Search Results

Now showing 1 - 10 of 94
  • Thumbnail Image
    PublicationEmbargo
    Cryptographic Issues and Vulnerabilities in Web Applications
    (2021) Herath, H M P Kavinda Ranjan Kumara
    Web application security is the most controversial and crucial factor to be concentrated on considering the security aspect of cyberspace. Cryptography takes critical parts of security by implementing encryption and decryption phenomena on data at rest, in moving, and in use to be protected the security breaches. Cryptographic concepts had developed over the last few decades as a result of well-known series of mathematical and logical functions. Weakness of poor programming techniques or leakiness of traditional software development life cycles is a crucial element of the security vulnerabilities that can be a huge impact on several web applications which are currently in existence. The cryptographic vulnerabilities of the web application would depend on several factors such as lack of knowledge on particular subject matters of cryptography, least privilege and contribution of security techniques while cording, unable to proceed with proper standardized vulnerability assessment criteria, the improper adaptation of cryptographic concepts, unable to intended with high secure framework like DevSecOps, depend on the procedures rather than empirical approaches, etc. Sophisticated tools and techniques are necessary factors of driving through the rectification and mitigation of the security vulnerabilities that exist in the web applications whereas implementation process, testing and monitoring of the System Development Life Cycle. This dissertation emphasized indeed a further illustration of cryptographic vulnerability assessment in several specimens collected from different domains from enterprise web applications and related APIs (Application Protocol Interface) currently established. The tools are the critical elements used to evaluate errors on the codes whereas statistical or dynamic analysis. Static tools are given in high percentage of accuracy of the results whereas automated tools are well suited for mega scripting projects such as millions of code evaluated for errors. Java-based code scripting has been dominated still among the huge percentage of the web sources. Python will be established gradually due to the high inbuilt security system on it. Java and Python are the programming languages still being dominated of existence to discuss in the cryptographic vulnerabilities on the process of web application developments. The ultimate goal of this dissertation could be retain valuable sources of documents enriched with sophisticated technics to be used a reference guide for the developers and the security engineers to fulfilled their gaps between code and security requirements
  • Thumbnail Image
    PublicationEmbargo
    Design and Development of an Agent Based Centralized Tool for Analyzing and Managing Security Enhanced Linux Policies
    (2021) Kularatna, Ishara Madushanka
    Security Enhanced Linux also known as the SELinux, facilitates and includes an extensible Mandatory-Access-Control which is called, “MAC” structure/system built within the Linux kernel. An application or a process life cycle which runs as a user (UID or SUID) has the specific authority to access objects such as files, sockets and other processes with Linux’s default Discretionary-Access-Control (DAC). SELinux prescribes the access and the progress privileges of each user, application, process, and the files on the system and administers the communications of these elements utilizing a security strategy that determines how severe or indulgent a given Red Hat EnterpriSELinux establishment ought to be. However, due to its constraints such as, not being user friendly, having too complicated policies and convoluted policy description language, are limiting the implementation of SELinux policies in the IT industry. As a result, there is only few research available on the subject of UI based policy management tools and even those research have limitations such as, inability to remotely manage a host/server, manual documentation and inability to monitor the systems automatically from a dashboard.In order to overcome the said research gap and problems, this research will implement a system, using a web-socket technology that facilitates ability to conversation in full duplex through a just one TCP connection. This system is included with a web socket-agent, which can be installed in server endpoints and has the ability to change SELinux policies, a web-socket server: which can do live communication with the agent to perform policy changes, UI component: to manage policies using user interface and a database component to store policy details.
  • Thumbnail Image
    PublicationOpen Access
    ColorGuard: Ensuring Mobile App Design Compliance with Google Material Design Color and Theme Guidelines
    (SLIIT, 2024-12) Balasooriya, S. A.
    Developing mobile applications today demands significant time and effort. Creating user-friendly user interfaces (UIs) is particularly challenging, with special attention needed for color-related details as they are the first thing customers notice. Numerous guidelines have been introduced to assist mobile UI designers in fostering good interaction between users and UIs. Among these, Google's Material Design guidelines are highly trusted, being developed and maintained by Google. Adhering to these guidelines enables developers and designers to create more efficient and effective UIs, which is crucial for commercial mobile applications. However, reading, understanding, and implementing all these guidelines can be overwhelming for novice UI designers. Additionally, having improvement tips and suggestions is highly beneficial. To address this challenge, this research proposes a web-based solution that reviews developed mobile UIs and provides textual suggestions to improve the UI design according to the guidelines. Since the solution is implemented as a web application, offering an effective way to provide this service across any device and operating system.
  • Thumbnail Image
    PublicationEmbargo
    Biomedical Waste Sorting & Classification Using Deep Learning
    (2021-05) Ahmed Akmal, M. A.
    Biomedical wastes (BMWs) include potentially infectious, sharps, pharmaceuticals and radioactive wastes probably generated by hospitals, vaccination centers, biomedical laboratories, etc. Handling and disposal of biomedical wastes potentially have multiple risk factors. Currently, hospitals and laboratories use color-coded bins to classify and categorize different types of wastes to ease the handling and the disposal process. Sometimes due to human errors these wastes could be miscategorized or misplaced in different bins. In recycling terms this is known as waste contamination. Contaminating the biomedical waste streams causes a huge potential threat to the people who handle them. Computer vision based biomedical waste classification is one of the best ways to prevent these issues. But applying pure computer vision algorithms is much more suitable for small tasks such as pattern recognition, edge detection etc. In order to classify different kinds of biomedical wastes, then convolutional neural networks (CNN) would be a much more suitable choice. This research proposes a deep learning model which accurately classifies several selected biomedical wastes such as syringes, blades and sample collection tubes with a prediction accuracy around 96% on the test dataset. Further the implemented model approximately localizes the biomedical wastes to serve robotics and smart-bin applications.
  • Thumbnail Image
    PublicationOpen Access
    Real-Time ML Integration with CFS to Improve Power Efficiency in Non-Hybrid Linux Systems
    (Sri Lanka Institute of Information Technology, 2025-12) Dissanayake M.D.
    Modern non-hybrid Linux systems rely on the Completely Fair Scheduler (CFS) and Dynamic Voltage and Frequency Scaling (DVFS) to balance performance and energy efficiency. However, this default approach has key limitations: CFS distributes tasks evenly across cores without distinguishing between workload types, while DVFS adjusts frequency based on aggregate load. As a result, CPU-bound and I/O-bound tasks often share the same cores, leading to unnecessary frequency boosts and wasted energy for tasks that don’t require high frequencies. This thesis proposes a machine learning-enhanced scheduling framework that integrates task-type awareness into non-hybrid Linux systems. A decision tree classifier predicts whether tasks are CPU-bound or I/O-bound using lightweight runtime features such as execution time, waiting time, context switches, priority, and niceness values. Classified CPU-bound tasks are consolidated onto selected cores running at higher frequencies, while I/O-bound tasks are grouped on separate cores maintained at lower frequencies. To prevent thermal hotspots and performance degradation, periodic rotation of CPU-bound and I/O-bound core groups is implemented. The scheduler is evaluated against the default CFS using controlled CPU-intensive, I/O-intensive, and mixed workloads generated with Sysbench and FIO. Energy consumption, performance, and Energy-Delay Product (EDP) are measured using perf and turbostat. Experimental results show that the ML-enhanced scheduler reduces energy consumption and improves EDP significantly, whilemaintaining performance levels comparable to the default scheduler. These findings highlight the potential of ML-based task classification to improve DVFS utilization and deliver more energy-efficient scheduling in general-purpose, non-hybrid Linux systems.
  • Thumbnail Image
    PublicationOpen Access
    Generating an Optimal Tour Plan with Optimization
    (2022-09) Rathnayake, R.M.B.P.M
    Tourism is an industry which has a widespread across the globe. It was built around the natural desire in humans to travel, and to facilitate their needs during tours. Within the last two decades there has been a significant expansion in tourism along with the evolution in information and technology. With the growth of the availability of information a lot of travel destinations were added as new choices in tour plans. Having a big number of options always makes finalizing a plan difficult as it complicates choosing between items. Tourists nowadays are facing this difficulty where they end up with tour plans that are not personalized which they do not receive a satisfactory experience. The concepts of optimization in machine learning are used to generate optimal groups of options out of large collections. This research was conducted on using an optimization algorithm to generate an optimal tour plan for a user in a personalized manner. The read will describe the improvements made to the 0-1 knapsack algorithm and present an analysis of the evaluation outcomes.
  • Thumbnail Image
    PublicationOpen Access
    Design and Simulation of a Secure Enterprise IoT Network Using Cisco Packet Tracer with a Federated Learning-Based Secure Method.
    (Sri Lanka Institute of Information Technology, 2025-12) Sumanadeera, H.M. G. G D
    The rapid growth of the Internet of Things (IoT) in businesses has led to major security issues, with botnet attacks being a serious threat. Although Federated Learning (FL) provides a way to detect threats while preserving privacy, it is still vulnerable to data poisoning from harmful devices. Current blockchain solutions for securing FL are often too heavy on resources for widespread use in IoT. This paper offers a two-part integrated approach. First, an enterprise IoT network was designed and simulated securely using a prototype with Cisco Packet Tracer. Second, a new lightweight novel FL framework was developed that did not rely on blockchain, using the N-BaIoT dataset to protect against botnet attacks. The paper proposed Reputation- Weighted Coordinate Median with Update Validity Tests (RWCM+UVT) framework incorporates a reputation-based system, a robust aggregation algorithm, and an adaptive update validation gate. By simulating botnet attacks within this controlled environment, this paper demonstrates that the RWCM+UVT framework effectively identifies and mitigates the impact of malicious devices, achieving near-perfect detection accuracy without the prohibitive overhead of blockchain technology.
  • Thumbnail Image
    PublicationOpen Access
    An IOT-based Design framework for Enhanced Accident Detection Utilizing GPS, GSM and Wi-Fi Technology
    (SLIIT, 2024-12) Sreen, A.S.H
    The rising number of road accidents harmed the increasing death rate and the development of the country. Current research studies have found that minimizing the accident rate is the best solution for death mitigation and crash control. The main objective of the study is to develop an advanced safety accident detection system utilizing GPS, GSM, and Wi-Fi technologies to enhance road safety and accelerate emergency responses. This research evaluates the conceptual framework and development of IOT utilized in advancing safety accident detection framework integrating the use of GPS, GSM, and Wi-Fi technologies to manage accidents and generate real-time alerts. This study expects to significantly enhance accident management through real-time alerting and emergency response generation. To detect the accident, the framework employs the YOLO module and integrates a random forest model to identify the accident environment under three main categories. The research approach included a review of the literature, the creation of a prototype, and modeling and testing. This research outcome shows how IoT-based accident detection systems work effectively by utilizing GPS, GSM, and Wi-Fi technologies to improve accident advanced safety and accident detection on time. The IoT framework was tested based on different testing phases; those steps offered high performance on each level of testing, like 90% accuracy, 95% precision, 100% recall, and 100% F1 score. These findings strengthen the framework's efficiency and effectiveness in accident detection and reporting with the advanced use of the YOLO module and ROBO FLAW features.
  • Thumbnail Image
    PublicationOpen Access
    IoT - Based Multispectral Imaging System for Early Detection of Diseases, Pest Infestations in Kochchi (Dark Green Scotch Bonnet) Plants Using Deep Learning Algorithms
    (Sri Lanka Institute of Information Technology, 2025-12) Banneheka, B. M. C. P.
    Kochchi, also known as the Dark Green Scotch Bonnet, is a valuable chili variety that thrives in Sri Lanka. However, the yield and quality of this crop often suffer due to pests and plant diseases. Traditional detection methods rely on manual inspection, which is labor-intensive, subjective, and typically identifies symptoms only after visible damage occurs. This study proposes a multispectral imaging (MSI) framework combined with deep learning algorithms to achieve early and accurate disease detection under greenhouse conditions. A DJI Mavic 3 Multispectral drone was used to capture synchronized RGB and multispectral bands (Green, Red, Red-Edge, NIR). Preprocessing involved band alignment, vegetation index computation (NDVI, NDRE, GNDVI), and reduce noise, all aimed at spotting early signs of distress before they become severe. A convolutional neural network (CNN) was trained for binary classification of healthy versus infected plants, achieving high accuracy across cross-validation. For plants classified as infected, severity mapping was performed using advanced instance segmentation models, YOLOv11 and Mask R-CNN, followed by HSV color transformation and K-means clustering to quantify lesion area as a percentage of total leaf surface. Evaluation using Accuracy, Precision, Recall, F1-score, Intersection over Union (IoU), and Dice Coefficient confirmed the robustness of the system. The proposed approach demonstrates the potential of multispectral imaging combined with deep learning for early disease detection and severity quantification in Kochchi cultivation, reducing reliance on pesticides and supporting sustainable agriculture.
  • Thumbnail Image
    PublicationOpen Access
    Development Of An Elephant Detection And Repellent System Based On EfficientDet-Lite models
    (2023-02) Pemasinghe, W.D.S.S
    Human-elephant conflict (HEC) has become a major concern in Sri Lanka that results in many unfortunate human and elephant deaths. Methods that are currently in place to mitigate HEC, such as electrical fences have undesirable consequences resulting in both human and elephant casualties. In this paper, we have proposed a method based on computer vision and deep learning that has promising potential for detecting and repelling elephants without endangering the lives of elephants or humans. We have used EfficientDet-Lite models that provide a good compromise between accuracy and performance to be usable with a resource-constrained device like a Raspberry Pi.