Back to Catalog
163 of 226
PS 26163SOFTWAREMiscellaneousHidden GemFast Prototype (36h)

Security Assessment of the World Monitor application

National Technical Research Organisation (NTRO)National Technical Research Organisation (NTRO)
Google Search
30-Second Plain English Summary

Open-source intelligence (OSINT) and global situational awareness platforms (like 'World Monitor') aggregating live global news, military flight tracking, vessel AIS, and satellite conflict data are vulnerable to API tampering, data poisoning, and unauthorized reverse-engineering. Build an Automated Security Assessment and Red-Teaming Framework for Global OSINT / World Monitor Applications for NTRO that audits web client architecture, tests API endpoints against OWASP Top 10 vulnerabilities, and evaluates supply chain dependency risks.

5-Dimension Strategic ScorecardOverall Score: 4 / 5.0
Innovation
4.1 / 5
36h Feasibility
4.4 / 5
Uniqueness
3.9 / 5
Jury Appeal
4 / 5
Tech Depth
3.8 / 5
Recommended System Architecture Pipeline
Target OSINT Web App / API -> DAST Fuzzer (OWASP ZAP / Custom) -> JavaScript Static Secret Scanner -> SBOM Vulnerability Analyzer -> Secure OSINT Audit Console
Recommended Tech StackClick to search similar
Official Government Problem Description
• Background The world Monitor application is a Web/ Mobile platform that provides users with real-time monitoring, analytics, and reporting features. The application handles user authentication, data visualization, API communication, and role-based access controls. As a security analyst, the task is to evaluate the application's security posture and identify vulnerabilities that could compromise the confidentiality, integrity, or availability of the system. • Description Conduct an authorized security assessment of the World Monitor application to: 1. Identify security vulnerabilities in the application. 2. Assess the potential impact of each vulnerability. 3. Demonstrate proof-of-concept exploitation in a controlled environment. 4. Recommend remediation measures to mitigate the identified risks. • Scope The assessment should focus on: • Authentication and session management • Authorization and access control • Input validation and data handling • API security • Client-side security controls • Secure communication mechanisms • Data storage and privacy protections • Success Criteria The assessment is considered successful if: • At least one valid vulnerability is identified and documented. • Evidence supports the existence of the vulnerability. • Risk and impact are clearly explained. • Practical mitigation strategies are provided • Expected Solution/Deliverables: For each vulnerability discovered, provide: • Vulnerability title • Description • Affected component • Severity rating (e.g., CVSS) • Steps to reproduce • Proof of concept demonstrating the issue in a safe testing environment • Business impact assessment • Remediation recommendations constraints • Testing must be performed only on authorized systems. • No actions should affect production users or data. • Exploitation should be limited to proof-of-concept validation. • Compliance with applicable laws, policies, and ethical hacking guidelines is required.
AI & PPT Citation Format

Smart India Hackathon 2026 Problem Statement PS-26163: "Security Assessment of the World Monitor application", Ministry: National Technical Research Organisation (NTRO). Strategy & Architecture via SIH ONE (https://sihone.pages.dev/ps/26163)

Related Problem Statements in Miscellaneous