Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 974
No
1

4,000원

오늘날 많은 기업들이 정보보안 사고로 인해 기업의 정보가 유출되면서 기업 이미지 훼손, 매출액 감소, 손해배상금 지불 등 직간접적인 피해를 경험하고 있다. 이에 따라 정보보안에 대한 중요성은 부각되고 있지만 정보보안 투자의 효과를 계량적으로 추정한 연구는 부족한 실정이다. 이로 인해 한정된 보안예산 으로 최적의 정보보안 정책을 수립하기 위한 의사결정에 어려움이 있다. 본 연구는 포아송 회귀 분석 방 법을 사용하여 기업의 정보보안 투자 중 정보보안 교육이 침해사고에 미치는 영향에 대하여 실증적인 연 구를 하고자 한다. 또한 교육 대상을 관리자와 일반직원으로 분류하여 살펴보고 정보보안 교육 서비스의 아웃소싱 여부에 따른 교육의 효과를 측정한다. 본 연구는 정보보안 교육의 효과를 계량적으로 측정하였 다는 점에서 학문적 공헌도를 가진다.

Recently, many firms have faced with direct and indirect incidents such as reputation decline, decreased sales, damage compensation and other damages caused by information security breaches. Although the importance of information security protection has been growing significantly, firms still have difficulties in decision making due to lack of measurable performance indicators of the investment effectiveness. This research empirically examines the impact of information security education on information security incidents using Poisson regression analysis. This study investigates the impact of information security education in educatee group perspective; manager group and employee group. This research contributes to business organizations by establishing a method to measure security investment which can support firm’s investment decision on security education. The research also contributes to academia by estimating the effectiveness about information security education quantitatively.

2

Korea’s “Foreign Trade Act” states that the goods(including technology determined by Presidential Decree) on which restriction, such as export license, is required for maintaining international peace and security as well as national security in accordance with the principles of the International Export Control Regimes, are to be referred to as “Strategic Item” and the list of such goods designated are publicly notified by the “Public Notice on Trade of Strategic Goods(hereinafter, the Public Notice)”. Information security systems, equipment and components above control parameter specified under control number 5A002.a of such list are classified as “Strategic Items”. In fact, this entry covers the majority of the information security equipment such as switch, firewall, server and network equipment. This paper studies negative classification cases of items that meet the control threshold of the list on the Public Notice but nonetheless excluded by the de-control notes available for certain items such as those sold in mass market or those with encryption technology exclusively for authentication. The date of classification results issued through the Information System for Management of Export and Import of Strategic Items(Yestrade) over the past 5 years are used. By Analyzing such data, we try to make recommendations for improvements.

3

조직 구성원의 정보보안 인식에 영향을 미치는 동기 및 심리적인 요인 분석 KCI 등재

전재찬, 신동천

한국EA학회 정보화연구 제15권 2호 2018.06 pp.165-177

※ 기관로그인 시 무료 이용이 가능합니다.

4,500원

정보통신기술의 급속한 발전에 따라 조직에서 정보보안에 대한 위협에 대처하는 것은 매우 중 요한 일이다. 보안 위협에 대처하기 위한 조직의 많은 노력도 조직 구성원의 보안 인식 강화가 선행 되어야 효과를 극대화 할 수 있음은 자명한 사실이다. 본 논문에서는 사람 중심의 보안관점에서 보안 인식을 유발하는 동기요인과 개인의 심리적 요인이 보안 인식에 미치는 영향을 분석한다. 결과에 따 르면 외적 동기요인이 내적 동기요인보다 보안인식에 더 큰 영향을 끼치고 있음을 알 수 있다. 또한 개인의 심리적인 요인 중의 하나인 지각된 심각성이 보안인식에 미치는 영향을 조절할 수 있음을 알 수 있다.

In accordance with the rapid development of information communication technology, to cope with security risks in the organization. It is evident that security perception of individual members plays very important roles in making the efforts to treat the risks by organizations effective. In this paper, we analyze the affects of motivational factors and psychological factors on the security perception from a human-centric security perspective. According to results, the external motivational factors have more effects on the security perception than the internal motivational factors. In addition, we can see that the perceived seriousness which is one of the psychological factors can control the effects on the security perception.

4

유비쿼터스컴퓨팅환경의 정보보안 인력공급시스템 연구 KCI 등재후보

김용훈

한국경영컨설팅학회 경영컨설팅연구 제11권 제3호 통권 제30호 2011.09 pp.95-115

※ 기관로그인 시 무료 이용이 가능합니다.

5,700원

5

4,500원

본 연구의 목적은 정보보안 정책 준수 의도의 선행변수인 정보보안에 대한 인지된 중요성에 유의한 영향을 미치는 요인을 규명하는 것이다. 이를 위해 구조방정식 모형을 기반으로 제안 모형을 분석했다. 분석결과, 첫째, 정보보안 교육의 효과성은 정책 준수에 따른 인지된 비용에 통계적으로 유의한 영향을 미치지 못하는 것으로 나타났다. 둘째, 정보보안 정책 의 효과성은 정책 준수에 따른 인지된 비용에 유의한 영향을 미치는 것으로 나타났다. 셋째, 인지된 취약성은 정책 준수에 따른 인지된 비용에 유의한 영향을 미치는 것으로 나타났다. 넷째, 정책 준수에 따른 인지된 비용은 정보보안에 대한 인지된 중요성에 유의한 영향을 미치는 것으로 나타났다. 다섯째, 정보보안 침묵에 대한 경영진의 태도는 구성원들의 보안 침묵 행위에 유의한 영향을 미치는 것으로 나타났다. 여섯째, 정보보안에 대한 의사소통 기회는 구성원들의 보안 침묵 행위에 유의한 영향을 미치는 것으로 나타났다. 마지막으로 구성원들의 보안 침묵 행위는 정보보안에 대한 인지된 중요성에 유의한 영향을 미치는 것으로 나타났다.

The ultimate intention of this research is to identify the factors that have a significant effect on the perceived importance of information security as the antecedent of intention to information security policy compliance. We found that the effectiveness of information security training program did not have statistically significant effect on the perceived cost of policy compliance. Second, the effectiveness of information security policy has significant influence on the perceived cost of policy compliance. Third, perceived vulnerability has a significant effect on the perceived cost of policy compliance. Fourth, perceived cost of policy compliance has a significant effect on perceived importance of information security. Fifth, supervisor's attitude toward information security silence has a significant effect on employee silent behavior towards information security. Sixth, communication opportunities towards information security has a significant influence on employee silent behavior towards information security. Finally, it was shown that employee silent behavior towards information security had a significant influence on the perceived importance of information security.

6

지각된 인터넷 정보보호 의식의 특성과 활동에 관한 연구

박승배, 민경식, 정남호

한국경영컨설팅학회 경영컨설팅연구 제10권 제3호 통권 제26호 2010.09 pp.1-19

※ 기관로그인 시 무료 이용이 가능합니다.

5,400원

7

정보보호 전문인력 양성을 위한 필수요구지식 및 교육인증 프로그램 KCI 등재

김정덕, 백태석

한국디지털정책학회 디지털융복합연구 제9권 제5호 2011.10 pp.113-121

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

정보보호에 대한 중요성이 점차 증대됨에 따라 관련 업무를 수행할 수 있는 전문인력에 대한 수요 역시 증가하고 있다. 하지만, 양질의 전문인력을 양성하는데 있어 현실적인 문제점이 존재하며 이에 대한 장·단기적 해결방안이 요구된다. 본 논문에서는 정보보호 전문인력 양성을 위한 정보보호 필수요구지식을 직무에 따라 제시하고, 융합전공 기반의 교육인증 프로그램 및 향후연구를 제안하였다. 이를 위하여 미국의 정보보호 교육인증 프로그램을 분석하는 한편, 국내 현실을 반영한 정보보호 교육인증 프로그램의 성공요인을 제시하였다.

As the importance of information security grows, the demand of professionals in information security field is continuing to increase. In developing as information security professionals, however, there are practical problems to be solved in advance. This study defines the body of essential knowledge(EBK) for information security professional development; on the other hand, this study suggests a education program as a multidisciplinary major based on the EBK.

8

4,600원

최근 정보기술의 발달로 해킹, 개인정보 유출 등의 각종 보안 위협이 증가 하고 있다. 이러한 보안 위협의 증가로 인하여 기업이나 기관에서 정보 보호라는 업무가 정보보호최고책임자(CISO)의 필요성까지 언급될 정도로 중요한 업무로 부상하고 있다. 정보보호최고책임자는 기업의 정보보호 업무뿐만 아니라 기업의 다른 보안 업무까지 책임을 지고 있고 이들의 의견이나 인식 그리고 역할이 기업이나 기관에서 중요한 비중을 차지하고 있다. 기업 내 비중이 높아진 정보보호최고책임자의 역할인식을 정리하고 이들 역할에 대한 인식이 조직의 정보보호성과에 영향이 있는가를 실증 연구하였다. 연구결과 정보보호최고책임자의 역할인식이 조직의 정보보호 성과에 영향이 있음을 확인 할 수 있었고 역할 인식별로도 성과에 미치는 영향이 차이가 있음을 발견 할 수 있었다. 연구결과는 조직의 정보보호 성과향상을 위하여 정보보호최고책임자의 역할인식이 중요하다는 점과 역할인식과 정보보호성과와는 밀접한 영향이 있음을 시사한다.

The recent technology development has been impacting on the growth of hacking and private information leakage. Such a security threat has made companies and agencies have keen interest in the information security as they even discuss the need of Chief Information Security Officer(CISO). Opinions, recognition for the job and the performance of CISO are believed to be significant as the job is concerned with not only the company information security but also the company’s other business security. In this study, the role recognition of CISO which has been forming an ever-greater part of the company was analyzed and an empirical study on how the recognition of CISO would affect the organizational information security was conducted. According to the results, it was confirmed that the role recognition of CISO would have an influence on the organizational information security while a level of the role recognition would also affect the performance. The results prove that the CISO role recognition is of the significance for the organizational information security as the recognition and the information security are closely related.

9

융합 보안관제시스템 구축 활성화 방안 연구 KCI 등재

원종혁, 임욱빈, 박유진

한국EA학회 정보화연구 제12권 4호 2015.12 pp.535-552

※ 기관로그인 시 무료 이용이 가능합니다.

5,200원

현대사회는 IT기술의 급속한 발전으로 인해 새로운 사회현상과 문화가 등장하게 되면서 다양한 분야의 융합이 이루어지고 있다. 이로 인해 정보자산의 가치도 함께 증가하게 되면서 이를 노리는 정보 유출 및 보안사고에 따른 피해도 급증하게 되었다. 이러한 시대적 변화에 대응하고자 보안 분야도 더욱 변화된 보호체계가 필요하게 되었다. 본 연구는 최근 들어 메가트랜드로 자리 잡고 있는 융합 보안관제 시스템의 도입에 있어서 공급자 관점이 아닌 수요자 관점에서 접근하기 위해 선행연구를 통한 정부정 책과 제도를 분석하였으며, 실제 구축사례를 통한 고객요구사항과 한계점을 파악하고 실제 운영관리자 와 관련업계 종사자들의 설문조사를 바탕으로 융합 보안관제시스템의 문제점과 시사점을 도출하였다.

Due to the rapid development of IT technology in modern times, as new social circumstances and cultures emerge, the integration of various industries is taking place. The value of information assets has seen an accompanied increase with this phenomenon followed by a dramatic increase in damaging cases of information leakage and security related breaches. In order to address such changes in the information age frontier, there is a need for appropriate changes to the security systems in the security industry. This research takes the perspective not of the supplier for the recently trending implementation of integrated security control systems, but approached this issue from the perspective of the demanding customer, and through analyzing government policies and guidelines through previous research, and by determining the needs of the customer and the limitations of the systems through case studies on actual implementations of security solutions, and finally, based on survey research of hands on system administrator and professionals in related industries, the problematic issues and potential suggestions for integrated security control systems were deduced.

10

What Matters in Cybersecurity? The Role of Citizen Perception and Attributes

Michael J. Ahn, Tae-Hyung Park, Chae-Hong Lim

인하대학교 글로벌e거버넌스연구소 IJPGN Volume 3 Number 1 2015.06 pp.1-22

※ 기관로그인 시 무료 이용이 가능합니다.

5,800원

This study aims to investigate the extent of citizen cyber threat awareness and the factors that influence behaviors to counter these threats. Using sur-vey data conducted by the South Korean government, on a stratified sam-ple of 6,000 citizens, this study found that the general public was well aware of the presence of various cyber threats. Citizens perceived that these threats have a high likelihood of occurring to them. While this study found a positive relationship between the perception of threats and security actions, most citizens only took a few essential security measures. These findings reveal an online environment where the responsibility of online security falls chiefly on individual citizens. Ultimately, this creates a situa-tion that leaves citizens vulnerable; there is high level of cyber threat awareness, but a low level of preventative actions. This study discusses policy implications related to these findings and citizen perception of the role of government in cybersecurity.

11

이미지 분류는 관심이 높은 연구 분야로 이미지 데이터의 방대한 양을 시각적 콘텐츠에 따라 다양한 클래스로 분류 한다. 연구자들은 다른 카테고리에 이미지를 분류하기 위한 다양한 하위 수준 특징 기반 기술을 제시하고 있다. 그 러나, 효율적이고 효과적인 분류 및 검색은 여전히 시각적인 내용의 복잡한 특성으로 인해 어려운 문제로 남아있다. 또한, 기존의 정보검색기술은 보안에 취약하여, 환자의 기록 및 법 집행 기관의 데이터베이스와 같은 개인의 시각적 콘텐츠를 제3자에 의해 검색이 쉬웠다. 그러므로, 우리는 보안 이미지 분류 및 정보 검색에 대한 이미지 스테가노그 래피를 사용하여 새로운 온톨로지 기반의 프레임 워크를 제안한다. 제안된 프레임워크는 하위 계층 이미지 특징을 효율적인 분류 결과인 온톨로지의 상위 계층 컨셉의 매핑을 위해 도메인 특징 온톨로지를 사용한다. 또한 제안된 방 법은 내용 안에 비밀 메시지와 같은 이미지의 의미를 숨기고 정보 검색 프로세스를 제3자로부터 보호하기 위해 이미 지 스테가노그래피를 이용한다. 제안된 프레임워크는 기존기술의 복잡도를 최소화하고 개인의 이미지 데이터베이스 로부터 안전하고 실시간 시각적 콘텐츠 검색을 위해 적합한 기술을 증대시킨다. 다른 최신 기술의 시스템과 비교하 여 실험한 결과 제안된 프레임 워크의 효율성, 유효성 및 보안을 확인 하였다.

Image classification is an enthusiastic research field where large amount of image data is classified into various classes based on their visual contents. Researchers have presented various low-level features-based techniques for classifying images into different categories. However, efficient and effective classification and retrieval is still a challenging problem due to complex nature of visual contents. In addition, the traditional information retrieval techniques are vulnerable to security risks, making it easy for attackers to retrieve personal visual contents such as patient’s records and law enforcement agencies’ databases. Therefore, we propose a novel ontology-based framework using image steganography for secure image classification and information retrieval. The proposed framework uses domain-specific ontology for mapping the low-level image features to high-level concepts of ontologies which consequently results in efficient classification. Furthermore, the proposed method utilizes image steganography for hiding the image’s semantics as a secret message inside them, making the information retrieval process secure from third parties. The proposed framework minimizes the computational complexity of traditional techniques, increasing its suitability for secure and real-time visual contents retrieval from personalized image databases. Experimental results confirm the efficiency, effectiveness, and security of the proposed framework as compared with other state-of-the-art systems.

12

4,000원

13

전사적 정보기술 리스크 체계를 위한 엔터프라이즈아키텍처 활용 KCI 등재

박주석, 구자면, 김승현, 김이환

한국EA학회 정보화연구 제10권 4호 2013.12 pp.451-466

※ 기관로그인 시 무료 이용이 가능합니다.

4,900원

기업들은 정보기술 리스크(IT Risk)에 대하여 어떻게 대처하고 있을까? 금융기관이나 공공기관 은 태생적으로 이미 위험관리를 적극적으로 수행하고 있다. 정보기술에 대한 위험관리도 지난 10년 동안 전산망 마비, 해킹 사고, 디도스 공격, 고객정보 유출 등을 겪으면서 적극적으로 대응해 왔다. 특 히 2011년 농협사태는 IT 성과보다는 IT 보안을 훨씬 중요하게 보는 계기가 되었다. IT 보안 인력과 예산이 대폭 강화되고 망분리 사업이 추진되는 것이 대표적인 사례이다. 하지만 그동안 IT 위험관리 는 특정 기술에 대한 사전 대응 및 사후 대응 강화에 집중되었다. 현재 IT 위험관리는 단편적 관리에 서 종합적 관리로 전환되고 있다. 최근에 많은 기업들이 전사 차원의 정보기술 리스크 거버넌스(IT Risk Governance) 체계를 구축하고 있거나 구축하는 계획을 갖고 있다. 하지만 아직도 IT보안은 전 사적으로 통합되지 못하였으며, IT 위험관리 프로세스는 조직에 내재화 되지 못하였고, IT 성과관리 와 연계성은 고려하지 못하고 있다. 본 논문에서는 IT 관리와 기술을 효과적으로 연계하기 위하여, 그 리고 IT 성과와 IT 위험을 균형되게 관리하기 위하여 엔터프라이즈아키텍처(EA: Enterprise Architecture) 활용을 제안하고자 한다.

Many corporations have increased thier investment in information technology (IT). In most corporations, more IT investment results in much higher productivity. On the other hand, most corporations are exposed to direct and indirect IT risk such as hacking, leakage of information, system destruction. Thus corporations have to establish information security systems. Information security means physical and logical correspondence against several threats and disaster. In the past, researches on information security focused on solutions against individual IT threats. Recently, researches have paid more attention to risk management for various IT threats together. For example, some corporations are establishing or plan to establish IT risk governance framework. In this paper we deal with not only IT governance issues but also IT architecture issues becasue corporations should integrate various IT risk solutions and manage them in an enterprise perspective. This paper attempts to apply Enterprise Architecture (EA) concept to IT risk framework. In this paepr we propose security architecture as a part of Enterprise Architecture and we also review the benefits and costs of security architecture.

14

프라이버시 무관심에 영향을 미치는 요인에 관한 연구 KCI 등재

정태석, 임명성

한국디지털정책학회 디지털융복합연구 제10권 제6호 2012.07 pp.49-59

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

본 연구는 왜 인터넷 사용자들이 자신의 개인정보 프라이버시에 무관심한지를 설명하는 것을 목적으로 한다. 이를 위해 Nate.com을 관련 사례로 선정하였다. Nate.com은 최근에 외부 침입에 의한 개인정보 유출사고를 경험하였다. 이 때 Nate.com은 이러한 사실을 사용자들에게 알렸으나 대부분의 사용자들은 Nate.com을 탈퇴하지 않고 여전히 이용하고 있다. 이를 무관심 관점에서 설명하기 위해 질적 그리고 양적 기법을 수행하였다. 우선, 연구설계를 위해 240명의 Nate.com 사용자를 인터뷰하였다. 인터뷰를 통해 나온 결과를 기반으로 연구모형을 수립하고 설문을 구성하였으며, 이를 배포하여 데이터를 수집하였다. 가설 검증은 구조방정식 모형을 통해 수행되었다.

This study is to explain why internet users are unconcerned with their privacy information. For this purpose, this study focuses on the Nate.com case. Nate.com recently suffered from external intrusion. They announced this fact to their users. However, users did not leave the Nate.com. To explain the reason, this study used a combination of qualitative and quantitative techniques. The grounded theory approach was used to analyze responses to open-ended questions answered by 240 Nate.com users. Using these responses, a survey instrument was developed. Survey results were analyzed using structural equation modeling. The conclusions and implications are discussed.

15

5,100원

사이버공간은 정보통신기술의 비약적인 발전과 더불어 정보기기와 컴퓨터 그리고 인터넷 등의 네트워크로 연결된 가상의 공간으로 이미 국민 생활의 보편적인 영역으로 자리매김 하고 있다. 따라서 시공간의 제약을 벗어나 발생하는 모든 사이버공격을 정부와 민간 어느 하나도 단독으로 차단하기에는 분명한 한계가 있다. 게다가 사이버공격으로 초래되는 사이버위기는 현실세계의 물리적 질서혼란과 달리 특정개인에 대한 것일지라도 국가전체의 위기로 확대될 수 있다. 우리나라는 아직 국가차원에서 사이버위기를 체계적으로 관리할 수 있는 제도와 구체적 방법·절차가 확립되어 있지 않아 사이버위기 발생시 국가안보와 국익에 중대한 위험과 막대한 손해를 끼칠 우려가 있다. 과거 산업사회와 정보화사회에 비하여 유비쿼터스 사회에서 정보의 침해문제는 더욱 심각해질 것이다. 따라서 국가위기관리기본법의 제정추진과 함께 사이버공간과, 유비쿼터스 환경을 포함하는 차원에서의 법의 제정이 이루어져야 할 것이다. 이법은 유비쿼터스환경에서의 위기관리에 관한 개념을 명확히 하고, 유비쿼터스 환경에서의 정보보안 및 위기관리를 국가차원에서 종합적이고 체계적인 대응을 하기 위하여 유비쿼터스위기관리센터를 대통령 직속기관으로 두어야 할 것이다.

As an imagined space connected by network such as information equipment, computer, and internet along with the rapid development of IC(information and communications) technology, cyber space is commonly positioned into the people’s life. Therefore, there is a certain limit that either the people or the government prevents solely cyber attack occurring regardless of barriers of time and space. In addition, cyber risks caused by cyber attack can be expanded as national risks even if it is about a certain individual unlike physical order chaos in the real world. Korea doesn’t establish institutions and specific methods and procedures to systematically manage national cyber risks yet, which may cause severe danger and huge damage to national security and interest. Information infringement problems will be more serious in the ubiquitous society compared to the industrial society and information society in past. Therefore, the legislation of the National Crisis Management Basic Act and of the law regarding cyber space and ubiquitous environment is required. This law needs to have the ubiquitous risk management center as an institute directly responsible to the President in order to clarify the concept risk management of ubiquitous environment and cope with comprehensively and systematically information security and risk management.

16

5,500원

17

Rule Protecting Scheme for Snort

Son, Hyeong-Seo, Lee, Sung-Woon, Kim, Hyun-Sung

한국정보기술응용학회 한국정보기술응용학회 학술대회 2005년도 6th 2005 International Conference on Computers, Communications and System 2005.11 pp.259-262

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

This paper addresses the problem of protecting security policies in security mechanisms, such as the detection policy of an Intrusion Detection System. Unauthorized disclosure of such information might reveal the fundamental principles and methods for the protection of the whole network. In order to avoid this risk, we suggest two schemes for protecting security policies in Snort using the symmetric cryptosystem, Triple-DES.

18

Information Security on Learning Management System Platform from the Perspective of the User during the COVID-19 Pandemic

Mujiono, Sadikin, Rakhmat, Purnomo, Rafika, Sari, Dyah Ayu Nabilla, Ariswanto, Juanda, Wijaya, Lydia, Vintari

[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.21 No.1 2023 pp.32-44

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Information security breach is a major risk in e-learning. This study presents the potential information security disruptions in Learning Management Systems (LMS) from the perspective of users. We use the Technology Acceptance Model approach as a user perception model of information security, and the results of a questionnaire comprising 44 questions for instructors and students across Indonesia to verify the model. The results of the data analysis and model testing reveals that lecturers and students perceive the level of information security in the LMS differently. In general, the information security aspects of LMSs affect the perceptions of trust of student users, whereas such a correlation is not found among lecturers. In addition, lecturers perceive information security aspect on Moodle is and Google Classroom differently. Based on this finding, we recommend that institutions make more intense efforts to increase awareness of information security and to run different information security programs.

19

Virtual World-Based Information Security Learning: Design and Evaluation

Ryoo, Jungwoo, Lee, Dongwon, Techatassanasoontorn, Angsana A.

[Kisti 연계] 한국과학기술정보연구원 Journal of information science theory and practice : JISTaP Vol.4 No.3 2016 pp.6-27

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

There has been a growing interest and enthusiasm for the application of virtual worlds in learning and training. This research proposes a design framework of a virtual world-based learning environment that integrates two unique features of the virtual world technology, immersion and interactivity, with an instructional strategy that promotes self-regulatory learning. We demonstrate the usefulness and assess the effectiveness of our design in the context of information security learning. In particular, the information security learning module implemented in Second Life was incorporated into an Introduction to Information Security course. Data from pre- and post- learning surveys were used to evaluate the effectiveness of the learning module. Overall, the results strongly suggest that the virtual world-based learning environment enhances information security learning, thus supporting the effectiveness of the proposed design framework. Additional results suggest that learner traits have an important influence on learning outcomes through perceived enjoyment. The study offers useful design and implementation guidelines for organizations and universities to develop a virtual world-based learning environment. It also represents an initial step towards the design and explanation theories of virtual world-based learning environments.

20

A New Approach for Information Security using an Improved Steganography Technique

Juneja, Mamta, Sandhu, Parvinder Singh

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.9 No.3 2013 pp.405-424

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

This research paper proposes a secured, robust approach of information security using steganography. It presents two component based LSB (Least Significant Bit) steganography methods for embedding secret data in the least significant bits of blue components and partial green components of random pixel locations in the edges of images. An adaptive LSB based steganography is proposed for embedding data based on the data available in MSB's (Most Significant Bits) of red, green, and blue components of randomly selected pixels across smooth areas. A hybrid feature detection filter is also proposed that performs better to predict edge areas even in noisy conditions. AES (Advanced Encryption Standard) and random pixel embedding is incorporated to provide two-tier security. The experimental results of the proposed approach are better in terms of PSNR and capacity. The comparison analysis of output results with other existing techniques is giving the proposed approach an edge over others. It has been thoroughly tested for various steganalysis attacks like visual analysis, histogram analysis, chi-square, and RS analysis and could sustain all these attacks very well.

 
1 2 3 4 5
페이지 저장