• Title/Summary/Keyword: RiskBased Testing

Search Result 246, Processing Time 0.022 seconds

A Method of Risk Assessment for Multi-Factor Authentication

  • Kim, Jae-Jung;Hong, Seng-Phil
    • Journal of Information Processing Systems
    • /
    • v.7 no.1
    • /
    • pp.187-198
    • /
    • 2011
  • User authentication refers to user identification based on something a user knows, something a user has, something a user is or something the user does; it can also take place based on a combination of two or more of such factors. With the increasingly diverse risks in online environments, user authentication methods are also becoming more diversified. This research analyzes user authentication methods being used in various online environments, such as web portals, electronic transactions, financial services and e-government, to identify the characteristics and issues of such authentication methods in order to present a user authentication level system model suitable for different online services. The results of our method are confirmed through a risk assessment and we verify its safety using the testing method presented in OWASP and NIST SP800-63.

A Study of Hazard Analysis and Monitoring Concepts of Autonomous Vehicles Based on V2V Communication System at Non-signalized Intersections (비신호 교차로 상황에서 V2V 기반 자율주행차의 위험성 분석 및 모니터링 컨셉 연구)

  • Baek, Yun-soek;Shin, Seong-geun;Ahn, Dae-ryong;Lee, Hyuck-kee;Moon, Byoung-joon;Kim, Sung-sub;Cho, Seong-woo
    • The Journal of The Korea Institute of Intelligent Transport Systems
    • /
    • v.19 no.6
    • /
    • pp.222-234
    • /
    • 2020
  • Autonomous vehicles are equipped with a wide rage of sensors such as GPS, RADAR, LIDAR, camera, IMU, etc. and are driven by recognizing and judging various transportation systems at intersections in the city. The accident ratio of the intersection of the autonomous vehicles is 88% of all accidents due to the limitation of prediction and judgment of an area outside the sensing distance. Not only research on non-signalized intersection collision avoidance strategies through V2V and V2I is underway, but also research on safe intersection driving in failure situations is underway, but verification and fragments through simple intersection scenarios Only typical V2V failures are presented. In this paper, we analyzed the architecture of the V2V module, analyzed the causal factors for each V2V module, and defined the failure mode. We presented intersection scenarios for various road conditions and traffic volumes. we used the ISO-26262 Part3 Process and performed HARA (Hazard Analysis and Risk Assessment) to analyze the risk of autonomous vehicle based on the simulation. We presented ASIL, which is the result of risk analysis, proposed a monitoring concept for each component of the V2V module, and presented monitoring coverage.

The First Korean Cancer Genetic Counseling Program for Nurses (국내 종양유전상담 간호사를 위한 단기 교육프로그램 개발)

  • Choi, Kyung-Sook;Anderson, Gwen;Jun, Myung-Hee
    • The Journal of Korean Academic Society of Nursing Education
    • /
    • v.12 no.1
    • /
    • pp.104-114
    • /
    • 2006
  • Genetic knowledge for oncology nurses is important in Korea because oncologists are incorporating genetic counseling and genetic testing into their practice. The purpose of this paper is to describe our method of developing the first academic cancer genetic risk assessment and counseling course for Korean nurses. A one-week (non-credit) cancer genetics counseling program was constructed for master's level Korean oncology nurses. The course emphasized basic genetic concepts and principles the genetics of cancer; hereditary cancer syndromes; family history assessments; pedigree construction; risk calculation; surveillance recommendations and treatment options ethical, legal, social, and psychological issues inherent in genetic testing. The goals of this program are to: 1) provide a comprehensive knowledge base for nurses who are currently expanding their scope of practice into the genetic counseling role 2) introduce this knowledge to nurses who want to use it in their practice; and 3) provide cancer genetic knowledge and resources to Korean nursing faculty who plan to incorporate this knowledge into existing master's courses. This academically-based course is recognized as valuable by nurses, nursing faculty, and physicians. With this new knowledge nurses can begin toexpand their role in delivering comprehensive cancer care services.

  • PDF

Flight Test Safety Risk Assessment and Mitigation (비행시험 안전 리스크 평가 및 완화 연구)

  • Kim, Mu-Geun;Yoo, Beong-Seon;Han, Jeongho;Kang, Ja-Young
    • Journal of Advanced Navigation Technology
    • /
    • v.22 no.6
    • /
    • pp.537-544
    • /
    • 2018
  • A national comprehensive aviation test center is being constructed for the purpose of flight tests for development and modification of aircraft or flight inspections for the development of navaids. Flight testing is a high-risk task, so strict risk management processes are required prior to operation. In addition, since the flight test center is subject to the airdrome regulations under the current law, the introduction of the safety management system will enhance safety as usual in ordinary airports. The establishment of a safety management system based on ICAO criteria is an optimal means of ensuring safe and effective operation of the test center and may mitigate the risks that may arise during flight testing. This paper focuses on risk assessment and mitigation required for safety management at the flight test center. We conducted risk assessments on the flight hazards identified in the previous study. Then the high risk group of hazards were selected and risk mitigation techniques such as avoidance, reduction, acceptance, and control were applied.

Lack of Association of Common Polymorphisms in MUC1 Gene with H. pylori Infection and Non-cardia Gastric Cancer Risk in a Chinese Population

  • Zhang, Bin;Hao, Guang-Yu;Gao, Fang;Zhang, Jian-Zu;Zhou, Cheng-Jiang;Zhou, Li-She;Wang, Ying;Jia, Yan-Bin
    • Asian Pacific Journal of Cancer Prevention
    • /
    • v.14 no.12
    • /
    • pp.7355-7358
    • /
    • 2013
  • Several lines of evidence support the notion that MUC1 is often aberrantly expressed in gastric cancer, and it is a ligand for Helicobacter pylori. Genetic variation in MUC1 gene may confer susceptibility to H. pylori infection and gastric cancer. We assessed the association of common polymorphisms in MUC1 gene with H. pylori infection and non-cardia gastric cancer using an LD-based tag SNP approach in north-western Chinese Han population. A total of four SNPs were successfully genotyped among 288 patients with non-cardia gastric cancer and 281 age- and sex-matched controls. None of the tested SNPs was associated with H. pylori infection. SNP rs9426886 was associated with a decreased risk of non-cardia gastric cancer, but lost significance after adjustment for multiple testing. Overall, our data indicated that common genetic variations in MUC1 gene might not make a major contribution to the risk of H. pylori infection and non-cardia gastric cancer in our studied population.

A Multi-level Approach to Perceived Risks of Medical Tourism Service and Purchase Intention: An Empirical Study from Korea

  • KIM, Minsook
    • The Journal of Asian Finance, Economics and Business
    • /
    • v.9 no.1
    • /
    • pp.373-385
    • /
    • 2022
  • Due to the lack of information, medical tourists are regarded to be at high risk. Prior medical tourism research has found that various types of perceived risks have a significant impact on medical tourists' purchase behavior. Even though medical tourism is predicted to increase, there is a lack of behavioral research to explain how perceived risks affect medical tourists' purchase behavior. In the context of Korean medical tourism, this study attempts to evaluate the effects of multi-level (macro, organizational, and personal) factors on medical tourists' perceived risks and purchase intentions. A conceptual model and hypotheses were built and empirically validated to investigate links between multi-level characteristics, perceived risks, and purchasing intentions. The data for this study was collected from Chinese tourists using a questionnaire. The impact of cognitive country image, affective country image, and medical service quality on fundamental risk is confirmed by statistical testing. Surprisingly, expectancy discrepancy risk is influenced only by cognitive country image and information search capabilities. Both fundamental and expectation discrepancy risks lower medical tourists' purchase intentions. The findings of this study show that a multi-level strategy is required to investigate the links between perceived risks and medical tourism purchasing intentions based on macro, organizational, and personal factors.

The Effects of Technological and International Marketing Capability of SMEs in Gwangju·Jeonnam Province on Export Performance: Focusing on the Moderating Role of CEO's Risk-taking Propensity (광주·전남지역 중소기업의 기술역량과 국제마케팅역량이 수출성과에 미치는 영향: CEO 위험감수성의 조절효과를 중심으로)

  • Young-Soo Yang;Jae-Eun Lee
    • Korea Trade Review
    • /
    • v.45 no.5
    • /
    • pp.261-277
    • /
    • 2020
  • The purpose of this study is to analyze whether SMEs' technological capabilities and international marketing capabilities affect the export performance of the SMEs and to empirically test the moderating effect of the CEO's risk propensity on such a relationship. We obtained data from 190 SMEs located in Gwangju and Jeonnam Province in Korea through survey and performed a regression analysis for hypothesis testing based on these data. As a result of the analysis, it was found that SMEs' technological capabilities and international marketing capabilities had a significantly positive (+) effect on export performance, respectively. Also, the CEO's risk propensity was found to reinforce the relationship between technical competence and export performance, and the relationship between marketing capabilities and export performance was also found to be strengthened in the positive (+) direction. These results suggest that it is necessary for SMEs to continuously develop technological capabilities and international marketing capabilities to achieve successful export performance in overseas markets. Also, the CEO's propensity to promote these relationships may be important.

Ecotoxicological Effects of NaDCC injection method in Ballast Water Management system on Marine Environments (NaDCC 주입 선박평형수 처리기술의 해양생태위해성에 대한 연구)

  • Kim, Tae won;Moon, Chang Ho;Kim, Young Ryun;Son, Min Ho
    • Proceedings of KOSOMES biannual meeting
    • /
    • 2017.11a
    • /
    • pp.236-236
    • /
    • 2017
  • Effluent treated by an NaDCC injection method in Ballast water management system (BWMS) contains reactive chlorine species and disinfection by-products (DBPs). In this study, we conducted whole effluent toxicity (WET) testing and ecological risk assessment (ERA) to investigate its ecotoxicological effects on marine environment. WET testing was carried out for four marine pelagic and freshwater organisms, i.e., diatom Skeletonema costatum, Navicula pellicuosa, chlorophyta Dunaliella tertiolecta, Pseudokirchneriella subcapitata, rotifer Brachionus plicatilis, Brachionus calyciflorus and fish Cyprinodon variegatus, Pimephales promelas. The biological toxicity test revealed that algae was the only biota that showed apparent toxicity to the effluent; it showed no observed effect concentration (NOEC), lowest observable effect concentration (LOEC) and effect concentration of 50% (EC50) values of 25-50%, 50-100% and >100%, respectively, at three water condition, but did not show any significant toxicities on other biota. Meanwhile, chemical analysis revealed that the BWMS effluent contained total residual oxidants (TROs) below $0.03{\mu}g/L$ and a total of 25 DBPs such as bromate, volatile halogenated organic compounds (VOCs), halogenated acetonitriles (HANs), halogenated acetic acids (HAAs), chloropicrin and Isocyanuric acid. Based on ERA, the 25 DBPs were not considered to have persistency, bioaccumulation and toxicity (PBT) properties. The ratio of predicted environmental concentration (PEC) to predicted no effect concentration (PNEC) of the other DBPs did not exceed 1 for General harbor environment. However, four substances (Isocyanuric acid, Tribromomethane, Chloropicrin and Monochloroacetic acid) were exceed 1 for Nearship environment. But observed toxicity in the test water on algal growth inhibition would be mitigated by normal dilution factor of 5 applied for nearship exposure. Thus, our results of WET testing and ERA showed that the BWMS effluent treated by NaDCC injection method would have no adverse impacts on marine environment.

  • PDF

Minimize Web Applications Vulnerabilities through the Early Detection of CRLF Injection

  • Md. Mijanur Rahman;Md. Asibul Hasan
    • International Journal of Computer Science & Network Security
    • /
    • v.23 no.2
    • /
    • pp.199-202
    • /
    • 2023
  • Carriage return (CR) and line feed (LF), also known as CRLF injection is a type of vulnerability that allows a hacker to enter special characters into a web application, altering its operation or confusing the administrator. Log poisoning and HTTP response splitting are two prominent harmful uses of this technique. Additionally, CRLF injection can be used by an attacker to exploit other vulnerabilities, such as cross-site scripting (XSS). Email injection, also known as email header injection, is another way that can be used to modify the behavior of emails. The Open Web Application Security Project (OWASP) is an organization that studies vulnerabilities and ranks them based on their level of risk. According to OWASP, CRLF vulnerabilities are among the top 10 vulnerabilities and are a type of injection attack. Automated testing can help to quickly identify CRLF vulnerabilities, and is particularly useful for companies to test their applications before releasing them. However, CRLF vulnerabilities can also lead to the discovery of other high-risk vulnerabilities, and it fosters a better approach to mitigate CRLF vulnerabilities in the early stage and help secure applications against known vulnerabilities. Although there has been a significant amount of research on other types of injection attacks, such as Structure Query Language Injection (SQL Injection). There has been less research on CRLF vulnerabilities and how to detect them with automated testing. There is room for further research to be done on this subject matter in order to develop creative solutions to problems. It will also help to reduce false positive alerts by checking the header response of each request. Security automation is an important issue for companies trying to protect themselves against security threats. Automated alerts from security systems can provide a quicker and more accurate understanding of potential vulnerabilities and can help to reduce false positive alerts. Despite the extensive research on various types of vulnerabilities in web applications, CRLF vulnerabilities have only recently been included in the research. Utilizing automated testing as a recurring task can assist companies in receiving consistent updates about their systems and enhance their security.

Study on Relationship Quality and L-Loyalty in Location-Based Service (위치기반서비스에서 관계 품질과 L-로열티에 관한 연구)

  • Jang, Sung-Hee
    • The Journal of the Korea Contents Association
    • /
    • v.16 no.9
    • /
    • pp.1-11
    • /
    • 2016
  • The purpose of this study is to examine the factors influencing relationship quality and L-Loyalty in Location-Based Service (LBS). This model tests various theoretical research hypotheses relating to LBS, relationship quality, and L-Loyalty. The target population of this study is LBS users. The results of hypothesis testing are as follows. First, personalization and perceived value positively influence commitment and perceived risk negatively influence commitment. Second, personalization, ubiquity, and perceived value positively influence satisfaction and perceived risk negatively influence satisfaction. Finally, commitment and satisfaction positively influence L-Loyalty. The results of the study will provide various implications to improve relationship quality and to secure high loyalty customers in LBS.