Session 1C
Wireless and the Cloud: Applications and Security
1:00 PM to 2:30 PM | Moderated by Joseph Janes
- Presenter
-
- Cristopher C. Claeys, Senior, Computer Engineering and Systems, Computer Science and Systems
- Mentor
-
- Jie Sheng, Computer Science & Engineering, UW Tacoma
- Session
-
- 1:00 PM to 2:30 PM
A modern computer control system contains mainly four parts, a process (e.g., a water tank where the water temperature is adjustable), an actuator (e.g., a heater to warm up the water), a sensor (e.g., the thermometer to get the real temperature of the water), and the controller. The controller compares the set-point of the interested signal (e.g., the water temperature) with the real measurement from the sensor, hence closed control loop; it also computes the adjustment signal and sends it to the process actuator so that the process will generate an output as close as possible to the set-point. Traditional computer control systems use wired sensors and actuators and have served well in the past century. With the development of wireless sensors and wireless communication technologies, there is a trend to make wireless a viable replacement for hard-wired control, due to low cost, mobility and ability to operate in a harsh or ultra clean environment. However, challenging issues arise; one of them is reliability, which will be investigated in our research. We use a water tank temperature control system as the test-bed; the controller is the MCF52233DEMO ColdFire board with a Real Time Operating System (RTOS) kernel; the control algorithm is the widely applied Proportional Integral Derivative (PID); and the wireless standard is the IEEE 802.11b (Wi-Fi). By comparing the performance between the hard-wired control system and the wireless control system using the same PID controller, we expect to see poor performance of the wireless control system due to wireless network issues such as packet loss, time delays, and so on. We will modify the classical PID algorithm for wireless control so that similar performance to hard-wired control could be achieved. In the future, we will investigate the co-design of communication protocols and control strategies for wireless control systems.
- Presenters
-
- Brookneh W. (Brook) Alemayehu, Senior, Information Technology (Tacoma)
- Gary D. Armstrong, Senior, Information Technology (Tacoma)
- Kultar Singh Khatra, Senior, Information Technology (Tacoma)
- Joshua Deovic Calderon, Senior, Information Technology (Tacoma)
- Mentor
-
- Sam Chung, Information Technology & Systems, UW Tacoma
- Session
-
- 1:00 PM to 2:30 PM
Information technology is changing at an exponential rate. The advent of cloud computing allows small businesses to take advantages of technological services that reduce the cost of their capital expenses. The Software as a Service (SaaS), which is the top layer of cloud computing, is taking the helm in this technology era for small businesses that cannot afford initial capital expenses for their businesses. Now software can be rented as a service instead of being purchased as an application package. The first purpose of our research is to demonstrate how cloud computing can be beneficial to the small businesses: we discover a need for photographers who are small business owners and have limited revenue for the commercialization of their products and services. To sell their photos via the internet, photographers are using other storefronts to sell. Our cloud based shopping cart allows photographers to create their accounts and sell their own photos; thereby, saving on cost and expenses. The second purpose of our research is to demonstrate how an agile software development methodology, Scrum, can be beneficial to the SaaS providers: we as the service providers manage the cloud-based shopping cart development project for photographers by using Scrum. The use of the agile methodology helps us to timely respond the changes of user requirements and the deliveries of the service components in a cloud environment.
- Presenter
-
- Joshua Marlin (Josh) Phelps, Senior, Information Technology (Tacoma)
- Mentor
-
- Sam Chung, Information Technology & Systems, UW Tacoma
- Session
-
- 1:00 PM to 2:30 PM
The world of computing has made major migrations into cloud computing. More and more enterprises, both big and small, begin to rapidly relocate their infrastructure to the cloud both internally, and externally. Virtualization has also become a key component to this migration and is often times inseparable from a particular application of a cloud computing solution. This major jump can be readily seen from major technology industry heavyweights such as Microsoft, Google, and Amazon. It is important to note that this migration to cloud computing is not only taking place externally as companies seek to provide cloud services for clients and consumers, but also taking place as companies and organizations move their internal infrastructure operations to the cloud, particularly, with a virtualized infrastructure as a service (VIaaS). Deploying a VIaaS provides cost effective and convenient solutions to companies and organizations that do not desire the rigors of managing and maintaining their infrastructure by way of physical locations. However, with the utilization of VIaaS, comes a host of concerns from an information assurance standpoint.We propose a scenario in which a simulated small business has moved their infrastructure to the cloud through a VIaaS. Specifically, two common servers in a given network, web and email, are used for testing and evaluation process in which an iterated approach is used after initial installation and configuration. Based upon our experiments using VIaaS, we will address and analyze the configuration and security issues that arise when employing a VIaaS. Since VIaaS can be different for each business, general best practice guidelines are proposed for developing the infrastructure.
- Presenter
-
- Tom Rochat, Junior, Information Technology (Tacoma)
- Mentor
-
- Sam Chung, Information Technology & Systems, UW Tacoma
- Session
-
- 1:00 PM to 2:30 PM
Current network frameworks that are in widespread use today are insufficient for protecting sensitive data, and cybercrime activities are continuing to rise at alarming rates. By adopting new network framework designs into current computing infrastructure, we need to offer users a more safe and secure infrastructure by which to handle sensitive information and data, while not limiting their ability to be productive. For this purpose, we show how a private cloud can be highly assured by integrating the current network infrastructure with the High Assurance Platform (HAP) framework. The National Security Agency proposed the HAP framework in order to provide a high security environment in which to conduct day-to-day computing activities by utilizing a mix of commercially available virtualization and network security technologies. By integrating a private cloud for an academic computing environment with the HAP framework, we can demonstrate how a high assurance private cloud can be designed and implemented. We plan to create a private cloud in a university computer lab using computing resources that are currently in use or available to the general public. This high assurance private cloud allows students to conduct day-to-day academic activities in the freedom of a low assurance environment, by offering low restriction access to common resources such as email, web browsing, and file sharing across an internal network. At the same time, students will have access to a high assurance environment in order to reference confidential or sensitive information. Through the use of virtualization technology and network security technology, sensitive information can be better protected than what is commonly seen today in our academic computing environment and students still have the freedom to perform daily computing activities quickly and efficiently.
- Presenter
-
- Yun-Tse Wu, Sophomore, Computer Science and Systems
- Mentor
-
- Sam Chung, Information Technology & Systems, UW Tacoma
- Session
-
- 1:00 PM to 2:30 PM
Beginning level programmers have learned basic programming concepts and skills without considering security at the beginning. However, the broad adoption of the Internet technologies allowed more software applications to be connected and vulnerable to attacks. It has become more important for beginning level programmers to learn coding with a security perspective in order to avoid bad coding habits. For this purpose, we introduce threat model to beginning level programmers, while they are studying programming fundamentals and examine how the threat model can create a paradigm of higher assurance when the beginning level programmers develop programs with the threat model. We conduct two programming assignments in a course for beginning level programmers without or with the threat models, respectively. Through the threat modeling, we create Data Flow Diagrams to check security trust boundaries and analyze the diagrams to countermeasure vulnerabilities of the programs. The number of vulnerabilities in the source code and the time for implementing the threat modeling are compared and analyzed. Regardless of the longer time for the threat modeling implementation, the early adoption of the threat model allows the beginning level programmers to discuss and expand ideas from the data flow diagram, help them to understand security trust boundaries better, categorize threats with computer security threat classifications, and make their code more secure.
- Presenter
-
- Vera V (Vera) Kayky, Fifth Year, Information Technology (Tacoma)
- Mentor
-
- Sam Chung, Information Technology & Systems, UW Tacoma
- Session
-
- 1:00 PM to 2:30 PM
Using the Internet is leaving tremendous amount of the identity information about the person who accessed. Perhaps it may not be an issue if this information were not used against this person. However, this is a wrong impression of anonymity of the online users who have formed by the users themselves trying to achieve Internet anonymity to ensure privacy. Most of the time the users are not aware of two types of information that can be gathered online: the information that software is gathering from the users and the information that every person leaves about himself, or herself. My research includes reviewing of the United States and Washington state cyber-crime law, developing a new model of cyber-crime investigation procedure and suspect’s profiling, mapping modern techniques of revealing the Internet identity, and developing a prototype of a software application Cyber Bounty Hunter with usage of Python and C++ programming languages. I created Cyber Bounty Hunter as all-in-one tool for tracing suspects via IP-address, HTTP cookies, flash cookies, tracking bugs, HTTP referrer, TCP protocol, browser plugins, search engine's queries, social networks and so on. All of these tools and options can be used in cyber-crime scene investigation applying to tracking of suspects and fugitives, analysis of crime profiler and suspects’ identity. Cyber technologies opened up new possibilities in tracking. Generally, Cyber Bounty Hunter application software deploys cyber-espionage techniques and is capable of tracking and profiling suspects such as professional hackers, thefts, cyber-stalkers, cyber pedophiles, electronic terrorists and vandals.
The University of Washington is committed to providing access and accommodation in its services, programs, and activities. To make a request connected to a disability or health condition contact the Office of Undergraduate Research at undergradresearch@uw.edu or the Disability Services Office at least ten days in advance.