As a core paradigm of modern warfare, the ground Manned-Unmanned Teaming (MUM-T) system is exposed to critical cyber threats, such as hijacking of control authority, sensor tampering, data latency and interruption, and supply chain contamination, due to its high autonomy and network dependence. However, even two years after the promulgation of the Korean Risk Management Framework (K-RMF) regulations, the existing uniform defense security authorization system has clear limitations in actively defending against dynamic operational environments and interoperability vulnerabilities among heterogeneous weapon systems. To address these challenges, this study precisely analyzes the operational concepts and data flows by asset layer (DFD) of ground MUM-T to derive five key mission failure factors, and defines the core security vulnerabilities and security requirements of Unmanned Ground Vehicles (UGVs) based on these factors. Furthermore, through AI-based mitigation keyword mapping, this study proposes a design method for a 'Ground MUM-T Specialized Security Control Overlay' that is not reflected in the current baseline, and compares the security requirement fulfillment rate of the security control configuration when applying the MUM-T overlay against the current K-RMF baseline.
한국어
현대 전장의 핵심 패러다임인 지상 유·무인복합체계(MUM-T, Manned-Unmanned Teaming)는 높은 자율성과 네트워크 의존성으로 인해 제어권 탈취, 센서 변조, 데이터 지연 및 단절, 공급망 오염 등 치명적인 사이버 위협에 노출될 수 있다. 그러나 한국형 위험관리프레임워크(K-RMF; Korean Risk Management Framework) 제도가 공포된 지 2년이 지난 현재까지도, 기존의 획일적인 국방 보안인증 제도는 동적인 작전 환경과 이기종 무기체계 간의 연동 취약점을 능동적으로 방어하는 데 명확한 한계를 지닌다. 이에 본 연구에서는 지상 MUM-T의 운용 개념과 자산 계층별 데이터 흐름(DFD)을 분석하여 5가지 부류의 임무 실패 요인을 도출하고, 이를 기반으로 무인지상차량(UGV, Unmanned Ground Vehicle)의 핵심 보안 취약점과 보안요구사항을 정의하였다. 나아가 AI 기법을 활용한 완화 조치 키워드 매핑을 통해 현행 기준선에 미반영된 '지상 MUM-T 특화 보안통제 오버레이' 설계 방안을 제안하고 K-RMF 현행 기준선 대비 MUM-T오버레이 적용시와 보안통제항목 구성의 보안요구 충족도를 비교하였다.
목차
요약 ABSTRACT 1. 서론 2. 관련 연구 2.1 K-RMF 오버레이 역할과 생성 절차 2.2 UGV 임무 특성과 데이터 흐름 2.3 UGV 사이버위협 3. UGV 임무 기반의 K-RMF 오버레이생성 설계 3.1 요구사항 정의 3.2 K-RMF의 UGV 오버레이 생성 설계 3.3 K-RMF의 UGV 오버레이를 적용한 보안통제 항목 식별 4. K-RMF 보안통제항목 적용 비교 4.1 K-RMF UGV 오버레이 적용 비교 4.2 UGV 사이버 위협 대응 역량 비교 5. 결론 참고문헌