• 제목/요약/키워드: system security

검색결과 9,746건 처리시간 0.038초

APT 공격 탐지를 위한 공격 경로 및 의도 인지 시스템 (Attack Path and Intention Recognition System for detecting APT Attack)

  • 김남욱;엄정호
    • 디지털산업정보학회논문지
    • /
    • 제16권1호
    • /
    • pp.67-78
    • /
    • 2020
  • Typical security solutions such as intrusion detection system are not suitable for detecting advanced persistent attack(APT), because they cannot draw the big picture from trivial events of security solutions. Researches on techniques for detecting multiple stage attacks by analyzing the correlations between security events or alerts are being actively conducted in academic field. However, these studies still use events from existing security system, and there is insufficient research on the structure of the entire security system suitable for advanced persistent attacks. In this paper, we propose an attack path and intention recognition system suitable for multiple stage attacks like advanced persistent attack detection. The proposed system defines the trace format and overall structure of the system that detects APT attacks based on the correlation and behavior analysis, and is designed with a structure of detection system using deep learning and big data technology, etc.

블랙보드구조를 활용한 보안 모델의 연동 (Coordination among the Security Systems using the Blackboard Architecture)

  • 서희석;조대호
    • 제어로봇시스템학회논문지
    • /
    • 제9권4호
    • /
    • pp.310-319
    • /
    • 2003
  • As the importance and the need for network security are increased, many organizations use the various security systems. They enable to construct the consistent integrated security environment by sharing the network vulnerable information among IDS (Intrusion Detection System), firewall and vulnerable scanner. The multiple IDSes coordinate by sharing attacker's information for the effective detection of the intrusion is the effective method for improving the intrusion detection performance. The system which uses BBA (Blackboard Architecture) for the information sharing can be easily expanded by adding new agents and increasing the number of BB (Blackboard) levels. Moreover the subdivided levels of blackboard enhance the sensitivity of the intrusion detection. For the simulation, security models are constructed based on the DEVS (Discrete Event system Specification) formalism. The intrusion detection agent uses the ES (Expert System). The intrusion detection system detects the intrusions using the blackboard and the firewall responses to these detection information.

모바일 환경에서의 MIR 시큐리티 시스템에 관한 연구 (Design of MIR Security System in Mobile Environment)

  • 김석수;하경재;한군희
    • 융합보안논문지
    • /
    • 제6권1호
    • /
    • pp.25-32
    • /
    • 2006
  • 본 논문에서 제시되는 MIR 시스템은 의료정보를 필요로 하는 어느 병원에서나 보건기관에서 즉시 사용할 수 있도록 전국적인 의무기록 정보 시스템을 구축하는 것으로 대부분 보안이 요구되는 자료들이다. 특히, 환자와 의사에 관련된 개인정보, 의료 전문기술 관련정보, 각 병원의 전산적 정보는 사용 빈도가 높고 정보의 변질을 통해 다른 목적으로 이용될 수 있는 가능성이 높다. 따라서 이러한 의료정보 서비스를 효과적으로 제공함과 동시에 정보의 유출을 방지하기 위한 보안대책이 강구된 시스템 개발이 필요하다.

  • PDF

안전도 향상을 위한 UPFC 운전 전략 (UPFC Operation Strategy for Enhancement of System Security)

  • 이동우;안선주;문승일;윤종수;장병훈;김수열;문승필
    • 대한전기학회:학술대회논문집
    • /
    • 대한전기학회 2006년도 제37회 하계학술대회 논문집 A
    • /
    • pp.177-178
    • /
    • 2006
  • The enhancement of system security is one of the most important objectives of UPFC operation. To describe the system security, the index related to line flows and bus voltages are used. For the enhancement of security, the operation point of UPFC is set to minimize the index. This paper proposes the minimization algorithm using the Marquardt method. Moreover, the coefficients minimizing iteration number will be derived. For verification of the proposed operation scheme, numerical simulations have been performed on power system in Kwanju area, Korea with a UPFC.

  • PDF

M-Commerce 보안 플랫폼상의 무선 전자지불시스템 설계 및 구현 (Design and implementation of Mobile Electronic Payment Gateway System based on M-Commerce Security Platform)

  • 김성한;이강찬;민재홍
    • 한국전자거래학회지
    • /
    • 제7권1호
    • /
    • pp.35-50
    • /
    • 2002
  • Recently, payment method is one of the most hot issues for transaction of contents in mobile and internet markets. Many kinds of mobile contents services are rapidly growing with the combination of internet application services. Payment method algorithms are demanded for the stable transaction between producer and consumer. Security protocol algorithms are widely adapted for mobile Platform terminals. In this Paper, we described security mechanism for the current wireless internet services and compared with the performance result. There are security protocols that based on java machine platform or WAP protocols. The system is based on J2ME technology for the java mobile platform. Based on this technology, a security system is proposed for the service of mobile commerce electronic payment. The system is designed for the stability of transaction so that it enables to apply into many kinds of internet payment system.

  • PDF

FACTS 기기를 이용한 전력시스템의 안전도 향상 (The Enhancement of Power System Security Using flexible AC Transmission Systems (FACTS))

  • 송성환;임정욱;문승일
    • 대한전기학회논문지:전력기술부문A
    • /
    • 제52권3호
    • /
    • pp.165-172
    • /
    • 2003
  • This paper presents an operation scheme to enhance the power system security by applying FACTS on Power systems. Three main generic types of FACTS devices are suggested an illustrated. Flow congestions over lines have been solved by controlling active power of series-compensated FACTS devices and low voltages at buses have been solved by controlling reactive power of shunt-compensated FACTS devices. Especially, Especially, UPFC has been applied in both line congestion and low voltages. Two kinds of indices which indicate the power system security level related to line flow and bus voltage are utilized in this paper. They have been minimized to enhance the power system security level through the iterative method and the sensitivity vector of security index is derived to determine the direction to minimum. The proposed algorithm has been tested on the IEEE 57-bus system with FACTS devices in a normal condition and a line-faulted contingency.

미국의 항공보안정책 적용과 프라이버시 문제점 (Implementation of the U.S. Aviation Security Policy and Privacy Protection Problem)

  • 강자영;김장환
    • 한국항공운항학회지
    • /
    • 제13권3호
    • /
    • pp.110-116
    • /
    • 2005
  • TSA needs to be more transparent with the new passenger screening system and its functioning to build the citizen trust. The system is needed to be not only effective but supported by Congress and the general public. Until this occurs, skepticism will underlie any discussion about its effectiveness in balancing the protection from terrorism with respect to individual liberties. CAPPS II can be a viable system if it is developed appropriately. The objectives of the study are to introduce the security program in the U.S. aviation security policy and to discuss privacy problems when it applies. Korea also needs to study a harmonious plan with the basis of global approach mind in the case of considering the transferring of passenger information from other states for the purpose of security.

  • PDF

The System of Digital Management of the Enterprise's Labor Resources in the Context of Ensuring Personnel Security and Economic Development

  • Dziubenko, Oleg;Halaz, Lina;Bala, Olha;Zozulia, Ihor;Berezovskyi, Ruslan
    • International Journal of Computer Science & Network Security
    • /
    • 제22권9호
    • /
    • pp.89-94
    • /
    • 2022
  • The main purpose of the article is to analyze the system of digital management of labor resources in the context of ensuring personnel security and economic development. In the context of the digital transformation of the economy, much attention is paid to the creation of an innovative personnel management system, as the competition between organizations is intensifying, the victory in which guarantees greater economic benefits. Based on the results of the study, the features and key aspects of the digital management system of the enterprise's labor resources were characterized in the context of ensuring personnel security and economic development. Further research will include consideration of the practical aspects of the digital management system of the enterprise's labor resources.

보안사고 예보시스템 (Forecast System for Security Incidents)

  • 이동근;임종인
    • 전자공학회논문지
    • /
    • 제53권6호
    • /
    • pp.69-79
    • /
    • 2016
  • 기업은 대부분의 경우 보안사고가 발생하면 내부 대응절차에 따라 신속한 사고처리에 집중하고 사고원인, 문제점 및 조치결과를 최고 경영진에게 보고하면서 사고를 마무리한다. 또한 외부에서 발생한 보안사고는 그때마다 관심을 가지고 적극적으로 내부와 연결하여 문제점을 발굴하고 조치를 하는 경우와 외부의 문제로 치부하며 잠시 관심정도만 가지고 넘기는 경우도 있을 것이다. 기업은 보안사고 발생 시점에 관심과 역량을 집중하여 대응하는 것 뿐만 아니라 보안사고가 발생하지 않도록 지속적인 사고예방 활동을 하는 것이 중요하며 이를 위해 체계적이며 일관성 있고 시스템적인 방법이 제공되어야 한다. 이와 같은 목적에서 본 논문에서는 보안사고 예보시스템을 제안한다. 보안사고 예보시스템은 기업의 내부에서 일어난 직접 보안사고 뿐만 아니라, 외부에서 발생한 간접 보안사고로부터 향후 보안사고 예측에 도움이 되는 사고발생 유발인자들을 모아서 데이터베이스화하고 기업에서 가지고 있는 축적된 사고 경험과 대응 프로세스들을 시스템화하여 상호작용을 하도록 만드는 것이다. 보안사고 예보시스템은 잠재적으로 발생할 수 있는 사고의 예방조치활동에 효과적인 대안이 될 수 있을 것이다.

Meeting Real Challenges in Eliciting Security Attributes for Mobile Application Development

  • Yusop, Noorrezam;Kamalrudin, Massila;Yusof, Mokhtar Mohd;Sidek, Safiah
    • 인터넷정보학회논문지
    • /
    • 제17권5호
    • /
    • pp.25-32
    • /
    • 2016
  • There has been a rapid growth in the development of mobile application resulting from its wide usage for online transaction, data storage and exchange of information. However, an important issue that has been overlooked is the lack of emphasis on the security issues at the early stage of the development. In fact, security issues have been kept until the later stage of the implementation of mobile apps. Requirements engineers frequently ignore and incorrectly elicit security related requirements at the early stage of mobile application development. This scenario has led to the failure of developing secure and safe mobile application based on the needs of the users. As such, this paper intends to provide further understanding of the real challenges in extracting security attributes for mobile application faced by novice requirements engineers. For this purpose, two experiments on eliciting security attributes requirements of textual requirements scenario were conducted. The performance related to the correctness and time taken to elicit the security attributes were measured and recorded. It was found that the process of eliciting correct security attributes for mobile application requires effort, knowledge and skills. The findings indicate that an automated tool for correct elicitation security attributes requirement could help to overcome the challenges in eliciting security attributes requirements, especially among novice requirements engineers.