References
- Standard Framework Portal. (2022). Introduction of the standard framework (applied cases - achievements), Retrieved from https://www.egovframe.go.kr/
- Standard Framework Portal. (2022). Download (Development Environment - Release Notes), Retrieved from https://www.egovframe.go.kr/
- Canitano, G. (2022). Development of framework for Attack/Defense Capture the Flag competition (Doctoral dissertation, Politecnico di Torino).
- Shcherbakov, M., Balliu, M., & Staicu, C. A. (2023). Silent spring: Prototype pollution leads to remote code execution in node. js. In USENIX Security Symposium 2023.
- Kim, S. S. (2020). [Diagnosis] E-Government Standard Framework, 'JAVA Only' have to change. Retrieved from https://www.comworld.co.kr/
- Standard Framework Portal. (2022). Introduction of the standard framework (applied cases - technical support details), https://www.egovframe.go.kr/
- NVD. (2022). Spring Framework CVE® List, Retrieved from https://www.cve.org/
- Krcert. (2022). Spring Java Framework Security Update Advisory, https://www.krcert.or.kr/
- Mohamed, H. M., & El-Gayar, O. (2022). Security Vulnerability Impact on Open Source: A Social Media Exploration. (AMCIS 2022 TREOS)
- Bai, S., Boe, E. B., & Hegland-Antonsen, R. C. (2022). Efficiently Weaponizing Vulnerabilities and Automating Vulnerability Hunting (Bachelor's thesis, NTNU).
- YANGJU CITY. (2022). Yangju City Hall - website. Retrieved from https://www.yangju.go.kr/
- Korea National University of Arts. (2022). Korea National University of Arts - website. https://www.karts.ac.kr/
- Hanam Urban Innovation Corporation. (2022). Hanam Urban Innovation Corporation - website. https://www.huic.co.kr/
- KDIT. (2022). Korea Credit Guarantee Fund, Retrieved from https://www.kodit.co.kr/
- KTO. (2022). Korea Tourism Information - E-learning. Retrieved from https://touredu. visitkorea.or.kr/
- Im, Y. G. (2022). Expanded to 11 types of private certifications on public sites...Added Hana Bank and Dream certifications. Retrieved from https://zdnet.co.kr/
- Ashouri, M. (2019). Practical dynamic taint tracking for exploiting input sanitization error in java applications. In Australasian Conference on Information Security and Privacy, 494-513. Springer, Cham. DOI : 10.1007/978-3-030-21548-4_27
- Ponta, S. E., Plate, H., & Sabetta, A. (2020). Detection, assessment and mitigation of vulnerabilities in open source dependencies. Empirical Software Engineering, 25(5), 3175-3215. DOI : 10.1007/s10664-020-09830-x
- Jung, B.-M., Jang, J.-Y., & Choi, C.-J. (2019). Countermeasure of an Application Attack Scenario Using Spring Server Remote Code Execution Vulnerability (CVE-2018-1270). The Journal of the Korea Institute of Electronic Communication Sciences, 14(2), 303-308. DOI : 10.13067/JKIECS.2019.14.2.303
- Standard Framework Portal. (2020). Standard Framework Security Development Guide for E-Government SW Developers and Operators, Retrieved from https://www.egovframe.go.kr/
- NIST. (2020). National Institute of Standards and Technology - CVE Record Metadata, Retrieved from https://csrc.nist.gov/
- ZAP. (2022). OWASP ZAP(OWASP Zed Attack Proxy), Retrieved from https://www.zaproxy.org/
- PortSwigger. (2022). Burp Suite - Application Security Testing Software, Retrieved from https://portswigger.net/burp
- NMAP. (2022). Nmap Security Scanner, Retrieved from https://nmap.org/
- ModSecurity. (2022). SpiderLabs - ModSecurity, Retrieved from https://www.modsecurity.org/
- Metasploit. (2022). Metasploit - Penetration Testing Software, Retrieved from https://www.metasploit.com/
- Im, M, C. (2021). Personal Information Commission, major public institution website security check⋯ "See HTTPS applied", Retrieved from https://www.ajunews.com/
- Ministry of Public Administration and Security. (2022). Guidelines for establishment and operation of information systems for administrative and public institutions, Retrieved from https://www.law.go.kr/
- Ministry of Public Administration and Security. (2021). Guidelines for Quality Management of E-Government Websites, Retrieved from https://www.law.go.kr/