
In the modern era, there are numerous metrics for overall Quality of Experience (QoE), both those with Full Reference (FR), such as Peak Signal-to-Noise Ratio (PSNR) or Structural Similarity (SSIM), and those with No Reference (NR), such as Video Quality Indicators (VQI), that are successfully used in video processing systems to assess videos whose quality is diminished by various processing scenarios. However, they are not appropriate for video sequences used for jobs that require recognition (Target Recognition Videos, TRV). As a result, a significant research problem remains to accurately assess the performance of the video processing pipeline in both human and Computer Vision (CV) recognition tasks. For recognition tasks, there is a need for objective ways to assess video quality. In this research, we demonstrate that it is feasible to create a novel idea of an objective model to assess video quality for automatic licence plate recognition (ALPR) tasks in response to this demand. A representative set of image sequences is used to train, test, and validate the model. The collection of degradation scenarios is based on a digital camera model and how a scene’s luminous flux eventually transforms into a digital image. The generated degraded images are evaluated for ALPR and VQI using a CV library. The value of the F-measure parameter of 0.777 represents the measured accuracy of a model.
Key agreement protocol is an essential step for establishing a secure connection. The inevitable advancements in quantum computing technologies pose a huge threat to the key agreement protocol in use today. Neural cryptography is an alternative key agreement protocol that is not susceptible to any known quantum algorithm. Since the invention of mutual learning of TPM, many improvements have been proposed. One of them was the usage of nonbinary input vectors. This study verifies the impact of nonbinary input vectors on TPM security features. A number of iterations, similarity to intruder’s TPM and effective key length were taken into account. The results show that the choice between fast synchronization times and higher security of the final key must be performed with perfect care.
This paper documents the approach to define cybersecurity certification schemes as candidate methods for sector cybersecurity product certification as part of the EU Cybersecurity Certification Framework being prepared by ENISA. Indeed, it is a very recent area of research within the EU landscape. Our work was undertaken within H2020 ECHO project ( www.echonetwork.eu ) and it is reported in detail in its deliverables. This document is completing the research reported in our previous publication, which had complete references to the existing state of the art about the certification topic in EU. Our work started with the identification of the sector-specific needs to be addressed for specific critical sectors. The mandatory Key Elements of a certification scheme, as described in the EU Cybersecurity Act, have been customized and the sector specific analysis allowed to define a Security Problem Definition baseline to be used to quickly draft a Protection Profile of an asset category of the considered sectors. Security needs have been identified using also the sectoral risk assessment guidelines provided by ENISA for certification purposes. It has also been developed an inter sector risk scenario to highlight the most important security needs to mitigate cross-sector security failures. Finally, Cyber Range technologies have been leveraged for the Conformity Assessment activities of two Maritime and a Healthcare product prototypes, for which the substantial assurance level certification has been simulated for the sake of validation of our approach.
Nowadays, there are many metrics for overall Quality of Experience (QoE), both those with Full Reference (FR), such as Peak Signal-to-Noise Ratio (PSNR) or Structural Similarity (SSIM), and those with No Reference (NR), such as Video Quality Indicators (VQI), which are successfully used in video processing systems to evaluate videos whose quality is degraded by different processing scenarios. However, they are not suitable for video sequences used for recognition tasks (Target Recognition Videos, TRV). Therefore, correctly estimating the performance of the video processing pipeline in both manual and Computer Vision (CV) recognition tasks is still a major research challenge. There is a need for objective methods to evaluate video quality for recognition tasks. In response to this need, we show in this paper that it is possible to develop the new concept of an objective model for evaluating video quality for face recognition tasks. The model is trained, tested and validated on a representative set of image sequences. The set of degradation scenarios is based on the model of a digital camera and how the luminous flux reflected from the scene eventually becomes a digital image. The resulting degraded images are evaluated using a CV library for face recognition as well as VQI. The measured accuracy of a model, expressed as the value of the F-measure parameter, is 0.87.
Technological development is unstoppable. Police forces are no strangers to this development. In this paper we present the advances in this field of different types of technologies applied to the police function (crime mapping, data mining and big data, social media, drones) and also the application of artificial intelligence to policing. Finally, we reflect on the suitability of these applications and the desirable future through recommendations.
A typical example of a Brain-Computer Interface (BCI) is a system that allows a person to move a ball displayed on a computer screen to the left or to the right, simply by imagining the movement of the left or right hand, respectively. Since the term Brain-Computer Interface was coined in 1973, the interest and efforts in this field have grown tremendously and there are now thought to be several hundred laboratories worldwide developing research in this topic. This paper aims at summarizing its resulting knowledge in a way that allows for a quick and clear consultation, highlighting the research lines, technologies and the most relevant cases of applications, so that policy makers, professionals and consumers can make effective use of the findings. With this in mind, a Brain-Computer Interface toolkit is proposed with a focus on different target audiences (e.g., children, seniors, people with intellectual disabilities) that can take advantage of this resource and promote an independent life routine.
New challenges arise with the upsurge of a Big Data era. Huge volumes of data, from the most varied natures, gathered from different sources, collected in different timings, often with high associated uncertainty, make the decision-making process a harsher task. Current methods are not ready to deal with characteristics of the new problems. This paper proposes a novel data selection methodology that filters big volumes of data, so that only the most correlated information is used in the decision-making process in each given context. The proposed methodology uses a clustering algorithm, which creates sub-groups of data according to their correlation. These groups are then used to feed a forecasting process that uses the relevant data for each situation, while discarding data that is not expected to contribute to improving the forecasting results. In this way, a faster, less computationally demanding, and effective forecasting is enabled. A case study is presented, considering the application of the proposed methodology to the filtering of electricity market data used by forecasting approaches. Results show that the data selection increases the forecasting effectiveness of forecasting methods, as well as the computational efficiency of the forecasts, by using less yet more adequate data.
The paper presents our solution based on the vision analysis and workflow management that can realise automated supervising of the workers, and/or their practical training to make better decisions and avoid various accidents. These tasks are the key objectives of the INRED system (created within R &D project) that integrates innovative solutions, components (e.g. surveillance system, workflow engine, knowledge bases, and so on), and has to improve the quality of complicated repair and service procedures. In general, the management of the sequence of work activities during the valve screwing process has been developed, and the proposed calibration and wrench detection modules are briefly described. Moreover, the workflow system and its constituent components are described, with particular emphasis on the Mobile Devices Communication Subsystem dedicated to organize Bluetooth/WiFi communication. The proposed solution was tested many times. In order to show its applicability, the selected results are presented. This solution met the requirement of maintenance training and monitoring of work activities, and can be readily applicable in many repair and service companies.
The paper investigates problems and ways of utilizing Artificial Intelligence (AI) to ensure the cybersecurity of autonomous transport systems (ATSs) in different domains (aviation, space, maritime). A systematic approach to solving problems of analyzing and assuring ATS cybersecurity in conditions of attacks by use of AI means is suggested. This approach is based on: the development of a set of scenarios describing the operation of ATS under cyberattacks and actor activities considering AI contribution to system protection; scenario-based development and analysis of user stories describing different cyber-attacks, their influence, and ways to protect ATs via AI means/platforms; profiling of AI platform requirements by use of characteristics based AI quality model and risk-based assessment of cyberattacks criticality and efficiency of countermeasures, which can be implemented by actors. A modified IMECA technique for risk-based cyber security assessment and choice of countermeasures applied by different actors to minimize the effect of attacks on the system is suggested.
This paper describes an approach to analyse transversal and inter-sectoral cybersecurity challenges and opportunities: dedicated risk assessment and management framework, which can be used to develop cybersecurity technology roadmaps. This multi-sector assessment framework is able to prioritise and evaluate cybersecurity risks in trans-sectoral and inter-sectoral contexts as well as supports proper resource allocations and mitigation actions. To achieve this goal, the analysis of known risk management and risk assessment frameworks was performed, and results are presented in this paper. Also, an overview on transversal, inter-sectoral and multi-sectoral technological challenges and opportunities is provided. The result of this analysis is an architecture of the ECHO Multi-sector Assessment Framework, which was described in detail, including identified and analysed transversal aspects, multi-sector dependencies, and technological challenges and opportunities determine the input data for the framework. This solution is applicable in many sectors, such as energy, healthcare, maritime transportation, or defence, however it can also be extended to others. The architecture of the framework proposed supports the design of cybersecurity technology roadmap and the definition of governance models.
The infrastructure in the maritime sector has evolved to integrate more and more connected systems. The maritime environment very much relies on modern technology to aid and optimize the daily operations of ships and harbour processes alike. The cyber protection of these systems is essential to prevent the disruption of their activity. While Security Operation Centre teams usually are aided in their tasks by Intrusion Detection Systems, the actual response to cyber attacks remains very much a human activity. In that regard, complex and realistic hands-on training is an excellent way to bolster the efficiency of the defensive actions; this type of exercise is usually performed on a cyber range. In that context, a federation of cyber range allows to generate more elaborate sector-specific scenarios. This paper presents a maritime-specific training delivered over a cyber range federation. The sector-specific aspects, as well as the technical issues of the federation, are discussed.
Today’s digital work environments require that organizations increase their cyber resilience. This calls for organizational solutions to find skilled cybersecurity professionals and efficient solutions and procedures that secure digital technologies. Some recent developments deepen the understanding of cybersecurity skills, build skills frameworks, taxonomies and certification systems to base trainings on work-life needs. This study is part of the project ECHO research activities, and it identifies skills that have been used as base skills to develop the ECHO E-skills and Training Toolkit. This case study collected recruitment advertisements from the web service Monster to understand what the Finnish labor market looks at the most desired e-skills that employers want from their future employees. The results of this study are based on a sample (n = 178) of Finnish job advertisements collected in the summer of 2021. This section looks at the job advertisements both by sector and level of expertise and then discusses the relevant skills categories of Technical, Situation awareness, Problem-solving, and Sector specific e-skills. The results show that companies are actively looking for Technical e-skills and Problem-solving e-skills. The most sought after Technical e-skills were programming, software (SW) and information technology (IT). The most important Problem-solving e-skills are, according to the results communication, interaction, self-driven, teamwork, and cooperation and collaboration, and situation awareness e-skills were surprisingly very little addressed to.
Today, more and more interactions rely on smart phones. Their security becomes a real concern to guarantee the protection of identity, life and property. Cybersecurity initiatives regularly emphasize the importance of good practices for passwords, updating patches, encryption or other appropriate defenses. They also announce vulnerabilities discovered in applications. But they rarely warn of the danger of SS7 (Signaling System No. 7), the stack of protocols used between 2G and 3G telecommunications network equipment, including cellular phones. This paper presents on-going research on the detection of SS7 attacks which target the SS7 Mobile Application Protocol (MAP). More specifically, we plan to detect attacks based on so-called Category 3 MAP messages which are difficult to manage with SS7 firewalls. The method verifies the consistency of the position/speed revealed by the telecommunications equipment involved in SS7 signaling when a subscriber is in outbound roaming situation. In particular, we plan to detect attacks spoofing a SS7 equipment (from anywhere in the world) and injecting Category 3 MAP messages in order to take control of voice or SMS delivery equipment, which would allow the attacker to intercept calls or SMSs or even to prevent communications.
The evolution of communication networks has created a huge requirement for massive connectivity, efficient spectral utilization, and high reliability. With the introduction of non-orthogonal Multiple Access (NOMA) technique, most of the user requirements were satisfied. Since NOMA performs the superimposed transmission of user signals in the same resource block, to differentiate these signals, Successive Interference Cancellation (SIC) technique will be used. Till now, most of the research has focused on combining NOMA with key technologies such as Reconfigurable Intelligent Surfaces (RIS), massive Multiple Input Multiple Output (MIMO), millimeter Waves, etc. Whereas, few works have been done on studying the physical layer security of NOMA in direct cooperative satellite networks. In this paper, we study the connection and secrecy performance of such a system in the presence of two legitimate users and one eavesdropper. Closed-form expressions were derived to understand and simulate device performance. To authenticate these expressions, we also performed the Monte-Carlo simulations.
The paper is devoted to an isolated word automatic speech recognition. The first part deals with a theoretical description of methods for speech signal processing and algorithms which can be used for automatic speech recognition such as a dynamic time warping, hidden Markov models and deep neural networks. The practical part is focused on the description of the proposal which is based on convolutional neural networks (CNN). The system was designed and implemented in Python using Keras and TensorFlow frameworks. An open audio dataset of spoken words was used for training and testing. A contribution of the paper lies in the specific proposal using CNN for automatic speech recognition and its validation. The presented results show that the proposed approach is able to achieve 94% accuracy.
This work presents an experimental study of malware classification using the Microsoft Malware Classification Challenge 2015 dataset. We combine the approach of the winning solution to the Microsoft Malware Classification Challenge with the neural network approach. Using a combination of n-grams features for both assembly (asm) and byte code enables us to significantly improve the result. By mixing multiple approaches, we are able to get the best log-loss result of 0.0025, so far. This comes mostly from the classical XGBoost method with n-gram contributions from the binary and assembly code. However, understanding this result is still incomplete. The standard neural network approaches (even with LSTM) alone give poorer results compared to the XGBoost, based on mostly n-gram. It is not clear why adding 6-grams to the binary code analysis does not improve results. There are many more options to be tested in the future, in particular networks.
Error Correcting Codes play an essential role in the digital communication. Especially a new digital technology like video watermarking demands sufficient error correcting capabilities, because of very high compression ratio (about 1:200). Normally the watermarks can barely survive such massive attacks, despite very sophisticated embedding strategies. In this paper, the authors introduce a new approach for Error Correcting Code based on 2D Hadamard Code and convolutional Neuronal Network (CNN). The main idea is that the 2D-Hadamard code words can be represented as 2D basis images. The errors cause a noise in these basis images. The decoding procedure of this 2D-Codewords is realized by a CNN, which was before trained with these basis images. With this approach, it is possible to overcome the theoretical limit of error correcting capability of (d − 1)/2 bits, where d is a minimum Hamming distance. To prove the efficiency and practicability of this new 2D Hadamard Code, the method was applied to a video Watermarking Coding Scheme. The Video Watermarking Embedding procedure decomposes the initial video through Multi-Level Interframe Wavelet Transform. The low pass filtered part of the video stream is used for embedding the watermarks, which are protected respectively by CNN based 2D Hadamard Code.
Currently, most of the affective computing research is about modifying and adapting the machine behavior based on the human emotional state. Although, the use of the affective state inference can be extended to provide a tool for other fields more society related such as gender violence detection, which is a real global emergency. Based on the World Health Organization (WHO) statistics, one in three women worldwide experiences gender-based violence, often from an intimate partner. Due to this motivation, the authors developed BINDI, which is a wearable solution for detecting automatically those situations. It uses affective computing together with short-term physiological and physical observations. It represents a step toward an autonomous, embedded, non-intrusive, and wearable system for detecting those situations and connecting the victim with a trusted circle. In this work, and as a response for improving the detection capability of BINDI, a novel hybrid data fusion architecture is proposed. This new architecture is intended to improve the already implemented decision level fusion architecture. Further details of the uni-modal systems and the different approaches needed to be explored in the future are given.
This paper presents a new approach to analyse cybersecurity challenges and opportunities, focused on the development of a new risk assessment and management framework. Such a multi-sector assessment framework should be able to evaluate and prioritize cybersecurity risks in trans-sectoral and inter-sectoral contexts. It leads toward proper resource allocations and mitigation actions. To achieve this goal, the analysis of existing risk assessment and management frameworks was performed. Also, an overview on common multi-sectoral technological challenges and opportunities were provided being derived from sector-specific use cases as well as transversal and inter-sectoral challenges and opportunities. As a result of this analysis the architecture of the ECHO Multi-sector Assessment Framework was proposed. The identified technological challenges and opportunities, multi-sector dependencies, and transversal aspects determine the input data for the new framework. The architecture is applicable in healthcare, energy, maritime transportation, and defence sectors, being extensible to others. The framework enables the definition of governance models or the design of cybersecurity technology roadmaps.
The paper outlines the basic principles and assumptions used to assess the criticality of critical infrastructure object (CIO) and critical information infrastructure objects (CIIO). Methods for assigning critical information infrastructure objects to the criticality levels are described. The sequence of carrying out the criticality assessment of CIOs is provided. The recommendations concerning evolving regulation in the field of critical information infrastructure objects protection are given. According to the results of the research, several drafts of the Ukrainian state-level normative documents were developed such as “Classification of critical information infrastructure objects by severity (criticality)” and “Criteria and procedure for assigning critical information infrastructure objects to one of the significance (criticality)”. The implementation of the developed documents is an important step in the construction of the Ukrainian state system of protection of critical information infrastructure.