• 제목/요약/키워드: intercepted

검색결과 124건 처리시간 0.025초

BOZ-PAD 방법을 사용하는 블록암호 기반 CBC|CBC 이중 모드에 대한 패딩 오라클 공격 (Padding Oracle Attack on Block Cipher with CBC|CBC-Double Mode of Operation using the BOZ-PAD)

  • 황성진;이창훈
    • 한국전자거래학회지
    • /
    • 제20권1호
    • /
    • pp.89-97
    • /
    • 2015
  • 최근 개인정보 관련 사고들이 빈번하게 발생함에 따라 전자거래나 응용 환경의 개인 정보 및 민감한 정보들의 안전성에 대한 관심이 높아졌다. 인터넷 환경에서 데이터나 정보를 안전하게 보호하기 위해서 안전한 암호 알고리즘을 사용한다. 하지만 암호 적용방식이 올바르지 않으면 악의를 가진 공격으로부터 안전하지 않을 수 있다는 것이 연구 결과와 방법들로 소개되고 있다. 본 논문에서는 다양한 공격 방법들 중 CBC|CBC 모드에서 BOZ-PAD 방법을 사용하는 환경에 대해 패딩 오라클 공격을 적용한 결과를 소개한다.

Enhancing the Security of Credit Card Transaction based on Visual DSC

  • Wei, Kuo-Jui;Lee, Jung-San;Chen, Shin-Jen
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제9권3호
    • /
    • pp.1231-1245
    • /
    • 2015
  • People have transferred their business model from traditional commerce to e-commerce in recent decades. Both shopping and payment can be completed through the Internet and bring convenience to consumers and business opportunities to industry. These trade techniques are mostly set up based on the Secure Sockets Layer (SSL). SSL provides the security for transaction information and is easy to set up, which makes it is widely accepted by individuals. Although attackers cannot obtain the real content even when the transferred information is intercepted, still there is risk for online trade. For example, it is impossible to prevent credit card information from being stolen by virtual merchant. Therefore, we propose a new mechanism to solve such security problem. We make use of the disposable dynamic security code (DSC) to replace traditional card security code. So even attackers get DSC for that round of transaction, they cannot use it for the next time. Besides, we apply visual secret sharing techniques to transfer the DSC, so that interceptors cannot retrieve the real DSC even for one round of trade. This way, we can improve security of credit card transaction and reliability of online business. The experiments results validate the applicability and efficiency of the proposed mechanism.

합류식 하수관거 지역에서 강우시 하수처리장 적정운영방안에 관한 연구 (Alternatives for The Stable Operation of Wastewater Treatment Plant in Combined Sewer System during Wet Weather)

  • 이두진;신응배;홍철의;안세영
    • 한국물환경학회지
    • /
    • 제20권2호
    • /
    • pp.132-144
    • /
    • 2004
  • The purpose of this study was to evaluate alternatives for stable operation of WWTP(Wastewater Treatment Plant) with a higher rate of inflows and a higher concentration of pollutants during wet weather to minimize the pollution loads being discharged into receiving waters. 3Q(Q: dry weather flow) of a base flow is normally intercepted and flows into WWTP as it was current practice. It is revealed by simulation that the bypassing alternative of 1Q through secondary treatment and 2Q into the stream after primary treatment was as good as it is expected. The bypass pollution loads were in the range of 23.9 ~ 38.5 % of the total loads flowing into the WWTP indicating that the bypassed flows need an extra treatment such as stormwater detention reservoir, high-rate coagulation with sedimentation, and step-feed. The high-rate coagulation with sedimentation was the most effective with respect to removal of the pollution loads.

급경사 국지도로에서의 횡유입부 설계 방법 (The Design Method of Transverse Grate Inlets on Steep Local Road)

  • 김재권;김정수;이준호;윤세의
    • 한국방재학회:학술대회논문집
    • /
    • 한국방재학회 2007년도 정기총회 및 학술발표대회
    • /
    • pp.195-198
    • /
    • 2007
  • The type, the length, and the install space of the grate inlets in main street were designed with the consideration of discharge calculated with street surface rainfall. However, the discharge that was not intercepted at transverse grate inlets in steep local roads increases inundation areas around main street Therefore, it is necessary to analyze the flow characteristics and interception capacity at transverse grate inlets in steep local roads. Hydraulic experimental apparatus which can be changed the longitudinal slopes($2{\sim}10%$) of street, the size ($20{\sim}50cm$) and the types(TYPE I, II) of grate inlet was installed for this study. The range of the experimental discharges were from $2{\ell}/sec$ to $24{\ell}/sec$. The interception discharges of transverse grate inlets per unit width changing the longitudinal slope of steep local road were calculated by the hydraulic experimental results. The design method of transverse grate inlets was developed by the interception discharges per unit width. This design method was applied to decide the space and size of transverse grate inlets.

  • PDF

약사에 의해 탐지된 항암제 처방오류 분석 (Analysis of Chemotherapy Prescribing Errors Detected by Pharmacists)

  • 이현주;양미경;조주희;김성은;석현주;김현아
    • 한국임상약학회지
    • /
    • 제20권2호
    • /
    • pp.120-127
    • /
    • 2010
  • Objective: The purpose of this study was to identify the type and frequency of chemotherapy-related prescribing errors and assess the pharmacist intervention in preventing potential harm. Methods: This study was performed in satellite pharmacy of oncology/hematology unit in tertiary teaching hospital from April to September, 2009. All chemotherapy prescribing errors detected by pharmacists were recorded. Frequency and characteristics of prescribing errors were analyzed. Pharmacists reviewed 28, 495 chemotherapy orders from 12,719 patients during 6-month periods. Results: A total of 835 prescription errors (2.93%) in 734 patients (5.77%) were detected by pharmacists. Alkylating agents (37.6%) followed by antimetabolite (23.35%), and mitotic inhibitors (21.44%) were the most prevalent classes in which errors occurs. The most common types of error detected were incorrect dose (34%), incorrect solution (33%), incorrect route (9%) and omission errors (8%). Changes in chemotherapy order due to pharmacists' intervention occurred in all error cases. Conclusion: Pharmacists' intervention in reviewing chemotherapy and drug orders intercepted potential harm due to prescribing errors. The current study provided strategies for reduction of medication errors.

강우시 합류식 하수관거의 유출특성 분석 (Analysis of Storm Water Run-off Characteristics during Wet Weather)

  • 최성현;최승철;박은영;임재명
    • 산업기술연구
    • /
    • 제22권B호
    • /
    • pp.95-101
    • /
    • 2002
  • Much of domestic city is served by combined sewer system rather than separate sanitary or storm sewers. During wet weather, when the volume of sanitary sewage and storm water entering the combined sewers exceeds the system capacity, the system is designed to overflow at several designated CSOs. The objective of this research is to have grasp of characteristics of combined sewer runoff and to evaluate efficiently the intercepted volume of CSOs. During the wet weather in first rainfall, SS load at each site H-1, H-2, and H-3 were 600kg/event, 370kg/event, and 289kg/event, SS load at each site in second rainfall were 216kg/event, 113kg/event, and 37.2kg/event. EMCs at each site were 702mg/L, 816mg/L, 861mg/L in first rainfall and 99.9mg/L, 161.9mg/L, 103.6mg/L in second rainfall, respectively. First flush coefficients b at each site were 0.237, 0.166, and 0.151.

  • PDF

하천생태계와 경관복원을 위한 도시소하천의 유지유량확보에 관한 연구 - 울산 무거천을 중심으로 - (A Study on Securing Instream Flow for Restoring Ecosystems and Riverine Aesthetics of a Degraded Urban Stream - Applied to the Mugeo Stream in the Ulsan Metropolitan Area -)

  • 이수식
    • 한국환경과학회지
    • /
    • 제16권5호
    • /
    • pp.649-655
    • /
    • 2007
  • This study was focused on estimating instream flow, and its optimal alternative for securing the required total amount of instream flow was also researched in order to restore ecosystems and riverine aesthetics of the Mugeo Stream. the first tributary of the Taewha River flowing through the center of Ulsan. In this study the hydraulic and hydrologic conditions and water quality were investigated at specific channel reaches and representative stations of the Mugeo Stream to determine a proper estimate of instream flow. And riverine functions, such as the minimum flow, water duality conservation, fish habitat, and recreation, were considered to restore the environmental functions of the stream, As a result, the total amount of $11,500m^3/day$ was set as the target instream flow for the Mugeo Stream. It was chosen as the optimal alternative for securing the total external supply of $10,000m^3/day$ which have to be transfered from the riverbed flow diverted through the Taewha Main river at upstream of Samho bridge. The water duality throughout the Mugeo Stream channels will be improved considerably to 3-4 mg/l of BOD standard if the target instream flow is supplied and sewage is intercepted by the sanitary sewage system.

수입재해충 나무좀류의 분류 I. 나무좀과와 긴나무좀과 (Classification of the Scolytidae and Platypodidae Intercepted From Imported Timbers I.)

  • 추호열;우건석;김병호
    • 한국응용곤충학회지
    • /
    • 제20권4호
    • /
    • pp.196-206
    • /
    • 1981
  • 국립식물검역소 인천지소에 소장중인 수입원목해충 중 나무좀류를 동정한 결과 다음과 같이 나무좀과에서 2 아과 6속 14종이 긴 나무좀에서 2아과 2속 11종이 확인되었다. Scolytidae Ipinae Arixyleborus granulifer A. rugosipes Xyleborus posticepilosus X. similis X. subcostatus Ips pini I. plastographus I. tridens Trypodendron lineatum Hylesininae Dendroctonus adjunctus D. brevicomis D. frontalis D. ponderosae Hylurgops porosus Platypodidae Platypodinae Platypus agnatus P. biuncus P. curtus P. geminatus P. jansoni P. maritimus P. pseudocupulatus pseudocupulatus P. shoreanus bifurcus P. solidus Diaporinae Diapus pendleburyi D. pusillimus.

  • PDF

A SECURITY ARCHITECTURE FOR THE INTERNET OF THINGS

  • Behrens, Reinhard;Ahmed, Ali
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제11권12호
    • /
    • pp.6092-6115
    • /
    • 2017
  • This paper demonstrates a case for an end-to-end pure Application Security Layer for reliable and confidential communications within an Internet of Things (IoT) constrained environment. To provide a secure key exchange and to setup a secure data connection, Transport Layer Security (TLS) is used, which provides native protection against replay attacks. TLS along with digital signature can be used to achieve non-repudiation within app-to-app communications. This paper studies the use of TLS over the JavaScript Object Notation (JSON) via a The Constrained Application Protocol (CoAP) RESTful service to verify the hypothesis that in this way one can provide end-to-end communication flexibility and potentially retain identity information for repudiation. As a proof of concept, a prototype has been developed to simulate an IoT software client with the capability of hosting a CoAP RESTful service. The prototype studies data requests via a network client establishing a TLS over JSON session using a hosted CoAP RESTful service. To prove reputability and integrity of TLS JSON messages, JSON messages was intercepted and verified against simulated MITM attacks. The experimental results confirm that TLS over JSON works as hypothesised.

Seismic design rules for ductile Eurocode-compliant two-storey X concentrically braced frames

  • Costanzo, Silvia;D'Aniello, Mario;Landolfo, Raffaele
    • Steel and Composite Structures
    • /
    • 제36권3호
    • /
    • pp.273-291
    • /
    • 2020
  • Two-storey X-bracings are currently very popular in European practice, as respect to chevron and simple X bracings, owing to the advantages of reducing the bending demand in the brace-intercepted beams in V and inverted-V configurations and optimizing the design of gusset plate connections. However, rules for two-storey X braced frames are not clearly specified within current version of EN1998-1, thus leading to different interpretations of the code by designers. The research presented in this paper is addressed at investigating the seismic behaviour of two-storey X concentrically braced frames in order to revise the design rules within EN1998-1. Therefore, five different design criteria are discussed, and their effectiveness is investigated. With this aim, a comprehensive numerical parametric study is carried out considering a set of planar frames extracted from a set of structural archetypes that are representative of regular low, medium and high-rise buildings. The obtained results show that the proposed design criteria ensure satisfactory seismic performance.