• Title/Summary/Keyword: risk scoring

Search Result 158, Processing Time 0.024 seconds

3-Step Security Vulnerability Risk Scoring considering CVE Trends (CVE 동향을 반영한 3-Step 보안 취약점 위험도 스코어링)

  • Jihye, Lim;Jaewoo, Lee
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.27 no.1
    • /
    • pp.87-96
    • /
    • 2023
  • As the number of security vulnerabilities increases yearly, security threats continue to occur, and the vulnerability risk is also important. We devise a security threat score calculation reflecting trends to determine the risk of security vulnerabilities. The three stages considered key elements such as attack type, supplier, vulnerability trend, and current attack methods and techniques. First, it reflects the results of checking the relevance of the attack type, supplier, and CVE. Secondly, it considers the characteristics of the topic group and CVE identified through the LDA algorithm by the Jaccard similarity technique. Third, the latest version of the MITER ATT&CK framework attack method, technology trend, and relevance between CVE are considered. We used the data within overseas sites provide reliable security information to review the usability of the proposed final formula CTRS. The scoring formula makes it possible to fast patch and respond to related information by identifying vulnerabilities with high relevance and risk only with some particular phrase.

Meta-analysis of the Diagnostic Test Accuracy of Pediatric Inpatient Fall Risk Assessment Scales

  • Kim, Eun Joo;Lim, Ji Young;Kim, Geun Myun;Lee, Mi Kyung
    • Child Health Nursing Research
    • /
    • v.25 no.1
    • /
    • pp.56-64
    • /
    • 2019
  • Purpose: This study was conducted to obtain data for the development of an effective fall risk assessment tool for pediatric inpatients through a systematic review and meta-analysis of the diagnostic test accuracy of existing scales. Methods: A literature search using Medline, Science Direct, CINAHL, EMBASE, and the Cochrane Library was performed between March 1 and 31, 2018. Of 890 identified papers, 10 were selected for review. Nine were used in the meta-analysis. Stata version 14.0 was used to create forest plots of sensitivity and specificity. A summary receiver operating characteristic curve was used to compare all diagnostic test accuracies. Results: Four studies used the Humpty Dumpty Falls Scale. The most common items included the patient's diagnoses, use of sedative medications, and mobility. The pooled sensitivity and specificity of the nine studies were .79 and .36, respectively. Conclusion: Considering the low specificity of the pediatric fall risk assessment scales currently available, there is a need to subdivide scoring categories and to minimize items that are evaluated using nurses' subjective judgment alone. Fall risk assessment scales should be incorporated into the electronic medical record system and an automated scoring system should be developed.

Quantitative Cyber Security Scoring System Based on Risk Assessment Model (위험 평가 모델 기반의 정량적 사이버 보안 평가 체계)

  • Kim, Inkyung;Park, Namje
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.29 no.5
    • /
    • pp.1179-1189
    • /
    • 2019
  • Cyber security evaluation is a series of processes that estimate the level of risk of assets and systems through asset analysis, threat analysis and vulnerability analysis and apply appropriate security measures. In order to prepare for increasing cyber attacks, systematic cyber security evaluation is required. Various indicators for measuring cyber security level such as CWSS and CVSS have been developed, but the quantitative method to apply appropriate security measures according to the risk priority through the standardized security evaluation result is insufficient. It is needed that an Scoring system taking into consideration the characteristics of the target assets, the applied environment, and the impact on the assets. In this paper, we propose a quantitative risk assessment model based on the analysis of existing cyber security scoring system and a method for quantification of assessment factors to apply to the established model. The level of qualitative attribute elements required for cyber security evaluation is expressed as a value through security requirement weight by AHP, threat influence, and vulnerability element applying probability. It is expected that the standardized cyber security evaluation system will be established by supplementing the limitations of the quantitative method of applying the statistical data through the proposed method.

Development of Korean Food-Chemical Ranking and Scoring System (Food-CRS-Korea) and Its Application to Prioritizing Food Toxic Chemicals Associated with Environmental Pollutants (환경유래 식품오염물질의 우선순위 선정 기법 (Food-CRS-Korea)의 개발과 적용)

  • Yang, Ji-Yeon;Jang, Ji-Young;Kim, Soo-Hwaun;Kim, Yoon-Kwan;Lee, Hyo-Min;Shin, Dong-Chun;Lim, Young-Wook
    • Environmental Analysis Health and Toxicology
    • /
    • v.25 no.1
    • /
    • pp.41-55
    • /
    • 2010
  • The aims of this study were to develop the suitable "system software" in chemical ranking and scoring (CRS) for the food hazardous chemicals associated with environmental emission and to suggest the priority lists of food contamination by environmental-origined pollutants. Study materials were selected with reference to the priority pollutants list for environment and food management from domestic and foreign research and the number of study materials is 103 pollutants (18 heavy metals, 10 PBTs, 10 EDs, and 65 organic compounds). The Food-CRS-Korea system consisted of the environmental fate model via multimedia, transfer environment to food model, and health risk assessment by contaminated food intake. We have established that health risks of excess cancer risks, hazard quotients (HQs) by chronic toxicity and HQs by reproductive toxicity convert to score, respectively. The creditable scoring system was designed to consider uncertainty of quantitative risk assessment based on VOI (Value-Of-Information). The predictability of the Food-CRS-Korea model was evaluated by comparing the presumable values and the measured ones of the environmental media and foodstuffs. The priority lists based on emissions with background-level-correction are 15 pollutants such as arsenic, cadmium, and etc. The priority lists based on environmental monitoring date are 17 pollutants including DEHP, TCDD, and so on. Consequently, we suggested the priority lists of 13 pollutants by considering the several emission and exposure scenarios. According to the Food-CRS-Korea system, arsenics, cadmium, chromes, DEHP, leads, and nickels have high health risk rates and reliable grades.

Development of Preliminary Assessment Methodology for Priority Listing of Soil and Groundwater Contamination Sources (토양.지하수오염원 관리우선순위 개략평가기법 개발)

  • Jeong, Seung-Woo;Kim, Young-Ju;Kim, Jae-Hoon;Hwang, Sang-Il
    • Journal of Soil and Groundwater Environment
    • /
    • v.16 no.6
    • /
    • pp.106-112
    • /
    • 2011
  • This study developed preliminary assessment methodology for priority listing of soil and groundwater contamination sources, considering source characteristics, local environments and risk receptors. Source characteristics were evaluated by scoring relative risk of contamination sources. Local environments were evaluated by scoring annual rainfall, hydraulic conductivity of aquifer, and annual groundwater use. Risk receptors were evaluated by scoring local population, direct distance to surface water, direct distance to drinking-water wells. Scores of each parameter were allocated by analysing distribution of parameter values obtained from government databases. Distributed scores of source characteristics local environments: risk receptors were 12 : 12 : 12. The preliminary assessment scored 0 to 36 for each soil and groundwater sources. Inventory of soil and groundwater sources consisted of 7 categories. This study applied the preliminary assessment methodology to Manan-Gu, Anyang City, Korea. The number of car repair and washing facility was the largest in the contamination source inventory. Petroleum storage facilities showed the highest assessment score. The preliminary assessment methodology also indicated that Anyang-Dong was the priority section among Anyang-Dong, Suksu-Dong, Bakdal-Dong. This study is the first trial for relative ranking soil and groundwater contamination sources by considering source and local characteristics. Therefore, further researches and revision of the preliminary assessment methodology need to be pursued for various applications.

A Study on Layered Weight Based Vulnerability Impact Assessment Scoring System (계층적 가중 기반의 취약점 영향성 평가 스코어링 시스템에 대한 연구)

  • Kim, Youngjong
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.8 no.7
    • /
    • pp.177-180
    • /
    • 2019
  • A typical vulnerability scoring system is Common Vulnerability Scoring System(CVSS). However, since CVSS does not differentiate among the individual vulnerability impact of the asset and give higher priority for the more important assets, it is impossible to respond effectively and quickly to high-risk vulnerabilities on large systems. We propose a Layered weight based Vulnerability impact assessment Scoring System which can hierarchically group the importance of assets and weight the number of layers and the number of assets to effectively manage the impact of vulnerabilities on a per asset basis.

A study on the risk scoring and risk index for the ecosystem-based fisheries assessment (생태계 기반 어업평가의 위험도 추정에 관한 개선연구)

  • Park, Hee Won;Zhang, Chang Ik;Kwon, You Jung;Seo, Young Il;Oh, Taeg-Yun
    • Journal of the Korean Society of Fisheries and Ocean Technology
    • /
    • v.49 no.4
    • /
    • pp.469-482
    • /
    • 2013
  • This study identified problems of the existing ecosystem-based fisheries assessment approach, and suggested new methods for scoring risk and for the estimation of fishery risk index. First, risk scores of zero to two for target and limit reference points for each indicator were replaced by those of zero to three, and the risk scores were calculated from new formulae which were developed in this study. Second, a new method for estimating fishery risk index (FRI) was developed in this study, considering the level of indicators. New method was applied to the Korean large purse seine fishery, large pair trawl fishery and drag net fishery. More precise and detailed risk scores were obtained from the new method, which can explain the risks by the wider range of both risk levels for 'better than target' and 'beyond limit'. The new method for estimating FRI could avoid the basic problem related with duplicated computations of fishery-level indicators, which improved the estimated FRI to be more accurate. Also, a method for estimating variance of FRI using the bootstrap was proposed in this study.

The Value of Calcium-scoring CT for Ischemic Cardiovascular Disease Screening (허혈성 심혈관 질환 선별을 위한 Calcium-scoring CT의 유용성)

  • Oh, Jung-Hoan;An, Sung-Min
    • Journal of radiological science and technology
    • /
    • v.32 no.1
    • /
    • pp.69-78
    • /
    • 2009
  • The cardiovascular disease has been known as a common cause of death for a long time in the west. The eating habits of Asia, including Korea, have changed recently, so that this disease is also a problem in Asia now. Annual Report on the Cause of Death Statistics from 1996 to 2006 reported that the cardiovascular disease would become the number one cause of death in the next $5{\sim}10$ years. Therefore we realize that more accurate examination is required. The aim of this study was to investigate the accuracy of Calcium-scoring CT and the relationship between risk factor and quantitative scores of Calcium-scoring CT. Through this study we expect that the national public health will be improved. Seventy patients with chest pain were chosen at random. The patients were undergone both coronary CT antigraphy and Calcium - scoring CT at G hospital in Incheon from February 1 to June 30, 2008. The result of the Calcium-scoring CT showed its usefulness for Ischemic cardiovascular disease, with an accuracy similar to that of exercise/pharmacologic stress or ECG when it is difficult for a patient to exercise due to joint problems, aging or for other reasons.

  • PDF

Reliability Evaluation for the Advanced Pressurized water Reactor 1400 (신형경수로 1400을 위한 신뢰성 평가)

  • 강영식
    • Journal of the Korean Society of Safety
    • /
    • v.16 no.3
    • /
    • pp.125-134
    • /
    • 2001
  • The Advanced Pressurized rater Reactor 1400(APR1400) system is advanced of the successful Korean Nuclear Power Plants(KSNP) design which meets functional needs for safety enhancement reliability improvement, and control in the human-computer monitoring system. Therefore this paper describes the scoring model in order to justify the reliability and safety in APR 1400 under uncertainty. The structure of this paper consists of the human engineering, risk safety, quality function, safety organization management factors of the qualitative factors in chapter 2, and the expectation results of the normalized scoring model in chapter 3. Finally, the proposed reliability model have provided the technical flexibility not only for functional control fields but also for accidents protection systems in APR 1400 under uncertainty.

  • PDF