• Title/Summary/Keyword: Security risk

Search Result 1,331, Processing Time 0.026 seconds

Study on File Recovery Based on Metadata Accoring to Linux Kernel (리눅스 커널에 따른 메타데이터 기반 파일 복원 연구)

  • Shin, Yeonghun;Jo, Woo-yeon;Shon, Taeshik
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.29 no.1
    • /
    • pp.77-91
    • /
    • 2019
  • Recent Linux operating systems having been increasingly used, ranging from automotive consoles, CCTV, IoT devices, and mobile devices to various versions of the kernel. Because these devices can be used as strong evidence in criminal investigations, there is a risk of destroying evidence through file deletion. Ext filesystem forensics has been studied in depth because it can recovery deleted files without depending on the kind of device. However, studies have been carried out without consideration of characteristics of file system which may vary depending on the kernel. This problem can lead to serious situations, such as those that can impair investigative ability and cause doubt of evidence ability, when an actual investigation attempts to analyze a different version of the kernel. Because investigations can be performed on various distribution and kernel versions of Linux file systems at the actual investigation site, analysis of the metadata changes that occur when files are deleted by Linux distribution and kernel versions is required. Therefore, in this paper, we analyze the difference of metadata according to the Linux kernel as a solution to this and recovery deleted file. After that, the investigating agency needs to consider the metadata change caused by the difference of Linux kernel version when performing Ext filesystem forensics.

A Case Study on Performance Analysis of Antimicrobial Copper Film Attaching to Window for Responding to COVID-19 and Others (코로나19 등 대응을 위한 "유리창 부착용 항바이러스 동필름" 성능분석 사례연구)

  • Kim, Seong Je
    • Journal of Korean Society of Disaster and Security
    • /
    • v.14 no.1
    • /
    • pp.23-40
    • /
    • 2021
  • In the era of the global coronal 19 pandemic, there is a risk of cross-infection in hospitals at the stage where treatments and vaccines are currently being developed and marketed, so individuals should enhance their acquired immunity and generalize their living systems by the performance of copper ions in the social environment. In order to prevent the spread of infection, the need for anti-bacterial film and its efficacy were analyzed through anti-viral performance tests based on research and development cases of worldwide and immemorial time. he Korea Construction Research Institute (KCL) has received anti-bacterial performance certification and anti-viral test scores from the "National Approval Performance Certification Agency." At the time, NCCP 43326 Human Corona virus (BetaCoV/Korea/KCDC03/2020), which was approved by the Centers for Disease Control and Prevention, was introduced to ensure that the activity rate of infected cells was satisfied in the anti-viral performance test. Anti-proliferation measures for the Corona 19 virus require a quality clinical trial study comparing the experimental group within the glass space where the antiviral copper film is constructed with the comparator of the same condition without copper film.

Concepts and Legal Problems Related to the Health-vulnerable Class, and Measures to Ensure Health (건강취약계층의 개념과 법적 문제점, 그리고 건강보장을 위한 방안)

  • Kim, JESUN
    • The Korean Society of Law and Medicine
    • /
    • v.22 no.3
    • /
    • pp.125-144
    • /
    • 2021
  • The purpose of this study is to present a legal improvement plan for health protection of the health-vulnerable class in our society in the 'COVID-19'. The contents of the first study examined the meaning of the existing (social) vulnerable class, and then critically considered the health-vulnerable class as an expanded concept in connection with the social risk of health. The term "vulnerable class" tends to have both meaning as the traditionally marginalized class such as the elderly, the disabled, and women, as well as the condition of having no ability to live due to low income, such as the low-income class. The concept of the health-vulnerable class is meaningful in that it appears as a recently expanded concept as it is linked to the concept of the vulnerable class and social risks such as health threats. The content of the second study looked at the problems that appeared when the health-vulnerable class was used together with the health care-vulnerable class in laws. Due to the laws used in both terms, there was a problem that the social security system related to health and health care could create blind spots. The contents of the third study suggested legal improvement directions for social security measures for health for the underprivileged.

When Disease Defines a Place: Batavia in British Diplomatic and Military Narratives, 1775-1850

  • Keck, Stephen
    • SUVANNABHUMI
    • /
    • v.14 no.2
    • /
    • pp.117-148
    • /
    • 2022
  • The full impact of COVID-19 has yet to be felt: while it may not define the new decade, it is clear that its immediate significance was to test many of the basic operating assumptions and procedures of global civilization. Even as vaccines are developed and utilized and even as it is possible to see the beginning of the end of COVID-19 as a discrete historical event, it remains unclear as to its ultimate importance. That said, it is evident that the academic exploration of Southeast Asia will also be affected by both the global and regional experiences of the pandemic. "Breakthroughs of Area Studies and ASEAN in the Era of Homo Untact" promises to help reconceptualize the study of the region by highlighting the importance of redefined spatial relationships and new potentially depersonalized modes of communication. This paper acknowledges these issues by suggesting that the transformations caused by the pandemic should motivate scholars to raise new questions about how to understand humanity-particularly as it is defined by societies, nations and regions. Given that COVID-19 (and the response to it) has altered many of the fundamental rhythms of globalized regions, there is sufficient warrant for re-examining both the ways in which disease, health and their related spaces affect the perceptions of Southeast Asia. To achieve "breakthroughs" into the investigation of the region, it makes sense to have another glance at the ways in which the discourses about diseases and health may have helped to inscribe definitions of Southeast Asia-or, at the very least, the nations, societies and peoples who live within it. In order to at least consider these larger issues, the discussion will concentrate on a formative moment in the conceptualization of Southeast Asia-British engagement with the region in the late 18th and early 19th centuries. To that end three themes will be highlighted: (1) the role that British diplomatic and military narratives played in establishing the information priorities required for the construction of colonial knowledge; (2) the importance not only of "colonial knowledge" but information making in its own right; (3) in anticipation of the use of big data, the manner in which manufactured information (related to space and disease) could function in shaping early British perceptions of Southeast Asia-particularly in Batavia and Java. This discussion will suggest that rather than see social distancing or increased communication as the greatest outcome of COVID-19, instead it will be the use of data-that is, big, aggregated biometric data which have not only shaped responses to the pandemic, but remain likely to produce the reconceptualization of both information and knowledge about the region in a way that will be at least as great as that which took place to meet the needs of the "New Imperialism." Furthermore, the definition and articulation of Southeast Asia has often reflected political and security considerations. Yet, the experience of COVID-19 could prove that data and security are now fused into a set of interests critical to policy-makers. Given that the pandemic should accelerate many existing trends, it might be foreseen these developments will herald the triumph of homo indicina: an epistemic condition whereby the human subject has become a kind of index for its harvestable data. If so, the "breakthroughs" for those who study Southeast Asia will follow in due course.

Cloud-Based Reservation and Notification System for Efficient Testing of Infectious Diseases (효율적인 감염병 검사 예약을 위해 클라우드에 기반한 예약 및 알림 시스템)

  • Je-Seong Hwangbo;Ho-Yoon Kim;Seung-Soo Shin
    • Journal of Industrial Convergence
    • /
    • v.21 no.1
    • /
    • pp.67-76
    • /
    • 2023
  • COVID-19, which occurred in 2019, has a strong contagious power, has serious symptoms of infection and after-effects, and death in severe cases depending on the underlying disease and symptoms. As COVID-19 is highly contagious, in Korea, screening clinics have been set up across the country to determine whether or not to be positive for COVID-19 and isolate the infected to prevent the spread of COVID-19. However, there are cases where COVID-19 test applicants flock to screening clinics and cannot receive tests due to longer waiting times, and there is a risk that secondary infections may occur in the atmosphere. In this study, the reservation and notification system can be applied from the existing screening care system to solve spatial constraints, reducing waiting time with screening appointments, and solving population bottlenecks to screening clinics. Taking the COVID-19 pandemic as an experience, we propose a system that can present directions in future pandemic situations. To process real-time data, we use Google's Firebase to use Realtime Database in the cloud environment. Because a real-time database is used, users can check the status of screening clinics in real time through the app, make reservations, and receive notifications about test reservations.

Cortex M3 Based Lightweight Security Protocol for Authentication and Encrypt Communication between Smart Meters and Data Concentrate Unit (스마트미터와 데이터 집중 장치간 인증 및 암호화 통신을 위한 Cortex M3 기반 경량 보안 프로토콜)

  • Shin, Dong-Myung;Ko, Sang-Jun
    • Journal of Software Assessment and Valuation
    • /
    • v.15 no.2
    • /
    • pp.111-119
    • /
    • 2019
  • The existing smart grid device authentication system is concentrated on DCU, meter reading FEP and MDMS, and the authentication system for smart meters is not established. Although some cryptographic chips have been developed at present, it is difficult to complete the PKI authentication scheme because it is at the low level of simple encryption. Unlike existing power grids, smart grids are based on open two-way communication, increasing the risk of accidents as information security vulnerabilities increase. However, PKI is difficult to apply to smart meters, and there is a possibility of accidents such as system shutdown by sending manipulated packets and sending false information to the operating system. Issuing an existing PKI certificate to smart meters with high hardware constraints makes authentication and certificate renewal difficult, so an ultra-lightweight password authentication protocol that can operate even on the poor performance of smart meters (such as non-IP networks, processors, memory, and storage space) was designed and implemented. As a result of the experiment, lightweight cryptographic authentication protocol was able to be executed quickly in the Cortex-M3 environment, and it is expected that it will help to prepare a more secure authentication system in the smart grid industry.

Scaling Attack Method for Misalignment Error of Camera-LiDAR Calibration Model (카메라-라이다 융합 모델의 오류 유발을 위한 스케일링 공격 방법)

  • Yi-ji Im;Dae-seon Choi
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.33 no.6
    • /
    • pp.1099-1110
    • /
    • 2023
  • The recognition system of autonomous driving and robot navigation performs vision work such as object recognition, tracking, and lane detection after multi-sensor fusion to improve performance. Currently, research on a deep learning model based on the fusion of a camera and a lidar sensor is being actively conducted. However, deep learning models are vulnerable to adversarial attacks through modulation of input data. Attacks on the existing multi-sensor-based autonomous driving recognition system are focused on inducing obstacle detection by lowering the confidence score of the object recognition model.However, there is a limitation that an attack is possible only in the target model. In the case of attacks on the sensor fusion stage, errors in vision work after fusion can be cascaded, and this risk needs to be considered. In addition, an attack on LIDAR's point cloud data, which is difficult to judge visually, makes it difficult to determine whether it is an attack. In this study, image scaling-based camera-lidar We propose an attack method that reduces the accuracy of LCCNet, a fusion model (camera-LiDAR calibration model). The proposed method is to perform a scaling attack on the point of the input lidar. As a result of conducting an attack performance experiment by size with a scaling algorithm, an average of more than 77% of fusion errors were caused.

A Study on Acceptance of Blockchain-Based Genetic Information Platform (블록체인 기반 유전자분석 정보플랫폼의 수용에 대한 연구)

  • In Seon Choi;Dong Chan Park;Doo Hee Chung
    • Information Systems Review
    • /
    • v.23 no.3
    • /
    • pp.97-125
    • /
    • 2021
  • Blockchain is a core technology to solve personal information leakage and data management issues, which are limitations of existing Genomic Sequencing services. Due to continuous cost reduction and deregulation, the market size of Genomic Sequencing has been increasing, also the potential of services is expected to increase when Blockchain's security and connectivity are combined. We created our research model by combining the Technology Acceptance Model (TAM) and the Innovation Resistance Theory also analyzed the factors affecting the acceptance intention and innovation resistance of the Blockchain Based Genomic Sequencing Information Platform. A survey was conducted on 150 potential users of Blockchain and Genomic Sequencing services. The analysis was conducted by setting the four Blockchain variables: Security, transparency, availability, and diversity). Also, we set the Perceived Usefulness, Perceived risk, and Perceived Complexity for Technology Acceptance and Innovation Resistance variables and analyzed the effect of the characteristics of the Blockchain on acceptance intention and innovation resistance through these variables. Through this analysis, key variables that need to be considered important to reduce resistance and increase acceptance intention could be identified. This study presents innovation factors that should be considered in companies preparing a new Blockchain Based Genomic Sequencing Information Platform.

Safety Verification Techniques of Privacy Policy Using GPT (GPT를 활용한 개인정보 처리방침 안전성 검증 기법)

  • Hye-Yeon Shim;MinSeo Kweun;DaYoung Yoon;JiYoung Seo;Il-Gu Lee
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.34 no.2
    • /
    • pp.207-216
    • /
    • 2024
  • As big data was built due to the 4th Industrial Revolution, personalized services increased rapidly. As a result, the amount of personal information collected from online services has increased, and concerns about users' personal information leakage and privacy infringement have increased. Online service providers provide privacy policies to address concerns about privacy infringement of users, but privacy policies are often misused due to the long and complex problem that it is difficult for users to directly identify risk items. Therefore, there is a need for a method that can automatically check whether the privacy policy is safe. However, the safety verification technique of the conventional blacklist and machine learning-based privacy policy has a problem that is difficult to expand or has low accessibility. In this paper, to solve the problem, we propose a safety verification technique for the privacy policy using the GPT-3.5 API, which is a generative artificial intelligence. Classification work can be performed evenin a new environment, and it shows the possibility that the general public without expertise can easily inspect the privacy policy. In the experiment, how accurately the blacklist-based privacy policy and the GPT-based privacy policy classify safe and unsafe sentences and the time spent on classification was measured. According to the experimental results, the proposed technique showed 10.34% higher accuracy on average than the conventional blacklist-based sentence safety verification technique.

A Research on RC3(RMF-CMMC Common Compliance) meta-model development in preparation for Defense Cybersecurity (국방 사이버보안을 위한 RMF-CMMC 공통규정준수 메타모델 개발방안 연구)

  • Jae-yoon Hwang;Hyuk-jin Kwon
    • Journal of Internet Computing and Services
    • /
    • v.25 no.1
    • /
    • pp.123-136
    • /
    • 2024
  • The U.S. Department of Defense, leading global cybersecurity policies, has two main cybersecurity frameworks: the Cybersecurity Maturity Model Certification (CMMC) for external defense industry certification, and the Risk Management Framework (RMF) for internal organizational security assessments. For Republic of Korea military, starting from 2026, the Korean version of RMF (K-RMF) will be fully implemented. Domestic defense industry companies participating in projects commissioned by the U.S. Department of Defense must obtain CMMC certification by October 2025. In this paper, a new standard compliance meta-model (R3C) development methodology that can simultaneously support CMMC and RMF security audit readiness tasks is introduced, along with the implementation results of a compliance solution based on the R3C meta-model. This research is based on practical experience with the U.S. Department of Defense's cybersecurity regulations gained during the joint project by the South Korean and U.S. defense ministries' joint chiefs of staff since 2022. The developed compliance solution functions are being utilized in joint South Korean-U.S. military exercises. The compliance solution developed through this research is expected to be available for sale in the private sector and is anticipated to be highly valuable for domestic defense industry companies that need immediate CMMC certification.