• 제목/요약/키워드: Computer Security Act

검색결과 65건 처리시간 0.027초

네트워크 시스템 생존성 : 소프트웨어 재활기법을 이용한 TCP의 프레임워크 (Network System Survivability: A Framework of Transmission Control Protocol with Software Rejuvenation Methodology)

  • Khin Mi Mi Aung;Park, Jong-Sou
    • 한국정보보호학회:학술대회논문집
    • /
    • 한국정보보호학회 2003년도 하계학술대회논문집
    • /
    • pp.121-125
    • /
    • 2003
  • In this paper, we propose a framework of Transmission Control Protocol with Software Rejuvenation methodology, which is applicable for network system survivability. This method is utilized to improve the survivability because it can limit the damage caused by successful attacks. The main objectives are to detect intrusions in real time, to characterize attacks, and to survive in face of attacks. To counter act the attacks' attempts or intrusions, we perform the Software Rejuvenation methods such as killing the intruders' processes in their tracks, halting abuse before it happens, shutting down unauthorized connection, and responding and restarting in real time. These slogans will really frustrate and deter the attacks, as the attacker can't make their progress. This is the way of survivability to maximize the deterrence against an attack in the target environment. We address a framework to model and analyze the critical intrusion tolerance problems ahead of intrusion detection on Transmission Control Protocol (TCP).

  • PDF

A Decision Making Model Proposal for Firewall Selection

  • Akturk, Cemal;Cubukcu, Ceren
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제15권10호
    • /
    • pp.3588-3607
    • /
    • 2021
  • Covid-19 pandemic required all the world to use internet more actively. As a result, individuals and businesses are more open to digital threats. In order to provide security within the network, firewalls should be used. Firewalls act as a gateway between the corporate and the external networks. Therefore, it is more important than ever to choose the right firewall for each network. In this study, a new linear decision making model is proposed in order to find out the most suitable firewall and the estimates are completed according to this new model. Also, this model is compared with multi-objective optimization on the basis of ratio analysis (MOORA) method. This study distinguishes from other studies by proposing a new solution which ranks the firewall alternatives using linear and MOORA approaches. These approaches are used in many fields before but not in information technologies. Thus, this study can be considered quite innovative in terms of the problem it handles and the approaches used. It offers up-to-date and practical suggestions related to a decision making problem that has not been previously studied in the literature.

Intelligent Automated Cognitive-Maturity Recognition System for Confidence Based E-Learning

  • Usman, Imran;Alhomoud, Adeeb M.
    • International Journal of Computer Science & Network Security
    • /
    • 제21권4호
    • /
    • pp.223-228
    • /
    • 2021
  • As a consequence of sudden outbreak of COVID-19 pandemic worldwide, educational institutes around the globe are forced to switch from traditional learning systems to e-learning systems. This has led to a variety of technology-driven pedagogies in e-teaching as well as e-learning. In order to take the best advantage, an appropriate understanding of the cognitive capability is of prime importance. This paper presents an intelligent cognitive maturity recognition system for confidence-based e-learning. We gather the data from actual test environment by involving a number of students and academicians to act as experts. Then a Genetic Programming based simulation and modeling is applied to generate a generalized classifier in the form of a mathematical expression. The simulation is derived towards an optimal space by carefully designed fitness function and assigning a range to each of the class labels. Experimental results validate that the proposed method yields comparative and superior results which makes it feasible to be used in real world scenarios.

Reasons for Adopting Weak Opinions in Islamic Jurisprudence

  • Alharthy, Meshal Qabbas
    • International Journal of Computer Science & Network Security
    • /
    • 제22권8호
    • /
    • pp.323-327
    • /
    • 2022
  • The field of this study is in Islamic jurisprudence. Taking the preferred saying is contrary to the original, and takes it if necessity or need arises. There are reasons for adopting the preferred saying that were mentioned in this research so that the mufti and jurist know when to take the preferred saying, and when to act with the most correct saying. The origin is the work of the jurist and mufti by saying the most correct. If the necessity or the need that prompted the mufti to take the preferred saying ceases, then he returns to work with the most correct saying, and gives it precedence over the most preferred opinion. The researcher recommends that this topic be given more attention from researchers, and that it is taken care of in jurisprudential developments; So that the embarrassment of the nation is lifted, and the jurists clarify the legal ruling on emerging issues.

A Legal Study on The Act Bill for Establishing The Game User Committee

  • Kyen, Seung-Yup
    • 한국컴퓨터정보학회논문지
    • /
    • 제27권3호
    • /
    • pp.165-171
    • /
    • 2022
  • 본 연구는 게임제작업자등에게 게임물이용자위원회를 두도록 하는 게임산업진흥에 관한 법률(안)에 대한 개선방안을 제시한다. 이 법안은 행정형벌에 있어서 불명확한 용어의 사용으로 인한 죄형법정주의 위반, 게임물이용자위원회 위원의 비밀 유지의무 규정의 미비 등으로 인한 헌법상 직업선택의 자유(영업의 자유) 및 재산권을 침해, 중복 규제제도로 인한 게임산업 발전을 저해 등 많은 문제점을 가지고 있는데, 선행연구와 판례를 분석하여 세 가지 개선방안을 도출하였다. 첫째 특별한 사유의 구체적인 내용은 시행령, 시행규칙 등 하위법령으로 위임하여 정하도록 하고, 징역, 벌금을 과태료 부과로 전환을 고려하거나, 둘째 제출받은 자료에 대한 게임물이용자위원회 위원의 비밀유지의 의무 및 벌칙에서의 공무원 의제 규정을 마련하며, 셋째, 현행 게임산업법상 게임물관리위원회에서 확률형 아이템 관리를 하거나 확률형 아이템 판매 시 콘텐츠분쟁조정위원회의 분쟁 조정제도의 고지 등 현행 제도를 활용할 수 있도록 하는 방안을 제시한다.

시스템 보안을 무력화 시키는 전산관리자의 시스템 침해 행위 연구 (To Neutralize the Security Systems, Infringement Actions by the Administrator on the Computer Networks)

  • 류경하;박대우
    • 한국정보통신학회:학술대회논문집
    • /
    • 한국정보통신학회 2012년도 추계학술대회
    • /
    • pp.165-168
    • /
    • 2012
  • 본 논문은 이 세상에 존재하는 어떤 종류의 보안시스템도 시스템 접근권한을 가진 전산 담당자의 시스템 침해 행위를 막아내기란 어려운 일이라는 점을 되새기고, 전산 담당자의 침해 행위 사례와 그로인한 피해의 정도 등 심각성을 재조명하고, 나아가 기술적 보안조치의 한계선상에 있는 전산 담당자의 권한 관리와 기술적 조치를 넘어 인적관리를 통한 침해예방 방안에 대해 나름의 대안을 찾아 보고자 한다.

  • PDF

Soft Systems are Ubiquitous-Defenses are Rare: A Case for Contingent Outsourcing of Patch Management

  • Arnett Kirk P.
    • 한국정보시스템학회지:정보시스템연구
    • /
    • 제14권3호
    • /
    • pp.23-30
    • /
    • 2005
  • Computer attacks on vulnerable software are ubiquitous. Today's attacks on client PCs can be used to create armies of zombie computers that are capable of wide reach attacks on high profile businesses and governments. The simple act of patching software vulnerabilities will certainly mitigate this problem, but patching has its own set of problems. Further, it is frequently the case that patches which are available to mitigate vulnerabilities are not being made on a timely basis and sometimes are not being made at all. One solution to the patch management dilemma is outsourcing. This paper notes that outsourcing is not a carte blanche decision that can be made based on dollars, but rather that a contingency decision matrix can provide guidance on outsourcing solutions for patch management and other security components as well. The matrix recognizes that IS staff expertise and employee security awareness are two important factors in the outsourcing decision.

  • PDF

개인정보시스템 위험도 분석 기준 지원 도구 개발 연구 (Personal Information System risk analysis standard supporting tool development)

  • 한경수;정현미;이강수
    • 한국정보통신학회:학술대회논문집
    • /
    • 한국정보통신학회 2012년도 춘계학술대회
    • /
    • pp.663-666
    • /
    • 2012
  • 2011년 9월 30일부터 개인정보보호법 제29조 및 개인정보의 안전성 확보조치 기준 제7조 5항에 따라 공공 및 민간 기업의 개인 정보처리 자가 내부 망에 고유 식별 정보를 저장하는 경우, 위험도 분석 기준결과에 따른 암호화의 적용여부 및 적용범위를 정하여 시행할 수 있다. 2012년 12월 31일까지 암호화 기술의 적용 또는 이에 상응하는 조치를 완료해야한다. 행정안전부 및 한국인터넷진흥원에서 제공한 개인정보 위험도 분석 기준을 토대로 해당 시스템에서 개인정보 처리 시 위험도분석 기준을 제시 하는 지원 도구를 개발 및 연구 하였다.

  • PDF

전자의무기록 보안표준화에 대한 고찰 (The Consideration about an Electronic Medical Record Security Standardization)

  • 박두희;송재영;이남용
    • 정보관리연구
    • /
    • 제36권1호
    • /
    • pp.125-154
    • /
    • 2005
  • 인터넷의 발달로 개인정보의 수집 및 이용이 일상화됨에 따라 개인정보의 침해가 급속도로 확대 되고 있다. 의료분야에 대한 개인정보보호에 대해서는 '정보통신망이용촉진 및 정보보호 등에 관한 법률'등에 체계적으로 규정되어 있으나, 법적용 대상이 정보통신 서비스 제공자 위주로 규정되어 의료분야에 적용하는 데 한계가 있다. 때문에 본 논문에서는 국내 의료기관이 전자의무기록 시스템에 보안을 적용하기 위해 우선적으로 선행되어야 할 개인의료정보 보호방안에 대해 정의하고, 적용근거를 위한 법 제도의 검토사항을 제시하였다. 또한, 전자의무기록에 대한 전자서명의 구체적인 적용방안을 예시하여 의료분야에 있어서 보안적용을 위한 기준을 제시하였다.

AVOIDITALS: Enhanced Cyber-attack Taxonomy in Securing Information Technology Infrastructure

  • Syafrizal, Melwin;Selamat, Siti Rahayu;Zakaria, Nurul Azma
    • International Journal of Computer Science & Network Security
    • /
    • 제21권8호
    • /
    • pp.1-12
    • /
    • 2021
  • An operation of an organization is currently using a digital environment which opens to potential cyber-attacks. These phenomena become worst as the cyberattack landscape is changing rapidly. The impact of cyber-attacks varies depending on the scope of the organization and the value of assets that need to be protected. It is difficult to assess the damage to an organization from cyberattacks due to a lack of understanding of tools, metrics, and knowledge on the type of attacks and their impacts. Hence, this paper aims to identify domains and sub-domains of cyber-attack taxonomy to facilitate the understanding of cyber-attacks. Four phases are carried in this research: identify existing cyber-attack taxonomy, determine and classify domains and sub-domains of cyber-attack, and construct the enhanced cyber-attack taxonomy. The existing cyber-attack taxonomies are analyzed, domains and sub-domains are selected based on the focus and objectives of the research, and the proposed taxonomy named AVOIDITALS Cyber-attack Taxonomy is constructed. AVOIDITALS consists of 8 domains, 105 sub-domains, 142 sub-sub-domains, and 90 other sub-sub-domains that act as a guideline to assist administrators in determining cyber-attacks through cyber-attacks pattern identification that commonly occurred on digital infrastructure and provide the best prevention method to minimize impact. This research can be further developed in line with the emergence of new types and categories of current cyberattacks and the future.