년 - 년
Security systems design for mis / oa related with computer network
한국경영정보학회 한국경영정보학회 정기 학술대회 2000 MIS/OA International Conference 2000.06 pp.205-208
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
국방 사이버 침해 대응을 위한 전산보안점검 프로그램 및 사용자 진단항목 개선 연구(육군 중심) KCI 등재
한국융합보안학회 융합보안논문지 제17권 제2호 2017.06 pp.101-108
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 해킹, 바이러스 등 대한민국을 노린 공격이 증가하고 있다. 이와 마찬가지로 우리 군도 사이버 침해에 대한 노출이 심해지고 있으며 이를 대응하기 위해 국방부는 사이버 안보에 대한 기본절차를 규정하고 지침을 제공하고 있다. 그럼에도 불구하고 육군에서 발간하는 사이버방호작전 분석결과를 보면 침해건수는 점점 증가하고 있다. 이에 대한 문제점들을 개선하고자 사이버 침해 대응을 위해 가장 중요하면서 기본인 사용자 환경에서의 전산보안 점검항목을 재점검하여 안전하고 효율적인 전산보안 점검항목을 제시한다.
Recent cyber attacks on South Korea, including hacking and viruses, are increasing significantly. To deal with the cybe r invasion of cyber aggression, the Ministry of National Defense defined the necessary procedures for cyber security with guidelines for cyber security. In spite of, based on the analyses the cyber defense operations published, the number of viol ations are increasing. To address issues stated above, the safety check items should be reviewed and revised. This paper will revisit current safety check items and provide new guidelines to prevent cyber security breaches, which will provide more safe and efficient cyber environment.
신뢰성이론을 바탕으로 한 통합 컴퓨터 보안 모형에 관한 연구 KCI 등재
한국경영정보학회 Asia Pacific Journal of Information Systems 제12권 제1호 2002.03 pp.123-138
※ 기관로그인 시 무료 이용이 가능합니다.
4,900원
4,000원
ICT 기술이 다양한 교육 분야에 적용되고 있지만 교육 평가 분야에 적용은 제한적이다. 컴퓨터 기반 평가는 기존의 지필 평가에 비해 시간적/공간적 제약을 넘어서는 장점을 가지며 있지만 시험 당사자들의 부정행위에 취약하다. 본 논문에서는 컴 퓨터 기반 평가의 보안성을 강화하기 위하여 실시간 모니터링 및 프로세스 관리 방안을 제안한다. 제안된 방식에서는 시험 화 면을 주기적으로 캡처하여 교수 화면에 표시하여 실시간 감시가 가능하도록 하고 부정행위에 사용될 프로세스를 시험 전에 차단할 수 있도록 한다. 많은 학생들의 화면을 실시간으로 감시하기 위해서는 캡처된 원본 이미지의 효과적인 압축이 중요하 다. 이를 위하여 이미지 압축 모듈의 사용, 해상도 약화, 재 압축의 3단계 압축 방식을 적용하였다. 이를 통하여 약 6MB의 원 본 이미지를 약 3.8KB의 저장 이미지로 변환하였다. 부정 프로세스 차단 기능을 위하여 윈도우즈 API를 이용한 프로세스 추 출 및 관리 기능을 사용하였다. 새로운 보안 강화 방안이 적용된 본 논문의 컴퓨터 기반 평가 시스템이 기존의 컴퓨터 기반 평가 시스템과의 보안 관련 기능 비교를 통하여 우수함을 보여준다.
ICT technology has been applied to various educational fields, but applying to educational test field is limited. Computer-based test (CBT) can overcome temporal and spatial constraints of conventional paper-based test, but is vulnerable to fraud by test parties. In this paper, we propose real-time monitoring and process management methods to enhance the security of CBT. In the proposed methods, the test screens of students are periodically captured and transferred to the professor screen to enable real-time monitoring, and the possible processes used for cheating can be blocked before testing. In order to monitor the screen of many students in real time, effective compression of the captured original image is important. We applied three-step compression methods: initial image compression, resolution reduction, and re-compression. Through this, the original image of about 6MB was converted into the storage image of about 3.8KB. We use the process extraction and management functions of Windows API to block the processes that may be used for cheating. The CBT system of this paper with the new security enhancement methods shows the superiority through comparison of the security related functions with the existing CBT systems.
4,300원
대학 전산망에서의 외부 침입에 적합한 대응을 위한 보안관제 기술 연구
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제4권 제1호 통권 제5호 2014.06 pp.23-39
※ 기관로그인 시 무료 이용이 가능합니다.
5,100원
정보의 양이 급격히 증가함에 따라 정보에 대한 관리 및 보안 취약점들이 다 양하게 존재하게 되었다. 뿐만 아니라 대학의 경우 다수의 IT자원에 대비하여 관 리 인력이 부족함에 따라서 외부의 위협에 대처할 수 있는 방안이 부족한 실정 이다. 따라서 본 연구에서는 보안 에이전트 도입을 통해서 소수의 보안 담당자 만으로도 효과적으로 보안 관제를 수행할 수 있는 환경을 마련한다. 또, 좀비 PC의 발생에 대처하기 위한 좀비PC탐지 기법과 외부 침입 탐지 및 방지 기술을 조합하여 대학 환경에 적합한 보안관제 방안을 제시한다. 주제어: 보안관제,
With the rapid increase of information, the security vulnerability are emerging issue in information management. In addition, coverage of security monitoring services in university is so large, but they have the problem of the lack of administrative staff. This paper suggests the appropriate solutions against external cyber-attacks. They are anti-virus solutions, detections of zombie PC and the intruder detections and preventions.
북한의 ICT 발전전략의 미래경향성에 관한 연구 : 텍스트마이닝 기법을 중심으로 KCI 등재
한국평화연구학회 평화학연구 제23권 3호 2022.09 pp.67-93
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
본고의 목적은 북한의 과학기술 전문 학술지와 언론 보도 내용을 통해 북한의 ICT 산업 발전전략과 의의를 분석하고 평가하고자 한다. 1996년 최초로 김정일 위원장이 IT를 강조한 이후 2019년 말 김정은 위원장 집권 시기까지 22년 동안 발행된 과학원통보 160권에 게재된 논문을 대상으로 텍스트 마이닝(text mining) 기법을 활용해 북한의 ICT 정책 및 연구 동향을 분석하였다. ICT 관련 논문은 북한 경제의 각 부문이 ‘수자 경제’ 즉 ‘디지털경제’로의 전환을 강조하고 있다. 북한은 수자경제를 정의하고 해외 사례를 벤치마킹하는데 주력하고 있다. 워드 클라우드 분석 결과에서도 ‘보안’, ‘암호’에 대한 키워드 빈도수가 높게 나타났다. 실제 북한은 2011년 제정한 콤퓨터망관리법에 보안 관련된 규정을 갖추고 있다. 외부로부터 컴퓨터 보안을 강화 하는데 주력하고 있다. 김정은 위원장은 북한 경제에서 ICT, 나노 및 생물 바이오 등 첨단산업의 비중을 높 일 것을 지시했다. 텍스트 마이닝의 분석결과 김 위원장의 지시가 학술지에서 적극적으로 반영하였고 경제 정책의 핵심 화두가 되었다.
The purpose of this paper is to analyze and evaluate North Korea's ICT industry development strategy and significance through the contents of North Korean scientific and technological journals and media reports. North Korea’s ICT policy using text mining techniques for papers published in the 160th volume of Science Academy News published for 22 years from Chairman Kim Jong-il’s first emphasis on IT in 1996 until Chairman Kim Jong-un took office at the end of 2019 and research trends were analyzed. ICT-related papers emphasize the transition of each sector of the North Korean economy to a ‘number economy’, that is, a ‘digital economy’. North Korea is focusing on defining the water economy and benchmarking overseas cases. In the word cloud analysis result, the frequency of key words for 'security' and 'password' was also high. In fact, North Korea has security-related regulations in the Computer Network Management Act enacted in 2011. We are focusing on strengthening computer security from the outside. Chairman Kim Jong-un ordered to increase the share of high-tech industries such as ICT, Nano and biology in the North Korean economy. As a result of the analysis of text mining, Chairman Kim's instructions were actively reflected in academic journals and became a key topic of economic policy.
An Integrity Protection Model based on Trusted Recovery Technology SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.4 2016.04 pp.167-178
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
This paper firstly through IBAC, integration of TE and RBAC, the use of compensatory well-formed transaction is proposed, the integrity of the structure can be recovered partial malicious transaction monitoring machine model. In the partial revocation of constitutive affairs, for the operation of data and tracking the affected, with two recovery policies. Conservative recovery policy to stop system the recovery of normal transaction execution, by analyzing log file dependencies list, according to operation performed after first order, cancel each affected operation. Another optimistic recovery policy can be in the normal operation of the system at the same time, the establishment of compensation operation corresponding to the operation to recover, and submitted to the monitoring machine scheduling integrity. This method can recover the system to a secure state in the face of failures and improves the availability of the system. It provides an important exploration for the design and implementation of the trusted recovery mechanisms of high-level secure operating system.
Multiple Selective Regions Image Cryptography on Modified RC4 Stream Cipher
보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.7 No.3 2014.06 pp.189-198
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cryptography is the technique which is utilized for secure communication over the network. By using Cryptography technique readable information is converted into an unreadable form. Cryptography is used to protect data from unauthorized access. Universality of security in modern internet based application is an explicit motivation to contribute in the area of Information Security. Multimedia data contain different types of data that include text, audio, video, graphic, images. This paper gives an initiation of an amending technique for multiple selective region image cryptography based on both RC4 stream cipher and chaos. This approach is derived from the standard RC4 algorithm. But Currently RC4 is vulnerable. So for making image encryption technique more secure, we have proposed RC4 with chaos. We have shown that, our proposed method will boost image security over any type of network with several types of attack.
A New Fast and High Performance Intrusion Detection System SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.5 2013.09 pp.67-80
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The cyber-attacks represent one of the most dangerous secret weapons. Intrusion detection system is an important tool to protect our systems and networks against the various forms of attacks. The purpose of this paper is to build a fast and high performance hybrid hierarchical intrusion detection system called NFPHIDS that possesses the following characteristics: have a short training time, detect the low frequent attacks, give a high detection rate for frequent attacks, and give a low false alarm rate. NFPHIDS contains two levels. The first one includes four fast classifiers Random Forest, Simple Cart, Best first decision tree, Naive Bayes used for their excellent performance on the detection of respectively Normal behavior and DOS, Probe, R2L, and U2R. Only five outputs of the first level are selected, and used as inputs of the second level that contains Naïve Bayes as final classifier. The experimentation on KDD99 shows the high performance of our model compared to the results obtained by some well-known classifiers.
The Perception of Computer Security Focused on the Familiarity of Rootkits in Korea and Kazakhstan SCOPUS
보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.5 No.2 2011.04 pp.13-24
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
This study is designed with an eye toward possible solutions for potential threats from Rootkits and more traditional malware. The survey data were collected from 371 students of five korea and three Kazakhstan universities to compare their knowledge and experience with various forms of malware. They provide an empirical assessment of the cross-cultural similarities and differences between students in the two countries. The variables examined include knowledge of computer viruses, spyware, and rootkits as well as perceptions of the damage that can result from various computer malware. While the two groups are similar with respect to their relative familiarity of rootkits compared with that of spyware and viruses, and in terms of how they perceive the malware knowledge of their peers, they exhibit significant differences in self-reported perceptions of rootkit familiarity. Korean. students report higher levels for all tested malware types, including the fictional “Trilobyte” virus. These comparisons reveal that little is known about rootkits today. However, this study can bring awareness of Rootkits and promote to seek for possible solutions for Rootkits and other malwares attacks.
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.6 2014.12 pp.185-196
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
This paper aimed at the actual situation of the difficult of getting a lot of the training sample of the security computer network system in the distributed intrusion detection. In this paper, we studied how to increase the intrusion detection accuracy in the case of small samples, so that processing, maintenance and deal with the invasion of the network timely. In this paper, we proposed a new intrusion detection method based on improved SVM Co - training. The specific implementation process of the algorithm is presented. Through the simulation experiments based on the actual data showed that the method is effective. Apply this method to a classified computer network system, effectively realized the detection to outside intruders and internal intruder.
국제인공지능학회(구 한국인터넷방송통신학회) International Journal of Internet, Broadcasting and Communication Vol.16 No.1 2024.03 pp.169-175
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this paper, we introduce a novel approach to enhance document security by integrating Computer Generated Hologram(CGH) encryption technology with a system for document encryption, printing, and subsequent verification using a smartphone application. The proposed system enables the encryption of documents using CGH technology and their printing on the edges of the document, simplifying document verification and validation through a smartphone application. Furthermore, the system leverages highresolution smartphone cameras to perform online verification of the original document and supports offline document decryption, ensuring tamper detection even in environments without internet connectivity. This research contributes to the development of a comprehensive and versatile solution for document security and integrity, with applications in various domains.
Risk Assessment of Computer Network Security in Banks SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.4 2016.04 pp.1-10
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The importance of computer system security of banks can never be exaggerated. Conducting risk assessment of computer system security of banks can increase safety management and ensure normal operation. This paper firstly figures out risk assessment indexes for computer system security of banks through literature review and survey. Secondly, it uses AHP to confirm the weight of indicators and establishes five security levels. According to the judgment of experts, it finally establishes the risk assessment model for computer system security of banks.
The Risk Evaluation Research of Computer Network Security based on Grey Clustering SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.8 2016.08 pp.191-200
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
With the rapid development of science and technology and the network popularization, computer network security becomes a social problem. Based on the analysis of the main factors influencing the computer network security, the risk evaluation index system of computer network security is established. The analytic hierarchy process (AHP) is used to calculate the weight of each index. Through the common criteria to determine the grey clustering of computer network security risk, establishing the whitenization weight function of computer network security risk evaluation model, and then calculating the whitenization clustering coefficient and clustering vector of computer network security risk evaluation model, the evaluation results are finally obtained. The method is scientific and reasonable, combining subjective evaluation with objective calculation.
GABP Neural Network Algorithm Applied in Evaluation of Computer Network Security SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.12 2016.12 pp.377-388
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this paper, in order to assess the risk of network, network security assessment process being involved in the content in detail. The above-mentioned research-based support system platform security test and evaluate research of the safety situation assessment. Prediction subsystem detailed design and carry out the implementation. In this paper, network security issues, as a detailed study of neural networks knowledge. Focus on the evaluation methods and calculation rules of nerve network technology, it has been studied by specific examples. Calculation demonstrated the feasibility of neural network evaluation model through actual case, which pointed out the traditional methods. This paper focuses on the network security assessment based on neural network technology, extensive analysis of the proposed major modeling tool indicator system for network security analysis. The application of neural networks was a network security assessment and to optimize the network by genetic algorithm. The key parameter combination operated efficiency of neural networks to get better play.
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.5 2015.05 pp.141-152
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
It is possible for virtualization of desktop to dramatically reduce maintenance costs and improve the security using various virtualization techniques rather than previous desktop environments. Also, with blocking beforehand the information leakage caused by data centralization, it is easy to manage the information security. This desktop virtualization provides creation and duplication of data and standardized desktop environments using easy and fast virtualization works. So, it is possible to improve efficiency, stability, and fusibility of virtualization. In this paper, with the desktop virtualization, the power saving effects are obtained from 65,750(kW) to 7,300(kW) , which is from 480(w) to 50 (w) for using one desktop for 8 hours per a day. In addition, the 62 desktops and 62 monitors are combined to one operational server with 62 thin clients. As a result of this, the security is improved greatly by data centralization, which the user can access the main server as a thin client with given space.
The Evaluation Analysis of Computer Network Information Security based on FAHP SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.9 2016.09 pp.229-242
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Computer network information security has attracted much attention of the society. The importance of computer network information is widely accepted. According to the determined selection criterion of computer network information security evaluation indexes to choose 5 first-level evaluation indexes and 19 second-level evaluation indexes to construct the evaluation system of computer network information security, using the analytic hierarchy process (AHP) to determine the weight of each evaluation index, the evaluation results of computer network information security are divided into 5 levels, that is, very safe, safe, general, dangerous, very dangerous. Establishing the fuzzy comprehensive evaluation model, through the expert evaluation method to carry on the level evaluation, the computer network information security evaluation of Weifang University of Science and Technology is taken as an example to carry on the simulation calculation. The fuzzy comprehensive evaluation model of the computer network information security is professional, scientific, and reasonable, which could provide theoretical basis for the development of computer network.
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.1 2016.01 pp.21-30
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this paper, we discuss the current situation of the comprehensive computer ability of PE teachers in colleges, and find out deficiencies, then provide valuable theoretical basis for optimized development. A total of 122 PE teachers were selected as the research objects of the network questionnaire during July 2014 and December 2014, and we investigate related data of those teachers, by using reliability and validity test, we find out relationship between their ability to use computers and the basic information. The results shows that the P value of the comprehensive ability to use computers of PE teachers in colleges and universities is less than 0.01 by sex, region, age group, school age, title, educational background structure, highest level of papers published in the past 5 years and the highest level of completed topics within the past 5 year.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.