• Title/Summary/Keyword: Web Tools

Search Result 692, Processing Time 0.024 seconds

Event and Command based Fuzzing Method for Verification of Web Browser Vulnerabilities (웹 브라우저 취약성 검증을 위한 이벤트 및 커맨드 기반 퍼징 방법)

  • Park, Seongbin;Kim, Minsoo;Noh, Bong-Nam
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.24 no.3
    • /
    • pp.535-545
    • /
    • 2014
  • As the software industry has developed, the attacks making use of software vulnerability has become a big issue in society. In particular, because the attacks using the vulnerability of web browsers bypass Windows protection mechanism, web browsers can readily be attacked. To protect web browsers against security threat, research on fuzzing has constantly been conducted. However, most existing web browser fuzzing tools use a simple fuzzing technique which randomly mutates DOM tree. Therefore, this paper analyzed existing web browser fuzzing tools and the patterns of their already-known vulnerability to propose an event and command based fuzzing tool which can detect the latest web browser vulnerability more effectively. Three kinds of existing fuzzing tools were compared with the proposed tool. As a result, it was found that the event and command based fuzzing tool proposed was more effective.

WebSHArk 1.0: A Benchmark Collection for Malicious Web Shell Detection

  • Kim, Jinsuk;Yoo, Dong-Hoon;Jang, Heejin;Jeong, Kimoon
    • Journal of Information Processing Systems
    • /
    • v.11 no.2
    • /
    • pp.229-238
    • /
    • 2015
  • Web shells are programs that are written for a specific purpose in Web scripting languages, such as PHP, ASP, ASP.NET, JSP, PERL-CGI, etc. Web shells provide a means to communicate with the server's operating system via the interpreter of the web scripting languages. Hence, web shells can execute OS specific commands over HTTP. Usually, web attacks by malicious users are made by uploading one of these web shells to compromise the target web servers. Though there have been several approaches to detect such malicious web shells, no standard dataset has been built to compare various web shell detection techniques. In this paper, we present a collection of web shell files, WebSHArk 1.0, as a standard dataset for current and future studies in malicious web shell detection. To provide baseline results for future studies and for the improvement of current tools, we also present some benchmark results by scanning the WebSHArk dataset directory with three web shell scanning tools that are publicly available on the Internet. The WebSHArk 1.0 dataset is only available upon request via email to one of the authors, due to security and legal issues.

A Study on Message Acquisition from Electron Apps: Focused on Collaboration Tools such as Jandi, Slack, and Microsoft Teams (Electron App의 메시지 획득 방안에 관한 연구: 협업 툴 잔디, 슬랙, 팀즈 중심으로)

  • Kim, Sung-soo;Lee, Sung-jin
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.32 no.1
    • /
    • pp.11-23
    • /
    • 2022
  • Collaboration tools are used widely as non-face-to-face work increases due to social distancing after COVID-19. The tools are being developed in a cross-platform manner with 'Electron', an open source framework based on Chromium, to ensure accessibility on multiple devices. Electron Apps, applications built with Electron framework, store data in a manner similar to Chromium-based web browsers, so the data can be acquired in the same way as the data is acquired from a web browser. In this paper we analyze the data structure of web storage and suggest a method to get the message from Electron Apps focused on collaboration tools such as Jandi, Slack, and Microsoft Teams. For Jandi, we get the message from Cache by using previously developed tools, and in the case of Slack and Microsoft Teams, we get the message from IndexedDB by using the message carving tool we developed.

Development of Web Based Machining Tool Data System Using XML(eXtensible Markup Language) (XML을 이용한 Web 기반 공구정보 시스템 개발)

  • Kim, Young-Jin;Yang, Yung-Mo
    • IE interfaces
    • /
    • v.16 no.1
    • /
    • pp.8-15
    • /
    • 2003
  • With rapid growth of internet technology, companies have developed an information system such as the electronic catalog for product data in the E-Business. Due to the heuristic nature of the catalog search for proper tools in the specific process, the intelligent and user friendly methods residing in the search process give a comfortable environment even for the beginners in the field. In this paper, we develop a web based catalog for machining tools especially in Milling process. It has two distinct procedures for the users of the catalog; Search and Analysis. The Search is to select a proper cutter, insert, component combination in the developed relational database based on the cutting process and material. The Analysis is to suggest a recommended optimal cutting conditions based on the machining tools and selected materials. All of these procedures are stored in a server with a program based on the ASP and Java Script where the procedure is initiated by the client using the internet which is accessed through insert. With the success on implementing the above engineering database in the internet, we can provide the foundation for developing PDM with heuristic procedure.

The Design and Implementation of RIA-Based DNA Sequence Analysis Tools (RIA 기반 DNA서열 분석도구의 설계 및 구현)

  • Kim, Myung-Gwan;Cho, Choong-Hyo
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.9 no.2
    • /
    • pp.29-36
    • /
    • 2009
  • Due to the progress of Bioinformatics field, We are making use of analyzing tools for effective analyzing enormous data of DNA sequence. But there was inconvenience in existing tools when searching and applying data for analyzing. Our treatise proposes a tool developed by a form based on RIA(Rich Internet Application) that you can solve the problems came from weak points. The analyzing tool for RIA indexing data of DNA sequence shows the results by real time in basis of Web 2.0 which supplemented basis on a form of Web. The web application was developed in Flex2 on Windows workstation.

  • PDF

A Comparison of Ontology Tools Based on OWL (OWL 기반의 온톨로지 도구 비교분석)

  • Ihm, Hyoung-Shin;Hwang, Yun-Young;Eom, Dong-Myuong;Lee, Kyu-Chul
    • Korean Journal of Oriental Medicine
    • /
    • v.12 no.1
    • /
    • pp.1-12
    • /
    • 2006
  • Recently according to the WIPO's policy of preserving traditional knowledge, constructing the database of traditional knowledge is in progress. To maximize the retrieving power of the knowledge resource systems which will be developed later, it is necessary to construct the ontology for the concepts used by traditional knowledge. In order to construct the ontology systematically, a standardized ontology representation method is needed, and OWL(Web Ontology Language) is the recommendation of W3C(World Wide Web Consortium) and is widely used. Ontology tools can be used to ease the construction of OWL ontology, but no research about the comparison of OWL ontology tools exists. This paper compares the tools of OWL by an objective point of view and with that one can make a decision of using the appropriate tool for constructing OWL ontologies.

  • PDF

Web Enabled Expert Systems using Hyperlink-based Inference

  • Yong U. Song;Kim, Wooju;June S. Hong
    • Proceedings of the Korea Inteligent Information System Society Conference
    • /
    • 2003.05a
    • /
    • pp.319-328
    • /
    • 2003
  • With the proliferation of WWW, providing more intelligence to Web sites has become a major concern in e-business industry. In recent days, this trend is more accelerated by prosperity of CRM (Customer Relationship Management) in terms of various aspects such as product recommendation, self after service, etc. To accomplish this goal, many e-companies are eager to embed web enabled rule-based system, that is, expert systems into their Web sites and several well-known commercial tools are already available in the market. Most of those tools are developed based on CGI so far but CGI based systems inherently suffer over-burden problem when there are too many service demands at the same time due to the nature of CGI. To overcome this limitation of the existing CGI based expert systems, we propose a new form of Web-enabled expert system using hyperlink-based inference mechanism. In terms of burden to Web server, our approach is proven to outperform CGI based approach theoretically and also empirically. For practical purpose, our this approach is implemented in a software system, WeBIS and a graphic rule editing methodology, Expert Diagram is incorporated into the system to facilitates rule generation and maintenance. WeBIS is now successfully operated for financial consulting in the web site of a leading financial consulting company in Korea.

  • PDF

Development of a Web-Based Remote Monitoring System for Evaluating Degradation of Machine Tools Using ART2 (ART2 신경회로망을 이용한 공작기계의 웹기반 원격 성능저하 모니터링 시스템 개발)

  • Kim, Cho-Won;Choi, Kook-Jin;Jung, Sung-Hwan;Hong, Dae-Sun
    • Transactions of the Korean Society of Machine Tool Engineers
    • /
    • v.18 no.1
    • /
    • pp.42-49
    • /
    • 2009
  • This study proposes a web-based remote monitoring system for evaluating degradation of machine tools using ART2(Adaptive Resonance Theory 2) neural network. A number of studies on the monitoring of machine tools using neural networks have been reported. However, when normal condition is changed due to factors such as maintenance, tool change etc., or a new failure signal is generated, such algorithms need to be entirely retrained in order to accommodate the new signals. To cope with such problems, this study develops a remote monitoring system using ART2 in which new signals when required are simply added to the classes previously trained. This system can monitor degradation as well as failure of machine tools. To show the effectiveness of the proposed approach, the system is experimentally applied to monitoring a simulator similar to the main spindle of a machine tool, and the results show that the proposed system can be extended to monitoring of real industrial machine tools and equipment.

Comparative Analysis of Web Archiving Tools (웹아카이빙 도구 비교분석 연구)

  • Kim, Heejung
    • Proceedings of the Korean Society for Information Management Conference
    • /
    • 2011.08a
    • /
    • pp.95-98
    • /
    • 2011
  • 디지털 자원의 장기보존을 위한 기법과 전략은 지속적인 관심 속에서 개발되어 오고 있다. 특히, 웹 자원에 대한 의존도가 증폭될수록 웹 아카이빙에 대한 중요성이 커지고 있다. 본 연구에서는 IIPC에서 제시하는 웹 아카이빙 체인의 네 단계에 해당하는 각 단계별 웹 아카이빙 툴과 그 특성을 살펴보았다. 대상이 되는 웹 아카이빙 도구는 총 9개로서, Heritrix, DeepArc, Web Curator Tool, NetarchiveSuite, BnFArcTools, Wayback, NutchWAX, WERA 그리고 Xinq 등이다.

  • PDF

Implementation of a Digital Album (WebAlbum) For Internal Service (인터넷 서비스를 위한 디지털 앨범(WebAlbum))

  • 박상호;박건주;김정규
    • Proceedings of the Korea Multimedia Society Conference
    • /
    • 2004.05a
    • /
    • pp.293-297
    • /
    • 2004
  • Recently, with the spread of digital camera and PC cam, need of tools for display and manipulation of digital images have increased remarkably. These tools are called as digital album. Af now, people want to see picture not alone in home but share with someone else. The purpose of this study is to develop a digital album, which is easy to use, easy to approach and has more function. Therefore people can see picture everywhere he want and management it. If computer is connected In Internet.

  • PDF