• 제목/요약/키워드: System Vulnerability

검색결과 992건 처리시간 0.023초

네트워크 취약점 검색공격 탐지 시스템을 위한 안전한 통신 프레임워크 설계 (A Secure Communication Framework for the Detection System of Network Vulnerability Scan Attacks)

  • 유일선;김종은;조경산
    • 정보처리학회논문지C
    • /
    • 제10C권1호
    • /
    • pp.1-10
    • /
    • 2003
  • 본 논문에서는 취약점 검색공격 탐지시스템 DS-NVSA(Detection System of Network Vulnerability Scan Attacks)에서 서버와 에이전트들 사이의 상호연동을 위한 안전한 통신 프레임워크를 제안한다. 기존 시스템과의 상호연동을 위하여 제안 프레임워크는 IETF의 IDWG에서 제안한 IDMEF와 IAP를 확장 적용하였다. 또한 공개키 기반의 환경을 지원하지 못하는 네트워크 시스템을 위해 대칭키 기반의 암호화 통신 프로토콜 SKTLS(Symmetric Key based Transport Layer Security Protocol)를 제시하였다. 제안된 프레임워크는 DS-NVSA 이외에도 기존의 이기종 침입탐지 시스템의 제사용과 탐지 영역의 확대를 제공하며, 또한 기업내 통합 보안환경시스템 ESM(Enterprise Security Management) 시스템에도 적용될 수 있다.

Fuzzy set을 이용한 실시간 지점단위 농경지 침수위험 지수 산정 (Estimating Real-time Inundation Vulnerability Index at Point-unit Farmland Scale using Fuzzy set)

  • 은상규;김태곤;이지민;장민원;서교
    • 농촌계획
    • /
    • 제20권2호
    • /
    • pp.1-10
    • /
    • 2014
  • Smartphones change the picture of data and information sharing and make it possible to share various real-time flooding data and information. The vulnerability indicators of farmland inundation is needed to calculate the risk of farmland flood based on changeable hydro-meteorological data over time with morphologic characteristics of flood-damaged areas. To find related variables show the vulnerability of farmland inundation using the binary-logit model and correlation analysis and to provide vulnerability indicators were estimated by fuzzy set method. The outputs of vulnerability indicators were compared with the results of Monte Carlo simulation (MCS) for verification. From the result vulnerability indicators are applicable to mobile_based information system of farmland inundation.

Empirical Risk Assessment in Major Graphical Design Software Systems

  • Joh, HyunChul;Lee, JooYoung
    • Journal of Multimedia Information System
    • /
    • 제8권4호
    • /
    • pp.259-266
    • /
    • 2021
  • Security vulnerabilities have been reported in major design software systems such as Adobe Photoshop and Illustrator, which are recognized as de facto standard design tools in most of the design industries. Companies need to evaluate and manage their risk levels posed by those vulnerabilities, so that they could mitigate the potential security bridges in advance. In general, security vulnerabilities are discovered throughout their life cycles repeatedly if software systems are continually used. Hence, in this study, we empirically analyze risk levels for the three major graphical design software systems, namely Photoshop, Illustrator and GIMP with respect to a software vulnerability discovery model. The analysis reveals that the Alhazmi-Malaiya Logistic model tends to describe the vulnerability discovery patterns significantly. This indicates that the vulnerability discovery model makes it possible to predict vulnerability discovery in advance for the software systems. Also, we found that none of the examined vulnerabilities requires even a single authentication step for successful attacks, which suggests that adding an authentication process in software systems dramatically reduce the probability of exploitations. The analysis also discloses that, for all the three software systems, the predictions with evenly distributed and daily based datasets perform better than the estimations with the datasets of vulnerability reporting dates only. The observed outcome from the analysis allows software development managers to prepare proactively for a hostile environment by deploying necessary resources before the expected time of vulnerability discovery. In addition, it can periodically remind designers who use the software systems to be aware of security risk, related to their digital work environments.

A study on Dirty Pipe Linux vulnerability

  • Tanwar, Saurav;Kim, Hee Wan
    • International Journal of Internet, Broadcasting and Communication
    • /
    • 제14권3호
    • /
    • pp.17-21
    • /
    • 2022
  • In this study, we wanted to examine the new vulnerability 'Dirty Pipe' that is founded in Linux kernel. how it's exploited and what is the limitation, where it's existed, and overcome techniques and analysis of the Linux kernel package. The study of the method used the hmark[1] program to check the vulnerabilities. Hmark is a whitebox testing tool that helps to analyze the vulnerability based on static whitebox testing and automated verification. For this purpose of our study, we analyzed Linux kernel code that is downloaded from an open-source website. Then by analyzing the hmark tool results, we identified in which file of the kernel it exists, cvss level, statistically depicted vulnerabilities on graph which is easy to understand. Furthermore, we will talk about some software we can use to analyze a vulnerability and how hmark software works. In the case of the Dirty Pipe vulnerability in Linux allows non-privileged users to execute malicious code capable of a host of destructive actions including installing backdoors into the system, injecting code into scripts, altering binaries used by elevated programs, and creating unauthorized user profiles. This bug is being tracked as CVE-2022-0847 and has been termed "Dirty Pipe"[2] since it bears a close resemblance to Dirty Cow[3], and easily exploitable Linux vulnerability from 2016 which granted a bad actor an identical level of privileges and powers.

Groundwater pollution risk mapping using modified DRASTIC model in parts of Hail region of Saudi Arabia

  • Ahmed, Izrar;Nazzal, Yousef;Zaidi, Faisal
    • Environmental Engineering Research
    • /
    • 제23권1호
    • /
    • pp.84-91
    • /
    • 2018
  • The present study deals with the management of groundwater resources of an important agriculture track of north-western part of Saudi Arabia. Due to strategic importance of the area efforts have been made to estimate aquifer proneness to attenuate contamination. This includes determining hydrodynamic behavior of the groundwater system. The important parameters of any vulnerability model are geological formations in the region, depth to water levels, soil, rainfall, topography, vadose zone, the drainage network and hydraulic conductivity, land use, hydrochemical data, water discharge, etc. All these parameters have greater control and helps determining response of groundwater system to a possible contaminant threat. A widely used DRASTIC model helps integrate these data layers to estimate vulnerability indices using GIS environment. DRASTIC parameters were assigned appropriate ratings depending upon existing data range and a constant weight factor. Further, land-use pattern map of study area was integrated with vulnerability map to produce pollution risk map. A comparison of DRASTIC model was done with GOD and AVI vulnerability models. Model validation was done with $NO_3$, $SO_4$ and Cl concentrations. These maps help to assess the zones of potential risk of contamination to the groundwater resources.

지하수 오염 취약성 기법의 비교 적용 연구: 충남 홍성군 금마면 일대에의 적용 (A Comparative Study of Groundwater Vulnerability Assessment Methods: Application in Gumma, Korea)

  • 기민규;윤희성;고동찬;함세영;이충모;김현수
    • 한국지하수토양환경학회지:지하수토양환경
    • /
    • 제18권3호
    • /
    • pp.119-133
    • /
    • 2013
  • In the present study, several groundwater vulnerability assessment methods were applied to an agricultural area of Gumma in Korea. For the groundwater intrinsic vulnerability assessment, the performance of DRASTIC, SINTACS and GOD models was compared and an ensemble approach was suggested. M-DRASTIC and multi-linear regression (MLR) models were applied for the groundwater specific vulnerability assessment to nitrate of the study site. The correlation coefficient between the nitrate concentration and M-DRASTIC index was as low as 0.24. The result of the MLR model showed that the correlation coefficient is 0.62 and the areal extents of livestock farming and upland field are most influential factors for the nitrate contamination of groundwater in the study site.

안전한 무기체계 소프트웨어를 위한 취약점 분석 기법에 관한 연구 (A Study on Vulnerability Analysis Techniques for Secure Weapon System Software)

  • 김종복;조인준
    • 한국콘텐츠학회논문지
    • /
    • 제18권8호
    • /
    • pp.459-468
    • /
    • 2018
  • 무기체계 관련 어플리케이션과 국방 관련 기관에서 활용하는 정보시스템이 사이버 공격을 받을 경우 국가의 안보가 위험해지는 결과를 초래한다. 이러한 위험을 줄이기 위해 개발 단계에서부터 시큐어 코딩을 적용하거나, 발견된 취약점들을 체계적으로 관리하기 위한 노력이 지속적으로 행해지고 있다. 또한 다양한 분석 도구를 이용하여 취약점을 분석, 탐지하고 개발 단계에서 취약점을 제거하거나, 개발된 어플리케이션에서 취약점을 제거하기 위해 노력하고 있다. 그러나 취약점 분석 도구들은 미탐지, 오탐지, 과탐지를 발생시켜 정확한 취약점 탐지를 어렵게 한다. 본 논문에서는 이러한 문제점 해결방안으로 분석 대상이 되는 어플리케이션의 위험도를 평가하고 이를 기반으로 안전한 어플리케이션을 개발 및 관리할 수 있는 취약점 탐지기법을 새롭게 제안하였다.

농업용 저수지 공급량과 수요량의 확률분포 및 신뢰성 해석 기법을 활용한 물 공급 취약성 평가 (Vulnerability Assessment of Water Supply in Agricultural Reservoir Utilizing Probability Distribution and Reliability Analysis Methods)

  • 남원호;김태곤;최진용;이정재
    • 한국농공학회논문집
    • /
    • 제54권2호
    • /
    • pp.37-46
    • /
    • 2012
  • The change of rainfall pattern and hydrologic factors due to climate change increases the occurrence probability of agricultural reservoir water shortage. Water supply assessment of reservoir is usually performed current reservoir level compared to historical water levels or the simulation of reservoir operation based on the water budget analysis. Since each reservoir has the native property for watershed, irrigation district and irrigation water requirement, it is necessary to improve the assessment methods of agricultural reservoir water capability about water resources system. This study proposed a practical methods that water supply vulnerability assessment for an agricultural reservoir based on a concept of probabilistic reliability. The vulnerability assessment of water supply is calculated from probability distribution of water demand condition and water supply condition that influences on water resources management and reservoir operations. The water supply vulnerability indices are estimated to evaluate the performance of water supply on agricultural reservoir system, and thus it is recommended a more objective method to evaluate water supply reliability.

사이버 위협 대응을 위한 군(軍) 정보화자산관리시스템과 연계한 군(軍) 취약점 관리 방안 (Military Vulnerability Management Plan based on Military IT Asset Management System for Cyber Threat Response)

  • 김종화;임재성
    • 융합보안논문지
    • /
    • 제18권1호
    • /
    • pp.111-116
    • /
    • 2018
  • 우리 군(軍)의 사이버 공간은 적으로부터 지속적인 위협을 받고 있다. 이 같은 사이버 위협에 대응하기 위해 군(軍) 정보화 자산에 대한 취약점을 조기에 식별하고 제거하여야 한다. 그러나 현재 우리 군(軍)은 취약점에 대한 체계적인 관리가 미흡한 실정이다. 따라서 본 논문에서는 취약점 관리에 대한 각 국의 동향과 군(軍) 취약점 관리 실태를 조사하고, 이를 바탕으로 군(軍) 정보화 자산에 대한 효율적인 취약점 관리를 위해 취약점 데이터베이스와 군(軍) 정보화자산관리시스템을 연계 구축하는 방안을 제시하였다.

  • PDF

SW 취약점의 보안성 강화를 위한 진단원의 교육 양성 연구 (Research on Education and Training of the Analyzer for Security Enhancement of SW Vulnerability)

  • 김슬기;박대우
    • 한국정보통신학회논문지
    • /
    • 제21권5호
    • /
    • pp.945-950
    • /
    • 2017
  • 소프트웨어의 취약점으로 인하여, 국가의 사이버 인프라와 실물 금융자산 에 대한 해킹 공격이 발생하고 있다. 소프트웨어는 인터넷 정보제공과 사이버 금융결제 및 사이버 인프라를 통제하고 운영하는, 운영체제 및 실행시스템을 구성하는 필수요소이기 때문이다. 이러한 소프트웨어 취약점을 분석하고, 보안성을 강화해야 사이버 인프라의 보안성이 강화되고, 실제 국가와 국민의 실제 생활에 보안성이 강화된다. 소프트웨어 개발보안 제도 분석과 소프트 웨어 개발보안 진단 분석 및 소프트웨어 취약점의 보안성 강화를 위한 연구를 한다. 또한 소프트웨어 취약점 진단원 양성 및 보수교육을 위한 교재개발과 진단원 시험문제 개발 및 진단원의 파일럿 테스트, 그리고 진단원의 투입인력 비용기준을 연구한다. 본 논문의 연구는 소프트웨어 취약점 진단원을 양성하는 교육과정과 진단가이드를 제시하여, 국가와 국민 생활의 사이버 인프라의 소프트웨어 보안성을 강화하는 데 목적이 있다.