Showing posts with label Computer Application open access journals. Show all posts
Showing posts with label Computer Application open access journals. Show all posts

Wednesday, 27 April 2022

Lupine Publishers| Detecting Distributed Denial-of-Service DDoS Attacks

 Lupine Publishers| Journal Computer Sciences & Applications



Abstract

Since the number of damage cases resulting from distributed denial-of-service (DDoS) attacks has recently been increasing, the need for agile detection and appropriate response mechanisms against DDoS attacks has also been increasing. The latest DDoS attack has the property of swift propagation speed and various attack patterns. There is therefore a need to create a lighter mechanism to detect and respond to such new and transformed types of attacks with greater speed. In a wireless network system, the security is a main concern for a user.

Introduction

Security of information is of utmost importance to organization striving to survive in a competitive marketplace. Network security has been an issue since computer networks became prevalent, most especially now that internet is changing the face of computing. As dependency on Internet increases on daily basis for business transaction, so also is cyber-attacks by intruder who exploit flaws in Internet architecture, protocol, operating systems and application software to carry out their nefarious activities Such hosts can be compromised within a short time to run arbitrary and potentially malicious attack code transported in a worm or virus or injected through installed backdoors. Distributed denial of service (DDoS) use such poorly secured hosts as attack platform and cause degradation and interruption of Internet services, which result in major financial losses, especially if commercial servers are affected (Duberdorfer, 2004).

Related Works

Brignoli et al. [1] proposed DDoS detection based on traffic selfsimilarity estimation, this approach is a relatively new approach which is built on the notion that undisturbed network traffic displays fractal like properties. These fractal-like properties are known to degrade in presence of abnormal traffic conditions like DDoS. Detection is possible by observing the changes in the level of self-similarity in the traffic flow at the target of the attack. Existing literature assumes that DDoS traffic lacks the self-similar properties of undisturbed traffic. The researcher shows how existing bot- nets could be used to generate a self-similar traffic flow and thus break such assumptions. Streilien et al,2005. Worked on detection of DoS attacks through the polling of Remote Monitoring (RMON) capable devices. The researchers developed a detection algorithm for simulated flood-based DoS attacks that achieves a high detection rate and low false alarm rate.

Yeonhee Lee [2] focused on a scalability issue of the anomaly detection and introduced a Hadoop based DDoS detection scheme to detect multiple attacks from a huge volume of traffic. Different from other single host-based approaches trying to enhance memory efficiency or to customize process complexity, our method leverages Hadoop to solve the scalability issue by parallel data processing. From experiments, we show that a simple counterbased DDoS attack detection method could be easily implemented in Hadoop and shows its performance gain of using multiple nodes in parallel. It is expected that a signature-based approach could be well suited with Hadoop. However, we need to tackle a problem to develop a real time defense system, because the current Hadoop is oriented to batch processing.

Proposed System Architecture of Intrusion Detection Based on Association Rule

The structure of the proposed architecture for real time detection of Dos instruction detection via association rule mining, it is divided into two phases: learning and testing. The network sniffer processed the tcpdump binary into standard format putting into learning, during the learning phase, duplicate records as well as columns with single same data were expunge from the record so as to reduce operational. Another table Hashmap was created by the classification model to keep track of the count of various likely classmark that can match the current read network traffic, this table will be discarded once the classmark with highest count had been selected. Depicted in Table 1 is the Association rule classifier algorithm (Tables 2-4).

Table 1: Association Rule Mining Classifier Algorithm.

Lupinepublishers-openaccess-computer-sciences-journal

Table 2: Sample Rules.

Lupinepublishers-openaccess-computer-sciences-journal

Table 3: Sampled number combination table.

Lupinepublishers-openaccess-computer-sciences-journal

Table 4: Sample Network Traffic Data.

Lupinepublishers-openaccess-computer-sciences-journal

System Implementation

This chapter presents implementation of Association rule classifier model, documentation of the designed system and the user interfaces. The software and hardware requirement needed for the system and also the testing of the system for verification and validation of functions, as well as the result [3-10].

Read More About  Lupine Publishers Journal of Computer Sciences and Applications Please Click on Below Link: https://computer-sciences-lupine-publishers.blogspot.com/

Tuesday, 26 April 2022

Lupine Publishers| Mini Overview of Key Issues in Routing for OSPF MANETs

 Lupine Publishers| Computer Sciences & Applications



Abstract

Open Shortest Path First (OSPF) is a well known and prominent Internet Protocol (IP) for network routing. By deploying a link state routing (LSR) algorithm OSPF comes under the category of interior gateway routing protocols. In today’s wireless ad hoc Internet, the current routing domain needs to maintain a peak level of service accessibility and availability, thus OSPF must be extended to the wireless ad hoc network for maximizing routing performance in the network by taking into account key routing issues, i.e., optimal Hello Interval, efficient flooding schemes, optimizing the traffic engineering related issues, optimum adjacency creations, connectivity factors, reducing control overhead, and QoS and security challenges. In addition, OSPF is very effective in its adoption of handling the network bandwidth utilization, therefore, wireless capacity planning is of utmost importance for today’s Internet with the possible presence of wireless infrastructure. Improving routing stability in OSPF MANET under topology change(s) due to variation in link connectivity becomes a very demanding challenge for the research community. Given a fascinating volume of review for literature and unavoidable importance relating to OSPF extension to MANETs, there has still persist a need to highlight key issues related with routing in OSPF MANET.

Keywords: MANETs; Routing; OSPF; Traffic Engineering; Connectivity Factors; Capacity Planning; Flooding Schemes

Introduction

Open Shortest Path First (OSPF) is a very well-known and prominent interior gateway protocol (responsible for routing) in the today’s Internet [1]. The routing functionality of such protocols can be seen within the domain, which can be, but not necessarily, is part of or contained within an autonomous system (AS). OSPF as part of the routing protocol comes under the group of link state routing protocol, which generally allows every router present in the network to learn about the complete network topology [2]. However, in order to achieve maximum routing performance, it is now for almost more than 3 decades that the Internet protocols for link state routing has been deployed in the Internet on the regular basis. When we go back in history, the first major and functional link state routing protocol was deployed in the year 1978, called the Shortest Path First (SPF) by replacing the popular distance vector approach in ARPANET at that time.

The OSPF Protocol is now being used by the Internet Service Providers (ISPs) for almost more than 25 years as a link state routing functionality in providing the Internet infrastructure. The maximum years of experience running with the OSPF Protocol and its wide spread deployment has put a lot of confidence in using it as a reliable and stable link state routing and has demanded and motivated the researchers from all over the world to put in the efforts to create room for further improvements and enhancements in its application for extending its operation to wireless ad hoc media in MANETs. As a matter of fact, the quality of service (QoS) requirements and the attributes of the routing infrastructures in MANETs is a demanding challenge as the network topology is frequently changing due to mobility [3,4].

The objective function of the OSPF-MANET Protocol is to provide highly scalable routing functionality and more flexible and robust operation on complex and highly dense networks. The prime concern in today 0 s wireless media is to somehow keep in limit the bandwidth processing requirements of the protocol while recovering from the network failure (Speed of Convergence) in the network topology is the prime concern [3,5]. Whenever there is a triggered event in the OSPF-MANET domain, in such case the protocol may typically required a few tens of seconds for recovering from any sort of router/link failure (network failure). During this ephemeral state, the network quality of service availability would go through a serious degradation or deterioration or in other cases there may be a complete breakdown of the network.

With the establishment of real time operations for certain applications over the Internet, (e.g. online video con-ferencing) or networked voice over IP from almost a previous decade, network service deterioration/ disruption for applications with quick response time, a few tens of seconds (network recovery time) can no more be permitted or accepted. The need to quickly recover from the failure has motivated the research community to present the possible scenarios to improve the OSPF Speed of Convergence and also to provide other proactive approaches and strategies for protecting the network traffic in the interim process [6]. One of the critical and important requirements for the today0 s routing infrastructure has highlighted the need of maximizing routing performance in response to the topology change.

Significantly, reducing the bandwidth/processing requirement of the Internet routing protocol persuades to be the crucial framework as before. As the OSPF protocol being distributed in nature, it incorporates the within limit execution of the certain operations like processing and generation of the Hello packets by the active routers taking part in it [7]. It is important to mention here that the routers may not be highly overloaded, so that it may continuously decline to do/perform these critical network resource management operations. Such failures may contribute to the network failure and eventually result in the complete shutdown of the entire network. Hence, a novel scheme, refereed to as multi point relay (MPR) based MANET is introduced to tackle this issue, as presented in (Figure 1).

Figure 1: MPR based MANET extension. .

Lupinepublishers-openaccess-computer-sciences-journal

Conventionally, OSPF routing protocol has been employed as the network framework including a wired connectivity by exhibiting the largely static regional network topology. However, in the recent times routing infrastructure incor-porates the wireless components of the network too. These chunk subsist of either mobile or static network devices, possibly going out or coming in of each other’s mobile wireless range, or a hodgepodge of both. An illustration/ case of such kind of network can be classified as wireless, mobile ad hoc networks (MANETs) of objects where some objects exhibits mobile wireless connections with one or more conventional wired network(s) running under OSPF routing protocol. In a pragmatic scenario, lots of routing protocols have been devised to operate for the MANET, by using the selected routing protocol for MANET environment; the complex exchange process is required in such case while going through a transition step for the routing information of OSPF between this protocol and the other protocol that is targeted. In such situation, the exchange process might not evade/shun path for sub optimality. In such compelling situations, there is a high demand to enhance routing protocol in MANETs for OSPF domain by providing routing functionality and to intelligently assimilate the wireless and the wired peripherals of a network in the routing world.

This argument presented above incorporates a view of multiple proposals to enhance OSPF for its operation on MANETs. Researches for the last 2 decades have proposed multiple optimized OSPF routing protocols for MANET by suggesting the reduced number of re-transmissions, which are redundant in nature while disseminating a broadcast message throughout the entire network and, thus efficiently reducing the computational overhead of the active control traffic. This proposal eventually enhance the main characteristics of maximizing routing performance by highlighting the precise demands of the MANET networking. A few of those techniques out of the mentioned proposal present in the paper may be applied to the wireless network and has the capability to significantly improving both the Convergence speed and the Scalability factor of the OSPF networks having wireless connectivity.

Introduction to Routing in MANETs

Mobile ad hoc Networks (MANETs), which are also called Mesh Networks, are characterized by the way in which nodes are placed in such a manner that give pathways to data to be routed from the user to the desired destination. In the event that one of the intermediate node were to come up short (e.g. that user leaves the range), the system will naturally reconfigure itself, locating a substitute way from the user to the router [3,6]. Normally, all accessible nodes additionally arrange users, each sharing the aggregate data exchange limit (total capacity) of the operational hardware and operating protocol being incorporated. The network could likewise associate users to different routers straightforwardly, as would be done in a modern control and monitoring network. Since there is no requirement for central organization of the network setup, it is most proficient to outline the framework for independent operation of each node. In a modern domain, a circumstance, for example, an alert would be engendered through the network and reached directly by each node. Each node would be customized to react as per its specific requirement machine control, handle observing, supervisory work force or central office.

MANETs decide their arrangement periodically under topology change in the network. Every node identify the nodes that are accessible for communications, on the basis of signal strength, which is essentially identified with separation between nodes, but on the other hand is influenced by interference or obstructions [8]. A nodes may be remote, others might be perceptible yet have insufficient signal strength for reliable communications. Once the accessible nodes are distinguished, this information is communicated to different nodes, along network topology regarding the desired destination. Incorporating the network configuration algorithms, the system setup calculations to choose a specific route for every user to its destination. This procedure requires system operating software to have better decision making algorithms in light of pragmatic criteria for signal strength, reliability of path over time, and configuration parameters for network [9]. After some time, or even close persistently, the network will change. Users may go back and forth, nodes might be in motion, or changes in the electromagnetic environment may modify the spread between nodes. As these progressions occur, the network will overhaul its design and distinguish new paths from users to destinations [3,8]. This kind of reconfiguration will be rehashed again and again as the network changes. It is important to mention here that this is a similar procedure being incorporated on part of the Internet, where system loading and other hardware issues require redirection of user’s information through different routers [2].

The key advantages of ad hoc network includes autonomy from central administration of network, self-arranging, nodes behave as routers, self-healing through nonstop re-arrangement, scalabilitymake room for the expansion of more nodes and flexibility-like having the capability to get to the Internet from various different areas. While MANETs are normally utilized where they have the best accentuation on its advantages, there are a few confinements: Every node must have full execution, throughput is influenced by system loading, reliability requires an adequate number of accessible nodes. Finally, sparse networks can have routing issues [10].

Large networks can have inordinate latency (time delay), which influences a few applications. Some of these restric-tions additionally apply to traditional hub-and-spoke based networks (like OSPF) or can’t be tended to/by interchange setups. For instance, all networks are influenced by system loading, and networks with couple of nodes are hard to legitimize in hard-wired arrangements [5]. Wireless local area network (W-LAN) is the underlying application that got a deliberate advancement exertion. Shared networks of PC/PDA users have become familiar in this regard. Commercial wireless Internet service providers (WISP) incorporate repeater nodes to extend to large coverage area, while user nodes can extend service in their local area. Control systems (e.g. natural controls) and industrial monitoring of different processes and control are getting to be significant applications for mesh networking. These environments are hard to present with devoted wiring, being spread over a vast area, frequently with troublesome access.

Key Issues with OSPF MANETs

Some of the important issues regarding MANETs are security, routing, hidden terminal problem, bandwidth, power limitation and corroboration of mobile devices. Safeguarding the data communication in MANETs is one of the key aspect to be addressed. It is important to mention here that MANETs are highly dynamic in nature where topology changes, for instance the link breakage happens quite frequently [5,9]. Thus, we need a security mechanism which is dynamic in nature too. Some of the important security requirements of MANETs are certain discovery, isolation of the in-appropriate nodes and some location policy regarding node location and network structure. From security aspect of MANETs, there are basically two types of attacks on the network, i.e., active attack which inserts arbitrary packets and attempts to disrupt the network operation and passive attack which do not disrupt the network operation [7,11]. Another important aspect regarding security in MANETs is that each node in the network relies upon the other nodes to forward the data packets while during communication. Hence, before communication in MANETs one must tackle efficiently with the presented issues.

Routing in Wireless Adhoc Networking

The no presence of fixed infrastructure in MANETs creates certain demanding challenges and difficulties. The biggest challenge among them is routing. Routing is the method of selecting paths in a network along which data need to be communicated to the desired destination through nodes [1,9]. An ad hoc network is a tradition, or standard, routing protocol that controls how routers choose which way to route the data packets between source(s) and destination(s) in MANETs. In MANETs, nodes don’t begin acquainted with the topology of their networks; rather, they need to find it [6,7]. The fundamental thought is that a new node may declare its presence and ought to listen for various announcements broad-casted by its neighbors. In the process each nodes learns about near-by nodes and how to reach them and may announce that it can get to that node as well. The routing procedure normally follows forwarding on the basis of routing tables which keep up a record of route(s) to different network destinations [2,5]. In this way, building routing tables, which are held in the memory of router, is critical for effective routing.

The development of laptops and 802.11/Wi-Fi wireless networking administration has made MANETs a famous look into point since the 1990s. Numerous academic papers assess protocols and capabilities expecting fluctuating degrees of mobility inside a bounded space, more often than not with all nodes inside a couple of hops from each other and typically with nodes sending information at a constant rate. Multiple protocols are then evaluated in view of the packet drop rate, expected routing load, expected end-toend- delay, and other different measures [3,11]. The proposed techniques for routing protocols could be gathered in to three classes: proactive (or table-driven), reactive (or on-request) and hybrid protocols. Indeed, even the reactive protocols have turned into the standard for MANET routing.

MANETs are suited for use in circumstances where network infrastructure is either not accessible on the other hand not trusted. For example, a communication network for military officers in a field, a mobile network of smart phones in a meeting or campus setting, temporary workplaces in a crusade home office, biological research in wireless sensor networks, mobile social networks like Facebook, My-Space and Twitter, and mobile mesh networks for Wi-Fi devices [8,10]. The main challenges in MANETs are taking advantage of wireless mesh nodes to build a robust backbone network for interconnecting all mesh nodes, and probably some external gateways to/from the Internet. Describing a class of MANET routing protocols that, by taking advantage of network backbone can sort out the best path(s) for traffic engineering by solving the Multi Commodity Flow (MCF) problem inside the network to/from the Internet and supporting dynamic user topology and mobility among wireless mesh networks [11]. These challenges are mainly centered on the major areas like, MANETs application scenarios, communication protocols, hardware and software requirements and QoS based optimization techniques.

Read More About  Lupine Publishers Journal of Computer Sciences and Applications Please Click on Below Link: https://computer-sciences-lupine-publishers.blogspot.com/

Wednesday, 19 January 2022

Lupine Publishers| Numerical Solution of Boundary Layer Flow of Viscous Fluid Via Successive Linearization Method

Lupine Publishers| Journal of Computer Sciences & Applications



Abstract

The aim of this work is to obtain the numerical solutions for the boundary layer flow of heat transfer of incompressible viscous fluid. The governing partial differential equations are converted into ordinary differential equation by using a similarity transformation. The nonlinear equation governing the flow problem is modeled and then solved numerically by means of a successive linearization method (SLM). The numerical results are derived in tables for comparisons. The important result of this comparison is to show the high precision of the SLM in solving system of nonlinear differential equations. Graphical outcomes of various parameters such as Prandtl number (Pr) and Eckert number (Ec) on the flow, field are discussed and analyzed. Besides this the present results have been tested and compared with the available published results in a limiting manner and an excellent agreement is found.

Keywords: Viscous fluid; Successive linearization; Boundary layer

Introduction

In the recent years, a great deal of interest has been gained to fluids applications. Some fluids not easy to expressed by particular constitutive relationship between shear rates and stress and which is totally different than the viscous fluids [1,2]. These fluids including many home items namely, toiletries, paints, cosmetics certain oils, shampoo, jams, soups etc. have different features and are denoted by non-Newtonian fluids. In general, the categorization of non-Newtonian fluid models is given under three class which are named the integral, differential, and rate types [3-6]. In the present study, the main interest is to discuss the heat transfer flow of hydrodynamic viscous fluid over a flat plate in a uniform stream of fluid with dissipation effect. The most phenomena in the field of engineering and science that occur is nonlinear. With this nonlinearity the equations become more difficult to handle and solve. Some of these nonlinear equations can be solved by using approximate analytical methods such as Homotopy analysis method (HAM) proposed by liao S [7,8], Homotopy Perturbation method (HPM) it was found by Ji-Huan [9] and Adomain decomposition method (ADM) Q Esmaili et al. [10], Makinde OD et al. [11] and Makinde OD [12].

However, some of these equations are solved via traditional numerical techniques such as finite difference method,shooting method and Keller box method, Runge-Kutta. Recently some studies have presented a new method called Successive Linearization Method (SLM). This method has been applied successfully in many nonlinear problems in sciences and engineering, such as the MHD flows of non- Newtonian fluids and heat transfer over a stretching sheet [13], viscoelastic squeezing flow between two parallel plates [14], two dimensional laminar flow between two moving porous walls [15] and convective heat transfer for boundary layer with pressure gradient [16,17]. Therefore, the effectiveness, validity, accuracy and flexibility of the SLM are verified among of all these successful applications. Presently a new investigation on the heat transfer flow of hydrodynamic viscous fluid over a flat plate in a uniform stream of fluid with dissipation effect is discussed. The numerical solution to the resulting nonlinear problem is computed by using the SLM approach. The embedded flow parameters are discussed and illustrated graphically.

Mathematical formulation of the problem

The governing equations are

Lupinepublishers-openaccess-computer-sciences-journal

where (u,v ) are the components of velocity in (x , y) directions, the kinematic viscosity T is temperature of fluid, the thermal diffusivity

k the fluid thermal conductivity, ρc the fluid capacity heat and cp the specific heat. The relevant boundary conditions are defined as

Lupinepublishers-openaccess-computer-sciences-journal

Where , Tw T are constants. Introducing the following dimensionless variables

Lupinepublishers-openaccess-computer-sciences-journal

Utilizing equation (6), equation (1) is satisfied automatically and equations (2) and (3) characterize to the following problems statement

Lupinepublishers-openaccess-computer-sciences-journal

The related boundary conditions

Lupinepublishers-openaccess-computer-sciences-journal

Solution of the problem

Here successive linearization method (SLM) [14-16] is implemented to obtain the numerical solutions for nonlinear system (8) and (10) corresponding to the boundary condition Eq. (11) – (13) (Table 1). The convergence for numerical values of f "(0) and −θ '(0) for different order of approximation when Ec = 0.01, Pr =1 and n =1.00 (Table 1).

Table 1: The convergence for numerical values of f "(0) and −θ '(0) for different order of approximation when Ec=0.01, Pr 1 and 1.00 Ec n=1.00.

Lupinepublishers-openaccess-computer-sciences-journal

The numerical values of f (η ) and f '(η )when, n =1, Pr =1 for Ec= 0.01. (Table 2).

Table 2: The numerical values of f (η ) and f '(η ) when, n =1, Pr =1 for Ec = 0.01.

Lupinepublishers-openaccess-computer-sciences-journal

The numerical values of θ (η ) and −θ '(η )when, n =1, Pr =1 for Ec =0.01 (Table 3).

Table 3: The numerical values of θ (η ) and −θ '(η ) when, n =1, Pr =1 for Ec =0.01.

Lupinepublishers-openaccess-computer-sciences-journal

Comparison of numerical values of f (η ) with Ref: [16] when, n= Ec = 0, Pr =1 (Table 4).

Table 4: Comparison of numerical values of f (η ) with Ref: [16] when, n= Ec = 0, Pr =1.

Lupinepublishers-openaccess-computer-sciences-journal

This section concerns with the graphical illustrations obtained by using successive linearization method for velocity, temperature profiles. These profiles show the variations of embedded flow parameters in the solution expressions for heat transfer analysis for an incompressible viscous fluid. The physical interpretation of the problem has been discussed in Figures 1 – 4. These figures are plotted in order to illustrate such variations. Here the graphs have been determined for the heat transfer flow of steady Newtonian fluid. Figures 1 & 2 shows the effects of the parameter on the velocity profile for f '(η ) and θ (η ) when Ec, Pr are fixed. It is worth noticing that by increasing the parameter η reveals that buoyancy because of augments of gravity which boosts on the velocity. Figure 3 is sketched for the variation of Prandtl number Pr on θ (η ) . It is noted that for lager Pr ,the thermal field is lower and then this reduce the temperature. In fact law Prandtl number Pr assist fluid with higher thermal conductivity and this create thicker thermal boundary layer than that for lager Pr. Finally, Figure 4 shows the effect of Ec on velocity and temperature profiles over the plate, and we note that by increasing in Ec parameter is seen that the effect is very big for the temperature.

Figure 1: Effects of n and f '(η ) .

Lupinepublishers-openaccess-computer-sciences-journal

Figure 2: Effects of n and θ (η ) .

Lupinepublishers-openaccess-computer-sciences-journal

Figure 3: Effects of Ec for θ (η ) .

Lupinepublishers-openaccess-computer-sciences-journal

Figure 4: Effects of Pr for θ (η ) .

Lupinepublishers-openaccess-computer-sciences-journal

Conclusion

In this research, the problem of heat transfer of an incompressible viscous fluid over flat pate is solved numerically. The numerical solutions are well established by SLM. The influence of various parameters is shown through different graphs. The present results have been tested and compared with the available published results in [16], in a limiting situation shown in tables v and an excellent agreement is found [17].

Read More About Lupine Publishers Journal of Computer Sciences & Applications Please Click on Below Link https://computer-sciences-lupine-publishers.blogspot.com/

Tuesday, 14 December 2021

Lupine Publishers| Mitigating Disaster using Secure Threshold-Cloud Architecture

 Lupine Publishers| Journal of Computer Sciences & Applications



Abstract

There are many risks in moving data into public cloud environments, along with an increasing threat around large-scale data leakage during cloud outages. This work aims to apply secret sharing methods as used in cryptography to create shares of cryptographic key, disperse and recover the key when needed in a multi-cloud environment. It also aims to prove that the combination of secret sharing scheme and multi-clouds can be used to provide a new direction in disaster management by using it to mitigate cloud outages rather than current designs of recovery after the outages. Experiments were performed using ten different cloud services providers at share policies of 2 from 5, 3 from 5, 4 from 5, 4 from 10, 6 from 10 and 8 from 10 for which at different times of cloud outages key recovery were still possible and even faster compared to normal situations. All the same, key recovery was impossible when the number of cloud outages exceeded secret sharing defined threshold. To ameliorate this scenario, we opined a resilient system using the concept of self-organization as proposed by Nojoumian et al in 2012 in improving resource availability but with some modifications to the original concept. The proposed architecture is as presented in our Poster: Improving Resilience in Multi-Cloud Architecture.

Keywords: Secret Shares; Disaster Mitigation; Thresholds Scheme; Cloud Service Providers

Introduction

With the introduction of cloud services for disaster management on a scalable rate, there appears to be the needed succour by small business owners to get a cheaper and more secure disaster recovery mechanism to provide business continuity and remain competitive with other large businesses. But that is not to be so, as cloud outages became a nightmare. Recent statistics by Ponemon Institute [1] on Cost of Data Centre Outages, shows an increasing rate of 38% from $505,502 in 2010 to $740,357 as at January 2016. Using activity-based costing they were able to capture direct and indirect cost to: Damage to mission-critical data; Impact of downtime on organizational productivity; Damages to equipment and other assets and so on. The statistics were derived from 63 data centres based in the United States of America. These events may have encouraged the adoption of multi-cloud services so as to divert customers traffic in the event of cloud outage. Some finegrained proposed solutions on these are focused on Redundancy and Backup such as: Local Backup by [2]; Geographical Redundancy and Backup [3]; The use of Inter-Private Cloud Storage [4]; Resource Management for data recovery in storage clouds [5], and so on. But in all these, cloud service providers see disaster recovery as a way of getting the system back online and making data available after a service disruption, and not on contending disaster by providing robustness that is capable of mitigating shocks and losses resulting from these disasters.

This work aims to apply secret sharing methods as used in cryptography [6,7] to create shares of cryptographic key, disperse and recover the key when needed in a multi-cloud environment. It also aims to prove that the combination of secret sharing scheme and multi-clouds can be used to provide a new direction in disaster management by using it to mitigate cloud outages rather than current deigns of recovery after the outages. Experiments were performed using ten different cloud services providers for storage services, which at different times of cloud outages, key recovery were still possible and even faster compared to normal situations. All the same, key recovery was impossible when the number of cloud outages exceeded secret sharing defined threshold. To ameliorate this scenario, we look forward to employ the concept of self-organisation as proposed by Nojoumian et al. [8] in improving resource availability but with some modifications as proposed. The rest of the work is organised into section II, Literature Review takes a closer look at current practices, use of secret sharing and cloudbased disaster recovery with much interest in the method used in design. III. Presents our approach, in section IV, present Results and Evaluations and Conclude in section V with future works and lessons learnt.

Literature Review

There are research solutions based on different variants of secret sharing schemes and multi-cloud architecture that give credence to its resilience in the face of failures, data security in keyless manner, such as: Ukwandu et al. [9] - RESCUE: Resilient Secret Sharing Cloud-based Architecture; Alsolami & Boult, [10], - CloudStash: Using Secret-Sharing Scheme to Secure Data, Not Keys, in Multi-Clouds. Others are: Fabian et al. [11] on Collaborative and secure sharing of healthcare data in multi-clouds and [12] on Secret Sharing for Health Data in Multi-Provider Clouds. While RESCUE provided an architecture for a resilient cloud-based storage with keyless data security capabilities using secret sharing scheme for data splitting, storage and recovery, Cloud Stash also relied on the above strengths to prove security of data using secret sharing schemes in a multi-cloud environment and Fabian et al proved resilience and robust sharing in the use of secret sharing scheme in a multi-cloud environment for data sharing. Because our approach is combining secret sharing and multi-clouds in developing a clouddisaster management the need therefore arise to review current method used in cloud-based disaster in a multi-cloud system and their shortcomings.

a) Remus: Cully et al. [13] described a system that provides software resilience in the face of hardware failure (VMs) in such a manner that an active system at such a time can continue execution on an alternative physical host while preserving the host configurations by using speculative execution. The strength lies on the preservation of system’s software independently during hardware failure.

b) Second Site: As proposed by Rajagopalan et al. [14] is built to extend the Remus high-availability system based on virtualization infrastructure by allowing very large VMs to be replicated across many data centres over the networks using internet. One main aim of this solution is to increase the availability of VMs across networks. Like every other DR systems discussed above, Second Site is not focused on contending downtime and security of data during cloud outages.

c) DR-Cloud: Yu et al. [15] relied on data backup and restore technology to build a system proposed to provide high data reliability, low backup cost and short recovery time using multiple optimisation scheduling as strategies. The system is built of multicloud architecture using Cumulus [16] as cloud storage interface. Thus providing the need for further studies on the elimination of system downtime during disaster, provide consistent data availability as there is no provision for such in this work.

Our Approach

Our approach is in combining secret sharing scheme with multi-clouds to achieve resilience with the aim of applying same in redefining cloud-based disaster management from recovery from cloud outages to mitigating cloud outages.

The Architecture

The architecture of as shown in Figure 1 shows key share creation, dispersal and storage, while that of Figures 2 & 3 is of shares retrieval and key recovery

Figure 1: Key Share Creation, Dispersal and Storage.

Lupinepublishers-openaccess-computer-sciences-journal

Figure 2: Share Retrievals and Key Recovery.

Lupinepublishers-openaccess-computer-sciences-journal

Figure 3: Cloud Service Providers at Different Scenarios.

Lupinepublishers-openaccess-computer-sciences-journal

Share creation and Secret recovery: The diagram above explains our design of key share creation, dispersal and storage using different cloud service providers (Figure 1). Share Creation: The dealer determines the number of hosts shares combination from which data recovery is possible known as threshold (t) and the degree of the polynomial, drived from subtracting 1 from the threshold. In this case, the threshold is 3 and the degree of polynomial is 2. He initiates a secret sharing scheme by generating the polynomial, the coefficients a and b are random values and c is the secret, the constant term of the polynomial as well as the intercept of the graph. He generates 5 shares for all the hosts H1… H5 and sends the shares to them for in an equal ratio and weights we, and thereafter leaves the scene [1].

Secret Recovery: Just as in Shamir [6] authorised participants following earlier stated rules are able to recover the secret using Lagrangian interpolation once the condition as stated earlier is met. The participants contribute their shares to recover the secret.

Results and Evaluations

Test: Cloud Outages against Normal situations. This test assumes that cloud outage prevents secret recovery.

Discussions

The results above show that cloud outage has no negative effect on key recovery, rather reduces the overhead in comparison with normal situations. It shows the relationship between cloud outage and normal operational conditions. From available results at twenty percent (20%) failure rate using 3 from 5 share policy, the system becomes faster by sixteen percent (16.41%), but at forty percent (40%) failure rate using same share policy, the download speed is faster by a little above fifty one percent (51.80%). Looking at a higher share policy of 6 from 10, at thirty percent (30%) failure rate, the system download speed is higher by a little above thirtyseven percent (37.90%), while at forty percent (40%) failure rate, the system performed better by about forty-three percent (42.99%). The implications therefore are that in as much as failure rate is not equivalent or above the threshold, system performance improves as there was no result obtained when the cloud outage exceeds or equal to threshold. These therefore do not support the assumption as above that cloud outage has negative effect in key recovery. There is no significant evidence to show that the size of the share has effect on the key recovery during cloud outages because at forty percent (40%) failure rate using share of 10KB in 3 from 5 shows performance rate of above fifty-one percent while in 6 from 10 share policy approximately forty-three (42.99%) percent performance rate.

Conclusions, Lessons Learnt and Future Work

Current cloud-based disaster recovery systems have focused on faster recovery after an outage and the underlying issue has been the method applied, which centered in data backup and replicating the backed-up data to several hosts. This method has proved some major delays in providing a strong failover protection as there has to be a switch from one end to another during disaster in order to bring systems back online, the need thus arises for research to focus on method capable of mitigating this interruption by providing strong failover protection as well as stability during adverse failures to keep systems running. This method we have provided here using this paper. Because, secret sharing schemes are keyless method of encryption, data at rest and in transit are safe as it exists in meaningless format.

The recovery of key is done using system memory and share verification is usually carried out using an inbuilt share checksum mechanism using SHA-512, which validates shares before recovery. Else, share recovery returns error and halts. We have learnt that cloud outage rather than prevent key recovery, using our method proved that it hastens key recovery from results available. Also, understand that when cloud outage exceeds threshold of the share policy, key recovery becomes impossible and to ameliorate this situation, we propose as future work to use the concept of Self- Organization as proposed by Nojoumian et al. [8] to manage cloud resources though with some modifications so as to maintain share availability from cloud service providers.

Read More About Lupine Publishers Journal of Computer Science and Applications Please Click on Below Link: https://computer-sciences-lupine-publishers.blogspot.com/

Monday, 26 July 2021

Lupine Publishers| Mini View on Current Trends in Computer Sciences & Applications

 Lupine Publishers| Current Trends in Computer Sciences & Applications (CTCSA)

 


Abstract

Computer science has contributed a lot for making the life of human being smooth. The recent developments in the field of computer science are proven to be more smarter and more applicable structures result from marrying the learning capability of the applications with the transparency and accuracy. Foundations of computer science applications highlights the advantages of integration making it a valuable resource for the students and researchers in engineering, computer science and applied mathematics. The authors’ tried to lime light various applications that are an asset to industrial practitioners, corporates, academicians and professionals for control systems, data analysis and optimization tasks. With the continuous improvisation in the computer science applications the need of the young generation is fulfilled, and they can achieve their targets with the help of updated and enhanced support system. Authors are highlighting on current trends in computer sciences & applications and further illustrate how these various technologies integrate with social and economic factors to provide a thorough solution to the real-world problems of the human being in every domain of life.

The authors demonstrated how a combination of both techniques and human interventions enhances control, decision-making and data analysis systems.

Keywords: Computer; Trends; VLSI Technology; Multiprocessor; Parallelism; Configurable Computing; DSP; Internet

Introduction

Although the very state forward answer for the latest trends in Computer science could be Machine learning, cloud computing and Artificial Intelligence. But basically, Industry build the software not only with what is new but by what customer problem can be solve easily and with good future scope and current market trends which covers customer requirements, this force towards innovation and create next generation products that can be quickly adopted for solving new use cases by Connecting to new data sources easily.

Top technologies which are in current trends in computer science & Application are as below:

A. Deep learning or Machine learning (ML).

B. Digital currencies: Example Bitcoin

C. Blockchain.

D. IoT

E. Robotics

F. Big Data Analytics.

G. Cloud Computing

H. Cyber Security

I. Virtual Reality

J. Predictive Analytics

The emerging areas that are seeking attention of many researchers in the field of computer science are designed and developed according to the latest market trends. Now a day trends in information technologies are directly or indirectly associated with the customer centric approach. One of the latest technology like computational biology where in the gathering and processing of biological data with the use of computer programs. This technology covers under Bio Informatics, which works with the combination of computers and living beings. It converts the biological data into readable format. This is helping the medical science a lot. Another most promising technology of today is Data Science or Big Data. This field has a very large and promising scope of research and development considering the huge volume of data being produced by organizations and individually in different sectors worldwide. It deals with the storage processing and analysing the massive data stored across the world in various organization and data centres.

The existence of newest trend of Virtual Reality cannot be ignored. The biggest stakeholders of VR applications are medical science, physical sciences, environment, businesses, space industry and entertainment industry. VR produces the set of the data which is used to develop new models training methods, communications and interaction. The major disadvantages in the use of VR application are time, cost and technological limitations. But because of its support system it is expected to become more affordable in future, today’s generation is grown up having technology at their disposal. They are familiar with smart phones, tablets therefore VR Developments will also increase in number of professionals more acquainted with the technology. Cloud Computing has already become the area of attention by most of the researcher and scientists. Cloud provider is basically data or internet provider. This plays an important role in various fields of business, computing security etc. This application works on the shared pools of configurable computer system recourses and higher-level services that ease the managerial effort with leads to economics of scale and development. It helps in running business more efficiently.

Cloud computing eliminates the capital expenses of buying hardware and software along with other related expenses. Business has become very flexible as cloud computing services are available on demand that leads to delivering right amount of IT resources resulting in scale elasticity. Lots of ‘Racking and Stacking’ task is being eliminated as cloud computing removes the needs for many of these tasks resulting in more time devotion towards more important business goals. Cloud computing services run on a worldwide network regularly upgraded data centres. This reduces network latency for application and improvises efficient computing hardware. It also helps in providing security to the data, apps from potential threats. However, several types of cloud computing is operational to help offer right solution for your needs like public, private and hybrid.

Deep Learning or Machine Learning is sub set of artificial intelligence and in today’s trends it’s one of most widely used computer science application, the ability of ML is to self-trend from data or able to learn from its own experiences, which can improve from application behaviour or experience without being explicitly programmed. Machine learning focuses on the development of computer programs that can access data and use it learn for themselves.

I. Example:

A good example can be a Navigation system or MAP application which initially developed with limited data but later on when this application gets used its design in a way so it trained itself to predict the best possible path.

Google search, uber, Pay Pal, Facebook are the good example of ML and these actually improving the usability of their services by applying deep learning algorithms. Below is the comparative example where one sector is using Machin learning and takin its benefits and other one is moving very slowly in digital and it’s far behind (Figure 1). Machine learning can help banks, insurers, and investors make smarter decisions in a number of different areas:

Figure 1:

Lupinepublishers-openaccess-computer-sciences-journal

a) Customer and Client Satisfaction: Machine learning helps financial services on below key points.

i. By analysing user activity.

ii. Smart machines can spot a potential account closure before it occurs.

b) Reacting to Market Trends: Another aspect can be cover by using a good ML algorithm which is generating the alerts or by preserving the trained to track trading volatility or manage wealth and assets on behalf of an investor.

c) Calculating Risk: Good ML algorithms can analyse datasets and based on the dataset (credit scores, spending patterns, financial data etc.) to accurately assess risk in both insurance underwriting and loan assessments, tailoring them to a specific customer profile.

Conclusion

Trends in Computer Sciences & Applications changed drastically the life of one and all. Be it a student learning or business corporate or any other professional, computer science and its applications are extending their updated support system to give more effective performance infrastructure in every sphere. Recent developments gives acceleration to the development of a Digital currency or digital money introduction in the form of digital, Blockchain a digital ledger in which transactions made in cryptocurrency. The contribution is endless and so the developments in this field are boundless.

Read More About Lupine Publishers Current Trends in Computer Sciences & Applications (CTCSA)  Please Click on Below Link:  https://computer-sciences-lupine-publishers.blogspot.com/




Monday, 10 May 2021

Lupine Publishers| Self-Payment Fraud Detection on Automated Teller Machine

 Lupine Publishers| Current Trends in Computer Sciences & Applications (CTCSA)


Abstract

Over the past decade the amount of transactions and reported frauds on Automated Teller Machines (ATM) has significantly increased. Various types of frauds have been reported around misusing ATM cards and many methods have been deployed to detect and prevent them. In some countries, banks sell ATMs to investors under predefined circumstances and pay them in commission in order to increase the availability of the service but some ATM owners have been found to create fake transactions to obtain extra commissions. This paper attempts to detect such frauds using a two-stage method. In the first stage fraudulent customers are detected by certain rules and in the second stage their accomplices are identified using transaction loop and cycle detection algorithm. Transactions of an Iranian bank have been used to evaluate the proposed method and all detected fraudsters by system were confirmed by bank fraud detection office.

Keywords: Fraud Detection; Cycle Detection; ATM Fraud Detection; Data warehouse

Introduction

Using credit and ATM cards for different purposes, such as buying services and products, has become one of prevalent methods in digital economy [1]. These cards help people buy anything without carrying cash and facing its risks. ATM cards also help buyers pay their product and service fees with minimum details of invoice. Effectively many customers use these cards instead of cash. Using ATMs for paying bills, transferring money, buying cell phone charges, viewing transactions list, and many other services causes customers to prefer doing their affairs without the need to be at bank, and banks benefit from these services through customer retention and higher cash flow. They can also use their human resources for other tasks and gain more productivity or alternatively reduce their staff to decrease their expenses. To increase customer satisfaction and liquidity, banks try to promote their services in cities. For this purpose they provide ATMs to investors under special conditions: if an investor can prepare required security and communication infrastructure banks allow them to buy ATM. The business model between bank and investors let banks to pay some percent of daily ATM transactions as commission to ATM owners.

Although ATM cards provide many advantages and services for customers and banks they are very susceptible to fraud. The significant number of ATM transactions compared to other payment methods has made them a worthy target for fraud [2]. This leads card issuers and beneficiaries to try to detect and confront ATM frauds. There are many methods proposed to detect frauds, which are presented in Figure 1. Due to Anderson classification on frauds there are eight classes of fraud [3]. In this classification ATM fraud is a subcategory in “Technologies ATM &Internet” category which can be further categorized into [4]

Figure 1: Types of Fraud.

Lupinepublishers-openaccess-computer-sciences-journal

Physical Attacks

Attacker tries to move or damage ATM device physically.

Gaining ATM User’s Banking Information

There are many methods for gaining ATM users information. Attacker tries to attach illegal objects to ATM in order to capture card data and password, card password is stolen using different methods such as looking over the shoulders of ATM users and etc.

Financial Transactions Made by Inappropriate Methods or Users

Inappropriate methods or users consist of many items like using stolen cards by fraudsters and using forged notes in ATM environments, etc.

Self-Payment Attack

Unlike other mentioned types of fraud, which are related to a third party, frauds can also be conducted by ATM owners to obtain more commission. This is known as self-payment attack. Due to bank business model the more transaction amount ATM has, more commission is paid to its owner. This is the main reason for creating fake transactions by some ATM owners. In this paper a novel method is proposed to detect self-payment frauds on ATMs. In this method the fraudsters are identified using rules obtained by experts. Then transactional networks of these customers are built and by extracting loops in these networks, other users who collaborated in the fraud are extracted. Using this method in an Iranian bank many fraudsters were identified. The rest of the paper is organized as follows. In the next section, definitions and related studies are reviewed briefly. Then in section 3, the proposed method is described with details. Result of this proposed method on the practical data of Iranian bank transactions is presented and discussed in section 4. Finally, the conclusion and some other hints for future works are described in section 5.

Related Works and Definitions

In this section related studies about ATM fraud detection along cycle detection algorithm, which is used in this paper, are explained.

ATM Fraud Detection

Extensive research has been carried out to prevent these crimes, which can be divided into three categories [4]. Detection of physical damage on ATM, prevention of ATM banking user’s information and prevent financial transaction made by inappropriate users and methods. For detecting physical attacks motion sensors are used to detect the suspicion activities around ATMs [5]. Also, in [6] mentioned three ways to overcome physical attack of ATMs: the certification level of the ATM safe, using alarm and sensors to detect physical attacks and at last using ink stain technology that will mark and effectively make any removed money unusable. There are methods to detect illegal objects, such as cameras and card reproducers, attached to ATM [7]. Also, in [8] proposed a system to detect criminal objects attached to ATM like cameras that could read the users’ password. To prevent password theft in [9] diversifies password entering methods to avoid another people looking from behind of user. In [8] a system developed which warn user when loiterers are behind the customer. To detect and prevent financial transactions made by inappropriate methods or users there are methods such as card holder identification via biometrics [6,10,11], forged note detection in ATM environment [6,9] and recording facial images of ATM users [5,12,13].

Eft Switch

Figure 2: EFT switch architecture.

Lupinepublishers-openaccess-computer-sciences-journal

Electronic banking architecture in many banks is as following Figure 2. The standard is used for financial transaction is ISO8583. This standard has three versions and they are related to 1987,1993 and 2003. Messages in this standard have 128 fields containing transaction information such as Amount, Date, Time, Device code, Function code, Process code etc. So, all devices on bank network have to be compatible with ISO8583 and they have to send and receive message with this format. For more information see [14]. As it is shown in Figure 3 each transaction is done by a device which is sent to its controller. After verifying message’s security and content, the transaction is sent to Channel manager. In addition to control payment channels this switch controls content and security of sent messages. After verifying messages by channel manager, they are sent to central EFT switch of bank. At central EFT switch if card is issued by other banks message is sent to Intra bank electronic message network, otherwise it is sent to Core banking system. The response is then provided to the customer.

Figure 3: Transfer loop.

Lupinepublishers-openaccess-computer-sciences-journal

Self-Payment Fraud

As mentioned before, some banks sell their ATMs to investors under predefined conditions. They pay some percent of transactions done by ATMs to the owner as commission. Unfortunately, some ATM owners make fake transactions for increasing their obtained profits, which is called self-payment fraud. For instance, suppose that there are four people with ATM card. First person transfer amount M to second person and second person transfers this amount to third person. Similarly, fourth person gets amount M from third person and finally transfer it to the first one. This way, four transactions with amount of M are done on the ATM for which the ATM owner obtains commission. Figure 2 depicts the elaborated process. This fake cycle could repeat many times and with shorter paths. Consequently, these transactions cost a lot in commission for the bank and also hinder them from their main goal and business model. Therefore, in this paper we focused on detect this type of frauds.

Proposed Method

In this part the proposed method for self-payment fraud detection is introduced. ATM’s transaction information is first sent to ATM controller and then they are sent to central bank switch. Information is periodically extracted from switch database of bank and ETL process is done on them. After this phase data warehouse is created. Due to high volume of bank transactions, using data warehouse increases fraud detection speed dramatically.

Phase I

In this part all EFT central switch data items need for future processes are extracted.

All transactions with ATM Device code are selected

From previous step transactions, all transactions with local transfer Function code are selected (As it was mentioned before fake transactions are created by local transfer)

All successful transactions are selected (transactions with response code=00)

In this step we have transactions in ISO8583 format, so ATM No, Card No, Amount, Date and Time data items are selected.

Selected items in previous step are transferred to a table with following format.

If money is transferred to card, “Deposit” field will be transferred amount and “Withdrawal” field will be 0 and if money is transferred from card, “Deposit” field will be 0 and “Withdrawal” field will be transferred amount.

In this part data warehouse and cubes are created on Table 1. ATM No, Card No, Date and Time are considered as dimensions. Deposit and Withdrawal amount are considered as measures. Sum function is selected for data warehouse function. Also, a KPI is defined as Amount ratio (ϴ). The formula is defined as follow:

Table 1:

Lupinepublishers-openaccess-computer-sciences-journal

ϴ(Card No)=Deposit/Withdrawal

In this formula Deposit is the amount transferred to card and Withdrawal is the amount transferred from card. Amount ratio ϴ (Card No) shows Deposit / Withdrawal for a card. Table 2 shows information about Dimensions and Measures. Data warehouse general schema is shown in Figure 3. As demonstrated, Time dimension includes Year, Month, Day and Hour. This dimension is used for fraud detection in various time ranges and with different granularities. In this paper following rules are used for fraud detection. 1-Cards with ϴ=1, ϴ between 0.9 and 1.1 or ϴ between 0.8 and 1.2 have higher probability of creating fake transactions. The smaller granularity on a dimension and KPI, the higher the probability of fake transactions. For example, if a customer on an ATM in a day has equal deposits and withdrawals with a high probability he has committed self-payment fraud (Table 3).

Table 2:

Lupinepublishers-openaccess-computer-sciences-journal

Table 3:

Lupinepublishers-openaccess-computer-sciences-journal

2-Because it is possible the fraud takes place on two or more ATMs, ATM dimension is omitted and then investigation about Amount ratio is repeated again. Each of transactions meeting KPI thresholds is considered as a probable fake transaction. In this type of fraud, customers of multiple ATMs collaborate to create fake transactions on their ATMs. Above rules are extracted from experts’ knowledge. The customers who fall into the above category are considered to have most likely committed the fraud. These rules can detect suspicious customers. Customers extracted by this method with high probability really have committed fraud actions.

Phase II

After extracting data items from central switch database, a restricted network is built with customer transactions. In previous section some customers who create fake transactions with high probability are discovered. But the point about this kind of fraud is that customers for doing this fraud need other customers. So, for finding other customers that are collaborating to create fake transactions more analysis is needed. As mentioned before, for increasing ATM amount operation, some customers transfer some amount of money to each other several times. With more analysis a loop is created between these customers. Result table format is as follow. Following algorithm is used for related card extraction.

First all cards that have relation with suspicious cards are extracted. These cards are those that transfer/receive money to/ from suspicious cards. So, all transactions which are related to these cards are extracted (Figure 4).

ϴ for extracted cards is calculated (as mentioned in Phase 1).

Transactions which have ϴ out of threshold range are omitted from transactions set.

Set Visited field for all transactions to 0.

Following Algorithm is used for Loop Detection

For more clarification an example is provided in Figures 5-9. Assume that there is a network of transactions. Figure 6 shows this network. Amount of transaction is on each edge. First phase of proposed method are executed on each node (card) and all nodes which have equal input and output are extracted(ϴ=1). These nodes are suspicious nodes. Figure 7 shows this phase. In this Figure 4 card holders are detected as suspicious. But as you see in Figure 7 not all of them are fraudsters. After detecting suspicious nodes, Phase 2 algorithm is executed on suspicious nodes. Detected loops are shown in Figure 8. As demonstrated some suspicous nodes from previous phase have been detected as normal behaviour. Two suspicious loops are detected in Figure 9. In addition to creating loop, all card holders which are in loop must have predefined range of amount ratio. In Figure 9 Amount ratio is equal to one. The detected customers can be introduced to bank fraud detection office for further investigations.

Figure 4: Data warehouse design.

Lupinepublishers-openaccess-computer-sciences-journal

Figure 5: Extract related cards flow chart. .

Lupinepublishers-openaccess-computer-sciences-journal

Figure 6: Extract related cards flow chart. .

Lupinepublishers-openaccess-computer-sciences-journal

Figure 7: Transactions network.

Lupinepublishers-openaccess-computer-sciences-journal

Figure 8: Detecting suspicious nodes.

Lupinepublishers-openaccess-computer-sciences-journal

Figure 9: Loop detection.

Lupinepublishers-openaccess-computer-sciences-journal

Results

To evaluate the proposed method, it is applied on transactions of an Iranian bank. For this purpose92702 local transfer transactions were investigated. Table 4 shows results of first phase of proposed method due to various dimensions (Card No, ATM, and Time). As it is illustrated in Table 4 using different periods for time dimension could affect the number of suspicious transactions. In Table 4 different ranges for ϴ is used. Due to these ranges and changing dimensions different card numbers and transactions are extracted. When ϴ range and Time dimension are bigger, more transactions and cards are extracted. But if ϴ range and Time dimensions are smaller fraud probability is higher. Because proposed method used database and data warehouse techniques, it has high performance for large amount of data like be Table 5 shows Phase II of proposed method results. As it can be seen in this table suspicious cards and related card are detected as it was described before. Then amount ratio filter applied on them. Finally loop detection phase is applied on cards. Table 5 shows detected cards, detected transactions, detected loops, average loop lengths and transactions which are bigger than 1000000 Rials. Detected cards certainly committed self-payment fraud. These cards, related ATMs, Date and Time were delivered to bank fraud detection office. They investigated transactions and loops and put some filters on these transactions. For example, if amount of a transaction in loop were smaller than 10000 Rials, these transactions were probably for system function test and were not fraud. Also, they decided if loop count for a specific card is bigger than one then this card committed self-payment fraud. With these two rules final results are as Table 6. Based on the amount of fake transactions some ATM owners had to pay penalty to the bank and for others the ATMs were seized.

Table 4:

Lupinepublishers-openaccess-computer-sciences-journal

Table 5:

Lupinepublishers-openaccess-computer-sciences-journal

Table 6:

Lupinepublishers-openaccess-computer-sciences-journal

Conclusion

In this paper we discussed self-payment fraud. Due to the nature of this fraud, all transactions should be investigated and fraud loops should be extracted. Two approaches were discussed in this paper. To the best of our knowledge there was no method for ATM owners’ fraud detection. Also, in this paper a method for loop detection is introduced that can be used for loop detection in many other systems. Proposed method extracts suspicious transactions in the first phase. Then related transactions are extracted in the second phase and all transactions are investigated again. Finally, it presents a list of fraudsters’ loops. Self-payment frauds are guaranteed in these loops. There is a problem with proposed method when all members of fraudsters loop have other transactions in addition to their fake transactions and amount sum of fake transactions by total transaction is lower than ϴ thresholds. For future work, proposed method can be used for link analysis in anti-money laundering. Also, it can be used for fraud detection on other payment channels like point of sale (POS) and fraud committed by their owners. Generally, proposed method loop detection can be used for all big data environments which need loop detection with some changes in details.

Read More Lupine Publishers Current Trends in Computer Sciences & Applications (CTCSA) Click on Below Link: https://computer-sciences-lupine-publishers.blogspot.com/



Wednesday, 14 April 2021

Lupine Publishers| Internet of Things and Privacy

 Lupine Publishers| Current Trends in Computer Sciences & Applications


Opinion

The Internet of Things is a concept that has been heard quite a lot in recent years, a concept that slowly emerged, but over time it has experienced a booming growth that was then adopted not only by giant IT companies, offering according to the directions of each company that adopts the corresponding services and applications to the end user. Undoubtedly this technology has come to stay for a long time, it has come to improve our living conditions and to simplify habits and functions that required time and many times difficulties. The Internet of Things is almost everywhere around us from the super market to the cars we drive, our everyday life is going easy and we are happy to live with, but there are two important points that we should consider:

a) Uncontrolled product design based on the Internet of Things.

b) Access to data managed by Internet of Things are inaccessible by the users.

According to the above, important questions arise, such as:

a) How and where these devices store and manage the data now?

b) How and where these devices store and manage data in the future?

c) What personal data are collected and for whom?

d) How protected they are from hacking attacks?

e) How capable is an Internet of Thing to take full control of an information system?

Surely for all of us who are involved in the security of information systems, we have a lot of work to do. The biggest challenges we have to face are:

a) No one knows an Internet of Thing how it collects, how it uses, and where stores personal data. One could construct an Internet of Thing that behaved properly according to the purpose it was created, but it could also act as intelligence espionage product to transmit personal sensitive data and information related to the online traffic and services of an organization, and the worst scenario is that this device can work for years without being noticed.

b) Depending on the complexity of the smart device, the amount of data it sends is increasing, for example a complex smart device can send up to 5 times the volume of unidentified data.

c) The Internet of Things, as I mentioned above, was designed to make our lives easier because technology evolves and these devices evolve, so many unknowingly use them in a computer room or in critical security infrastructures for which the devices have not been made for this purpose, and of course with unknown security implications for the company’s network since these devices do not have an management interface for the user, so it is impossible to access them.

d) Depending on the type of the device, third-party information is internally embeded, for example GPS maps, geostrategic data, human habits information, transaction information, which will then have to work all together for the Internet of Thing.

e) We do not know exactly what kind of data and metadata are collected, it is enough to ponder that an IoT card containing basic medical data of a patient sends about 200MB of unknown data per year.

f) The Internet of Things are not safe enough in external attacks, a denial of service attack on an Internet of thing could be the entry for violating an information system and collect sensitive information from it.

g) The construction of these devices varies, there are not enough standards to build and protect personal data, no one can guarantee that an Internet of Thing will protect its owner against an external threat, which for example could get the control of a car with unpleasant consequences for the driver.

Considering the above, we should consider whether we really need an Internet of Thing and if this is necessary, how much we can parameterize and access to it [1,2].

Read More About Lupine Publishers Current Trends in Computer Sciences & Applications Please Click on Below Link https://computer-sciences-lupine-publishers.blogspot.com/