• Title/Summary/Keyword: Security Rules

Search Result 326, Processing Time 0.028 seconds

A Design of a Korean Programming Language Ensuring Run-Time Safety through Categorizing C Secure Coding Rules (C 시큐어 코딩 규칙 분류를 통한 실행 안전성을 보장하는 한글 언어 설계)

  • Kim, Yeoneo;Song, Jiwon;Woo, Gyun
    • Journal of KIISE
    • /
    • v.42 no.4
    • /
    • pp.487-495
    • /
    • 2015
  • Since most of information is computerized nowadays, it is extremely important to promote the security of the computerized information. However, the software itself can threaten the safety of information through many abusive methods enabled by coding mistakes. Even though the Secure Coding Guide has been proposed to promote the safety of information by fundamentally blocking the hacking methods, it is still hard to apply the techniques on other programming languages because the proposed coding guide is mainly written for C and Java programmers. In this paper, we reclassified the coding rules of the Secure Coding Guide to extend its applicability to programming languages in general. The specific coding guide adopted in this paper is the C Secure Coding Guide, announced by the Ministry of Government Administration and Home Affairs of Korea. According to the classification, we applied the rules of programming in Sprout, which is a newly proposed Korean programming language. The number of vulnerability rules that should be checked was decreased in Sprout by 52% compared to C.

Logic Based Bad Data Processing Algorithm in Substations (논리 결합에 의한 변전소 오류 데이터 처리 알고리즘 개발)

  • Jin, B.G.;Hyun, S.H.;Lee, S.J.
    • Proceedings of the KIEE Conference
    • /
    • 2005.07a
    • /
    • pp.408-410
    • /
    • 2005
  • It is important to identify and correct bad data for maintaining the security and the reliability of data acquisition and management in a substation. This paper presents a bad data processing method based on rules acquired by analysis of cause and effect of bad data. The proposed method verified by the case study in a typical substation model.

  • PDF

Development of evaluation criteria for selection of source code security vulnerability verification rules for industrial control systems (산업제어시스템의 소스코드 보안 취약점 검증 룰 선정을 위한 평가 기준 개발)

  • Kim, Eunbi;Choi, Yisoo;Han, Dongjoon
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2021.11a
    • /
    • pp.449-452
    • /
    • 2021
  • 산업제어시스템은 IT 기술의 발전에 따라 다양한 기기 환경과 네트워크를 적용해 진화하고 있다. 이러한 상황에서 사이버 보안의 위협은 가중되고 있으며, 이를 예방하는 방법의 하나로 산업제어시스템에 탑재되는 소프트웨어의 소스코드 개발 과정에서 보안 취약점을 예방하기 위해 소스코드 보안 룰을 적용하여 위반사항을 제거한다. 본 연구에서는 소스코드 보안 룰에서 적용 우선순위를 선정하기 위한 가이드를 개발한다.

The UNESCO Action Plan and 2030 Agenda of Sustainable Development Goals for Climate Change

  • Thriveni, Thenepalli;Ramakrishna, Chilakala;Habte, Lulit;Ahn, Ji Whan
    • Journal of Energy Engineering
    • /
    • v.27 no.2
    • /
    • pp.89-94
    • /
    • 2018
  • UNESCO is an international specialized agency based on the United Nations (UN) located in the Paris. The United Nations Educational, Scientific and Cultural Organization abbreviated as UNESCO. The mission and goal of UNESCO are to maintain the peace and security throughout the globe by encouraging international collaborations through educational, scientific, and cultural heritage in order to increase respect for principals of justice, international rules of law, and international human rights. Recently, the UNESCO published a new set of 17 goals for the nation's sustainable society. The Organization ensures to actively participate in UN activities to improve harmony and planning within the United Nations system. The 2030 agenda is primarily about shifting the world on to a sustainable and most in-depth. Currently, UNESCO launched broad goals and objectives for the international community including the Millennium Development Goals (MDGs). Among these sustainable goals, climate change, water security is more significant. In this paper, we briefly reviewed the seventeen goals by UNESCO.

A Development of Intrusion Detection and Protection System using Netfilter Framework (넷필터 프레임워크를 이용한 침입 탐지 및 차단 시스템 개발)

  • Baek, Seoung-Yub;Lee, Geun-Ho;Lee, Geuk
    • Convergence Security Journal
    • /
    • v.5 no.3
    • /
    • pp.33-41
    • /
    • 2005
  • Information can be leaked, changed, damaged and illegally used regardless of the intension of the information owner. Intrusion Detection Systems and Firewalls are used to protect the illegal accesses in the network. But these are the passive protection method, not the active protection method. They only react based on the predefined protection rules or only report to the administrator. In this paper, we develop the intrusion detection and protection system using Netfilter framework. The system makes the administrator's management easy and simple. Furthermore, it offers active protection mechanism against the intrusions.

  • PDF

A Study on the Serious Game for the Military Training (군사훈련용 기능성 게임에 관한 연구)

  • Ha, Soo-Cheol
    • Journal of National Security and Military Science
    • /
    • s.7
    • /
    • pp.233-270
    • /
    • 2009
  • Serious game played with a computer in accordance with specific rules, that uses entertainment to further government or corporate training, education, health, public policy, and strategic communication objectives. The main goal of a serious game is usually to train or educate users while giving them an enjoyable experience. Serous games are video games with serious purposes such as teaching or training and whose principal aim is education. The major characteristics of serious games involve pedagogy which are all of the activities that educate, train, or instruct the player. Other characteristics of serious games are that they use entertainment principles, creativity and technology to build games that carry out serious purposes. This study is to introduce a serious game for the military training and to describe the elements of game design for developing it.

  • PDF

Contingency Severity Ranking Using Direct Method in Power Systems (전력계통에 있어서 직접법을 활용한 상정사고 위험순위 결정)

  • Lee, Sang-Keun
    • The Transactions of the Korean Institute of Electrical Engineers P
    • /
    • v.54 no.2
    • /
    • pp.67-72
    • /
    • 2005
  • This paper presents a method to select contingency ranking considering voltage security problems in power systems. Direct method which needs not the detailed knowledge of the post contingency voltage at each bus is used. Based on system operator's experience and knowledge, the membership functions for the MVAR mismatch and allowable voltage violation are justified describing linguistic representation with heuristic rules. Rule base is used for the computation of severity index for each contingency by fuzzy inference. Contingency ranking harmful to the system is formed by the index for security evaluation. Compared with 1P-1Q iteration, this algorithm using direct method and fuzzy inference shows higher computation speed and almost the same accuracy. The proposed method is applied to model system and KEPCO pratical system which consists of 311 buses and 609 lines to show its effectiveness.

A Study on the Specification Rules for Security Systems in Z (Z 언어를 이용한 보안시스템의 명세 규칙)

  • Kim, Myong-Jae;Lee, Hyong-Hyo;Noh, Bong-Nam
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2002.04b
    • /
    • pp.849-852
    • /
    • 2002
  • 전통적으로 소프트웨어 공학분야에서는 소프트웨어 설계 및 개발을 위한 자동화도구와 정형화기법이 적용되었으며, 안전한 보안시스템의 개발을 위해서도 수학적인 명세와 검증도구를 사용하는 경우, 보다 안전하고 완전한 보안시스템을 구축할 수 있다. 본 연구는 정형화 명세언어인 Z를 이용하여 보안시스템을 기술하고, 기술된 명세를 소프트웨어 검증도구를 이용하여 보안시스템이 제공하는 보안특성 만족 여부 점검을 목적으로 한다. 이를 위해 본 논문에서는 수학적으로 기술된 시스템에 대한 명세를 Z스키마로 변환하는 변환규칙을 기술하고, 이와 함께 Z언어 검증도구인 Z/EVES를 이용한 검증결과를 제시한다.

  • PDF

Artificial Intelligence and Pattern Recognition Using Data Mining Algorithms

  • Al-Shamiri, Abdulkawi Yahya Radman
    • International Journal of Computer Science & Network Security
    • /
    • v.21 no.7
    • /
    • pp.221-232
    • /
    • 2021
  • In recent years, with the existence of huge amounts of data stored in huge databases, the need for developing accurate tools for analyzing data and extracting information and knowledge from the huge and multi-source databases have been increased. Hence, new and modern techniques have emerged that will contribute to the development of all other sciences. Knowledge discovery techniques are among these technologies, one popular technique of knowledge discovery techniques is data mining which aims to knowledge discovery from huge amounts of data. Such modern technologies of knowledge discovery will contribute to the development of all other fields. Data mining is important, interesting technique, and has many different and varied algorithms; Therefore, this paper aims to present overview of data mining, and clarify the most important of those algorithms and their uses.

Stock Forecasting Using Prophet vs. LSTM Model Applying Time-Series Prediction

  • Alshara, Mohammed Ali
    • International Journal of Computer Science & Network Security
    • /
    • v.22 no.2
    • /
    • pp.185-192
    • /
    • 2022
  • Forecasting and time series modelling plays a vital role in the data analysis process. Time Series is widely used in analytics & data science. Forecasting stock prices is a popular and important topic in financial and academic studies. A stock market is an unregulated place for forecasting due to the absence of essential rules for estimating or predicting a stock price in the stock market. Therefore, predicting stock prices is a time-series problem and challenging. Machine learning has many methods and applications instrumental in implementing stock price forecasting, such as technical analysis, fundamental analysis, time series analysis, statistical analysis. This paper will discuss implementing the stock price, forecasting, and research using prophet and LSTM models. This process and task are very complex and involve uncertainty. Although the stock price never is predicted due to its ambiguous field, this paper aims to apply the concept of forecasting and data analysis to predict stocks.