• Title/Summary/Keyword: Event Correlation Analysis

Search Result 206, Processing Time 0.025 seconds

Modeling and Simulation of Firewall System and Security Functions of Operating System for Network Security (네트워크 보안을 위한 침입차단 시스템과 운영체제 보안 기능 모델링 및 시뮬레이션)

  • 김태헌;이원영;김형종;김홍근;조대호
    • Journal of the Korea Society for Simulation
    • /
    • v.11 no.2
    • /
    • pp.1-16
    • /
    • 2002
  • The need for network security is being increasing due to the development of information communication and internet technology. In this paper, firewall models, operating system models and other network component models are constructed. Each model is defined by basic or compound model, referencing DEVS formalism. These models and the simulation environment are implemented with MODSIM III, a general purpose, modular, block-structured high-level programming language which provides direct support for object-oriented programming and discrete-event simulation. In this simulation environment with representative attacks, the following three attacks are generated, SYN flooding and Smurf attack as an attack type of denial of service, Mail bomb attack as an attack type of e-mail. The simulation is performed with the models that exploited various security policies against these attacks. The results of this study show that the modeling method of packet filtering system, proxy system, unix and windows NT operating system. In addition, the results of the simulation show that the analysis of security performance according to various security policies, and the analysis of correlation between availability and confidentiality according to security empowerment.

  • PDF

Design and Implementation of Web Attack Detection System Based on Integrated Web Audit Data (통합 이벤트 로그 기반 웹 공격 탐지 시스템 설계 및 구현)

  • Lee, Hyung-Woo
    • Journal of Internet Computing and Services
    • /
    • v.11 no.6
    • /
    • pp.73-86
    • /
    • 2010
  • In proportion to the rapid increase in the number of Web users, web attack techniques are also getting more sophisticated. Therefore, we need not only to detect Web attack based on the log analysis but also to extract web attack events from audit information such as Web firewall, Web IDS and system logs for detecting abnormal Web behaviors. In this paper, web attack detection system was designed and implemented based on integrated web audit data for detecting diverse web attack by generating integrated log information generated from W3C form of IIS log and web firewall/IDS log. The proposed system analyzes multiple web sessions and determines its correlation between the sessions and web attack efficiently. Therefore, proposed system has advantages on extracting the latest web attack events efficiently by designing and implementing the multiple web session and log correlation analysis actively.

Washoff Characteristics of NPS Pollutants from Artificial Grassland (강우시 인공 초지의 비점오염물질 유출특성 및 상관성)

  • Lee, Jeong-Young;Maniquiz, Marla C.;Choi, Ji-Yeon;Lee, Ja-Eun;Kim, Lee-Hyung
    • Journal of Wetlands Research
    • /
    • v.11 no.3
    • /
    • pp.145-151
    • /
    • 2009
  • Recently the water quality management policy has been changed from managing the point source to controlling the nonpoint sources (NPSs) because of TMDL program. Most NPSs are accumulated on the surface during dry periods. These accumulated pollutants are washed-off during a storm event and highly impairing the water quality of the receiving water bodies. Usually NPS has high uncertainty and is hard to control because of the variability of the rainfall and watershed characteristics. Also, NPS is derived from various land uses. The Ministry of Environment (MOE) is studying and monitoring the pollutant loads from each land use since 2007 to determine the unit pollutant loads. This research was a part of long-term monitoring program conducted to characterize the washoff and provide the mean EMC of artificial grassland. The average EMCs result of BOD, COD, DOC, SS, TN, NH4-N, NO3-N, TP, and PO4-P of the artificial grassland were deterined to 8.2, 17.5, 11.3, 110.1, 3.07, 0.20, 0.75, 0.86 and 0.08 mg/L, respectively. The results of statistical analysis conducted showed a low correlation to the contaminants.

  • PDF

A Study on the Real-time Cyber Attack Intrusion Detection Method (실시간 사이버 공격 침해사고 탐지방법에 관한 연구)

  • Choi, Jae-Hyun;Lee, Hoo-Jin
    • Journal of the Korea Convergence Society
    • /
    • v.9 no.7
    • /
    • pp.55-62
    • /
    • 2018
  • Recently, as the threat of cyber crime increases, the importance of security control to cope with cyber attacks on the information systems in the first place such as real-time detection is increasing. In the name of security control center, cyber terror response center and infringement response center, institutional control personnel are making efforts to prevent cyber attacks. Especially, we are detecting infringement accident by using network security equipment or utilizing control system, but it's not enough to prevent infringement accident by just controlling based on device-driven simple patterns. Therefore, the security control system is continuously being upgraded, and the development and research on the detection method are being actively carried out by the prevention activity against the threat of infringement. In this paper, we have defined the method of detecting infringement of major component module in order to improve the problem of existing infringement detection method. Through the performance tests for each module, we propose measures for effective security control and study effective infringement threat detection method by upgrading the control system using Security Information Event Management (SIEM).

Comparison of the Response Inhibitory Event Related Potential between Suicide Attempt and Ideation (자살 시도와 자살 사고 간 반응억제 사건유발전위 비교 연구)

  • Kim, Ji Sun;Kwon, Young Joon;Shim, Se-hoon
    • Anxiety and mood
    • /
    • v.16 no.1
    • /
    • pp.41-48
    • /
    • 2020
  • Objective : There have been limited scientific studies differentiating those who attempt suicide from those who think about suicide but do not attempt suicide. Altered event-related potential (ERP) performance, such as GoNogo ERP has been regarded as the neurocognitive processes associated with behavioral inhibition and poor impulse control. The purpose of this study was to investigate the association between Nogo ERP and suicide attempt. Methods : A total of 63 participants (33 participants with suicide ideation and 30 with suicide attempt) were recruited, and performed GoNogo tasks during the electroencephalogram measurement. Depression, anxiety, emotional regulation and impulsivity were evaluated by self-rating scales. The clinical measures and Nogo P3 component were compared between the groups. The correlational analyse was conducted to evaluate the relationship between the clinical characteristics and the Nogo P3 component. Results : Participants with suicide attempt significantly decreased the Nogo P3 amplitudes at the frontal-central electrode than participants with suicide ideation (p=0.004, FDR adjusted p=0.032). In the correlation analysis, the Nogo P3 amplitude at frontal-central electrode was correlated with the total score of the Barrett impulsivity scale (r=-0.383, p=0.002), attentional impulsivity (r=-0.365, p=0.003) and motor impulsivity (r=-0.389, p=0.002) subscales of the Barrett impulsivity scale. Conclusion : These findings suggest that the decreased Nogo P3 amplitude may be one of the candidates of biological marker for poor impulse control in those who attempt suicide.

The photochemical reactions of iron species in rain and snow in Higashi-Hiroshima, Japan

  • Kim, Do Hoon;Takeda, Kazuhiko;Sakugawa, Hiroshi;Lee, Jin Sik
    • Analytical Science and Technology
    • /
    • v.16 no.6
    • /
    • pp.466-474
    • /
    • 2003
  • This paper describes the concentrations of total dissolved iron (tFe) and $Fe^{2+}$ in rainwater and snow, the relationship of Fe species with other metals and ions in bulk rainwater, and the $Fe^{2+}$ generation mechanism in aqueous samples in rainwater of time series collection. Volume weight mean concentrations of tFe and $Fe^{2+}$ were 3.22 and $1.25{\mu}gL^{-1}$ in bulk rainwater, and 50.1 and $43.5{\mu}gL^{-1}$ in snow, respectively. $Fe^{2+}$ was significant fraction to the tFe, accounted for 3.25-93.4% of the tFe in rainwater and 87% in snow. We also investigated temporal variations of tFe, $Fe^{2+}$, other metals and ions in rainwater of time series collection during rain event. Although the concentration range of tFe was different from those of other species, a decreasing trend of tFe from the beginning of the rain event was similar with other species. However, though $Fe^{2+}$ did not show such a decreasing trend, $Fe^{2+}$/tFe was in good correlation with solar radiation. From the results of multiple linear regression analysis and thermodynamic calculations (Mineql+), $Fe^{2+}$ in our samples may be generated from photochemical reduction of $Fe^{3+}$ species (such as $Fe(OH)^{2+}$,$Fe(OH)^{2+}$ and Fe-oxalate) at daytime.

Factors Influencing Posttraumatic Growth of North Korean Defectors in South Korea (북한이탈주민의 외상 후 성장에 영향을 미치는 요인)

  • Kim, Yun Ah;Kim, MiYoung
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.17 no.5
    • /
    • pp.332-338
    • /
    • 2016
  • This study examined the posttraumatic growth of North Korean defectors, the relation between their characteristics and posttraumatic growth and the factors influencing their posttraumatic growth, and explored methods of improving their mental health status. 145 North Korean defectors, who were trained in B city and G city, participated in the survey from February 1 to March 10, 2016. The posttraumatic growth, resilience, self-esteem, deliberate rumination, and impact of the (traumatic) event were measured using the PTGI (Posttraumatic Growth Inventory), RS (Rumination Scale, Resilience Scale), SES (Self-esteem Scale) and ISR (Impact of Event). The data were analyzed using the t-test, ANOVA, Pearson correlation coefficient and stepwise multiple regression. The mean scores were 29.64 for posttraumatic growth. There were significant positive correlations between posttraumatic growth and resilience and between posttraumatic growth and rumination. The influence of the independent variables on the total posttraumatic growth was examined using regression analysis. Models including the variables (resilience, positive self-esteem, and rumination) explained 54.2% of the variance for the posttraumatic growth. These findings demonstrate that it is essential for nurses to continuously intervene and help North Korean defectors so as to promote their posttraumatic growth and resilience. Furthermore, it is also necessary for nurses to find ways to develop ideal interventions in order to activate deliberate rumination.

OECD/NEA BENCHMARK FOR UNCERTAINTY ANALYSIS IN MODELING (UAM) FOR LWRS - SUMMARY AND DISCUSSION OF NEUTRONICS CASES (PHASE I)

  • Bratton, Ryan N.;Avramova, M.;Ivanov, K.
    • Nuclear Engineering and Technology
    • /
    • v.46 no.3
    • /
    • pp.313-342
    • /
    • 2014
  • A Nuclear Energy Agency (NEA), Organization for Economic Co-operation and Development (OECD) benchmark for Uncertainty Analysis in Modeling (UAM) is defined in order to facilitate the development and validation of available uncertainty analysis and sensitivity analysis methods for best-estimate Light water Reactor (LWR) design and safety calculations. The benchmark has been named the OECD/NEA UAM-LWR benchmark, and has been divided into three phases each of which focuses on a different portion of the uncertainty propagation in LWR multi-physics and multi-scale analysis. Several different reactor cases are modeled at various phases of a reactor calculation. This paper discusses Phase I, known as the "Neutronics Phase", which is devoted mostly to the propagation of nuclear data (cross-section) uncertainty throughout steady-state stand-alone neutronics core calculations. Three reactor systems (for which design, operation and measured data are available) are rigorously studied in this benchmark: Peach Bottom Unit 2 BWR, Three Mile Island Unit 1 PWR, and VVER-1000 Kozloduy-6/Kalinin-3. Additional measured data is analyzed such as the KRITZ LEU criticality experiments and the SNEAK-7A and 7B experiments of the Karlsruhe Fast Critical Facility. Analyzed results include the top five neutron-nuclide reactions, which contribute the most to the prediction uncertainty in keff, as well as the uncertainty in key parameters of neutronics analysis such as microscopic and macroscopic cross-sections, six-group decay constants, assembly discontinuity factors, and axial and radial core power distributions. Conclusions are drawn regarding where further studies should be done to reduce uncertainties in key nuclide reaction uncertainties (i.e.: $^{238}U$ radiative capture and inelastic scattering (n, n') as well as the average number of neutrons released per fission event of $^{239}Pu$).

Model Proposal for Detection Method of Cyber Attack using SIEM (SIEM을 이용한 침해사고 탐지방법 모델 제안)

  • Um, Jin-Guk;Kwon, Hun-Yeong
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.16 no.6
    • /
    • pp.43-54
    • /
    • 2016
  • The occurrence of cyber crime is on the rise every year, and the security control center, which should play a crucial role in monitoring and early response against the cyber attacks targeting various information systems, its importance has increased accordingly. Every endeavors to prevent cyber attacks is being attempted by information security personnel of government and financial sector's security control center, threat response Center, cyber terror response center, Cert Team, SOC(Security Operator Center) and else. The ordinary method to monitor cyber attacks consists of utilizing the security system or the network security device. It is anticipated, however, to be insufficient since this is simply one dimensional way of monitoring them based on signatures. There has been considerable improvement of the security control system and researchers also have conducted a number of studies on monitoring methods to prevent threats to security. In accordance with the environment changes from ESM to SIEM, the security control system is able to be provided with more input data as well as generate the correlation analysis which integrates the processed data, by extraction and parsing, into the potential scenarios of attack or threat. This article shows case studies how to detect the threat to security in effective ways, from the initial phase of the security control system to current SIEM circumstances. Furthermore, scenarios based security control systems rather than simple monitoring is introduced, and finally methods of producing the correlation analysis and its verification methods are presented. It is expected that this result contributes to the development of cyber attack monitoring system in other security centers.

Development of Runoff Hydrograph Model for the Derivation of Optimal Design Flood of Agricultural Hydraulic Structures(1) (농업수리구조물의 적정설계홍수량 유도를 위한 유출수문곡선모형의 개발(I))

  • 이순혁;박명근;맹승진
    • Magazine of the Korean Society of Agricultural Engineers
    • /
    • v.37 no.3_4
    • /
    • pp.34-47
    • /
    • 1995
  • It is experienced fact as a regular annual event that the structure to he designed on unreasonable flood for the agricultural structures including reservoirs have been brought not only loss of lives, but also enormous property damage. For the solution of this problem at issue, this study was conducted to develop an optimal runoff hydrograph model by comparison of the peak flows and time to peak between observed and simulated flows derived by linear time-invariant and linear time-variant models under the condition of having a short duration of heavy rainfall with uniform rainfall intensity at nine small watersheds which are within the range of 55.9 to 140.7 square kilometers in area in Han, Geum, Nagdong and Yeongsan Rivers. The results obtained through this study can be summarized as follows. 1. Storage constants and Gamma function arguments were calculated within the range of 1.2 to 6.42 and of 1.28 to 8.05 respectively by the moment method as the parameters for the analysis of runoff hydrograph based on linear time-invariant model. 2. Parameters for both linear time-invariant and linear time-variant models were calibrated with nine gaged watershed data, using a trial and error method. The resulting parameters including Gamma function argument, N and storage constant, K for linear time-invariant model were related statistically to watershed characteristic variables such as area, slope, length of main stream and the centroid length of the basin. 3. Average relative errors of the simulated peak discharge of calibrated runoff hydrographs by using linear time-variant and linear time-invariant models were shown to be 0.75 and 5.42 percent respectively to the peak of observed runoff hydrographs. Correlation coefficients for the statistical analysis in the same condition were shown to be 0.999 and 0.978 with a high significance respectively. Therefore, it can be concluded that the accuracy of a linear time-variant model is approaching more closely to the observed runoff hydrograph than that of a linear time-invariant model in the applied watersheds. 4. Average relative errors of the time to peak of calibrated runoff hydrographs by using linear time-variant and linear time-invariant models were shown to be 16.44 and 19.89 percent respectively to the time to peak of observed runoff hydrographs. Correlation coefficients in the same condition were also shown to be 0.999 and 0.886 with a high significance respectively. 5. It can be seen that the shape of simulated hydrograph based on a linear time- variant model is getting closer to the observed runoff hydrograph than that of a linear time-invariant model in the applied watersheds. 6. Two different models were verified with different rainfall-runoff events from data for the calibration by relative error and correlation analysis. Consequently, it can be generally concluded that verification results for the peak discharge and time to peak of simulated runoff hydrographs were in good agreement with those of calibrated runoff hydrographs.

  • PDF