Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 47
No
1

On the Configuration and Improvement of Security Control Systems KCI 등재

Seung Jae Yoo

한국융합보안학회 융합보안논문지 제17권 제2호 2017.06 pp.69-80

※ 기관로그인 시 무료 이용이 가능합니다.

4,300원

IT시대의 고도화로 인한 사이버 범죄는 지능화, 다양화, 고도화 되고 있는 가운데 보안 관제의 역할은 더욱중요해졌다. 과거 방화벽이나 IDS 등 보안 장비에만 의존하던 방식과는 달리 실시간 감시를 통해 사이버 공격에 대한 대응을 하는 보안 관제 업무가 광범위해지고 그 역할 또한 중요하게 되었다. 현재의 사이버 위협에 대해 보안 장비만으로는 안정적인 방어를 할 수 없기 때문에 보안 장비를 운영 및 감시하고 실시간적인 대응을할 수 있는 보안 관제의 업무가 필수 요소가 된 것이다. 본 연구에서는 네트워크 보안시스템을 효율적으로 구성하는 방법과 보안시스템을 실시간 운영하는 보안관제의 현황과 개선방안에 대해 다루고자 한다.

Due to the advanced IT environment, the role of Security Monitoring & Control becomes more important as the cyber-crime is becoming intelligent, diversified, and advanced. In contrast to the way it relied solely on security devices such as Firewall and IDS in the past, Security Monitoring & Control tasks responding to cyber attacks through real-time monitoring have become wide spread and their role is also important. In response to current cyber threats, since security equipment alone can not be guaranteed a stable defense, the task of Security Monitoring & Control became essential to operate and monitor security equipment and to respond in real time. In this study, we will discuss how to configure network security system effectively and how to improve the real-time Security Monitor & Control.

2

FTS를 이용한 논리적 망 분리와 행위기반 탐지 시스템에 관한 연구 KCI 등재

김민수, 신상일, 안정준, 김귀남

한국융합보안학회 융합보안논문지 제13권 제4호 2013.09 pp.109-115

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷망을 이용한 정보 전달의 대표적인 수단인 이메일 서비스 등을 통한 보안위협이 급증하고 있다. 이러한 보안위협의 공격 경로는 첨부된 문서파일에 악성코드를 삽입하고, 해당 응용프로그램의 취약점을 이용하여 사용자의 시스템을감염시키게 된다. 따라서 본 연구에서는 파일 전송과정에서 위장악성코드의 감염을 차단하기 위해, 논리적 망 분리인FTS(File Transfer System)를 이용한 무결성 검증 및 행위기반 탐지 시스템을 제안하고, 기존의 보안기법과의 비교 및검증하고자 한다.

Security threats through e-mail service, a representative tool to convey information on the internet, are on the sharp rise. The security threats are made in the path where malicious codes are inserted into documents files attached and infect users' systems by taking advantage of the weak points of relevant application programs. Therefore, to block infection of camouflaged malicious codes in the course of file transfer, this work proposed an integrity-checking and behavior-based detection system using File Transfer System (FTS), logical network partition,and conducted a comparison analysis with the conventional security techniques.

3

행동기반 사물 감지를 통한 위급상황 확인 시스템 개발 KCI 등재

김민제, 고규한, 조재춘

중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제10권 제6호 2020.06 pp.140-146

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

기존의 방범 시스템은 피해자가 직접 구조를 요청하거나 인근 제 3자에 의해 도움을 받아야 하는 구조이기 때문에 신속하게 대응이 불가능한 상황에서는 경우에 따라 적절한 도움을 받기 힘들다. 본 연구에서는 Deep Learning과 OpenCV를 활용한 자동 구조 요청 모델을 제안하고 시스템을 개발하였다. 본 연구는 사용자의 안전을 보장할 수 있어야 하기 때문에 신속히 정확한 결과를 도출할 수 있어야 한다는 전제 조건이 밑바탕 되어 객체의 정확성은 약 99% 이상을 확인할 수 있었으며 모든 알고리즘이 종료되는 데까지의 소요 시간을 약 3초까지 단축시킬 수 있었다. 다양한 위협 요소 와 예측 불가능한 특수한 경우 등 모든 위험 상황을 인식하기 위해 다양한 종류의 위협 요소와 많은 양의 데이터를 수집하 여 예기치 못한 상황에도 대처할 수 있도록 강화하여야 할 것이다.

Since the current crime prevention systems have a standard mechanism that victims request for help by themselves or ask for help from a third party nearby, it is difficult to obtain appropriate help in situations where a prompt response is not possible. In this study, we proposed and developed an automatic rescue request model and system using Deep Learning and OpenCV. This study is based on the prerequisite that immediate and precise threat detection is essential to ensure the user’s safety. We validated and verified that the system identified by more than 99% of the object’s accuracy to ensure the user’s safety, and it took only three seconds to complete all necessary algorithms. We plan to collect various types of threats and a large amount of data to reinforce the system’s capabilities so that the system can recognize and deal with all dangerous situations, including various threats and unpredictable cases.

4

4,000원

최근 악성코드 발생률은 약 수만 건이 넘는 추세로, 전부 탐지/대응하는 것은 불가능에 가깝다고 알려졌다. 본 연구는 새로운 악성코드 대응방법으로 그래프 데이터베이스 기반 다중행위 패턴 탐지 기법을 제안한다. 기존 동적 분석 기법과는 다른 새로운 그래프 모델을 설계하고, 대표적인 악성코드 패턴(프로세스, PE, 레지스트리 등)의 그래프 연관 관계를 분석하는 방법을 적용했다. 패턴 검증 결과 기본 악성 패턴에 대한 행위 탐지와 기존 분석이 어려웠던 변종 공격 행위(5단계 이상)의 탐지를 확인했다. 또한, 성능 분석결과 5단계 이상의 복잡한 패턴에 대하여 관계형 데이터베이스 대비 약 9.84배 이상 성능이 향상되었음을 확인하였다.

Recently, the incidence rate of malicious codes is over tens of thousands of cases, and it is known that it is almost impossible to detect/respond all of them. This study proposes a method for detecting multiple behavior patterns based on a graph database as a new method for dealing with malicious codes. Traditional dynamic analysis techniques and has applied a method to design and analyze graphs of representative associations malware pattern(process, PE, registry, etc.), another new graph model. As a result of the pattern verification, it was confirmed that the behavior of the basic malicious pattern was detected and the variant attack behavior(at least 5 steps), which was difficult to analyze in the past. In addition, as a result of the performance analysis, it was confirmed that the performance was improved by about 9.84 times or more compared to the relational database for complex patterns of 5 or more steps.

5

머신러닝 기반 우주체계 경량형 이상 행위 탐지시스템 연구 KCI 등재

성도진, 김완주, 박상규, 임재성

한국융합보안학회 융합보안논문지 제26권 제1호 2026.02 pp.71-79

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 논문은 ROS2 기반 우주체계에서 발생 가능한 사이버물리적 보안 위협에 대응하기 위해 머신러닝 기반 이상 행위 탐지 시스템을 제안한다. ROS2 및 DDS/RTPS 기반 통신은 실시간 데이터 교환에 적합하지만, RTPS의 개방형 구조로 인해 명령 삽입, 세션 변조, 서비스 거부 공격에 취약하여 우주 임무의 무결성과 가용성을 저해할 수 있다. 이를 해결하기 위해 RTPS 통 신 메타데이터를 활용한 경량 침입탐지 모델을 설계하였으며, 공개 RTPS Attack Dataset에서 시간 간격, 시퀀스 차이, 직렬 화 데이터를 특징으로 추출하고 LLaMA 기반 토크나이저를 적용하였다. LightGBM, XGBoost, CatBoost, Random Forest 모 델을 비교한 결과, LightGBM이 높은 탐지 성능과 빠른 학습 속도를 보여 실시간 우주체계 보안 환경에 가장 적합함을 확인하였다.

This paper presents a machine learning–based intrusion detection system for mitigating cyber-physical threats in ROS2-based space systems. Due to the open architecture of DDS/RTPS, such systems are vulnerable to attacks that can compromise mission integrity and availability. To address this issue, a lightweight detection model using RTPS communication metadata is proposed and evaluated on the public RTPS Attack Dataset. Comparative experiments with LightGBM, XGBoost, CatBoost, and Random Forest models show that LightGBM offers the best balance between detection performance and computational efficiency, making it suitable for real-time security monitoring in defense space systems.

6

4,900원

도시철도(지하철) 객차처럼 폐쇄·혼잡한 환경에서 발생할 수 있는 방화·화재·흉기 난동 등 고위험 상황을 조기 포착하기 위해 영상분석 기반의 규칙형 이상상황 감지 알고리즘을 제안한 다. 정상 운행 장면과 함께 2025년 5월 31일 5호선 객차 방화 사건의 CCTV 영상을 활용해 검증 하였으며, 사람 검출에는 YOLOv5s, 다중객체 추적에는 DeepSORT를 사용하였다. 제안 안골리 즘은 가림(occlusion) 상황에서도 ID 일관성을 확보하고, 프레임 단위 평균 속도(avg_speed)와 방향각의 원형 표준편차(dir_std)를 계산한다. 집단이 한쪽 방향으로 빠르게 동조 이동하는 전이 신호를 두 지표로 간단히 포착해 빠른 이상 판단을 가능케 한다는 점이 해당 알고리즘의 핵심 강점이다. 최종 판정은 (avg_speed > 1.700 m/s) OR (dir_std < 91.0°)의 1차 조건을 연속 K=3 프레임 유지하고, 최근 W=13 프레임의 이상 비율 r≥0.45를 만족할 때 ‘이상상황’으로 판단한다. 알고리즘 평가 결과, 프레임 단위 Precision 0.905, Recall 0.909, F1 0.907, Accuracy 0.869를 달성하 였다. 이는 관제의 조기 인지와 2차 피해 억제를 통해 도시철도 안전체계의 고도화를 뒷받침하 며, 제안 로직은 현장 CCTV 기반 조기경보 모듈의 핵심으로 활용될 수 있음을 보여준다.

We present an interpretable, rule based video analysis algorithm for early recognition of high risk events (e.g., arson, fire, knife attacks) inside subway coaches. Validation uses routine operation footage and CCTV from the May 31, 2025 Line 5 arson incident. Using YOLOv5s for person detection and DeepSORT for multi object tracking, we compute frame level average speed (avg_speed) and the circular standard deviation of headings (dir_std) while preserving ID consistency under occlusion. The key advantage is rapid anomaly judgment by capturing collective behavior transitions—a sudden surge of movement aligned in one direction—through two simple statistics. The final decision declares an anomaly when (avg_speed > 1.700 m/s) OR (dir_std < 91.0°) holds for K = 3 consecutive frames and the anomaly fraction within W = 13 satisfies r ≥ 0.45. On the evaluated videos, the method achieved Precision 0.905, Recall 0.909, F1 0.907, and Accuracy 0.869 at the frame level. The results underpin enhancements to urban-rail safety by enabling earlier operator awareness and mitigating secondary harm, and the proposed rule set shows strong potential as a core component of CCTV-based early-warning modules.

7

딥러닝 기반 운전자 행동인식을 통한 졸음운전 감지방법

이지민, 최현민, 문창주

한국ITS학회 한국ITS학회 학술대회 Net-Zero Mobility 2023.04 pp.385-389

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

8

최근 교통사고의 주요한 원인 중 하나인 운전자 졸음으로 인한 교통사고를 예방하기 위해 졸음 인식 연구가 활발히 진행되는 중이다. 기존 졸음 인식 시스템은 운전자의 신체적 특징을 이용하여 졸음 상태를 인식하지만 신체 부위 폐 색에 의한 가려짐으로 제한되는 한계가 있다. 본 논문에서는 운전자의 다중 행동 특징을 이용한 SERN(Squeeze and Excitation Resnet Network) 기반 졸음 인식 시스템을 제안한다. 제안한 시스템은 다중 행동적 특징 기반 특징 추출 과정, 데이터의 계층적 레이블링 세분화 과정, SERN 모델에 의한 졸음 인식 과정으로 구성된다. 공개 DB인 NTHU-DDD를 사용한 실험 결과, 제안하는 SERN 모델 기반 운전자 졸음 검출 성능이 기존 네트워크 모델 보다 정확도 1.03% 우수함을 확인했다.

Recently, driver drowsiness has been one of the major causes of traffic accidents, and study on drowsiness detection has been actively conducted to prevent drowsiness-related accidents. Existing drowsiness detection systems recognize the drowsy state of the driver using the driver's physical features, but they have limitations due to occlusion caused by obstructed body parts. In this paper, we propose a drowsiness detection system based on the squeeze and excitation resnet network (SERN) using the driver's multi-behavioral features. The proposed system consists of a multibehavioral feature extraction process, a hierarchical data labeling refinement process, and a drowsiness detection process using the SERN model. As a result of an experiment using public DB’s NTHU-DDD, it was confirmed that the proposed SERN model based driver drowsiness detection performance was 1.03% better than the existing network model.

9

4,000원

최근 등장하는 랜섬웨어들은 다양한 공격 기법과 다양한 경로를 통해 공격을 수행하고 있어 조기 탐지와 방어에 많 은 어려움을 겪고 있으며, 그 피해 규모도 날로 증가하고 있다. 따라서 본 논문에서는 효과적인 랜섬웨어 탐지를 위하여 파일 암호화와 암호화 패턴을 머신러닝 기반으로 하는 감지 기법을 제안한다. 파일 암호화는 랜섬웨어가 공격하는데 필수적으로 사용하는 기능으로 암호 행위와 암호화 패턴을 분석함으로써 랜섬웨어를 탐지하고 랜섬웨어의 특정 변종이나 새로운 유형의 랜섬웨어를 탐지할 수 있기 때문에 랜섬웨어 공격을 식별하고 차단하는 데 매우 효과적이다. 제안한 머신러닝 기반의 암호화 행위 감지 기법은 암호화 특성과 암호화 패턴 특성을 추출하여 머신러닝 기반의 분류기를 통해 각각 학습을 시켜 해당 행위에 대한 탐지를 진행하고 최종 결과는 두 분류기의 평가 결과를 기반으로 앙상블 분류기에서 랜섬웨어 유무를 판별하여 좀 더 정 확도를 높였다. 또한, 제안한 기법을 numpy와 pandas, 파이썬의 사이킷런 라이브러리를 사용하여 구현하여 평가지표를 사 용한 성능를 평가한 결과 평균적으로 94%,의 정확도와 95%의 정밀도, 93%의 재현률과 95%의 F1 스코어가 산출되었다. 성 능 평가 결과를 보면 암호화 행위 감지를 통해 랜섬웨어 탐지가 가능하다는 것을 확인할 수 있었고 랜섬웨어의 사전 탐지를 위해 제안한 기법의 성능을 높이기 위한 연구도 계속해서 진행되어야 한다.

Recent ransomware attacks employ various techniques and pathways, posing significant challenges in early detection and defense. Consequently, the scale of damage is continually growing. This paper introduces a machine learning-based approach for effective ransomware detection by focusing on file encryption and encryption patterns, which are pivotal functionalities utilized by ransomware. Ransomware is identified by analyzing password behavior and encryption patterns, making it possible to detect specific ransomware variants and new types of ransomware, thereby mitigating ransomware attacks effectively. The proposed machine learning-based encryption behavior detection technique extracts encryption and encryption pattern characteristics and trains them using a machine learning classifier. The final outcome is an ensemble of results from two classifiers. The classifier plays a key role in determining the presence or absence of ransomware, leading to enhanced accuracy. The proposed technique is implemented using the numpy, pandas, and Python's Scikit-Learn library. Evaluation indicators reveal an average accuracy of 94%, precision of 95%, recall rate of 93%, and an F1 score of 95%. These performance results validate the feasibility of ransomware detection through encryption behavior analysis, and further research is encouraged to enhance the technique for proactive ransomware detection.

10

4,000원

본 논문은 가스 누출 감지와 거주자의 비정상 행동 분석을 결합한 AI 기반 스마트 안전 모 니터링 시스템을 제안한다. 기존 가스 감지 시스템의 오경보 문제와 행동 감지 시스템의 한계를 극 복하기 위해 LSTM, CNN, Random Forest 모델을 결합하여 위험 예측의 정확도를 향상시켰다. 실험 결과, 최종 위험 감지 정확도는 94.1%, 오경보 발생률은 22.3%에서 7.8%로 감소되었다. 특히, AI 모 델을 통해 가스 농도의 급격한 변화와 거주자의 비정상 행동을 종합적으로 분석하여 실제 위험 상 황을 보다 정확하게 판단하고, 실시간으로 위험을 감지하고 자동으로 긴급 구조 요청이 가능함을 입 증했다. 또한, 가스 누출 및 행동 패턴에 따른 위험도를 다단계로 평가하여 대응의 신속성과 정확성 을 높였다. 본 연구는 가정, 산업 현장, 스마트홈 환경에서 실용적으로 적용 가능하며, 향후 다양한 센서 추가, 맞춤형 AI 모델 적용, 실제 환경에서의 장기적 성능 평가를 통한 지속적인 개선 방향을 논의한다. 이를 통해 인명 피해를 최소화하고 더욱 안전한 생활 환경 조성에 기여할 수 있을 것으로 기대된다.

This paper proposes an AI-based smart safety monitoring system that integrates gas leak detection and abnormal behavior analysis to enhance risk prediction accuracy. To address the limitations of traditional gas detection systems with high false alarm rates and the restricted capabilities of behavior detection systems, the study combines LSTM, CNN, and Random Forest models. Experimental results show that the proposed system achieves a final risk detection accuracy of 94.1% and reduces the false alarm rate from 22.3% to 7.8%. Notably, the AI models enable a comprehensive analysis of rapid changes in gas concentration and abnormal behavior patterns, allowing for more accurate risk assessment and real-time emergency response automation. Additionally, the system evaluates risk levels in multiple stages based on gas leaks and behavior patterns, enhancing the speed and accuracy of response. The findings suggest that the proposed system can be practically applied in homes, industrial sites, and smart home environments. Future research will focus on integrating various sensors, developing personalized AI models, and conducting long-term performance evaluations in real-world settings. This approach is expected to minimize casualties and contribute to creating safer living environments.

11

Violent Behavior Detection Based on SVM in the Elevator SCOPUS

Guang Shu, Gaojing Fu, Peng Li, Haiyu Geng

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.5 2014.09 pp.31-40

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

To avoid fighting and violence occurred in the elevator, this paper proposed an abnormal behavior detection method based on SVM to achieve real-time monitoring. Firstly, the corners of the video sequences were detected and the Lucas-Kanade algorithm was used to calculate the optical flow to obtain velocity vector information. Secondly, this algorithm established a feature vector combining the corner kinetic energy with movement characteristics of targets (including change rate of area, change rate of external rectangle length-width ratio, distance between the targets and the angle difference of target movement direction) as the basis of violent behavior detection. Finally, SVM classifier was constructed to identify the violent behavior. The experiment results showed that the method could detect violent behavior in the elevator effectively and the algorithm was with less complex calculation and higher detection rate thus it could alarm real-time.

12

Research on Intrusion Detection Systems and Unknown Malcode Detection based on Network Behavior SCOPUS

Xiaoyong YU

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.5 2016.05 pp.315-326

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In all kinds of Internet security incidents, the most serious is malicious code. The increasingly serious problem caused by malicious code, not only make the enterprises and users suffered huge economic losses, but also makes network security facing serious threat. In this paper, based on the analysis of malicious code detection technology and detection system, the author designs and implements an unknown malicious code detection system based on network behavior analysis. Test results show that the detection system can distinguish three kinds of ARP attack; it can produce normal alarm information and achieve the desired results. At the same time, the network behavior analysis method needs to be further improved in order to achieve better analysis results, and provide more reliable results for the detection system.

13

Increasing Accuracy of Process-based Fraud Detection Using a Behavior Model SCOPUS

Solichul Huda, Riyanarto Sarno, Tohari Ahmad

보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.10 No.5 2016.05 pp.175-188

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Process-based fraud (PBF) is fraud caused by deviation from a business process model. Some studies have proposed methods for PBF detection; however, these are still not able to fully detect the occurrence of fraud. In this context, we propose a new method of PBF detection which carries out the behavior of the originators (users who perform events) to adjust the levels of fraud occured in the events. In this research, we propose a method of PBF detection with behavior model in order to increase accuracy. This is done firstly by analyzing the business processes that correspond to those in the standard operating system (SOP). Secondly, by calculating the event execution performed by the originator and his/her relations within the organization, whose behavior is then analyzed. Thirdly, by using the number of deviations and the originator behavior to calculate the attribute value. By using attribute importance weights, an attribute rating of each originator is kept. Finally, Multi Attribute Decision Making is used to decide the PBF rating of a case, on the basis of which it is decided whether fraud occurred or not. The experimental results show that this behavior model is able to reduce false positive and false negative, therefore, the method can increase the accuracy level by 0.03.

14

Intrusion Detection System for Mobile Ad hoc Networks Based on the Behavior of Nodes

S. Mamatha, A. Damodaram

보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.7 No.6 2014.12 pp.241-256

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

A Mobile Ad hoc Network (MANET) can be defined as a network of mobile nodes that communicate over the wireless radio communication channel. It is also defined as a network without any underlying infrastructure and offers unrestricted mobility. Due to their open nature and lack of infrastructure, security for MANETs has become an intricate problem. To transmit data over such a network, generally any routing protocol that enables dynamic, self-starting multi hop routing between mobile nodes is used. However these routing protocols are vulnerable to various kinds of attacks. The conventional security mechanisms of protecting a network are not sufficient for these networks. Hence a second level of defense to detect and respond to the security problem called an Intrusion Detection System (IDS) is required. An IDS based on anomaly based intrusion detection that works by checking the behavior of the nodes was proposed to overcome some of the attacks like blackhole, grayhole and flooding attacks. Generally the malicious nodes demonstrate a different behavioral pattern of all the other normal nodes. So the specified approach where a Data Transmission Quality (DTQ) function is used to determine the behavior of the nodes as malicious or legitimate is used. The DTQ function is defined in such a way that it will be close to a constant or keep changing smoothly for genuine nodes and will keep on diminishing for malicious nodes. The proposed method was implemented using AODV as the routing protocol for transmitting data. The evaluation results show that the performance of the AODV protocol under attacks has improved significantly by using the proposed approach.

15

Detection of Seam Carved Image Based on Additional Seam Carving Behavior

Yongzhen Ke, Qingqing Shan, Fan Qin, Weidong Min, Jing Guo

보안공학연구지원센터(IJSIP) International Journal of Signal Processing, Image Processing and Pattern Recognition Vol.9 No.2 2016.02 pp.167-178

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Seam carving is a kind of content aware image retargeting algorithm and can be applied to resize and deliberately remove objects from digital images. Based on the observation that after applying an additional seam carving operation, the similarity, the energy relative error, and the difference of seam distance of original image are quite different from those of the seam-carved image, we propose and develop a new method for detecting seam carving or seam insertion of natural images without knowledge of the original image. First, we apply an additional seam carving operation to the testing image, then calculate similarity, energy relative error, and difference of seam distance between the testing image and its seam carved version. Last, we extract 11 dimensional features to detect seam carving operation to train a support vector machine classifier for recognizing whether an image is an original or it has been modified using seam-carving. Our experimental results demonstrate that our proposed forensic method achieves not only better detection rate but also lower dimensional features compared with other existing seam carved detection methods.

16

TCP-Flow 시퀀스를 이용한 네트워크 행위 기반 안드로이드 악성코드 탐지 KCI 등재

성명재, 박해룡, 최보민, 임을규

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.11 No.6 2014.12 pp.551-566

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

안드로이드 악성코드는 빠르게 증가하고 있다. 많은 안드로이드 악성코드들은 불분명한 곳으로부터 악성코드를 설치하도록 유도하고 있다. 따라서 안드로이드장치들은 항상 악성코드 위협에 노출되어있다. 안드로이드 운영체제에서 악성코드를 차단하기 위해서 많은 연구가 진행 중이며 이런 연구 중 본 논문에서 네트워크 행위 기반 안드로이드 악성코드 탐지 방법을 연구하였다. 네트워크 행위 기반 안드로이드 악성코드 탐지방법은 악성코드가 행위를 수행할 때 발생되는 네트워크 패킷을 이용하여 특징을 생성하였으며, 이 특징은 TCP-Flow에 패킷 크기를 사상하고 코드변환을 통해 코드를 나열 시킨, TCP-Flow 시퀀스(TCP-flow sequence)와 도메인 네임(Domain Name)을 사용해 하나의 특징으로 구성된다. 본 논문에서는 이 특징을 이용해 네트워크 행위 기반 악성코드 탐지 시스템을 구현하였다.

The number of Android malware is increasing rapidly. Android malware is spreaded through unclear sources or markets. Therefore, Android devices are always exposed to malware threats. In order to prevent malware from damaging the Android operating system, there are many ongoing researches. In this paper, we propose Android malware detection method based on network behavior. this method generates features using network packets which occur during executions of malware. these features were consisted from a pair of domain names and TCP packet-flow sequences such as TCP flows. We Implemented the proposed method, and experimented with test data.

17

Selection of Monitoring Nodes to Maximize Sensing Area in Behavior-based Attack Detection

Chong, Kyun-Rak

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.21 No.1 2016 pp.73-78

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In wireless sensor networks, sensors have capabilities of sensing and wireless communication, computing power and collect data such as sound, movement, vibration. Sensors need to communicate wirelessly to send their sensing data to other sensors or the base station and so they are vulnerable to many attacks like garbage packet injection that cannot be prevented by using traditional cryptographic mechanisms. To defend against such attacks, a behavior-based attack detection is used in which some specialized monitoring nodes overhear the communications of their neighbors(normal nodes) to detect illegitimate behaviors. It is desirable that the total sensing area of normal nodes covered by monitoring nodes is as large as possible. The previous researches have focused on selecting the monitoring nodes so as to maximize the number of normal nodes(node coverage), which does not guarantee that the area sensed by the selected normal nodes is maximized. In this study, we have developed an algorithm for selecting the monitoring nodes needed to cover the maximum sensing area. We also have compared experimentally the covered sensing areas computed by our algorithm and the node coverage algorithm.

18

Virus Detection Method based on Behavior Resource Tree

Zou, Mengsong, Han, Lansheng, Liu, Ming, Liu, Qiwen

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.7 No.1 2011 pp.173-186

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Due to the disadvantages of signature-based computer virus detection techniques, behavior-based detection methods have developed rapidly in recent years. However, current popular behavior-based detection methods only take API call sequences as program behavior features and the difference between API calls in the detection is not taken into consideration. This paper divides virus behaviors into separate function modules by introducing DLLs into detection. APIs in different modules have different importance. DLLs and APIs are both considered program calling resources. Based on the calling relationships between DLLs and APIs, program calling resources can be pictured as a tree named program behavior resource tree. Important block structures are selected from the tree as program behavior features. Finally, a virus detection model based on behavior the resource tree is proposed and verified by experiment which provides a helpful reference to virus detection.

19

Game Bot Detection Approach Based on Behavior Analysis and Consideration of Various Play Styles

Chung, Yeounoh, Park, Chang-Yong, Kim, Noo-Ri, Cho, Hana, Yoon, Taebok, Lee, Hunjoo, Lee, Jee-Hyong

[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.35 No.6 2013 pp.1058-1067

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

An approach for game bot detection in massively multiplayer online role-playing games (MMORPGs) based on the analysis of game playing behavior is proposed. Since MMORPGs are large-scale games, users can play in various ways. This variety in playing behavior makes it hard to detect game bots based on play behaviors. To cope with this problem, the proposed approach observes game playing behaviors of users and groups them by their behavioral similarities. Then, it develops a local bot detection model for each player group. Since the locally optimized models can more accurately detect game bots within each player group, the combination of those models brings about overall improvement. Behavioral features are selected and developed to accurately detect game bots with the low resolution data, considering common aspects of MMORPG playing. Through the experiment with the real data from a game currently in service, it is shown that the proposed local model approach yields more accurate results.

20

HB-DIPM: Human Behavior Analysis-Based Malware Detection and Intrusion Prevention Model in the Future Internet

Lee, Jeong Kyu, Moon, Seo Yeon, Park, Jong Hyuk

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.12 No.3 2016 pp.489-501

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

As interest in the Internet increases, related technologies are also quickly progressing. As smart devices become more widely used, interest is growing in words are missing here like "improving the" or "figuring out how to use the" future Internet to resolve the fundamental issues of transmission quality and security. The future Internet is being studied to improve the limits of existing Internet structures and to reflect new requirements. In particular, research on words are missing here like "finding new forms of" or "applying new forms of" or "studying various types of" or "finding ways to provide more" reliable communication to connect the Internet to various services is in demand. In this paper, we analyze the security threats caused by malicious activities in the future Internet and propose a human behavior analysis-based security service model for malware detection and intrusion prevention to provide more reliable communication. Our proposed service model provides high reliability services by responding to security threats by detecting various malware intrusions and protocol authentications based on human behavior.

 
1 2 3
페이지 저장