Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 44
No
2

유비쿼터스 환경의 데이터베이스 보안을 위한 CSS 설계 KCI 등재후보

이대식, 윤동식, 안희학

한국융합보안학회 융합보안논문지 제5권 제3호 2005.09 pp.15-22

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷의 보급과 다운사이징, SI 기법이 등장하면서 기존의 집중식 컴퓨팅은 급격히 분산 컴퓨팅으로 변하고 있다. 또한 분산 컴퓨팅은 유선으로 연결된 네트워크에서 벗어나 유비쿼터스 컴퓨팅으로 빠르게 변화하고 있다. 점차 복잡해지는 이기종 환경에서 용융 프로그램과 운영체제에 원만한 통신을 이룰 수 있게 하는 미들웨어로 CORBA가 널리 사용되고 있다. 그러나 지능적이고 다양화되는 공격들(해커, 바이러스, 웜 등) 속에서 분산처리 환경은 절대 안전할 수 없는 것이 현실이다. 본 논문에서는 OMG에서 제시한 CSS를 기반으로 유비쿼터스 환경에 적합한 DB보안 모델을 설계하고 기존 모델과 비교 분석하여 효율성을 제시하고자 한다.

The spread of Internet and the appear of Downsizing, SI(System Integration) is chaning centralized computing to distributed computing. Also distributed computing is rapidly changing to Ubiquitous computing escape from hard wire connected network. CORBA(Common Object Request Broker Architecture) is a middleware that used for smoothness communication between application program and operation system in a different environment. However distributed computing environment is not safe from the danger, the attack like virus, worm is too intellectual and variety. In this paper, we design a new DB security model and suggest efficiency of it in Ubiquitous environment base on CSS(CORBA Security Service) that present ed from OMG(Object Management Group).

3

Data Base 보안과 Oracle 보안 구현

노시춘, 박상민, 조성백, 김귀남

한국융합보안학회 융합보안논문지 제3권 제3호 2003.09 pp.7-18

※ 기관로그인 시 무료 이용이 가능합니다.

4,300원

4

정보기술의 발달과 개발된 시스템의 규모가 증대되고, 여러 IT 환경이 융합됨에 따라 사이버 위협 및 공격이 증가하고 있으며, 공격 양상도 복잡해지고 있다. 이러한 위협에 대응하기 위해서는 실제와 유사한 사이버공격 훈련이 필요하며, 훈련에는 공격 시나리오가 필수적으로 수립되어야 한다. 하지만, 한 번 수립된 시나리오는 반복해서 사용되어 지속적으로 발전하는 최신 사이버위협을 반영하기 어려운 단점이 존재한다. 본 논문에서는 최신의 보안위협이 공개된 보안위협 지식 데이터베이스를 이용하여 공격 시나리오와의 연계성을 도출하고, 시나리오 개발에서의 활용 방안을 제안한다.

5

대학 학사 데이터베이스 통합 보안 모델 설계 KCI 등재

정윤수, 신승수

한국디지털정책학회 디지털융복합연구 제10권 제4호 2012.05 pp.235-241

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 교육 수월성 제고와 질적 수준 향상을 위해서 대학에서는 정보화를 추진하고 있으나 개인정보를 비롯한 학사행정과 관련된 중요 정보들이 학사 데이터베이스에 집적되어 있어 그에 따른 보호 대책이 필요하다. 이 논문에서는 학사 데이터베이스 구축에 사용되는 DBMS의 접근제어, 기밀성, 무결성 그리고 보안감사 등이 보장되도록 대학의 현실에 적합한 학사 데이터베이스 통합 보안 모델을 제안한다. 제안 모델은 상당 수 대학들이 데이터베이스 보안 제품을 활용하고 있지 못한 여건을 고려하여 DBMS가 제공하는 기능만으로 보안의 가장 핵심 요소인 기밀성 등을 구현하는 세부 방안을 제시하고 있다.

To improve educational excellence and quality, academies carry forward integrative security model related to academic affairs including personal information. This paper proposes an integrative security model for academic affairs database, which guarantees DBMS access control, confidentiality, integrity, and security inspection. This proposed model considered that most academies can’t make good use of data security product and suggests a detailed measure to realize the confidentiality based on the function of DBMS.

6

4,000원

If the classification system currently used to develop artificial intelligence security search automatic reading technology is used, problems such as data integrity, security, and quick decision-making using data may occur. Using the newly proposed 10-digit classification system, first, it is possible to quickly find and analyze necessary information using systematically structured data. Since it is possible to register data objectively according to the classification system from the time it is registered, the performance of analysis and processing on stored data is improved and time and cost are reduced. In addition, detailed trends by data can be compared and analyzed through continuous management. Second, data consistency, integrity, and security can be improved. Consistency can be maintained in data input because data is stored according to a specific category, and security can be strengthened by limiting access to sensitive or security-requiring data belonging to a specific category. As a result, it is possible to improve the efficiency of database algorithms, and ultimately, the accuracy and speed of product search will be improved by assisting search personnel in security search using AI X-ray.

7

대학 학사 데이터베이스 보안현황 조사 분석 비교에 관한 연구 KCI 등재

정윤수, 박남규, 신승수

한국디지털정책학회 디지털융복합연구 제10권 제3호 2012.04 pp.113-119

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

IT 기술의 급속한 발전은 대학의 질적 수준 향상을 위한 정보화 추진을 가속화하고 있으나 학사행정과 관련된 중요 정보들은 학사 데이터베이스에 집적되어 있어 보안의 취약성에 대한 보안 대책이 요구되고 있다. 이 논문에서는 대학이 보유하고 있는 가장 중요한 정보라 할 수 있는 학사 데이터베이스의 보안성을 지속적으로 유지 및 향상시킬 수 있는 운영 모델을 도출하기 위해서 국내 각 대학들의 데이터베이스 보안 실태를 조사 분석한다. 또한, 국내상당 수 대학들이 데이터베이스 보안 제품을 활용하고 있지 못한 여건을 고려하여 DBMS가 제공하는 기능만으로 보안의 가장 핵심 요소인 기밀성 등을 구현하는 세부 방안을 제시한다.

Even though the rapid development of IT technique accelerates informationization for quality improvement of university, security measures are needed for security problems because the major information related to academic affairs is centered on academic database. In this paper, we research and analyze the actual condition of database security of domestic university to develop process model that can consistently keep and improve the security of academic database which is the most important data in university. Also, considering the situation that a lot of universities can't use database security product, we propose details that implement the most important key part like confidentiality with the function that DBMS provides only.

8

Database Security Model in the Academic Information System SCOPUS

Ema Utami, Suwanto Raharjo

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.3 2014.05 pp.163-174

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Database plays an important role on both web-based or desktop based academic information system (AIS) in Indonesian higher education institutions (HEI). Nowadays web-based AIS dominates in Indonesian HEI, almost every HEI uses web-based AIS with relational database management system (RDBMS) as database software. Relational database systems such as Oracle, MySQL, MS SQL Server or PostgreSQL are familiarly used as database management system in the AIS. There are many researches on development of AIS in HEI but none of them is discussing database security and integrity. This research will perform the analysis of database security model that could be used in AIS such as table constraints, table relationships and role-based access control (RBAC).

9

An Experimental Evaluation for a New Column – Level Access Control Mechanism for Electronic Health Record Systems

Pham Thi Bach Hue, Sven Wohlgemuth, Isao Echizen, Nguyen Dinh Thuc, Dong Thi Bich Thuy

보안공학연구지원센터(IJUNESST) International Journal of u- and e- Service, Science and Technology Vol.4 No.4 2011.12 pp.1-14

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Despite the fact that health care providers such as Google Health and Microsoft Corp.'s Health Vault comply with the U.S Health Insurance Portability and Accountability Act (HIPAA), the privacy of patients is still at risk. There needs to be a strategy for securing the privacy of patients when exchanging health records between various entities over the Internet. Several encryption schemes and access control mechanisms have been suggested to protect the disclosure of a patient’s health record especially from unauthorized entities. However, by implementing these approaches, data owners are not capable of controlling and protecting the disclosure of the individual sensitive attributes of their health records. This raises the need to adopt a secure mechanism to protect personal information against unauthorized disclosure. We propose a new column-level access control mechanism that is based on subkeys, which would allow a data owner to further control the access to his data at the column-level. We also propose a new mechanism to reduce the number of keys held by each user in the system. Therefore, the number keys maintained by the data owner is also reduced. The experimental results show that our proposals can ensure system’s availability, thus applicable in the real world. Keywo

10

An Experimental Evaluation for a New Column – Level Access Control Mechanism for Electronic Health Record Systems

Pham Thi Bach Hue, Sven Wohlgemuth, Isao Echizen, Nguyen Dinh Thuc, Dong Thi Bich Thuy

보안공학연구지원센터(IJUNESST) International Journal of u- and e- Service, Science and Technology Vol.4 No.3 2011.09 pp.73-86

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Despite the fact that health care providers such as Google Health and Microsoft Corp.'s Health Vault comply with the U.S Health Insurance Portability and Accountability Act (HIPAA), the privacy of patients is still at risk. There needs to be a strategy for securing the privacy of patients when exchanging health records between various entities over the Internet. Several encryption schemes and access control mechanisms have been suggested to protect the disclosure of a patient’s health record especially from unauthorized entities. However, by implementing these approaches, data owners are not capable of controlling and protecting the disclosure of the individual sensitive attributes of their health records. This raises the need to adopt a secure mechanism to protect personal information against unauthorized disclosure. We propose a new column-level access control mechanism that is based on subkeys, which would allow a data owner to further control the access to his data at the column-level. We also propose a new mechanism to reduce the number of keys held by each user in the system. Therefore, the number keys maintained by the data owner is also reduced. The experimental results show that our proposals can ensure system’s availability. So they are applicable in the real world.

11

데이터베이스 보안 취약 사이트의 공격 및 대응 방안 KCI 등재후보

황성운

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.8 No.2 2011.04 pp.203-213

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 논문에서는 보안이 취약한 가상 사이트 환경을 구축하고 이의 문제점 - DB 접속 정보 파일을 루트 디렉토리에 두는 것 - 을 분석하고 보완할 수 있는 방안을 제시하였다. 이 문제점을 본 논문에서는 휴대폰 인증 채널이라는 부가 채널을 통해 사용자 인증을 제공함으로써 해결하고 있다.

In this paper, we show an attack scenario on Web sites with vulnerable security caused by putting a DB include file in index root and suggest its contermeasure by introducing additional cell-phone authentication channel.

12

Analytical Approach for Security of Sensitive Business Database SCOPUS

Anusha Gupta, Sanjay Kumar Dubey

보안공학연구지원센터(IJDTA) International Journal of Database Theory and Application Vol.8 No.3 2015.06 pp.49-56

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Sensitive database security is an integral part to meet the company's abeyance. Securing the sensitive data in mixed database environment has increased over the past few years. This paper conducts the literature review about providing solutions to secure all databases. This will help the users to know what all things are required to be protected when they are planning to protect the database. Sometimes in some of the business it requires highest level of security even if the performance is being compromised. So, this paper will help user to choose appropriate security mechanism to for the sensitive database according to their business requirement. A brief view of securing the network, server and operating system is also provided in the present paper. Aim of this research is to provide the security to sensitive data at all the three levels physical security, network security, information security from unauthorized user.

13

Database Security System for Information Protection in Network Environment

Jung, Myung-Jin, Lee, Chung-Yung, Bae, Sang-Hyun

[Kisti 연계] 한국산학기술학회 한국산학기술학회 학술대회논문집 2003 pp.211-215

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Network security should be first considered in a distributed computing environment with frequent information interchange through internet. Clear classification is needed for information users should protect and for information open outside. Basically proper encrypted database system should be constructed for information security, and security policy should be planned for each site. This paper describes access control, user authentication, and User Security and Encryption technology for the construction of database security system from network users. We propose model of network encrypted database security system for combining these elements through the analysis of operational and technological elements. Systematic combination of operational and technological elements with proposed model can construct encrypted database security system secured from unauthorized users in distributed computing environment.

14

Database Security and Integrity for the Republic of Korea Military

Kim, Se-Kyung, Lim, Seong-Nam

[Kisti 연계] 한국국방경영분석학회 한국국방경영분석학회지 Vol.12 No.2 1986 pp.82-99

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

15

A Study of Database Design and Construction for Voltage Security On-line Monitoring System(VSECOMs)

임종호, 김건중, 최장흠, 최익순, 한현규, 김태균, 전동훈

[Kisti 연계] 대한전기학회 대한전기학회 학술대회논문집 1999 pp.1253-1255

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

This paper presents database design and construction for VSECOMs (Voltage Security On-line Monitoring System). The database design has steps of requirements collection and analysis, conceptual design, logical design, and physical design. For interconnection between New EMS and VSECOMs to get the needed data, Snapshots in ORACLE are proposed. It proved the proposal to be compatible through the case study.

16

Legislation, Co-ordination Centre and Database System to Respond Security Incidents at Sea

Deyi, Gao

[Kisti 연계] 한국항해항만학회 한국항해항만학회 학술대회논문집 2004 pp.155-159

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The International Ship and Port Facility Security (ISPS) Code has come into force on July 7$^{th}$ 2004. It would therefore be prudent that all parties' concerned put in place, methodically, systematically and as soon as possible, all the necessary infrastructure needed to give effect to all the decisions of the Conference. But the ISPS Code doesn't have the details during implementation. For example, how to legislate, administrate\ulcorner How are the data relating to security incident saved\ulcorner So, the author will lay emphasis to expatiate on three aspects in this thesis on the basis of the fact of anti-terrorism at sea.

17

Database 복호화 키 저장 위치에 따른 Database 보안성 연구

이창원, 최형기

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2020 pp.376-379

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

메신저 애플리케이션은 사용자의 채팅 로그나 전화번호와 같은 개인 정보를 데이터베이스에 저장하며, 비밀번호 관리 애플리케이션은 사용자의 비밀번호 정보를 데이터베이스에 저장한다. 따라서 사용자의 개인 정보들이 들어 있는 데이터베이스를 안전하게 보호하는 것은 매우 중요하다. 본 논문에서는 암호화된 데이터베이스를 복호화하기 위한 키를 저장하는 위치에 따라 애플리케이션을 분류하고, 각 경우 보안성이 어떻게 달라지는지에 관한 연구를 수행했다.

18

상세 접근 제어를 위한 데이터베이스 보안 모델

이금순, 김영호, 원용관

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2002 pp.889-892

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

데이터베이스를 사용하는 정보가 다양해짐에 따라 요구사항 또한 다양해져서 데이터 하나 하나에 대한 접근제어의 필요가 요구되고 있다. 이러한 데이터별 접근제어를 만족하는 보안정책을 정의하고, 정보의 기밀성, 무결성 및 가용성을 유지하는 데이터베이스 보안 모델을 제안한다. 본 논문의 목적은 공통된 data에 대하여 다양한 유형의 접근제어와 지속적으로 변화가 요구되는 접근제어 요구에 대한 해결방법을 제공한다.

19

상세 접근 통제와 안전한 데이터 관리를 위한 데이터베이스 보안 시스템

조은애, 문창주, 박대하, 홍성진, 백두권

[Kisti 연계] 한국정보과학회 정보과학회논문지:데이타베이스 Vol.36 No.5 2009 pp.352-365

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 데이터베이스의 보안 취약성으로 인해, 내부의 비인가자 또는 인가자의 데이터 접근에 대한 통제 정책이 제대로 이루어지지 않아 정보 유출 사고가 발생하고 있다. 현재의 데이터베이스 권한부여 방식은 관리자가 데이터베이스 오브젝트에 접근할 수 있는 권한을 사용자에게 부여하는 방식이다. 그러나 이러한 방법은 다양한 사용자 접근을 통제하기 위한 정책을 데이터베이스에 적용할 수 없다. 또 다른 데이터베이스 보안 방법인 데이터 암호화는 데이터의 인덱싱이 어렵다는 단점이 있다. 본 논문에서는 다양한 보안 정책을 반영하기 위해, 클라이언트에서 데이터베이스 서버로 요청되는 네트워크상의 패킷 분석을 통한 데이터베이스의 접근 통제 시스템을 제안한다. 제안된 보안 시스템에서는 특정 일자 및 시간, SQL에 포함되어 있는 특정 문자열, 결과 데이터 수, 레벨에 따른 컬럼 제한 등의 통제 정책을 적용할 수 있을 뿐만 아니라 사용자 정보 및 SQL의 위변조를 방지하기 위해서 공개키 인증과 메시지 인증코드 교환으로 무결성을 확보할 수 있다.

Recently, data access control policies have not been applied for authorized or unauthorized persons properly and information leakage incidents have occurred due to database security vulnerabilities. In the traditional database access control methods, administrators grant permissions for accessing database objects to users. However, these methods couldn't be applied for diverse access control policies to the database. In addition, another database security method which uses data encryption is difficult to utilize data indexing. Thus, this paper proposes an enhanced database access control system via a packet analysis method between client and database server in network to apply diverse security policies. The proposed security system can be applied the applications with access control policies related to specific factors such as date, time, SQL string, the number of result data and etc. And it also assures integrity via a public key certificate and MAC (Message Authentication Code) to prevent modification of user information and query sentences.

20

쿼리 은폐 기법을 활용한 위링크의 데이터베이스 보안 구현

임복출, 김인구, 김순곤

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2016 pp.356-357

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

기존에 PC나 서버에 설치하여 제공되던 방식에서 클라우드 컴퓨팅 환경의 서비스 방식이 일반화되어가고 있다. 클라우드 환경에서 발생하는 데이터는 형태와 양이 기존 방식처럼 관리하는 것은 불가능에 가깝다. 이러한 시대적 흐름에 발맞춰 데이터의 처리 및 저장과 관련된 기술의 중요성도 더욱 커져가고 있다. 본 논문에서는 중소기업을 위한 프레임워크인 위링크(WeLink)내에서 데이터 저장, 조회, 수정, 삭제 등을 위한 보안방안을 모색하였다. 또한 프레임워크 기반으로 데이터 보안을 위한 쿼리나 데이터베이스에 상관없이 서비스를 제공할 수 방법을 제안하였다.

 
1 2 3
페이지 저장