• 제목/요약/키워드: abusing

검색결과 69건 처리시간 0.027초

IPv6 주소자동설정 기능을 악용한 서비스거부공격 대응 기법 (A Response Mechanism for Denying DoS Attacks abusing IPv6 Address Auto-configuration)

  • 강성구;김재광;고광선;엄영익
    • 한국정보과학회:학술대회논문집
    • /
    • 한국정보과학회 2004년도 가을 학술발표논문집 Vol.31 No.2 (1)
    • /
    • pp.493-495
    • /
    • 2004
  • IPv6 프로토콜은 현재 인터넷 프로토콜로 사용되고 있는 IPv4 프로토콜이 가지고 있는 주소 고갈 문제, 미흡한 QoS지원, 그리고 다양한 보안 문제를 해결하도록 설계되었다. 이 중에서 이동기기의 원활한 IPv6 네트워크와의 접속을 위하여 IPv6 프로토콜에서는 주소자동설정 기능이 추가되었으나, 이 기능을 악용한 서비스거부 공격 발생 가능성이 존재한다 이에 본 논문에서는 IPv6 프로토콜의 주소자동설정 기능을 악용한 서비스거부공격에 대응할 수 있는 메커니즘으로써 RA 메시지에 일회용 키를 사용하는 방법을 제안한다.

  • PDF

가짜 학술지와 가짜 학술대회의 특성과 피해 방지 방안 (Pseudo-Journals and Pseudo-Conferences: the Characteristics and Preventive Measures)

  • 최인홍
    • 대한신경과학회지
    • /
    • 제36권4호
    • /
    • pp.289-293
    • /
    • 2018
  • This article explains the relationship between open-access publications and pseudo-journals, and explores their characteristics including predatory journals and journal hijackers. Pseudo-journals and pseudo-conferences cause the disruption of academic development by spreading low quality information as well as the violation of research ethics by abusing research funds. Finally, preventive measures are described from the perspective of journal authors/researchers, institutions/funding organizations, and journal editors.

웹 기반 디바이스 핑거프린팅을 이용한 온라인사기 및 어뷰징 탐지기술에 관한 연구 (A Study on Online Fraud and Abusing Detection Technology Using Web-Based Device Fingerprinting)

  • 장석은;박순태;이상준
    • 정보보호학회논문지
    • /
    • 제28권5호
    • /
    • pp.1179-1195
    • /
    • 2018
  • 최근 PC, 태블릿, 스마트폰 등 다중 접속환경을 통하여 웹 서비스에 대한 다양한 공격이 발생하고 있다. 이런 공격은 웹 서비스의 취약점을 통해 온라인 사기거래, 계정의 탈취 및 도용, 부정로그인, 정보 유출 등 여러 가지 후속 피해를 발생시키고 있다. Fraud 공격을 위한 새로운 가짜 계정의 생성, 계정도용 및 다른 이용자 이름 또는 이메일 주소를 사용하면서 IP를 우회하는 방법 등은 비교적 쉬운 공격 방법임에도 불구하고 이런 공격을 탐지하고 차단하는 것은 쉽지 않다. 본 논문에서는 웹 기반의 디바이스 핑거프린팅을 이용하여 웹 서비스에 접근하는 디바이스를 식별하여 관리함으로써 온라인 사기거래 및 어뷰징을 탐지하는 방법에 대해 연구하였다. 특히 디바이스를 식별하고 이를 스코어링 하여 관리는 것을 제안하였다. 제안 방안의 타당성 확보를 위하여 적용 사례를 분석하였고, 온라인 사기의 적극적인 대응과 이용자 계정에 대한 가시성을 확보할 수 있어 다양한 공격에 효과적으로 방어할 수 있음을 증명하였다.

가정폭력과 음주문제의 동시발생 - 피해여성의 경험은 무엇인가? - (Co-occurrence of Domestic Violence and Drinking Problem - What is Experiences of Female Victims? -)

  • 김주현;장수미
    • 한국사회복지학
    • /
    • 제63권2호
    • /
    • pp.291-317
    • /
    • 2011
  • 본 연구는 가정폭력과 음주문제의 동시발생 현상과 그 피해의 심각화 및 만성화에 주목하여 음주문제를 가진 가정폭력배우자로 인해 피해를 당한 여성(이하: 음주폭력피해여성)의 경험을 이해하는 데 목적을 두었다. 이를 위해 10명의 음주폭력피해여성을 대상으로 심층 인터뷰한 후, Giorgi의 현상학적 연구방법을 활용하여 결과를 도출하였다. 연구 결과, 시간성과 관계성을 고려하여 혼전 음주폭력 몰이해단계, 음주폭력 피해와 대처단계, 음주폭력 휴지기단계로 구분할 수 있었다. 혼전 음주폭력 몰이해 단계에서는 상위구성요소로서 '음주폭력문제를 간과함'이 나타났다. 음주폭력 피해와 대처단계에서는 '음주폭력의 악순환에 갇힘'과 '지역사회에서 음주폭력을 다룸'이 도출되었다. 마지막으로 음주폭력 휴지기 단계에서는 '관계 재정립'의 의미가 나타났다. 이와 같은 연구결과에 근거하여 실천적, 정책적 함의를 제안하였다.

  • PDF

The Effect of Franchisors' Gapjil on Economic Satisfaction, Social Satisfaction, and Recontract Intention

  • HUR, Soon-Beom;LEE, Yong-Ki
    • 한국프랜차이즈경영연구
    • /
    • 제12권2호
    • /
    • pp.35-49
    • /
    • 2021
  • Purpose: The major objective of this study is to develop a model for the impact of franchisors' Gapjil (verbal·nonverbal Gapjil, abusing bargaining position, refusing transaction, false or exaggerated information, restrictive practices, unfair damage compensation) on franchisee's recontract intention. We also examine the mediating role of economic satisfaction and social satisfaction in the relationship between franchisors' Gapjil and franchisee's contract intention. Research design, data, and methodology: Data were collected from franchisee owners located nationwide in Korea. Out of 256 questionaires distributed, a total of 256 questionnaires were returned. After excluding 10 invalid respondent questionnaires, we coded and analyzed 246 valid questionnaires (effective response rate of 96.09%) using frequency, confirmatory factor analysis, correlations analysis, and structural equation modeling with SPSS 22.O and SmartPLS 3.0. Results: The findings of this study are summarized as follows: First, among the Gapjil of the franchisors, restrictive practices and unfair damage compensation had negative effects on economic and social satisfaction, but verbal and nonverbal Gapjil for economic and social satisfaction was not significant. Second, abusing bargaining positions and false or exaggerated information had negative effects on social satisfaction, but for economic satisfaction, found to be insignificant. Third, economic and social satisfaction had positive effects on the franchisee's recontract intention to the franchisor. Conclusion: The following implications of this study are as follows. First, the construct of Gapjil that occurs between the franchisors and the franchisees was first presented, and the franchisors' Gapjil is divided into interpersonal Gapjil and structural Gapjil. Second, the Gapjil of the franchisors can be an important predictor variable in maintaining and developing a long-term relationship between the franchisors and the franchisees. Third, solving conflict due to the Gapjil problem between franchisors and franchisees can be an important factor for franchisors and franchisees to co-survive and thrive in Korean franchise system. Fourth, this study suggest that managing the Gapjil of the franchisors was a important antecedent factor in maintaining long-term relationship between the franchisors and the franchisees. Therefore, this study will help franchisors formulate effective symbiotic marketing strategies to satisfy relationships with franchisees and consequently enhance long-term orientation.

신용카드 연체자 분류모형의 성능평가 척도 비교 : 예측률과 유틸리티 중심으로 (Comparison of Performance Measures for Credit-Card Delinquents Classification Models : Measured by Hit Ratio vs. by Utility)

  • 정석훈;서용무
    • Journal of Information Technology Applications and Management
    • /
    • 제15권4호
    • /
    • pp.21-36
    • /
    • 2008
  • As the great disturbance from abusing credit cards in Korea becomes stabilized, credit card companies need to interpret credit-card delinquents classification models from the viewpoint of profit. However, hit ratio which has been used as a measure of goodness of classification models just tells us how much correctly they classified rather than how much profits can be obtained as a result of using classification models. In this research, we tried to develop a new utility-based measure from the viewpoint of profit and then used this new measure to analyze two classification models(Neural Networks and Decision Tree models). We found that the hit ratio of neural model is higher than that of decision tree model, but the utility value of decision tree model is higher than that of neural model. This experiment shows the importance of utility based measure for credit-card delinquents classification models. We expect this new measure will contribute to increasing profits of credit card companies.

  • PDF

Analysis of the Threats abusing IPv6 Fragment Header

  • Zhao, Zhen;Gyeong, Gye-Hyeon;Ko, Kwang-Sun;Eom, Young-Ik
    • 한국정보처리학회:학술대회논문집
    • /
    • 한국정보처리학회 2007년도 춘계학술발표대회
    • /
    • pp.1087-1090
    • /
    • 2007
  • The security issues related to IPv6 protocol have been focused on by many researchers and engineers. Especially, extension headers of IPv6 protocol provide various functionalities such as IP security, mobile IP, and in principle, it is said to give much more effective network services than the previous protocol, IPv4. In this paper, the cases are surveyed in which fragment header, that is one of many extension headers in IPv6 protocol, is abused and made to be the sources of threats. Prevention mechanisms are also surveyed to countermeasure the threats.

  • PDF

SET을 기반으로 한 전자상거래 트랜잭션 모델링에 대한 연구 (A Study on Electronic Commerce Transaction Modeling based on SET)

  • 고영철;송병열;조현규;함호상
    • 한국전자거래학회지
    • /
    • 제2권1호
    • /
    • pp.79-94
    • /
    • 1997
  • Commerce activities which are free form space and time constraint using a communication network are called Electronic Commerce(EC). Because of sending a commercial information using open network such as Internet in EC, they need the security of commerce information (payment information and purchase information), checking the integrity of transferring data and certifying all parts participated in commerce for a secure commerce. Recently Visa and MasterCard Co. released the Secure Electronic Transaction (SET) Protocol for secure payment card transaction on Internet. This paper proposes a Secure Electronic Commerce Transaction Model(SECTM) using SET in order to support the secure commerce on Internet. The proposed transaction model prevents merchant from abusing the cardholder's payment information (credit-card number etc.) and enables cardholder to shop securely in Electronic Shopping Mall.

  • PDF

Updated SSDP Scheme for DDoS Attack Defense

  • Huang, Haiou;Hu, Liang;Chu, Jianfeng
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제12권9호
    • /
    • pp.4599-4617
    • /
    • 2018
  • Abusing the Simple Server Discovery Protocol (SSDP) can induce an SSDP attack (including SSDP DoS, DDoS, DRDoS) posing a significant threat to UPnP devices. Rapid and extensive developments in computer technology, especially in regards to IoT, have made Upnp devices an indispensable part of our daily lives - but also render them susceptible to a variety of SSDP attacks without suitable countermeasures. This paper proposes the Two-dimensional table scheme, which provides high security at a reasonable computational cost. The feasibility and effectiveness of the proposed scheme are also validated by comparison against four other schemes (Stateless connections, Failing-together, Cookie, and Client puzzle).

경쟁우위 전략에서의 기업윤리에 관한 연구 (A Study on Business Ethics of Competitive Superiority Strategy)

  • 임웅석;김형준;이내형
    • 대한안전경영과학회지
    • /
    • 제9권1호
    • /
    • pp.157-174
    • /
    • 2007
  • Corporation had been made by important action rule of business ethics that observes legal standard that is prescribed in each class of administration activity. But it does not keep ethicality of corporation action that conforms law. Law can not include all parts of business ethics because it is forcing essential class for public order preservation and public welfare in right. Moreover, partial corporations are doing to justify unethical action of other evasion of taxes, consultation, manufacturing etc. with legal basis meaning abusing legal standard. For these reason, Insistence that is in point of legal standard and ethical standard is not different each other that is in equal viewpoint is brought.