• Title/Summary/Keyword: Macro detection

Search Result 61, Processing Time 0.023 seconds

A Research of Anomaly Detection Method in MS Office Document (MS 오피스 문서 파일 내 비정상 요소 탐지 기법 연구)

  • Cho, Sung Hye;Lee, Sang Jin
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.6 no.2
    • /
    • pp.87-94
    • /
    • 2017
  • Microsoft Office is an office suite of applications developed by Microsoft. Recently users with malicious intent customize Office files as a container of the Malware because MS Office is most commonly used word processing program. To attack target system, many of malicious office files using a variety of skills and techniques like macro function, hiding shell code inside unused area, etc. And, people usually use two techniques to detect these kinds of malware. These are Signature-based detection and Sandbox. However, there is some limits to what it can afford because of the increasing complexity of malwares. Therefore, this paper propose methods to detect malicious MS office files in Computer forensics' way. We checked Macros and potential problem area with structural analysis of the MS Office file for this purpose.

Detection of Gradual Transitions in MPEG Compressed Video using Hidden Markov Model (은닉 마르코프 모델을 이용한 MPEG 압축 비디오에서의 점진적 변환의 검출)

  • Choi, Sung-Min;Kim, Dai-Jin;Bang, Sung-Yang
    • Journal of KIISE:Software and Applications
    • /
    • v.31 no.3
    • /
    • pp.379-386
    • /
    • 2004
  • Video segmentation is a fundamental task in video indexing and it includes two kinds of shot change detections such as the abrupt transition and the gradual transition. The abrupt shot boundaries are detected by computing the image-based distance between adjacent frames and comparing this distance with a pre-determined threshold value. However, the gradual shot boundaries are difficult to detect with this approach. To overcome this difficulty, we propose the method that detects gradual transition in the MPEG compressed video using the HMM (Hidden Markov Model). We take two different HMMs such as a discrete HMM and a continuous HMM with a Gaussian mixture model. As image features for HMM's observations, we use two distinct features such as the difference of histogram of DC images between two adjacent frames and the difference of each individual macroblock's deviations at the corresponding macroblock's between two adjacent frames, where deviation means an arithmetic difference of each macroblock's DC value from the mean of DC values in the given frame. Furthermore, we obtain the DC sequences of P and B frame by the first order approximation for a fast and effective computation. Experiment results show that we obtain the best detection and classification performance of gradual transitions when a continuous HMM with one Gaussian model is taken and two image features are used together.

Investigation of Water Safety in Non-treated Drinking Water with Trace Toxic Metals

  • Ly, Suw Young;Kim, Dae Hong;Lee, Ga Eun
    • Toxicological Research
    • /
    • v.29 no.3
    • /
    • pp.211-215
    • /
    • 2013
  • The trace toxic metal copper was assayed using mercury immobilized on a carbon nanotube electrode (MCW), with a graphite counter and a reference electrode. In this study, a macro-scale convection motor was interfaced with a MCW three-electrode system, in which a handmade MCW was optimized using cyclic- and square-wave stripping voltammetry. An analytical electrolyte for tap water was used instead of an expensive acid or base ionic solution. Under these conditions, optimum parameters were 0.09 V amplitude, 40 Hz frequency, 0.01 V incremental potential, and a 60-s accumulation time. A diagnostic working curve was obtained from 50.0 to 350 ${\mu}g/L$. At a constant Cu(II) concentration of 10.0 ${\mu}g/L$, the statistical relative standard deviation was 1.78% (RSD, n = 15), the analytical accumulation time was only 60 s, and the analytical detection limit approached 4.6 ${\mu}g/L$ (signal/noise = 3). The results were applied to non-treated drinking water. The content of the analyzed copper using 9.0 and 4.0 ${\mu}g/L$ standards were 8.68 ${\mu}g/L$ and 3.96 ${\mu}g/L$; statistical values $R^2$ = 0.9987 and $R^2$ = 0.9534, respectively. This method is applicable to biological diagnostics or food surveys.

Damage state evaluation of experimental and simulated bolted joints using chaotic ultrasonic waves

  • Fasel, T.R.;Kennel, M.B.;Todd, M.D.;Clayton, E.H.;Park, G.
    • Smart Structures and Systems
    • /
    • v.5 no.4
    • /
    • pp.329-344
    • /
    • 2009
  • Ultrasonic chaotic excitations combined with sensor prediction algorithms have shown the ability to identify incipient damage (loss of preload) in a bolted joint. In this study we examine a physical experiment on a single-bolt aluminum lap joint as well as a three-dimensional physics-based simulation designed to model the behavior of guided ultrasonic waves through a similarly configured joint. A multiple bolt frame structure is also experimentally examined. In the physical experiment each signal is imparted to the structure through a macro-fiber composite (MFC) patch on one side of the lap joint and sensed using an equivalent MFC patch on the opposite side of the joint. The model applies the waveform via direct nodal displacement and 'senses' the resulting displacement using an average of the nodal strain over an area equivalent to the MFC patch. A novel statistical classification feature is developed from information theory concepts of cross-prediction and interdependence. This damage detection algorithm is used to evaluate multiple damage levels and locations.

Detection of Foliar Nutrients of Oil Palm Crop Using Remote Sensing

  • Ibrahim, Ab.Latif;Hashim, Mazlan;Rasib, Abd.Wahid;Ali, Mohamad Idris;Kadir, Wan Hazli Wan;Sumairi, Mohd Razif;Haron, Khalid
    • Proceedings of the KSRS Conference
    • /
    • 2003.11a
    • /
    • pp.558-560
    • /
    • 2003
  • This paper examines the capability of remote sensing technique for detecting and quantifying the foliar nutrients of oil palm crop. Study has been carried out in the Malaysian Palm Oil Board (MPOB) Research Station in Kluang Johore, Malaysia. Result of the study shows a strong relationship between measured foliar nutrient and the spectral reflectance measured using spectroradiometer. Model that has been developed can be used to estimate the nutrient concentration in the oil palm plantation at micro level and also at macro -level using appropriate satellite data.

  • PDF

Laser based impedance measurement for pipe corrosion and bolt-loosening detection

  • Yang, Jinyeol;Liu, Peipei;Yang, Suyoung;Lee, Hyeonseok;Sohn, Hoon
    • Smart Structures and Systems
    • /
    • v.15 no.1
    • /
    • pp.41-55
    • /
    • 2015
  • This study proposes a laser based impedance measurement system and impedance based pipe corrosion and bolt-loosening monitoring techniques under temperature variations. For impedance measurement, the laser based impedance measurement system is optimized and adopted in this paper. First, a modulated laser beam is radiated to a photodiode, converting the laser beam into an electric signal. Then, the electric signal is applied to a MFC transducer attached on a target structure for ultrasonic excitation. The corresponding impedance signals are measured, re-converted into a laser beam, and radiated back to the other photodiode located in a data interrogator. The transmitted impedance signals are treated with an outlier analysis using generalized extreme value (GEV) statistics to reliably signal off structural damage. Validation of the proposed technique is carried out to detect corrosion and bolt-loosening in lab-scale carbon steel elbow pipes under varying temperatures. It has been demonstrated that the proposed technique has a potential to be used for structural health monitoring (SHM) of pipe structures.

Traffic Emission Modelling Using LiDAR Derived Parameters and Integrated Geospatial Model

  • Azeez, Omer Saud;Pradhan, Biswajeet;Jena, Ratiranjan;Jung, Hyung-Sup;Ahmed, Ahmed Abdulkareem
    • Korean Journal of Remote Sensing
    • /
    • v.35 no.1
    • /
    • pp.137-149
    • /
    • 2019
  • Traffic emissions are the main cause of environmental pollution in cities and respiratory problems amongst people. This study developed a model based on an integration of support vector regression (SVR) algorithm and geographic information system (GIS) to map traffic carbon monoxide (CO) concentrations and produce prediction maps from micro level to macro level at a particular time gap in a day in a very densely populated area (Utara-Selatan Expressway-NKVE, Kuala Lumpur, Malaysia). The proposed model comprised two models: the first model was implemented to estimate traffic CO concentrations using the SVR model, and the second model was applied to create prediction maps at different times a day using the GIS approach. The parameters for analysis were collected from field survey and remote sensing data sources such as very-high-resolution aerial photos and light detection and ranging point clouds. The correlation coefficient was 0.97, the mean absolute error was 1.401 ppm and the root mean square error was 2.45 ppm. The proposed models can be effectively implemented as decision-making tools to find a suitable solution for mitigating traffic jams near tollgates, highways and road networks.

Mechanical behavior of sandstones under water-rock interactions

  • Zhou, Kunyou;Dou, Linming;Gong, Siyuan;Chai, Yanjiang;Li, Jiazhuo;Ma, Xiaotao;Song, Shikang
    • Geomechanics and Engineering
    • /
    • v.29 no.6
    • /
    • pp.627-643
    • /
    • 2022
  • Water-rock interactions have a significant influence on the mechanical behavior of rocks. In this study, uniaxial compression and tension tests on different water-treated sandstone samples were conducted. Acoustic emission (AE) monitoring and micro-pore structure detection were carried out. Water-rock interactions and their effects on rock mechanical behavior were discussed. The results indicate that water content significantly weakens rock mechanical strength. The sensitivity of the mechanical parameters to water treatment, from high to low, are Poisson ratio (𝜇), uniaxial tensile strength (UTS), uniaxial compressive strength (UCS), elastic modulus (E), and peak strain (𝜀). After water treatment, AE activities and the shear crack percentage are reduced, the angles between macro fractures and loading direction are minimized, the dynamic phenomenon during loading is weakened, and the failure mode changes from a mixed tensile-shear type to a tensile one. Due to the softening, lubrication, and water wedge effects in water-rock interactions, water content increases pore size, promotes crack development, and weakens micro-pore structures. Further damage of rocks in fractured and caved zones due to the water-rock interactions leads to an extra load on the adjoining coal and rock masses, which will increase the risk of dynamic disasters.

Development of Macro Program Detection System using Access_log (Access_log를 활용한 매크로 프로그램 탐지 시스템 개발)

  • Kim, Jun-young;Kim, Kyu-rim;Park, Han-sol;An, Seung-hwan;Lee, Hyun-tak;Choi, Sang-Yong;Lee, Jong-Rak
    • Proceedings of the Korean Society of Computer Information Conference
    • /
    • 2020.07a
    • /
    • pp.103-106
    • /
    • 2020
  • 매크로 프로그램에 의한 피해는 꾸준히 보고되어 왔다. 최근 코로나 19로 인해 마스크 품귀 현상이 발생하여 매크로 프로그램을 이용한 구매가 사회적 이슈로 떠오르면서 매크로에 대하여 법적 처벌을 하는 등 매크로에 대한 관심이 부각되고 있다. 본 논문에서는 매크로 프로그램을 효과적으로 탐지하기 위한 방법을 제안한다. 본 논문에서는 매크로 탐지를 위해 access.log의 다양한 필드를 분석하고, 이 중 매크로 식별에 효과가 있는 필드를 추출하여 매크로를 탐지한다. 제안하는 기술의 효과성 검증을 위해 매크로의 공통적인 기능이 포함된 매크로 프로그램을 직접 제작하고, 실제 구매 웹사이트와 유사한 판매 사이트를 제작하여 실험을 통해 제안하는 방법이 매크로를 효과적으로 탐지하는 것을 보인다.

  • PDF

The Classification, Origin, Collection, Determination of Activity, Purification, Production, and Application of Agarases (Agarase의 분류, 기원, 확보, 활성파악, 분리정제, 생산 및 응용)

  • Lee, Dong-Geun;Lee, Sang-Hyeon
    • Journal of Life Science
    • /
    • v.22 no.2
    • /
    • pp.266-280
    • /
    • 2012
  • Agar is a cell wall component of macro red algae that can be hydrolyzed by agarase. Agarases are classified into ${\alpha}$-agarase (E.C. 3.2.1.158) and ${\beta}$-agarase (E.C. 3.2.1.81), in accordance with their cleavage pattern, and can be grouped in the glycoside hydrolase (GH)-16, -58, -86, -96, and -118 family according to the amino acid sequences of the proteins. Many agarases and/or their genes have been detected, isolated, and recombinantly expressed from bacteria, and metagenomes have their origins in sea and terrestrial environments. Products of agarases, agarooligosaccharides and neoagarooligosaccharides, represent wide functions such as antitumor, immune stimulation, antioxidation, prebiotic, hepa-protective, antibacterial, whitening, and moisturizing effects; hence, broad applications would be possible in the food industry, cosmetics, and medical fields. In addition, agarases are also used as a tool enzyme for research. This paper reviews the sources, purifications and detection methods, and application fields of agarases. The role of agarases in agar metabolism and the function of their enzymatic products are also surveyed.