• 제목/요약/키워드: Poisoning attack

검색결과 21건 처리시간 0.024초

Implementation of a security system using the MITM attack technique in reverse

  • Rim, Young Woo;Kwon, Jung Jang
    • 한국컴퓨터정보학회논문지
    • /
    • 제26권6호
    • /
    • pp.9-17
    • /
    • 2021
  • 본 논문에서는 기존 네트워크의 물리적인 구조 및 구성을 변경하지 않고 네트워크 보안을 도입할 수 있는 방안으로 "Man In The Middle Attack" 공격 기법을 역이용함으로, Single Ethernet Interface만으로 가상 네트워크 오버레이를 형성하여 논리적인 In-line Mode를 구현하여 외부의 공격으로부터 네트워크를 보호하는 초소형 네트워크 보안 센서와 클라우드서비스를 통한 통합관제 방안을 제안한다. 실험 결과, Single Ethernet Interface만으로 가상 네트워크 오버레이를 형성하여 논리적인 In-line Mode를 구현할 수 있었으며, Network IDS/IPS, Anti-Virus, Network Access Control, Firewall 등을 구현할 수 있었고, 초소형 네트워크보안센서를 클라우드서비스에서 통합관제하는 것이 가능했다. 본 논문의 제안시스템으로 저비용으로 고성능의 네트워크 보안을 기대하는 중소기업에 도움이 되고 또한, IoT 및 Embedded System 분야에 안전·신뢰성을 갖춘 네트워크 보안환경을 제공할 수 있다.

섬소(蟾?)에 관(關)한 문헌적(文獻的) 고찰(考察) (Bibliographic Studies on the Bufonis Venenum)

  • 강계성;권기록
    • 대한약침학회지
    • /
    • 제4권2호
    • /
    • pp.35-47
    • /
    • 2001
  • Objectives : Through the literatures on the effets of Bufonis Venenum, we are finding out the clinical possibility and revealing the more effective to intractable diseases. Methods : We investigated the literatures of Oriental Medicine and experimental reports about Bufonis Venenum. Results : 1. Bufonis Venenum is made of bufonidae bufo bufo gargarizans cantor or bufo melanostictus schneider of white serum which secreted from parotid gland or dermato gland, and it is dried for using. 2. In oriental medicine, Bufonis Venenum has been mainly used on the tumors, cacanthrax and dermatic disease, and then it has been clinically used on infantile athrepsia, tetanus, sore throat, toothache, and so on. 3. The pharmacological effects of Bufonis Venenum are cardiotonic, respiration stimulation, depressor or vasopressor, topical anesthcsia, hallucination, striped muscle stimulation, antiasthmatic, antibacterial, antiinflammatory, anticancer, diuretic, immuno effects, etc. 4. Bufonis Venenum is largely divided in ether binding steroid compound, hydroxyl steroid compound, carboxyl or aldehyde steroid compound, indole compound, and adrenaline, cholesterole, etc. 5. Symptoms of Bufonis Venenum poisoning in digestive system are vommitig, abdominal pain, diarrhea, dehydration, in circulatory system are palpitation, shock, bradycardia, in nervous system are vertigo, somnolentia, muscle-tendon reflex weakness, and critical conditions to tissue necrosis and heart attack. 6. Ways to treat Bufonis Venenum poisoning include gastric irrigation with $0.2~0.5\%$ potassium permanganate fluid and atropine $0.5{\sim}1.0mg$ subcutaneous injection. From the chinese book of Bon Cho Gang Moke(本草綱目), if white serum of Bufonis Venenum enter the eyes, it happens the edema and pain. And then washed the eyes by juice of Lithospermi Radix(紫草) that the edema is removed. Conclusions and Discussion : The results from above literary studies show that prescriptions and Aqua-acupuncture of Bufonis Venenum could be clinically used to sedative, anticonvulsant, antibacterial, antiinflammatory, anticancer and topical ataralgesia. However it is expected that pharmacological and side effects of Bufonis Venenum are further studied.

Data Correction For Enhancing Classification Accuracy By Unknown Deep Neural Network Classifiers

  • Kwon, Hyun;Yoon, Hyunsoo;Choi, Daeseon
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제15권9호
    • /
    • pp.3243-3257
    • /
    • 2021
  • Deep neural networks provide excellent performance in pattern recognition, audio classification, and image recognition. It is important that they accurately recognize input data, particularly when they are used in autonomous vehicles or for medical services. In this study, we propose a data correction method for increasing the accuracy of an unknown classifier by modifying the input data without changing the classifier. This method modifies the input data slightly so that the unknown classifier will correctly recognize the input data. It is an ensemble method that has the characteristic of transferability to an unknown classifier by generating corrected data that are correctly recognized by several classifiers that are known in advance. We tested our method using MNIST and CIFAR-10 as experimental data. The experimental results exhibit that the accuracy of the unknown classifier is a 100% correct recognition rate owing to the data correction generated by the proposed method, which minimizes data distortion to maintain the data's recognizability by humans.

리소스 레코드 부분암호화를 이용한 DNS 변조공격 탐지 프로토콜 연구 (A Study on DNS Poisoning Attack Detection Protocol Based on Partial Encryption of Resource Record)

  • 심재화;민재원;최영현;정태명
    • 한국정보처리학회:학술대회논문집
    • /
    • 한국정보처리학회 2013년도 춘계학술발표대회
    • /
    • pp.683-686
    • /
    • 2013
  • 최근 인터넷을 이용한 금융거래가 활발해지면서 피싱이나 파밍과 같은 공격을 통한 개인정보 유출 사고가 빈번히 발생하고 있다. 특히 파밍의 경우, 공격자가 DNS 정보를 변조하여 사용자가 올바른 URL을 입력하더라도 악의적 사이트로 컴퓨터가 접속을 하기 때문에 위험성이 매우 높다. 이러한 공격들을 방지하기위하여 여러 연구가 진행되었지만, DNS 정보의 검증을 위한 추가적인 절차를 필요로 하거나 과도한 네트워크 트래픽을 유발할 수 있는 문제점을 가지고 있다. 따라서 본 논문에서는 이러한 문제점을 극복하고자 DNS 리소스 레코드(Resource Record)의 부분 암호화를 이용하여 DNS 변조 공격을 탐지 하는 프로토콜을 제안한다.

Tokenless OTP를 활용한 인증 모델 (The Authentication Model which Utilized Tokenless OTP)

  • 김기환;박대우
    • 한국컴퓨터정보학회지
    • /
    • 제14권2호
    • /
    • pp.205-214
    • /
    • 2006
  • 유비쿼터스 컴퓨팅 시대의 업무를 위하여 인터넷을 통한 원격 접속이 필요하고, 입력되는 ID와 패스워드에 대한 기밀성 무결성의 네트워크 보안을 위하여 OTP를 적용하고 있다. 현재의 OTP는 Token이라는 하드웨어를 보유하고 있어야 하며, 보안에서도 취약점이 있다. 본 논문에서는 OTP 네트워크에 스니핑 도구를 설치하고, Cain을 이용하여 ARP Cache poisoning 공격을 시행하여 사용자 암호에 대하여 스니핑으로 취약점을 확인한다. 새로운 보안 방안으로 Tokenless OTP를 적용할 수 있는 새로운 시스템을 제안하고, 기밀성과 무결성을 보장하고자 한다. 외부에서 원격 접속 시 Tokenless OTP를 활용하여 접근제어를 위한 테스트를 하고, 접속에서 인증시스템과 연동하여 접속제어를 할 수 있었다. 만약 인증과정에서 해킹을 당해도 사용자만이 알고 있는 핀 번호 없이는 접속이 불가능하다는 것이 확인되었다. 이 결과 Tokenless OTP를 적용할 시에 패스워드의 유출 및 오용과 해킹에 대한 방어가 되어 보안성을 강화하고, 안전성을 높이는 보안 시스템으로 평가되었다.

  • PDF

Tokenless OTP를 활용한 인증 모델 (The Authentication Model which Utilized Tokenless OTP)

  • 김기환;박대우
    • 한국컴퓨터정보학회논문지
    • /
    • 제12권1호
    • /
    • pp.107-116
    • /
    • 2007
  • 유비쿼터스 컴퓨팅 시대에서 업무를 위하여 인터넷을 통한 원격 접속을 할 때, 정보보안을 위해 입력되는 ID와 패스워드에 대한 기밀성, 무결성의 네트워크 보안을 위하여 OTP를 적용하고 있다. 현재의 OTP는 Token이라는 하드웨어를 보유하고 있어야 하며, 보안에서도 취약점이 있다. 본 논문에서는 OTP 네트워크에 스니핑 도구를 설치하고, Cain을 이용하여 ARP Cache poisoning 공격을 시행하여 사용자 암호에 대하여 스니핑으로 취약점을 확인한다. 새로운 보안 방안으로 Tokenless OTP를 적용할 수 있는 새로운 시스템을 제안하고, 기밀성과 무결성을 보장하고자 한다. 외부에서 원격 접속 시 Tokenless OTP를 활용하여 접근제어를 위한 테스트를 하고, 접속에서 인증시스템과 연동하여 접속제어를 할 수 있었다. 만약 인증과정에서 해킹을 당해도 사용자만이 알고 있는 핀 번호 없이는 접속이 불가능하다는 것이 확인되었다. 이 결과 Tokenless OTP를 적용할 시에 패스워드의 유출 및 오용과 해킹에 대한 방어가 되어 보안성을 강화하고, 안전성을 높이는 보안 시스템으로 평가되었다.

  • PDF

강원 영서 북부 지역의 약물 중독 실태 (The Clinical Investigation of Drug Intoxication in the North-Youngseo District of Kangwon Province)

  • 옥택근;조준휘;박찬우;김성은;최기훈;배지훈;서정열;정재봉;안희철;안무업;유기철
    • 대한임상독성학회지
    • /
    • 제2권2호
    • /
    • pp.83-89
    • /
    • 2004
  • Acute poisoning is one of the diseases which need the most fastest emergency measures at the very beginning. However, at present, The Korea doesn't manage the toxication all over the country, and in particular, there is no guide to medical cure paying due regard to the traits of each area. This paper focused on the issue that the necessary data in preparing the facilities for the treatment of the poisoned patients and materials for medical treatment including antidote would have to be collected, after finding the special features of the symptoms by searching the present conditions of the poisoning in small towns next to farm villages in the North area of Youngseo, Kangwon province. This study was based on the questionnaires from 111 patients who were carried into the emergency room by the poisoning in two university hospitals of the North area of Youngseo, Kangwon, for one year, 2002. Upon investigation, the patients(111) visiting emergency room by the acute poisoning during the research period was found to be 0.37 percent of all patients(30,085) visiting emergency room. Among them, the most high percentage was given in their twenties and thirties at the rate of $39.6\%$, and the ratio($40.5\%$) of the poisoned patients after their fifties was much higher than a research($10\%$) of other areas. Many poisoned patients came to their rescue in an emergency room generally in spring and in winter, from 7 a.m. to 3 p.m. Agricultural chemical of the toxic materials had a majority at a ratio of $57.7\%$, and paraquat of the agricultural chemicals was found to have a lot of toxicity by $31.7\%$. As the trace of the toxication, the oral poisoning was common by $89.2\%$, and $55.9\%$ in the case of operating gastric lavage and nasogastric irrigation, but only $14.4\%$ for prescribing antidote. The mortality of the acute poisoned patients was $17.2\%$, and the toxication by paraquat held a majority. As a result, the acute poisoning of the North area in Youngseo, Kangwon had both of the characteristics of the rural and the city, and the patients over their fifties by the population aging had more attack of the disease than other regions. Also, with the high ratio of the toxication by the agricultural chemicals, especially, the lethal agricultural chemical was used frequently. Therefore, these dangerous situations need to find the ways to cope with.

  • PDF

Minimize Web Applications Vulnerabilities through the Early Detection of CRLF Injection

  • Md. Mijanur Rahman;Md. Asibul Hasan
    • International Journal of Computer Science & Network Security
    • /
    • 제23권2호
    • /
    • pp.199-202
    • /
    • 2023
  • Carriage return (CR) and line feed (LF), also known as CRLF injection is a type of vulnerability that allows a hacker to enter special characters into a web application, altering its operation or confusing the administrator. Log poisoning and HTTP response splitting are two prominent harmful uses of this technique. Additionally, CRLF injection can be used by an attacker to exploit other vulnerabilities, such as cross-site scripting (XSS). Email injection, also known as email header injection, is another way that can be used to modify the behavior of emails. The Open Web Application Security Project (OWASP) is an organization that studies vulnerabilities and ranks them based on their level of risk. According to OWASP, CRLF vulnerabilities are among the top 10 vulnerabilities and are a type of injection attack. Automated testing can help to quickly identify CRLF vulnerabilities, and is particularly useful for companies to test their applications before releasing them. However, CRLF vulnerabilities can also lead to the discovery of other high-risk vulnerabilities, and it fosters a better approach to mitigate CRLF vulnerabilities in the early stage and help secure applications against known vulnerabilities. Although there has been a significant amount of research on other types of injection attacks, such as Structure Query Language Injection (SQL Injection). There has been less research on CRLF vulnerabilities and how to detect them with automated testing. There is room for further research to be done on this subject matter in order to develop creative solutions to problems. It will also help to reduce false positive alerts by checking the header response of each request. Security automation is an important issue for companies trying to protect themselves against security threats. Automated alerts from security systems can provide a quicker and more accurate understanding of potential vulnerabilities and can help to reduce false positive alerts. Despite the extensive research on various types of vulnerabilities in web applications, CRLF vulnerabilities have only recently been included in the research. Utilizing automated testing as a recurring task can assist companies in receiving consistent updates about their systems and enhance their security.

지하상가 가스누출 사고 환자들에 대한 임상적 고찰 - 일산화탄소 중독 - (Clinical Evaluation of Patients Intoxicated by a Gas Leak at an Underground Shopping Center - Carbon Monoxide Poisoning -)

  • 안지영;고영길
    • 대한임상독성학회지
    • /
    • 제4권2호
    • /
    • pp.122-127
    • /
    • 2006
  • Purpose: It is not easy to detect carbon monoxide (CO) leakage, and CO-intoxicated patients do not show a specific set of symptoms. The aims of this study are to clinically evaluate patients with CO gas intoxication from a CO leak at an underground shopping center, and to discuss the establishment of a disaster prevention plan. Methods: A total of 51 patients intoxicated by CO gas exposure in a gas disaster at a underground shopping center in Seoul on September 8, 2006 were enrolled in this study, and the patients' medical records were retrospectively reviewed. Results: The mean patient age was $29.4{\pm}6.3$. The initial mean COHb level was $14.98{\pm}6.97%$. The number of patients with COHb greater than 25% was three, and six patients experienced a syncopal attack. Only one patient-was treated with hyperbaric oxygen therapy. However, none of the patients complained of severe neurologic or cardiovascular symptoms. Conclusion: The symptoms of CO intoxication are non-specific and difficult to define, and the detection of CO leak-age is difficult. Thus, workplaces should be equipped with leakage sensors and automatic alarm systems and should have develop disaster prevention plans.

  • PDF

2014년 울산시 일개 고등학교 야구부원들에서 발생한 장독소생성대장균의 유행에 관한 역학조사 (Epidemiological Investigation on an Outbreak of Enterotoxigenic E. coli among the Baseball Club Students of High School in Ulsan City, 2014)

  • 강영은;임현술;이관;김병석
    • 농촌의학ㆍ지역보건
    • /
    • 제40권2호
    • /
    • pp.53-61
    • /
    • 2015
  • 2014년 울산광역시 일개 고등학교에서 장독소생성대장균의 유행이 발생하였고, 이에 대한 원인과 전파 양식 등을 규명하고 예방 및 관리대책을 마련하기 위해 역학조사를 시행하였다. 학교 야구부원 26명과 조리담당 학부모 2명을 대상으로 설문조사를 실시하였으며, 6월 13~14일 발생한 의심환자 7명과 조리담당 학부모 2명을 대상으로 보건환경연구원에서 세균 10종 및 바이러스 5종에 관한 검사를 시행하였다. 일별로 가장 많이 발생한 6월 14일을 기준으로 3일 전인 11일부터 13일까지의 식단을 이용하여 후향적 코호트 연구를 시행하였다. 학교 운동부 학생 26명 및 조리담당 학부모 2명 등 총 28명 중 환례는 10명으로 장독소생성대장균의 발병률은 35.7%이었다. 위험요인 분석에서 통계적으로 유의한 음식은 없었다. 이번 유행의 원인으로 생활관 식당 내 제빙기의 얼음퍼개 및 얼음이 6월 9일 초발자에 의하여 사용 과정에서 오염된 것으로 추정하였다. 오염된 얼음퍼개가 제빙기 내부에 보관되어, 얼음과 주변 녹은 물이 오염되고 그로 인해 원인병원체의 전파가 이루어졌다고 추정하였다.