년 - 년
기업 내 생성형 AI 시스템의 보안 위협과 대응 방안 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제2호 2024.06 pp.9-17
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문은 기업 내 생성형 AI(Generative Artificial Intelligence) 시스템의 보안 위협과 대응 방안을 제시한다. AI 시스템이 방대한 데이터를 다루면서 기업의 핵심 경쟁력을 확보하는 한편, AI 시스템을 표적으로 하는 보안 위협에 대 비해야 한다. AI 보안 위협은 기존 사람을 타겟으로 하는 사이버 보안 위협과 차별화된 특징을 가지므로, AI에 특화된 대응 체계 구축이 시급하다. 본 연구는 AI 시스템 보안의 중요성과 주요 위협 요인을 분석하고, 기술적/관리적 대응 방 안을 제시한다. 먼저 AI 시스템이 구동되는 IT 인프라 보안을 강화하고, AI 모델 자체의 견고성을 높이기 위해 적대적 학습 (adversarial learning), 모델 경량화(model quantization) 등 방어 기술을 활용할 것을 제안한다. 아울러 내부자 위 협을 감지하기 위해, AI 질의응답 과정에서 발생하는 이상 징후를 탐지할 수 있는 AI 보안 체계 설계 방안을 제시한다. 또한 사이버 킬 체인 개념을 도입하여 AI 모델 유출을 방지하기 위한 변경 통제와 감사 체계 확립을 강조한다. AI 기술 이 빠르게 발전하는 만큼 AI 모델 및 데이터 보안, 내부 위협 탐지, 전문 인력 육성 등에 역량을 집중함으로써 기업은 안전하고 신뢰할 수 있는 AI 활용을 통해 디지털 경쟁력을 제고할 수 있을 것이다.
This paper examines the security threats to enterprise Generative Artificial Intelligence systems and proposes countermeasures. As AI systems handle vast amounts of data to gain a competitive edge, security threats targeting AI systems are rapidly increasing. Since AI security threats have distinct characteristics compared to traditional human-oriented cybersecurity threats, establishing an AI-specific response system is urgent. This study analyzes the importance of AI system security, identifies key threat factors, and suggests technical and managerial countermeasures. Firstly, it proposes strengthening the security of IT infrastructure where AI systems operate and enhancing AI model robustness by utilizing defensive techniques such as adversarial learning and model quantization. Additionally, it presents an AI security system design that detects anomalies in AI query-response processes to identify insider threats. Furthermore, it emphasizes the establishment of change control and audit frameworks to prevent AI model leakage by adopting the cyber kill chain concept. As AI technology evolves rapidly, by focusing on AI model and data security, insider threat detection, and professional workforce development, companies can improve their digital competitiveness through secure and reliable AI utilization.
사이버 위협 중심의 국방 사이버 방호수준 분석에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제4호 2021.10 pp.77-85
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
사이버 방호란 사이버 공격 및 위협으로부터 우리가 운영하는 정보시스템을 보호하는 활동[1]이다. 현재 운영중인 사이버 방호체계의 방호수준을 알기 위해서는 시시각각 새롭게 발전하고 있는 사이버 위협을 반영하여 공격기술 현 황을 최신화하고 방호기능으로 대응이 가능한지 분석할 필요가 있다. 이에 본 논문에서는 사이버 킬 체인의 공격절 차와 방어유형으로 분류한 공격기술을 MITRE의 방어기술(Mitigation ID)과 연관 관계를 분석하고 방어적 사이버활 동 중심으로 군 부대 유형별 사이버 방호수준을 제시하고자 한다. 향후 국방영역에서 운영중인 사이버 방호체계의 대응역량을 실시간 분석하여 부대별 방호수준을 가시화하고 알려지지 않은 사이버 위협에 대한 조사 및 적극적인 취약점 보완을 통해 사이버 방호수준이 향상되길 기대한다.
Cyber protection is an activity that protects the information systems we operate from cyber attacks and threats. To know the level of protection of the currently operating cyber protection system, it is necessary to update the current state of attack technology by reflecting the constantly evolving cyber threats and to analyze whether it is possible to respond with the protection function. Therefore, in this paper, we analyze the relationship between the attack procedures and defense types of the cyber kill chain with the defense technology(Mitigation ID) of MITRE and present the cyber protection level for each military unit type with a focus on defensive cyber activities. In the future, it is expected that the level of cyber protection will be improved through real-time analysis of the response capabilities of cyber protection systems operating in the defense sector to visualize the level of protection for each unit, investigate unknown cyber threats, and actively complement vulnerabilities.
공세적 사이버 작전을 위한 사이버 킬체인 모델 연구 KCI 등재
한국융합보안학회 융합보안논문지 제23권 제4호 2023.10 pp.71-80
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
사이버공간은 지상, 해상, 공중, 우주에 이어 다섯 번째 새로운 전쟁 공간으로 자리매김하였고, 군사작전 측면에서도 사이버공간이 핵심적인 공격과 방어 목표가 되고 있다. 세계 각국은 이러한 사이버공간에 대한 공세적 사이버 작전 수행 의지를 보인다. 본 논문에서는 기존의 방어적 전략인 사이버 킬체인 모델에 합동 항공임무명령서(ATO)의 임무수행주 기와 합동표적처리 절차를 융합한 공세적 개념의 사이버 킬체인 모델을 제안한다. 제안한 모델은 사이버 작전의 합동성 측면에서 물리 작전과 사이버 작전의 통합을 통해 전략적 차원의 국가 사이버 작전 역량 개선에 기여할 것으로 기대한다
Cyberspace has emerged as the fifth domain of warfare, alongside land, sea, air, and space. It has become a crucial focus for offensive and defensive military operations. Governments worldwide have demonstrated their intent to engage in offensive cyber operations within this domain. This paper proposes an innovative offensive cyber kill chain model that integrates the existing defensive strategy, the cyber kill chain model, with the joint air tasking order (ATO) mission execution cycle and joint target processing procedure. By combining physical and cyber operations within a joint framework, this model aims to enhance national cyber operations capabilities at a strategic level. The integration of these elements seeks to address the evolving challenges in cyberspace and contribute to more effective jointness in conducting cyber operations.
APT 공격 사례 분석을 통한 사이버 킬체인과 TTP에 대한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제20권 제4호 2020.10 pp.91-101
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
과거 해외에서 발생한 APT 공격사례를 사이버 킬체인 모델과 TTP 모델로 분석하였다. 분석 결과 사이버 킬체인 모 델은 전체적인 윤곽을 파악하는데 효과적이지만 구체적인 방어 전략을 수립하는 데에는 부적합하며, TTP 모델로 분석 해야만 실질적인 방어 체제를 구비하는데 적합함을 알 수 있었다. 이러한 분석 결과를 바탕으로 사이버 공격을 대비하 는 관점에서 심층 방어선 구축에 적합한 TTP 모델 관점에서 방어 기술 개발이 필요함을 제시한다.
We analyzed APT attack cases that occurred overseas in the past using a cyber kill chain model and a TTP model. As a result of the analysis, we found that the cyber kill chain model is effective in figuring out the overall outline, but is not suitable for establishing a specific defense strategy, however, TTP model is suitable to have a practical defense system. Based on these analysis results, it is suggested that defense technology development which is based on TTP model to build defense-in-depth system for preparing cyber attacks.
공세적 통합 사이버작전을 위한 사이버 킬체인 전략 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.13 No.5 2016.10 pp.325-340
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
큰 위험을 수반하지 않으면서 저렴한 비용으로 군사적 도발을 감행할 수 있으며, 사후 보복이나 확산에 대한 부담이 거의 없으면서 한국과 미국의 취약점을 파악할 수 있는 이상적인 수단이기 때문에, 사이버 능력은 북한의 군사전략에 있어 핵심적인 요소가 되어 가고 있다. 그러나 북한의 사이버작전 수행을 사전에 통제하거나 억제할 수 있는 명문화된 정책이나 전략의 부재로 인해, 북한의 사이버 능력 사용은 향후에도 지속될 것이다. 이러한 문제 인식에 근거하여 본 논문에서는 기존 킬체인 개념을 준용하면서 북한의 사이버 공격에 대한 선제적 억제와 공세적 대응을 가능하게 해 주는 명문화된 기반전략으로서의 사이버 킬체인 전략을 제안한다. 기존 킬체인의 각 단계들은 작전 지휘관 및 작전 요원들에게 친숙한 개념이기 때문에, 제안된 사이버 킬체인 전략은 작전 지휘관 및 작전 요원들의 사이버 방어 전략에 대한 이해도를 증진시킬 수 있을 뿐만 아니라, 사이버 킬체인 전략을 현행 군사교리에 통합하는 것 또한 용이하다.
Because cyber capabilities can provide a low-cost and low-risk military option for provocation and can be an ideal mean for exploiting the vulnerabilities of ROK and U.S. with low intensity and minimal risk of escalation or retaliation, cyber capabilities may have became a key component in North Korean military strategy. However, ROK has no firmly established norms that can be adopted to control or suppress the NK's cyber operations in advance, the NK seems to use their cyber capabilities continuously. To address this problem, this paper describes an offensive cyber kill chain strategy based on the traditional kill chain to provide a basis for enabling pre-emptive suppress and offensive response to NK's cyber attacks. Because each step in traditional kill chain is very familiar with combatant officers, our cyber kill chain strategy can improve the understanding of cyber defense strategy. This also makes it easy to integrate our cyber kill chain strategy and current military doctrines.
[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.15 No.4 2019 pp.865-889
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The need for cyber resilience is increasingly important in our technology-dependent society where computing devices and data have been, and will continue to be, the target of cyber-attackers, particularly advanced persistent threat (APT) and nation-state/sponsored actors. APT and nation-state/sponsored actors tend to be more sophisticated, having access to significantly more resources and time to facilitate their attacks, which in most cases are not financially driven (unlike typical cyber-criminals). For example, such threat actors often utilize a broad range of attack vectors, cyber and/or physical, and constantly evolve their attack tactics. Thus, having up-to-date and detailed information of APT's tactics, techniques, and procedures (TTPs) facilitates the design of effective defense strategies as the focus of this paper. Specifically, we posit the importance of taxonomies in categorizing cyber-attacks. Note, however, that existing information about APT attack campaigns is fragmented across practitioner, government (including intelligence/classified), and academic publications, and existing taxonomies generally have a narrow scope (e.g., to a limited number of APT campaigns). Therefore, in this paper, we leverage the Cyber Kill Chain (CKC) model to "decompose" any complex attack and identify the relevant characteristics of such attacks. We then comprehensively analyze more than 40 APT campaigns disclosed before 2018 to build our taxonomy. Such taxonomy can facilitate incident response and cyber threat hunting by aiding in understanding of the potential attacks to organizations as well as which attacks may surface. In addition, the taxonomy can allow national security and intelligence agencies and businesses to share their analysis of ongoing, sensitive APT campaigns without the need to disclose detailed information about the campaigns. It can also notify future security policies and mitigation strategy formulation.
거부적 억제 수단으로서의 사이버 킬체인에 관한 연구; 스턱스넷 사이버 공격 사례를 중심으로
[NRF 연계] 미래군사학회 한국군사학논총 Vol.14 No.1 2025.03 pp.29-50
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문의 목적은 한국형 킬체인의 대안으로 제시될 수 있는 사이버 킬체인이 거부적 억제를 달성할 수 있는지, 이를 위한 필수 요소들은 무엇인지 규명하는 것이다. 본 연구는 통상 방어적 형태를 띄는 거부적 억제의 개념을 사이버 공간 내로 적용하여 적극적인 사이버 공격이 오히려 적의 능력을 저하하고 비용을 부과시켜, 행동을 자제하게 만든다고 주장했다. 이에 2009년 침투를 시작한 스턱스넷 사례를 분석한 결과, 스턱스넷은 사이버 킬체인의 공격 과정을 보여준 사례임을 확인했다. 그리고 스턱스넷은 3년 간의 감염 공격으로 이란의 핵 원심분리기에 직·간접적인 피해를 주었으나 명확한 의사소통의 부재와 이후 추가 개발 및 지속적 공격의 결여로 신뢰성을 확보하지 못해 장기적인 거부적 억제를 달성하지 못했다. 본 연구는 사이버 킬체인이 북한의 핵·미사일 개발을 저지하기 위한 효과적인 거부적 억제 수단으로 활용될 가능성을 제시한다. 스턱스넷과 같은 사이버 킬체인은 고도의 은밀성을 지녔고 C&C 서버 등을 통해 원하는 시기, 원하는 목표에 선별적으로 피해를 줄 수 있다. 하지만 전략적 소통을 동반한 지속적이고 체계적인 장기적 사이버 작전이 필요하다. 이를 위해 다양한 침투 방식을 활용할 수 있고 또 가상의 주체를 이용해 억제를 위한 의사소통이 가능할 것이다.
The purpose of this paper is to examine whether the cyber kill chain, as a potential alternative to the Korean Kill Chain, can achieve denial deterrence and to identify the essential elements required for this. This study applies the concept of denial deterrence, traditionally a defensive concept, to cyberspace, arguing that proactive cyberattacks can instead degrade the enemy's capabilities and impose costs, thereby deterring their actions. By analyzing the Stuxnet case, which began infiltrating in 2009, this study confirmed that Stuxnet demonstrated the cyber kill chain attack process. Over a three-year period of infection attacks, it inflicted direct and indirect damage on Iran's nuclear centrifuges. However, the absence of clear communication and the lack of subsequent development and sustained attacks led to a failure in establishing credibility, ultimately hindering the achievement of long-term denial deterrence. This study suggests that the cyber kill chain has potential as an effective means of denial deterrence to hinder North Korea's nuclear and missile development. Cyber kill chains, like Stuxnet, exhibit a high level of stealth and can selectively inflict damage on desired targets at desired times through mechanisms such as C&C servers. However, sustained and systematic long-term cyber operations accompanied by strategic communication are essential. To achieve this, various infiltration methods can be utilized, and fictitious entities could be employed to facilitate deterrence-focused communication.
사회공학 사이버작전을 고려한 사회공학 사이버킬체인 개념정립 연구
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.28 No.5 2018 pp.1247-1258
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
록히드 마틴사(社)에서 제안한 사이버킬체인은 사이버 공격절차를 7단계로 표준화하고, 각 단계별로 적절한 대응방안을 제시함으로써 궁극적으로 공격자가 공격목적을 달성하지 못하도록 하는 사이버작전 수행 간 방어에 대한 방법론을 제공한다. 이와 같은 사이버킬체인 모델을 활용하면 기존의 방법들로는 대응하기 어려웠던 지능형 지속공격(APT)에 보다 효과적인 대응이 가능하다는 장점이 있다. 하지만 최근의 사이버작전은 목표시스템을 직접 공격하는 기술적 사이버작전보다는 목표시스템 관리자나 사용자의 취약점을 통해 목표시스템을 우회적으로 공격하는 사회공학 사이버작전의 비중이 늘어가고 있는 추세이다. 이런 상황에서 기술적 사이버작전을 방어하기 위한 기존의 사이버킬체인 개념만으로는 사회공학 사이버작전에 효과적으로 대응할 수 없다. 따라서 본 논문에서 우리는 사회공학 사이버 작전에 효과적으로 대응할 수 있는 사회공학 사이버킬체인에 대한 개념을 정립하고자 한다.
The Cyber Kill Chain originally proposed by Lockheed Martin defines the standard procedure of general cyber attacks and suggests tailored defensive actions per each step, eventually neutralizing the intent of the attackers. Defenders can effectively deal with Advanced Persistent Threat(APT)s which are difficult to be handled by other defensive mechanisms under the Cyber Kill Chain. Recently, however, social engineering techniques that exploits the vulnerabilities of humans who manage the target systems are prevail rather than the technical attacks directly attacking the target systems themselves. Under the circumstance, the Cyber Kill Chain model should evolve to encompass social engineering attacks for the improved effectiveness. Therefore, this paper aims to establish a definite concept of Cyber Kill Chain for social engineering based cyber attacks, called Social Engineering Cyber Kill Chain, helping future researchers in this literature.
[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2017 pp.306-309
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
현대 ICT 기술의 발달은, 국가와 사회에 인프라를 이용하여 사이버 세계를 구성하고 있다. 사이버 세계에서는 국경이 없다. 세계 각국들은 자국의 이익을 목적으로, 사이버 공격을 수행하고 있다. 사이버 공격을 방어하기 위해서는 사이버 킬체인 전략이 필요하다. 사이버 공격을 방어하거나, 공격책임을 판단하기 위해서는, 공격 원점지의 파악이 중요하다. 공격 원점지에 대한 타격을 하기 위해서는, 전략적인 사이버 킬체인이 필요하다. 본 논문에서는 공격 원점지를 분석하는 연구를 한다. 그리고 공격 원점지 타격을 위한 사이버 킬체인을 분석한다. 공격 원점지 타격을 위한 효율적이고 맞춤형 사이버 킬체인 전략을 연구한다. 사이버 킬체인 전략은 비대칭 전력으로, 핵과 미사일의 위력을 대치할 수 있는 실용적인 전략이 될 것이다.
The development of modern ICT technology constitutes cyber world by using infrastructure in country and society. There is no border in cyber world. Countries around the world are carrying out cyber attacks for their own benefit. A cyber killer strategy is needed to defend cyber attacks. In order to defend the cyber attack or to determine the responsibility of attack, it is important to grasp the attacker origin point. Strategic cyber kill chains are needed to strike against the attacker origin. In this paper, we study the analysis of attacker origin. And analyze the cyber kill chain for attacker origin point strike. Study the efficient and customized cyber kill chain strategy for attacking the origin point. The cyber kill chain strategy will be a practical strategy to replace the power of nuclear and missiles with asymmetric power.
[Kisti 연계] 한국정보통신학회 한국정보통신학회논문지 Vol.21 No.11 2017 pp.2199-2205
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
현대 ICT 기술의 발달은, 국가와 사회에 인프라를 이용하여 사이버 세계를 구성하고 있다. 사이버 세계에서는 국경이 없다. 세계 각국들은 자국의 이익을 목적으로, 사이버 공격을 수행하고 있다. 사이버 공격을 방어하기 위해서는 사이버 킬체인 전략이 필요하다. 사이버 공격을 방어하거나, 공격책임을 판단하기 위해서는, 공격 원점지의 파악이 중요하다. 공격 원점지에 대한 타격을 하기 위해서는, 전략적인 사이버 킬체인이 필요하다. 본 논문에서는 공격 원점지를 분석하는 연구를 한다. 그리고 공격 원점지 타격을 위한 사이버 킬체인을 분석한다. 공격 원점지 타격을 위한 효율적이고 맞춤형 사이버 킬체인 전략을 연구한다. 사이버 킬체인 전략은 비대칭 전력으로, 핵과 미사일의 위력을 대치할 수 있는 실용적인 전략이 될 것이다.
The development of modern ICT technology constitutes cyber world by using infrastructure in country and society. There is no border in cyber world. Countries around the world are carrying out cyber attacks for their own benefit. A cyber killer strategy is needed to defend cyber attacks. In order to defend the cyber attack or to determine the responsibility of attack, it is important to grasp the attacker origin point. Strategic cyber kill chains are needed to strike against the attacker origin. In this paper, we study the analysis of attacker origin. And analyze the cyber kill chain for attacker origin point strike. Study the efficient and customized cyber kill chain strategy for attacking the origin point. The cyber kill chain strategy will be a practical strategy to replace the power of nuclear and missiles with asymmetric power.
공격 결과 기반의 웹 취약점 위험도 평가 모델 연구: 사이버 킬체인 중심으로
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.31 No.4 2021 pp.779-791
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
보통의 웹 서비스는 불특정 다수에게 허용을 해야하는 접근 통제 정책으로 인하여, 지속적으로 해커들의 공격 대상이 되어 왔다. 이러한 상황에 대응하고자 기업들은 주기적으로 웹 취약점 점검을 실시하고, 발견된 취약점의 위험도에 따라 조치를 취하고 있다. 이러한 웹 취약점 위험도는 국내외 유관기관의 사전 통계 및 자체적인 평가를 통해 산정되어 있다. 하지만 웹 취약점 점검은 보안설정 및 소스코드 등의 정적 진단과는 달리 동적 진단으로 이루어진다. 동일한 취약점 항목일지라도 다양한 공격 결과를 도출할 수 있으며, 진단 대상 및 환경에 따라 위험도가 달라질 수 있다. 이러한 점에서 사전 정의된 위험도는 실제 존재하는 취약점의 위험도와는 상이할 수 있다. 본 논문에서는 이러한 점을 개선하고자 사이버 킬체인 중심으로 공격 결과 기반의 웹 취약점 위험도 평가 모델을 제시한다.
Common web services have been continuously targeted by hackers due to an access control policy that must be allowed to an unspecified number of people. In order to cope with this situation, companies regularly check web vulnerabilities and take measures according to the risk of discovered vulnerabilities. The risk of these web vulnerabilities is calculated through preliminary statistics and self-evaluation of domestic and foreign related organizations. However, unlike static diagnosis such as security setting and source code, web vulnerability check is performed through dynamic diagnosis. Even with the same vulnerability item, various attack results can be derived, and the degree of risk may vary depending on the subject of diagnosis and the environment. In this respect, the predefined risk level may be different from that of the actual vulnerability. In this paper, to improve this point, we present a web vulnerability risk assessment model based on the attack result centering on the cyber kill chain.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.