• Title/Summary/Keyword: Port-security

Search Result 306, Processing Time 0.026 seconds

Study on the mechanism for the dynamic traversing of multiple firewalls using the concept of one-time master key (일회용 마스터 키 개념을 이용한 다중 방화벽 동적 통과 메커니즘 연구)

  • Park, Hyoung-Woo;Kim, Sang-Wan;Kim, Jong-Suk Ruth.;Jang, Haeng-Jin
    • The Journal of Korean Association of Computer Education
    • /
    • v.13 no.5
    • /
    • pp.103-110
    • /
    • 2010
  • If an exterior computer wants to join the Grid/cloud computing platform for a while, all of the related firewalls' filtering rule should be immediately updated. As the platform of Internet application is gradually evolving into the Grid/Cloud environment, the R&D requirement for the dynamic traversing of the multiple firewalls by a single try is also increasing. In this paper, we introduce the new mechanism for the dynamic traversing of the multiple firewalls using the concept of the one-time master key that can dynamically unlock the tiers of firewalls simultaneously instead of the existed filtering rule based method like a lock management at each firewall. The proposed master keys are like one-time password, consisted of IP addresses, port numbers, and TCP's initial sequence numbers, and generated by end users not administrators. They're exchanged mutually in advance and used to make a hole at local-side firewalls for the other's packet incoming. Therefore, the proposed mechanism can function regardless of the number or type of firewalls.

  • PDF

Design and Implementation of a Network Packet Scanner based on Multi-Platform (멀티 플랫폼 기반의 네트워크 패킷 스캐너 설계 및 구현)

  • Lee, Woo-In;Yang, Hae-Sool
    • The Journal of the Korea Contents Association
    • /
    • v.10 no.3
    • /
    • pp.101-112
    • /
    • 2010
  • The recent trend of the hacking deals with all the IT infrastructure related to the profit of the companies. Presently, they attack the service itself, the source of the profit, while they tried to access to the service infrastructure through the non-service port in the past. Although they affect the service directly, it is difficult to block them with the old security solution or the old system and they threaten more and more companies with the demand of money menacing the protection of customers and the sustainable management. This paper aims to design and implement multi-platform network packet scanner targeting the exception handling network intrusion detection system which determines normal, abnormal by traffic. Linux and unix have the various network intrusion detection and packet management tools like ngrep, snort, TCPdump, but most of them are based on CUI (Character based User Interface) giving users discomfort who are not used to it. The proposed system is implemented based on GUI(Graphical User Interface) to support the intuitive and easy-to-use interface to users, and using Qt(c++) language that supports multi-platform to run on any operating system.

A Study on the IUU Governance System of Regional Fishery Management Organization and Major State (국제 지역 수산 관리 기구와 주요 국가의 IUU 통제제도 연구)

  • Park, Min-Gyu
    • The Journal of Fisheries Business Administration
    • /
    • v.41 no.3
    • /
    • pp.103-127
    • /
    • 2010
  • The FAO reports that IUU fishing activities have widespread economic, social, and management consequences, including depriving legitimate fishers of harvest opportunities. It affects all fisheries from small scale to industrial. It also affects the ability of governments to support sustainable livelihoods for fishers and, more broadly, to achieve food security. The complexity of IUU requires various measures to combat IUU fishing such as adoption of IUU vessel lists; stronger port State controls; improved monitoring, control and surveillance (MCS); implementation of market-related measures to help ensure compliance; and capacity-building assistance. Trade and market measures reduce opportunities for IUU fishing activities by precluding or impeding access to markets for IUU product in a manner consistent with international law. ICCAT, CCAMLR, and IATTC, have put in place trade tracking programs or catch documentation schemes, and WCPFC is considering such a program. Vessel lists assist enforcement authorities in determining which vessels are or are not authorized to be fishing or conducting fishing support activities in specified areas. A number of RFMOs maintain records of IUU vessels: CCAMLR, IATTC, ICCAT, NAFO, NASCO, NPAFC, WCPFC. Section 608 of the US MSRA calling on the Secretary of Commerce, in consultation with the Secretary of State, and in cooperation with relevant regional fishery management councils and any relevant advisory committees, to take actions to improve the effectiveness of international fishery management organizations in conserving and managing stocks under their jurisdiction. EU IUU Regulation entered into force on 1 January 2010, was intended to regulate the highly complex multi-channel fisheries supply system of the European Community (EC) in an effort to improve global fisheries sustainability.

논제 부정 Access에 대한 Firewall의 과제와 대책

  • 변성준;서정석;최원석
    • Proceedings of the Korea Database Society Conference
    • /
    • 2000.11a
    • /
    • pp.227-238
    • /
    • 2000
  • Firewall은 다양한 부정Access의 방지책으로서 확실히 유효한 수단이지만 이 Firewall은 사용자로부터 지시된 설정을 충실히 실행하는 것으로 설정 오류, 소프트웨어의 정지, 허가된 룰을 악용한 침입 등 반드시 사용자가 바라는 작용을 무조건적 상태에서 보증해 주는 것은 아니다. 따라서 사용자는 도입 후 에도 운용시에 Access log를 감시하고 본래의 Security Policy에 반하는 행위를 매일 매일 체크하지 않으면 안될 상황에 처해 있다. 본 연구는 이러한 부정Access에 대한 이와 같은 Firewall의 현상에 대한 과제 중에서 "부정Access를 어떻게 하면 일찍, 정확히 체크할 수 있는가\ulcorner"라는 주제를 선택하여 Firewall의 한계와 그 대응책을 실제로 부정Access를 시험해 보는 것으로 검증하기로 하였다. 실험결과에서 (1)Port Scan이나 전자메일 폭탄(서비스정지공격)등은 Firewall로 방지하는 것은 불가능하거나 혹은 Checking이 곤란하다. (2)공격마다 로그 수집을 했음에도 관계없이 Firewall의 로그는 번잡하므로 단시간에 사태의 발견이 대단히 곤란하다고 하는 Firewall의 한계를 인식하였다. 그리고 그 대책으로서 우리는 체크 툴의 유효성에 착안하여 조사한 결과, 결국 무엇이 부정Access인가에 대해서는 어디까지나 이용하는 측이 판단하여 Firewall 상에 설정하지 않으면 안되지만 체크 툴은 이 부정Access 정보를 데이터베이스로서 갖고 있음으로써 '무엇이 부정Access인가'를 이용자 대신에 판단하고 툴에 따라서는 설정을 자동적으로 변경하여 부정 Access의 저지율을 향상시킨다. 이처럼 체크 툴은 Firewall의 수비능력을 보강하는 위치에 있다고 생각할 수 있다.다. 4 장에서는 3장에서 제기한 각각의 문제점에 대해 RAD 의 관점에 비추어 e-business 시스템의 단기개발을 실현하기 위한 고려사항이나 조건 해결책을 제안한다. 본 논문이 지금부터 e-business 를 시작하려고 하는 분, e-business 시스템의 개발을 시작하려고 하는 분께 단기간의 e-business 실현을 위한 하나의 지침이 된다면 다행이겠다.formable template is used to optimize the matching. Then, clustering the similar shapes by the distance between each centroid, papaya can be completely detected from the background.uage ("Association of research for algorithm of calculating machine (1992)"). As a result, conventional NN and CNN were available for interpolation of sampling data. Moreover, when nonlinear intensity is not so large under the field condition of small slope, interpolation performance of CNN was a little not so better than NN. However, when nonlinear intensity is large under the field condition of large slope, interpolation performance of CNN was relatively better than NN.콩과 자연 콩이 성분 분석에서 차이를

  • PDF

A Study on Hacking Attack of Wire and Wireless Voice over Internet Protocol Terminals (유무선 인터넷전화 단말에 대한 해킹 공격 연구)

  • Kwon, Se-Hwan;Park, Dea-Woo
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2011.10a
    • /
    • pp.299-302
    • /
    • 2011
  • Recently, Voice over Internet protocol(VoIP) in IP-based wired and wireless voice, as well as by providing multimedia information transfer. Wired and wireless VoIP is easy on illegal eavesdropping of phone calls and VoIP call control signals on the network. In addition, service misuse attacks, denial of service attacks can be targeted as compared to traditional landline phones, there are several security vulnerabilities. In this paper, VoIP equipment in order to obtain information on the IP Phone is scanning. And check the password of IP Phone, and log in successful from the administrator's page. Then after reaching the page VoIP IP Phone Administrator Settings screen, phone number, port number, certification number, is changed. In addition, IP Phones that are registered in the administrator page of the call records check and personal information is the study of hacking.

  • PDF

Analysis and Design of IP Traceback for Intrusion Response (침입대응을 위한 IP 역추적 시스템 분석 및 설계)

  • 이성현;이원구;이재광
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2004.05b
    • /
    • pp.412-415
    • /
    • 2004
  • As computers and networks become popular, corporation or country organization composes security network including various kinds information protection system to protect informations and resources from internet and is operating system and network. But current firewall and IDS(Intrusion Detection System) of the network level suffers from many vulnerabilities in internal computing informations and resources. In this paper, we design of ICMP-based Traceback System using a ICMP Traceback Message for efficiently traceback without change structure of routers. ICMP-based Traceback System. Create of ICMP message is managed by “Traceback Agent” mirroring port for router. Victim's systems that are received the message store it and “Traceback Manager” is detect a attack(like a DDoS). Using a information of this message starting a traceback and detecting a source of attacker, so response a attack.

  • PDF

Study on Equivalent Consumption Minimization Strategy Application in PTI-PTO Mode of Diesel-Electric Hybrid Propulsion System for Ships

  • Lee, Dae-Hong;Kim, Jong-Su;Yoon, Kyoung-Kuk;Hur, Jae-Jung
    • Journal of the Korean Society of Marine Environment & Safety
    • /
    • v.28 no.3
    • /
    • pp.451-458
    • /
    • 2022
  • In Korea, five major ports have been designated as sulfur oxide emission control areas to reduce air pollutant emissions, in accordance with Article 10 of the "Special Act on Port Air Quality" and Article 32 of the "Ship Pollution Prevention Regulations". As regulations against vessel-originated air pollutants (such as PM, CO2, NOx, and SOx) have been strengthened, the Ministry of Oceans and Fisheries(MOF) enacted rules that newly built public ships should adopt eco-friendly propulsion systems. However, particularly in diesel-electric hybrid propulsion systems,the demand for precise control schemes continues to grow as the fuel saving rate significantly varies depending on the control strategy applied. The conventional Power Take In-Power Take Off(PTI - PTO) mode control adopts a rule-based strategy, but this strategy is applied only in the low-load range and PTI mode; thus, an additional method is required to determine the optimal fuel consumption point. The proposed control method is designed to optimize fuel consumption by applying the equivalent consumption minimization strategy(ECMS) to the PTI - PTO mode by considering the characteristics of the specific fuel oil consumption(SFOC) of the engine in a diesel-electric hybrid propulsion system. To apply this method, a specific fishing vessel model operating on the Korean coast was selected to simulate the load operation environment of the ship. In this study, a 10.2% reduction was achieved in the MATLAB/SimDrive and SimElectric simulation by comparing the fuel consumption and CO2 emissions of the ship to which the conventional rule-based strategy was applied and that to which the ECMS was applied.

A Study on the Sailing Speed of Ancient Ships - especially on the average speed and the effect of the wind, the tide, and the man-power at the oar - (고대 선박의 항해속도 연구 - $\ll$고려도경$\gg$을 중심으로-)

  • Yoon, Il-Young
    • Journal of National Security and Military Science
    • /
    • s.7
    • /
    • pp.155-231
    • /
    • 2009
  • Xu-Jing(徐競) an official of the Song(宋), a medieval Kingdom of China, wrote a book titled $\ll$Koryo Tu Jing(高麗圖經)$\gg$ which explains his travel to the Koryo as a member of diplomatic mission in 1123. $\ll$Koryo Tu Jing$\gg$ is the record of his personal experience in Koryo with many explanatory illustrations and especially contains 5 months' voyage record of his diplomatic fleet. His fleet set sail at a port located in the Ding Hai Xian(定海縣), Ming Zhou(明州) via a few islands of Koryo [Hyup Kye San(俠界山) , the Kun San Do(群山島) , the Ja Yon Do(紫燕島) , the Keup Su Mun(急水門) in Kang Hwa Gun(江華郡) and the Hap Gul(蛤窟) ] and finally arrived the Port Ye Song Hang(禮成港) . According to the Xu-Jing's record his fleet sailed the sea with the help of the favorable seaward winds and tides as the usual way of ancient sailing. The Xu- Jing's Fleet sailed the sea between the Mei Cen(梅岑), Ming Zhou(明州) of China and the Hyup Kye San(俠界山) of Koryo from about 5:00 a.m., May 24th(of the lunar calendar) to about 5:00 p.m., June 2nd. At this section, the average speed of the seaward winds was 19.45km/h and the average speed of the fleet which sailed only by the power of the winds was 6.29km/h. This means that 32.3% of the favorable seaward winds' speed was equal to the speed of the ancient fleet which sailed only by the power of the favorable seaward winds. The fleet sailed the sea between the Ja Yon Do(紫燕島) and the Keup Su Mun(急水門) from about 9:00 a.m., June 10th to about 1:00 p.m., the same day. At this section the fleet sailed by the power of tides in addition to the favorable seaward winds without oaring. The average speed of the winds was not different from that of former section and the average speed of the tides was 1.937km/h. And at this section the average speed of the fleet increased by 0.41km/h than that of the former section. This means that 21.1% of the speed of the tides was equal to the increased speed of the ancient fleet by virtue of the tides. The fleet sailed the sea between Keup Su Mun(急水門) and the Hap Gul(蛤窟) from about 1:00 p.m., June 10th to about 3:00 p.m., the same day. At this section, there were no seaward winds and the fleet sailed only by the powers of tides and oaring. And at this section, the tide increased the average speed of the fleet by 0.3114km/h and the fleet could sail at the speed of 4.3km/h. So we can conclude that the average speed of ancient fleet without any influences of the seaward winds and tides was 3.98 km/h. We can make use of the various sailing speeds of ancient fleets when judging their maritime activities. If we make use of the various sailing speeds of the ancient fleets as calculated in this article, we will be able to get various important informations about the certain ancient fleet's maritime maneuver. For example, we can infer the sailing routs of a certain fleet and the time when the fleet passed a certain spot by making use of the various sailing speeds of the ancient fleet. In this article I did not take account of the shapes of ships that consist of the ancient fleets and the sizes of the various ships and fleets. It was because that such factors would not change the foresaid conclusions seriously.

  • PDF

A Study on Methods of the use of Coastal Station for the Analysis of Marine Contamination - Focusing on Busan Coastal Sea Area - (해양오염도 분석을 위한 연안 정점 데이터의 활용방안에 관한 연구 - 부산연안해역을 중심으로 -)

  • Hwang, Jin-Wook;Kim, Ho-Yong;Lee, Sung-Ho
    • Journal of the Korean Association of Geographic Information Studies
    • /
    • v.9 no.4
    • /
    • pp.71-80
    • /
    • 2006
  • The land area, which is on the inner side of the water line, is controlled to a certain degree due to the purposes of space utilities controllers' respective roles, but the sea area is not so much controlled as the land area. However, as interest in the security and utility of the marine space, as well as that in the consistent development of the land space, has increased, there has been increase of the requirement for information about marine data and environment. The object of this study, Busan, plays various roles such as a harbor and bay, a tourist resort, and a port unlike coastal seas of other areas, and thus needs systematic control because it has numerous environmental factors. However, there are limitations in the number of data about Busan coastal sea constantly provided while the acquisition of data from main points and many areas is important for the analysis of marine contamination in Busan coastal sea area. Thus, using nautical charts with numerical values in preparing increase of the demand of them according to the degree of information requirement for the analysis of the changes in coastal areas, this study constructs property data and space data by combining vertex data about Busan's 17 coastal sea areas provided by NFRDI, and tries to present the analytical techniques for grasping the environmental conditions and continuity of the coastal areas and methods of their utilities, using GIS Geostatistical Analysis Technique.

  • PDF

Performance Evaluation Plan of Maritime VHF Digital Communications System (해상용 VHF 디지털통신 시스템의 성능평가 방안)

  • Ju, Yang-Ro;Kim, Kab-Ki;Choi, Jo-Cheon;Lee, Seong Ro
    • The Journal of Korean Institute of Communications and Information Sciences
    • /
    • v.39C no.7
    • /
    • pp.582-588
    • /
    • 2014
  • IMO and IALA have undertaken projects that GMDSS Modernization and E-navigation, which refer to "Future digital communications systems" for a more efficient transmission of voice and data communications in the VHF maritime mobile service. ITU has also resolved in WRC-07 Resolution 357 to study the use of spectrum-efficient technologies in order to provide for the operation of ship and port security and maritime safety systems. IALA and ITU WP5B have coordinated for the technical developments and the spectrum issues. Recommendation ITU-R M.1842-1 has approved by WP5B meeting. This revision provides a wideband data service both 50kHz and 100kHz in the VHF maritime mobile service. This paper has studied E-navigation, its needs for data exchange that includes explanations of the current methods for transmitting data by VHF that based in land mobile radio service. A further technologies trend is estimated for Recommendation ITU-R M.1842-1, that is based on the land mobile radio standards with some tailored to fit the needs of the maritime mobile service.