• 제목/요약/키워드: Security

검색결과 26,024건 처리시간 0.039초

A Security Metrics Taxonomization Model for Software-Intensive Systems

  • Savola, Reijo M.
    • Journal of Information Processing Systems
    • /
    • 제5권4호
    • /
    • pp.197-206
    • /
    • 2009
  • We introduce a novel high-level security metrics objective taxonomization model for software- intensive systems. The model systematizes and organizes security metrics development activities. It focuses on the security level and security performance of technical systems while taking into account the alignment of metrics objectives with different business and other management goals. The model emphasizes the roles of security-enforcing mechanisms, the overall security quality of the system under investigation, and secure system lifecycle, project and business management. Security correctness, effectiveness and efficiency are seen as the fundamental measurement objectives, determining the directions for more detailed security metrics development. Integration of the proposed model with riskdriven security metrics development approaches is also discussed.

Enhanced Security Scheme to Support Secure and Fast ASN-anchored Mobility in Mobile WiMAX

  • Park, Chang-Seop;Kang, Hyun-Sun
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제5권11호
    • /
    • pp.2204-2220
    • /
    • 2011
  • Without providing a proper security measure to the handover procedure in Mobile WiMAX, several security attacks can be mounted. Even though security schemes have been previously proposed for this purpose, they are still vulnerable to several security attacks due to fatal design flaws. A newly proposed security scheme in this paper is based on the framework of authentication domain and concept of handover ticket. A method of establishing security associations within the authentication domain is proposed, and a lightweight security measure to protect the management messages associated with the handover is also proposed. Especially, using the handover ticket, the new security scheme can defend against a Redirection Attack arising from a compromised base station. The new security scheme is comparatively analyzed with the previous security schemes in terms of Replay, Session Hijacking, Man-In-The-Middle, and Redirection attacks.

Incoterms(R) 2010상 수출입 당사자의 보안관련 의무에 관한 연구 (A Study on the Security related Obligations of Contracting Party under the Incoterms(R) 2010 Rules)

  • 양정호
    • 무역상무연구
    • /
    • 제54권
    • /
    • pp.45-80
    • /
    • 2012
  • Since the 9.11 terror attack, the event which caused supply chain disruption, supply chain security has become more important than ever before. With this as a momentum, a customs supply chain security paradigm emerged intended to guarantee secure flow of cargo across boarder. Under this circumstances Incoterms(R) 2010 rules have allocated obligations between the buyer and seller to obtain or to render assistances in obtaining security clearances. Thus, security related obligations such as providing advance manifest information is the mandatory requirements for any export and import. The impact on the seller and buyer of security related obligations under the Incoterms(R) 2010 rules environment is obvious. Assistance to provide the security information in advance has become indispensable obligations to the seller and buyer. As such assistances is at the cost and risk of the party responsible for the clearances of the goods, the choice of recognised partner and compliance with the relevant security program, in order to enjoy the relevant benefits, becomes paramount.

  • PDF

소셜 네트워크 서비스의 보안기능 사용의도에 영향을 미치는 요인 : Facebook을 중심으로 (Factors Affecting Intention to Use Security Functions in SNS)

  • 김협;김경규;이호
    • 한국IT서비스학회지
    • /
    • 제13권2호
    • /
    • pp.1-17
    • /
    • 2014
  • Social networking service (SNS) is a service that allows people to share information, manage relationships with others, and express themselves on the Internet. The number of SNS users have increased explosively with the growth of mobile devices such as smartphones. As the influence of SNS has grown extensively, potential threats to privacy have also become pervasive. The purpose of this study is to empirically examine the main factors that affect users' intentions to use security functions provided by their SNS. The main theories for this study include the rational choice theory and the theory of planned behavior. This study has identified the factors that affect intention to use security functions. In addition, security function awareness and information security awareness are found to be important antecedents for intention to use security functions. The results of this study implies that when SNS providers develop security policies, they should consider the ways to improve users information security awareness and security function awareness simultaneously.

Advanced Information Security Management Evaluation System

  • Jo, Hea-Suk;Kim, Seung-Joo;Won, Dong-Ho
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제5권6호
    • /
    • pp.1192-1213
    • /
    • 2011
  • Information security management systems (ISMSs) are used to manage information about their customers and themselves by governments or business organizations following advances in e-commerce, open networks, mobile networks, and Internet banking. This paper explains the existing ISMSs and presents a comparative analysis. The discussion deals with different types of ISMSs. We addressed issues within the existing ISMSs via analysis. Based on these analyses, then we proposes the development of an information security management evaluation system (ISMES). The method can be applied by a self-evaluation of the organization and an evaluation of the organization by the evaluation committee. The contribution of this study enables an organization to refer to and improve its information security levels. The case study can also provide a business organization with an easy method to build ISMS and the reduce cost of information security evaluation.

An Analysis of Security Threats and Security Requirements on the Designated PC Solution

  • Lee, Kyungroul;Lee, Sun-Young;Yim, Kangbin
    • 한국컴퓨터정보학회논문지
    • /
    • 제22권5호
    • /
    • pp.29-39
    • /
    • 2017
  • In this paper, we analyse security threats and security requirements about the designated PC solution which restricts usable PCs that are only an user own PCs or a registered PC for online banking or very important services. Accordingly, causable threats of the designated PC solution are classified a process, a network layer, a software module, and an environment of platform, and we draw security requirements based on analysed security threats. Results of this research are considered utilization of criteria for improving security of the designated PC solution and standards for giving hint of imposition of the designated PC solution.

Empirical Research on Security Awareness of Multicultural Family Marriage Migrant Women

  • Park, Kap Lyong
    • 한국컴퓨터정보학회논문지
    • /
    • 제20권10호
    • /
    • pp.141-148
    • /
    • 2015
  • This study aims to inspect national security consciousness of marriage migrant women, and to figure out factors which affect on awareness of national security. Based on this, this study also suggests a way to build up national security of marriage migrant women. As the result of the factors on security situation, there were several things which are necessity of education, trust in the army and government, positivity toward North Korea and so on, while necessity of education, trust in the army and government, national pride and positivity toward North Korea were on the awareness of national security. There are three ways of building up national security consciousness of marriage migrant women. First, security education is needed to be in the social adjustment program of marriage migrant women. Secondly, concern on security is required to them. Third, a necessity of production on security education material is demanded for marriage migrant women.

민간경비원의 법적 지위에 관한 비교연구 (Private Security comparative study on the legal status)

  • 서진석
    • 융합보안논문지
    • /
    • 제14권1호
    • /
    • pp.43-50
    • /
    • 2014
  • 민간경비원은 특별한 법적 권한이 주어지지 않은 일반인과 동등한 법적 지위를 보유하고 있다. 그러나 민간경비산업은 그동안 업무영역의 확대를 가져와 제한적이지만 일부 법적 권한을 보유할 시기가 되었다는 주장이 있다. 이 연구에서는 일본 미국 등 주요국가의 경비원 법적 지위를 비교 분석하고 우리나라 민간경비원의 법적 지위에 관하여는 현행법인 경비업법상의 경비원의 법적 지위를 분석함으로써 우리나라의 민간경비원 법적 지위의 문제점을 도출하고 그에 대한 대안을 제안하는데 목적이 있다.

정보보호 활동이 정보경영성과에 미치는 영향에 관한 실증분석 (Empirical analysis on Information Management Performance Impact of Information Security activities)

  • 손태현;박정선
    • 대한안전경영과학회지
    • /
    • 제17권3호
    • /
    • pp.205-213
    • /
    • 2015
  • This study aims to verify the structural correlation empirically between information security performance and information management performance. To verify the correlation, three factors such as managerial controlled activity, technical controlled activity, and physical controlled activity are divided for the information security activities variable. the security performance are divided into accident prevention and accident response variables. As a result, security organization activity is a unique factor being positively significant to information security and management performance. And three activities such as human security, security training, development security do not affect at all on both information security and management performance.

물리보안 시장경제 활성화 방안에 관한 연구 (A study on the physical security market economy revitalization plan)

  • 김민수
    • 융합보안논문지
    • /
    • 제23권2호
    • /
    • pp.115-120
    • /
    • 2023
  • 국내 물리보안(기계경비) 시장은 대기업과 중소 및 영세 기업의 인프라로 인한 경비구역의 확장에 있어 편차가 증가하고 있는 실정이다. 즉, 출동 시간에 따른 출동 범위에 대한 물리보안 서비스의 한정으로 기업 간 현장 출동과 관련한 문제가 끊임없이 제기되고 있다. 이에 본 연구에서는 현장 출동과 관련한 시뮬레이션을 통해 출동 시간에 대한 기준으로 출동 범위의 기준에 대한 결과를 바탕으로 향후 물리보안(기계경비) 시장의 활성화 방안에 대하여 제안한다.