• Title/Summary/Keyword: Web Databases

Search Result 622, Processing Time 0.026 seconds

A Method for SQL Injection Attack Detection using the Removal of SQL Query Attribute Values (SQL 질의 애트리뷰트 값 제거 방법을 이용한 효과적인 SQL Injection 공격 탐지 방법 연구)

  • Lee, In-Yong;Cho, Jae-Ik;Cho, Kyu-Hyung;Moon, Jong-Sub
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.18 no.5
    • /
    • pp.135-148
    • /
    • 2008
  • The expansion of the internet has made web applications become a part of everyday lift. As a result the number of incidents which exploit web application vulnerabilities are increasing. A large percentage of these incidents are SQL Injection attacks which are a serious security threat to databases with potentially sensitive information. Therefore, much research has been done to detect and prevent these attacks and it resulted in a decline of SQL Injection attacks. However, there are still methods to bypass them and these methods are too complex to implement in real web applications. This paper proposes a simple and effective SQL Query attribute value removal method which uses Static and Dynamic Analysis and evaluates the efficiency through various experiments.

A Design and Implementation of Heterogeneous Metadata Searching System using Ontology (Ontology를 이용한 이종 메타데이터 검색 시스템의 설계 및 구현)

  • Choe, Hyun-Jong;Kim, Tae-Young
    • Journal of The Korean Association of Information Education
    • /
    • v.8 no.3
    • /
    • pp.353-360
    • /
    • 2004
  • World Wide Web is not more meaningless sea of information but is becoming the Semantic Web that provides many users with meaningful information. The starting point is the XML and metadata, RDF is a stopover which gives technique to relate arbitrary web resources. And now, the semantic and logic of web resources can be settled in the Ontology. A lot of educational multimedia web resources in Korea have produced their metadata with KERIS's KEM(Korea Educational Metadata). Therefore our country have to start the study of the semantic and logic in web resources. But, many researchers in Korea are more eager to study Dublin Core's DC and SCORM's LOM metadata specification than KEM. Thus the study of method about sharing and integrating these three metadata specifications should be performed before the study of semantic and logic in web resources in Korea. We design the Ontology to integrate these three metadata specifications and implement the prototype system using this Ontology. These three metadata have some elements that have same labels and meanings, and other elements have different labels and same meanings. To match these different labels which have same meanings, we adapted the one-to-one mapping technique in designing our Ontology. This designed Ontology was imported as "integrated schema" in our prototype searching system to integrate three different metadata in databases. Moreover we know that the more specific property design of class in Ontology was needed in order to provide users with more informed searching results such as synonym, antonym, hierarchy and associations.

  • PDF

XML View Indexing Using an RDBMS based XML Storage System (관계 DBMS 기반 XML 저장시스템 상에서의 XML 뷰 인덱싱)

  • Park Dae-Sung;Kim Young-Sung;Kang Hyunchul
    • Journal of Internet Computing and Services
    • /
    • v.6 no.4
    • /
    • pp.59-73
    • /
    • 2005
  • Caching query results and reusing them in processing of subsequent queries is an important query optimization technique. Materialized view and view indexing are the representative examples of such a technique. The two schemes had received much attention for relational databases, and have been investigated for XML data since XML emerged as the standard for data exchange on the Web. In XML view indexing, XML view xv which is the result of an XML query is represented as an XML view index(XVI), a structure containing the identifiers of xv's underlying XML elements as well as the information on xv. Since XVI for xv stores just the identifiers of the XML elements not the elements themselves, when xv is requested, its XVI should be materialized against xv's underlying XML documents. In this paper, we address the problem of integrating an XML view index management system with an RDBMS based XML storage system. The proposed system was implemented in Java on Windows 2000 Server with each of two different commercial RDBMSs, and used in evaluating performance improvement through XML view indexing as well as its overheads. The experimental results revealed that XML view indexing was very effective with an RDBMS based XML storage system while its overhead was negligible.

  • PDF

Development of a Web-based User Experience Certification System based on User-centered System Design Approach (사용자 중심의 웹 기반 제품 사용경험 인증·평가 시스템 개발)

  • Na, Ju Yeoun;Kim, Jihee;Jung, Sungwook;Lee, Dong Hyun;Lee, Cheol;Bahn, Sangwoo
    • The Journal of Society for e-Business Studies
    • /
    • v.24 no.1
    • /
    • pp.29-48
    • /
    • 2019
  • Recently, product design innovation to improve user experience has been perceived as a core element of enterprise competitiveness due to the fierce market competition and decrease of the technological gap between companies, but there is insufficient services to support the product experience evaluation of small and medium-sized companies (SMCs). The aim of this study is to develop a web-based product user experience evaluation and certification system supporting product design practices for SMCs. For system interface design, we conducted systematic functional requirement elicitation methods such as user survey, workflow analysis, user task definition, and function definition. Then main functions, information structure, navigation method, and detailed graphic user interfaces were developed with consideration of user interactions and requirements. In particular, it provides the databases for evaluation efficiency to support the evaluation process above a certain level of performance and efficiency, and knowledge databases to utilize in the evaluation and product design improvement. With help of the developed service platform, It is expected that the service platform would enhance SMCs' product development capability with regard to the user experience evaluation by connecting the consulting firms with SMCs.

Ontology for Semantic Retrieval of MPEG-7 MDS and TV-Anytime Multimedia Data (멀티미디어 데이터의 의미적 검색을 위한 MPEG-7 MDS 와 TV-Anytime 기반 온톨로지)

  • Song Chull-Hwan;Yoo Seong-Joon
    • Journal of Broadcast Engineering
    • /
    • v.11 no.1 s.30
    • /
    • pp.42-53
    • /
    • 2006
  • This paper describes how to compose multimedia ontology for integrating/searching different types of multimedia databases. For this, we build integrated ontology based on MPEG-7 Multimedia Description Schemes (MDS), which is a representative standard for specifying multimedia contents, and the concept of TV-Anytime and re-express it using Web Ontology Language (OWL). In addition, we explain interoperability of the developed integrated ontology with other types of ontology with different concepts. Lastly, this paper describes the method of semantic search and retrieval using the integrated multimedia ontology.

Internet-based RAMINS II as a Future Communication Framework for AgroMeteorological Information in Asia (아시아 지역 농업기상정보 공유를 위한 인터넷기반 기상정보 연동시스템)

  • Byong-Lyol Lee;G. Ali Kamali;Wang Shili
    • Korean Journal of Agricultural and Forest Meteorology
    • /
    • v.4 no.2
    • /
    • pp.127-132
    • /
    • 2002
  • All the countries in RA II (Asia Region in WMO) welcome the establishment of a Web site dedicated to agricultural meteorology, because it is believed that the best way to improve and speed up the flow of information is the use of the Internet and the establishment of a Web site. In providing recommendation for the promotion and improvement of the AgroMeteorological service in RA II, a couple of key suggestions were proposed: (a) Exchanges of data and AgroMeteorological knowledge between member countries and between RAs, (b) Exchanges of experts between member countries as a necessary way to share the knowledge, and (c) Joint research between member countries to solve common problems in AgroMeteorological affairs. In order to meet the above requirements for RA II, an AgroMeteorological information network will be the most critical and dynamic aspect in sustainable agriculture in this region. In addition, the establishment of a Core AgroMeteorological station, recommended by CAgM of WMO, will require its own information sharing systems for communication among member countries. Inevitable use of information technologies (IT) such as information networks, databases, simulation models, GIS, and RS for regional impact assessment of environmental change on AgroEcosystem will be enforced. Thus, the regional Internet-based Agrometeorological information network has been in place since 1999, though all contributions to it have been volunteered by individuals, institutes, universities, etc.

KAREBrowser: SNP database of Korea Association REsource Project

  • Hong, Chang-Bum;Kim, Young-Jin;Moon, Sang-Hoon;Shin, Young-Ah;Cho, Yoon-Shin;Lee, Jong-Young
    • BMB Reports
    • /
    • v.45 no.1
    • /
    • pp.47-50
    • /
    • 2012
  • The International HapMap Project and the Human Genome Diversity Project (HGDP) provide plentiful resources on human genome information to the public. However, this kind of information is limited because of the small sample size in both databases. A Genome-Wide Association Study has been conducted with 8,842 Korean subjects as a part of the Korea Association Resource (KARE) project. In an effort to build a publicly available browsing system for genome data resulted from large scale KARE GWAS, we developed the KARE browser. This browser provides users with a large amount of single nucleotide polymorphisms (SNPs) information comprising 1.5 million SNPs from population-based cohorts of 8,842 samples. KAREBrowser was based on the generic genome browser (GBrowse), a web-based application tool developed for users to navigate and visualize the genomic features and annotations in an interactive manner. All SNP information and related functions are available at the web site http://ksnp.cdc. go.kr/karebrowser/.

CONSTRUCTION OF ASTRONOMICAL DATABASE BASED ON MySQL AND JSP (MySQL과 JSP를 기반으로 한 관측자료의 데이터베이스화)

  • SUNG HYUN-IL;KIM SANG CHUL;YIM IN SUNG;KIM BONG GYU;AHN YOUNG SUK;NAM HYUN-WOONG;SOHN SANGMO;YANG HONG-JIN
    • Publications of The Korean Astronomical Society
    • /
    • v.19 no.1
    • /
    • pp.109-119
    • /
    • 2004
  • As a core project of the Korean Astronomical Data Center (KADC) in Korea Astronomy Observatory (KAO), we have constructed a framework of astronomical database using MySQL and JSP. MySQL database server is a powerful open source database management system, and JSP technology provides a simplified, fast way to create dynamic web content. Combined together, MySQL and JSP enable us to develop server-independent web-based applications efficiently in a short amount of time. The MySQL tables and JSP programs embedded in our database are built/written in a way to benefit both users and managers. We plan to expand our database by supplementing additional data in the near future. Our newly constructed database is expected to be the prototype of the Korean Virtual Observatory (KVO).

NutriSyn: Knowledge Based Synonym Retrieval Service for Food and Dishes on the Web (NutriSyn(식품어휘지능망): 웹 기반 식품.음식 유의어 지식 구축 및 검색 서비스 구현)

  • Hong, Soon-Myung;Cho, Jee-Ye;Park, Yu-Jeong;Kim, Min-Chan;Kim, Gon
    • Journal of the Korean Dietetic Association
    • /
    • v.15 no.3
    • /
    • pp.286-297
    • /
    • 2009
  • Studies based on food analysis or food databases use the national standard food database. Although Internet information services are increasing gradually, users are only able to get definitive and profitable information using standard food terms. Until now, it has been uncommon to find food retrieval services that include users' regional or historical characteristics. Thus, this study introduces a prototype for Food and Dish Synonym Retrieval (NutriSyn) that includes synonyms and related words. The environments which NutriSyn was implemented were Linux for the server operating system, the Microsoft Windows series for the users' operating system and Apache for a web server. The development languages used are PHP, JavaScript and HTLM with a MySQL database. Users can access NutriSyn using Internet browsers. The main menu items are (1) Food Synonym DB, (2) Dish Synonym DB, (3) Food Information DB, (4) Dish Information DB, and (5) Food and Menu Synonym Retrieval. This system is expected to be a useful tool for food experts and interdisciplinary research.

  • PDF

Design of Environmental Information Systems Architecture Based on the Internet : The Building of a Database for Environmental Factors and GIS (인터넷 환경에 기반한 환경정보시스템 아키텍쳐 설계 : 환경요인을 Database 구축과 이를 이용한 GIS 구축)

  • Suh, Eui-Ho;Lee, Dae-Ho;Yu, Sung-Ho
    • Asia pacific journal of information systems
    • /
    • v.8 no.2
    • /
    • pp.1-18
    • /
    • 1998
  • As the management and preservation of the environment become an important social issue, information required to support environmental task is required. So, there is an increasing demand for environmental information and appropriate systems to manage it. The vast volume of environmental data is distributed in different knowledge domains and systems. Environmental data objects have the complex structure containing environmental quality data and attribute data. Environmental information systems must be able to address these properties. This research has aimed at constructing well-defined schema design of environmental data, and making system architecture that environmental data kept by authorities should be made available to the public user. There are 3 major components in environmental information systems architecture ; User interface, Catalog libraries, Communication Provider. Web browsers provide consistent and intuitive user interfaces on Internet. The communication provider is a collection of diverse CGI functions. The main roles of the CGIs are to build interfaces between the Web, databases. Catalog libraries is libraries of various matadata including administration matadata. Administration matadata support the environmental administration and the managerial aspects of environmental data rather than explain a database itself or its properties.

  • PDF