년 - 년
Genetic Algorithm Optimized Packet Filtering SCOPUS
보안공학연구지원센터(IJCA) International Journal of Control and Automation Vol.6 No.5 2013.10 pp.57-66
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this paper, we present a method to optimize packet filtering by genetic algorithm. Packet filtering in our work consists of packet capturing and firewall rules reordering. Genetic algorithm is used to automate rules reordering and the discovery of optimal combination of packet capture configuration, in the framework of PF_RING platform and rules ordering. Our method has been tested in different sizes of network traffic load. Genetic Algorithm evolves configuration based on the recorded throughput rates; the higher the throughput the better the solution. Results obtained indicate the effectiveness of the approach.
Sequence‑Aware Hybrid LSTM‑Transformer Intrusion Detection on a Custom Packet‑Capture Dataset
국제인공지능학회(구 한국인터넷방송통신학회) The International Journal of Advanced Smart Convergence Volume 14 Number 4 2025.12 pp.358-372
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
As cyber threats continue to evolve in sophistication, there is urgent need for intelligent, adaptive and context aware intrusion detection systems. In this paper, we present an intrusion detection framework that employs deep learning models to detect anomalies in network traffic using custom dataset. The dataset was constructed in a controlled lab environment using various intrusion attack scenarios such as DoS, SSH abuse and VPN exploitation. Deep learning models were then applied to detect the intrusions. The performance of the models in performing detection tasks were evaluated using metrics of accuracy, precision, recall and F1- score. The results that were obtained indicate that hybrid model achieved the best results with overall accuracy of 0.99 followed by transformer (0.98) and LSTM model (0.97) being the last. This study highlights the potential of leveraging well designed custom IDS datasets and deep learning techniques to enhance intrusion detection mechanisms thereby providing a robust framework for intrusion detection applications.
합법적 감청의 표준화 동향과 이기종 통신망에서의 연속적 패킷 수집에 관한 연구 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.12 No.5 2015.10 pp.427-444
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
합법적 감청이란 각국의 관련법령에 따라 사법수행기관(LEA: Law Enforcement Agencies)에 의하 여 수행되는 감청행위와 이러한 합법적 감청 절차를 수행하기 전에 감청에 관한 권한(영장)을 부여 받는 행위를 말한다. 기존의 공중망인 PSTN(Public Switched Telephone Network), 2, 3세대 무선 통 신망과 전통적인 케이블 통신망에서의 감청은 일반적으로 통화가 수행되는 스위치 장치들에 직접 접 속함으로써 이루어 졌다. 하지만 휴대전화(mobile phone)나 Voice over IP(VoIP) 기술 같이 사용자의 이동성을 보장하는 IP의 이동성 제공 환경에서는 새로운 접근 방법이 필요하게 되었다. 즉, 다양한 종 류의 네트워크 환경을 통신의 연속성을 보장하면서 이동하는 노드에 대하여 연속적인 감청을 수행할 필요가 있다. 따라서 본 논문에서는 전통적인 Lawful Interception의 개념과 미국, 유럽 중심의 국제 Lawful Interception 표준화 동향과 기타 국가의 감청 관련 법규들과 동향에 대해 분석하였다. 또한, LI 대상이 서로 다른 망을 이동하면서 통신할 때의 통신 내용을 효율적으로 감청하기 위하여 다양한 Access망에서의 연속적인 감청이 가능한 Dynamic Triggering 아키텍처를 제안하고 그 효율성을 검증 하였다.
Lawful interception(LI) is carried out in accordance with the relevant laws and regulations of each country‘s law enforcement authorities(LEA: Law Enforcement Agencies) and is refers to the act of receiving authorization (warrant) on the interception before performing the tapping of these legal acts. Lawful interception of the traditional public network PSTN (Public Switched Telephone Network), 2nd and 3rd generation of wireless networks was carred out by connecting directly to the switch like a conventional cable network. However, the mobile phone (mobile phone) or Voice over IP (VoIP) technology those provide mobility need a new approach to ensure LI. It is necessary to perform a continuous LI in the wide range of network environments while guarantee the continuity of mobile node’s communication. In this paper, we analyzed the traditional lawful interception laws and concepts of the United States, Europe and international standardization trend of LI. In addition, we proposed continuous LI architecture to perform dynamic triggering in heterogeneous networks and verified its effectiveness by experiment.
SDN을 활용한 네트워크 검역시 패킷캡쳐 기능 개선 방안
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2015 pp.438-441
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
패킷 캡쳐는 IDS 및 IPS에서 가장 중요한 개념이다. 악성 패킷에 대한 시그니쳐를 탐지하여 사전에 차단할 수 있기 때문이다. OpenFlow를 이용하여 네트워크 패킷 요청 혹은 응답을 특화된 서버, 즉 인터넷검역소를 거친 후 종단 사용자에게 전달할 수 있다. SDN의 특성을 활용하여 종단 사용자는 어떤 프로그램도 설치하지 않고도 네트워크에 연결되어 있는 것만으로 가장 빠른 보안을 적용받을 수 있다. 본 논문에서는 SDN상에서 네트워크 검역을 위해 오픈 소스 Bro IDS를 이용하여 패킷을 캡쳐하는 방법과 발생한 문제와 그에 대한 해결법을 제안한다.
[Kisti 연계] 한국해양정보통신학회 한국해양정보통신학회 학술대회논문집 2002 pp.391-395
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
컴퓨터 확산 및 네트워크 이용의 급격한 증가에 따른 부작용으로 컴퓨터 보안 문제가 중요하게 대두되고 있다. 공격자들의 공격은 운영체제, 프로토롤, 응용프로그램에서 취약점을 이용하고 있으며 그 기술이 고도화, 전문화 되어가고 있다. 그러므로 정보통신망의 기반구조를 구성하는 구성요소들에 대한 구조, 관리에서의 문제점을 해결하기 위한 기반구조 보호기술이 필요하다. 본 논문에서는 효과적으로 침입자를 차단하여 중요 시스템에서 분리시키기 위한 침입탐지시스템을 개발하고, IDS 모델을 선계 및 구현한다.
Computer security is considered important due to the side effect generated from the expansion of computer network and rapid increase of use of computers. A attach of intruders using a vulnerability of operating system, protocol and application programs. And so, The attack methods is to be high technology and professional. Thus It must be necessity that we necessary a solution to structure, management for framework of information technology. This paper develope intrusion detecting system for separating intruders form critical system and design IDS model and implementation of it.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.