Earticle

현재 위치 Home

한국산업안보연구(구 한국산업보안연구) [Korean Journal of Industrial Security]

간행물 정보
  • 자료유형
    학술지
  • 발행기관
    한국산업안보학회(구 한국산업보안연구학회) [The Korean Association for Industrial Security(구 The Korean Association for Research of Industrial Security)]
  • pISSN
    3140-5576
  • eISSN
    3140-5673
  • 간기
    연3회
  • 수록기간
    2009 ~ 2026
  • 등재여부
    KCI 등재
  • 주제분류
    사회과학 > 경영학
  • 십진분류
    KDC 325 DDC 330
제16권 2호 (9건)
No

[일반논문]

1

5,700원

정보체계는 소프트웨어, 펌웨어, 하드웨어 및 협력사 개발 환경이 결합된 복합 공급망 구조에서 운영되며, 공급망 오염과 탐지 지연은 보안사고 확산으로 이어질 수 있다. 특히 외부 공급자를 통해 유입되는 실행파일, 라이브러리 및 업데이트 패키지는 공급망 기반 악성코드 유입 위험을 증가시킨다. 본 연구는 공급망 환경에서 유통되는 소프트웨어 산출물에 대한 정적 악성코드 탐지 결과를 산업보안 관점의 정책 의사결정에 활용하는 방안을 제시한다. NIST SP 800-161 Rev.1의 C-SCRM 프레임워크를 기반으로 탐지 결과를 격리, 반입 보류, 정밀 분석 및 공급자 재평가와 같은 보안 통제 조치로 연결하는 정책 기반 운영 구조를 설계하였다. 실험에서는 XGBoost(Byte n-gram), MalConv(입력 길이 제한형), 1D CNN-GLU, Byte-Image CNN 등 네 모델을 stratified 5-fold 교차검증으로 평가하고, Recall 우선·비용 최소화·오탐률(FPR) 제한 정책을 적용하여 Recall, FPR, 정규화 기대비용(Cost_norm)과 경보량을 함께 비교하였다. 분석 결과, 정책 효과는 모델 특성과 운영 제약에 따라 조건부로 나타났다. 고성능 모델에서는 정책 간 차이가 제한적인 반면, 1D CNN-GLU에서는 FPR 제한 정책이 오탐률과 비용을 함께 낮추는 절충점을 제공하였다. Byte-Image CNN에서는 FPR이 감소했지만 Recall 손실로 Cost_norm이 증가하여 FPR 제약이 항상 총비용 최소화로 이어지지는 않았다. 또한 낮은 악성코드 유병률을 가정한 운영 시나리오에서는 오탐이 경보량의 대부분을 차지할 수 있음을 확인하였다. 따라서 Policy C는 비용 최소화 정책이라기보다 분석 인력·처리용량과 같은 운영상 오탐 상한을 관리하는 제약 기반 정책으로 해석할 필요가 있다. 본 연구는 AI 기반 탐지 결과를 산업보안 환경의 정책 의사결정 체계와 연계하는 운영 프레임워크를 제시한다.

Modern information systems operate within complex software and supplier ecosystems, and compromised executables, libraries, or update packages can propagate supply-chain incidents. This study proposes a policy-oriented approach for converting static malware detection scores into industrial-security decisions under NIST SP 800-161 Rev.1 C-SCRM. Four models - XGBoost (Byte n-gram), a truncated MalConv baseline, 1D CNN-GLU, and Byte-Image CNN - are evaluated using stratified five-fold cross-validation. Recall-first, cost-minimization, and FPR-constrained threshold policies are compared using Recall, FPR, normalized expected cost (Cost_norm), and false-positive workload. The results show that policy effects are conditional on model characteristics and operational constraints. For high-performing models, policy differences are limited. For 1D CNN-GLU, the FPRconstrained policy provides a useful trade-off by reducing false alarms and normalized cost, whereas for Byte-Image CNN it lowers FPR but increases Cost_norm because of recall loss. A low-prevalence operational scenario further shows that false positives can dominate the alert queue even when classification metrics are high. Thus, the FPR-constrained policy should be interpreted as a capacity-control mechanism rather than a universal cost minimizer. The proposed framework links AI-based malware detection outputs to quarantine, intake deferral, in-depth analysis, and supplier reassessment decisions in software supply-chain security.

2

7,300원

공공기관의 디지털 전환에 따라 정보의 중요도와 유출 영향을 반영한 위험 기반 보안체계의 필요성이 커지고 있다. 본 연구는 공개자료를 활용한 탐색적 사례연구로서, 국가망 보안체계(National Network Security Framework: N2SF)의 업무·기능 분석, 업무정보 식별 및 기밀(C)·민감(S)·공개(O) 등급 분류 절차를 국립대병원에 적용하고 단계별 산출물을 연계하는 분석 절차를 제시하는 데 목적이 있다. 9개 국립대병원의 직제·업무분장 자료에서 4,774개 소관사항을 분석하여 5개 상위 업무영역과 10개 기능그룹을 도출하였다. 이어 서울대학교병원의 감염관리, 교육·수련, 연구·기관생명윤리위원회(IRB), 공공의료 및 정보보호 기능을 대상으로 20개 핵심 업무정보 인벤토리를 구축하였다. 식별된 정보는 정보공개법상 비공개 사유, 개인정보·의료정보 포함 여부와 유출 영향을 종합하여 분류하였다. 분석 결과 개인정보, 심의·평가, 내부 의사결정 및 정보보호 운영자료는 주로 S등급으로, 승인·공개된 정책·계획과 비식별 집계자료는 O등급으로 나타났다. 공개자료만으로 C등급을 확정하기는 어려웠으며, C등급은 국민의 생명·신체 또는 핵심 의료서비스에 현저한 영향을 미치는 구체적 고위험 정보에 제한적으로 적용할 필요가 있었다. 본 연구는 기능 ID와 정보 ID를 연계하여 업무·기능, 업무정보 및 등급판정 근거를 추적할 수 있는 국립대병원 N2SF 적용의 기초 모형을 제시하였다.

This exploratory case study applies the business-function analysis, business information identification, and Classified, Sensitive, and Open (C/S/O) classification procedures of the National Network Security Framework (N2SF) to national university hospitals. A total of 4,774 assigned duties from nine hospitals were analyzed, yielding five major business domains and ten functional groups. Based on this structure, a core inventory of 20 information items was developed for five functions at Seoul National University Hospital: infection control, education and training, research and institutional review board administration, public healthcare, and information security. Classification considered statutory grounds for nondisclosure, the inclusion of personal and medical data, and potential disclosure impacts. Personal information, review and evaluation records, internal decision-making materials, and security-operation records were mainly classified as Sensitive, whereas approved public policies, plans, and de-identified aggregate data were classified as Open. No Classified item could be conclusively confirmed from public sources. Classified status should therefore be applied restrictively to specific high-risk information whose disclosure could seriously affect life, safety, or critical medical services. Linking function IDs and information IDs provides a traceable foundation for N2SF implementation in national university hospitals.

3

6,000원

본 연구는 산업기술·영업비밀 분쟁(산업보안 분쟁)에서 데이터베이스가 핵심 증거로 대두되는 상황에 주목하고, 데이터베이스 증거의 제출과 검증 문제를 산업보안 관점에서 분석하였다. 그간 전자증거개시 관련 논의는 제도 도입과 증거보존의무에 집중되어 왔으며, 데이터베이스의 구조, 쿼리, 로그, 메타데이터, 해시값을 어떻게 보존·제출·검증할 것인지에 대하여 충분히 검토되지 못하였다. 이에 따라 국내 전자증거개시 및 산업보안 연구 문헌을 검토하고, 미국의 Sound Around, Inc. v. Friedman 사건과 Sedona Database Principles를 참고 기준으로 분석하였다. 대상 특정(Definition), 추출 조건(Protocol), 검증 가능성(Validation), 전문성·협업(Competence)을 데이터베이스 증거의 확보·검증을 위한 검토 요소로 제시하였다. 특허법 제132조·산업기술보호법 제22조의3과 달리 부정경쟁방지법 제14조의3의 자료제출은 손해액 산정 자료에 머물러 있어, 영업비밀 침해소송에서 그 한계가 상대적으로 두드러진다는 점도 같이 검토하였다. 이를 통해 향후 산업보안분쟁에서 정형 데이터 증거의 신뢰성과 재현성을 평가하는 비교법적 분석 틀을 제시하였다.

This study examines the acquisition and verification of database evidence in industrial technology and trade secret disputes from an industrial security perspective. In Korea, scholarship on electronic evidence disclosure has largely fixated on its adoption and duties to preserve evidence. Far less attention has gone to how a database's structure, query conditions, logs, metadata, and hash values ought to be preserved, produced, and verified. It first surveys the Korean literature on electronic evidence disclosure and industrial security. It then examines two U.S. reference materials: the Sound Around, Inc. v. Friedman opinion and the Sedona Database Principles. The case was selected because it consolidates production duties, search obligations, counsel's technological competence, and sanctions within a single recent opinion. The analysis sets out four key issues: defining the scope of database evidence (Definition), clarifying query-based extraction conditions (Protocol), securing verification through hashes and logs (Validation), and promoting cooperation between legal and technical professionals (Competence). Together, these four support a comparative assessment of the reliability and reproducibility of structured data evidence. The aim is not to transplant U.S.-style e-discovery wholesale. Instead, it offers Korean industrial security disputes a set of practical review points for handling such evidence.

4

5,100원

본 연구는 현행 항공보안법 제50조제4항제2호와 제5항제2호에서 사용하는 소홀이라는 문언을 검토한다. 이 문언이 죄형법정주의상 명확성 원칙에 부합하는지가 핵심이다. 보안검색 업무는 항공보안검색요원이 개별적으로 수행하는 검색행위에 그치지 않는다. 항공보안검색요원은 항공보안장비를 운영하고, 보안검색절차를 이행한다. 보안검색감독자는 현장을 감독하고, 공항운영자는 품질관리체계를 운영한다. 보안검색은 이러한 업무가 유기적으로 결합된 예방적 통제 절차다. 군산공항 사건에서는 문형금속탐지장비가 작동하지 않았다. 이를 확인하지 못한 행위와 위험을 인식한 뒤 재검색 조치를 하지 않은 행위가 하나의 문언으로 평가되었다. 두 행위는 주체, 인식, 권한과 위법성 정도가 다르다. 산업·시설안전 법제와 국제 항공보안 기준을 비교하면 형사책임은 주체별 의무와 통제 권한에 따라 구분할 필요가 있다. 중대한 위반이나 결과도 고려해야 한다. 조직에 부과할 관리책임도 개인책임과 구분해야 한다. 개정 항공보안법인 법률 제21821호는 소홀이라는 문언을 삭제하였다. 개정법은 보안검색을 실시하지 않은 경우와 불성실한 보안검색으로 불법방해행위를 발생시킨 경우를 구분하여 처벌한다. 이에 따라 처벌 대상 행위와 결과가 구체화되었다. 명확성과 비례성도 개선되었다. 다만, 불성실한 실시를 판단하는 기준은 더 구체화할 필요가 있다. 불법방해행위와 맺는 인과관계도 명확히 해야 한다. 불법방해행위가 발생하지 않은 불성실한 보안검색은 위험 정도와 반복성을 고려하여 행정제재와 품질관리로 규율할 필요가 있다.

This study examines whether the term negligence (sohol) in Article 50(4)(2) and Article 50(5)(2) of the Korean Aviation Security Act satisfies the constitutional principle of clarity. Security screening is a preventive control process that combines aviation security equipment operation, screening procedures, on-site supervision, and organizational quality control. The Gunsan Airport case illustrates the need to distinguish failure to detect a walk-through metal detector malfunction from failure to take rescreening measures after recognizing the risk. The actors, awareness, authority, and degree of wrongfulness differ. A comparison with Korean industrial and facility-safety legislation and international aviation security standards shows that criminal responsibility should reflect each actor's duties and actual control authority. Amended Aviation Security Act No. 21821 deletes sohol and distinguishes a complete failure to conduct screening from unfaithful screening that causes an act of unlawful interference. This distinction improves clarity and proportionality. Further standards are needed for unfaithful performance and causation. Unfaithful screening that does not cause an act of unlawful interference should be addressed through proportionate administrative sanctions and quality control, while the separate offense of failing to conduct screening remains punishable without a result requirement.

5

7,000원

본 연구는 경기도 소재 중소기업을 대상으로 산업기술보호 수준에 영향을 미치는 요인을 실증적으로 조사·분석하고, 산업기술보호 정책에 대한 기업의 수요와 우선순위를 파악하여 정책적 시사점을 제시하는 데 목적이 있다. 이를 위해 중소기업 388개사를 대상으로 수집한 설문자료를 바탕으로 다중선형회귀분석과 IPA 분석을 실시하였다. 분석 결과, 보안정책 활동은 산업기술보호 수준에 유의한 정(+)의 영향을 미치는 것으로 나타났으며, 물리적 보안 활동 중 출입통제에서도 유의한 정(+)의 영향이 확인되었다. 반면 조직·인력 운영형태, 인적 보안 활동, 기술적 보안활동은 통계적으로 유의하지 않았으며, 산업기술보호 실태점검과 교육은 정(+)의 방향을 보였으나 통계적 유의성을 확보하지는 못하였다. 한편 IPA 분석에서는 네트워크 보안 강화와 보안솔루션 등 기술적 지원에 대한 정책 수요가 상대적으로 높게 나타났다. 이러한 결과는 기업의 산업기술보호 수준에 실질적으로 영향을 미치는 요인과 기업이 우선적으로 요구하는 정책지원 분야가 서로 다를 수 있음을 보여준다. 따라서 중소기업 산업기술보호 정책은 보안정책의 지속적인 운영과 출입통제 등 기업 내부에서 실질적인 보호 활동을 강화하는 한편, 자체적으로 확보하기 어려운 기술적 보호수단에 대한 정책지원을 연계하는 방향으로 추진될 필요가 있다.

This study examines the factors affecting industrial technology protection among small and medium-sized enterprises (SMEs) in Gyeonggi Province and identifies their priority policy needs. Using survey data from 388 SMEs, multiple linear regression and Importance- Performance Analysis (IPA) were conducted. The results show that security policy activities and access control had significant positive effects on industrial technology protection, while other security activities were not statistically significant. Inspections and security education showed positive but statistically insignificant effects. IPA results revealed high demand for technical support, particularly network security and security solutions. These findings indicate a gap between firms’ internal protection activities and their external policy support needs. Therefore, SME policies should strengthen practical internal protection activities while providing technical support that firms have difficulty securing on their own.

6

7,600원

원화 스테이블코인은 디지털 금융 혁신과 통화주권 확보의 주요 수단으로 주목받고 있으며, 국내에서도 제도화 논의가 활발히 이루어지고 있다. 그러나 기존 연구는 주로 법·제도적 측면이나 금융시장 영향 분석에 집중되어, 사회적 담론 구조와 시장 전망·확산 간의 구성적 관계를 실증적으로 분석한 연구는 부족한 실정이다. 이에 본 연구는 원화 스테이블코인에 대한 사회적 담론 구조를 분석하고, 시장 전망·확산과 관련된 조건들의 구성경로를 규명하고자 하였다. 이를 위해 2025년 1월 1일부터 2026년 1월 31일까지 네이버·구글·다음을 통해 온라인 텍스트 5,055건을 수집하고, 정제를 거친 최종 2,500건을 대상으로 키워드 빈도분석과 LDA 토픽모델링을 수행한 후 fsQCA로 구성경로를 분석하였다. 분석결과, 총 11개의 토픽이 도출되었으며, 주요담론은 디지털 금융혁신, 시장·활용, 정책·제도화, 통화·규제 환경, 글로벌 통화경쟁 및 핀테크 결제 등으로 나타났다. fsQCA 분석에서는 높은 수준의 시장 전망·확산(MOD)과 관련된 3개, 낮은 수준의 MOD와 관련된 4개의 구성경로가 각각 도출되었으며(전반적 설명력·일관성:0.422/0.879, 0.581/0.850), 이는 시장 전망·확산 관련 주제가 단일 조건이 아닌 다양한 조건조합과 함께 나타남을 보여준다. 본 연구는 LDA 토픽모델링과 fsQCA를 통합하여 원화 스테이블코인의 사회적 담론 구조와 시장 전망·확산 관련 구성경로를 분석하였다는 점에서 의의가 있으며, 향후 관련 정책 및 제도 논의를 위한 탐색적 기초자료를 제공한다.

KRW stablecoin has recently attracted considerable attention as a key instrument for digital financial innovation and monetary sovereignty. Along with the rapid growth of the global stablecoin market, discussions regarding its institutionalization and market expansion have become increasingly active in South Korea. However, existing studies have primarily focused on legal and institutional issues or financial market impacts, while empirical research on the social discourse structure and configurational pathways associated with market outlook and diffusion remains limited. Accordingly, this study aims to analyze the social discourse structure of KRW stablecoin and identify relevant combinations of conditions. To achieve this objective, online text data collected between January 1, 2025 and January 31, 2026 were analyzed using keyword frequency analysis and Latent Dirichlet Allocation (LDA) topic modeling. A total of 2,500 documents were included in the final analysis, yielding 11 topics. Subsequently, fuzzy-set Qualitative Comparative Analysis (fsQCA) was employed to examine configurational pathways related to market outlook and diffusion. The results identified major topics related to digital financial innovation, market and global utilization, policy and institutionalization, monetary and regulatory environment, global stablecoin utilization, and fintech-based payment systems. The fsQCA identified three pathways for market outlook and diffusion, with solution coverage of 0.422 and consistency of 0.879, and four pathways for low market outlook and diffusion, with corresponding values of 0.581 and 0.850. These findings suggest that market outlook and diffusion are associated with multiple combinations of technological, market, policy, and regulatory conditions rather than a single factor. This study contributes by integrating LDA topic modeling and fsQCA to examine the social discourse structure and configurational pathways of KRW stablecoin, providing empirical insights for future policy and institutional discussions.

7

5,500원

최근 디지털 전환과 공급망 고도화로 사이버보안은 침해사고의 예방·차단을 넘어 사고 이후의 대응과 복구를 포함하는 사이버복원력으로 확장되고 있다. 국내 「방위산업기술 보호법」은 방위산업기술의 유출 방지와 불법적 접근의 탐지·차단을 중심으로 보호체계를 규정하고 있으며, 「방위산업기술 보호지침」에서는 침해사고 이후의 복구 관련 조치도 규정하고 있다. 이에 본 연구는 현행 방위산업기술 보호체계를 보완하기 위해 EU CRA의 제품 복원력과 DORA의 운영 복원력 요소를 분석하였다. 분석 결과, 현행 보호체계는 침해사고 이후의 보호기능 유지와 대응·복구, 소프트웨어 구성요소 식별·관리 측면에서 보완이 필요한 것으로 나타났다. 이에 정보보호체계의 범위를 보완하고, 소프트웨어 구성요소 관리의 기본사항은 시행령에서, 세부 관리기준과 대응·복구 관련 이행사항은 보호지침에서 구체화하는 방안을 제안하였다. 본 연구는 CRA와 DORA의 관련 요소를 참고하여 현행 방위산업기술 보호체계의 구체적인 개선방안을 제시하였다는 데 의의가 있으며, 향후에는 제안된 개선방안의 실제 적용 가능성을 검증할 필요가 있다.

Recent advances in digital transformation and increasingly complex supply chains have expanded the scope of cybersecurity beyond the prevention and blocking of cyber incidents to cyber resilience, which encompasses response and recovery after an incident occurs. In Korea, the Defense Industrial Technology Protection Act primarily establishes a protection framework focused on preventing the leakage of defense industrial technology and detecting and blocking unauthorized access, while the Defense Industrial Technology Protection Guidelines also prescribe recovery-related measures following cyber incidents. Accordingly, this study analyzes the product resilience elements of the EU Cyber Resilience Act (CRA) and the operational resilience elements of the Digital Operational Resilience Act (DORA) to identify ways to strengthen the current defense industrial technology protection framework. The analysis shows that the current framework requires further improvement in maintaining protection functions after cyber incidents, strengthening response and recovery capabilities, and identifying and managing software components. Based on these findings, this study proposes expanding the scope of the information protection framework, specifying basic requirements for software component management in the Enforcement Decree, and detailing software component management criteria and response and recovery requirements in the relevant protection guidelines. This study contributes by proposing concrete improvements to the current defense industrial technology protection framework with reference to relevant elements of the CRA and DORA. Future research should further examine the practical applicability of the proposed measures.

8

9,400원

산업기술 유출의 약 80%는 전·현직 임직원에 의한 내부자 유출로 보고되고 있으나, 기존 데이터 유출 방지(DLP) 및 시그니처 기반 탐지 체계는 정의된 패턴 외의 변종 행위에 대한 일반화 성능이 낮고, 정량적 행동지표와 비정형 텍스트에 잠재된 유출 의도를 동시에 고려하지 못한다는 한계가 있다. 본 연구는 이러한 한계를 보완하기 위해 행동 시퀀스(Behavioral Sequence)와 텍스트 의도(Textual Intent)를 이중채널로 결합한 내부자 이상행동 탐지 모델 DC-IID(Dual- Channel Insider Intent Detection)를 제안한다. 본 연구의 기여는 Bi-LSTM, LoRA, Late Fusion 등 개별 알고리즘의 신규성에 있지 않다. 본 연구는 산업기술 유출이라는 특정 문제영역에서 (1) ‘무엇을 하였는가(what)’를 담는 행동 신호와 ‘왜 하였는가(why)’를 담는 의도 신호를 시간해상도와 표현공간이 서로 다른 이질적 정보원으로 규정하여 독립적으로 추론하고, (2) 이를 결정 수준(decision level)에서 결합하며, (3) 퇴직 예고·접근권한·부서 위험도 등 조직 컨텍스트를 두 채널의 추론 이후에 작동하는 별도의 위험 보정 계층으로 분리하고, (4) 그 산출물을 Human-in-the-loop 검토 및 산업보안 거버넌스 절차와 연결한 문제정의와 통합 구조에 기여의 초점이 있다. 행동 채널은 시스템 로그로부터 추출한 시계열 특성을 양방향 LSTM으로 인코딩하고, 의도 채널은 산업보안 코퍼스로 LoRA 미세조정한 한국어 LLaMA 계열 대규모 언어모델(KoLLaMA-7B, 약 70억 파라미터)이 6개 범주의 유출 관련 의도를 분류한다. 개별 텍스트의 의도 확률분포는 위험범주 심각도 가중을 거쳐 텍스트 단위 위험점수로 환산되고, 동일 사용자의 30일 윈도우에 속한 텍스트 위험 점수 가운데 최댓값이 사용자 단위 의도 위험점수로 집계된다. 두 채널의 위험점수는 Late Fusion 방식으로 결합되며, 퇴직 예고·접근 권한·부서 위험도 등 조직 컨텍스트가 위험점수를 직접 판정하는 독립 증거가 아니라 두 채널의 판정을 보정하는 항으로 반영된다. 공개 내부자 위협 데이터셋과 시나리오 자료로 구성된 총 3,600건의 사용자 시퀀스(개발셋 3,000건 + 구조적으로 분리된 합성 홀드아웃셋 600건)를 대상으로 개발셋 5-fold 교차검증과 홀드아웃 평가를 수행한 결과, 제안 모델은 F1=0.92, AUC=0.94를 달성하여 룰 기반 대비 F1 기준 39.4% 향상, 행동 단독 대비 16.5% 향상, 의도 단독 대비 12.2% 향상되었으며, 5개 폴드 전반에서 일관된 성능 차이가 관찰되었다. 다만 폴드 수가 5에 불과하고 동일 데이터에서 파생된 폴드 간 독립성 가정에 제약이 있으므로, 본 논문이 보고하는 p-value와 효과크기는 확증적 근거가 아니라 탐색적·보조적 근거로 해석되어야 한다. 또한 본 연구의 검증은 공개 데이터셋과 합성 시나리오로 구성된 통제된 실험환경에서의 유효성 확인에 한정되며, 실제 기업의 장기 운영데이터에 대한 외적 타당성 검증, 대규모 동시 사용자 환경에서의 처리성능 검증, LLM 의도 추론의 강건성 검증은 수행되지 않았다. 나아가 본 연구는 조직 내부의 보안·기술보호 의사결정체계, 인사관리, 보안교육과 연계되는 거버넌스 적용방안을 함께 제시하여, 기술적 탐지와 조직적 통제가 결합된 산업보안 관리체계의 개 념적 모형을 제안한다.

Approximately 80% of industrial technology leakages are attributed to current or former insiders. However, existing data-loss-prevention (DLP) and signature-based detection systems exhibit limited generalization to novel behavioral patterns and cannot simultaneously consider quantitative behavioral indicators and the latent leakage intent embedded in unstructured text. This study proposes DC-IID (Dual-Channel Insider Intent Detection), an insider anomaly detection model that integrates behavioral sequences and textual intent through a Late Fusion architecture. The contribution of this study does not lie in the algorithmic novelty of its individual components. Bi-LSTM encoders, LoRA fine-tuning, LLM-based classification, and late fusion are all established techniques. Rather, the contribution lies in the problem formulation and the layered design developed for the specific domain of industrial technology leakage: (i) framing behavioral logs (what was done) and communication texts (why it was done) as heterogeneous and complementary information sources with different temporal resolutions, (ii) combining them at the decision level rather than at the feature level, (iii) treating organizational context as a separate post-inference risk calibration layer rather than as an input feature, and (iv) connecting the resulting risk grades to human-in-the-loop review and industrial-security governance procedures. The behavioral channel encodes time-series features extracted from system logs using a bidirectional LSTM. The intent channel employs KoLLaMA-7B, a Korean pretrained LLaMA-family large language model (approximately 7 billion parameters), fine-tuned with LoRA on a Korean industrial-security corpus, to classify communication texts into six intent categories: routine work, dissatisfaction, external contact, data request, resignation intent, and negotiation. Each text is converted into a text-level risk score by weighting the five risk categories with severity coefficients normalized to [0, 1], and the user-level intent score is obtained by taking the maximum of the text-level scores within the same 30-day window, so that a single decisive utterance is not diluted by routine messages. The two risk scores are combined via a learned weighted sum, with an additional bounded calibration term for organizational context such as resignation notice, access privileges, and departmental risk. Organizational context is never used as an input feature of either channel; it enters only through this post-inference calibration layer. Because the calibration weight is limited to γ = 0.10, organizational context alone can never produce a Medium or High risk grade; the raw score therefore ranges over [0, 1.10] and can be equivalently normalized to [0, 1] by a strictly monotone transformation that leaves rankings, AUC, and grade assignments unchanged. Five-fold cross-validation on a development set of 3,000 user sequences and evaluation on a structurally separated synthetic holdout set of 600 sequences (3,600 sequences in total) demonstrated that DC-IID achieves an F1-score of 0.92 (development) and 0.89 (holdout), with an AUC of 0.94 and 0.92 respectively. Cross-validation folds were partitioned at the level of user sequences, which correspond one-to-one with users, so no user appears in both training and evaluation folds. The model outperformed rule-based detection by 39.4% in F1, behavior-only models by 16.5%, and intent-only models by 12.2%, and these differences were observed consistently across all five folds. Because only five folds were available and the folds share four-fifths of their training data, the accompanying p-values and effect sizes are reported as exploratory, supporting evidence rather than as confirmation of superiority. Ablation studies indicate that domain-specific LoRA fine-tuning contributes most significantly to performance, and that the intent channel effectively complements behavioral signals. The scope of validation is deliberately limited. All experiments were conducted on public benchmark data and synthetic scenarios in a controlled setting; no data from an operating company were used, and the holdout set is itself synthetic rather than externally sourced. Robustness of LLM-based intent inference under paraphrasing, indirect expressions, and prompt injection was not measured, and no throughput, concurrency, or GPU utilization benchmarks were conducted. Accordingly, this study reports effectiveness under controlled public and synthetic data rather than validated industrial deployment, and external validity in real operating environments remains future work. Beyond technical validation, the study presents a governance application framework linking the model's outputs to the organization's internal technology-protection responsibility structure prescribed by the Act on Prevention of Divulgence and Protection of Industrial Technology, human resources management, and security education, including an explicit six-stage human-in-the-loop verification procedure and the principle that risk grades constitute investigative prioritization signals rather than determinations of leakage. The statutory Industrial Technology Protection Committee established under the Minister of Trade and Industry is a national deliberative body and is distinguished here from the in-house review arrangements that organizations may adopt.

9

9,100원

금융거래 사기 탐지 시스템(FDS)은 진화하는 적대적 공격에 대응하기 위해 새로운 공격 데이터를 반영하며 반복적으로 재학습된다. 그러나 이러한 과정은 새 공격 유형에 적응하는 동시에 기존 공격 방어 능력을 잃는 치명적 망각(Catastrophic Forgetting)을 유발할 수 있으며, 이는 오탐과 미탐의 교차 증가와 장기적 탐지 성능 저하로 이어진다. 기존 금융 사기 탐지 벤치마크는 대부분 정적 데이터셋과 단일 시점 평가에 머물러, 반복적 공격-재학습 환경에서의 망각과 공격유형별 취약점을 효과적으로 평가하지 못한다. 본 연구는 이러한 한계를 해결하기 위해 공격자 페르소나 기반 적대적 거래 데이터셋 생성과 반복적 공격-재학습 과정을 결합한 동적 FDS 평가벤치마크를 제안한다. 임곗값 회피 분할결제, 동일 카드 반복 사용 등 6가지 공격 원형(Attack Archetype)을 기반으로 사기 행위자의 공격 시나리오를 페르소나로 정의하고, 이를 LLM과 실제 금융거래 분포를 결합해 현실적인 공격 거래 데이터로 생성하며, 공격 유형 정보를 유지한 채 재학습을 수행하여 기존 벤치마크가 다루지 못한 공격 유형별 취약점에 대한 방어 능력과 치명적 망각을 정량 평가할 수 있다. 실험 결과, 제안하는 페르소나 기반 생성 데이터셋을 학습에 사용한 경우의 분류 성능은 원본 실제 사기 거래로 학습한 경우보다 낮았으나, 공격 유형 라벨을 통해 유형별 취약점 진단(RDAP), 미학습 유형 일반화(LOTO), 유형-선택적 망각 분석등 공격유형에 대한 보다 구체적인 해석가능성을 보였다. 또한 피처 공간만을 이용한 유형 예측의 경우 기준선과 유사한 성능을 보였으며, 유형 신호는 LLM이 생성한 문제 공간에서 6개 공격 유형 중 4개에 한해 확인되었다.

Financial fraud detection systems (FDSs) are repeatedly retrained with newly observed attack data to adapt to evolving adversarial attacks. However, this process can lead to catastrophic forgetting, in which the system adapts to new attack types while losing its ability to defend against previously observed attacks. This phenomenon can result in a simultaneous increase in false positives and false negatives, ultimately degrading long-term detection performance. Existing financial fraud detection benchmarks largely rely on static datasets and single-point evaluations, making them inadequate for effectively assessing catastrophic forgetting and vulnerabilities to specific attack types in iterative attack– retraining environments. To address these limitations, this study proposes a dynamic FDS evaluation benchmark that integrates attacker-persona-based adversarial transaction data generation with an iterative attack–retraining process. We define fraudster attack scenarios as personas based on six attack archetypes, including threshold-evasion split payments and repeated use of the same card. Realistic adversarial transaction data are then generated by combining large language models (LLMs) with real-world financial transaction distributions. By retaining attack-type information throughout the retraining process, the proposed benchmark enables quantitative evaluation of both defensive capabilities against specific attack types and catastrophic forgetting, thereby addressing aspects that existing benchmarks fail to capture. Experimental results show that models trained on the proposed persona-based synthetic dataset exhibited lower classification performance than those trained on original real-world fraudulent transactions. Nevertheless, the availability of attack-type labels enabled more fine-grained interpretability of vulnerabilities across attack types through analyses such as vulnerability diagnosis by attack type (RDAP), generalization to unseen attack types (LOTO), and type-selective forgetting analysis. Furthermore, when predicting attack types using only the feature space, the performance was comparable to that of the baseline. Attack-type signals were identified for only four of the six attack types in the problem space generated by the LLM.

 
페이지 저장