Abstract:
PURPOSE: An apparatus and method for defending a modulation of a client screen is provided to prevent the transformation of a client screen due to a web injection attack and a memory hacking attack by offering a dynamically created random web to the client. CONSTITUTION: A random web generator(230) changes the same web page into a random URI(Uniform Resource Identifier) by the requests of clients, creates different random web sources, and supplies the random web sources to the clients. A web modification determiner(250) determines the screen modification of the random web sources by comparing the generated web source ID value about the random web source and the generated web source ID value.
Abstract:
접근권한별로분리된브라우저프로세스를이용한브라우저제공방법및 이를이용한장치가개시된다. 제1 웹페이지에상응하는제1 주소를획득하는단계; 권한제어목록에서제1 주소를기반으로제1 단말접근권한을획득하고, 제1 단말접근권한에상응하는제1 브라우저프로세스를실행하는단계; 제1 브라우저프로세스가제2 웹페이지의렌더링을시도하는경우에, 제1 단말접근권한과제2 웹페이지에상응하는제2 단말접근권한을비교하여렌더링허용여부를판단하는단계; 및렌더링이허용되지않은경우에제1 브라우저프로세스의렌더링시도를차단하고, 제2 단말접근권한에상응하는제2 브라우저프로세스를실행하여제2 웹페이지를렌더링하는단계를포함한다.
Abstract:
PURPOSE: An online financial transaction authentication method and apparatus thereof are provided to confirm the recognition state of a user randomly using a part of main transaction information as authentication information. CONSTITUTION: An authentication information generation unit(110) randomly selects a part of main transaction information corresponding to a user. The authentication information generation unit generates authentication information by combining the selected information. A display unit(140) provides the converted authentication information and the main transaction information to the user. A user recognition determination unit(160) determines whether the user recognizes the authentication information.