LLM 기반 대화형 보안 위험 커뮤니케이션 시스템에 관한 연구 : 웹 취약점 진단 기반 사용자 인지·행동 유도 사례를 중심으로
An LLM-Based Interactive Security Risk Communication System : A Case Study on Web Vulnerability Assessment and User Cognitive-Behavioral Guidance
Recent advances in Large Language Models (LLMs) and Vision-Language Models (VLMs) have created new opportunities for cybersecurity automation and security risk communication. However, conventional security assessment results are typically delivered as static reports, making it difficult for non-experts to understand security risks and response priorities. This study proposes an LLM-based interactive security risk communication system that automatically generates explainable security reports from web vulnerability assessment screenshots. The proposed system utilizes a VLM to analyze vulnerability images and generates security reports based on OWASP-oriented structured results and Protection Motivation Theory (PMT)-based prompting. A chatbot interface enables users to query and reinterpret the generated reports through natural language interaction. Preliminary expert evaluation results indicate that the proposed system has the potential to improve user comprehension and risk awareness compared with conventional static reports. The findings suggest that LLM-based security automation can be extended toward a user-centered explainable security communication framework.
한국어
최근 대규모 언어 모델(LLM)과 Vision-Language Model(VLM)의 발전은 사이버보안 자동화와 위험 정보 전달 방식에 새로운 가능성을 제시하고 있다. 그러나 기존의 보안 진단 결과는 주로 PDF 기반 정적 보고서 형태로 제공되어, 비전문가와 의사결정자가 위험성과 대응 우선순위를 직관적으로 이해하는 데 한계가 존재한다. 본 연구는 웹 취약점 진단을 사례로 하여, 진단 스크린샷 이미지를 기반으로 설명형 보안 보고서를 자동 생성하고 자연어 질의를 지원하는 LLM 기반 대화형 보안 위험 커뮤니케이션 시스템을 제안한다. 제안 시스템은 VLM을 활용하여 웹 취약점 이미지를 분석하고, OWASP 기반 구조화 결과와 보호동기이론(PMT)을 반영한 프롬프트 설계를 통해 위험 설명과 대응 방안을 포함하는 보안 보고서를 생성한다. 또한 챗봇 기반 상호작용 기능을 통해 사용자가 생성된 보고서 내용을 자연어 형태로 질의하고 재해석할 수 있도록 구성하였다. 전문가 기반 초기 평가 결과, 제안 시스템은 기존 정적 보안 보고서 대비 사용자 이해도와 위험 인식 향상 측면에서 긍정적인 가능성을 보였다. 본 연구는 LLM 기반 보안 자동화를 사용자 중심의 설명형 보안 커뮤니케이션 구조로 확장할 수 있는 가능성을 제시한다.
목차
요약 ABSTRACT 1. 서론 2. 관련 연구 2.1 LLM 기반 보안 자동화 및 보고 연구 2.2 PMT 기반 보안 인식 및 행동 유도 연구 2.3 기존 연구와의 차별성 3. AI 기반 보안 커뮤니케이션 시스템설계 3.1 전체 시스템 구조 및 이미지 기반 분석 3.2 PMT 기반 LLM 보고서 생성 구조 3.3 구현 환경 및 운영 구조 4. 전문가 기반 초기 평가 및 분석 4.1 평가 구성 및 측정 항목 4.2 평가 결과 및 해석 5. 결론 및 향후 과제 참고문헌