• Title/Summary/Keyword: Preliminary Security Assessment

Search Result 12, Processing Time 0.028 seconds

A Study for Effectiveness of Preliminary Security Assessment on Online Game Service Domain (온라인게임 서비스 분야에 정보보호 사전진단 적용시 효과성에 관한 연구)

  • Yoo, Dong-Young;Seo, Dong-Nam;Kim, Huy-Kang;Choi, Jin-Young
    • Journal of Information Technology Services
    • /
    • v.10 no.2
    • /
    • pp.293-308
    • /
    • 2011
  • The preliminary security assessment is an information security process to analyze security weaknesses before beginning of services. Discovering security weakness through preliminary security assessment is highly required because it costs much when security incident occur in the middle of service operation. However, this assessment is not widely spread in the online game service domain yet. In this paper, we summarize the security risk existed in the online game service, and we classify the security requirements related to the each risk. Also, through the case study, we evaluated the effectiveness of preliminary security assessment in this domain. In addition, we suggest checklists that should be reviewed once in game-client side, network-side and game-server side for the purpose of security enhancement.

A Basic Study on the Checklists for Crime Risk Assessment in Physical Environment of the Pedestrian Passage at Residential Area (주거지역 소규모 보행로의 물리적 환경을 대상으로 한 범죄 위험도 평가 체크리스트에 관한 기초 연구)

  • Lee, You-Mi;Park, Hyeon-Ho;Kang, Boo-Seong;Sung, Gi-Ho;Lim, Dong-Hyun
    • KIEAE Journal
    • /
    • v.16 no.3
    • /
    • pp.47-55
    • /
    • 2016
  • Purpose: This study was aimed at providing the basic checklist as a means to assess the crime risk in physical environment of the pedestrian passage at residential area. Method: For this purpose, the preliminary checklists were selected according to the review of the precedent studies of checklists in exterior pedestrian passage. The usefulness and the importance of the preliminary checklists were analyzed through the seven expert group meetings, the 87 questionnaires survey of the crime experts & the architectural/urban experts, preliminary assessment and field survey. Results: The assessment categories of checklists were sorted into six types, i.e. spatial structure & function, lighting, landscaping, security facilities, other facilities and cleaning & maintenance. The 49 checklists were proposed according to the assessment categories. The final checklists were divided key checklists and general checklists based on the results of experts' weighting of each list item. There were significant differences between crime experts' weighting and architectural/urban experts' weighting in several checklists, i.e. dividing between pavements and streets, the brightness of light, white light.

A Study on Web Vulnerability Risk Assessment Model Based on Attack Results: Focused on Cyber Kill Chain (공격 결과 기반의 웹 취약점 위험도 평가 모델 연구: 사이버 킬체인 중심으로)

  • Jin, Hui Hun;Kim, Huy Kang
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.31 no.4
    • /
    • pp.779-791
    • /
    • 2021
  • Common web services have been continuously targeted by hackers due to an access control policy that must be allowed to an unspecified number of people. In order to cope with this situation, companies regularly check web vulnerabilities and take measures according to the risk of discovered vulnerabilities. The risk of these web vulnerabilities is calculated through preliminary statistics and self-evaluation of domestic and foreign related organizations. However, unlike static diagnosis such as security setting and source code, web vulnerability check is performed through dynamic diagnosis. Even with the same vulnerability item, various attack results can be derived, and the degree of risk may vary depending on the subject of diagnosis and the environment. In this respect, the predefined risk level may be different from that of the actual vulnerability. In this paper, to improve this point, we present a web vulnerability risk assessment model based on the attack result centering on the cyber kill chain.

A Study on Construction of Disaster Management System at a Large-scale Concert (대형공연 시 재난관리시스템의 구축에 관한 연구)

  • Min, Se Hong
    • Journal of the Korea Safety Management & Science
    • /
    • v.15 no.4
    • /
    • pp.17-24
    • /
    • 2013
  • On this study, we extracted pending problem and controversial point from management of disaster such as terror for domestic massive performance and then, investigated countermeasure plan against disaster for massive performance through comparison and analysis between anti-disaster strategy of Korea and U.S. U.S are conducting security system actively for passenger of major facilities such as public institution. Nonetheless, In U.S that has the world's best security system, serious affair such as 911 terror and Boston marathon terror are continued to happen. When considering domestic situation that North Korea and South Korea are antagonistic to each other, it is judged when it is high time to prepare for threat of terrorism. Accordingly, On this study, through analyzing of latest terror attacks in U.S and disaster risk in the nation, we analyzed in detail countermeasure plan classified as legislation, operation of security system, instilling a sense. As the result of this analyzing, using by flow-chart, we suggested domestic optimized disaster management system for massive performance. Consequently, we propose to establish systematized disaster management system such as preliminary survey of disaster influence for massive performance.

Improvement of the Administration System of Customs Payments in the Modern Conditions

  • Mishina, Natalya V.;Kuzminov, Vitaly A.;Kuzminova, Olga A.;Konovalova, Elena E.;Gubanova, Natalia V.
    • International Journal of Computer Science & Network Security
    • /
    • v.22 no.10
    • /
    • pp.347-351
    • /
    • 2022
  • The article is devoted to the formation of approaches to improving the system of administration of customs payments in modern conditions. It is established that important components of the administration of customs payments are customs expertise, customs value assessment, and control over the declaration of goods to ensure the completeness and timeliness of customs duties payments to the budget. It is found that the practice of customs administration shifts the emphasis of foreign trade regulation to the use of the principles of work implying the use of the latest technologies for the preliminary electronic exchange of information, remote customs clearance of goods without the physical presence of an official, and consistent application of risk management. It is established that an important place in the structure of the state authorities regulating the foreign economic activity is given to the customs service. Furthermore, the existing problems in the implementation of international trade operations necessitate the improvement of approaches to the customs regulation of export-import activities of enterprises.

Preliminary Selection of Safety-Relevant Radionuclides for Long-Term Safety Assessment of Deep Geological Disposal of Spent Nuclear Fuel in South Korea

  • Kyu Jung Choi;Shin Sung Oh;Ser Gi Hong
    • Journal of Nuclear Fuel Cycle and Waste Technology(JNFCWT)
    • /
    • v.21 no.4
    • /
    • pp.451-463
    • /
    • 2023
  • With South Korea increasingly focusing on nuclear energy, the management of spent nuclear fuel has attracted considerable attention in South Korea. This study established a novel procedure for selecting safety-relevant radionuclides for long-term safety assessments of a deep geological repository in South Korea. Statistical evaluations were performed to identify the design basis reference spent nuclear fuels and evaluate the source term for up to one million years. Safety-relevant radionuclides were determined based on the half-life criteria, the projected activities for the design basis reference spent nuclear fuel, and the annual limit of ingestion set by the Nuclear Safety and Security Commission Notification No. 2019-10 without considering their chemical and hydrogeological properties. The proposed process was used to select 56 radionuclides, comprising 27 fission and activation products and 29 actinide nuclides. This study explains first the determination of the design basis reference spent nuclear fuels, followed by a comprehensive discussion on the selection criteria and methodology for safety-relevant radionuclides.

Collision Risk Assessment by using Hierarchical Clustering Method and Real-time Data (계층 클러스터링과 실시간 데이터를 이용한 충돌위험평가)

  • Vu, Dang-Thai;Jeong, Jae-Yong
    • Journal of the Korean Society of Marine Environment & Safety
    • /
    • v.27 no.4
    • /
    • pp.483-491
    • /
    • 2021
  • The identification of regional collision risks in water areas is significant for the safety of navigation. This paper introduces a new method of collision risk assessment that incorporates a clustering method based on the distance factor - hierarchical clustering - and uses real-time data in case of several surrounding vessels, group methodology and preliminary assessment to classify vessels and evaluate the basis of collision risk evaluation (called HCAAP processing). The vessels are clustered using the hierarchical program to obtain clusters of encounter vessels and are combined with the preliminary assessment to filter relatively safe vessels. Subsequently, the distance at the closest point of approach (DCPA) and time to the closest point of approach (TCPA) between encounter vessels within each cluster are calculated to obtain the relation and comparison with the collision risk index (CRI). The mathematical relationship of CRI for each cluster of encounter vessels with DCPA and TCPA is constructed using a negative exponential function. Operators can easily evaluate the safety of all vessels navigating in the defined area using the calculated CRI. Therefore, this framework can improve the safety and security of vessel traffic transportation and reduce the loss of life and property. To illustrate the effectiveness of the framework proposed, an experimental case study was conducted within the coastal waters of Mokpo, Korea. The results demonstrated that the framework was effective and efficient in detecting and ranking collision risk indexes between encounter vessels within each cluster, which allowed an automatic risk prioritization of encounter vessels for further investigation by operators.

The in-situ Assessment of GIS-Based Geotechnical Hazard Map (GIS기반 지반재해위험지도의 현장 적용성 평가)

  • Ryu, Ji Hyeob;Seo, Sang Hoon;Hwang, Ui Jin
    • Journal of Korean Society of Disaster and Security
    • /
    • v.6 no.1
    • /
    • pp.35-45
    • /
    • 2013
  • In recent years, increasing damage due to landslides. So the government is to create a geotechnical hazard map. This study was to evaluate the applicability of the geotechnical hazard map by using 4 years of landslide cases in Seoul and Busan. And the in-situ aseessment has been carried out in test-bad area with specialists. Study has shown dangerous grade in geotechnical hazard map is more dangerous than the actual. Thus we can utilize geotechnical hazrd map in the purpose of the geotechnical hazard preliminary assessment. However, the in-site inspection and evaluation is required for in order to select the hazard area.

Calculation of preliminary site-specific DCGLs for nuclear power plant decommissioning using hybrid scenarios

  • Seo, Hyung-Woo;Sohn, Wook
    • Nuclear Engineering and Technology
    • /
    • v.51 no.4
    • /
    • pp.1098-1108
    • /
    • 2019
  • Korea's first commercial nuclear power plant at Kori site was permanently shut down in 2017 and is currently in transition stage. Preparatory activities for decommissioning such as historical site assessment, characterization, and dismantling design are being actively carried out for successful D&D (Dismantling and Decontamination) at Kori site. The ultimate goal of decommissioning will be to ensure the safety of workers and residents that may arise during the decommissioning of nuclear facilities and, thereby finally returning the site to its original status in accordance with the release criteria. Upon completion of decommissioning, the resident's safety at a site released will be assessed from the evaluation of dose caused by radionuclides expected to be present or detected at the site. Although the U.S. commercial nuclear power plants with decommissioning experience use different site release criteria, most of them are 0.25 mSv/y. In Korea, both the unrestricted and restricted release criteria have been set to 0.1 mSv/y by the Nuclear Safety and Security Commission. However, since the dose is difficult to measure, measurable concentration guideline levels for residual radionuclides that result in dose equivalent to the site release criteria should be derived. For this derivation, site reuse scenario, selection of potential radionuclides, and systematic methodology should be developed in planning stage of Kori site decommissioning. In this paper, for calculation of a preliminary site-specific Derived Concentration Guideline Levels (DCGLs) for the Nuclear Power Plant site, a novel approach has been developed which can fully reflect practical reuse plans of the Kori site by taking into account multiple site reuse scenarios sequentially, thereby striking a remarkable distinction with conventional approaches which considers only a single site scenario.

A Study of Emergency Plan Making Programs for Personnel Handling Accident Precaution Chemicals (사고대비물질 취급자를 위한 비상대응계획 작성 프로그램 연구)

  • Kim, Sung Bum;Cho, Mun Sik;Park, Choon Hwa;Yoon, Yi;Hwang, Kyung Sup;Yang, Sang Yong
    • Journal of Korean Society of societal Security
    • /
    • v.3 no.2
    • /
    • pp.27-32
    • /
    • 2010
  • Emergency preparedness plan (EPP) is the systematic management of activities that involve a material degree of risk of loss or other damage to the surroundings (people, property and environment), and the boundary of accident recovery plan (ARP). The main purpose of the program is to provide a safety management system to each facility in order to enable to prevent accident and to control accident immediately. The EPP includes not only typical safety-related documentations such as material safety data sheet (MSDS), standard operation procedure (SOP), emergency response plan(ERP). EPP is established basis of the preliminary safety analysis involving risk identification, assessment and prevention plans. The program is also helpful for government or related agencies to control a number of accidents in small-scale companies in the whole country.

  • PDF