Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 29
No
1

4,000원

본 연구는 사이버작전을 전문적으로 수행하지 않는 非사이버작전부대 장교들을 위한 교육체계를 개발하고 방향성을 제안 하기 위한 연구이다. 사이버작전을 합동작전으로 수행하기 위해서는 非사이버작전부대 장교들도 사이버작전을 알아야하나 이 들을 위한 교육체계는 현재 軍에는 없으며, 이에 대한 선행연구 또한 거의 없어 해당 분야의 연구가 필요하다. 따라서, 非사이 버작전부대 장교 교육체계는 사전에 실시한 관련 문헌연구를 기반으로, 교육체계를 구성할 수 있는 5가지 항목 즉, 교육의 필 요성, 교육대상, 교육목표 및 내용, 교육과정에 관한 사항을 개발하였다. 또한, 관련 전문가들에게 델파이방법으로 각 항목의 타당성을 확인하였다. 그 결과, 일부 향상의 필요성도 보였으나, 전체적으로 적합함을 보였다. 향후에는 이 연구를 바탕으로 세부 교육프로그램 개발이 개발될 수 있다.

The purpose of this study is to suggest the educational system and direction of cyber operations officers of non-cyber operations forces who do not specialize in cyber operations. In order to carry out cyber operations as a joint operation, non-Cyber Operations officers must also know about cyber operations, but there is no education system for them at present, Since there is almost no previous research on this, research in the relevant field is necessary. Therefore, the education system was developed based on the prior literature review, that is, the education system, that is, the necessity of education, the object of education, the goals and contents of the education, and the curriculum. In addition, the relevant experts confirmed the validity of each item with Delphi method, and as a result, some improvement was needed, but it was shown to be suitable as a whole. In addition, detailed educational program development can be developed based on this in the future.

2

사이버 작전 군대부호 표준화에 관한 연구 KCI 등재

이종관, 이민우, 김종화, 김종화, 이재연, 오행록

한국융합보안학회 융합보안논문지 제21권 제1호 2021.03 pp.149-158

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 논문은 사이버 작전 상황을 직관적으로 이해하기 위한 사이버 군대부호를 제안한다. 현재 사용하고 있는 군대부호 들은 사이버 작전을 고려하지 않고 물리적 작전만을 고려하여 표준화되었다. 미군의 합동군대부호 표준인 MIL-STD-25 25D에서는 일부 사이버 작전을 위한 부호들이 포함되어 있으나 영문자 3자로 구성된 아이콘만이 표준화되어 있다. 따라 서 사이버 작전을 효과적으로 표현하는데 한계가 있다. 이러한 이유로 본 논문은 현존하는 군대부호 생성 규칙에 부합 하는 사이버 작전을 위한 군대 부호를 제안한다. 단지 군대부호만을 제시하는 것에 그치지 않고 제안하는 부호의 효용 성을 증명하기 위해 제안하는 부호를 사용하여 다양한 사이버 상황을 표현한 예제도 함께 제시한다. 본 논문에서 제안 한 부호들이 모든 사이버 상활을 표현할 수는 없으나, 제안한 부호들을 기반으로 더 많은 부호들이 향후 표준화될 수 있을 것으로 기대한다.

In this paper, we propose military symbols for cyber operations to understand the situation in cyberspace intuitively. Currently, standardized military symbols are mainly for kinetic operations, and they do not consider cyber operations. Although, MIL-STD-2525D includes some symbols for cyber operations, only icons that are composed of three letters are standardized. So there is a limit to effectively expressing cyber operations. That is why we propose military symbols for cyber operations compatible with existing military symbol building rules. In addition to merely presenting the symbols, we present examples of expressing various cyber situations using the proposed symbols. It proves the usefulness of the proposed symbol. The small number of symbols proposed in this paper will not be able to represent all cyber situations. However, based on the proposed symbols, it is expected that more symbols will be standardized in the future to more clearly express the cyber situation.

3

4,600원

본 연구는 지능형 지속 위협(APT)과 공급망 공격으로 대표되는 고도화된 사이버 위협 환경에서, 기존의 인간 중심⋅사후 대응형 사이버 작전 체계가 기술적 성능의 문제가 아니라 전력 개념 차원에서 구조적 한계를 지니고 있음을 분석한다. 이러 한 한계를 극복하기 위한 대안으로, 본 논문은 ‘사이버 드론(Cyber Drone)’이라는 자율형 사이버 전력 개념을 제안한다. 사 이버 드론은 물리적 드론의 형상을 모방한 기술 개념이 아니라, 무인성, 지속적 정찰, 조건부 자율성, 효과 중심 작전이라는 운용 논리를 사이버 공간에 적용한 전력 단위(force element)로 정의된다. 사이버 드론은 탐색, 분석, 대응, 학습의 기능을 분산⋅자율적으로 수행하면서 중앙 통제 체계와 결합된 구조를 통해 사이 버 공간 전반에 걸친 지속적 작전 수행 가능성을 제시한다. 본 연구는 Stuxnet⋅NotPetya⋅SolarWinds 사례 분석을 통해 기존 사이버 방어 체계의 사후 탐지 중심 구조와 중앙집중식 대응 방식이 고도화된 공격에 취약함을 확인하고, 사이버 드론 개념이 이러한 한계를 어떻게 보완할 수 있는지를 개념적으로 검토한다. 아울러 본 논문은 자율형 사이버 전력의 도입과 관련하여 행위 귀속, 비례성, 책임성, 감사 가능성 등 법적⋅윤리적⋅제도 적 쟁점을 분석하고, 완전 자율이 아닌 인간 통제 하의 조건부 자율성 모델을 제시한다. 나아가 사이버 드론을 개방형 아키 텍처와 서비스 기반 전력 운용 개념에 부합하는 전력 요소로 위치시킴으로써, 향후 자율형 사이버 전력의 제도화와 방위산업 적 시사점을 도출한다.

This paper analyzes the structural limitations of conventional, human-centered, and reactive cyber operations in the context of increasingly sophisticated cyber threats, including advanced persistent threats (APTs) and supply-chain attacks. To address these limitations, it proposes the concept of a “Cyber Drone” as an autonomous cyber force element that applies the operational logic of physical drones—unmanned operation, persistent reconnaissance, conditional autonomy, and effects-based operations—to the cyber domain. Cyber Drones are defined not as individual technologies or automated tools, but as distributed force units capable of autonomously performing cycles of reconnaissance, analysis, response, and learning while remaining integrated within a centralized command-and-control framework. Through case analyses of the Stuxnet, NotPetya, and SolarWinds attacks, the paper examines how existing cyber defense architectures— characterized by centralized monitoring and post-incident response—are structurally vulnerable to stealthy and persistent cyber operations, and explores how the Cyber Drone concept may mitigate these vulnerabilities. The paper further analyzes the legal, ethical, and institutional implications of autonomous cyber power, focusing on attribution, proportionality, accountability, and auditability. It advocates a model of conditional autonomy under human oversight rather than fully autonomous cyber weapons. By framing Cyber Drones as a force element aligned with open architectures, software-defined systems, and service-based operational concepts, the study derives strategic implications for the institutionalization of autonomous cyber power and future defense-industrial development.

4

국방 네트워크 환경에서 ATT&CK 기반 취약점 완화 체계 구축 방안 KCI 등재

안광현, 이한희, 박원형, 강지원

한국융합보안학회 융합보안논문지 제20권 제4호 2020.10 pp.135-141

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

국방부는 주기적인 사이버방호 훈련을 실시함에 따라 사이버작전의 전력과 역량을 보강하고 있다. 하지만 적 사이버 공격 능력 수준을 고려할 때 군의 사이버방호 능력 수준은 현저히 낮으며 군용 네트워크망에 대한 사이버위협을 대응할 수 있는 보호대책과 대응체계가 명확하게 설계되어 있지 않아 민·관의 사이버보안 능력 수준에도 못 미치고 있는 실태 이다. 따라서 본 논문에서는 국내·외 사이버보안 프레임워크를 참조하여 국방 네트워크망 취약점 완화 체계를 구축할 수 있는 요소로 군 특수성을 지닌 군 내부망 주요 위협 정보 및 국방정보시스템 보안 요구사항을 파악하고, 공격자의 의도파악과 전술, 기법 및 절차 정보(ATT&CK)를 적용하여 국방 네트워크 환경에 대한 사이버공격을 효율적으로 보호 해주는 군 내부망 취약점 완화 체계 구축 방안을 제안한다.

The Ministry of National Defense is strengthening the power and capacity of cyber operations as cyber protection training is conducted. However, considering the level of enemy cyber attack capability, the level of cyber defense capability of the ministry of national defense is significantly low and the protection measures and response system for responding to cyber threats to military networks are not clearly designed, falling short of the level of cyber security capabilities of the public and private sectors. Therefore, this paper is to investigate and verify the establishment of a military internal network vulnerability mitigation system that applies the intention of attackers, tactics, techniques and procedures information (ATT&CK Framework), identified military internal network main threat information, and military information system security requirements with military specificity as factors that can establish a defense network vulnerability mitigation system by referring to the domestic and foreign cyber security framework It has the advantage of having.

5

공세적 사이버 작전을 위한 사이버 킬체인 모델 연구 KCI 등재

조성배, 김완주, 임재성

한국융합보안학회 융합보안논문지 제23권 제4호 2023.10 pp.71-80

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

사이버공간은 지상, 해상, 공중, 우주에 이어 다섯 번째 새로운 전쟁 공간으로 자리매김하였고, 군사작전 측면에서도 사이버공간이 핵심적인 공격과 방어 목표가 되고 있다. 세계 각국은 이러한 사이버공간에 대한 공세적 사이버 작전 수행 의지를 보인다. 본 논문에서는 기존의 방어적 전략인 사이버 킬체인 모델에 합동 항공임무명령서(ATO)의 임무수행주 기와 합동표적처리 절차를 융합한 공세적 개념의 사이버 킬체인 모델을 제안한다. 제안한 모델은 사이버 작전의 합동성 측면에서 물리 작전과 사이버 작전의 통합을 통해 전략적 차원의 국가 사이버 작전 역량 개선에 기여할 것으로 기대한다

Cyberspace has emerged as the fifth domain of warfare, alongside land, sea, air, and space. It has become a crucial focus for offensive and defensive military operations. Governments worldwide have demonstrated their intent to engage in offensive cyber operations within this domain. This paper proposes an innovative offensive cyber kill chain model that integrates the existing defensive strategy, the cyber kill chain model, with the joint air tasking order (ATO) mission execution cycle and joint target processing procedure. By combining physical and cyber operations within a joint framework, this model aims to enhance national cyber operations capabilities at a strategic level. The integration of these elements seeks to address the evolving challenges in cyberspace and contribute to more effective jointness in conducting cyber operations.

6

선제적·적극적 사이버 방어작전 프레임워크 제안 KCI 등재

김완주, 이수진

한국융합보안학회 융합보안논문지 제25권 제4호 2025.10 pp.107-118

※ 기관로그인 시 무료 이용이 가능합니다.

4,300원

최근 민·관·군 전 영역에 대한 사이버 위협 증가와 러-우 전쟁에서 증명된 사이버공격의 전략적 가치는 한국군 사이버 방 어작전의 강력한 대응 변화를 요구하고 있다. 전 세계 각국은 기존의 사이버 방어전략을 보다 공세적인 방향으로 강화하고 있 으며, 해킹백 활용 등 공격자에 대한 직접적 대응도 적극적으로 검토되고 있다. 군사작전 측면에서 사이버 공격에 효과적으로 방어하기 위해서는 공격자 또는 공격 기반체계에 대한 감시정찰 및 무력화 등 선제적 대응이 필요하며 내부의 침투한 적을 적극적으로 식별하여 제거하는 적극적 작전활동이 수행되어야 한다. 본 연구에서는 선제적·적극적 사이버 방어작전 수행을 위 한 구체적인 작전활동으로 정보감시정찰, 무력화, 위협분석, 적극방어, 조사분석을 제시하고 있다. 제시하는 사이버 방어작전 프레임워크가 한국군에 적용된다면 보다 효과적인 사이버 방어작전 수행에 기여할 것이다.

The recent increase in cyber threats across all civilian, public, and military sectors, combined with the strategic value of cyber attacks proven in the Russo-Ukrainian War, demands a fundamental change in the Republic of Korea (ROK) military's cyber defense operations. Countries around the world are strengthening their existing cyber defense strategies in a more offensive direction and actively considering direct responses to attackers, such as the use of hacking back. From a military operations perspective, to effectively defend against cyber attacks, preemptive responses such as surveillance, reconnaissance, and neutralization of attackers or their infrastructure are necessary, along with proactive operational activities to identify and eliminate internal infiltrators. This study proposes specific operational activities for conducting preemptive and proactive cyber defense operations, including information surveillance and reconnaissance, neutralization, threat analysis, proactive defense, and investigation and analysis. Applying the proposed cyber defense operations framework to the ROK military will contribute to the execution of more effective cyber defense operations.

7

가상현실(VR)에서 조작행위가 사이버멀미에 미치는 영향 KCI 등재

고윤서, 한정완

한국디지털정책학회 디지털융복합연구 제18권 제6호 2020.06 pp.451-457

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 연구는 멀미 측정 도구인 SSQ도구를 바탕으로 가상현실에서 조작행위에 따라 나타나는 멀미 정도를 측정하 여 비교분석을 통해 사이버멀미에 영향을 미치는 요인 및 증상을 규명하는 데 목적이 있다. 연구결과 첫 번째 실험인 조작방식실험에서는 간단한 조작방식이 멀미가 높게 측정되었으며 Nausea요인의 영향을 크게 받는 것으로 측정되었 다. 이에 대한 증상으로 Nausea, Burping, Headache증상이 발현되었다. 두번째 신체회전방식 실험에서는 신체회전 반경이 클수록 멀미가 높게 측정되었으며 Nausea요인의 영향을 크게 받는 것으로 측정되었다. 이에 대한 증상으로 Burping, Headache, Fullness of head증상이 발현되었다. 세번째 신체이동방식 실험에서는 행위를 수반하지 않은 컨트롤러의 이동방식이 멀미가 높게 측정되었으며 Nausea요인의 영향을 크게 받는 것으로 측정되었다. 이에 대한 증상 으로 Sweating, Headache, Fullness of head증상이 발현되었다. 본 연구를 통해 가상현실에서 신체(고개, 상체, 하 체)가 고정되고 조작이 단순 할수록 사용자는 멀미에 민감하게 반응하며, 신체회전에 있어 회전반경이 클수록 멀미에 민감하게 반응하는 것을 확인하였다. 본 연구는 VR조작행위에 대한 멀미와 영향을 미치는 요인과 증상을 규명하는데 의의가 있으며 향후 VR콘텐츠 개발자들이 사용자의 특정 행위 멀미 정도와 증상에 관하여 인지하고 콘텐츠 개발에 활용 될 것으로 기대한다.

In this study, the degree of motion sickness displayed according to actions in virtual reality is measured based on the SSQ tool, a measuring tool, and factors and symptoms affecting cyber motion sickness are investigated through comparative analysis. In the first experiment, the operation method experiment, the simple operation method is measured to be highly affected by the Nausea factor. As symptoms of this, nausea, burp and headache symptoms were developed. In the second experiment, the larger the body rotation radius, the higher the motion sickness was measured, and the greater the influence of Nausea factors. Symptoms of this were the symptoms of burping, headaches, and a full head. In the third experiment, the physical mobility experiment, motion sickness was measured highly in the non-action controller. It was measured to be greatly affected by the Nausea factor. Symptoms of this include fever, headache, and a full head. Through this study, we found that the more fixed and simple the body is operated in virtual reality, the more sensitive the user is to motion sickness, and the larger the radius of rotation, the more sensitive it is to motion sickness. This study is meaningful in identifying factors and symptoms that affect motion sickness and VR manipulation, and is expected to be used by developers in the future to recognize the degree and symptoms of motion sickness of users and to develop content.

8

보안관제 조직을 위한 사이버보안 프레임워크 개선에 관한 연구 KCI 등재

조창섭, 신용태

한국융합보안학회 융합보안논문지 제19권 제1호 2019.03 pp.111-120

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

사이버공격이 지능화되고 고도화되면서 이를 체계적으로 대응하기 위한 보안관제센터(SOC : Security Operations Center)의 중요성이 높아지고 있고, SOC의 규모와 그 수도 늘어나고 있다. 각 기관 및 조직에서 다양한 사이버보안 표준을 활용하여 업무 절차를 만들어 사용하고 있으나 SOC는 자체 인력보다는 보안관제전문기업과 협업하는 경우가 많아 SOC환경에 맞게 개선이 필요하다. NIST 사이버보안 프레임워크(CSF : Cybersecurity Framework)와 정보보호 관리체계 그리고 보안관제전문기업의 업무절차를 비교 분석한 결과 NIST CSF가 보안관제에 적용하기 용이한 프레임 워크이나 국내 SOC에 적용하기 위해서는 SOC의 운영 및 관리 부분이 추가적으로 보완될 필요가 있다. 따라서 본 연 구에서는 NIST CSF를 참조 모형으로 하여 SOC환경에 필요한 관리적 항목을 도출하였으며 각 항목에 대한 필요성, 중요성, 용이성을 델파이 조사방식으로 검증하고 개선된 사이버보안 프레임워크를 제안하였다.

As cyber-attacks become more intelligent and sophisticated, the importance of Security Operations Center(SOC) has increased and the number of SOC has been increasing. In order to cope with cyber threats, institutions and organizations use a variety of cyber security standards to create business procedures. However, SOC often need to be improved in accordance with the SOC environment because they collaborate with managed security service specialists rather than their own personnel. The NIST cyber security framework, information security management system, and managed security service companies were compared and analyzed. As a result, it was found that the NIST CSF is a framework that is easy to apply to managed security service, The content was judged to be insufficient. Therefore, in this study, NIST CSF was used as a reference model to derive the management items required for SOC environment, and the necessity, importance and ease of each item were confirmed through an Delphi technique and an improved cyber security framework was proposed.

9

Roles and Responsibilities of Cyber Intelligence for Cyber Operations in Cyberspace SCOPUS

Jung ho Eom

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.5 2014.09 pp.323-332

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we proposed roles and responsibilities of cyber intelligence in cyber operations. In particular, we focused on the roles and responsibilities of cyber intelligence on each phase of cyber operations. Cyber operations are activities related to defense, assurance, and attack to achieve objectives in or through cyberspace. While cyber operation is conducting, cyber intelligence must properly support cyber commander and units for ensuring cyberspace intelligence superiority. Cyber intelligence is a cyber-discipline that exploits a number of information collection and analysis approaches to provide direction and decision to cyber commander and cyber operation units. This is a key role in both cyber-attack and cyber defense. We know that the branch of information and communications conducts cyber operations in cyberspace. But we don’t know well that the cyber intelligence is more in charge of the policy, strategic, and tactics in cyber operations. It is collected information requested from cyber command and units, and is disseminated information to department related to cyber operations. The cyber intelligence is a key factor in cyber operation cycle.

10

Roles and Responsibilities of Cyber Intelligence for Cyber Operations in Cyberspace SCOPUS

Jung ho Eom

보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.8 No.9 2014.09 pp.137-146

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we proposed roles and responsibilities of cyber intelligence in cyber operations. In particular, we focused on the roles and responsibilities of cyber intelligence on each phase of cyber operations. Cyber operations are activities related to defense, assurance, and attack to achieve objectives in or through cyberspace. While cyber operation is conducting, cyber intelligence must properly support cyber commander and units for ensuring cyberspace intelligence superiority. Cyber intelligence is a cyber-discipline that exploits a number of information collection and analysis approaches to provide direction and decision to cyber commander and cyber operation units. This is a key role in both cyber-attack and cyber defense. We know that the branch of information and communications conducts cyber operations in cyberspace. But we don’t know well that the cyber intelligence is more in charge of the policy, strategic, and tactics in cyber operations. It is collected information requested from cyber command and units, and is disseminated information to department related to cyber operations. The cyber intelligence is a key factor in cyber operation cycle.

11

공세적 통합 사이버작전을 위한 사이버 킬체인 전략 KCI 등재

김영환, 이수진

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.13 No.5 2016.10 pp.325-340

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

큰 위험을 수반하지 않으면서 저렴한 비용으로 군사적 도발을 감행할 수 있으며, 사후 보복이나 확산에 대한 부담이 거의 없으면서 한국과 미국의 취약점을 파악할 수 있는 이상적인 수단이기 때문에, 사이버 능력은 북한의 군사전략에 있어 핵심적인 요소가 되어 가고 있다. 그러나 북한의 사이버작전 수행을 사전에 통제하거나 억제할 수 있는 명문화된 정책이나 전략의 부재로 인해, 북한의 사이버 능력 사용은 향후에도 지속될 것이다. 이러한 문제 인식에 근거하여 본 논문에서는 기존 킬체인 개념을 준용하면서 북한의 사이버 공격에 대한 선제적 억제와 공세적 대응을 가능하게 해 주는 명문화된 기반전략으로서의 사이버 킬체인 전략을 제안한다. 기존 킬체인의 각 단계들은 작전 지휘관 및 작전 요원들에게 친숙한 개념이기 때문에, 제안된 사이버 킬체인 전략은 작전 지휘관 및 작전 요원들의 사이버 방어 전략에 대한 이해도를 증진시킬 수 있을 뿐만 아니라, 사이버 킬체인 전략을 현행 군사교리에 통합하는 것 또한 용이하다.

Because cyber capabilities can provide a low-cost and low-risk military option for provocation and can be an ideal mean for exploiting the vulnerabilities of ROK and U.S. with low intensity and minimal risk of escalation or retaliation, cyber capabilities may have became a key component in North Korean military strategy. However, ROK has no firmly established norms that can be adopted to control or suppress the NK's cyber operations in advance, the NK seems to use their cyber capabilities continuously. To address this problem, this paper describes an offensive cyber kill chain strategy based on the traditional kill chain to provide a basis for enabling pre-emptive suppress and offensive response to NK's cyber attacks. Because each step in traditional kill chain is very familiar with combatant officers, our cyber kill chain strategy can improve the understanding of cyber defense strategy. This also makes it easy to integrate our cyber kill chain strategy and current military doctrines.

12

Establishment of a Feasible Cyber Organization Structure to Enhance the Capabilities of Cyberspace Operations in the ROK’s Defense Forces

이영주

[NRF 연계] 한국국방연구원 The Korean Journal of Defense Analysis Vol.28 No.2 2016.06 pp.223-248

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The paper discusses ways of establishing a feasible cyber organization for enhancing cyber response capabilities in defense of the ROK. To prepare for the rise of cyberspace as a war-combat domain, together with the realization that cyberspace is indispensable in fulfilling operational requirements, it is essential to search for and establish a new, suitable organization for cyberspace operations. To achieve this, the author suggests a design of an organization based on the so-called “three-party authority,” the ROK’s way of managing cyberspace, the difference in each echelon’s accountability for the fulfillment of the operational requirements?mission accomplishment for its commander as well as the characteristics of cyberspace. The article also presents validation and verification of the suggested composition of the cyber organization suitable for defense of the ROK to identify its pros and cons.

13

군사동맹의 사이버 영역 확장과 협력 과제: 사이버 확장억지와 연합 사이버 작전시 주권 문제를 중심으로

박병찬

[NRF 연계] 한국군사문제연구원 한국군사 Vol.14 2023.12 pp.39-67

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버 공간에서의 공격 및 침해 행위가 점차 고도화되면서 사이버 보안은 국가안보와 직결되는 중요한 문제로 부각되고 있다. 따라서, 각국가들은 사이버 보안강화를 위해 민·관·군, 동맹 및 우방국과의 협력을 확대해나가고 있다. 우리나라도 올해 4월 윤석열 대통령의 미국 방문시 ‘워싱턴 선언’과 함께 ‘한미 전략적 사이버안보협력 프레임워크’를 발표함으로써 기존의 한미 동맹이 사이버 공간으로확장될 것임을 시사했다. 동맹의 사이버 영역으로의 확장은 기존 한미 상호방위조약이 사이버 공간에서 어떻게 적용될 것인지에 대한 논의의 시작을 필요로 하게되었다. 이를 위해 본 논문은 ‘사이버 공격시 확장억지 문제’와 ‘연합 사이버 작전시 주권 문제’ 두 가지 측면에서 검토하였다. 사이버 공간에서의 확장억지는 공격자를 특정하는 문제와 피해에 대한 기준이 모호한 문제 등의 현실적 제약이 있으나, 억지의 신뢰성을 배가 시킬 수 있다는 점에서 사이버 공간에서 안보를 강화하는 하나의 방편이 될 것이다. 또한, 동맹이 사이버 공간으로 확대될 경우 연합작전도 사이버 공간으로 확대될 것이다. 이 경우 ‘데이터 주권 문제’, ‘사이버 인프라 공유시 주권 문제’ 등이 발생할 수 있다. 따라서, 동맹의 사이버 영역으로의 확장 추세에 맞춰 발생 가능한 다양한 쟁점들을 미리 고민하고 한미 양국 간의 충분한 논의와 준비가 필요하다.

As attacks and infringement in cyberspace gradually advance, cybersecurity is emerging as an important issue directly related to national security. Therefore, each country is expanding cooperation between the civil, public, and military and externally with allies and friendly countries to strengthen cyber security. Korea also announced the ‘Korea-U.S. Strategic Cyber Security Cooperation Framework’ along with the ‘Washington Declaration’ when President Yoon Suk Yeol visited the U.S. in April this year, suggesting that the existing Korea-U.S. alliance will expand into cyberspace. As such, the expansion of the alliance's domain into the cyber domain required the beginning of a discussion on how the existing mutual defense treaty between Korea and the United States will be applied in the future cyberspace. To this end, it was reviewed in two aspects: ‘extended deterrence issues in the event of cyber attacks’ and ‘sovereignty issues in combined cyber operations.’ Extended deterrence in cyberspace has practical limitations, such as the problem of identifying attackers and ambiguous standards for damage, but providing extended deterrence between allies can increase the credibility of deterrence for adversaries, thereby increasing security in cyberspace. It will be a way to strengthen. Additionally, if the alliance expands into cyberspace, combined operations will also expand into cyberspace. In this case, the ‘data sovereignty problem’ and ‘the sovereignty problem when sharing cyber infrastructure’ may occur. Therefore, it is necessary to consider in advance various issues that may arise in line with the alliance's expansion into the cyber domain and to conduct a preparatory process through sufficient prior discussion between the ROK and the United States.

14

군사동맹의 사이버 영역 확장과 협력 과제 : 사이버 확장억지와 연합 사이버 작전시 주권 문제를 중심으로

박병찬

[NRF 연계] 한국군사문제연구원 한국군사 Vol.14 2023.12 pp.39-67

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

15

신호이론으로 보는 국제위기 시 사이버 작전의 의도: 2022년 양안 긴장 사례를 중심으로

최은아, 김인욱

[NRF 연계] 동아시아국제정치학회 국제정치연구 Vol.26 No.3 2023.09 pp.225-250

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 연구는 신호이론(theory of signaling)을 적용하여 국제위기 상황에서 이해당사국이 수행하는 사이버 작전의 의미를 분석하는 데 목적이 있다. 국제정치학에서 신호는 타겟국가의 행동을 변화시키기 위해 수행하는 강압외교의 핵심 요소로, 신호를 보내는 목적은 대개 결의(resolve)로 풀이돼왔다. 하지만 최신 연구논의들은 위기관리 차원에서 위기의 확대방지를 위한 조정(accommodative) 신호에 주목하고 있다. 공격국가는 대외적으로 갈등이 고조되는 상황과 확전을 피하고 대내적으로 국내정치적 비용을 낮추는 지렛대로써 사이버 작전을 사용할수 있다. 주장을 검증하기 위해 2022년 8월 중국-대만 국제위기 사례 분석을 시도하였다. 사이버 작전 신호의 요건과 구분 기준 등을 정리하여 사이버 작전 신호를 구분하는 틀을 제시하였다는 점이 본 연구의 기여점이다.

This paper examines how states can employ cyber operations to signal accommodative intentions during interstate crises. Signals are typically conceptualized as a demonstration of resolve, thereby functioning as a coercive tool to influence the target’s behavior during crises. Recently, the scholarship explored an accommodative signal, which is to message an intent to control escalation risk and de-escalate crises. We theorize how and when cyber operations can serve as the accommodative signal, highlighting whether operation is costly, publicly acknowledged, and its intention publicly communicated as key factors. We examine the China’s cyber operations surrounding the US House Speaker Nancy Pelosi’s visit to Taiwan in 2022 as an illustrative case and show that they largely bear out the theoretical expectations. The paper contributes to the literature on signaling, cyber operations, and crisis management.

16

한국군 합동 사이버작전 강화방안 연구-합동작전과 연계를 중심으로-

송재익

[NRF 연계] 한국군사문제연구원 한국군사 Vol.2 2017.12 pp.147-186

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

현대 전장은 지상, 해상, 공중의 3차원 공간에서 우주 및 사이버공간까지 확장되었다. 21세기는 4세대 전쟁방식으로 사이버전을 기반으로 하는 전쟁이 전개될 것으로 예상하고 있다. 현재 한반도는 사이버전이 진행 중에 있다. 북한은 사이버전의 중요성을 인식하여 비대칭 전력으로 사이버전 능력을 강화하여 왔다. 특히 2013년에 3.20 및 6.25 사이버테러를 감행하여 우리 언론사 및 금융회사의 전산망을 무력화시켰다. 2014년에는 한국수력원자력의 원전 도면과 2016년에는 국방통합데이터센터(DIDC)를 해킹하여 군사기밀 문서까지 유출되었다. 북한은 한국 사회기반 및 국방정보통신 체계에 대한 무력화를 집요하게 시도하고 있다. 북한의 사이버 위협에 대비하여 사이버전에 대한 인식이 아직 미흡하다. 우리 군은 합동작전 하에서 사이버작전을 발전시킬 필요가 있다. 먼저 군은 적의 사이버공격에 대해 효과적인 사이버작전을 위해 인식의 대전환이 요구된다. 따라서 본 연구는 한국군의 사이버전 현상을 진단하여 합동작전과 연계한 합동 사이버작전 수행개념, 사이버작전 조직 및 운영 체계를 강화하는 방안을 제시하였다.

Contemporary Battlefield has been expanded to multi-dimensions in ground, sea, air, airspace and cyberspace. Development of Information Communication Technology (ICT) has increased battlefield control domains and a possibility of cyber warfare. Since cyber warfare is executed by asymmetric method of conducting war, it has difficulty in understanding an attacking agent. Cyber experts expect that cyber warfare is now referred to as fourth generation war in the 21st century. North Korea has developed cyber warfare capabilities after recognizing the importance of cyber warfare since 2000. In fact, North Korea's DDoS attacks in 2009 and 2011 as well as 3.20 and 6.25 cyber terror in 2013 neutralized our mass media service and finance company. Additionally, North Korea, in 2014, hacked Korea Hydro & Nuclear Power (KHNP) and stole a nuclear plan and in 2016, broke into the Defense Integrated Data Center (DIDC) and took out classified military documents. The ROK forces' awareness about cyber warfare is insufficient. The ROK forces have established Cyber Command in the Ministry of National Defense (MND) and Department of Cyber Operations in the Joint Chiefs of Staff (JCS). But the ROK forces think that their functions are to provide operational support for cyber operations, and that communications and computer personnel only conduct cyber operations. The ROK forces must work on ensuring the implementation of cyber security at the national level to defense against North Korea cyber threats. First of all, we have to change our thinking about cyber operations. We also must conduct cyber operations in the joint operations system. The ROK forces need to build a joint cyber operations system. Therefore, the purpose of this study is to assess the present situation of the ROK forces' cyber operations and seek course of actions to enhance our joint cyber operations.

17

사회공학 사이버작전을 고려한 사회공학 사이버킬체인 개념정립 연구

신규용, 김경민, 이종관

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.28 No.5 2018 pp.1247-1258

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

록히드 마틴사(社)에서 제안한 사이버킬체인은 사이버 공격절차를 7단계로 표준화하고, 각 단계별로 적절한 대응방안을 제시함으로써 궁극적으로 공격자가 공격목적을 달성하지 못하도록 하는 사이버작전 수행 간 방어에 대한 방법론을 제공한다. 이와 같은 사이버킬체인 모델을 활용하면 기존의 방법들로는 대응하기 어려웠던 지능형 지속공격(APT)에 보다 효과적인 대응이 가능하다는 장점이 있다. 하지만 최근의 사이버작전은 목표시스템을 직접 공격하는 기술적 사이버작전보다는 목표시스템 관리자나 사용자의 취약점을 통해 목표시스템을 우회적으로 공격하는 사회공학 사이버작전의 비중이 늘어가고 있는 추세이다. 이런 상황에서 기술적 사이버작전을 방어하기 위한 기존의 사이버킬체인 개념만으로는 사회공학 사이버작전에 효과적으로 대응할 수 없다. 따라서 본 논문에서 우리는 사회공학 사이버 작전에 효과적으로 대응할 수 있는 사회공학 사이버킬체인에 대한 개념을 정립하고자 한다.

The Cyber Kill Chain originally proposed by Lockheed Martin defines the standard procedure of general cyber attacks and suggests tailored defensive actions per each step, eventually neutralizing the intent of the attackers. Defenders can effectively deal with Advanced Persistent Threat(APT)s which are difficult to be handled by other defensive mechanisms under the Cyber Kill Chain. Recently, however, social engineering techniques that exploits the vulnerabilities of humans who manage the target systems are prevail rather than the technical attacks directly attacking the target systems themselves. Under the circumstance, the Cyber Kill Chain model should evolve to encompass social engineering attacks for the improved effectiveness. Therefore, this paper aims to establish a definite concept of Cyber Kill Chain for social engineering based cyber attacks, called Social Engineering Cyber Kill Chain, helping future researchers in this literature.

18

최근 국가실행을 통해 비춰본 국제법상 무력 사용으로서 사이버 오퍼레이션

박주희

[NRF 연계] 대한국제법학회 국제법학회논총 Vol.64 No.4 2019.12 pp.97-126

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

기술 발전을 통해 사이버공간이 등장하고 그 이용이 확대되어 사이버공간에 대한 의존 도가 심화되면서 군사적 이익을 취함에 있어 사이버공간은 매력적인 수단이자 표적이 되 었다. 이렇듯 기술적 환경이 변화하자, 국가들은 무력 사용을 규율하는 jus ad bellum이 사이버공간에 어떻게 적용될 수 있는지에 관하여 많은 관심을 가져왔다. 무력 사용의 개념 을 사이버 오퍼레이션에 적용하는 세 가지 접근법이 나타나고 있으나 모두 완벽히 만족스 럽지는 않다. 먼저 ‘무기’의 성격을 중심으로 국제법상 금지되는 무력 사용 여부가 결정되 는 수단 중심적 접근법은 사이버 오퍼레이션에 적용하기 어렵다. 또한 표적 중심적 접근법 은 사이버 오퍼레이션의 효과가 얼마나 심각한지 여부에 대한 고려 없이 사이버 오퍼레이 션의 대상의 성격에만 지나치게 집중하고 있다는 점에서 한계를 갖는다. 또한 효과 중심적 접근법은 무력 사용과 비무력적 강제사이의 전통적 구분을 모호하게 할 수 있다는 점에서 한계를 나타내며, 물리적 효과만을 고려하여 사이버 오퍼레이션이 물리적 효과를 야기하 지 않고도 한 국가의 안전을 위협할 수 있다는 점을 간과한다는 점에서 한계를 갖는다. 각각의 접근법이 가지는 한계점에도 불구하고 현재 사이버 오퍼레이션이 무력 사용인 지 여부를 판단하는데 효과 중심적 접근법이 국제법 학자들 사이에서 가장 많은 지지를 받는 접근법임은 부인하기 힘들다. 또한 최근 서방국가들을 중심으로 효과 중심적 접근법 이 확대되고 있다. 본 연구는 사이버 오퍼레이션에 UN헌장 제2조 4항의 무력 사용의 개념 을 적용하는 접근법에 대하여 검토해보고, 최근까지의 국가들의 실행을 고려하여 그러한 접근법을 평가해보고자 한다.

As cyberspace has emerged through technological development and its use has expanded, it has become an attractive means or a target for taking military advantage. As the technological environment changed, countries were concerned about how jus ad bellum, which governs the use of armed force by states, could be applied to cyberspace. There are three approaches to applying the concept of use of force to cyber operations, but they are not all completely satisfactory. First, the instrument-based approach, according to which the nature of the means used determines whether the prohibition in the Article 2(4) of the UN Charter applies, is difficult to apply to cyber operations. Second, the target-based approach has a limitation in that it focuses too much on the nature of the target of cyber operations without considering how serious the effects of cyber operations. Third, the effect-based approach represents a limitation in that it can obscure the traditional distinction between armed coercion (armed force) and non-armed coercion, accordingly blurring normative distinction between the prohibition of the use of force and the prohibition of non-intervention. This approach, which considers only the physical effects of cyber operation, overlooked the fact that cyber operations can threaten the safety of a country without causing a physical effect. Despite the limitations of each approach, it is hard to deny that the effect-based approach is the most supportive approach among international law scholars. In addition, recently this approach has been expanded around Western countries. Against this background, this study examines the approach of applying the concept of use of force in Article 2(4) of the UN Charter on cyber operations, and assess these approaches in light of the recent state practices in that regard.

19

비국가 행위자의 사이버오퍼레이션에 대한 국가책임법상 귀속: 북한의 사례를 중심으로

박노형, 박주희

[NRF 연계] 고려대학교 법학연구원 고려법학 Vol.93 2019.06 pp.1-38

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버공간에서의 국제법의 적용 가능성은 2013년 ‘정보안보에 관한 UNGGE’가 국제법 및 UN헌장의 국가에 의한 정보통신기술(ICTs)의 이용, 즉 사이버공간의 이용에 대한 적용을 권고한 이후 UN 등 국제사회에서 인정되고 있다. 사이버공간의 초연결성과 익명성 등의 특성으로 사이버공간에서 또는 사이버공간을 통하여 악의적으로 활동하는 자를 찾아서 그 자의 행위를 국가에 귀속시키는 데 많은 어려움이 발생한다. 단순히 국가의 사이버 기반시설로부터 사이버오퍼레이션이 개시되었다는 것을 근거로 해당 사이버오퍼레이션을 그 국가에 귀속시킬 수 없기 때문이다. 네트워크로 연결되어 있는 사이버 기반시설은 ‘비국가 행위자’(non-State actor)가 탈취하기 쉽고, 사이버오퍼레이션에 관여하는 자들은 실제 스푸핑의 일환으로 의도적으로 특정 국가가 해당 사이버오퍼레이션의 배후에 있는 것 같은 흔적을 남겨놓는다. 특히, 사이버오퍼레이션의 속도나 파급력을 고려했을 때 악의적 사이버오퍼레이션에 신속하게 대응할 필요가 있으나, 귀속의 문제로 인해 대응에 어려움이 발생한다. 마침 2014년 발생한 소니픽처스 해킹, 2016년 발생한 방글라데시 중앙은행 해킹 및 2017년 발생한 워너크라이 랜섬웨어 공격을 비롯한 미국을 대상으로 수행된 비국가 행위자의 악의적 사이버오퍼레이션에 대한 미국 연방수사국(FBI)의 2018년 공소 제기는 사이버오퍼레이션의 국가책임에 있어서 귀속(attribution)의 문제에 관하여 시사하는 바가 크다. 국가책임에 있어서 귀속에 관하여 FBI는 이미 2014년 12월 첫째, 소니픽처스 해킹에 이용된 맬웨어의 분석, 둘째, 소니픽처스 해킹에 이용된 기반시설과 이전에 북한과 직접적으로 관련되었던 악의적 사이버오퍼레이션 사이의 상당한 중복성, 셋째, 소니픽처스 해킹에 사용된 기법이 2013년 한국의 은행 및 방송사를 상대로 북한이 수행한 사이버오퍼레이션과 상당히 유사하다는 점 등을 근거로 북한이 소니픽처스 해킹에 책임이 있다고 발표하였다. 이러한 배경에서 2018년 6월 미국 FBI가 소니픽처스 해킹을 포함한 일련의 악의적 사이버오퍼레이션의 공모자들을 대상으로 제기한 공소장은 악의적 사이버오퍼레이션의 행위자를 찾아내어 특정 국가에 귀속시키는 단계 및 근거를 확인해보는데 중요한 사례가 된다. 요컨대, 조선엑스포는 소프트웨어 등을 제공하는 기업이지만, 북한 정부의 해킹조직인 110호 연구소와 연계된 보조 조직으로 북한 정부의 지시를 받는 실체로 확인되었다. 국가의 보조자(auxiliary)로 기능하는 비국가 행위자는 해당 국가의 지시에 따라 행동하는 것으로 볼 수 있다. 국가가 사실상 지시한 비국가 행위자의 행위는 해당 국가에 귀속되므로 소니픽처스 해킹은 북한에 귀속되는 것이다. 본 논문은 사이버오퍼레이션의 국제법상 국가 귀속의 문제를 다루고, 2014년 소니픽처스 해킹, 2016년 방글라데시 중앙은행 해킹 및 2017년 워너크라이 랜섬웨어 공격의 북한에 대한 사실상의 귀속 문제를 검토하며, 비국가 행위자 행위를 국가에 귀속시키는 문제에 관하여 동 사례들이 시사하는 바를 검토한다.

A possibility of applying international law to cyberspace was agreed by the 3rd UNGGE in information security in 2013, and then it was continually endorsed internationally. Due to connectedness and anonymity in cyberspace, however, it would be difficult to find those having done malicious cyber operations and attribute those or their activities to a certain State. It would be difficult to attribute such cyber operations to a certain State from a mere fact that a certain cyber operation was launched from that State. In addition, non-State actors are likely to exploit cyber infrastructure connected through networks, and those involved in cyber operations may leave certain traces intentionally implying another State or entity is to be blamed for their own cyber operations. There is a good need to deal with those malicious cyber operations, given the speed and resulting effects of cyber operations, but attribution is still a difficult matter. The US DoJ's complaint made in 2018 against malicious cyber operations directed at the US including Sony Pictures hacking is meaningful for understanding an issue of attributing cyber operation in State responsibility. In December 2014 the FBI already declared that North Korea was responsible for Sony Pictures hacking on the basis of the following reasoning: first, the analysis of the malware used in Sony Picture hacking; second, the overlapping between the infrastructure used for Sony Picture hacking and the previous malicious cyber operations directly related to North Korea; third, the method used in Sony Pictures hacking is very similar to those cyber operations done by North Korea towards those banks and broadcasting companies in the ROK. In this respect the complaint by the FBI against malicious cyber operations including Sony Pictures hacking in 2018 must be a good resource in ascertaining both finding those who did a series of malicious cyber operations and attributing those to a certain country, here North Korea. For example, Chosun Expo is a private company doing business like supplying software, but it was found to be affiliated to Lab 101 which is a hacking element of North Korean government. The action done by non-State actors, here Park and Chosun Expo, which were instructed by a State is to be attributed to the latter State, here North Korea. The attribution of cyber operations under international law, factual attribution of malicious cyber operations targeting the US including Sony Pictures hacking to North Korea, and any implications of those cyber operations for the matter of attribution of non-State actors are discussed accordingly.

20

사이버공간에서 선제공격의 성격과 확장성

장노순

[NRF 연계] 한국국가정보학회 국가정보연구 Vol.15 No.2 2022.12 pp.39-74

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버위협 활동에 대한 대응전략으로 외교협상, 공개지목, 형사기소, 경제제재 등은 만족할만한 억지 효과를 거두지 못하고 있다. 사이버보복이나 응징은 사이버위협 행위자를 대상으로 직접 취하기에 사이버공간의 불확실성과 실질적인 효과를 담보하기 어렵다. 또한 배후 국가에 대해 책임을 묻기에는 정당성 확보의 한계와 안보질서의 부작용 때문에 현실적으로 제한되어 있다. 사이버 억지전략의 제약을 극복하기 위한 사이버 선제공격이 적극적으로 채택되는 경향이다. 사이버 선제공격은 사이버안보구조에서 기존의 우려를 해소하는 대안으로 전략적 효용성이 크다. 사이버보복과 응징은 확전의 위험이 있고, 이를 우려하는 국가는 단호한 의지를 상대방에게 전달하는 정보전달력의 제약에 놓이는 단점이 있다. 상대방에게 자국의 의도를 정확하게 전달하는 역량으로 정보전달력은 사이버공간에서 물리적 공간에 비해 어렵다. 그러나 사이버 선제공격은 확전의 위험을 완화하는 전략의 목적을 설정하고 표적을 선정한다. 이 과정에서 사이버 비밀 선제공격은 정보전달력의 모호성을 적정하게 유지하면서 확전의 위험을 오히려 조절하는 긍정적인 기능을 한다. 이런 이유로 사이버 선제공격은 다른 안보수단의 대체용, 보조용, 보충용으로 폭넓게 이용되고 있다. 그럼에도 확전의 위험은 적절하게 조절되고 있고, 선제공격의 책임과 정당성을 회피하는 전략수단으로 기여한다.

As a response against cyber threats, current countermeasures such as diplomacy, public attribution and economic sanctions are not enough to assure the deterrent effects. It is inappropriate to apply cyber retaliation or punishment directly into cyber attackers because of strategic uncertainty in cyberspace, which is characterized with limits of cyber deterrence and potential of cyber escalation. Also, any states sponsoring hackers can easily deny their involvements with cyber threats. Offensive cyber operations are regarded as an alternative that is more effective to overcome those difficulties. Cyber retaliation can escalate cyber conflict so that it constrains a victim state to control its actions that may convey high intelligibility. However, offensive cyber operations are likely to set clear targets to relieve low intelligibility. Secret offensive cyber operations alleviate the danger of escalation while protecting the information sources required to disclose the opponent's vulnerabilities. Secret offensive cyber operations intend to be expanded into substitution, supplement and support for national security.

 
1 2
페이지 저장