년 - 년
윈도우 환경에서의 메모리 인젝션 기술과 인젝션 된 DLL 분석 기술 KCI 등재후보
한국융합보안학회 융합보안논문지 제6권 제3호 2006.09 pp.59-67
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 개인 PC 해킹과 경제적 이익을 목적으로 하는 게임 해킹이 급증하면서 윈도우즈 시스템을 대상으로 하는 특정 목적의 악성코드들이 늘어나고 있다. 악성코드가 은닉 채널 사용이나 개인 방화벽과 같은 보안 제품 우회, 시스템 내 특정 정보를 획득하기 위한 기술로 대상 프로세스의 메모리 내에 코드나 DLL을 삽입하는 기술이 보편화되었다.본 논문에서는 대상 프로세스의 메모리 영역에 코드를 삽입하여 실행시키는 기술에 대해 분석한다. 또한 피해 시스템에서 실행중인 프로세스 내에 인젝션 된 DLL을 추출하기 위해 파일의 PE 포맷을 분석하여 IMPORT 테이블을 분석하고, 실행중인 프로세스에서 로딩중인 DLL을 추출하여 명시적으로 로딩된 DLL을 추출하고 분석하는 기법에 대해 설명하였다. 인젝션 기술 분석과 이를 추출하는 기술을 통해 피해시스템 분석시 감염된 프로세스를 찾고 분석하는 시발점이 되는 도구로 사용하고자 한다
Recently the Personal Computer hacking and game hacking for the purpose of gaining an economic profit is increased in Windows system. Malicious code often uses methods which inject dll or code into memory in target process for using covert channel for communicating among them, bypassing secure products like personal and obtaining sensitive information in system.This paper analyzes the technique for injecting and executing code into memory area in target process. In addition, this analyzes the PE format and IMPORT table for extracting injected dll in running process in affected system and describes a method for extracting and analyzing explicitly loaded dll files related running process. This technique is useful for finding and analyzing infected processes in affected system.
권력범죄양상으로서의 기억조작 - 영화 『토탈 리콜』 분석 - KCI 등재
한국사회안전범죄정보학회 한국범죄정보연구 제9권 제2호 통권 제18호 2023.12 pp.1-13
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
본 논문의 목적은 영화 『토탈 리콜』(1990) 분석을 통해 조작된 기억이 권력 범죄로 발전할 수 있다는 문제제기를 하는 것에 있다. 현실세계에서 기억조작은 대체현실 기술로 가능해질 것이라 전망된다. 영화 의 주인공 더글라스 퀘이드는 가짜 기억을 파는 리콜사를 방문한 어느 날 자신이 지금과는 전혀 다른 존재임을 알게 된다. 그의 이전의 모든 인격과 정체성이 지워지고 더글라스 퀘이드라는 인물로 조작된 기억을 주입받은 것이다. 그는 연방정부 수상 코하겐의 심복이었던 하우저였다. 하우저는 코하겐의 부와 권력에 대한 욕망으로 인해 다른 사람의 인생을 살게 된 것이다. 하지만 더글라스 퀘이드는 하우저라는 존재를 기억하지 못한다. 권력층이 과거를 인지하는 방식을 바꿀 수 있다면 미래 역시 바꿀 수 있는 힘을 얻게 된다. 그로 인해 현재도 지배할 수 있게 된다. 이는 권력층의 기억조작 남용으로 이어질 수 있다. 따라서 현재를 살아가는 우리들도 대체현실의 상용화에 앞서서 법제도 정비 등을 통한 적극적이며 선제적 대응을 준비해야 할 때이다.
The purpose of this paper is to raise the problem that manipulated memories can develop into power crimes through analysis of the film Total Recall(1990). It is expected that memory manipulation in the real world will become possible with substantial reality technology. One day, the film's main character, Douglas Quaid, visits a company called Rekall, which sells fake memories, and discovers that he is a completely different being than he is now. All of his previous personality and identity were erased and he was injected with falsified memories of Douglas Quaid. He was Howser, a confidant of Federal Chancellor Cohagen. Cohagen's desire for wealth and power led Howser to live someone else's life. However, Douglas Quaid does not remember Howser. If those in power can change the way they perceive the past, they will have the power to change the future as well. This allows him to dominate the present as well. This can lead to abuse of memory manipulation by those in power. Therefore, it is time for those of us living today to prepare for active and preemptive responses through the overhaul of the legal system ahead of the commercialization of substantial realities.
[Kisti 연계] 대한약침학회 Journal of pharmacopuncture Vol.4 No.1 2001 pp.49-53
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This experiment has investigated the influence of Yamen (Du. 15) point injection on learning and memory dysfunction caused by cerebral ischemia and reprofusion in bilateral cervical general artery combined with bleeding on mouse tail to mimic vascular dementia in human beings. By dividing 40 mice into 4 groups (group1false operation group, group2model group, group3point injection with Cerebrolysin group4point injection with saline.) According to random dividing principles, we observed the influence of Yamen(Du. 15) point injection on the time of swimming the whole course used by model mice which had received treatment for different days in different groups, and the influence of those mice on wrong times they entered blind end. The result showed that point injection with Cerebrolysin and saline could improve learning and memory dysfunction of the mice caused by cerebral ischemia.
[NRF 연계] 한국생활환경학회 한국생활환경학회지 Vol.23 No.4 2016.08 pp.573-582
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In the present study, we attempted to determine the effects of maternal swimming exercise and nicotine injection during pregnancy on spatial learning memory ability and synaptic plasticity neurotrophic factor in hippocampal in rat offspring. After confirming pregnancy, the pregnant rats were divided into four groups (n = 6 in each group): the control group (CG), the swimming group (EG), the nicotine-treated group (NCG), and the swimming and nicotine-treated group (NEG). The experimental animals received 1mg nicotine/kg maternal body weight/day during gestation and lactation (G&L). Beginning on the 7 day of pregnancy, the pregnant rats in the swimming group were forced to swim on a pool for 30 min at a mild-intensity, once a day until delivery. After all the pregnant rats had given birth, there were rat pups available for use in this study in each group (n = 12 in each group). Here in this study, we have shown that both synaptic-plasticity neurotrophic factor expression and PSD were suppressed in nicotine-treated rats, whereas swimming exercise alleviated the nicotine-induced suppression of both synaptic-plasticity neurotrophic factor expression and PSD in the hippocampus of rats. The results of the present study indicate that swimming exercise may facilitate recovery from the CNS complications associated with smoking by inducing enhanced the morphological development of synapses in the hippocampus via the augmentation of synaptic-plasticity neurotrophic factor expression in the hippocampus.
[Kisti 연계] 한국스마트미디어학회 스마트미디어저널 Vol.8 No.1 2019 pp.19-26
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
2018년 평창 동계 올림픽 개막식에서 출처를 알 수 없는 사이버공격이 발생하였다. 해당 공격에서 사용된 악성코드는 인 메모리 악성코드로 기존 악성코드와 은닉하는 장소가 다르며, 140개 이상의 은행, 통신, 정부 기관에서 발견될 정도로 빠르게 확산되고 있다. 인 메모리 악성코드는 전체 악성코드의 15%이상을 차지하며 매우 심각한 피해를 주고 있다. 비휘발성 저장장치로 알려진 하드디스크에 자신의 정보를 저장하는 것이 아닌 휘발성 저장장치 인 램의 특정 메모리영역인 프로세스에 삽입하여 악성행위를 일으키는 악성코드를 인 메모리 악성코드라고 지칭한다. 결과적으로 자신의 정보를 남기지 않아 메모리 탐지 도구를 우회하여 악성코드 분석가들의 분석을 어렵게 한다. 또한 현대 메모리는 갈수록 크기가 증가해 메모리 탐지 도구를 사용하여 메모리전체를 보기 힘들다. 따라서 본 논문에서는 인 메모리 악성코드인 Dorkbot과 Erger를 대상으로 IDA Pro 디버거를 통해 인젝션을 언 패킹하여 효율적으로 페이로드를 산출하는 방법을 제안한다.
At the opening ceremony of 2018 Winter Olympics in PyeongChang, an unknown cyber-attack occurred. The malicious code used in the attack is based on in-memory malware, which differs from other malicious code in its concealed location and is spreading rapidly to be found in more than 140 banks, telecommunications and government agencies. In-memory malware accounts for more than 15% of all malicious codes, and it does not store its own information in a non-volatile storage device such as a disk but resides in a RAM, a volatile storage device and penetrates into well-known processes (explorer.exe, iexplore.exe, javaw.exe). Such characteristics make it difficult to analyze it. The most recently released in-memory malicious code bypasses the endpoint protection and detection tools and hides from the user recognition. In this paper, we propose a method to efficiently extract the payload by unpacking injection through IDA Pro debugger for Dorkbot and Erger, which are in-memory malicious codes.
[Kisti 연계] 한국전기전자재료학회 전기전자재료 Vol.6 No.2 1993 pp.152-160
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
MNOS 구조에서 23.angs.의 얇은 산화막을 성장한 후 LPCVD방법으로 S $i_{3}$ $N_{4}$막을 각각 530.angs., 1000.angs. 두께로 달리 증착했을때 비휘발성 기억동작에 미치는 전하주입 및 기억유지 특성을 자동 .DELTA. $V_{FB}$ 측정 시스템을 제작하여 측정하였다. 전하주입 측정은 펄스전압 인가전의 초기 플랫밴드전압 0V.+-.10mV, 펄스폭 100ms 이내로 설정하고 단일 펄스전압을 인가하였다. 기억유지특성은 기억트랩에 전하를 포획시킨 직후 $V_{FB}$ 유지와 0V로 유지한 상태에서 $10^{4}$sec까지 측정하였다. 본 논문에서 유도된 산화막 전계에 대한 터넬확률을 적용한 전하주입 이론식은 실험결과와 잘 일치하였으며 본 해석방법으로 직접기억트랩밀도와 이탈진도수를 동시에 평가할 수 있었다. 기억트랩의 포획전하는 실리콘쪽으로의 역 터넬링으로 인한 조기감쇠가 컸으며 $V_{FB}$ 유지인 상태가 초기 감쇠율이 0V로 유지한 경우 보다 낮았다. 그리고 기억유지특성은 S $i_{3}$ $N_{4}$막의 두께보다 기억트랩밀도의 의존성이 크며 S $i_{3}$ $N_{4}$막두께의 축소로 기록전압을 저전압화시킬 수 있음을 알 수 있었다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.