Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Engineering (31)
- Computer Engineering (13)
- Business (9)
- Operations Research, Systems Engineering and Industrial Engineering (9)
- Electrical and Computer Engineering (8)
-
- Information Security (4)
- Operations and Supply Chain Management (4)
- Other Operations Research, Systems Engineering and Industrial Engineering (4)
- Computer and Systems Architecture (3)
- Digital Communications and Networking (3)
- Signal Processing (3)
- Business Administration, Management, and Operations (2)
- Business Analytics (2)
- Electrical and Electronics (2)
- Government Contracts (2)
- Hardware Systems (2)
- Industrial Engineering (2)
- Law (2)
- Numerical Analysis and Scientific Computing (2)
- Oceanography and Atmospheric Sciences and Meteorology (2)
- Social and Behavioral Sciences (2)
- Systems Engineering (2)
- Aerospace Engineering (1)
- Atmospheric Sciences (1)
- Civil and Environmental Engineering (1)
- Communication (1)
- Economics (1)
- Keyword
-
- Software engineering (27)
- Computer software--Development (7)
- Reverse engineering (6)
- Computer software--Reusability (5)
- Intelligent agents (Computer software) (5)
-
- Software development (5)
- Object-oriented programming (Computer science) (4)
- Software protection (4)
- Computer security (3)
- Computer software--Specifications (3)
- Software verification (3)
- Specifications (3)
- #antcenter (2)
- Automatic programming (Computer science) (2)
- Computer architecture (2)
- Computer simulation (2)
- Computer software--Evaluation (2)
- Computer-aided software engineering (2)
- Decision making (2)
- Expert systems (Computer science) (2)
- FORTRAN (2)
- Java (Computer program language) (2)
- Malware (Computer software) (2)
- Object-oriented programming (2)
- Software defined radio (2)
- Software-Defined Networking (2)
- #ctisr (1)
- 3D Scene Reconstruction (1)
- AOC Pathfinder (1)
- Ada (computer program language) (1)
- Publication Year
- Publication
- Publication Type
Articles 31 - 60 of 124
Full-Text Articles in Software Engineering
Eliciting A Sensemaking Process From Verbal Protocols Of Reverse Engineers, Adam R. Bryant, Robert F. Mills, Gilbert L. Peterson, Michael R. Grimaila
Eliciting A Sensemaking Process From Verbal Protocols Of Reverse Engineers, Adam R. Bryant, Robert F. Mills, Gilbert L. Peterson, Michael R. Grimaila
Faculty Publications
A process of sensemaking in reverse engineering was elicited from verbal protocols of reverse engineers as they investigated the assembly code of executable programs. Four participants were observed during task performance and verbal protocols were collected and analyzed from two of the participants to determine their problem-solving states and characterize likely transitions between those states. From this analysis, a high-level process of sensemaking is described which represents hypothesis generation and information-seeking behaviors in reverse engineering within a framework of goal-directed planning. Future work in validation and application of the process is discussed.
Short Message Service (Sms) Command And Control (C2) Awareness In Android-Based Smartphones Using Kernel-Level Auditing, Robert J. Olipane
Short Message Service (Sms) Command And Control (C2) Awareness In Android-Based Smartphones Using Kernel-Level Auditing, Robert J. Olipane
Theses and Dissertations
This thesis addresses the emerging threat of botnets in the smartphone domain and focuses on the Android platform and botnets using short message service (SMS) as the command and control (C2) channel. With any botnet, C2 is the most important component contributing to its overall resilience, stealthiness, and effectiveness. This thesis develops a passive host-based approach for identifying covert SMS traffic and providing awareness to the user. Modifying the kernel and implementing this awareness mechanism is achieved by developing and inserting a loadable kernel module that logs all inbound SMS messages as they are sent from the baseband radio to …
Understanding How Reverse Engineers Make Sense Of Programs From Assembly Language Representations, Adam R. Bryant
Understanding How Reverse Engineers Make Sense Of Programs From Assembly Language Representations, Adam R. Bryant
Theses and Dissertations
This dissertation develops a theory of the conceptual and procedural aspects involved with how reverse engineers make sense of executable programs. Software reverse engineering is a complex set of tasks which require a person to understand the structure and functionality of a program from its assembly language representation, typically without having access to the program's source code. This dissertation describes the reverse engineering process as a type of sensemaking, in which a person combines reasoning and information foraging behaviors to develop a mental model of the program. The structure of knowledge elements used in making sense of executable programs are …
3-D Scene Reconstruction From Aerial Imagery, Jared M. Ekholm
3-D Scene Reconstruction From Aerial Imagery, Jared M. Ekholm
Theses and Dissertations
3-D scene reconstructions derived from Structure from Motion (SfM) and Multi-View Stereo (MVS) techniques were analyzed to determine the optimal reconnaissance flight characteristics suitable for target reconstruction. In support of this goal, a preliminary study of a simple 3-D geometric object facilitated the analysis of convergence angles and number of camera frames within a controlled environment. Reconstruction accuracy measurements revealed at least 3 camera frames and a 6 convergence angle were required to achieve results reminiscent of the original structure. The central investigative effort sought the applicability of certain airborne reconnaissance flight profiles to reconstructing ground targets. The data sets …
Combinational Circuit Obfuscation Through Power Signature Manipulation, Hyunchul Ko
Combinational Circuit Obfuscation Through Power Signature Manipulation, Hyunchul Ko
Theses and Dissertations
Today's military systems are composed of hardware and software systems, many of which are critical technologies, and must be protected to ensure our adversaries cannot gain any information from a various analysis attacks. Side Channel Analysis (SCA) attacks allow an attacker to gain the significant information from the measured signatures leaked by side-channels such as power consumption, and electro-magnetic emission. In this research the focus on detecting, characterizing, and manipulating the power signature by designing a power signature estimation and manipulation method. This research has determined that the proposed method capable of characterizing and altering the type of power signature …
Android Protection System: A Signed Code Security Mechanism For Smartphone Applications, Jonathan D. Stueckle
Android Protection System: A Signed Code Security Mechanism For Smartphone Applications, Jonathan D. Stueckle
Theses and Dissertations
This research develops the Android Protection System (APS), a hardware-implemented application security mechanism on Android smartphones. APS uses a hash-based white-list approach to protect mobile devices from unapproved application execution. Functional testing confirms this implementation allows approved content to execute on the mobile device while blocking unapproved content. Performance benchmarking shows system overhead during application installation increases linearly as the application package size increases. APS presents no noticeable performance degradation during application execution. The security mechanism degrades system performance only during application installation, when users expect delay. APS is implemented within the default Android application installation process. Applications are hashed …
Software And Critical Technology Protection Against Side Channel Analysis Through Dynamic Hardware Obfuscation, John R. Bochert
Software And Critical Technology Protection Against Side Channel Analysis Through Dynamic Hardware Obfuscation, John R. Bochert
Theses and Dissertations
Side Channel Analysis (SCA) is a method by which an adversary can gather information about a processor by examining the activity being done on a microchip though the environment surrounding the chip. Side Channel Analysis attacks use SCA to attack a microcontroller when it is processing cryptographic code, and can allow an attacker to gain secret information, like a crypto-algorithm's key. The purpose of this thesis is to test proposed dynamic hardware methods to increase the hardware security of a microprocessor such that the software code being run on the microprocessor can be made more secure without having to change …
Sub-Circuit Selection And Replacement Algorithms Modeled As Term Rewriting Systems, Eric D. Simonaire
Sub-Circuit Selection And Replacement Algorithms Modeled As Term Rewriting Systems, Eric D. Simonaire
Theses and Dissertations
Intent protection is a model of software obfuscation which, among other criteria, prevents an adversary from understanding the program’s function for use with contextual information. Relating this framework for obfuscation to malware detection, if a malware detector can perfectly normalize a program P and any obfuscation (variant) of the program O(P), the program is not intent protected. The problem of intent protection on programs can also be modeled as intent protection on combinational logic circuits. If a malware detector can perfectly normalize a circuit C and any obfuscation (variant) O(C) of the circuit, the circuit is not intent protected. In …
Secureqemu: Emulation-Based Software Protection Providing Encrypted Code Execution And Page Granularity Code Signing, William B. Kimball
Secureqemu: Emulation-Based Software Protection Providing Encrypted Code Execution And Page Granularity Code Signing, William B. Kimball
Theses and Dissertations
This research presents an original emulation-based software protection scheme providing protection from reverse code engineering (RCE) and software exploitation using encrypted code execution and page-granularity code signing, respectively. Protection mechanisms execute in trusted emulators while remaining out-of-band of untrusted systems being emulated. This protection scheme is called SecureQEMU and is based on a modified version of Quick Emulator (QEMU) [5]. RCE is a process that uncovers the internal workings of a program. It is used during vulnerability and intellectual property (IP) discovery. To protect from RCE program code may have anti-disassembly, anti-debugging, and obfuscation techniques incorporated. These techniques slow the …
Hardware, Software And Data Analysis Techniques For Sram-Based Field Programmable Gate Array Circuits, Eugene B. Hockenberry
Hardware, Software And Data Analysis Techniques For Sram-Based Field Programmable Gate Array Circuits, Eugene B. Hockenberry
Theses and Dissertations
This work presents a built, tested, and demonstrated test structure that is low-cost, flexible, and re-usable for robust radiation experimentation, primarily to investigate memory, in this case SRAMs and SRAM-based FPGAs. The space environment can induce many kinds of failures due to radiation effects. These failures result in a loss of money, time, intelligence, and information. In order to evaluate technologies for potential failures, a detailed test methodology and associated structure are required. In this solution, an FPGA board was used as the controller platform, with multiple VHDL circuit controllers, data collection and reporting modules. The structure was demonstrated by …
Obfuscation Framework Based On Functionally Equivalent Combinatorial Logic Families, Moses C. James
Obfuscation Framework Based On Functionally Equivalent Combinatorial Logic Families, Moses C. James
Theses and Dissertations
This thesis aims to be a few building blocks in the bridge between theoretical and practical software obfuscation that researchers will one day construct. We provide a method for random uniform selection of circuits based on a functional signature and specific construction specifiers. Additionally, this thesis includes the first formal definition of an algorithm that performs only static analysis on a program; that is analysis that does not rely on the input and output behavior of the analyzed program. This is analogous to some techniques used in real-world software reverse engineering. Finally, this thesis uses the equivalent circuit library to …
Software Obfuscation With Symmetric Cryptography, Alan C. Lin
Software Obfuscation With Symmetric Cryptography, Alan C. Lin
Theses and Dissertations
Software protection is of great interest to commercial industry. Millions of dollars and years of research are invested in the development of proprietary algorithms used in software programs. A reverse engineer that successfully reverses another company‘s proprietary algorithms can develop a competing product to market in less time and with less money. The threat is even greater in military applications where adversarial reversers can use reverse engineering on unprotected military software to compromise capabilities on the field or develop their own capabilities with significantly less resources. Thus, it is vital to protect software, especially the software’s sensitive internal algorithms, from …
Locating Encrypted Data Hidden Among Non-Encrypted Data Using Statistical Tools, Walter J. Hayden
Locating Encrypted Data Hidden Among Non-Encrypted Data Using Statistical Tools, Walter J. Hayden
Theses and Dissertations
This research tests the security of software protection techniques that use encryption to protect code segments containing critical algorithm implementation to prevent reverse engineering. Using the National Institute of Standards and Technology (NIST) Tests for Randomness encrypted regions hidden among non-encrypted bits of a binary executable file are located. The location of ciphertext from four encryption algorithms (AES, DES, RSA, and TEA) and three block sizes (10, 100, and 500 32-bit words) were tested during the development of the techniques described in this research. The test files were generated from the Win32 binary executable file of Adobe's Acrobat Reader version …
Software Protection Against Reverse Engineering Tools, Joshua A. Benson
Software Protection Against Reverse Engineering Tools, Joshua A. Benson
Theses and Dissertations
Advances in technology have led to the use of simple to use automated debugging tools which can be extremely helpful in troubleshooting problems in code. However, a malicious attacker can use these same tools. Securely designing software and keeping it secure has become extremely difficult. These same easy to use debuggers can be used to bypass security built into software. While the detection of an altered executable file is possible, it is not as easy to prevent alteration in the first place. One way to prevent alteration is through code obfuscation or hiding the true function of software so as …
Afit Uav Swarm Mission Planning And Simulation System, James N. Slear
Afit Uav Swarm Mission Planning And Simulation System, James N. Slear
Theses and Dissertations
The purpose of this research is to design and implement a comprehensive mission planning system for swarms of autonomous aerial vehicles. The system integrates several problem domains including path planning, vehicle routing, and swarm behavior. The developed system consists of a parallel, multi-objective evolutionary algorithm-based path planner, a genetic algorithm-based vehicle router, and a parallel UAV swarm simulator. Each of the system's three primary components are developed on AFIT's Beowulf parallel computer clusters. Novel aspects of this research include: integrating terrain following technology into a swarm model as a means of detection avoidance, combining practical problems of path planning and …
Metamorphism As A Software Protection For Non-Malicious Code, Thomas E. Dube
Metamorphism As A Software Protection For Non-Malicious Code, Thomas E. Dube
Theses and Dissertations
Most organizations are aware that threats from trusted insiders pose a great risk to their organization and are very difficult to protect against. Auditing is recognized as an effective technique to detect malicious insider activities. However, current auditing methods are typically applied with a one-size-fits-all approach and may not be an appropriate mitigation strategy, especially towards insider threats. This research develops a 4-step methodology for designing a customized auditing template for a Microsoft Windows XP operating system. Two tailoring methods are presented which evaluate both by category and by configuration. Also developed are various metrics and weighting factors as a …
Toward The Static Detection Of Deadlock In Java Software, Jose E. Fadul
Toward The Static Detection Of Deadlock In Java Software, Jose E. Fadul
Theses and Dissertations
Concurrency is the source of many real-world software reliability and security problems. Concurrency defects are difficult to detect because they defy conventional software testing techniques due to their non-local and non-deterministic nature. We focus on one important aspect of this problem: static detection of the possibility of deadlock - a situation in which two or more processes are prevented from continuing while each waits for resources to be freed by the continuation of the other. This thesis proposes a flow-insensitive interprocedural static analysis that detects the possibility that a program can deadlock at runtime. Our analysis proceeds in two steps. …
Software Development Outsourcing Decision Support Tool With Neural Network Learning, James D. Newberry
Software Development Outsourcing Decision Support Tool With Neural Network Learning, James D. Newberry
Theses and Dissertations
The Air Force (AF) needs an evolving software tool for guiding decision makers through the complexities of software outsourcing. Previous research identified specific outsourcing strategies and linked them to goals and consequences through a variety of relationship rules. These strategies and relationship rules were inserted into a decision support tool. Since that time, more historical data and outsourcing literature has been collected thus necessitating an update to such a tool. As the number of software outsourcing projects are completed, the AF must capture the outsourcing decision experiences which guided the projects and their outcomes. In order to efficiently incorporate this …
The Generalizability Of Private Sector Research On Software Project Management In Two Usaf Organizations: An Exploratory Study, Michael R. Garman
The Generalizability Of Private Sector Research On Software Project Management In Two Usaf Organizations: An Exploratory Study, Michael R. Garman
Theses and Dissertations
Project managers typically set three success criteria for their projects: meet specifications, be on time, and be on budget. However, software projects frequently fail to meet these criteria. Software engineers, acquisition officers, and project managers have all studied this issue and made recommendations for achieving success. But most of this research in peer reviewed journals has focused on the private sector. Researchers have also identified software acquisitions as one of the major differences between the private sector and public sector MIS. This indicates that the elements for a successful software project in the public sector may be different from the …
Inquisitive Pattern Recognition, Amy L. Magnus
Inquisitive Pattern Recognition, Amy L. Magnus
Theses and Dissertations
The Department of Defense and the Department of the Air Force have funded automatic target recognition for several decades with varied success. The foundation of automatic target recognition is based upon pattern recognition. In this work, we present new pattern recognition concepts specifically in the area of classification and propose new techniques that will allow one to determine when a classifier is being arrogant. Clearly arrogance in classification is an undesirable attribute. A human is being arrogant when their expressed conviction in a decision overstates their actual experience in making similar decisions. Likewise given an input feature vector, we say …
Visual Execution Analysis For Multiagent Systems, Chong Kil
Visual Execution Analysis For Multiagent Systems, Chong Kil
Theses and Dissertations
Multiagent systems have become increasingly important in developing complex software systems. Multiagent systems introduce collective intelligence and provide benefits such as flexibility, scalability, decentralization, and increased reliability. A software agent is a high-level software abstraction that is capable of performing given tasks in an environment without human intervention. Although multiagent systems provide a convenient and powerful way to organize complex software systems, developing such system is very complicated. To help manage this complexity this research develops a methodology and technique for analyzing, monitoring and troubleshooting multiagent systems execution. This is accomplished by visualizing a multiagent system at multiple levels of …
Suitability Of Unidata Metapps For Incorporation In Platform-Independent User-Customized Aviation Weather Products Generation Software, Harmen P. Visser
Suitability Of Unidata Metapps For Incorporation In Platform-Independent User-Customized Aviation Weather Products Generation Software, Harmen P. Visser
Theses and Dissertations
The Air Force Combat Climatology Center (AFCCC) is tasked to provide long-range seasonal forecasts for worldwide locations. Currently, the best long-range temperature forecasts the weather community has are the climatological standard normals. This study creates a stepping-stone into the solution of long-range forecasting by finding a process to predict temperatures better than those using climatological standard normals or simple frequency distributions of occurrences. Northern Hemispheric teleconnection indices and the standardized Southern Oscillation index are statistically compared to three-month summed Heating Degree Days (HDDs) and Cooling Degree Days (CDDs) at 14 U.S. locations. First, linear regression was accomplished. The results showed …
A Flexible Framework For Collaborative Visualization Applications Using Java Spaces, Sean C. Butler
A Flexible Framework For Collaborative Visualization Applications Using Java Spaces, Sean C. Butler
Theses and Dissertations
The complexity of modern tasks is rising along with the level of technology. Two techniques commonly used to deal with complexity are collaboration and information visualization. Recently, computer networks have arisen as a powerful means of collaboration, and many new technologies are being developed to better utilize them. Among the newer, more promising of these technologies is Sun Microsystems' JavaSpaces ™, a high-level network programming API. This thesis describes a tool for developing collaborative visualization software using JavaSpaces-an application framework and accompanying toolkit. In addition to a detailed description of the framework, the thesis also describes an application implemented using …
Software Domain Model Integration Methodology For Formal Specifications, Joel C. Nonnweiler
Software Domain Model Integration Methodology For Formal Specifications, Joel C. Nonnweiler
Theses and Dissertations
Using formal methods to create automatic code generation systems is one of the goals of Knowledge Based Software Engineering (KBSE) groups. The research of the Air Force Institute of Technology KBSE group has focused on the utilization of formal languages to represent domain model knowledge within this process. The code generation process centers around correctness preserving transformations that convert domain models from their analysis representations through design to the resulting implementation code. The diversity of the software systems that can be developed in this manner is limited only by the availability of suitable domain models. Therefore it should be possible …
Selecting A Software Engineering Methodology Using Multiobjective Decision Analysis, Scott A. O'Malley
Selecting A Software Engineering Methodology Using Multiobjective Decision Analysis, Scott A. O'Malley
Theses and Dissertations
With the emergence of agent-oriented software engineering methodologies, software developers have a new set of tools to solve complex software requirements. One problem software developers face is to determine which methodology is the best approach to take to developing a solution. A number of factors go into the decision process. This thesis defines a decision making process that can be used by a software engineer to determine whether or not a software engineering approach is an appropriate system development strategy. This decision analysis process allows the software engineer to classify and evaluate a set of methodologies while specifically considering the …
Transforming Analysis Models Into Design Models For The Multiagent Engineering Systems (Mase) Methodology, Clint H. Sparkman
Transforming Analysis Models Into Design Models For The Multiagent Engineering Systems (Mase) Methodology, Clint H. Sparkman
Theses and Dissertations
Agent technology has received much attention in the last few years because of the advantages that multiagent systems have in complex, distributed environments. For multiagent systems are to be effective, they must be reliable, robust, and secure. AFIT's Agent Research Group has developed a complete lifecycle methodology, called Multiagent Systems Engineering (MaSE), for analyzing, designing, and developing heterogeneous multiagent systems. However, developing multiagent systems is a complicated process, and there is no guarantee that the resulting system meets the initial requirements and will operate reliably with the desired behavior. The purpose of this research was to develop a semi-automated formal …
Design And Specification Of Dynamic, Mobile And Reconfigurable Multiagent Systems, Athie L. Self
Design And Specification Of Dynamic, Mobile And Reconfigurable Multiagent Systems, Athie L. Self
Theses and Dissertations
Multiagent Systems use the power of collaborative software agents to solve complex distributed problems. There are many Agent-Oriented Software Engineering (AOSE) methodologies available to assist system designers to create multiagent systems. However, none of these methodologies can specify agents with dynamic properties such as cloning, mobility or agent instantiation. This thesis starts the process to bridge the gap between AOSE methodologies and dynamic agent platforms by incorporating mobility into the current Multiagent Systems Engineering (MaSE) methodology. Mobility was specified within all components composing a mobile agent class. An agent component was also created that integrated the behavior of the components …
Validation And Verification Of Formal Specifications In Object-Oriented Software Engineering, Steven A. Thomson
Validation And Verification Of Formal Specifications In Object-Oriented Software Engineering, Steven A. Thomson
Theses and Dissertations
The use of formal specifications allows for a software system to be defined with stringent mathematical semantics and syntax via such tools as propositional calculus and set theory. There are many perceived benefits garnered from formal specifications, such as a thorough and in-depth understanding of the domain and system being specified and a reduction in user requirement ambiguity. Probably the greatest benefit of formal specifications, and that which is least capitalized upon, is that mathematical proof procedures can be used to test and prove internal consistency and syntactic correctness in an effort to ensure comprehensive validation and verification (V&V). The …
Distributed Object System Engineering For Terminal Aerodrome Forecast Validation And Metrics Processing, James S. Douglas
Distributed Object System Engineering For Terminal Aerodrome Forecast Validation And Metrics Processing, James S. Douglas
Theses and Dissertations
Distributed object systems are a very complex intertwining of heterogeneous hardware, software, and operating systems coupled with communication networks of varying protocols and capacities. Distributed components offer improved performance through parallel processing, improved expansion and scalability opportunities through modularity, improved availability through replication, and improved resource sharing and interoperability through interconnection. This research provides a distributed system design methodology to validate terminal forecasts and gather metrics for the Air Force Weather Agency. Proven principles such as component reuse and architectural development are applied through the use of parameterized types and design patterns. A client/server measurement model is developed to show …
A Formal Methodology And Technique For Verifying Communication Protocols In A Multi-Agent Environment, Timothy H. Lacey
A Formal Methodology And Technique For Verifying Communication Protocols In A Multi-Agent Environment, Timothy H. Lacey
Theses and Dissertations
As network bandwidth increases, distributed applications are becoming increasingly prevalent. Systems using these applications are very complicated to build and must be dependable. Software agents are ideal for breaking complicated problems into manageable subtasks. Agent conversations, a series of messages passed between agents, are the cornerstone of multi-agent systems and must be deemed correct before being placed into service. The purpose of this research was to develop a formal methodology and technique to verify that the communication protocols defined in a multi-agent environment were valid. This was accomplished by examining agent conversations before deploying the system. An additional goal of …