• Title/Summary/Keyword: SQL-database

Search Result 433, Processing Time 0.037 seconds

A Study on the Secure Coding for Security Improvement of Delphi XE2 DataSnap Server (델파이 XE2 DataSnap 서버의 보안성 개선을 위한 시큐어 코딩에 관한 연구)

  • Jung, Myoung-Gyu;Park, Man-Gon
    • Journal of Korea Multimedia Society
    • /
    • v.17 no.6
    • /
    • pp.706-715
    • /
    • 2014
  • It is used to lead to serious structural vulnerability of the system security of security-critical system when we have quickly developed software system according to urgent release schedule without appropriate security planning, management, and assurance processes. The Data Set and Provider of DataSnap, which is a middleware of Delphi XE2 of the Embarcadero Technologies Co., certainly help to develop an easy and fast-paced procedure, but it is difficult to apply security program and vulnerable to control software system security when the connection structure Database-DataSnap server-SQL Connection-SQL Data set-Provider is applied. This is due to that all kinds of information of Provider are exposed on the moment when DataSnap Server Port is sure to malicious attackers. This exposure becomes a window capable of running SQL Command. Thus, it should not be used Data Set and Provider in the DataSnap Server in consideration of all aspects of security management. In this paper, we study on the verification of the security vulnerabilities for Client and Server DataSnap in Dlephi XE2, and we propose a secure coding method to improve security vulnerability in the DataSnap server system.

An Efficient Design and Implementation of an MdbULPS in a Cloud-Computing Environment

  • Kim, Myoungjin;Cui, Yun;Lee, Hanku
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.9 no.8
    • /
    • pp.3182-3202
    • /
    • 2015
  • Flexibly expanding the storage capacity required to process a large amount of rapidly increasing unstructured log data is difficult in a conventional computing environment. In addition, implementing a log processing system providing features that categorize and analyze unstructured log data is extremely difficult. To overcome such limitations, we propose and design a MongoDB-based unstructured log processing system (MdbULPS) for collecting, categorizing, and analyzing log data generated from banks. The proposed system includes a Hadoop-based analysis module for reliable parallel-distributed processing of massive log data. Furthermore, because the Hadoop distributed file system (HDFS) stores data by generating replicas of collected log data in block units, the proposed system offers automatic system recovery against system failures and data loss. Finally, by establishing a distributed database using the NoSQL-based MongoDB, the proposed system provides methods of effectively processing unstructured log data. To evaluate the proposed system, we conducted three different performance tests on a local test bed including twelve nodes: comparing our system with a MySQL-based approach, comparing it with an Hbase-based approach, and changing the chunk size option. From the experiments, we found that our system showed better performance in processing unstructured log data.

Analysis of Encryption Algorithm Performance by Workload in BigData Platform (빅데이터 플랫폼 환경에서의 워크로드별 암호화 알고리즘 성능 분석)

  • Lee, Sunju;Hur, Junbeom
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.29 no.6
    • /
    • pp.1305-1317
    • /
    • 2019
  • Although encryption for data protection is essential in the big data platform environment of public institutions and corporations, much performance verification studies on encryption algorithms considering actual big data workloads have not been conducted. In this paper, we analyzed the performance change of AES, ARIA, and 3DES for each of six workloads of big data by adding data and nodes in MongoDB environment. This enables us to identify the optimal block-based cryptographic algorithm for each workload in the big data platform environment, and test the performance of MongoDB by testing various workloads in data and node configurations using the NoSQL Database Benchmark (YCSB). We propose an optimized architecture that takes into account.

Study on Security Weakness of Barcode Devices (바코드를 이용하는 기기에서의 보안적 취약점 탐구)

  • Park, Beom-joon
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2017.10a
    • /
    • pp.457-461
    • /
    • 2017
  • Barcode is widely being used in many places such as supermarket, cafeteria, library, etc. ISBN, Code 128, Code 39 are mainly used in barcode. Among them, Code 128 which is based on ASCII Code can transfer control letters that range from ASCII Code 0 to ASCII 32. Control letters intrinsically imply letters that are used to deliver information to peripheral devices such as a printer or communication joint, however, they play quite different roles if they are inputted on Windows. Generally, barcode devices doesn't verify input data, thus it enables people to tag any barcode that has specific control letters and execute the commands. Besides, most barcode recognition programs are using a database and they have more security weakness compared to other programs. On the basis of those reasons, I give an opinion that SQL Injection can attack barcode recognition programs through this study.

  • PDF

W3C XQuery Update facility on SQL hosts (관계형 테이블을 이용한 W3C XQuery 변경 기능의 지원)

  • Hong, Dong-Kweon
    • Journal of the Korean Institute of Intelligent Systems
    • /
    • v.18 no.3
    • /
    • pp.306-310
    • /
    • 2008
  • XQuery is a new recommendation for XML query. As an efforts for extending XQuery capabilities XML insertion and deletion are being studied and its standardization are going on. Initially XML databases are developed simply for XML document management. Now their functions are extending to OLTP. In this paper we are adding updating functions to XQuery processing system that is developed only for XQuery retrievals. We suggest the structure of tables, numbering schemes for hierarchical structures, and the methods for SQL translations for XQuery updates.

Performance Comparisons on MongoDB with B-Tree Indexes and Fractal Tree Indexes (MongoDB에서 B-트리 인덱스와 Fractal 트리 인덱스를 이용한 성능 비교)

  • Jang, Seongho;Kim, Suhee
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2014.05a
    • /
    • pp.622-625
    • /
    • 2014
  • As Big data began to produce a variety of values, a database that allows for huge amount of data with varieties became to be needed. Therefore, for the purpose of overcoming the limitations of the complexity and capacity of the existing RDBMS, NoSQL databases were introduced. Among the different types of NoSQL databases, MongoDB is most commonly used and is offered as open sources. The B-Tree index, used in MongoDB, experiences a significant decrease in performance as the amount of data increases. The fractal tree index enables to enhance the performance of B-Tree substantially by improving B-Tree's insertion algorithm. In this paper, the performances of MongoDB when using B-Tree Index and when using Fractal Tree Index are compared.

  • PDF

Fuzzy Structured Query Language for Fuzzy Database System (퍼지 데이터베이스 시스템을 위한 퍼지 질의어 연구(FSQL))

  • 정은영;신세영;김승권;유자영;박순철
    • Proceedings of the Korea Society for Industrial Systems Conference
    • /
    • 2000.05a
    • /
    • pp.79-84
    • /
    • 2000
  • 우리가 일상적으로 사용하는 말속에는 모호한 표현들이 많이 들어있다. 예를 들어, '젊다', '크다', '어느 정도' 등의 표현들은 정해진 값을 갖는 말들이 아니다. 가장 보편화된 RDBMS에서의 질의어인 SQL(Structured Query Language, 이하 SQL)은 데이터베이스에서 허용된 값, 즉 정량적인 값들에 대해서만 질의할 수 있도록 되어 있다. '젊은 여자' 혹은 '20세 정도의 여자'라는 질의는 할 수 없으며, '25세의 여자' 라는 식으로 정확한 질의만이 허용된다. 그러나 정보량이 급증하고 있고, 정보가 곧 힘이 되는 지금, 일반 사용자들도 데이터베이스에서 자신이 원하는 정보를 얻어 낼 수 있어야만 하게 되었다. 따라서 본 논문에서는 일반 사용자들도 데이터베이스에서 일상적으로 사용하는 단어(이하 자연어)로 질의를 할 수 있도록 하는 FSQL에 대해 논의하고자 한다.

  • PDF

Design and Implementation of an Application for Internet Banking (인터넷뱅킹을 위한 어플리케이션의 설계 및 구현)

  • 남철기;장길상
    • The Journal of Society for e-Business Studies
    • /
    • v.4 no.2
    • /
    • pp.95-113
    • /
    • 1999
  • Recently, Internet services are rapidly spreading all over the world. Internet will have a great influence on financial market and banking industry. Customers will obtain full banking services over Internet. Thus, Internet banking is an unavoidable choice to strengthen the competitive edge of banks. This paper designs and develops an application for Internet banking services in the existing banks. The implementation of Internet banking requires the construction of website, web pages and links to other related information. Using Oracle DBMS(Database Management System), Oracle Application Server, PL/SQL(Procedural Language/SQL), Java Applet, and Java Script, a prototype for Internet banking is implemented.

  • PDF

Dynamic Knowledge Map and SQL-based Inference Architecture for Medical Diagnostic Systems

  • Kim, Jin-Sung
    • Journal of the Korean Institute of Intelligent Systems
    • /
    • v.16 no.1
    • /
    • pp.101-107
    • /
    • 2006
  • In this research, we propose a hybrid inference architecture for medical diagnosis based on dynamic knowledge map (DKM) and relational database (RDB). Conventional expert systems (ES) and developing tools of ES has some limitations such as, 1) time consumption to extend the knowledge base (KB), 2) difficulty to change the inference path, 3) inflexible use of inference functions and operators. To overcome these Limitations, we use DKM in extracting the complex relationships and causal rules from human expert and other knowledge resources. The DKM also can help the knowledge engineers to change the inference path rapidly and easily. Then, RDB and its management systems help us to transform the relationships from diagram to relational table.

Implementation of Learning Management System for Philippines (필리핀 학습관리시스템 설계 및 구현)

  • Kim, Byeo-Ri;Yoo, Bo-Ram;Jung, Suk-Yong
    • Journal of the Korea Convergence Society
    • /
    • v.3 no.2
    • /
    • pp.1-5
    • /
    • 2012
  • South Korea is one of major trading partner of Philippines. Many Korean manufacturers and tour companies have branches in the Philippines. Korean companies need to enhance Korean language capabilities for Filipino employee. South Korea has many successive experiences for e-learning. In this paper, we developed Learning Management System (LMS) for Philippines. LMS was implemented in JAVA, ASP and HTML. All lectures are stored in database managed by MS SQL-server.