년 - 년
Efficient Assessment and Evaluation for Websites Vulnerabilities Using SNORT SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.1 2013.01 pp.7-16
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
An endless number of methods or ways exists to access illegally a web server or a website. The task of defending a system (e.g. network, server, website, etc.) is complex and challenging. SNORT is one of the popular open source tools that can be used to detect and possibly prevent illegal access and attacks for networks and websites. However, this largely depends on the way SNORT rules are designed and implemented. In this paper, we investigated in details several examples of SNORT rules and how they can be tuned to improve websites protection. We demonstrated practical methods to design and implement those methods in such ways that can show to security personnel how effectively can SNORT rules be used. Continuous experiments are conducted to evaluate and optimized the proposed rules. Results showed their ability to prevent tested network attacks. Each network should try to find the best set of rules that can detect and prevent most network attacks while at the same time cause minimal impact on network performance.
Enhance Rule Based Detection for Software Fault Prone Modules SCOPUS
보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.6 No.1 2012.01 pp.75-86
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Software quality assurance is necessary to increase the level of confidence in the developed software and reduce the overall cost for developing software projects. The problem addressed in this research is the prediction of fault prone modules using data mining techniques. Predicting fault prone modules allows the software managers to allocate more testing and resources to such modules. This can also imply a good investment in better design in future systems to avoid building error prone modules. Software quality models that are based upon data mining from previous projects can identify fault-prone modules in the current similar development project, once similarity between projects is established. In this paper, we applied different data mining rule-based classification techniques on several publicly available datasets of the NASA software repository (e.g. PC1, PC2, etc). The goal was to classify the software modules into either fault prone or not fault prone modules. The paper proposed a modification on the RIDOR algorithm on which the results show that the enhanced RIDOR algorithm is better than other classification techniques in terms of the number of extracted rules and accuracy. The implemented algorithm learns defect prediction using mining static code attributes. Those attributes are then used to present a new defect predictor with high accuracy and low error rate.
A Semantic Rule-based Detection Scheme against Flooding Attacks on Cloud Environment SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.6 No.2 2012.04 pp.341-346
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
With the progress the Internet, more and more applications provide Web services. The presentation of web page has evolved to be dynamic. You also can interact with the web page. Some malicious users have malicious browsing behaviors, such as flooding attack, to waste the resources and bandwidth of the host for web page. Nowadays, more and more web services are developed on cloud computing. Flooding attack on the application layer has no ability to cause denial of service to a Web server on cloud computing. But resources on cloud mean cost. Any waste of resource will cause unnecessary cost. Therefore, in this paper we analyze PHP dynamic pages. According to analysis, we propose a method based on semantic concept to formulate rules to indentify malicious browsing behaviors in order to slice the cost.
보안공학연구지원센터(IJFGCN) International Journal of Future Generation Communication and Networking Vol.9 No.6 2016.06 pp.339-350
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In the field of network security, researchers have implemented different models to secure the network. Intrusion Detection System is also one of them and Snort is an open source tool for Intrusion Detection and Prevention System. Today intrusion Detection System is a growing technology in network security and mostly researchers have focused in this field, some of them used signature or rule-based technique and some are anomaly based techniques to improve security of network. In this paper we propose a rule-base Intrusion Detection System with our self generated new Efficient Port Scan Detection Rules (EPSDR). These rules will be used to detect naive port scan attacks in real time network using Snort and Basic Analysis Security Engine (BASE). BASE is used to view the snort results in font-end web page because Snort has no graphic user interface. In This rule-based Intrusion Detection System we will match the signature with our Efficient Port Scan Detection Rules (EPSDR) from captured packet. As a definition of signature based IDS this new EPSDR based IDS will be useful to reduce the false positive alarm.
Rule-Based Anomaly Detection Technique Using Roaming Honeypots for Wireless Sensor Networks
[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.38 No.6 2016 pp.1145-1152
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Because the nodes in a wireless sensor network (WSN) are mobile and the network is highly dynamic, monitoring every node at all times is impractical. As a result, an intruder can attack the network easily, thus impairing the system. Hence, detecting anomalies in the network is very essential for handling efficient and safe communication. To overcome these issues, in this paper, we propose a rule-based anomaly detection technique using roaming honeypots. Initially, the honeypots are deployed in such a way that all nodes in the network are covered by at least one honeypot. Honeypots check every new connection by letting the centralized administrator collect the information regarding the new connection by slowing down the communication with the new node. Certain predefined rules are applied on the new node to make a decision regarding the anomality of the node. When the timer value of each honeypot expires, other sensor nodes are appointed as honeypots. Owing to this honeypot rotation, the intruder will not be able to track a honeypot to impair the network. Simulation results show that this technique can efficiently handle the anomaly detection in a WSN.
Simple Fuzzy Rule Based Edge Detection
[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.9 No.4 2013 pp.575-591
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Most of the edge detection methods available in literature are gradient based, which further apply thresholding, to find the final edge map in an image. In this paper, we propose a novel method that is based on fuzzy logic for edge detection in gray images without using the gradient and thresholding. Fuzzy logic is a mathematical logic that attempts to solve problems by assigning values to an imprecise spectrum of data in order to arrive at the most accurate conclusion possible. Here, the fuzzy logic is used to conclude whether a pixel is an edge pixel or not. The proposed technique begins by fuzzifying the gray values of a pixel into two fuzzy variables, namely the black and the white. Fuzzy rules are defined to find the edge pixels in the fuzzified image. The resultant edge map may contain some extraneous edges, which are further removed from the edge map by separately examining the intermediate intensity range pixels. Finally, the edge map is improved by finding some left out edge pixels by defining a new membership function for the pixels that have their entire 8-neighbourhood pixels classified as white. We have compared our proposed method with some of the existing standard edge detector operators that are available in the literature on image processing. The quantitative analysis of the proposed method is given in terms of entropy value.
Implementation of Rule-based Smartphone Motion Detection Systems
[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.26 No.7 2021 pp.45-55
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
스마트폰에 내장된 각종 센서를 통해 획득할 수 있는 정보는 사용자의 움직임, 상황 등을 파악하고 분석하는데 유용하게 활용될 수 있다. 본 논문에서는 스마트폰의 가속도 센서와 자이로스코프 센서에서 얻은 정보를 분석하여 'I', 'S', 'Z' 모션을 인식하는 두 가지 규칙기반 시스템을 제안한다. 먼저, 각 모션에 대한 가속도 및 각속도의 특성을 분석한다. 이를 기반으로 두 가지 종류의 규칙기반 모션 인식 시스템을 제안하고 이를 안드로이드 앱으로 구현하여 각 모션에 대한 성능을 비교한다. 두 가지 규칙기반시스템은 각 모션에 대해서 90% 이상의 인식률을 보이며 앙상블을 이용한 규칙기반 시스템은 다른 시스템보다 향상된 성능을 보인다.
Information obtained through various sensors embedded in a smartphone can be used to identify and analyze user's movements and situations. In this paper, we propose two rule-based motion detection systems that can detect three alphabet motions, 'I', 'S', and 'Z' by analyzing data obtained by the acceleration and gyroscope sensors in a smartphone. First of all, the characteristics of acceleration and angular velocity for each motion are analyzed. Based on the analysis, two rule-based systems are proposed and implemented as an android application and it is used to verify the detection performance for each motion. Two rule-based systems show high recognition rate over 90% for each motion and the rule-based system using ensemble shows better performance than another one.
Network Intrusion Detection Based on Directed Acyclic Graph and Belief Rule Base
[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.39 No.4 2017 pp.592-604
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Intrusion detection is very important for network situation awareness. While a few methods have been proposed to detect network intrusion, they cannot directly and effectively utilize semi-quantitative information consisting of expert knowledge and quantitative data. Hence, this paper proposes a new detection model based on a directed acyclic graph (DAG) and a belief rule base (BRB). In the proposed model, called DAG-BRB, the DAG is employed to construct a multi-layered BRB model that can avoid explosion of combinations of rule number because of a large number of types of intrusion. To obtain the optimal parameters of the DAG-BRB model, an improved constraint covariance matrix adaption evolution strategy (CMA-ES) is developed that can effectively solve the constraint problem in the BRB. A case study was used to test the efficiency of the proposed DAG-BRB. The results showed that compared with other detection models, the DAG-BRB model has a higher detection rate and can be used in real networks.
퍼지 기반 퀸-맥클러스키 규칙 감축 기법을 이용한 대용량 스트리밍 데이터의 고속 이벤트 탐지 기법 연구
[Kisti 연계] 한국컴퓨터정보학회 한국컴퓨터정보학회 학술대회논문집 2014 pp.373-376
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 모바일 기기 및 무선기기의 발달로 인하여 센서 네트워크가 다양한 분야에서 응용되고 있다. 따라서 센서에서 실시간으로 발생하는 스트리밍 데이터에서 이벤트를 감지하고 분석하는 것은 중요한 연구 분야로 부각되고 있다. 단순 이벤트의 발생 조건을 빠르게 판별하기 위해 비트맵 인덱스 기반 복합 이벤트 검출 기법 등 여러 가지 방법들이 사용되고 있지만, 아직까지 이기종 센서에서 발생하는 각기 다른 형태의 데이터를 융합하여 이벤트를 검출하는 복합 이벤트 처리에 대한 연구는 미비한 실정이다. 본 논문에서는 각기 다른 형태를 가지는 스트리밍 데이터에 멤버쉽 함수를 적용하여 퍼지화 함으로서 이기종 센서에서 발생하는 데이터를 융합 처리가능하며, Quine-Mccluskey 감축기법을 통하여 규칙의 신뢰도 및 속도가 향상된 의사결정을 하는 고속 이벤트 탐지기법을 제안한다.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2005 pp.965-968
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 보안 정책 및 규칙에 기반을 둔 네트워크 포트 기반의 오용침입 탐지 기능 및 센서 객체 기반의 이상침입 탐지 기능을 갖춘 리눅스 서버 시스템을 제안 및 구현한다. 제안한 시스템은 먼저 시스템에 사용하는 보안 정책에 따른 규칙을 수립한다. 이러한 규칙에 따라 정상적인 포트들과 알려진 공격에 사용되고 있는 포트번호들을 커널에서 동적으로 관리하면서, 등록되지 않은 새로운 포트에도 이상탐지를 위해 공격 유형에 대하여 접근제어 규칙을 적용하여 이상 침입으로 판단될 경우 접근을 차단한다. 알려지지 않은 이상침입 탐지를 위해서는 주요 디렉토리마다 센서 파일을, 주요 파일마다 센서 데이터를 설정하여 센서 객체가 접근될 때마다 감사로그를 기록하면서, 이들 센서 객체에 대해 불법적인 접근이 발생하면 해당 접근을 불허한다. 본 시스템은 보안정책별 규칙에 따라 다단계로 구축하여 특정 침입에 대한 더욱 향상된 접근제어를 할 수 있다.
[Kisti 연계] 대한설비공학회 대한설비공학회 학술대회논문집 2005 pp.241-246
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The objective of this study is to develop a rule-based fault detection and diagnosis algorithm and an experimental verification using air handling unit. To develop an analytical algorithm which precisely detects a faulted component, energy equations at each control volume of AHU were applied. An experimental verification was conducted in the AHU at Green Building in KIER. In the experiment conducted in hot summer condition, the rule based FDD algorithm isolated a faulted sensor from HVAC components.
선박에서 화재탐지를 위한 규칙 및 사례기반 추론의 통합
[Kisti 연계] 한국지능시스템학회 한국지능시스템학회 학술대회논문집 2000 pp.303-306
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 선박에서 화재탐지를 위해서 규칙 기반 추론과 사례 기반 추론을 통합하는 방법에 대해서 논의하였다. 규칙은 어떤 영역에서 광범위한 경향을 표현하는데 적합하며 사례는 규칙에서 예외적인 상황을 다루는데 적합하다는 점에서 규칙과 사례는 상호 보완적이라 할 수 있다. 즉 어떤 행동이 충분히 반복되면 자연스럽게 규칙이 되며, 잘 확립된 규칙이 있다면 사례를 먼저 추론할 필요가 없다. 그러나 규칙이 실패하게 되면 실패를 만회하기 위해서 사례를 생성하는 것이 하나의 대안이 될 수 있다. 본 논문에서는 일반적인 화재탐지 지식은 규칙으로 표현하고, 예외적인 화재탐지 지식은 사례로 표현함으로써 규칙과 사례가 서로 보완적인 역할을 할 수 있는 통합 방법을 제안하였다. 또한 기존의 규칙 기반 FFES(Fire Fighting Expert System)와 사례기반 추론에 의해 확장된 C-FFES(Combined-Fire Fighting Expert System)를 비교를 통해, 제안한 접근 방법이 화재 탐지율을 향상시킴을 보였다.
계층적 규칙을 이용한 사선 보간 기법을 갖는 3차원 순차 주사화 기법
[Kisti 연계] 대한전자공학회 대한전자공학회 학술대회논문집 2003 pp.2080-2083
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 움직임이 존재하는 부분의 사선 방향 보간 성능을 개선하여 기존의 움직임 적응형 3 차원 순차 주사화 알고리즘 기법을 개선한 순차 주사화 방법을 제안하였다. 움직임 적응형 3 차원 순차 주사화를 위하여 밝기 형태 패턴(brightness profile pattern)을 이용하여 필드간의 움직임 정보를 좀 더 정확하게 추출할 수 있었으며 움직임이 있는 부분의 경우 에지의 방향 정보를 이용하여 사선 방향 보간을 수행함으로써 전체적인 순차 주사 변환 화질을 개선할 수 있었다. 제안된 알고리즘을 하드웨어로 구현하여 다양한 동영상에 대해서 성공적으로 적용됨을 확인하였다.
영상특성에 기반한 통계적 판정법을 이용한 적응 워터마크 검출 알고리즘
[Kisti 연계] 한국멀티미디어학회 한국멀티미디어학회 학술대회논문집 2003 pp.104-107
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 웨이브릿 영역에서 HVS 및 NVF 함수를 사용하여 영상특성에 기반한 통계적 판정법을 이용한 적응 워터마크 검출 알고리즘을 판정법을 제안한다. 워터마크는 4레벨로 분해된 웨이브릿 영역에서 JND(just noticeable difference) 특성과 NVF(noise visibility function)를 이용한 통계적 특성을 기반으로 정상상태 가우시안 모델에 따라 지각적 동조 특성을 이용하여 적응적으로 삽입하고, Bayes 이론 및 Neyman-Pearson 정리를 이용한 통계적 판정법을 이용하여 워터마크를 추출함으로써 기존의 통계적 판정법 보다 정확하게 워터마크 존재 유무를 판정 할 수 있음을 확인하였다.
연관규칙을 기반으로한 Web Page 침입탐지 시스템 구현
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2003 pp.1347-1350
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근에 들어서 Web Pgae 및 서버에 악의적인 사용자들로 하여금 많은 피해가 발생하고 있다. 본 논문에서는 연관규칙을 이용한 침입탐지 시스템을 구현함으로써 해킹 및 부정사용자를 방지하여 시스템의 가용성, 효율성을 높이고 안정적인 운용을 제공한다. 그리고 연관규칙의 신뢰성을 높이기 위하여 가중치 개념을 사용하여 효율적인 침입탐지 시스템 구현을 제시하였다.
네트워크 기반 침입탐지 시스템의 취약성 규칙 DB를 자동적으로 갱신하는 에이전트 설계
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2002 pp.327-330
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
네트워크와 컴퓨터시스템의 보안을 강화하기 위해서는 보안상의 취약성이 발견되는 대로 파악하고 점검해 주어야 한다. 그러나 대부분의 네트워크기반 침입탐지 시스템은 취약성을 파악하기 위해서는 국내외 관련 사이트들을 수동적인 방법으로 검색하기 때문에, 취약성 규칙을 갱신하는 것은 매우 어렵다. 본 논문에서는 에이전트가 스스로 관련 사이트에서 취약성 정보를 검색하여 새로운 취약성 정보를 추출한 후, Snort의 최적 규칙 형태로 변환하고 취약성 규칙을 갱신해주게 된다. 본 에이전트에 의해 갱신된 취약성 규칙 DB는 많은 규칙이 추가될지라도 침입을 탐지하는 속도가 떨어지지 않고, 확장성 및 이식성이 용이하다는 특징을 가진다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.