• Title/Summary/Keyword: Infrastructure Vulnerability

Search Result 133, Processing Time 0.026 seconds

Analysis of Construction Plans of Rapid Charging Infrastructures based on Gas Stations in Rural Areas to Propagate Electric Vehicles (전기자동차 보급을 위한 농촌지역의 주유소 기반 급속 충전인프라 구축 방안 분석)

  • Kim, Solhee;Kim, Taegon;Suh, Kyo
    • Journal of Korean Society of Rural Planning
    • /
    • v.21 no.1
    • /
    • pp.19-28
    • /
    • 2015
  • As environmental concerns including climate change drive the strong regulations for car exhaust emissions, electric vehicles attract the public eye. The purpose of this study is to identify rural areas vulnerable for charging infrastructures based on the spatial distributions of the current gas stations and provide the target dissemination rates for promoting electric cars. In addition, we develop various scenarios for finding optimal way to expand the charging infrastructures through the administrative districts data including 11,677 gas stations, the number of whole national gas stations. Gas stations for charging infrastructures are randomly selected using the Monte Carlo Simulation (MCS) method. Evaluation criteria for vulnerability assessment include five considering the characteristic of rural areas. The optimal penetration rate is determined to 21% in rural areas considering dissemination efficiency. To reduce the vulnerability, the charging systems should be strategically installed in rural areas considering geographical characteristics and regional EV demands.

Using Genetic Algorithm for Optimal Security Hardening in Risk Flow Attack Graph

  • Dai, Fangfang;Zheng, Kangfeng;Wu, Bin;Luo, Shoushan
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.9 no.5
    • /
    • pp.1920-1937
    • /
    • 2015
  • Network environment has been under constant threat from both malicious attackers and inherent vulnerabilities of network infrastructure. Existence of such threats calls for exhaustive vulnerability analyzing to guarantee a secure system. However, due to the diversity of security hazards, analysts have to select from massive alternative hardening strategies, which is laborious and time-consuming. In this paper, we develop an approach to seek for possible hardening strategies and prioritize them to help security analysts to handle the optimal ones. In particular, we apply a Risk Flow Attack Graph (RFAG) to represent network situation and attack scenarios, and analyze them to measure network risk. We also employ a multi-objective genetic algorithm to infer the priority of hardening strategies automatically. Finally, we present some numerical results to show the performance of prioritizing strategies by network risk and hardening cost and illustrate the application of optimal hardening strategy set in typical cases. Our novel approach provides a promising new direction for network and vulnerability analysis to take proper precautions to reduce network risk.

Intrusion Prevention Using Harmful Traffic Analysis (유해 트래픽 분석을 이용한 침입 방지)

  • Chang, Moon-Soo;Koo, Hyang-Ohk;Oh, Chang-Suk
    • Journal of the Korea Society of Computer and Information
    • /
    • v.10 no.4 s.36
    • /
    • pp.173-179
    • /
    • 2005
  • The continuous development of computing technique and network technology bring the explosive growth of the Internet, it accomplished the role which is import changes the base facility in the social whole and public infra, industrial infrastructure, culture on society-wide to Internet based environment. Recently the rapid development of information and technology environment is quick repeated the growth and a development which is really unexampled in the history but it has a be latent vulnerability, Therefore the damage from this vulnerability like worm, hacking increases continually. In this paper, in order to resolve this problem, implement the analysis system for harmful traffic for defending new types of attack and analyzing the traffic takes a real-time action against intrusion and harmful information packet.

  • PDF

Secured Authentication Scheme and Charging & Discharging System Operation for Electric Vehicles (정보보호를 고려한 전기자동차 충방전 시스템의 인증과 운영에 관한 연구)

  • Lee, Sunguk
    • The Journal of the Convergence on Culture Technology
    • /
    • v.7 no.1
    • /
    • pp.551-557
    • /
    • 2021
  • With increase of electric vehicle in the road, the number of charging/discharging infrastructure for electric vehicle in public space is also increased rapidly. To charge or discharge the electric vehicle the user of electric vehicle and service provider should verify the each other's identity to minimize security vulnerability. This paper proposes mutual authentication scheme between electric vehicle and charging/discharging service provider with help of hash function and Message Authentication Code(MAC). Also efficient operating scheme for charging/discharging service system is proposed. The analysis shows that the system has robustness against security vulnerability. Also this system can keep the sensitive personal information of service user safely.

A Study on the Development of Adversarial Simulator for Network Vulnerability Analysis Based on Reinforcement Learning (강화학습 기반 네트워크 취약점 분석을 위한 적대적 시뮬레이터 개발 연구)

  • Jeongyoon Kim; Jongyoul Park;Sang Ho Oh
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.34 no.1
    • /
    • pp.21-29
    • /
    • 2024
  • With the development of ICT and network, security management of IT infrastructure that has grown in size is becoming very difficult. Many companies and public institutions are having difficulty managing system and network security. In addition, as the complexity of hardware and software grows, it is becoming almost impossible for a person to manage all security. Therefore, AI is essential for network security management. However, since it is very dangerous to operate an attack model in a real network environment, cybersecurity emulation research was conducted through reinforcement learning by implementing a real-life network environment. To this end, this study applied reinforcement learning to the network environment, and as the learning progressed, the agent accurately identified the vulnerability of the network. When a network vulnerability is detected through AI, automated customized response becomes possible.

Assessment of the Potential Impact of Climate Change on the Drought in Agricultural Reservoirs under SSP Scenarios (SSP 시나리오를 고려한 농업용 저수지의 이수측면 잠재영향평가)

  • Kim, Siho;Jang, Min-Won;Hwang, Syewoon
    • Journal of The Korean Society of Agricultural Engineers
    • /
    • v.66 no.2
    • /
    • pp.35-52
    • /
    • 2024
  • This study conducted an assessment of potential impacts on the drought in agricultural reservoirs using the recently proposed SSP (Shared Socioeconomic Pathways) scenarios by IPCC (Intergovernmental Panel on Climate Change). This study assesses the potential impact of climate change on agricultural water resources and infrastructure vulnerability within Gyeongsangnam-do, focusing on 15 agricultural reservoirs. The assessment was based on the KRC (Korea Rural Community Corporation) 1st vulnerability assessment methodology using RCP scenarios for 2021. However, there are limitations due to the necessity for climate impact assessments based on the latest climate information and the uncertainties associated with using a single scenario from national standard scenarios. Therefore, we applied the 13 GCM (General Circulation Model) outputs based on the newly introduced SSP scenarios. Furthermore, due to difficulties in data acquisiton, we reassessed potential impacts by redistributing weights for proxy variables. As a main result, with lower future potential impacts observed in areas with higher precipitation along the southern coast. Overall, the potential impacts increased for all reservoirs as we moved into the future, maintaining their relative rankings, yet showing no significant variability in the far future. Although the overall pattern of potential impacts aligns with previous evaluations, reevaluation under similar conditions with different spatial resolutions emphasizes the critical role of meteorological data spatial resolution in assessments. The results of this study are expected to improve the credibility and accuracy formulation of vulnerability employing more scientific predictions.

Security Problems in Aircraft Digital Network System and Cybersecurity Strategies (항공기 디지털 네트워크 시스템 보안 문제점과 사이버 대응 전략)

  • Lim, In-Kyu;Kang, Ja-Young
    • Journal of Advanced Navigation Technology
    • /
    • v.21 no.6
    • /
    • pp.633-637
    • /
    • 2017
  • Cyber attacks on aircraft and aeronautical networks are not much different from cyber attacks commonly found in the ground industry. Air traffic management infrastructure is being transformed into a digital infrastructure to secure air traffic. A wide variety of communication environments, information and communications, navigation, surveillance and inflight entertainment systems are increasingly threatening the threat posed by cyber terrorism threats. The emergence of unmanned aircraft systems also poses an uncontrollable risk with cyber terrorism. We have analyzed cyber security standards and response strategies in developed countries by recognizing the vulnerability of cyber threats to aircraft systems and aviation infrastructure in next generation data network systems. We discussed comprehensive measures for cybersecurity policies to consider in the domestic aviation environment, and discussed the concept of security environment and quick response strategies.

Internal Network Partition Security Model Based Authentication using BlockChain Management Server in Cloud Environment (클라우드 환경에서 블록체인관리서버를 이용한 인증기반 내부망 분리 보안 모델)

  • Kim, Young Soo;Lee, Byoung Yup
    • The Journal of the Korea Contents Association
    • /
    • v.18 no.6
    • /
    • pp.434-442
    • /
    • 2018
  • Recently, the threat to the security and damage of important data leaked by devices of intranet infected by malicious code through the Internet have been increasing. Therefore, the partitioned intranet model that blocks access to the server for business use by implementing authentication of devices connected to the intranet is required. For this, logical net partition with the VDI(Virtual Desktop Infrastructure) method is no information exchange between physical devices connected to the intranet and the virtual device so that it could prevent data leakage and improve security but it is vulnerable to the attack to expose internal data, which has access to the server for business connecting a nonregistered device into the intranet. In order to protect the server for business, we suggest a blockchain based network partition model applying blockchain technology to VDI. It contributes to decrease in threat to expose internal data by improving not only capability to verify forgery of devices, which is the vulnerability of the VDI based logical net partition, but also the integrity of the devices.

The Security Considerations for Implementation of Secure and Reliable e-Government (안전하고 신뢰성있는 전자정부 구축을 위한 보안요구사항)

  • 김명은;오승희;정연서;서동일
    • Convergence Security Journal
    • /
    • v.4 no.2
    • /
    • pp.77-83
    • /
    • 2004
  • According as information society has been raised, many countries of the world have taken a lot of interests in e-government implementation. The several guidance countries already have offered people various administrative service and popular enmity service in the Internet conveniently People can use e-government service more conveniently by the Internet, but important personal information or state secret can be leaked in the Internet. Because of these security vulnerabilities, a lot of countries are constructing security infrastructure that can protect personal information. In this paper, we examine e-government construction trends of the several guidance countries, and propose security considerations to provide safe and reliable e-government service.

  • PDF

An Optimized Authentication Method between Mobile Node and Home Agent using AAA in Mobile IPv6 (Mobile IPv6에서 AAA를 이용한 이동노드와 홈 에이전트간의 최적화된 인증 방안)

  • 김미영;문영성
    • Journal of KIISE:Information Networking
    • /
    • v.30 no.6
    • /
    • pp.714-719
    • /
    • 2003
  • A Mobile IPv6 services exposes its vulnerability when a mobile node is roaming the subnets belonging to the different domains. The AAA infrastructure is strongly recommended when the ISPs need to authenticate the mobile user comes from the different domains. In addition to the basic requirements for the AAA service, the authentication latency and AAA message overhead should be minimized for the continuity of the mobile service. This paper considers the roaming service with AAA infrastructure in Mobile IPv6 and proposes an authentication scheme using delegation to authenticate the mobile node with effective manner. The effectiveness of the proposed scheme is confirmed using the cost analysis. The result shows at least 50% of performance enhancement when the MN is roaming fast under the control of the delegation.