Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 528
No
1

According to security breach level index millions of records are stolen world widely. Keeping in view the application of blockchain we have proposed novel secure mechanism based on neural network to train the model and to record the behavior of the users accessing the personal health records through blockchain. Recent solutions to storing and distributing patient data have several confines that limit users’ access to their patient health records (PHR), decrease the accessibility of critical information to care providers, and eventually extant a boundary in the transfer of traditional healthcare a digital healthcare approach. In order to remediate such shortcomings, a blockchain-based solutions the best tool to provide storage and trust. Numerous cloud-based approaches have been suggested in digital healthcare data allocation, but it would be untrustworthy to rely on a third party. In recent times, blockchain has been implemented in digital healthcare record sharing, which skip trusting on a third-party.

2

The Effect of Access Control on Security Policy Compliance and Security Performance in the Airports and Ports KCI 등재

Lee, Ju-Lak, Choi, Yeon-Jun

한국경찰연구학회 한국경찰연구 제18권 제4호 2019.12 pp.141-158

※ 기관로그인 시 무료 이용이 가능합니다.

5,200원

본 연구는 공항 및 항만의 출입통제가 특수경비원의 보안정책준수의지와 보안성과에 미치는 영향을 분석하여 각종 위협으로부터 공항 및 항만을 보호하여 보안 목표를 달성할 수 있도록 하는데 그 목적이 있다. 이를 위해 2019년 4월 1일부터 2019년 4월 26일까지 국가중요시설 중 공항 및 항만에서 근무하는 특수경비원들을 대상으로 설문조사를 실시하였으며, 312부를 회수하여 극단치(Outlier)와 응답한 내용이 부실한 18부를 제외한 총 294부의 설문지를 분석하였다. 수집된 자료는 SPSS 24.0을 사용하여 빈도분석, 탐색적 요인분석, 신뢰도 분석, 상관관계분석, 다중회귀분석을 실시하였다. 연구결과 첫째, 공항 및 항만의 출입통제는 보안정책준수의지에 유의한 정(+)의 영향을 미치는 것으로 나타났다. 둘째, 공항 및 항만의 출입통제는 보안성과의 하위요인인 대응성과와 예방성과에 유의한 정(+)의 영향을 미치는 것으로 나타났다. 이러한 연구결과를 바탕으로 본 연구에서는 공항 및 항만의 안전성 확보를 위한 출입통제 수준이 향상되면 특수경비원들의 보안정책준수의지와 보안성과가 높아져 범죄 및 테러 등 각종 위협으로부터 자산을 보호하는데 큰 도움을 줄 수 있음으로 공항 및 항만의 출입통제를 지속적으로 관리하여 보안성을 향상시키고자 노력해야 한다는 정책적 시사점을 제시하였다.

The purpose of current research is to offer suggestions for security management at two types of port of entry, airports and harbors, by analyzing the effect of access control on the special security guards’ willingness to comply with security policies and work performance In this article, the terms work performance and security performance are used interchangeably. . Data were collected from the special security guards working at critical facilities in South Korea, including airports and harbors during the period of April 1 to 26, 2019. 294 survey questionnaires (out of 312 returned) were included in the analyses after removing eighteen cases with missing values and outliers. After coding and entering the data into SPSS 24.0, the authors conducted descriptive, exploratory factor, reliability, correlation, and multiple regression analyses. The results showed that the access control at these ports of entry had a positive impact on the participants’ willingness to comply with security policies as well as on response and prevention outcomes, the two measures of security performance. Drawing from the findings, the authors offer practical implications for improved security management at the nation’s airports and harbors.

3

Recent solutions of storing and distribution of patient data have a number of confines that limits users access to their patient health records(PHR), decrease accessibility of critical information to care providers, and eventually extant a boundary in the transfer of traditional healthcare into a digital healthcare approach. In order to remediate such shortcomings blockchain based solution is the best tool to provide storage and trust. In digital healthcare data allocation, numerous cloud based approaches have been suggested, but it would be untrustworthy to rely on the third-party. In recent times, blockchain has been implemented in digital healthcare record sharing, which skip to trust on a third party. Although, current methods only focus over the clinical related records received from medical diagnosis. They are not considered resourceful regarding its data sharing which are always generated from biomedical and monitoring devices. In this research we have proposed blockchain as a novel approach to secure patient related data access, implementation obstacles, and a strategy for transitioning gradually from current technology to a blockchain based solution. Keywords: Blockchain, healthcare, patient health record, hyperledger fabric, data sharing, security, decentralization, trust chain.

4

클라우드 융합을 위한 MAC 정책 기반 접근통제 메커니즘 KCI 등재

최은복, 이상준

한국융합학회 한국융합학회논문지 제7권 제1호 2016.02 pp.1-8

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

클라우드 컴퓨팅 환경은 가상화 기술을 이용하여 네트워크에 기반한 컴퓨터 자원, 소프트웨어, 인프라 등을 서로 공유하는 기능을 제공한다. 가상화는 기업의 서버 운영효율과 비용절감을 위해 매우 유용한 기술이지만 보안을 고려하지 않고 수행할 경우 새로운 보안 위협의 대상이 될 수 있다. 본 논문에서는 클라우드 시스템 환경에서 발생할 수 있는 다양한 문제점을 해결하는 클라우드 융합을 위한 MAC 기반 접근통제 메커니즘을 제안한다. 이 메커니즘은 접근통제 시스템 모니터의 상태규칙 집합, 보안특성 그리고 알고리즘으로 구성된다. 본 논문에서는 제안된 접근통제 메커니즘을 갖는 제어 시스템과 초기 보안 상태가 안전한 시스템임을 증명하였다. 본 메커니즘은 정책 모듈을 통해 접근통제 시스템들 간의 통제된 자원들이 서로 안전하게 공유되며 유지 관리되어질 수 있는 장점을 제공한다.

5

응급 상황에서 환자의 프라이버시를 보장하는 속성기반 접근 제어 프로토콜 KCI 등재

정윤수, 한군희, 이상호

한국디지털정책학회 디지털융복합연구 제12권 제7호 2014.07 pp.279-284

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 m-헬스케어는 응급상황이 발생할 경우, 환자의 정보가 제 3자에게 쉽게 노출되어 악용될 수 있는 문제 가 있다. 본 논문에서는 m-헬스케어의 응급상황 환경에서 환자의 정보를 이용하여 환자의 프라이버시 노출을 최소화 하기 위한 속성 기반의 환자 접근 제어 프로토콜을 제안한다. 제안 프로토콜은 환자의 민감한 정보를 제 3자에게 노 출시키지 않도록 환자의 민감한 정보를 개인 건강 정보에 포함하여 병원관계자와 환자가 생성한 랜덤수로 해쉬한 서 명키로 암호화한다. 또한 제 3자로부터 환자 정보가 불법적으로 악용되는 것을 예방하기 위해서 환자와 병원관계자 사이의 동기화를 유지함으로써 개인 건강 정보의 유출을 예방한다.

Recently, m-health care is be a problem that the patient's information is easily exposed to third parties in case of emergency situation. This paper propose an attribute-based access control protocol to minimize the exposure to patient privacy using patient information in the emergency environment. Proposed protocol, the patient's sensitive information to a third party do not expose sensitive information to the patient's personal health information, including hospital staff and patients on a random number to generate cryptographic keys to sign hash. In addition, patient information from a third party that is in order to prevent the illegal exploitation of the patient and the hospital staff to maintain synchronization between to prevent the leakage of personal health information.

6

웹 환경에서 SPKI 인증서를 이용한 접근 제어 KCI 등재후보

김점구

한국융합보안학회 융합보안논문지 제6권 제4호 2006.12 pp.11-19

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

7

클라우드 환경에서 서로 다른 IoT 장치간 효율적인 접근제어 기법 KCI 등재

정윤수, 한군희

한국융합학회 한국융합학회논문지 제9권 제4호 2018.04 pp.57-63

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

IoT 장치는 클라우드 환경에서 다양한 역할과 기능을 수행할 수 있도록 여러 분야에서 사용되고 있다. 그러나, IoT 장치를 안정적으로 제어할 수 있는 접근제어에 대한 방안은 아직 구체적으로 제시되고 있지 않은 상황이다. 본 논문에서는 클라우드 환경에서 사용되고 있는 IoT 장치의 안정적인 접근을 수행할 수 있는 계층적 기반의 다단계 속성 접근제어 기법을 제안한다. 제안 방법은 IoT 장치의 원활한 접근을 돕기 위해서 IoT Hub을 두어 IoT 장치에 고유한 ID 키(보안 토큰)를 제공 할 뿐만 아니라 수 있도록 하는 X.509 인증서 및 개인 키를 IoT Hub에서 인증하도록 하여 IoT 장치의 개인키를 IoT 장치 외부에서 알 수 없도록 하였다. 성능평가 결과, 제안방법은 기존 기법보다 인증 정확도가 평균 10.5% 향상되었으며 처리 시간 도 14.3% 낮은 결과를 얻었다. IoT 속성 수에 따른 IoT Hub의 오버헤드는 기존 기법보다 9.1% 낮은 결과를 얻었다.

IoT devices are used in many areas to perform various roles and functions in a cloud environment. However, a method of access control that can stably control the IoT device has not been proposed yet. In this paper, we propose a hierarchical multi-level property access control scheme that can perform stable access of IoT devices used in a cluster environment. In order to facilitate the access of the IoT device, the proposed method not only provides the ID key (security token) unique to the IoT device by providing the IoT Hub, but also allows the IoT Hub to authenticate the X.509 certificate and the private key, So that the private key of the IoT device can not be seen outside the IoT device. As a result of the performance evaluation, the proposed method improved the authentication accuracy by 10.5% on average and the processing time by 14.3%. The overhead of IoT Hub according to the number of IoT attributes was 9.1% lower than the conventional method.

8

4,000원

클라우드 환경의 대규모 인프라 구조에서는 응용프로그램들과 디바이스의 공유로 인하여 불법적인 접근권 한 문제가 빈번하게 발생하기 때문에 이러한 공격에 적극적으로 대응하기 위해서는 상황별로 대비가 가능한 강화 된 접근통제 시스템이 요구된다. 우리는 대규모 인프라 환경에 기반한 보안등급과 릴레이션 개념의 개체 속성 기반 접근통제 모델을 제시하였다. 본 모델은 주체와 객체에 무결성과 기밀성 등급을 부여하고 동일한 역할에 대해 서로 다른 서비스가 가능한 강화된 접근제어 특성을 가지며, 서비스와 관련된 릴레이션과 상태정보인 컨텍스트에 의해 역할과 권한을 배정함으로써 권한 관리의 유연성을 갖는다. 또한, 대학이라는 대규모 인프라 구조를 갖는 다중 서 비스 환경에 적용한 응용 사례를 통하여 본 모델의 적용 가능성을 제시하였다.

In the large-scale infrastructure of cloud environment, illegal access rights are frequently caused by sharing applications and devices, so in order to actively respond to such attacks, a strengthened access control system is required to prepare for each situation. We proposed an entity attribute-based access control(EABAC) model based on security level and relation concept. This model has enhanced access control characteristics that give integrity and confidentiality to subjects and objects, and can provide different services to the same role. It has flexibility in authority management by assigning roles and rights to contexts, which are relations and context related to services. In addition, we have shown application cases of this model in multi service environment such as university.

9

4,000원

접근제어 목적은 컴퓨팅 자원을 불법적인 사용자로부터 유출, 수정, 파괴와 같은 비합법적인 행위로부터 원천적으로 차단하고 보호하는데 있다. 클라우드 컴퓨팅 환경이 가상화 기술을 활용한 자원공유 서비스로 확장됨에 따라 동적이고 안전한 클라우드 기반 서비스를 제공하기 위해서는 새로운 보안 모델과 접근제어 기법이 요구되어진다. 본 가상화 관리 융합접근제어 모델은 역할기반 접근제어 기법에 동적 권한 배정 기능을 적용하여 유연한 사용자 권한 부여 기능을 제공하였다. 또한 보안등급과 규칙에 의거한 접근제어 기법을 적용함으로써 공유개념의 가상머신 시스템에서 권한충돌 문제 해결과 물리적 자원의 안전성을 보장토록 하였다. 본 모델은 안전하고 효율적인 클라우드 기반의 가상화 관리 시스템을 구축하는데 도움이 될 것이며 향후 다단계 특성을 반영한 메카니즘으로 확장될 필요성이 있다.

The purpose of access control is to prevent computing resources from illegal behavior such as leakage, modification, and destruction by unauthorized users. As the cloud computing environment is expanded to resource sharing services using virtualization technology, a new security model and access control technique are required to provide dynamic and secure cloud-based computing services. The virtualization management convergence access control model provides a flexible user authorization function by applying the dynamic privilege assignment function to the role based access control mechanism. In addition, by applying access control mechanism based on security level and rules, we solve the conflict problem in virtual machine system and guarantee the safeness of physical resources. This model will help to build a secure and efficient cloud-based virtualization management system and will be expanded to a mechanism that reflects the multi-level characteristics

10

모바일 클라우드 환경에서 안전한 데이터 접근 제어에 관한 연구 KCI 등재

김시정, 여상수

한국디지털정책학회 디지털융복합연구 제11권 제2호 2013.02 pp.317-322

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 다양한 환경을 통한 인터넷 접속으로 모바일 클라우드 환경이 대중화되고 있다. 컴퓨터의 성능 향상과 서비스 개발을 통해 그 수요가 날로 증가됨에 따라 그 피해도 급증하고 있다. 때문에 모바일 클라우드 서비스에서 발 생하는 대량의 데이터베이스 관리에서 요구되는 보안 사항의 문제점에 관한 연구가 요구된다. 현재 다양한 방식으로 데이터베이스로의 접근을 제한하는 보안 솔루션이 적용되고 있으나 모바일 클라우드와 같이 새로운 사용자 환경에 대한 보안 정책의 분석이 필요하다. 본 논문은 모바일 클라우드 환경에서 데이터베이스 관리를 통한 안전한 데이터 접근에 관한 취약성을 분석해 보고 안전한 데이터 관리에 대한 보안 요구사항을 알아본다. 클라우드에서 제공되는 서 비스 상에서 발생하는 보안 위협에 관한 요소를 분석하고 이를 통하여 보다 안전한 접근제어에 대한 보안 요구사항 을 도출한다. 향후 접근제어에 대한 보안 요구사항에 대한 시스템 적용과 평가에 대한 연구가 요구된다.

Mobile cloud environment is recently becoming popular due to Internet access through various environments. Driven by computer performance improvement and service development, the demand for mobile cloud is increasing and accordingly the damage is on the rise. Therefore, it needs to conduct a study on problems of security necessary in large database that occurs in mobile cloud services. Although various security solutions limiting database access, security strategies about new user environments should be analyzed. This study analyzes weakness of safe data access through database management in mobile cloud environment and examines security requirements for safe data management. In addition, this study looks into threatening factors of security in cloud services and then draws security requirements about safer access control. A study on system application and evaluation of security requirements about access control is required.

11

의료 정보유출 방지를 위한 네트워크 이중 접근통제 모델 연구 KCI 등재

최경호, 강성관, 정경용, 이정현

한국디지털정책학회 디지털융복합연구 제10권 제6호 2012.07 pp.341-347

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

시스템 및 네트워크에 설치/운용되는 의료자산보호 솔루션 중 네트워크 접근통제 시스템은 내부 네트워크에 접근하는 정보통신 디바이스의 안전성을 검증한 후 자원을 사용하게 하는 프로세스를 제공한다. 그러나 인가된 정보통신 디바이스의 위장 및 허가된 사용자의 이석 시간을 이용한 비인가 사용 등으로 내부 네트워크에 대한 의료 정보절취 위협은 여전히 존재하고 있고, 장시간 운영되는 정보통신 디바이스의 경우는 사용자가 인지하지 못하는 시간대에 악성코드 감염에 의한 외부 네트워크 임의 접속 및 의료 정보유출도 발생할 수 있기 때문에 이러한 위협을 차단하기 위한 보안 대책이 필요하다. 따라서 본 논문에서는 의료 정보유출 방지를 위해 현행 네트워크 접근통제 시스템을 개선하여 적용한 네트워크 이중 접근통제 모델을 제시한다. 제안한 네트워크 이중 접근통제 모델은 사용자가 실제 조직 내부에 위치하고 있어 인가된 정보통신 디바이스를 활용하는 때에만 내부 네트워크 접속을 허용한다. 그러므로 비인가자의 내부 네트워크 접근을 차단하고, 허가된 사용자 부재 시의 불필요한 외부 인터넷 접속을 차단함으로써 의료 정보를 보호할 수 있는 안전한 의료자산 환경을 제공한다.

Network Access Control system of medical asset protection solutions that installation and operation on system and network to provide a process that to access internal network after verifying the safety of information communication devices. However, there are still the internal medical-data leakage threats due to spoof of authorized devices and unauthorized using of users are away hours. In this paper, Network 2-Factor Access Control Model proposed for prevention the medical-data leakage by improving the current Network Access Control system. The proposed Network 2-Factor Access Control Model allowed to access the internal network only actual users located in specific place within the organization and used authorized devices. Therefore, the proposed model to provide a safety medical asset environment that protecting medical-data by blocking unauthorized access to the internal network and unnecessary internet access of authorized users and devices.

12

4,000원

4차 산업혁명의 핵심 IT기술인 사물인터넷은 타산업과 융합되어 사용자로부터 다양한 서비스를 제공하고 있다. IoT 융합기술은 사용자의 편의성 증대에 따른 통신환경에 대한 커뮤니케이션 패러다임을 이끌고 있다. 하지만 빠르게 발 전하는 IoT 융합기술에 대한 보안 방안 마련이 시급하다. IoT는 디지털 윤리와 개인정보보호와 밀접한 관계를 가지고 있어, 타 산업에 IoT 도입에 따른 위협요소 대책안을 마련해야한다. 보안사고 발생 시 정보유출, 이미지 실추, 금적적인 손해, 인명피해 등 다양한 문제가 나타날 수 있다. 그러므로 본 논문에서는 IoT기반 클라우드 융합 환경에서 안전한 접근 제어를 위한 인증서 관리기법을 제안한다. 디바이스 및 사용자 등록, 메시지 통신 프로토콜, 디바이스 갱신 및 관리 기법을 설계하였다. 공격기법 및 취약점에 따른 안전성 분석을 수행하였으며, 기존 PKI 기반 인증서 관리기법 대비 효율성 평가결 과 약 32%의 감소된 수치를 확인 할 수 있었다.

IoT which is the core IT of the 4th industrial revolution, is providing various services from users in the conversion with other industries. The IoT convergence technology is leading the communication paradigm of communication environment in accordance with the increase of convenience for users. However, it is urgently needed to establish the security measures for the rapidly-developing IoT convergence technology. As IoT is closely related to digital ethics and personal information protection, other industries should establish the measures for coping with threatening elements in accordance with the introduction of IoT. In case when security incidents occur, there could be diverse problems such as information leakage, damage to image, monetary loss, and casualty. Thus, this paper suggests a certificate management technique for safe control over access in IoT-based Cloud convergence environment. This thesis designed the device/user registration, message communication protocol, and device renewal/management technique. On top of performing the analysis on safety in accordance with attack technique and vulnerability, in the results of conducting the evaluation of efficiency compared to the existing PKI-based certificate management technique, it showed about 32% decreased value.

13

NCW 컴퓨팅 환경에서 CA-TRBAC의 접근제어 효율성에 관한 연구 KCI 등재후보

엄정호, 박선호, 정태명

한국융합보안학회 융합보안논문지 제9권 제1호 2009.03 pp.45-53

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

NCW(Network Centric Warfare) 컴퓨팅 환경에 적용되는 CA-TRBAC(Context Aware-Task Role Based Access Control)은 유비쿼터스 전장 컴퓨팅 환경에 적합하고 군사정보의 기밀성을 보장할 수 있도록 기존의 T-RBAC(Task-Role Based Access Control)에 상황인식 기술을 추가 하고 보안등급 속성을 활용한 접근제어 모델이다. CA-TRBAC은 접근제어 구성요소들의 상황 에 따라서 접근제어할 수 있도록 하고 보안등급에 의해서 서로 다른 보안등급의 역할, 태스크, 객체간 정보가 유출되지 않도록 통제한다. 특히, 보안등급 속성을 이용하여 객체간의 접근모드 를 조절하여 객체간의 정보의 흐름이 발생하지 않도록 한다.

CA-TRBAC(Context Aware-Task Role Based Access Control) is access control model which add context awareness technology and security level attribute to existent T-RBAC for secure confidentiality of military intelligence and adapt to NCW(Network Centric Warfare) computing environment. CA-TRBAC can control access according to contexts of access control components and excludes intelligence leakage among roles, tasks, objects by security level attribute. Specially, it prevents information flow between different security level’s objects as controlling access mode by security level attribute.

14

4,000원

연구목적: 최근 국내외에서 해킹으로 피해자의 데이터를 암호화하고 이를 풀어주는 대가로 금전적 대 가를 요구하는 랜섬웨어 피해가 증가하고 있다. 이에 다양한 방식의 대응기술과 솔루션에 대한 연구개 발이 진행되고 있으며, 본 연구에서는 데이터를 저장하는 저장장치에 대한 보안 연구개발을 통해 근본 적인 대응방안을 제시하고자 한다. 연구방법: 동일한 가상환경에 보안 저장영역과 일반 저장영역을 생 성하고 접근 프로세스를 등록하여 샘플 데이터를 저장하였다. 저장된 샘플 데이터의 침해 여부를 확인 하기 위해 랜섬웨어 샘플을 실행하여 침해 여부를 해당 샘플 데이터의 Hash 함수를 확인하였다. 접근 제어 성능은 등록된 접근 프로세스와 동일한 이름과 저장위치를 통해 샘플 데이터의 접근 여부를 확인 하였다. 연구결과: 실험한 결과 보안 저장 영역의 샘플 데이터는 랜섬웨어 및 비인가된 프로세스로부터 데이터의 무결성을 유지하였다. 결론: 본 연구를 통해 보안 저장영역의 생성과 화이트리스트 기반의 접 근 제어 방법이 중요한 데이터를 보호하는 방안으로 적합한 것으로 평가되며, 향후 기술의 확장성과 기 존 솔루션과의 융합을 통해 보다 안전한 컴퓨팅 환경을 제공할 수 있을 것으로 기대된다.

Purpose: Recently, ransomware damage that encrypts victim's data through hacking and demands money in exchange for releasing it is increasing domestically and internationally. Accordingly, research and development on various response technologies and solutions are in progress. Method: A secure storage area and a general storage area were created in the same virtual environment, and the sample data was saved by registering the access process. In order to check whether the stored sample data is infringed, the ransomware sample was executed and the hash function of the sample data was checked to see if it was infringed. The access control performance checked whether the sample data was accessed through the same name and storage location as the registered access process. Result: As a result of the experiment, the sample data in the secure storage area maintained data integrity from ransomware and unauthorized processes. Conclusion: Through this study, the creation of a secure storage area and the whitelist-based access control method are evaluated as suitable as a method to protect important data, and it is possible to provide a more secure computing environment through future technology scalability and convergence with existing solutions.

15

ARC 접근제어 정책 기반의 공공 교육망 제로트러스트 보안 모델 연구 KCI 등재

김동우, 한수진, 이기찬, 오수현

한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.145-154

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 업무 환경이 확장되면서 네트워크의 경계가 모호해지고 기존 경계 기반 보안 모델의 한계가 부각됨에 따라, 새로운 대안으로 제로트러스트 보안 모델이 주목받고 있다. 이에 다양한 분야에서 제로트러스트 도입을 위한 노력이 활발한 가운데, 민감한 데이터를 다루는 공공 교육망 환경에서의 적용은 고려되지 않고 있다. 특히 2006년부터 교육기관을 대상으로 전용회선 을 구축해 온 스쿨넷 사업은 경계 기반 보안 모델을 채택하고 있어 기존의 취약점에 여전히 노출되어 있다. 따라서 본 논문에 서는 공공 교육망에 제로트러스트 보안 모델을 적용한 아키텍처를 제안한다. 또한 접근 주체의 신뢰도를 평가하기 위한 접근 위험 계수(Access Risk Coefficient)를 정의하고 이를 시스템에 적용하여 보안성을 강화한다. 나아가 제안하는 시스템에서 고 려해야 할 보안 요구사항을 도출하고, 안전성을 분석함으로써 공공 교육망에 적합한 제로트러스트 보안 모델을 제시한다.

As the work environment has expanded recently, the boundaries of the network have become ambiguous and the limitations of the existing perimeter-based security model have been highlighted, so the zero-trust security model is attracting attention as a new alternative. Accordingly, while efforts to introduce zero-trust are active in various fields, its application in the public education network environment that handles sensitive data has not been considered. In particular, the SchoolNet project, which has been building dedicated lines for educational institutions since 2006, has adopted a perimeter-based security model and is still exposed to existing vulnerabilities. Therefore, this paper proposes an architecture that applies the zero-trust security model to the public education network. In addition, the access risk coefficient for evaluating the reliability of the access subject is defined and applied to the system to enhance security. Furthermore, the security requirements to be considered in the proposed system are derived and the safety is analyzed, thereby proposing a zero-trust security model suitable for the public education network.

16

SaaS 협업 환경 보안 취약점 분석 및 다층 보안 아키텍처 제안 KCI 등재

오다은, 이호준, 이동휘

한국융합보안학회 융합보안논문지 제25권 제4호 2025.10 pp.161-168

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 기업과 기관에서 도입이 급격히 확산되고 있는 클라우드 기반 협업 도구(Software as a Service, SaaS)는 높은 접근 성과 편의성을 제공하지만, 네트워크 분리 정책과 다중 사용자 환경에서 다양한 보안 위협에 노출되고 있다. 특히 Adversary-in-the-Middle(AiTM) 공격, 권한 오남용, 접근제어 설정 오류, 세션 하이재킹, 그리고 제3자 애플리케이션 연계로 인한 공급망 위협 등은 SaaS 환경에서 빈번히 발생하는 주요 취약점으로 지적된다. 본 연구에서는 SaaS 협업 환경의 보안취 약점을 체계적으로 분석하고, 이를 대응하기 위한 다층 보안 아키텍처를 제안한다. 제안 아키텍처는 (1) 데이터 민감도에 따른 C/S/O 분류 기반 망 분리, (2) WebAuthn 기반 다중 인증과 RBAC·ABAC 기반 정교한 접근제어, (3) UTM(Unified Threat Management)을 통한 네트워크 및 웹 필터링, (4) TLS 기반 로그 암호화 및 ELK 스택 기반 실시간 보안관제의 네 가지 계층 으로 구성된다. 이를 통해 기존 망 분리 모델의 한계였던 업무 효율성과 비용 부담 문제를 완화하면서도, 최신 위협(AiTM, 세 션 하이재킹 등)에 대한 방어력을 확보하였다.

Cloud-based collaboration tools, or Software as a Service (SaaS), have seen rapid adoption in companies and institutions due to their high accessibility and convenience. However, they are exposed to multiple security threats in multi-user environments and under network segmentation policies. Key vulnerabilities include Adversary-in-the-Middle (AiTM) attacks, privilege abuse, misconfigured access controls, session hijacking, and supply chain risks from third-party integrations. This study systematically analyzes these vulnerabilities and proposes a multi-level security architecture to address them. The architecture comprises four layers: (1) network segmentation based on data sensitivity using C/S/O classification, (2) multi-factor authentication with WebAuthn combined with RBAC and ABAC-based access control, (3) network and web filtering through Unified Threat Management (UTM), and (4) TLS-based log encryption with real-time monitoring via the ELK stack. The proposed approach mitigates the limitations of existing segmentation models, such as operational inefficiency and high costs, while providing effective defense against modern threats like AiTM attacks and session hijacking.

17

정보 공유를 위한 토큰 기반 KMS 연구 KCI 등재

한성화, 이후기

한국융합보안학회 융합보안논문지 제23권 제5호 2023.12 pp.29-34

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

KMS(Knowledge Management System)은 다양한 기관에서 정보 공유를 위해 사용하고 있다. 이 KMS는 각 기관에서 사 용하는 기본 정보 뿐만 아니라, 중요 정보를 포함하고 있다. KMS에 저장된 중요 정보에 대한 접근을 통제하기 위하여, 많은 KMS는 사용자 식별 및 인증 기능을 적용하고 있다. 이러한 KMS 보안 환경은, KMS에 접근할 수 있는 사용자 계정 정보가 유출되면, 해당 계정 정보를 사용하는 악의적 공격자는 KMS에 접근하여 허가된 모든 중요 정보에 접근할 수 있는 한계점이 있다. 본 연구에서는 사용자 계정 정보가 유출되더라도 중요 정보를 보호할 수 있는 사용자 토큰(Token)을 적용한 파일 접근 통제 기능 적용 KMS를 제안한다. 제안하는 토큰 기반 KMS는 암호 알고리즘을 적용하여 KMS에 등록된 파일을 보호한다. 실효성 검증을 위해 목표하는 사용자 접근통제 기능에 대한 단위 기능을 확인한 결과, KMS에서 제공해야 할 접근통제 기능 을 정상 제공하는 것을 확인하였다.

KMS (Knowledge Management System) is used by various organizations to share information. This KMS includes imp ortant information as well as basic information used by each organization. To protect infortant information stored in KMS, many KMS use user identification and authentication features. In such a KMS security environment, if the account inform ation of a user who can access the KMS is leaked, a malicious attacker using the account information can access the KM S and access all authorized important information. In this study, we propose KMS with user access control function that c an protect important information even if user account information is leaked. The KMS with the user access control functio n proposed in this study protects the stored files in the KMS by applying an encryption algorithm. Users can access impo rtant documents by using tokens after logging in. A malicious attacker without a Token cannot access important files. As a result of checking the unit function for the target user access control function for effectiveness verification, it was confir med that the access control function to be provided by KMS is normally provided.

18

4,000원

본 논문은 M365(Microsoft 365)의 정보보안 체계 점검과 규제 준수를 위한 방안을 제시한다. M365은 기업의 업 무 개선, 협업 강화, 비용 절감, 보안 및 규정 준수를 위한 전략적인 결정으로 간주된다. M365은 사용자 인증과 접근 관리, 데이터 분류와 민감도 분석, 엔드포인트 보호, 이메일 및 문서 보안 등 다양한 기능을 제공하여 기업 의 정보를 안전하게 보호할 수 있다. 망분리 환경에서 M365에 접근하기 위해서는 적절한 접근 방법을 선택해야 한다. PaaS 서비스에 접근하는 방식과는 다른 방식을 선택하여, SaaS 형태의 서비스의 경우에는 접근통제가 된 망분리 환경에서 접속 방안을 고려해야 한다.

This Study presents an approach to assessing the information security system and regulatory compliance of Microsoft 365 (M365). M365 is considered a strategic decision for enterprises, aiming to improve business processes, enhance collaboration, reduce costs, and ensure security and regulatory compliance. M365 offers various features such as user authentication and access management, data classification and sensitivity analysis, endpoint protection, and email and document security to securely protect enterprise information. To access M365 in a segmented network environment, appropriate access methods should be chosen. Different approaches should be considered for accessing SaaS services compared to accessing PaaS services, particularly in a segmented network environment with access controls.

19

본 논문은 Fog/Edge Computing과 같은 분산 네트워크에서 publish/subscribe 시스템과 같이 채널 기반으로 브 로드캐스트 되는 데이터의 흐름을 수신자의 아이디를 바탕으로 추적할 수 있는 암호 알고리즘을 제안한다. IoT 네 트워크와 같은 분산 네트워크의 경우 데이터가 여러 다른 노드를 통해 전달되기 때문에, 데이터에 대한 접근 통제가 어려운 것으로 알려져 있다. 특히, publish/subscribe 프로토콜과 같이 데이터를 복수 수신자가 공유하는 프로토 콜의 경우, 어떤 수신자가 실제로 데이터에 접근했는 지 추적하기 어렵다. 본 논문은 브로드캐스트 트래픽의 정확한 수신자에 파악하고 이를 통해 데이터의 흐름을 추적하기 위한 새로운 암호 체계를 제안한다. 본 논문에서는 데이터 의 흐름의 추적이 가능한 채널 기반 암호를 구현하기 위해 속성 기반 암호를 사용하였고 이에 네트워크의 엣지 서버 에서 암호문의 수신자의 아이디를 특정하여 부분 복호화 및 재암호화를 수행하도록 하는 프로세스를 더함으로써 데 이터 흐름의 추적이 가능하도록 하였다. 기존의 재암호화가 가능한 속성 기반 암호의 경우, 재암호화를 수행하는 엣 지 서버에 암호문이 전달된 이후에만 암호문에 대한 접근 통제가 가능하고 엣지 서버에 도달하기 이전의 암호문은 접근 통제가 되지 않아 데이터의 흐름을 정확하게 추적하는 것이 불가능하다. 따라서, 본 논문에서는 암호화된 데이 터가 엣지 서버에 부분적으로 복호화하게 함으로써, 엣지 서버 통하지 않고서는 어떤 수신자도 암호문을 복호화 할 수 없도록 하여 데이터 흐름의 완전한 추적을 가능하게 하였다. 본 논문에서 이런 안전성이 DDH (Decisional Diffie-Hellman) 가정을 통해 증명하였다.

In this paper, we propose channel based encryption with identity-based traceability for decentralized networks such as fog/edge networks. In a decentralized network, controlling access to data is difficult as the data are transmitted via multiple other nodes. Particularly, when data is transmitted using a protocol that has multiple legitimate recipients like a publish/subscribe protocol, tracing who has accessed broadcast data is difficult. To resolve this problem, we present a new encryption scheme that enables us to trace the data flow by confirming the identity of the actual recipient. We construct a channel-based encryption scheme tracing the data flow, which is suitable for a publish/subscribe protocol, based on revocable attribute-based encryption (ABE). We, then, set the edge server to preprocess the ciphertext by re-encrypting and partially decrypting the ciphertext for the actual recipient. Prior to our work, revocable attribute-based broadcast encryption (ABE) was used only to revoke users by re-encryption. However, this method only allows us to trace recipients after the ciphertext is re-encrypted. That means that the data before reaching the re-encryption oracle, that is the edge server in our proposed system, can be accessed by other recipients without leaving any trace and this makes tracing the data flow difficult. In our proposed scheme, the ciphertext cannot be decrypted only after it is partially decrypted by the edge server. Therefore, tracing the data flow is possible via the edge server. We provide proof of security using the Decisional Diffie-Hellman assumption in the paper.

20

국립공원 내 백두대간 보전과 지속가능한 이용을 위한 정책연구

허학영, 조우, 전근철, 최윤호, 유병혁, 김미리, 심규원, 장진, 박준효, 윤주웅, 박홍철, 남승민, 김보현, 정승준, 최승운

국립공원연구원 국립공원연구지 Volume.13 Number.1 2022.06 pp.119-127

본 연구는 국립공원 내 백두대간의 효과적 보전 및 탐방체계 개선을 위한 정책 방안을 도출하기 위해, 국립공원 내 백두대간 관련 논의 및 정책 동향 분석, 마루금 통제구간에 대한 현장 조사, 대국민 인식조사 및 관련 사례 고찰을 수행하였다. 대중의 관심 추세를 파악하기 위한 신문기사(1991-2019)와 검색량(2004-2019)을 분석한 결과 백두대간을 언급한 기사는 총 38,358건이었으며, 종주를 함께 언급한 기사는 1,413건(4%정도)이었다. 검색량에 있어서 2010년 이후 백두대간과 종주에 대한 검색량이 상대적으로 감소한 것으로 나타났다. 백두대간 통제구간을 포함한 연간 종주 인원은 400 여명으로 추정되며, 대국민 인식조사 결과 백두대간에 대한 인지도는 73.5%인반면 백두대간보호 지역에 대한 인지도는 42%로 상대적으로 낮은것으로 나타났다. 69.1%의 응답자가 백두대간에 대한 방문 경험이 있으나 종주 목적의 방문은 15.7%로 상대적으로 낮으며, 향후 백두대간 종주 의향이 있는 응답자는 24.8%인 것으로 나타났다. 국립공원 내 백두대간 마루금 통제구간의 보전성⋅안전성을 평가한 결과 4개 공원 11개 구간 모두 전반적으로 보전성이 우수하며, 안전성 측면 에서는 전반적으로 위험지역이 다수 존재하는 것으로 나타났다. 본 연구 결과를 토대로 국립공원 내 백두대간의 효과적 관리를 위해 적극적인 검토가 필요한 정책으로 ①“백두대간 마루금 종주 탐방문화”의 전환 추진, ②국립공원 내 백두대간 마루금 통제구간 보전 수단 강화, ③“고지대 능선부 탐방로의 효과적 관리 방향” 도출을 위한 시범사업 추진, ④통제구역의 효과적 출입 관리를 위한 법적 근거 강화 등을 제안하였다.

This study aims to derive the policy measures to effectively conserve and sustainable use the Baekdudaegan in National Parks through the literature review on policy trends, public awareness survey, on-site survey, and so on. As a trend of public concern, From 1991 to 2019, there were a total of 38,358 articles mentioning Baekdudaegan, and 1,413 articles( 4%) mentioning Jongju(successive climbing) together. In terms of search volume, the volume for Baekdudaegan and Jongju has decreased relatively since 2010. The annual number of visitors including the closed section was estimated to be 400. The public awareness survey showed that the awareness of Baekdudaegan was 73.5%, while the awareness of Baekdudaegan Mountains Reserve was 42%. 69.1% have visited Baekdudaegan, however, only 15.7% aim for Jongju(successive climbing). 24.8% of the respondents are willing to visit Baekdudaegan for Jongju(successive climbing) in the future. As a result of evaluating the conservation and safety of the Baekdudaegan Closed Section, all 11 sections of the park have excellent conservation values overall, and there are many dangerous areas in terms of safety. Based on the results of this study, 4 policies were suggested; ①to promote the transition of the “Baekdudaegan Visitation Culture”, ②to strengthen the means of conservation of the Baekdudaegan Closed Section in the National Park, ③to sketch a pilot project to derive “effective management directions of ridge trail” ④to strengthen the legal basis for effective access control of the closed section.

 
1 2 3 4 5
페이지 저장