• Title/Summary/Keyword: Rule Protection Scheme

Search Result 16, Processing Time 0.023 seconds

Extraction of Network Threat Signatures Using Latent Dirichlet Allocation (LDA를 활용한 네트워크 위협 시그니처 추출기법)

  • Lee, Sungil;Lee, Suchul;Lee, Jun-Rak;Youm, Heung-youl
    • Journal of Internet Computing and Services
    • /
    • v.19 no.1
    • /
    • pp.1-10
    • /
    • 2018
  • Network threats such as Internet worms and computer viruses have been significantly increasing. In particular, APTs(Advanced Persistent Threats) and ransomwares become clever and complex. IDSes(Intrusion Detection Systems) have performed a key role as information security solutions during last few decades. To use an IDS effectively, IDS rules must be written properly. An IDS rule includes a key signature and is incorporated into an IDS. If so, the network threat containing the signature can be detected by the IDS while it is passing through the IDS. However, it is challenging to find a key signature for a specific network threat. We first need to analyze a network threat rigorously, and write a proper IDS rule based on the analysis result. If we use a signature that is common to benign and/or normal network traffic, we will observe a lot of false alarms. In this paper, we propose a scheme that analyzes a network threat and extracts key signatures corresponding to the threat. Specifically, our proposed scheme quantifies the degree of correspondence between a network threat and a signature using the LDA(Latent Dirichlet Allocation) algorithm. Obviously, a signature that has significant correspondence to the network threat can be utilized as an IDS rule for detection of the threat.

Security Structure for Protection of Emergency Medical Information System (응급의료정보시스템의 보호를 위한 보안 구조)

  • Shin, Sang Yeol;Yang, Hwan Seok
    • Journal of Korea Society of Digital Industry and Information Management
    • /
    • v.8 no.2
    • /
    • pp.59-65
    • /
    • 2012
  • Emergency medical information center performs role of medical direction about disease consult and pre-hospital emergency handling scheme work to people. Emergency medical information system plays a major role to be decreased mortality and disability of emergency patient by providing information of medical institution especially when emergency patient has appeared. But, various attacks as a hacking have been happened in Emergency medical information system recently. In this paper, we proposed security structure which can protect the system securely by detecting attacks from outside effectively. Intrusion detection was performed using rule based detection technique according to protocol for every packet to detect attack and intrusion was reported to control center if intrusion was detected also. Intrusion detection was performed again using decision tree for packet which intrusion detection was not done. We experimented effectiveness using attacks as TCP-SYN, UDP flooding and ICMP flooding for proposed security structure in this paper.

A Threats Statement Generation Method for Security Environment of Protection Profile (PP의 보안환경을 위한 위협문장 생성방법)

  • 고정호;이강수
    • The Journal of Society for e-Business Studies
    • /
    • v.8 no.3
    • /
    • pp.69-86
    • /
    • 2003
  • A Protection Profile(PP) is a common security and assurance requirements for a specific class of Information Technology security products such as firewall and smart card. A PP should be included "TOE(Target of Evaluation) Security Environment", which is consisted of subsections: assumptions, treat, organizational security policies. This paper presents a new threats statement generation method for developing TOE security environment section of PP. Our survey guides the statement of threats in CC(Common Criteria) scheme through collected and analysed hundred of threat statements from certified and published real PPs and CC Tool Box/PKB that is included a class of pre-defined threat and attack statements. From the result of the survey, we present a new asset classification method and propose a threats statement generation model. The former is a new asset classification method, and the later is a production rule for a well formed statement of threats.

  • PDF

A Study on Resolution of Validity in XML Document (XML 문서의 유효성 문제 해결에 관한 연구)

  • Hong, Seong-Pyo;Song, Gi-Beom;Bang, Keug-In;Lee, Joon
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2003.05a
    • /
    • pp.564-567
    • /
    • 2003
  • XML has weakness problems on document modulation and elimination of data Because of the XML gives priority to present data format, XML electrical signature, XML cryptography, or XML access control is provided to overcome those weakness problems. However, structured XML efficiency contravention problem occurred from XML encryption and absence of protection from DTD attack are still remains unsolved. In this paper, we provide XML scheme that satisfies both efficiency and encryption. DTD is unnecessary because XML scheme supports formatting(Well-Formed XML) XML documents and it also include meta information. Because of the XML scheme has possibility to generate each XML document dynamically and self efficiency investigator rule, it has an advantage on extendability of DID based encryption of XML documents.

  • PDF

History of the Korean Society of Applied Entomology for its First Fifty Years (한국응용곤충학회의 첫 50년 역사)

  • Boo, Kyung-Saeng
    • Korean journal of applied entomology
    • /
    • v.51 no.2
    • /
    • pp.171-190
    • /
    • 2012
  • The Korean Society of Applied Entomology (KSAE) celebrates its First 50 years history this year, 2011. It began in the year 1962, as the Korean Society of Plant Protection (KSPP) to discuss all aspects of plant protection including entomology and plant pathology. At that time it was one of the earliest scientific ones among agricultural societies in Korea. Before liberation from the Japanese colonial rule there were a few scientific societies for Japanese scientists only in the Korean Peninsula. It seemed that there was a single exception, in medical field, formed by and operated for Korean ethnics. Right after the liberation, Korean scientists rushed to form new scientific societies in the fields of mechanical engineering, architecture, textile, internal medicine, biology, etc. in 1945, mathematics, chemistry, metallurgy, etc. in 1946, and so on. But agricultural scientists had to wait for more time before setting up their own scientific society, Korean Agricultural Society(韓國農學會), comprising all agricultural subfields, in 1954. They had annual meetings and published their own journal every year until 1962. Then those working in the plant protection field established their own KSPP, right after their section meeting in 1962. At that time the total number of participants for KSPP were only around 50. KSPP scientists were interested in plant pathology, agricultural chemicals, weed science, or bioclimate, besides entomology. They had annual meetings once or twice a year until 1987 and published their own journal, Korean Journal of Plant Protection (KJPP), once a year at the earlier years but soon gradually increasing the frequency to four times a year later. Articles on entomology and plant pathology occupied about 40% each, but the number of oral or posters were a little bit higher on plant pathology than entomology, with the rest on nematology, agricultural chemicals, or soil microarthropods. There also had a number of symposia and special lectures. The presidentship lasted for two years and most of president served only one term, except for the first two. The current president should be $28^{th}$. In the year 1988, KSPP had to be transformed into the applied entomology society, Korean Society of Applied Entomology (KSAE), because most of plant pathologists participating left the society to set up their own one, Korean Society of Plant Pathology in 1984. Since that time the Society concentrates on entomology, basic and applied, with some notes on nematology, acarology, soil microarthropods, agricultural chemicals, etc. The Society has been hosting annual meetings at least twice a year with special lectures and symposia, from time to time, on various topics. It also hosted international symposia including binational scientific meetings twice with two different Japanese (applied entomology in 2003 and acarology in 2009) societies and the Asia-Pacific Congress of Entomology in 2005. The regular society meeting of this year, 2011, turns out to be the 43rd and this autumn non-regular meeting would be the 42nd. It has been publishing two different scientific journals, Korean Journal of Applied Entomology (KJAE) since 1988 and the Journal of Asia-Pacific Entomology (JAPE) since 1998. Both journals are published 4 times a year, with articles written in Korean or English in the first, but those in English only in the latter with cooperation from the Taiwan Entomological Society and the Malaysian Plant Protection Society since 2008. It is now enlisted as one of those SCI(science citation index) extended. The highest number of topics discussed at their annual meetings was on ecology, behavior, and host resistance. But at the annual meetings jointly with the Korean Society of Entomology, members were more interested in basic aspects, instead of applied aspects, such as physiology and molecular biology fields. Among those societies related to entomology and plant protection, plant pathology, pesticide, and applied entomology societies are almost similar in membership, but entomology and plant pathology societies are publishing more number of articles than any others. The Society is running beautifully, but there are a few points to be made for further improvement. First, the articles or posters should be correctly categorized on the journals or proceedings. It may be a good idea to ask members to give their own version of correct category for their submissions, either oral or poster or written publication. The category should be classified detailed as much as possible (one kind of example would be systematics, morphology, evolution, ecology, behavior, host preference or resistance, physiology, anatomy, chemical ecology, molecular biology, pathology, chemical control, insecticides, insecticide resistance, biocontrol, biorational control, natural enemies, agricultural pest, forest pest, medical pest, etc.) and such scheme should be given to members beforehand. The members should give one or two, first and second, choices when submitting, if they want. Then the categories might be combined or grouped during editing for optimal arrangement for journals or proceedings. Secondly the journals should carry complete content of the particular year and author index at the last issue of that year. I would also like to have other information, such as awards and awardees in handy way. I could not find any document for listing awards. Such information or article categorization may be assigned to one of the vice presidents. I would rather strongly recommend that the society should give more time and energy on archive management to keep better and more correct history records.

A Study on Ensuring Biosafety of Biotechnology Product under Debate about Trade and the Environment (DDA 무역-환경 논의와 생명공학제품의 안전성 확보)

  • Sung, Bong-Suk;Yoon, Ki-Kwan
    • Environmental and Resource Economics Review
    • /
    • v.13 no.3
    • /
    • pp.519-547
    • /
    • 2004
  • This paper analyze problems about scope of specific trade obligations(STOs), principle of dispute settlement procedure, and non-parties in context of the Cartagena Protocol on Biosafety(POB), which based on sub-paragraph 31(i) of DDA WTO Ministrial Declaration. The implications based on result of this study are as follows. First, to accept the wider scope of STOs under POB in Korea, importing country, won't be harmful to LMOs and Bioindustry. Instead, it will ensure a high level of biosafety concerning the import of LMOs. Exporters can take different kinds of trade measures to countervail adverse effect on the export of LMOs in this case. Therefore importer will endure the aftereffect. However, if korea were in exporter's place, to accept the wider scope STOs under POB will not have a good influence on the export of LMOs. Korea, therefore, should devise scheme for responding to debate about the STOs in MEAs, which have to be based on cost-benefit analysis and scenarios taking into account of speed and level in biotechology progress, status and trend of LMOs R&D and production, and condition of other industries. Second, it is not easy to agree with applying to what's rule between the POB and WTO for settlement dispute. Because there is the incompatibility between the POB characterized according to social rationality and WTO's rules for safety and environmental protection characterized according to scientific rationality. This issue have to be discussed for long period due to gap like that. Accordingly Korea, one of major LMOs importing countries, should suggest continuously that the effort is needed to ensure an adequate level of protection in transboundary movements of LMOs and scientific, environmental and socio-economic study. Third, in case of dispute between party and non-party of the POB, the duties under the WTO of non-party of the POB(if WTO member country) is valid. The country, therefore, will try to settle dispute based on WTO's rules. However, international society have to ensure for sound and safe use of LMOs in the field of transboundary movements. Accordingly Korea should devise scheme for preventing the possibility of dispute between party and non-party of the POB(if WTO member country), which is supported by policy options under the POB.

  • PDF