302 resultados para Vulnerabilities
Resumo:
Esta tesis se centra en el análisis de dos aspectos complementarios de la ciberdelincuencia (es decir, el crimen perpetrado a través de la red para ganar dinero). Estos dos aspectos son las máquinas infectadas utilizadas para obtener beneficios económicos de la delincuencia a través de diferentes acciones (como por ejemplo, clickfraud, DDoS, correo no deseado) y la infraestructura de servidores utilizados para gestionar estas máquinas (por ejemplo, C & C, servidores explotadores, servidores de monetización, redirectores). En la primera parte se investiga la exposición a las amenazas de los ordenadores victimas. Para realizar este análisis hemos utilizado los metadatos contenidos en WINE-BR conjunto de datos de Symantec. Este conjunto de datos contiene metadatos de instalación de ficheros ejecutables (por ejemplo, hash del fichero, su editor, fecha de instalación, nombre del fichero, la versión del fichero) proveniente de 8,4 millones de usuarios de Windows. Hemos asociado estos metadatos con las vulnerabilidades en el National Vulnerability Database (NVD) y en el Opens Sourced Vulnerability Database (OSVDB) con el fin de realizar un seguimiento de la decadencia de la vulnerabilidad en el tiempo y observar la rapidez de los usuarios a remiendar sus sistemas y, por tanto, su exposición a posibles ataques. Hemos identificado 3 factores que pueden influir en la actividad de parches de ordenadores victimas: código compartido, el tipo de usuario, exploits. Presentamos 2 nuevos ataques contra el código compartido y un análisis de cómo el conocimiento usuarios y la disponibilidad de exploit influyen en la actividad de aplicación de parches. Para las 80 vulnerabilidades en nuestra base de datos que afectan código compartido entre dos aplicaciones, el tiempo entre el parche libera en las diferentes aplicaciones es hasta 118 das (con una mediana de 11 das) En la segunda parte se proponen nuevas técnicas de sondeo activos para detectar y analizar las infraestructuras de servidores maliciosos. Aprovechamos técnicas de sondaje activo, para detectar servidores maliciosos en el internet. Empezamos con el análisis y la detección de operaciones de servidores explotadores. Como una operación identificamos los servidores que son controlados por las mismas personas y, posiblemente, participan en la misma campaña de infección. Hemos analizado un total de 500 servidores explotadores durante un período de 1 año, donde 2/3 de las operaciones tenían un único servidor y 1/2 por varios servidores. Hemos desarrollado la técnica para detectar servidores explotadores a diferentes tipologías de servidores, (por ejemplo, C & C, servidores de monetización, redirectores) y hemos logrado escala de Internet de sondeo para las distintas categorías de servidores maliciosos. Estas nuevas técnicas se han incorporado en una nueva herramienta llamada CyberProbe. Para detectar estos servidores hemos desarrollado una novedosa técnica llamada Adversarial Fingerprint Generation, que es una metodología para generar un modelo único de solicitud-respuesta para identificar la familia de servidores (es decir, el tipo y la operación que el servidor apartenece). A partir de una fichero de malware y un servidor activo de una determinada familia, CyberProbe puede generar un fingerprint válido para detectar todos los servidores vivos de esa familia. Hemos realizado 11 exploraciones en todo el Internet detectando 151 servidores maliciosos, de estos 151 servidores 75% son desconocidos a bases de datos publicas de servidores maliciosos. Otra cuestión que se plantea mientras se hace la detección de servidores maliciosos es que algunos de estos servidores podrán estar ocultos detrás de un proxy inverso silente. Para identificar la prevalencia de esta configuración de red y mejorar el capacidades de CyberProbe hemos desarrollado RevProbe una nueva herramienta a través del aprovechamiento de leakages en la configuración de la Web proxies inversa puede detectar proxies inversos. RevProbe identifica que el 16% de direcciones IP maliciosas activas analizadas corresponden a proxies inversos, que el 92% de ellos son silenciosos en comparación con 55% para los proxies inversos benignos, y que son utilizado principalmente para equilibrio de carga a través de múltiples servidores. ABSTRACT In this dissertation we investigate two fundamental aspects of cybercrime: the infection of machines used to monetize the crime and the malicious server infrastructures that are used to manage the infected machines. In the first part of this dissertation, we analyze how fast software vendors apply patches to secure client applications, identifying shared code as an important factor in patch deployment. Shared code is code present in multiple programs. When a vulnerability affects shared code the usual linear vulnerability life cycle is not anymore effective to describe how the patch deployment takes place. In this work we show which are the consequences of shared code vulnerabilities and we demonstrate two novel attacks that can be used to exploit this condition. In the second part of this dissertation we analyze malicious server infrastructures, our contributions are: a technique to cluster exploit server operations, a tool named CyberProbe to perform large scale detection of different malicious servers categories, and RevProbe a tool that detects silent reverse proxies. We start by identifying exploit server operations, that are, exploit servers managed by the same people. We investigate a total of 500 exploit servers over a period of more 13 months. We have collected malware from these servers and all the metadata related to the communication with the servers. Thanks to this metadata we have extracted different features to group together servers managed by the same entity (i.e., exploit server operation), we have discovered that 2/3 of the operations have a single server while 1/3 have multiple servers. Next, we present CyberProbe a tool that detects different malicious server types through a novel technique called adversarial fingerprint generation (AFG). The idea behind CyberProbe’s AFG is to run some piece of malware and observe its network communication towards malicious servers. Then it replays this communication to the malicious server and outputs a fingerprint (i.e. a port selection function, a probe generation function and a signature generation function). Once the fingerprint is generated CyberProbe scans the Internet with the fingerprint and finds all the servers of a given family. We have performed a total of 11 Internet wide scans finding 151 new servers starting with 15 seed servers. This gives to CyberProbe a 10 times amplification factor. Moreover we have compared CyberProbe with existing blacklists on the internet finding that only 40% of the server detected by CyberProbe were listed. To enhance the capabilities of CyberProbe we have developed RevProbe, a reverse proxy detection tool that can be integrated with CyberProbe to allow precise detection of silent reverse proxies used to hide malicious servers. RevProbe leverages leakage based detection techniques to detect if a malicious server is hidden behind a silent reverse proxy and the infrastructure of servers behind it. At the core of RevProbe is the analysis of differences in the traffic by interacting with a remote server.
Resumo:
The crisis has forced the Euro area to establish an emergency fund that supports member states experiencing a sovereign debt crisis. The difficulties of coming up with such a fund for Greece and other Euro area members stands in marked contrast to the balance of payments support that non-Euro members like Hungary received, swiftly and quietly. In order to solve this puzzle, we first establish the difference between EU interventions and IMF programs and, second, trace the evolution of crisis management with France and Germany in the lead. The lens of hegemonic stability theory suggests that the Franco-German leadership is too weak to provide stability and the extensive use of conditionality is one symptom of this weakness. Providing incentives for cooperation "after hegemony" (Keohane) is the unresolved issues troubling the monetary union. Its dominant powers must acknowledge that markets perceive monetary union to be already politically more integrated than its lack of fiscal integration suggests.
Resumo:
Shipping list no.: 2000-0249-P.
Resumo:
No abstract available.
Resumo:
This thesis presents security issues and vulnerabilities in home and small office local area networks that can be used in cyber-attacks. There is previous research done on single vulnerabilities and attack vectors, but not many papers present full scale attack examples towards LAN. First this thesis categorizes different security threads and later in the paper methods to launch the attacks are shown by example. Offensive security and penetration testing is used as research methods in this thesis. As a result of this thesis an attack is conducted using vulnerabilities in WLAN, ARP protocol, browser as well as methods of social engineering. In the end reverse shell access is gained to the target machine. Ready-made tools are used in the attack and their inner workings are described. Prevention methods are presented towards the attacks in the end of the thesis.
Resumo:
2009
Resumo:
Security defects are common in large software systems because of their size and complexity. Although efficient development processes, testing, and maintenance policies are applied to software systems, there are still a large number of vulnerabilities that can remain, despite these measures. Some vulnerabilities stay in a system from one release to the next one because they cannot be easily reproduced through testing. These vulnerabilities endanger the security of the systems. We propose vulnerability classification and prediction frameworks based on vulnerability reproducibility. The frameworks are effective to identify the types and locations of vulnerabilities in the earlier stage, and improve the security of software in the next versions (referred to as releases). We expand an existing concept of software bug classification to vulnerability classification (easily reproducible and hard to reproduce) to develop a classification framework for differentiating between these vulnerabilities based on code fixes and textual reports. We then investigate the potential correlations between the vulnerability categories and the classical software metrics and some other runtime environmental factors of reproducibility to develop a vulnerability prediction framework. The classification and prediction frameworks help developers adopt corresponding mitigation or elimination actions and develop appropriate test cases. Also, the vulnerability prediction framework is of great help for security experts focus their effort on the top-ranked vulnerability-prone files. As a result, the frameworks decrease the number of attacks that exploit security vulnerabilities in the next versions of the software. To build the classification and prediction frameworks, different machine learning techniques (C4.5 Decision Tree, Random Forest, Logistic Regression, and Naive Bayes) are employed. The effectiveness of the proposed frameworks is assessed based on collected software security defects of Mozilla Firefox.
Resumo:
Water is now considered the most important but vulnerable resource in the Mediterranean region. Nev ertheless, irrigation expanded fast in the region (e.g. South Portugal and Spain) to mitigate environmental stress and to guarantee stable grape yield and quality. Sustainable wine production depends on sustain able water use in the wine’s supply chain, from the vine to the bottle. Better understanding of grapevine stress physiology (e.g. water relations, temperature regulation, water use efficiency), more robust crop monitoring/phenotyping and implementation of best water management practices will help to mitigate climate effects and will enable significant water savings in the vineyard and winery. In this paper, we focused on the major vulnerabilities and opportunities of South European Mediterranean viticulture (e.g. in Portugal and Spain) and present a multi-level strategy (from plant to the consumer) to overcome region’s weaknesses and support strategies for adaptation to water scarcity, promote sustainable water use and minimize the environmental impact of the sector.
Resumo:
Water is now considered the most important but vulnerable resource in the Mediterranean region. Nevertheless, irrigation expanded fast in the region (e.g. South Portugal and Spain) to mitigate environmental stress and to guarantee stable grape yield and quality. Sustainable wine production depends on sustainable water use in the wine’s supply chain, from the vine to the bottle. Better understanding of grapevine stress physiology (e.g. water relations, temperature regulation, water use efficiency), more robust crop monitoring/phenotyping and implementation of best water management practices will help to mitigate climate effects and will enable significant water savings in the vineyard and winery. In this paper, we focused on the major vulnerabilities and opportunities of South European Mediterranean viticulture (e.g. in Portugal and Spain) and present a multi-level strategy (from plant to the consumer) to overcome region’s weaknesses and support strategies for adaptation to water scarcity, promote sustainable water use and minimize the environmental impact of the sector.
The bubbles or the boiling pot?: an ecosystemic approach to culture, environment and quality of life
Resumo:
For the diagnosis and prognosis of the problems of quality of life, a multidisciplinary ecosystemic approach encompasses four dimensions of being-in-the-world, as donors and recipients: intimate, interactive, social and biophysical. Social, cultural and environmental vulnerabilities are understood and dealt with, in different circumstances of space and time, as the conjugated effect of all dimensions of being-in-the-world, as they induce the events (deficits and assets), cope with consequences (desired or undesired) and contribute for change. Instead of fragmented and reduced representations of reality, diagnosis and prognosis of cultural, educational, environmental and health problems considers the connections (assets) and ruptures (deficits) between the different dimensions, providing a planning model to develop and evaluate research, teaching programmes, public policies and field projects. The methodology is participatory, experiential and reflexive; heuristic-hermeneutic processes unveil cultural and epistemic paradigms that orient subject-object relationships; giving people the opportunity to reflect on their own realities, engage in new experiences and find new ways to live better in a better world. The proposal is a creative model for thought and practice, providing many opportunities for discussion, debate and development of holistic projects integrating different scientific domains (social sciences, psychology, education, philosophy, etc.)
Resumo:
This article provides a preliminary assessment of the agroterrorism threat to Australia. Based on primary research conducted among Australia's biotechnology and agriculture sectors, it examines current threat scenarios and existing vulnerabilities within Australia. It argues that the threat of agroterrorism to Australia is real, and, for prudential reasons, should be taken more seriously by government authorities. The article concludes with a series of broad policy options to mitigate the threat of agroterrorism to Australia.
Resumo:
The impacts of climate change in the potential distribution and relative abundance of a C3 shrubby vine, Cryptostegia grandiflora, were investigated using the CLIMEX modelling package. Based upon its current naturalised distribution, C. grandiflora appears to occupy only a small fraction of its potential distribution in Australia under current climatic conditions; mostly in apparently sub-optimal habitat. The potential distribution of C. grandiflora is sensitive towards changes in climate and atmospheric chemistry in the expected range of this century, particularly those that result in increased temperature and water use efficiency. Climate change is likely to increase the potential distribution and abundance of the plant, further increasing the area at risk of invasion, and threatening the viability of current control strategies markedly. By identifying areas at risk of invasion, and vulnerabilities of control strategies, this analysis demonstrates the utility of climate models for providing information suitable to help formulate large-scale, long-term strategic plans for controlling biotic invasions. The effects of climate change upon the potential distribution of C. grandiflora are sufficiently great that strategic control plans for biotic invasions should routinely include their consideration. Whilst the effect of climate change upon the efficacy of introduced biological control agents remain unknown, their possible effect in the potential distribution of C. grandiflora will likely depend not only upon their effects on the population dynamics of C. grandiflora, but also on the gradient of climatic suitability adjacent to each segment of the range boundary.
Resumo:
O artigo analisa a estrat??gia implementada em 2006 e 2007 pelo Programa Bolsa Fam??lia (PBF) para a articula????o de programas complementares ??s transfer??ncias condicionadas de renda, enfatizando sua contribui????o para o enfrentamento da desigualdade e da exclus??o social no Brasil, e apresenta resultados preliminares alcan??ados por alguns destes programas executados em n??vel federal. A articula????o de programas complementares possibilita o reconhecimento de necessidades de grupos populacionais em situa????o de risco social e promove a oferta de a????es espec??ficas para as suas necessidades, para uma inclus??o cidad?? diferenciada. A estrat??gia implementada em 2006 e 2007 foi caracterizada pela intersetorialidade e transversalidade e a cria????o de um espa??o prop??cio para o desenvolvimento de inova????es no campo das pol??ticas sociais. Apesar do car??ter recente dos programas complementares e das dificuldades de monitoramento, os resultados obtidos em programas federais e o comprometimento dos governos municipais na articula????o de programas municipais demonstram que essa pode ser uma op????o na agenda das pol??ticas sociais dos tr??s n??veis de governo no Brasil.
Resumo:
ABSTRACTThis paper reports an empirical case study on the interface between microfinance and climate change actions. Climate change, which until recently seemed a luxury for the microfinance sector, now appears to be crucial for its future. For their low adaptive capacity, the millions of microfinance clients worldwide happen to be the most vulnerable to a changing climate. However, such an arena is still blurred from an academic viewpoint, and inexistent among Brazilian academia. Therefore, by investigating Brazil’s largest rural MFI, Agroamigo, we aim at providing an empirical contribution to green microfinance. The main conclusion is that, albeit Agroamigo offers important links to climate change initiatives, it will need to take better account of specific vulnerabilities and risks to protect its portfolio and clients better from climate change impacts.