Earticle

현재 위치 Home

C·I·A 기반 침해사고 심각도 정량적 모델 연구
A Study on Quantitative Modeling of Cyber Incident Severity Based on C·I·A

첫 페이지 보기
  • 발행기관
    한국융합보안학회 바로가기
  • 간행물
    융합보안논문지 KCI 등재 바로가기
  • 통권
    제26권 제3호 (2026.06)바로가기
  • 페이지
    pp.43-50
  • 저자
    김현지, 백남균
  • 언어
    한국어(KOR)
  • URL
    https://www.earticle.net/Article/A487594

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

원문정보

초록

영어
Organizational information systems operate through interdependent assets, services, and business functions; thus, the impact of a cyber incident affecting a specific asset can propagate across services and operations, requiring prompt and systematic response. However, conventional risk assessment is a predictive framework centered on pre-incident likelihood and potential impact, making it inadequate for directly explaining the actual scale of damage and financial loss after an incident has occurred. Accordingly, this study distinguishes qualitative pre-incident risk from quantitative post-incident severity and proposes a model for evaluating realized damage from a security perspective. Specifically, actual incident outcomes, including information leakage, data tampering, and service disruption, are quantified as Confidentiality, Integrity, and Availability (CIA) loss rates. The proposed model calculates severity by combining these CIA loss rates with asset importance derived from asset–service dependency structures. It also enables interpretation of the contribution of individual assets and security attributes, thereby supporting more efficient decision-making in response prioritization and resource allocation. Furthermore, the results can be fed back into the recalibration of risk management levels and the refinement of Degree of Assurance (DoA) criteria, contributing to improved organizational security management.
한국어
조직의 정보시스템은 자산, 서비스, 업무가 상호 의존하는 구조로 운영되므로, 특정 자산에서 발생한 침해사고의 영향이 서비스와 업무 전반으로 확산될 수 있어 신속하고 체계적인 대응이 요구된다. 그러나 기존 위험평가는 사고 이전의 가능성과 잠재적 영향을 중심으로 하는 예측적 평가 체계이므로, 사고 이후의 실제 피해 규모와 피해액을 직접적으로 설명하기 어렵다. 이에 본 연구는 정성적인 사전 위험도와 정량적인 사후 심각도를 구분하여 정의하고, 사고로 인해 실제 발생한 정보 유·노출, 데이터 변조, 서비스 중단을 각각 기밀성(C)·무결성(I)·가용성(A) 손실률로 정량화함으로써, 실현된 피해의 규모를 보안 관점에서 평가하는 모델을 제안한다. 제안 모델은 자산–서비스 의존 구조를 반영한 자산 중요도와 CIA 손실률을 결합하여 심각도를 산정하며, 자산별 및 보안 속성별 기여도를 해석할 수 있어 대응 과정에서의 우선순위 설정과 자원 배분 등 보다 효율적인 의사결정을 지원한다. 이는 향후 위험관리 수준의 재설정과 DoA 기준의 구체화에 반영되어 조직의 보안관리 체계 개선으로 환류될 수 있다.

목차

요약
ABSTRACT
1. 서론
2. 이론적 배경 및 관련 연구
2.1 사이버보안 위험평가 프레임워크
2.2 위험평가의 한계와 심각도 평가의 필요성
3. 침해사고 심각도 평가 모델
3.1 조직 구조 모델링
3.2 자산 중요도 산정
3.3 CIA 손실률 산정
3.4 최종 심각도 산정
4. 가상 시나리오 기반 적용 및 분석
4.1 가상 시나리오 설정
4.2 자산의 중요도 산정 결과
4.3 CIA 손실률 산정 결과
4.4 최종 심각도 산정 결과 및 해석
5. 결론
참고문헌

저자

  • 김현지 [ Hyun-ji Kim | 덕성여자대학교 사이버보안전공 대학생 ] 주저자
  • 백남균 [ Nam-kyun Baik | 덕성여자대학교 사이버보안전공 교수 ] 교신저자

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    한국융합보안학회 [Korea Information Assurance Society]
  • 설립연도
    2001
  • 분야
    공학>전자/정보통신공학
  • 소개
    본 학회는 사이버테러 및 정보전에 관한 학문연구ㆍ기술 개발ㆍ기반 구축을 도모하고 국내ㆍ외 관계기관과 학술교류와 정보교환을 통하여 회원 상호간의 전문지식을 배양하고, 궁극적으로는 국가 중요 정보기반구조를 보호함을 그 목적으로 한다.

간행물

  • 간행물명
    융합보안논문지 [Jouranl of Information and Security]
  • 간기
    연5회
  • pISSN
    1598-7329
  • 수록기간
    2001~2026
  • 등재여부
    KCI 등재
  • 십진분류
    KDC 005 DDC 005

이 권호 내 다른 논문 / 융합보안논문지 제26권 제3호

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장