제로 트러스트 통제 강도가 업무 우회와 기밀 유출에 미치는 영향 : 업무형 그리드 기반 시뮬레이션 연구
Effects of Zero Trust Control Intensity on Workaround Behavior and Confidential Information Leakage : A Work-Oriented Grid-Based Simulation Study
This study proposes a work-oriented grid simulation platform to quantify the structural trade-offs between zero trust control intensity, user behavior, and system performance in industrial security environments. The experiment manipulates authentication strength, segmentation intensity, normative pressure, compliance rewards, and attacker rewards through one-factor sweeps and analyzes workaround rate, procedure skip rate, average task completion time, compliance rate, and leakage rate based on step-level logs and episode summaries. The results show that stronger authentication procedures, especially increased steps and time costs, tend to increase both workaround behavior and task delay. Lower default access levels and stronger performance-oriented normative pressure also raise the likelihood of procedure skipping and workaround actions. In contrast, compliance rewards show limited effectiveness under high-friction conditions. Intentional leakage emerges when attacker rewards exceed a certain threshold, indicating a threshold effect. These findings suggest that zero trust should be designed not only around stronger controls but also around friction management and threshold-based policy tuning.
한국어
업무형 그리드 환경에서 제로 트러스트 통제 강도와 사용자 행동 및 시스템 성과 간 구조적 트레이드오프를 정량화하기 위해 시뮬레이션 플랫폼을 제안하였다. 인증 절차 강도, 인증 시간 비용, 권한 분리 수준, 규범 압박, 준수 보상, 공격자 보상 등의 변수를 단일요인 스윕 방식으로 조정하고, step-level JSONL 로그와 episode summary를 기반으로 우회율, 절차 생략률, 평균 업무 완료시간, 제출률, 기밀 유출률을 비교하였다. 분석 결과 인증 단계와 시간비용이 증가할수록 우회행동과 업무 지연이 함께 확대되었으며, 낮은 기본 권한 수준과 강한 성과압박 규범은 절차 생략과 우회를 더욱 증가시키는 경향을 보였다. 반면 준수 보상은 환경 마찰 수준에 따라 효과가 제한적이었으며, 공격자 보상이 일정 임계 구간을 넘는 경우 의도적 유출이 발생하였다. 이는 보안성과를 높이더라도 과도한 통제 마찰은 역으로 비정상 경로 선택을 유발할 수 있음을 보여주며, 산업안보 환경에서 통제 강화 자체보다 마찰 관리와 임계값 기반 정책 설계가 병행되어야 함을 시사한다.
목차
【 요약 】 Ⅰ. 서론 Ⅱ. 이론적 배경 및 연구가설 Ⅲ. 연구설계 및 실험방법 Ⅳ. 실험결과 및 분석 Ⅴ. 결론 참고문헌 【Abstract】