Earticle

현재 위치 Home

[일반논문]

제로 트러스트 통제 강도가 업무 우회와 기밀 유출에 미치는 영향 : 업무형 그리드 기반 시뮬레이션 연구
Effects of Zero Trust Control Intensity on Workaround Behavior and Confidential Information Leakage : A Work-Oriented Grid-Based Simulation Study

첫 페이지 보기
  • 발행기관
    한국산업안보학회(구 한국산업보안연구학회) 바로가기
  • 간행물
    한국산업보안연구 KCI 등재 바로가기
  • 통권
    제16권 1호 (2026.04)바로가기
  • 페이지
    pp.73-96
  • 저자
    이기호, 황득빈, 딩도안, 이용준, 최용하
  • 언어
    한국어(KOR)
  • URL
    https://www.earticle.net/Article/A484433

※ 기관로그인 시 무료 이용이 가능합니다.

6,100원

원문정보

초록

영어
This study proposes a work-oriented grid simulation platform to quantify the structural trade-offs between zero trust control intensity, user behavior, and system performance in industrial security environments. The experiment manipulates authentication strength, segmentation intensity, normative pressure, compliance rewards, and attacker rewards through one-factor sweeps and analyzes workaround rate, procedure skip rate, average task completion time, compliance rate, and leakage rate based on step-level logs and episode summaries. The results show that stronger authentication procedures, especially increased steps and time costs, tend to increase both workaround behavior and task delay. Lower default access levels and stronger performance-oriented normative pressure also raise the likelihood of procedure skipping and workaround actions. In contrast, compliance rewards show limited effectiveness under high-friction conditions. Intentional leakage emerges when attacker rewards exceed a certain threshold, indicating a threshold effect. These findings suggest that zero trust should be designed not only around stronger controls but also around friction management and threshold-based policy tuning.
한국어
업무형 그리드 환경에서 제로 트러스트 통제 강도와 사용자 행동 및 시스템 성과 간 구조적 트레이드오프를 정량화하기 위해 시뮬레이션 플랫폼을 제안하였다. 인증 절차 강도, 인증 시간 비용, 권한 분리 수준, 규범 압박, 준수 보상, 공격자 보상 등의 변수를 단일요인 스윕 방식으로 조정하고, step-level JSONL 로그와 episode summary를 기반으로 우회율, 절차 생략률, 평균 업무 완료시간, 제출률, 기밀 유출률을 비교하였다. 분석 결과 인증 단계와 시간비용이 증가할수록 우회행동과 업무 지연이 함께 확대되었으며, 낮은 기본 권한 수준과 강한 성과압박 규범은 절차 생략과 우회를 더욱 증가시키는 경향을 보였다. 반면 준수 보상은 환경 마찰 수준에 따라 효과가 제한적이었으며, 공격자 보상이 일정 임계 구간을 넘는 경우 의도적 유출이 발생하였다. 이는 보안성과를 높이더라도 과도한 통제 마찰은 역으로 비정상 경로 선택을 유발할 수 있음을 보여주며, 산업안보 환경에서 통제 강화 자체보다 마찰 관리와 임계값 기반 정책 설계가 병행되어야 함을 시사한다.

목차

【 요약 】
Ⅰ. 서론
Ⅱ. 이론적 배경 및 연구가설
Ⅲ. 연구설계 및 실험방법
Ⅳ. 실험결과 및 분석
Ⅴ. 결론
참고문헌
【Abstract】

저자

  • 이기호 [ Lee, Ki-Ho | 극동대학교 인공지능보안학과 박사과정 ] 제1저자
  • 황득빈 [ Hoang, Duc-Binh | 극동대학교 인공지능보안학과 박사과정 ] 공동저자
  • 딩도안 [ Tran, Dinh-Doan | 극동대학교 인공지능보안학과 석사과정 ] 공동저자
  • 이용준 [ Lee, Yong-Joon | 극동대학교 인공지능보안학과 교수 ] 공동저자
  • 최용하 [ Choi, Yong-Ha | 극동대학교 해킹보안학과 교수 ] 교신저자

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    한국산업안보학회(구 한국산업보안연구학회) [The Korean Association for Industrial Security(구 The Korean Association for Research of Industrial Security)]
  • 설립연도
    2009
  • 분야
    사회과학>경영학
  • 소개
    학회는 기업, 연구소, 대학의 산업기술 등 물적, 인적자산 및 절ㅇ보에 대한 보보방안 연구를 통해 산업보안을 학문으로 체계화하고 국가경제 및 기업의 성장과 경쟁력 강화를 지원하는 한편 산업보안 관련 산업의 국제화 도모를 목적으로 한다.

간행물

  • 간행물명
    한국산업보안연구 [Korean Journal of Industry Security]
  • 간기
    연3회
  • pISSN
    2765-2327
  • eISSN
    2733-8363
  • 수록기간
    2009~2026
  • 등재여부
    KCI 등재
  • 십진분류
    KDC 325 DDC 330

이 권호 내 다른 논문 / 한국산업보안연구 제16권 1호

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장