• Title/Summary/Keyword: detection technique

Search Result 4,102, Processing Time 0.032 seconds

Anomaly Detection Using Visualization-based Network Forensics (비정상행위 탐지를 위한 시각화 기반 네트워크 포렌식)

  • Jo, Woo-yeon;Kim, Myung-jong;Park, Keun-ho;Hong, Man-pyo;Kwak, Jin;Shon, Taeshik
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.27 no.1
    • /
    • pp.25-38
    • /
    • 2017
  • Many security threats are occurring around the world due to the characteristics of industrial control systems that can cause serious damage in the event of a security incident including major national infrastructure. Therefore, the industrial control system network traffic should be analyzed so that it can identify the attack in advance or perform incident response after the accident. In this paper, we research the visualization technique as network forensics to enable reasonable suspicion of all possible attacks on DNP3 control system protocol, and define normal action based rules and derive visualization requirements. As a result, we developed a visualization tool that can detect sudden network traffic changes such as DDoS and attacks that contain anormal behavior from captured packet files on industrial control system network. The suspicious behavior in the industrial control system network can be found using visualization tool with Digital Bond packet.

High Efficiency Binding Aptamers for a Wide Range of Bacterial Sepsis Agents

  • Graziani, Ana Claudia;Stets, Maria Isabel;Lopes, Ana Luisa Kalb;Schluga, Pedro Henrique Caires;Marton, Soledad;Ferreira, Ieda Mendes;de Andrade, Antero Silva Ribeiro;Krieger, Marco Aurelio;Cardoso, Josiane
    • Journal of Microbiology and Biotechnology
    • /
    • v.27 no.4
    • /
    • pp.838-843
    • /
    • 2017
  • Sepsis is a major health problem worldwide, with an extremely high rate of morbidity and mortality, partly due to delayed diagnosis during early disease. Currently, sepsis diagnosis requires bacterial culturing of blood samples over several days, whereas PCR-based molecular diagnosis methods are faster but lack sensitivity. The use of biosensors containing nucleic acid aptamers that bind targets with high affinity and specificity could accelerate sepsis diagnosis. Previously, we used the systematic evolution of ligands by exponential enrichment technique to develop the aptamers Antibac1 and Antibac2, targeting the ubiquitous bacterial peptidoglycan. Here, we show that these aptamers bind to four gram-positive and seven gram-negative bacterial sepsis agents with high binding efficiency. Thus, these aptamers could be used in combination as biological recognition elements in the development of biosensors that are an alternative to rapid bacteria detection, since they could provide culture and amplification-free tests for rapid clinical sepsis diagnosis.

Advanced protocol against MITM attacks in Industrial Control System (산업제어시스템에서의 MITM 공격을 방어하기 위해 개선된 프로토콜)

  • Ko, Moo-seong;Oh, Sang-kyo;Lee, Kyung-ho
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.25 no.6
    • /
    • pp.1455-1463
    • /
    • 2015
  • If the industrial control system is infected by malicious worm such as Stuxnet, national disaster could be caused inevitably. Therefore, most of the industrial control system defence is focused on intrusion detection in network to protect against these threats. Conventional method is effective to monitor network traffic and detect anomalous patterns, but normal traffic pattern attacks using MITM technique are difficult to be detected. This study analyzes the PROFINET/DCP protocol and weaknesses with the data collected in real industrial control system. And add the authentication data field to secure the protocol, find out the applicability. Improved protocol may prevent the national disaster and defend against MITM attacks.

A Design of Secure Audit/ Trace Module to Support Computer Forensics (컴퓨터 포렌식스를 지원하는 보안 감사/추적 모듈 설계)

  • 고병수;박영신;최용락
    • Journal of the Korea Society of Computer and Information
    • /
    • v.9 no.1
    • /
    • pp.79-86
    • /
    • 2004
  • In general, operating system is offering the security function of OS level to support several web services. However, it is true that security side of OS level is weak from many parts. Specially, it is needed to audit/trace function in security kernel level to satisfy security more than B2 level that define in TCSEC(Trusted Computer System Evaluation Criteria). So we need to create audit data at system call invocation for this, and do to create audit data of equal format about almost event and supply information to do traceback late. This Paper Proposes audit/trace system module that use LKM(Loadable Kernel Module) technique. It is applicable without alteration about existing linux kernel to ensure safe evidence. It offers interface that can utilize external audit data such as intrusion detection system, and also offers safe role based system that is divided system administrator and security administrator These data will going to utilize to computer forensics' data that legal confrontation is Possible.

  • PDF

Simultaneous Measurement of Thickness and Refractive Index of Transparent Material Using a Collimated Beam Having a Finite Radius (유한 반경의 시준 광속을 이용한 투명 매질의 두께와 굴절률의 동시 측정)

  • Park, Dae-Seo;O, Beom-Hoan;Park, Se-Geun;Lee, El-Hang;Lee, Seung-Gol
    • Korean Journal of Optics and Photonics
    • /
    • v.20 no.1
    • /
    • pp.29-33
    • /
    • 2009
  • We propose a new measuring technique based on optical low-coherence reflectometry that enables us to determine the refractive index and the geometrical thickness of a transparent sample by one-time scanning only. By passing a collimated beam having a finite size through the edge of the sample, the refractive index and the geometrical thickness can be determined simultaneously from the comparison of interferograms generated by two kinds of reflected beams. In this study, a refractive index could be determined with the accuracy of $10^{-3}$, and its accuracy would be enhanced by using a more precise translator and a thicker sample.

Recent Advanced Toxicological Methods for Environmental Hazardous Chemicals (환경 오염물질의 진보된 독성 평가 기법)

  • 류재천;최윤정;김연정;김형태;방형애;송윤선
    • Environmental Analysis Health and Toxicology
    • /
    • v.14 no.1_2
    • /
    • pp.1-12
    • /
    • 1999
  • Recently, several new methods for the detection of genetic damages in vitro and in vivo based on molecular biological techniques were introduced according to the rapid progress in toxicology combined with cellular and molecular biology. Among these methods, mouse lymphoma thymidine kanase (tk) gene forward mutation assay, single cell gel electrophoresis (comet assay) and transgenic animal and cell line model as a target gene of lac I (Big Blue) and lac Z (Muta Mouse) gene mutation are newly introduced based on molecular toxicological approaches. The mouse lymphoma tk$\^$+/-/ gene assay (MOLY) using L5178Y tk$\^$+/-/ mouse lymphoma cell line is one of the mammalian forward mutation assays, and has many advantages and more sensitive than hprt assay. The target gene of MOLY is a heterozygous tk$\^$+/-/ gene located in 11 chromosome, so it is able to detect the wide range of genetic changes like point mutation, deletion, rearrangement, and mitotic recombination within tk gene or deletion of entire chromosome 11. The comet assay is a rapid, simple, visual and sensitive technique for measuring and analysing DNA breakages in mammalian cells, Also, transgenic animal and cell line models, which have exogenous DNA incorporated into their genome, carry recoverable shuttle vector containing reporter genes to assess endogenous effects or alteration in specific genes related to disease process, are powerful tools to study the mechanism of mutation in vivo and in vitro, respectively. Also in vivo acridine orange supravital staining micronucleus assay by using mouse peripheral reticulocytes was introduced as an alternative of bone marrow micronucleus assay. In this respect, there was an International workshop on genotoxicity procedure (IWGTP) supported by OECD and EMS (Environmental Mutagen Society) at Washington D. C. in March 25-26, 1999. The objective of IWGTP is to harmonize the testing procedures internationally, and to extend to finalization of OECD guideline, and to the agreement of new guidelines under the International Conference of Harmonization (ICH) for these methods mentioned above. Therefore, we introduce and review the principle, detailed procedure, and application of MOLY, comet assay, transgenic mutagenesis assay and supravital staining micronucleus assay.

  • PDF

Analysis of the Partial Discharge Pattern in XLPE Insulators using Distribution Statistical Models (분포통계모델에 의한 가교폴리에틸렌 절연체의 부분방전 패턴해석)

  • Kim Tag-Yong;Park Hee-Doo;Cho Kyung-Soon;Park Ha-Yong;Hong Jin-Woong
    • Journal of the Korean Institute of Electrical and Electronic Material Engineers
    • /
    • v.19 no.10
    • /
    • pp.947-952
    • /
    • 2006
  • It has been confirmed that the inner defect of insulator and the perfect diagnosis for aging are closely related to safe electric power transmission system and that the detection of accident and diagnosis technique turn out to be very important issues. But perfect diagnosis is difficult because discharge pattern is irregular. Thus, we investigated discharge pattern using the new distribution statistical models with cross-inked polyethylene(XLPE) specimens. Voltage was applied to power frequency by step method, and calibration of discharge was set to 50 pC. After the voltage was applied, it measured the discharge occurring during 10s. We investigated discharge pattern using the K-means analysis and Weibull function. We also investigated variation of centroid and shape parameter due to variation of voltage. As a result of analyzing K-means, it was confirmed that cluster including many object numbers was formed by the presence of void. And result of Weibull distribution, it was confirmed that shape parameter of discharge varied from 1.28 to 1.62 in no void specimens, and that shape parameter of discharge number varied from 1.28 to 1.62. In the void, shape parameter of discharge varied from 5.66 to 6.43, and shape parameter of discharge number varied from 5.05 to 5.08.

Characterization of Norepinephrine Release in Rat Posterior Hypothalamus Using in vivo Brain Microdialysis

  • Sung, Ki-Wug;Kim, Seong-Yun;Kim, Ok-Nyu;Lee, Sang-Bok
    • The Korean Journal of Physiology and Pharmacology
    • /
    • v.6 no.1
    • /
    • pp.9-14
    • /
    • 2002
  • In the present study, we used the microdialysis technique combined with high performance liquid chromatography (HPLC) and electrochemical detection to measure the extracellular levels of norepinephrine (NE) in the posterior hypothalamus in vivo, and to examine the effects of various drugs, affecting central noradrenergic transmission, on the extracellular concentration of NE in the posterior hypothalamus. Microdialysis probes were implanted stereotaxically into the posterior hypothalamus (coordinates: posterior 4.3 mm, lateral 0.5 mm, ventral 8 mm, relative to bregma and the brain surface, respectively) of rats, and dialysate collection began 2 hr after the implantation. The baseline level of monoamines in the dialysates were determined to be: NE $0.17{\pm}0.01,$ 3,4-dihydroxyphenylacetic acid (DOPAC) $0.94{\pm}0.07,$ homovanillic acid (HVA) $0.57{\pm}0.05$ pmol/sample (n=8). When the posterior hypothalamus was perfused with 90 mM potassium, maximum 555% increase of NE output was observed. Concomitantly, this treatment significantly decreased the output of DOPAC and HVA by 35% and 28%, respectively. Local application of imipramine $(50\;{\mu}M)$ enhanced the level of NE in the posterior hypothalamus (maximum 200%) compared to preperfusion control values. But, DOPAC and HVA outputs remained unchanged. Pargyline, an irreversible monoamine oxidase inhibitor, i.p. administered at a dose of 75 mg/kg, increased NE output (maximum 165%), while decreased DOPAC and HVA outputs (maximum 13 and 12%, respectively). These results indicate that NE in dialysate from the rat posterior hypothalamus were neuronal origin, and that manipulations which profoundly affected the levels of extracellular neurotransmitter had also effects on metabolite levels.

Proton implantation mechanism involved in the fabrication of SOI wafer by ion-cut process (Ion-cut에 의한 SOI웨이퍼 제조에서의 양성자조사기구)

  • 우형주;최한우;김준곤;지영용
    • Journal of the Korean Vacuum Society
    • /
    • v.13 no.1
    • /
    • pp.1-8
    • /
    • 2004
  • The SOI wafer fabrication technique has been developed by using ion-cut process, based on proton implantation and wafer bonding techniques. It has been shown by TRIM simulation that 65 keV proton implantation is required for the standard SOI wafer (200 nm SOI, 400 nm BOX) fabrication. In order to investigate the optimum proton dose and primary annealing condition for wafer splitting, the surface morphologic change has been observed such as blistering and flaking. As a result, effective dose is found to be in the 6∼$9\times10^{16}$ $H^{+}/\textrm{cm}^2$ range, and the annealing at $550^{\circ}C$ for 30 minutes is expected to be optimum for wafer splitting. The depth distribution of implanted hydrogen has been experimentally confirmed by ERD and SIMS measurements. The microstructure evolution in the damaged layer was also studied by X-TEM analysis.

Video Segmentation using the Automated Threshold Decision Algorithm (비디오 분할을 위한 자동 임계치 결정 알고리즘)

  • Ko Kyong-Cheol;Lee Yang-Won
    • Journal of the Korea Society of Computer and Information
    • /
    • v.10 no.6 s.38
    • /
    • pp.65-74
    • /
    • 2005
  • This Paper Propose a robust scene change detection technique that use the weighted chi-square test and the automated threshold-decision algorithm. The weighted chi-test can subdivide the difference values of individual color channels by calculating the color intensities according to mSC standard, and it can detect the scene change by joining the weighted color intensities to the predefined chi-test which emphasize the comparative color difference values. The automated decision algorithm uses the difference values of frame-to-frame that was obtained by the weighted chi-test. In the first step, The average of total difference value and standard deviation value is calculated and then, subtract the mean value from the each difference values. In the next step, the same process is performed on the remained difference value. The propose method is tested on various sources and in the experimental results, it is shown that the Proposed method is efficiently estimates the thresholds and reliably detects scene changes.

  • PDF