• Title/Summary/Keyword: Security Enhancement

Search Result 356, Processing Time 0.028 seconds

Outcome and Enhancement of ISO 27001(ISMS) in National R&D Information Management Environment (국가R&D정보관리 환경에서 ISO 27001(ISMS) 성과 및 개선 방향)

  • Lee, Byeong-Hee;Yeo, Il-Yeon;Kim, Jae-Soo
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2011.04a
    • /
    • pp.823-825
    • /
    • 2011
  • R&D에 관한 주요 국가 및 산업기술의 정보 유출이 문제가 되고 있다. 2009년 11월 국가과학기술지식정보서비스(NTIS)는 영국표준협회(BSI)로부터 ISO 27001에 대한 11개 도메인, 133개 보안 통제항목의 정보보호관리체계((Information Security Management System) 인증을 획득하였고 이후 사후인증 심사를 받고 있다. 본 논문에서는 정보보호 국제 표준인증인 ISO 27001과 관련하여 NTIS의 정보보호관리체계에 대하여 국가R&D정보관리의 경영적 관점에서 실증적 현황 및 성과와 향후 개선 및 발전 방향에 대하여 검토한다. ISO 27001 도입 후 133개 통제항목 중에서 적용율이 증가하였고 중부적합/경부적합/개선권고 사항이 크게 감소하였으나 정보자산 및 개인정보 관리는 지속적인 관심과 개선이 필요함을 알 수 있었다.

Enhancement of WiBro PKMv2 EAP-AKA Authentication Security Against Rogue BS based Redirection Attacks (WiBro PKMv2 EAP-AKA 기반 인증 과정에서의 Redirection Attack 에 대한 보안 취약성 및 개선 방안)

  • Lee, Hyun-Chul;Eom, Sung-Hyun;Cho, Sung-Jae;Choi, Hyoung-Kee
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2007.11a
    • /
    • pp.1210-1213
    • /
    • 2007
  • WiBro는 무선랜과 3G 이동통신의 장점을 결합한 휴대 인터넷 기술로 최근 국내에서 상용화 되었다. WiBro의 장점인 이동성과 고속 무선 통신에 기인하여, 향후 지속적인 발전이 기대된다. 이러한 WiBro의 확산에 따라 개인 사용자에 대한 보안문제가 최근 크게 부각되고 있다. 현재 Wibro는 3G 이동통신 및 무선랜과 효율적인 연동을 위해 EAP-AKA 인증기법을 사용하고 있다. 하지만 EAP-AKA는 단말이 기지국을 인증하지 못하는 치명적인 취약점이 있다. 따라서 공격자는 임의로 rogue BS를 설치할 수 있고, 정상 사용자의 데이터를 이종 네트워크로 보내는 Redirection Attack을 시도할 수 있다. Redirection Attack은 전송 속도 저하, Denial-of-Service (DoS) 을 초래하며, 데이터가 redirection 되는 이종 네트워크에 따라 암호화된 데이터가 노출될 수 있다. 본 논문에서는 EAP-AKA와 Redirection Attack에 대해 분석하고, 그 해결책을 제시한다. 논문은 1) 프로토콜을 일부 수정하여 공격을 막는 방법과 2) traffic 분석을 통한 공격 탐지 방식을 다루고 있으며, 이러한 두 가지 방법을 통해 Redirection Attack에 대한 취약점을 근본적으로 제거할 수 있다.

Water/nutrient use efficiency and effect of fertigation: a review

  • Woojin Kim;Yejin Lee;Taek-Keun Oh;Jwakyung Sung
    • Korean Journal of Agricultural Science
    • /
    • v.49 no.4
    • /
    • pp.919-926
    • /
    • 2022
  • Fertigation, which has been introduced in agricultural fields since 1990, has been widely practiced in upland fields as well as in plastic film houses as part of the crop production system. In accordance with demands in the agricultural sector, a huge number of scientific studies on fertigation have been conducted worldwide. Moreover, with a combination of advanced technologies such as big-data, machine learning, etc., fertigation is positioned as an indispensable tool to achieve sustainable crop production and to enhance nutrient and water use efficiency. In this review, we focused on providing valuable information in terms of crop production and nutrient/water use efficiency. A variety of fertigation studies have described that enhancement of crop production did not differ relative to conventional method or slightly increased. In contrast, fertigation significantly improved nutrient/water use efficiency, with a reduction in use ranging from 20 to 50%. Water-soluble organic resources such as livestock manure and agricultural byproducts also have been identified as useful resources like chemical fertilizers. Furthermore, the initial irrigation point was generally recommended in a range of -10 - -40 kPa, although the point differed according to the crop and crop growth stage. From this review, we suggest that fertigation, which is closely integrated with advanced technology, could be a leading technology to attain not only food security but also carbon neutrality via improvement of nutrient/water use efficiency.

The Policing of the G20 Seoul Protests: A Case Analysis on the Death of Ian Tomlinson (G20 서울 정상회의 관련 집회시위 경비방안 : 이안 톰린슨(Ian Tomlinson) 사망사건 분석을 중심으로)

  • Lee, Ju-Lak
    • Korean Security Journal
    • /
    • no.24
    • /
    • pp.125-146
    • /
    • 2010
  • The G20 summit is the premier forum for international economic cooperation and it will be held in Seoul in November 2010. However, protests are expected during the Seoul summit, as a part of the deepening global war against capitalism. The Korean Police need to deal with these protests effectively in order to provide security to the participating leaders and make the meeting run on wheel as planned. The current study attempts to analyze the death of Ian Tomlinson who died in the context of a heavily policed protest during 2009 G20 London summit. There are number of unique features regarding this incident, such as the public scrutiny of police conduct through video footage, the police use of excessive force, and the process to hold the police to account for misconduct. This incident caused serious damages to the public's faith in the British police. Based on the analysis, this study found that during the G20 London summit British police had the problems such as the lack of the clear standards on the use of force, improper training in the use of force, poor communications with the media and protesters, inappropriate use of the close containment tactic, and the failure to display police identification. Therefore, this study suggests the inducement of peaceful protests, the adoption of a set of standards on the use of force, public order training that is more directed and more relevant to the public order challenges facing the Korean police, improvement of the communication with the media and protesters, enhancement of individual officer's accountability as public order policing strategies for G20 Seoul summit meeting. However, the most fundamental principle is that Korean police must place a high value on tolerance and winning the consent of the public.

  • PDF

A Partial Encryption Method for the Efficiency and the Security Enhancement of Massive Data Transmission in the Cloud Environment (클라우드 환경에서의 대용량 데이터 전송의 효율성과 보안성 강화를 위한 부분 암호화 방법)

  • Jo, Sung-Hwan;Han, Gi-Tae
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.6 no.9
    • /
    • pp.397-406
    • /
    • 2017
  • In case of using the existing encrypted algorithm for massive data encryption service under the cloud environment, the problem that requires much time in data encryption come to the fore. To make up for this weakness, a partial encryption method is used generally. However, the existing partial encryption method has a disadvantage that the encrypted data can be inferred due to the remaining area that is not encrypted. This study proposes a partial encryption method of increasing the encryption speed and complying with the security standard in order to solve this demerit. The proposed method consists of 3 processes such as header formation, partial encryption and block shuffle. In step 1 Header formation process, header data necessary for the algorithm are generated. In step 2 Partial encryption process, a part of data is encrypted, using LEA (Lightweight Encryption Algorithm), and all data are transformed with XOR of data in the unencrypted part and the block generated in the encryption process. In step 3 Block shuffle process, the blocks are mixed, using the shuffle data stored with the random arrangement form in the header to carry out encryption by transforming the data into an unrecognizable form. As a result of the implementation of the proposed method, applying it to a mobile device, all the encrypted data were transformed into an unrecognizable form, so the data could not be inferred, and the data could not be restored without the encryption key. It was confirmed that the proposed method could make prompt treatment possible in encrypting mass data since the encryption speed is improved by approximately 273% or so compared to LEA which is Lightweight Encryption Algorithm.

A Study on National Cyber Capability Assessment Methodology (국가 사이버 역량 평가 방법론 연구)

  • Kang, JungMin;Hwang, HyunUk;Lee, JongMoon;Yun, YoungTae;Bae, ByungChul;Jung, SoonYoung
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.22 no.5
    • /
    • pp.1039-1055
    • /
    • 2012
  • It is required for us to enhance the national cyber capability as the worldwide countries have been doing effort to strengthen their cyber capabilities. However, we are encountering the difficulty in estimating national cyber capability due to the absence of any cyber capability assessment methodology. This paper presents the national cyber capability assessment methodology which is used for settle up national cyber policy. We also introduce the result of five major nations(US, China, Japan, Russia, Korea)' cyber capability assessment using the proposed methodology. The methodology is developed using open data and includes three areas; base capability, attack capability and defense capability. The assessment result shows the in the order of US, China, Korea, Russia, Japan. As the analysis of that result, in order to enhance the our cyber capability, we recommend that first, cyber budget and human resources for the base capability should be more invested, second, the strategy for attack capability enhancement is strongly required and lastly, the patch ratio and security monitoring level should be upgraded.

A Study on Analysis and Enhancement Strategy of South Korea's Defense Industry Exports Amidst Global Geopolitical Crisis (세계 지정학적 위기 속에서 한국의 방산수출 분석 및 강화 전략 연구)

  • Dongbum Kim;Youngsam Yoon
    • Convergence Security Journal
    • /
    • v.24 no.2
    • /
    • pp.181-188
    • /
    • 2024
  • Amid global geopolitical crises that are heightening tensions worldwide, the importance of national security is being reevaluated. Consequently, South Korea is gaining attention in the global defense market due to its superior technology, competitive pricing, and rapid delivery capabilities. The increasing international demand for defense materials offers opportunities for the development of the domestic defense industry and has the potential to lead to long-term defense strategies and an expansion of exports. In particular, the development of future advanced weapons systems and the expansion of defense exports are likely to be possible through a deep understanding of the international political and economic situation and proactive defense diplomacy. This study analyzes the impact of current global geopolitical crises on Korea's defense industry and presents effective strategies based on these findings, including innovative improvements to defense acquisition systems and the discovery of overseas defense cooperation partners to strengthen defense exports. This strategic approach aims to balance domestic consumption with exports, enhance military strength, and improve the country's standing in the international community. Therefore, efforts are needed to ensure the sustainable growth of the defense industry, enabling South Korea to achieve economies of scale and play a pivotal role in the global defense industry.

A Study on Improvement of Laws regarding Welfare for the Aged (노인복지 관련법제의 발전방향)

  • Park, Ji-Soon
    • Journal of Legislation Research
    • /
    • no.41
    • /
    • pp.87-123
    • /
    • 2011
  • Korea is expected to become an 'aged society' with more than 14 percent of the public aged 65 years or more by 2018. The rapid aging is giving rise to various problems within the society along with falling birthrate in a short period of time. In this context, the role and function of laws on welfare for the aged must be particularly emphasized. Also the Senior Citizens Welfare Act is of great importance as it provides social welfare service on the basis of functional connection with social insurance and public assistance. First, this paper looks into the history of laws related to welfare for the elderly such as the Senior Welfare Act, the Act on Long-term Care Insurance for Senior Citizens and the Basic Old Age Pension Act as well as the findings of earlier studies. In the second place, it will break down such laws by main components aiming to examine details of the laws and questions raised regarding them and to seek ways to achieve improvement with an emphasis on health care, old age income security, housing welfare(assisted living facilities), job security for the aged. The Senior Welfare Act offers substance of social welfare service for the elderly. Income security, health and medical care, welfare measures through long-term care and assisted living facilities, social participation by working are the key elements and all of them should be closely associated to ensure citizens get sufficient public support in their old age. For this purpose, the Senior Welfare Act is under a normative network with laws such as Act on Long-term Care Insurance for Senior Citizens and Basic Old Age Pension Act. Current laws on welfare for the aged including Senior Welfare Act are not sufficiently responsive to the aged society of the 21st century. Income security combined with decent social participation, health and medical care closely connected with long-term care system, efficient expense sharing between government and local government, enhancement of effectiveness of welfare measures can be considered as means to improve current welfare system so that the elderly can enjoy their old age with dignity and respect.

A Study on the Korea Future Internet Promotion Plan for Cyber Security Enhancement (사이버 보안 강화를 위한 한국형 미래 인터넷 추진 방안에 관한 연구)

  • Lim, Gyoo-Gun;Jin, Hai-Yan;Ahn, Jae-Ik
    • Informatization Policy
    • /
    • v.29 no.1
    • /
    • pp.24-37
    • /
    • 2022
  • Amid rapid changes in the ICT environment attributed to the 4th Industrial Revolution, the development of information & communication technology, and COVID-19, the existing internet developed without considering security, mobility, manageability, QoS, etc. As a result, the structure of the internet has become complicated, and problems such as security, stability, and reliability vulnerabilities continue to occur. In addition, there is a demand for a new concept of the internet that can provide stability and reliability resulting from digital transformation-geared advanced technologies such as artificial intelligence and IoT. Therefore, in order to suggest a way of implementing the Korean future internet that can strengthen cybersecurity, this study suggests the direction and strategy for promoting the future internet that is suitable for the Korean cyber environment through analyzing important key factors in the implementation of the future internet and evaluating the trend and suitability of domestic & foreign research related to future internet. The importance of key factors in the implementation of the future internet proceeds in the order of security, integrity, availability, stability, and confidentiality. Currently, future internet projects are being studied in various ways around the world. Among numerous projects, Bright Internet most adequately satisfies the key elements of future internet implementation and was evaluated as the most suitable technology for Korea's cyber environment. Technical issues as well as strategic and legal issues must be considered in order to promote the Bright Internet as the frontrunner Korean future internet. As for technical issues, it is necessary to adopt SAVA IPv6-NID in selecting the Bright Internet as the standard of Korean future internet and integrated data management at the data center level, and then establish a cooperative system between different countries. As for strategic issues, a secure management system and establishment of institution are needed. Lastly, in the case of legal issues, the requirement of GDPR, which includes compliance with domestic laws such as Korea's revised Data 3 Act, must be fulfilled.

The Role of Process Systems Engineering for Sustainability in the Chemical Industries (화학공정 산업에서의 지속가능성과 공정시스템 공학)

  • Jang, Namjin;Dan, Seungkyu;Shin, Dongil;Lee, Gibaek;Yoon, En Sup
    • Korean Chemical Engineering Research
    • /
    • v.51 no.2
    • /
    • pp.221-225
    • /
    • 2013
  • Sustainability, in general, means the protection of environmental resources and economic prosperity, with the consideration of the social, economic and environmental effect, as well as human health and the enhancement of life. Profound consideration about sustainability has to handle the overall cycle of feedstock, resource extraction, transportation and production in addition to the environmental effect. Sustainable development of the chemical industries should be carried out complementarily by strengthening the chemical process safety of the industries. In this respect, chemical process safety can be called an opportunity to enhance the compatibility internationally. Changing new paradigm in chemical process safety is formed from the overall life cycle considering basic design of existing systems and production processes. To improve the chemical process safety, the integrated smart system is necessary, comprising various chemical safety database and knowledge base and improved methods of quantitative risk analysis, including management system. This paper discussed the necessity of overall life cycle in chemical process safety and proposed new technology to improve the sustainability. To develop the sustainable industries in process systems engineering, three S, which include Safety, Stability and Security, will have to be combined appropriate.