• Title/Summary/Keyword: Social engineering attack

Search Result 70, Processing Time 0.031 seconds

A Study on Secure Digital Convergence Curation System to WebShell (웹셀에 안전한 디지털 융합 큐레이션 시스템에 관한 연구)

  • Shin, Seung-Soo;Kim, Jung-In;Lee, Jun-Yeon
    • Journal of the Korea Convergence Society
    • /
    • v.6 no.4
    • /
    • pp.187-195
    • /
    • 2015
  • In the knowledge and information society which came into being with the advancements made in information and communication technology, there is an increasing perception of the importance of having knowledge and therefore being able to appropriately respond to the rapidly-changing society. Along with this, for the paradigm that stresses creativity and character, there must accompany advanced ways of conducting education which are capable of supporting changes in the educational objectives and contents. With respect to this, there is a need for sustained and long-term research into ways of utilizing SNS and ICT in the field of education. Accordingly, in this paper, a digital curation system was developed for educational contents that aim to develop one's creativity and character. Recently, web hacking is taking place actively. In this paper, a digital curation system that is secure against WebShell - one of the web hacking methods - is analyzed, as well as how to appropriately deal with this type of an attack.

A Multi-Agent framework for Distributed Collaborative Filtering (분산 환경에서의 협력적 여과를 위한 멀티 에이전트 프레임워크)

  • Ji, Ae-Ttie;Yeon, Cheol;Lee, Seung-Hun;Jo, Geun-Sik;Kim, Heung-Nam
    • Journal of Intelligence and Information Systems
    • /
    • v.13 no.3
    • /
    • pp.119-140
    • /
    • 2007
  • Recommender systems enable a user to decide which information is interesting and valuable in our world of information overload. As the recent studies of distributed computing environment have been progressing actively, recommender systems, most of which were centralized, have changed toward a peer-to-peer approach. Collaborative Filtering (CF), one of the most successful technologies in recommender systems, presents several limitations, namely sparsity, scalability, cold start, and the shilling problem, in spite of its popularity. The move from centralized systems to distributed approaches can partially improve the issues; distrust of recommendation and abuses of personal information. However, distributed systems can be vulnerable to attackers, who may inject biased profiles to force systems to adapt their objectives. In this paper, we consider both effective CF in P2P environment in order to improve overall performance of system and efficient solution of the problems related to abuses of personal data and attacks of malicious users. To deal with these issues, we propose a multi-agent framework for a distributed CF focusing on the trust relationships between individuals, i.e. web of trust. We employ an agent-based approach to improve the efficiency of distributed computing and propagate trust information among users with effect. The experimental evaluation shows that the proposed method brings significant improvement in terms of the distributed computing of similarity model building and the robustness of system against malicious attacks. Finally, we are planning to study trust propagation mechanisms by taking trust decay problem into consideration.

  • PDF

A Study on a Secure Internet Service Provider Model Using Smart Secure-Pad (스마트 보안패드를 이용한 안전한 인터넷 서비스 제공 모델에 관한 연구)

  • Lee, Jae-Sik;Kim, Hyung-Joo;Jun, Moon-Seog
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.14 no.3
    • /
    • pp.1428-1438
    • /
    • 2013
  • Services take place in Internet environment, a formation of the trust relationship between user and service provider for services. Different authentication schemes such as using Certificate of Public Key Infrastructure authentication and using ID/PW for a simple user authentication have been proposed for trust relationship. In addition, in the case of electronic financial transactions, transaction integrity and non-repudiation features are provided. These services are provided in Internet environment, use various measures to ensure service safety. However, it was difficult to prevent attacks using existing security technology because of emergence of MITB attack that manipulate the memory area of the Web browser and social engineering attacks such as phishing/pharming, requires application of new security technologies became. In this paper, we propose a concept of smart secure-pad, and utilize it safely formed a trust relationship between user and service provider, a model has been proposed to ensure safety of data transmission. Proposed model's security evaluation results show security against to MITB attack and phishing/pharming that can't be prevent attack using existing security technology. In addition, service provider can easily apply the model in safe environment can provide Internet service using provided representative services applying the proposed model.

A Study on the Security Structure of Next Generation E-mail System (차세대 이메일 보안 기술에 관한 연구)

  • Kim, Kui-Nam J.
    • Convergence Security Journal
    • /
    • v.8 no.4
    • /
    • pp.183-189
    • /
    • 2008
  • E-mail's role has been increased due to its merit which is sending demanded information in real-time anywhere, anytime. However, Today's E-mail security threats have being changed intelligently to attack against the specific agency. The threat is a limit to respond. Therefore precise definition and development of security technology is needed to analyze changing environment and technologies of e-mail so that remove fundamental security threat. we proposed Next Generation E-mail System Security Structure and the Next Generation fusion System using authentication As a result, in this study, we development of Next Generation E-mail System Security Structure. This system can protect E-mail user from social engineering hacking technique, spam, virus, malicious code and fabrication.

  • PDF

A Scheme of Social Engineering Attacks and Countermeasures Using Big Data based Conversion Voice Phishing (빅데이터 기반의 융합 보이스피싱을 이용한사회공학적 공격 기법과 대응방안)

  • Kim, Jung-Hoon;Go, Jun-Young;Lee, Keun-Ho
    • Journal of the Korea Convergence Society
    • /
    • v.6 no.1
    • /
    • pp.85-91
    • /
    • 2015
  • Recently government has distributed precautionary measure and response procedures for smishing(SMS phishing), pharming, phishing, memory hacking and intensified Electronic Financial Transaction Act because of the sharp increase of electronic bank frauds. However, the methods of electronic bank frauds also developed and changed accordingly so much it becomes hard to cope with them. In contrast to earlier voice phishing targeted randomizing object, these new methods find out the personal information of targets and analyze them in detail making a big data base. And they are progressed into new kind of electronic bank frauds using those analyzed informations for voice phishing. This study analyze the attack method of voice phishing blended with the Big Data of personal informations and suggests response procedures for electronic bank frauds increasingly developed. Using the method to save meaningless data in a memory, attackers cannot deduct accurate information and try voice phishing properly even though they obtain personal information based on the Big Data. This study analyze newly developed social technologic attacks and suggests response procedures for them.

Antioxidant Property of Genistein: Inhibitory Effect on HOCI Induced Protein Degradation, DNA Cleavage, and Cell Death

  • Choi, Je-Min;Ryu, Hyun-Jin;Chung, Jae-Hwan;Park, Jae-Chul;Hwang, Jae-Kwan;Shin, Dong-Bum;Lee, Sang-Kyou;Ryang, Ryung
    • Food Science and Biotechnology
    • /
    • v.14 no.3
    • /
    • pp.399-404
    • /
    • 2005
  • The aim of this study was to investigate the in vitro antioxidant profiles of genistein and other isoflavonoids. The reactivity of genistein towards stable radical and reactive oxygen species including ${\bullet}\;ABTS^+$, ${\bullet}{O_2}^-$, $H_2O_2$ and HOCl has been investigated, and the effects were compared with other isoflavonoids and antioxidants. All the tested isoflavonoids showed remarkable ${\bullet}\;ABTS^+$ scavenging activity and genistein was more potent than BHT and ascorbic acid. Genistein was more effective in scavenging hypochlorous acid than superoxide and hydrogen peroxide. At $10\;{\mu}M$ concentrations of genistein and genistin showed about 90% inhibitory effect on HOCl, while BHT and ascorbic acid showed lower than 50% inhibitory effect. Moreover, genistein could inhibit plasmid DNA cleavage, protein degradation and cell death from HOCl attack, while daidzein, BHT and ascorbic acid could not protect them effectively. These results suggest that genistein is a more potent radical scavenger than other isoflavonoids, and it can remarkably reduce cellular damage induced by HOCl.

The Automation Model of Ransomware Analysis and Detection Pattern (랜섬웨어 분석 및 탐지패턴 자동화 모델에 관한 연구)

  • Lee, Hoo-Ki;Seong, Jong-Hyuk;Kim, Yu-Cheon;Kim, Jong-Bae;Gim, Gwang-Yong
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.21 no.8
    • /
    • pp.1581-1588
    • /
    • 2017
  • Recently, circulating ransomware is becoming intelligent and sophisticated through a spreading new viruses and variants, targeted spreading using social engineering attack, malvertising that circulate a large quantity of ransomware by hacking advertising server, or RaaS(Ransomware-as-a- Service), from the existing attack way that encrypt the files and demand money. In particular, it makes it difficult to track down attackers by bypassing security solutions, disabling parameter checking via file encryption, and attacking target-based ransomware with APT(Advanced Persistent Threat) attacks. For remove the threat of ransomware, various detection techniques are developed, but, it is very hard to respond to new and varietal ransomware. Accordingly, in this paper, find out a making Signature-based Detection Patterns and problems, and present a pattern automation model of ransomware detecting for responding to ransomware more actively. This study is expected to be applicable to various forms in enterprise or public security control center.

Durability Performance Evaluation On Early-Aged Concrete with Rice Husk Ash and Silica Fume (Rice Husk Ash와 실리카퓸을 혼입한 초기재령 콘크리트의 내구성능 평가)

  • Saraswathy, Velu;Kwon, Seung-Jun
    • Journal of the Korea Concrete Institute
    • /
    • v.27 no.4
    • /
    • pp.343-351
    • /
    • 2015
  • Currently, lots of researches have been performed for reducing cement usages due to increasing social/engineering problems caused by $CO_2$ emission. Supplementary cement materials like fly ash, slag, and silca fume are usually employed for cement replacement, and nowadays rice husk ash (RHA) is widely studied for enhancement of concrete performance as mineral admixture. In this paper, concrete samples with RHA and SF which is known for its engineering advantages are prepared and a resistance to chloride attack is evaluated in early-aged concrete. For the work, replacement ratios of 10~30% for RHA concrete and 2~8% for SF concrete are considered, and various durability tests such as density, void, sorptivity, current measurement, and chloride diffusion coefficient are performed including mechanical test like compressive and tensile strength. Replacement of RHA 10~15% shows better improvement of corrosion resistance and strength than that of SF 2~4% and normal concrete, which shows a strong applicability for utilization as construction materials.

An analysis on the distribution characteristics of PM10 concentration and its relation to the death from Asthma in Seoul, Korea (서울지역 PM10 농도의 분포 특성과 천식 사망자 수의 상관성 분석)

  • Park, Jong-Kil;Choi, Yun-Jeong;Jung, Woo-Sik
    • Journal of Environmental Science International
    • /
    • v.24 no.7
    • /
    • pp.961-968
    • /
    • 2015
  • The production of highly concentrated $PM_{10}$ is in the spotlight as a social issue, and it increases the attack rate of Asthma. This study aimed to analyze the characteristics of concentration and distribution for $PM_{10}$ from 2000 to 2011, and investigate its correlation with the death from Asthma. Furthermore, this study was designed to analyze it by dividing into two cases like including Asian dust and excluding Asian dust because it presented the high concentration when Asian dust was occurred in the spring. This study has found that the annual average concentration distribution of $PM_{10}$ in Seoul was higher in the central area than the peripheral area. The annual average concentration of $PM_{10}$ and death from asthma displayed the tendency to gradually decrease. The correlation coefficient for all period was 0.92(p=0.000), and the correlation was 0.84(p=0.001) in case of remove Asian dust. The monthly average concentration of $PM_{10}$ has increased in the winter and decreased in the summer. The death from Asthma and correlation coefficient for all period was 0.588(p=0.044) and 0.640(p=0.025) in case of removing Asian dust. Although the causes of Asthma had a great diversity, the similar tendency by a factor of $PM_{10}$ meant that the correlation was high.

Analysis on National Economic Loss of Cyber Attack: Voice Phishing Case (사이버공격의 국가 경제적 손실분석 - 보이스 피싱을 중심으로)

  • Shin, Jin
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.16 no.11
    • /
    • pp.2341-2346
    • /
    • 2012
  • Voice phishing against the old or weak persons have used the methods which are social engineering in the object and financial structure and function. Until recently Voice phishing from Chaina caused economic devastation and the economic loss by phishing grows with the South Koreans in the whole. Korean government and public organizations involved have been strengthening protection system and a financial security devices. But it is not easy to verify how much effects of security measures are. In this paper I will study the economic loss caused by voice phishing and potential economic effects of security measures and security device reinforcements of the Republic of Korea. Direct costs are reported about 100 million dollars and potential economic effects of voice phinshing secure measures may be around 320 million dollars.