년 - 년
APT 공격 사례 분석을 통한 사이버 킬체인과 TTP에 대한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제20권 제4호 2020.10 pp.91-101
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
과거 해외에서 발생한 APT 공격사례를 사이버 킬체인 모델과 TTP 모델로 분석하였다. 분석 결과 사이버 킬체인 모 델은 전체적인 윤곽을 파악하는데 효과적이지만 구체적인 방어 전략을 수립하는 데에는 부적합하며, TTP 모델로 분석 해야만 실질적인 방어 체제를 구비하는데 적합함을 알 수 있었다. 이러한 분석 결과를 바탕으로 사이버 공격을 대비하 는 관점에서 심층 방어선 구축에 적합한 TTP 모델 관점에서 방어 기술 개발이 필요함을 제시한다.
We analyzed APT attack cases that occurred overseas in the past using a cyber kill chain model and a TTP model. As a result of the analysis, we found that the cyber kill chain model is effective in figuring out the overall outline, but is not suitable for establishing a specific defense strategy, however, TTP model is suitable to have a practical defense system. Based on these analysis results, it is suggested that defense technology development which is based on TTP model to build defense-in-depth system for preparing cyber attacks.
산업망에서의 APT(지능형 지속위협) 침투경로 분석 및 대응방안 고찰 - 스턱스넷 사례를 중심으로 -
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제5권 제1호 통권 제7호 2015.06 pp.223-253
※ 기관로그인 시 무료 이용이 가능합니다.
7,200원
최근에는 과거의 단순한 해킹공격과는 달리 산업망을 위협하는 APT, Cyber War 등의 공격이 문제가 되고 있다. 그러던 중 2010년 6월, 이란 원자로를 파괴 한 신종 악성코드인 「스턱스넷」이 출현했다. 이로 인해 과거 안전하다고 여겨 졌던 산업시설의 안전성에 대한 우려가 점차 가중되었다. 그러나 국내 산업계에 는 여전히 산업망 보안에 대한 무관심, 관리 감독할 국가 기관의 부재, 관련 법 규정의 미비 등 수많은 문제점이 남아있다. 이에 따라 우리는 산업망을 보호하 기 위해 APT의 침투경로와 공격기법을 분석하고 국내 산업망 취약부분에 대한 정책적, 기술적 방어대책을 고찰코자 한다.
Unlike simple hacking attack before, recently, new attacks such as APT and Cyber War are making serious problems and becoming new threat for industrial network. In June 2010, it was emerged new exploit 「Stuxnet」 which destructed Iran's atomic reactor. From this, though industrial facilities is considered as safety still now but the safety concern about industrial facilities is bigger than before. But It seems that there are many problems in our country such as indifference about safety of industrial facilities, absence of national agency for supervisory duties, lack of related law and regulatory policy and so on. Therefore, for industrial network security, we are considering new strategy and technical defense methodology for domestic industrial network's vulnerability through analysis of APT's intrusion paths and attack method.
지능형 지속 위협 공격 (APT) 특성 분석 - 2009 ~ 2012 년, 국내 방위산업계 공격을 중심으로 KCI 등재후보
한국방위산업학회 한국방위산업학회지 제19권 제2호 2012.12 pp.73-89
※ 기관로그인 시 무료 이용이 가능합니다.
5,100원
Attempts to distribute malware using social engineering email deployment to the domestic defense industry have been detected from CY 2009 to 2012, up to the present. The analysis of the characteristics of the attacks showed their consistency and specificity. They commonly use social engineering to distribute malware. In addition, they have typical APT characteristics. On the other hand, the persistence of the same techniques and forms was seen. These are done by the same group or the same person who launched the APT attack. According to the APT attack characteristics, there is a limit to malware defense and prevention. Therefore, all of the executives and staff members understand and share the characteristics of APT and need to be strengthened in security management. Only prevention can reduce the risk of a security incident from an APT attack via social engineering. <Keywords> APT, Advanced Persistent Threat, Social Engineering Attack
SDN 구조기반 악성봇 및 APT 대응 알고리즘 연구 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제5호 2021.12 pp.87-95
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
SDN(Software Defined Networks)은 기존 네트워크 기술의 폐쇄성과 복잡성의 문제를 극복하기 위하여 소프트웨어 애플리케이션을 사용한 중앙집중적 관리와 제어를 할 수 있는 네트워크 구조이다. 프로그래밍 기반의 네트워크 서비스 를 제공함으로써 악성봇 및 APT와 같은 사이버위협에 대해 네트워크 수준에서의 효과적인 대응을 할 수 있다. 본 논 문에서는 SDN 구조기반에서 악성봇 및 APT의 감염이 되더라도 '명령 및 제어(C&C)' 연결을 차단함으로써 사이버 공 격단계를 더 이상 진행되지 못하도록 대응하여 무력화시키는 방식을 제안하고자 한다. 제안하는 기법은 DNS 싱크홀을 활용하여 C&C서버로의 연결을 시도하는 악성봇 및 APT에 감염된 호스트의 IP를 식별/차단하고, DNS 싱크홀을 우회 하여 외부 DNS로 질의하는 내부 호스트의 트래픽을 DNS 싱크홀 재전송하여 그 결과값으로 C&C서버와의 연결을 차 단한다. 또한, 도메인이 아닌 IP 방식의 직접 접속을 차단하고, 식별되지 않은 신규 C&C서버 도메인으로의 접근을 식 별하고 차단할 수 있다. 제안한 기법의 성능은 실험을 통하여 검증하였으며, 악성봇 및 APT 위협에 효과적인 대응이 가능한 것으로 확인되었다.
SDN (Software Defined Networks) is a network structure that enables centralized management and control using software applications to overcome the problems of closure and complexity of existing network technologies. By pro viding programming-based network services, it may be possible to effectively respond to cyber threats such as malicious bots and APT at the network level. In this paper, we propose a method to neutralize the cyber attack stage by blocking the 'command and control (C&C)' connection even if it is infected b y malicious bots and APT based on the SDN structure. The proposed technique uses DNS sinkholes to identify/block the IPs of hosts infected with malicious bots and APT that attempt to connect to the C& C server, and blocks the connection with the C&C server by returning the result of retransmitting the t raffic from the internal host that queries the external DNS to bypass DNS sinkhole. In addition, it is po ssible to block direct access by IP method rather than a domain name, and to identify and block access to unidentified new C&C server domains. The performance of the proposed technique was verified throu gh experiments, and it was confirmed that it is possible to effectively respond to malicious bots and AP T threats.
산업기술 유출 방지를 위한 보안 프레임워크 연구 KCI 등재
한국융합보안학회 융합보안논문지 제23권 제4호 2023.10 pp.33-41
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 지능형 지속위협(APT) 공격조직은 국가핵심기술을 보유한 기업이나 기관을 대상으로 다양한 취약점 및 공격기 법을 악용해서 랜섬웨어를 유포한 후 금전을 요구하거나 국가적으로 중요한 산업기밀 자료를 절취해서 암시장(다크웹)에 유통시키거나 제3국에 판매 또는 기술격차를 줄이는데 활용하는 등 국가차원의 보안대비가 필요하다. 이 논문에서는 Kimsuky, Lazarus 등한국을대상으로APT 공격으로산업기밀유출피해를입혔던공격조직의 공격수법을 MITRE ATT&CK 프레임워크로분석하고, 기업의 보안시스템이추가적으로갖추어야 할 사이버 보안관련 관리적, 물리적 및 기술적 보안요구 사항 26개를 도출하였다. 또한, 보안 요구사항을 실제 보안업무에 활용할 수 있도록 보안 프레임워크 및 시스템 구성 방안도 제안하였다. 이 논문에서 제시한 보안요구 사항은 보안시스템 개발 및 운영자들이 기업의 산업기밀 유출 방지를 위한 보안업무에 활용할 수 있도록 실질적인 방법 및 프레임워크를 제시했으며 향후 이 논문을 기반으로 다양한 APT 공격그룹의 고도화·지능화된 공격을 분석하고 관련 보안대책 연구가 추가적으로 필요하다.
In recent years, advanced persistent threat (APT) attack organizations have exploited various vulnerabilities and attack techniques to target companies and institutions with national core technologies, distributing ransomware and demanding payment, stealing nationally important industrial secrets and distributing them on the black market (dark web), selling them to third countries, or using them to close the technology gap, requiring national-level security preparations. In this paper, we analyze the attack methods of attack organizations such as Kimsuky and Lazarus that caused industrial secrets leakage damage through APT attacks in Korea using the MITRE ATT&CK framework, and derive 26 cybersecurity-related administrative, physical, and technical security requirements that a company's security system should be equipped with. We also proposed a security framework and system configuration plan to utilize the security requirements in actual field. The security requirements presented in this paper provide practical methods and frameworks for security system developers and operators to utilize in security work to prevent leakage of corporate industrial secrets. In the future, it is necessary to analyze the advanced and intelligent attacks of various APT attack groups based on this paper and further research on related security measures.
산업제어시스템에 대한 고도화된 Kill Chain 공격 기법 연구 KCI 등재
한국EA학회 정보화연구 제17권 4호 2020.12 pp.331-342
※ 기관로그인 시 무료 이용이 가능합니다.
4,300원
산업제어시스템은 일반적으로 IT 시스템과 분리된 폐쇄망으로 운영되며 제어망 네트워크 통신 을 위한 전용 프로토콜을 사용해 왔다. 그러나 정보통신 기술의 발달로 개방형 프로토콜 환경으로 변 화하고 있다. 또한, 다양한 ICT 환경과 연계되어 상호 의존적 시스템을 구성하면서 제어망은 내부자 위협을 포함하여 침투 경로가 다양해졌다. 특히 에너지 분야와 같은 기반시설에 대한 사이버 위협은 사회적으로나 경제적으로나 큰 손실을 발생시킬 수 있다. 따라서 공격이 발생하기 이전에 방어 전략 을 수립해야 하며, 공격에 대해 효과적인 대응 체계를 구축해야 한다. 본 연구에서는 OT의 다양한 산 업 중 에너지 분야에 대해 1년간 발생했던 침해 사례를 중심으로 보안 취약점을 분석한다. 또한, MITRE ATT&CK 프레임워크를 활용하여 공격자의 침투 전략 및 공격 기술을 분석하여 제어시스템 에 잠재적인 영향을 미칠 수 있는 위험을 식별하고 대응 전략을 제시한다.
Industrial control systems are generally operated as a closed network separated from the IT system and have used a dedicated protocol for control network communication. However, with the development of information and communication technology, it is changing to an open protocol environment. In addition, as the system is interdependent in connection with various ICT environments, the control network has diversified penetration routes including insider threats. In particular, cyber threats to infrastructure such as the energy sector can cause great losses both socially and economically. Therefore, it is necessary to establish a defense strategy before an attack occurs, and an effective response system to the attack must be established. This study analyzes security vulnerabilities based on cases of infringements that have occurred for one year in the energy field among various industries of OT. In addition, by using the MITER ATT&CK framework, the attacker's intrusion strategy and attack technology are analyzed to identify risks that may have a potential impact on the control system and propose a countermeasure strategy.
7,300원
‘동아시아’와 ‘동아시아지역주의’, 그리고 동아시아 ‘공동체’ 및 ‘정체성’ 형성에 관한 문제는 지난 20년간 우리나 라 학계 안팎에서 꾸준히 주된 논쟁의 주제가 되어왔다. 초기에 주로 문학, 역사, 철학 등 인문학 분야에서 ‘동아 시아’가 호명되기 시작하더니, 1990년대 말부터 동아시아 발전문제를 다루는 사회과학자들 사이에는 동아시아의 특수성과 정체성에 대한 논의로 이어졌고, 그 후 경제학자들과 국제정치학자들 사이에서 동아시아지역에 경제 공동체와 안보공동체를 형성해야 할 필요성에 대한 논의가 제기되었다. 동아시아의 지역공동체 형성이란 주제를 제대로 다루기 위해서는 자신의 학문적 소영지를 고수하려는 학문적 지역주의에서 벗어나 분과학문간 경계를 자유롭게 넘나드는 융⋅복합적 상상력을 발휘할 필요가 있다. 또한 이는 동아시아에 대한 기본적인 문제의식만 공유한다면 어떤 학문영역에서 제기된 논의라도 분과학문 간의 경계를 뛰어넘어 이를 하나로 묶어 사유해 보고자 하는 시도이기도 하다. 그리고 지금이야말로 동아시아와 동아시아지 역주의에 관한 여러 가지 의제를 놓고, 여러 학문 분야에서 다양한 관점과 주장을 가진 사람들이 서로 소통하고 함께 고민할 수 있는 공통의 담론의 장이 열려야 할 때가 아닌가 생각한다. 그리고 타지역을 타자화하고 이를 배제하고 경계하는 폐쇄적 자세로는 시공간적으로 더욱 더 압축되고 있는 미 래의 지식정보화, 세계화 사회에서 지역공동체를 담보하는 것이 결코 쉽지 않은 일일 것이다. 보다 전향적, 적극 적인 입장에서 타지역의 여러 국가와 대화하고 협력하는 개방적 지역주의에 입각할 때만이 비로소 보다 현실적 이고 미래사회에 적합한 동아시아공동체의 가능성은 열릴 것이다.
‘East Asia’ and ‘East Asian Regionalism’ and the East Asian ‘Community’ and ‘Identity’ have received substantial recognitions as a topic for debates from both the inside and outside of the Korean scholarly society. The early debate had been mainly about how to define East Asia from the standpoint of humanities studies such as literature, history, and philosophy, but from the late 1990s, especially among social scientists specializing the development studies, the focus of the topic has been shifted to the particularity and identity of East Asia. In that regard, economists and political scientists have raised the necessity of economic community and security community. For a comprehensive investigation of East Asian regional community, it is necessary to take interdisciplinary imaginary beyond academic parochialism. This is especially for the case of mutually shared fundamental understandings on East Asia. Nowadays, it is appropriate to share discourses across different disciplines. The starting point would be in defining the scope and boundary of East Asia. ‘Soft regionalism’ or ‘Elastic regionalism’ can be a reference point because the boundary and membership of a regional community is dependent upon the characteristics of its objective rather than is predetermined. The recent interdependence among citizens and countries in East Asia is the holistic social interaction process. Rather operating separate manners, the economic, political, security, and cultural aspects are coherently shaped, thus efforts on how to produce synergistic effects have substantial merits. The East Asian Community is not necessarily to be a counterpart of those of the western society. To achieve a certain objective of a community, it is essential to work in collaborative manners nowadays because the global society has become increasingly interdependent. The global-level effort for sustainable environments would be a good example. Under the fast-paced, interdependent global regime, with exclusive manners, it would not be possible to structure a regional community. Through the open regionalism, which is the progressive and collaborative approach with countries in other regions, realistic and sustainable East Asian Communities would be possible.
FTS를 이용한 논리적 망 분리와 행위기반 탐지 시스템에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제13권 제4호 2013.09 pp.109-115
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷망을 이용한 정보 전달의 대표적인 수단인 이메일 서비스 등을 통한 보안위협이 급증하고 있다. 이러한 보안위협의 공격 경로는 첨부된 문서파일에 악성코드를 삽입하고, 해당 응용프로그램의 취약점을 이용하여 사용자의 시스템을감염시키게 된다. 따라서 본 연구에서는 파일 전송과정에서 위장악성코드의 감염을 차단하기 위해, 논리적 망 분리인FTS(File Transfer System)를 이용한 무결성 검증 및 행위기반 탐지 시스템을 제안하고, 기존의 보안기법과의 비교 및검증하고자 한다.
Security threats through e-mail service, a representative tool to convey information on the internet, are on the sharp rise. The security threats are made in the path where malicious codes are inserted into documents files attached and infect users' systems by taking advantage of the weak points of relevant application programs. Therefore, to block infection of camouflaged malicious codes in the course of file transfer, this work proposed an integrity-checking and behavior-based detection system using File Transfer System (FTS), logical network partition,and conducted a comparison analysis with the conventional security techniques.
4,000원
최초 사회공학기법의 발달로 해킹, 악성코드가 고도화, 첨단화 되어 기업에 대한 표적 공격인 APT(Advanced Persistent Threat)공격이 급격히 증가하고 있다. APT공격의 가장 큰 특징 중 하나는 지속성이다. 공격자는 내외부에서 지속적으로 공격대상의 정보를 수집 및 활용한다. 보안관제 시스템(Enterprise Security Management)의 경우 이러한 지속적인 공격에 대하여 정상적인 접근 실패로 오인 공격을 받고 있음에도 별도의 경고를 할 수 없는 한계점이 있다. 이러한 오탐 데이터를 철저히 분석하기 위한 시스템 설계 및 연구가 필요하다. 본 논문에서는 데이터마이닝을 이용하여 지나칠 수 있는 오탐을 임계치 기준 분류하여, 산출된 비교 값을 기준으로 지속적으로 일어나는 공격에 대한 예측 및 공격에 대한 개선된 대응 방안을 제시한다. 제안 기법을 사용하여 장기적으로 시도되는 공격 데이터를 분류, 앞으로 일어날 수 있는 공격 징후 탐지가 가능하다.
Advanced Persistent Threat (APT), aims a specific business or political targets, is rapidly growing due to fast technological advancement in hacking, malicious code, and social engineering techniques. One of the most important characteristics of APT is persistence. Attackers constantly collect information by remaining inside of the targets. Enterprise Security Management (EMS) system can misidentify APT as normal pattern of an access or an entry of a normal user as an attack. In order to analyze this misidentification, a new system development and a research are required. This study suggests the way of forecasting APT and the effective countermeasures against APT attacks by categorizing misidentified data in data-mining through threshold ratings. This proposed technique can improve the detection of future APT attacks by categorizing the data of long-term attack attempts.
Evaluating Asset Pricing Models in the Korean Stock Market
한국재무학회 한국재무학회 학술대회 2011년 5개 학회 공동학술연구발표회 2011.05 pp.922-957
※ 기관로그인 시 무료 이용이 가능합니다.
7,900원
This paper evaluates and compares asset pricing models in the Korean stock market. The asset pricing models considered are the CAPM, APT-motivated models, the Consumptionbased CAPM, Intertemporal CAPM-motivated models, and the Jagannathan and Wang conditional CAPM model. By using various test portfolios as well as individual stocks, we conduct time-series tests and cross-sectional regression tests based on individual t-tests, the joint F-tests, the Hansen and Jagannathan (1997) distance, and R-squares. Overall, the Fama and French (1993) five-factor model performs most satisfactorily among the asset pricing models considered in explaining the intertemporal and cross-sectional behavior of stock returns in Korea. The Fama and French (1993) three-factor model, the Chen, Novy-Marx, and Zhang (2010) three-factor model, and the Campbell (1996) model are the next. The results indicate that the two bond portfolios, term spread and default spread, play an important role in explaining stock returns in Korea.
한국 주식시장에서 유동성 요인을 포함한 3요인 모형의 설명력에 관한 연구 KCI 등재
한국재무학회 재무연구 제22권 제1호 2009.02 pp.1-44
※ 기관로그인 시 무료 이용이 가능합니다.
9,100원
Fama-French의 3요인 모형은 미국을 비롯한 여러 나라 주식시장에서 유용한 설명력을 가지고 있는 것으로 검증되어 왔다. 하지만, 국내 주식시장에서 주식수익률과 장부가치 대 시장가치 비율간의 관계가 비유의적이고, 또 그 모방포트폴리오인 HML의 위험프리미엄도 유의적이지 않은 것으로 나타나기 때문에 국내 주식시장에서 주식수익률들의 공통적인 변동을 설명하기 위해 Fama-French 3요인 모형을 사용하는 것이 과연 적절한가에 대한 의문이 제기된다. 반면, 주식거래회전율(turnover)은 국내 주식수익률과 유의한 관계를 가지고 있는 것으로 파악된 바, 본 연구에서는 주식거래회전율을 이용하여 유동성위험 모방포트폴리오(NMP)를 구성한 후, 이를 시장위험포트폴리오(MKT), 기업규모효과 모방포트폴리오인 SMB와 함께 모형에 포함시켜 3요인 모형을 구성해 이것의 국내 주식수익률의 체계적 변동에 관한 설명력을 분석하였다. 그 결과, 이 유동성 요인을 포함한 3요인 모형이 Fama-French 3요인 모형보다 더 우월한 설명력을 보일 뿐 아니라, NMP 또한 유의한 설명력을 가지고 있는 것으로 나타났는데, 이것은 국내 주식수익률의 변동을 설명하는 체계적 위험요인 중 하나로서 HML 보다는 NMP가 더 우월한 실증적 근거를 가지고 있음을 의미하는 것으로 볼 수 있다.
This paper is an empirical investigation of the determinants of the cross- section of stock returns in Korea. While Fama and French’s (1993) three-factor asset pricing model is known to perform reasonably well in explaining the cross-section of stock returns in the U.S. and many other stock markets in developed countries, the model’s performance in explaining the cross-section of stock returns in Korea has been less than satisfactory. More specifically, there is mixed evidence for the existence of the book-to-market effect in the Korean stock market. Because Fama and French’s three-factor model is empirically motivated without firm theoretical grounds, it is difficult to argue that the book-to-market factor (HML) is a priced risk factor in the Korean stock market without clear empirical evidence for the book-to-market effect in the cross- section of stock returns in Korea. Consequently, an alternative asset pricing model is necessary to be used widely in Korea for the purpose of risk adjustment in estimating the cost of capital or performance evaluation. Using monthly stock returns and accounting information for the sample of non-financial firms belonging to the KOSPI index over the 1991~ 2007 period, we first investigate the cross-sectional relationship between stock returns and firm characteristics in the Fama-MacBeth regression framework. We find no evidence for the book-to-market or momentum effect. Firm characteristics which show significant relationship with the cross-section of stock returns in Korea are firm size measured by market capitalization and liquidity measured by turnover. Given the evidence for the size and turnover effects, we construct portfolios by sorting firms into four size groups and four turnover groups independently, similar to the way in which Fama and French (1993) construct their size and book-to-market portfolios. The sixteen size-turnover portfolios show clear patterns in average returns, decreasing in both firm size and turnover. Moreover, these size-turnover portfolios exhibit much bigger spread in average returns than the portfolios constructed using firm size and book-to-market (size-BM portfolios), which suggests that the size-turnover portfolios may be more useful and relevant test assets than the size-BM portfolios in the Korean stock market. The clear pattern of average returns in the size-turnover portfolios suggests that liquidity measured by turnover may be a priced risk factor in Korea. In order to estimate the magnitude of the risk premium associated with the size and turnover effects, we construct mimicking portfolios which are designed to capture the effects of firm size and turnover in the cross-section of stock returns, similar to the way in which Fama and French (1993) construct their mimicking portfolios, SMB and HML. Consistent with the results from the Fama-MacBeth regressions, the size factor (SMB) and the turnover factor (NMP) show significantly positive average returns while the average return of the book-to-market factor (HML) is positive but statistically insignificant. The magnitudes of the average returns for SMB and NMP are also economically significant at 0.99% per month for SMB and 1.19% per month for NMP. We then perform standard time-series and cross-sectional tests of asset pricing models using the size- turnover and size-BM portfolios as test assets. The asset pricing models we consider are the Fama-French three-factor model and our alternative three-factor model which replaces the book-to-market factor HML with the liquidity factor NMP. The main findings are as follows. When the size-turnover portfolios are used as test assets, the GRS F-test rejects the Fama- French three-factor model while it does not reject our alternative three-factor model. Moreover, the estimated risk premium for the liquidity factor NMP is both economically and statistically significant at 1.3% per month, which is also similar in magnitude to its average return of 1.19% per month. When the size-BM portfolios are used as test assets, the two models show broadly comparable performance. These main findings remain unchanged when we test the models using the first half or the second half of the sample period. In particular, we find that the liquidity factor NMP shows significant explanatory power for the cross-section of stock returns in each of the sub-sample periods. The Fama-French three-factor model is widely used in research and practice for risk adjustment and performance evaluation in both the U.S. and Korea. But the lack of clear empirical evidence for the book- to-market effect in Korea raises a question about the relevance of the book-to-market factor HML and the Fama-French three-factor model in understanding the determinants of stock returns in Korea. The findings in this paper suggest that our alternative three-factor model which incorporates a liquidity factor may be more useful and relevant for understanding the systematic variation of stock returns in Korea.
동중앙아시아경상학회 동중앙아시아연구(구 한몽경상연구) 제19권 제1호 2008.06 pp.63-82
※ 기관로그인 시 무료 이용이 가능합니다.
5,500원
주가는 기업의 내적요인 못지않게 기업의 경영여건을 결정짓는 거시경제변수와도 밀접한 상관관계를 갖는다. 즉, 거시경제변수인 금리, 환율, 국제유가, 국제수지, 산업생산지수 등은 개별기업이 아닌 전체기업의 경영여건과 관련되어 경제전반의 성장성, 안전성 등을 예측하는 출발점이 되므로 증권시장의 전반적인 움직임에 대한 기초자료를 제공한다고 할 수 있다. 따라서 본 연구는 알려지지 않은 유의적인 공통요인에 관련된 경제변수를 찾아냄으로써 공통요인이 어떠한 경제적 의미를 갖고 있으며 주가에 어떻게 영향을 미치는 가에 관한 연구로 APM을 이용하고 있다. 즉, 주가가 거시적 경제변수들에 의해 어떻게 영향을 받는가를 실증적으로 검증하는데 있다.
Stock prices are influenced by the inside factors of enterprises as well as macroeconomic factors which affect the management circumstance of enterprises. Macroeconomic variables like interest rates, exchange rate, international oil price, international balance of payment, and industrial product index are correlated with the management circumstance of whole enterprises and can be used as a starting point to expect the economic growth and economic stability. Moreover, these variables may offer basic data for the movement of stock market. Therefore, this study tries to find the important and common macroeconomic variables and then these variables are used for empirical test of the stock prices formation as if APM does.
한국 주식시장에서 유동성 요인의 횡단면적 설명력에 관한 연구
한국재무학회 한국재무학회 학술대회 2008년 5개 학회 공동학술연구발표회 2008.05 pp.1823-1865
※ 기관로그인 시 무료 이용이 가능합니다.
9,000원
Fama and French(1993)의 3요인 모형은 미국을 비롯한 여러 나라 증권시장에서 유용한 설명력을 가지고 있는 것으로 검증되어 왔다. 하지만, 국내 주식시장에서는 HML의 횡단면적 설명력이 유의하지 않다라는 결과를 여러 연구들이 보여주고 있고, 또한 1990년대 이후로 갈수록 SMB와 HML이 상당히 큰 절대값의 상관관계를 보이고 있다는 사실 등을 감안할 때, 적어도 국내 주식시장의 공통적인 변동을 설명하기 위해 Fama-French 3요인 모형을 사용하는 것이 과연 적절한가에 대한 의문이 제기된다. 따라서 본 연구에서는 주식거래회전율(Turnover)을 유동성위험의 측정치로 하는 모방포트폴리오를 구성하여 시장위험포트폴리오, SMB와 함께 모형에 포함시켜 대안적(Alternative) 3요인 모형을 구성한 후 국내 주식시장을 분석해 본 결과, 이 대안적 3요인 모형이 Fama-French 3요인 모형보다 더 우월한 설명력을 보였을 뿐 아니라, Turnover 요인 또한 횡단면적으로 유의한 설명력을 가지고 있다는 사실을 발견하였다. 이러한 현상은 표본기간을 2000년 이전과 이후로 나눈 두 기간 모두에서 나타났으며, 2000년 이후의 기간에서 Turnover 요인의 횡단면적 설명력은 더 강하게 나타났다. 이것은 적어도 국내 주식수익률의 변동을 설명하는 공통위험요인으로 시장위험프리미엄, SMB와 함께 유동성 위험요인이 HML보다 더 비중 있게 고려되어야 함을 의미하는 것으로 볼 수 있다.
Fama and French (1993) propose a three-factor asset pricing model which uses a proxy for the market portfolio and mimicking portfolios designed to capture the size and book-to-market effects in stock returns. Empirical applications of this threefactor model in Korea, however, can be problematic because i) the book-to-market effect in the cross section of stock returns is not significant, and ii) the size factor (SMB) and the book-to-market factor (HML) are highly correlated. In this paper, we propose a three-factor asset pricing model which uses a mimicking portfolio designed to capture liquidity risk in place of HML as an alternative to the Fama-French threefactor model. We find that our alternative model performs better than the Fama- French model in explaining the cross section of average stock returns in primarily due to the significant explanatory power of the proposed liquidity factor proxy. The results are robust in both sub-samples (before and after the year 2000), and the significance of the liquidity factor proxy is stronger for the post-2000 sample period.
APT(S) 제조 시 전기투석법을 이용한 H2WO4(Aq)내의 Na 제거 방법에 관한 연구
[NRF 연계] 한국자원리싸이클링학회 자원리싸이클링 Vol.26 No.6 2017.12 pp.65-72
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
APT (Ammonium paratungstate)는 금속절단 공구, 드릴의 날, 광산공구, 군사무기 재료 등 산업 전반에 다양한 용도로 사용되며, 고순도의 APT(S)를 제조하기 위해서는 Na2WO4 수용액으로부터 전환된 H2WO4 내의 불순물 정제 공정이 필요하다. 이미 널리 알려진 기존의 습식방법인 Na2WO4 수용액에 HCl(Aq)을 첨가하여 H2WO4(S)을 제조하는 경우에는 불순물인 Na를 200 ppm 이하로제거하는데 어려움이 있다. 이러한 점을 개선하기 위하여 본 연구에서는 양이온 격막을 이용한 전기투석 공정을 통해 Na를 제거하는 보다 경제적이고 효율적인 방법을 연구하였다. 폐 텅스텐 초경드릴 및 스크랩을 용해하기 위해 첨가되었던 Na2CO3(S)로 인한H2WO4 수용액 내의 다량의 Na를 전기투석 공정을 통해 20 ppm 이내로 제거함으로써 전기투석법 이용 시 Na 제거 효과가 큼을확인하였다.
APT (Ammonium paratungstate) is widely used in various industries such as metal cutting tools, drill bits, mining tools, and military inorganic materials. In order to produce high purity APT(S), an impurity purification step in an aqueous Na2WO4 convert H2WO4 solution is required. It is difficult to remove impurity Na of 200 ppm or less when H2WO4(S) is prepared by adding HCl(Aq) to an aqueous solution of Na2WO4, which is a well-known conventional wet method. However, in this study, a more economical and efficient method of removing Na through electrodialysis using a cationic membrane was studied. A large amount of Na in aqueous solution of H2WO4 due to Na2CO3(S) which was added to dissolve waste tungsten carbide drill and scrap was removed to 20ppm or less through electrodialysis process, and it was confirmed that the effect of Na removal was great when using electrodialysis.
APT 부모교육을 병행한 집단미술치료가 부모의 양육태도 및 양육스트레스에 미치는 효과
[NRF 연계] 한국미술치료학회 미술치료연구 Vol.18 No.2 2011.04 pp.309-324
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구의 목적은 부모교육을 병행한 집단미술치료를 통하여 청소년 자녀를 둔 부모들의 양육태도와 양육스트레스를 감소시키는데 있다. 연구대상은 K시에 소재한 청소년 자녀를 둔 14명의 부모다. 부모교육을 병행한 집단미술치료는 2009년 7월 9일부터 11월 5일까지, 주 2회, 회기 당 150분으로 총 20회기를 진행하였다. 측정도구는 염문현(1983)의 양육태도척도와 이귀원(1996)의 양육스트레스 척도 PSL/SF를 사용하였다. 자료분석은 SAS 9.1.3프로그램을 활용하여 사전, 사후, 추후검사의 평균과 표준편차를 구하고 반복측청치로 한 변량분석을 하였다. 본 연구의 결과는 다음과 같다. 첫째, 부모교육을 병행한 집단미술치료가 부모의 양육태도 전체와 하위영역 전체에서 통계적으로 유의한 차이를 나타내었으며, 프로그램의 효과가 지속되고 있음을 알 수 있었다. 둘째, 부모교육을 병행한 집단미술치료가 부모의 양육스트레스 전체와 하위영역 전체에서 통계적으로 유의한 차이를 나타내었으며, 프로그램의 효과가 지속되고 있음을 알 수 있었다. 따라서 부모교육을 병행한 집단미술치료가 부모의 양육태도를 변화시키고 양육스트레스를 감소시키는데 효과가 있음을 알 수 있었다.
The aim of this study is to reduction of the nurturing attitudes and the nurture stress of parents with adolescent child by way of group art therapy with parent education. The subject is 14 parents with adolescent child, who live in K city. This group art therapy by way of parent education is carried out during 20 sessions for 150 minutes per session twice a week from July 9, 2009 to November 5, 2009. The measurement tool is the nurturing attitude scale of Youm Moon Hyun(1983), the nurture stress scale of Lee Kwi Won(1996), and PSL/SF. Also to examine out the maintenance of the effect of this program, the same nurturing attitude test and nurture stress test are carried out once before this program, once after this program for the research group. The research materials collected are scored by the scoring criteria of each test. And the statistical analysis is carried out by SAS(ver.9.1.3), and by which the average and the standard deviation of the results at pretest, post test, and further test are valued, and then mixed repeated ANOVA is carried out. The results are as follows. Firstly, group art therapy with parent education is a significant difference in the category of the whole nurturing attitude and all the subcategories of the nurturing attitude and And there is not a significant difference between the scores of the post test and the further test. Secondly, group art therapy with parent education is a significant difference in the category of the whole nurturing attitude and all the subcategories of the nurturing attitude and And there is not a significant difference between the scores of the post test and the further test. In conclusion, it is clear that this group art program is effective on the change of the nurturing attitude of parents and on the reduction of nurture stress.
APT 래더링 기법을 활용한 여성 전용 피트니스클럽 이용의 가치체계 KCI 등재
한국체육무용과학회 Journal of Sport and Dance Science Vol. 6 No. 2 2026.05 pp.189-199
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
이 연구는 여성 전용 피트니스클럽에서 재현되고 있는 몸만들기 실천을 살펴봄으로써 그들이 지각하는 가치체계를 APT 래더링 기법을 통해 심층적으로 규명하였다. 이를 위해 내용분석, 함축 매트릭스 분석, 가치체계도 단계를 통해 분석하였다. 내용분석을 위해 연구참여자 7명을 선정하였으며, 함축 매트릭스 분석을 위해 100명을 대상으로 설문조사를 실시하였다. 가치체계도 분석을 통해 중심래더를 도출하였다. 연구결과는 다음과 같다. 먼저, 여성 전용 피트니스클럽의 속성, 혜택, 가치에 대한 주제어를 생성하였다. 여성 전용 피트니스클럽의 속성으로는 남성 출입 금지, 여성 맞춤 서킷 트레이닝, FA, 마일리지제, 동일 시설 및 프로그램, 커브스 프렌즈, 트레블 카드 총 7개의 주제어가 도출되었다. 여성 전용 피트니스클럽의 혜택으로는 다이어트, 커뮤니티 형성, 이용의 편리성, 회원등록비 할인, 스트레스 해소, 자세 및 체형 개선 총 6개의 주제어가 도출되었다. 여성 전용 피트니스클럽의 가치로는 사회관계망 확대, 자기 계발, 생활 습관 및 건강 증진 총 4개의 주제어가 도출되었다. 다음으로 여성 전용 피트니스클럽의 속성, 혜택, 가치 간의 연결관계를 바탕으로 중심래더를 도출하였다. 첫째, [남성 출입 금지→커뮤니티 형성→사회관계망 확대] 래더이다. 둘째 [여성 맞춤 서킷 트레이닝→다이어트→자존감 향상] 래더이다. 셋째 [FA(fitness assessment, 건강 및 체형 분석)→자세, 체형 개선→생활 습관 및 건강 증진] 래더이다.
Objectives The purpose of this study was to examine the body-shaping practices reproduced in women-only fitness clubs and, through the APT laddering technique, provided an in-depth analysis of the value system perceived by women users. Methods Seven participants were selected for the content analysis, and a survey was administered to 100 respondents for the implication matrix analysis. Core ladders were then derived through hierarchical value map analysis. Results & Conclusions First, key terms related to the attributes, benefits, and values of women-only fitness clubs were identified. For the attributes, seven key terms were derived: prohibition of male entry, a mileage system, a travel card, women-tailored circuit training, standardized facilities and programs, and FA(health and body-shape record analysis). For the benefits, six key terms were identified: dieting, community building, convenience of use, discounts on membership registration fees, stress relief, and improvements in posture and body shape. For the values, four key terms were derived: expansion of social networks, self-development, and the promotion of healthy lifestyles and health. Next, core ladders were derived based on the linkages among the attributes, benefits, and values of women-only fitness clubs. The first ladder was [prohibition of male entry → community building → expansion of social networks]. The second ladder was [women-tailored circuit training → dieting → enhanced self-esteem]. The third ladder was [FA(health and body-shape analysis) → improvement in posture and body shape → promotion of healthy lifestyles and health]
APT부모교육프로그램이 자기분화와 양육태도에 미치는 영향 - 아내폭력피해여성을 대상으로 -
한국에니어그램학회 에니어그램연구 제17권 제2호 2020.12 pp.61-88
※ 기관로그인 시 무료 이용이 가능합니다.
6,700원
4,000원
APT공격은 해커가 다양한 보안 위협을 만들어 특정 기업이나 조직의 네트워크에 지속적으로 가하는 공격 을 뜻한다. 지능형 지속 공격이라 한다. 특정 조직 내부 직원의 PC를 장악한 뒤 그 PC를 통해 내부 서버나 데이터베 이스에 접근한 뒤 기밀정보 등을 빼오거나 파괴한다. APT의 공격 방법은 제로데이와 루트킷 이렇게 크게 두 가지 공격이 있다. APT의 공격 과정은 침투, 검색, 수집, 유출 단계 4단계로 구분된다. 과정을 통하여 APT에 어떻게 대응 할 수 있는지 두 가지 방안으로 정의하였다. 기술을 통한 악성코드 공격자의 공격 소요 시간을 지연시키는 방안과 공격에 대한 탐지 및 제거 할 수 있는 방안으로 나누어서 설명하였다.
The APT attacks are hackers created a variety of security threats will continue to attack applied to the network of a particular company or organization. It referred to as intelligent sustained attack. After securing your PC after a particular organization's internal staff access to internal server or database through the PC or remove and destroy the confidential information. The APT attack is so large, there are two zero-day attacks and rootkits. APT is a process of penetration attack, search, acquisition, and is divided into outlet Step 4. It was defined in two ways how you can respond to APT through the process. Technical descriptions were divided into ways to delay the attacker's malicious code attacks time and plan for attacks to be detected and removed through.
제로트러스트 아키텍처 기반 공공 클라우드 전환 환경에서의 AI 지능형 지속위협(APT) 탐지 모델 연구 KCI 등재
한국융합보안학회 융합보안논문지 제26권 제3호 2026.06 pp.51-60
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
공공기관의 클라우드 전환이 가속화됨에 따라 지능형 지속위협(APT)에 대한 선제적 대응 체계 수립이 국가 사이버안보의 핵심 과제로 부상하고 있다. 본 연구는 공공 클라우드 전환 단계별 발생 가능한 APT 위협을 MITRE ATT&CK 프레임워크 기반으로 분류하고, 제로트러스트 아키텍처(ZTA)와 AI 탐지 기술을 융합한 ZETA-AD 프레임워크를 제안한다. 제안 모델은 비지도·지도학습 및 그래프 신경망(GNN)을 결합한 다층 앙상블 탐지 엔진을 통해 위협을 식별하며, 이를 ZTA 정책 엔진과 연동하여 실시간 동적 권한 제어를 수행한다. 실험 결과, F1-Score 92.8%의 높은 탐지 정확도를 기록하였으며, 기존 체계 대비 APT 평균 체류 시간을 81.8% 단축시키고 데이터 유출 성공률을 80.4% 감소시키는 성과를 확인하였다. 또한 SHAP 기반의 설명 가능한 AI(XAI)를 적용하여 탐지 근거의 투명성을 확보함으로써, 공공 보안 관제 현장에서의 실무적 활용성을 높였다.
As public cloud migration accelerates, establishing a proactive defense against Advanced Persistent Threats (APT) has become a vital national cybersecurity challenge. This study classifies APT threats by migration phase using the MITRE ATT&CK framework and proposes the ZETA-AD framework, which integrates Zero Trust Architecture (ZTA) with AI detection technologies. The proposed model utilizes a multi-layered ensemble engine combining unsupervised/supervised learning and Graph Neural Networks (GNN) to identify threats, while enabling real-time dynamic control through integration with the ZTA policy engine. Evaluation results show an F1-Score of 92.8%, a 81.8% reduction in average APT dwell time, and a 80.4% decrease in data exfiltration success rates. Furthermore, by incorporating SHAP-based Explainable AI (XAI), the framework ensures transparency in detection rationale, providing a practical and reliable model for security administration in public institutions.
정확한 공격 시도 감지를 위한 BERT 기반 APT 특성 추출 및 분류 KCI 등재
대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제23권 제5호 2025.05 pp.29-36
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
APT 공격은 특정 조직을 장기간 표적화하며 정교한 해킹 기법을 활용하는 사이버 위협으로, 국가 주도 해킹 그룹 및 사이버 범죄 조직에 의해 자주 수행되며, 고도로 정교한 방식으로 특정 표적을 오랜 기간에 걸쳐 지속적으로 공격하면서 기밀 정보에 접근하여 이를 탈취하는 방법으로 진행되고 있어 이를 적시에 탐지하는 것이 어려운 실정이다. 그리고 일반 악성 코드 들은 불특정 다수를 대상으로 하지만, APT 공격은 정부 관련 기관, 금융기관 또는 기업을 공격 대상으로 삼고 있기에 그 피해 는 개인뿐만 아니라 국가, 기업 등과 같이 사회 전반에 영향을 미쳐 사회, 경제, 국가 안보를 크게 위협할 수 있어 조기에 탐지 하는 것이 절실히 필요하다. 따라서 본 논문에서는 APT 공격 실행 파일의 특성을 분류하기 위해 n-gram 분석 및 BERT 기반 텍스트 마이닝 기법을 활용한 특성 분류 기법을 제안한다. 이 기법은 APT 실행 파일을 16진수 문자열로 변환한 후 n-gram 방 식으로 특징을 표현하고, 이를 BERT 모델에 입력하여 고유한 특징 벡터를 생성한다. 이후 퓨삿 학습(Few-shot Learning)을 적용하여 실행 파일의 패턴을 보다 정밀하게 분류하는 방식으로 APT 특성을 체계적으로 분류하였다. 본 논문에서 제안한 기법 은 기존의 머신러닝 기반 탐지 모델보다 APT 공격 탐지 정확도가 8~12% 향상되었음을 확인할 수 있었다. 특히 난독화된 코드 와 파일리스 공격 기법을 탐지하는 데 있어 기존 탐지 모델보다 효과적임을 알 수 있었다. 이를 바탕으로 APT 공격 실행 파일 탐지를 위한 보다 정교한 분석 프레임워크 개발과 향후 실시간 APT 탐지 시스템 개발에 기여할 수 있을 것으로 기대된다.
APT attacks are cyber threats that target specific organizations for a long period of time and utilize sophisticated hacking techniques. They are frequently carried out by state-sponsored hacking groups and cybercrime organizations. They are carried out by continuously attacking specific targets over a long period of time in a highly sophisticated manner, accessing and stealing confidential information, making it difficult to detect them in a timely manner. In addition, while general malware targets an unspecified number of people, APT attacks target government-related organizations, financial institutions, or companies, so the damage can affect not only individuals but also the entire society, such as countries and companies, and can significantly threaten society, economy, and national security. Therefore, early detection is urgently needed. Therefore, in this paper, we propose a feature classification technique that utilizes n-gram analysis and BERT-based text mining techniques to classify the characteristics of APT attack executable files. This technique converts APT executable files into hexadecimal strings, expresses the features in n-gram format, and inputs them into a BERT model to generate a unique feature vector. After that, we systematically classified the APT characteristics by applying Few-shot Learning to classify the patterns of executable files more precisely. We could confirm that the technique proposed in this paper improved the APT attack detection accuracy by 8-12% compared to the existing machine learning-based detection model. In particular, it was found to be more effective than the existing detection model in detecting obfuscated codes and fileless attack techniques. Based on this, it is expected to contribute to the development of a more sophisticated analysis framework for detecting APT attack executable files and the development of a real-time APT detection system in the future.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.