년 - 년
초등학생의 스크래치 프로젝트 코드 분석을 통한 컴퓨팅 사고력 평가 KCI 등재
한국정보교육학회 정보교육학회논문지 제23권 제3호 2019.06 pp.207-217
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
컴퓨팅 사고력을 향상시키기 위해 초등학교에서는 블록형 프로그래밍 언어인 스크래치를 활용한 기초 프로그 래밍 교육을 하고 있으나 컴퓨팅 사고력에 대한 평가 연구는 초기 단계이다. 따라서 본 연구에서는 스크래치 프 로젝트의 코드를 분석하는 방법을 활용하여 초등학생들의 컴퓨팅 사고력의 개념 수준을 평가하였다. 이를 위해 스크래치 코드 분석 자동화 도구인 Dr. Scratch를 활용하여 초등학교 6학년 학생들이 제작한 179개의 스크래치 프로젝트를 분석하였다. 연구결과 초등학생의 컴퓨팅 사고력의 개념수준은 개발자 수준이 많았고, 성별과 작품 유형에 따라 차이가 있었고, 논리와 추상화 요소에서 가장 낮은 수준을 보였으며, 프로그래밍 과정에서 컴퓨팅 사고력이 향상되는 것으로 나타났다. 본 연구는 초등학생의 프로그래밍 학습에서 교수방법의 개선과 자기주도적 컴퓨팅 사고력의 평가에 대한 시사점을 제공한다.
In order to improve computational thinking, elementary schools have been using ‘Scratch’ to provide basic programming education. However, the study on evaluation of computational thinking is at an early stage. Therefore, this study evaluated the conceptual level of computational thinking using the scratch code analyzing. For this, Dr. Scratch was used to analyze 179 scratch projects. The results showed that the conceptual level of computational thinking of most elementary students was at the developing level, and that it varied according to gender and production style, showed the lowest level of logic and abstraction, and improved computational thinking during programming. This study is meaningful in that it provides implications for the improvement of teaching methods and self-directed evaluation in learning.
Development of a Flow Analysis Code Using an Unstructured Grid with the Cell-Centered Method
[Kisti 연계] 대한기계학회 Journal of mechanical science and technology Vol.20 No.12 2006 pp.2218-2229
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
A conservative finite-volume numerical method for unstructured grids with the cell-centered method has been developed for computing flow and heat transfer by combining the attractive features of the existing pressure-based procedures with the advances made in unstructured grid techniques. This method uses an integral form of governing equations for arbitrary convex polyhedra. Care is taken in the discretization and solution procedure to avoid formulations that are cell-shape-specific. A collocated variable arrangement formulation is developed, i.e. all dependent variables such as pressure and velocity are stored at cell centers. For both convective and diffusive fluxes the forms superior to both accuracy and stability are particularly adopted and formulated through a systematic study on the existing approximation ones. Gradients required for the evaluation of diffusion fluxes and for second-order-accurate convective operators are computed by using a linear reconstruction based on the divergence theorem. Momentum interpolation is used to prevent the pressure checkerboarding and a segregated solution strategy is adopted to minimize the storage requirements with the pressure-velocity coupling by the SIMPLE algorithm. An algebraic solver using iterative preconditioned conjugate gradient method is used for the solution of linearized equations. The flow analysis code (PowerCFD) developed by the present method is evaluated for its application to several 2-D structured-mesh benchmark problems using a variety of unstructured quadrilateral and triangular meshes. The present flow analysis code by using unstructured grids with the cell-centered method clearly demonstrate the same accuracy and robustness as that for a typical structured mesh.
Analysis and Comparison of Noncoherent Code Tracking Loops for DS-CDMA Systems
[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.1 No.1 1997 pp.70-80
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 CDMA 이동전파 환경에서 두 가지 비동기식 동기 추적 회로 즉, TCTL과 MCTL의 성능을 비교, 분석한다. 먼저, 두 가지 방식에 대해 안정 상태에서의 지터 분산을 펄스 성형 필터, 타이밍 오프셋, 신호 대 잡음 비 및 루우프 대역폭의 함수로 이론적으로 유도한다. 또한, 루우프 필터의 설계 방법에 대해 2차 동기 추적회로를 중심으로 고찰한다. 끝으로, 동기 추적 오차에 의한 BER 성능 저하를 ETRI 에 의해 IMT-2000용으로 설계된 CDMA 시스템의 역방향 링크에 대해 분석한다.
In this paper, the performances of two noncoherent code tracking loops, i. e., traditional code tracking loop(TCTL) and modified code tracking loop(MCTL) are analyzed and compared in a CDMA mobile environment. Closed-form formulas for steady-state jitter variance are derived analytically for the two schemes as a function of the pulse shaping filter, timing offset, signal-to-interference ratio, and loop bandwidth. The design issues of the loop filter are also addressed with emphasis on the second-order tracking loop. Finally, the degradation of BER performance due to timing errors is examined in a CDMA reverse link for IMT-2000 designed by ETRI.
A Semiotic Analysis on the Awareness Advertising Code - Focusing on Absolut Advertising
한국일러스트레이션학회 일러스트레이션 포럼 vol.5 2002.12 pp.113-129
※ 기관로그인 시 무료 이용이 가능합니다.
5,100원
Linguistic Analysis of Korean- English Code-Switching in K-Pop Lyrics KCI 등재후보
한국언어연구학회 언어학연구 제17권 1호 2012.04 pp.137-160
※ 기관로그인 시 무료 이용이 가능합니다.
6,100원
The present study is to examine the nature of morpho-syntactic characteristics of code-switching in K-Pop lyrics and its intelligibility. For this purpose, this study adopts the Matrix Language Frame model (MLF model) to analyze specific switches between the English and Korean language. The qualitative analysis of code switching found in CPs (Projection of Complimentizer: a unit of analysis) shows the use of nativized English affecting the intelligibility of lyrics. The results of analysis also indicate that the MLF model and its two principals, the System Morpheme principal and the Morpheme Order principal, account for the code-switching in K-pop lyrics. Moreover, the switches display the development of nativized variety of English in Korean society.
[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.6 No.12 2006 pp.155-162
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Code Red와 같은 인터넷 웜이 얼마나 심각하게 우리들 일상생활에 영향을 미쳤는지 잘 알려져 있다. 오늘날 인터넷의 고속화와 함께 이러한 웜의 피해는 단기간 내에 발생할 것이 자명하다. 따라서 이러한 웜에 대항하기 위해서 웜의 전파 특성을 분석하는 것이 무엇보다 중요하다. 본 논문에서는 컴퓨터 시뮬레이션을 통해 Code Red 웜의 전파 특성을 분석한다. 특히 Code Red웜 감염 호스트 수에 관한 기존 시뮬레이션 연구 결과가 관측된 자료와 매칭되지 않음을 보이고 이를 해결하기 위해 개선된 시뮬레이션 환경을 제시하였다. 또한 웜에 대한 초기 대응과 감염에 따른 대응이 웜의 전파 속도 변화에 어떠한 영향을 미치는지 그 결과를 보였다.
It was well known that how much seriously the Internet worm such as the Code Red had an effect on our daily activities. Recently the rapid growth of the Internet speed will produce more swift damage us in a short term period. In order to defend against future worm, we need to understand the propagation pattern during the lifetime of worms. In this paper, we analyze the propagation pattern of the Code Red worm by a computer simulation. In particular, we show that an existing simulation result about the number of infectious hosts does not match the observed data, and then we introduce a factor of revised human countermeasures into the simulation. We also show the simulation results presenting the importance of patching and pre-patching of the Internet worm.
IEEE 754 부동 소수점 32비트 float 변수의 Morton Code 변환 분석
[Kisti 연계] 한국디지털콘텐츠학회 디지털콘텐츠학회 논문지 Vol.17 No.3 2016 pp.165-172
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
GPU 기반 병렬처리에서 대규모 데이터의 인접 정보 검색(nearest neighbor search)에서 Morton code의 역할이 점점 더 중요하게 부각되고 있으며 그 응용 사례도 점차 증가하고 있다. 본 논문에서는 Tero Karras가 제안한 float 형 변수에 기반한 $[0,1]^3$ 공간 내의 3차원 기하 정보를 32비트 unsigned int형 Morton code로 변경하는 기존의 방법을 논의하고 그 기하학적인 의미를 분석함으로써, 보다 높은 해상도를 구현할 수 있는 64비트 unsigned long long형의 Morton code 변환 알고리듬을 제안한다. 제안하는 알고리듬은 GPU에서 구현되었을 때 CPU에서 실행하는 것보다 약 1000배 수준의 성능 향상을 달성한다.
Morton codes play important roles in many parallel GPU applications for the nearest neighbor (NN) search in huge data and queries with its applications growing. This paper discusses and analyzes the meaning of Tero Karras's 32-bit 'unsigned int' Morton code algorithm for three-dimensional spatial information in $[0,1]^3$ and its geometric implications. Based on this, this paper proposes 64-bit 'unsigned long long' version of Morton code and compares the results in both CPU vs. GPU and 32-bit vs. 64-bit versions. The proposed GPU algorithm runs around 1000 times faster than the CPU version.
Deflate 압축 알고리즘에서 악성코드 주입 취약점 분석
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.5 2022 pp.869-879
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구를 통해 매우 대중적인 압축 알고리즘인 Deflate 알고리즘을 통해 생성되는 3가지 유형의 압축 데이터 블록 가운데 원본 데이터 없는 비 압축 블록(No-Payload Non-Compressed Block;NPNCB) 유형을 임의로 생성하여 정상적인 압축 블록 사이에 미리 설계된 공격 시나리오에 따라 삽입하는 방법을 통해 악의적 코드 또는 임의의 데이터를 은닉하는 취약점을 발견하였다. 비 압축 블록의 헤더에는 byte align을 위해서만 존재하는 데이터 영역이 존재하며, 본 연구에서는 이 영역을 DBA(Disposed Bit Area)라고 명명하였다. 이러한 DBA 영역에 다양한 악성 코드와 악의적 데이터를 숨길 수 있었으며, 실험을 통해 정상적인 압축 블록들 사이에 오염된 블록을 삽입했음에도 기존 상용 프로그램에서 정상적으로 경고 없이 압축 해제 되었고, 악의적 디코더로 해독하여 악성 코드를 실행할 수 있음을 보였다.
Through this study, we discovered that among three types of compressed data blocks generated through the Deflate algorithm, No-Payload Non-Compressed Block type (NPNCB) which has no literal data can be randomly generated and inserted between normal compressed blocks. In the header of the non-compressed block, there is a data area that exists only for byte alignment, and we called this area as DBA (Disposed Bit Area), where an attacker can hide various malicious codes and data. Finally we found the vulnerability that hides malicious codes or arbitrary data through inserting NPNCBs with infected DBA between normal compressed blocks according to a pre-designed attack scenario. Experiments show that even though contaminated NPNCB blocks were inserted between normal compressed blocks, commercial programs decoded normally contaminated zip file without any warning, and malicious code could be executed by the malicious decoder.
정적 오염 분석을 활용한 타입스크립트 코드의 보안 취약점 탐지
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.31 No.2 2021 pp.263-277
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
자바스크립트로 작성된 웹 어플리케이션에서 Cross-Site Scripting (XSS), SQL Injection과 같은 검증되지 않은 사용자 입력 데이터로 인해 발생하는 취약점을 탐지하기 위해 오염 분석 기법이 널리 사용되고 있다. 이러한 취약점을 탐지하기 위해서는 사용자 입력 데이터에 영향을 받는 변수들을 추적하는 것이 중요하지만, 자바스크립트의 동적인 특성으로 인해 웹 어플리케이션을 실행해 보지 않고 그러한 변수들을 식별하는 것은 매우 어렵다. 때문에, 기존의 오염 분석 도구들은 대상 어플리케이션을 실행하는 오버헤드가 존재하는 동적 오염 분석을 사용하도록 개발되었다. 본 논문에서는 타입스크립트(자바스크립트의 상위집합) 컴파일러를 활용해 얻은 심볼 정보를 기반으로 데이터의 흐름을 정확히 추적하고, 타입스크립트 코드에서 보안 취약점을 발견하는 새로운 정적 오염 분석 기법을 제안하였다. 제안한 기법은 개발자가 검증되지 않은 사용자 입력 데이터를 포함할 수 있는 변수에 표시를 할 수 있도록 하며, 이를 활용해 사용자 입력 값에 영향을 받는 변수와 데이터를 추적한다. 제안한 기법은 TypeScript 컴파일러에 원활히 통합될 수 있기 때문에, 별도의 도구로 작동하는 기존 분석 도구와 달리 개발자가 개발 과정에서 취약점을 발견할 수 있게 한다. 제안한 기법의 유효성을 확인하기 위해 프로토타입을 구현하였으며, 취약점이 보고된 8개의 웹 어플리케이션을 선정하여 분석을 수행하여 성능을 평가한 결과 기존의 취약점을 모두 탐지할 수 있음을 확인하였다.
Taint analysis techniques are popularly used to detect web vulnerabilities originating from unverified user input data, such as Cross-Site Scripting (XSS) and SQL Injection, in web applications written in JavaScript. To detect such vulnerabilities, it would be necessary to trace variables affected by user-submitted inputs. However, because of the dynamic nature of JavaScript, it has been a challenging issue to identify those variables without running the web application code. Therefore, most existing taint analysis tools have been developed based on dynamic taint analysis, which requires the overhead of running the target application. In this paper, we propose a novel static taint analysis technique using symbol information obtained from the TypeScript (a superset of JavaScript) compiler to accurately track data flow and detect security vulnerabilities in TypeScript code. Our proposed technique allows developers to annotate variables that can contain unverified user input data, and uses the annotation information to trace variables and data affected by user input data. Since our proposed technique can seamlessly be incorporated into the TypeScript compiler, developers can find vulnerabilities during the development process, unlike existing analysis tools performed as a separate tool. To show the feasibility of the proposed method, we implemented a prototype and evaluated its performance with 8 web applications with known security vulnerabilities. We found that our prototype implementation could detect all known security vulnerabilities correctly.
코드패치 및 하이브리드 분석 환경을 활용한 악성코드 데이터셋 추출 프레임워크 설계
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.34 No.3 2024 pp.403-416
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
악성코드는 금전적인 목적에 의하여 서비스의 한 형태로 블랙마켓에 판매되고 있다. 판매에 따른 수요가 증가함에 따라 악성코드를 통한 공격이 확장되었다. 이에 대응하기 위해 인공지능을 활용한 탐지 및 분류 연구들이 등장하였지만, 공격자들은 분석을 방지하고자 다양한 안티 분석기술을 악성코드에 적용하고 있다. 본 논문에서는 안티 분석 기술이 적용된 악성코드들로부터 데이터셋을 확보하기 위해 하이브리드형 바이너리 분석 프레임워크 Malware Analysis with Dynamic Extraction(MADE)을 제안한다. MADE 프레임워크는 Anti-VM, Anti-Debugging이 적재된 바이너리를 포함하여 자동화된 동적 분석을 수행할 수 있다. MADE 프레임워크는 Anti-Analysis 기술이 적용된 다양한 악성코드들에 대해 90% 이상 우회가 가능하며, API 호출 정보를 포함한 데이터셋 추출이 가능함을 실험을 통해 검증하였다.
Malware is being commercialized and sold on the black market, primarily driven by financial incentives. With the increasing demand driven by these sales, the scope of attacks via malware has expanded. In response, there has been a surge in research efforts leveraging artificial intelligence for detection and classification. However, adversaries are integrating various anti-analysis techniques into their malware to thwart analytical efforts. In this study, we introduce the "Malware Analysis with Dynamic Extraction (MADE)" framework, a hybrid binary analysis tool devised to procure datasets from advanced malware incorporating Anti-Analysis techniques. The MADE framework has the proficiency to autonomously execute dynamic analysis on binaries, encompassing those laden with Anti-VM and Anti-Debugging defenses. Experimental results substantiate that the MADE framework can effectively circumvent over 90% of diverse malware implementations using Anti-Analysis techniques and can adeptly extract relevant datasets.
도로교설계기준(한계상태설계법)의 콘크리트부재 설계를 위한 재료계수 결정법 및 신뢰도 분석
[Kisti 연계] 대한토목학회 대한토목학회논문집 Vol.39 No.1 2019 pp.13-24
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
이 연구에서는 국내 도로교 한계상태설계법에서 콘크리트부재의 설계를 위하여 적용하고 있는 재료계수의 문제점을 제기하고, 잘 정립된 최적화 과정에 의한 재료계수를 제안하였다. 신뢰도분석을 통하여 현 설계기준의 하중계수와 제안 재료계수가 목표신뢰도지수 보다 높은 신뢰도수준을 확보하고 있음을 보이고, 역신뢰도해석을 통하여 목표신뢰도지수를 잘 근사할 수 있는 하중계수를 제시하였다. 유로코드에서 제시하고 있는 기본 개념에 근거하여 신뢰도기반 하중-재료계수 결정법을 정식화하였다. 제안된 접근법이 신뢰도개념에 의하여 유도되었지만, 이 접근법에 의하여 계산된 하중-재료 계수가 목표신뢰도지수를 정확히 만족시키지 못하는 요인으로서 재료와 부재간에 존재하는 불확실성의 차이를 지적하고, 이러한 차이를 고려하지 않는 유로코드의 개념적 문제점을 제기하였다.
This paper brings up fallacy of material factors specified for the design of concrete members in the current Korean limit state design code for highway bridges, and proposes new material factors based on a robust optimization scheme to overcome the fallacy. It is shown that the current load factors in the code and the proposed material factors lead to a much higher reliability index than the target index. The load factors are adjusted to yield the target reliability index using the inverse reliability analysis. A reliability-based approach following the basic concept of Eurocode is formulated to determine material factors as well as load factors. The load-material factors obtained by the proposed reliability-based approach yield a lower reliability level than the target index. Drawbacks of the basic concept of Eurocode are discussed. It is pointed out that differences in the uncertainties between materials and members may cause the lower reliability index of concrete member than the target.
2세대 PT(Processor Trace)를 이용한 동적 코드분석 방법 연구 KCI 등재
한국융합보안학회 융합보안논문지 제19권 제1호 2019.03 pp.97-101
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
운영 체제의 코어에 Intel PT가 포함된 경우, 크래시 발생 시 디버거는 프로그램 상태를 검사할 수 있을 뿐만 아니라 크래 시를 발생시킨 제어 플로우를 재구성할 수 있다. 또한, 커널 패닉 및 기타 시스템 정지와 같은 상황을 디버그하기 위해 실행 트레이스 범위를 전체 시스템으로 확장할 수도 있다. 2세대 PT인 WinIPT 라이브러리는 Windows 10 (버전 1809/Redstone 5) 에서 제공하는 IOCTL 및 레지스트리 메커니즘을 통해 프로세스 별 및 코어 별 트레이스를 실행할 수 있는 추가 코드가 포함 된 Intel PT 드라이버를 포함하고 있다. 즉 기존 1세대 PT에서 비정규화된 방식으로만 제한적인 접근이 가능했던 PT 트레이 스 정보를 2세대 PT에서는 운영 체제에서 제공하는 IOCTL 및 레지스트리 메커니즘을 통해 프로세스 별 및 코어 별 트레이 스를 실행할 수 있게 되었다. 본 논문에서는 1/2세대 PT를 이용하여 윈도우 환경에서 PT 데이터 패킷의 수집·저장·디코딩 및 악성코드 검출을 위한 방법을 비교·설명하였다.
If the operating system's core file contains an Intel PT, the debugger can not only check the program state at the time of the crash, but can also reconfigure the control flow that caused the crash. We can also extend the execution trace scop e to the entire system to debug kernel panics and other system hangs. The second-generation PT, the WinIPT library, inc ludes an Intel PT driver with additional code to run process and core-specific traces through the IOCTL and registry mec hanisms provided by Windows 10 (RS5). In other words, the PT trace information, which was limited access only by the first generation PT, can be executed by process and core by the IOCTL and registry mechanism provided by the operatin g system in the second generation PT. In this paper, we compare and describe methods for collecting, storing, decoding an d detecting malicious codes of data packets in a window environment using 1/2 generation PT.
[Kisti 연계] 한국디지털콘텐츠학회 디지털콘텐츠학회 논문지 Vol.19 No.7 2018 pp.1357-1363
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
정보 기술의 발전과 더불어 인공 지능 및 기계 학습 분야는 다양한 응용 분야에서 성능을 인정받고 있으며, 다양한 응용 분야로 확대되고 있다. 본 논문에서는 기계 학습 방법을 응용한 소프트웨어 분석 방법을 제안한다. 소프트웨어의 특성을 표현하기 위해 소프트웨어의 코드 분포를 분석하고 이 정보를 기계 학습 방법인 선형 회귀를 통해 분석함으로써 유사 소프트웨어를 분석할 수 있는 방법을 제안한다. 소프트웨어의 특성은 프로그램 내에 포함된 명령어에 의해 표현될 수 있으며, 명령어의 분포 정보를 학습 데이터로 활용하였다. 또한, 학습 데이터를 통한 학습 과정은 소프트웨어 유사성 분석을 위한 선형 회귀 모델을 구성한다. 본 논문에서 제안한 방법은 구현 및 실험을 통해 정확성을 검증한다. 본 논문에서 제안한 방법은 소프트웨어의 유사성을 판단할 수 있는 기본 기술로 활용될 수 있을 것으로 기대된다. 또한 기계 학습 방법을 통한 소프트웨어 분석 기술에 응용될 수 있을 것으로 기대된다.
In addition to advances in information technology, machine learning approach is applied to a variety of applications, and is expanding to a variety of areas. In this paper, we propose a software analysis method that applies linear regression to analyse software similarity from the code distribution of the software. The characteristics of software can be expressed by instructions contained within the program, so the distribution information of instructions is used as learning data. In addition, a learning procedure with the learning data generates a linear regression model for software similarity analysis. The proposed method is evaluated with real world Java applications. The proposed method is expected to be used as a basic technique to determine similarity of software. It is also expected to be applied to various software analysis techniques through machine learning approaches.
한국 상담 윤리강령에서 다양성 존중 가치 향상을 위한 국제 비교 연구
[NRF 연계] 한국상담심리학회 한국심리학회지: 상담 및 심리치료 Vol.33 No.1 2021.02 pp.1-27
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
한국 사회는 단일민족을 강조하던 사회에서 점차 다른 인종, 민족, 성적 지향성, 종교 등을 가진 개인들이 모인 다문화 사회로 진입하였으며 심리상담 분야에서도 내담자의 다양성이 중요한 문제로 떠올랐다. 본 논문은 각기 다른 문화적 배경을 가진 내담자를 이해하고 존중하는 것의 중요성을 인지하고, 앞으로 심리상담 분야에서 다양성에 대한 논의를 활성화시키기 위해 관련 윤리강령의 제시가 필요하다고 보았다. 그리하여 미국과 캐나다의 상담 윤리강령을 1) 비밀보장, 2) 사전 동의, 3) 선물, 4) 상담종결 및 의뢰, 5) 수퍼비전 6) 심리 평가 영역에서 한국의 것과 비교 분석하였다. 이를 바탕으로 한국의 다양성 관련 윤리강령이 나아가야 할 방향성을 제시하였다. 첫째, 비밀보장, 종결 및 의뢰, 수퍼비전 등에서 문화적 배경과 관련된 내용이 확대되어야 하며 둘째로는 한국의 문화적 특수성과 세계적 보편성을 고려한 윤리강령의 정립이 필요함을 주장하였다. 마지막으로는 다양성 존중을 기반으로 상담 윤리강령의 원칙 정립의 중요성을 언급하였다.
Korea has transformed into a multicultural society with increased diversity in race, ethnicity, sexual orientation, and religion. Although client diversity has emerged as an important issue in counseling psychology, there is a lack of discussion on the matter. Acknowledging the importance of respecting clients’ diversity, the authors propose that the consideration of diversity in the counseling code of ethics should be strengthened. The authors compared the counseling codes of ethics in Korea, the United States, and Canada in the areas of confidentiality, informed consent, receiving gifts, termination and referral, supervision, and evaluation and assessment. Next, recommendations for the Korean counseling code of ethics are presented. Specifically, diversity should be emphasized in areas such as confidentiality, termination and referral, and supervision. Additionally, Korea should consider cultural specificity and universality when strengthening its counseling code of ethics. Lastly, fundamental principles of this code of ethics should be established based on diversity.
C언어 소스코드 보안 취약점 탐지를 위한 LSTM 딥러닝 하이브리드 모델의 성능 비교 분석: GNN, CNN, GRU
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.3 2026 pp.949-958
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
C언어의 메모리 직접 접근 특성으로 발생하는 보안 취약점 탐지를 위해, 본 논문은 LSTM의 한계를 보완하는 하이브리드 딥러닝 모델들을 비교 분석하였다. LSTM을 기반으로 CNN, GRU, GNN을 각각 결합한 모델들을 소스코드에 적용하였으며, 탐지 성능을 다각도로 분석하기 위해 클래스 불균형 조건에서 성능을 실험적으로 평가하였다. 실험 결과, 소스코드의 전역적 문맥과 CPG(코드 속성 그래프) 기반의 구조적 정보를 적응형 게이트(Adaptive Gate)로 융합한 LSTM-GNN 모델('CPGate Keeper' 프레임워크)이 가장 뛰어난 성능을 보였다. 이를 통해 구조 중심적 하이브리드 접근법이 LSTM 경로가 추출한 '문맥 정보'와 GNN이 추출한 '구조적 특징' 중 탐지에 더 결정적인 요소가 무엇인지 모델이 스스로 판단하게 노이즈와 오탐을 최소화할 수 있다.
This paper compared and analyzed hybrid deep learning models that complement the limitations of LSTM in order to detect security vulnerabilities arising from the direct access characteristics of memory in C language. Based on LSTM, models that combine CNN, GRU, and GNN were applied to the source code, and the performance was experimentally evaluated under class imbalance conditions to analyze the detection performance from various angles. As a result of the experiment, the LSTM-GNN model ('CPGate Keeper' framework), which combines the global context of the source code and structural information based on CPG (code attribute graph) with an adaptive gate, showed the best performance. Through this, the structure-oriented hybrid approach can minimize noise and false positives so that the model can judge for itself what is more decisive in detection among the 'contextual information' extracted by the LSTM path and the 'structural features' extracted by GNN.
LS-DYNA를 이용한 자동차 승객용 에어백 모듈의 헤드 충격 해석
[Kisti 연계] 한국정밀공학회 한국정밀공학회지 Vol.23 No.12 2006 pp.88-94
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this study, the dynamic impact analysis for the passenger air-bag(PAB) module has been carried out by using FEM to predict the dynamic characteristics of vehicle ride safety against head impact. The impact performance of vehicle air-bag is directly related to the design parameters of passenger air-bag module assembly, such as the tie bar bracket's width and thickness, respectively, However, the product's design of PAB module parameters are estimated through experimental trial and error according to the designer's experience, generally. Therefore, the dynamic analysis of head impact test of the passenger air-bag module assembly of automobile is needed to construct the analytical methodology At first, the FE models, which are consist of instrument panel, PAB Module, and head part, are combined to the whole module system. Then, impact analysis is carried out by the explicit solution procedure with assembled FE model. And the dynamic characteristics of the head impact are observed to prove the effectiveness of the proposed method by comparing with the experimental results. The better optimized impact performance characteristics is proposed by changing the tie bracket's width md thickness of module. The proposed approach of impact analysis will provides an efficient vehicle to improve the design quality and reduce the design period and cost. The results reported herein will provide a better understanding of the vehicle dynamic characteristics against head impact.
4,000원
최근 다양한 형태의 악성코드 등장으로 인해 기존의 정적 분석은 많은 한계를 노출하고 있다. 정적분석 은 (악성)코드를 실제로 실행하지 않고 원시 코드나 목적 코드를 가지고 코드나 프로그램의 구조를 분석 하는 것을 의미한다. 한편 정보보안 분야에서의 동적 분석이란 일반적으로 (악성)코드를 직접 실행하여 분석하는 형태로 프로그램의 실행 플로우를 파악하기 위해 (악성)코드의 실행 전후 상태를 비교·조사하여 분석하는 형태를 의미한다. 그러나 동적 분석을 위해서는 막대한 양의 데이터와 로그를 분석해야 하며 모 든 실행 플로우를 실제로 저장하기도 어려웠다. 본 논문에서는 윈도우 환경(윈도우 10 R5 이상)에서 2세 대 PT를 기반으로 악성코드 탐지 및 실시간 다중 동적 분석을 수행하는 시스템의 전처리기 구조를 제안 하였고 이를 구현하였다.
Recently, due to the appearance of various types of malware, the existing static analysis expose s many limitations. Static analysis means analyzing the structure of a code or program with sourc e code or object code without actually executing the (malicious) code. On the other hand, dynamic analysis in the field of information security generally refers to a form that directly executes and a nalyzes (malware) code, and compares and examines and analyzes the state before and after execu tion of (malware) code to grasp the execution flow of the program. However, dynamic analysis req uired analyzing huge amounts of data and logs, and it was difficult to actually store all execution flows. In this paper, we propose and implement a preprocessor architecture of a system that performs malware detection and real-time multi-dynamic analysis based on 2nd generation PT in Windows environment (Windows 10 R5 and above).
자체 수정 코드를 탐지하는 정적 분석방법의 LLVM 프레임워크 기반 구현 및 실험
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.2 2022 pp.171-179
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
자체 수정 코드(Self-Modifying-Code)란 실행 시간 동안 스스로 실행 코드를 변경하는 코드를 말한다. 이런 기법은 특히 악성코드가 정적 분석을 우회하는 데 악용된다. 따라서 이러한 악성코드를 효과적으로 검출하려면 자체 수정 코드를 파악하는 것이 중요하다. 그동안 동적 분석 방법으로 자체 수정 코드를 분석해왔으나 이는 시간과 비용이 많이 든다. 만약 정적 분석으로 자체 수정 코드를 검출할 수 있다면 악성코드 분석에 큰 도움이 될 것이다. 본 논문에서는 LLVM IR로 변환한 바이너리 실행 프로그램을 대상으로 자체 수정 코드를 탐지하는 정적 분석 방법을 제안하고, 자체 수정 코드 벤치마크를 만들어 이 방법을 적용했다. 본 논문의 실험 결과 벤치마크 프로그램을 컴파일로 변환한 최적화된 형태의 LLVM IR 프로그램에 대해서는 설계한 정적 분석 방법이 효과적이었다. 하지만 바이너리를 리프팅 변환한 비정형화된 LLVM IR 프로그램에 대해서는 자체 수정 코드를 검출하기 어려운 한계가 있었다. 이를 극복하기 위해 바이너리를 리프팅 하는 효과적인 방법이 필요하다.
Self-Modifying-Code is a code that changes the code by itself during execution time. This technique is particularly abused by malicious code to bypass static analysis. Therefor, in order to effectively detect such malicious codes, it is important to identify self-modifying-codes. In the meantime, Self-modify-codes have been analyzed using dynamic analysis methods, but this is time-consuming and costly. If static analysis can detect self-modifying-code it will be of great help to malicious code analysis. In this paper, we propose a static analysis method to detect self-modified code for binary executable programs converted to LLVM IR and apply this method by making a self-modifying-code benchmark. As a result of the experiment in this paper, the designed static analysis method was effective for the standardized LLVM IR program that was compiled and converted to the benchmark program. However, there was a limitation in that it was difficult to detect the self-modifying-code for the unstructured LLVM IR program in which the binary was lifted and transformed. To overcome this, we need an effective way to lift the binary code.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.