• 제목/요약/키워드: control flow integrity

Search Result 62, Processing Time 0.03 seconds

A lightweight detection mechanism of control flow modification for IoT devices (IoT 기기를 위한 경량의 소프트웨어 제어 변조 탐지 기법)

  • Pak, Dohyun;Lee, JongHyup
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.25 no.6
    • /
    • pp.1449-1453
    • /
    • 2015
  • Constrained IoT devices cannot achieve full coverage of software attestation even though the integrity of software is critical. The limited modification attacks on control flow of software aim at the shadow area uncovered in software attestation processes. In this paper, we propose a light-weight protection system that detects modification by injecting markers to program code.

Limitations of Windows CFG compared with LLVM CFI (LLVM CFI 와 비교한 Windows CFG 의 한계점)

  • Park, Sang-min;Choi, Hyung-kee
    • Annual Conference of KIPS
    • /
    • 2022.11a
    • /
    • pp.225-227
    • /
    • 2022
  • CFI(Control Flow Integrity)는 제어 흐름을 검증해 프로그램을 보호하는 기법이다. Windows에서는 CFG(Control Flow Guard)란 이름으로 CFI 를 지원하고 LLVM 에서는 동일하게 CFI 란 이름으로 지원한다. 본 논문에서는 Windows CFG 의 몇 가지 한계점을 LLVM IFCC 와 비교해서 찾아보고 대안책을 제안한다. CFG 에 성능, 확장성, 보안 측면에서 LLVM IFCC 와 비교하여 한계점이 존재한다는 것을 확인하였다. 본 논문에서는 각 항에 대한 이론적 근거를 제시하고 문제를 해결할 수 있는 몇 가지 대응책을 소개한다.

Piping Failure Analysis In Domestic Nuclear Safety Piping System (국내 안전등급 배관에 대한 손상사례 분석)

  • Choi, Sun-Yeong;Choi, Young-Hwan
    • Proceedings of the KSME Conference
    • /
    • 2003.04a
    • /
    • pp.617-621
    • /
    • 2003
  • The purpose of this paper is to analyze piping failure trend of safety pipings In domestic nuclear power plants. First, database for the piping failure was constructed with 105 data fields. The database includes plant population data, event data, and service history data. 7 kinds of piping failures in domestic NPPs were investigated. Among the 7 cases, detailed root causes were investigated for 3 cases. The first one is pipe wall thinning in main feedwater pipings of Westinghouse 3 loop type plants. The root cause of the wall thinning was flow accelerated corrosion near welding area. The next one is leak event in chemical and volume control system(CVCS) due to vibration. Some cracks occurred in socket welding area. The events showed that the integrity or socket weld is very vulnerable to vibration. The last one is also a leak event in primary sampling line in Korean standard reactor due to thermal fatigue. Although the structural integrity was not maintained by the events, there was no effect on nuclear safety in the above 3 piping failure eases.

  • PDF

Effect of Nicotinic Acid on Fresh Semen Characteristics in Miniature Pigs

  • Lee, Yeon-Ju;Lee, Sang-Hee;Lee, Eunsong;Lee, Seung Tae;Cheong, Hee-Tae;Yang, Boo-Keun;Lee, Seunghyung;Park, Choon-Keun
    • Journal of Embryo Transfer
    • /
    • v.29 no.4
    • /
    • pp.385-391
    • /
    • 2014
  • Objective of this study was to investigate the effect of nicotinic acid (NA) on the characteristics in fresh semen of miniature pig. We evaluated viability, acrosome reaction and mitochondrial integrity of sperm on 0, 3, 7 and 10 days during storage period with nicotinic acid. As results, the survival rate of sperm in 15 mM NA (day 3, $87.8{\pm}1.2%$; day 5, $84.0{\pm}2.7%$; day 7, $82.2{\pm}0.9%$) and 30 mM NA (day 3, $87.7{\pm}0.3%$; day 5, $84.4{\pm}2.5%$; day 7, $82.3{\pm}0.7%$) groups were higher than control and 5 mM NA groups in 3, 7 and 10 days of semen storage. The NA-treated sperm on 10 day was used day for observing acrosome integrity. The survival sperm with acrosome reaction was higher in 30 mM NA group (day 3, $2.7{\pm}0.2%$; day 5, $3.3{\pm}0.6%$; day 7, $11.4{\pm}0.3%$) than in the control, significantly (P<0.05). Moreover, the live sperm with mitochondrial integrity was higher in whole treatment groups of NA than control group, significantly (P<0.05). Specially, most mitochondrial integrity on 10 day of semen storage was significantly higher in 30 mM NA group ($90.2{\pm}1.6%$) than other treatment groups (control, $81.8{\pm}3.1%$; 5 mM NA, $83.4{\pm}3.0%$; 15 mM NA, $89.1{\pm}0.7%$, P<0.05). In conclusion, supplement of NA in liquid semen of miniature pig can improve and maintain semen quality, such as viability, acrosome reaction, and mitochondria integrity.

TCST : A Technology for Verifying Control Flow Integrity for Smart Contracts within a Trusted Execution Environment (TCST : 신뢰실행환경 내에서 스마트 컨트랙트의 제어 흐름 무결성 검증을 위한 기술)

  • Park, Seonghwan;Kwon, Donghyun
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.32 no.6
    • /
    • pp.1103-1112
    • /
    • 2022
  • Blockchain technology is widespread in everyday life and various industry fields. It guarantees integrity and transparency between blockchain network participants through a distributed ledger. The smart contract is modifying and managing the distributed ledger, which is the most important component of guaranteeing integrity and transparency of blockchain network. Still, smart contracts are also a component of blockchain networks, it is disclosed to network participants transparently. For this reason, the vulnerability of smart contracts could be revealed easily. To mitigate this, various studies are leveraging TEE to guarantee the confidentiality of smart contracts. In existing studies, TEE provides confidentiality of smart contracts but guaranteeing the integrity of smart contracts is out of their scope. In this study, we provide not only the confidentiality of smart contracts but also their integrity, by guaranteeing the CFI of smart contracts within TEE.

A Study on Secure Role-Based Access Control (안전한 직무 기반 접근 제어에 대한 연구)

  • Lee, Ho
    • Journal of the Korea Society of Computer and Information
    • /
    • v.6 no.4
    • /
    • pp.119-124
    • /
    • 2001
  • In the paper, is proposed a secure role-based access control model that not only has s functions such as security, integrity and flow control, but also can easily meet access requirements of role-based social organizations. The proposed role-based access control mod designed based on proven existing rule-based access control mechanisms in order to be app real access control systems. The model proposed in the paper is simple and secure. It can be used for the web-based application systems working on the Internet.

  • PDF

Design of a Role-Based Access Control Model for Web-based Applications (웹 기반 응용을 위한 직무 기반 접근 제어 모델의 설계)

  • Lee, Ho
    • Convergence Security Journal
    • /
    • v.2 no.2
    • /
    • pp.59-66
    • /
    • 2002
  • The access controls are the methods which are generally used in such systems as computer operating systems, workflow systems, information security systems and etc.. In the paper, is proposed a role-based access control model which not only has fundamental security functions such as security, integrity and flow control, but also meets the access control requirements of role-based social organizations. The proposed role-based access control model is designed in order to perform its functions in simple and secure way, largely in the environment of web-based applications.

  • PDF

Safety Evaluation of a Cylinder Valve for Compressed Natural Gas Vehicle Pressure Vessels using Fluid-structure Interaction Analysis (연성해석을 이용한 CNG 차량 압력 용기용 밸브의 안전성 평가)

  • Lee, Hyo Ryeol;Ahn, Jung Hwan;Kim, Bok Man;Kim, Hwa Young
    • Journal of the Korean Society of Manufacturing Technology Engineers
    • /
    • v.23 no.2
    • /
    • pp.103-108
    • /
    • 2014
  • Growing concerns about environmental pollution have led to an increase in the demand for compressed natural gas (CNG) vehicles in recent years. CNG vehicles are equipped with a cylinder valve installed in a high-pressure vessel to control the CNG flow. The cylinder valve must meet high quality safety standards because the pressure vessel stores high-pressure CNG. Therefore, safety evaluation of the cylinder valve is necessary to ensure the safety of CNG vehicles. In this study, fluid-structure interaction analysis for the structural integrity of the cylinder valve were conducted using a commercial finite element analysis code(ANSYS WORKBENCH V14). The CFD analysis was performed using a steady-state technique according to the inlet and outlet pressures in order to predict the pressure distribution. Structural analysis was performed by a static structure technique at the maximum working pressure to evaluate the structural integrity of the cylinder valve. From the results, the safety factor of the valve component is between 1.57 and 21.5.

Quality Grading of Concrete Soil Erosion Control Dam in the Aspect of Unconfined Concrete Strength by Surface-Wave Technique (표면파 기법에 의한 콘크리트 사방댐의 콘크리트 강도 등급 평가)

  • Lee, Chang-Woo;Joh, Sung-Ho;Park, Ki-Hyung;Kim, Min-Sik;Yoon, Ho-Joong;Raja Ahmad, Raja Hassanul
    • Journal of Korean Society of Forest Science
    • /
    • v.101 no.3
    • /
    • pp.412-425
    • /
    • 2012
  • Concrete Soil Erosion Control Dam, which blocks flow of debris flow in torrential stream, are reported to lose expected functions due to structural failure and collapses, caused by poor construction, material deterioration and external impacts. In this paper, an integrity assessment technique for debris barriers was proposed, which allows preliminary detection of problems inherent in debris barriers. The proposed integrity assessment technique is a non-destructive method based on SASW method, one of surface-wave tests. In this paper, a practical procedure and analysis guidelines in applying the SASW technique to debris barrier was proposed and its validity was verified using five decrepit debris barriers older than 20-year old. As a result, the SASW method was validated for the reliable grade evaluation method for concrete soil erosion control dam, and the resulting grades turned out to agree with the results determined by Sabang Associations.

Analysis of steam generator tube rupture accidents for the development of mitigation strategies

  • Bang, Jungjin;Choi, Gi Hyeon;Jerng, Dong-Wook;Bae, Sung-Won;Jang, Sunghyon;Ha, Sang Jun
    • Nuclear Engineering and Technology
    • /
    • v.54 no.1
    • /
    • pp.152-161
    • /
    • 2022
  • We analyzed mitigation strategies for steam generator tube rupture (SGTR) accidents using MARS code under both full-power and low-power and shutdown (LPSD) conditions. In general, there are two approaches to mitigating SGTR accidents: supplementing the reactor coolant inventory using safety injection systems and depressurizing the reactor coolant system (RCS) by cooling it down using the intact steam generator. These mitigation strategies were compared from the viewpoint of break flow from the ruptured steam generator tube, the core integrity, and the possibility of the main steam safety valves opening, which is associated with the potential release of radiation. The "cooldown strategy" is recommended for break flow control, whereas the "RCS make-up strategy" is better for RCS inventory control. Under full power, neither mitigation strategy made a significant difference except for on the break flow while, in LPSD modes, the RCS cooldown strategy resulted in lower break and discharge flows, and thus less radiation release. As a result, using the cooldown strategy for an SGTR under LPSD conditions is recommended. These results can be used as a fundamental guide for mitigation strategies for SGTR accidents according to the operational mode.