info.icomtechnologies

Research

An Efficient Operations and Management Challenges of Next Generation Network (NGN)

Article June 1, 2014

Next Generation Network (NGN) is envisioned to be an inter-working environment of heterogeneous networks of wired and wireless access networks, PSTN, satellites, broadcasting, etc., all interconnected through the service provider’s IP backbone and the Internet. NGN uses multiple broadband, QoS-enabled transport technologies and servicerelated functions independent from underlying transportrelated technologies. The operations and management of such interconnected networks are expected to be much more difficult and important than the traditional network environment. In this paper, we present an overview of the current status towards the management of NGN and discuss challenges in operating and managing NGN. We also present the operations and management requirements of NGN in accordance with the challenges and verified two routing protocols for QOS support and providing security using caesarchiper encryption/decryption in Ad-hoc networks and also provide QOS for wired networks by AQM techniques and simulated results of AQM, Routing protocols using NS-2 and Encryption/Decryption using Matlab tools.

Defensive Approaches on SQL Injection and Cross-Site Scripting Attacks

Article June 1, 2014

SQL Injection attacks are the most common attacks on the web applications. Statistical analysis says that so many web sites which interact with the database are prone to SQL Injection/XSS attacks. Different kinds of vulnerability detection system and attack detection systems exist, there is no efficient system for detecting these kinds of attacks. SQL Injection attacks are possible due to the design drawbacks of the websites which interact with back-end databases. Successful attacks may damage more. The state-of-art web application input validation echniques fails to identify the proper SQL/XSS Vulnerabilities accurately because of the systems correctness of sanity checking capability, proper placement of valuators on the applications. The systems fail while processing HTTP Parameter pollution attacks. An extensive survey on the SQL Injection attacks is conducted to present various detection and prevension mechanisms.

Different Models for MANET Routing Attacks

Article August 25, 2013

Mobile ad-hoc networks are becoming ever more popular due to their flexibility, low cost, and ease of deployment. Among these attacks, routing attacks have received considerable attention since it could cause the most devastating damage to MANET Early proposed routing protocols were not designed to operate in the presence of attackers. There have been many subsequent attempts to secure these protocols, each with its own advantages and disadvantages. Even though there exist several intrusions response techniques to mitigate such critical attacks, existing solutions typically attempt to isolate malicious nodes based on binary or native fuzzy response decisions. To allow for a comparison of these secure protocols, a single common attacker model is needed. Our first contribution in this work is to develop a comprehensive attacker model categorizing attackers based on their capabilities. This is in contrast to the existing models which seek to categorize attacks and then map that categorization back onto the attackers. However, binary responses may result in the unexpected network partition, causing additional damages to the network infrastructure, and native fuzzy responses could lead to uncertainty in countering routing attacks in MANET. Our second contribution is an analysis of the SAODV routing protocol using our new model, which demonstrates the structured approach inherent in our model and its benefits compared to existing work.

Enhancement of Secure and Dependable Storage Services and Security Using Third Party Auditing

Article August 25, 2013

Cloud Computing is the long dreamed vision of computing as a utility, Cloud storage facilitates users to store the data remotely and enjoy the on-demand high quality cloud servers without the burden of local software and hardware systems. By outsourcing the data, users can be comforted from the burden of local data storage and maintenance. By having these many benefits, such a service is also abandon users’ physical control of their outsourced data, which unavoidably posture new security risks towards the accuracy of the data in cloud. In order to address this new problem and further achieve a secure and dependable cloud storage service, we propose in this paper a flexible distributed storage integrity auditing mechanism, utilizing the homomorphic token and distributed erasure-coded data. The proposed design allows users to audit the cloud storage with very lightweight communication and computation cost. The auditing result not only ensures strong cloud storage correctness guarantee, but also simultaneously achieves fast data error localization, i.e., the identification of misbehaving server. Considering the cloud data are dynamic in nature, the proposed design further supports secure and efficient dynamic operations on outsourced data, including block modification, deletion, and append. Analysis shows the proposed scheme is highly efficient and resilient against Byzantine failure, malicious data modification attack, and even server colluding attac

Show all publications