• Title/Summary/Keyword: Registry file

Search Result 23, Processing Time 0.023 seconds

Study on Forensic Analysis with Access Control Modification for Registry (레지스트리 접근권한 변조에 관한 포렌식 분석 연구)

  • Kim, Hangi;Kim, Do-Won;Kim, Jongsung
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.26 no.5
    • /
    • pp.1131-1139
    • /
    • 2016
  • In the Hive file format, the sk(Security Key) cell provides access control to registry key. An attacker can figure out secret information on registry or change the security set-up if she could apply modified hive files on system. This paper presents various methods to change access control of registry key by modifying or replacing cell on hive file. We also discuss threats by access control modification and signs of attacks analysis by modified hive files.

Implementation of Decision Making Process for Long-Term Preservation Strategy of Electronic Records (전자기록의 장기보존 전략을 위한 의사결정 프로세스 구현)

  • Cha, Hyun Chul
    • Journal of Korea Multimedia Society
    • /
    • v.23 no.9
    • /
    • pp.1201-1209
    • /
    • 2020
  • Based on the risk factor evaluation for the file format, this paper defines the procedures for presenting the long-term preservation plan for that format and the technical information registry necessary for building the system. This is a procedure to perform a risk assessment for the format, evaluate the risk, and select a long-term preservation strategy based on the information registered in the registry and information on the external signature and internal signature of the electronic record. We also reviewed the criteria for selecting appropriate long-term preservation strategies in the process and provided the criteria for adopting each detailed strategy of migration and emulation, which are long-term preservation strategies. And we implemented this process as a long-term preservation decision support system. This system can be used to provide guidelines for the maintenance, management, service and long-term preservation of information resources of electronic records in public institutions such as National Archives of Korea and Libraries.

Cancer Registration in Korea: The Present and Furtherance (암 등록사업의 현황과 추진방향)

  • Ahn, Yoon-Ok
    • Journal of Preventive Medicine and Public Health
    • /
    • v.40 no.4
    • /
    • pp.265-272
    • /
    • 2007
  • It was not until 1975 that cancer registration was initiated in Korea; voluntary registration of cancer patients of training hospitals throughout the country began under the auspices of the Korean Cancer Society(KCS). However, an official cancer registration, the Korea Central Cancer Registry(KCCR), began on July 1st, 1980. Forty-five training and two non-training hospitals throughout the country initiated registration of patients in whom neoplasms had been found. Data related to case information specified are to be sent to the KCCR at the National Medical Center(it moved at National Cancer Center in 2000). The initial cancer registration of KCS was merged to the KCCR in 1980. Although the KCCR covers most all the large training hospitals in Korea, it cannot provide incidence data. It is, however, the only of its kind in the world, being neither hospital nor population based. The first population based cancer registry(PBCR) was launched in a small county, Kangwha(it has around 80,000 inhabitants), by Yonsei University Medical College in 1983. All data were collected by active methods, and incidence statistics for 1986-1992 appeared in Vol VII of the CI5. Another PBCR, Seoul Cancer Registry(SCR), started in 1991. It was supported by a civilian foundation, the Korean Foundation for Cancer Research. The basic idea of case registration of SCR was the incorporation of KCCR data to PBCR, e. g. dual sources of case registration, i.e., from the KCCR and also including cases diagnosed in small hospitals and other medical facilities. Assessing completeness and validity of case registration of SCR, the program and methodology used by the SCR was later extended to other large cities and areas in Korea, and the PBCR in each area was established. Cancer incidence statistics of Seoul for 1993-1997, Busan for 1996-1997, and Daegu for 1997-1998, as well as Kangwha for 1993-1997, appeared eventually in Vol VIII of the CI5. The Korean or 'pillar' model for a PBCR is a new one. The KCCR data file is a reliable basis, as a pillar, for a PBCR in each area. The main framework of the model for such a registry is the incorporation of a KCCR data file with data from additionally surveyed cases; the data related to cancer deaths, medical insurance claims, and visit-and surveillance of non-KCCR medical facilities. Cancer registration has been adopted as a national cancer control program by Korean government in 2004 as the Anti-Cancer Act was enacted. Since then, some officers have tried to launch a nation-wide PBCR covering whole country. In the meantime, however, cancer registration was interrupted and discontinued for years due to the Privacy Protection Law, which was solved by an amendment of the Anti-Cancer Act in 2006. It would be premature to establish the nation-wide PBCR in Korea. Instead, continuous efforts to improve the completeness of registration of the KCCR, to progress existing PBCRs, and to expand PBCRs over other areas are still to be devoted. The nation-wide PBCR in Korea will be established eventually with summation of the PBCRs of the Korean model.

A study on the Digital Format Registry for digital objects preservation in Korea (디지털 객체 보존을 위한 디지털 포맷 레지스트리에 관한 연구)

  • Sohn, Won-Sung;Lim, Sun-Bum;Nam, Dong-Sun;Kim, Eun-Mi
    • Journal of Korea Multimedia Society
    • /
    • v.12 no.10
    • /
    • pp.1397-1406
    • /
    • 2009
  • This paper propose the "Digital Format Registry(DFR)" to solve the problem related digital objects preservation system in the Korean Industry. Digital format registry is a kind of database that saves syntax and meaning informations of a digital file format and for giving help to make preserve in long-term even technical environment of a specific application has been changing. The role of the Technical Information Registry has been developed in this research and development is maintaining a technical information that is the foundation to maintain the long-term preservation and access to a digital objects. The function that can extract text information from a digital document object is implemented in DFR as a basic function at the first time in the world. This function make information consumers search a information that is needed easily and conveniently and can be used for development more effective records management system with retrieving the Key(index).

  • PDF

A Design and Implementation of Application virtualization method using virtual supporting system and Copy-on-Write scheme (가상화 지원 시스템과 Copy-on-Write 방법을 이용한 응용프로그램 가상화 방법의 설계 및 구현)

  • Choi, Won Hyuk;Choi, Ji Hoon;Kim, Won-Young;Choi, Wan
    • Proceedings of the Korea Contents Association Conference
    • /
    • 2007.11a
    • /
    • pp.807-811
    • /
    • 2007
  • In this paper, we introduce an application virtualization method that could be supported without changing and modifying any resources and execution environment on host system, using non-installable portable software format that could be executed by one-click on any host without installing process. For the purpose of designing and implementing an application virtualization method, we construct virtual supporting system that includes virtual file system and virtual registry hive on kernel level of Windows operating system. Also, when users execute portable software on any hosts to provide consistency on using portable software, we describe method of processing information of appending and modifying files and registry datum on virtual file system and virtual registry hive through Copy-on-Write scheme.

  • PDF

Simplified Forensic Analysis Using List of Deleted Files in IoT Envrionment (사물인터넷 환경에서 삭제된 파일의 목록을 이용한 포렌식 분석 간편화)

  • Lim, Jeong-Hyeon;Lee, Keun-Ho
    • Journal of Internet of Things and Convergence
    • /
    • v.5 no.1
    • /
    • pp.35-39
    • /
    • 2019
  • With the rapid development of the information society, the use of digital devices has increased dramatically and the importance of technology for analyzing them has increased. Digital evidence is stored in many places such as Prefetch, Recent, Registry, and Event Log even if the user has deleted it. Therefore, there is a disadvantage that the forensic analyst can not grasp the files used by the user at the beginning. Therefore, in this paper, we propose a method that the RemoveList folder exists so that the user can grasp the information of the deleted file first, and the information about the deleted file is automatically saved by using AES in RemoveList. Through this, it can be expected that the analyst can alleviate the difficulty of initially grasping the user's PC.

Web Service Method using WSDL Repository (웹서비스를 위한 WSDL 리포지토리 설계)

  • Choi, Yue-Soon;Park, Jong-Goo
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.11 no.4
    • /
    • pp.745-753
    • /
    • 2007
  • Web service, the next generation of distributed computing, is a distributed solution that handles all businesses through standard techniques in the internet. Web service performs its function using web interface. The goal of this thesis is to reduce network overloading. to manage WSDL efficiently, and to provide convenience to service users by simplifying the web service procedure. Web service system proposed in this thesis is based on WSDL Repository that can include UDDI and store WSDL. WSDL Repository manages WSDL by file system and has UDDI Registry embedded within it. Because this system is based on WSDL Repository, Web service supplier must register WSDL when he registers services. Then, users can receive WSDL too when he searches for services.

Method of estimating the deleted time of applications using Amcache.hve (앰캐시(Amcache.hve) 파일을 활용한 응용 프로그램 삭제시간 추정방법)

  • Kim, Moon-Ho;Lee, Sang-jin
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.25 no.3
    • /
    • pp.573-583
    • /
    • 2015
  • Amcache.hve file is a registry hive file regarding Program Compatibility Assistant, which stores the executed information of applications. With Amcache.hve file, We can know execution path, first executed time as well as deleted time. Since it checks both the first install time and deleted time, Amcache.hve file can be used to draw up the overall timeline of applications when used with the Prefetch files and Iconcache.db files. Amcache.hve file is also an important artifact to record the traces of anti-forensic programs, portable programs and external storage devices. This paper illustrates the features of Amcache.hve file and methods for utilization in digital forensics such as estimation of deleted time of applications.

A Study of Multiple Compression for Malicious Code Execution and Concealment (악성코드 실행과 은닉을 위한 다중 압축 연구)

  • Yi, Jeong-Hoon;Park, Dea-Woo
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2010.05a
    • /
    • pp.299-302
    • /
    • 2010
  • Recently, the malicious code is not easily detectable in the vaccine for the virus, malicious code as a compressed file by modulation pattern is the tendency to delay. Among the many antivirus engines on the market a compressed file that can be modulated by malicious code, and test whether the pattern will need to know. We cover a multi-compressed files, malicious code modulated secreted by examining patterns of test engine is being detected is through a computer simulation. Analysis of secreted activities of malicious code and infect the host file tampering with the system driver files and registry, it gets registered is analyzed. this study will contribute hidden malicious code inspection and enhance vaccine efficacy in reducing the damage caused by malicious code.

  • PDF

A Study on the STN International (STN International 온라인 정보검색(情報檢索) 시스템)

  • Jeong, Hye-Soon
    • Journal of Information Management
    • /
    • v.23 no.3
    • /
    • pp.45-73
    • /
    • 1992
  • STN International is operated in North America by CAS, a division of the American Chemical Society;by FIZ Karlsruhe in Eruope ; and by JICST in Japan. All three are not-for-profit scientific organizations. This paper describes Messenger software that is designed for fast and efficient information retrieval, the advanced front-end STN Express software that saves time and effort, and databases in STN.

  • PDF