Browse > Article
http://dx.doi.org/10.13089/JKIISC.2009.19.6.113

The Study on the Security Model for ActiveX Control Management through Security Authentication  

Park, Sung-Yong (Graduate School of Information Management & Security, Korea University)
Moon, Jong-Sub (Graduate School of Information Management & Security, Korea University)
Abstract
In recent years, to provide visitors with the various and dynamic services, many ActiveX Controls are developed and distributed in most of the web sites such as e-Government Internet banking Portal in Korea. However, unsecure ActiveX Controls may be critical security threats on Internet User. Although hacking incidents increase sharply for these vulnerable ActiveX Controls, there are not enough national security actions or policies. Thus, in this paper we propose the technical method to design 'Security model for ActiveX Control Managemnet through Security Authentication' to be able safe and useful security management in three aspects of development distribution using.
Keywords
ActiveX Controls; ActiveX Control vulnerability; vulnerability attacks; Security Authentication;
Citations & Related Records
Times Cited By KSCI : 2  (Citation Analysis)
연도 인용수 순위
1 국가정보원 국가사이버안전센터, "ActiveX Control 개발 보안가이드라인," 2008년 11월
2 김재현, "ActiveX 컨트롤의 보안모델 설계," 석사학위, 동국대학교 국제정보대학원, 2006년 2월
3 Microsoft Corporation, "Introduction to ActiveX Controls," http://msdn.microsoft.com/en-us/library/aa751972(VS.85).aspx
4 MBC TV, "DDoS 공격 근원지는 국내 웹하드 사이트," http://imnews.imbc.com/replay/nwdesk/article/2398580_5780.html
5 김수용, 손기욱, "ActiveX Control 취약점 검사 및 검증기법 연구," 정보보호학회논문지, 15(6), pp. 3-12, 2005년 12월
6 전상훈, "게임 산업에서의 Vista(ActiveX) 파급효과와 보안의 이슈," 정보보호학회지, 17(2), pp. 57-65, 2007년 4월
7 InternetTrend, http://trend.logger.co.kr
8 전병선, Microsoft Visual C++ 6.0 ATL COM Programming, 삼양출판사, pp. 297-298, 2001년2월
9 Micorsoft Corporation, "What is an ActiveX Control-Microsoft Security," http:// www.microsoft.com/protect/terms/activex.aspx