Abstract:
본 발명은 디지털 포렌식 방법 및 장치에 관한 것이다. 본 발명에 따른 디지털 포렌식 장치는 대상 저장 매체에 저장된 페이지파일을 추출하는 페이지파일 추출부, 상기 추출된 페이지파일에 저장된 페이지의 특징을 추출하는 저장 페이지 특징 추출부, 상기 추출된 페이지의 특징을 미리 결정된 적어도 하나의 분류 기준과 비교하고 상기 비교 결과에 따라 상기 페이지를 분류하는 페이지 분류부, 상기 분류된 페이지에 상응하여 디지털 포렌식을 수행하는 디지털 포렌식 수행부를 포함할 수 있다. 본 발명에 의하면 페이지 파일의 정보만을 이용하여 디지털 포렌식을 수행할 수 있다. 디지털 포렌식, 페이지파일(pagefile), 섹션, PE
Abstract:
PURPOSE: An apparatus and a method for checking personal computer security are provided to manage the PC security setting depending on the check results. CONSTITUTION: A check module(122) checks a security setup of a target check PC based on the policy received from a security check server. The check module outputs the check result. The check module performs the security setup check for a PC according to the security check start command received from the security check server. A control module(121) carries out the security setup change of a PC based on the control policy received from the security check server and the check result received from the check module. The control module transmits the check result received from the checked out module to the security check server.
Abstract:
An information asset identifying and evaluating method is provided to suggest a quantitative evaluation standard for asset value evaluation, asset analysis and asset evaluation to provide an effective and objective asset evaluation method and establish a formula for asset value evaluation and asset analysis to secure objectivity. An information asset identifying and evaluating method includes a step(S100) of detecting constitution forms of information assets in a list, a step(S110) of calculating asset value through a quantitative evaluation standard for each information asset, and a step(S120) of determining priority of major assets through the quantitative asset evaluation result and listing the major assets.
Abstract:
A cyber threat forecast system for forecasting a frequency, possibility, and period of cyber threat, and a method thereof are provided to offer a forecast result to a user by forecasting a frequency, possibility, and a period of cyber threat through time series analysis method and Delphi analysis method considering various variables. An information collecting/processing module(10) collects and processes intrusion detection event information, network traffic statistics information, and cyber threat information of an Internet bulleting board, and specialist opinion information for cyber threat occurrence. A forecasting engine subsystem(120) forecasts a frequency, possibility, and a period for the cyber threat by selecting time series analysis method and Delphi analysis method according to the processed information. A result display GUI(Graphic User Interface) and managing module(110) displays a forecasting result of the forecasting engine subsystem in a screen, and changes and manages setting of the forecasting engine subsystem and an information collecting/processing module.
Abstract:
A multi-step integrated security management system using an intrusion detection log collection engine and a traffic statistics generation engine, and a method thereof are provided to reduce a false detection rate by relating/analyzing an intrusion detection log collected in the intrusion detection log collection engine and traffic quantity generated from the traffic statistics generation engine. Each monitoring agent(100) is installed to each agency using the independent network, and comprises the intrusion detection log collection engine(101) collecting the intrusion detection log and the traffic statistics generation engine(102) collecting traffic statistics. Each management server(200,300) separately or mutually analyzes the intrusion detection log and the traffic statistics received from each monitoring agent. The intrusion detection log collection engine includes an external interface accessing an IDS(Intrusion Detection System) to collect the intrusion detection engine, a format converter, a log contractor, and a transmitter. The traffic statistics generation engine includes a network interface, a packet analyzer, a traffic information manager, a statistics information generator, and the transmitter.
Abstract:
대상에정보를삽입하고, 대상부터정보를추출하기위한방법및 장치가제공된다. 정보삽입장치는정보를적어도하나의점의집합으로변환할수 있고, 변환에의해생성된적어도하나의점의집합을대상에출력할수 있다. 정보추출장치는대상에출력된적어도하나의점의집합을식별할수 있고, 식별된적어도하나의점의집합으로부터정보를추출할수 있다.