Abstract:
An apparatus for preemptively protecting against malicious code by selective virtualization comprises: a compulsory resource storage unit which selects and stores compulsory resources required for executing a vulnerable program having an interface with an external source in a separated space; a modified resource-generating unit which generates a new resource by modifying the content of a resource accessed by the vulnerable program in the event the vulnerable program accesses a resource other than said compulsory resources; and a resource control unit which performs an operating system-level virtualization when the vulnerable program accesses the compulsory resource, and permits the vulnerable program to access the modified resource when the vulnerable program accesses a resource other than the compulsory resource.
Abstract:
The invention relates to an apparatus for host-based network separation, comprising: a network separation switch which, when a process is being executed on a host computer, checks whether the network allocated to the process is an internal network or an external network in accordance with the network access authority allocated to the process, and separates the process by IPs allocated to each network; and a packet processor which blocks the access of packet data when the packet data of the process separated by IPs by the network separation switch access a network other than the network to which the relevant IP is allocated.
Abstract:
A duplex stainless steel consisting of a ferrite phase and an austenite phase is disclosed which is superior in the hot ductility, the high temperature oxidation resistance, the corrosion resistance and the impact toughness. The duplex stainless steel is applied to marine facility and the like. The duplex stainless steel which consists of a ferrite phase and an austenite phase is composed of in weight %: less than 0.03% of C, less than 1.0% of Si, less than 2.0% of Mn, less than 0.04% of P, less than 0.004% of S, less than 2.0% of Cu, 5.0-8.0% of Ni, 22-27% of Cr, 1.0-2.0% of Mo, 2.0-5.0% of W, and 0.13-0.30% of N. Or there are further added one or two elements selected from a group consisting of: less than 0.03% of Ca, less than 0.1% of Ce, less than 0.005% of B and 0.5% of Ti. Further, the ratio (Cr.sub.eq /Ni.sub.eq) of the Cr equivalent (Cr.sub.eq) to the Ni equivalent (Ni.sub.eq) is 2.2-3.0. Further, the weight ratio (W/Mo) of the W to Mo is 2.6-3.4. That is, the duplex stainless steel of the present invention satisfies the above condition, and the Ni.sub.eq and Cr.sub.eq are defined as follows: Ni.sub.eq =%Ni+30.times.%C+0.5.times.%Mn+0.33.times.%Cu+30.times.(%N-0.045), Cr.sub.eq =%Cr+Mo+1.5.times.%Si+0.73.times.%W.
Abstract:
In an apparatus and method for protecting resources of a computing system from a malicious code by selective virtualization, at least a part of the resources is classified as compulsory resources for executing a program on the computing system. When a vulnerable program executed in a separate space attempts to access one of the compulsory resources, an operating system level virtualization is performed. Further, when the vulnerable program attempts to access one of the resources of the computing system which is other than the compulsory resources, the vulnerable program is permitted to access a modified resource which is generated by modifying content of the resource.
Abstract:
A system for logically separating a server using client virtualization includes a client terminal including a virtual environment generation unit for generating a virtual environment, and a virtualized server including a local storage unit, an authentication server for performing authentication on the client terminal when a request for access to the local storage unit is received from a process executed in the virtual environment, and a virtualization filter drier for allowing or blocking the access request to the local storage unit based on the authentication result of the client terminal. The client terminal further includes a virtualization filter drives for transmitting the access request from the process executed in the virtual environment to the local storage unit, and blocking the access request from the process without being made through the virtual environment to the local storage unit.
Abstract:
The present invention relates to a cerebrovascular analysis system which enables early diagnosis of various incurable cerebrovascular diseases such as cerebral thrombosis by measuring an elastic coefficient, blood vessel compliance, blood flow resistance, and blood flow in each cerebrovascular branch. The measurement is achieved by biomechanically analyzing blood vessels in the brain using an electrocardiogram, phonocardiogram, electroencephalogram, pulse wave, and ultrasonic doppler signal as basic data in order to measure biomechanical properties and blood flow properties of blood vessels in the brain for the diagnosis of cerebrovascular diseases.
Abstract:
A network separation apparatus allows a user terminal, connected to an internal network, to connect an external network. The network separation apparatus includes a packet transmission/reception unit to receive a packet generated in a virtual environment on the user terminal and transmit the packet either to the external network or the internal network. The apparatus also includes a packet analysis unit to analyze the packet received from the packet transmission/reception unit and a packet processing unit to allow the packet to be transmitted to the external network or the internal network, separately, based on an analysis result of the packet from the packet analysis unit and a preset packet processing policy.
Abstract:
The present invention relates to a method and apparatus for protecting data using a virtual environment, which creates a safe virtual environment that supports the execution of application programs being operated on a computer and which enables important data to be inputted or outputted only within the virtual environment, such that access to the important data is prevented in a general local environment. According to the present invention, data leakage is initially prevented to protect data, and convenience is provided in that a user may use the computer in a general manner while performing desired work.
Abstract:
The present invention relates to a cardiovascular diagnostic system which enables early detection of cardiovascular diseases and defines their causes. Unlike known electrocardiographs, the cardiovascular diagnosis system can further measure elastic coefficient of blood vessels (the degree of arteriosclerosis), blood vessel compliance, blood flow, and blood flow resistance and velocity in blood vessel branches of the right and left coronary arteries. The elastic coefficient shows organic changes to blood vessels. The compliance shows organic and functional changes of blood vessels simultaneously. The blood flow shows blood flow resistance.
Abstract:
The present invention relates to a cerebrovascular analysis system which enables early diagnosis of various incurable cerebrovascular diseases such as cerebral thrombosis by measuring an elastic coefficient, blood vessel compliance, blood flow resistance, and blood flow in each cerebrovascular branch. The measurement is achieved by biomechanically analyzing blood vessels in the brain using an electrocardiogram, phonocardiogram, electroencephalogram, pulse wave, and ultrasonic doppler signal as basic data in order to measure biomechanical properties and blood flow properties of blood vessels in the brain for the diagnosis of cerebrovascular diseases.