
Electronic Health Record (EHR) is a valuable tool to store patients' history as well as to promote evidence-based best practices and advances in healthcare. However, these benefits are limited due to problems related to data quality, difficulties in information retrieval, and semantic interoperability issues. We present the BioFrame aiming to standardize and semantically annotate EHR forms. Our proposal is composed of a multi-dimensional conceptual model, an EHR specification process, and a catalog of software tools. We expect to contribute with a framework that enables the efficient real-life application of semantic technologies and EHR standards to healthcare software systems. A case study was carried out on the specification of pediatric oncology nutrition records in a specialized hospital. The results point to the feasibility of BioFrame, as well as limitations, improvements, and challenges regarding the increase of productivity in the specification process.
In recent years, Blockchain technology has proved its efficiency in many domains. A smart contract is a software component allowing exposing services via the Blockchain network. Smart contracts are small programs that automatically execute the terms of an agreement when predetermined terms and conditions are reached. With the increasing growth in the popularity of smart contracts, searching, retrieving and understanding smart contracts before executing them becomes a significant challenge. Nevertheless, the majority of these contracts are closed source contracts. Therefore, users cannot understand their functionality and their internal mechanism. In addition, their description lacks the expressiveness and it didn't cover the QOS parameters. In this paper, we propose a Uniform Description language for Smart Contract named UDL-SC. This proposal is an extension of USDL based on the MDA approach to promote trust and minimize the ambiguity between the user and the contract provider.
Unsupervised intrusion detection methods are an important component of modern, network based, ICT systems. One of key challenges in the development of such methods is the assessment of anomaly detection algorithms utilized for intrusion detection. In many real-life scenarios labeled network data is not available, hence typical criteria for evaluation of anomaly detection based on Receiver Operating Characteristic or Precision-Recall curves cannot be utilized. In this paper, an alternative approach utilizing Excess-Mass and Mass-Volume curves is presented, which can enable anomaly detection algorithms quality assessments without need for labeled datasets. The article discusses these criteria and presents the test intrusion detection algorithms that will be assessed with them. This discussion is followed by experimental evaluation of this approach, which is conducted with utilization of real-life network traffic datasets in order to provide a strong indication if this approach is viable in production environments.
Internet of Things and cyber-physical systems are characterised by openness and an increasing number of devices and their associated services. In a previous work, we have proposed to exploit opportunistically these services in order to automatically make emerge customised applications that suit user preferences. For that, we have developed a generic solution for bottom-up opportunistic service composition, based on reinforcement learning. In this work, it is extended to handle more efficiently the appearance of new components using service annotation and quality attributes in order to generalise and share knowledge with new discovered services. A didactic use case is used for illustration and demonstration purposes.
The network interface selection (NIS) is an important function that should be executed to connect the user's equipment to the best available network anytime and anywhere by meeting the user/application QoS requirements. Multi-attribute decision-making approaches (MADM) are commonly applied to model and solve NIS problems. Although they can rank networks quickly with a high precision, they suffer f...
We consider Initial Public Offering (IPO) on blockchains while preserving privacy using Secure Multiparty Computation (MPC), which allows participants to perform a computation on secret data. We provide "MPC as a service", where users requiring a computation distributes shares of their data to MPC workers who run an MPC protocol on the shares and return the result. Previous work by Benhamouda et al. considered IPO over Hyperledger Fabric. We improve by providing a tighter and easier integration of MPC protocol in Fabric using the MPC library SCALE-MAMBA. We explain the obtained security benefits and experimental results are provided.
This paper presents an overview of autoscaling solutions for microservices-based applications during elastic treatment. Actually, most of existing work propose solutions dealing with elasticity at the VM level. These solutions launch elasticity when VM overload is detected or predicted. Few solutions treat this issue at the container level and deal with elasticity of microservices- based applications. In addition, these latter use ideas employed at the VM level without considering the specificity of microservice architecture. In this paper, we study and classify existing autoscalers dealing with containers and deploying microservices-based applications. We explain the strength and the shortcomings of each category. As a conclusion, we describe the challenges of autoscaling treatment and we give recommendations for future solutions.
With the development of various technologies, the modern industry has been promoted to a new era known as Industry 4.0. Within such paradigm, smart factories are becoming widely recognized as the fundamental concept. These systems generate and exchange vast amounts of privacy-sensitive data, which makes them attractive targets of attacks and unauthorized access. To improve privacy and security within such environments, a more decentralized approach is seen as the solution to allow their longterm growth. Currently, the blockchain technology represents one of the most suitable candidate technologies able to support distributed and secure ecosystem for Industry 4.0 while ensuring reliability, information integrity and access authorization. Blockchain based access control frameworks address encountered challenges regarding the confidentiality, traceability and notarization of access demands and procedures. However significant additional fears are raised about entities' privacy regarding access history and shared policies. In this paper, our main focus is to ensure strong privacy guarantees over the access control related procedures regarding access requester sensitive attributes and shared access control policies. The proposed scheme called PDAMF based on ring signatures adds a privacy layer for hiding sensitive attributes while keeping the verification process transparent and public. Results from a real implementation plus performance evaluation prove the proposed concept and demonstrate its feasibility.
Over the last few years, multiple-device ownership have continuously and rapidly increased, driven by the continuous progress of Internet of Things solutions deployment. At the same time, the way people use their multiple devices is also changing making it common and even necessary to switch from one device to another for the same task. This evolution raises several issues regarding the migration process and the choice of the device to migrate to. In this paper, we address the problem of recommending the most suitable devices for a successful migration. We propose a semantic and rule-based approach for device recommendation that takes into account the characteristics of devices, services, and migration contexts. We propose an OWL ontology defining the necessary concepts describing devices, services, users, etc. and the relationships between them. Based on this ontology, we propose a set of SWRL rules defining the common requirements for a successful service migration across devices. The ontology is populated in real-time using appropriate APIs to get devices and context characteristics. This allows the rule-based reasoning to be held over updated values and provides relevant recommendations. The approach is implemented as a recommendation system within a web application to demonstrate its effectiveness and scalability.
In the past years, trust management systems have been proven suitable for solving the authorization problem in distributed systems, such as peer to peer systems, social networks, cloud, mobile ad-hoc networks, and Internet of things. Trust management systems could be either managed by a central authority or decentralized. In both cases the entity or, respectively, the set of entities managing the system need to be trusted for all users. To overcome this limitation, this paper brings blockchain technology into trust management systems, proposing a novel implementation of the Role-based Trust management framework (RT) on blockchain. The approach relies on smart contracts to represent user trust networks and to infer new trust relations through the chain discovery algorithm. We evaluated a prototype implemented on Ethereum on a representative set of policies related to different scenarios.
When medical information and documents are exchanged outside of the secure medical facilities networks, patient' privacy is at risk. This can compromise biomedical studies, patients privacy, and all other medical stakeholders' data. Therefore, blockchain is more and more adopted as infrastructure for Electronic Medical Records Management Systems (EMRMS) to address secure data sharing, access management and critical data handling issues. In this paper, we consider the problem of reducing transactions scheduling delays in blockchains as a main issue impacting the performances of EMRMS. We suggest a novel approach that aims to design a structured and weighted queue of transactions request that can promote differentiated level of service for requested transactions. A logical scheduling strategy based on a hybridization of the Genetic Algorithm and the Variable Neighborhood Search (VNS) algorithm for scheduling transactions is also proposed.
Access control in Blockchain context is a crucial step. During this process it is important to verify that users have the right roles to get access to the protected resources. To model its access control, the Ethereum Blockchain is based on RBAC model. The whole process is written in a smart Contract imported from The OpenZepplin Library [1]. However, the automatic generation of the access control policy still missing. This automation can widely enhance and simplify the implementation of access control for developers of blockchain based applications. In this paper, we propose a new model for automatically generating the access control smart contract. Our approach is based on the Model Driven Engineering (MDE).
The growth of the Internet of Things (IoT) has led to the increase of new threats, particularly IoT botnets that are a serious cybersecurity concern. This paper proposes a Machine Learning (ML) framework using black-box models for IoT botnet detection. It offers a trade-off between performance - high model accuracy - and interpretability - by providing security experts with explainable results. Our experimentation on real traffic data infected with Mirai and Bashlite malwares, showed that the framework achieves the best accuracy using random forest and extra tree models. In addition, it provides security experts with information on features that are important for a particular instance (i.e., local interpretation) and for the whole dataset (i.e., global interpretation), allowing them to trust the models results and save time and resources.
DevOps methodologies reduce the gap between Developers and Operations teams, enabling automation, integration, monitoring, and team collaboration by exploiting continuous integration and deployment and providing high-scale performance for the cloud software delivery life-cycle. AIOps seems to represent the future of IT automation by leveraging DevOps methodologies, Big Data, and AI-enabled strategies for the smart orchestration of Cloud-native applications. Based on the Ananke monitoring model, this paper investigates design issues and strategies required to enable integration between clusters and applications managed by Ananke, and their metrics stored in the Prometheus Monitoring system. Some classic algorithms for anomaly detection and forecasting of time series have been introduced in the proposed AIOps Prometheus Framework for the system analysis and orchestration of applications. Finally, we propose, as a case study, an auto-scaling strategy based on the prediction of traffic peeks for a web application using the Facebook Prophet model.
Blockchain brings many added values to modern business systems. However, Blockchain-based applications with massive IoT devices experience some limitations. The limitations are due to the linear structure and the consensus algorithms used in Blockchain that consume the participating nodes' considerable resources. In addition, IoT devices are generally with limited resources and have limited bandwidth connections. IOTA, based on Directed Acyclic Graph (DAG), is a new distributed ledger technology (DLT) for IoT devices. It proves its high scalability by providing parallel data processing. However, DAG is still not mature enough to fully replace Blockchain. In previous work, we proposed combining Blockchain and IOTA technologies to allow scalable transactions where Blockchain is employed in the backend, and Tangle is used in the frontend. This paper considers the proposed solution, focusing mainly on the connector part that intermediates both DLT technologies. The connector is a decentralized software component that supports the interaction between the DLT implicitly. The experiments' results show the flexibility to merge both DLTs using a message queuing protocol that enables smart contracts to run on the Tangle nodes and enriches the new platform with reliability and working offline features.
Our streets will be soon populated by multitudes of autonomous (i.e., self-driving) vehicles, calling for appropriate solutions to coordinate their collective movements in order to ensure safety and efficiency. In particular, crossing intersections can be based on a number of different coordination approaches, from traditional ones (e.g., traffic lights) to innovative ones (e.g., based on dynamic negotiations between vehicles). In this paper, after having introduced the general issues associated to intersection management in the presence of autonomous vehicles, we show by simulation experiments that no single approach exhibits the best behaviour for all traffic conditions and for all performance indicators. On this basis, we introduce an adaptation mechanism that enables an intersection to dynamically select the most proper coordination approach depending on traffic conditions and the performance indicator to be optimized. Simulation experiments show the effectiveness of such adaptive approach.
Wireless Sensor Networks (WSNs) are getting more interest from industrialists as well as from researchers thanks to their low cost, low power and multi-functionality. However, their performance is greatly dependent on the process of sensor nodes' deployment. Thus, an efficient and deterministic deployment technique is needed to enhance the performance of the network. In this paper, a new deployment strategy, that we named HANDLS, is proposed based on hexagonal distribution. The proposed approach considers the coverage probability as well as the number of nodes. Simulation results show that the proposed approach outperforms available deployment techniques mainly in maximizing the network coverage and the nodes' connectivity, while minimizing the number of deployed nodes.
While Blockchains can open intriguing opportunities of research in many application contexts, they come with the risk of bringing new unconventional problems. In fact, because of the monetary value they hold, Blockchains have been subject to many attacks. Smart contracts, which are at the core of second-generation Blockchains, have been proven to be the origin of such attacks due to the exploitable vulnerabilities their code may hold. It is therefore an essential requirement to prove the correctness of the smart contracts to be deployed on a Blockchain to ensure its protection. The existing approaches have been focusing on targeting generic vulnerabilities like reentrancy, without offering the possibility to check temporal-based contract-specific properties. In this paper, we aim to address smart contracts verification while supporting such properties. We propose and implement a transformation of Solidity smart contracts into Coloured Petri nets and investigate the capability of existing model checking tools to check specific temporal properties of the formally modeled contract.
In the past few years, Android security is enhanced and state-of-the-art anti-malware tools have been introduced to counter Android malware. These tools use both static and dynamic analysis techniques to detect malicious applications. Despite these, the attack surface against Android phones has risen exponentially and malware detection tools are failed to counter sophisticated threats. Therefore, it is a need to audit and evaluate Anti Malware Solutions (AMTs). In our research, we have analyzed various Android malware evasion techniques, along with their pros and cons. Moreover, we conducted a detailed comparison of existing anti-malware tools and measured their efficacy against the discussed evasion techniques. Finally, a more sophisticated anti-malware evasion technique is proposed that uses exhaustive obfuscation and remote code execution to audit static and dynamic detection capabilities of AMTs. The proposed technique is practically validated and results prove that it evades all known anti-malware solutions. This technique can be utilized by anti-malware solution providers for making their products more resilient and powerful.
Artificial intelligence is a popular and rapidly growing branch of computer science. For several years, the number of artificial intelligence applications in various fields has increased. Deep learning is a subcategory of machine learning and involves the use of more complex models in existing tasks. Its use allows the extraction of more features, thanks to which the precision of recognition is greater. Malware is a software, considered intrusive and harmful, which has access to the user's confidential information and subsequent use. Due to the growing popularity of mobile devices, the number of malware for these devices is also increasing. There are many malware detection solutions, mainly based on the signature of the applications, however, due to the development of malware, these methods become less effective. Many publications have proposed the use of artificial intelligence in this field. The work describes the basic concepts of the Android and deep learning algorithms. The work focuses on testing several features of the application and checking several deep learning algorithms. In addition, a solution based on the use of binary file representation and self-organizing maps was proposed.