• Title/Summary/Keyword: Security Program

Search Result 1,236, Processing Time 0.025 seconds

Improved Original Entry Point Detection Method Based on PinDemonium (PinDemonium 기반 Original Entry Point 탐지 방법 개선)

  • Kim, Gyeong Min;Park, Yong Su
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.7 no.6
    • /
    • pp.155-164
    • /
    • 2018
  • Many malicious programs have been compressed or encrypted using various commercial packers to prevent reverse engineering, So malicious code analysts must decompress or decrypt them first. The OEP (Original Entry Point) is the address of the first instruction executed after returning the encrypted or compressed executable file back to the original binary state. Several unpackers, including PinDemonium, execute the packed file and keep tracks of the addresses until the OEP appears and find the OEP among the addresses. However, instead of finding exact one OEP, unpackers provide a relatively large set of OEP candidates and sometimes OEP is missing among candidates. In other words, existing unpackers have difficulty in finding the correct OEP. We have developed new tool which provides fewer OEP candidate sets by adding two methods based on the property of the OEP. In this paper, we propose two methods to provide fewer OEP candidate sets by using the property that the function call sequence and parameters are same between packed program and original program. First way is based on a function call. Programs written in the C/C++ language are compiled to translate languages into binary code. Compiler-specific system functions are added to the compiled program. After examining these functions, we have added a method that we suggest to PinDemonium to detect the unpacking work by matching the patterns of system functions that are called in packed programs and unpacked programs. Second way is based on parameters. The parameters include not only the user-entered inputs, but also the system inputs. We have added a method that we suggest to PinDemonium to find the OEP using the system parameters of a particular function in stack memory. OEP detection experiments were performed on sample programs packed by 16 commercial packers. We can reduce the OEP candidate by more than 40% on average compared to PinDemonium except 2 commercial packers which are can not be executed due to the anti-debugging technique.

A Study on the Analysis and Efficiency of Police Budget (경찰의 예산분석 및 효율화 방안에 관한 연구)

  • Park, Jong-Seung;Kim, Chang-Yun
    • Korean Security Journal
    • /
    • no.38
    • /
    • pp.7-32
    • /
    • 2014
  • This study is aimed to analyze problems of police budgetary execution and to suggest better ways for establishing effective budget implementation as well as legitimacy of securing budget in the field of police work. For this purpose, this paper analyzed the annual reports on police budgetary execution, from 2009 to 2012, conducted by National Assembly Budget Office. In result, most parts of the police budgetary execution were not satisfied with the audit standard, and especially in terms of management of budgetary execution, it showed 40% in inappropriateness. In addition, excessive and underestimate appropriation in the police budgetary execution, which happened frequently in other offices, was recorded on the second place. 10% of the amount of budget was executed for ordinance violence. Given results analyzed from each division, Transportation Division occupied 40% of the amount of related problems and all of types in the field did not meet the audit standard, thus it is required to manage budgetary execution effectively. In terms of Public Safety Division, the problem was related to budgetary allocation prior to execution, such as overlap in other works, excessive and underestimate appropriation, and inappropriate business plans. Director General for Planning and Coordination did not meet the standard of law system maintenance, Given the light of the result of analyzing programs, traffic safety and securing communication was the most problematic and support for police administration, crime prevention and protecting the disadvantaged, educating professional police officers, and establishment of policing infrastructure were required to be reformed in sequence. In order to resolve these problems, it is demanded to check budgetary execution and the process in business plans on a regular basis. Additionally, in case of using budget in inappropriate parts, tough penality including reduction of budget in related to the local police should be implemented to increase the importance of budgetary execution. Moreover, because of the fact that a part of problem of budgetary execution was originally caused by the budgetary allocation, it is advised to allocate police budget using the budget proposal of National Finance Act and Ministry of Strategy and Finance.

  • PDF

A Comparative Study on Attitude of the Collegiate an4 Non-Collegiate Nursing Students toward Their Clinical Affiliation in a Mental Hospital (정신과 간호 실습에 대한 간호 대학생과 간호학교 학생들의 태도 비교 연구)

  • 김소야자
    • Journal of Korean Academy of Nursing
    • /
    • v.4 no.2
    • /
    • pp.17-31
    • /
    • 1974
  • Today, over seventy five percent of nursing in Korea provide a psychiatric experience in the basic curriculum. The psychiatric affiliation presents numerous major problems of adjustment to the student. The Importance of positive attitude toward the nursing care of psychiatric patients is recognized by the nursing profession. I have fined out the unfavorable attitude of non collegiate nursing students toward psychiatric nursing affiliation by previous research. This study was undertaken in response to a felt need to explore the use of several devices which might yield information about attitudes toward psychiatric nursing as a basis for future planning of the program offered at a selected hospital. This study is designed to meet the following objectives; (1) In order to find out the expressed attitudes of fifty·three collegiate nursing students toward their psychiatric affiliation. (2) To compare responses given by selected group of collegiate and non collegiate nursing students to same questionnaire (3) To determine the relationship between the attitudes of nursing students toward psychiatric nursing and the type of instructions where experience was obtained. A questionnaire, a Korean translation of the "Psychiatric Nursing Attitude Questionnaire" by Moldered Elizabeth fletcher, was administered to fifty-three collegiate nursing students who had completed a four-week psychiatric affiliation in a S hospital psychiatric ward during May 7, 1973 to Dec. 16, 1973. - The questionnaire of 100 statements was administered in the following way; (1) Part Ⅰ, Preconceptions, was, given in individual conferences with each subject, during the first few days of their affiliation, and again during the final week of affiliation. The responses to Part I were oral. (2) Part Ⅱ, Expectations, Part Ⅲ, Personal Relations, Part Ⅳ, Personal Feelings, and Part V, Attitudes and Activities of Patients were given to all of the subjects in a group meeting during the second week of the affiliation, and again, during the fourth week at the termination of the affiliation. Responses to Parts Ⅱ, Ⅲ, Ⅳ·, and V, were written. Each of the 100 statements of the questionnaire was considered to be either Positive or Negative. A favorable response was assigned the positive value of 1 and an unfavorable response was assigned the Negative value of O. The coefficient of correlation was computed between the two sets of scores for the fifty-three nursing students, The mean score, the standard deviation, and the differences in the means on each of the five parts of the questionnaire were computed and the relationships calculated by at-test. The results of the study were as follows; 1. There was no significant correlation between the two sets of the scores for the fifty-three nursing students during the four-week psychiatric affiliation. (r= 0.36) 2. There was no significant difference in the mean scores between the first and final tests for any of the questionnaire. 3. The Part Ⅰ, Preconceptions, data indicated collegiate nursing students have positive attitudes in preconceptions than non collegiate nursing students and preconceptions toward the psychiatric affiliation which affect their psychiatric nursing experience. 4. The Part Ⅱ, Expectations, data indicated more appropriate expectations of collegiate nursing students related to pre psychiatric affiliation orientation and sufficient theory learning than non-collegiate nursing students. 5. The Part Ⅲ, Personal relations, data indicated some students have negative attitudes in personal relations with normal people in respect to psychological security and social responsibilities. 6. The Part Ⅳ, Personal feelings, data indicated nursing students have psychological insecurity & inappropriateness. 7. The Part V, Attitudes and activities of patients, data indicated collegiate nursing students have more positive attitudes to the psychotic behavior of certain situations due to sufficient theory learning. 8. The data indicated collegiate·nursing students have more positive attitude than non-collegiate nursing students. 5. The Part Ⅲ, Personal relations, data indicated some students have negative attitudes in personal relations with normal people in respect to psychological security and social responsibilities. 6. The Part Ⅳ, Personal feelings, data indicated nursing students have psychological insecurity & inappropriateness. 7. The Part V, Attitudes and activities of patients, data indicated collegiate nursing students have more positive attitudes to the psychotic behavior of certain situations due to sufficient theory learning. 8. The data indicated collegiate·nursing students have more positive attitude than non-collegiate nursing students through psychiatric affiliation.

  • PDF

Middle-Old Age's Retirement Transition, Old Age Income Security and the Support of Gradual Retirement (중고령자의 퇴직전환 및 노후소득보장과 점진적 퇴직지원)

  • Ji, Eun-Jeong
    • Korean Journal of Social Welfare
    • /
    • v.58 no.3
    • /
    • pp.135-168
    • /
    • 2006
  • This study reviewed pension reform's overall characteristic and(anticipated) positive negative effect in OECD countries's and then analysed middle-old age's retirement transition and determinants of full/gradual retirement through the $3{\sim}7th$ Korea Labor and Income Panel considering that Korea has been aging society quickly and it is necessary to suggest not only solution of early retirement and working age reduction but also pension reform. As a result of this study, about 1/4 of 50 years and older have been continuing to work through various pathways after retirement and 98% among fully retired older who passed by re-employment step of occupational status including retirement are still searching for jobs. This showed that it is also inappropriate to typical retirement concept itself on the lines of labour market participation in Korea and part-time/temporary work or self-employment have been used by means of alternatives of maintaining works for middle-old ages. However, the duration of changed occupational status of gradual retirees is mostly only $1{\sim}2$ years. Therefore it is necessary to support the gradual retirement to minimize a term of income insecurity and promote the work of the old ages who have will and capacity of work. Most of all, partial pension system which is main program of gradual retirement, should make the rules that beneficiaries are those who age less than pensionable age and benefit levels should be actuarial fairness together with pension system and provide substantial help. But, the introduction of partial pension system is not the only way to solve and needs overall social economic approach. Especially guarantee the increase of quantitative qualitative employment for middle-old ages linking labor market policy and supporting gradual retirement not ought to be abused to force the part time works and early retirement route against their own will.

  • PDF

An Integrated Model based on Genetic Algorithms for Implementing Cost-Effective Intelligent Intrusion Detection Systems (비용효율적 지능형 침입탐지시스템 구현을 위한 유전자 알고리즘 기반 통합 모형)

  • Lee, Hyeon-Uk;Kim, Ji-Hun;Ahn, Hyun-Chul
    • Journal of Intelligence and Information Systems
    • /
    • v.18 no.1
    • /
    • pp.125-141
    • /
    • 2012
  • These days, the malicious attacks and hacks on the networked systems are dramatically increasing, and the patterns of them are changing rapidly. Consequently, it becomes more important to appropriately handle these malicious attacks and hacks, and there exist sufficient interests and demand in effective network security systems just like intrusion detection systems. Intrusion detection systems are the network security systems for detecting, identifying and responding to unauthorized or abnormal activities appropriately. Conventional intrusion detection systems have generally been designed using the experts' implicit knowledge on the network intrusions or the hackers' abnormal behaviors. However, they cannot handle new or unknown patterns of the network attacks, although they perform very well under the normal situation. As a result, recent studies on intrusion detection systems use artificial intelligence techniques, which can proactively respond to the unknown threats. For a long time, researchers have adopted and tested various kinds of artificial intelligence techniques such as artificial neural networks, decision trees, and support vector machines to detect intrusions on the network. However, most of them have just applied these techniques singularly, even though combining the techniques may lead to better detection. With this reason, we propose a new integrated model for intrusion detection. Our model is designed to combine prediction results of four different binary classification models-logistic regression (LOGIT), decision trees (DT), artificial neural networks (ANN), and support vector machines (SVM), which may be complementary to each other. As a tool for finding optimal combining weights, genetic algorithms (GA) are used. Our proposed model is designed to be built in two steps. At the first step, the optimal integration model whose prediction error (i.e. erroneous classification rate) is the least is generated. After that, in the second step, it explores the optimal classification threshold for determining intrusions, which minimizes the total misclassification cost. To calculate the total misclassification cost of intrusion detection system, we need to understand its asymmetric error cost scheme. Generally, there are two common forms of errors in intrusion detection. The first error type is the False-Positive Error (FPE). In the case of FPE, the wrong judgment on it may result in the unnecessary fixation. The second error type is the False-Negative Error (FNE) that mainly misjudges the malware of the program as normal. Compared to FPE, FNE is more fatal. Thus, total misclassification cost is more affected by FNE rather than FPE. To validate the practical applicability of our model, we applied it to the real-world dataset for network intrusion detection. The experimental dataset was collected from the IDS sensor of an official institution in Korea from January to June 2010. We collected 15,000 log data in total, and selected 10,000 samples from them by using random sampling method. Also, we compared the results from our model with the results from single techniques to confirm the superiority of the proposed model. LOGIT and DT was experimented using PASW Statistics v18.0, and ANN was experimented using Neuroshell R4.0. For SVM, LIBSVM v2.90-a freeware for training SVM classifier-was used. Empirical results showed that our proposed model based on GA outperformed all the other comparative models in detecting network intrusions from the accuracy perspective. They also showed that the proposed model outperformed all the other comparative models in the total misclassification cost perspective. Consequently, it is expected that our study may contribute to build cost-effective intelligent intrusion detection systems.

A Study on the Violation of Probation Condition Determinants between Sex Offenders and Non-Sex Offenders (성범죄자와 일반범죄자의 보호관찰 경고장 관련 요인 비교)

  • Cho, Youn-Oh
    • Korean Security Journal
    • /
    • no.43
    • /
    • pp.205-230
    • /
    • 2015
  • This study aims to compare the differences of crucial factors that are associated with probation warning tickets between sex offenders and non-sex offenders in South Korea. Serious high-profile cases have occurred in recent years which resulted in public and political conners for successful sex offender management and monitoring strategy through community corrections. The official response has been to initiate a series of legislative probation and parole measures by using GPS electronic monitoring system, chemical castration, and sex offender registry and notification. In this context, the current study is designed to explore the major factors that could affect the failure of probation by comparing the differences between sex offenders and non-sex offenders in terms of their major factors which are related to the failure of probation. The failure of probation is measured by the number of warning tickets which would be issued when there is the violation of probation conditions. The data is obtained from Seoul Probation office from January, 29, 2014 to February, 28, 2014. The sample number of sex offenders is 144 and the number of non-sex offenders is 1,460. The data includes the information regarding the offenders who completed their probation order after they were assigned to Seoul Probation in 2013. Furthermore, this study uses the chi-square and logistic regression analysis by using SPSS statistical package program. The result demonstrated that only prior criminal history was statistically significant factor that was related to the number of warning tickets in the sex offender group when other variables were controlled($X^2=25.15$, p<0.05, Nagelkerke $R^2=0.23$)(b=0.19, SE=0.08, p<0.05). By contrast, there were various factors that were associated with the number of warning tickets in non-sex offender group. Specifically, the logistic regression analysis for the non-sex offenders showed that demographic variable(marital status and employment type), offender-victim relationships, alcohol addiction, violent behavior, prior criminal history, community service order, and attendance order were statistically significant factors that were associated with the odds of warning tickets. Further policy implication will be discussed.

  • PDF

Employment Support for the Low-income Elderly in the OECD Countries: Implications for Senior Employment Policy (OECD 국가의 저소득 고령자 고용지원정책 : 노인일자리사업에 주는 함의)

  • Ji, Eun Jeong
    • Korean Journal of Social Welfare Studies
    • /
    • v.44 no.3
    • /
    • pp.177-206
    • /
    • 2013
  • The Korean government has implemented the senior employment policy as a direct job creation policy since 2004. A realistic discussion of policy alternatives and orientation for this has been given little attention even though senior employment policy has been carried out for the last 10 years and it will be expanded next year. This study tries to examine active labor market policy especially focusing on direct job creation programs and policies for the disadvantaged low-income elderly in OECD countries, and then it suggests some developmental alternatives for senior employment policy based on the study's results. The main results from this analysis are summarized in two points. Firstly, except pension policies, employment policy for older workers in the OECD countries is highly proportional to the tackling of objective factors reducing the demand for older workers (wage subsidies, reduced social security contribution rate etc). And the strategies of improving employability have not been relatively important and direct job creation policy has been marginal. Secondly, employment support policies for the low-income elderly can be divided into three types: support for the low-income elderly, alleviating early retirement and support for full employment according to the criteria which are determined by policy objectives and the social economic index. Korea's employment support policies belong to the type of direct job creation among them. This seems to be due to the fact that the rate of elderly poverty is extremely high and an income security system has not been developed in Korea. However, the policy objective is still uncertain. Therefore, this policy needs to set up clear objectives and establish a proper system for the achievement of its goals. If we focus on the strength of its employment characteristics, we need to modify the policy's plan in the perspective of labor market policy. But if we intend to keep both of the current objectives, it is better for this policy to be divided into two parts: social participation and income supplements. Or it also may be a solution to transform the system into an employment service, a training system which supports participants to move into unsubsidized jobs such as SCSEP in the U. S.

Research on the Circumstance for Agricultural Investment of Cambodia (캄보디아 농업투자 환경에 관한 연구)

  • Lee, Kyu-Seong;Bae, Dong-Jin;Kim, Seong-Nam;Kang, Young-Shin
    • Journal of the Korean Society of International Agriculture
    • /
    • v.23 no.5
    • /
    • pp.475-484
    • /
    • 2011
  • International price of cereal has been dramatically increasing for the past few years. This price hike amplified the importance of food self-sufficiency in numerous countries due to the fact that food security is directly proportional to food self-sufficiency. In this study, we conducted a survey to provide useful information of Cambodia's agricultural environment to possible Korean agricultural investors and as to highlight Cambodia as a strong candidate for the establishment of Korea's foreign base for cereal production. The survey conducted includes information regarding Cambodia's agricultural environment and investment circumstances including the political, economical and other contributing factors affecting agricultural investment in Cambodia. Seventy percent of the Cambodia's total population engage in agriculture and this comprises about 30% of the country's GDP. This statistics reflects the possibility of Cambodia's poverty alleviation which proves that agriculture in Cambodia is the driving force for the improvement of the country's economy. In addition, low labor cost, fertile land, abundant water resources, like the Tonle sap lake and the Mekong river, and unreclaimed lands are the strong points that could attract agricultural investors to Cambodia. Poor infrastructure, irrigation systems, law reforms, including social and cultural differences may be the biggest setbacks for the acceleration of Cambodia's agriculture development. However, the Cambodian government is open and willing to make adjustments for Cambodia to be both foreign and domestic agricultural investor-friendly, expecting that it will boost its country's agricultural development. Making the best out of this opportunity, the coordination of KOICA with Korean agricultural investors in building infrastructures and with the help of the KOPIA program for the transfer of agricultural technology will benefit both countries and will play an important role in Cambodia's agriculture.

Content Analysis of the Health Counseling by the Intranet in University : 2000-2004 (일개 대학교 5년간 인트라넷 건강상담 내용분석)

  • Kim, Hyeung-Dae;Bae, Seok-Hwan;Na, Bak-Ju;Kim, Keon-Yeop;Kim, Chul-Woung;Kang, Moon-Young;Kim, Dae-Kyung;Oh, Kyung-Hee;Lee, Moo-Sik
    • Journal of agricultural medicine and community health
    • /
    • v.32 no.2
    • /
    • pp.75-86
    • /
    • 2007
  • Objectives: The research was aimed at analyzing the contents of university intranet for systematically execution of the healthy information provision and healthy consultation services from 2000 January to 2004 December. Methods: We have analyzed 300(28.3%) the instances of accomplished health consultation cases from the whole 1,059 instances which were the replied in a university intranet. Results: According to the contents of health consultation in ICPC code, a general symptom 91 cases(30.3%) was most, muscle-skeletal system 44 cases(14.7%), and digestive system 43 cases(14.3%) in order of cases of health counselling. The symptoms and complaint with 155 cases(51.7%) were most in the distribution of the health counselling contents by 17 charter of ICPC. The most common reason of counselling by 17 charter of ICPC were as follows; questions about the symptom and diagnosis(118 cases, 39.3%), the preventive and treatment methods(91 cases, 30.0%), and medical fee(20cases, 6.7%) in order. We mainly answer on the content of health counselling were as follows; make an offer of medical information and knowledge(48.3%), recommend visit clinic or hospital(23.7%), guide to treatment(12.7%), and so on. Conclusions: This research showed that the program of health counselling may not meet completely the high quality and adequate distribution of health counselling by the intranet in a university by content analysis. The finding suggests that health counselling by intranet in a university may be used to supplement of systemic improvement on the intranet Q/A format from current lack of essential health information and security for the quality of the health counselling.

Implementation of a Web-based Virtual Educational System for Java Language Using Java Web Player (자바 웹플레이어를 이용한 웹기반 자바언어 가상교육시스템의 구현)

  • Kim, Dongsik;Moon, Ilhyun;Choi, Kwansun;Jeon, Changwan;Lee, Sunheum
    • The Journal of Korean Association of Computer Education
    • /
    • v.11 no.1
    • /
    • pp.57-64
    • /
    • 2008
  • This paper presents a web-based virtual educational system for Java language, which consists of a management system named Java Web Player (JWP) and creative multimedia contents for the lectures of Java language. The JWP is a Java application program free from security problems by the Java Web Start technologies that supports an integrated learning environment including three important learning procedures: Java concept learning process, programming practice process and assessment process. On-line voice presentation and its related texts together with moving images are synchronized for efficiently conveying creative contents to learners. Furthermore, a simple and useful compiler is included in the JWP for providing user-friendly language practice environment enabling such as coding, editing, executing, and debugging Java source files on the Web. Finally, simple multiple choices are given suddenly to the learners while they are studying through the JWP and the test results are displayed on the message box. In order to show the validity of the proposed virtual educational system we analysed and assessed the learners' academic performance on the five quizzes for one semester.

  • PDF