• 제목/요약/키워드: event study

검색결과 4,880건 처리시간 0.031초

윈도우 이벤트 로그 기반 기업 보안 감사 및 악성코드 행위 탐지 연구 (Study on Windows Event Log-Based Corporate Security Audit and Malware Detection)

  • 강세림;김소람;박명서;김종성
    • 정보보호학회논문지
    • /
    • 제28권3호
    • /
    • pp.591-603
    • /
    • 2018
  • 윈도우 이벤트 로그는 윈도우 운영체제에서 시스템 로그를 기록하는 형식이며, 시스템 운영에 대한 정보를 체계적으로 관리한다. 이벤트는 시스템 자체 또는 사용자의 특정 행위로 인해 발생할 수 있고, 특정 이벤트 로그는 기업 보안 감사, 악성코드 탐지 등에 사용될 수 있다. 본 논문에서는 기업 보안 감사 및 악성코드 탐지와 관련된 이벤트 로그(외부장치 연결, 응용 프로그램 설치, 공유 폴더 사용, 프린터 사용, 원격 연결/해제, PC 시작/종료, 로그온/오프, 절전모드, 네트워크 연결/해제, 이벤트 로그 삭제, 시스템 시간 변경, 파일/레지스트리 조작, 프로세스 생성, DNS 질의, 윈도우 서비스 추가)들을 선정하고, 발생하는 이벤트 ID를 분류 및 분석하였다. 또한, 기존의 이벤트 로그 분석도구는 EVTX 파싱 기능만을 포함하고 있어 이를 포렌식 수사에 이용할 경우 사용자의 행적을 추적하기 어렵다. 이에 본 연구에서 새로운 분석도구를 구현하였으며, EVTX 파싱과 행위 분석이 가능하다.

복합 이벤트 처리기술을 적용한 효율적 재해경보 전파에 관한 연구 (A study on the efficient early warning method using complex event processing (CEP) technique)

  • 김형우;김구수;장성봉
    • 한국정보통신설비학회:학술대회논문집
    • /
    • 한국정보통신설비학회 2009년도 정보통신설비 학술대회
    • /
    • pp.157-161
    • /
    • 2009
  • In recent years, there is a remarkable progress in ICTs (Information and Communication Technologies), and then many attempts to apply ICTs to other industries are being made. In the field of disaster managements, ICTs such as RFID (Radio Frequency IDentification) and USN (Ubiquitous Sensor Network) are used to provide safe environments. Actually, various types of early warning systems using USN are now widely used to monitor natural disasters such as floods, landslides and earthquakes, and also to detect human-caused disasters such as fires, explosions and collapses. These early warning systems issue alarms rapidly when a disaster is detected or an event exceeds prescribed thresholds, and furthermore deliver alarm messages to disaster managers and citizens. In general, these systems consist of a number of various sensors and measure real-time stream data, which requires an efficient and rapid data processing technique. In this study, an event-driven architecture (EDA) is presented to collect event effectively and to provide an alert rapidly. A publish/subscribe event processing method to process simple event is introduced. Additionally, a complex event processing (CEP) technique is introduced to process complex data from various sensors and to provide prompt and reasonable decision supports when many disasters happen simultaneously. A basic concept of CEP technique is presented and the advantages of the technique in disaster management are also discussed. Then, how the main processing methods of CEP such as aggregation, correlation, and filtering can be applied to disaster management is considered. Finally, an example of flood forecasting and early alarm system in which CEP is incorporated is presented It is found that the CEP based on the EDA will provide an efficient early warning method when disaster happens.

  • PDF

The Influence of Event Quality on Brand Value, Satisfaction and Recommend Intention as perceived by Local Food Event Participants: Case of Miderdok Festival in Changwon Province

  • Kang, Hee-Seog;Park, Jeong-Mee;Lee, Sang-Mook
    • 한국조리학회지
    • /
    • 제23권6호
    • /
    • pp.135-142
    • /
    • 2017
  • The purpose of current study was to identify the influence of event quality on brand value, satisfaction, and recommend intention as perceived by a local food festival participants. Survey was distributed to the Changwon Miderdok festival participants, 350 questionnaire surveys were distributed and 330 participants were employed for statistical analysis with erasing invalid responses. Based on the process of hypothesis verification on the formulated model, it suggested that motivation factors have significantly impact on evolvement element. Specifically, humanic and physical elements were significant predictors of both brand value and satisfaction, and all factors of event quality except convenience were critical antecedents of visitors' satisfaction. In current study, in addition, brand value has positive influence on satisfaction and satisfied visitors tried to recommend the destination to others. This study will help to develop meaningful marketing strategy for local food festival industry. Furthermore, this study will contribute to improve an attractive business model to increase profit for both local society and academic study related to local food festival.

국적항공사 판매촉진이벤트의 서비스품질과 만족도 연구 (A Study on the Between Service Quality of National Airline Sales Promotion Event and Customer Satisfaction)

  • 윤선영
    • 한국항행학회논문지
    • /
    • 제13권4호
    • /
    • pp.566-576
    • /
    • 2009
  • 본 논문은 국적항공사에서 경쟁적 차별화의 방안으로 고객들에게 다양한 판매촉진이벤트를 제공함에 있어 이에 대한 서비스품질과 고객만족 그리고 행동의도와의 관계검증에 그 목적이 있다. 분석결과 항공사 판매촉진이벤트의 경우, 서비스품질의 품질차원보다 서비스품질의 경험차원에서 고객의 만족과 행동의도 간에 더 큰 영향을 미치는 것으로 나타났다. 세부적인 가설에 대한 분석결과, 서비스품질 경험차원 중 가치추구, 실용성, 정보혜택에서 큰 영향을 미치는 것으로 나타났다. 그리고 항공사 판매촉진이벤트에 대한 고객만족이 높을수록 행동의도도 높아지는 것으로 나타났다.

  • PDF

효율적인 이벤트 큐의 구조에 관한 연구 (A Study on the Structures for Efficient Event Queues)

  • 김상욱
    • 한국시뮬레이션학회논문지
    • /
    • 제4권2호
    • /
    • pp.61-68
    • /
    • 1995
  • The performance of event-driven logic simulation frequently used for VLSI design verification depends on the data structures for event queues. This paper improves the existing Timing Wheel as a data structure for an event queue. In case of the use of B+ tree, an efficient node degree is also presented based on the experiment results. A new Timing Wheel index structure, which eliminates the insertion and deletion overhead of B+ tree, is proposed and analyzed.

  • PDF

중련편성 열차를 위한 효율적인 사건기록기 운영방안 (Effective event recorder operation method for multi-coupled trainset)

  • 최권희;정병호;민평오;오용석;이종우
    • 한국철도학회:학술대회논문집
    • /
    • 한국철도학회 2007년도 추계학술대회 논문집
    • /
    • pp.1428-1432
    • /
    • 2007
  • One of the most important targets of transportation is to transport human and commodities to the destination safely. Railway has low risk, compared with land, ocean and flight route and it assures high security as well as high speed driving, since it runs on regular track. However, train accident may result in tragic accident due to small carelessness, so special event recorder is preferably used in order for clarity of responsibility in case of accident, maintenance of signal device and defect analysis. JRU(Juridical Recorder Unit) for ATC/ATS/ATP can be more advanced event recorder. Event recorder of KTX-I which is running now is installed one by one on each leading car and last car, and operation plan of event recorder in case of single trainset is suggested. But regarding train operation of multi-coupled trainset operation such as KTX-II, more detailed study is required for event recorder revitalization and record data process method. Therefore, this research aims at operation plan used in existing event recorder, and suggests effective operation and management plan of event recorder in multi-coupled trainset such as new High Speed Train.

  • PDF

FLB Event Analysis with regard to the Fuel Failure

  • Baek, Seung-Su;Lee, Byung-Il;Lee, Gyu-Cheon;Kim, Hee-Cheol;Lee, Sang-Keun
    • 한국원자력학회:학술대회논문집
    • /
    • 한국원자력학회 1996년도 춘계학술발표회논문집(2)
    • /
    • pp.622-627
    • /
    • 1996
  • Detailed analysis of Feedwater Line Break (FLB) event for the fuel failure point of view are lack because the event was characterized as the increase in reactor coolant system (RCS) pressure. Up to now, the potential of the rapid system heatup case has been emphasized and comprehensively studied. The cooldown effects of FLB event is considered to be bounded by the Steam Line Break (SLB) event since the cooldown effect of SLB event is larger than that of the FLB event. This analysis provides a new possible path which can cause the fuel failure. The new path means that the fuel failure can occur under the heatup scenario because the Pressurizer Safety Valves (PSVs) open before the reactor trips. The 1000 MWe typical C-E plant FLB event assuming Loss of Offsite Power (LOOP) at the turbine trip has been analyzed as an example and the results show less than 1% of the fuel failure. The result is well within the acceptance criteria. In addition to that, a study was accomplished to prevent the fuel failure for the heatup scenario case as an example. It is found that giving the proper pressure gap between High Pressurizer Pressure Trip (HPPT) analysis setpoint and the minimum PSV opening pressure could prevent the fuel failure.

  • PDF

A Study on Reversals after Stock Price Shock in the Korean Distribution Industry

  • Jeong-Hwan, LEE;Su-Kyu, PARK;Sam-Ho, SON
    • 유통과학연구
    • /
    • 제21권3호
    • /
    • pp.93-100
    • /
    • 2023
  • Purpose: The purpose of this paper is to confirm whether stocks belonging to the distribution industry in Korea have reversals, following large daily stock price changes accompanied by large trading volumes. Research design, data, and methodology: We examined whether there were reversals after the event date when large-scale stock price changes appeared for the entire sample of distribution-related companies listed on the Korea Composite Stock Price Index from January 2004 to July 2022. In addition, we reviewed whether the reversals differed depending on abnormal trading volume on the event date. Using multiple regression analysis, we tested whether high trading volume had a significant effect on the cumulative rate of return after the event date. Results: Reversals were confirmed after the stock price shock in the Korean distribution industry and the return after the event date varied depending on the size of the trading volume on the event day. In addition, even after considering both company-specific and event-specific factors, the trading volume on the event day was found to have significant explanatory power on the cumulative rate of return after the event date. Conclusions: Reversals identified in this paper can be used as a useful tool for establishing a trading strategy.

시뮬레이션을 이용한 EPCIS의 효율화 방안에 관한 연구 (A Study on the Efficiency of the EPCIS using Simulation)

  • 이종석;이창호
    • 대한안전경영과학회:학술대회논문집
    • /
    • 대한안전경영과학회 2010년도 추계학술대회
    • /
    • pp.349-355
    • /
    • 2010
  • EPCIS(EPC Information Services) system is a core component of EPCglobal Architecture Framework offering information of the freights, the time of awareness and the location of awareness on the EPCglobal Network. The role of EPCIS is to exchange information based on EPC. There are four kinds of event data which are object event data, aggregation event data, quantity event data, and transaction event data. These EPCIS events data are stored and managed in EPCIS repository. This paper leads to separate a in-out data overload of integrated EPCIS event and suggests the method to effectively manage EPCIS repository for exchanging data smoothly. In order to verify a effectiveness, we measure the performance of the system using a simple testing simulation by comparing existing method and suggested method.

  • PDF

황사시와 비황사시 대기 입자상 탄소성분의 농도 특성 (Concentration Characteristics of Elemental and Organic Carbons During Asian Dust Episode and Non-Episode)

  • 황경철;조기철;신은상
    • 환경위생공학
    • /
    • 제24권4호
    • /
    • pp.102-111
    • /
    • 2009
  • In this study, Particulate carbon were determined from 1990 to 1995. The annual variation were investigated. The sampling was carried out using high volume air sampler. Average concentrations of EC and OC during the yellow sand event were $25.70{\mu}g/m^3$ and $13.91{\mu}g/m^3$, respectively, $22.10{\mu}g/m^3$ and $10.33{\mu}g/m^3$ during the non-yellow sand event. TC concentration of TSP were 10.7% during the yellow sand event and 20.6% during the non-yellow sand event. Average concentration rate of EC and OC of TC were 64.9% and 35.1%, respectively during the yellow sand event, 67.6% and 32.4% during the non-yellow sand event.