Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 136
No
1

Optimizing Intrusion Detection Pattern Model for Improving Network-based IDS Detection Efficiency

Kim, Jai-Myong, Lee, Kyu-Ho, Jong-Seob Kim, Kuinam J Kim

한국융합보안학회 융합보안논문지 제1권 제1호 2001.12 pp.37-45

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

In this paper, separated and optimized pattern database model is proposed. In order to improve efficiency of Network-based IDS, pattern database is classified by proper basis. Classification basis is decided by the specific Intrusions validity on specific target. Using this model, IDS searches only valid patterns in pattern database on each captured packets. In result, IDS can reduce system resources for searching pattern database. So, IDS can analyze more packets on the network. In this paper, proper classification basis is proposed and pattern database classified by that basis is formed. And its performance is verified by experimental results.

3

4,000원

최근 침입 탐지 시스템에 대한 관심이 증대되고 있다. 침입 탐지 시스템에서 침입 여부 확인을 위하여 패턴매칭 기법이 주로 사용된다. 기존의 패턴매칭 기법들은 다양한 공격 패턴들에 대한 패턴 비교 시간이 많이 소요되는 문제점이 있었다. 본 논문에서는 기존의 패턴매 칭 기법들이 가지고 있는 문제점을 해결하기 위하여 새로운 침입 탐지 시스템을 제안한다. 제안한 시스템은 효율적인 패턴 비교를 위하여 룰 패턴을 분류한다. 분류된 패턴은 매칭을 위하여 정형화된 트리로 구현한다. 그러므로, 본 논문에서 제안한 침입 탐지 시스템 모델은 효율적으로 네트워크 침입 탐지를 수행할 수 있다.

Recently, lots of researchers work focused on the intrusion detection system. Pattern matching technique is commonly used to detect the intrusion in the system, However, the method requires a lot of time to match between systems rule and inputted packet data. This paper proposes a new intrusion detection system based on the pattern matching technique. Proposed system reduces the required time for pattern matching by using classified system rule. The classified rule is implemented with a general tree for efficient pattern matching. Thereby, proposed system could perform network intrusion detection efficiently.

4

침입탐지시스템 탐지성능 향상 위한 해시기반 패턴 매칭 시스템

김병훈, 신제철, 하옥현

한국융합보안학회 융합보안논문지 제9권 제4호 2009.12 pp.21-27

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

네트워크 대역폭과 침입기술의 발달하는 상황에서 침입탐지 시스템의 패턴 매칭 방식으로는 대용량 화된 모든 패킷을 기존의 침입탐지 시스템의 패턴 매치 방식으로 패턴을 분석하는 것에는 한계가 발 생한다. 패킷들이 단편화되어 수신될 때 패킷들을 효율성 있게 탐지하기 위해서 Esnort (1)와 같은 운 영체제에 일치되는 패킷들의 패턴만 매치하는 방법이 제시되었다. Esnort의 기본 매커니즘인 NMAP 을 이용하여 동일한 네트워크의 시스템의 운영체제를 스캔하여 스캔된 정보와 수신된 패킷과 동일한 운영체제만을 선별하여 패턴 매치를 적용하여 패턴 매치의 성능을 개선하였다. 하지만 운영체제의 종 류가 다양해지고 nmap의 운영체제 식별의 오류로 수신된 패킷이 무시되어 인입되는 경우가 발생할 수 있다. 본 연구에서는 유동적인 사용자의 시스템 환경과 독립적으로 침입탐지 시스템의 패턴의 해시 화를 통해 해시테이블을 생성하여 패턴 매치의 시간을 단축는 개선된 침입탐지 시스템을 제시하고 검 증하고자 한다.

In the environment of development of network bandwidth and intrusion technology there is limit to the pattern analysis of all massed packets through the existing pattern matching method by the intrusion detection system. To detect the packets efficiently when they are received fragmented, it has been presented the matching method only the pattern of packets consisting with the operation system such as Esnort. Pattern matching performance is improved through the use of NMAP, the basic mechanism od Esnort, by scanning the operation system of the same network system and appling pattern match selectively scanned information and the same operation system as the received packets. However, it can be appeared the case of disregarding the receivied packets depending on the diversity of the kind of operaation systems and recognition mistake of operation system of nmap. In this paper, we present and verify the improved intrusion detection system shortening the pattern matching time by the creation of hashy table through the pattern hash of intrusion detection system independently with the users system environment .in the state of flux.

5

5,500원

범죄사건을 수사하는 데 있어서 사진은 현실을 그대로 기록하는 매체의 특성 때문에 중요한 수사 도구로써 활용되고 있다. 최근에는 디지털 이미지 분야 관련 과학기술이 급속도로 발달함에 따라, 경찰수사 활동에도 디지털 카메라의 사용이 보편화 되었으며 대부분의 증거 사진들 역시 디지털 이미지의 형태로 주어지고 있다. 그러나 디지털 카메라에 의해 촬영된 이미지는 기존에 사용되어오던 아날로그 방식의 사진에 비해 위·변조가 쉬운 단점이 있다. 그 때문에 디지털 이미지는 법적 증거능력을 인정받기에 많은 문제점이 발생하지만, 디지털 이미지의 증거능력이 인정되기 위해 필요한 표준운용절차나 기술에 대한 규정이 많이 부족한 상황이다. 따라서 본 연구는 디지털 이미지의 증거능력 인정을 위한 기술 개발의 일환으로 이미지를 촬영한 카메라 기종을 추적하는 방법을 연구하였다. 이는 모든 디지털 이미지에 포함된 고유의 고정 패턴 노이즈가 마치 인간의 DNA와 같은 역할을 할 수 있는 점을 활용한 것이다. 먼저 각각의 디지털 이미지에서 고정 패턴 노이즈 정보를 추출했으며, 추출된 노이즈 정보들의 유사도를 비교하기 위해 교차상관 계산법을 적용하였다. 아울러 임의 디지털 이미지의 노이즈 정보와 다른 카메라들의 노이즈 정보 유사도를 비교함으로써 실효성을 확인하였다.

The photography can be applied to criminal investigation method because of its scene reproduction characteristics. Recently, the application of digital camera is universally accepted, as the imaging technology is improved. Also, most of the photographic evidences are provided in digital images. However, compare with the analog photographs, the digital images are much easier to forge so that the admissibility of evidence for digital images had many problems. Therefore we need some kind of standard operation process or regulations for the digital photography in criminal investigation. In this study, developing method has been proposed to detect the digital camera originality. It started from the idea that the fixed pattern noise which is shown in every image, can work as a human DNA in the criminal investigation. The first step is to extract the fixed pattern noise from every single image. And to check its practical value, we compared the noise data between two cameras, by the cross correlation function

7

4,000원

최근 STB 보급이 증가하면서 제품 출하 전 품질검사의 중요성이 부각되고 있다. 본 논문에서는 STB 영상 신호의 다채널 동시 입력을 통한 품질검사 자동화를 지원하기 위한 방법을 제안한다. 제안 방법은 먼저 색상 정보와 LDP 코드를 결합한 CeLDP를 이용하여 안정적인 비디오 샷 경계 검출 후 영상의 중앙 스캔라인을 이용한 핑거프린 트를 추출하여 입력 비디오 채널 간 동기화를 수행한다. 제안하는 방법은 기존 샷 검출 방법과 비교를 통해 더욱 강인한 샷 경계 검출 성능을 보이는 것을 확인하였으며, 실제 환경에 적용한 실험을 통해 STB 품질검사 시 필요한 다채널 입력 간 동기화를 위한 신뢰성 확보 및 실시간 품질검사가 가능함을 입증하였다. 또, 제안된 방법을 바탕으로 향후 대규모 품질검사 방법을 연구하여 보다 효과적인 품질검사 체계를 제안하고자 한다.

Recently, the importance of pre-shipment quality inspection has been emphasized due to the increase of STB supply. In this paper, we propose a method to support automation of quality inspection through simultaneous multi-channel input of STB video signal. The proposed method extracts a fingerprint using the center scan line of the image after stable video shot boundary detection using CeLDP combining color information and LDP code and performs synchronization between input video channels. The proposed method shows stronger shot boundary detection performance than the conventional shot detection method. Through the experiments applied to the real environment, it is possible to secure reliability and real-time quality check for synchronization between multi-channel inputs required for STB quality inspection. Also, based on the proposed method, we intend to study a large-scale quality inspection method in the future and propose a more effective quality inspection system.

8

본 연구는 교통사고의 공간적 분포와 사고 위험도를 고려한 고위험 구간을 체계적으로 탐지하고 해당 구간의 사고 영향 요인 도출을 위해 종합적인 분석 체계를 연구하고자 하였으며, 인천시 전역에서 발생한 교통사고를 대상으로 공간 좌표 기반의 사고 위치정보를 활용하여 연구를 진행하였다. 또한, 단순 빈도 중심의 기존 분석 틀에서 벗어나 교통사고의 공간적 밀도와 질적인 심각도를 종합적으로 반영한 DBSCAN-EPDO 기반의 체계와 함께 기계학습 기반 사고 심각도 예측 모델 및 해석을 활용해 교 통안전 분야의 정밀하고 효과적인 위험 구간 분석 체계를 제시하고자 하였다.

9

자극의 주체와 움직임의 유형이 지향성 탐지에 미치는 영향

조경자, 김혜리, 시은경

[NRF 연계] 한국심리학회 산하 한국발달심리학회 한국심리학회지: 발달 Vol.19 No.2 2006.06 pp.61-76

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

지향성 탐지란 사람들이 특정 방향으로 움직이고 있는 자극을 그 방향으로 가려고 하는 목적과 바람을 가진 행위자(agent)로 해석하는 것이다. 본 연구에서는 사람들이 자극의 움직임을 탐지할 때, 스스로 움직임을 유발하는 사람자극만을 지향적으로 해석하는지, 아니면 특정방향으로 움직이는 모든 자극의 움직임(기하학적 도형, 꽃, 사람 자극)을 지향적인 것으로 이해하는지를 알아보았다. 또한 특별한 의미를 부여하기 힘든 움직임, 목표지향적인 움직임, 두 자극들 간에 상호작용하는 움직임에 따라 지향적으로 해석하는 정도가 달라지는지 알아보았다. 실험 결과 사람들은 삼각형과 꽃 자극보다는 사람 자극의 움직임에서 지향적으로 판단하는 경향이 강했으며, 무의미한 움직임과 목표지향적인 움직임 보다는 상호작용하는 움직임을 더 지향적인 것으로 판단했다. 또한 행위자가 스스로 움직임을 유발하는 사람일 경우에는 모든 움직임을 지향적으로 해석하였다. 그러나 스스로 움직일 수 없는 자극인 기하학적인 도형과 꽃 자극에서는 다른 움직임에 비해 상호작용 움직임을 보일 때 지향적으로 해석하는 경향이 강했다. 본 연구 결과는 자극의 주체와 움직임 유형에 따라 지향성 탐지 정도가 달라진다는 것을 시사한다.

Intentional detection is defined as when people detect an object which moves toward special direction as an agent having a goal and desire to go there. This study examined whether people detect the motions of self-propelled objects like human silhouettes and the motions of nonself-propelled objects like geometrical shapes or flowers as intentional agents when they interpret their movements. This study also, examined whether people detect and interpret motions differently when they see different motions, non-meaningful motions, goal-directed motions and interacting motions between two objects. The results demonstrate that people have tendency to detect the motions of human silhouettes more intentionally than the motions of geometrical shapes and flowers, and detect the interacting motions more intentionally than non-meaningful motions and goal-directed motions. Especially when the motions of human silhouettes were presented, people detect and interpret them as fully intended motions even when non-meaningful motions and goal-directed motions were presented. However when presented with nonself-propelled objects, geometrical shapes and flowers combined with interactive movements, people demonstrated a strong tendency to interpret their movements more intentionally than the other motions. This study suggests that people detect and interpret different agent's motions and motions of objects differently.

10

요일 패턴을 고려한 지점속도와 구간속도간의 상관관계 분석

김보성, 김혜선, 조준한, 김성호

한국ITS학회 한국ITS학회 학술대회 2012년 한국ITS학회 춘계학술대회 2012.04 pp.360-365

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

11

루프검지기 기반 위험운전 검지 알고리즘 개발

홍성민, 조수빈, 심진섭, 김은영, 오철

한국ITS학회 한국ITS학회 학술대회 2010년 한국ITS학회 추계학술대회 2010.10 pp.249-254

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

12

4,000원

Novel porous silicon chip exhibiting dual optical properties, both Frbry-Perot fringe (optical reflectivity) and photoluminescence had been developed and used as chemical sensors. Porous silicon samples were prepared by an electrochemical etch of p-type sillicon wafer (boron-doped, <100> orientation, resistivity 1 - 10 Ω). The ething solution was prepared by adding an equal volume of pure ethanol to an aqueous solution of HF (48% by weight). The porous silicon was illuminated with a 300 W tungsten lamp for the duration of etch. Ething was carried out as a two-electrode Kithley 2420 preocedure at an anodic current. The surface of porous silicon was characterized by FT-IR instrument. The porosity of samples was about 80%. Three different types of porous silicon, fresh porous silicon (Si-H termianated), oxidized porous silicon (Si-OH terminated), and surface-derivatized porous silicon (Si-R terminated), were prepared by the thermal oxidation and hydrosilylation. Then the samples were exposed to the wapor of various organics vapors. such as chloroform, hexane, methanol, benzene, isopropanol, and toluene. Both reflectivity and photoluminescence were simultaneously measured under the exposure of organic wapors.

13

물체 블록의 삼진 패턴을 이용한 컬러 영상의 연기 검출 방법 KCI 등재후보

이용훈, 김원호

한국위성정보통신학회 한국위성정보통신학회논문지 제9권 제4호 2014.12 pp.1-6

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

컬러 영상 처리 기반의 연기 검출은 화재의 조기 검출에 적합한 검출 대상이다. 연기 검출을 위한 방법으로 움직임과 색상이 전처리로서 처리되며, 확산, 질감, 형태, 방향성 등의 성질이 후처리로서 사용된다. 본 논문은 연기의 특성 중 밀도적인 분포 특성 검출방법을 제안한다. 연기의 움직임을 10Frame 간격으로 1초 동안 축적한 이미지에 색상을 문턱치 처리해 후보영역을 생성하고,OBTP(Object Block Ternary Pattern)을 적용해 연기의 패턴임을 확인한다. 모든 처리는 Block 기반으로, 움직임 검출은 차분 영상에 적응 문턱치를 적용해 움직이는 물체의 후보영역을 결정했다. 결정된 후보영역을 1초간 축적하고 연기 색상의 문턱치 조건을적용한다. 각각의 연기 후보 영역을 특정 위치의 16개 Block 값을 중앙 Block 값과 비교하고 삼진화 된 패턴을 연기의 패턴과 비교하여 연기를 결정한다.

Color image processing based on smoke detection is suitable detecting target to early detection of fire smoke. A methodfor detecting the smoke is processed in the pre-processing movement and color. And Next, characteristics of smoke suchas diffusion, texture, shape, and directionality are used to post-processing. In this paper, propose the detection method ofdensity distribution characteristic in characteristics of smoke. the generate a candidate regions by color thresholding imagein Detecting the movement of smoke to the 10Frame interval and accumulated while 1second image. then check whetherthe pattern of the smoke by candidate regions to applying OBTP(Object Block Ternary Pattern). every processing isBlock-based processing, moving detection is decided the candidate regions of the moving object by applying an adaptivethreshold to frame difference image. The decided candidate region accumulates one second and apply the threshold conditionof the smoke color. make the ternary pattern compare the center block value with block value of 16 position in eachcandidate region of the smoke, and determine the smoke by compare the candidate ternary pattern and smoke ternary pattern

14

Adding a Pre processing Phase to ASMOV for Improving the Alignment Result

Bahareh Behkamal, Mahmoud Naghibzadeh, Reza Askari Moghadam

보안공학연구지원센터(IJAST) International Journal of Advanced Science and Technology Vol.49 2012.12 pp.25-36

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Ontology matching is one of the most important challenges in the semantic web. It is a technique which is used to find the semantic correspondences between entities which are modeled in different ontologies. Despite many research efforts in ontology matching, the matching process still suffers from severe problems with respect to the quality of the matching results. Furthermore, finding the correspondences, for the most part, is very time-consuming. In this paper, we examine how a pre-processing phase can improve the results of the matching process. A pre-processing phase is added to the matchers for the analysis of input ontologies so as to detect some inappropriate patterns which are modeled by various developers. Then, refactoring operations are utilized on detected patterns for achieving assimilated ontologies. Finally, our proposed approach is tested by ASMOV (Automated Semantic Matching of Ontologies with Verification), which is one of the top matchers in OAEI (Ontology Alignment Evaluation Initiative). Experimental results show that ontologies achieved from this proposed approach are more efficient than the original unrepaired ones, with respect to standard evaluation measures.

15

Bugs Pattern Detection Application in JDBC using Static Analysis Non-Linear Method SCOPUS

Shadrach Jabonir, Ford Lumban Gaol

보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.7 No.5 2013.09 pp.435-448

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, it will be explained about an application which able to analyze the quality of java program code in implementing Java Database Connectivity (JDBC). The analysis will be based on existing best practice in implement JDBC. To analyze JDBC, bugs patterns are needed to be compared with existing best practice. Various methods are available to be used in constructing this kind of application, but in this paper, static analysis non-linear method is used in designing this application. Static analysis means the java program code will be read and analyzed without executing. Non-linear means the java program code will not read sequentially, but it will follow the flow of the program code itself. And this application will be called Bedhigasan, which able to detect bugs pattern in implementing JDBC and it will report those bugs to the web page including with location of the bugs.

16
17

A Design Pattern Detection Technique that Aids Reverse Engineering SCOPUS

Hakjin Lee, Hyunsang Youn, Eunseok Lee

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.2 No.1 2008.01 pp.1-11

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

If software design-patterns could be captured and reused then this would be very helpful to reverse-engineering often practiced by those who develop and who maintain software. The ad-hoc nature and informality of this reverse-engineering process however, makes the discovery of these patterns not straightforward. Moreover, a high false positive rate results from trying to detect these design-patterns. Although several static and dynamic analysis approaches have been proposed to overcome these difficulties, each technique cannot be used separately because of different reasons. And, even if this were possible, each technique in isolation cannot address detection of all of the important patterns. We propose a new taxonomy of GoF design patterns that can guide the reverse-engineering process. This new approach not only combines static analysis with dynamic analysis but also adds what we call the implementation-specific analysis. Using it we demonstrate that the reverse engineering process is faster and more accurate.

18

Single Digit Hash Boyer Moore Horspool Pattern Matching Algorithm for Intrusion Detection System

Sakshi Sharma, Manish Dixit

보안공학연구지원센터(IJFGCN) International Journal of Future Generation Communication and Networking Vol.9 No.9 2016.09 pp.169-180

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

During the past time information on internet increasing enormously which greed the attacker and invite them for attack. In order to provide protection from illegal access the concept of Intrusion Detection System (IDS) is introduced. Intrusion detection system recognized as a powerful tool for identifying malicious attacks over the network. IDS works on the concept of string matching with the help of Detection engine. Detection engine of IDS uses String matching algorithm for comparing against malicious activities. This comparison takes enough processing time nearly 70% of the whole IDS processing time by improving performance of searching algorithm. In this paper, we proposed an enhanced version of Hash-Boyer-Moore-Horspool string matching algorithm by adding a single digit hash function for reduced the number of character comparisons and improve the efficiency of IDS by reducing the number of false positive match.

19

Mobile Botnet Detection Model based on Retrospective Pattern Recognition SCOPUS

Meisam Eslahi, Moslem Yousefi, Maryam Var Naseri, Y.M.Yussof, N.M.Tahir, H. Hashim

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.9 2016.09 pp.39-44

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The dynamic nature of Botnets along with their sophisticated characteristics makes them one of the biggest threats to cyber security. Recently, the HTTP protocol is widely used by Botmaster as they can easily hide their command and control traffic amongst the benign web traffic. This paper proposes a Neural Network based model to detect mobile HTTP Botnets with random intervals independent of the packet payload, commands content, and encryption complexity of Bot communications. The experimental test results that were conducted on existing datasets and real world Bot samples show that the proposed method is able to detect mobile HTTP Botnets with high accuracy.

20

Malicious URL Detection Algorithm based on BM Pattern Matching SCOPUS

Fuqiang Yu

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.9 2015.09 pp.33-44

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In the virus world of Internet, it is a challenging and urgent problem that how can we ensure the safety of search engines. A security subsystem of the search engine based on the research of content-based image search engine system V2.0 is developed. A malicious URL (Uniform Resource Locator) detection method based on BM (Boyer-Moore) pattern matching is proposed. The main research contents and results are as follows: Many malicious URLs could be downloaded by web image search, which may cause unnecessary loses to the users. So the malicious URL detection algorithm based on BM pattern matching is proposed. This method is to let the URL source code match the virus characteristics in the database to confirm whether the URL is safe or not. Web image search detects 203 malicious URLs based on this method. By kaspersky scanning, we confirmed 189 URLs to be malicious URLs, and the error rate is 6.9%, and the accurate rate is 93.1%. The experimental results show that the malicious URL detection algorithm provides secure URLs for web image search engine..

 
1 2 3 4 5
페이지 저장