Earticle

현재 위치 Home

한국산업보안연구 [Korean Journal of Industry Security]

간행물 정보
  • 자료유형
    학술지
  • 발행기관
    한국산업안보학회(구 한국산업보안연구학회) [The Korean Association for Industrial Security(구 The Korean Association for Research of Industrial Security)]
  • pISSN
    2765-2327
  • eISSN
    2733-8363
  • 간기
    연3회
  • 수록기간
    2009 ~ 2026
  • 등재여부
    KCI 등재
  • 주제분류
    사회과학 > 경영학
  • 십진분류
    KDC 325 DDC 330
많이 이용된 논문 (최근 1년 기준)
No
1

5,200원

AI 기술의 급속한 발전과 함께 생성형 AI의 활용이 증가함에 따라 AI 할루시네이션 문제를 해결하는 것이 중요한 과제로 부상하고 있다. 잘못된 정보나 비현실적인 결과물을 생성하는 AI 할루시네이션은 AI의 신뢰성과 투명성을 저해하며, 사회적 혼란을 초래할 수 있기 때문에 이에 대 한 체계적인 연구가 필요하다. 기존 선행연구는 대부분 기술적 측면에서 진행되었으나, 본 연구 에서는 빅데이터 분석 기법을 통해 AI 할루시네이션 관련 사회문제에 대한 새로운 시각을 제시 하고자 한다. 본 연구는 AI 할루시네이션 문제를 분석하기 위해 키워드 빈도분석, LDA 토픽 모델링과 감성 분석을 활용하였다. 연구 데이터는 ChatGPT 출시 이후의 기간인 2023년 1월 1일부 터 2024년 5월 31일까지 수집된 자료를 기반으로 분석하였으며, LDA 토픽 모델링을 통해 11개 의 토픽을 도출하였고, 감성 분석을 통해 대중의 인식을 긍정, 중립, 부정으로 구분하여 제시하 였다. 이와 같이 도출된 연구결과를 바탕으로 AI 할루시네이션 관련 이슈를 파악하고, 생성형 AI 관련 최대 이슈인 AI 할루시네이션에 대한 대중의 인식 및 반응을 파악하였다. 이러한 접근은 기 존 선행연구와 달리, 연구방법에 있어 큰 차별성을 가지며, AI 할루시네이션 관련 연구 분야에 새로운 시각을 제시하고, AI 기술의 발전 방향과 정책 수립에 학문적 및 정책적 시사점을 제공할 수 있을 것이다.

With the rapid development of AI technology and the increasing use of generative AI, solving the problem of AI hallucination has become an important issue. AI hallucination, which produces misleading information or unrealistic results, hinders the reliability and transparency of AI and can cause social disruption, so systematic research is needed. While most of the previous studies have been conducted from a technical perspective, this study aims to provide a new perspective on the social issues related to AI hallucination through big data analysis techniques. This study utilized keyword frequency analysis, LDA topic modeling, and sentiment analysis to analyze the AI hallucination problem. The research data was analyzed based on data collected from January 1, 2023 to May 31, 2024, the period after the launch of ChatGPT. 11 topics were derived through LDA topic modeling and public perceptions were classified into positive, neutral, and negative by sentiment analysis. Based on the research results derived in this way, we identified issues related to AI hallucination and identified public perceptions and reactions to AI hallucination, the biggest issue related to generative AI. Unlike existing prior research, this approach has a significant difference in research methods, presents new perspectives on AI hallucination-related research, and can provide academic and policy implications for the development direction and policy establishment of AI technology.

2

5,400원

이 연구에서는 아동·청소년들이 ‘디지털 네이티브’(Digital Native) 세대로서 AI 디지털교과서 및 개인정보의 안전한 활용을 위해 우리 사회의 불안전함을 인지하고 적절한 개인정보보호를 위한 지식을 확보할 수 있도록, 실제 개인정보 침해 사례를 기반으로 한 개인정보보호 교육콘텐츠의 개선 방향을 제시하고자 하였다. 아동·청소년의 개인정보보호 교육의 공공성은 지역, 학교 규모, 인원에 차별받지 않고 개인정보보호 대면 교육을 받을 수 있음을 의미하며, 또 보이스피싱과 딥페이크 등 사회적 현안에 대해 실효성 있는 교육을 통해 인식을 제고할 수 있음도 의미한다. 이 연구에서는 현재 활동하고 있는 개인정보보호 분야 전문 강사를 대상으로 한 설문조사 결과, 보이스피싱(스미싱, 큐싱 등) 및 딥페이크 관련 내용이 개인정보 교육에 포함 개선되어야 함을 확인하였다. 그리고 문헌연구에서는 개인정보보호 교육 시 한국인터넷진흥원(KISA) 등 외부 공식 교육을 받은 집단과 내부 자체 교육을 받은 집단으로 나누어 비교한 결과, 교육 효과에 대해 유의미한 차이가 있음을 입증하였다. 이에 이 연구에서는 초·중·고 학생들의 개인정보보호교육의 공공성을 위해서 개인정보위 전문 강사의 방문 교육이 필요하며 몰입도 있는 강의를 위한 콘텐츠를 개인정보 정책에 반영되도록 개선해야 한다는 정책적 시사점을 제시하였다.

In this study, we aimed to improve the privacy education content based on real cases of privacy breaches so that children and adolescents, as a generation of “digital natives,” can recognize the insecurity of our society and acquire the knowledge to properly protect their personal information for the safe use of AI digital textbooks and personal information. The openness of privacy education for children and adolescents means that they can receive face-to-face privacy education without being discriminated against by region, school size, or number of people, and it also means that they can raise awareness of social issues such as voice phishing and deep fakes through effective and immersive education. In this study, a survey of active privacy instructors confirmed that the content related to voice phishing (Smishing, Qshing, etc.) and deep fakes should be improved in privacy education. In addition, a literature study showed that there is a significant difference in the effectiveness of personal information protection education between those who received external formal education such as KISA and those who received internal self-education. Therefore, the study suggested policy implications that visiting lecturers specialized in personal information protection are necessary for public education of elementary, middle, and high school students, and that the content for immersive lectures should be improved to reflect personal information policies.

3

6,400원

최근 기업 및 공공기관에서 생성형 AI 기술을 적극적으로 도입하여 업무 자동화와 생산성이 향상되는 반면, 민감한 기술 정보 유출 위험도 증가하고 있다. 기존 연구는 개인정보 재식별 위 험 측정이나 악성 프롬프트 및 데이터 오염 대응에 주목하고 있어 업무 시 발생하는 중요기술 유 출 문제를 실시간으로 대응하기에 한계가 존재한다. 본 연구는 업무용 생성형 AI 모델의 안전한 활용을 위해 프롬프트 입력문서 내 중요 기술 정보를 식별하고 비식별처리하는 기술보존 비식별 화 기법을 제안한다. 구체적으로, 개체명 인식 기법으로 중요기술용어를 BIO 태깅하고, 퓨샷 기 반 거대언어모델을 활용하여 핵심 기술어를 추출한다. 이후 k-익명성 기반 기술보존 비식별화를 적용하여, 마스킹·대체어·토큰화와 비교분석한다. 특허 대표청구항을 대상으로 실험한 결과, BIO 태깅을 통한 기술용어 인식 정확도와 비식별화 전후 문서 간 의미론적 유사도가 높게 나타 나 원문 기술 정보 보존 효과를 확인하였다. 본 연구는 생성형 AI의 안전한 활용을 위한 실질적 방안을 제시함으로써, 기술정보 유출 방지와 업무 품질 유지를 동시에 달성할 수 있는 새로운 패 러다임을 제안하여 산업적·학문적 기여를 도모한다. 향후 연구에서는 다양한 산업 도메인에 적 용한 프레임워크로 확장하여 범용성을 확보하고자 한다.

While enterprises and public institutions are actively adopting generative AI technologies to enhance work automation and productivity, the risk of sensitive technical information leakage has also increased. Existing research has primarily focused on measuring personal information re-identification risks and addressing malicious prompts and data poisoning, presenting limitations in real-time response to critical technology leakage issues during business operations. This study proposes a technique-preserving de-identification method to identify and de-identify critical technical information in prompt input documents for the safe utilization of generative AI models in business contexts. Specifically, the approach employs Named Entity Recognition techniques to perform BIO tagging of important technical terms and utilizes few-shot learning to extract key technical terminology. Subsequently, masking, substitution, and tokenization methods are compared and applied. Experimental results on representative patent claims demonstrate high accuracy in technical term recognition through BIO tagging and high semantic similarity between documents before and after de-identification, confirming the effectiveness of preserving original technical information. This research presents a practical solution for safe generative AI utilization, proposing a new paradigm that simultaneously achieves technical information leakage prevention and work quality maintenance, thereby contributing to both industrial and academic advancement. Future research aims to expand the framework to various industrial domains to ensure broader applicability.

4

5,700원

불법도박, 불법 웹툰, 불법 OTT와 같은 불법 콘텐츠가 큰 사회적 문제를 초래하고 있다. 건전 한 콘텐츠 유통 및 저작권 보호를 위해서 반드시 근본적인 해결책이 필요한 시점이다. 이런 문제 를 해결하고자 관련 법령이나 여러 차단 기술이 생겨났지만, 효과는 미비하고 계속해서 불법시 장에서의 기술 또한 발전해 나가기 때문에 해결이 쉽지 않다. 본 논문에서는 불법 콘텐츠 웹사이 트를 효율적으로 무력화하는 방법에 관해서 연구한다. 기존 기술들을 조사하여 문제점에 대해서 분석하고 그 분석을 통해 블록체인과 토큰 이코노미 기반의 화이트 DDoS 공격시스템을 설계한 다. 기존의 DDoS 공격의 경우 악성코드나 바이러스 등을 통해 좀비 PC 형태로 만든 후 공격에 동원했다. 하지만 화이트 DDoS 공격의 경우 불법 콘텐츠 웹사이트를 무력화하기 위한 선의의 임무를 수행하는 서비스거부공격으로써 사전 동의를 얻은 PC와 스마트폰으로 진행한다. 공격이 종료되면 참여율에 따라 토큰 또는 코인으로 보상받으며 참여내역이 블록체인에 저장되어 투명 성, 독립성, 탈중앙화를 추구한다. 이런 비즈니스 모델을 설계 후 실험을 통해서 어떤 효과가 있 는지에 대해서 평가한다. 마지막으로 민관 협조사항에 대해서도 집어본다.

Illegal contents such as illegal gambling, illegal webtoons, and illegal OTT are causing great social problems. A fundamental solution is needed for healthy content distribution and copyright protection. Related laws and blocking technologies have been developed to solve these problems, but their effectiveness is limited and the technology in the illegal market is constantly evolving, therefore it is not easy to solve. In this paper, we study how to efficiently neutralize illegal content websites. We investigate the existing technologies, analyze the problems, and design a white DDoS attack system based on blockchain and token economy. In the case of conventional DDoS attacks, zombie PCs are created through malware or viruses and then mobilized for attacks. However, in the case of a white DDoS attack, it is the denial-of-service attack that performs a good faith mission to neutralize illegal content websites and is carried out with PCs and smartphones that have obtained prior consent. At the end of the attack, participants are rewarded with tokens or coins depending on the participation rate, and the participation details are stored on the blockchain to pursue transparency, independence, and decentralization. After designing this business model, we evaluate its effectiveness through an experiment. Finally, we discuss public-private cooperation.

5

이용수:54회 생성형 AI를 활용하는 산업현장의 기술 유출 위협 분석과 기술안보 정책 및 전략

류정화, 전유란, 김수경, 이일구

한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제14권 제3호 2024.12 pp.221-241

※ 기관로그인 시 무료 이용이 가능합니다.

5,700원

최근 생성형 AI(Artificial Intelligence)는 인간의 지식수준을 넘어서 발전하고 있으며, 산업 전 반에 걸쳐 활용되고 있다. 기술 안보의 관점에서, 생성형 AI를 활성화하기 위한 정책들은 활발하 게 논의되고 있지만 생성형 AI를 악용한 산업기술 유출 문제와 법적 대응 방안은 부재한 상황이 다. 본 논문은 국내외 AI 규제 동향과 종래 수동적 도구를 이용한 기술 유출 대응에만 초점을 맞 춘 기존 산업기술보호법의 한계를 분석한다. 이를 바탕으로 생성형 AI의 사용자에 따른 차등적 접근 통제 정책 및 최고정보보안임원(CISO, Chief Information Security Officer) 중심의 산업기술 유출 위협에 대한 법적·정책적 대응 방안을 제시한다. 제안하는 방법론은 새로운 기술 안보 위 협 요소에 대한 선제적인 대응 조치로 기능할 것이며, 국가경쟁력을 제고하는 효과적인 수단으 로 자리매김할 것이다.

Recently, generative artificial intelligence (AI) has advanced beyond the limits of human knowledge and is being utilized across various industries. From a cybersecurity perspective, while policies to activate generative AI are actively being discussed, there is a lack of legal responses to the misuse of this technology for industrial technology leaks. This paper analyzes the limitations of existing industrial technology protection laws that focus solely on passive tools like emails and the trends in AI regulations both domestically and internationally. Based on this analysis, it proposes Differentiated Access Control policies for users of generative AI and legal measures centered around the Chief Information Security Officer (CISO) to address the threats of industrial technology leakage. The proposed methodology will function as a proactive measure against new cybersecurity threats and establish itself as an effective means to enhance national competitiveness.

6

7,500원

미국 국방부의 CMMC 도입은 K-방산의 글로벌 확대를 위한 필수 관문이지만, 국내 제도와의 차이로 인해 우리 기업들은 상당한 기술적·제도적 제약에 직면해 있다. 본 연구는 이러한 문제 의식 하에, 실증 및 비교 연구 방법론을 통해 국내 방산기업의 CMMC 2.0 대응을 위한 구체적인 해결 방안을 제시하고자 하였다. 이를 위해 CMMC 2.0과 국내 통합실태조사를 심층 비교·분석 하고, 암호화 인증체계 충돌, C3PAO 국내 부재, 평가 중복이라는 3대 핵심 제약 요인을 도출하 였다. 본 연구는 기존의 거시적 정책 제안을 넘어, 기업이 즉시 적용할 수 있는 실천적 전략을 제시했다는 점에서 차별성을 갖는다. 첫째, 이중 암호화 모델의 성능을 실증적으로 검증하여 기 술적 대안의 현실성을 입증하였다. 둘째, 국내 C3PAO 자립을 위한 단계별 이행 전략을 구체적으 로 설계하였다. 셋째, CMMC 2.0 인증과 통합실태조사를 연계하는 인센티브 기반의 평가 효율화 모델을 제안하였다. 본 연구는 국내 방산보안 수준을 높이고 기업의 부담을 경감시키는 실질적인 해결책을 제시함으로써, 정부의 효율적인 지원 정책 수립에 필요한 근거를 제공하고 국내 방산기 업의 글로벌 경쟁력 강화에 기여할 수 있다는 점에서 높은 학술적·정책적 기여도를 가진다.

While the adoption of the U.S. Department of Defense’s CMMC is essential for the global expansion of the South Korean defense industry, domestic companies face significant technical and institutional constraints due to discrepancies with local systems. This paper, through an empirical and comparative study, aims to present concrete solutions for South Korean defense companies to navigate CMMC 2.0 compliance. Through an in-depth comparative analysis of CMMC 2.0 and the domestic Integrated Security Inspection, this research identifies three core challenges: conflicts in the cryptographic certification system, the absence of domestic C3PAOs, and redundant audit overlaps. This study is differentiated by proposing practical and actionable strategies that move beyond existing macro-level policy suggestions. First, it empirically validates the feasibility of a dual-encryption model. Second, it designs a phased implementation strategy for establishing domestic C3PAO capabilities. Third, it proposes an incentive-based linkage model to streamline domestic audits for CMMC 2.0-certified companies. The contribution of this research lies in providing tangible solutions that enhance defense industrial security and alleviate corporate burdens. It offers a basis for the government to establish effective support policies and ultimately contributes to strengthening the global competitiveness of the nation’s defense industry.

7

6,600원

2024년 2월 개정된 「부정경쟁방지법」은 ‘영업비밀 훼손‧멸실‧변경 행위’에 대하여「형법」과 「정보통신망법」보다도 강한 형사처벌규정을 도입하였다. 이는 영업비밀 등이 가진 경제적 가치를 고 려한 것이다(제9조의3). 다만 목적범으로 규정하고 있기 때문에 실수나 불가항력적인 서버공격 등으로 인한 경우는 처벌할 수 없다(제18조 제3항). 법인에 대한 벌금형을 개인에 대한 벌금형의 3배로 중과한 것과 개인과 법인의 공소시효를 동일하게 적용하도록 규정한 것은 법인의 범죄억지 측면에서 타당하다(제19조 및 제19조의2). 영업비밀 침해물 등에 대한 몰수규정 도입도 영업비밀 침해로부터 만들어진 물건의 유통에 따른 2차 피해 방지 측면에서 적절하다(제18조의5). 2025년 1월 개정된 「산업기술보호법」의 ‘산업기술 삭제‧반환 거부‧기피‧사본을 보유하는 행위’의 열거는 그 행위자체만으로 처벌대상이 될 수 있기 때문에 효과적인 규정이다(제14조 제4호). 또한 기술유출 브로커의 처벌 규정 도입도 적절하다고 할 것이다(제14조 제6호). 다만, 기술유출 정황이 매우 큼 에도 불구하고 이를 제대로 살펴보지 않고 이직을 알선하는 등 브로커의 ‘중과실’을 처벌대상으로 할 것인지도 차후 검토할 필요가 있다. 부정수출행위를 열거한 것은 그간 입법상 불비를 보완한 것으로 보인다(제14조 제8호). 한편, 제14조 제7호는 ‘거짓이나 그 밖의 부정한 방법으로 승인을 얻어’라는 문구로 개정될 필요가 있다. 제14조 및 제36조의 목적요건이 고의요건으로 전환되었다. 이에 부정한 목적이 있었는지 여부에 대한 입증은 필요 없으며, 고의범은 ‘미필적 고의’도 포함하 기 때문에 처벌이 훨씬 더 용이해진 상태로 과잉범죄화가 우려된다. 2024년 12월 개정된 「방위산 업기술보호법」에서는 방위산업기술 삭제‧반환 거부‧기피‧사본을 보유하는 행위에 대한 규정이 신 설되었다(제10조 제4호 및 제5호). 다만, 「산업기술보호법」과 같이 ‘원시코드’까지 그 대상으로 열 거될 필요가 있다. 방위산업기술의 국외유출에 대한 처벌이 ‘1년 이상 징역, 20억원 이하 벌금’으 로 상향되었다(제21조제1항). 방위산업기술을 중요성을 감안하자면 국가핵심기술 또는 국가첨단 전략기술의 형사처벌 수준까지 상향하는 것고 고려할 필요가 있다고 생각된다.

In February 2024, the revised 「Unfair Competition Prevention Act (UCPA)」 introduced criminal penalties for the damage, loss, or alteration of trade secrets. The law requires intentional misconduct for punishment, excluding cases involving mistakes or force majeure events, such as server attacks. Corporations are subject to fines three times higher than those for individuals, and both individuals and corporations now share the same statute of limitations. The introduction of confiscation provisions aims to prevent secondary damage from the distribution of goods derived from trade secret violations. In January 2025, the revised 「Industry Technology Protection Act (ITPA)」 made actions such as deleting, refusing to return, avoiding, or possessing copies of industrial technology punishable offenses. It also introduced penalties for brokers involved in technology leakage. However, further consideration is needed regarding the penalization of brokers for 'gross negligence.' Additionally, the Act addresses fraudulent export activities, but the phrasing should be updated to specify actions such as “obtaining approval by false or fraudulent means.” The law’s shift to intentional misconduct requirements could lead to over-criminalization. In December 2024, the 「Defense Industry Technology Protection Act (DITPA)」 implemented similar provisions for the deletion or withholding of defense industry technology. However, the inclusion of ‘source code’ as a protected item should also be considered. Penalties for the outflow of defense industry technology were raised to imprisonment for more than one year and fines of up to 2 billion won. Since defense industry technology is important, it is reasonable to raise the level of criminal punishment to be similar to that for national core technologies or national strategic technologies.

8

5,800원

사이버 범죄는 정보통신기술의 발달과 함께 등장한 새로운 유형의 범죄로, 기존의 물리적 공 간을 기반으로 한 전통 범죄와 달리 사이버 공간이라는 비물질적 환경에서 발생한다. 이러한 사 이버 범죄는 컴퓨터와 네트워크가 없이는 성립할 수 없는 ‘사이버 의존 범죄’와 전통적 범죄가 사 이버 공간을 수단으로 변형된 ‘사이버 가능 범죄’로 구분되며, 그 정의와 분류는 국가 및 국제기 구마다 다양하게 존재한다. 디지털 기술의 확산과 사이버 공간의 일상화는 사이버 범죄의 양상 과 수법을 다변화하고 고도화시키며, 전통적 수사체계의 한계를 드러내고 있다. 사이버 범죄는 로그, 통신기록, 암호화폐 거래정보, SNS 및 다크웹 정보 등 수많은 디지털 흔적을 단서로 남기 고 있으나, 이러한 단서들은 비정형적이고 분산되어 있으며, 실시간 수집과 분석이 이루어지지 않을 경우 증거로서의 가치를 상실하기 쉬운 특성을 가진다. 본 연구는 사이버 범죄 수사에서 핵 심이 되는 수사단서의 특성과 유형을 분류하고, 이를 체계적으로 수집·분석·활용하기 위한 통 합 분석 프레임워크를 설계하였다. 제안된 프레임워크는 다중 출처 단서의 자동 수집, 데이터 전 처리 및 메타처리, 지식그래프 기반 사회연결망 분석, AI 기반 용의자 추론 및 위험도 평가, 시각 화 및 수사 피드백 순환 구조로 구성된다. 이 과정은 수사단서의 비정형성, 실시간성, 고도의 은 닉성, 법적 민감성 등 사이버 단서의 특수성을 반영하여 설계되었으며, 수사 효율성과 정확도를 동시에 제고하는 데 목적이 있다. 프레임워크의 효율성을 높이기 위해서는 수사정보 공유체계 정비, 범정부 통합 플랫폼 구축, AI 기술 수용성 확대, 리빙랩 기반의 실증 환경 조성, 수사 전문 인력 양성 등이 필요하다. 후속연구에서는 실증 기반의 성능 평가 및 법적 정합성 검토 등이 이 루어져야 할 것이다.

Cybercrime is a new form of criminal activity that has emerged alongside the advancement of information and communication technology (ICT). Unlike traditional crimes that occur in physical space, cybercrimes unfold in the intangible environment of cyberspace. These crimes are generally classified into two categories: cyber-dependent crimes, which cannot occur without the use of computers and networks and cyber-enabled crimes, which are conventional crimes transformed through digital means. Definitions and classifications vary by country and international organization, reflecting the diverse nature of the phenomenon. The widespread adoption of digital technologies and the normalization of cyberspace have significantly diversified and intensified cybercrime patterns, exposing limitations in traditional investigative systems. While cybercrimes leave behind digital traces such as logs, communication records, cryptocurrency transactions, social media content, and dark web data, these clues are often unstructured, decentralized, and perishable, thereby requiring immediate and systematic collection and analysis. This study aims to classify the types and characteristics of investigative clues in cybercrime and proposes an integrated analytical framework to systematically collect, process, analyze, and utilize them. The framework consists of automated multi-source clue collection, data preprocessing and metadata processing, knowledge graph-based social network analysis, AI-driven suspect inference and risk assessment, and visualization with investigator feedback. It reflects key attributes of cybercrime clues— unstructuredness, real-timeness, concealability, and legal sensitivity—and is designed to improve both the efficiency and accuracy of cyber investigations. To enhance the practical utility of the framework, policy recommendations include establishing a national information-sharing system, developing a cross-agency investigative platform, improving institutional AI acceptance, building living-lab testing environments, and fostering specialized human resources. Future research should focus on empirical validation of performance and legal compatibility of AI-based inference systems.

9

6,000원

이 연구는 퀴싱(Quishing)이라는 새로운 피싱 형태의 개념, 현황, 범죄 발생 과정, 그리고 사회 공학적 기법의 적용 메커니즘을 고찰하였다. 퀴싱은 COVID-19 팬데믹 이후 QR코드 사용이 보 편화되면서 급증한 사이버범죄로, 공격자가 사용자의 신뢰를 악용하여 민감한 정보를 탈취하거 나 악성 코드를 전파하는 방식으로 이루어진다. 이 연구는 일상활동이론 및 생활양식/노출이론 과 사회공학적 기법의 메커니즘을 통해 퀴싱 범죄피해의 발생 메커니즘을 분석하였다. 거시적 관점에서 일상활동이론에 따르면, 동기화된 가해자, 적합한 대상, 그리고 유능한 보호자의 부재 라는 세 가지 요소가 범죄 발생의 주요 조건으로 작용한다. 또, 중범위적 관점에서는 생활양식/ 노출이론의 핵심 개념인 노출, 접근성, 유인성, 보호 부재가 퀴싱의 핵심 조건으로 작동할 수 있 다고 보았다. 한편, 이 연구는 미시적 관점에서 사회공학적 기법의 다양한 메커니즘인 신뢰 구 축, 긴급성 조성, 사회적 증거 활용을 통해 공격자가 피해자를 심리적으로 조작하고, 피해자의 인지적 한계를 활용하여 범죄를 유발하는 과정을 상세히 다루었다. 그 결과, 퀴싱 범죄는 사용자 의 심리적 취약성과 기술적 특성을 동시에 악용하는 복합적 기법임을 확인하였다. 이러한 문제 를 해결하기 위해서는 기술전략 측면에서 QR코드 스캐너 및 리디렉션 과정에 대한 보안 기술 보급, 사용자 교육 측면으로, 안전한 QR코드 이용 습관을 위한 교육과 실습, 정책개선 측면에서 QR코드 생성, 사용 및 배치에 대한 표준화와 의심스러운 QR코드 신고 플랫폼 신설 등을 제안하였다.

This study explores the concept, current state, crime mechanisms, and applications of quishing, a rising cybercrime exploiting QR codes, which has grown with their widespread use post-COVID-19. Quishing manipulates user trust to steal data or spread malware. Using routine activity theory, lifestyle/exposure theory, and social engineering techniques, the study examines factors enabling such crimes. At the macro level, routine activity theory highlights a motivated offender, a suitable target, and the absence of a capable guardian. Mid-level insights from lifestyle/exposure theory emphasize exposure, accessibility, attractiveness, and lack of protection. Micro-level analysis reveals attackers’ use of psychological manipulation, such as trust-building, urgency creation, and social proof, to exploit victims’ cognitive vulnerabilities. Findings confirm that quishing combines technical and psychological exploitation. Solutions proposed include enhancing QR security technologies, educating users on safe QR practices, and standardizing QR code creation and reporting mechanisms. These strategies aim to reduce quishing threats and strengthen cybersecurity.

10

4,900원

대규모 언어모델(LLM)의 활용이 보편화됨에 따라, 프롬프트 인젝션(Prompt Injection), 데이터 탈취 등 이를 악용한 신종 보안 위협이 급증하고 있다. 기존의 방어 체계로는 예측 및 대응이 어 려운 이러한 공격들에 효과적으로 대처하기 위해, 본 연구는 LLM 기반 공격의 행위적 특성을 체 계적으로 분석하고 이를 기반으로 새로운 보안 프레임워크를 제안하는 것을 목적으로 한다. 이 를 위해, 2023년 1월부터 2025년 6월까지 공개된 실제 공격 사례들을 수집하여 ‘단일 행위 (Atomic Unit)’ 단위로 분해하였다. 이후, 각 행위를 MITRE ATT&CK 프레임워크에 매핑하여 공격 의 핵심 전술, 기술, 절차를 구조화하였다. 분석 결과, 공격자가 AI를 공격 준비 단계의 '보조 도 구'로 활용하는 패턴과 LLM 자체의 취약점을 직접 공격하는 패턴 등 핵심적인 공격 유형을 도출 할 수 있었다. 본 연구가 제시하는 공격 패턴 분석 및 프레임워크는 날로 지능화되는 LLM 위협 에 대한 산업 방어 전략 수립에 중요한 기초 자료를 제공한다는 점에서 의의를 갖는다.

With the widespread adoption of Large Language Models (LLMs), novel security threats such as prompt injection and data exfiltration are rapidly increasing. To effectively counter these attacks, which are difficult to predict and respond to with existing defense systems, this study aims to systematically analyze the behavioral characteristics of LLM-based attacks and propose a new security framework based on the findings. To this end, real-world attack cases from January 2023 to June 2025 were collected and decomposed into 'Atomic Units.' Subsequently, each action was precisely mapped to the MITRE ATT&CK framework to structure the core Tactics, Techniques, and Procedures (TTPs) of the attacks. The analysis identified key attack patterns, including the use of AI as an 'auxiliary tool' in the attack preparation phase and patterns that directly exploit the vulnerabilities of the LLM itself. The attack pattern analysis and framework presented in this study hold academic and practical significance by providing foundational data for establishing proactive defense strategies at both the industrial and national levels against increasingly sophisticated LLM threats.

 
페이지 저장