Vol. 5 No. 2 (2010)
Published: December 15, 2010
IADIS International Journal on Computer Science and Information Systems Volume 5, Issue 2, 2010.
Table of Contents
Peer-Reviewed ResearchOriginal Research
Evangelos D. Frangopoulos School of Computing, University of South Africa (UNISA)., Alexandras Avenue, Athens Researcher, GR, Greece. Researcher
In the context of Information System Security and s ecurity in general, Social Engineering (SE) attacks exploit vulnerabilities that are based on principles of human psychology. The attackers who employ such methods are identified as “Social Engineers”. In co njunction with loopholes in the security structure of the organisation, SE attacks can yield results that would be difficult, if not impossible, to obtain t hrough the use of purely technical hacking methods. As SE attacks are based on deception, they are very difficult to categorise. Hence, designing counterme asures for them is even more difficult and as such, to this day, provisions present in current security st andards and best practices against SE methods are limited, indirect and rather inadequate. Thus, a mo re fundamental approach is called for, if effective defense methods are to be devised. The current analysis of the psychological aspects o f SE forms part of a larger effort to identify the risks emerging from the largely non-technical issues of I nformation Security (IS) and devise methods for the ir mitigation. To this end, the notion of the Ψ-wall is introduced.
Teppo Räisänen . School of Business, Information Management, Oulu University of Applied Sciences, Finland Teuvo Pakkalan katu, Oulu.
This paper discusses the usability and applicabilit y of argumentation-based knowledge. We are especially interested to find out how the sense-mak ing of argumentation-based knowledge by contemporary Web users could be supported. We use t he Lost on the Moon experiment for studying this and compare the achieved results between three expe rimental groups and a control group. These results demonstrate that support for explicating informatio n and voting over proposed solutions may help in th e sense-making process, in particular with issues whi ch are in a true sense open for debate. The sense- making was partially improved in all three experime ntal versions implemented. The experiment emphasizes that in order to support complex problem s it is the simple solutions with easy to use interfaces that are needed in the Web2.0 era.
Trust-based Hotspot Selection
pp. 37–55Xavier Titi . University of Geneva.
Wi-Fi networks and its users are more and more nume rous. Unfortunately, the risk of using one Wi-Fi or another varies because there is no means of selecti ng the most trustworthy hotspot. Mobile wireless connections are still risky and the performance varies greatly depending on the different nearby networks connections. For instance, new soft Access Point (A P) may easily spoof the identity of another AP unde r maintenance and thus compromise the privacy or the power consumption of the users’ mobiles. Our solution proposes using trust management to mitigat e malicious APs. We define a malicious AP in two ways: first the AP is defined such as an AP which c heats by capturing users’ sensitive information while the user surfs the Web during their connection to t his AP. Second, the AP is defined such as an AP which constrains user to use a lot of battery of th e users’ mobile by constraining to use encryption when the user does not need that. We have analyzed the n etwork utilization and power consumption of mobile devices in the case of Geneva Hotspot AP locations. We have validated our proposed solution under resource constraints through simulation based on dynamic simulation tools named AnyLogic. In second part of this paper we present a solution that solution allows the users to rate the networks they have used and to check that their rating corresponds to the true network quality they have experienced by measuring and certifying Quality of Service (QoS) e vidence such as delay, jitter and packet loss. We u se Quality of Service (QoS) evidence such as Delay, Ji tter, Packet Loss to compute a trust value. This tr ust value will define the state of the AP (Good, Bad). W e validate our solution by proving when this certification is irrefutable.
Ariel Monteserin. ISISTAN, Fac. Cs. Ex., UNCPBA – CONICET. Campus Universitario, Pje. Arroyo Seco, Tandil Researcher, Argentina Researcher
Argument selection is considered the essence of the strategy in argumentation-based negotiation. An agent, which is arguing during a negotiation, has t o decide what arguments are the best to persuade th e opponent. In fact, in each negotiation step, the ag ent must select an argument from a set of candidate arguments by applying some selection criterion. For this task, the agent observes some factors of the negotiation context, for instance trust in the oppo nent, expected utility, among others. Usually, argu ment selection mechanisms are defined statically. Howeve r, as the negotiation context varies from a negotiation to another, defining a static selection mechanism it is not useful. For this reason, we pr esent in this paper a novel approach to personalize argum ent selection mechanisms in the context of argumentation-based negotiation. The selection mech anism defines a set of preferences that determine how preferable it is to utter an argument in a give n context. Our approach maintains a hierarchy of preferences in order to learn new preferences and u pdate the existing ones as the agent experience increases. We tested this approach in a simulated multiagent system and obtained promising results.
Salah Saleh Al-Majeed. University of Essex, Colchester CO 3SQ, UK .
The idea of multi-connection congestion control was originally applied to aggregate flows passing from computer cluster to cluster communicating over the public Internet. This paper considers the extension of multi-connection streaming to wired/wireless networ ks and in doing so reviews theoretical results for multi-connection streaming, including virtual multi -connections within a single physical connection. Streaming a single video over multiple TCP-Friendly Rate Control connections is a promising way of separately coping with both wireless channel losses and traffic congestion, without the need for cross - layer intervention or retransmission delay at the data-link layer. At the same time, the wireless channel is properly utilized, as throughput improves with an i ncreasing number of connections. Nevertheless, over IEEE 802.16e (mobile WiMAX) tuning is needed to sel ect the number of connections and the Time Division Duplex (TDD) frame size. The paper assesse s the impact on video quality of packet drops due both to channel loss over a WiMAX access link and r outer buffer overflow across an all-IP network, consisting of broadband wireless access and core ne twork. The paper also considers end-to-end delay and start-up delay when employing several connectio ns. Results show that provided the TDD frame size is selected appropriately then using multiple conne ctions preserves video quality and improves wireles s channel utilization, with a minimal impact on end-t o-end delay. As a trade-off, there is an increase in start-up delay arising from the need to avoid possible buffer underflow.
Tülin İnkaya . Industrial Engineering Department, Middle East Technical University, Ankara, Turkey. Researcher
We consider the clustering problem with arbitrary shapes and different densities both within and between the clusters, where the number of clusters is unkno wn. We propose a new density-based approach in the graph theory context. The proposed algorithm has three phases. The first phase makes use of graph-based and density-based clustering approaches in order to identify the neighborhood structure of data points . The second phase detects outliers using the local o utlier concept. In the third phase, a hiearchical agglomeration is performed to form the final cluste rs. The algorithm is tested on a number data sets a nd compared with the well-known clustering algorithms in the literature. Its strengths and limitations ar e explored in detail.
Foundational Models & Architectures
G.P. De Jager . School of Computer, Statistical Researcher, Potchefstroom Researcher, South Africa.
Many organizations have deployed system development methodologies in order to improve information systems development. Various factors influencing th e successful adoption of system development methodologies have been identified by numerous stud ies. However, a need was identified to evaluate the post-implementation efficiency of system developmen t methodologies. The aim of this paper is to present theoretical and empirical background for an evaluation model to measure the efficiency of a software development methodology after implementati on. A linear programming method called Data Envelopment Analysis was used to compare the applic ation of the Extreme Programming system development methodology in different organizations. According to the results of the analysis, it was possible to classify organizations’ use of Extreme Programming as efficient or inefficient. Recommendations could be made to increase efficiency of individual organizations that were classified as inefficient.
Case Studies & Applications
Wil Janssen. Achmea, Spoorlaan, 5017 JZ Tilburg, Netherlands Researcher
In a former published study (Versendaal et al., 2010) the authors identified process-related factors that influence the performance of application management in banks and insurance firms in terms of operational excellence. The identified factors were validated through a case study. In this extended version of the study we re-present our earlier research integrated with: 1) further validation of the results with IT management professionals from outside the initial case study company, 2) explicating and validating culture-related factors that influence application management performance. Our extended findings support the validity of the identified process and cultural factors and as such can be used to indicate directions for implementation of application management.
Editorial
Editorial
pp. 1–1Pedro IsaĂas
Editorial preface for Volume 5, Issue 2 of the IADIS International Journal on Computer Science and Information Systems (IJCSIS). This issue brings together peer-reviewed original research contributions covering the wide spectrum of Information Systems, Artificial Intelligence, Software Engineering, and Digital Transformation.