• Title/Summary/Keyword: Test packet

Search Result 216, Processing Time 0.031 seconds

A Study of Security Certification and Accreditation for DNP3 linkage section in EMS/SCADA (EMS/SCADA의 DNP3 연계구간 보안성 평가·인증 기술 연구)

  • Kim, Jongwan;Shon, Taeshik
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.25 no.3
    • /
    • pp.703-713
    • /
    • 2015
  • The linking system between the control system and the field devices in the existing EMS/SCADA, in order to increase the reliability of the data, and access control through the separation of external network. Currently, There is a tendency that the need for connection to an external network that takes into account the economic aspect, systematic management and efficiency of operations is increasing. Such is evolved linkage section, is to have more security vulnerabilities than in the past, Eventually communication EMS/SCADA linkage section requires special management method. In this paper, taking into account the domestic environment, were presented the security Certification and Accreditation technology that was applied to serial DNP3 and TCP/IP based DNP3 that are mainly used in EMS/SCADA linkage section. Presented to security of Certification and Accreditation technology, divided into Resource Robustness Test and Malicious Packet Test for evaluate the safety. Each of the security requirements and evaluation method in proposed technology, is an attempt to present the differentiation of the existing Certification and Accreditation technology.

Study on the Conformance Testing of Data Exchange between Transport Information Center and Terminal Equipment (교통정보센터와 단말기간 데이터교환 기술기준 적합성 시험에 관한 연구)

  • Lee, Sang-Hyun;Kim, Gyeong-Seok
    • The Journal of The Korea Institute of Intelligent Transport Systems
    • /
    • v.7 no.5
    • /
    • pp.147-158
    • /
    • 2008
  • Recently, Intelligent Transportation System (ITS) has been actively developed and built since the Transportation System Efficiency Promotion Act was enacted. However, since mutual connection among transportation information systems was not considered, the integration of transportation information services did not occur. Accordingly, the Ministry of Land Transport and Maritime Affairs established and announced the technical standard on ITS. In this study, the conformance testing of the transportation information and communication system interface standard on data exchange between the Transportation Information Center and terminals was researched The test items were categorized as data request tests and data providing tests by analyzing the communication procedures specified in the standard. A detail testing scenario was created for each item. The test assessment was established based on the conformance of data exchange procedures and the accuracy of data packet messages. Under the established technical standard, the number of times that tests should be performed was thought set to 30 and the success rate was set to 95%. The purpose of this study is to help the ITS of Korea perform the integrated management of transportation information by researching methods for conformance testing on the technical standard on ITS.

  • PDF

A Scheme of Distributed Network Security Management against DDoS Attacks (DDoS 공격에 대응하는 분산 네트워크 보안관리 기법)

  • Kim Sung-Ki;Yoo Seung-Hwan;Kim Moon-Chan;Min Byoung-Joon
    • Journal of the Institute of Electronics Engineers of Korea TC
    • /
    • v.43 no.7 s.349
    • /
    • pp.72-83
    • /
    • 2006
  • It is not a practical solution that the DDoS attacks or worm propagations are protected and responded within a domain itself because it clogs access of legitimate users to share communication lines beyond the boundary a domain. Especially, the DDoS attacks with spoofed source address or with bogus packets that the destination addresses are changed randomly but has the valid source address does not allow us to identify access of legitimate users. We propose a scheme of distributed network security management to protect access of legitimate users from the DDoS attacks exploiting randomly spoofed source IP addresses and sending the bogus packets. We assume that Internet is divided into multiple domains and there exists one or more domain security manager in each domain, which is responsible for identifying hosts within the domain. The domain security manager forwards information regarding identified suspicious attack flows to neighboring managers and then verifies the attack upon receiving return messages from the neighboring managers. Through the experiment on a test-bed, the proposed scheme was verified to be able to maintain high detection accuracy and to enhance the. normal packet survival rate.

A Study of Future Internet Testbed Construction using NetFGA/OpenFlow Switch on KOREN/KREONET (KOREN/KREONET기반 NetFPGA/OpenFlow 스위치를 이용한 미래인터넷 테스트 베드 구축 방안 연구)

  • Park, Man-Kyu;Jung, Whoi-Jin;Lee, Jae-Yong;Kim, Byung-Chul
    • Journal of the Institute of Electronics Engineers of Korea TC
    • /
    • v.47 no.7
    • /
    • pp.109-117
    • /
    • 2010
  • Building a large-scale testbed for Future Internet is very important to evaluate a new protocol and new network architecture designed by clean-slate approach. In Korea, new Future Internet testbed project, called FIRST (Future Internet Research for Sustainable Testbed), has been started since Mar. 2009 to design and test new protocols. This project is working together with ETRI and 5 universities. The FIRST@PC is to implement a virtualized hardware-accelerated PC-node by extending the functions of NetFPGA card and build a Future Internet testbed on the KOREN and KREONET for evaluating newly designed protocols and interesting applications. In this paper, we first briefly introduce FIRST@PC project and explain a 'MAC in IP Capsulator' user-space program using raw-socket in Linux to interconnect OpenFlow enabled switch sites on the KOREN and KREONET. After that, we address test results for TCP throughput performance for varying packet size. The test results show that the software based capsulator can support a reasonable bandwidth performance for most of applications.

Mapping of QoS Information Elements and Implementation of Rs/Rw Interface Resource Control Protocols in NGN (NGN에서의 QoS 정보요소 매핑 및 Rs/Rw 인터페이스의 자원제어 프로토콜 구현)

  • Jeon, Jin-Su;Kim, Hae-Hyun;Cha, Young-Wook;Kim, Choon-Hee;Jeong, You-Hyeon
    • The KIPS Transactions:PartC
    • /
    • v.15C no.5
    • /
    • pp.429-438
    • /
    • 2008
  • NGN is a packet-based converged network to support session and non-session services in QoS-enabled broadband transport network. QoS based resource control must be defined to support differentiated services for various network users in NGN. We designed and implemented DIAMETER protocol as the Rs interface, and also defined mapping rules between DIAMETER information elements and SDP(Session Description Protocol) attributes for QoS based resource control in NGN. We selected and implemented DIAMETER protocol among alternate resource control protocols in ITU-T as the Rw interface because of simple interworking method with Rs interface and adequate AAA functionality. We defined mapping rules of messages and information elements between Rs and Rw interfaces for resource control from a service layer to a transport layer. Based on the mapping rule of QoS information elements and the interworking method between Rs and Rw interfaces, we built up a test-bed that support differentiated delivery services.

Implementation of Ring Buffer based Massive VLBI Data Stream Input/Output over the Wide Area Network (광역 네트워크 상의 링 버퍼 기반 대용량 VLBI 데이터 스트림 입출력 구현)

  • Song, Min-Gyu;Kim, Hyo-Ryung;Kang, Yong-Woo;Je, Do-Heung;Wi, Seog-Oh;Lee, Sung-Mo
    • The Journal of the Korea institute of electronic communication sciences
    • /
    • v.14 no.6
    • /
    • pp.1109-1120
    • /
    • 2019
  • In the field of VLBI, If the quality of the connected network between the VLBI station and the correlation center is ensured, the existing inefficiency of repeatedly storing the observation data in each station and the correlation center can be overcome. In other words, the data center can be unified with the correlation center where data analysis is performed, which can improve data processing speed and productivity. In this paper, we design a massive VLBI data system that directly transmits and stores the observation data stream obtained from the VLBI station to the correlation center via the high - speed network KREONET. Based on this system, VLBI test observations confirmed that the observation data was stored perfectly in the recording system of the correlation center without a single packet loss.

Realtime No-Reference Quality-Assessment Over Packet Video Networks (패킷 비디오 네트워크상의 실시간 무기준법 동영상 화질 평가방법)

  • Sung, Duk-Gu;Kim, Yo-Han;Hana, Jung-Hyun;Shin, Ji-Tae
    • Journal of Broadcast Engineering
    • /
    • v.14 no.4
    • /
    • pp.387-396
    • /
    • 2009
  • No-Reference video-quality assessments are divided into two kinds of metrics based on decoding pixel domain or the bitstream one. Traditional full-/reduced- reference methods have difficulty to be deployed as realtime video transmission because it has problems of additional data, complexity, and assessment accuracy. This paper presents simple and highly accurate no-reference video-quality assessment in realtime video transmission. Our proposed method uses quantization parameter, motion vector, and information of transmission error. To evaluate performance of the proposed algorithm, we perform subjective test of video quality with the ITU-T P.910 Absolute Category Rating(ACR) method and compare our proposed algorithm with the subjective quality assessment method. Experimental results show the proposed quality metric has a high correlation (85%) in terms of subjective quality assessment.

High Strength SA508 Gr.4N Ni-Cr-Mo Low Alloy Steels for Larger Pressure Vessels of the Advanced Nuclear Power Plant (차세대 원전 대형 압력용기용 고강도 SA508 Gr.4N Ni-Cr-Mo계 저합금강 개발)

  • Kim, Min-Chul;Park, Sang-Gyu;Lee, Ki-Hyoung;Lee, Bong-Sang
    • Transactions of the Korean Society of Pressure Vessels and Piping
    • /
    • v.10 no.1
    • /
    • pp.100-106
    • /
    • 2014
  • There is a growing need to introduce advanced pressure vessel steels with higher strength and toughness for the optimizatiooCn of the design and construction of longer life and larger capacity nuclear power plants. SA508 Gr.4N Ni-Cr-Mo low alloy steels have superior strength and fracture toughness, compared to SA508 Gr.3 Mn-Mo-Ni low alloy steel. Therefore, the application of SA508 Gr.4N low alloy steel could be considered to satisfy the strength and toughness required in advanced nuclear power plants. The purpose of this study is to characterize the microstructure and mechanical properties of SA508 Gr.4N low alloy steels. 1 ton ingot of SA508 Gr.4N model alloy was fabricated by vacuum induction melting followed by forging, quenching, and tempering. The predominant microstructure of the SA508 Gr.4N model alloy is tempered martensite having small packet and fine Cr-rich carbides. The yield strength at room temperature was 540MPa, and it was decreased with an increase of test temperature while DSA phenomenon occurred at around $288^{\circ}C$. Overall transition property of SA508 Gr.4N model alloy was much better than SA508 Gr.3 low alloy steel. The index temperature, $T_{41J}$, of SA508 Gr.4N model alloy was $-132^{\circ}C$ in Charpy impact tests, and reference nil-ductility transition temperature, $RT_{NDT}$ of $-105^{\circ}C$ was obtained from drop weight tests. From the fracture toughness tests performed in accordance with the ASTM standard E1921 Master curve method, the reference temperature, $T_0$ was $-147^{\circ}C$, which was improved more than $60^{\circ}C$ compared to SA508 Gr.3 low alloy steels.

Performance Evaluation for TCP/IP over UBR (UBR 위에서 동작하는 TCP/IP 성능 평가)

  • Ahn, Sung-Soo;Yu, Hyung-Sik;Whang, Sun-Ho;Lee, Jun-Won;Kim, Sung-Un
    • Journal of KIISE:Information Networking
    • /
    • v.27 no.1
    • /
    • pp.76-87
    • /
    • 2000
  • ATM is a key technology of integration of multimedia service. Recently, Many study have been concentrated on performance testing for evaluation network performance are stronger everyday. The performance testing is on evaluation of maximal throughput of network by measuring and analyzing of various performance parameters. There are two ways to test ATM network performance; one is using QoS in cell level on the point of network's view, and the other is using metric in frame level in the point of user's view. And, the standardization process is also under way. In this paper, we derive a performance requirement of TCP in TCP/IP data transmission over ATM UBR service. By applying the derived requirements to ATM and packet networks, we evaluate the performance of TCP over UBR based on the result of our simulations. Therefore, we evaluate the result of simulation and find degradation of network throughput by interaction between TCP congestion control and ATM cell drop policy. So we suggest the accelerated Vegas that modify traditional TCP Vegas in congestion control mechanism for batter network throughput.

  • PDF

Development of Visible Light Communication (VLC) System Technology Based on High Brightness LED light (고휘도 LED 조명 기술을 이용한 고속 가시광통신 시스템 기술 개발)

  • Lee, Jong-Hyeok;Jang, Kyung-Soon;Kim, Byung-Gyu;Kim, Jin-Ho
    • Convergence Security Journal
    • /
    • v.14 no.7
    • /
    • pp.29-36
    • /
    • 2014
  • In this study, we design and develop a VLC test-bed system which has been recently issued and focused as good convergence technology in the world. We classify the developed system into transmission part including analog LED driver module, digital signal modulation module, and receiver part with light sensing module and signal demodulation module. Then we introduce important characteristics and components. We analyze some factors for each module. To validate the communication of the designed VLC system, we develop a VLC sender-receiver simulator which can control the dimming factor and flicker-free effect. From the developed system, we observed about 12Mbps of data transmission rate with 0.5m~1m of distance, without packet loss. We verified the real-time communication with multimedia streaming which can be considered as very high date rate. The developed system and technology will be useful for some converged data services like indoor positing, home appliances, and indoor parking system.