摘要:
Provided are a network node and a method of performing discovery, which may stably perform discovery without delay or crash of a network at the time of initial discovery in a large-scale network. The network node operated in a distributed network includes a discovery performing unit that determines a discovery back-off time that is a transmission wait time of a discovery message based on levels of priority of the network node, and a communication unit that transmits the discovery message using the discovery back-off time.
摘要:
The present disclosure relates to a method and apparatus for electronic voting performed in response to insertion of an electronic ballot by a voter into an electronic voting machine. The method includes storing candidate information in a candidate database, issuing an electronic ballot by a ballot dispenser in response to a ballot issuance request of a voter, displaying by the electronic voting machine a list of candidates from the candidate database when the electronic ballot is inserted into the electronic voting machine, and printing by a printer vote data related to a selected candidate on the electronic ballot, followed by dispensing the printed electronic ballot when the voter selects the candidate whom the voter wishes to vote from among the list of candidates. The electronic ballot is printed with a barcode corresponding to vote information containing at least one of data for authentication, precinct ID and polling place ID.
摘要:
A method includes, when a passage network connecting at least one first communication entity in a first local domain with at least one second communication entity in a second local domain does not support the broadcast scheme and the multicast scheme, transmitting, by a first discovery gateway, a discovery request to a second discovery gateway, which is one of all discovery gateways connected with the first discovery gateway, in the second local domain via the passage network. Even when a passage network that does not support broadcasting and multicasting is between two communication entities, the method enables a communication entity to search for connection information about a counterpart communication entity without information required for communication entities requiring interaction on a network to connect with each other, thereby performing a function such as data exchange and service provision at a global level.
摘要:
Provided is an apparatus for detecting a network attack situation. The apparatus includes an alarm receiver receiving a plurality of alarms raised in a network to which the alarm receiver is connected, converting the alarms into predetermined alarm data, and outputting the alarm data; an alarm processor analyzing an attack situation in the network based on attributes of the alarm data and a number of times that the alarm data is generated; a memory storing basic data needed to analyze the state of the network and providing the basic data to the alarm processor; and an interface transmitting the result of the analysis by the alarm processor to an external device, receiving a predetermined critical value from the external device, which is a basis for determining the occurrence of the attack situation, and outputting the critical value to the alarm processor such that the alarm processor can store the critical value in the memory. Equal numbers of hash engines and detection engines for processing the alarms in the network to the number of data groups classified as network attack situations are formed in a line. Therefore, a network attack situation can be detected in real time based on a great number of alarms indicating intrusion detection.
摘要:
Provided are a network node and a method of performing discovery, which may stably perform discovery without delay or crash of a network at the time of initial discovery in a large-scale network. The network node operated in a distributed network includes a discovery performing unit that determines a discovery back-off time that is a transmission wait time of a discovery message based on levels of priority of the network node, and a communication unit that transmits the discovery message using the discovery back-off time.
摘要:
An apparatus and method for visualizing a network condition related to a network security are provided. The apparatus includes a traffic feature extracting unit, a network condition displaying unit, and a traffic abnormal condition determining unit. The traffic feature extracting unit extracts information including source address, source port, destination address, and destination port from network traffics, selects two of the extracted information, and calculates unique dispersion degrees of two unselected information. The network condition displaying unit displays a two-dimensional cube expressed using the calculated unique dispersion degrees for the classified traffics. The traffic abnormal condition determining unit determines whether the traffics are in an abnormal condition or not based on the two-dimensional security cube.
摘要:
A network status display device using a traffic pattern map is provided. The device includes: a traffic feature extractor extracting a port number of a port having the maximum occupancy of micro-flows and macro-flows for each network address section and host address section with reference to traffic information collected by an external traffic information collector, calculating and storing an occupancy rate of the port; a traffic status display unit making a network traffic pattern map expressed by destination-source network addresses and a host traffic pattern map expressed by destination-source host addresses and displaying the port information stored in the traffic feature extractor on the network traffic pattern map and the host traffic pattern map; and a traffic anomaly determination unit determining whether a network status is abnormal with reference to the network traffic pattern map and the host traffic pattern map and detecting and reporting a harmful or abnormal traffic which causes the abnormal network status. The device can determine whether the anomaly deteriorating the network performance exists and can easily and quickly detect the harmful or abnormal traffic which causes the anomaly by the use of the port information of the port having the maximum occupancy of the micro-flows and the macro-flows for each network address section and each host address section.
摘要:
A network status display device using a traffic flow-radar is provided. The network status display device includes: a traffic feature extractor calculating flow occupancy rates for total flows, micro-flows and macro-flows with respect to each of a plurality of traffic features with reference to traffic information for each traffic feature such as a network address, a port, a transmitting/receiving host address or a protocol collected by an external traffic information collector, and storing the calculation result; a traffic status display unit displaying the flow occupancy rates for each traffic feature calculated and stored in the traffic feature extractor on a radar with dots for each traffic feature; and a traffic anomaly determination unit determining whether a network status is abnormal with reference to the radar for each traffic feature, detecting and reporting the type of the abnormal network status and harmful or abnormal traffic that generates the abnormal network status, when the abnormal status occurs.
摘要:
An apparatus and method for visualizing a network condition related to a network security are provided. The apparatus includes a traffic feature extracting unit, a network condition displaying unit, and a traffic abnormal condition determining unit. The traffic feature extracting unit extracts information including source address, source port, destination address, and destination port from network traffics, selects two of the extracted information, and calculates unique dispersion degrees of two unselected information. The network condition displaying unit displays a two-dimensional cube expressed using the calculated unique dispersion degrees for the classified traffics. The traffic abnormal condition determining unit determines whether the traffics are in an abnormal condition or not based on the two-dimensional security cube.
摘要:
Provided is an apparatus for detecting and visualizing anomalies in network traffic which includes a traffic information storing portion storing information on network traffic, a traffic state display portion presenting a status of the network traffic generated for a predetermined threshold time based on the information on network traffic on an orthogonal coordinates system in a form of a graph connecting at least one point data as a coordinate value, and a traffic anomalies determination portion determining an existence of anomalies in the network traffic based on a shape of the graph.