• Title/Summary/Keyword: Security Integration

Search Result 447, Processing Time 0.068 seconds

Supply chain attack detection technology using ELK stack and Sysmon (ELK 스택과 Sysmon을 활용한 공급망 공격 탐지 기법)

  • hyun-chang Shin;myung-ho Oh;seung-jun Gong;jong-min Kim
    • Convergence Security Journal
    • /
    • v.22 no.3
    • /
    • pp.13-18
    • /
    • 2022
  • With the rapid development of IT technology, integration with existing industries has led to an increase in smart manufacturing that simplifies processes and increases productivity based on 4th industrial revolution technology. Security threats are also increasing and there are. In the case of supply chain attacks, it is difficult to detect them in advance and the scale of the damage is extremely large, so they have emerged as next-generation security threats, and research into detection technology is necessary. Therefore, in this paper, we collect, store, analyze, and visualize logs in multiple environments in real time using ELK Stack and Sysmon, which are open source-based analysis solutions, to derive information such as abnormal behavior related to supply chain attacks, and efficiently We try to provide an effective detection method.

Scale and Scope Economies and Prospect for the Korea's Banking Industry (우리나라 은행산업(銀行産業)의 효율성분석(效率性分析)과 제도개선방안(制度改善方案))

  • Jwa, Sung-hee
    • KDI Journal of Economic Policy
    • /
    • v.14 no.2
    • /
    • pp.109-153
    • /
    • 1992
  • This paper estimates a translog cost function for the Korea's banking industry and derives various implications on the prospect for the Korean banking structure in the future based on the estimated efficiency indicators for the banking sector. The Korean banking industry is permitted to operate trust business to the full extent and the security business to a limited extent, while it is formally subjected to the strict, specialized banking system. Security underwriting and investment businesses are allowed in a very limited extent only for stocks and bonds of maturity longer than three year and only up to 100 percent of the bank paid-in capital. Until the end of 1991, the ceiling was only up to 25 percent of the total balance of the demand deposits. However, they are prohibited from the security brokerage business. While the in-house integration of security businesses with the traditional business of deposit and commercial lending is restrictively regulated as such, Korean banks can enter the security business by establishing subsidiaries in the industry. This paper, therefore, estimates the efficiency indicators as well as the cost functions, identifying the in-house integrated trust business and security investment business as important banking activities, for various cases where both the production and the intermediation function approaches in modelling the financial intermediaries are separately applied, and the banking businesses of deposit, lending and security investment as one group and the trust businesses as another group are separately and integrally analyzed. The estimation results of the efficiency indicators for various cases are summarized in Table 1 and Table 2. First, security businesses exhibit economies of scale but also economies of scope with traditional banking activities, which implies that in-house integration of the banking and security businesses may not be a nonoptimal banking structure. Therefore, this result further implies that the transformation of Korea's banking system from the current, specialized system to the universal banking system will not impede the improvement of the banking industry's efficiency. Second, the lending businesses turn out to be subjected to diseconomies of scale, while exhibiting unclear evidence for economies of scope. In sum, it implies potential efficiency gain of the continued in-house integration of the lending activity. Third, the continued integration of the trust businesses seems to contribute to improving the efficiency of the banking businesses, since the trust businesses exhibit economies of scope. Fourth, deposit services and fee-based activities, such as foreign exchange and credit card businesses, exhibit economies of scale but constant returns to scope, which implies, the possibility of separating those businesses from other banking and trust activities. The recent trend of the credit card business being operated separately from other banking activities by an independent identity in Korea as well as in the global banking market seems to be consistent with this finding. Then, how can the possibility of separating deposit services from the remaining activities be interpreted? If one insists a strict definition of commercial banking that is confined to deposit and commercial lending activities, separating the deposit service will suggest a resolution or a disappearance of banking, itself. Recently, however, there has been a suggestion that separating banks' deposit and lending activities by allowing a depository institution which specialize in deposit taking and investing deposit fund only in the safest securities such as government securities to administer the deposit activity will alleviate the risk of a bank run. This method, in turn, will help improve the safety of the payment system (Robert E. Litan, What should Banks Do? Washington, D.C., The Brookings Institution, 1987). In this context, the possibility of separating the deposit activity will imply that a new type of depository institution will arise naturally without contradicting the efficiency of the banking businesses, as the size of the banking market grows in the future. Moreover, it is also interesting to see additional evidences confirming this statement that deposit taking and security business are cost complementarity but deposit taking and lending businesses are cost substitute (see Table 2 for cost complementarity relationship in Korea's banking industry). Finally, it has been observed that the Korea's banking industry is lacking in the characteristics of natural monopoly. Therefore, it may not be optimal to encourage the merger and acquisition in the banking industry only for the purpose of improving the efficiency.

  • PDF

Learning from the USA's Single Emergency Number 911: Policy Implications for Korea (미국 긴급번호 911 운영시스템에 관한 연구: 긴급번호 실질적 통합을 위한 정책 시사점 제시 중심으로)

  • Kim, Hak-Kyong;Lee, Sung-Yong
    • Korean Security Journal
    • /
    • no.43
    • /
    • pp.67-97
    • /
    • 2015
  • In Korea, a single emergency number, such as 911 of the USA and 999 of the UK, does not exist. This issue became highly controversial, when the Sewol Ferry Sinking disaster occurred last year. So, the Korean government has planned to adopt a single emergency number, integrating 112 of the Police, 119 of the Fire and Ambulance, 122 of the Korean Coast Guard, and many other emergency numbers. However, the integration plan recently proposed by the Ministry of Public Safety Security seems to be, what is called, a "partial integration model" which repeals the 122 number, but still maintains 112, 119, and 110 respectively. In this context, the study looks into USA's (diverse) 911 operating system, and subsequently tries to draw general features or characteristics. Further, the research attempts to derive policy implication from the general features. If the proposed partial integration model reflects the policy implications, the model can virtually operate like the 911 system -i.e. a single emergency number system - creating inter-operability between responding agencies such as police, fire, and ambulance, even though it is not a perfect integration model. The features drawn are (1) integration of emergency call-taking, (2) functional separation of call-taking and dispatching, (3) integration of physical facilities for call-taking and dispatching, and (4) professional call-takers and dispatchers. Moreover, the policy implications derived from the characteristics are (1) a user-friendly system - fast but accurate responses, (2) integrated responses to accidents, (3) professional call-taking and dispatching & objective and comprehensive risk assessment, and finally (4) active organizational learning in emergency call centers. Considering the policy implications, the following suggestions need to be applied to the current proposed plan: 1. Emergency services' systems should be tightly linked and connected in a systemic way so that they can communicate and exchange intelligence with one another. 2. Public safety answering points (call centers) of each emergency service should share their education and training modules, manuals, etc. Common training and manuals are also needed for inter-operability. 3. Personal management to enable-long term service in public safety answering points (call centers) should be established as one of the ways to promote professionalism.

  • PDF

Advanced Resolution on Escort Security Area by Reviewing the System in Private Security Business (민간경비업의 제도적 고찰을 통한 호송경비업의 개선방안)

  • Kim, Sung-Su
    • Korean Security Journal
    • /
    • no.25
    • /
    • pp.63-87
    • /
    • 2010
  • Our society nowadays sees the increase in damage from crime on lives and properties by leaps and bounds in line with the economic take-off, and as a result, the raise of individual income. When considering such a hike in crime, it is desirable that the police framework be enhanced. However, thanks to the failure to correspond to this, it could be safely said that a good portion of accountability was shifted to the private security industry in regard to security for the people. Accordingly, the request for escort security business is on the increase regarding expansion and improvement about this industrial sector. As such, it is necessary to get the related system rearranged for authority on the part of escort guards, who are directly exposed to numerous crimes. On top of this, dispersion is required for the escort security businesses centralized in the metropolitan area. It is also necessary for the security guard system to be strengthened and disintegrated into details so that the escort security services are available to people in more safe and easily manners than ever before. When the qualification regime is operated based on this refreshed system, the efficient escort security work would be realized. The dichotomy into act on Special Security Guard and act on Security Business should be dealt with once again for integration as an issue on the front burner in the academic area, and through which the escort security market could be fit for the globalization as well. This paper would provide the solution that leads to more professional and efficient results from comprehension of progress situations in reality by starting from the concept on private security to the analysis of the conditions in this industrial sector.

  • PDF

An Empirical Study on the Competition Factor Electronic Logistics Information and International Logistics Management (국제물류관리와 전자적물류정보의 경쟁요인에 관한 실증연구)

  • Kwak, Hyun
    • International Commerce and Information Review
    • /
    • v.9 no.2
    • /
    • pp.257-283
    • /
    • 2007
  • As Global industrial structure is diversified, multinational corporations accomplished fast internationalization to introduction of new management policy by development of an IT technology. Enterprise' business environment is changing transcending border. To overcome raging waves of change accident and to be secured enterprise's future, the logistics is recognized the third profit source joining in curtailment of sale enlargement, production cost. To seek cost saving or reform in logistics class that is last area of pursuit of profits within ancient city life in the fast lane from these viewpoint, importance of study that integrates and manages international logistics bases supply neck walk is emphasized. Specially, to meet on in terms of competitive power security regarding curtailment of logistics cost is available through link between logistics bases, various consumer's request, merchandise and service logistics management that supply fixed quantity as is reliable in right place at good season was embossed by point game plan of business management, and SCM efficiency anger of mortification international logistics activity importance of study that see at that dominate competitive advantage point bring. This study analyzes interrelation and presents model for integration of international logistics bases supply network with supply network habit at factor and supply chain, and supply network activity in integration of supply chain process and production. Also, it establishes following method of study to achieve study purpose for actual proof analysis for integration sequence of international logistics bases supply network. Specially, immersion of network and supply network, very high interrelation appeared by thing which is with international logistics base supply network integration. The integration of international logistics base supply network means that the enterprises which give trust and sincerity deal with market environment change positively and can decide proceeding of various cooperative work. Also, it means the possibility by necessity of cooperative relation and interdependence to continuous immersion and normative immersion, for the maintain of long business relations.

  • PDF

The Study of Service Integration using Ontology-based Service Association (온톨로지 기반의 서비스 연관관계를 이용한 서비스 통합에 관한 연구)

  • Hwang, Chi-Gon;Shin, Hyo-Young;Lee, Sang-Hoon;Jung, Kye-Dong
    • Journal of Digital Convergence
    • /
    • v.12 no.2
    • /
    • pp.327-333
    • /
    • 2014
  • Recently, most of computing technology is based on web. Therefore, the users register web services or needed resources, and they can find and use the registered item. These services can be used alone or can be used in combination. When the item is used in combination, the ordering and association of service is important, and an ontology that defined association of services is required. In this paper, we define association of services based on ontology, and propose a method that can be used by services integration. The proposed method provides an efficient retrieval service by compositing the ontology with the service area and data association area.

A Safety Process Guideline of Medical Device System Based on STPA (STPA를 적용한 의료기기 시스템의 안전성 프로세스 가이드라인)

  • Choi, Bo-yoon;Lee, Byong-gul
    • Journal of Internet Computing and Services
    • /
    • v.22 no.6
    • /
    • pp.59-69
    • /
    • 2021
  • Malfunctions and failures linked to medical devices may result in significant damage for human being. Thus, in order to ensure that safety of medical device is achieved, it should be established and applied the international standard. It is required to integrate and customize activities at standards, owing to reference relationship between standards, especially, activities based safety analysis is too expensive. This paper proposes a integration process that integrate activities of development lifecycle and safety process. Additionally, we derived a guidance based on STPA for integration process. As a result, we can be performed systematically from early stage of the development and increased effectiveness of integration process by the guidance.

A Study of Software Architecture Design Methods for Multiple Access Con trol under Web-based Medical Information System Environment (웹 기반 의료정보시스템 다중 접근제어를 위한 소프트웨어아키텍쳐 설계방법)

  • Noh, Si-Choon;Hwang, Jeong-Hee
    • Convergence Security Journal
    • /
    • v.11 no.4
    • /
    • pp.43-49
    • /
    • 2011
  • Web-based health information provides a lot of conveniences, however the security vulnerabilities that appear in the network environment without the risk of exposure in the use of information are growing. Web-based medical information security issues when accessing only the technology advances, without attempting to seek a safe methodology are to increase the threat element. So it is required. to take advantage of web-based information security measures as a web-based access control security mechanism-based design. This paper is based on software architecture, design, ideas and health information systems were designed based on access control security mechanism. The methodologies are to derive a new design procedure, to design architecture and algorithms that make the mechanism functio n. To accomplish this goal, web-based access control for multiple patient information architecture infrastructures is needed. For this software framework to derive features that make the mechanism was derived based on the structure. The proposed system utilizes medical information, medical information when designing an application user retrieves data in real time, while ensuring integration of encrypted information under the access control algorithms, ensuring the safety management system design.

Relations between Conflict Management Style of Private Security Guards in Organizational Effectiveness (민간경호경비조직의 갈등관리방식과 조직성과의 관계)

  • Park, Young-Man;Kim, Eun-Jung;Jung, Joo-Sub;Kang, Ho-Jung
    • The Journal of the Korea Contents Association
    • /
    • v.10 no.9
    • /
    • pp.375-386
    • /
    • 2010
  • The purpose of this study aimed to examine relations between conflict management method and organization of private security companies. 286 guards who worked at security compromies in Seoul in 2010 were selected by using the method of judgment sampling and 279 guards were used for analysis. Reliability of questionnaire used for this study was over .642 in value of Cronbach's $\alpha$. Collected data was analyzed by using factor analysis, reliability analysis, t-test, F-test, multiple regression analysis and SPSSWIN 17.0. The result is as follows. First, conflict management method for security guards is different depending on socio-demographic features. Second, organizational performance of security guards is different depending on socio-demographic features. Third, conflict management method of security guards has effect on organizational performance. The higher the method of managing conflict through integration, compromise, favor and governance, the higher cohesion, organizational immersion and job satisfaction.

A New National Security Strategy for South Korea: Exploring the Implementation of Positive Peace (한국의 새로운 국가 안보 전략: 적극적 평화 구축 방안 연구)

  • Choul-Hee Lee;Kyoung-Haing Lee;Sang Hyuk Park
    • The Journal of the Convergence on Culture Technology
    • /
    • v.10 no.4
    • /
    • pp.457-465
    • /
    • 2024
  • In the 21st century, the global security environment has undergone rapid changes, presenting South Korea with complex security dilemmas. This study aims to explore a new national security strategy for South Korea through the implementation of 'Positive Peace.' Based on Johan Galtung's concept of 'Positive Peace,' the study proposes a comprehensive approach to build sustainable peace by redesigning the peace process on the Korean Peninsula, establishing a multilateral security cooperation framework in Northeast Asia, expanding global peace contributions, promoting domestic social integration, and spreading a culture of peace. To realize these goals, the study discusses the need to redefine the role of the military, reallocate defense budgets, introduce the concept of a peace dividend, promote the peaceful use of science and technology, and legislate for the realization of the right to peace. The implementation of a 'Positive Peace' strategy aims to transform South Korea into a leading nation in peace, contributing to the peace and stability of the Korean Peninsula, Northeast Asia, and the global community.