• Title/Summary/Keyword: network separation

Search Result 309, Processing Time 0.022 seconds

Enhancement of a Secure Remote Working Environment using CloudHSM and edge-DRM Proxy (Cloud HSM와 edge-DRM Proxy를 활용한 안전한 원격근무 환경 강화 연구)

  • Kim, Hyunwoo;Lee, Junhyeok;Park, Wonhyung
    • Convergence Security Journal
    • /
    • v.21 no.3
    • /
    • pp.25-30
    • /
    • 2021
  • Due to the current COVID-19 pandemic, companies and institutions are introducing virtual desktop technology, one of the logical network separation technologies, to establish a safe working environment in a situation where remote work is provided. With the introduction of virtual desktop technology, companies and institutions can operate the network separation environment more safely and effectively, and can access the business network quickly and safely to increase work efficiency and productivity. However, when introducing virtual desktop technology, there is a cost problem of high-spec server, storage, and license, and it is necessary to supplement in terms of operation and management. As a countermeasure to this, companies and institutions are shifting to cloud computing-based technology, virtual desktop service (DaaS, Desktop as a Service). However, in the virtual desktop service, which is a cloud computing-based technology, the shared responsibility model is responsible for user access control and data security. In this paper, based on the shared responsibility model in the virtual desktop service environment, we propose a cloud-based hardware security module (Cloud HSM) and edge-DRM proxy as an improvement method for user access control and data security.

Secure File Transfer Method and Forensic Readiness by converting file format in Network Segmentation Environment (망분리 환경에서 파일형식 변환을 통한 안전한 파일 전송 및 포렌식 준비도 구축 연구)

  • Han, Jaehyeok;Yoon, Youngin;Hur, Gimin;Lee, Jaeyeon;Choi, Jeongin;Hong, SeokJun;Lee, Sangjin
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.29 no.4
    • /
    • pp.859-866
    • /
    • 2019
  • Cybersecurity attack targeting a specific user is rising in number, even enterprises are trying to strengthen their cybersecurity. Network segmentation environment where public network and private network are separated could block information coming from the outside, however, it is unable to control outside information for business efficiency and productivity. Even if enterprises try to enhance security policies and introduce the network segmentation system and a solution incorporating CDR technology to remove unnecessary data contained in files, it is still exposed to security threats. Therefore, we suggest a system that uses file format conversion to transmit a secure file in the network separation environment. The secure file is converted into an image file from a document, as it reflects attack patterns of inserting malicious code into the document file. Additionally, this paper proposes a system in the environment which functions that a document file can keep information for incident response, considering forensic readiness.

A Percolation based M2M Networking Architecture for Data Transmission and Routing

  • Lu, Jihua;An, Jianping;Li, Xiangming;Yang, Jie;Yang, Lei
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.6 no.2
    • /
    • pp.649-663
    • /
    • 2012
  • We propose a percolation based M2M networking architecture and its data transmission method. The proposed network architecture can be server-free and router-free, which allows us to operate routing efficiently with percolations based on six degrees of separation theory in small world network modeling. The data transmission can be divided into two phases: routing and data transmission phases. In the routing phase, probe packets will be transmitted and forwarded in the network thus multiple paths are selected and performed based on the constriction of the maximum hop number. In the second phase, the information will be encoded, say, with the fountain codes, and transmitted using the paths generated in the first phase. In such a way, an efficient routing and data transmission mechanism can be built, which allow us to construct a low-cost, flexible and ubiquitous network. Such a networking architecture and data transmission can be used in many M2M communications, such as the stub network of internet of things, and deep space networking, and so on.

Congestion Aware Fast Link Failure Recovery of SDN Network Based on Source Routing

  • Huang, Liaoruo;Shen, Qingguo;Shao, Wenjuan
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.11 no.11
    • /
    • pp.5200-5222
    • /
    • 2017
  • The separation of control plane and data plane in Software Defined Network (SDN) makes it flexible to control the network behavior, while also causes some inconveniences to the link failure recovery due to the delay between fail point and the controller. To avoid delay and packet loss, pre-defined backup paths are used to reroute the disrupted flows when failure occurs. However, it may introduce large overhead to build and maintain these backup paths and is hard to dynamically construct backup paths according to the network status so as to avoid congestion during rerouting process. In order to realize congestion aware fast link failure recovery, this paper proposes a novel method which installs multi backup paths for every link via source routing and per-hop-tags and spread flows into different paths at fail point to avoid congestion. We carry out experiments and simulations to evaluate the performance of the method and the results demonstrate that our method can achieve congestion aware fast link failure recovery in SDN with a very low overhead.

Scalable Search based on Fuzzy Clustering for Interest-based P2P Networks

  • Mateo, Romeo Mark A.;Lee, Jae-Wan
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.5 no.1
    • /
    • pp.157-176
    • /
    • 2011
  • An interest-based P2P constructs the peer connections based on similarities for efficient search of resources. A clustering technique using peer similarities as data is an effective approach to group the most relevant peers. However, the separation of groups produced from clustering lowers the scalability of a P2P network. Moreover, the interest-based approach is only concerned with user-level grouping where topology-awareness on the physical network is not considered. This paper proposes an efficient scalable search for the interest-based P2P system. A scalable multi-ring (SMR) based on fuzzy clustering handles the grouping of relevant peers and the proposed scalable search utilizes the SMR for scalability of peer queries. In forming the multi-ring, a minimized route function is used to determine the shortest route to connect peers on the physical network. Performance evaluation showed that the SMR acquired an accurate peer grouping and improved the connectivity rate of the P2P network. Also, the proposed scalable search was efficient in finding more replicated files throughout the peer network compared to other traditional P2P approaches.

A Study on the Effect of the Stemming Hole medium to the Blasting Separation Distance of Structure (공내 매질이 구조물의 발파이격거리에 미치는 영향에 관한 연구)

  • Kang, Hee-Seop;Jeong, Jung-Gyu;Bang, Myung-Seok
    • Journal of the Korea institute for structural maintenance and inspection
    • /
    • v.21 no.1
    • /
    • pp.100-108
    • /
    • 2017
  • Because of urbanization, Industrialization and expansion of transportation network, blasting works are recently increasing in construction field. The blasting work influences environmental effects to residents and the safety of facilities around the working place, so the development of blasting technology is needed to reduce the damage to residents. The blasting mechanism in the hole was studied and tested in the blasting sites by the difference of diameter between explosives and drilling hole, which is named by the decoupling effect. This effect was tested by changing the medium between explosives and hole wall in three working sites(railway, highway and industrial complex). The vibration velocity of blasting was recorded and vibration equations were produced by regression analyses. Finally, the structure separation distance was derived using these equations. The testing results show that the specific gravity of medium is larger, the separation distance is smaller and the duration time of blasting is shorter in case of large specific gravity of medium, so the vibration effect stops more fastly in the water compared with the air.

Analysis of Channel Capacity with Respect to Antenna Separation of an MIMO System in an Indoor Channel Environment (실내 채널 환경에서 MIMO 시스템의 안테나 이격거리에 따른 채널 용량 분석)

  • Kim, Sang-Keun;Oh, Yi-Sok
    • The Journal of Korean Institute of Electromagnetic Engineering and Science
    • /
    • v.17 no.11 s.114
    • /
    • pp.1058-1064
    • /
    • 2006
  • In this paper, the channel capacity of a specified wireless indoor multiple-input multiple-output(MIMO) channel is estimated by analyzing spatial characteristics of this channel using the three-dimensional ray tracing method, and a technique for deriving an optimized separation of multi-antenna elements is proposed. At first, the ray paths, the path losses, and the time-delay profile are computed using the three-dimensional ray tracing method in an indoor corridor environment, which has the line of sight(LOS) and non-line of sight(NLOS) regions. The ray tracing method is verified by a comparison between the computation results and the measurements which are obtained with dipole antennas, an amplifier and a network analyzer. Then, an MIMO system is positioned in the indoor channel environment and the ray paths and path losses are computed for four antenna-position combinations and various values of the antenna separation to obtain the channel capacity for the MIMO system. An optimum antenna-separation is derived by averaging the channel capacities of 100 receiver positions with four different antenna combinations.

Base Flow Estimation in Uppermost Nakdong River Watersheds Using Chemical Hydrological Curve Separation Technique (화학적 수문곡선 분리기법을 이용한 낙동강 최상류 유역 기저유출량 산정)

  • Kim, Ryoungeun;Lee, Okjeong;Choi, Jeonghyeon;Won, Jeongeun;Kim, Sangdan
    • Journal of Korean Society on Water Environment
    • /
    • v.36 no.6
    • /
    • pp.489-499
    • /
    • 2020
  • Effective science-based management of the basin water resources requires an understanding of the characteristics of the streams, such as the baseflow discharge. In this study, the base flow was estimated in the two watersheds with the least artificial factors among the Nakdong River watersheds, as determined using the chemical hydrograph separation technique. The 16-year (2004-2019) discontinuous observed stream flow and electrical conductivity data in the Total Maximum Daily Load (TMDL) monitoring network were extended to continuous daily data using the TANK model and the 7-parameter log-linear model combined with the minimum variance unbiased estimator. The annual base flows at the upper Namgang Dam basin and the upper Nakdong River basin were both analyzed to be about 56% of the total annual flow. The monthly base flow ratio showed a high monthly deviation, as it was found to be higher than 0.9 in the dry season and about 0.46 in the rainy season. This is in line with the prevailing common sense notion that in winter, most of the stream flow is base flow, due to the characteristics of the dry season winter in Korea. It is expected that the chemical-based hydrological separation technique involving TANK and the 7-parameter log-linear models used in this study can help quantify the base flow required for systematic watershed water environment management.

Flat Sheet Polybenzimidazole Membranes for Fuel Cell, Gas Separation and Organic Solvent Nanofiltration: A Review (평막형태의 폴리벤지다미졸 분리막의 연료전지, 기체분리막, 유기물분리용 나노여과막으로의 응용: 총설)

  • Anupam Das;Sang Yong Nam
    • Membrane Journal
    • /
    • v.33 no.6
    • /
    • pp.279-304
    • /
    • 2023
  • Polybenzimidazole (PBI) based membranes have evolved in literature as a popular membrane material for various applications in the past two decades because of their high temperature thermal durability, strong mechanical and tensile properties, high glass transition temperature (Tg), ion conduction ability at elevated temperature (up to 200℃), oxidative or chemical durability along with robust network like structural rigidity, which make PBI membranes suitable for various potential applications in chemically challenging environments. Ion conducting PBI based membranes have been extensively utilized in high temperature proton exchange membrane fuel cells (HT-PEMFC). In addition, PBI based membranes have been vastly utilized for the development of gas separation membranes and organic solvent nanofiltration (OSN) membranes for their unique characteristics. This review will cover the recent progress and application of various types of flat sheet PBI based membranes for HT-PEMFC, gas separation and OSN application.

HIERARCHICAL CLUSTER ANALYSIS by arboART NEURAL NETWORKS and its APPLICATION to KANSEI EVALUATION DATA ANALYSIS

  • Ishihara, Shigekazu;Ishihara, Keiko;Nagamachi, Mitsuo
    • Proceedings of the Korean Society for Emotion and Sensibility Conference
    • /
    • 2002.05a
    • /
    • pp.195-200
    • /
    • 2002
  • ART (Adaptive Resonance Theory [1]) neural network and its variations perform non-hierarchical clustering by unsupervised learning. We propose a scheme "arboART" for hierarchical clustering by using several ART1.5-SSS networks. It classifies multidimensional vectors as a cluster tree, and finds features of clusters. The Basic idea of arboART is to use the prototype formed in an ART network as an input to other ART network that has looser distance criteria (Ishihara, et al., [2,3]). By sending prototype vectors made by ART to one after another, many small categories are combined into larger and more generalized categories. We can draw a dendrogram using classification records of sample and categories. We have confirmed its ability using standard test data commonly used in pattern recognition community. The clustering result is better than traditional computing methods, on separation of outliers, smaller error (diameter) of clusters and causes no chaining. This methodology is applied to Kansei evaluation experiment data analysis.

  • PDF