• Title/Summary/Keyword: 취약성 지도

Search Result 1,849, Processing Time 0.031 seconds

Weakness of Andriod Smartphone Applications against Electromagnetic Analsysis (안드로이드 기반 스마트폰 어플리케이션의 전자기파분석 공격 취약성)

  • Park, JeaHoon;Kim, Soo Hyeon;Han, Daewan
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.23 no.6
    • /
    • pp.1017-1023
    • /
    • 2013
  • With the growing use of smartphones, many secure applications are performed on smartphones such as banking, payment, authentication. To provide security services, cryptographic algorithms are performed on smartphones' CPU. However, smartphone's CPU has no considerations against side-channel attacks including Electromagnetic Analysis (EMA). In DesignCon 2012, G. Kenworthy introduced the risk of cryptographic algorithms operated on smartphone against EMA. In this paper, using improved experimental setups, we performed EMA experiments on androin smartphones' commercial secure applications. As a result, we show that the weakness of real application. According to the experimental setups, we picked up the operation of w-NAF scalar multiplication from the operation of Google's Play Store application using radiated EM signal. Also, we distinguished scalar values (0 or not) of w-NAF scalar multiplication.

The Structural Analysis and Implications of Security Vulnerabilities In Mobile Srevice Network (모바일 서비스 네트워크의 구조적 분석과 보안 취약성)

  • Kim, Jang-Hwan
    • Convergence Security Journal
    • /
    • v.16 no.5
    • /
    • pp.49-55
    • /
    • 2016
  • Recently mobile service industry has grown very rapidly. In this paper, We investigated the changes in mobile service network as well as security vulnerabilities of network in future 5G mobile service network, too. Recently, there are rapid developement of information and communication and rapid growth of mobile e-business users. Therefore We try to solve security problem on the internet environment which charges from wire internet to wireless internet or wire/wireless internet. Since the wireless mobile environment is limited, researches such as small size, end-to-end and privacy security are performed by many people. In addition, there is a need of internetworking between mobile and IoT services. Wireless Application Protocol has weakness of leaking out information from Gateway which connected wire and wireless communication. As such, We investigate the structure of mobile service network in order to gain security vulnerabilities and insights in this paper.

Study on the physical vulnerability factors in the convergence IT environment (융합 IT 환경의 물리적 취약요인에 관한 연구)

  • Jeon, Jeong Hoon;Ahn, Chang Hoon;Kim, Sang Choon
    • Convergence Security Journal
    • /
    • v.16 no.1
    • /
    • pp.59-68
    • /
    • 2016
  • Recently, many domestic and foreign industries is increasing gradually in the importance of security such as the emergence of a Convergence Information Technology(internet of things, cloud computing service, big data etc). Among these techniques, the industrial security market is expected to grow gradually and the evolution of security technologies, as well as vulnerabilities are also expected to increase. Therefore, an increase in physical vulnerability factors it is no exaggeration to standards that are determining the security of industrial security. In this paper will be analyzed to the physical security technology and case study, physical vulnerability factor. Thereby this is expected to be utilized as a basis for the countermeasure of physical corresponding infringement and attack in a future.

Development of User Oriented Vulnerability Analysis Application on Smart Phone (사용자 중심의 스마트폰 보안 취약성 분석 어플리케이션 개발)

  • Cho, Sik-Wan;Jang, Won-Jun;Lee, Hyung-Woo
    • Journal of the Korea Convergence Society
    • /
    • v.3 no.2
    • /
    • pp.7-12
    • /
    • 2012
  • An advanced and proactive response mechanism against diverse attacks should be proposed for enhance its security and reliability on android based commercial smart work device. In this study, we propose a user-oriented vulnerability analysis and response system on commercial smart work device based on android when diverse attacks are activated. Proposed mechanism uses simplified and optimized memory for monitoring and detecting the abnormal behavior on commercial smart work device, with which we can find and determine the attacker's attempts. Additionally, proposed mechanism provides advanced vulnerability analysis and monitoring/control module.

A Study of Effectiveness of the Improved Security Operation Model Based on Vulnerability Database (취약점 데이터베이스 기반 개선된 보안관제 모델의 효과성 연구)

  • Hyun, Suk-woo;Kwon, Taekyoung
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.29 no.5
    • /
    • pp.1167-1177
    • /
    • 2019
  • In this paper, the improved security operation model based on the vulnerability database is studied. The proposed model consists of information protection equipment, vulnerability database, and a dashboard that visualizes and provides the results of interworking with detected logs. The evaluation of the model is analyzed by setting up a simulated attack scenario in a virtual infrastructure. In contrast to the traditional method, it is possible to respond quickly to threats of attacks specific to the security vulnerabilities that the asset has, and to find redundancy between detection rules with a secure agent, thereby creating an optimal detection rule.

A Study on the Security Processor Design based on Pseudo-Random Number in Web Streaming Environment

  • Lee, Seon-Keun
    • Journal of the Korea Society of Computer and Information
    • /
    • v.25 no.6
    • /
    • pp.73-79
    • /
    • 2020
  • Nowadays, with the rapid spread of streaming services in the internet world, security vulnerabilities are also increasing rapidly. For streaming security, this paper proposes a PN(pseudo-random noise) distributed structure-based security processor for web streaming contents(SP-WSC). The proposed SP-WSC is basically a PN distributed code algorithm designed for web streaming characteristics, so it can secure various multimedia contents. The proposed SP-WSC is independent of the security vulnerability of the web server. Therefore, SP-WSC can work regardless of the vulnerability of the web server. That is, the SP-WSC protects the multimedia contents by increasing the defense against external unauthorized signals. Incidentally it also suggests way to reduce buffering due to traffic overload.

Investigation of Side Channel Analysis Attacks on Financial IC Cards (금융IC카드에 대한 부채널분석공격 취약성 분석)

  • Kim, Chang-Kyun;Park, Il-Hwan
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.18 no.1
    • /
    • pp.31-39
    • /
    • 2008
  • The development of next-generation resident registration cards, financial IC cards and administrative agency IC cards based on a smart card is currently coming out in Korea. However, the low-price IC cards without countermeasures against side channel analysis attacks are expected to be used fer cost reduction. This paper has investigated the side channel resistance of financial IC cards that are currently in use and have performed DPA attacks on the financial IC cards. We have been able to perform successful DPA attacks on these cards by using only 100 power measurement traces. From our experiment results, we have been able to extract the master key used for encryption of a count PIN number.

Analysis of Improvement Effects on Building Approach Vulnerability by Expanding Emergency Rescue Centers in Busan (부산지역 119구조대 증설을 통한 건축물 접근취약성 개선효과 분석)

  • Choi, Jun-Ho;Lee, Ji-Soo;Hong, Won-Hwa
    • Fire Science and Engineering
    • /
    • v.29 no.5
    • /
    • pp.79-87
    • /
    • 2015
  • The placement of Korean fire-fighting administrative power in urban areas shows regional unbalance. In an ideal system, all citizens would be provided with equal fire protection and rescue services, but this is usually difficult to realize due to regional conditions or budget problems. In the case of Busan Metropolitan City, we deduced that it is impossible for half of the buildings to receive rescue services within 5 min, and the conditions are much worse for areas with long or wide fire-fighting service regions. The approach vulnerability for the existing emergency rescue squad locations was assessed. The results revealed that if a rescue team's location is shifted, the improvement effect will be virtually insignificant because of their geographical position. Therefore, this study suggests the establishment of additional rescue squads. It is proven that adding 5 rescue centers in the following locations could solve the problem of approach vulnerability: Bukbu, Gangseo, Geumjeong, Gijang, and Haeundae, in order of effectiveness. The number of buildings in the areas is 53,546.

The Development and Application Of Cyber Counseling System for the Gifted Class (영재 학급을 위한 사이버 상담 시스템 개발 및 적용)

  • Chung, Hyun-Nam;Kim, Dong-Hyu;Goh, Byung-Oh
    • Journal of The Korean Association of Information Education
    • /
    • v.8 no.2
    • /
    • pp.177-187
    • /
    • 2004
  • It soaks but from 2003 the gifted child whom it is propelling as the enterprise of real national dimension oneself will know and it will do well the case which with the thought which goes wrong it lets to let alone is many but about lower social unsuitable Eung and melancholia, nervous characteristic anorexia cung with the back the same multi branch problem point occurs with emotional vulnerability of the gifted person. From the gifted people it grasps the emotional vulnerability which occurs from the dissertation which it sees consequently and the gifted person cyber counseling system which does the hazard web which solves a problem point in base plan and it embodies. One side, it applied the gifted child and the parents who are participating to an Dae-jeon 6th area joint the gifted person class in the gifted person cyber counseling system which it develops the result and it analyzed. Emotional vulnerability of the analysis result the gifted child considerable portion there is a possibility the fact that it overcomes, if facing each other it will be able to complement the portion which is insufficient from consultation.

  • PDF

An Analysis of The Relationship Among Nursing Students' Perception of Target Vulnerability and Target Advocacy, Child Rights Awareness, and Child Abuse Reporting Intention (간호대학생이 지각한 대상자 취약성 및 옹호, 아동권리인식, 아동학대 신고의도 간의 관계 분석)

  • Ji-Ah Song;Jae Woo Oh
    • Journal of Industrial Convergence
    • /
    • v.22 no.3
    • /
    • pp.155-163
    • /
    • 2024
  • Nursing students, as prospective nurses, are expected to act as child abuse reporters and advocates for child targets. Therefore, this study aimed to provide a basis for developing a child abuse prevention education program for nursing students by determining the extent of nursing students' perceived target vulnerability and target advocacy, child rights awareness, and intention to report child abuse, and analyzing the relationships among the variables. This study is a descriptive survey study to identify the effects of target vulnerability, target advocacy, and child rights awareness on intention to report child abuse among 154 nursing students, and the data collection period was from July 3 to July 31, 2023, and the collected data were analyzed using SPSS 25.0 program. As a result of identifying the influential factors on nursing students' intention to report child abuse, child abuse education, championing social justice as a sub-variable of target advocacy, and target vulnerability, the explanatory power of these variables was 35.8%. Based on the results of this study, it is suggested that it is necessary to increase activities through the development and application of simulation education based on actual clinical cases in order to increase nursing students' interest in and education about child abuse.