-
ISSRE - Trustworthiness Assessment of Web Applications: Approach and Experimental Study using Input Validation Coding Practices
2019 IEEE 30th International Symposium on Software Reliability Engineering (ISSRE), 2019Co-Authors: Cristiano Inacio Lemes, Vincent Naessens, Marco VieiraAbstract:The popularity of web applications and their world-wide use to support business critical operations raised the interest of hackers on exploiting Security vulnerabilities to perform malicious operations. Fostering trust calls for assessment techniques that provide indicators about the quality of a web application from a Security Perspective. This paper studies the problem of using coding practices to characterize the trustworthiness of web applications from a Security Perspective. The hypothesis is that applying feasible Security practices results in applications having a reduced number of unknown vulnerabilities, and can therefore be considered more trustworthy. The proposed approach is instantiated for the concrete case of input validation practices, and includes a Quality Model to compute trustworthiness scores that can be used to compare different applications or different code elements in the same application. Experimental results show that the higher scores are obtained for more secure code, suggesting that it can be used in practice to characterize trustworthiness, also providing guidance to compare and/or improve the Security of web applications.
Weidong Mei - One of the best experts on this subject based on the ideXlab platform.
-
safeguarding wireless network with uavs a physical layer Security Perspective
IEEE Wireless Communications, 2019Co-Authors: Weidong Mei, Rui ZhangAbstract:Integrating unmanned aerial vehicles (UAVs) into future wireless systems such as the fifth-generation cellular network is anticipated to bring significant benefits for both the UAV and telecommunication industries. Generally speaking, UAVs can be used as new aerial platforms in the cellular network to provide communication services for terrestrial users, or become new aerial users of the cellular network served by the terrestrial base stations. Due to their high altitude, UAVs usually have dominant line-ofsight channels with the ground nodes, which, however, pose new Security challenges to future wireless networks with widely deployed UAVs. On one hand, UAV-ground communications are more prone than terrestrial communications to eavesdropping and jamming attacks by malicious nodes on the ground. On the other hand, compared to malicious ground nodes, malicious UAVs can launch more effective eavesdropping and jamming attacks to terrestrial communications. Motivated by the above, in this article, we aim to identify such new issues from a physical-layer Security viewpoint and present novel solutions to tackle them efficiently. Numerical results are provided to validate their effectiveness, and promising directions for future research are also discussed.
-
safeguarding wireless network with uavs a physical layer Security Perspective
arXiv: Information Theory, 2019Co-Authors: Weidong Mei, Rui ZhangAbstract:Integrating unmanned aerial vehicles (UAVs) into future wireless systems such as the fifth-generation (5G) cellular network is anticipated to bring significant benefits for both UAV and telecommunication industries. Generally speaking, UAVs can be used as new aerial platforms in the cellular network to provide communication services for terrestrial users, or become new aerial users of the cellular network served by the terrestrial base stations. Due to their high altitude, UAVs usually have dominant line-of-sight (LoS) channels with the ground nodes, which, however, pose new Security challenges to future wireless networks with widely deployed UAVs. On one hand, UAV-ground communications are more prone than terrestrial communications to eavesdropping and jamming attacks by malicious nodes on the ground. On the other hand, compared to malicious ground nodes, malicious UAVs can launch more effective eavesdropping and jamming attacks to terrestrial communications. Motivated by the above, in this article, we aim to identify such new issues from a physical-layer Security viewpoint and propose novel solutions to tackle them efficiently. Numerical results are provided to validate their effectiveness and promising directions for future research are also discussed.