• 제목/요약/키워드: Software countermeasures

검색결과 64건 처리시간 0.021초

Higher-Order Countermeasures against Side-Channel Cryptanalysis on Rabbit Stream Cipher

  • Marpaung, Jonathan A.P.;Ndibanje, Bruce;Lee, Hoon Jae
    • Journal of information and communication convergence engineering
    • /
    • 제12권4호
    • /
    • pp.237-245
    • /
    • 2014
  • In this study, software-based countermeasures against a side-channel cryptanalysis of the Rabbit stream cipher were developed using Moteiv's Tmote Sky, a popular wireless sensor mote based on the Berkeley TelosB, as the target platform. The countermeasures build upon previous work by improving mask generation, masking and hiding other components of the algorithm, and introducing a key refreshment scheme. Our contribution brings improvements to previous countermeasures making the implementation resistant to higher-order attacks. Four functional metrics, namely resiliency, robustness, resistance, and scalability, were used for the assessment. Finally, performance costs were measured using memory usage and execution time. In this work, it was demonstrated that although attacks can be feasibly carried out on unprotected systems, the proposed countermeasures can also be feasibly developed and deployed on resource-constrained devices, such as wireless sensors.

강원도 SW산업의 글로벌화전략에 관한 연구 (A Study on the Globalization Strategy of SW Industry in Gangwon Province)

  • 엄광열;홍종민
    • 통상정보연구
    • /
    • 제10권3호
    • /
    • pp.437-458
    • /
    • 2008
  • In these days the global software market is experiencing diastrophism due to globalization, convergence, and the spread of web 2.0. In particular, today"s global economy has entered the so-called "Globalization 3.0" era, and the world is evolving into a flat world where labor, capital, and resources are moving freely. In this rapidly changing global economy, the growth of the Korean economy is in a state of continuous decline. Particularly software industry is also suffering continuously slow growth due to market saturation and low service earning, which require urgent countermeasures. Therefore, the purpose of this study is: 1) to analyze the current industrial condition of the software industry, which have special characteristics differ from manufacturing industry; and 2) to analyze the major obstacles of local companies working in the software industry in order to cope with the recent changes in the global market environment and 3) to draw out the strategy for the domestic software industry in gangwon province in order to promote local software industry and to achieve globalization.

  • PDF

A study on Countermeasures by Detecting Trojan-type Downloader/Dropper Malicious Code

  • Kim, Hee Wan
    • International Journal of Advanced Culture Technology
    • /
    • 제9권4호
    • /
    • pp.288-294
    • /
    • 2021
  • There are various ways to be infected with malicious code due to the increase in Internet use, such as the web, affiliate programs, P2P, illegal software, DNS alteration of routers, word processor vulnerabilities, spam mail, and storage media. In addition, malicious codes are produced more easily than before through automatic generation programs due to evasion technology according to the advancement of production technology. In the past, the propagation speed of malicious code was slow, the infection route was limited, and the propagation technology had a simple structure, so there was enough time to study countermeasures. However, current malicious codes have become very intelligent by absorbing technologies such as concealment technology and self-transformation, causing problems such as distributed denial of service attacks (DDoS), spam sending and personal information theft. The existing malware detection technique, which is a signature detection technique, cannot respond when it encounters a malicious code whose attack pattern has been changed or a new type of malicious code. In addition, it is difficult to perform static analysis on malicious code to which code obfuscation, encryption, and packing techniques are applied to make malicious code analysis difficult. Therefore, in this paper, a method to detect malicious code through dynamic analysis and static analysis using Trojan-type Downloader/Dropper malicious code was showed, and suggested to malicious code detection and countermeasures.

Secure Hardware Implementation of ARIA Based on Adaptive Random Masking Technique

  • Kang, Jun-Ki;Choi, Doo-Ho;Choi, Yong-Je;Han, Dong-Guk
    • ETRI Journal
    • /
    • 제34권1호
    • /
    • pp.76-86
    • /
    • 2012
  • The block cipher ARIA has been threatened by side-channel analysis, and much research on countermeasures of this attack has also been produced. However, studies on countermeasures of ARIA are focused on software implementation, and there are no reports about hardware designs and their performance evaluation. Therefore, this article presents an advanced masking algorithm which is strong against second-order differential power analysis (SODPA) and implements a secure ARIA hardware. As there is no comparable report, the proposed masking algorithm used in our hardware module is evaluated using a comparison result of software implementations. Furthermore, we implement the proposed algorithm in three types of hardware architectures and compare them. The smallest module is 10,740 gates in size and consumes an average of 47.47 ${\mu}W$ in power consumption. Finally, we make ASIC chips with the proposed design, and then perform security verification. As a result, the proposed module is small, energy efficient, and secure against SODPA.

정보보안대책과 정보시스템 오남용과의 인과적 관계 (The Causal Relationship between Information Security Countermeasures and Information System Misuse)

  • 이준택;김상훈
    • 한국IT서비스학회지
    • /
    • 제14권4호
    • /
    • pp.81-104
    • /
    • 2015
  • Intentional information systems (IS) misuse is a serious problem in many organizations. This study aims at developing the theoretical framework of deterring IS misuse on the basis of Nagin's General Deterrence Theory (GDT) which is very famous in the area of socio-criminology. Applying GDT to the IS misuse situation could be reasoned that the perceived certainty and the perceived severity of sanctions associated with committing IS misuse have positive impact on deterring the deviant behaviors. Also, these two constructs (certainty of sanctions and severity of sanctions) could be inferred to be influenced by the four types of IS security countermeasures (security policies, security awareness program, monitoring practices and preventive security software) derived through critically reviewing IS security-relevant literature. The proposed research model and ten hypotheses were empirically analysed using structural equation modelling with the data collected by conducting a questionnaire survey of staff members in business organizations in Korea. As a result, it was found that five ones of ten hypotheses were supported. It is thought that this study makes theoretical contribution to expanding research area of IS security and also has strong implications for IS security management practices within organizations.

사이버테러의 현황과 대책에 관한 연구 (Countermeasures against Cyber terror in Korea)

  • 안창훈
    • 시큐리티연구
    • /
    • 제5호
    • /
    • pp.211-241
    • /
    • 2002
  • Koreans are the most avid Internet surfers in the world according to Nielson/NetRatings(Reuters, August 2001) and most Internet connections are made through high-speed connections like Digital Subscriber Lines (DSLs). The result of such internet fervor is a nation that is fertile in both hackers and software companies(over 200 in the field of network security alone). However, by-product of Internet activity is cyber crime and the need to protect innocent users from the dangers of cyber criminals and cyber-terrorists be they are individuals or organized groups. Hence the Cyber Terror Response Team (CTRT) was organized in late 2000 with the mandate to fulfill that role. In these contexts, this study analyzes the actual conditions of cyber terror and suggests the countermeasures against cyber terror in Korea.

  • PDF

경영진의 정보보안 지능이 조직원의 보안대책 인식에 미치는 영향 (The Effect of Managerial Information Security Intelligence on the Employee's Information Security Countermeasure Awareness)

  • 한진영;유현선
    • 경영정보학연구
    • /
    • 제18권3호
    • /
    • pp.137-153
    • /
    • 2016
  • 조직의 비즈니스 환경이 스마트워크와 같이 모바일이나 네트워크에 의존하는 비중이 높아지면서, 기업들은 정보보안에 더 높은 관심을 가지게 되었다. 특히, 내부자의 의한 정보유출은 기업입장에서 상당히 부정적인 영향을 미치게 된다. 따라서 기업뿐 아니라 정보보안 관련 연구자들은 조직원의 정보보안 정책 준수에 초점을 두어 연구를 해왔다. 그 중에서 정보보안 대책(Information security countermeasure)은 조직원의 정보보안 정책 준수 의도의 선행요인으로 알려져 왔다. 하지만 조직원이 정보보안 대책을 인식하도록 하는 선행요인에 대한 연구는 미흡한 실정이다. 본 연구는 조직원의 보안대책 인식에 대한 선행요인으로 경영진의 정보보안 지능을 제안하고 이들의 관계를 실증적으로 연구하였다. 정보보안 지능은 Kirwan(2008)이 제안한 안전지능을 응용하여 정보보안 관련 문제해결능력, 사회적 역량, 정보보안 지식으로 구성된다. 연구결과 경영진의 정보보안 관련 문제해결 능력과 정보보안 지식은 조직원이 정보보안 정책 및 교육/훈련 프로그램을 인식하는데 긍정적인 영향을 미치는 것으로 나타났다.

오픈 소스 취약점 분석과 대응 방안 (Open Source Vulnerabilities Analysis and Countermeasures)

  • 유승민
    • 한국정보처리학회:학술대회논문집
    • /
    • 한국정보처리학회 2019년도 춘계학술발표대회
    • /
    • pp.149-151
    • /
    • 2019
  • 오픈소스 활용이 증가함에 따라 같이 증가하는 보안 위험성에 대한 문제점을 제시하고자 한다. 오픈소스 활용의 생산성 향상과 비용 절감 대비 보안 취약점이 따르는 문제를 분석 하고자 한다. 본 논문에서는 널리 알려진 오픈소스의 취약점과 이를 해결할 방법에 대해서 소개하고자 한다. 오픈소스의 취약점 공격 방법과 해결 방안을 제시하고 이를 해결할 분석 도구를 소개하는 것을 목표로 한다.

하둡과 순차패턴 마이닝 기술을 통한 교통카드 빅데이터 분석 (Analysis of Traffic Card Big Data by Hadoop and Sequential Mining Technique)

  • 김우생;김용훈;박희성;박진규
    • Journal of Information Technology Applications and Management
    • /
    • 제24권4호
    • /
    • pp.187-196
    • /
    • 2017
  • It is urgent to prepare countermeasures for traffic congestion problems of Korea's metropolitan area where central functions such as economic, social, cultural, and education are excessively concentrated. Most users of public transportation in metropolitan areas including Seoul use the traffic cards. If various information is extracted from traffic big data produced by the traffic cards, they can provide basic data for transport policies, land usages, or facility plans. Therefore, in this study, we extract valuable information such as the subway passengers' frequent travel patterns from the big traffic data provided by the Seoul Metropolitan Government Big Data Campus. For this, we use a Hadoop (High-Availability Distributed Object-Oriented Platform) to preprocess the big data and store it into a Mongo database in order to analyze it by a sequential pattern data mining technique. Since we analysis the actual big data, that is, the traffic cards' data provided by the Seoul Metropolitan Government Big Data Campus, the analyzed results can be used as an important referenced data when the Seoul government makes a plan about the metropolitan traffic policies.

공개소프트웨어 기반 다자간 음성 및 영상통화용 미디어처리보드 개발 (Development of Media Processing Board for Multi-Party Voice and Video Telephony using Open Source Software)

  • 송형민;권재식;김진환;김동길
    • 한국산업정보학회논문지
    • /
    • 제24권5호
    • /
    • pp.105-113
    • /
    • 2019
  • 우리나라 군에서 부대간 정보교환을 위해 전술정보통신체계(Tactical information communication network; TICN)를 사용하고 있다. 본 연구에서는 공개소프트웨어(Open source software; OSS)를 기반으로 TICN 체계에 적용 가능한 다자간 음성 및 영상통화용 미디어처리보드를 개발하였다. 한편 무기체계 및 무기체계에 장착되는 부품에 공개소프트웨어를 적용하기 위해서는 방위사업청의 무기체계 소프트웨어 개발 및 관리 매뉴얼에 따른 적절한 검토를 필요로 한다. 본 연구에서는 미디어처리보드에 적용된 공개소프트웨어를 대상으로 방위사업청 메뉴얼의 부록인 '공개소프트웨어 무기체계 적용 가이드라인'에서 요구하는 검토 사항에 대한 분석을 수행하고, 적절한 대응 방안을 제시하였다.