• Title/Summary/Keyword: LOGGING

Search Result 672, Processing Time 0.023 seconds

Event Log Analysis Framework Based on the ATT&CK Matrix in Cloud Environments (클라우드 환경에서의 ATT&CK 매트릭스 기반 이벤트 로그 분석 프레임워크)

  • Yeeun Kim;Junga Kim;Siyun Chae;Jiwon Hong;Seongmin Kim
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.34 no.2
    • /
    • pp.263-279
    • /
    • 2024
  • With the increasing trend of Cloud migration, security threats in the Cloud computing environment have also experienced a significant increase. Consequently, the importance of efficient incident investigation through log data analysis is being emphasized. In Cloud environments, the diversity of services and ease of resource creation generate a large volume of log data. Difficulties remain in determining which events to investigate when an incident occurs, and examining all the extensive log data requires considerable time and effort. Therefore, a systematic approach for efficient data investigation is necessary. CloudTrail, the Amazon Web Services(AWS) logging service, collects logs of all API call events occurring in an account. However, CloudTrail lacks insights into which logs to analyze in the event of an incident. This paper proposes an automated analysis framework that integrates Cloud Matrix and event information for efficient incident investigation. The framework enables simultaneous examination of user behavior log events, event frequency, and attack information. We believe the proposed framework contributes to Cloud incident investigations by efficiently identifying critical events based on the ATT&CK Framework.

Characteristics of Lode Development and Structural Interpretation for the High Au Contents within the Fault Gouge Zones in Jinsan Au Mine, Chungcheongnam-do (충남 금산 진산금광산의 광맥 발달특성과 단층점토에 농집된 고품위 금함량에 대한 구조지질학적 해석)

  • Shin, Dongbok;Gwon, Sehyeon;Kim, Young-Seog
    • Economic and Environmental Geology
    • /
    • v.48 no.2
    • /
    • pp.103-114
    • /
    • 2015
  • Jinsan gold deposit is a hydrothermal vein type deposit consisting of several fissure filling quartz veins developed within the Changri Formation of the Ogcheon Supergroup in Geumsan, Chungnam. This study is to provide an efficient exploration and development strategies based on the characteristics of the geology, geological structure, core logging, and ore vein occurrence and grade for the four pits (New pit, Main pit, Yanghapan pit and Teugho pit). Quartz veins are mostly developed with the strike of $N10^{\circ}-25^{\circ}W$ and $N5^{\circ}-20^{\circ}E$, and the thickness is in the range of 0.1~0.5 m, sometimes extending to over 1m. Although the quartz veins commonly form massive shape, they sometimes show zonal structure, comb structure as well as brecciated texture. Major ore minerals are pyrite and chalcopyrite, and pyrrhotite, sphalerite, galena, marcasite, electrum and chalcocite are also accompanied as minor phases. Gray and milky white quartz veins, which are occasionally crosscut by calcite vein, also include fluorite. Ore evaluations for the 22 samples revealed that the samples from the pits generally have very low Au contents, lower than 1 g/t, but some clay samples of drilled core show very high Au concentrations, up to 141 g/t, indicating that Au content is much higher within fault gouges rather than within fresh quartz veins. This may represent that gold might have been reworked and reprecipitated by hydrothermal fluids in association with reactivation of the faults, and thus suggest that ore occurrence in this deposit is very complex and irregular and therefore more precise and systematic exploration is required.

Behavioural Analysis of Password Authentication and Countermeasure to Phishing Attacks - from User Experience and HCI Perspectives (사용자의 패스워드 인증 행위 분석 및 피싱 공격시 대응방안 - 사용자 경험 및 HCI의 관점에서)

  • Ryu, Hong Ryeol;Hong, Moses;Kwon, Taekyoung
    • Journal of Internet Computing and Services
    • /
    • v.15 no.3
    • /
    • pp.79-90
    • /
    • 2014
  • User authentication based on ID and PW has been widely used. As the Internet has become a growing part of people' lives, input times of ID/PW have been increased for a variety of services. People have already learned enough to perform the authentication procedure and have entered ID/PW while ones are unconscious. This is referred to as the adaptive unconscious, a set of mental processes incoming information and producing judgements and behaviors without our conscious awareness and within a second. Most people have joined up for various websites with a small number of IDs/PWs, because they relied on their memory for managing IDs/PWs. Human memory decays with the passing of time and knowledges in human memory tend to interfere with each other. For that reason, there is the potential for people to enter an invalid ID/PW. Therefore, these characteristics above mentioned regarding of user authentication with ID/PW can lead to human vulnerabilities: people use a few PWs for various websites, manage IDs/PWs depending on their memory, and enter ID/PW unconsciously. Based on the vulnerability of human factors, a variety of information leakage attacks such as phishing and pharming attacks have been increasing exponentially. In the past, information leakage attacks exploited vulnerabilities of hardware, operating system, software and so on. However, most of current attacks tend to exploit the vulnerabilities of the human factors. These attacks based on the vulnerability of the human factor are called social-engineering attacks. Recently, malicious social-engineering technique such as phishing and pharming attacks is one of the biggest security problems. Phishing is an attack of attempting to obtain valuable information such as ID/PW and pharming is an attack intended to steal personal data by redirecting a website's traffic to a fraudulent copy of a legitimate website. Screens of fraudulent copies used for both phishing and pharming attacks are almost identical to those of legitimate websites, and even the pharming can include the deceptive URL address. Therefore, without the supports of prevention and detection techniques such as vaccines and reputation system, it is difficult for users to determine intuitively whether the site is the phishing and pharming sites or legitimate site. The previous researches in terms of phishing and pharming attacks have mainly studied on technical solutions. In this paper, we focus on human behaviour when users are confronted by phishing and pharming attacks without knowing them. We conducted an attack experiment in order to find out how many IDs/PWs are leaked from pharming and phishing attack. We firstly configured the experimental settings in the same condition of phishing and pharming attacks and build a phishing site for the experiment. We then recruited 64 voluntary participants and asked them to log in our experimental site. For each participant, we conducted a questionnaire survey with regard to the experiment. Through the attack experiment and survey, we observed whether their password are leaked out when logging in the experimental phishing site, and how many different passwords are leaked among the total number of passwords of each participant. Consequently, we found out that most participants unconsciously logged in the site and the ID/PW management dependent on human memory caused the leakage of multiple passwords. The user should actively utilize repudiation systems and the service provider with online site should support prevention techniques that the user can intuitively determined whether the site is phishing.

A Study on Strategy of Forest Rehabilitation Support Corresponding to the Spread of Marketization in North Korea (북한의 시장화 확산에 대응한 대북 산림복구 지원전략 연구)

  • Song, Minkyung;Yi, Jong-Min;Park, Kyung-Seok
    • Journal of Korean Society of Forest Science
    • /
    • v.106 no.4
    • /
    • pp.487-496
    • /
    • 2017
  • The marketization in North Korea is spreading rapidly. This study proposes forest rehabilitation strategy for North Korea in light of their major shift toward market economy. This current trend of marketization in North Korea is now affecting the forest sector, especially the way the residents utilize small forest land. For analyzing the influence of marketization on forest management in North Korea, we reviewed the official documents issued by North Korea and related materials of North Korean marketization. The government of Kim Jong Eun has set up policies and systems regarding the spread of marketization, such as guaranteeing individuals a right to dispose certain products on their own and establishing a special economic zone to attract foreign investments. In the forestry sector, the North Korean government has been trying to fully implement its forest restoration plan by carrying out measures like re-claiming of sloping lands that had been previously used by residents. However, as marketization progresses, it is expected that there lies much difficulty in government-led massive mobilization for forest restoration due to the increase of illegal logging to meet high demand for timber, illegal firewood harvesting, collecting non-timber products for livelihoods and illegal crop cultivation to sell in the market. Therefore, South Korea's support for forest restoration should also consider the recent marketization phenomenon in North Korea. It is necessary to formulate strategic measures such as conducting joint commercialization project on agroforestry management using cooperative farming unit, helping to improve income source from small forest lands, and to activate a comprehensive mountain village special economic zone by utilizing forest business. We do hope that our proposed forest rehabilitation strategy in this paper regarding the changes in North Korea's marketization and forest policy can give a meaningful suggestion on supporting forest restoration in North Korea in an effective way.

Geological Characteristics of Extra Heavy Oil Reservoirs in Venezuela (베네주엘라 초중질유 저류층 지질 특성)

  • Kim, Dae-Suk;Kwon, Yi-Kyun;Chang, Chan-Dong
    • Economic and Environmental Geology
    • /
    • v.44 no.1
    • /
    • pp.83-94
    • /
    • 2011
  • Extra heavy oil reservoirs are distributed over the world but most of them is deposited in the northern part of the Orinoco River in Venezuela, in the area of 5,500 $km^2$, This region, which has been commonly called "the Orinoco Oil Belt", contains estimated 1.3 trillion barrels of original oil-in-place and 250 billion barrels of established reserves. The Venezuela extra heavy oil has an API gravity of less than 10 degree and in situ viscosity of 5,000 cP at reservoir condition. Although the presence of extra heavy oil in the Orinoco Oil Belt has been initially reported in the 1930's, the commercial development using in situ cold production started in the 1990's. The Orinoco heavy oil deposits are clustered into 4 development areas, Boyaco, Junin, Ayachoco, and Carabobo respectively, and they are subdivided into totally 31 production blocks. Nowadays, PDVSA (Petr$\'{o}$leos de Venzuela, S.A.) makes a development of each production block with the international oil companies from more than 20 countries forming a international joint-venture company. The Eastern Venezuela Basin, the Orinoco Oil Belt is included in, is one of the major oil-bearing sedimentary basins in Venezuela and is first formed as a passive margin basin by the Jurassic tectonic plate motion. The major source rock of heavy oil is the late Cretaceous calcareous shale in the central Eastern Venezuela Basin. Hydrocarbon materials migrated an average of 150 km up dip to the southern margin of the basin. During the migration, lighter fractions in the hydrocarbon were removed by biodegradation and the oil changed into heavy and/or extra heavy oil. Miocene Oficina Formation, the main extra heavy oil reservoir, is the unconsolidated sand and shale alternation formed in fluvial-estuarine environment and also has irregularly a large number of the Cenozoic faults induced by basin subsidence and tectonics. Because Oficina Formation has not only complex lithology distribution but also irregular geology structure, geological evolution and characteristics of the reservoirs have to be determined for economical production well design and effective oil recovery. This study introduces geological formation and evolution of the Venezuela extra heavy oil reservoirs and suggest their significant geological characteristics which are (1) thickness and geometry of reservoir pay sands, (2) continuity and thickness of mud beds, (3) geometry of faults, (4) depth and geothermal character of reservoir, (5) in-situ stress field of reservoir, and (6) chemical composition of extra heavy oil. Newly developed exploration techniques, such as 3-D seismic survey and LWD (logging while drilling), can be expected as powerful methods to recognize the geological reservoir characteristics in the Orinoco Oil Belt.

Hand-Arm Vibration and Noise Levels of Double-Hammer Type and Oil-Pulse Type Impact Wrenches in Automobile Assembly Lines (자동차 조립라인에서 이중-헴머형(Double-hammer type) 임펙트 렌치와 오일-펄스형(Oil-pulse type)임펙트 렌치 에어공구의 국소진동가속도 및 소음수준)

  • Jeung, Jae-Yeal;Kim, Jung-Man
    • Journal of Korean Society of Occupational and Environmental Hygiene
    • /
    • v.5 no.2
    • /
    • pp.147-159
    • /
    • 1995
  • This study was conducted to introduce fundamental data of hand-arm vibration and noise exposure levels with impact wrenches(double-hammer impact wrenches and oil-pulse impact wrenches) used in automobile assembly lines considering the process variables and tool variables. In studing, products per day, required time screwing the bolts or nuts per bolts or nut were considered as process variables, and capacity of bolts or nuts, air consumptions per minute, tool weights, RPM were considered as tool variables. Hand-arm vibration levels of 3 axis in each hand were measured using the instruments compling with ISO/DIS 5349 and noise levels were measured using a noise logging dosimeter. The results were as follows : 1. Required time to screwing the bolt or nut by oil-pulse impact wrenches is shorter than double-hammer impact wrenches but total daily exposure time of oil-pulse impact wrenches was higher than double-hammer impact wrenches because the number of bolts or nuts per cycle was many. 2. Oil-pulse impact wrenches have been used to screwing the large bolt or nut in comparing with double-hammer impact wrenches and required time to screwing the bolts or nuts were shorter than double-hammer impact wrenches because oil-pulse impact wrenches were using high RPM and large air consumption per minute. Noise level of oil-pulse impact wrenches was 8 dB(A) lower than double-hammer impact wrenches. 3. Dominant hand-arm vibration levels of double-hammer impact wrenches in each hand were $8.24m/sec^2$ of Zh axis in right hand and $9.60m/sec^2$ of Xh axis in left hand. Dominant hand-arm vibration level of oil-pulse impact wrenches in each hand was $2.59m/sec^2$ of Xh axis in right hand and $3.23m/sec^2$ of Yh axis in left hand. 4. In double-hammer impact wrenches, corresponding hand-arm vibration levels of Xh, Yh, Zh axis in left hand were higher than hand-arm vibration levels of right hand in 3 axis. In oil-pulse impact wrenches, Xh axis of right, Yh axis of left, Zh axis of left were higher than the corresponding hand-arm vibration levels of Xh, Yh, Zh axis in right and left hand. 5. Correlation coefficients among Xh, Yh. Zh axis of right and left hand hand-arm vibration levels in double-hammer impact wrenches and oil-pulse impact wrenches were commonly high in Yh axis and correlation coefficients of Yh axis in double-hammer impact wrenches and oil-pulse impact wrenches were 0.76 and 0.86,respectively. 6. As a measure repetitiveness, plotting total daily exposure time with the number of bolts or nut per cycle, direct correlation was shown between repetitiveness and hand-arn vibration exposure, and correlation coefficient between the number of bolts or nut per cycle and total daily exposure time in double-hammer impact wrenches, oil-pulse impact wrenches were 0.84 and 0.50, respectively. 7. Considering the total acceleration level and tool variables in double-hammer impact wrenches and oil-pulse impact wrenches, air consumption in right hand, and bolt or nut capacity in left hand were commonly the variable that explainability was high. Considering the noise and tool variables in double-hammer impact wrenches and oil-pulse impact wrenches, air consumption per minute was commonly the variable that explainability was high.

  • PDF

A Study on Industrial Potential of Artificial Intelligence through the Cases of Film and Artificial Intelligence Art (예술에서 살펴본 인공지능의 미래 산업화 가능성 - 영화와 인공지능 예술을 중심으로)

  • Kim, Hee-Young
    • Cartoon and Animation Studies
    • /
    • s.50
    • /
    • pp.423-452
    • /
    • 2018
  • The possibility of future industrialization of artificial intelligence was studied through aspects of artificial intelligence art and movie. The field of artificial intelligence is developing by imitating humans through past and present, so it can be inferred that it is important to grasp the future image presented in movie and artificial intelligence art. Human values are represented differently in artificial intelligence films and arts. Artificial intelligence film and art are concerned with the external and internal aspects of human values, respectively. The AI movie looks at similar external aspects in human and AI shape and function, but artificial intelligence art deals with human alienation and lack of communication due to artificial intelligence technology development. Artificial intelligence in movies is a direction to visualize the imagination for artificial intelligence technology, and artificial intelligence art is expressed in the way of making and implementing works using technology. The future of artificial intelligence, which we have shown in imagination in movies today, is being realized technologically. Artificial intelligence art reflects the problems of artificial intelligence technology that can be appeared through current technology, and human problems that may arise from artificial intelligence technology development. Movies and artificial intelligence art reflect the current problems, and through them we can see the future of artificial intelligence. The future of artificial intelligence in movies is an artificial intelligence service that provides human convenience, cyborg artificial intelligence industry, industry that uses exoskeleton robot and exoskeleton suit, and artificial intelligence secretary. If we look at the future of artificial intelligence through the artificial intelligence art in terms of the problems of artificial intelligence technology and the problem of human value, there are artificial intelligence to learn from trial and error or mistakes, self-expression and communication by lifelogging, recovery of miscommunications by a reflective thinking, and an expansion of the area of artificial intelligence artist through human uncertainty. The future industrialization potential of artificial intelligence as study through aspects of artificial intelligence art and movie is an industry that extends the five senses, an industry that improves the insufficient physical ability of the human, an industry that enhances the physical ability of the human being, and an industry that maintains psychological and mental well-being.

Analysis of transmissivity tensor in an anisotropic aquifer (이방성 대수층에서의 투수량계수텐서 해석)

  • 강철희;이대하;김구영;이철우;김용제;우남칠
    • Journal of Soil and Groundwater Environment
    • /
    • v.7 no.2
    • /
    • pp.53-61
    • /
    • 2002
  • An Aquifer test was carried out on five boreholes to determine the hydrologic anisotropy and the major groundwater flow direction in the aquifer system of the study area. With an assumption of the aquifer's anisotropy and homogeneity, the major transmissivity(T(equation omitted)), the minor transmissivity( $T_{ηη}$ ), and primary tensor direction ($\theta$) for each borehole were determined from the test. Besides the boreholes BH-1, BH-4 and BH-5, the anisotropy transmissivity tensor values of BH-2 and BH-3 did not correspond with the assumption. Thereafter the values were plotted on the polar coordinate, and showed that the tensor values were out of the anisotropy ellipsoid due to the high heterogeneity of BH-2 and BH-3 comparing with the other boreholes. Therefore. the anisotropy of the aquifer was examined from BH-1, BH-4. and BH-5. In BH-1, T(equation omitted) is 171.9 $\m^2$/day. $T_{ηη}$ is $71.01\m^2$/day, and the principal tensor direction is Nl5.39$^{\circ}$E. In BH-4. T(equation omitted) is $268.2 \m^2$/day, $T_{ηη}$ / is $28.75\m^2$/day and the principal tensor direction is N7.55$^{\circ}$E. In BH-5, T(equation omitted) is $168.4\m^2$/day, $T_{ηη}$ is 66.80 $\m^2$/day, and the principal tensor direction is $N76.59^{\circ}$E. On the basis of teleview logging performed on each borehole. the principal fracture directions were revealed as $N0^{\circ}$~4$^{\circ}$E/$30^{\circ}$~$50^{\circ}$SE and $N30^{\circ}$~$80^{\circ}$W/$20^{\circ}$~$50^{\circ}$NE that are the most frequently occurred sets as well as that correspond well with the calculated transmissivity tensor.

Effect of Fineness of Siliceous Materials on Correction of Soil Acidity under Submerged Condition (담수시(湛水時) 규산물질(珪酸物質)들의 입도별(粒度別) 토양산도교정능력(土壤酸度矯正能力))

  • Lee, Yun Hwan;Han, Ki Hak;Kim, Bok Jin
    • Korean Journal of Soil Science and Fertilizer
    • /
    • v.5 no.2
    • /
    • pp.59-64
    • /
    • 1972
  • The liming effect of the four different siliceous materials with six grades of fineness were investigated in comparison with limestone under the submerged condition for three months, and the alkalinity extracted by 0.07N-EDTA and N-NaOAc solutions were determined to evaluate the neutralizing power of these materials. 1. Fused phosphate took 20 days with finer particles than 60 mesh (Tyler), 34 days with -40+48 mesh particles and 84 days with -20+25 mesh particles to reach the pH 5.5 from pH 4.0 of initial soil pH. These adjusted soil acidities were less 1.0-0.5 unit of pH compared with the pH of particles of limestone. 2. The basic reduction furnace slag increased the pH value to 5.5 in the finer particles than 100 mesh, but the other coarse particles appeared to have slow changes of the soil acidity to pH 4.5-4.7 for the three months. Wollastonite didn't affect the increase of soil pH in coarser particles than 25 mesh whereas other finer particles increased upto pH 4.5-5.0. Blast furnace slag is definitely slower through all sizes of particles. 3. In the relationship between the adjusted soil acidities and alkalinities dissolved in EDTA and NaOAc solution, NaOAc-alkalinity agreed quite closely to the activity of neutralizing value of silicates and limestone containing fineness of particles. The correlation coefficients between the amended soil acidities and NaOAc-alkalinities were stabilized with high significance at the 8 days after water logging and 16 days with the EDTA-alkalinities.

  • PDF

A Feasibility Study of AMT Application to Tidal Flat Sedimentary Layer (갯벌 지역의 하부퇴적층에 대한 AMT 탐사의 적용 가능성 평가)

  • Kwon, Byung-Doo;Lee, Choon-Ki;Park, Gye-Soon;Choi, Su-Young;Yoo, Hee-Young;Choi, Jong-Keun;Eom, Joo-Young
    • Journal of the Korean earth science society
    • /
    • v.28 no.1
    • /
    • pp.64-74
    • /
    • 2007
  • The marine seismic prospecting using a research vessel in the shallow sea near the coastal area has certain limits according to the water depth and survey environment. Also, for the electrical resistivity survey at seashore area, one may need a specially designed high-voltage source to penetrate the very conductive surface layer. Therefore, we have conducted a feasibility study on the application of magnetotelluric method (MT), a passive geophysical method, on investigating of shallow marine environment geology. Our study involves both theoretical modeling and field survey at the tidal flat area which represent the very shallow marine environment. We have applied the audio-frequency magnetotelluric (AMT) method to the intertidal deposits of Gunhung Bay, west coast of Korea, and analysed the field data both qualitatively and quantitatively to investigate the morphology and sedimentary stratigraphy of the tidal flat. The inversion of AMT data well reveals the upper sedimentary layer of Holocene intertidal sediments having a range of 13-20 m thickness and the erosional patterns at the unconformable contact boundary. However, the AMT inversion results tend to overestimate the depth of basement (30-50 m) when compared with the seismic section (27-33 m). Since MT responses are not significantly sensitive to the resistivity of middle layer or the depth of basement, the AMT inversion result for basement may have to be adjusted using the comparison with other geophysical information like seismic section or logging data if possible. But, the AMT method can be an effective alternative choice for investigating the seashore area to get important basic informations such as the depositional environment of the tidal flat, sea-water intrusion and the basement structure near the sea shore.