• Title/Summary/Keyword: system vulnerability

Search Result 1,000, Processing Time 0.03 seconds

A Design of Secure Communication for Device Management Based on IoT (사물인터넷 기반 디바이스 관리를 위한 안전한 통신 프로토콜 설계)

  • Park, Jung-Oh;Choi, Do-Hyeon;Hong, Chan-Ki
    • Journal of Convergence for Information Technology
    • /
    • v.10 no.11
    • /
    • pp.55-63
    • /
    • 2020
  • The IoT technology is a field that applies and converges the technologies in the existing industrial environment, instead of new technologies. The IoT technology is releasing various application services converged with other industries such as smart home, healthcare, construction, and automobile, and it is also possible to secure the work efficiency and convenience of users of IoT-based technologies. However, the security threats occurring in the IoT-based technology environment are succeeding to the vulnerability of the existing wireless network environment. And the occurrence of new and variant attacks in the combination with the ICT convergence environment, is causing damages. Thus, in the IoT technology-based environment, it would be necessary to have researches on the safe transmission of messages in the communication environment between user and device, and device and device. This thesis aims to design a safe communication protocol in the IoT-based technology environment. Regarding the suggested communication protocol, this thesis performed the safety analysis on the attack techniques occurring in the IoT technology-based environment. And through the performance evaluation of the existing PKI-based certificate issuance system and the suggested communication protocol, this thesis verified the high efficiency(about 23%) of communication procedure. Also, this thesis verified the reduced figure(about 65%) of the issued quantity of certificate compared to the existing issuance system and the certificate management technique.

Properties of a Social Network Topology of Livestock Movements to Slaughterhouse in Korea (도축장 출하차량 이동의 사회연결망 특성 분석)

  • Park, Hyuk;Bae, Sunhak;Pak, Son-Il
    • Journal of Veterinary Clinics
    • /
    • v.33 no.5
    • /
    • pp.278-285
    • /
    • 2016
  • Epidemiological studies have shown the association between transportation of live animals and the potential transmission of infectious disease between premises. This finding was also observed in the 2014-2015 foot-and-mouth disease (FMD) outbreak in Korea. Furthermore, slaughterhouses played a key role in the global spread of the FMD virus during the epidemic. In this context, in-depth knowledge of the structure of direct and indirect contact between slaughterhouses is paramount for understanding the dynamics of FMD transmission. But the social network structure of vehicle movements to slaughterhouses in Korea remains unclear. Hence, the aim of this study was to configure a social network topology of vehicle movements between slaughterhouses for a better understanding of how they are potentially connected, and to explore whether FMD outbreaks can be explained by the network properties constructed in the study. We created five monthly directed networks based on the frequency and chronology of on- and off-slaughterhouse vehicle movements. For the monthly network, a node represented a slaughterhouse, and an edge (or link) denoted vehicle movement between two slaughterhouses. Movement data were retrieved from the national Korean Animal Health Integrated System (KAHIS) database, which tracks the routes of individual vehicle movements using a global positioning system (GPS). Electronic registration of livestock movements has been a mandatory requirement since 2013 to ensure traceability of such movements. For each of the five studied networks, the network structures were characterized by small-world properties, with a short mean distance, a high clustering coefficient, and a short diameter. In addition, a strongly connected component was observed in each of the created networks, and this giant component included 94.4% to 100% of all network nodes. The characteristic hub-and-spoke type of structure was not identified. Such a structural vulnerability in the network suggests that once an infectious disease (such as FMD) is introduced in a random slaughterhouse within the cohesive component, it can spread to every other slaughterhouse in the component. From an epidemiological perspective, for disease management, empirically derived small-world networks could inform decision-makers on the higher potential for a large FMD epidemic within the livestock industry, and could provide insights into the rapid-transmission dynamics of the disease across long distances, despite a standstill of animal movements during the epidemic, given a single incursion of infection in any slaughterhouse in the country.

Balancing Water Supply Reliability, Flood Hazard Mitigation and Environmental Resilience in Large River Systems

  • Goodwin, Peter
    • Proceedings of the Korea Water Resources Association Conference
    • /
    • 2016.05a
    • /
    • pp.1-1
    • /
    • 2016
  • Many of the world's large ecosystems are severely stressed due to population growth, water quality and quantity problems, vulnerability to flood and drought, and the loss of native species and cultural resources. Consequences of climate change further increase uncertainties about the future. These major societal challenges must be addressed through innovations in governance, policy, and ways of implementing management strategies. Science and engineering play a critical role in helping define possible alternative futures that could be achieved and the possible consequences to economic development, quality of life, and sustainability of ecosystem services. Science has advanced rapidly during the past decade with the emergence of science communities coalescing around 'Grand Challenges' and the maturation of how these communities function has resulted in large interdisciplinary research networks. An example is the River Experiment Center of KICT that engages researchers from throughout Korea and the world. This trend has been complemented by major advances in sensor technologies and data synthesis to accelerate knowledge discovery. These factors combine to allow scientific debate to occur in a more open and transparent manner. The availability of information and improved communication of scientific and engineering issues is raising the level of dialogue at the science-policy interface. However, severe challenges persist since scientific discovery does not occur on the same timeframe as management actions, policy decisions or at the pace sometimes expected by elected officials. Common challenges include the need to make decisions in the face of considerable uncertainty, ensuring research results are actionable and preventing science being used by special interests to delay or obsfucate decisions. These challenges are explored in the context of examples from the United States, including the California Bay-Delta system. California transfers water from the wetter northern part of the state to the drier southern part of the state through the Central Valley Project since 1940 and this was supplemented by the State Water Project in 1973. The scale of these activities is remarkable: approximately two thirds of the population of Californians rely on water from the Delta, these waters also irrigate up to 45% of the fruits & vegetables produced in the US, and about 80% of California's commercial fishery species live in or migrate through the Bay-Delta. This Delta region is a global hotspot for biodiversity that provides habitat for over 700 species, but is also a hotspot for the loss of biodiversity with more than 25 species currently listed by the Endangered Species Act. Understanding the decline of the fragile ecosystem of the Bay-Delta system and the potential consequences to economic growth if water transfers are reduced for the environment, the California State Legislature passed landmark legislation in 2009 (CA Water Code SS 85054) that established "Coequal goals of providing a more reliable water supply for California and protecting, restoring, and enhancing the Delta ecosystem". The legislation also stated that "The coequal goals shall be achieved in a manner that protects and enhances the unique cultural, recreational, natural resource, and agricultural values of the Delta as an evolving place." The challenges of integrating policy, management and scientific research will be described through this and other international examples.

  • PDF

An Interpretable Log Anomaly System Using Bayesian Probability and Closed Sequence Pattern Mining (베이지안 확률 및 폐쇄 순차패턴 마이닝 방식을 이용한 설명가능한 로그 이상탐지 시스템)

  • Yun, Jiyoung;Shin, Gun-Yoon;Kim, Dong-Wook;Kim, Sang-Soo;Han, Myung-Mook
    • Journal of Internet Computing and Services
    • /
    • v.22 no.2
    • /
    • pp.77-87
    • /
    • 2021
  • With the development of the Internet and personal computers, various and complex attacks begin to emerge. As the attacks become more complex, signature-based detection become difficult. It leads to the research on behavior-based log anomaly detection. Recent work utilizes deep learning to learn the order and it shows good performance. Despite its good performance, it does not provide any explanation for prediction. The lack of explanation can occur difficulty of finding contamination of data or the vulnerability of the model itself. As a result, the users lose their reliability of the model. To address this problem, this work proposes an explainable log anomaly detection system. In this study, log parsing is the first to proceed. Afterward, sequential rules are extracted by Bayesian posterior probability. As a result, the "If condition then results, post-probability" type rule set is extracted. If the sample is matched to the ruleset, it is normal, otherwise, it is an anomaly. We utilize HDFS datasets for the experiment, resulting in F1score 92.7% in test dataset.

Elicitation of drought alternatives based on Water Policy Council and the role of Shared Vision Model (협의체 기반 가뭄 대응 대안 도출과 비전공유모형의 역할)

  • Kim, Gi Joo;Seo, Seung Beom;Kim, Young-Oh
    • Journal of Korea Water Resources Association
    • /
    • v.52 no.6
    • /
    • pp.429-440
    • /
    • 2019
  • The numbers of multi-year droughts due to climate change are increasing worldwide. Boryeong Dam, located in Chungcheongnam-do, South Korea, was also affected by a 4-year drought from 2014 to 2017. Since traditional unilateral decision making processes to alleviate drought damage have, until now, resulted in conflicts between many of the involved groups, the need for active participation from both stakeholders and policymakers is greater than before. This study introduced Shared Vision Planning, a collaborative decision making process that involves participation from various groups of stakeholders, by organizing Water Policy Council for Climate Change Adaptation in Chungcheongnam-do. A Shared Vision Planning Model was then developed with a system dynamics software by working together with relevant stakeholders to actively reflect their requests through three council meetings. Multiple simulations that included various future climate change scenarios were conducted, and future drought vulnerability analysis results of Boryeong Dam and districts, in terms of frequency, length, and magnitude, were arrived at. It was concluded that Boryeong Dam was more vulnerable to future droughts than the eight districts. While the total water deficit in the eight districts was not so significant, their water deficit in terms of spatial discordance was proved to be more problematic. In the future, possible alternatives to the model will be implemented so that stakeholders can use it to agree on a policy for possible conflict resolutions.

A System for Measuring the Similarity and Redundancy of R&D Project (R&D 과제의 유사도 및 중복도 측정 시스템에 관한 연구)

  • Choi, Kook-Hyun;Kang, Yong-Suk;Kim, Jong-Hee;Shin, Yong-Tae;Kim, Jong-Bae
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2014.05a
    • /
    • pp.329-331
    • /
    • 2014
  • The analysis of the similarities and redundancies among R&D projects is important for the efficient investment of government budgets. When government R&D projects are planned, the redundancies of research tasks are examined by institutions specializing in research management, relevant offices and departments, and the government to prevent redundant funding. However, as existing similarity analyses depend on methods wherein new task proposals and existing R&D project proposals are compared and looked up based on keywords. This results in vulnerability wherein similarity cannot be accurately measured in the event of partial modifications of the task name or technical substitutions. This study aims to use patent information as characteristics by which R&D project documents can be identified. The patent data used is based on materials officially published by the government's R&D patent trend survey project (http://ipas.rndip.re.kr). The study aims to propose a method by which patent information can be used to analyze the similarity and redundancy among R&D projects when new projects are entered. For this purpose, a similarity measurement model based on set theory and probability theory is presented. The presented measurement model is implemented into an actual system to identify redundant documents, and calculate and show their similarity.

  • PDF

A Study on the Improvement of Disaster and Safety Management for Local Cultural Heritages (지방문화재 재난안전관리 개선방안에 관한 연구)

  • Kim, Twe-Hwan;Kim, Jung-Gon;Been, Ju-Hee
    • Journal of the Society of Disaster Information
    • /
    • v.15 no.3
    • /
    • pp.358-366
    • /
    • 2019
  • Purpose: This paper aims to clarify the problems and to examine the improvement methods by investigating the management condition of local-designated cultural property of which management is relatively poor in comparison with state-designated cultural heritage. Method: In order to grasp the management situation of the local-designated cultural heritage, a research on cultural heritage management situation and problems will be carried out with 35 cultual heritages in Goryeong-gun. Also, the improvement methods about the property type vulnerability on the basis of interview with cultual property managers, fire-fighting officers and civil servants, etc. Results: Local cultural heritages were investigated to be very vulnerable to the fire of wooden buildings, the theft of movable cultural heritages, and the effects of wind and water damage. It is because cultural heritages are scattered over wide areas fundamentally. As the result, it has difficulty in the patrols of police officers and fire fighters, and in the situation that it lacks disaster monitoring and CCTV for countermeasures to replace them, electronic security including fire hydrant, sensors, etc and fire extinguishing facilities and so on. It is difficult for local governments managing local-designated cultural heritages to enhance their management systems directly due to their lack of budget and manpower. Conclusion: In order to strengthen disaster and safety management system for the cultural heritages designated by local governments, they have to clarify disaster countermeasure task of fire fighting, police, and cultural heritage managers prepare their manuals, and systematize them through disaster drill mainly in local autonomous governments. Also, so as to establish a surveillance system every day, they have to enhance the community for local cultural heritage manage consisting of local volunteer fire departments, local voluntary disaster prevention organizations, volunteers, etc.

Hash-based Authentication Protocol for RFID Applicable to Desynchronization between the Server and Tag with efficient searching method (서버와 태그 비동기시에도 효율적으로 검색이 가능한 해시기반 RFID 인증 프로토콜)

  • Kwon, Hye-Jin;Kim, Hae-Mun;Jeong, Seon-Yeong;Kim, Soon-Ja
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.21 no.5
    • /
    • pp.71-82
    • /
    • 2011
  • The RFID system provides undeniable advantages so that it is used for various application. However recent RFID system is vulnerable to some attacks as eavesdropping, replay attack, message hijacking, and tag tampering, because the messages are transmitted through the wireless channel and the tags are cheap. Above attacks cause the tag and reader impersonation, denial of service by invalidating tag, and the location tracking concerning bearer of tags, A lot of RFID authentication protocol bas been proposed to solve the vulnerability. Since Weis, Sanna, Rivest, and Engel, proposed the bash-based RFID authentication protocol, many researchers have improved hash-based authentication protocol and recent bash-based authentication protocols provide security and desirable privacy. However, it remains open problem to reduce the tag identification time as long as privacy and security are still guaranteed. Here we propose a new protocol in which the tags generate the message depending on the state of previous communitions between tag and reader. In consequence, our protocol allows a server to identify a tag in a reasonable amount of time while ensuring security and privacy, To be specific, we reduced the time for the server to identify a tag when the last session finished abnormally by at least 50% compared with other bash-based schemes that ensure levels of security and privacy similar to ours.

Security Analysis of KS X 4600-1 / ISO IEC 12139-1 (원격 검첨용 PLC 기술(KS X 4600-1 / ISO IEC 12139-1) 보안성 분석)

  • Hong, Jeong-Dae;Cheon, Jung-Hee;Ju, Seong-Ho;Choi, Moon-Suk
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.21 no.1
    • /
    • pp.65-75
    • /
    • 2011
  • Power Line Communication (PLC) is a system for carrying data on a conductor used for electric power transmission. Recently, PLC has received much attention due to connection efficiency and possibility of extension. It can be used for not only alternative communication, in which communication line is not sufficient, but also for communication between home appliances. Korea Electronic Power Cooperation (KEPCO) is constructing the system, which automatically collects values of power consumption of every household. Due to the randomness and complicated physical characteristics of PLC protocol (KS X4600-1), it has been believed that the current PLC is secure in the sense that it is hard that an attacker guesses or modifies the value of power consumption. However, we show that the randomness of the protocol is closely related to state of the communication line and thus anyone can easily guess the randomness by checking the state of the communication line. In order to analyze the security of PLC, we study the protocol in detail and show some vulnerability. In addition, we suggest that PLC needs more secure protocol on higher layers. We expect that the study of PLC help in designing more secure protocol as well.

Simulation and Analysis of Response Plans against Chemical and Biological Hazards (화학 생물 위험 대응 시뮬레이션 및 분석)

  • Han, Sangwoo;Seo, Jiyun;Shim, Woosup
    • Journal of the Korea Society for Simulation
    • /
    • v.30 no.2
    • /
    • pp.49-64
    • /
    • 2021
  • M&S techniques are widely used as scientific means to systematically develop response plans to chemical and biological (CB) hazards. However, while the theoretical area of hazard dispersion modeling has achieved remarkable practical results, the operational analysis area to simulate CB hazard response plans is still in an early stage. This paper presents a model to simulate CB hazard response plans such as detection, protection, and decontamination. First, we present a possible way to display high-fidelity hazard dispersion in a combat simulation model, taking into account weather and terrain conditions. We then develop an improved vulnerability model of the combat simulation model, in order to simulate CB damage of combat simulation entities based on other casualty prediction techniques. In addition, we implement tactical behavior task models that simulate CB hazard response plans such as detection, reconnaissance, protection, and decontamination. Finally, we explore its feasibility by analyzing contamination detection effects by distributed CB detectors and decontamination effects according to the size of the {contaminated, decontamination} unit. We expect that the proposed model will be partially utilized in disaster prevention and simulation training area as well as analysis of combat effectiveness analysis of CB protection system and its operational concepts in the military area.