• 제목/요약/키워드: Bypass structure

검색결과 59건 처리시간 0.027초

Detection of Malicious PDF based on Document Structure Features and Stream Objects

  • Kang, Ah Reum;Jeong, Young-Seob;Kim, Se Lyeong;Kim, Jonghyun;Woo, Jiyoung;Choi, Sunoh
    • 한국컴퓨터정보학회논문지
    • /
    • 제23권11호
    • /
    • pp.85-93
    • /
    • 2018
  • In recent years, there has been an increasing number of ways to distribute document-based malicious code using vulnerabilities in document files. Because document type malware is not an executable file itself, it is easy to bypass existing security programs, so research on a model to detect it is necessary. In this study, we extract main features from the document structure and the JavaScript contained in the stream object In addition, when JavaScript is inserted, keywords with high occurrence frequency in malicious code such as function name, reserved word and the readable string in the script are extracted. Then, we generate a machine learning model that can distinguish between normal and malicious. In order to make it difficult to bypass, we try to achieve good performance in a black box type algorithm. For an experiment, a large amount of documents compared to previous studies is analyzed. Experimental results show 98.9% detection rate from three different type algorithms. SVM, which is a black box type algorithm and makes obfuscation difficult, shows much higher performance than in previous studies.

Automated Link Tracing for Classification of Malicious Websites in Malware Distribution Networks

  • Choi, Sang-Yong;Lim, Chang Gyoon;Kim, Yong-Min
    • Journal of Information Processing Systems
    • /
    • 제15권1호
    • /
    • pp.100-115
    • /
    • 2019
  • Malicious code distribution on the Internet is one of the most critical Internet-based threats and distribution technology has evolved to bypass detection systems. As a new defense against the detection bypass technology of malicious attackers, this study proposes the automated tracing of malicious websites in a malware distribution network (MDN). The proposed technology extracts automated links and classifies websites into malicious and normal websites based on link structure. Even if attackers use a new distribution technology, website classification is possible as long as the connections are established through automated links. The use of a real web-browser and proxy server enables an adequate response to attackers' perception of analysis environments and evasion technology and prevents analysis environments from being infected by malicious code. The validity and accuracy of the proposed method for classification are verified using 20,000 links, 10,000 each from normal and malicious websites.

MedisGroups를 이용한 관상동맥우회술의 중증도 보정사망률에 관한 연구 (Severity-Adjusted Mortality Rates of Coronary Artery Bypass Graft Surgery Using MedisGroups)

  • 권영대
    • 한국의료질향상학회지
    • /
    • 제7권2호
    • /
    • pp.218-228
    • /
    • 2000
  • Background : Among 'structure', 'process' and 'outcome' approaches, outcome evaluation is considered as the most direct and best approach to assess the quality of health care providers. Risk-adjustment is an essential method to compare outcome across providers. This study has aims to judge performance of hospitals by severity adjusted mortality rates of coronary artery bypass graft (CABG) surgery. Methods : Medical records of 584 patients who got the CABG surgery in 6 general hospitals during 1996 and 1997 were reviewed by trained nurses. The MedisGroups was used to quantify severity of patients. The predictive probability of death was calculated for each patient in the sample from a multivariate logistic regression model including the severity score, age and sex. For evaluation of hospital performance, we calculated ratio of observed number to expected number of deaths and z score [(observed number of deaths - expected number of deaths)/square root of the variance in the number of deaths], and compared observed mortality rate with confidence interval of adjusted mortality rate for each hospital. Results : The overall in-hospital mortality was 7.0%, ranged from 2.7% to 15.7% by hospital. After severity adjustment the mortality by hospital was from 2.7% to 10.7%. One hospital with poor performance was distinctly divided from others with good performance. Conclusion : In conclusion, severity-adjusted mortality rate of CABG surgery might be applied as an indicator for hospital performance evaluation in Korea. But more pilot studies and improvement of methodologies has to be done to use it as quality indicator.

  • PDF

메모리 분석 우회 기법과 커널 변조 탐지 연구 (A study on Memory Analysis Bypass Technique and Kernel Tampering Detection)

  • 이한얼;김휘강
    • 정보보호학회논문지
    • /
    • 제31권4호
    • /
    • pp.661-674
    • /
    • 2021
  • 커널을 변조하는 루트킷과 같은 악성코드가 만약 메모리 분석을 회피하기 위한 메커니즘을 추가하게 될 경우, 분석이 어려워지거나 불가능하게 되면서 분석가의 판단에 악영향을 미칠 수 있다. 따라서 향후 고도화된 커널 변조를 통해 탐지를 우회하는 루트킷과 같은 악성코드에 선제적으로 대응하고자 한다. 이를 위해 공격자의 관점에서 윈도우 커널에서 사용되는 주요 구조체를 분석하고, 커널 객체를 변조할 수 있는 방법을 적용하여 메모리 덤프 파일에 변조를 진행하였다. 변조 결과 널리 사용되는 메모리 분석 도구에서 탐지가 되지 않는 것을 실험을 통해 확인하였다. 이후 분석가의 관점에서 변조 저항성의 개념을 사용하여 변조를 탐지할 수 있는 소프트웨어 형태로 만들어 기존 메모리 분석 도구에서 탐지되지 않는 영역에 대해 탐지 가능함을 보인다. 본 연구를 통해 선제적으로 커널 영역에 대해 변조를 시도하고 정밀 분석이 가능하도록 인사이트를 도출하였다는 데 의의가 있다 판단된다. 하지만 정밀 분석을 위한 소프트웨어 구현에 있어 필요한 탐지 규칙을 수동으로 생성해야 한다는 한계점이 존재한다.

비육용 곡물사료의 가공방법과 증체효율 (Grain Processing on Feed Efficiency for Beef Production)

  • 김영길
    • 생명과학회지
    • /
    • 제5권3호
    • /
    • pp.126-136
    • /
    • 1995
  • The studies had been conducted to evaluate the grain processing effects for ruminants on starch digestion, body weight gain and feed efficiency since 1970. This research deals with experimental results on chemical structure, gelatinization, microbial starch digestion in rumen, intestinal starch digestion in rumen, roles of protozoa, intestinal starch digestion of bypass starch, limits to starch digestion in small intestine. The grain processing has different effects on digestion, weight gain and feed efficiency when different grain sources and contents is used, and the quality and quantity of roughage is different. The economical and efficient method of grain processing should be selected considering weight gain and feed efficiency enhancement than digestibility.

  • PDF

저층수 배사관 내 유입된 사석 배출능력에 대한 연구 (A Experimental Study on Exclusion Ability of Riprap into Bypass Pipe)

  • 정석일;이승오
    • 대한토목학회논문집
    • /
    • 제37권1호
    • /
    • pp.239-246
    • /
    • 2017
  • 국내 중소하천의 횡단구조물인 보 또는 낙차공은 대부분 고정식 콘크리트 구조물이며, 저층수의 배제가 쉽지 않다. 횡단구조물로 인해 유사가 퇴적되며, 유사에 흡착한 오염물들이 그대로 하천의 바닥을 오염시키고 있다. 이에 저층수 및 퇴적유사에 대한 관심이 증가하고 있는 실정이며, 이러한 대안의 하나로 횡단구조물 상류와 하류를 하상 아래로 연결시키는 구조물로써, 보 상류 저층의 물 및 유사 배제를 목적으로 저층수배출관을 설치하는 방안이 있다. 그러나 사석이 유입되고, 배제 되지 않을 경우 효율성이 크게 저하될 가능성이 있다. 이에 본 연구에서는 저층수 배출관 내 사석을 배제할 수 있는 능력에 대한 연구를 수행하였다. 사석과 거동이 유사한 유사(sediment)의 한계조건(critical condition) 중 한계전단력(critical shear stress) 유도과정과 달랑베르의 원리(d'Alembert principle)를 응용하여 이동 중인 사석이 배제될 수 있는 조건(${\tau}_c{^*}$)을 유도하였다. 그러나 저층수 배출관 내 유입된 사석은 정지상태가 아닌 이동 중이므로, Lagrangian 기법을 활용하여 수리실험에서 도출된 유속으로 상대속도(relative velocity)를 제시하였다. 수리실험은 축척효과(scale effect)를 최소화하기 위해 폭이 5.0 m이고, 높이가 1.0 m인 광폭 개수로를 제작하였으며, 사용된 사석은 가공된 완전 구형을 사용하였다. 실험 결과 유속과 구형 입자 속도와의 비가 0.5~0.7 사이로 나타났으며, 이러한 결과를 유도된 식에 적용하여, 최종적으로 사석이 배제되는 조건을 도출하게 되었다. 구간은 입자레이놀즈수($Re_p$)와 무차원 한계 전단력(${\tau}_c{^*}$)에 따라 크게 3가지로 구분되었다. 배제 구간(exclusion section), 확률적 배제 구간(probabilistic exclusion section), 비배제 구간(no exclusion section)이다. 본 연구결과는 횡단구조물의 저층수 배출관 설계시 유용한 기초 정보를 제공할 수 있을 것이다.

국제 핵융합실험로용 VS(Vertical Stabilization) 컨버터의 운전모드 및 보호동작 (Operation modes and Protection of VS(Vertical Stabilization) Converter for International Thermonuclear Experimental Reactor)

  • 조현식;조종민;오종석;서재학;차한주
    • 전력전자학회논문지
    • /
    • 제20권2호
    • /
    • pp.130-136
    • /
    • 2015
  • This study describes the structure and operation modes of vertical stabilization (VS) converter for international thermonuclear experimental reactor (ITER) and proposes a protection method. ITER VS converter supplies voltage (${\pm}1000V$)/current (${\pm}22.5kA$) to superconducting magnets for plasma current vertical stabilization. A four-quadrant operation must be achieved without zero-current discontinuous section. The operation mode of the VS converter is separated in 12-pulse mode, 6-pulse mode and circulation current mode according to the magnitude of the load current. Protection measures, such as bypass and discharge, are proposed for abnormal conditions, such as over current, over voltage, short circuit, and voltage sag. VS converter output voltage is controlled to satisfy voltage response time within 20 msec. Bypass operation is completed within 60 msec and discharge operation is performed successfully. The feasibility of the proposed control algorithm and protection measure is verified by assembling a real controller and implementing a power system including the VS converter in RTDS for a hardware-in-loop (HIL) facility.

Molecular Characterization of AceB, a Gene Encoding Malate Synthase in Corynebacterium glutamicum

  • Lee, Heung-Shick;Anthony J. Sinskey
    • Journal of Microbiology and Biotechnology
    • /
    • 제4권4호
    • /
    • pp.256-263
    • /
    • 1994
  • The aceB gene, encoding for malate synthase, one of the key enzymes of glyoxylate bypass, was isolated from a pMT1-based Corynebacterium glutamicum gene library via complementation of an Escherichia coli aceB mutant on an acetate minimal medium. The aceB gene was closely linked to aceA, separated by 598 base pairs, and transcribed in divergent direction. The aceB expressed a protein product of Mr 83, 000 in Corynebacterium glutamicum which was unusually large compared with those of other malate synthases. A DNA-sequence analysis of the cloned DNA identified an open-reading frame of 2, 217 base pairs which encodes a protein with the molecular weight of 82, 311 comprising 739 aminoo acids. The putative protein product showed only limited amino acid-sequence homology to its counteliparts in other organisms. The N-terminal region of the protein, which shows no apparent homology with the known sequences of other malate synthases, appeared to be responsible for the protein s unusually large size. A potential calciumbinding domain of EF-hand structure found among eukaryotes was detected in the N-terminal region of the deduced protein.

  • PDF

신생돈을 이용한 이식 자가 폐동맥의 성장에 관한 연구, 제1보, 수술의 적합성 (Growth of Pulmonary Autograft in Swine, I.Feasibility of the Operation)

  • 안재호
    • Journal of Chest Surgery
    • /
    • 제28권10호
    • /
    • pp.885-891
    • /
    • 1995
  • In order to test the hypothesis that the pulmonic valve, when used to replace the aortic root as a pulmonary autograft, will remain a viable anatomical structure and will grow and develop normally along with the host, we performed aortic valve replacement with the pulmonary autograft in 15 neonatal piglets. The weight of the donor was 9.3 $\pm$ 0.2 kg, the recipient 9.6 $\pm$ 0.3 kg. Measured diameters of pulmonic annulus were 14 $\pm$ 0.2 mm for autograft and 14.2 $\pm$ 0.2 mm for pulmonary artery homograft. Operation was performed under cardiopulmonary bypass with deep hypothermia [20oC at low flow perfusion [70 ml/kg/min . The mean operation time was 227 $\pm$ 10 min., bypass time 152$\pm$ 7.6 min. and aortic cross clamp time 73$\pm$ 4.6 min.. 9 piglets survived more than 12 hours. One survived 12 days and died of pneumonia and the latest one survived in good condition and sacrificed at postoperative 6th week for cardiac catheterization and pathologic examination that revealed the viability and growing of the pulmonary autograft. Currently we are able to complete the operation with good preservation of cardiac function, and our postoperative care has evolved to the extent that we are now confident enough of having an acceptable percentage of long term survivors to undertake a definite study in this regard.

  • PDF

Q-보정을 이용한 디지털 픽킹 필터 설계 (Design of Digital Peaking Filters Using Q-Compensation)

  • 이지하;이규하;박영철;안동순;윤대희
    • 한국음향학회지
    • /
    • 제19권3호
    • /
    • pp.63-71
    • /
    • 2000
  • 본 논문에서는 표준 대역통과 필터와 무증폭 바이패스 이득의 조합을 이용한 구조에 근거하여 전문가용 디지털 오디오에 적합한 정교한 주파수응답을 갖고, 실시간 시스템에서 적은 계산량과 메모리로 구현이 용이한 2차 디지털 픽킹 필터의 설계방식을 제안하였다. 이와 같이 설계된 디지털 픽킹 필터는 이득요인에 따라 필터의 대역폭이 왜곡되는 단점을 Q-보정을 통해 제거하였으며, 컨포말 변환에 의한 설계보다 수학적으로 간단하고 구현이 용이하며, 적은 계산량 및 메모리를 필요로 한다.

  • PDF