Internship

AlmaSec actively collaborates with companies, in Italy and in the World. The main purpose is to consolidate the link between university and industry to better shape the students who want to join as early as possible the business world. The first step is the internship experience, on this page you can find the ones currently active.

SAP

Opportunity for a 6-month internship Security Research @ SAP Labs France Sophia-Antipolis – France

SAP’s security vision is built on 5 ideals to secure business: Defendable Application, Zero-Knowledge, Zero-Vulnerability, Security by Default, and Transparency. SAP’s security research group lays the foundation for realising the vision: The 30+ researchers of the Security Research unit focus on security engineering (e.g., the automation of the secure software development lifecycle), secure business execution (e.g., business process security and security in cloud based business applications) and secure operations (e.g., secure maintenance and support of complex and heterogeneous cloud IT landscapes). Security Research proposes a 6-month internship in its Sophia-Antipolis offices (Mougins, France).

Available Internships:

Controlled Cyber Security Threat Information Sharing

The internship focusses on the development of access and usage control solutions applied to the Hadoop software family, big data architecture and on their interplay with CTI-related standards. The activities are part of a collaborative innovation project funded by the European Commission, C3ISP, in cooperation with major academic and industrial organizations.

MORE INFO

Discover Vulnerabilities in Open-Source through Mining Software Repositories

Today, tools supporting such impact assessments rely on so-called vulnerability databases such as the NVD, which are enumerations of known software vulnerabilities. Those databases, however, cannot provide complete coverage, i.e., many known vulnerabilities will never be listed. This internship aims at automatically discovering vulnerabilities and their fixes by mining the software repositories of open-source projects. The goal is to become independent from questions like whether, when and how information about vulnerabilities is listed in vulnerability databases.

MORE INFO

Secure Integration of Internet of Things

The involvement of multiple actors in an IoT scenario (e.g. device, network, platform, application,professional services providers, etc) together with LPN constraints makes the fulfillment of an end-to-end data protection (i.e. confidentiality and integrity) a challenging endeavor. Nevertheless, the integration of IoT with business applications raises several security challenges: confidentiality and integrity of IoT information, secure device and software management. The goal of this internship is thus to assess different industry scenarios, identify associated security requirements. In a second phase, the candidate will have to implement a Proof of Concept demonstrating a security solution on a selected scenario.

MORE INFO

Honeypot-based Self Defense

We have developed a basic proof-of-concept named “SunDEw” (Self-Defense Environment) working for cloud applications running on node.js. There are many areas where it can be enhanced to bring it to the next level. In this context, the goals of the internship will be to address a maximum of the following enhancement tracks: • Understand the current prototype, its features and limitations; • Re-design it as a Software-as-a-Service architecture for enabling developers to ‘tokenize’ their app with low effort; • Fingerprint attackers in order to rethink / fine-tune the trapping mechanism; • Develop the ‘response’ part of the solution, consisting in: automatic application cloning, database replication and fake data generation; • Develop a just-in-time tokenization process, for auto-capturing backdoors created on the fly by attackers; • Test the solution on productive applications, gather developer feedback and tune the solution accordingly.

MORE INFO

Machine learning based Dark Web Crawler

In this internship, the student will work on a prototype that automatically monitors server’s sources from the Dark Web to identify on real time the new Cyber Security threats targeting companies. In order to identify and classify the collected data, we rely on an advanced supervised machine learning system.

MORE INFO

Discover Vulnerabilities in Open-Source through Mining Software Repositories

Today, tools supporting such impact assessments rely on so-called vulnerability databases such as the NVD, which are enumerations of known software vulnerabilities. Those databases, however, cannot provide complete coverage, i.e., many known vulnerabilities will never be listed. This internship aims at automatically discovering vulnerabilities and their fixes by mining the software repositories of open-source projects. The goal is to become independent from questions like whether, when and how information about vulnerabilities is listed in vulnerability databases.

MORE INFO

Security for Deep Learning

Applying deep learning to a problem involving medical, financial, personal sensitive data requires not only accurate predictions, but also a careful attention to data privacy and security, in conformity and compliance with regulation on data protection. The goal of this internship is two-fold: 1. State of the art on deep learning training and learning over encrypted data 2. Implementation of a PoC demonstrating the feasibility of such approach in an industrial use case

MORE INFO

Development and Support for Security Testing Training

The intern will be directly in contact with experts from different areas like pentesters, static and dynamic tools experts and tools consultants and he/she will gain expertise in the area of static and dynamic security analysis. The intern will work mainly on development tasks. However, he/she should be flexible in order to tackle diverse type of tasks (like support, testing, design and communication).

MORE INFO

Advanced Security Testing Strategies for Web Applications

The specific goals of the internship are as follows: 1) Understanding the SAP development process; 2) Understanding SAST and DAST approaches as well as experiencing with concrete tools/techniques; 3) Studying challenging vulnerabilities (e.g., CSRF and logic flaws) and investigating solutions to detect them with a high degree of automation; 4) Contributing to the development of our testing framework at SAP, based on SAPUI5 technology; 5) Contributing to the development of our testing core engine; 6) Assessing our testing engine against real world SAP and non-SAP scenarios; 7) Support SAP internal users toward the consumption of the testing framework; 8) Documenting the developed software and the overall activities

MORE INFO

Advanced Security Testing Strategies for Web Applications

The specific goals of the internship are as follows: 1) Understanding the SAP development process; 2) Understanding SAST and DAST approaches as well as experiencing with concrete tools/techniques; 3) Studying challenging vulnerabilities (e.g., CSRF and logic flaws) and investigating solutions to detect them with a high degree of automation; 4) Contributing to the development of our testing framework at SAP, based on SAPUI5 technology; 5) Contributing to the development of our testing core engine; 6) Assessing our testing engine against real world SAP and non-SAP scenarios; 7) Support SAP internal users toward the consumption of the testing framework; 8) Documenting the developed software and the overall activities

MORE INFO

Streaming Data Anonymization

The goal of this internship is to perform research and development in streaming data anonymization approaches. We will target the big data scenarios using the Toreador project platform (http://www.toreador-project.eu/ ). We will experiment with machine learning (perhaps using deep learning) to train models on performing anonymization or even on measuring re-identification risks.

MORE INFO

Threat Detection dataset

We are aiming at enhancing the current capabilities of the product by introducing big data analytics capabilities on top of the existing rule-based detection mechanism, as well as applying advanced anonymization techniques on the gathered dataset. In this context, we are aiming at generating diverse realistic datasets in order to assess the capability of different analytics algorithms (supervised learning, unsupervised learning) and anonymization techniques (privbayes, privkagr, ...). As such, the goals of the internship are the following: 1) Deploy the demo SAP Enterprise Threat Detection (SAP ETD) virtual machines into an Amazon AWS account; 2) Setup the demo systems, comprising SAP ETD as well as a Netweaver system, so that Netweaver logs are consumed and analysed by SAP ETD; 3) Write a report dumping log data on the Netweaver side and on the ETD side, for offline import and analysis; 4) Develop programs simulating Netweaver system users, generating log data for analysis 5) Develop ‘vulnerable’ programs prone to abuse; 6) Simulate users both using and abusing the vulnerable program(s) in order to generate a realistic log dataset

MORE INFO

Contact

© Copyright 2017 by AlmaSec Lab Lab 2 University of Bologna, Engineering Faculty; Viale del Risorgimento,2 Bologna, 40136 Italy (+39) 051 20 93148