• 제목/요약/키워드: Code Vulnerability

검색결과 149건 처리시간 0.198초

Fragility assessment of RC-MRFs under concurrent vertical-horizontal seismic action effects

  • Farsangi, Ehsan Noroozinejad;Tasnimi, Abbas Ali;Mansouri, Babak
    • Computers and Concrete
    • /
    • 제16권1호
    • /
    • pp.99-123
    • /
    • 2015
  • In this study, structural vulnerability of reinforced concrete moment resisting frames (RC-MRFs) by considering the Iran-specific characteristics is investigated to manage the earthquake risk in terms of multicomponent seismic excitations. Low and medium rise RC-MRFs, which constitute approximately 80-90% of the total buildings stock in Iran, are focused in this fragility-based assessment. The seismic design of 3-12 story RC-MRFs are carried out according to the Iranian Code of Practice for Seismic Resistant Design of Buildings (Standard No. 2800), and the analytical models are formed accordingly in open source nonlinear platforms. Frame structures are categorized in three subclasses according to the specific characteristics of construction practice and the observed seismic performance after major earthquakes in Iran. Both far and near fields' ground motions have been considered in the fragility estimation. An optimal intensity measure (IM) called Sa, avg and beta probability distribution were used to obtain reliable fragility-based database for earthquake damage and loss estimation of RC buildings stock in urban areas of Iran. Nonlinear incremental dynamic analyses by means of lumped-parameter based structural models have been simulated and performed to extract the fragility curves. Approximate confidence bounds are developed to represent the epistemic uncertainties inherent in the fragility estimations. Consequently, it's shown that including vertical ground motion in the analysis is highly recommended for reliable seismic assessment of RC buildings.

A study on Merchant Ship′s Security System for the Correspondence of Maritime Security Threats (해양보안위협 대응을 위한 선박보안시스템에 관한 연구)

  • 이은방
    • Journal of the Korean Society of Marine Environment & Safety
    • /
    • 제9권1호
    • /
    • pp.17-23
    • /
    • 2003
  • With the terrorist attacks on 11 September 2001, the ships and their crew' safety and security have become a major issue in the maritime industries, In high-risk terrorism, not only ship owners and port authorities but also crew members on board should take precautions in the conduct of their business. In this paper, the vulnerability and essential elements in overall security of merchant ship are analyzed with a discussion in depth of the concept and principles of maritime security of merchant ship are analyzed with a discussion in depth of the concept and principles of maritime security management. And then, ship's security model and security system to reduce security rish and to minimize damage are proposed.

  • PDF

Separate Signature Monitoring for Control Flow Error Detection (제어흐름 에러 탐지를 위한 분리형 시그니처 모니터링 기법)

  • Choi, Kiho;Park, Daejin;Cho, Jeonghun
    • IEMEK Journal of Embedded Systems and Applications
    • /
    • 제13권5호
    • /
    • pp.225-234
    • /
    • 2018
  • Control flow errors are caused by the vulnerability of memory and result in system failure. Signature-based control flow monitoring is a representative method for alleviating the problem. The method commonly consists of two routines; one routine is signature update and the other is signature verification. However, in the existing signature-based control flow monitoring, monitoring target application is tightly combined with the monitoring code, and the operation of monitoring in a single thread is the basic model. This makes the signature-based monitoring method difficult to expect performance improvement that can be taken in multi-thread and multi-core environments. In this paper, we propose a new signature-based control flow monitoring model that separates signature update and signature verification in thread level. The signature update is combined with application thread and signature verification runs on a separate monitor thread. In the proposed model, the application thread and the monitor thread are separated from each other, so that we can expect a performance improvement that can be taken in a multi-core and multi-thread environment.

Integrated Security Manager with Agent-based automatic vulnErability checking code generating scanner from intermediate vulnerability checking Language (ISMAEL) (매개 취약점 점검 언어로부터 점검 코드를 자동으로 생성하는 에이전트를 이용한 취약점 관리 시스템)

  • 김수용;서정석;김한성;조상현;임채호;차성덕
    • Proceedings of the Korea Institutes of Information Security and Cryptology Conference
    • /
    • 한국정보보호학회 2001년도 종합학술발표회논문집
    • /
    • pp.453-458
    • /
    • 2001
  • 악의의 침입자로부터 시스템을 보호하기 위한 첫 번째 단계는 시스템의 취약점을 분석하는 일이다. 기존의 시스템 취약점 분석 방법은 주로 네트워크 기반 취약점 점검 도구에 의존해 왔다. 하지만, 네트워크 기반 취약점 점검 도구는 대상 시스템의 제한된 정보만을 이용하여 취약점을 점검하기 때문에 시스템의 모든 취약점에 대한 검사가 불가능하다는 단점이 있다. 호스트 기반 취약점 점검 도구를 사용하면 시스템 내부의 모든 정보를 이용할 수 있지만, 시스템의 OS 종류나 버전에 따라 각기 다른 호스트 기반 취약점 점검 도구를 개발해야 한다는 단점이 있다. 또한, 호스트 기반 취약점 점검 도구들은 많은 호스트들을 동시에 점검하기 힘들다는 점이 문제로 지적되고 있다. 본 논문에서는 호스트 기반 취약점 점검 도구를 에이전트로 구현하여 대상 시스템에 설치하고, 하나의 관리 프로그램에서 여러 에이전트들을 관리함으로써 동시에 많은 호스트의 취약점들을 관리할 수 있는 모델인 ISMAEL을 제시한다. 또한 ISMAEL은 OS에 맞는 여러 호스트 기반 취약점 점검 도구들을 개발해야 하는 문제를 해결하기 위해 OS에 독립인 부분만을 뽑아내고, 그 외 OS에 종속된 부분은 Library 형태로 제공하여, OS에 독립인 부분에서 이 Library를 참조하여 특정 취약점 점검 코드를 자동 생성하고 이를 실행하여 취약성 여부를 판단할 수 있는 구조를 채택하고 있다.

  • PDF

A Study on the Effect of Format String on Secure Programming in C Language (C언어에서 포맷 스트링이 프로그램 보안에 미치는 영향)

  • Lee, Hyung-Bong;Cha, Hong-Jun;Choi, Hyung-Jin
    • The KIPS Transactions:PartC
    • /
    • 제8C권6호
    • /
    • pp.693-702
    • /
    • 2001
  • One of the major characteristics of C language is that it allows us to use pointer type variables to access any area of virtual address space. So, we can read/write/execute from/to virtual memory area not controlled delicately by operating system. We can access such memory area by using format string and it can be a vulnerability of C language from the point of secure programming. In this paper, we analyze in detail the process of security attack based on format string and then exploit a new virus style attack which is stepwise and durable with some actual scenarios to warn the severity of it, and grope for some preliminary responding actions.

  • PDF

Methodology for investigating the behavior of reinforced concrete structures subjected to post earthquake fire

  • Behnam, Behrouz;Ronagh, Hamid R.;Baji, Hassan
    • Advances in concrete construction
    • /
    • 제1권1호
    • /
    • pp.29-44
    • /
    • 2013
  • Post earthquake fire (PEF) can lead to the collapse of buildings that are partially damaged in a prior ground-motion that occurred immediately before the fire. The majority of standards and codes for the design of structures against earthquake ignore the possibility of PEF and thus buildings designed with those codes could be too weak when subjected to a fire after an earthquake. An investigation based on sequential analysis inspired by FEMA356 is performed here on the Life-Safety performance level of structures designed to the ACI 318-08 code after they are subjected to two different earthquake levels with PGA of 0.35 g and 0.25 g. This is followed by a four-hour fire analysis of the weakened structure, from which the time it takes for the weakened structure to collapse is calculated. As a benchmark, the fire analysis is also performed for undamaged structure and before occurrence of earthquake. The results show that the vulnerability of structures increases dramatically when a previously damaged structure is exposed to PEF. The results also show the damaging effects of post earthquake fire are exacerbated when initiated from second and third floor. Whilst the investigation is for a certain class of structures (regular building, intermediate reinforced structure, 3 stories), the results confirm the need for the incorporation of post earthquake fire in the process of analysis and design and provides some quantitative measures on the level of associated effects.

Effects of numerical modeling simplification on seismic design of buildings

  • Raheem, Shehata E Abdel;Omar, Mohamed;Zaher, Ahmed K Abdel;Taha, Ahmed M
    • Coupled systems mechanics
    • /
    • 제7권6호
    • /
    • pp.731-753
    • /
    • 2018
  • The recent seismic events have led to concerns on safety and vulnerability of Reinforced Concrete Moment Resisting Frame "RC-MRF" buildings. The seismic design demands are greatly dependent on the computational tools, the inherent assumptions and approximations introduced in the modeling process. Thus, it is essential to assess the relative importance of implementing different modeling approaches and investigate the computed response sensitivity to the corresponding modeling assumptions. Many parameters and assumptions are to be justified for generation effective and accurate structural models of RC-MRF buildings to simulate the lateral response and evaluate seismic design demands. So, the present study aims to develop reliable finite element model through many refinements in modeling the various structural components. The effect of finite element modeling assumptions, analysis methods and code provisions on seismic response demands for the structural design of RC-MRF buildings are investigated. where, a series of three-dimensional finite element models were created to study various approaches to quantitatively improve the accuracy of FE models of symmetric buildings located in active seismic zones. It is shown from results of the comparative analyses that the use of a calibrated frame model which was made up of line elements featuring rigid offsets manages to provide estimates that match best with estimates obtained from a much more rigorous modeling approach involving the use of shell elements.

A Study of Program Execution Control based on Whitelist (화이트리스트 기반 프로그램 실행 통제 방안 연구)

  • Kim, Chang-hong;Choi, Dae-young;Yi, Jeong-hyun;Kim, Jong-bae
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 한국정보통신학회 2014년도 추계학술대회
    • /
    • pp.346-349
    • /
    • 2014
  • Currently, the growing cyber threat continues, the damage caused by the evolution of malicious code incidents become more bigger. Such advanced attacks as APT using 'zero-day vulnerability' bring easy way to steal sensitive data or personal information. However it has a lot of limitation that the traditional ways of defense like 'access control' with blocking of application ports or signature base detection mechanism. This study is suggesting a way of controlling application activities focusing on keeping integrity of applications, authorization to running programs and changes of files of operating system by hardening of legitimate resources and programs based on 'white-listing' technology which analysis applications' behavior and its usage.

  • PDF

Mobile Auto questions and scoring system (국가 사이버안보 시스템 관련 법률안 분석과 연구)

  • Nam, Won-Hee;Park, Dea-Woo
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 한국정보통신학회 2014년도 추계학술대회
    • /
    • pp.363-365
    • /
    • 2014
  • Internet baking, e-commerce, business processing, etc on smartphone handing could be possible in present days. Ambiguity between cyber and real life has made vulnerability on infrastructure, Gov't Service and National security by cyber terrorism. Especially, Lots of Infrastructure and Gov't Service based on Information Technology were exposed by Cyber terror. Legal system should be improved to keep from these threats. This paper proposed needs of cyber legal system by analyzing proposed cyber related code on Korean National Assembly, issue on Cyber Control Tower, National Cyber Security Industry and Human resource.

  • PDF

Seismic fragility analysis of RC frame-core wall buildings under the combined vertical and horizontal ground motions

  • Taslimi, Arsam;Tehranizadeh, Mohsen;Shamlu, Mohammadreza
    • Earthquakes and Structures
    • /
    • 제20권2호
    • /
    • pp.175-185
    • /
    • 2021
  • This study strives to highlight the importance of considering the vertical ground motions (VGM) in the seismic evaluation of RC buildings. To this aim, IDA (Incremental Dynamic Analysis) is conducted on three code-based designed high-rise RC frame-core wall buildings using a suite of earthquake records comprising of significant VGMs. To unravel the significance of the VGM inclusion on the performance of the buildings, IDAs are conducted in two states (with and without the vertical component), and subsequently based on each analysis, fragility curves are developed. Non-simulated collapse criteria are used to determine the collapse state drift ratio and the area under the velocity spectrum (SIm) is taken into account as the intensity measure. The outcome of this study delineates that the inclusion of VGM leads to the increase in the collapse vulnerability of the structures as well as to the change in the pattern of inter-story drifts and failure mode of the buildings. The results suggested that it would be more conservative if the VGM is included in the seismic assessment and the fragility analysis of RC buildings.