Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 28
No
1

Artificial Intelligence based Network Intrusion Detection with hyper-parameter optimization tuning on the realistic cyber dataset CSE-CIC-IDS2018 using cloud computing

V. Kanimozhi, T. Prem Jacob

[NRF 연계] 한국통신학회 ICT Express Vol.5 No.3 2019.09 pp.211-214

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

One of the latest emerging technologies is artificial intelligence, which makes the machine mimic human behaviour. The most important component used to detect cyber attacks or malicious activities is the intrusion detection system (IDS). Artificial intelligence plays a vital role in detecting intrusions and widely considered as the better way in adapting and building IDS. In modern days, neural network algorithms are emerging as a new artificial intelligence technique that can be applied to real-time problems. The proposed system is to detect a classification of botnet attack which poses a serious threat to financial sectors and banking services. The proposed system is created by applying artificial intelligence on a realistic cyber defence dataset (CSE-CIC-IDS2018), the latest IDS Dataset in 2018 by Canadian Institute for Cybersecurity (CIC) on AWS (Amazon Web Services). The proposed system of Artificial Neural Networks provides an outstanding performance of Accuracy score is 99.97% and an average area under ROC(Receiver Operator Characteristic) curve is 0.999 and an average False Positive rate is a mere value of 0.03. The proposed system of Artificial Intelligence-based Intrusion detection of botnet attack classification is powerful, more accurate and precise. The novel proposed system can be applied to conventional network traffic analysis, cyber-physical system traffic analysis and also can be applied to the real-time network traffic data analysis.

2

Artificial Intelligence outflanks all other machine learning classifiers in Network Intrusion Detection System on the realistic cyber dataset CSE-CIC-IDS2018 using cloud computing

V. Kanimozhi, T. Prem Jacob

[NRF 연계] 한국통신학회 ICT Express Vol.7 No.3 2021.09 pp.366-370

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Our paramount task is to examine and detect network attacks, is one of the daunting tasks because the variety of attacks are day by day existing in colossal number. The program proposed detects botnet attacks using the newest CSE-CIC-IDS2018 cyber dataset published by the Canadian Cybersecurity Establishment (CIC). The cyber dataset can be accessed on AWS (Amazon Web Services). The realistic network dataset consists of all the modern and existing attacks such as Brute-force attacks and password cracking, Heartbleed, Botnet, DoS (Denial of Service), DDoS also known as Distributed Denial of Service, Web attacks i.e. vulnerable web app attacks, and infiltration of the network from inside. The objective of the proposed research is to identify a classification of Botnet attacks. Botnet attack is a Trojan Horse malware attack that poses a serious security threat to the banking and financial sectors. Since a specific classifier could possibly work for such datasets it is crucial to finish a comparative examination of classifiers in order to achieve the most noteworthy execution in such basic detection of network attacks. The proposed framework is to incorporate different classifier methods such as KNearset Neighbor classifier, Naive Bayes, Adaboost with Decision Tree, Support Vector Machine classifier, Random Forest classifier, and Artificial Intelligence to distinguish a portrayal of botnet attacks on the recent and realistic cyber dataset CSE-CIC-IDS2018. The results of the classification are given as precise precision for the specific classifiers. And furthermore, the proposed framework uses the Calibration curve as a standard approach in analytical methods which generates reliability diagrams to check the predicted probabilities of various classifiers are well-calibrated or not. Finally, the displayed graph proves how well the artificial intelligence technique outperforms all other classifiers which generates reliability diagrams to check the predicted probabilities of various classifiers are well-calibrated or not.

3

4,000원

국가는 전통적으로 국토를 방위하고 국민의 생명과 재산을 보호하는 사명을 가지고 있으며, 이러한 방위의 범위는 지상, 공중, 바다, 우주에 이어 제5의 영역인 사이버 영역을 포함한다. 사이버 영역으로 국가 방위의 범위가 확대 되었지 만, 사이버 영역에 있어서는 국가보다는 민간이 더 많은 사이버 관련 출처와 수집수단을 보유하는 정보역전 현상 때문에 정부 주도의 사이버 영역 방위에 어려움을 겪고 있다. 이를 해결하기 위해, 본 논문에서는 먼저 사이버위협정보를 정의하고 그 특성을 분석하였다. 다음으로 정보역전 현상을 극복하기 위한 각국의 노력과 우리나라의 현 주소를 조사하였고, 그 결과 를 바탕으로 정부 주도의 사이버 방위를 위한 국가정보기관의 역할과 사이버위협정보의 민간 공유 모델을 제안하였다. 제 안된 모델을 국가정보기관에서 활용한다면 사이버위기에 보다 효과적으로 대응할 수 있는 기반 체계가 마련될 것을 기대해 볼 수 있다.

The role of government is to defend its lands and people from enemies. The range of that defense has now extended into the cyber domain, regarded as the fourth domain of the conventional defense domains (i.e., land, sea, sky, and universe). Traditionally, a government’s intelligence power overrides that of its civilians, and government is exclusively responsible for defense. However, it is difficult for government to take the initiative to defend in the cyber domain because civilians already have a greater means for collecting information, which is known as being “intelligence inverse” in the cyber domain. To this end, we first define the intelligence inverse phenomenon and then analyze its main features. Then we investigate foreign countries’ efforts to overcome the phenomenon and look at the current domestic situation. Based on these results, we describe the appropriate role of the National Intelligence Agency to handle cyber threats and offer a cyber threat intelligence model to share with civilians to help protect against these threats. Using the proposed model, we propose that the National Intelligence Agency should establish a base system that will respond to cyber threats more effectively.

4

5,800원

4차 산업혁명 시대를 맞이하면서 ICT의 발전과 함께 지능적이고 고도화된 새로운 공격 이 증가하고 있다. 사이버 위협 인텔리전스 시스템은 사이버 위협에 대한 정보를 수집하고 이를 통해 능동적인 대응을 위한 분석 및 정보 공유를 하는 시스템이다. 사이버 위협 인텔 리전스 공유는 사이버 보안 공격에 대응하는 데 도움이 되는 중요한 자원으로 간주한다. 하지만 프라이버시, 법 정책적 과제 및 공유 비용에 대한 문제들과 같이 효과적인 사이버 위협 인텔리전스 공유를 개선해야 할 많은 과제가 존재한다. 이러한 문제를 해결하기 위해 수해 된 최근 추세 중 하나는 블록체인 기반의 공유 아키텍처를 사용하는 것이다. 하지만 이러한 플랫폼은 공유 효율성을 높이는 데 도움이 될 수 있지만, 위의 모든 문제를 완전히 해결하지는 못한다. 특히 신뢰와 관련된 문제는 현재의 접근 방식으로 만족스럽게 해결되 지 않는다. 이에 본 논문에서는 기존 방식과 다르게 사이버 위협 인텔리전스 공유의 신뢰 문제를 해결하기 위해 블록체인 기술 적용 방안을 연구하였다. 이를 통해 이에 국내 사이 버 위협 인텔리전스의 블록체인 기술 활용 가능성을 확인한다. 특히 새로운 공유 프로세스 를 통해 신뢰성 향상 가능성을 제공하면서 블록체인 기술의 특징을 통해 공유 시스템의 신뢰성 향상을 위한 방향성을 제시하고자 한다.

With the coming of the fourth industrial revolution, new threats using advanced intelligence are increasing due to ICT development. Cyber threat intelligence systems collect, analyze and share the information about cyber threats for an active response. The initial role of cyber threats intelligence systems is to maximize each node's threat response capabilities through information sharing. Because of this approach, the cyber threat intelligence system is considered as a crucial factor for the next-generation security strategy to respond to advanced cyber threats effectively. However, many problems need to be addressed to operate cyber threat intelligence systems effectively. In particular, trust-related issues are not satisfactorily solved by current approaches. Thus, this paper will investigate how to apply blockchain technology to solve cyber threat intelligence sharing's trust problem, unlike conventional methods. Through this approach, it will discuss the possibility of using blockchain technology cyber threat intelligence. In particular, we want to present directions for improving the reliability of shared systems through blockchain technology's characteristics while providing the possibility of enhancing reliability through the new sharing process.

5

공개출처정보를 활용한 사이버위협 평가요소의 중요도 분석 연구 KCI 등재

강성록, 문미남, 신규용, 이종관

한국융합보안학회 융합보안논문지 제20권 제1호 2020.03 pp.49-57

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

우리는 일상생활 가운데 사이버위협에 노출된 채 살아가고 있다. 그럼에도 불구하고 많은 사이버위협 및 공격은 공격자, 공 격목적, 피해규모 등을 명확히 식별하기 어렵고, 단일출처의 정보에 의존하게 되어 객관성 있는 정보를 획득하는 것이 제한된 다. 이에 본 연구의 선행연구[1]에서는 공개출처정보(Open Source Intelligence, OSINT)를 활용한 사이버공격 데이터베이스 (Database, DB)를 구축하기 위한 새로운 방법론을 제시하였다. 본 연구는 사이버 위협을 정량화할 수 있도록 사이버공격 DB 중 사이버 위협 평가요소를 선정하고 그 평가요소에 대한 중요도를 분석하고자 한다. 사이버공격 DB 중 사이버위협의 상대적 중요도에 영향을 미치는 평가요소로 공격목적, 공격범주, 공격대상, 공격 용이성, 공격 지속성, 공개출처정보의 빈도를 선별하고, 각 평가요소들에 대한 하위 계층의 요소들을 선정한 후 각 요소들의 중요도를 계층분석적 의사결정방법(Analytic Hierarchy Process, AHP)을 활용하여 분석하였다.

It is no exaggeration to say that we live with cyber threats every day. Nevertheless, it is difficult for us to obtain objective information about cyber threats and attacks because it is difficult to clearly identify the attacker, the purpose of attack, and the range of damage, and rely on information from a single source. In the preceding research of this study, we proposed the new approach for establishing Database (DB) for cyber attacks using Open Source Intelligence(OSINT). In this research, we present the evaluation factors for cyber threats among cyber attack DB and analyze the priority of those factors in oder to quantify cyber threats. We select the purpose of attack, attack category, target, ease of attack, attack persistence, frequency of OSINT DB, and factors of the lower layer for each factor as the evaluation factors for cyber threats. After selection, the priority of each factor is analyzed using the Analytic Hierarchy Process(AHP).

6

7,800원

2001년 9/11 테러공격 이후에 미국은 사이버 안보를 가장 위중한 국가안보 문제로 인식한다. 미국 국방부는 2013년 처음으로 사이버 전쟁이 물리적인 테러보다 더 큰 국가안보위협임을 확인했다. 단적으로 윌리암 린(William J. Lynn) 국방부 차관의 지적처럼 오늘날사이버 공간은 육지, 바다, 하늘, 우주 다음의 ‘제5의 전장(the fifth domain of warfare)’이라고 함에 의문이 없다. 인터넷의 활용과 급속한 보급은 사이버 공간에서 의 상상하지 못했던역기능을 창출한 것이다. 이에 사이버 정보와 사이버 네트워크 보호까지를 포괄하지 않으면 국가안보 수호의 목표를 달성할 수 없게 되 었다. 그런데 이러한 위험성에도 불구하고 각국은 운영상의 효율성과 편리성, 국제교류 등 외부세계와의 교류 확대를 위해 국가기간망의 네트워크화를 더욱확대해 가고 있고 인터넷에의 의존도는 심화되고 있다. 하지만 그 실천적인 위험성에도불구하고 우리의 법제도적 장치와 사이버 안전에 대한 인식수준은 현실을 제대로 반 영하지 못하고 있는 것으로 판단된다. 오늘날 가장 실천적이고 현실적인 위협을 제기하는 사이버 안보의 핵심은 하나도 둘도계획의 구체성과 실천 력의 배양이다. 대책회의나 교육 등은 부차적이다. 실전적인 사이버사령부와 사이버 정보기구 그리고 사이버 전사의 창설과 육성에 더 커다란 노력을 경주해야 하고, 우리의 경우에는 가장 많은 경험을 가지고 인력과 장 비를 가진 국가정보원의 사이버 수호 역량을 고양하고 더 많은 책무를 부담시키고 합리적인 업무 감독을 다하 는 것에있다고 할 것이다. 이에 본고는 법규범적으로 치안질서와 별개 개념으로서의 국가안보에 대한 무한책임기구인 국가정보기구의 사이버 안보에 대한 책무와 그에 더하여 필요한 사이버 정보활동과유관활동의 범위를 검토하고자 한다. 사이 버 테러와 사이버 공격을 포괄한 사이버 공격(Cyber Attack)에 대한 이해와 전자기장을 물리적으로 장악하는 전자전에 대한 연구도 포함한다.

Cyber-based technologies are now ubiquitous around the glob and are emerging as an"instrument of power" in societies, and are becoming more available to a country'sopponents, who may use it to attack, degrade, and disrupt communications and the flowof information. The globe-spanning range of cyberspace and no national borders willchallenge legal systems and complicate a nation's ability to deter threats and respond tocontingencies. Through cyberspace, competitive powers will target industry, academia,government, as well as the military in the air, land, maritime, and space domains of ournations. Enemies in cyberspace will include both states and non-states and will range fromthe unsophisticated amateur to highly trained professional hackers. In much the same waythat airpower transformed the battlefield of World War II, cyberspace has fractured thephysical barriers that shield a nation from attacks on its commerce and communication. Cyberthreats to the infrastructure and other assets are a growing concern to policymakers. In 2013 Cyberwarfare was, for the first time, considered a larger threat than Al Qaedaor terrorism, by many U.S. intelligence officials. The new United States military strategymakes explicit that a cyberattack is casus belli just as a traditional act of war. The Economistdescribes cyberspace as "the fifth domain of warfare and writes that China, Russia, Israeland North Korea. Iran are boasting of having the world's second- largest cyber-army. Entitiesposing a significant threat to the cybersecurity of critical infrastructure assets includecyberterrorists, cyberspies, cyberthieves, cyberwarriors, and cyberhacktivists. These malefactors may access cyber-based technologies in order to deny service, steal ormanipulate data, or use a device to launch an attack against itself or another piece ofequipment. However because the Internet offers near-total anonymity, it is difficult to discern the identity, the motives, and the location of an intruder. The scope and enormity of thethreats are not just focused to private industry but also to the country’s heavily networkedcritical infrastructure. There are many ongoing efforts in government and industry that focus on makingcomputers, the Internet, and related technologies more secure. As the national intelligenceinstitution's effort, cyber counter- intelligence is measures to identify, penetrate, or neutralizeforeign operations that use cyber means as the primary tradecraft methodology, as well asforeign intelligence service collection efforts that use traditional methods to gauge cybercapabilities and intentions. However one of the hardest issues in cyber counterintelligenceis the problem of "Attribution". Unlike conventional warfare, figuring out who is behindan attack can be very difficult, even though the Defense Secretary Leon Panetta has claimedthat the United States has the capability to trace attacks back to their sources and hold theattackers "accountable". Considering all these cyber security problems, this paper examines closely cyber securityissues through the lessons from that of U.S experience. For that purpose I review the arisingcyber security issues considering changing global security environments in the 21st centuryand their implications to the reshaping the government system. For that purpose this study mainly deals with and emphasis the cyber security issues asone of the growing national security threats. This article also reviews what our intelligenceand security Agencies should do among the transforming cyber space. At any rate, despiteof all hot debates about the various legality and human rights issues derived from the cyberspace and intelligence service activity, the national security should be secured. Therefore, thispaper suggests that one of the most important and immediate step is to understanding thelegal ideology of national security and national intelligence.

7

정보기관 다원화를 통한 사이버안보법 제정 방안 KCI 등재

정태진, 이광민

한국경찰연구학회 한국경찰연구 제19권 제4호 2020.12 pp.167-182

※ 기관로그인 시 무료 이용이 가능합니다.

4,900원

오래동안 논의된 사이버안보 관련 법안은 국내 정치 상황과 왜곡된 정보 등의 이유 로 국회를 통과하지 못하고 있다. 오늘날의 사이버안보는 전세계 강대국 및 모든 국가 가 우리에게 잠재적으로 위협을 줄 수 있으며 사이버공격은 국가의 근간을 흔들 수 있 을 정도의 피해를 줄 수 있다. 따라서 사이버안보 의식 변화와 법률적인 지원이 절실히 필요하다. 사이버안보 입법을 위해서는 사이버안보를 좀 더 큰 틀에서 국내보다는 국제 적인 차원에서 고찰하고 필요한 법률안을 제시해야 할 것이다. 특히, 국가사이버안전업 무를 ‘민간사찰과 정보감시’라고 오해하는 시선을 완화하기 위해서 미국CIA나 영국 MI6 같이 휴민트업무를 하는 정보기관 역할과 미국 NSA, CISA나 영국 GCHQ 같이 ‘신호감청 및 사이버공간 감시’하는 역할을 하는 언택트 정보기관으로 분리하여 운영한 다면 사이버안보법 제정에 큰 반대가 없을 것으로 본다. 지난 10여년간 국가사이버안전 센터의 위상과 역할 그리고 규모가 지속적으로 발전하는 걸 보면 , 국가사이버안전센터 의 분리는 피할 수 없는 미래 정보기관 조직 개편안이라 볼 수 있다. 그러므로, 국가사 이버안전센터를 국가정보원으로부터 분리하여 독립적인 ‘사이버안보전문’ 정보기관으 로 만들어서 사이버안보법 제정의 물고를 터는 하나의 방안이다.

For the last fifteen years, National Cyber Security Act has not been able to pass the high threshold of the national congress due to the issue of surveillance of private sector and intelligence watch. Since most serious cyber attack have been occurred in the private sector, it is imperative to defend the private sector of cyberspace by the most effective measures and agencies. Corporate interest is not less important than national interest in terms of tax burden and national economy. The enactment of the National Cyber Security Act can allow the NCSC to monitor the both public and private sector of cyberspace. Cyber attack is considered as the most serious asymmetric force and most cyber attacks and clandestine operation is supported by the state actors. Korea has to enhance the overall national cyber response capability through the restructuring intelligence agencies. NCSC(National Cyber Security Center) has been operated by the NIS (National Intelligence Service). In order to enhance the national cyber security, Korea government has to consider the establishment of the independent intelligence agency for the national cyber security such as NSA or GCHQ. It is not only for the enactment of the National Cyber Security Act but also for the division of labor of the intelligence agency. The separation between HUMINT and Untact (SIGINT & Cybersecurity) operation of NIS can be a future-oriented and mutually beneficial decision for the Nation Security.

8

공개출처정보의 정량화를 이용한 인공신경망 기반 사이버위협 예측 모델 KCI 등재

이종관, 문미남, 신규용, 강성록

한국융합보안학회 융합보안논문지 제20권 제3호 2020.09 pp.115-123

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

사이버공격은 최근 몇 년간 더욱 더 진화하고 있다. 이렇게 고도화, 정교화된 사이버위협에 대응하기 위한 최선의 대책 중 하나는 사이버 공격을 사전에 예측하는 것이다. 사이버위협을 예측하기 위해서는 많은 정보와 노력이 요구되며 최근 정보획득 의 핵심인 공개출처정보(Open Source Intelligence, OSINT)를 활용한다면 사이버위협을 보다 정확히 예측할 수 있을 것이다. 공개출처정보를 활용하여 사이버위협을 예측하기 위해서는 공개출처정보로부터 사이버위협 데이터베이스의 구축과 구축된 DB 에서 사이버위협을 평가할 수 있는 요소를 선정하는 것이 선행되어야 한다. 이를 위해 데이터마이닝 기법을 활용하여 DB를 구 축하고, 축적된 DB 요소 중 핵심요소에 대한 중요도를 AHP 기법으로 분석한 선행연구를 기초로 하였다. 본 연구에서는 공개 출처정보로부터 축적된 사이버공격 DB를 활용하여 사이버위협을 정량화할 수 있는 방안을 제시하고 인공신경망을 기반으로 한 사이버위협 예측 모델을 제안한다.

Cyber Attack have evolved more and more in recent years. One of the best countermeasure to counter this advanced and sophisticated cyber threat is to predict cyber attacks in advance. It requires a lot of information and effort to predict cyber threats. If we use Open Source Intelligence(OSINT), the core of recent information acquisition, we can predict cyber threats more accurately. In order to predict cyber threats using OSINT, it is necessary to establish a Database(DB) for cyber attacks from OSINT and to select factors that can evaluate cyber threats from the established DB. We are based on previous researches that built a cyber attack DB using data mining and analyzed the importance of core factors among accumulated DG factors by AHP technique. In this research, we present a method for quantifying cyber threats and propose a cyber threats prediction model based on artificial neural networks.

9

공개출처정보를 활용한 사이버공격 데이터베이스 구축방안 연구 KCI 등재

신규용, 유진철, 한창희, 김경민, 강성록, 문미남, 이종관

한국융합보안학회 융합보안논문지 제19권 제2호 2019.06 pp.113-121

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷과 정보통신기술의 발달로 매일 대량의 공개출처정보(Open Source Intelligence, OSINT)가 발생하고 있다. 최근에는 전체 정보의 95%가 공개출처정보에서 나온다고 할 정도로 공개출처의 활용도가 높아졌다. 이러한 공개출처정보는 잘 정제되어 활용된다면 매우 효과적인 고가치 정보로 활용될 수 있다. 일례로 ISVG나 START 프로그램은 테러나 범죄와 관련된 공개출처 정보를 수집해 테러리스트 색출이나 범죄예방에 활용해 많은 효과를 거두고 있다. 하지만 사이버공격과 관련된 공개출처정보는 기존의 테러나 범죄와 관련된 공개출처정보와는 달리 공격자, 공격목적, 피해범위 등을 명확히 식별하기 어렵고, 자료 자체가 상대적으로 정형화되지 않았다는 특징이 있다. 이러한 이유 때문에 공개출처정보를 활용해 사이버공격에 대한 데이터베이스 (Database, DB)를 구축하고 활용하기 위해서는 기존의 방식과는 전혀 다른 새로운 접근방식이 요구된다. 따라서 본 논문에서는 공개출처정보를 활용해 사이버공격 데이터베이스를 구축하는 방법론을 제시하고 향후 활용방안에 대해 토의하고자 한다.

With the development of the Internet and Information Communication Technology, there has been an increase in the amount of Open Source Intelligence(OSINT). OSINT can be highly effective, if well refined and utilized. Recently, it has been assumed that almost 95% of all information comes from public sources and the utilization of open sources has sharply increased. The ISVG and START programs, for example, collect information about open sources related to terrorism or crime, effectively used to detect terrorists and prevent crime. The open source information related to the cyber attacks is, however, quite different from that in terrorism (or crime) in that it is difficult to clearly identify the attacker, the purpose of attack, and the range of damage. In addition, the data itself of cyber attacks is relatively unstructured. So, a totally new approach is required to establish and utilize an OSINT database for cyber attacks, which is proposed in this paper.

10

Roles and Responsibilities of Cyber Intelligence for Cyber Operations in Cyberspace SCOPUS

Jung ho Eom

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.5 2014.09 pp.323-332

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we proposed roles and responsibilities of cyber intelligence in cyber operations. In particular, we focused on the roles and responsibilities of cyber intelligence on each phase of cyber operations. Cyber operations are activities related to defense, assurance, and attack to achieve objectives in or through cyberspace. While cyber operation is conducting, cyber intelligence must properly support cyber commander and units for ensuring cyberspace intelligence superiority. Cyber intelligence is a cyber-discipline that exploits a number of information collection and analysis approaches to provide direction and decision to cyber commander and cyber operation units. This is a key role in both cyber-attack and cyber defense. We know that the branch of information and communications conducts cyber operations in cyberspace. But we don’t know well that the cyber intelligence is more in charge of the policy, strategic, and tactics in cyber operations. It is collected information requested from cyber command and units, and is disseminated information to department related to cyber operations. The cyber intelligence is a key factor in cyber operation cycle.

11

Roles and Responsibilities of Cyber Intelligence for Cyber Operations in Cyberspace SCOPUS

Jung ho Eom

보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.8 No.9 2014.09 pp.137-146

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we proposed roles and responsibilities of cyber intelligence in cyber operations. In particular, we focused on the roles and responsibilities of cyber intelligence on each phase of cyber operations. Cyber operations are activities related to defense, assurance, and attack to achieve objectives in or through cyberspace. While cyber operation is conducting, cyber intelligence must properly support cyber commander and units for ensuring cyberspace intelligence superiority. Cyber intelligence is a cyber-discipline that exploits a number of information collection and analysis approaches to provide direction and decision to cyber commander and cyber operation units. This is a key role in both cyber-attack and cyber defense. We know that the branch of information and communications conducts cyber operations in cyberspace. But we don’t know well that the cyber intelligence is more in charge of the policy, strategic, and tactics in cyber operations. It is collected information requested from cyber command and units, and is disseminated information to department related to cyber operations. The cyber intelligence is a key factor in cyber operation cycle.

12

사이버공간에서 효율적인 정보 활용을 위한 사이버 정보순환 및 융합체계 제안 KCI 등재

엄정호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.11 No.4 2014.08 pp.313-324

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 논문에서는 사이버공간에서 수집한 데이터를 효율적으로 사용하기 위한 사이버 정보순환체계와 정보융합체계를 제안하였다. 현재까지 사이버 위협에 대한 상황 대응 분야는 지속적으로 발전하고 있 으나 수집한 정보를 효율적으로 활용하는 정보기능은 사후 인식 수준에 머물고 있다. 그래서 효율적 인 정보수집을 위해서 정보 수집단계부터 공고 및 표준화하는 정보순환체계를 제안하였다. 아울러 사 이버공간에서 수집한 방대한 데이터를 가치 있는 데이터들만 추출하고 연관성을 분석하여 위협을 예 측하고 대응할 수 있는 정보융합체계도 제안하였다. 정보융합체계는 JDL 모델을 활용하였다.

In this paper, we proposed cyber intelligence cycle and fusion system to efficiently apply collected data in the cyberspace. Until now, situation reaction and operations related to cyber threats are constantly evolving, but intelligence functions for effective application of information don't develop as cyber operational field. So, we proposed cyber intelligence cycle system from information collection to announcement & standardization for efficient information collection. We also derived intelligence fusion system that it can filter only valuable data and respond threat as analyzing the correlation between data. Intelligence fusion system is based on JDL(Joint Directors of Laboratories) model.

13

Business Process Reengineering of an Information Exchange Management System for a Nationwide Cyber Threat Intelligence

Pramadi, Yogha Restu, Rosmansyah, Yousep, Kim, Myonghee, Park, Man-Gon

[Kisti 연계] 한국멀티미디어학회 멀티미디어학회논문지 Vol.20 No.2 2017 pp.279-288

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Nowadays, nations cyber security capabilities play an important role in a nation's defense. Security-critical infrastructures such as national defenses, public services, and financial services are now exposed to Advanced Persistent Threats (APT) and their resistance to such attacks effects the nations stability. Currently Cyber Threat Intelligence (CTI) is widely used by organizations to mitigate and deter APT for its ability to proactively protect their assets by using evidence-based knowledge. The evidence-based knowledge information can be exchanged among organizations and used by the receiving party to strengthen their cyber security management. This paper will discuss on the business process reengineering of the CTI information exchange management for a nationwide scaled control and governance by the government to better protect their national information security assets.

14

Is Artificial Intelligence(AI) Lecturer Acceptable for Adult Learners in Distance Education?: An Exploratory Study on a Cyber University, South Korea

정용균, 김중렬

[NRF 연계] 한국인터넷전자상거래학회 인터넷전자상거래연구 Vol.20 No.2 2020.04 pp.65-81

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Nowadays, artificial intelligence emerges as one of the powerful tools to deliver personalized educational services to college students in distance education. The purpose of this study is to examine adult learner's user acceptance of artificial intelligence lecturer in distance education. For this purpose, we utilize in-depth interview method as well as questionnaire method for data collection from a distance education university in South Korea. Our findings show that adult learners are reluctant to accept artificial intelligence(AI) as a lecturer in distance education. For example, a respondent expresses her opinion that human being must play the role of managing director of her course, if is inevitable to deploy artificial intelligence as a lecturer in distance education. For the choice among robot-type avatar and human-type avatar as the form of AI lecturer, most of students chose human-type avatar, instead of robot-type avatar as lecturer. Furthermore, adult learners do not agree to a view that AI lecturer may lessen the loneliness. Because they thought that loneliness is originated from the innate structure of distance education. On the other hand, however, non-negligible number of respondents participated in interview show that it is possible for them to build empathic relationship with AI lecturer.

15

사이버작전 상황도 구현을 위한 사이버 전장정보분석과 다영역 기동에 관한 연구

이민우, 이종관, 임남규, 김종화, 권구형, 오행록

[NRF 연계] 육군사관학교 화랑대연구소 한국군사학논집 Vol.77 No.2 2021.06 pp.434-463

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버 공간은 제5전장으로서 군사작전의 새로운 작전 영역으로 여겨지고 있다. 우리가 사이버 공간을 전쟁터로 이해할 때, 다중 영역에서 그리고 다중 영역을 통한 기동에 사이버 공간을 사용할 수 있다. 따라서 사이버 공간을 전장으로 분석하는 과정이 있어야 전장 상황을 이해하고 방책을 수립할 수 있다. 본 논문에서는 사이버 전장에 대한 사이버 전장정보분석(C-IPB), 다영역 기동(MDM)을 연구하였다. MDM 개념을 평가하기 위해 IT(정보 기술) 및 OT(운영 기술)와 관련된 Purdue Model을 살펴보았다. Industrier 사례를 참고하여 그 개념을 설명하였다. 또한, MITRE ATT&CK for ICS를 이용하여 MDM을 설명할 수 있음을 보였다. 마지막으로, MDM 개념의 구현 방법을 보이기 위해 가상의 잠수함 시나리오를 살펴보았다.

Cyberspace is considered a newly discovered domain of military operations, which is called the fifth battlefield. It is possible for us that we may maneuver in and through multi-domain via cyberspace when we fully understand cyberspace as a battlefield. Therefore, a process for analysis of cyberspace as a battlefield is needed to understand the situation and make a course of action. This paper studied the Cyber-Intelligence Preparation for Battlefield(C-IPB), Multi-Domain Maneuver(MDM). The Purdue Model concerning IT (Information Technology) and OT (Operational Technology) was considered to evaluate the MDM concept. The Industroyer was also referred to explain the concept. In addition, we showed that the MITRE ATT&CK for ICS can be used to describe the MDM. Finally, an imaginary submarine scenario was reviewed to show how the concept might be implemented.

16

사이버위협 인텔리전스 기반SIEM-포렌식 융합 모델 체계 연구

우건호, 박지후(동국대학교 국제정보보호대학원 정보보호학과, 이동건, 황진석

[NRF 연계] 한국IT정책경영학회 한국IT정책경영학회 논문지 Vol.18 No.1 2026.03 pp.4275-4283

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 연구는 증가하는 지능형 사이버 공격에 효과적으로 대응하기 위해, 위협 인텔리전스와 보안 로그, 포렌식 분석을 통합하는 분석 모델을 제안한다. 기존 보안관제 환경에서는 탐지와 분석 체계가 분리되어 운영됨에 따라 위협 정보가 실시간 탐지 과정에 충분히 반영되지 못하는 한계가 존재한다. 이를 개선하기 위해 외부 위협 인텔리전스에서 수집한 침해지표를 자동으로 정규화하고 SIEM 환경과 연계하여 로그 기반 탐지에 활용하는 구조를 설계하였다. 제안 모델은 신뢰도 기반 위험도 평가를 통해 경보의 우선순위를 판단하며 탐지 결과가 포렌식 분석으로 연속적으로 확장될 수 있도록 분석 흐름을 통합한다. 실험 결과 본 모델은 기존 수작업 분석 대비 탐지 및 분석 효율성을 향상시키고 보안 인력의 업무 부담을 완화하는 효과를 보였다.

To address the growing sophistication of cyber attacks, this study presents an integrated analytical model that unifies threat intelligence, security log analysis, and digital forensics. In many existing security monitoring environments, detection and analysis functions are operated independently, limiting the effective use of threat intelligence in real-time detection processes. To overcome this limitation, the proposed model automatically normalizes indicators of compromise collected from external threat intelligence sources and incorporates them into a SIEM-based log analysis framework. Threats are evaluated using a reliability-oriented risk scoring mechanism, enabling prioritized alert generation and improved decision-making. In addition, the analytical workflow is designed to allow detected security events to be seamlessly extended into forensic investigation. Experimental results indicate that the proposed approach enhances detection and analysis efficiency while reducing the operational burden on security personnel.

17

OSINT와 기업 내 사이버 위협 인텔리전스를 통한 효과적인 위험 대응 기법

문광석, 허준범

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.34 No.5 2024 pp.949-959

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 기업들이 클라우드와 인공지능을 활용하면서 기존의 경계선 보안 방식으로는 노출된 인터페이스를 보호하기가 점점 어려워지고 있다. 이에 따라 제로 트러스트 기반의 전방위적인 위험 관리가 필요해지고 있다. 대부분의 기업은 기본적인 위험 관리 방식으로 취약점 점검과 버그 바운티(보안 취약점 신고제)를 사용하고 있지만, 이러한 방식만으로는 제로데이 공격이나 오픈소스 취약점과 같은 예측하기 어려운 문제점에 효과적으로 대응하기 어렵다. 따라서 본 논문에서는 CTI(사이버 위협 인텔리전스)를 통해 위협을 탐지하기 위해 외부 OSINT(공개 소스 정보)와 국가 정부 기관의 CTI를 연동하고, 기업 자체의 CTI를 수집하여 위협 탐지 체계를 구축하는 기업 전반에 걸친 위험 대응 기법을 제안한다. 효과적인 위협 탐지를 위해 허니팟을 구성하여 기업 자체의 CTI를 수집하고 이를 외부 정부 기관의 CTI와 연동한 위협 탐지 및 차단 방식과 비교한 결과, 제안 기법이 탐지 정확도 측면에서 65.8% 더 높은 성능 향상을 보였으며, 해당 방식을 통해 기관의 공격자가 감소한 효과를 검증하였다.

Recently, as enterprises utilize the cloud and artificial intelligence, it is becoming increasingly difficult to protect exposed interfaces with existing perimeter security methods. Accordingly, zero trust-based comprehensive risk management is becoming necessary. Most enterprises use vulnerability inspection and bug bounty (security vulnerability reporting system) as basic risk management methods, but it is difficult to effectively respond to unpredictable problems such as zero-day attacks or open source vulnerabilities with these methods alone. Therefore, in this paper, we propose a risk response technique for the entire enterprise that links external OSINT (open source information) and CTI of national government agencies to detect threats through CTI (cyber threat intelligence) and collects the enterprise's own CTI. As a result of comparing the method of threat detection and blocking that collects the enterprise's own CTI by configuring a honeypot for effective threat detection and links it to the CTI of an external government agency, the proposed technique showed a 65.8% higher performance improvement in detection accuracy and verified the effect of reducing the number of attackers in the organization through this method

18

LLM 기반 CTI 자동 분석 평가 프레임워크 제안

유진호, 조효진

[NRF 연계] 서울사이버대학교 미래사회전략연구소 미래사회 Vol.17 No.1 2026.02 pp.176-193

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 개인정보 유출과 랜섬웨어 등 사이버 위협이 증가함에 따라 Cyber Threat Intelligence (CTI) 분석의 중요성이 커지고 있다. 그러나 CTI 보고서는 비정형 자연어로 작성되어 수동분석에 한계가 있으며, 이를 해결하기 위해 대규모 언어 모델(LLM)을 활용한 자동 분석 연구가 활발히 진행되고 있다. 본 연구는 2023∼2025년 발표된 주요 연구를 분석하여, 기술 흐름이 단순 객체 추출에서 지식 구조화 및 운영 산출물 생성으로 확장되고 있음을 확인하였다. 하지만 기존 연구들은 서로 다른 데이터셋과 평가 지표를 사용해 정량적 비교가 어렵고, 환각문제와 근거 추적성 부족으로 실무 적용에 제약이 있다. 이에 본 논문은 LLM 기반 CTI 분석기술을 객관적으로 평가하기 위한 CTI 자동 분석 평가 프레임워크를 제안한다. 제안 프레임워크는 단계별 태스크 번들, 산출물 표준화, 근거 추적성 평가, 운영 효율성 지표, 그리고 다양성을 고려한 데이터셋 구축 원칙을 포함하며, 이를 통해 신뢰할 수 있는 자동 위협 분석 기술의 발전에 기여하고자 한다.

The recent growth in data breaches and ransomware has increased the need for effective cyber threat intelligence (CTI) analysis. However, most CTI reports are unstructured, rendering manual analysis inefficient. Consequently, recent studies have employed large language models (LLMs) to automate CTI analysis. This paper reviews representative works published between 2023 and 2025, highlighting a shift from basic entity extraction to knowledge structuring and the generation of operational outputs, such as detection rules. Despite this progress, inconsistent datasets, evaluation methods, and hallucinations have limited fair comparisons and real-world use. Consequently, we propose a CTI automated analysis evaluation framework for LLM-based CTI analysis that includes task bundles, standardized outputs, evidence-based evaluation, operational efficiency metrics, and guidelines for diverse dataset construction. This framework supports reliable comparison and practical deployment of automated threat analysis.

19

사이버위협정보 수집ㆍ공유 관련 법제도적 쟁점과 개선방안 ―민간부문을 중심으로―

이원상

[NRF 연계] 안암법학회 안암법학 Vol.65 2022.11 pp.231-262

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

과거에는 물리적인 전쟁이 한 국가를 위협하는 가장 큰 인적 재난이라고 할 수 있었다. 한국은 이미 한국전쟁을 통해 그 무시무시함을 경험하였다. 하지만 지금은 물리적인 전쟁만큼이나 무서운 인적 재난이 사이버위협이라고 할 수 있다. 사이버위협은 한 국가를 정보화 시대에서 한 순간에 산업시대 이전으로 회귀시킬 수도 있다. 사이버위협이 단순히 삶의 불편함을 초래하는 것이 아니라 일상생활을 초토화 시킬 수 있게 된 것이다. 그러므로 사이버위협에 대한 신속한 대응은 국가의 존립을 위한 필수사항이라고 할 수 있다. 그런데 사이버위협에 신속하게 대응하기 위해서는 법제도의 지원이 요구된다. 그래서 본 연구에서는 민간부문의 사이버위협정보 수집․공유를 활성화 하기 위한 법제도적 개선방안을 모색해 보았다. 결과적으로 사이버보안 법체계는 전문법 영역에 속한다. 그래서 다른 전문법 영역과의 충돌도 있을 수 있으며. 내부적으로는 계속해서 하위 전문법으로 분화되는 과정이 있게 될 것이다. 그러므로 사이버보안 법체계가 다른 전문법 영역과 충돌을 피하고, 내부적으로 정합적인 법체계를 구축하도록 법제도를 개선해야 한다. 그를 위해 첫째로, 현재 공공부문과 민간부문으로 구분되어 있는 법체계를 하나의 단일한 법체계로 통합할 필요성이 있으며, 사이버보안 기본법을 제정하여 법제도를 체계화 시킬 필요성이 있다. 둘째로, 그와 같은 작업에는 많은 시간과 노력이 필요하기 때문에, 그 이전까지는 여러 전문법 영역이 충돌하지 않을 수 있도록 포트를 만들어 둘 필요성이 있다. 그와 같은 작업이 체계적으로 이루어 질 수 있도록 독일의 조항법률 체계를 통해 법률 개정작업을 하는 것을 고려해 볼 필요성이 있다. 그리고 셋째로, 사이버위협정보 수집․공유에 대한 법제도는 대부분 제재를 통해 그 목적을 이루고자 한다. 하지만 제재는 형식적인 수집․공유는 가능할 수 있지만, 실질화 하기에는 한계가 있다. 그러므로 민간부문에서 실질적으로 사이버위협정보의 수집․공유가 원할히 이루어지기 위해서는 인센티브 제도를 적극 활용할 필요성이 있다. 대표적인 것이 ‘책임 경감 및 책임 한정, 법적 베네핏’을 제공할 수 있는 장치를 법제도에 포함하는 것이다. 물론 현재도 그와 같은 것이 일부 마련되어 있지만, 민간부문의 사이버위협정보 수집․공유의 적극성을 이끌어 낼 수 있는 인센티브를 지속적으로 마련할 필요성이 있다. 그리고 넷째로, 형법 체계에 부합하는 형사처벌에 대한 정비가 요구된다. 그를 통해 사이버보안 법체계가 형법 체계와의 정합성을 유지할 수 있도록 할 필요성이 있다.

In the past, war was the biggest disaster that threatened a country. Korea has already experienced the horrors of war due to the Korean War. But now, a disaster as scary as a physical war is a cyber threat. Cyber threats can bring a country back from the information age to the pre-industrial age at a moment's In other words, cyber threats are not just causing inconvenience in life, but can devastate all of our daily lives. Therefore, it can be said that responding quickly to cyber threats is essential for the existence of the country. However, in order to respond quickly to cyber threats, above all, support from the legal system is required. Therefore, this study sought how to improve the legal system to activate the collection and sharing of cyber threat information in the private sector. As a result, cyber security legal system is specialized law within the realm. Therefore, collisions with other specialized law regions may occur, and internally, a process of differentiating into sub-specialized law continues to occur. Therefore, the legal system should be improved so that cyber security laws avoid conflicts with other specialized law areas and establish an internally consistent legal system. For that, first, the legal system currently divided into the public and private sectors should be integrated into a single legal system. In addition, there is a need to systematize the legal system by enacting the Framework Act on Cyber Security. Secondly, such work requires a lot of time and effort. Therefore, before that, it is necessary to create a connection point so that several specialized law regions do not collide with each other. In order for such work to be carried out systematically, it should be considered to revise the law through Germany's "Artikelgesetz" system. And thirdly, most of the laws on collecting and sharing cyber threat information aim to achieve their purpose through sanctions. However, sanctions can allow information to be collected and shared formally, but there is a limit to actually collecting and sharing information. Therefore, it is necessary to actively utilize the incentive system in order to enable the private sector to collect and share cyber threat information. Of course, there are still some incentive systems in place, but there is a need to improve the incentive system in order to actively collect and share cyber threat information in the private sector. Fourth, it is required to revise the punishment regulations so that criminal punishment in accordance with the ideology of the criminal law is carried out. Through this, the cyber security legal system will be able to maintain consistency with the criminal law system.

20

사이버 위협정보를 활용한 위협분석 능력 향상방안 연구

신기호

[NRF 연계] 육군사관학교 화랑대연구소 한국군사학논집 Vol.77 No.3 2021.10 pp.507-535

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

국방 사이버공간에서 적은 단순한 공격이 아닌 다양한 형태로 사이버위협과 공격을 감행하고 있다. 또한, 사이버작전의 선두주자인 미국 사이버사령부도 기존 수세적이고 피동적인 방어작전의 형태에서 ‘Persistent Engagement’ 개념을 적용하여 공세적이고 능동적인 방어작전을 시행하고 있다. 우리도 이를 적극 벤치마킹하여 우리군의 사이버작전에 적용할 필요가 있다. 공세적이고 능동적인 사이버 방어작전을 위해서는 적의 TTPs 등 사이버 위협정보를 선제적으로 수집하여 분석한 후 대응할 수 있는 역량을 조기에 갖추는 것이 무엇보다 필요하고 중요하다. 본 연구에서는 ‘OODA Loop’ 개념을 적용한 위협분석 수행방안과 사이버 위협정보(TTPs 등)를 기반으로 ‘MITRE ATT&CK 프레임워크’를 활용한 사이버 위협분석 수행방안을 알아본다. 이를 위해 'OODA Loop'의 기본 개념과 군 적용사례, 'MITRE ATT&CK Framework'의 개념 및 실 적용 사례 등 기본적인 이론적 배경 지식과 실 적용 사례를 먼저 살펴본 후, 한국군에 대한 적용 방안을 제시한다.

In national defense cyberspace, the enemy is conducting Cyber threats and attacks in various forms, not simply attacks. The US Cyber Command, a leader in World Cyber operations, is implementing offensive and active defensive operations by applying the concept of ‘Persistent Engagement’ to the existing defensive and passive defensive operations. We also need to actively introduce this and apply it to our military's cyber operations. For offensive and active Cyber defense operations, it is necessary and important to preemptively collect and analyze Cyber Threat Intelligence such as TTPs, and then acquire the capability to respond early. In this study, we will find out the threat analysis execution method applying the concept of 'OODA Loop' and the Cyber Threat analysis execution method using the MITER ATT&CK framework based on Cyber Threat Intelligence (TTPs, etc.). To this end, basic theoretical background knowledge such as the basic concept of 'OODA Loop' and military application cases, the concept of 'MITER ATT&CK Framework' and practical application cases will be first reviewed, and then the application plan for the Korean military will be presented.

 
1 2
페이지 저장