• 제목/요약/키워드: ShellCode

검색결과 153건 처리시간 0.026초

엔트로피를 이용한 ShellCode 탐지 방법 (Detecting ShellCode Using Entropy)

  • 김우석;강성훈;김경신;김승주
    • 정보처리학회논문지:컴퓨터 및 통신 시스템
    • /
    • 제3권3호
    • /
    • pp.87-96
    • /
    • 2014
  • 해커들은 웹 사이트를 해킹 또는 경유 사이트를 운영하는 등 다양한 방법으로 목적을 달성하기 위한 해킹을 시도한다. 악성코드를 웹 사이트에 업로드하여 경유 사이트를 만드는 경우 해당 사이트에 접속하는 사용자는 좀비 PC가 되어 아이디와 패스워드 및 개인 정보가 대량 유출되고 해킹된 개인정보들은 다른 해킹 방법에 사용되고 있다. 기존의 탐지기법은 Snort rule을 사용하여 패턴을 IDS/IPS 장비에 입력하여 네트워크에서 패턴이 일치되면 탐지하는 기법으로 동작하고 있다. 하지만 입력된 패턴을 벗어난 공격을 하였을 경우 IDS/IPS 장비에서는 탐지하지 못하고 정상적인 행위로 간주하여 사용자 PC를 감염시킨다. 공격자는 패턴 탐지 방법의 취약점을 찾아 ShellCode를 진화시킨다. 진화된 ShellCode 공격에 대응하여 악의적인 공격을 탐지 및 대응할 수 있는 방법의 제시가 필요한 실정이다. 본 논문은 정보량 측정을 통한 ShellCode를 탐지하는 방법에 관한 연구이며, 기존의 보안 장비를 우회하여 사용자PC에 공격 시도를 탐지하는 방법을 제시한다.

안전한 웹 서버 환경을 위한 시큐어코딩 도구, 웹쉘 탐지도구 간의 상호연동 시스템 설계 (A Design of Inter-Working System between Secure Coding Tools and Web Shell Detection Tools for Secure Web Server Environments)

  • 김범용;최근창;김준호;석상기
    • 디지털산업정보학회논문지
    • /
    • 제11권4호
    • /
    • pp.81-87
    • /
    • 2015
  • Recently, with the development of the ICT environment, the use of the software is growing rapidly. And the number of the web server software used with a variety of users is also growing. However, There are also various damage cases increased due to a software security vulnerability as software usage is increasing. Especially web shell hacking which abuses software vulnerabilities accounts for a very high percentage. These web server environment damage can induce primary damage such like homepage modification for malware spreading and secondary damage such like privacy. Source code weaknesses checking system is needed during software development stage and operation stage in real-time to prevent software vulnerabilities. Also the system which can detect and determine web shell from checked code in real time is needed. Therefore, in this paper, we propose the system improving security for web server by detecting web shell attacks which are invisible to existing detection method such as Firewall, IDS/IPS, Web Firewall, Anti-Virus, etc. while satisfying existing secure coding guidelines from development stage to operation stage.

철근콘크리트 원통 SHELL TANK 에 관한 최적설계 (The Optimum Design of Reinforced Concrete Cylindrical Shell Tanks)

  • 최열;강문명
    • 한국전산구조공학회:학술대회논문집
    • /
    • 한국전산구조공학회 1992년도 가을 학술발표회 논문집
    • /
    • pp.61-66
    • /
    • 1992
  • The present paper deals with the optimum design of reinforced concrete cylindrical shell tanks in according to ACI 318-89 code. The purpose of this investigation is to find the optimum values of the steel ratio and the effective thickness of reinforced concrete cylindrical shell tanks. The analysts is carried out using a simple computer programming, SMAP(segmented matrix analysis package). The optimization is carried out using GINO programming. Optimum results for cylindrical shell tanks with uniform, stepwise and piecewise linealy varying thicknesses are presented.

  • PDF

박판성형공정해석에서의 계층적 접촉탐색 알고리즘 적용 (A Hierarchical Contact Searching Algorithm in Sheet Forming Analysis)

  • 김용환
    • 한국소성가공학회:학술대회논문집
    • /
    • 한국소성가공학회 1999년도 춘계학술대회논문집
    • /
    • pp.22-25
    • /
    • 1999
  • A dynamic explicit finite element code for simulating sheet forming processes has been developed The code utilises the discrete Kirchhoff shell element and contact force is treated by a conventional penalty method. In order to reduce the computational cost a new and robust contact searching algorithm has been developed and implemented into the code. in the method a hierarchical structure of tool segments called a tree structure is built for each tool at the initial stage of the analysis Tree is built in a way to divide a trunk to 8 sub-trunk 2 in each direction until the lowest level of the tree(leaf) contains exactly one segment of the tool. In order to have a well-balanced tree each box on each sub level contains one eighth of the segments. Then at each time step contact line from a node comes out of the surface of the tool. Simulation of various sheet forming processes were performed to verify the validity of the developed code with main focus on he usefulness of the developed contact searching algorithm.

  • PDF

Plate and Shell 열교환기의 압력강하 특성에 관한 연구 (A study on the pressure drop characteristics of plate and shell heat exchangers)

  • 서무교;김영수
    • 대한기계학회:학술대회논문집
    • /
    • 대한기계학회 2000년도 춘계학술대회논문집B
    • /
    • pp.25-30
    • /
    • 2000
  • Plate and shell heat exchanger(P&SHE) has been applied to the refrigeration and air conditioning systems as evaporators or condensers fur their high efficiency and compactness. The purpose of this study is to analyze the characteristics of pressure drop in plate and shell heat exchanger. An experiment for single phase (low pressure drop in plate and shell heat exchanger was performed. Also numerical work was conducted using the FLUENT code for $ {\kappa}-{\varepsilon}$ model. The dependence of friction factor on geometrical Parameters was numerically investigated. The study examines the internal flow and the pressure distribution in the channel of plate and shell heat exchanger. The results of CFD analysis compared with experimental data, and the difference of frictor factor in plate side and shell side are 10% and 12%, respectively. Therefore, the CFD analysis model is effectively predict the performance of plate and shell heat exchanger.

  • PDF

Performance of a Shell-and-Tube Heat Exchanger with Spiral Baffle Plates

  • 손영석;신지영
    • Journal of Mechanical Science and Technology
    • /
    • 제15권11호
    • /
    • pp.1555-1562
    • /
    • 2001
  • In a conventional shell-and-tube heat exchanger, fluid contacts with tubes flowing up and down in a shell, therefore there is a defect in the heat transfer with tubes due to the stagnation portions . Fins are attached to the tubes in order to increase heat transfer efficiency, but there exists a limit. Therefore, it is necessary to improve heat exchanger performance by changing the fluid flow in the shell. In this study, a highly efficient shell-and-tube heat exchanger with spiral baffle plates is simulated three-dimensionally using a commercial thermal-fluid analysis code, CFX4.2. In this type of heat exchanger, fluid contacts with tubes flowing rotationally in the shell. It could improve heat exchanger performance considerably because stagnation portions in the shell could be removed. It is proved that the shell-and-tube heat exchanger with spiral baffle plates is superior to the conventional heat exchanger in terms of heat transfer.

  • PDF

스펙트럴유한요소법과 경계요소법을 이용한 셸의 공기 중 진동 및 방사소음 해석 (Analysis of Vibration and Radiated Noise of Circular Cylindrical Shell in the Air Using Spectral Finite Element Method and Boundary Element Method)

  • 이영구;홍석윤;송지훈
    • 한국소음진동공학회논문집
    • /
    • 제19권11호
    • /
    • pp.1192-1201
    • /
    • 2009
  • Analysis of the vibration characteristic for cylindrical shell is more complex than plates since the coupling effects are considered on three dimensions. Based on Love's equation, spectral finite element method(SFEM) is introduced to predict frequency response function of finite circular cylindrical shell in the air with simply supported - free boundary condition without simplifying the equation of motion. And for the radiated noise analysis of cylindrical shell, indirect boundary element method(BEM) is applied using out-of-plane displacements as an input from structural vibration analysis. Comparisons of the structural vibration results by the spectral finite element method and commercial code, NASTRAN(FEM based) are carried out. Likewise, for verification of radiated noise analysis results, commercial code, SYSNOISE(BEM based) are used.

산업정보시스템의 웹쉘공격에 대한 방어 대응책 연구 (Study on defense countermeasures against Webshell attacks of the Industrial Information System)

  • 홍성혁
    • 산업융합연구
    • /
    • 제16권4호
    • /
    • pp.47-52
    • /
    • 2018
  • 웹쉘은 해커가 원격으로 웹 서버에 명령을 내릴 수 있도록 작성한 웹 스크립트 파일이다. 해커는 웹쉘을 이용하여 보안 시스템을 우회, 시스템에 접근하여 파일 수정, 복사, 삭제 등의 시스템 제어를 할 수 있고 웹 소스코드에 악성코드를 설치해 사용자들의 PC를 공격하거나 연결된 데이터베이스의 정보를 유출하는 등 큰 피해를 입힐 수 있다. 웹쉘 공격의 유형은 여러 가지가 있지만 그중 대표적으로 사용되는 PHP, JSP 기반 웹 서버에 대한 공격에 대해 연구하고 이런 유형의 웹쉘 공격에 대한 대응 방법인 웹페이지 관리차원에서의 방법과 개발과정에서의 방법, 그 외 몇 가지 방법을 제안하였다. 이런 대응 방법들을 활용한다면 웹쉘 공격에 의한 피해를 효과적으로 차단할 수 있다.

A Data Hiding Scheme Based on Turtle-shell for AMBTC Compressed Images

  • Lee, Chin-Feng;Chang, Chin-Chen;Li, Guan-Long
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제14권6호
    • /
    • pp.2554-2575
    • /
    • 2020
  • Data hiding technology hides secret information into the carrier, so that when the carrier is transmitted over network, it will not attract any malicious attention. Using data compression, it is possible to reduce the data size into a small compressed code, which can effectively reduce the time when transmitting compressed code on the network. In this paper, the main objective is to effectively combine these two technologies. We designed a data hiding scheme based on two techniques which are turtle-shell information hiding scheme and absolute moment block truncation coding. The experimental results showed that the proposed scheme provided higher embedding capacity and better image quality than other hiding schemes which were based on absolute moment block truncation coding.

Damage prediction of RC containment shell under impact and blast loading

  • Pandey, A.K.
    • Structural Engineering and Mechanics
    • /
    • 제36권6호
    • /
    • pp.729-744
    • /
    • 2010
  • There is world wide concern for safety of nuclear power installations after the terrorist attack on World Trade Center in 2001 and several other civilian structures in the last decade. The nuclear containment structure in many countries is a double shell structure (outer shell a RCC and inner a prestressed concrete). The outer reinforced concrete shell protects the inner shell and is designed for external loading like impact and blast. A comparative study of non-linear response of reinforced concrete nuclear containment cylindrical shell subjected to impact of an aircraft (Phantom) and explosion of different amounts of blast charges have been presented here. A material model which takes into account the strain rate sensitivity in dynamic loading situations, plastic and visco-plastic behavior in three dimensional stress state and cracking in tension has been developed earlier and implemented into a finite element code which has been validated with published literature. The analysis has been made using the developed software. Significant conclusions have been drawn for dissimilarity in response (deflections, stresses, cracks etc.) of the shell for impact and blast loading.