년 - 년
북한의 대남 사이버공격 양상과 행태 : 사이버파워와 강압이론을 통한 분석 KCI 등재
한국융합보안학회 융합보안논문지 제18권 제1호 2018.03 pp.117-128
※ 기관로그인 시 무료 이용이 가능합니다.
4,300원
본 논문은 주요 국제정치이론을 바탕으로 2009년 들어 지속되어온 북한의 사이버 상에서 대남공격 행태를 분석하여 한국의 정책적 대응방안을 제시하는 것이 목적이다. 이를 위해 본 논문은 국제안보학계에서 최근 주목받는 ‘사이버파워’ 의 행동영역과 특성 및 ‘강압의 역동성’ 모델을 적용하였다. 북한의 사이버공격 유형은 권력기반 잠식, 지도자 리더십 공 격과 음해, 군사작전 방해, 사회불안과 혼란유도 유형으로 분류된다. 사이버파워 유형과 수단 면에서 북한의 GPS 교란, 국방부 서버해킹, EMP 등은 보복·위협성이 강한 하드파워이고, 사이버머니 현금화, 렌섬웨어 등은 소프트웨어를 볼모로 거액의 돈을 강탈하거나 요구하는 점에서 설득·유인의 행동 영역에서 힘으로 분석된다. 북한의 사이버공격은 2차 핵실 험을 기점으로 현실적 제재에 따른 탈출구적 성격을 갖는다. 한국은 북한의 공세적 사이버파워가 방법과 능력에서 변화 하고 있음을 명확히 인식하고, 북한의 행동이 이득보다 감당할 수 없는 손실이 훨씬 더 클 것이라는 결과를 갖게끔 만 드는 것이 중요하다. 이를 위해서는 사이버심리전, EMP공격 대비, 해킹보안의 전문성 강화 등 제도적 보완과 신설을 통 해 공격과 방어가 동시에 이루어지는 사이버보안과 역량을 강화할 필요가 있다.
The purpose of this paper is to analyze the behavior of North Korea's cyber attack against South Korea since 2009 based on major international security theories and suggest South Korea’s policy option. For this purpose, this paper applied the behavioral domain and characteristics of 'cyber power' and ‘coercion dynamics' model, which are attracting attention in international security studies. The types of cyber attacks from North Korea are classified into the following categories: power-based incarceration, leadership attacks and intrusions, military operations interference, and social anxiety and confusion. In terms of types and means of cyber power, North Korean GPS disturbance, the Ministry of Defense server hacking and EMP are hard power with high retaliation and threat and cyber money cashing and ransomware are analyzed by force in the act of persuasion and incentive in the point of robbing or asking for a large amount of money with software pawns. North Korea 's cyber attack has the character of escape from realistic sanctions based on the second nuclear test. It is important for South Korea to clearly recognize that the aggressive cyberpower of North Korea is changing in its methods and capabilities, and to ensure that North Korea's actions result in far greater losses than can be achieved. To do this, it is necessary to strengthen the cyber security and competence to simultaneously attack and defend through institutional supplement and new establishment such as cyber psychological warfare, EMP attack preparation, and enhancement of security expertise against hacking.
북한 사이버공격에 대한 대응방안에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제16권 제6호 제1호 2016.10 pp.43-50
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
북한이 우리 사회의 취약한 전산망에 대한 충분한 사이버 공격능력을 갖추고 있어 다양한 대규모의 사이버 공격을 시도할 것으로 예상된다. 북한의 사이버전 수준은 세계 최고수준으로 알려져 있다. 사이버 요원의 수도 지속적으로 증가 하고 있다. 최근 북한의 사이버공격은 수법과 대상을 가리지 않는 전방위적으로 행해지고 있다. 그러나 지금까지의 북한 사이버공격은 실질적인 공격이라기보다는 탐색의 성격이 강하다. 남한이 얼마나 빨리 문제를 발견하고 복구하는지를 알 아보기 위한 목적이었다고 볼 수 있다. 하지만 앞으로는 막대한 실질적 피해를 주는 사이버공격을 자행할 개연성이 높 다. 주요 교통·금융·에너지시설 등의 국가기반시설에 대한 공격이 발생할 경우 그 피해규모는 상상을 초월할 것이므로 이에 대한 대책이 필요하다. 따라서 본 논문에서는 최근 북한 사이버공격의 특징을 살펴보고 대응 방안으로 사이버테러 방지법제정, 대응모의훈련실시, 민관협력체제 구축, 사이버보안 인프라 확대 등을 제시하고자 한다.
As North Korea has a sufficient ability to attack our society’s vulnerable computer network, various large-scale cyber attacks are expected to be tried. North Korea’s cyber military strength is known a world-class level. The number of its cyber agents is increasing consistently. Recently North Korea’s cyber attack has been made regardless of trick and target. But up to now North Korea’s cyber attack is more of an exploration than a real attack. Its purpose was to check how fast Korea found a problem and recovered from it. In future, cyber attack that damages substantially is highly probable. In case of an attack against national infrastructure like traffic, financial and energy services, the extent of the damage will be great beyond imagination. In this paper, characteristics of recent North Korea’s cyber attack is addressed in depth and countermeasures such as the enactment of cyber terror prevention law, simulation training enforcement, private and public cooperation system construction, cyber security infrastructure expansion, etc. are proposed.
북한의 비대칭 전략 - ‘사이버 기습공격’에 대한 대책 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제10권 제4호 2010.12 pp.83-91
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 한반도내에서 발생 가능한 비대칭 전략으로서의 ‘사이버 기습공격’의 발생 가능성에 대해 분석하고 이에 대한 정책적 대책을 제시하기 위해 작성한 것이다. 최근 발생하고 있는 이 란, 중국 등에서 발생한 ‘Stuxnet’ 사이버 기습공격 피해 사례로 볼 때 만일 북한이 남한의 인프 라 시설을 공격한다면 남한 사회에 큰 혼란과 피해를 줄 수 있을 것이다. 최근 발생한 연평도 기습도발 사건 이후 계속적인 도발 위협을 하고 있는 북한의 태도로 볼 때 ‘Stuxnet’과 같은 사 이버공격을 감행할 개연성이 높기 때문에 이에 대한 정책적 대책을 제시하였다. 주요 대책은 1) 독립된 중앙집권적 정부통합조직 신설, 2) 특수대학 설립으로 사이버전 전문인력 양성, 3) 예산 증액 및 전문인력 관리체계 개선이다.
Information security is a critical issue for national defense. This paper provides a result of a study on the countermeasures to the North Korean Asymmetric Strategy-‘Cyber Surprise Attack’. After the attack on Yeonpyeong island, the North Korea threatened there will be more surprise attack to the South Korea. Based on the analysis of ‘Stuxnet’ cyber attack to Iran and China, the North Korean surprise attack may be ‘Stuxnet’ class cyber attack. This paper several strategic countermeasures in order to overcome the anticipated the North Korean cyber surprise attack.
교육기관을 위한 클라우드 보안관제 연동체계 구축 방안 KCI 등재
한국융합보안학회 융합보안논문지 제25권 제1호 2025.03 pp.37-46
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
정부의 ‘민간 클라우드 도입 활성화 정책’ 및 ‘디지털 플랫폼 정부(digital platform government)’ 구현을 위해 교육기관의 민간 클라우드 도입이 확대되고 있다. 그러나 교육기관의 클라우드 환경에서의 사이버공격 대응과 보안관제 분야는 아직 초기 수준이다. 특히, 정보보안업체와 부처 사이버안전센터에서 클라우드 서비스 제공자(CSP)의 네트워크 환경에 따라 보안관제 탐지 장비를 설치하고, 탐지된 결과를 부처 사이버안전센터로 전송하는 부분, 즉 보안관제 연동에 많은 어려움을 겪고 있다. 본 논문에서는 2021년 국가․공공기관에서 개발한 사이버공격 탐지프로그램을 기반으로 클라우드 환경에서 클라우드 서비스 보안인증(CSAP) 업체를 대상으로 보안관제 연동을 위한 방법론을 제시한다. 이를 통해 교육기관에 특화된 클라우드 환경과 유연하고 효과적인 보안관제 모델을 제시하는데 본 연구의 의의가 있다.
The government’s "Policy to Promote the Adoption of Private Cloud" and the implementation of the "Digital Platform Government" have led to an increase in the adoption of private cloud in educational institutions. However, the response to cyberattacks and the field of security monitoring in cloud environments within educational institutions are still in their early stages. In particular, there are significant challenges in the integration of security monitoring, where security monitoring detection devices are installed based on the network environment of cloud service providers (CSPs) by information security companies and ministry cyber safety centers, and the detected results are transmitted to the ministry's cyber safety center. This paper presents a methodology for security monitoring integration in cloud environments targeting Cloud Security Assurance Providers (CSAPs) based on the cyberattack detection programs developed by national and public institutions in 2021. The significance of this study lies in proposing a cloud environment tailored to educational institutions, as well as a flexible and effective monitoring model.
4,000원
21세기 정보통신기술의 발달은 주요기반시설의 제어시스템에 초연결성과 초지능성을 갖게 하여 운용 효율성을 높였 으나, 보안 취약점을 증가시켜 해킹 위협에 노출되고 있다. 그중에서도 일상생활에 필수적으로 사용하는 전력을 공급하 는 전력시스템은 국가 중요기반체계로서 사이버공격의 주요 표적이 되고 있다. 최근에는 전력시스템을 보호하기 위해 서 다양한 보안체계를 개발하고 실전형 사이버공방훈련을 통해서 전력시스템의 안정성을 유지하고자 한다. 하지만, 사 이버공격이 인공지능과 빅데이터 등의 첨단 ICT 기술과 접목되면서 기존의 보안체계로 지능화되고 있는 사이버공격을 방어하기가 쉽지 않게 되었다. 이러한 지능화되는 사이버공격을 방어하기 위해서는 지능형 사이버공격의 유형과 양상 을 사전에 파악하고 있어야 한다. 본 연구에서는 첨단 ICT 기술과 접목된 사이버공격의 진화에 대해서 분석하였다.
The development of information and communication technology in the 21st century has increased operational effic iency by providing hyper-connectivity and hyper-intelligence in the control systems of major infrastructure, but is a lso increasing security vulnerabilities, exposing it to hacking threats. Among them, the electric power system that s upplies electric power essential for daily life has become a major target of cyber-attacks as a national critical infras tructure system. Recently, in order to protect these power systems, various security systems have been developed a nd the stability of the power systems has been maintained through practical cyber battle training. However, as cybe r-attacks are combined with advanced ICT technologies such as artificial intelligence and big data, it is not easy to defend cyber-attacks that are becoming more intelligent with existing security systems. In order to defend against s uch intelligent cyber-attacks, it is necessary to know the types and aspects of intelligent cyber-attacks in advance. In this study, we analyzed the evolution of cyber attacks combined with advanced ICT technology.
사이버 전쟁에 대한 법적 규율에 관한 연구 KCI 등재
동국대학교 비교법문화연구원 비교법연구 제22권 3호 2022.12 pp.807-835
※ 기관로그인 시 무료 이용이 가능합니다.
6,900원
오늘날 사이버 안보는 국가안보의 핵심으로 부상했다. 사이버 안보 는 단적으로 사이버 공격의 충격으로부터의 국가안전의 확보이다. SNS 등 눈부신 의사소통 과학기술의 발달로 국가안보의 핵심으로 부 상한 사이버 안보는 정확한 개념 정의에서 출발한다. 사이버 전쟁과 사이버 테러리즘은 대표적으로 사이버 안보를 위협하는 사이버 공격이 다. 사이버 전쟁은 사이버공간에서 전쟁 수준의 무력 공격이다. 이론적 으로는 사이버 공격을 받은 국가가 비례적인 무력 사용으로 물리적으 로 군사적 대응을 촉발할 수 있는 사이버 공격이다. 반면에 사이버 테 러는 사이버공간에서 이념적ㆍ종교적ㆍ정치적 목적으로 극도의 공포심 을 초래하려는 파괴적 활동이다. 이외에도 사이버 범죄도 사이버 안보 를 위협하는 사이버 공격에 포괄된다. 그들 사이버 전사, 사이버 테러 리스트, 사이버 범죄자의 목표는 다르다. 사이버 전쟁은 궁극적으로는 대상 국가의 전복을 목표로 한다. 사이 버 테러리스트는 정치적ㆍ이념적ㆍ종교적 목표를 추구하여 극도의 공 포심을 야기하여 대상국가의 정책을 변경하려는 의도로 사이버공간에 서 다양한 공격을 감행하는 테러분자이다. 반면에 사이버 범죄를 자행 하는 사이버 활동가들은 단순한 즐거움 또는 범죄 철학, 정치적, 금전 적 이유로 사이버 공격을 하는 개인들이다. 어떤 수준의 사이버 공격 이 사이버 전쟁인지, 사이버 테러인지 아니면 사이버 범죄인지를 판단 할 수 있는 명확한 기준은 아직 없다. 또한 사이버공간에서 국가간 관 계를 규제하기 위한 국제적 법적 구속력이 있는 법제나 수단도 아직 마련되어 있지 않다. 현실적으로 사이버 전사, 사이버 테러리스트, 사이버 범죄자 등의 각 범주 내에서 다양한 행위자의 의도 및 방법은 중복될 뿐만 아니라 다양한 동기가 대응 옵션을 복잡하게 만드는 것이 현실이다. 이에 본 고는 사이버 안보의 위험성이 점증하는 현실에서 사이버 공격에 대한 법치적 접근의 현실과 미래 과제를 살펴보고 졸견을 제시하고자 한다.
Cyber-attacks have become increasingly common in recent years. As a result, some have suggested that cyber-attacks should be treated as acts of war. Cybersecurity is, in short, securing national security from the impact of cyber attacks. Cybersecurity starts with an accurate conceptual definition of related terms. This Article examines how existing law may be applied— and adapted and amended—to meet the distinctive challenge posed by cyber-attacks. It begins by clarifying what cyber-attacks are and how they already are regulated by existing bodies of law, including the law of war, international treaties, and domestic criminal law. Cyber warfare is a war-level armed attack in cyberspace. Cyberwar ultimately aims to overthrow the target country. Cyber terrorists are terrorists who carry out various attacks in cyberspace with the intention of changing the policy of the target country by causing extreme fear in pursuit of political, ideological, and religious goals. On the other hand, cyber activists who commit cybercrime are individuals who engage in cyberattacks for simple pleasures or criminal philosophy, political, and financial reasons. There are no clear criteria yet to determine what level of cyberattacks are cyber warfare, cyber terrorism, or cybercrime. In addition, there are no international legally binding laws or means yet in place to regulate relations between countries in cyberspace. In reality, the intentions and methods of various actors within each category of cyber attacks are not only overlapping, but also various motives complicate response options. From these point of views, this paper aims to examine the reality and future challenges of the rule of law approach to cyber attacks in the reality of the increasing risk of cybersecurity and to present poor opinions.
제로트러스트 보안 모델에서 보안관제 시스템 강화 연구 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제2호 2022.06 pp.51-57
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 제로 트러스트에 대한 개념이 도입되며 차세대 보안관제 시스템에 필요한 보안 요소 강화가 필요 하다. 또한, 4차 산업혁명 시대의 보안 패러다임도 바뀌고 있다. 클라우드 컴퓨팅과 코로나 19로 인해 업무 환경이 변화되면서 발생하는 사이버보안 문제는 지속 발생하고 있다. 그리고 이와 동시에 새로운 사이버 공격기법들도 지능화·고도화되고 있는 상황에서 보안을 강화할 미래의 보안관제 시스템이 필요하다. 제로 트러스트 보안 개념은 모든 것을 의심하며 신뢰하지 않는다는 개념을 기반으로 모든 통신을 감시하고 접근 요청자에 대한 엄격한 인증과 최소한의 접근 권한을 핵심으로 보안성을 높인다. 본 논문에서는 기존 보안관제 시스템의 문제점을 이해하고 이를 해결할 수 있는 제로 트러스트 보안 모델을 통해 보안관제 분야의 보안 강화 방안을 제안 한다.
Recently, the concept of zero trust has been introduced, and it is necessary to strengthen the security elements required for the next-generation security control system. Also, the security paradigm in the era of the 4th industrial revolution is c hanging. Cloud computing and the cybersecurity problems caused by the dramatic changes in the work environment due t o the corona 19 virus continue to occur. And at the same time, new cyber attack techniques are becoming more intelligent and advanced, so a future security control system is needed to strengthen security. Based on the core concept of doubting and trusting everything, Zero Trust Security increases security by monitoring all communications and allowing strict auth entication and minimal access rights for access requesters. In this paper, we propose a security enhancement plan in the s ecurity control field through a zero trust security model that can understand the problems of the existing security control system and solve them.
모자이크전 수행 개념을 적용한 능동형 상황 탄력적 사이버 방어작전 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제4호 2021.10 pp.41-48
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 4차 산업혁명기술로 인해 전쟁의 양상까지 진화하고 있다. 그 중에서도 인공지능 기술이 첨단 무기체계와 의사 결정시스템에 적용됨에 따라 전쟁 수행 방식을 변모시키고 있다. 미국의 방위고등연구계획국에서 제시한 모자이크전은 사물인터넷, 클라우드 컴퓨팅, 빅데이터, 모바일, 인공지능 기술을 접목시킴으로써 군사적전을 소모중심에서 결심중심으 로 전환하고 네트워크화된 전장 상황에 따라 분산 배치된 전력을 적절히 재조합하여 신속하게 전쟁을 수행하는 방식이 다. 즉, 획일화된 전투 프로세스에 의해 군사작전을 수행하는 것이 아니라 상황에 따라 분산체계를 통해 다양한 전력을 운용한다는 것이다. 사이버전에서도 인공지능이 사이버공격 기술에 적용됨에 따라 기존의 사이버 킬 체인과 같은 절차 적 대응 방식으로는 한계가 있다. 그래서 본 논문에서는 공격 상황에 따라 대응 시스템을 운용할 수 있는 능동형 상황 탄력적 사이버작전을 효과적으로 수행하기 위해서 모자이크전의 수행 방식을 적용하고자 한다.
Recently, the aspect of war is evolving due to the 4th industrial revolution technology. Among them, AI technolo gy is changing the way of war as it is applied to advanced weapon systems and decision-making systems. Mosaic Warfare, presented by the U.S. DARPA, is shifting military warfare from attrition-centric warfare to decision-centri c warfare by combining Internet of Things, cloud computing, big data, mobile, and artificial intelligence technologies. In addition, it is a method to perform operations quickly so that the most offensive effect can be achieved by appro priately combining the distributed and deployed forces according to the battlefield context. In other words, military o perations are not carried out through a uniform combat process, but various forces are operated through a distribute d system depending on the battlefield context. In cyber warfare, as artificial intelligence is applied to cyber attack te chnology, there is a limit to responding with the same procedural response method as the existing cyber kill chain. Therefore, in this paper, the execution method of mosaic warfare is applied to perform context-resilient cyber operat ions that can operate a response system according to the attack and cyberspace context.
사이버 안보 전문인력 양성을 위한 교육시스템 개선 방안 KCI 등재
한국경찰연구학회 한국경찰연구 제20권 제1호 2021.03 pp.409-426
※ 기관로그인 시 무료 이용이 가능합니다.
5,200원
정보통신 기술의 발전으로 인하여 현대 인간들은 생활의 편리함을 더욱 누리면서 삶을 영위하고 있지만 반대급부로 이러한 편리한 기술들로 인하여 가상현실에서의 악 의적 위협을 받고 있다. 현재 한국은 미·중 무역전쟁으로 인하여 주변국들에게 많은 안 보적 위협에 노출되어 있으며, 전통적인 물리적 안보위협뿐만 아니라 가상공간에서의 위협도 나날이 증가하고 있어 사이버 위협에 대한 심각성이 고조되고 있다. 그러나 우 리나라는 사이버 안보에 관련된 기본법도 제정이 되어 있지 않은 상태이므로 오랜 시 간과 비용이 투자되어야 하는 사이버 안보 전문인력 양성에 대하여서는 정보보호 분야 에 치중하여 교육이 운용되고 있다. 현재까지 많은 사이버 안보 관련 법안이 발의 되었 지만 아직 제정이 되고 있지 못하고 있다. 이에 따라 본 연구는 사이버 안보관련 대학 교육과 국가기관에서의 전문인력 양성과 관련하여 사이버 안보 법제 마련과 교육시스 템 개선을 목적으로 하며, 사이버 안보를 담당하기 위한 전문 인력 양성을 위한 교육 인프라가 확충되어야 함과 동시에 지도자 양성과 공신력 있는 자격검증 제도가 마련되 어야 한다. 또한 수도권 중심으로 편중된 교육환경 제약을 극복하고, 대학 역할의 강화 와 더불어 관련 정부기관과 연계된 교육사업이 전국적으로 강화되어야 한다.
With the development of information and communication technology, modern humans are living their lives while enjoying the convenience of life more, but as a counter benefit, these convenient technologies are threatened with malicious in virtual reality. Currently, Korea is exposed to many security threats to neighboring countries due to the US-China trade war, and the seriousness of cyber threats is increasing as threats in virtual space as well as traditional physical security threats are increasing day by day. However, since the basic laws related to cybersecurity in Korea have not been enacted, education is being operated with a focus on the field of information protection for the training of cybersecurity professionals that require a long time and cost. And until now, many cybersecurity related laws have been proposed, but they have not been enacted yet. Accordingly, this study aims to prepare cybersecurity legislation and improve the education system accordingly in relation to cybersecurity-related university education and training of professional manpower in national institutions. At the same time, the infrastructure must be expanded and a system for training leaders and credible qualifications must be established. In addition, concrete measures to overcome the constraints of the educational environment concentrated in the metropolitan area must be realized. To this end, the role of universities must be reinforced and educational projects linked with related government agencies must be strengthened nationwide.
코로나19 환경에서 무중단 보안관제센터 구성 및 운영 강화 연구 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제1호 2021.03 pp.25-31
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구의 목적은 코로나19 바이러스 유행 시기에 교대근무체계로 운영하는 보안관제센터를 무중단으로 유지하기 위 한 연구 이다. 사이버 보안위협에 대응하는 보안관제 시설은 24시간 365일 실시간으로 운영해야 하는 필수 보안시설이 며, 보안운영 및 관리적인 부분에서 매우 중요하다. 만약 감염병 유행, 시스템 장애, 물리적 영향 등 보안관제 시설이 폐 쇄되거나 영향이 있는 경우 실시간 사이버 보안위협에 대응 할 수 없으며, 보안문제에 치명적이 될 수 있다. 최근 코로 나19 바이러스 유행으로 인한 시설 폐쇄, 장마철로 인한 보안시스템 가용성 장애 등 보안관제 시설 운영을 할 수 없는 사례가 확인되고 있으며, 이 외에도 물리적 영향으로 보안관제 시설을 운영 할 수 없는 상황에 대한 대비가 필요하다. 본 논문에서는 보안관제 시설을 다중화 시설로 구성하여 폐쇄되는 상황 발생 시 무중단으로 운영 할 수 있는 방안을 제안한다.
The purpose of this study was to keep the Security Control Center, which operates under a shift system, uninterrupted during the COVID-19 virus epidemic. Security facilities responding to cybersecurity threats are essential security facilities that must be operated 24 hours a day, 365 days a day in real time, and are critical to security operations and management. If security facilities such as infectious disease epidemic, system failure, and physical impact are closed or affected, they cannot respond to real-time cyberattacks and can be fatal to security issues. Recently, there have been cases in which security system facilities cannot be operated, such as the closure of facilities due to the COVID-19 virus epidemic and the availability of security systems due to the rainy season, and other cases need to be prepared. In this paper, we propose a plan to configure a security system facility as a multiplexing facility and operate it as an alternative in the event of a closed situation.
4,000원
본 연구의 목적은 북한의 사이버 공격과 우리의 대응에 대해 노무현 정부 부터 문재인 정부까지 정부별로 비교 분석 하는 데 있다. 현재 한반도는 미국, 중국, 러시아 등 다양한 이해관계가 상충되면서 새로운 세계질서의 주도권 다툼이 사이버상에서 충돌로 이어지고 있다. 사이버 공격의 속도는 빨라지고 위협의 수위는 높아지고 있다. 사이버 위협은 몇 가지 특징을 보이고 있다. 무엇보다 위협의 주체를 확인하거나 추적하기 어렵다는 점이다. 또한 정보통신기술의 발달로 공격기술이 지능화되어 이에 대응하는 수단을 마련하기도 쉽지 않다. 따라서, 국가사이버안보를 위해 지속적이고 선제 적인 대응 역량을 제고하고, 국가간 또는 민간 전문가간의 국제협력과 같은 여러 행위자간의 거버넌스 구축이 필요하다.
The purpose of this paper is to ccompare and analyze North Korean cyber attacks and our responses by government, fr om the Roh Moo-hyun administration to the Moon Jae-in administration. The current conflict of interests on the Korean p eninsula, such as the United States, China, and Russia, is leading to a conflict for the leadership of a new world order in cyberspace. Cyber attacks are accelerating and threats are rising. Cyber threats exhibit several characteristics. Above all, i t is difficult to identify or track the subject of the threat. Also, with the development of information and communication te chnology, attack technology has become more intelligent, and it is not easy to prepare a means to respond. Therefore, it is necessary to improve continuous and preemptive response capacity for national cybersecurity, and to establish governance among various actors, such as international cooperation between countries or private experts.
6,400원
이 논문은 북한의 대남 사이버공격의 대표적인 사례와 그 특성을 분석하여 향후 우리정부가 북한의 사이버공격에 대한 체계적이고 실효적인 정책을 수립ㆍ시행함에 있어서 고려하여야 할 기본적인 대비전략을 장ㆍ단기적인 관점에서 개략적으로 제시하는 데 그 목적이 있다. 이를 위하여 우선 논제인 북한의 대남 사이버공격 논의에 있어서 기본적 검토사항인 사이버공격과 관련 유사용어의 정의, 사이버공격의 본질적 속성, 사이버공격의 방법을 검토하여 본 논제의 대상과 범위에 대한 명확성을 확보하고자 하였으며, 이어서 북한의 대남 사이버공격의 대표적 사례와 그 특성을 분석하였고, 다음으로 북한의 사이버공격의 사례와 그 특성에 대한 분석을 토대로 북한의 대남 사이버공격에 대한 대비전략을 장ㆍ단기적 관점에서 개략적으로 제시하였으며, 결론 부문에서는 전술한 내용을 근거로 하여 종합적인 관점에서 향후 북한의 사이버공격에 대한 대비전략의 마련에 있어서 고려해야 할 주요 사항을 요약하여 기술하였다. 결론적으로 이 논문에서는 우리정부가 북한의 사이버공격의 가능성이 상존하고 있음을 인식하고 이에 대한 대비전략의 수립ㆍ시행함에서 있어서, 단기적인 실무적 차원에서 사이버보안 교육 및 홍보의 보완, 사이버공격 대응 모의훈련의 개선, 사이버보안민간단체와의 협력체제의 강화, 보안정보를 이용한 사이버공격대응, 관련 국가와의 공조의 강화 등을, 그리고 중ㆍ장기적인 법적ㆍ제도적 차원에서 사이버보안 관련 법제의 정비, 사이버공격 대응 지휘체계 및 총괄기구의 정비, 사이버 전문 인력 양성체제의 개선 등을 고려할 필요가 있음을 제시하였다.
The purpose of this study is to analyze typical cases and characteristics of North Korea's cyber attacks toward South Korea, and roughly present in the short and long term viewpoint fundamental counter strategies to be considered by our government for establishing and enforcing systematic and effective policies against North Korea's cyber attacks in future. For such purpose, the concept of cyber attack and relevant similar terms that are fundamental theories in the discussion of North Korea's cyber attacks were defined, and the intrinsic characteristics and methods of cyber attack were examined in order to clarify the target and range of this subject. Next, typical cases and characteristics of North Korea's cyber attacks toward South Korea were analyzed. And then, counter strategies against North Korea's cyber attacks toward South Korea were presented roughly in the short and long term viewpoint based on the analysis of the cases and characteristics of North Korea's cyber attacks. In conclusion, major considerations for preparing counter strategies against North Korea's cyber attacks in future were summarized and outlined. Conclusionally, in this study I put forward that in establishing and enforcing counter strategies against North Korea's cyber attacks, our korean government should consider synthetically information protection educations and promotions, execution of preliminary exercises, reinforcement of cooperation systems with private sectors, reinforcement of international cooperation systems and responses to cyber attacks using security information etc in the short-term working-level, and the establishment of legislative grounds, reorganization of command structures and comprehensive organizations, and einforcement of cyber specialists cultivation systems etc, in the long-term institutional-level.
국내 관련 법과 비교 분석을 통한 국가사이버안보법안의 제정 필요성 연구 KCI 등재
한국보안관리학회(구 한국경호경비학회) 시큐리티 연구 제54호 2018.03 pp.9-35
※ 기관로그인 시 무료 이용이 가능합니다.
6,600원
제 4차 산업혁명이 도래하고 있는 오늘날, 사이버공격은 초국가적인 형태로 민간과 공공 구분 없이 동시다발적으로 일어나고 있으며, 지난 2009년의 DDOS 사건을 포함하여 청와대, 언론, 금융기관 전산 시스템 마비 등 사이버 위협은 갈수록 심각성을 더하고 있다. 그러나 현재 우리나라는 사이버안보와 관련된 기본법이 존재하지 않고, 국내의 여러 법률에 관련 내용이 산재되어 있는 형편이다. 이는 사이버안보와 관련된 내용의 법 적용 및 판단 근거에 혼선을 초래할 수 있다. 이러한 상황을 극복하기 위해 2006년 ‘사이버위기 예방 및 대응에 관한 법률안’이 발의되었지만 폐기되었고, 이후 꾸준히 발의되었지만 기존 법률과의 중복문제 및 개인정보침해우려 등으로 번번이 통과가 무산되었다. 가장 최근 발의안은 ‘국가사이버안보법안’으로 2017년 1월 정부가 발의하였다. 이 법안은 사이버안보와 관련된 기본법의 부재를 해결하고, 사이버안보위기시의 대응 능력 강화 및 안보력 함양 등을 주요 내용으로 하고 있다. 따라서 본 연구는 ‘국가사이버안보법안’을 사이버안보와 관련된 국내의 기존법과 비교 분석을 통해 그 필요성을 고찰하고, 개선점을 제언함으로써 사이버안보 기본법으로서의 ‘국가사이버안보법안’의 올바른 제정에 기여하고자 한다.
During the recent years, cyber attacks have been increasing both in the private sector and the government. Those include the DDOS cases in 2009, the Blue House cyber attack, bank hackings etc. Cyber threats are becoming increasingly serious. However, there is no basic law related to cyber security at present, and regulations related to cyber security are scattered in various domestic laws. This can lead to confusion in the application of the law and difficult to grasp the regulations related to cyber security. In order to overcome this situation, the bill on the prevention and countermeasures against cyber crisis was initiated in 2006, but it has been abrogated. Since then, it has been repeatedly proposed, but it has been abrogated repeatedly due to the overlapping of existing laws and concerns about infringement of personal information. The most recent initiative was the National Cyber Security Act, which was initiated by the government in January 2017. The act focuses on resolving the absence of a basic law related to cyber security, strengthening its responsiveness in the event of a cyber security crisis, and fostering security strength. Therefore, this study seeks to contribute to the establishment of National Cyber Security legislation as a basic law of cyber security by examining the necessity of National Cyber Security legislation through comparative legal analysis with existing domestic laws related to cyber security and suggesting policy implications.
본 연구에서는 선진 각국에서 현재 추진하고 있는 사이버테러 대응실태 검토 분석을 통하여 우리나라의 사이버테러 공격에 대한 보안 문제점들을 진단해보고 효과적인 대응체 계를 구축하는데 필요한 최선의 방안과 대응 전략을 제시하였다. 첫째, 국내의 사이버테러 안보에 대해 먼저 우리에게 직접적으로 위협을 주고 있는 북한 의 사이버전 위협실태를 공격사례 위주로 검토 분석해보았다. 이에 따라 북한이 국내ž외에 서 감행한 사이버테러 공격 사건과 사이버전 능력을 토대로 향후 북한이 감행할 수 있는 사이버테러 공격 수단의 진화 방향을 유형별로 구분하여 제시하였다. 둘째, 해외 각국에서 발생하고 있는 사이버테러 공격 사례를 검토함에 있어 주요기반시 설 분류 기준을 적용하여 분석하였고, 선진 각국에 추진하고 있는 사이버테러 대응체계에 대해 관련 법제 및 조직체계와 그 추진실태를 사례 위주로 검토하여 우리나라에 적용 가능 한 시사점을 도출하였다. 셋째, 국내ž외에서 발생하고 있는 사이버테러 공격에 대한 보안 리스크가 매년대폭 증가 하고 있으며, 이로 인한 개인 및 조직, 국가적 경제적 손실이 확산되고 있기 때문에 이에 대한 최소한의 피해 구제, 배상 차원에서 미국의 사이버보험 제도 및 정책을 검토하여, 우 리나라에 적용할 사이버보험 활성화 방안을 제시하였다. 넷째, 우리나라의 사이버테러 대응 법제와 조직체계, 국방 사이버테러 대응체계, 국제 협력에 대한 체계, 민ž관 거버넌스 체계 등에 대한 개선방안을 제시하였다.
In this study, we propose the best strategies and countermeasures to diagnose the security ramifications of cyber terror attacks in Korea and to establish an effective response system by analyzing the present situation of cyber terrorism in developed countries. First, we analyzed the cyber threats posed by North Korea, which directly threatens the South Korean state through cyber terrorism. In particular, we applied special focus to aforementioned instances of North Korean cyber terrorism. Based on these cyber attack cases and the cyberspace attacks that North Korea has carried out both at home and abroad, we have classified the types of North Korean cyber terror attacks into 6 individual categories. Secondly, in analyzing cases of cyber terrorism occurring in foreign countries, the analysis was applied to major infrastructure classification criteria, and related legislative system and organizational system followed by the respective subject’s national cyber terrorism response system. Implications for Korea are derived from these examples. Third, the security risks of cyber terror attacks occurring both at home and abroad continue to increase rapidly every year. We further examine the attacks from an economic standpoint, placing special emphasis on the losses from individuals, organizations, and countries in that they continue to rise while minimal damage relief and compensation schema continue to be the norm. Within the private sector, the proliferation and effectiveness of Korean cyber insurance policies are examined. Fourth, we suggested strategic improvements to contemporary cyber terrorism countermeasures, organizational systems, the Korean defense cyber terrorism response system, international counter cyber terrorism systems, and civili and administrative governance systems.
4,000원
현대사회에서 정보통신기술의 발달은 인류에게 많은 기회를 제공하고 있지만, 그 이면에는 사이버 공격으로 인한 막대한 손해도 발생하고 있다. 최근 한국도 사이버 공격의 대상이 되었고, 그 위협의 범위도 점차 확대되고 있다. 특히 북한은 한국을 대상으로 한 적대행위를 지속적으로 자행하고 있으며, 최근에는 국가중요시설 등의 전산망을 공격하는 사이버 공격을 감행하고 있다. 이러한 북한의 사이버 공격 유형으로는 소프트웨어(Software) 측면에서 인터넷 내부를 파괴하거나 조정하는 컴퓨터 바이러스(Virus)와 웜(Worms), 트로이 목마(Trojan Horse), 분산서비스 거부공격(Distributed Denial of Service) 등이 있다. 이를 해결하기 위해 다음과 같은 제언을 하고자 한다. 첫째, 북한은 사이버 공격을 위하여 일원화된 조직체계를 갖추고 있으므로, 한국도 효과적인 대처를 위해 일원화된 대응조직체제로 전환할 필요성이 있다. 둘째, 소프트웨어 측면의 공격에 체계적으로 대응하기 위해서는 가칭 『사이버테러리즘방지법』의 제정을 적극 검토하여야 한다.
In modern society, the development of Information and Communication Technology has given people a lot ofopportunities. But on the other side cyber attack also gives enormous damage to people. Recently Korea has becomethe target of cyber attack. The threat of it is growing. Especially North Korea has committed hostile actions againstSouth Korea. North Korea has recently attacked the computer networks of South Korea’s important nationalfacilities. The types of North Korea’s cyber attacks include the followings. First, if we see it with the viewpoint ofsoftware, it tries to destroy or control the Internet, infects the networks with viruses, worms, Trojan Horse andDistributed Denial of Service. I suggest the following to solve the problem. First, South Korea should unify theorganizations to respond to the attacks of North Korea, as North Korea has a unified organization for the cyberattack. Second, they should think about the establishment of 『Cyber Terrorism Prevention Act』to systematicallyrespond to the software attacks.
익명네트워크를 이용한 사이버공격에 대한 대응방안 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제11권 제3호 2011.06 pp.31-37
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 네트워크상에 익명성을 보장하는 Mixed Network에 관한 연구가 활발히 진행되고 있다. 이는 노드간 암호화 통신을 이용하고 통신 경로도 수시로 변경되는 등 공격자에 대한 역추적 및 대응을 어렵게 만든다. 그럼에도 악의적인 형태의 인터넷 사용을 즐기는 사람들에 의해 지속적으로 진화되고 있으며, 새로운 형태의 기술이 지속적으로 개발되고 있는 상황이다. 이러한 상황에 익명네트워크를 이용하여 국가기관 및 기반시설에 대한 사이버공격이 대규모로 이루어진다면 국가차원에서 엄청난 재앙이 아닐 수 없다. 또한 향후에도 이러한 기술을 응용한 공격기법이 지속적으로 출현할 것으로 예상되고 있으나, 이에 대한 마땅한 대비책이 마련되어 있지 않다. 이에 본 논문에서는 다양한 익명네트워크 기술에 대한 분석 및 이를 이용한 사이버 공격에 효율적 대응을 위한 조기탐지 방안 연구를 진행하고자 한다.
Recently on the network to ensure the anonymity of Mixed networking has been actively researched. It uses encrypted communications between Nodes and communications path is changed often to the attacker traceback and response, including the difficult thing is the reality. National institutions and infrastructure in these circumstances, the attack on the national level, if done on a large scale can be disastrous in. However, an anonymous network technology to cover up their own internet communication, a malicious form of Internet use by people who enjoy being continually updated and new forms of technology being developed is a situation continuously. In addition, attacks in the future application of these technologies is expected to continue to emerge. However, this reality does not deserve this thesis is prepared. In this paper, anonymously using a network to respond effectively to a cyber attack on the early detection research is to proceed.
[NRF 연계] 한국통신학회 ICT Express Vol.12 No.2 2026.04 pp.324-329
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Modern network security has a great difficulty in cyber attack detection. In this context, this work presents an CNN-LSTM-GRU Model for cyber attack detection. AEO was used to maximize feature selection for the model, therefore lowering unnecessary data while maintaining important attack patterns. With 98% accuracy, the suggested model beats conventional GRU, LSTM, and RNN architectures according to experimental data. Computationally efficient for the proposed model achieves equivalent accuracy to the Transformer model with less number of FLOPs and parameters.
Adaptive robust FDI attack detection for cyber?physical? systems with disturbance
[NRF 연계] 한국통신학회 ICT Express Vol.9 No.4 2023.08 pp.656-663
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This paper investigates the problem of attack detection for cyber?physical systems (CPSs) with disturbances, measurement noises, and false data injection (FDI) attacks. A classical linear discrete-time system attack model is constructed and a robust attack detector based on the mixed H_/H is designed. Firstly, a system with an actuator that suffered a malicious attack is modeled. Then, a robust attack detector based on the mixed H_/H is designed in which the H_ index and H index are used to characterize the sensitivity to attacks and robustness to disturbances and measurement noises, respectively. And an adaptive detection threshold with a compensation term is proposed. Besides, the designed robust attack detector enables the attack detection dynamic system to be asymptotically stable and to guarantee the H_/H performance, and the robust attack detector gains are solved from a convex optimization. Finally, the obtained theoretical results are validated through a numerical simulation and a three-area power system simulation.
Camp2Vec: Embedding cyber campaign with ATT&CK framework for attack group analysis
[NRF 연계] 한국통신학회 ICT Express Vol.9 No.6 2023.12 pp.1065-1070
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
As the cyberattack subject has expanded from individual to group, attack patterns have become a complicated form of cyber campaigns. Although detecting the attack groups that operated the cyber campaigns is an important issue, complex methods such as deep learning are difficult to use due to the lack of campaign data. This paper proposes Camp2Vec, a lightweight statistics-based embedding for cyber campaigns, enabling attack group detection. The proposed method models a relationship between a campaign and techniques in the ATT&CK® framework as a document and words. Experimental results with expert-labeled datasets prove that Camp2Vec identifies representative attack groups successfully.
행정언어와 질적연구학회 행정언어와 질적연구 제1권 2호 2010.12 pp.37-56
※ 기관로그인 시 무료 이용이 가능합니다.
5,500원
This paper examines methods for protection of government organization’s websites on the focus of 7 7 Cyber Attack in South Korea. On July 7, 2009, twelve websites including the websites of Cheong Wa Dae(the Presidential Office), the National Assembly, the Ministry of National Defense, top internet portals Daum and Naver, and Auction in South Korea and fourteen websites including the websites of the White House and the Department of State in US were attacked by DDoS collectively. The internet sites of South Korea and the abroad important government offices were attacked by DDoS for the first time simultaneously. The affected or zombie computers for themselves could attack the internet sites of important public organizations and agencies. The first attack was that the affected or zombie twenty three thousand PCs in South Korea at 6 p.m. of July 7, 2009 and two thousand PCs abroad helped to attack the websites of important government organizations and agencies. The second attack happened on July 8, 2009. Sixteen thousand zombie PCs were used at the second attack. The third attack was at 6 p.m. of July 9, 2009. Hard diskettes and data in ‘zombie PCs’ which were affected by DDoS were destroyed on July 10, 2009. Zombie PCs with malicious codes exploded for themselves from at least thirty thousand to almost sixty thousand zombie PCs. Methods for protection of government organization’s websites from cyber attacks might be considered as measures for level of citizen, for level of government organization, for state level and for inter‐�state level. Developed countries like US and Japan allocated ten percent of the total budget 10 years ago. South Korea was labeled an internet powerhouse, but Korean government ironically spent only one percent of its entire annual budget on cyber security. Budget for internet security in South Korea should be increased. All owners of virus‐�infected computers should pay immediate attention to cleaning up their operating systems.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.