Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 132
No
1

eGovFrame 보안 분석 및 대응 방안에 관한 연구 KCI 등재

박중오

대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제21권 제3호 2023.03 pp.181-188

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

전자정부 표준 프레임워크는 국내 정부/공공기관 등 웹 환경 개발을 위한 공통 컴포넌트 재사용, 표준 모듈의 연계와 종속성 해소 등 전반적인 기술을 제공하고 있다. 그러나, 획일화된 개발 환경은 코어 버전에 따른 구버전 업데이트 문제와 해 킹이나 컴퓨터 바이러스 등에 의한 개인정보와 기밀정보 유출 가능성이 존재한다. 본 연구는 국내 eGovFrame을 운영하는 웹사이트 중심으로 보안 취약성을 직접 분석한다. 내부 프로그래밍 언어 소스 코드 수준에서 취약점을 분석/분류한 결과, 대 표 보안 취약성과 연계되는 5개 항목을 다시 추출할 수 있었다. 이에 대한 대응책으로, 2단계(1, 2차)를 통한 보안 설정과 기 능 그리고 보안 정책을 설명한다. 본 연구는 향후 전자정부 프레임워크 보안 기능 개선하고 서비스 활성화에 이바지하고자 한 다.

The e-Government standard framework provides overall technologies such as reuse of common components for web environment development such as domestic government/public institutions, connection of standard modules, and resolution of dependencies. However, in a standardized development environment, there is a possibility of updating old versions according to core versions and leakage of personal and confidential information due to hacking or computer viruses. This study directly analyzes security vulnerabilities focusing on websites that operate eGovFrame in Korea. As a result of analyzing/classifying vulnerabilities at the internal programming language source code level, five items associated with representative security vulnerabilities could be extracted again. As a countermeasure against this, the security settings and functions through the 2 steps (1st and 2nd steps) and security policy will be explained. This study aims to improve the security function of the e-government framework and contribute to the vitalization of the service.

2

효율적인 Sniffing 공격 대응방안 연구 KCI 등재후보

홍성혁, 서유정

중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제6권 제2호 2016.06 pp.31-36

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

Sniffing은 공격자가 암호화 되지 않은 패킷들을 수집하여 순서대로 재조합 하고난 후 공격 대상의 개인정보, 계좌정보 등 중요 정보를 유출하기 위한 수동적 형태의 공격이다. Sniffing 공격으로 인해 패킷들이 유출되는 것을 방지하기 위해 기존의 방법들을 살펴보고, 효율적인 방어대책을 제시하였다. Sniffing공격은 공격 대상의 근거리 네 트워크를 Promiscuous Mode을 이용해 조작한 후 필터링을 해제하고 패킷을 훔치는 방식으로 작동한다. 공격의 형태 로 Switch Jamming, Port mirroring, ARP Redirect, ICMP Redirect 공격 등이 있다. 제안하는 공격 대응 방법으로는 SSL을 통한 패킷의 암호화, 스위칭 환경의 네트워크 구성 관리, DNS를 이용하는 방법과 decoy방법을 이용하면 안전 한 통신이 가능할 것으로 기대하며, 더 효율적이며 안전한 ICT 연구에 기여한다. 향후 프로토타입 프로토콜을 통하 여 효율성을 증명하는 것은 향후 연구로 진행할 예정이다.

Sniffing attack is a passive attack which is reassembling packets to collect personal information, bank accounting number, and other important information. Sniffing attack happens in LAN and uses promiscuous mode which is opening filtering by pass all packets in LAN, attackers could catch any packets in LAN, so they can manipulate packets. They are Switch Jamming, Port mirroring, ARP Redirect, and ICMP Redirect attack. To defend these attacks, I proposed to use SSL packet encryption, reconfiguration of switching environment, DNS, and decoy method for defending all kinds of Sniffing attacks.

3

창의ㆍ인성 교육기반의 디지털 융합 큐레이션 시스템에 관한 취약점 분석 KCI 등재후보

신승수, 김정인, 윤정진

한국융합학회 한국융합학회논문지 제6권 제4호 2015.08 pp.225-234

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

웹 서비스 사용자가 증가하면서 웹 애플리케이션을 공격하는 방법들이 여러 가지 유형들로 나타나면서 웹 애플리케이션 보안에 관한 중요성의 인식도 증가하고 있다. 정보통신기술 발달과 함께 도래한 지식정보사회는 급변하는 사회에서 창의성과 인성 교육에 필요한 웹사이트의 구축이 절실히 요구되고 있다. 본 논문에서는 창의․인성 교육기반의 디지털 큐레이션 시스템에서 제공하는 교육 콘텐츠에 대한 SQL Injection과 XSS에 대한 공격 방법과 취약점을 분석한다. 그리고 SQL Injection과 XSS에 대한 웹 공격에 대응하는 방법을 제시하고자 한다.

With the growing number of people that use web services, the perception of the importance of securing web applications is also increasing. There are many different types of attacks that target web applications. In the rapidly-changing knowledge and information society, which came into being with the advancements made in information and communication technology, there is currently an urgent need for building web sites for the purposes of developing one's creativity and character. In this paper, attack schemes that use SQL injections and XSS and target educational digital curation systems which provide educational contents with the aim of developing of one's creativity and character are analyze, in terms of how the attacks are carried out and their vulnerabilities. Furthermore, it suggests ways of dealing appropriately with these web-based attacks that use SQL injections and XSS.

4

웹 어플리케이션 콘텐츠 보호를 위한 분산 보안

허진경

[Kisti 연계] 한국디지털콘텐츠학회 디지털콘텐츠학회 논문지 Vol.9 No.1 2008 pp.125-130

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷 기술의 발전으로 웹을 통해서 이루어지는 사용자 서비스가 증가하고 있다. 또한 암호화 기술의 발전과 함께 네트워크를 통해 전달되는 암호화 데이터의 양이 증가하고 있다. 이로 인해 웹 어플리케이션 시스템에서 사용자에게 보내지는 인터넷에서의 콘텐츠에 대한 신뢰성 및 불법적인 복재에 대한 문제가 발생하게 된다. 네트워크를 통해 전달되는 데이터를 제3자가 가로채도 그 내용을 알 수 없게 하는 암호화 기술, 현재 사용자가 올바른 사용자인지를 구분하는 인증기술, 원본 데이터와 복제된 데이터를 구분할 수 있게 하는 디지털 서명 등의 기술은 웹상에서 콘텐츠 보호를 위해 사용되는 기술들이다. 웹 어플리케이션 시스템에서 발생할 수 있는 보안상 취약점을 해결하기 위한 방법으로 전달되는 메시지의 암호화와 공개키를 관리가 필요하다. 본 논문은 웹 어플리케이션 시스템에서 데이터의 기밀성 및 사용자 인증을 제공함과 동시에, 다수의 클라이언트 접속시 암호화 서버의 병목현상으로 인한 성능저하를 방지하고 서비스 질을 향상시키기 위한 방법으로 분산 보안 시스템을 제안한다.

User web service is increasing by development of internet technology. Quantity of encrypted data that transmitted through the network are increasing by development of encipherment technology. We have many problems; it is caused by technical development and service increase of user requests. It is like that, we have reliability of contents and illegality copy problem of internet contents in web application system. It is contents protection skills in web that encipherment technology, authentication and digital signature. We need message encoding and secret key for solve vulnerability of encipherment in web application system. In this paper, we propose a distributed secure system that can data confidentiality and user authentication. It prevent performance degradation from bottle neck in encipherment server, and improve service quality.

5

웹 기반 사회 안전 서비스를 위한 오류 관리기

고응남, 홍성룡

[Kisti 연계] 한국디지털콘텐츠학회 디지털콘텐츠학회 논문지 Vol.15 No.1 2014 pp.87-91

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문은 웹 기반 사회 안전 서비스를 위한 오류 관리기에 대해서 제안하였다. 본 시스템은 멀티미디어 협동 작업 환경에서 소프트웨어 오류를 감지, 공유, 복구하기에 적합한 시스템이다. 이 시스템에 의해서 오류를 공유할 수 있다. 웹 기반 사회 안전 서비스를 위한 오류 관리기는 사용자들에게 상호작용 인지를 통하여 오류 객체 공유를 가능하게 한다. 인지의 구현 방법에는 파일 공유, 윈도우 복사, 윈도우 오버레이, 또는 윈도우 공유 등이 있다. 본 시스템은 공동 작업에 참여한 사용자들이 다른 참여자들에게 같은 뷰로써 공유된 오류 객체들을 참조할 수 있도록 구축하였다.

This paper suggested a web based error manager for societal security service. This is a system that is suitable for detecting, sharing and recovering software error based on multimedia CSCW(Computer Supportes Cooperated Work). With error sharing system, a group cooperating users can share error applications. Our a web based error manager for societal security service enables user to share error objects through interaction awareness. This method has a file sharing, a window copy, a window overlay, or a window sharing. We implemented the web based error manager for societal security service so that the users participated in collaborative work may refer shared error objects as the same view to others.

6

보안이 강화된 특수목적용 웹서버 설계 및 구축 제안

홍성락, 조인준

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.22 No.2 2022 pp.71-79

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

현재 웹 서버의 보안을 위해 관제와 모의 해킹을 한다고 해도 계속해서 취약점이 발생하고 해킹을 당하는 것이 현실이다. 해당 문제를 해결하기 위해 L4와 L5 사이에서 소켓을 사용해 모든 웹 통신을 제어할 수 있는 보안 웹 서버를 개발했다. 그리고 HTTP 응답을 줄 때 매번 파일과 헤더를 합치는 행위를 미리 합쳐놓는 방식을 제안했다. 그 결과 보안과 속도를 둘 다 향상할 수 있었다. 따라서 본 논문에서는 관제와 모의 해킹을 해도 취약점이 발생하는 이유와 그것에 대한 해결방안과 더 나아가 DB까지 보안을 유지할 수 있는 보안 웹 서버개발 방식을 제안하였다.

Currently, even if control and mock hacking are performed for the security of web servers, vulnerabilities continue to occur and be hacked. To solve this problem, we have developed a secure web server that can control all web communication using sockets between L4 and L5. And when giving HTTP responses, we proposed a method of combining files and headers in advance. As a result, both security and speed could be improved. Therefore, in this paper, we proposed the reason why vulnerabilities occur even if control and mock hacking occur, a solution to it, and a security web server development method that can maintain security up to DB.

7

4,000원

최근 웹 애플리케이션의 복잡성 증가와 함께 새로운 보안 취약점이 지속적으로 발생하고 있으나, 기존 알려진 정적 분석 도구는 취약점(CVE) 데이터베이스에 의존적으로 제로데이 공격 및 복합적인 위협에 대응이 어려운 한계를 지니고 있 다. 따라서, 본 연구는 Nmap 기반 정적 분석과 생성형 AI를 결합한 하이브리드 웹 보안 프레임워크를 제안한다. 기본 정적 도구는 단계에서 알려진 취약점(CVE) 매핑을 수행한 후, AI 기반으로 동적 테스트 케이스(SQLi/XSS 페이로드 등)를 실시간 으로 스캐닝한다. 취약점 패턴 분석 결과, 기존 정적 분석 대비 40% 향상된 탐지율(F1-Score 0.91)과 AI의 문맥 이해 능력을 활용해 오탐지율을 25% 감소시켰다. 본 연구는 향후 오픈소스(Nmap)와 클라우드 기반 ChatGPT API의 연동을 통해 저비 용·고효율 보안 솔루션 개발을 위한 기초연구로서 의의가 있다.

The increasing complexity of modern web applications has led to the continuous emergence of new security vulnerabilities. However, existing static analysis tools rely heavily on vulnerability (CVE) databases, limiting their ability to effectively counter zero-day attacks and complex threats. Therefore, this study proposes a hybrid web security framework that combines Nmap-based static analysis with generative AI. The basic static tool performs known vulnerability (CVE) mapping in a step, and then AI-based dynamic test cases (SQLi/XSS payloads, etc.) are scanned in real-time. Analysis of vulnerability patterns showed a 40% improvement in detection rate (F1-Score 0.91) compared to existing static analysis, while leveraging AI's contextual understanding capability reduced false positive rates by 25%. This research holds significance as foundational work for developing low-cost, high-efficiency security solutions through future integration with open-source tools (Nmap) and cloud-based ChatGPT APIs.

8

웹기반 보안 관리 수준 분석 도구 KCI 등재후보

김점구, 최경호, 노시춘, 이도현

한국융합보안학회 융합보안논문지 제12권 제3호 2012.06 pp.85-92

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

기존의 보안 관리 수준을 측정하기 위한 방법들이 다양하지만 IT 자산을 중심으로 한 평가만이 이루어지고 있는 관 계로 조직 전반에 걸친 분석이 이루어지지 못했다. 따라서 본 논문에서는 보안 관리 수준 점검을 손쉽게 할 수 있도록 웹 기반 보안 관리 수준 분석 도구에 대해 제시한다. 본 도구의 경우는 전사적 정보 보호 관리 방법론인 ISO 27001의 보안통제 항목들을 기반으로 설문 내용을 구성하였다.

Today, the typical web hacking attacks are cross-site scripting(XSS) attacks, injection vulnerabilities, malicious fi le execution and insecure direct object reference included. Web hacking security systems, access control solutions, a ccess only to the web service and flow inside but do not control the packet. So you have been illegally modified to pass the packet even if the packet is considered as a unnormal packet. The defense system is to fail to appropriate controls. Therefore, in order to ensure a successful web services diagnostic system development is necessary. Web a pplication diagnostic system is real and urgent need and alternative. The diagnostic system development process mu st be carried out step of established diagnostic systems, diagnostic scoping web system vulnerabilities, web applicati on, analysis, security vulnerability assessment and selecting items. And diagnostic system as required by the web s ystem environment using tools, programming languages , interfaces, parameters must be set.

9

ISO/IEC9000모델을 참조한 웹 애플리케이션 보안품질 관리체계 설계 KCI 등재후보

김점구, 노시춘, 이도현

한국융합보안학회 융합보안논문지 제12권 제3호 2012.06 pp.11-17

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

ISO/IEC 9000에 의하면 품질이란 사용 시 사용자 요구사항을 만족시키는 제품이나 서비스의 특성을 종합한 개념으 로 정의하고 있다. 웹애플리케이션의 시큐어코딩은 안정성과 함께 정보시스템 서비스 품질을 결정짓는 요소 중의 하나 이다. 시큐어코딩을 달성하기 위해서는 품질을 기반으로 하는 설계 모델이 필요하다. 그 이유는 보안도 하나의 품질 속 성으로서 비 기능적 요구사항의 범위에 속하기 때문이다. 웹애플리케이션 품질평가체계 설계를 위해서는 품질의 정의를 기초로 품질속성, 품질요구사항, 품질측정 시나리오가 정의되고 설정되어야 한다. 이를 위해 IEEE 1061 품질모델을 참 조한 웹애플리케이션 품질모델 관리체계를 개발한다. 웹 애플리케이션 아키텍쳐 설계는 시큐어코딩 품질모델 체계, 웹 어플리케이션 이해관계자 관심 도출, 아키텍처 동인 결정, 품질속성 도출, 보안품질 요구사항 설정, 웹어플리케이션 아키 텍처기술서 작성, 보안 프레임워크 설계 순서로 구성된다.

According to ISO/IEC 9000, quality to satisfy users' requirements when using the product or service is defined as the characteristics of the synthesized concept. Secure web application coding information systems with the reliability and quality of service is one of the determining factor. Secure coding in order to achieve the quality based on the m odel is necessary. The reason is that the security is in quality properties in the range of non-functional requirements that necessitates. Secure coding for the design of quality systems based on the quality of the definition of quality att ributes, quality requirements, quality attribute scenarios are defined, and must be set. To this end, referring to IEEE 1061 quality model for web application, quality model structure is developed. Secure web application architecture desi gn is composed of coding quality of the model systems, web applications draw interest to stakeholders, decision driv ers secure coding architecture, quality attributes, eliciting quality requirements of the security settings, creating web application architecture descriptions and security framework.

10

웹 서비스 보안 성능 평가 테스트 방법론 연구 KCI 등재후보

이동휘, 하옥현

한국융합보안학회 융합보안논문지 제10권 제4호 2010.12 pp.31-37

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

IT에서 보안은 위험 및 위협으로부터 시스템을 보호하고, 피해를 방지하며 Risk를 최소화해야 한다. 이와 같은 맥락으로 정보보안 제품의 정보가 처리, 저장, 전달되는 과정에서 정보와 시스 템의 보안기준, 즉 기본적인 기밀성, 가용성, 무결성과 부차적인 명확성, 증명가능성, 감지, 경보 및 방어능력 등이 충분히 보장될 수 있도록 하여야 한다. 웹 서비스에서 보안은 가장 중요한 요 소이며, 웹 특성상 서비스를 위해 80번 포트 같은 통로를 열어놔야 하는 구조로서, 웹 어플리케 이션, 웹 소스 및 서버, 네트워크 모든 요소가 근본적인 취약점을 안고 있다. 이에 따라 이런 요 소를 통해 웹 프로그램의 설정오류나 개발 오류 및 웹 애플리케이션 자체의 취약점을 이용한 홈페이지 와 웹 서버 해킹을 방지하며, 효율성을 높이는 웹서비스 보안 BMT 수행 방법론을 제 시하고자 한다.

The risks and threats in IT security systems to protect, prevent damage and Risk should be minimized. Context of information security products such as information processing, storage, delivery, and in the process of information system security standards, That is the basic confidentiality, availability, integrity and secondary clarity, potential evidence, detection, warning and defense capabilities, to ensure sufficient and should be. Web services are the most important elements in the security, the web nature of port 80 for the service to keep the door open as a structure, Web applications, web sources and servers, networks, and to hold all the elements are fundamental weaknesses. Accordingly, these elements through a set of Web application development errors and set-up errors and vulnerabilities in Web applications using their own home pages and web servers to prevent hacking and to improve the efficiency of Web services is proposed methodology performs security BMT.

11

웹 서비스 보안기술에 관한 연구

김배현, 권문택

한국융합보안학회 융합보안논문지 제4권 제2호 2004.06 pp.61-70

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

웹 서비스로의 진화는 기존에 존재하고 있는 다양한 시스템들을 통합하여 운영해줌으로써 기업의 비즈니스 환경에 변화를 가져올 뿐 아니라 다양한 분야에서 활용될 것이다. 하지만 아직 웹 서비스 표준이 완전히 정립되지 않았고, 업체 간 상호운영성 및 보안 문제 등 웹 서비스가 실제적으로 운영되기 위해서 해결 되어할 문제가 아직 많다. 특히 웹 서비스 보안 문제를 해결하지 않는다면 웹 서비스 기술은 더 이상 활성화되지 않을 것이다. 그러므로 웹 서비스의 특성에 적합한 보안기술 개발이 요구된다. 본 논문은 웹 서비스가 실제적으로 운영되기 위한 몇 가지 문제점들 가운데 보안에 관련된 문제점을 해결하기 위한 웹 서비스 보안 기술의 개발 방향과 발전 방향을 분석하여 제시한다.

Web service technology will be used in various business fields and it will affect business paradigms. But, however, there is no standard so far and we have many problems to be solved in order to insure interoperability and security. Especially we have to solve Web service security for effective utilization of the technology and otherwise, the technology will not be used in the business field. We, therefore, need to develope security technology which fits to the Web service characteristics. This document describes a proposed strategy for addressing security within a Web service environment based on the results of analysis on the Web service security problems.

12

가상화를 이용한 웹 서버 보안시스템 설계 및 구현 KCI 등재후보

유재형, 김도형, 김용호, 김귀남, 하옥현

한국융합보안학회 융합보안논문지 제8권 제4호 2008.12 pp.199-207

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

웹 서비스는 기능의 특성상 다른 서비스와는 달리 외부에 노출되어 있고 다양한 어플리케이션들이 웹 서비스와 연동되어 있어서 많은 보안 취약점들이 존재한다. 특히 새로운 웹 기술들이 개발되면서 전에 없던 새로운 형태의 보안 취약점들이 꾸준히 생겨나고 있다. 본 논문에서는 이러한 취약점들을 바탕으로, 가상화 환경을 이용하여 웹서버와 허니웹을 구축함으로써 어떤 공격에 대해서도 시스템의 하드웨어까지 영향을 미치지 않도록 구성되며 허니웹을 통하여 새로운 공격에 대해서도 정보를 수집할 수 있도록 웹 서버 보안시스템을 설계 및 구현 하였다. 이를 통하여 상호 통신의 웹 환경에서 적절한 보안을 제공 할 수 있다.

Web service has many security weekness because it is exposure to outside and connected with various application. Especially, as new technology developed new type of security weakness has occured consistently. In this paper, we construct webserver and honeyweb by using virtual reality on a basis these weakness. So it cannot be influenced by any attack to the hardware of the system. By using honey web, it disigned and embodied web server secutiry system to collect the data about new attack. Through this, it can provide proper secutiry in a web environment of mutual communication.

13

웹 어플리케이션 보안성 검증방법

노시춘, 전익수, 김귀남

한국융합보안학회 융합보안논문지 제3권 제2호 2003.06 pp.11-20

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

오늘날 인터넷 상에서 web 시스템 취약점을 이용한 해킹이 점차 증가하고 있는 추세이다. 이같은 위협에 대처하기 위해 web을 통한 위협의 종류와 그 대응 방안을 소개하고 web 어플리케이션 보안성 검증방법을 제시한다.

Now a days the threatenings of using internet web system's vulnerability are rapidly increasing. To protect the threat we introduce the sorts of threats and present the verification method of web application security.

14

정보보안과 웹기반 회계정보만족도에 관한 연구

이신남, 신용재

한국기업경영학회 기업경영연구 제19권 제3호 2012.06 pp.111-130

※ 기관로그인 시 무료 이용이 가능합니다.

5,500원

본 연구는 정보보안과 관련하여 행정안전부의 정보보호 수준의 관리지표인 정보보호 정책 환경, 정보침해대응과 회계정보만족도의 관계를 규명하기 위하여 실증 연구를 하였으며 그 결과를 요약하면 다음과 같다. 첫째, 정보보호 정책 환경변수 중에서 수집 및 보유, 기술기반은 5%의 유의수준에서 회계정보만족도에 통계적으로 정(+)의 유의한 영향을 미치는 것으로 나타났으나 정책기반은 회계정보만족도에 통계적으로 유의한 영향을 미치지 않는 것으로 나타났다. 이러한 결과는 정보수집, 정보파일대장, CCTV, 정보저장 및 출력매체가 잘 구비되어 있을수록 회계정보만족도는 높아진다고 볼 수 있다. 또한 정보보호시스템, 정보처리시스템의 접근통제, 정보를 저장․전송할 때 암호화가 잘 되어 있을수록 회계정보만족도가 높아진다는 것을 의미한다. 둘째, 정보침해대응 변수 중에서 웹사이트 정보노출 방지정책, 정보유출 대응절차, 정보침해 구제절차는 5%의 유의수준에서 회계정보만족도에 통계적으로 정(+)의 유의한 영향을 미치는 것으로 나타났으나, 이용 및 파기는 회계정보만족도에 통계적으로 유의한 영향을 미치지 않는 것으로 나타났다. 이러한 결과는 웹사이트 정보노출 방지정책에 대한 지원이 많을수록 회계정보만족도는 높아진다고 볼 수 있다. 또한 정보유출 대응절차에 적극적으로 참여할수록 회계정보만족도는 높아지고 손해배상제도와 같은 정보침해 구제절차가 잘 되어 있을수록 회계정보만족도는 높아진다는 것을 의미한다

Today, the use of computers and software is an integral part of our daily work life. The ubiquitous use of information management software by workers is rampant in many officies, both large and small. However, it is believe that soft usage is illegal in Korea today, where approximately half of that software is used in companies. Realistically, we have to pay when we purchase any general goods. But in the case of software, there are possibilities of alternatives-such as illegally copied software. Business have been adopting security systems and making a variety of practical policies promoting and implementing information security awareness among employees in orer to safeguard valuable corporate information and resources. Firm implement public relations activities and offer security and privacy education for their staffs continuously. However corporate confidential information can be frequently stolen due to lack of employees’ security awareness. Small and medium-sized organization are also introducing various information technology and IT systems in order to secure competitiveness. Lack of prevention systems and awareness of adverse effects of information technology as well as the possibility of leakage, allows exposure to even more risk. Numerous cases related to information security leakage have been reported both at home and abroad, stressing the need for constant alertness. Thus, for small-medium companies to grow beyond survival, there must exist information as well as consideration of the possible detrimental effects of information, including preventative measures for such effects. Most companies introduce technical elements only as measures for information security and subsequent measures for individuals within an organization are minimal. this is due largely to a lack of consideration of situational factors, such as corporal culture and environment. Information security should begin from companies’ recognition of its undeniable importance. the fundamental issue of information security is based on human will and behavior to protect information and system. In Web-based, accounting information’s motivation is the essential component that enables the to participate in information spontaneously and continuously. The most effective strategy of accounting information’s motivation would be provided after the users’ motivation state is precisely measured in process and then prescribed according to results. The purpose of this study is to analyze the accounting information protective environment and accounting information infringement response which is considered to affect the satisfaction of accounting information. The major findings of the study are as follows. First, among accounting information protective policy environment, the support from collection and expense, technical base show the 5% of positive significance in the satisfaction of accounting information. But politic base does not affect the satisfaction of accounting information. This result suggests that the support from collection and expense is prior to other factors in the satisfaction of accounting information. The technical base in the maintenance of system is also importance to raise satisfaction of accounting information. It is needed to make Information protective system and Information encryption. Second, among accounting information infringement response variables, web site information exposure prevention policy, information leakage response procedures, information infringement remedial procedures affect positively the satisfaction of accounting information by 5%. However use and abandonment do not show significant relation with the satisfaction of accounting information. The result of the study show that it is needed to web site information exposure prevention policy and information leakage response procedures, information infringement remedial procedures. When information infringement remedial procedures are highly correlated with compensation for the loss system the satisfaction of accounting information is achieved. The study has been conducted via a questionnaire survey, the collectde data is somewhat small in scale. The limitation on this study was that only mutual effects between factors such as accounting information protective environment and accounting information infringement response. In future, the study that precisely measures related variables with clear understanding of those measurement factors should be encouraged.

15

웹 컨텐츠 보호를 위한 암호화 키의 분산 객체 활성화 KCI 등재후보

허진경

한국융합보안학회 융합보안논문지 제9권 제1호 2009.03 pp.113-120

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷 사용자의 증가와 인터넷 쇼핑몰의 대중화로 인해 웹 어플리케이션 시스템에서 사용자가 요구하는 컨텐츠의 양과 암호화 되는 데이터의 양은 점점 증가하고 있다. 이로 인해 웹 어플리케이 션 시스템에는 서버의 과부하 및 병목현상으로 인한 성능 저하뿐만 아니라, 컨텐츠 보안에 많은 취약점들이 발생한다. 또한 웹 어플리케이션 시스템에서는 클라이언트 요청에 의한 암호화가 필요 하고 사용자를 인증하기 위한 공개키를 제공한다. 이때 발생하는 보안상 취약점을 해결하기 위한 방법으로 전송되는 컨텐츠의 암호화와 공개키에 대한 관리가 필요하다. 본 논문은 웹 어플리케이션 시스템에서 기밀성 및 인증을 제공함과 동시에, 다수의 클라이언트 접속시 암호화 처리 때문에 발 생할 수 있는 성능저하를 감소시켜 서비스 질을 향상시키기 위한 방법으로 분산 객체 활성화를 이 용한 분산 암호화 시스템을 제안한다.

Web contents and encrypted data that transmitted through the network are increased by development of encipherment technology in web application system. We have many security problems that servers overload and data bottleneck; it is caused by technical development and service increase of user requests in one place. It is necessary that create a many encryption key in one web application system. As a result, service quality comes to be low because of increased network traffic and system overload. There must be a system. That should be improved in secure service quality to process data. This paper describes a new approach for design and implementation of distributed encryption key processing for web application system. In this paper, it is based on distributed object activation of encipherment key, for the purpose of confidentially, integrity and authentication. It can prevent system performance degradation from server’s data bottleneck and can improve service quality.

16

웹 어플리케이션 보안을 위한 가상화 기반 보안 모델 KCI 등재

양환석, 유승재

한국융합보안학회 융합보안논문지 제14권 제4호 2014.06 pp.27-32

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

네트워크 기술의 빠른 발전과 컴퓨팅 환경의 변화로 인하여 웹 어플리케이션 활용 분야가 최근 몇 년 사이에 광범위 하게 넓어졌으며 복잡해졌다. 이러한 웹 어플리케이션이 중요한 서비스에 많이 사용되면서, 이를 대상으로 한 공격도 증가하고 있으며, 그 방법도 다양해지고 지능화되고 있다. 본 논문에서는 웹 어플리케이션의 취약점을 이용한 공격을 막기 위해 가상화 기술을 이용한 보안 모델을 제안하였다. 제안한 모델에서는 클라이언트 요청에 의해 생성되는 세션에 ID를 부여한 후 해당 요청에서 쿼리 유형을 분석하여 해당 가상 웹 서버에 전달함으로써 데이터베이스 서버에서도 쿼 리에 대한 요청 정보를 인지할 수 있도록 하였다. 그리고 가상 웹 서버들 사이의 트래픽을 감시하고, Host OS의 자원 낭비를 줄이기 위해 VM-Master 모듈을 구성하였다. 제안한 기법의 공격탐지 및 자원 활용의 우수한 성능은 실험을 통 하여 확인할 수 있었다.

Utilization of web application has been widely spread and complication in recent years by the rapid development of network technologies and changes in the computing environment. The attack being target of this is increasing and the means is diverse and intelligent while these web applications are using to a lot of important services. In this paper, we proposed security model using virtualization technology to prevent attacks using vulnerabilities of web application. The request information for query in a database server also can be recognized by conveying to the virtual web server after ID is given to created session by the client request and the type of the query is analyzed in this request. VM-Master module is constructed in order to monitor traffic between the virtual web servers and prevent the waste of resources of Host OS. The performance of attack detection and resource utilization of the proposed method is experimentally confirmed.

17

외주 개발 웹 어플리케이션 테스팅의 보안성 강화 방안 KCI 등재

최경호, 이동휘

한국융합보안학회 융합보안논문지 제15권 제4호 2015.06 pp.3-9

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

웹 서비스를 가능하게 하는 웹 어플리케이션은 내부 개발자가 보안 의식을 갖고 만든다면 일정 수준 이상의 안전성을 보여준다. 하지만 외주 개발의 경우, 품질의 우수성보다는 요구 사항을 충족하고 요청 받은 기능을 실행시키는데 주안점이 있기 때문에 안전성이 우선되지 못한다. 따라서, 본 논문에서는 소프트웨어에 대한 객관적이고도 독립적인 시각으로의 평가를 가능하게 해주는 소프트웨어 테스트 절차를 보안 중심으로 개선하였다. 제안된 모델은 웹 어플리케이션의 외주 개발 시에도 초기부터 보안을 고려할 수 있게 해주며, 특히 보안 인식이 부족한 상황에서 작성된 프로그램의수정 소요 발생으로 인한 개발 일정 지연 사태를 미연에 방지할 수 있는 효과가 있음을 확인하였다. 이러한 결과는 자원관리체계를 중심으로 웹 어플리케이션에 대한 소요가 증가하고 있는 국방 분야에서도 엄격한 테스트를 토대로 보안취약점을 지닌 채 서비스되는 것을 방지할 수 있기에 활용이 가능할 것으로 판단된다.

A web application that allows a web service created by a internal developer who has security awareness show certain level of security. However, in the case of development by outsourcing, it is inevitable to implement the development centered on requested function rather than the issue of security. Thus in this paper, we improve the software testing process focusing on security for exclusion the leakage of important information and using an unauthorized service that results from the use of the vulnerable web application. The proposed model is able to consider security in the initial stage of development even when outsourced web application, especially, It can prevent the development schedule delay caused by the occurrence of modification for program created by programer who has low security awareness. This result shows that this model can be applied to the national defense area for increasing demand web application centered resource management system to be able to prevent service of web application with security vulnerability based on high test.

18

4,000원

19

웹서비스 보안성 강화 방안 KCI 등재

이성훈

한국디지털정책학회 디지털융복합연구 제11권 제12호 2013.12 pp.361-366

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 인터넷이 발전함에 따라 월드와이드웹(world wide web) 기반의 서비스 규모는 기하급수적으로 증가하 였다. 또한 최근 기업간 비즈니스 로직의 구현에 웹 서비스를 이용하고 응용 간 통신 및 상호 응용의 사례가 많아지 고 있으며 이를 위한 기업 내의 기반 시스템 구축에도 웹 서비스의 이용이 활발해지고 있다. 이에 따라 인터넷을 이 용한 웹서비스에서 다루어지는 정보의 품질에 대한 중요성이 증대되고 있으며, 다양하고 방대한 정보에 대한 보안 역시 점점 더 중요성을 띄고 있다. 따라서 본 연구에서는 웹서비스에 대한 표준 동향들을 고찰하고, 사용자들의 정 보를 보호하기 위한 다양한 보안정책들을 분석하였다. 이를 기반으로 웹서비스의 보안성을 강화하기 위한 방안을 기 술하였다.

As the Internet has been growing, WWW(World Wide Web) based services were popularized and users using the service were increased excessively. Recently, the instances of communications between the applications and interaction applications using the Web services in the implementation of the business logics among the enterprises are spread widely. Therefore, it has been emphasized quality and security of web services. In this paper, we described standard trends for web servises. And we analyzed the security policies to protect user's informations. Eventually, We described a security enhancement method for web service.

20

웹기반 원격진료시스템에서 암호화인증방식이 적용된 회원관리기법 KCI 등재후보

김석수

한국융합보안학회 융합보안논문지 제5권 제1호 2005.03 pp.19-27

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

이 연구는 인터넷 기반에서의 3자(환자, 의사, 약사)간의 상호대화형 원격진료 시스템 구현으로서, 효율적인 진료와 빠른 처리를 위한 전자진료차트 및 자료처리에 관한 내용을 제시하고 있으며, 데이타베이스 구축은 IIS 4.0 웹서버 상에서 ASP와 SQL을 연동하여 구현하였으며, 온라인 및 오프라인 겸용모드의 효율적인 자료처리를 위한 시스템 통합과 환자와 의사간의 상담, 그리고 오프라인 상에서의 진료와 환자가 지정한 약사로의 처방전 전송 및 조제, 그리고 진료데이터의 저장 및 검색으로 인한 반영구적인 진료데이터저장, 환자 및 의사의 이 진료데이터를 이용한 보다 정확한 진료 및 처방 등이 가능하도록 하였다. 그리고, 일반회원 및 유료회원, 의사와 악사간의 데이터처리를 각각 등급을 나누어 다르게 하고 있으며, 이에 따른 서비스 접근권한이 부여되기에 각 회원들의 인증이 반드시 뒤따르게 하였다.

This paper presents the content regarding electronic medical examination chart and data processing for efficient medical examination and fast treatment by realizing remote medical examination system of mutual conversation type among 3 parties(patient, doctor, pharmacist) on internet base, and establishment of database enabled system integration for efficient data processing in both on-line and off-line mode by interconnecting ASP and SQL on IIS 4.0 web server, consultation between patient and doctor, medical examination on off-line mode, transmission of prescription sheet to the pharmacist designated by patient, preparation of medicine, semieternal storage of medical examination data owing to storage and check of medical examination data, more accurate medical examination and prescription using this medical examination data by patient and doctor, and so on. And, data processing between doctor and pharmacist is differently performed based on class such as general member and charge member, and service access right pursuant to this is endowed, so that certification of each member must follow by all means.

 
1 2 3 4 5
페이지 저장