• 제목/요약/키워드: Sandbox

검색결과 65건 처리시간 0.021초

모바일 앱 최소권한 사전검증에 관한 연구 - 금융, 안드로이드 운영체제 중심으로 - (A Study of Security Checks for Android Least Privilege - focusing on mobile financial services -)

  • 조병철;최진영
    • 인터넷정보학회논문지
    • /
    • 제17권1호
    • /
    • pp.91-99
    • /
    • 2016
  • 안드로이드 운영체제의 보안체계는 샌드박스와 권한모델을 적용하고 있다. 특히 권한모델은 설치시점 확인과 all-or-nothing 정책을 운영하고 있기 때문에 안드로이드는 앱을 설치할 때 필요한 권한에 대해 사용자 동의를 요구하고 있다. 하지만 안드로이드 권한에 대한 사용자의 인식은 부족한 상황이다. 따라서 본 논문에서는 실제 모바일 앱을 대상으로 권한요구 실태를 조사하고 금융회사를 중심으로 모바일 서비스 제공자가 모바일 앱의 최소권한 정책에 위배되는 사항을 자체점검하고자 할 때 활용가능한 중점 점검항목과 방법을 제시하고 그 유용성에 대해 알아보고자 한다.

선택적 함묵증 여아의 모래놀이치료 사례연구 (A Case Study on Sandplay Therapy for a Girl Suffering from Selective Mutism)

  • 심희옥
    • 아동학회지
    • /
    • 제33권1호
    • /
    • pp.41-62
    • /
    • 2012
  • This study explored the case of sandplay therapy for a 4th grade girl suffering from selective mutism. Her selective mutism apparently began following an extremely embarrassing experience in kindergarten. Her symptoms were a combination of symbiotic, reactive and passive- aggressive type behaviors. The goal of the therapy undertaken with this child was to enable her to express her repression and suppression, within a free and protective space during sandplay therapy. There were a total of 60 sessions of sandplay therapy. The client described the situations she had experienced in the first sandtray, by placing babies absent caring adults and food on the sandbox. She also placed baby fish away from their mother. In the mid-point of the sessions, she repeated her regressive behaviors by babbling like a baby and fought with snakes and monsters. In the final sessions, she showed integration and adaptation by engaging in snow play, expressing the union of opposites, placing blue and red mig and making a cross on the sand. This study showed the effectiveness of sandplay therapy since her selective mutism was lessened.

Supplementary Event-Listener Injection Attack in Smart Phones

  • Hidhaya, S. Fouzul;Geetha, Angelina;Kumar, B. Nandha;Sravanth, Loganathan Venkat;Habeeb, A.
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제9권10호
    • /
    • pp.4191-4203
    • /
    • 2015
  • WebView is a vital component in smartphone platforms like Android, Windows and iOS that enables smartphone applications (apps) to embed a simple yet powerful web browser inside them. WebView not only provides the same functionalities as web browser, it, more importantly, enables a rich interaction between apps and webpages loaded inside the WebView. However, the design and the features of WebView lays path to tamper the sandbox protection mechanism implemented by browsers. As a consequence, malicious attacks can be launched either against the apps or by the apps through the exploitation of WebView APIs. This paper presents a critical attack called Supplementary Event-Listener Injection (SEI) attack which adds auxiliary event listeners, for executing malicious activities, on the HTML elements in the webpage loaded by the WebView via JavaScript Injection. This paper also proposes an automated static analysis system for analyzing WebView embedded apps to classify the kind of vulnerability possessed by them and a solution for the mitigation of the attack.

Recent Advances in Cryptovirology: State-of-the-Art Crypto Mining and Crypto Ransomware Attacks

  • Zimba, Aaron;Wang, Zhaoshun;Chen, Hongsong;Mulenga, Mwenge
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제13권6호
    • /
    • pp.3258-3279
    • /
    • 2019
  • Recently, ransomware has earned itself an infamous reputation as a force to reckon with in the cybercrime landscape. However, cybercriminals are adopting other unconventional means to seamlessly attain proceeds of cybercrime with little effort. Cybercriminals are now acquiring cryptocurrencies directly from benign Internet users without the need to extort a ransom from them, as is the case with ransomware. This paper investigates advances in the cryptovirology landscape by examining the state-of-the-art cryptoviral attacks. In our approach, we perform digital autopsy on the malware's source code and execute the different malware variants in a contained sandbox to deduce static and dynamic properties respectively. We examine three cryptoviral attack structures: browser-based crypto mining, memory resident crypto mining and cryptoviral extortion. These attack structures leave a trail of digital forensics evidence when the malware interacts with the file system and generates noise in form of network traffic when communicating with the C2 servers and crypto mining pools. The digital forensics evidence, which essentially are IOCs include network artifacts such as C2 server domains, IPs and cryptographic hash values of the downloaded files apart from the malware hash values. Such evidence can be used as seed into intrusion detection systems for mitigation purposes.

수소관련 규제특례사업 안전관리강화 방안 마련을 통한 안전성 제고 (Improving Safety by Preparing Measures to Strengthen Safety Management for Special Hydrogen-Related Regulatory Projects)

  • 김도현;한주연;탁송수;조호연
    • 한국가스학회지
    • /
    • 제25권6호
    • /
    • pp.106-110
    • /
    • 2021
  • 수소관련 신기술 및 신사업의 등장으로 액화수소 제조(충전), 액화수소 저장탱크 및 용기 제조 등 관련 분야에 대한 제도 정비 필요성이 확대되었고, 이를 실증하기 위한 규제특례(규제자유특구 및 규제샌드박스)제도가 도입됨에 따라 특례 신청이 지속적으로 증가하는 추세에 있다. 이에, 수소 관련 규제특례사업 지정현황을 파악하고 최소한의 안전성을 확보하기 위한 안전 관리 강화 방안을 수립하여 시행하고자 한다.

Development FintechEcosystem: Evidence of European Countries for Ukraine

  • Fedyshyn, Maiia;Abramova, Alla;Morozova, Liudmyla;Lavrov, Ruslan;Kovalova, Olena;Malin, Oleksandr
    • International Journal of Computer Science & Network Security
    • /
    • 제22권2호
    • /
    • pp.29-38
    • /
    • 2022
  • The growth of digitalization processes around the world, covering almost all areas of human life, including the Fintech sector. In the field of financial technology, radical changes are taking place with increasing levels of automation, openness and consumer focus. In addition, in the context of the spread of coronavirus infection, quarantine and forced isolation, the role of digital technology is coming to the fore worldwide, including in Ukraine. The purpose of the article is to assess the development of Fintech ecosystem of European countries and outline the strategic parameters of domestic Fintech development. The study concluded that the investment raised for the Fintech industry increases annually and the quality and size of transactions gradually increases. Today, Fintech maintains its position as one of the most attractive markets for venture capitalists and the image of an industry with high potential, especially in the era of open banking. The most attractive markets for investors are mature markets, such as the United States, Germany and the United Kingdom, and the preferred niches for investment - the vertical of payments and lending. Trends in investment activity in terms of investing in financial technologies are studied. Moreover, investors prefer businesses that already have a significant scale or considerable potential to achieve it and become sustainable businesses.

메타버스 플랫폼을 활용한 민화 미술관 기획 연구 -제페토 사례를 중심으로- (A Study on the Planning of Minhwa Museum Utilizing the Metaverse Platform : Focusing on Zepeto Case)

  • 최은진;이영숙
    • 한국게임학회 논문지
    • /
    • 제21권6호
    • /
    • pp.63-74
    • /
    • 2021
  • 메타버스는 스마트폰을 상시 휴대하는 MZ세대의 생활 패턴과 자신의 정체성을 중요시하는 성향에 잘 맞는 가상공간이다. 이 연구는 한국의 전통문화 예술인 민화를 메타버스 플랫폼인 제페토에서 미술관으로 개발하는 기획 모델을 제안한다. 이를 위해 메타버스 플랫폼의 특징인 오픈월드, 샌드박스, 크리에이터 이코노미, 아바타에 대해 분석하고, 이를 제페토에 민화 미술관을 개장하는 기획 아이템으로 발전시킨다. 한국 전통예술을 현대적으로 재해석하면서, MZ세대의 뉴트로 감성에 맞는 메타버스 기획 개발 모델로서의 연구 가치가 있다.

Effects of Furnished Cage Type on Behavior and Welfare of Laying Hens

  • Li, Xiang;Chen, Donghua;Li, Jianhong;Bao, Jun
    • Asian-Australasian Journal of Animal Sciences
    • /
    • 제29권6호
    • /
    • pp.887-894
    • /
    • 2016
  • This study was conducted to compare the effects of layout of furniture (a perch, nest, and sandbox) in cages on behavior and welfare of hens. Two hundred and sixteen Hyline Brown laying hens were divided into five groups (treatments) with four replicates per group: small furnished cages (SFC), medium furnished cages type I (MFC-I), medium furnished cages type II (MFC-II), and medium furnished cages type III (MFC-III) and conventional cages (CC). The experiment started at 18 week of age and finished at 52 week of age. Hens' behaviors were filmed during the following periods: 8:00 to 10:00; 13:00 to 14:00; 16:00 to 17:00 on three separate days and two hens from each cage were measured for welfare parameters at 50 wk of age. The results showed that feeding and laying of all hens showed no effect by cage type (p>0.05), and the hens in the furnished cages had significantly lower standing and higher walking than CC hens (p<0.05). The birds in MFC-III had significant higher preening, scratching and feather-pecking behavior than in the other cages (p<0.05). No difference in nesting behavior was found in the hens between the furnished cages (p>0.05). The hens in MFC-I, -II, and -III showed a significant higher socializing behavior than SFC and CC (p<0.05). The lowest perching was for the hens in SFC and the highest perching found for the hens in MFC-III. Overall, the hens in CC showed poorer welfare conditions than the furnished cages, in which the feather condition score, gait score and tonic immobility duration of the hens in CC was significantly higher than SFC, MFC-I, MFC-II, and MFC-III (p<0.05). In conclusion, the furnished cage design affected both behavior and welfare states of hens. Overall, MFC-III cage design was better than SFC, MFC-I, and MFC-II cage designs.

제4차 산업혁명 대응 전략: 일본의 사례와 시사점 (Fourth Industrial Revolution Strategy: Japan's Case and Implications)

  • 김방룡
    • 한국정보통신학회논문지
    • /
    • 제22권2호
    • /
    • pp.314-322
    • /
    • 2018
  • 일본은 다가올 제4차 산업혁명 시대에 선제적으로 대응하기 위해 전략적이면서도 구체적인 계획을 수립하였다. 일본의 제4차 산업혁명 대응 전략은 강점 활용 전략과 약점 보완 전략의 두 가지로 나누어지는데, 전자에 속하는 것이 '현실 데이터 활용' 및 '신 로봇 개발'이며, 후자에 속하는 것이 '글로벌 이슈 해결'이다. 특히 일본 정부는 제4차 산업혁명의 지향점이라 할 수 있는 Society 5.0 실현을 위한 사회 실증 제도로 일본판 '규제 샌드 박스' 제도 도입과 관련하여 다른 어떤 국가들보다 적극적 입장을 취하고 있다. 본 연구에서는 제4차 산업혁명 관련 주요 문건들에서 제시하는 주요 전략을 고찰하고, 이 고찰을 토대로 한국이 제4차 산업혁명 대응전략을 수립할 때 참고할 만한 시사점들을 제시한다.

모래상자 수리모형실험을 통한 경계면 모델의 관정 염도 모의실험 (Applicability of a Sharp-Interface Model in Simulating Saltwater Contents of a Pumping Well in Coastal Areas)

  • 시뢰;최뢰;이찬종;홍성훈;박남식
    • 지질공학
    • /
    • 제19권1호
    • /
    • pp.9-14
    • /
    • 2009
  • 본 연구에서는 해안지역 대수층에서 담수와 해수의 흐름을 개략적으로 모의하는 경계면(sharp-interface)모델이 관정규모의 지하수 흐름 문제에도 적용될 수 있는 지 조사하였다. 해안 지역에서 지하수를 개발할 때 고려해야하는 중요한 인자 중의 하나는 해수침투이다. 관정규모의 지하수흐름 문제에서 해수침투 여부를 평가하기 위해서는 양수관정의 염분도를 모의할 수 있어야한다. 경계면 모델의 양수관정 염도 모의 능력을 검증하기 위하여 소규모 모래상자 수리모형실험을 수행하고 경계면모델의 모의능력을 평가하였다. 여러 가지 실험에서 측정된 관정의 염분도는 0%에서 12%의 범위를 보였으며 모의된 염분도는 측정치를 잘 나타내었다.