• Title/Summary/Keyword: Security manager

Search Result 242, Processing Time 0.022 seconds

A Hybrid Model of Network Intrusion Detection System : Applying Packet based Machine Learning Algorithm to Misuse IDS for Better Performance (Misuse IDS의 성능 향상을 위한 패킷 단위 기계학습 알고리즘의 결합 모형)

  • Weon, Ill-Young;Song, Doo-Heon;Lee, Chang-Hoon
    • The KIPS Transactions:PartC
    • /
    • v.11C no.3
    • /
    • pp.301-308
    • /
    • 2004
  • Misuse IDS is known to have an acceptable accuracy but suffers from high rates of false alarms. We show a behavior based alarm reduction with a memory-based machine learning technique. Our extended form of IBL, (XIBL) examines SNORT alarm signals if that signal is worthy sending signals to security manager. An experiment shows that there exists an apparent difference between true alarms and false alarms with respect to XIBL behavior This gives clear evidence that although an attack in the network consists of a sequence of packets, decisions over Individual packet can be used in conjunction with misuse IDS for better performance.

Policy System of Data Access Control for Web Service (웹 서비스를 위한 데이터 접근 제어의 정책 시스템)

  • Jo, Sun-Moon;Chung, Kyung-Yong
    • The Journal of the Korea Contents Association
    • /
    • v.8 no.11
    • /
    • pp.25-32
    • /
    • 2008
  • Access control techniques should be flexible enough to support all protection granularity levels. Since access control policies are very likely to be specified in relation to document types, it is necessary to properly manage a situation in which documents fail to be dealt with by the existing access control policies. In terms of XML documents, it is necessary to describe policies more flexibly beyond simple authorization and to consider access control methods which can be selected. This paper describes and designs the access control policy system for authorization for XML document access and for efficient management to suggest a way to use the capacity of XML itself. The system in this paper is primarily characterized by consideration of who would exercise what access privileges on a specific XML document and by good adjustment of organization-wide demands from a policy manager and a single document writer.

Secure Location Information Protection Scheme from the Network Provider and the third party in Mobile Communication Environments (이동통신 환경에서 네트워크 제공자 및 제 3자로부터 안전한 위치정보 보호기법)

  • Kim, Soon-Seok;Lee, Chang-Hun
    • The KIPS Transactions:PartC
    • /
    • v.10C no.7
    • /
    • pp.867-878
    • /
    • 2003
  • In thls Paper, we Propose a new scheme, protecting information about the location of a mobile user against attacks from inside users of the mobile communication, especially the network providers. There have already been some proposals about how to protect location information of user in mobile communication environments〔1-5〕. Among them, Kesdogan et al.〔2, 3〕 proposed a new method, using so-called temporary pseudonyms and also described protection method against a passive and an active attack of network providers. However, the description of protection method against the active attack between the two is not clear. Moreover, there is an additional load that it should append a reachability manager〔1, 6〕 to the proposed system. Therefore, we propose a new scheme improving the above method of Kesdogan et al. and analyze its security and effectiveness.

A Study on Management Plans for Activating of Smart Work (스마트워크 활성화를 위한 경영관리 방안)

  • Lee, Seung-Hee;Do, Hyeon-Ok;Seo, Kyeong-Do
    • Journal of Digital Convergence
    • /
    • v.9 no.4
    • /
    • pp.245-252
    • /
    • 2011
  • This study review about smart work to appear the use of smart device, and find the management plan for activating of smart work. Our national's smart work that is the best internet environment in worldwide fall behind foreign country. This study offers for the activating strategies of smart work. Fist, it is to change perception about smart work. Second, it should be clear up legal definition and category of smart-work. Third, it is that tighten up security of smart equipment. It is hard to achieve effects, as long as we get used to face-to-face work processing. Based on accurate perception about smart work on both employees and manager, this study suggest that it is important to change perception and to make actively use of smart work.

A study on the integrated management model of the national disaster resources (국가 방재 자원 통합 운영 모델에 관한 연구)

  • Lee, Changyeol;Kim, Taehwan;Park, Giljoo
    • Journal of the Society of Disaster Information
    • /
    • v.9 no.3
    • /
    • pp.358-364
    • /
    • 2013
  • Conventional disaster resources management systems among the several institutes are not mutually connected. In case of NDMS(National Disaster Management System), the data of the system is confined to the resources of the local governments and not connected with any other disaster resource management systems. Therefore, it is difficult to find the needed resources, when the large scale disaster is occurred. In this paper, we developed the integrated model of the distributed resources management framework considering the current resource management environment among the institutes. It is loosely coupling model under the centralized system, called IDRM(Integrated Disaster Resource Manager). The system will be verified with the test sites including Korea Expressway Corporation, JeonBuk local government, and Korea Construction Equipment Association. Via the field testing, the system will be the base of the real available system in the future.

Design and Implementation of a Real Time Access Log for IP Fragmentation Attack Detection (IP Fragmentation 공격 탐지를 위한 실시간 접근 로그 설계 및 구현)

  • Guk, Gyeong-Hwan;Lee, Sang-Hun
    • The KIPS Transactions:PartA
    • /
    • v.8A no.4
    • /
    • pp.331-338
    • /
    • 2001
  • With the general use of network, cyber terror rages throughout the world. However, IP Fragmentation isn\`t free from its security problem yet, even though it guarantees effective transmission of the IP package in its network environment. Illegal invasion could happen or disturb operation of the system by using attack mechanism such as IP Spoofing, Ping of Death, or ICMP taking advantage of defectiveness, if any, which IP Fragmentation needs improving. Recently, apart from service refusal attack using IP Fragmentation, there arises a problem that it is possible to detour packet filtering equipment or network-based attack detection system using IP Fragmentation. In the paper, we generate the real time access log file to make the system manager help decision support and to make the system manage itself in case that some routers or network-based attack detection systems without packet reassembling function could not detect or suspend illegal invasion with divided datagrams of the packet. Through the implementation of the self-managing system we verify its validity and show its future effect.

  • PDF

Analyzing the Requirements for Improving Construction Managers' Work-life Balance (건축공사 현장관리자의 근로실태 및 워라밸 분석)

  • Kim, Jae-Yeob;Lim, Hyeong-Eun
    • Journal of the Korea Institute of Building Construction
    • /
    • v.18 no.6
    • /
    • pp.603-609
    • /
    • 2018
  • It has been widely-reported that the quality of life in Korea is lower than that of the economic growth. In particular, construction managers are reported to have a lower quality of life compared to people in other job types due to the specific nature of the tasks they have to carry out. These include early work attendance time and fewer holidays. In this respect, the aim of this study is to analyse construction managers' requirements on work-life balance. The results showed that the working hours of construction managers were long and their leisure hours were shorter. The requirements for work-life balance were in the order of non-working time, working time, salary, and job security. The requirements by group showed a statistically significant difference in work hours. The requirements on the shortening of work hours were highest in the group of "section chiefs and deputy heads" and lowest in the group of "department heads" and up. It is hoped that the results of this study will be used as basic data for future government-level policy making and construction companies' business directions in relation to the improvement of workers' work-life balance.

Empirical Study to Strengthen the Disaster Management of Wooden Cultural Heritage - Focused on Concept and Range of Cultural Heritage Disaster Management and Investigation of On-site Manager (목조문화재의 안전관리 강화를 위한 실증적 연구 - 문화재 안전관리의 개념과 범주 및 현장 관리자 의식조사를 중심으로 -)

  • Lim, Suhng-bin;Ryu, Ho-cheol
    • Korean Journal of Heritage: History & Science
    • /
    • v.46 no.2
    • /
    • pp.96-113
    • /
    • 2013
  • The concept of disaster management of cultural heritage is not clearly established and the range and type of it is not organized yet. Also, there is an ever-present danger in the field control because there is no system that can provide safety of cultural heritage from various dangerous factors. Concretely, institutionally, the regulation of disaster management of cultural heritage remains limited and there are not enough reasonableness in installation and management of fire-fighting equipment and safety equipment. Also, we need to take an action to secure the safety of cultural heritage from its surroundings. In this research, we setup the concept, type and criteria for disaster management of cultural heritage to overcome limitations and problems of management of cultural heritage. In addition, in order to raise the level of disaster management of cultural heritage, this research proposes direction to reinforce the disaster management of cultural heritage by investigating and analyzing consciousness of security guards and fire-fighting officers.

Worker Location Tracking System of Shipyard using Power Line Communication and Beacon (전력선 통신과 비컨을 활용한 선박 건조 현장의 작업자 위치 추적 시스템)

  • Taewoong Hwnag;Young-Doo Lee;Ki-Woong Park;In-Soo Koo
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.24 no.2
    • /
    • pp.41-49
    • /
    • 2024
  • This paper discusses the modeling and implementation of a worker location system at a shipbuilding site. The importance of worker location in an industrial environment is highlighted as a critical element in the prevention of industrial accidents. The paper presents a worker tracking system that integrates power line and beacon communication to accurately track worker position. Through experiments, the paper demonstrates how to monitor the changes in worker location based on different scenarios and how to access the status of worker location using the manager's web service. The paper can be used for the design of a system that will provide real-time location information to safety managers for the improvement of worker safety management.

An Automatic Network Vulnerability Analysis System using Multiple Vulnerability Scanners (다양한 취약점 점검 도구를 이용한 자동화된 네트워크 취약점 통합 분석 시스템 설계)

  • Yoon, Jun;Sim, Won-Tae
    • Journal of KIISE:Computing Practices and Letters
    • /
    • v.14 no.2
    • /
    • pp.246-250
    • /
    • 2008
  • This paper presents the design of network vulnerability analysis system which can integrate various vulnerability assessment tools to improve the preciseness of the vulnerability scan result. Manual checking method performed by a security expert is the most precise and safe way. But this is not appropriate for the large-scale network which has a lot of systems and network devices. Therefore automatic scanning tool is recommended for fast and convenient use. The scanning targets may be different according to the kind of vulnerability scanners, or otherwise even for the same scanning target, the scanning items and the scanning results may be different by each vulnerability scanner, Accordingly, there are the cases in which various scanners, instead of a single scanner, are simultaneously utilized with the purpose of complementing each other. However, in the case of simultaneously utilizing various scanners on the large-scale network, the integrative analysis and relevance analysis on vulnerability information by a security manager becomes time-consumable or impossible. The network vulnerability analysis system suggested in this paper provides interface which allows various vulnerability assessment tools to easily be integrated, common policy which can be applied for various tools at the same time, and automated integrative process.