• 제목/요약/키워드: Vulnerable Companies

검색결과 81건 처리시간 0.027초

국방 사이버 방호체계 구축 생태계 취약점 분석 및 개선방안 (Cyber Defense Analysis and Improvement of Military ecosystem with Information Security Industry)

  • 백재종;문병무
    • 정보보호학회논문지
    • /
    • 제24권6호
    • /
    • pp.1263-1269
    • /
    • 2014
  • 상용제품에 종속적인 국방 사이버 방호체계 생태계는 APT(Advanced Persistent Threat) 등 지능화된 최근 사이버 공격양상에 더욱 취약할 수 있다. 일반무기체계는 대부분 특정 방위산업체가 양산한 관급제품으로 원천기술 등에 대한 보호가 가능하지만 사이버 방호체계는 대부분 상용제품으로 군을 공격하지 않고 산업체 공격을 통해 군 공격이 직 간접적으로 가능하다. 본 논문에서는 국방 사이버 방호체계를 구축해나가는 생태계에 있어서 적 공격의 가상 시나리오를 분석해보고, 이에 대한 취약성 및 위협성을 평가 및 검증하여 안전한 국방 사이버 방호체계 생태계 구축을 위한 기술적, 정책적 방안을 제시한다.

A Study on Threat Containment through VDI for Security Management of Partner Companies Operating at Industrial Control System Facility

  • Lee, Sangdo;Huh, Jun-Ho
    • 한국정보처리학회:학술대회논문집
    • /
    • 한국정보처리학회 2019년도 추계학술발표대회
    • /
    • pp.491-494
    • /
    • 2019
  • The results from the analysis of recent security breach cases of industrial control systems revealed that most of them were caused by the employees of a partner company who had been managing the control system. For this reason, the majority of the current company security management systems have been developed focusing on their performances. Despite such effort, many hacking attempts against a major company, public institution or financial institution are still attempted by the partner company or outsourced employees. Thus, the institutions or organizations that manage Industrial Control Systems (ICSs) associated with major national infrastructures involving traffic, water resources, energy, etc. are putting emphasis on their security management as the role of those partners is increasingly becoming important as outsourcing security task has become a common practice. However, in reality, it is also a fact that this is the point where security is most vulnerable and various security management plans have been continuously studied and proposed. A system that enhances the security level of a partner company with a Virtual Desktop Infrastructure (VDI) has been developed in this study through research on the past performances of partner companies stationed at various types of industrial control infrastructures and its performance outcomes were statistically compiled to propose an appropriate model for the current ICSs by comparing vulnerabilities, measures taken and their results before and after adopting the VDI.

The Impact of COVID-19 Pandemic on Firm Performance: Empirical Evidence from Vietnam

  • BUI, Trung Huy;NGUYEN, Huong Thu;PHAM, Yen Nhu;NGUYEN, Trang Thu Thi;LE, Linh Thao;LE, Giang Thu Tran
    • The Journal of Asian Finance, Economics and Business
    • /
    • 제9권7호
    • /
    • pp.101-108
    • /
    • 2022
  • The outbreak of Coronavirus disease 2019 (COVID-19) has caused serious impacts not only on human health but also on the economies around the world. Enterprises play an important role in the development of every country but it is also one of the most affected sectors during the pandemic. Drawing on panel data of 131 enterprises listed on the Vietnamese stock exchange from 2016Q1 to 2021Q3, this study aims to investigate the impact of the COVID-19 pandemic on firm performance. Enterprises are classified into seven industries including Agriculture, Material, Industry, Real estate and Construction, Energy, Consumer, and Service. The paper also analyzes the variation of the effects among companies, focusing on differences in revenue and capital structure. The results show that the COVID-19 pandemic negatively affects business performance. In addition, the empirical findings indicate that revenue and debt decreasing can cause deterioration of firm performance during the pandemic period. The decrease in revenue has a direct impact on firm profitability. The reduction of debt levels affects the corporate leverage leading to adverse effects on firm performance. The negative effect is more pronounced for companies in some specific sectors including industry, real estate, construction, consumption, and services.

Risk assessment in international EV battery closed loop supply chain: developing a conceptual framework

  • Nataliia Grekova;Dong-WookKwak
    • 한국항해항만학회:학술대회논문집
    • /
    • 한국항해항만학회 2022년도 춘계학술대회
    • /
    • pp.201-203
    • /
    • 2022
  • Increasing global market of used electric vehicle (EV) battery encourages international firms to establish its subsidiary companies or business units specializing in battery recycling. Such kind of companies predominantly use closed loop supply chain (CLSC) for their operations of battery manufacturing and used battery recycling/reusing in global scale. However, EV battery recycling, as a relatively new industry, makes its global CLSC be exposed to various types of risks, which leads to inefficiency of supply processes and makes supply chains more complicated and vulnerable. Identifying, evaluating, and analyzing possible risks in CLSC has a great importance for optimization and increasing effectiveness for the global supply chain of used EV battery. Itwill assist to elaborate the efficient CLSC management and possible risk mitigation strategies to keep the global EV battery supply chain resilient and sustainable. This study aims to develop a conceptual framework for risk assessment in this new sector. Therefore, it will populate the framework with possible failure modes identified from various literature on EV battery recycling and closed loop supply chains so that future research can validate and utilize the conceptual framework.

  • PDF

국내 건설경기 변화와 해외건설수주 간의 관계성 분석 (Dynamic Relationship between Domestic Construction Market Condition and Overseas Construction Business)

  • 장세웅
    • 한국건설관리학회논문집
    • /
    • 제15권5호
    • /
    • pp.22-30
    • /
    • 2014
  • 본 논문은 시기별 국내 건설경기 변화와 해외건설수주 간의 관계성을 벡터오차수정모형을 통해 비교분석하는 것을 목적으로 한다. 분석결과 IMF 외환위기 이후에는 주거용 건설경기가 하락할 경우에만, 해외건설시장 진출이 더욱 활발히 나타나는 것으로 확인되었다. 게다가 IMF 외환이기 이전보다 외환위기 이후에는 국내 주거용 건설경기 변화에 즉각적으로 반응하여 해외건설시장 진출 규모가 확대되는 것으로 나타났다. 이와 같은 현상은 국내 건설업체들의 사업 포트폴리오 상 주거용 건설경기에 매우 민감하게 반응할 수밖에 없음에 기인한다. 즉 국내 주택시장 침체는 국내 건설업체의 경영상태에 심각한 영향을 미치게 되고, 이를 긴급히 타개하기 위하여 해외건설시장 진출 규모를 확대한 것으로 판단된다. 본 연구에서 분석을 통해 확인한 바와 같이 주택경기 침체에 따른 건설업체 경영상태 악화를 개선하기 위하여 해외건설시장 진출의 외연적확대는 오히려 건설업체 경영상태를 더욱더 악화시키는 결과를 초래한 것이다. 이에 따라 급박한 상황에서의 사업 전환은 오히려 수익률 확보보다 회사 내 현금흐름 확보를 위한 수단으로 전락할 수도 있기 때문에 전략적 유연성을 확보할 수 있도록 사업 다각화 수준을 지속적으로 일정 범위 안에서 관리할 필요가 있을 것으로 판단된다.

한국의 근대적 대기업 및 기업집단 형성사 - 정부 개입(1960년대와 70년대)을 중심으로 (Historical Essay on the Growth of Modern Big Business Corporations and the Formation of Business Groups in Korea - With the Focus on the Government Intervention)

  • 백광기
    • 산학경영연구
    • /
    • 제17권
    • /
    • pp.27-52
    • /
    • 2004
  • 1960년대와 1970년대에 걸친 한국경제의 성공적 도약과 이에 따른 기업의 성장은 정부의 적극적 개입에 의한 것이다. 이러한 정부주도의 경제성장이 우리나라에서 성공하게 된 이유는 박정희 정권이 효과적인 관료제를 확립하였을 뿐 아니라 수출실적 등과 같은 객관적 기구에 의하여 시장기구 못지않은 기율을 기업들에 실시한데 있다. 1960년대의 기업성장 및 기업집단 형성의 요인들로는 경제개발과정에서의 정부정책사업 및 수출 진흥정책에의 편승에 의한 특혜, 차관도입을 위시한 금융특혜, 공기업의 민영화 및 부실차관기업의 정리, 그리고 월남특수 등을 들 수 있다. 1970년대에는 8.3 사채동결조치, 중화학공업화, 중동건설특수, 종합무역상사제도의 도입 그리고 60년대 정부의 금융지배이후 계속되어오는 금융 및 자본시장에서의 경제적 지대를 기업성장 및 기업집단형성의 요인들로 들 수 있다. 그러나 이러한 특혜에 의한 성장은 기업의 비관련 다각화를 촉진시켰고, 간접금융에 의존하는 악성 기업재무구조를 유도하였고, 재벌중심의 독과점산업구조를 형성시켰다.

  • PDF

Design and Implementation of Secure 3-Tier Web Application with Open Source Software

  • 김창수;유혜인;이용주
    • 디지털산업정보학회논문지
    • /
    • 제6권1호
    • /
    • pp.33-54
    • /
    • 2010
  • Providing a secure 3-tier Web application has become a high priority for companies as e-businesses have increased the amount and the sensitivity of corporate information that can be accessed through the web. Web applications become more difficult to secure with this very increase in online traffic and transactions. This paper first reviews the 3-tier of web application, types of attacks that can threaten web application services and security principles. We then are designing and implementing a secure web application with open source software that able to mitigate the web application vulnerable to attack.

우리 나라 산업재해의 발생 원인 및 특성에 관한 연구 (Characteristics and Causes of Industrial Accidents in Korean Industry)

  • 정병용
    • 산업공학
    • /
    • 제10권2호
    • /
    • pp.99-107
    • /
    • 1997
  • The purpose of accident analysis is to obtain accurate and objective information about the causes of accidents in order to prevent accidents from reoccurring. This study investigated the characteristics and causes of occupational accidents in Korean industry by comparison with those of Japan and U.S.A The results show that there are some characteristics in the accidents of Korean industry; (1)larger companies tend to have lower accident rates than the smaller ones; (2) inexperience is related to high accident rates; (3) 'awkward or sudden movement' and 'caught in and between object' represents the leading accident type; (4) the body sites most vulnerable to injury are the hands and fingers; and (5) 'fractures' is the leading injury type. These findings identified in this study can be used to prevent the industrial accidents.

  • PDF

CRAMM을 이용한 정보시스템 위험관리 - 신용카드회사 사례연구 - (The Risk Management of Information System Using CRAMM - Case of a Korean Credit Card Company -)

  • 김법진;한인구;이상재
    • Asia pacific journal of information systems
    • /
    • 제10권2호
    • /
    • pp.149-176
    • /
    • 2000
  • As companies become more dependent upon information systems(IS), the potential losses of IS resources become critical. IS management must assume the increasing responsibility for protection of IS resources as the IS and business environments become more vulnerable to various threats. The major issues facing management, when attempting to manage risks, include the assessment of the impact of risks on business objectives and the design of security safeguards to reduce the unacceptable risks to an acceptable level. This paper provides a case study of the risk management for IS. A Korean credit card company which has the high sensitivity for customers security was selected as a case. The risk management procedure using a powerful tool, CRAMM(the Central Computer and Telecommunications Agencys Risk Analysis and Management Method) was applied for this company.

  • PDF

A Proposed Framework for the Automated Authorization Testing of Mobile Applications

  • Alghamdi, Ahmed Mohammed;Almarhabi, Khalid
    • International Journal of Computer Science & Network Security
    • /
    • 제21권5호
    • /
    • pp.217-221
    • /
    • 2021
  • Recent studies have indicated that mobile markets harbor applications (apps) that are either malicious or vulnerable, compromising millions of devices. Some studies indicate that 96% of companies' employees have used at least one malicious app. Some app stores do not employ security quality attributes regarding authorization, which is the function of specifying access rights to access control resources. However, well-defined access control policies can prevent mobile apps from being malicious. The problem is that those who oversee app market sites lack the mechanisms necessary to assess mobile app security. Because thousands of apps are constantly being added to or updated on mobile app market sites, these security testing mechanisms must be automated. This paper, therefore, introduces a new mechanism for testing mobile app security, using white-box testing in a way that is compatible with Bring Your Own Device (BYOD) working environments. This framework will benefit end-users, organizations that oversee app markets, and employers who implement the BYOD trend.