Earticle

현재 위치 Home

A Study of the Airport Model Based on Security Risk

첫 페이지 보기
  • 발행기관
    보안공학연구지원센터(IJSEIA) 바로가기
  • 간행물
    International Journal of Software Engineering and Its Applications SCOPUS 바로가기
  • 통권
    Vol.8 No.11 (2014.11)바로가기
  • 페이지
    pp.67-74
  • 저자
    Yong-Suk Kang, Yang-Ha Chun, Yong-Tae Shin, Jong-Bae Kim
  • 언어
    영어(ENG)
  • URL
    https://www.earticle.net/Article/A235313

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

원문정보

초록

영어
The recent APT attacks including cyber terror are caused by a high level of malicious codes and hacking techniques. The substantive problem is that there are frequent cases in which accounts are seized by malicious hackers and servers are attacked due to a high dependence on the ID/Password system, or account information is exposed through new malicious codes that are not detected by vaccines. This implies that essentially, advanced security management is required, from the perspective of 5A. According to the consideration and research on the big information Security accident cases that have occurred over the last 5 years, the paralysis of A-Bank networks resulted from the non-observance of account management policy, even though there was an account management process, and the user information leakage of B-Portal was caused by APT attacks using malicious codes, but it could prevent it by using the Multi-Factor certification of users to have access to DB or server using OTP, rather than ID/Password. Also, the customer information leakage of C-Capital wouldn’t occur, if it deleted the accounts of employees who resigned, in accordance with security policy, and the customer information leakage of KT agencies could be prevented in advance through a verification of users and devices of subcontractors. Lastly, the exposure of internal information of the domestic large company, S to North Korea wouldn’t be occurred, if foreign users were not allowed access to particular tasks and networks. The changes of IT environment are represented by Mobile, Cloud and BYOD, and all the devices of IT are being serviced via wired and wireless networks. In this situation, the security model needs to be changed, too into the Airport model which emphasizes prevention, and connection, security and integration of functions from the existing Castle model. The risk-based Airport model consists of 5A (Accounting, Authorization, Authentication, Auditing and Administration), and for applying this model, a preventive process of threatening factors should be designed. This study suggested an application method of the risk-based Airport model to the cyber security environment.

목차

Abstract
 1. Introduction
 2. Case Study
  2.1. Paralysis of A-Bank Network
  2.2. B-Portal Identity Theft
  2.3. C-Capital Leakage of Customer Information
  2.4. D-Telco Leakage of Customer Information
  2.5. North Korea’s Network Penetration to South Korea E-Corp
  2.6. Suggestions of Security Accident
 3. Security Risk-based Airport Model
  3.1. Changes in Security Model Depending on Changes in IT Service
  3.2. Security Risk-based Airport Model with 5A
 4. Conclusions
 References

저자

  • Yong-Suk Kang [ Department of IT Policy and Management, Graduate School of Soongsil University, Seoul 156-743, Korea ]
  • Yang-Ha Chun [ Yongin University, Gyeonggi-do 449-714, Korea ]
  • Yong-Tae Shin [ Department of Computer Science, Soongsil University, Seoul 156-743, Korea ]
  • Jong-Bae Kim [ Graduate School of Software, Soongsil University, Seoul 156-743, Korea ] Corresponding author

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    보안공학연구지원센터(IJSEIA) [Science & Engineering Research Support Center, Republic of Korea(IJSEIA)]
  • 설립연도
    2006
  • 분야
    공학>컴퓨터학
  • 소개
    1. 보안공학에 대한 각종 조사 및 연구 2. 보안공학에 대한 응용기술 연구 및 발표 3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최 4. 보안공학 기술의 상호 협조 및 정보교환 5. 보안공학에 관한 표준화 사업 및 규격의 제정 6. 보안공학에 관한 산학연 협동의 증진 7. 국제적 학술 교류 및 기술 협력 8. 보안공학에 관한 논문지 발간 9. 기타 본 회 목적 달성에 필요한 사업

간행물

  • 간행물명
    International Journal of Software Engineering and Its Applications
  • 간기
    월간
  • pISSN
    1738-9984
  • 수록기간
    2008~2016
  • 등재여부
    SCOPUS
  • 십진분류
    KDC 505 DDC 605

이 권호 내 다른 논문 / International Journal of Software Engineering and Its Applications Vol.8 No.11

    피인용수 : 0건 (자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장