Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 74
No
1

방화벽 로그를 이용한 침입탐지기법 연구 KCI 등재

윤성종, 김정호

한국정보기술응용학회 JITAM Vol.13 No.4 2006.12 pp.141-153

※ 기관로그인 시 무료 이용이 가능합니다.

4,500원

According to supply of super high way internet service, importance of security becomes more emphasizing. Therefore, flawless security solution is needed for blocking information outflow when we send or receive data. Large enterprise and public organizations can react to this problem, however, small organization with limited work force and capital can"t. Therefore they need to elevate their level of information security by improving their information security system without additional money. No hackings can be done without passing invasion blocking system which installed at the very front of network. Therefore, if we manage isolation log effective, we can recognize hacking trial at the step of pre-detection. In this paper, it supports information security manager to execute isolation log analysis very effectively. It also provides isolation log analysis module which notifies hacking attack by analyzing isolation log.

2

리눅스 기반 침입 방지를 위한 로그 분석 방법 연구 KCI 등재

임성화, 이도현, 김점구

한국융합보안학회 융합보안논문지 제15권 제2호 2015.03 pp.33-41

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

보안성 향상을 위한 안전한 리눅스 시스템은 자료의 불법적인 유출과 위․변조를 막고 사용 원칙에 위배되는 행위의 추적을 위한 감사(audit)능력을 가지고 있어야 한다. 또한 시스템 관리 및 운영자의 책임과 사용자의 행위를 명확히 구 분 지울 수 있는 로그관리가 반드시 이루어 져야 할 것이다. 본 논문에서는 리눅스 시스템의 보안 로그를 분석하여 침 입차단 및 탐지에 활용하는 방법을 제안하였다. 이를 통해 시스템의 침입차단 상태와 침입탐지 상태, 그리고 파일 시스 템의 무결성 변화를 실시간 확인하여 신속히 시스템의 문제를 해결할 수 있어 시스템의 신뢰성 향상에 크게 기여하게 될 것이다.

A safe Linux system for security enhancement should have an audit ability that prohibits an illegal access and alt ernation of data as well as trace ability of illegal activities. In addition, construction of the log management and moni toring system is a necessity to clearly categorize the responsibility of the system manager or administrator and the u sers' activities. In this paper, the Linux system's Security Log is analyzed to utilize it on prohibition and detection of an illegal protrusion converting the analyzed security log into a database. The proposed analysis allows a safe manag ement of the security log. This system will contribute to the enhancement of the system reliability by allowing quick response to the system malfunctions.

3

4,000원

Especially, system security is very important in the ubiquitous environment. This paper proposes a protecting scheme for security policies in Firewall and intrusion detection system (IDS). The one-way hash function and the symmetric cryptosystem are used to make the protected rules for Firewalls and IDSs. The proposed scheme could be applied in diverse kind of defense systems which use rules.

4

통합보안 관리를 위한 침입대응 시스템 설계 KCI 등재후보

이창우, 손우용, 송정길

한국융합보안학회 융합보안논문지 제5권 제2호 2005.06 pp.51-56

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷의 사용자 증가와 네트워크 환경이 점점 복잡해지고 제공되는 서비스 및 사용자의 요구사항들이 다양해짐에 따라 안정적이고 효과적인 환경을 유지하기 위한 서비스 운용관리는 점점 어려워지고 있다. 또한 초창기 보안은 침입차단시스템에 국한되었지만, 최근에는 침입탐지시스템(IDS), 가상 사설망(VPN), 시스템 보안, 인증 등 관련 솔루션이 대거 등장함에 따라 통합관리가 중요시되어 지고 있다. 이런 문제를 해결하기 위해 제안한 본 로그 분석을 통한 침입 대응시스템은 로그 파일을 XML 형식으로 저장함으로써 XML의 장점인 로그 파일의 검색이 용이하고 빠르게 이루어 질 수 있으며, 데이터의 구조화에 따라 시스템의 로그 파일들을 통합 분석, 관리하는데 이점을 가질 수 있다. 또한, 본 논문에서 제안한 생성된 로그파일을 IP 주소에 의해 소트된 로그와 Port 번호에 의해 소트된 로그, 침입 유형에 의해 소트된 로그, 탐지 시간에 의해 소트된 로그 등 다양한 형태로 변환하기 때문에 다른 침입탐지시스템에서 생성된 로그 파일과 비교 분석이 가능하다.

Service operating management to keep stable and effective environment according as user increase and network environment of the Internet become complex gradually and requirements of offered service and user become various is felt constraint gradually. To solve this problem, invasion confrontation system through proposed this log analysis can be consisted as search of log file that is XML's advantage storing log file by XML form is easy and fast, and can have advantage log files of system analyze unification and manages according to structure anger of data. Also, created log file by Internet Protocol Address sort by do log and by Port number sort do log, invasion type sort log file and comparative analysis created in other invasion feeler system because change sort to various form such as do log by do logarithm, feeler time possible.

5

XML을 이용한 침입차단 로그 모니터링 시스템 설계 및 구현

김석훈, 손우용, 송정길

한국융합보안학회 융합보안논문지 제4권 제2호 2004.06 pp.9-15

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷은 본질적으로 신뢰할 수 없는 네트워크들의 집합체이다. 인터넷상에서는 정보의 흐름을 통제하기가 대단히 어렵기 때문에, 산재한 자원을 충분히 활용하면서 내부의 중요한 자원을 인터넷으로부터 보호해 줄 수 있는 보안문제가 심각하게 대두되고 있다. 최근 발생하는 바이러스 사고와 시스템 불법 침입에 대한 발생률이 과거보다 훨씬 높으며 다양해지고 있다. 이러한 시기에 불법 행동을 막기 위한 침입 차단에 대한 연구가 활발하게 진행 중이며 계속적인 발전을 하고 있다. 본 논문에서는 침입자의 불법 행동에 대한 로그 정보를 XML 포맷 형식에 맞추어 관리자에게 통보하고, 원격으로 제어 할 수 있는 침입 차단 시스템을 개발하여 관리측면에서 발생하는 문제점을 해결하고자 하였다.

The Internet is aggregate of trustless networks essentially Because the Internet is very difficult to control flowing of information, taking advantage of enough sporadic resource, security problem that can protect internal important stock from the Internet is risen seriously. Recently, virus accident and generation rate about system intrusion that happen become much higher and various than past. On these time, is progressing researcher for invasion cutout to keep away illegal act vigorouslyand do continuous development. In this paper, reporting administrator log information about invader's illegal act depending on XML format form, and I wished to solve problem that happen in administration side developing invasion interception system that can control to remote.

6

4,000원

In this paper, Wish to handle in priority about security of wishing to do data transmission between users specially among way to cope network service problems. Propose firewall that can solve problem of security between users for problematic solution, do so that can do smooth communication with network users sharing resource between each other safety in P2P environment. So that, users who is not given authority in network that consist through imperfect communication channel do not make a problem on security tapping, insertion and erasing of information, and rightful user through only firewall can use service.

7

이중 방화벽과 다중 필터링을 이용한 DDoS 차단 시스템 KCI 등재

조지호, 신지용, 이극

한국융합보안학회 융합보안논문지 제14권 제2호 2014.03 pp.65-72

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 논문에서는 DDoS 탐지를 위해 기존의 이중 방화벽에 다중 필터링 방법을 적용한다. 1차 방화벽에서는 외부에서 유입되는 패킷 경로를 분석하여 R-PA(Router Path Anlaysis) 패킷 필터링 알고리즘과 엄격한 홉 카운터 필터링을 적 용한다. 2차 방화벽에서는 1차 방화벽을 거쳐서 온 패킷의 데이터를 검사하여 정상적인 패킷과 비정상적인 패킷을 구분 하고, 패킷 트래픽이 사용자에게 할당 된 임계치를 초과하는지를 검사하여 DDoS 공격을 차단한다.

This paper proposes multi-filtering method on the double firewall to prevent DDoS attack. In the first firewall, R-PA filtering algorithm and rigid hop counter filtering method are applied by analyzing packet paths. In the second firewall, packets are examined to be distinguished abnormal from normal packets. Security policy system monitors each user sessions and if the traffic is over the threshold value, the system blocks that session for an assigned time.

8

본 논문에서는 클러스터링 알고리즘을 활용하여 과다 허용 방화벽 정책을 최적화 하는 방법을 제시 한다. 과다 허용 방화벽 정책의 트래픽 로그 데이터 1,698,420개를 클러스터링 알고리즘을 활용하여 효율적인 방화벽 정책을 도출하고 이를 시각화 및 성능 지표로 평가하였다. 이를 통해 특히 인력이 부 족한 네트워크 보안 관리 분야에서 적은 자원으로 보안 위험 감소에 기여할 수 있는 방안을 제시한다.

9

웹방화벽의 보안성 평가 기준의 구축 KCI 등재

이하용, 양효식

한국디지털정책학회 디지털융복합연구 제15권 제5호 2017.05 pp.197-205

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

웹방화벽이 정보유출방지 등의 웹 보안 기능을 효과적으로 제공하여 웹 애플리케이션 보안이라는 목표를 달성하기 위해서는 웹사이트 보안 강화와 안전한 서비스 제공이라는 목표를 달성할 수 있어야 한다. 따라서 관련된 표준을 근간으로 웹방화벽시스템의 보안성 평가를 체계적으로 수행할 수 있는 연구가 필요하다. 본 논문에서는 웹방화벽시스템의 기반 기술 과 웹방화벽의 보안성 품질에 관한 요구사항을 분석하고 소프트웨어 제품평가에 관한 국제표준과 정보보안 관련 제품의 평가에 관련된 표준을 근간으로 보안성 품질을 평가하는 기준을 구축하였다. 본 연구를 통해 웹방화벽시스템의 보안성 품 질수준을 확인하고 품질향상을 제고할 수 있는 기준의 확보를 기대할 수 있을 것으로 사료된다. 향후 연구과제로 지속적으 로 변화하고 있는 국제표준에 따라 평가기준을 지속적으로 업그레이드할 필요가 있다.

To achieve web application security goals effectively by providing web security features such as information leakage prevention, web application firewall system must be able to achieve the goal of enhancing web site security and providing secure services. Therefore, it is necessary to study the security evaluation of web application firewall system based on related standards. In this paper, we analyze the requirements of the base technology and security quality of web application firewall, and established the security evaluation criteria based on the international standards for software product evaluation. Through this study, it can be expected that the security quality level of the web application firewall system can be confirmed and the standard for enhancing the quality improvement can be secured. As a future research project, it is necessary to continuously upgrade evaluation standards according to international standards that are continuously changing.

10

Remotely Controlled Management on a Small Firewall Server Using a Virtual Server

NamHo Kim

보안공학연구지원센터(IJSH) International Journal of Smart Home Vol.9 No.3 2015.03 pp.195-204

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

This study suggests a firewall management method using a virtual server in order to allow a manager equipped with a smart phone not only to detect and prevent security threats but also to control firewalls anytime, anywhere. Recently, hackers’ threatening over security is constantly increasing, but companies or institutions operating a small PC server are exposed to a serious threat on security as they cannot afford to maintain manpower that can control it for 24 hours. As a solution for it, this study suggests a way to provide stable services and also save time and money by detecting an illegal access or intrusion at an early stage and reporting it to the server manager in a remote place via a smart phone so as to cope with it properly. For the solution proposed here, this researcher has designed and realized a system which conducts a pattern matching inspection on the packet using the virtual server and Aho-Corasick algorithm to monitor and detect an intrusion and can realize prompt safety management in a remote place with the system control that is realized by an android app.

11

Safeguard Intranet Using Embedded and Distributed Firewall System

Chu-Hsing Lin, Jung-Chun Liu, Chien-Ting Kuo, Mei-Chun Chou, Tsung-Che Yang

보안공학연구지원센터(IJFGCN) International Journal of Future Generation Communication and Networking vol.2 no.1 2009.03 pp.9-16

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Due to the impact of the rapid popularization of Internet and e-commerce, most organizations and enterprises take great effort to protect their information systems against malicious attacks and invasions. The firewall is the most familiar method among relevant technologies for Internet security. However, the firewall systems in use today are either application software or utilities running on the personal computers or network nodes. It is very inconvenient to implement and manage the conventional firewalls. In order to make the management and construction of them easier without disrupting the existing network topology, we implement an embedded and distributed firewall system to safeguard the Internet. In this way, we combine the functions of the firewall and a central security policy server into an embedded system, which can be realized as a network interface card.

12

머신러닝 기반의 자동 정책 생성 방화벽 시스템 개발 KCI 등재

한경현, 황성운

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제20권 제2호 2020.04 pp.29-37

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

기존에 사용되던 방화벽들은 기본적으로 정책을 수동적으로 입력해 주는 방식으로 되어 있어 공격이 오는 즉시 대응하기 쉽지 않다. 왜냐하면 전문 보안 관리자가 이를 분석하고 해당 공격에 대한 방어 정책을 입력해 주어야하기 때문이다. 또한, 기존 방화벽 정책은 공격을 막기 위해 정상 접속까지 차단하는 경우가 많다. 패킷 자체는 정상적이지만 유입량이 많아 서비스 거부를 발생시키는 공격이 많기 때문이다. 본 논문에서는 방어 정책을 입력하는 부분을 인공지능 으로 대체하여 정책을 자동으로 생성하고, 정상 접속 학습을 통해 생성된 화이트리스트 정책으로 정상 접속은 가능하면 서 Flooding, Spoofing, Scanning과 같은 공격만을 차단하는 방법을 제안한다.

Conventional firewalls cannot cope with attacks immediately. It is because security professionals or administrators need to analyze them and enter relevant policies to the firewalls. In addition, those policies may often block even normal accesses. Even though the packet themselves are normal, there exist many attacks that cause denial of service due to the inflow of a large amount of those packets. In this paper, we propose a method to block attacks such as Flooding, Spoofing and Scanning while allowing normal accesses based on whitelist policies which are automatedly generated by learning normal access patterns.

13

리눅스 방화벽에 관한 연구 KCI 등재후보

배유미, 정성재

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.8 No.5 2011.10 pp.599-610

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

서버 운영체제인 UNIX를 기반으로 탄생한 리눅스(Linux)는 다양한 서비스와 많은 사용자들이 접속한다. 사용자가 많아지면서 원치 않는 접속이 발생하게 되고, 이러한 접속은 시스템의 트래픽을 유발하게 된다. 리눅스에서는 접속 제한을 하기 위해 TCP Wrapper를 비롯하여 ipfwadm 및 ipchains 사용하였고, 현재는 iptables를 이용하여 패킷 필터링 및 방화벽 기능을 수행하고 있다. 최근의 iptables는 방화벽 기능 이외에 다양한 기능을 보유하고 있으며, 관련 응용프로그램들과 융합하여 상용 방화벽 프로그램에 필적할 만한 성능을 보이고 있다. 본 논문에서는 리눅스 방화벽 프로그램인 iptables를 분석하여 비용 부담 없는 보안 시스템 구축 방안에 대해 연구하고자 한다.

Linux is based on Unix operating system has variety of Services and has connected by many users. Unnecessarily connections have occurred by many users, these connections cause traffic of system. Linux used TCP Wrapper, ipfwadm and ipchains for connection limit, but now use iptables for packet filtering and firewall function. Recently iptables has variety of functions including firewall function, has been showing equal ability compared to commercial firewall program by integrating with applications. In this paper we analyze iptables is linux firewall program and study ways to build cost effective secure system.

14

네트워크를 위한 보안 시스템의 기술 개발 동향 및 전망 KCI 등재

양경아, 신동우, 김종규, 배병철

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제18권 제5호 2018.10 pp.1-8

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

최근 사이버 공격은 진보된 기술을 활용하여 방어 기술의 발전 속도보다 빠르게 고도화되고 있어 그 위험수위가 갈수록 높아지고 있다. 이에 대응하기 위해 학계는 물론 산업계에서도 다양한 방법을 적용한 보안 기술을 개발하고 있으며 이를 기반으로 한 보안 시스템들이 적용되고 있다. 본 논문에서는 세대별로 진화하는 공격들을 살펴보고 이에 대응하여 발전하는 네트워크 보안 관련 현황을 소개한다. 특히, 네트워크 보안 시스템 중 최근까지 가장 큰 비중을 차지하고 있는 UTM과 관련하여 상용 제품을 중심으로 해외 및 국내 기술의 동향과 성능 및 기능에 관한 비교 분석을 수행하였다. 또한 차세대 네트워크 기술의 등장으로 인한 네트워크 인프라 변화에 대한 향후 전망에 대해 논의하고자 한다.

The latest cyber attack utilizing advanced technologies is more rapidly advancing than developing speed of defense technology, thereby escalates the security risk. In responding to this recent threat, academia and industries are developing some sophisticated security technologies applying various methods. Based on these technologies, security systems are used in many fields. This article aims to select noticeable network security related technologies for the security systems. In particular, we compared and analyzed the trend, performance, and functions of both foreign and domestic technologies in regard to UTM having the largest portions among network security systems so far. We will also discuss the prospect for the change in network infrastructure due to the emergence of the next-generation network technology.

15

Contextual Security with IF-MAP SCOPUS

Abdelmajid Lakbabi, Ghizlane Orhanou, Said El Hajji

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.5 2014.09 pp.427-438

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The multi-context attacks are serious challenges to security detection process. Actually, each security solution produces a considerable number of security events, heterogeneous and difficult to correlate. Sensors usually work independently making hard to extract security information related to a multi-step attacks. Therefore, correlation and sharing mechanism becomes the key to deal with such challenging IT security threats. This paper provides an analysis of the current security state and proposes our security architecture based on local and global contextual protections that share security events in a real time IF-MAP approach in response to malicious activities. As to implementation phase we used opensource Omapd as a MAPS central data repository, apache web server and iptables as MAPC clients in perspective to provide real time containment when attacks are detected.

16

Genetic Algorithm Optimized Packet Filtering SCOPUS

Okta Nurika, Nordin Zakaria, Low Tan Jung

보안공학연구지원센터(IJCA) International Journal of Control and Automation Vol.6 No.5 2013.10 pp.57-66

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we present a method to optimize packet filtering by genetic algorithm. Packet filtering in our work consists of packet capturing and firewall rules reordering. Genetic algorithm is used to automate rules reordering and the discovery of optimal combination of packet capture configuration, in the framework of PF_RING platform and rules ordering. Our method has been tested in different sizes of network traffic load. Genetic Algorithm evolves configuration based on the recorded throughput rates; the higher the throughput the better the solution. Results obtained indicate the effectiveness of the approach.

17

Using Low-Level Architectural Features for Configuration InfoSec in a General-Purpose Self-Configurable System

Nicholas J. Macias, Peter M. Athanas

보안공학연구지원센터(IJUNESST) International Journal of u- and e- Service, Science and Technology vol.2 no.4 2009.12 pp.17-28

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Unique characteristics of biological systems are described, and similarities are made to certain computing architectures. The security challenges posed by these characteristics are discussed. A method of securely isolating portions of a design using introspective capabilities of a fine-grain self-configurable device is presented. Experimental results are discussed, and plans for future work are given.

18

The Firewall Rule Authentication Method Based on 6to4 Tunnel SCOPUS

Li Zhou, Liangyi Gong, Xin Zou

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.3 2013.05 pp.133-142

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The enterprise internal information security faced with many hidden trouble, and information leakage has been the largest security problem. Firewall is the main technology to solve information leakage, but end-to-end cryptograph tunnel communication can through firewall information filtering detection. In order to prevent the information leakage, it is common to add the block rules in firewall. There is short of a simple and effective verification method for the correctness of firewall blocking rules. We raise a method to verify firewall rules based on dual-protocol. With 64 tunnel technology, virtual an external node, analog communication scene between inside and outside, to verify the effectiveness of firewall rules. The experiments shows that this method is simple to deploy, and can verify rules effectively.

19

The Research and Application of Multi-Firewall Technology in Enterprise Network Security SCOPUS

Jing Li

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.5 2015.05 pp.153-162

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

A firewall’s complexity is known to increase with the size of its rule set. Empirical studies show that as the rule set grows larger, the number of configuration errors on a firewall increases sharply, while the performance of the firewall degrades. When designing a security-sensitive network, it is critical to construct the network topology and its routing structure carefully in order to reduce the multi-firewall rule sets, which helps lower the chance of security loopholes and prevent performance bottleneck. This paper studies the problems of how to place the firewalls in a topology during network design and how to construct the routing Tables during operation such that the maximum firewall rule set can be minimized. We have two major contributions. First, we prove that the problems are NP-complete. Second, we propose a heuristic solution and demonstrate the effectiveness of the algorithm by simulations. The results show that the proposed algorithm reduces the maximum multi-firewall rule set when comparing with other algorithms.

20

Design and Analysis of Client Control System Using DNS Control Firewall

Bong-Hyun Kim, Young-Gil Park

보안공학연구지원센터(IJSH) International Journal of Smart Home Vol.7 No.5 2013.09 pp.135-144

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, the client control system designed for infringement blocking system development. In order words, infected with harmful files on your computer by using a user-centered information systems development and security through the design of a control system using DNS control firewall client access to the site randomly for acts that can block the under solving techniques. Design of the client control system was classified as Dynamic intrusion prevention system module design, Embedded domain name service system module design, Interlocking DNS service module design and Cert & Analysis module design. Finally, through simulation, an average of 14% was measured by abnormal packet ratio.

 
1 2 3 4
페이지 저장